[Full-disclosure] [USN-508-1] Linux kernel vulnerabilities

2007-08-30 Thread Kees Cook
=== Ubuntu Security Notice USN-508-1August 31, 2007 linux-source-2.6.15 vulnerabilities CVE-2005-0504, CVE-2007-2242, CVE-2007-3104, CVE-2007-3105, CVE-2007-3848, CVE-2007-4308 =

Re: [Full-disclosure] [Tool] - Metagoofil

2007-08-30 Thread Christian Martorella
Hi Deeþan, In the README, you can find information about the configuration. You must install "libextractor" and change the content of the "extcommand" variable. The program by default has a windows example, comment line 25 and uncomment line 27 for OSX. Regards, Deeþan Chakravarthy wrote:

Re: [Full-disclosure] [Tool] - Metagoofil

2007-08-30 Thread Deeþan Chakravarthy
Christian Martorella wrote: > Tool page: http://www.edge-security.com/soft.php > Download link http://www.edge-security.com/soft/metagoofil-1.2.tar > > Regards, > > Hi Christian, The program seems to work only in windows. I'm only have linux and OSX. Let me know if you have a linux version.

Re: [Full-disclosure] sqlninja 0.1.3 released

2007-08-30 Thread Deeþan Chakravarthy
A. R. wrote: > Hello, fellow security enthusiasts, > > a new version of sqlninja is out at sourceforge ! > > Hi AR, Do you have demo video ? Are there similar tools for non-Microsoft SQL servers ? I'm a linux guy, so really can't simulate SQL servers in my machine. Can you use SQLNinja for no

[Full-disclosure] [USN-509-1] Linux kernel vulnerabilities

2007-08-30 Thread Kees Cook
=== Ubuntu Security Notice USN-509-1August 31, 2007 linux-source-2.6.17 vulnerabilities CVE-2007-3104, CVE-2007-3105, CVE-2007-3513, CVE-2007-3848, CVE-2007-3851, CVE-2007-4308 =

Re: [Full-disclosure] UTF reverse-writing WYSINWG "feature"

2007-08-30 Thread HASEGAWA Yosuke
Hi. On 8/28/07, Tonu Samuel <[EMAIL PROTECTED]> wrote: > But by concerns are related to security. For example even looking title > of this digg.com page with Firefox or Konqueror and you see that browser > name is reversed! I looked into source code with Firefox and lot of > things are reversed to

[Full-disclosure] Immunity Debugger v1.1 Release

2007-08-30 Thread Nicolas Waisman
The number one request this month was "Please implement a Python shell so I can write scripts and play with immlib features on the fly!". This is now done. Enjoy! Next to that we continued our efforts to improve the overall debugging experience with two new libraries, libstackanalyze and Ero C

[Full-disclosure] Cisco CSS WebNS ssh crash

2007-08-30 Thread NetExpress
Undocument bug on Cisco CSS series 11000 with Webns 8.20.0.1 Cisco CSS series 11000 with webns system and ssh daemon crash on ssh crc32 old 2001 exploit Cisco CSS : Webns Version: 08.20.0.01 (using command sh ver) SSH Version: SSHield version 1.6.1, SSH version OpenSSH_3.0.2p1 (using comman

[Full-disclosure] iDefense Security Advisory 08.30.07: Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities

2007-08-30 Thread iDefense Labs
Yahoo Messenger YVerInfo.dll ActiveX Multiple Remote Buffer Overflow Vulnerabilities iDefense Security Advisory 08.30.07 http://labs.idefense.com/intelligence/vulnerabilities/ Aug 30, 2007 I. BACKGROUND Yahoo! Messenger is a instant messaging application that allows users to chat online, share f

Re: [Full-disclosure] [mwp] (Fwd) barclays.co.uk securiy contact

2007-08-30 Thread Gadi Evron
Someone is taking care of you, and at the very least, you will hear a response. > > --- Forwarded message follows --- > From: Gavin Atkinson <[EMAIL PROTECTED]> > To: full-disclosure@lists.grok.org.uk > Date sent:Wed, 29 Aug 2007 18:58:56 +01

Re: [Full-disclosure] UTF reverse-writing WYSINWG "feature"

2007-08-30 Thread Mark Janssen
On 8/30/07, Deeþan Chakravarthy <[EMAIL PROTECTED]> wrote: > scott wrote: > > -BEGIN PGP SIGNED MESSAGE- > > Hash: SHA1 > > > > I remember a guy that set up a firewall box for his wireless AP that > > flipped every page that an unauthorized user accessing his AP would > > get.Really great s

[Full-disclosure] SUSE Security Announcement: Opera (SUSE-SA:2007:050)

2007-08-30 Thread Thomas Biege
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 __ SUSE Security Announcement Package:opera Announcement ID:SUSE-SA:2007:050 Date:

Re: [Full-disclosure] Point, Click ... Eavesdrop: How the FBI Wiretap Net Operates

2007-08-30 Thread hack the gov
On 8/30/07, Ivan . <[EMAIL PROTECTED]> wrote: > http://www.wired.com/politics/security/news/2007/08/wiretap if you own microsoft windows vista they "point,click,get root". -- freenode #n3td3v ___ Full-Disclosure - We believe in it. Charter: http://lis

Re: [Full-disclosure] UTF reverse-writing WYSINWG "feature"

2007-08-30 Thread Deeþan Chakravarthy
scott wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > I remember a guy that set up a firewall box for his wireless AP that > flipped every page that an unauthorized user accessing his AP would > get.Really great stuff! How exactly do you flip webpages from a proxy ? Actually If I und