[Full-disclosure] [SECURITY] [DSA 1527-1] New debian-goodies packages fix privilege escalation

2008-03-25 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1527-1 [EMAIL PROTECTED] http://www.debian.org/security/ Thijs Kinkhorst March 24, 2008

[Full-disclosure] [SECURITY] [DSA 1528-1] New serendipity packages fix cross site scripting

2008-03-25 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1528-1 [EMAIL PROTECTED] http://www.debian.org/security/ Thijs Kinkhorst March 24, 2008

Re: [Full-disclosure] Fwd: Offensive Security Backtrack Training

2008-03-25 Thread Tonu Samuel
On Mon, 2008-03-24 at 15:31 +, n3td3v wrote: > -- Forwarded message -- > From: Markus Krassnitzer <[EMAIL PROTECTED]> > Date: Sat, Mar 22, 2008 at 1:28 PM > Subject: Re: Offensive Security Backtrack Training > To: [EMAIL PROTECTED] > > > I see postings like this in several ma

[Full-disclosure] sellings

2008-03-25 Thread Stephen Flaw
hi All, I am private security researcher. Working also with some security compagnies, I am coding exploits for used application (Win and unix). I am selling some of these exploits there. Rgds, Steph -- Powered by Outblaze ___ Full-Disclosure - We bel

Re: [Full-disclosure] sellings

2008-03-25 Thread Ozan Ozkara
Security through obscurity :) -ozan - Original Message - From: Stephen Flaw To: full-disclosure@lists.grok.org.uk Sent: Tuesday, March 25, 2008 10:41 Subject: [Full-disclosure] sellings hi All, I am private security researcher. Working also with some security compagnies, I am coding e

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Bob Bruen
Hi Jerome, This is the only time I will participate in this thread. We all know lots about Tibet and we all know that China invaded Tibet, a free country. The Dalai Lama is the true head of state of the Tibet government in exile. The Han should stop murdering the people of Tibet and leave the

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Tremaine Lea
Jerome, I find it odd that you would tell someone to ignore a media source and then not provide an alternative. While there are plenty of reasons, and good reasons, to be suspicious of western media, the facts speak for themselves. - There was violence in Tibet and a lot of protesters died. - T

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Kern
>Jerome, I find it odd that you would tell someone to ignore a media >source and then not provide an alternative. I think the "alternative" sources of "media" are in Chinese. On Tue, Mar 25, 2008 at 8:41 AM, Tremaine Lea <[EMAIL PROTECTED]> wrote: > Jerome, I find it odd that you would tell some

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Tremaine Lea
Nah, there are a number of blogs and non-Western sources that are providing much the same information. Check out the English Al-Jazeera site for examples. Hardly a news source that is 'friendly' to Western interests, and definitely not a puppet like Fox or similar. There are also a number of vid

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Dmitry
This list is not about political problems. Go find yourself a free tibet mailing list. On Tue, Mar 25, 2008 at 3:00 PM, Tremaine Lea <[EMAIL PROTECTED]> wrote: > Nah, there are a number of blogs and non-Western sources that are > providing much the same information. Check out the English Al-Jaze

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Tremaine Lea
True that. I'll leave it alone now. --- Tremaine Lea Network Security Consultant Intrepid ACL "Paranoia for hire" On 25-Mar-08, at 7:13 AM, Dmitry wrote: This list is not about political problems. Go find yourself a free tibet mailing list. On Tue, Mar 25, 2008 at 3:00 PM, Tremaine Lea <[E

[Full-disclosure] Static Injection into Commercial Lines - DoS on Vonage - Current Status

2008-03-25 Thread Jan Clairmont
I have received calls and the caller is injected with a sound similar to a fax modem static. Now my outbound callers hear static. This is obviously a problem either with Comcasts injecting noise packets or Verizon or a carrier that carries the VOIP call. This is prevalent with others who subs

[Full-disclosure] [SECURITY] [DSA 1530-1] New cupsys packages fix multiple vulnerabilities

2008-03-25 Thread Noah Meyerhans
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1530-1 [EMAIL PROTECTED] http://www.debian.org/security/ Noah Meyerhans March 25, 2008

Re: [Full-disclosure] Static Injection into Commercial Lines - DoS on Vonage - Current Status

2008-03-25 Thread Kern
Where is the packet capture? How to you intend to file a lawsuit and not have evidence? On Tue, Mar 25, 2008 at 11:45 AM, Jan Clairmont <[EMAIL PROTECTED]> wrote: > I have received calls and the caller is injected with a sound similar to a > fax modem static. Now my outbound callers hear static.

[Full-disclosure] CVE-2008-0073 - MPlayer and VLC "sdpplin_parse()" Array Indexing Vulnerability

2008-03-25 Thread Guido Landi
Hello, CVE-2008-0073 apply also to MPlayer and VLC. -MPlayer-1.0-rc2, stream/realrtsp/sdpplin.c: 161: desc->stream_id=atoi(buf); 283: desc->stream[stream->stream_id]=stream; - vlc-0.8.6e, modules/access/rtsp/real_sdpplin.c: 141: desc->stream_id=atoi(buf); 257: desc->stream[stream->stream_id]=

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Garrett M. Groff
Maybe the relevance of this post is escaping me. Over the weekend, quite a few unread FD emails were purged to make the task of catching up a little more bearable... But I'll bite. Regarding China, as they've been liberalizing their economy for nearly the last three decades, personal freedoms h

[Full-disclosure] CORE-2007-1212: SILC pkcs_decode buffer overflow

2008-03-25 Thread Core Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ SILC pkcs_decode buffer overflow *Advisory Information* Title: SILC pkcs_decode buffer overflow Advisory ID: CORE-2007-1212 Advisory URL: http://w

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Byron Sonne
This list is about whatever I want it to be. You see any moderation around here? Everything is political, my friend. Get your head out of the sand, and let's do something about those murderous thugs called the Chinese government. Did you forget Tiananmen square? You seen how Falun Gong member

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Anders B Jansson
Byron Sonne wrote: > This list is about whatever I want it to be. You see any moderation > around here? > > Everything is political, my friend. > > Get your head out of the sand, and let's do something about those > murderous thugs called the Chinese government. > > Did you forget Tiananmen sq

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Gautam
Well, I was in Dharamshala a week back, my mother is Tibetan & I know from her that many of our relatives in Tibet have disappeared over time. I speak from my heart that Tibet needs to be free but my brain thinks this is not possible.. >From what I know, China has beein actively spying everywhere,

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Peter Dawson
yeah, Fux..how about th US getting into FD mode on the minuteman missile heads sent into Taiwan.. yeah and the chinese had their hands on them for 2yrs .. On Tue, Mar 25, 2008 at 6:47 PM, Gautam <[EMAIL PROTECTED]> wrote: > Well, I was in Dharamshala a week back, my mother is Tibetan & I know f

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Sowhat
I really do not want to be involved here, because this is a security list, not Free tibet list. However, I can not tolerate with this and I'm sick of it. Just one question: how much do you know about Tibet? A very good reference you can check http://www.youtube.com/watch?v=x9QNKB34cJo# Btw: If

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Jun Zhao
another question to all of u guy raving "Free Tibet": how much do you know about China? Do you know how long that Tibet belong to China? and why not go back and check how long of your country was combined? then please compare the time and then open your mouth. "Free Tibet"? go to see what ha

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread www417
Agree with Mr.Rain 2008/3/26, Jun Zhao <[EMAIL PROTECTED]>: > > another question to all of u guy raving "Free Tibet": how much do you know > about China? > > Do you know how long that Tibet belong to China? and why not go back and > check how long of your country was combined? then please compare

Re: [Full-disclosure] Free Tibet..

2008-03-25 Thread Adam Hunt
Hey Jun, Tibet was invaded during the cultural revolution and has been captive since. Why don't you get an education, then cry foul rather than pin your lack of knoledge on anybody. I live in Canada (PRC West) I Had a Chinese National try to compare the running over of people with tanks to