[Full-disclosure] OWASP AppSec DC 2009 CALL FOR PAPERS

2009-04-27 Thread Mark Bristow
Colleagues, OWASP is currently soliciting papers for the OWASP AppSec DC 2009 Conference that will take place at the Walter E. Washington Convention Center in Washington, DC on November 10th through 13th of 2009. There will be training courses on November 10th and 11th followed by plenary session

[Full-disclosure] full disclosure?

2009-04-27 Thread sunjester
this is in regards to... Message: 1 > Date: Mon, 27 Apr 2009 16:39:32 +0200 > From: Thierry Zoller > Subject: [Full-disclosure] [TZO-13-2009] Avira Antivir generic CAB >evasion / bypass > To: NTBUGTRAQ , bugtraq >,full-disclosure >, , >, , , > > Me

[Full-disclosure] [ MDVSA-2009:099 ] openafs

2009-04-27 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:099 http://www.mandriva.com/security/

[Full-disclosure] [USN-767-1] FreeType vulnerability

2009-04-27 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-767-1 April 27, 2009 freetype vulnerability CVE-2009-0946 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8

[Full-disclosure] [USN-766-1] acpid vulnerability

2009-04-27 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-766-1 April 27, 2009 acpid vulnerability CVE-2009-0798 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 8.04

[Full-disclosure] [USN-761-2] PHP vulnerabilities

2009-04-27 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-761-2 April 27, 2009 php5 vulnerabilities CVE-2008-5814, CVE-2009-1271 === A security issue affects the following Ubuntu releases: Ubuntu 9.04

Re: [Full-disclosure] About HSM

2009-04-27 Thread T Biehn
Hi Klaw, Looking to jump on the PIN Cracking money train are we? -Travis On Mon, Apr 27, 2009 at 3:22 PM, Thiago Musa wrote: > Hi, > > > > First of all sorry for my poor English. I’ve been working with security for > many years now, but I never had any experience with HSM (hardware security > mo

[Full-disclosure] About HSM

2009-04-27 Thread Thiago Musa
Hi, First of all sorry for my poor English. I've been working with security for many years now, but I never had any experience with HSM (hardware security model) before. Since I started to look the available solutions on the market, I came up with two different types: PKI HSM and EFT (or EMV) H

[Full-disclosure] [ MDVSA-2009:096-1 ] printer-drivers

2009-04-27 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:096-1 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:098 ] krb5

2009-04-27 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:098 http://www.mandriva.com/security/

[Full-disclosure] T2'09: Call for Papers 2009 (Helsinki / Finland)

2009-04-27 Thread Tomi Tuominen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ### T2'09 - Call For Papers ### Helsinki, Finland 29 - 30 October 2009 We are pleased to announce the annual T2´09 conference, which will take place in Helsinki, Finland, from October 29 to 30

[Full-disclosure] [SECURITY] [DSA 1779-1] New apt packages fix several vulnerabilities

2009-04-27 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1779-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst April 26, 2009

[Full-disclosure] SumatraPDF <= 0.9.3 Heap Overflow PoC

2009-04-27 Thread c
The overflow occurs at the following location: mupdf/mupdf/pdf_function.c:1167 obj = fz_dictgets(dict, "C0"); if (fz_isarray(obj)) { func->n = fz_arraylen(obj); for (i = 0; i < func->n; ++i) func->u.e.c0[i] = fz_toreal(fz_arrayget(obj, i)); } func->n

[Full-disclosure] DEFCON London DC4420 meet this Thursday - 30th April 2009

2009-04-27 Thread Major Malfunction
OK, so we're all set for an awesome meet this month: new venue with huge space in central london... 3 Fantastic talks: *** Andrea Barisani & Daniele Bianco: Sniffing Keystrokes With Lasers/Voltmeters - Side Channel Attacks Using Optical Sampling Of Mechanical Energy And Power Line Leaka

[Full-disclosure] [TZO-15-2009] Aladdin eSafe generic bypass - Forced release

2009-04-27 Thread Thierry Zoller
__ From the low-hanging-fruit-department - Aladdin eSafe bypass/evasion __ Release mode: Forced relaese, vendor has not replied. Ref : TZO-152009 - Ala

[Full-disclosure] [TZO-14-2009] Comodo Antivirus RAR evasion

2009-04-27 Thread Thierry Zoller
__ From the low-hanging-fruit-department - Comodo antivir bypass/evasion __ Release mode: Coordinated but limited disclosure. Ref : TZO-142009 - Comodo

[Full-disclosure] [TZO-13-2009] Avira Antivir generic CAB evasion / bypass

2009-04-27 Thread Thierry Zoller
__ From the low-hanging-fruit-department - Avira antivir bypass/evasion __ Release mode: Coordinated but limited disclosure. Ref : TZO-132009 - Avira A