Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread gjgowey
I think he's thinking that we're following google's example and using pigeons not monkeys. Geoff Sent from my BlackBerry wireless handheld. -Original Message- From: "Harry Muchow" <[EMAIL PROTECTED]> Date: Tue, 9 Oct 2007 11:38:36 To:"sushil Agarwal" <[EMAIL PROTECTED]> Cc:full-disclo

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread S/U/N
[EMAIL PROTECTED] a écrit : > You want to 'unsubscribe'. You now have two choices: No, actually radical one: throw your computer through da window ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Ho

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread gjgowey
For cases like that I usually recommend that the person sells all their worldly posessions and takes up life as a Tibetan monk. Geoff Sent from my BlackBerry wireless handheld. -Original Message- From: S/U/N <[EMAIL PROTECTED]> Date: Tue, 09 Oct 2007 09:23:41 To:full-disclosure@lists.

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread Paul Ooi Cong Jen
I think the best would be stop using email ;) pocj takizo.com/blog On Oct 9, 2007, at 3:23 PM, S/U/N wrote: > [EMAIL PROTECTED] a écrit : >> You want to 'unsubscribe'. You now have two choices: > No, actually radical one: throw your computer through da window > > >

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread Ferdinand Klinzer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yes and back to old school with fire since! ferdinand Am 09.10.2007 um 09:31 schrieb Paul Ooi Cong Jen: > I think the best would be stop using email ;) > > > pocj > takizo.com/blog > > On Oct 9, 2007, at 3:23 PM, S/U/N wrote: > >> [EMAIL PROTECTED]

[Full-disclosure] rPSA-2007-0210-1 xen

2007-10-09 Thread rPath Update Announcements
rPath Security Advisory: 2007-0210-1 Published: 2007-10-08 Products: rPath Linux 1 Rating: Severe Exposure Level Classification: Indirect Root Deterministic Unauthorized Access Updated Versions: xen=/[EMAIL PROTECTED]:devel//1/3.0.3_0-1.6-1 rPath Issue Tracking System: https://issues.r

[Full-disclosure] rPSA-2007-0212-1 util-linux

2007-10-09 Thread rPath Update Announcements
rPath Security Advisory: 2007-0212-1 Published: 2007-10-08 Products: rPath Linux 1 Rating: Major Exposure Level Classification: Local Root Deterministic Privilege Escalation Updated Versions: util-linux=/[EMAIL PROTECTED]:devel//1/2.12r-1.5-1 rPath Issue Tracking System: https://issues

Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

2007-10-09 Thread Andreas Lindenblatt
Juergen Schmidt wrote: > the URI handling problem on Windows XP systems with IE 7 installed hits > a lot of applications, not only Firefox (and mIRC) -- namely Skype, > Acrobat Reader, Miranda, Netscape. Testing shows that the mailto: thingy in Acrobat also works on Windows 2003 Server, SP2. --

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread Fabrizio
"well-defined procedure" go here: https://lists.grok.org.uk/mailman/listinfo/full-disclosure and unsubscribe. no need to flood the list with pointless BS. f On 10/9/07, Ferdinand Klinzer <[EMAIL PROTECTED]> wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Yes and back to old schoo

[Full-disclosure] Owning the internal network with SIP (part 1) and a Linksys Phone

2007-10-09 Thread Radu State
SIP, the IETF endorsed VoIP signaling protocol, is currently used to establish and manage VoIP calls. Many security issues have been addressed until know about the security of VoIP due to the large numbers of attacks coming from the traditional IP networks, but none have addressed the securing

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread Juha-Matti Laurio
We have been waiting this link very-easy-to-find to the list since Monday. The office day is over in many countries outside of USA already and people post OT stuff to the list... Like Fabrizio said, just go and unsubscribe. - Juha-Matti Fabrizio <[EMAIL PROTECTED]> wrote: > "well-defined proce

Re: [Full-disclosure] Core Impact 7.5 Web App pen-testing framework, as good as the hype?

2007-10-09 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Mad technical! On Sun, 07 Oct 2007 19:55:24 -0400 Dude VanWinkle <[EMAIL PROTECTED]> wrote: >On 10/7/07, [EMAIL PROTECTED] [EMAIL PROTECTED]> wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >> Dude, your hacker name sucks, Van Winkle. >

[Full-disclosure] ANSA editorial system vulnerable

2007-10-09 Thread Rosario Valotta
ANSA is the greatest italian press agency. It has offices and employees all around the world. ANSA provides news to all main italian news aggregators and information web sites. ANSA is "trusted". ANSA editorial web portal is vulnerable, it lacks the basic security principles. Everyone with a small

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread Valdis . Kletnieks
On Tue, 09 Oct 2007 10:26:17 +0530, sushil Agarwal said: > UNSUBSCRIBE Read RFC2369, then ponder the headers of any message from the list, and wait for enlightenment. pgpwF6qcw9ZgR.pgp Description: PGP signature ___ Full-Disclosure - We believe in it.

Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

2007-10-09 Thread Thierry Zoller
Dear Pappa Bär, 3> What URL is is defined by RFC 1738, what mailto: is is defined by RFC 3> 2368. String in question is definetly _not_ URL because of %xx and ". Thank you for clarifying, though I must tell you I never claimed this was a URL. Did I ? So why are you trying to tell me it's not

[Full-disclosure] [USN-527-1] xen-3.0 vulnerability

2007-10-09 Thread Kees Cook
=== Ubuntu Security Notice USN-527-1 October 05, 2007 xen-3.0 vulnerability CVE-2007-4993 === A security issue affects the following Ubuntu releases: Ubuntu 7.04 This adviso

Re: [Full-disclosure] UNSUBSCRIBE

2007-10-09 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SHUT UP VLADIS On Tue, 09 Oct 2007 12:14:08 -0400 [EMAIL PROTECTED] wrote: >On Tue, 09 Oct 2007 10:26:17 +0530, sushil Agarwal said: >> UNSUBSCRIBE > >Read RFC2369, then ponder the headers of any message from the >list, >and wait for enlightenment. --

[Full-disclosure] NULL pointer crash in World in Conflict 1.000

2007-10-09 Thread Luigi Auriemma
### Luigi Auriemma Application: World in Conflict http://www.worldinconflict.com Versions: <= 1.000 Platforms:Windows Bug: access to NULL pointer Exploitation: remote,

[Full-disclosure] iDefense Security Advisory 10.09.07: Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow

2007-10-09 Thread iDefense Labs
Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow iDefense Security Advisory 10.09.07 http://labs.idefense.com/intelligence/vulnerabilities/ Oct 09, 2007 I. BACKGROUND Microsoft Windows Mail and Outlook Express are the default mail and news clients for Windows operating syst

[Full-disclosure] The Death of Defence in Depth ? - An invitation to Hack.lu

2007-10-09 Thread Thierry Zoller
Invitation to Hack.lu [1] - A small but nice Conference in the Heart of Europe. As you may or may not know, we always prepare something special for Hack.lu, last year BTcrack, this year we'd like to announce our (n.runs AG) Presentation @ this years Hack. lu, entitled: ---

[Full-disclosure] yahoo news been offline for hours

2007-10-09 Thread worried security
-- Forwarded message -- From: n3td3v <[EMAIL PROTECTED]> Date: Oct 9, 2007 10:09 PM Subject: Re: yahoo news offline for at least 3 hours To: Yahoo Security Contact <[EMAIL PROTECTED]>, "[EMAIL PROTECTED]" < [EMAIL PROTECTED]>, Henri Torgemane <[EMAIL PROTECTED]> On 10/9/07, n3td3v

Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

2007-10-09 Thread Thierry Zoller
Dear KJK, KH> I repeat. Nowhere is said that ShellExecute (the default "run stuff" KH> function) takes URLs. Nowehere is determined that it does NOT take URLS. You forget a consideration, an Important one in my opinion. This is not straight forward ShellExecute(), it's a shellexecute call to a Ha

[Full-disclosure] Who still trust filevault? Finally TrueCrypt for Mac OS X!

2007-10-09 Thread Fabio Pietrosanti
Dear guys, We are looking for funding for the porting, in full opensource, of Truecrypt encrypted volume software to Mac OS X operating system. http://www.osxcrypt.org Now read the story.

Re: [Full-disclosure] If internet goes down out of hours, we're screwed

2007-10-09 Thread worried security
On 10/9/07, Steven Adair <[EMAIL PROTECTED]> wrote: > > I think you guys are both mixing up CERT (cert.org) and US-CERT > (us-cert.gov) -- both of which have very different functions. As > mentioned though, you probably wouldn't want to call either if your > Internet goes down. > > Steven > > They

[Full-disclosure] [ GLSA 200710-09 ] NX 2.1: User-assisted execution of arbitrary code

2007-10-09 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[Full-disclosure] [ GLSA 200710-08 ] KOffice, KWord, KPDF, KDE Graphics Libraries: Stack-based buffer overflow

2007-10-09 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

2007-10-09 Thread Gregory Rubin
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 http://support.microsoft.com/kb/224816 <= Use ShellExecute to launch the default Web browser I agree that we need sanity checking on the applications accepting the input, but the fact remains that ShellExecute is doing dangerous things based on bad in

Re: [Full-disclosure] Who still trust filevault? Finally TrueCrypt for Mac OS X!

2007-10-09 Thread Joey Mengele
LOLOLOLOL MACOSX KERNEL IS AS INSECURE AS LINUX WITH SUCKIT,GRSEC,ADORE, ETC. INSTALLED. IF YOU WANT REAL CRYPTO AND SECURITY USE NSA LINUX OR WINDOWS. J On Tue, 09 Oct 2007 17:20:00 -0400 Fabio Pietrosanti <[EMAIL PROTECTED]> wrote: >Dear guys, > >

[Full-disclosure] [vuln.sg] Adobe PageMaker Long Font-Name Buffer Overflow Vulnerability

2007-10-09 Thread TAN Chew Keong
[vuln.sg] Vulnerability Research Advisory Adobe PageMaker Long Font-Name Buffer Overflow Vulnerability by Tan Chew Keong Release Date: 2007-10-09 Summary --- A vulnerability has been found in Adobe PageMaker for Windows. When exploited, the vulnerability allows execution of arbitrary code wh

Re: [Full-disclosure] Core Impact 7.5 Web App pen-testing framework, as good as the hype?

2007-10-09 Thread Dude VanWinkle
Sorry, I didnt mean to go over your head. I will dumb it down for you next time. -JP On 10/9/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Mad technical! > > On Sun, 07 Oct 2007 19:55:24 -0400 Dude VanWinkle > <[EMAIL PROTECTED]> wrote: > >

Re: [Full-disclosure] Core Impact 7.5 Web App pen-testing framework, as good as the hype?

2007-10-09 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 What do you mean? On Tue, 09 Oct 2007 21:18:58 -0400 Dude VanWinkle <[EMAIL PROTECTED]> wrote: >Sorry, I didnt mean to go over your head. I will dumb it down for >you next time. > >-JP > >On 10/9/07, [EMAIL PROTECTED] [EMAIL PROTECTED]> wrote: >>

Re: [Full-disclosure] URI handling woes in Acrobat Reader, Netscape, Miranda, Skype

2007-10-09 Thread KJK::Hyperion
Since this issue is a great big rats nest, I promise a third-party patch for it by tomorrow. Deal? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com

Re: [Full-disclosure] Core Impact 7.5 Web App pen-testing framework, as good as the hype?

2007-10-09 Thread Dude VanWinkle
On 10/9/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > >Note: This signature can be verified at https://www.hushtools.com/verify >Charset: UTF8 Version: Hush 2.5 > What do you mean? well I was just wondering if I could verify you are a s00per l

Re: [Full-disclosure] yahoo news been offline for hours

2007-10-09 Thread Jim Popovitch
On Tue, 2007-10-09 at 22:12 +0100, worried security wrote: > Same headlines i've seen for hours with dead links are: > > of 10:07 p.m. That happens a least once every few months. It's a distributed caching issue. No worries, someone gets around to fixing it within a day or two. -Jim P.

Re: [Full-disclosure] If internet goes down out of hours, we're screwed

2007-10-09 Thread Dude VanWinkle
I didn't read that book you sent in response to an offhanded remark, but I am impressed you learned about paragraphs! Now, lets focus on capital letters. -JP On 10/9/07, worried security <[EMAIL PROTECTED]> wrote: > On 10/9/07, Steven Adair <[EMAIL PROTECTED]> wrote: > > I think you guys are bot

Re: [Full-disclosure] Core Impact 7.5 Web App pen-testing framework, as good as the hype?

2007-10-09 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Huh? On Tue, 09 Oct 2007 21:33:46 -0400 Dude VanWinkle <[EMAIL PROTECTED]> wrote: >On 10/9/07, [EMAIL PROTECTED] [EMAIL PROTECTED]> wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA1 >> >>Note: This signature can be verified at >https://www.hu

Re: [Full-disclosure] If internet goes down out of hours, we're screwed

2007-10-09 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 You missed an apostrophe here: http://lists.grok.org.uk/pipermail/full-disclosure/2007- October/066452.html On Tue, 09 Oct 2007 22:06:47 -0400 Dude VanWinkle <[EMAIL PROTECTED]> wrote: >I didn't read that book you sent in response to an offhanded >r

Re: [Full-disclosure] If internet goes down out of hours, we're screwed

2007-10-09 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 You also missed an apostrophe in this post. On Tue, 09 Oct 2007 22:06:47 -0400 Dude VanWinkle <[EMAIL PROTECTED]> wrote: >I didn't read that book you sent in response to an offhanded >remark, >but I am impressed you learned about paragraphs! > >Now, l

Re: [Full-disclosure] If internet goes down out of hours, we're screwed

2007-10-09 Thread Dude VanWinkle
On 10/9/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > You also missed an apostrophe in this post. > > On Tue, 09 Oct 2007 22:06:47 -0400 Dude VanWinkle > <[EMAIL PROTECTED]> wrote: > to worried security <[EMAIL PROTECTED]> Man, netdev, you a

Re: [Full-disclosure] Core Impact 7.5 Web App pen-testing framework, as good as the hype?

2007-10-09 Thread Dude VanWinkle
On 10/9/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > -BEGIN PGP SIGNED MESSAGE-ww.hushtools.com/verify > Charset: UTF8 > Version: Hush 2.5 So iz yer new [EMAIL PROTECTED] handl3 UTF8 or Hush 2.5? -JP ___ Full-Disclosure - We believe in i

Re: [Full-disclosure] Report to Recipient(s)

2007-10-09 Thread gjgowey
Sometimes I really do have to wonder about people. Obviously it wasn't a message that came from me since the blackberry.net in my email might be a good clue that I'm using a blackberry to do my emails (in case the T-Mobile tagline/nagline was an obvious enough hint as is). Now I wonder which b

Re: [Full-disclosure] Report to Recipient(s)

2007-10-09 Thread Andrew Farmer
On 09 Oct 07, at 20:04, [EMAIL PROTECTED] wrote: > Sometimes I really do have to wonder about people. Obviously it > wasn't a message that came from me since the blackberry.net in my > email might be a good clue that I'm using a blackberry to do my > emails (in case the T-Mobile tagline/nagl