[Full-disclosure] Reminder: HITBSecConf2007 - Malaysia is less than 2 weeks away

2007-08-22 Thread Praburaajan
HITBSecConf2007 - Malaysia is a mere 2 weeks away! Organized as a community centric, non-profit effort, HITBSecConf is Asia's largest network security event featuring 4 keynote speakers, 7 tracks of technical training sessions and access to over 30 hours of deep knowledge demos and presentation

Re: [Full-disclosure] Vulnerabilities digest

2007-08-22 Thread Steven M. Christey
On Tue, 21 Aug 2007, 3APA3A wrote: > 6. Ivan Nl (http://uNkn0wn.eu) reports vulnerabilities in > Linkliste 1.2, Butterfly online vistors counter 1.08, mcLinksCounter > 1.2, My_REFERER 1.08. > > Original messages in English are available from > http://securityvulns.com/sour

[Full-disclosure] Popular Malware Kits and Tools

2007-08-22 Thread Dancho Danchev
The following are links to some of the currently popular malware kits in action, as well as several misc tools, with assessments of the malicious URLs, detection rates, and related screenshots that were obtained : The Nuclear Malware Kit http://ddanchev.blogspot.com/2007/08/nuclear-malware-kit.htm

[Full-disclosure] [ GLSA 200708-17 ] Opera: Multiple vulnerabilities

2007-08-22 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200708-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ GLSA 200708-16 ] Qt: Multiple format string vulnerabilities

2007-08-22 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200708-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] Buffer-overflow in the Asura engine

2007-08-22 Thread Luigi Auriemma
### Luigi Auriemma Application: Asura engine (network SDK) http://www.rebellion.co.uk Games:Rogue Trooper <= 1.0 Prism: Guard

[Full-disclosure] Camino release 1.5.1 fixes several vulnerabilities

2007-08-22 Thread Juha-Matti Laurio
It appears that Camino Project has released new security update version 1.5.1 recently. Reference: Camino 1.5.1 Release Notes http://www.caminobrowser.org/releases/1.5.1/ "Upgraded to version 1.8.1.6 of the Mozilla Gecko rendering engine, which includes several critical security and stability fi

Re: [Full-disclosure] Security Contact for FOX Sports

2007-08-22 Thread Jay
May try: Fox Sports Interactive Media, LLC. Business & Legal Affairs 407 N. Maple Drive Beverly Hills, California 90210 Telephone: (310) 969-7192 e-mail: [EMAIL PROTECTED] Jay - Original Message - From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] To: full-disclosure@lists.grok.org.uk

[Full-disclosure] Security Contact for FOX Sports

2007-08-22 Thread foxworm
Does anyone have a security contact for FOX sports? -- Click for free information on accounting careers, $150/hour potential. http://tagline.hushmail.com/fc/Ioyw6h4dCeQnmNQQ42y45NE9mVwnL3mYaWR0APZbmb61bKKPUSSzmI/ ___ Full-Disclosure - We believe in it.

Re: [Full-disclosure] Announcement: Releasing CORE GRASP for PHP. An open source, dynamic web application protection system.

2007-08-22 Thread Ezequiel Gutesman
The correct URL is http://grasp.coresecurity.com Ezequiel Gutesman wrote: > CORE GRASP for PHP is a web-application protection software aimed at > detecting and blocking injection vulnerabilities and privacy violations. > As mentioned during its presentation at Black Hat USA 2007, GRASP is > bein

[Full-disclosure] Announcement: Releasing CORE GRASP for PHP. An open source, dynamic web application protection system.

2007-08-22 Thread Ezequiel Gutesman
CORE GRASP for PHP is a web-application protection software aimed at detecting and blocking injection vulnerabilities and privacy violations. As mentioned during its presentation at Black Hat USA 2007, GRASP is being released as open source under the Apache 2.0 license and can be obtained from http

[Full-disclosure] Ripe Website Manager SQL Injection and Cross Site Scripting Vulnerabilities

2007-08-22 Thread OS2A BTO
Refer to the advisory... OS2A Ripe Website Manager SQL Injection and Cross Site Scripting Vulnerabilities OS2A ID: OS2A_1009 Status: 07/11/2007 Issue Discovered

[Full-disclosure] Remote eavesdropping with SIP Phone GXV-3000

2007-08-22 Thread Radu State
While playing with the SIP Madynes stateful fuzzer (for a description see http://hal.inria.fr/inria-00166947/en), we have realized that some SIP stack engines have serious bugs allowing to an attacker to automatically make a remote phone accept the call without ringing and without asking the