Re: [Full-disclosure] CCBILL.COM Internet billing service multiple vulnerabilities

2010-08-16 Thread Jeffrey Walton
On Mon, Aug 16, 2010 at 10:06 PM, Michal Zalewski wrote: >> A COI knows no national boundaries. > > Oh sure - but Jeffrey seems to be particularly critical of US > policies; I suspect this is unfair ;-) Agreed! I don't have a neutral point of view when it comes to the folks who are the back bone o

Re: [Full-disclosure] CCBILL.COM Internet billing service multiple vulnerabilities

2010-08-16 Thread Michal Zalewski
> A COI knows no national boundaries. Oh sure - but Jeffrey seems to be particularly critical of US policies; I suspect this is unfair ;-) /mz ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted

Re: [Full-disclosure] CCBILL.COM Internet billing service multiple vulnerabilities

2010-08-16 Thread mrx
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 17/08/2010 01:17, Michal Zalewski wrote: >> It seems that corporate America's purchasing of politicians (err, PAC >> contributions) has been well worth the investment. Legislation is such >> that victims and shareholders both suffer after a breach.

Re: [Full-disclosure] CCBILL.COM Internet billing service multiple vulnerabilities

2010-08-16 Thread Michal Zalewski
> It seems that corporate America's purchasing of politicians (err, PAC > contributions) has been well worth the investment. Legislation is such > that victims and shareholders both suffer after a breach. > > * Heartland Databreach Lawsuit Dismissed >   http://news.cnet.com/8301-27080_3-10413194-24

Re: [Full-disclosure] CCBILL.COM Internet billing service multiple vulnerabilities

2010-08-16 Thread Jeffrey Walton
> # 30/07/2010 - Vendor notified. / no response > # 03/08/2010 - Vendor notified. / no response > # 10/08/2010 - Vendor notified. / no response Its unfortunate that the vendor did not respond. But in the US, legislation is such that its more cost effective to suffer the breach and then turn it over

[Full-disclosure] CCBILL.COM Internet billing service multiple vulnerabilities

2010-08-16 Thread Vulnerabilities
We want to warn you about security vulnerabilities in CCBILL.COM Internet billing service. CCBill is an Internet billing service. Established in 1998, the company provides third-party billing, or turn-key solutions, for e-Merchants requiring payments by way of credit card, debit card, or e-ch

[Full-disclosure] CVE-2010-3014: Coda Filesystem Kernel Memory Disclosure

2010-08-16 Thread VSR Advisories
ty.com/resources/advisory/20100816-1/ - -=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=- Product Description - --- - From [1]: "Coda is a distributed filesystem with its origin in AFS2. It has many features that are very desirable

[Full-disclosure] blackboard security contact that can actually handle a report?

2010-08-16 Thread Charles Morris
is there anyone?? vulnerabilities found, off-list replies sought. fall students approach; standard contact methods give: just disappointment. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted an

[Full-disclosure] [ MDVSA-2010:154 ] cabextract

2010-08-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:154 http://www.mandriva.com/security/ _

[Full-disclosure] [ MDVSA-2010:153 ] apache

2010-08-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:153 http://www.mandriva.com/security/ _

[Full-disclosure] [USN-971-1] OpenJDK vulnerabilities

2010-08-16 Thread Kees Cook
=== Ubuntu Security Notice USN-971-1August 16, 2010 openjdk-6 vulnerabilities CVE-2010-2548, CVE-2010-2783 === A security issue affects the following Ubuntu releases: Ubuntu

[Full-disclosure] [ MDVSA-2010:152 ] apache

2010-08-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:152 http://www.mandriva.com/security/ _

[Full-disclosure] [ MDVSA-2010:151 ] libmikmod

2010-08-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:151 http://www.mandriva.com/security/ _