[Full-disclosure] [SECURITY] [DSA 1389-2] New zoph packages fix SQL injection

2007-10-24 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1389-2[EMAIL PROTECTED] http://www.debian.org/security/Thijs Kinkhorst October 24th, 2007

[Full-disclosure] [ GLSA 200710-27 ] ImageMagick: Multiple vulnerabilities

2007-10-24 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ GLSA 200710-26 ] HPLIP: Privilege escalation

2007-10-24 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ GLSA 200710-25 ] MLDonkey: Privilege escalation

2007-10-24 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200710-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] "Hackers can divert Vonage calls: security firm" =>?

2007-10-24 Thread Peter Dawson
I have not heard of any chatter on this one.. http://ca.today.reuters.com/news/newsArticle.aspx?type=technologyNews&storyID=2007-10-24T183023Z_01_N24160249_RTRIDST_0_TECH-VONAGE-HACKERS-COL.XML&archived=False does anyone know different or is this just some company pimping ?? /pd

[Full-disclosure] Using GPUs to crack hashes

2007-10-24 Thread North, Quinn
Looks I now have something to do with my idle SLi cycles! < http://technology.newscientist.com/article.ns?id=dn12825&feedId=online-news_rss20 > --=Q=--   This email is intended for the recipient only. If you are not the intended recipient please disregard, and do not use the information for

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Michael Holstein
> I'm sorry everyone I was just trying to highlight a valid point, i > didn't expect a flame war to errupt. Then be more judicious in your use of "Reply-All". > > The DHS need to ban ISP's from talking about infrastructure security > in public places. it should be classified information don'

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread worried security
On 10/24/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > On 10/24/07, worried security <[EMAIL PROTECTED]> > wrote: > > Don't fuck with me you prick or i'll track you down. > > On 10/24/07, worried security <[EMAIL PROTECTED]> > wrote: > > ..

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread 31337
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 10/24/07, worried security <[EMAIL PROTECTED]> wrote: > Don't fuck with me you prick or i'll track you down. On 10/24/07, worried security <[EMAIL PROTECTED]> wrote: > ... homo, ... watch your back with who you're talking to. On 10/24/07, worried

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Mike Owen
On 10/24/07, worried security <[EMAIL PROTECTED]> wrote: > I'm sorry everyone I was just trying to highlight a valid point, i didn't > expect a flame war to errupt. > > The DHS need to ban ISP's from talking about infrastructure security in > public places. it should be classified information don't

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Valdis . Kletnieks
On Wed, 24 Oct 2007 17:32:04 BST, worried security said: > The DHS need to ban ISP's from talking about infrastructure security in > public places. it should be classified information don't you all think? Please note a few things: 1) The level of detail actually discussed on NANOG comes nowhere *

[Full-disclosure] rPSA-2007-0221-1 php php-mysql php-pgsql

2007-10-24 Thread rPath Update Announcements
rPath Security Advisory: 2007-0221-1 Published: 2007-10-24 Products: rPath Linux 1 Rating: Severe Exposure Level Classification: Remote System User Deterministic Unauthorized Access Updated Versions: [EMAIL PROTECTED]:1/4.3.11-15.15-1 [EMAIL PROTECTED]:1/4.3.11-15.15-1 [EMAIL PROTEC

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Epic
Stop spamming the list with useless garbage and maybe some will respect rather than hate? Just a thought... -E On 10/24/07, worried security <[EMAIL PROTECTED]> wrote: > > I'm sorry everyone I was just trying to highlight a valid point, i didn't > expect a flame war to errupt. > > The DHS need

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Glenn.Everhart
I suspect rather that DHS needs to first acquire the expertise to deal with these issues, and participate as helpers rather than as directors. Nanog has dealt with interruptions to the Internet in the past, with success enough that most people are unaware that major problems ever occurred. The

[Full-disclosure] iDefense Security Advisory 10.23.07: IBM Lotus Domino IMAP Buffer Overflow Vulnerability

2007-10-24 Thread iDefense Labs
IBM Lotus Domino IMAP Buffer Overflow Vulnerability iDefense Security Advisory 10.23.07 http://labs.idefense.com/intelligence/vulnerabilities/ Oct 23, 2007 I. BACKGROUND IBM Lotus Domino Server software provides messaging, calendaring and scheduling capabilities on a variety of operating systems

[Full-disclosure] iDefense Security Advisory 10.23.07: IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability

2007-10-24 Thread iDefense Labs
IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability iDefense Security Advisory 10.23.07 http://labs.idefense.com/intelligence/vulnerabilities/ Oct 23, 2007 I. BACKGROUND IBM Corp.'s Lotus Notes software is an integrated desktop client option for accessing e-mail, calendars

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread worried security
I'm sorry everyone I was just trying to highlight a valid point, i didn't expect a flame war to errupt. The DHS need to ban ISP's from talking about infrastructure security in public places. it should be classified information don't you all think? Just because Nanog has been offending for years b

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Mark Senior
Some people are immune to satire, and always will be... On 10/24/07, php0t wrote: > > > > After all this crap, you guys still fall for the trollbait? f*cking sad :-( > > ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-dis

Re: [Full-disclosure] How to use the tools rainbowrack 1.2-src

2007-10-24 Thread Verhoeven Dimitri
edison schreef: > hello Mr Fabien Kraemer: > I have download the rainbowrack 1.2-src.But I don't know how to use > the tools to find the password of the oracle user password .Would you tell me > how to do it or give me an example. Thank you . > > _

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread Prohest
Hey stop making fun of netdouche! So what if he couldent hack out a bag of toastbread? I, for one, welcome Netdork as our new über official pseudo-God. Route dissapered in some torture-chamber under Cisco, the smart guys from L0pht got a haircut and a tie and sum cash. Kevin found out he was coole

Re: [Full-disclosure] Distributed SSH username/password brute forceattack

2007-10-24 Thread Vincent Archer
On Mon, 2007-10-22 at 22:34 +0200, [EMAIL PROTECTED] wrote: > Hi, > > > Oct 22 20:36:13 nms sshd[90657]: Failed password for invalid user gopher > > from 77.46.152.2 port 55120 ssh2 > > user/password authentication for SSH? one way of cleaning up your > logs and killing this type of attack is to

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread John Kinsella
On Wed, Oct 24, 2007 at 08:39:56AM +0200, php0t wrote: > After all this crap, you guys still fall for the trollbait? f*cking sad :-( Yeah, I'll give ya that. Let's try "Lack of sleep" for $400, Alex. ___ Full-Disclosure - We believe in it. Charter: ht

Re: [Full-disclosure] DHS need to get on top of this right now

2007-10-24 Thread php0t
After all this crap, you guys still fall for the trollbait? f*cking sad :-( > No? I've just recently applied here https://www.mi5careers.gov.uk/ homo, so > watch your > back with who you're talking to. ___ Full-Disclosure - We believe in it. Charte