Re: [Full-disclosure] ProtectFly/RegisterFly - Whoisinformation - Non-Disclosure legal??

2006-08-06 Thread Nancy Kramer
I agree. Everytime I want to build a site I have a terrible time finding a good name that is not taken. All the best names are taken and parked with junk on them or even worse spyware. Often business people do ruin what they touch especially when they just want to take the money and run and

Re: [Full-disclosure] LONG LIVE HEZBOLLAH AND LEBANON; DOWN WITH AMERICA AND ISRAEL

2006-08-06 Thread A . L . M . Buxey
Hi, your email address is interesting, googlemail.com, not gmail.com? are you from google? nah, probably from UK - they've forced people to use that new name due to some legal 'gmail' dispute. http://mail.google.com/mail/help/intl/en-GB/googlemail.html alan

[Full-disclosure] bugs

2006-08-06 Thread Thomas Pollet
Hi,I have found ie crashing when refreshing an iframe containing an xml file with xsl stylesheet (takes a while to crash).I used this html:- htmlheadscript language=_javascript_function refresh() { frames[0].window.location.reload(); setTimeout(refresh();,

Re: [Full-disclosure] 0-day XP SP2 wmf exploit

2006-08-06 Thread FuLLBLaSTstorm
P-o-C really works and successfully crashed my explorer.exe :)) . Impatiently waiting for public release of the final exploit.P.S. I think It was not last vulnerability in GDI32.DLL. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] 0-day XP SP2 wmf exploit

2006-08-06 Thread [EMAIL PROTECTED]
a crash does not mean exploitable ... and the chance there is something to exploit with this are low regarding how it has been sent to the list (another shit parts of the common shits here), nor the shit discloser is much than ignorant. FuLLBLaSTstorm wrote: P-o-C really works and

[Full-disclosure] PHP: Zend_Hash_Del_Key_Or_Index Vulnerability

2006-08-06 Thread Stefan Esser
Hello, word about this vulnerability is out for several weeks (or months). Because of this I spare you the advisory and only point you to my little article describing what exactly this vulnerability is, that I disclosed to the PHP project 6 months ago: The rating for this vulnerability should

[Full-disclosure] [ GLSA 200608-09 ] MySQL: Denial of Service

2006-08-06 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200608-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] Multiple vulnerabilities in DConnect Daemon 0.7.0 (CVS 30 Jul 2006)

2006-08-06 Thread Luigi Auriemma
### Luigi Auriemma Application: DConnect Daemon http://www.dc.ds.pg.gda.pl Versions: = 0.7.0 and CVS = 30 Jul 2006 Platforms:Windows, *nix, *BSD and others Bugs: A]

[Full-disclosure] [ GLSA 200608-10 ] pike: SQL injection vulnerability

2006-08-06 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200608-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200608-11 ] Webmin, Usermin: File Disclosure

2006-08-06 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200608-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Re: when will AV vendors fix this???

2006-08-06 Thread ...
good idea indeed and, since ntfs drivers are available for linux for a long time now, someone really willing to fix the issue could start there... - Original Message - From: Denis Jedig [EMAIL PROTECTED] To: full-disclosure@lists.grok.org.uk Cc: bugtraq@securityfocus.com Sent:

[Full-disclosure] 0-day XP SP2 wmf exploit (some details)

2006-08-06 Thread cyanid-E
There is some details for wannabees :) 1. 'Bad' wmf record: 07 00 00 00 length of record (in words) FC 02 type (CreateBrushIndirect) 08 00 00 00 00 00 00 80 'packed' (good old Win16 days) LOGBRUSH data: 08 00 - 'packed' lpStyle (may be BS_DIBPATTERNPT [6] or BS_DIBPATTERN8X8 [8]) 00 00 00