Re: [Full-disclosure] Webwasher SSL scanner

2007-12-24 Thread coderman
On Dec 24, 2007 3:53 PM, coderman <[EMAIL PROTECTED]> wrote: > i am looking for details of the PKI for integration of webwasher ssl > scanner into an organization. thanks to those who responded. in the interest of propagating useful information: the structure of PKI implemented in an organizatio

[Full-disclosure] Webwasher SSL scanner

2007-12-24 Thread coderman
i am looking for details of the PKI for integration of webwasher ssl scanner into an organization. they do not appear forthcoming with details... does the organization's root CA certify the appliance as a CA (so it can sign the MitM certs?) does the organization's CA have to sign each MitM cert

[Full-disclosure] XSS @ DHL

2007-12-24 Thread Static Rez
I know these XSS vulns are kind of easy to find and they usually come off as "so easy a monkey could do it", but i thought i'd throw this one out there... http://track.dhl-usa.com//atrknav.asp?shipmentNumber= alert('test') sincerely, a monkey. ___ Full-

[Full-disclosure] Buffer-overflow and format string in VideoLAN VLC 0.8.6d

2007-12-24 Thread Luigi Auriemma
### Luigi Auriemma Application: VideoLAN (VLC) http://www.videolan.org Versions: <= 0.8.6d Platforms:Windows, Mac, *BSD, *nix and more Bugs: A] buffer-overflow in the h

[Full-disclosure] Double directory traversal in ImgSvr 0.6.21

2007-12-24 Thread Luigi Auriemma
### Luigi Auriemma Application: Ada Image server (ImgSvr) http://adaimgsvr.sourceforge.net Versions: <= 0.6.21 and SVN <= 28 Platforms:Windows and *nix Bug: directory

[Full-disclosure] Unicode buffer-overflow in Zoom Player 6.00b2

2007-12-24 Thread Luigi Auriemma
### Luigi Auriemma Application: Zoom Player http://www.inmatrix.com Versions: <= v6.00 beta 2 and naturally all the stable v5 versions Platforms:Windows Bug: unicode b

[Full-disclosure] Installshield Update Service isusweb.dll Buffer Overflow

2007-12-24 Thread Elazar Broad
The InstallShield Update Service Web Agent version 5.1.100.47363 suffers from an exploitable buffer overflow in the ProductCode parameter of the DownloadAndExecute() function. This object is marked safe for scripting. Note that this issue appears to different from http://www.securityfocus.com/bid