[Full-disclosure] Month Of Hackerrats Bugs

2007-06-17 Thread snitches
Following suit to the "month of" bugs - we are pleased to announce the disclosures of cooperating snitches liars and conmen in the industry. We present our second Hackerrat with an eye opening Jericho Jericho (Brian Martin) and his cohorts at the website Attrition were at one time mining hacker

[Full-disclosure] TIBS Infrastructure Dissection...

2007-06-17 Thread Botnet Hunter
UNDESTRUCtibsLE http://dailymarc.blogspot.com/2007/06/undestructibsle.html "So there's a Tibs in a nutshell. There is a password protected admin interface to the whole shooting match, but I'm not the type to attempt cracking such things. Versions of the interface have been seen in the past due to

[Full-disclosure] WSPortal version 1.0 Path Disclosure Vulnerability

2007-06-17 Thread SecurityResearch
netVigilance Security Advisory #32 WSPortal version 1.0 Path Disclosure Vulnerability Description: WSPortal is a site management system coded in PHP/MySQL. It is capable of adding pages, adding news to pages, adding images to news articles, alerting the site or a specific ip address, private messa

[Full-disclosure] WSPortal version 1.0 SQL Injection Vulnerability

2007-06-17 Thread SecurityResearch
netVigilance Security Advisory #33 WSPortal version 1.0 SQL Injection Vulnerability Description: WSPortal is a site management system coded in PHP/MySQL. It is capable of adding pages, adding news to pages, adding images to news articles, alerting the site or a specific ip address, private messag

[Full-disclosure] Utopia News Pro version 1.4.0 XSS Attack Vulnerability

2007-06-17 Thread SecurityResearch
netVigilance Security Advisory #34 Utopia News Pro version 1.4.0 XSS Attack Vulnerability Description: Utopia News Pro is a powerful and scalable news management system for any web site. News Pro, written in PHP and backed by the renowned MySQL database system, Utopia Software's News Pro is an ide

[Full-disclosure] [LJVN-0001] Livejournal.ru non-persistent XSS

2007-06-17 Thread ljuser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Summary === Livejournal.ru non-persistent XSS leaks livejournal.com user name and may allow cookie-stealing attacks on livejournal.ru itself. Attack works on users that have never visited livejournal.ru - only requirement is that they are logged in

[Full-disclosure] [SECURITY] [DSA 1311-1] New PostgreSQL 7.4 packages fix privilege escalation

2007-06-17 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1311-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff June 17th, 2007

[Full-disclosure] [SECURITY] [DSA 1312-1] New libapache-mod-jk packages fix information disclosure

2007-06-17 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1312-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff June 18th, 2007

Re: [Full-disclosure] Month Of Hackerrats Bugs

2007-06-17 Thread johnny.mcdanger
quite a pleasure to see another well drafted composition to full disclosure. it appears we have quite a real hacker/wanker giving us some wonderful information. i hope the people you reveal had great success in working with the authorities. we should rename this to a month of heros if you should co

Re: [Full-disclosure] Month Of Hackerrats Bugs

2007-06-17 Thread J. M. Seitz
Well, in response: 1) If the Month of BS that you are spraying is all you can contribute to the security community, you are leagues behind Jericho who heads the OSVDB, VIM and does many other countless things, tirelessly day in and day out. 2) Who cares? If the FBI or RCMP (in my case from Canada