[Full-disclosure] Disinfectors for the calculator virus (ti89.Gaara)

2007-06-03 Thread Piotr Bania
Hey, For those who are interrested, i made two types of Gaara (the calculator virus) disinfectors. The first one patches the virus body, which causes to return the control to the host just when the EPO injection travels the control to the virus. So the virus will not get executed at all. And t

[Full-disclosure] SNMY200706_01 : GBD UPX File Handling Buffer Overflow Vulnerability

2007-06-03 Thread xWinGs
Title : GBD UPX File Handling Buffer Overflow Vulnerability security.net.my Advisory: SNMY200706_01 Release Date: 2007-06-02 Last Update : 2007-06-02 Critical: Low Impact : System access Where : From Local Solution Status

[Full-disclosure] RESEND new Copy : SNMY200706_01 : GBD UPX File Handling Buffer Overflow Vulnerability

2007-06-03 Thread xWinGs
Title : GBD UPX File Handling Buffer Overflow Vulnerability security.net.my Advisory: SNMY200706_01 Release Date: 2007-06-02 Last Update : 2007-06-02 Critical: Low Impact : System access Where : From Local Solution Status

[Full-disclosure] FoFuS - PoC bot using DNS cover channel

2007-06-03 Thread Fábio Martins a.k.a Fósforo
I haven't seem a bot using dns covert channel, so i've tried to create one. client poorly written in assembly 32 bits and server poorly written in perl. given a list of public domains extracted from http://freedns.afraid.org/ the bot tries to contact his master and after a very simple challenge (x

[Full-disclosure] apryl maynard, internet humanitarian

2007-06-03 Thread Joseph Evers
Now this is a story all about how Apryl's life got flipped, turned upside down and I'd like to take a minute to tell you a tale of how this fat lesbian WEB DESIGNER failed Wetwork: Apryl Maynard, daughter of Robin and John (deceased) birthday: april 12, 1979 lj: wetwork.livejournal.com myspace: m

[Full-disclosure] screen 4.0.3 local Authentication Bypass

2007-06-03 Thread rembrandt
Please take a look at the Attachement dear List moderator. :) Kind regards, Rembrandt _ _ _ _ ___ _ _ _ / / / / / / / _/_ __/ / / / / /_/ / __/ / // / / / / /_/ / / __ / /___/ // / / / / __

[Full-disclosure] Full Path Disclosure eqDKP 1.3.2c and prior

2007-06-03 Thread kefka
eqDKP 1.3.2c and prior 'compare' variable reveals the full path because eqdkp fails to properly sanitize user-supplied input Example: /path-to-eqdkp/listmembers.php?compare=%00 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/