[Full-disclosure] POC: for Asterisk SIP INVITE remote DOS

2007-03-24 Thread Radu State
Due to many requests for the POC and since most Asterisk systems should have been patched by now, please find in this message the POc for our advisory posted on http://seclists.org/fulldisclosure/2007/Mar/0315.html http://seclists.org/fulldisclosure/2007/Mar/0315.html usage

Re: [Full-disclosure] Sexy, spankable 22 year old girl looking for a wild time

2007-03-24 Thread rob musial
It's funny that this received more attention than any other topic I've seen in awhile On 3/23/07, Dude VanWinkle [EMAIL PROTECTED] wrote: On 3/22/07, evilrabbi [EMAIL PROTECTED] wrote: I called that number because I didn't think it was real snip suuure, THATS why you called up, you deviant

Re: [Full-disclosure] Chinese Professor Cracks Fifth Data SecurityAlgorithm (SHA-1)

2007-03-24 Thread Dude VanWinkle
On 3/23/07, Michael Silk [EMAIL PROTECTED] wrote: On 3/23/07, Dave No, not that one Korn [EMAIL PROTECTED] wrote: Tim wrote: Hello, On Wed, Mar 21, 2007 at 06:45:19PM +0300, 3APA3A wrote: Dear Michael Silk, First, by reading 'crack' I thought lady can recover full

[Full-disclosure] FLEA-2007-0002-1: inkscape

2007-03-24 Thread Foresight Linux Essential Announcement Service
Foresight Linux Essential Advisory: 2007-0002-1 Published: 2007-03-24 Rating: Major Updated Versions: inkscape=/[EMAIL PROTECTED]:1-devel//1/0.45.1-1 group-dist=/[EMAIL PROTECTED]:1-devel//1/1.1-0.8-4 References: https://issues.foresightlinux.org/browse/FL-199

Re: [Full-disclosure] [fuzzing] Fuzzled - Perl fuzzing framework

2007-03-24 Thread Jared DeMott
Tim Brown wrote: Having noticed the popularity of fuzzing tools recently, I was feeling a bit left out. Where is the Perl framework to complete the family? With that in mind I've spent the last months working on something that should fill the gap - Fuzzled. Fuzzled is a powerful fuzzing

Re: [Full-disclosure] Sexy, spankable 22 year old girl looking for a wild time

2007-03-24 Thread Knud Erik Højgaard
On 3/24/07, rob musial [EMAIL PROTECTED] wrote: It's funny that this received more attention than any other topic I've seen in awhile people love the tampon stuff, pervs. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Chinese Professor Cracks Fifth Data Security Algorithm (SHA-1)

2007-03-24 Thread wac
Of course not, is enough to find a collision and you'll get for example a message signed by somebody else that looks completely authentic since signatures encrypt that hash with the private key. On 3/21/07, Blue Boar [EMAIL PROTECTED] wrote: 3APA3A wrote: First, by reading 'crack' I

[Full-disclosure] Fizzle : Firefox Extension Vulnerability

2007-03-24 Thread CrYpTiC MauleR
-- Powered by Outblaze ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Fizzle : Firefox Extension Vulnerability

2007-03-24 Thread CrYpTiC MauleR
-- Powered by Outblaze ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] hi5 Antiphishing Departement

2007-03-24 Thread beNi
I felt the need to extend the list of Antiphishing Departements of some Social Networks, so the Myspace Antiphishing Departement ( http://www.myspace.com/antiphishing ) got another friend, the hi5 Antiphishing Departement ( http://antiphishing.hi5.com ). Full blog post is available here:

Re: [Full-disclosure] XBOX ID's being Jacked

2007-03-24 Thread Jason Miller
i didn't say your son got pwnd, kevin and yeah they both prob pissed each other off. go figure. On 3/24/07, Kevin Finisterre (lists) [EMAIL PROTECTED] wrote: Its not my son... and as far as getting cocky, its a 2 way street for sure in this situation. -KF On Mar 24, 2007, at 11:47 AM, Jason

[Full-disclosure] Fizzle : Firefox Extension Vulnerability

2007-03-24 Thread CrYpTiC MauleR
Fizzle allows feeds to use HTML in feed data resulting in JavaScript being run in the chrome: window with chrome permissions. The extension will convert HTML entities back to their ASCII equivalents thus lt; becomes and so forth. Various feeds fields are vulnerable including the title which

Re: [Full-disclosure] Chinese Professor Cracks Fifth Data Security Algorithm (SHA-1)

2007-03-24 Thread Valdis . Kletnieks
On Sat, 24 Mar 2007 11:48:10 CDT, wac said: Of course not, is enough to find a collision and you'll get for example a message signed by somebody else that looks completely authentic since signatures encrypt that hash with the private key. No, if you have a signature to some text, you need to