[Full-disclosure] Layered Defense Advisory: Symantec AV Corporate Edition Format String Vulnerability

2006-09-13 Thread Deral Heiland
== Layered Defense Advisory 13 September 2006 == 1) Affected Software Symantec AntiVirus Corporate Edition 10.0 Symantec AntiVirus Corporate Edition 9.0 Symantec AntiVirus Corporate Edition 8.1 ==

[Full-disclosure] Re: Backdooring PDF Files

2006-09-13 Thread Markus Jansson
POC did nothing for my Foxit PDF reader. No www-page was opened and no script was executed. Maybe you folks should just dump the clumsy and insecure Acrobat Reader and move onto something better for reading .pdf documents? ;) -- My computer security & privacy related homepage http://www.ma

[Full-disclosure] Hotmail/MSN Multiple cross site scripting ( XSS )

2006-09-13 Thread securma
Title: Hotmail/MSN Multiple cross site scripting ( XSS )   Author:  Securma MassineMorX Security Research Teamhttp://www.morx.org   Original Advisory/Xploit : http://www.morx.org/msnxss.txt   Vulnerability : Multiple cross site scripting ( XSS )  Severity: Medium/High   Description : msn.com

Re: [Full-disclosure] Backdooring PDF Files

2006-09-13 Thread pdp (architect)
I have tested both of the examples and no warning boxes are showing. It seams that everybody is getting different results. Interesting! On 9/13/06, Juha-Matti Laurio <[EMAIL PROTECTED]> wrote: Proof of Concept for example 1 (backdoored1.pdf) opened with Adobe Reader 7.0.8 (i.e. no browser plug-i

Re: [Full-disclosure] Backdooring PDF Files

2006-09-13 Thread David Kierznowski
I installed 7.0.8 (latest version) for testing. If the document is loaded from the browser you receive no warning. v7.0.8 seems to warn the user if the document is loaded from the desktop. I think this has to do with different Adobe contexts. -- David Kierznowski On 13/09/06, pdp (architect) <

[Full-disclosure] Re: RSA SecurID SID800 Token vulnerable by design

2006-09-13 Thread Vin McLellan
On FD, and in several other security forums, Hadmut Danisch <[EMAIL PROTECTED]>, a respected German information security analyst, recently published a harsh critique of one optional feature in the SID800, one of the newest of the six SecurID authentication tokens -- some with slightly differe

Re: [Full-disclosure] RE: OT - Check this out - Full disclosure is apt for this.

2006-09-13 Thread Nick FitzGerald
[EMAIL PROTECTED] to me: > === > So you agree with the > thinking part of the world > that GWB and his so- > called "advisors" are a > bunch of idiots... > == > I don't recall seeing your credentials for even belonging to that group, > let alone t

[Full-disclosure] Mailman 2.1.8 Multiple Security Issues

2006-09-13 Thread Moritz Naumann
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SA0013 - Public Advisory + + Mailman 2.1.8 Multiple Security Issues + + PUBLISHED ON Sep 13, 2006 PUBLIS

[Full-disclosure] [NETRAGARD-20060822 SECURITY ADVISORY] [ APPLE COMPUTER CORPORATION KEXTLOAD VULNERABILITY + ROXIO TOAST TITANUM 7 HELPER APP - LOCAL ROOT COMROMISE]

2006-09-13 Thread Netragard Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Netragard, L.L.C Advisory* *** ~ Strategic Reconnaissance Team ~ ~ http://www.netragard.com -- "We make I.T. Safe.

[Full-disclosure] RE: OT - Check this out - Full disclosure is apt for this.

2006-09-13 Thread [EMAIL PROTECTED]
Nick FitzGerald - === So you agree with the thinking part of the world that GWB and his so- called "advisors" are a bunch of idiots... == I don't recall seeing your credentials for even belonging to that group, let alone the memo that appointe

Re: [Full-disclosure] Backdooring PDF Files

2006-09-13 Thread Juha-Matti Laurio
It is always possible to check the installed Acrobat plug-in with the following test URL: http://gemal.dk/browserspy/acrobat.html (FF and MSIE) The following command works only in Gecko-based browsers: about:plugins - Juha-Matti ___ Full-Disclosur

Re: [Full-disclosure] Backdooring PDF Files

2006-09-13 Thread Juha-Matti Laurio
Yes, the first example opens MSIE without any user interaction when visiting your PoC link with Firefox 1.5.0.6. This issue is more serious due to recent unpatched issues and public exploits in IE. - Juha-Matti David Kierznowski <[EMAIL PROTECTED]> wrote: I installed 7.0.8 (latest version)

Re: [Full-disclosure] RE: OT - Check this out - Full disclosure is apt for this

2006-09-13 Thread ninjadaito
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 BRAVO! Well done bkfsec!! It seems that most everybody knows the truth except those still blinkered by the Neocons and their media brainwashing campaign. BTW, quite a good related article by Manuel Valenzuela (for those interested) can be found

Re: [Full-disclosure] Backdooring PDF Files

2006-09-13 Thread Juha-Matti Laurio
Proof of Concept for example 1 (backdoored1.pdf) opened with Adobe Reader 7.0.8 (i.e. no browser plug-in used) issued a Security Warning dialog box: "The document is trying to conenct to the site: http://www.google.com/owned.html If you trust the site click "Allow", otherwise click "Block"." Op

[Full-disclosure] [SECURITY] [DSA 1176-1] New zope2.7 packages fix information disclosure

2006-09-13 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1176-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff September 13th, 2006

[Full-disclosure] [ GLSA 200609-09 ] FFmpeg: Buffer overflows

2006-09-13 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200609-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ GLSA 200609-08 ] xine-lib: Buffer overflows

2006-09-13 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200609-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ GLSA 200609-07 ] LibXfont, monolithic X.org: Multiple integer overflows

2006-09-13 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200609-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] Multiple Vulnerabilities in Apple QuickTime

2006-09-13 Thread David_Marcus
___ McAfee, Inc. McAfee Avert(tm) Labs Security Advisory Public Release Date: 2006-09-12 Apple QuickTime Multiple Vulnerabilities CVE-2006-4382, CVE-2006-4384, CVE-2006-4385, CVE-2006-4386, CVE-2006-4388, CVE-2006-4389

[Full-disclosure] Backdooring PDF Files

2006-09-13 Thread David Kierznowski
Recently, there has been alot of hype involving backdooring various web technologies. pdp (arcitect) has done alot of work centered around this area. I saw Jeremiah Grossman mention PDF's being "BAD", however, I was unable to easily locate any practical reasons as to why. I decided to investigate

[Full-disclosure] [SECURITY] [DSA 1175-1] New isakmpd packages fix replay protection bypass

2006-09-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1175-1[EMAIL PROTECTED] http://www.debian.org/security/ Noah Meyerhans September 13th, 2006

Re: [Full-disclosure] RE: OT - Check this out - Full disclosure is apt for this

2006-09-13 Thread bkfsec
[EMAIL PROTECTED] wrote: It's not a joke Gary. If you are attempting to make the claim that Saddam NEVER had WMD you are either Profoundly Misinformed, Astonishingly Ignorant of Late 20th Century History; or simply Lying. Wow. How utterly intellectually dishonest of you... Saying that the

[Full-disclosure] Cisco IOS VTP issues

2006-09-13 Thread FX
Phenoelit Advisory [ Title ] Cisco Systems IOS VTP multiple vulnerabilities [ Authors ] FX <[EMAIL PROTECTED]> Phenoelit Group (http://www.phenoelit.de) Advisoryhttp://www.phenoelit.de/stuff/CiscoVTP.txt [ Affected Products ] Cisco I

[Full-disclosure] Re: OT - Check this out - Full disclosure is aptfor this

2006-09-13 Thread Dave \"No, not that one\" Korn
[EMAIL PROTECTED] wrote: > Contex - > > > >> If you consider that America are >> able to lie about the weapons of mass >> destruction and then admit it, > > "America" never lied about WMD. > America is not in a posit

[Full-disclosure] [USN-345-1] mailman vulnerabilities

2006-09-13 Thread Martin Pitt
=== Ubuntu Security Notice USN-345-1 September 13, 2006 mailman vulnerabilities CVE-2006-2941, CVE-2006-3636 === A security issue affects the following Ubuntu releases: Ubuntu

[Full-disclosure] [SECURITY] [DSA 1161-2] New Mozilla Firefox packages fix several vulnerabilities

2006-09-13 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1161-2[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 13th, 2006

[Full-disclosure] NetPerformer FRAD ACT Multiple Vulnerabilities

2006-09-13 Thread arif . jatmoko
NetPerformer Frame Relay Access Device (FRAD) ACT Multiple Vulnerabilities                         .<=[ Arif Jatmoko ]=>. Release Date : 8 July 2006 Product Affected :    - NetPerformer FRAD ACT SDM-95xx version 7.xx (R1), earlier, and possibly newer    - NetPerformer FRAD ACT SDM-93xx versio

[Full-disclosure] THC Nokia Phone Unlock

2006-09-13 Thread rm
The Hacker's Choice is proud to release http://www.thc.org/thc-nokia-unlock The tools exploits a design flaw on nokia mobile phones to remove the phone-lock. >From Nokia's webpage: "The Phone Lock prevents your phone data from being accessed if your phone is stolen. "The l