Re: [Full-disclosure] Blackberry pwd hack or reset

2010-06-06 Thread jim . hewitt
Do you have a link or any specific version that allows this. I would love to test it. As for the backups, when creating one it prompts you if you want to Encrypt the backup. -Original Message- From: Michael Graham Date: Fri, 4 Jun 2010 18:18:27 To: full-disclosure@lists.grok.org.uk S

[Full-disclosure] [SECURITY] [DSA 2056-1] New zonecheck packages fix cross-site scripting

2010-06-06 Thread Sebastien Delafond
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2056-1 secur...@debian.org http://www.debian.org/security/ Sébastien Delafond June 06, 2010

[Full-disclosure] DoS attacks on email clients via protocol handlers

2010-06-06 Thread MustLive
Hello Full-Disclosure! I want to warn you about security vulnerabilities in email clients, particularly in Outlook Express and Outlook. This advisory is concerned with my series of advisories about vulnerabilities in browsers, which belong to group of DoS via protocol handlers. All those who doub

[Full-disclosure] IceMan`s a.k.a romanian skiddie e107 botnet

2010-06-06 Thread zeus penguin
http://php-security.org/2010/05/19/mops-2010-035-e107-bbcode-remote-php-code-execution-vulnerability/index.html <= e107 recent vuln 94.249.152.10 - - [05/Jun/2010:14:10:39 +0100] "POST /contact.php HTTP/1.1" 200 18708 "-" "Mozilla/5.0" <= my apache logs http://188.24.49.67/ <= his home ip inetnum

Re: [Full-disclosure] RSA Key Manager SQL injection Vulnerability ( CVE-2010-1904 )

2010-06-06 Thread Security_Alert
What is the issue? This message is in response to the original message posted on June 3, 2010 addressing a SQL Injection vulnerability in the RSA Key Manager C Client version 1.5. The original message referenced CVE-2010-1904. A vulnerability has been identified in the RSA Key Manager (RKM) C cl

Re: [Full-disclosure] Blackberry pwd hack or reset

2010-06-06 Thread Michael Graham
Older versions of the BB windows desktop sync application do not respect the password prompt and will allow you to pull info from the phone, or to pull info from phone backups. For phone connections, these versions understand serial ports only. Which versions and getting a serial to usb connectio

[Full-disclosure] Vulnerabilities in Gigya Socialize for WordPress

2010-06-06 Thread MustLive
Hello Full-Disclosure! I want to warn you about security vulnerabilities in plugin Gigya Socialize for WordPress. - Advisory: Vulnerabilities in Gigya Socialize for WordPress - URL: http://websecurity.com.ua/4153/ ---

Re: [Full-disclosure] DoS vulnerability in Internet Explorer

2010-06-06 Thread MustLive
Hello Christian! I'm glad for your attention to my letter about DoS vulnerability in Internet Explorer. But your answer (as Jeff's) is completely unequal and is completely off-topic. So I'll draw your attention to the next. As I already wrote in February to another reader of Full-disclosure, who