Re: [Full-disclosure] *** OFF LIST *** Re: in Memory of Dude VanWinkle / Justin Plazzo

2008-02-20 Thread Andrew A
Please note that Byron Sonne actually has employment in the information security field and not as a sysad at some university. So maybe he isn't a "respected member" of the bottom-feeding loser circlejerk on some mailing list, but he can actually fucking do something worthwhile. On Wed, Feb 20, 20

[Full-disclosure] [ MDVSA-2008:046-1 ] - Updated xine-lib package fixes arbitrary code execution vulnerability

2008-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:046-1 http://www.mandriva.com/security/ ___

[Full-disclosure] iDefense Security Advisory 02.20.08: Symantec Veritas Storage Foundation Scheduler Service DoS Vulnerability

2008-02-20 Thread iDefense Labs
iDefense Security Advisory 02.20.08 http://labs.idefense.com/intelligence/vulnerabilities/ Feb 20, 2008 I. BACKGROUND The Veritas Storage Foundation is based on the Veritas File System and Veritas Volume Manager products. It allows virtualization of storage over a variety of platforms. It contain

Re: [Full-disclosure] *** OFF LIST *** Re: in Memory of Dude VanWinkle / Justin Plazzo

2008-02-20 Thread Byron Sonne
> respected member of the online community (now you have something to aspire > to) I couldn't care less what you think I ought to aspire to. I'm perfectly content being a 36 year old immature prick. So fuck off, and keep your aspirations for yourself. Dead is dead. Move on. __

[Full-disclosure] ZDI-08-007: Symantec VERITAS Storage Foundation Administrator Service Heap Overflow Vulnerability

2008-02-20 Thread zdi-disclosures
ZDI-08-007: Symantec VERITAS Storage Foundation Administrator Service Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-08-007.html February 20, 2008 -- CVE ID: CVE-2008-0638 -- Affected Vendor: Symantec -- Affected Products: Veritas Storage Foundation 5.0 -- TippingP

Re: [Full-disclosure] iDefense Security Advisory 02.19.08: EMC RepliStor Multiple Heap Overflow Vulnerabilities

2008-02-20 Thread iDefense Labs
The correct CVE number is CVE-2007-6426 (not 2008). VeriSign iDefense Labs ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] iDefense Security Advisory 02.19.08: EMC RepliStor Multiple Heap Overflow Vulnerabilities

2008-02-20 Thread iDefense Labs
iDefense Security Advisory 02.19.08 http://labs.idefense.com/intelligence/vulnerabilities/ Feb 19, 2008 I. BACKGROUND EMC RepliStor is a data backup and recovery application for Windows. For more information, visit the vendor's website at the following URL. http://software.emc.com/products/softw

[Full-disclosure] two (not critical) bugs in libnids 1.22

2008-02-20 Thread michele dallachiesa
hi all, libnids 1.22 has two bugs preventing it to work correctly in 802.11x networks. I and the libnids author have no time to write a patch. After some silent months, I decided to public them so probably someone will do the required fixes and will propose a working patch to the author. for libni

[Full-disclosure] Heap overflow in Sybase MobiLink 10.0.1.3629

2008-02-20 Thread Luigi Auriemma
### Luigi Auriemma Application: Sybase MobiLink http://www.sybase.com/developer/mobile/sqlanywhere/mobilink Versions: <= 10.0.1.3629 Platforms:Windows and Linux/Unix Bug:

[Full-disclosure] Advisory SE-2008-01: PunBB Blind Password Recovery Vulnerability

2008-02-20 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SektionEins GmbH www.sektioneins.de -= Security Advisory =- Advisory: PunBB Blind Password Recovery Vulnerability Release Date: 2008/02/20 Last Modified: 2008/02/2

Re: [Full-disclosure] Tarot

2008-02-20 Thread S/U/N
Nice to know some on your ( über cool ) sexual french life Slythers Bro a écrit : > moi je veut bien jouer au tarot avec lise > > > ___ > Full-Disclosure - We believe in it. > Chart

Re: [Full-disclosure] Tarot

2008-02-20 Thread Slythers Bro
moi je veut bien jouer au tarot avec lise ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] DO NOT USE logsurfer configuration recommended by DFN CERT

2008-02-20 Thread kcope
##Logsurfer default recommendation / configuration Remote Code Execution / Injection ##discovered by kcope when securing a box The Logsurfer program distributed by DFN CERT at http://www.dfn-cert.de/eng/logsurf/ has a ridicolous remote code execution bug in one of its mailing scripts when it is

Re: [Full-disclosure] Tarot

2008-02-20 Thread Guillaume Sicard
Le 4 c'est un mardi, donc c'est mort pour moi, je vous en avais déjà parlé, je sors à 8h, désolé. On Wednesday 20 February 2008 11:12:41 Fabrice RIMBLOT wrote: > OK pour moi, si tant est que ca convient à tout le monde bien entendu. > > > > Guillaume et Benji ? Le 4 mars OK pour vous ? > > > > >

Re: [Full-disclosure] Anyone else seeing this?

2008-02-20 Thread Fredrick Diggle
also diggle sec has been in mourning for our emo monkey friend and therefore unable to disclose elite 0day. stop blocking us joey. On Feb 19, 2008 3:37 PM, Simon Smith <[EMAIL PROTECTED]> wrote: > Thats because you've been writing less you moron. > > Joey Mengele wrote: > > SPAM levels greatly dec