[Full-disclosure] [Professional IT Security Providers - Exposed] Pivot Point Security ( A )

2008-04-05 Thread secreview
Pivot Point Security, whose website can be found at http://www.pvtpt.com, is a provider of Information Security Auditing, Security Event Management, and Penetration Testing services. We found them by doing yet another search for “Penetration Testing” on Google. Unlike some other providers who are a

Re: [Full-disclosure] Fwd: Let's outlaw mass securityconferencespamming its f****** gay

2008-04-05 Thread Ureleet
i love how you like to make everything so confrontational. insecure much? i am no longer talking about this, you obviously didnt read my email, nor did you read michael cottinghams. stop trolling. On Fri, Apr 4, 2008 at 6:11 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Fri, Apr 4, 2008 at 9:34

Re: [Full-disclosure] n3td3v agenda & Solid Information Security State Release 0012

2008-04-05 Thread Ureleet
i know i was just checking. On Fri, Apr 4, 2008 at 5:41 PM, Razi Shaban <[EMAIL PROTECTED]> wrote: > It's called "a joke." > > -- > Razi > > On 4/4/08, Ureleet <[EMAIL PROTECTED]> wrote: > > r u serious? > > > > > > On Fri, Apr 4, 2008 at 10:48 AM, Micheal Turner <[EMAIL PROTECTED]> > > wrote: >

Re: [Full-disclosure] n3td3v has a fan

2008-04-05 Thread Ureleet
that doesnt look like a list of things you are at the forefront of, from what i have seen it looks like a list of personal gripes that you have chosen to oust to the community. i dont think that counts. what have you published? besides a shitload of emails on your google group list of news you g

Re: [Full-disclosure] n3td3v has a fan

2008-04-05 Thread n3td3v
On Thu, Apr 3, 2008 at 3:29 AM, scott <[EMAIL PROTECTED]> wrote: > What security are you at the forefront of? Well as of recently: Storm Worm (We need the White House to put pressure on Russia to end RBN operations.) Profiteering on FD (Do you know the difference between disclosure and profitee

[Full-disclosure] Medium security hole affecting Festival on Debian unstable/testing and Ubuntu Hardy Heron

2008-04-05 Thread Tim Brown
It has been recently been identified that the Festival text to speech server was vulnerable to unauthenticated remote code execution. Further research indicated that this vulnerability has already been reported as a local privilege escalation against both the Gentoo and SuSE GNU/Linux distribut

Re: [Full-disclosure] n3td3v has afan

2008-04-05 Thread scott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >> I'm the one at the forefront of security trying to make a difference, >> > and what are you? He supports me because of my cause to stop the Storm >> > Worm, so what solutions have you got, instead of annoying everyone? >> > > > What security are

[Full-disclosure] Vulnerabilities in kses-based HTML filters

2008-04-05 Thread lpilorz
Vulnerabilities in kses-based HTML filters == During internal code review performed by Allegro.pl, some weaknesses were discovered in kses - PHP HTML/XHTML filter. HTML filters using or based on kses are part of many popular projects, including WordPress,

[Full-disclosure] rPSA-2008-0139-1 gnome-ssh-askpass openssh openssh-client openssh-server

2008-04-05 Thread rPath Update Announcements
rPath Security Advisory: 2008-0139-1 Published: 2008-04-04 Products: rPath Linux 1 rPath Appliance Platform Linux Service 1 Rating: Minor Exposure Level Classification: Local User Deterministic Privilege Escalation Updated Versions: [EMAIL PROTECTED]:1/4.9p1-0.1-1 [EMAIL PROTEC

[Full-disclosure] rPSA-2008-0138-1 tshark wireshark

2008-04-05 Thread rPath Update Announcements
rPath Security Advisory: 2008-0138-1 Published: 2008-04-04 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: Indirect Deterministic Denial of Service Updated Versions: [EMAIL PROTECTED]:1/1.0.0-0.1-1 [EMAIL PROTECTED]:1/1.0.0-0.1-1 rPath Issue Tracking System:

[Full-disclosure] rPSA-2008-0136-1 cups

2008-04-05 Thread rPath Update Announcements
rPath Security Advisory: 2008-0136-1 Published: 2008-04-04 Products: rPath Linux 1 Rating: Severe Exposure Level Classification: Remote Root Deterministic Unauthorized Access Updated Versions: [EMAIL PROTECTED]:1/1.1.23-14.7-1 rPath Issue Tracking System: https://issues.rpath.com/

[Full-disclosure] [SECURITY] [DSA 1539-1] New mapserver packages fix multiple vulnerabilities

2008-04-05 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1539-1 [EMAIL PROTECTED] http://www.debian.org/security/ Devin Carraway April 04, 2008

[Full-disclosure] [SECURITY] [DSA 1538-1] New alsaplayer packages fix arbitrary code execution

2008-04-05 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1538-1 [EMAIL PROTECTED] http://www.debian.org/security/ Devin Carraway April 04, 2008

[Full-disclosure] [SECURITY] [DSA 1537-1] New xpdf packages fix multiple vulnerabilities

2008-04-05 Thread Devin Carraway
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1537-1[EMAIL PROTECTED] http://www.debian.org/security/ Devin Carraway April 02, 2008 h

[Full-disclosure] [ GLSA 200804-03 ] OpenSSH: Privilege escalation

2008-04-05 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200804-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -