[Full-disclosure] HITB Security Conference 2010 Dubai Call for Papers

2009-11-22 Thread Hafez Kamal
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The Call for Papers for HITB Security Conference 2010 Dubai is now open! Talks that are more technical or that discuss new and never before seen attack methods are of more interest than a subject that has been covered several times before. Summaries

[Full-disclosure] Millions of PDF invisibly embedded with your internal disk paths

2009-11-22 Thread Inferno
Millions of PDF invisibly embedded with your internal disk paths I found an interesting privacy issue while analyzing PDF files. This bug occurs when you are using Internet Explorer to print locally saved web pages as PDF and

Re: [Full-disclosure] Millions of PDF invisibly embedded with your internal disk paths

2009-11-22 Thread Juha-Matti Laurio
The local path is being disclosed with a simple query too without putting .HTM/.MHT to the string: http://www.google.com/search?hl=enq=filetype%3Apdf+file+c Another issue is the disclosure of user names - you can simply find the author's full name John Smith from the pdf document and see that

[Full-disclosure] Climategate: how the MSM rep orted the greatest scandal in modern science – Telegraph Blogs

2009-11-22 Thread Ivan .
hackers providing a public service.. http://blogs.telegraph.co.uk/news/jamesdelingpole/100017451/climategate-how-the-msm-reported-the-greatest-scandal-in-modern-science/ ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] ICMPv4/IP fuzzer prototype.

2009-11-22 Thread laurent gaffie
Should be kweel for UTesting http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-prototype.html Enjoy. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

[Full-disclosure] [Bkis-13-2009] e107 Multiple Vulnerabilities

2009-11-22 Thread Bkis
[Bkis-13-2009] e107 Multiple Vulnerabilities 1. General Information e107 is a free content management system (CMS) written in PHP language and is available at http://e107.org/news.php . In October 2009, Bkis Security discovered a number of XSS and Blind SQL Injection vulnerabilities on this

Re: [Full-disclosure] ICMPv4/IP fuzzer prototype.

2009-11-22 Thread Andrew Farmer
On 22 Nov 2009, at 19:48, laurent gaffie wrote: Should be kweel for UTesting http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-prototype.html ... Dont forget it's a prototype, and i ASSUME you know what you're doing, do not ask for help. You definitely have to know what you're

[Full-disclosure] Fwd: ICMPv4/IP fuzzer prototype.

2009-11-22 Thread laurent gaffie
Hell no random.randrang - randrange(_) rtfm. and yeah u'r welcome. 2009/11/23 Andrew Farmer andf...@gmail.com On 22 Nov 2009, at 19:48, laurent gaffie wrote: Should be kweel for UTesting http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-prototype.html ... Dont forget