Re: [Full-disclosure] Most Secure Browser

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 That is hardly sporting. On Thu, 18 Oct 2007 05:23:03 -0400 "[EMAIL PROTECTED]" <[EMAIL PROTECTED]> wrote: >Could you stfu a moment please thanks , do not reply you're >filtered, >motherfucker. > >[EMAIL PROTECTED] wrote: >> -BEGIN PGP SIGNED MESS

Re: [Full-disclosure] Did people power get rid of Gadi Evron from Full-Disclosure?

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I haven't heard from Gadi since he called Turkey "a nation of Muslim terrorists" on his blog. Has anyone tried calling him? 703-286-7723, extension 110 . On Wed, 17 Oct 2007 13:43:20 -0400 worried security <[EMAIL PROTECTED]> wrote: >Did people powe

Re: [Full-disclosure] Most Secure Browser

2007-10-18 Thread Andre Gironda
On 10/17/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > 1) Personal favorite browser, http://crawler.archive.org > 2) Most secure browser, links ... not elinks or lynx... links > 3) Best browser plugins, none > 4) Favorite youtube video, youtube takes down really important content, such as http

[Full-disclosure] .aware eZine (beta edition)

2007-10-18 Thread rattle
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hello World! I am posting this to inform you about the existence of a little eZine called ".aware", over at http://www.awarenetwork.org/etc/ The second issue was just released, namely http://www.awarenetwork.org/etc/beta/ Then, certain people

[Full-disclosure] peace

2007-10-18 Thread fabio
https://intranet.usip.org/datacenter/eps/CustomCal.php ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] .aware eZine (beta edition)

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Let us know when the stable version is available. On Thu, 18 Oct 2007 02:08:45 -0400 rattle <[EMAIL PROTECTED]> wrote: >Hello World! > >I am posting this to inform you about the existence of a little >eZine >called ".aware", over at > > http://www.awa

Re: [Full-disclosure] Your email requires verification.

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Huh? I am a real person! - -JP On Thu, 18 Oct 2007 10:00:57 -0400 [EMAIL PROTECTED] wrote: >The message you sent requires you to verify that you >are a real live human being and not a spam source. To complete >this verification, simply reply to this

[Full-disclosure] [SECURITY] [DSA 1388-1] New dhcp packages fix arbitrary code execution

2007-10-18 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA 1388-1 [EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp October 18th, 2007

Re: [Full-disclosure] peace

2007-10-18 Thread Nikolay Kichukov
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 so? - -Nikolay fabio wrote: > https://intranet.usip.org/datacenter/eps/CustomCal.php > > ___ > Full-Disclosure - We believe in it. > Charter: http://lists.grok.org.uk/full-disclosure-charter.html > Hosted

Re: [Full-disclosure] Netgear SSL312 XSS vulnerability

2007-10-18 Thread rembrandt
Dear SkyOut, dear Packetstorm team (tedd :)) and dear List. The author brocke a NDA during the releasing of this "uber"-Advisory. Skyout: What the fuck is wrong with u? Even ignoring our mails... wow? We provided the Router, told him to take a look and he angreed to a NDA. Do I care if you relea

Re: [Full-disclosure] Netgear SSL312 XSS vulnerability

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 What? On Wed, 17 Oct 2007 14:15:31 -0400 [EMAIL PROTECTED] wrote: >Dear SkyOut, dear Packetstorm team (tedd :)) and dear List. > >The author brocke a NDA during the releasing of this "uber"- >Advisory. > >Skyout: What the fuck is wrong with u? Even ig

Re: [Full-disclosure] peace

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 One word replies are unnecessary on the full-disclosure. On Thu, 18 Oct 2007 12:15:52 -0400 Nikolay Kichukov <[EMAIL PROTECTED]> wrote: >so? > >-Nikolay > >fabio wrote: >> https://intranet.usip.org/datacenter/eps/CustomCal.php >> >> __

Re: [Full-disclosure] Zone-H.org: 10 reasons websites get hacked

2007-10-18 Thread worried security
On 10/18/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > I thought the main reasons for intrusion were fun and/or profit. I > don't see them on your list anywhere. > > I think your list sucks. the no.1 threat to corporate and national secu

Re: [Full-disclosure] Zone-H.org: 10 reasons websites get hacked

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 very thought provoking as usual bro thank you for your contributions to our list! On Thu, 18 Oct 2007 15:16:08 -0400 worried security <[EMAIL PROTECTED]> wrote: >On 10/18/07, [EMAIL PROTECTED] [EMAIL PROTECTED]> >wrote: >> >> -BEGIN PGP SIGNED MES

[Full-disclosure] [ GLSA 200710-18 ] util-linux: Local privilege escalation

2007-10-18 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] password plugin for linux?

2007-10-18 Thread . /
hi all, naive question - but you know how i can load password plugins in window's to capture password changes in the clear. is there any way to achieve the same in linux? atm all i can think of (naively as i said) is to monitor the shadow file or whatever and then to open the hash. but i am reall

[Full-disclosure] rPSA-2007-0219-1 libpng

2007-10-18 Thread rPath Update Announcements
rPath Security Advisory: 2007-0219-1 Published: 2007-10-18 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: Indirect User Deterministic Denial of Service Updated Versions: [EMAIL PROTECTED]:1/1.2.22-1-0.1 rPath Issue Tracking System: https://issues.rpath.com/browse/

Re: [Full-disclosure] password plugin for linux?

2007-10-18 Thread full-disclosure
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ask john hale On Thu, 18 Oct 2007 11:11:24 -0400 ". /" <[EMAIL PROTECTED]> wrote: >hi all, > >naive question - but you know how i can load password plugins in >window's to >capture password changes in the clear. is there any way to achieve >the same >

[Full-disclosure] [SECURITY] [DSA 1389-1] New zoph packages fix SQL injection

2007-10-18 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1389-1[EMAIL PROTECTED] http://www.debian.org/security/Thijs Kinkhorst October 18th, 2007

Re: [Full-disclosure] Netgear SSL312 XSS vulnerability

2007-10-18 Thread Lolek of TK53
Yoyo, On 10/17/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > Dear SkyOut, dear Packetstorm team (tedd :)) and dear List. > > The author brocke a NDA during the releasing of this "uber"-Advisory. > > Skyout: What the fuck is wrong with u? Even ignoring our mails... wow? > We provided the Router

[Full-disclosure] Serious holes affecting SiteBar 3.3.8

2007-10-18 Thread Tim Brown
All, As a result of a short security audit of SiteBar, a number of security holes were found. The holes included code execution, a malicious redirect and multiple cases of Javascript injection. After liasing with the developers, the holes have been patched. Attached are the advisory and patc

Re: [Full-disclosure] password plugin for linux?

2007-10-18 Thread Valdis . Kletnieks
On Thu, 18 Oct 2007 10:11:24 CDT, ". /" said: > naive question - but you know how i can load password plugins in window's to > capture password changes in the clear. is there any way to achieve the same > in linux? atm all i can think of (naively as i said) is to monitor the > shadow file or whate

[Full-disclosure] [ GLSA 200710-19 ] The Sleuth Kit: Integer underflow

2007-10-18 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-19 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] S21SEC-038-en: Alcatel Omnivista 4760 Cross-Site Scripting

2007-10-18 Thread S21sec Labs
## - S21Sec Advisory - ## Title: Alcatel Omnivista 4760 Cross-Site Scripting ID: S21SEC-038-en Severity: Medium - History:

[Full-disclosure] [ MDKSA-2007:200 ] - Updated tk packages fix vulnerabilities

2007-10-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:200 http://www.mandriva.com/security/ ___

[Full-disclosure] [ GLSA 200710-20 ] PDFKit, ImageKits: Buffer overflow

2007-10-18 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-20 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [TOOL] w3af - Web Application Attack and Audit Framework

2007-10-18 Thread Andres Riancho
List, I'm glad to release the fifth beta of w3af. For those that still don't know, w3af is a fully automated auditing and exploiting framework for the web. More info can be found at http://w3af.sourceforge.net/ . They are really *a lot* of changes from beta4 to make an detailed list, but