[Full-disclosure] Metasploit Framework 4.0 / PwnCraft RTS Game

2008-03-31 Thread METASPLOIT CORPORATION
FOR IMMEDIATE RELEASE - APR 1, 200(2<<2) METASPLOIT CORPORATION ANNOUNCES VERSION 4.0 OF THE METASPLOIT FRAMEWORK WITH EXCITING FEATURES AND A CLOSED SOURCE LICENSE AGREEMENT. After over a year and a half in stealth-mode, Metasploit Corporation has announced the 4.0 r

Re: [Full-disclosure] CAU-2008-0001 - Slowly Closing Door Race Condition

2008-03-31 Thread Nate McFeters
Hahaha, nice find. On 4/1/08, I)ruid <[EMAIL PROTECTED]> wrote: > > ____ > /\/\ | | | | >/ /\__\##/ /\ \##| |##| | > | | | |__| | | | | | >

[Full-disclosure] CAU-2008-0001 - Slowly Closing Door Race Condition

2008-03-31 Thread I)ruid
____ /\/\ | | | | / /\__\##/ /\ \##| |##| | | | | |__| | | | | | | | ___ | __ | | | | | --==##\ \/ /#| |

[Full-disclosure] iDefense Security Advisory 03.31.08: Macrovision InstallShield InstallScript One-Click Install Untrusted Library Loading Vulnerability

2008-03-31 Thread iDefense Labs
iDefense Security Advisory 03.31.08 http://labs.idefense.com/intelligence/vulnerabilities/ Mar 31, 2008 I. BACKGROUND Macrovision InstallShield InstallScript One-Click Install (OCI) is a web based installer technology that allows software publishers to distribute minimal installer packages which

[Full-disclosure] ProxyStrike - Active Web Application Proxy

2008-03-31 Thread Christian Martorella
Hi everyone, we have released a new tool: ProxyStrike is an active Web Application Proxy, is a tool designed to find vulnerabilities while browsing an application. It was created because the problems we faced in the pentests of web applications that heavily depends on Javascript, not many

[Full-disclosure] Directory traversal in 2X ThinClientServer v5.0_sp1-r3497

2008-03-31 Thread Luigi Auriemma
### Luigi Auriemma Application: 2X ThinClientServer http://www.2x.com/thinclientserver/ Versions: <= v5.0_sp1-r3497 (TFTPd.exe <= 3.2.0.0) Platforms:Windows Bug:

Re: [Full-disclosure] sans handler gives out n3td3v e-mail to public

2008-03-31 Thread Jason
n3td3v wrote: > On Sun, Mar 23, 2008 at 10:44 AM, <[EMAIL PROTECTED]> wrote: >> I think this the most worst and alarming situation ..where SANS like >> organization is doing the way.. from onwards no body will report >> info to SANS... E+1 t+1 b+1 j+1 it OFF!!! > > SANS hasn't adm

Re: [Full-disclosure] London DEFCON meet - DC4420 - New Venue - Wednesday 2nd April, 2008

2008-03-31 Thread Valdis . Kletnieks
On Mon, 31 Mar 2008 14:29:21 BST, n3td3v said: > This is piss man, an over 18's Defcon? Can kiddies get in if we just > drink coca cola? Bad planning in my humble opinion. Learning is about > all age groups having access, not a small elite of adults. And here I thought the effective drinking age

Re: [Full-disclosure] London DEFCON meet - DC4420 - New Venue - Wednesday 2nd April, 2008

2008-03-31 Thread n3td3v
On Mon, Mar 31, 2008 at 11:28 AM, Major Malfunction <[EMAIL PROTECTED]> wrote: > meet will be at the St. George's Tavern, Victoria: > http://www.beerintheevening.com/pubs/s/17/174/St_Georges_Tavern/Victoria > > starting at 19:30 on Wednesday 2nd April, 2008. > > we have the lower bar all to ourselv

[Full-disclosure] London DEFCON meet - DC4420 - New Venue - Wednesday 2nd April, 2008

2008-03-31 Thread Major Malfunction
i'm very pleased to (finally) announce a meet for 2008... we've got a new venue which we're trying out, so hopefully we'll solve the problem of non-exclusivity which we've suffered at the last few meets, as well as a more central location which should be easier for folks to get to... meet will