Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability

2006-05-02 Thread 0x80
CERT has more leaks than a whore who has been anally fucked with a loaded shotgun. On Mon, 01 May 2006 12:31:50 -0700 [EMAIL PROTECTED] wrote: On Mon, 01 May 2006 14:51:23 EDT, Tim Bilbro said: Some have suggested a 'Vulnerability Escrow' A third party that tracks and holds vulnerability

[Full-disclosure] [SECURITY] [DSA 1049-1] New Ethereal packages fix several vulnerabilities

2006-05-02 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1049-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze May 2nd, 2006

Re: [Full-disclosure] MSIE (mshtml.dll) OBJECT tag vulnerability

2006-05-02 Thread Sol Invictus
Gee All this fornication under the command of the king is turning violent. I don't think the King would approve [EMAIL PROTECTED] wrote: CERT has more leaks than a whore who has been anally fucked with a loaded shotgun. On Mon, 01 May 2006 12:31:50 -0700 [EMAIL PROTECTED] wrote:

[Full-disclosure] Oracle, where are the patches???

2006-05-02 Thread David Litchfield
A regular patch release cycle is a good thing. It allows system administrators to plan ahead and minimize server downtime. If I, as a system administrator, know that on the 18th of April 2006 a critical patch is going to be released I'll plan to stay late at work that night and start the

[Full-disclosure] [ GLSA 200605-02 ] X.Org: Buffer overflow in XRender extension

2006-05-02 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200605-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200605-03 ] ClamAV: Buffer overflow in Freshclam

2006-05-02 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200605-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200605-04 ] phpWebSite: Local file inclusion

2006-05-02 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200605-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] Hola Distro Help me

2006-05-02 Thread Edgardo Zavala
en español mi idioma --- Suplico su ayuda ¿Como crear mi propia distribucion basada en fedora? Auxilio, se que se puede modificar, pero como. Perdonen mi ignorancia. Pero les agradezco me den informacion. Gracias. --- en ingles --- :( -- I need your

[Full-disclosure] Hola Distro Help me

2006-05-02 Thread Edgardo Zavala
en espanol mi idioma --- Suplico su ayuda Como crear mi propia distribucion basada en fedora? Auxilio, se que se puede modificar, pero como.Perdonen mi ignorancia.Pero les agradezco me den informacion.Gracias.--- en ingles --- :( --I need your help How

[Full-disclosure] RE: Oracle, where are the patches???

2006-05-02 Thread Kornbrust, Alexander
David, You are right. I have only a few things to add. 1.) In the April CPU 2006 patches for 9.2.0.7, Oracle forgot to sanitize a parameter in one of the SDO packages. Oracle sanitized one parameter twice (Copy/Paste-Error). Oracle assigned a new bug number (7520291) for this issue. == Such

Re: [Full-disclosure] Hola Distro Help me

2006-05-02 Thread f y
But I am thankful to them give information me. you suck ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Hola Distro Help me

2006-05-02 Thread Edgardo Zavala
jijiji estan re locos se creen muy inteligentes jeje Falta que se crean dioses ademas, me imagino que la lista es para ayudar no para contestar estupideces bytes2006/5/2, f y [EMAIL PROTECTED]: But I am thankful to them give information me. you suck

Re: [Full-disclosure] Hola Distro Help me

2006-05-02 Thread 0x80
Should you not be downtown NYC protesting or something? www.redhat.com is probably a better place to start than on here. But as the saying goes, if you have to ask -- you probably aren't smart enough to do. On Tue, 02 May 2006 12:31:41 -0700 Edgardo Zavala [EMAIL PROTECTED] wrote:

[Full-disclosure] Heard of Scab 5 or Scab V for Hard Drive evidence elimination?

2006-05-02 Thread Red Leg
I had a client claim that an outside lab found that a subject of an investigation used Scab 5 or Scab V software to cover tracks on a windows machine. Anyone hear of this program? Frankly, I'm wondering if the non-tech person with whom I speaking, phonetically erred? Anyone? Thanks

Re: [Full-disclosure] Hola Distro Help me

2006-05-02 Thread 'FoR ReaLz' E. Balansay
Dude, I'm Edgardo too, and yes you do suck. Try http://www.fedoraforum.org/ Laters! Edgardo On Tue, 2 May 2006, Edgardo Zavala wrote: jijiji estan re locos se creen muy inteligentes jeje Falta que se crean dioses ademas, me imagino que la lista es para ayudar no para contestar estupideces

Re: [Full-disclosure] Hola Distro Help me

2006-05-02 Thread Edgardo Zavala
jajajaja buena broma has de ser gringo jiji realy and in serious I apologize to write so many stupid words here jijiEl día 2/05/06, 'FoR ReaLz' E. Balansay [EMAIL PROTECTED] escribió: Dude, I'm Edgardo too, and yes you do suck.Try http://www.fedoraforum.org/Laters!EdgardoOn Tue, 2 May 2006,

[Full-disclosure] [ MDKSA-2006:081 ] - Updated xorg-x11 packages fix vulnerability

2006-05-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2006:081 http://www.mandriva.com/security/

[Full-disclosure] Quagga RIPD unauthenticated route table broadcast

2006-05-02 Thread Konstantin V. Gavrilenko
Arhont Ltd - Information Security Advisory by:Konstantin V. Gavrilenko (http://www.arhont.com) Arhont ref: arh200604-1 Advisory: Quagga RIPD unauthenticated route table broadcast Class: design bug? Version:Tested on Quagga suite v0.98.5 v0.99.3(Gentoo, 2.6.15) Model

[Full-disclosure] Quagga RIPD unauthenticated route injection

2006-05-02 Thread Konstantin V. Gavrilenko
Arhont Ltd - Information Security Advisory by:Konstantin V. Gavrilenko (http://www.arhont.com) Arhont ref: arh200604-2 Advisory: Quagga RIPD unauthenticated route injection Class: design bug? Version:Tested on Quagga suite v0.98.5 v0.99.3 (Gentoo, 2.6.15) Model

[Full-disclosure] Dynamic Evaluation Vulnerabilities in PHP applications

2006-05-02 Thread Steven M. Christey
-- Dynamic Evaluation Vulnerabilities in PHP applications -- Following is a brief introduction to a growing class of serious vulnerabilities in PHP applications. They can allow execution of

Re: [Full-disclosure] What is wrong with schools these days?

2006-05-02 Thread Valdis . Kletnieks
On Sun, 30 Apr 2006 20:16:27 EDT, Gaddis, Jeremy L. said: While this often holds true, there should always a central infosec department that has the ability to kill a switch port. Kill the network connection to a critical server exposing private information and people take notice pretty