[Full-disclosure] [USN-779-1] Firefox and Xulrunner vulnerabilities

2009-06-12 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-779-1 June 12, 2009 firefox-3.0, xulrunner-1.9 vulnerabilities CVE-2009-1832, CVE-2009-1833, CVE-2009-1834, CVE-2009-1835, CVE-2009-1836, CVE-2009-1837, CVE-2009-1838, CVE-2009-1839, CVE-2009-1840, C

[Full-disclosure] [DDOS] Target:switzerland

2009-06-12 Thread Julien godin
Hello, A person ( ya know ? the friend of a friend that have a well-position cousin that eard about some rumor ) told me about an upcoming DDOS attack on switzerland network infrastrucure. Does any of you have further information about this threat? Regards Julien ___

[Full-disclosure] Backdooring Windows Media Files (once again...)

2009-06-12 Thread Rosario Valotta
Hi everybody, I released a whitepaper concerning some new vulnerabilities I've found in Windows Media Player. These vulns could be exploited basicly in two scenarios: - local file enumeration on the victim's local pc - information gathering and network scanning in an Intranet environment Al

[Full-disclosure] Secunia Research: Mozilla Firefox Java Applet Loading Vulnerability

2009-06-12 Thread Secunia Research
== Secunia Research 12/06/2009 - Mozilla Firefox Java Applet Loading Vulnerability - == Table of Contents Affected Software.

[Full-disclosure] Backdooring windows media files (once again)

2009-06-12 Thread Rosario Valotta
Hi everybody, I've just published over my blog a whitepaper concerning some new vulnerabilities I've found in Windows Media Player.These vulns could be exploited basicly in two scenarios: - local file enumeration on the victim's local pc - information gathering and network scanning in an Int

[Full-disclosure] Alphanumeric ASCII SEH GetPC for XP up to sp3

2009-06-12 Thread Berend-Jan Wever
Hi all, I have released an updated version of my alphanumeric ASCII SEH GetPC code which works on Windows XP up to and including sp3: http://skypher.com/wiki/index.php/Hacking/Shellcode/Alphanumeric/ALPHA3/x86/ASCII/Mixedcase/SEH_GetPC_(XP_sp3) It bypasses the mitigations that stopped my previous