Re: [Full-disclosure] *BSD banner INT overflow vulnerability

2006-11-25 Thread J.A. Terranson
On Wed, 22 Nov 2006, Sean Comeau wrote: > On Wed, Nov 22, 2006 at 12:25:46PM +0300, dead code crew wrote: > > > > %uname -sir > > FreeBSD 6.1-RELEASE GENERIC > > %gdb banner > > (gdb) r -w 1700 > > Program received signal SIGSEGV, Segmentation fault. > > 0x01010101 in ?? () > > > > This

Re: [Full-disclosure] RCSR fun: stealing FF passwords the easy way

2006-11-25 Thread Stefan Esser
Sorry to disappoint you but this RCSR is nothing else than the usual Web Application Security Hype that happens when one of the big Web2.0 websites that does something really stupid is hit by old stuff. The "new vulnerability" discovered in Firefox was already described in 2005 in Web Application

[Full-disclosure] New Windows tool - NBTEnum 3.3

2006-11-25 Thread Reed Arvin
New Windows tool - NBTEnum 3.3 Tool location: http://reedarvin.thearvins.com/tools/NBTEnum33.zip = Description: NetBIOS Enumeration Utility (NBTEnum) version 3.3 is a utility for Windows that can be used to enumerate NetBIOS information from one host or a range of hosts. The enumerated inf

[Full-disclosure] AttackAPI 2.0 alpha

2006-11-25 Thread pdp (architect)
http://www.gnucitizen.org/projects/attackapi/ I understand that this announcement may be disturbing but I decided to do it anyway. I am quite happy to introduce AttackAPI 2.0 branch which is a lot better then the 1.x. Now it is a lot easier to code JavaScript attack vectors. There are also quite

Re: [Full-disclosure] RCSR fun: stealing FF passwords the easy way

2006-11-25 Thread pagvac
FYI, it appears this issue was reported way back in August 2006 by RSnake: http://ha.ckers.org/blog/20061122/programmatic-password-theft-is-back/ On 11/24/06, pagvac <[EMAIL PROTECTED]> wrote: > RCSR (Reverse Cross-Site Request) attacks discovered by Robert Chapin, > make the theft of passwords i