Re: [Full-disclosure] Joomla Component com_joomradio SQL Injection

2009-02-19 Thread Packet Storm
Already discovered in June, 2008. http://packetstormsecurity.org/0806-exploits/joomlajoomradio-sql.txt bc9c589fca40fce9a4f4484333f207b5 The Joomla Joomradio component version 1.0 suffers from a remote SQL injection vulnerability. Authored By a href=mailto:His0k4.hlm[at]gmail.com;His0k4/a On

Re: [Full-disclosure] Joomla Component com_joomradio SQL Injection

2009-02-19 Thread bobby . mugabe
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Dear gov-boi, Please follow the established etiquette of this list by linking to content on archive.org to establish credibility for alleged historic content. Linking to obscure post-dated content on your own Internet site, that easily can be faked,

Re: [Full-disclosure] Joomla Component com_joomradio SQL Injectionhas

2009-02-19 Thread infolookup
Has this been tested and verified this? Sent from my Verizon Wireless BlackBerry -Original Message- From: bobby.mug...@hushmail.com Date: Thu, 19 Feb 2009 10:22:48 To: zeus.olimpusk...@gmail.com; pac...@packetstormsecurity.org Cc: bugt...@zone-h.org; full-disclosure@lists.grok.org.uk;

[Full-disclosure] [ MDVSA-2009:043 ] gnumeric

2009-02-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:043 http://www.mandriva.com/security/

[Full-disclosure] Worthless Disclosure

2009-02-19 Thread T Biehn
While I can never hope to live up to Jim Bell's seminal work 'assassination politics' the following is a rough draft of something that follows the same vein. A theme, which many of you undoubtedly will recognize from the current TPB cout proceedings, of making money indirectly by taking advantage

[Full-disclosure] Oh Yeah, botnet communications

2009-02-19 Thread T Biehn
You know how the current amateur botnet offerings are basing domain lists off the current time to allow the 'good guys' to prepare? Why not base the seed off something like a news RSS feed? I asked some whitehats when I was ruined in Washington DC and they couldn't tell me. News isn't

Re: [Full-disclosure] Worthless Disclosure

2009-02-19 Thread Jason Starks
Of course. You get what you pay for and is there really any real point of relevance in asking? Jason On Thu, Feb 19, 2009 at 11:03 PM, T Biehn tbi...@gmail.com wrote: While I can never hope to live up to Jim Bell's seminal work 'assassination politics' the following is a rough draft of

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-19 Thread Valdis . Kletnieks
On Thu, 19 Feb 2009 23:13:38 EST, T Biehn said: You know how the current amateur botnet offerings are basing domain lists off the current time to allow the 'good guys' to prepare? Why not base the seed off something like a news RSS feed? I asked some whitehats when I was ruined in

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-19 Thread T Biehn
God Valdis, Dont concentrate on the mundane, the core issue is the unpredictable nature of it. You have them all coordinate reading the news at 12:00 AM GMT. You build some silly algorithm that ensures they pick the right article. -Travis On Thu, Feb 19, 2009 at 11:34 PM, valdis.kletni...@vt.edu

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-19 Thread Elazar Broad
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 You know how the current amateur botnet offerings are basing domain lists off the current time to allow the 'good guys' to prepare? Shhh, your gonna wake the insert A/V company here writes all the malware theorists... On Thu, 19 Feb 2009 23:13:38

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-19 Thread Valdis . Kletnieks
On Thu, 19 Feb 2009 23:38:37 EST, T Biehn said: God Valdis, Dont concentrate on the mundane, the core issue is the unpredictable nature of it. You have them all coordinate reading the news at 12:00 AM GMT. You build some silly algorithm that ensures they pick the right article. Right, so