[Full-disclosure] [ GLSA 200810-02 ] Portage: Untrusted search path local root vulnerability

2008-10-09 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200810-02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] CA ARCserve Backup Multiple Vulnerabilities

2008-10-09 Thread Williams, James K
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Title: CA ARCserve Backup Multiple Vulnerabilities CA Advisory Date: 2008-10-09 Reported By: Haifei Li of Fortinet's FortiGuard Global Security Research Team Vulnerability Research Team of Assurent Secure Technologies, a TELUS Company Greg

[Full-disclosure] Metasploit 3.2 Offers More 'Evil Deeds'

2008-10-09 Thread Ivan .
Metasploit 3.2 looks like it rocks! http://www.internetnews.com/dev-news/article.php/3776831/Metasploit+32+Offers+More+Evil+Deeds.htm ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

[Full-disclosure] Diamond Prize Center internal documents not secure ...

2008-10-09 Thread James Malberry
Here's an actual tele marketing script to get you to goto a timeshare presentation. I do not work for diamond prize, nor a former employee. I am a tax accountant that has a background in Information Technology. Their Company site, www.diamondprizecenter.com a single webpage that is password

Re: [Full-disclosure] Metasploit 3.2 Offers More 'Evil Deeds'

2008-10-09 Thread n3td3v
http://www.internetnews.com/dev-news/article.php/3776831/Metasploit+32+Offers+More+Evil+Deeds.htm i don't think it should be publicly available, you should need to register to prove your who you are, have a background check done on you before you get it.

[Full-disclosure] security industry software license

2008-10-09 Thread n3td3v
there should be a central license that people apply for to use software like metasploit. all the *respected* programmers would require the license before you get to download. anyone can apply for a licence, however only those who meet the criteria get given the licence. background checks are

Re: [Full-disclosure] security industry software license

2008-10-09 Thread Valdis . Kletnieks
On Fri, 10 Oct 2008 02:31:06 BST, n3td3v said: there should be a central license that people apply for to use software like metasploit. You don't want to go there. They start requiring licenses to have Metasploit or Snort or Nessus, it's a slippery slope, and they'll start requiring a

Re: [Full-disclosure] Metasploit 3.2 Offers More 'Evil Deeds'

2008-10-09 Thread H D Moore
You can find our SecTOR presentation online at: http://metasploit.com/research/conferences/ Grab an early of 3.2 (testing) from SVN: $ svn co http://metasploit.com/svn/framework3/trunk/ msf32/ A little bit about the new licensing (much more to follow):

[Full-disclosure] ZDI-08-067: Apple CUPS 1.3.7 (HP-GL/2 filter) Remote Code Execution Vulnerability

2008-10-09 Thread zdi-disclosures
ZDI-08-067: Apple CUPS 1.3.7 (HP-GL/2 filter) Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-08-067 October 9, 2008 -- CVE ID: CVE-2008-3641 -- Affected Vendors: Apple -- Affected Products: Apple OS X -- TippingPoint(TM) IPS Customer Protection:

[Full-disclosure] [USN-651-1] Ruby vulnerabilities

2008-10-09 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-651-1 October 10, 2008 ruby1.8 vulnerabilities CVE-2008-2376, CVE-2008-3443, CVE-2008-3655, CVE-2008-3656, CVE-2008-3657, CVE-2008-3790, CVE-2008-3905

[Full-disclosure] Fwd: Secret Service, Lockheed Martin and partners to fight cyber crime

2008-10-09 Thread n3td3v
-- Forwarded message -- From: n3td3v [EMAIL PROTECTED] Date: Fri, Oct 10, 2008 at 12:13 AM Subject: Secret Service, Lockheed Martin and partners to fight cyber crime To: n3td3v [EMAIL PROTECTED] A consortium of government, corporate and academic institutions have joined forces to

Re: [Full-disclosure] Metasploit 3.2 Offers More 'Evil Deeds'

2008-10-09 Thread James Matthews
I think it's a nice tool, enabling people that cannot afford the more expensive (Core Impact or Immunity CANVAS) so still have a nice stable framework. On Thu, Oct 9, 2008 at 6:38 PM, H D Moore [EMAIL PROTECTED] wrote: You can find our SecTOR presentation online at: