Re: [Full-disclosure] Technical Details of Security Issues Regarding Safari for Windows

2008-06-11 Thread LIUDIEYU dot COM
Aviv really gave huge hint on the issue: http://blog-imgs-24.fc2.com/l/i/u/liudieyu0/0001.png ( posted at http://liudieyu0.blog124.fc2.com/blog-entry-5.html ) On Tue, Jun 10, 2008 at 10:28 PM, LIUDIEYU dot COM [EMAIL PROTECTED] wrote: The first issue is the one described in Microsoft

Re: [Full-disclosure] Technical Details of Security Issues Regarding Safari for Windows

2008-06-11 Thread LIUDIEYU dot COM
Errata -- The PNG graphic can't be reached directly. Can be viewed by following link in the aforementioned blog entry: http://liudieyu0.blog124.fc2.com/blog-entry-5.html On Wed, Jun 11, 2008 at 5:17 PM, LIUDIEYU dot COM [EMAIL PROTECTED] wrote: Aviv really gave huge hint on the issue:

[Full-disclosure] CORE-2008-0125: CitectSCADA ODBC service vulnerability

2008-06-11 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ~ Core Security Technologies - CoreLabs Advisory ~ http://www.coresecurity.com/corelabs/ ~ CitectSCADA ODBC service vulnerability *Advisory Information* Title: CitectSCADA ODBC service vulnerability Advisory ID: CORE-2008-0125

[Full-disclosure] Many bugs on CMS system Piugame

2008-06-11 Thread Psymera
Many bugs on CMS system Piugame http://www.piugame.com Researcher: Psymera 1.-Overview Piugame CMS is one system used for control and contac of Pump It up Gamers over the world and Metod of control for official tournamets over the wold 2.-Description This system has a vulnerabily as Sql

Re: [Full-disclosure] Out of Office AutoReply: Snort Signature to det ect credit ca rds

2008-06-11 Thread West, Bill (USA)
... just saw this while browsing the archive. Belated apologies for the annoyance. There had been a milter rule to block these from my account to the internet, but was disabled at some point for debugging and (obviously) never turned back on. Cheers Bill -Original Message- From:

Re: [Full-disclosure] Mambo Cookie Authentication Bypass Exploit

2008-06-11 Thread crunkd
My social skills are great when it comes to talking to rational, non-fame-seeking people. However when the XSS and not-a-real-bug fanboys start posting someone has to stand up. As for you... I am sure you were that kid at school who told on the others just so the teacher would like you because

[Full-disclosure] persistant XSS, Manipulation of Data and privileg escalation in gpotato.eu forums

2008-06-11 Thread MC Iglo
Hi all, the forums of gpotato.eu is prone to multiple different vulnerabilities. Timeline for XSS: 14. May: notified gpotato.eu stating, that there are security wholes in their forum I could use to steal login-information 15. May: response: there is no bug in the forum, and as the login

[Full-disclosure] Secunia Research: uTorrent / BitTorrent Web UI HTTP Range Header DoS

2008-06-11 Thread Secunia Research
== Secunia Research 11/06/2008 - uTorrent / BitTorrent Web UI HTTP Range Header DoS - == Table of Contents Affected

[Full-disclosure] XSS Browser hijacking PoC?

2008-06-11 Thread Aaron Katz
Hi all, Several months ago, there was a post about a proof of concept for complete browser hijacking via XSS. IIRC, the hijacked browser would periodically query a management server, and the management server would track the hijacked browsers in a database. The person controlling the management

Re: [Full-disclosure] netdouche

2008-06-11 Thread Ureleet
On Fri, Jun 6, 2008 at 5:25 PM, n3td3v [EMAIL PROTECTED] wrote: I'm not a troll---i'm a serious security researcher, that doesn't mean i'm a hacker, it just means I read news articles on Cnet News and post my opinion on the Talkback feature. you are a reposter. you havent researched

Re: [Full-disclosure] I am who I am...

2008-06-11 Thread Ureleet
On Fri, Jun 6, 2008 at 8:21 PM, n3td3v [EMAIL PROTECTED] wrote: WHY DIDN'T YOU JUST LET ME GO AWAY AND LEAD A LIFE INSTEAD OF WRITING ABOUT ME? why dont you go away then? ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] POP QUIZ

2008-06-11 Thread Ureleet
On Sun, Jun 8, 2008 at 11:19 PM, Professor Micheal Chatner [EMAIL PROTECTED] wrote: A) You are a gay faggot who sucks dicks B) All of the above go away you are not better then some of the other guys around here. ___ Full-Disclosure - We believe in

Re: [Full-disclosure] To clear the air and conspiracy about n3td3v

2008-06-11 Thread Ureleet
On Thu, Jun 5, 2008 at 11:06 AM, n3td3v [EMAIL PROTECTED] wrote: Why did you ruin the build up to Web Application Security Awareness Day? It was because of what you and Valdis said on the weeks running upto it that nobody post anything. I mentioned mi6 to try and scare you and stop you

Re: [Full-disclosure] Fwd: www.Amazon.com down?

2008-06-11 Thread Ureleet
On Fri, Jun 6, 2008 at 4:31 PM, n3td3v [EMAIL PROTECTED] wrote: Shut up you faggot Amazon.com was down for hours, did you not read the news report? http://news.cnet.com/8301-10784_3-9962010-7.html amazon was down. it was a routing issue. ___

Re: [Full-disclosure] netdouche

2008-06-11 Thread Professor Micheal Chatner
u dudez r obviously all a bunch of retardo losers from planet earth probably. what a bunch of ding dong lickin wang gobblin homoooz.hacking is basically gay as fuck and ppl who care about it are TOTAL FUCKING LOSERS. steve manzuik is a fuckin retard. if anyone can find his

[Full-disclosure] [SECURITY] [DSA 1594-1] New imlib2 packages fix arbitrary code execution

2008-06-11 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1594-1 [EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff June 11, 2008

[Full-disclosure] iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension AllocateGlyph() Integer Overflow Vulnerability

2008-06-11 Thread iDefense Labs
iDefense Security Advisory 06.11.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 11, 2008 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. The Render extension is used to provide Porter-Duff image compositing for the X server. It is

[Full-disclosure] iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension ProcRenderCreateCursor() Integer Overflow Vulnerability

2008-06-11 Thread iDefense Labs
iDefense Security Advisory 06.11.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 11, 2008 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. The Render extension is used to provide Porter-Duff image compositing for the X server. It is

[Full-disclosure] iDefense Security Advisory 06.11.08: Multiple Vendor X Server Render Extension Gradient Creation Integer Overflow Vulnerability

2008-06-11 Thread iDefense Labs
iDefense Security Advisory 06.11.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 11, 2008 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. The Render extension is used to provide Porter-Duff image compositing for the X server. It is

[Full-disclosure] iDefense Security Advisory 06.11.08: Multiple Vendor X Server Record and Security Extensions Multiple Memory Corruption Vulnerabilities

2008-06-11 Thread iDefense Labs
iDefense Security Advisory 06.11.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 11, 2008 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. For more information, see the vendor's site found at the following link.

[Full-disclosure] iDefense Security Advisory 06.11.08: Multiple Vendor X Server MIT-SHM Extension Information Disclosure Vulnerability

2008-06-11 Thread iDefense Labs
iDefense Security Advisory 06.11.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jun 11, 2008 I. BACKGROUND The X Window System is a graphical windowing system based on a client/server model. More information about about The X Window system is available at the following link.

Re: [Full-disclosure] Metasploit - Hack ?

2008-06-11 Thread T Biehn
oh man. sarcasm On Wed, Jun 11, 2008 at 2:28 PM, Ureleet [EMAIL PROTECTED] wrote: oh, and for those that were confused.. sarcasm On Thu, Jun 5, 2008 at 4:14 PM, T Biehn [EMAIL PROTECTED] wrote: Did you just totally match up two instances of the string ARP Poisoning? You've got a lot more