Re: [Full-disclosure] NiX - Linux Brute Forcer (the beast) has been released!]]

2010-11-14 Thread nix
Are there any exclusively NiX forums? I've run into similar issues and google isnt finding much for me ugh There are no NiX forums, if you are having issues, just ask me. What kind of issues? Some people have asked what advantages NiX offers over other tools, this question should have

Re: [Full-disclosure] Joomla 1.5.21 | Potential SQL Injection Flaws

2010-11-14 Thread Henri Salo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Fri, 5 Nov 2010 21:41:42 +0800 YGN Ethical Hacker Group li...@yehg.net wrote: This public disclosure has achieved its aim. Joomla! Team finally patched this hole.

[Full-disclosure] [SECURITY] [DSA 2038-3] New pidgin packages fix regression

2010-11-14 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2038-3 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst November 13, 2010

Re: [Full-disclosure] Python ssl handling could be better...

2010-11-14 Thread dave b
Just when you thought it couldn't get worse... http://bugs.python.org/issue3596 http://bugs.python.org/issue4870 So now the programmer still needs to say OH disable sslv2 (or doesn't select sslv2) but by default it will be enabled. The python doc says this: ssl.PROTOCOL_SSLv23 Selects SSL

Re: [Full-disclosure] Archive of NoMarriage.com, The definitive guide on marriage and staying single.

2010-11-14 Thread Kenneth Voort
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Aside from being insanely bigoted, stereotypical, and offensive (satirical or otherwise), I fail to see the relevance of this material to this list. It belongs here no more than jokes about blacks and cotton, or Jews and ashtrays. On 10-11-12 3:56

Re: [Full-disclosure] Archive of NoMarriage.com, The definitive guide on marriage and staying single.

2010-11-14 Thread Jens Christian Hillerup
On Fri, Nov 12, 2010 at 9:56 PM, Troy Canasta kingofpainfo...@ymail.comwrote: Jon Hertzog is a voice echoing out in the wilderness. My oracle of the day, an ode to you I giveth. (... and so on) What the fuck is this? ___ Full-Disclosure - We

[Full-disclosure] Facebook API

2010-11-14 Thread RandallM
so..who's worked with http://developers.facebook.com/docs/api and have used it in interesting ways? -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted

Re: [Full-disclosure] Facebook API

2010-11-14 Thread Christian Sciberras
I think that's the wrong question. You should be asking: Does this even work? Cheers. On Sun, Nov 14, 2010 at 8:45 PM, RandallM randa...@fidmail.com wrote: so..who's worked with http://developers.facebook.com/docs/api and have used it in interesting ways? -- been great, thanks RandyM

Re: [Full-disclosure] Saved XSS vulnerability in Internet Explorer

2010-11-14 Thread Zach C
But it requires that the user/potential victim go to the URL and save it, you say? That doesn't quite seem realistic at all in terms of an attack... On Nov 14, 2010, at 9:56 AM, MustLive mustl...@websecurity.com.ua wrote: Hello Full-Disclosure! I want to warn you about Cross-Site Scripting

Re: [Full-disclosure] Saved XSS vulnerability in Internet Explorer

2010-11-14 Thread Christian Sciberras
...rename it and run it again. If MustLive says so, it must be realistic... On Sun, Nov 14, 2010 at 9:14 PM, Zach C fxc...@gmail.com wrote: But it requires that the user/potential victim go to the URL and save it, you say? That doesn't quite seem realistic at all in terms of an attack... On

Re: [Full-disclosure] Facebook API

2010-11-14 Thread RandallM
On Sun, Nov 14, 2010 at 1:48 PM, Christian Sciberras uuf6...@gmail.com wrote: I think that's the wrong question. You should be asking: Does this even work? Cheers. On Sun, Nov 14, 2010 at 8:45 PM, RandallM randa...@fidmail.com wrote: so..who's worked with