[Full-disclosure] [USN-1062-1] Kerberos vulnerabilities

2011-02-14 Thread Steve Beattie
=== Ubuntu Security Notice USN-1062-1 February 15, 2011 krb5 vulnerabilities CVE-2010-4022, CVE-2011-0281, CVE-2011-0282 === A security issue affects the following Ubuntu release

Re: [Full-disclosure] Linksys WAP610N Unauthenticated Root Console

2011-02-14 Thread Matteo Ignaccolo
The correct public disclosure date is 10/02/2011 In data Thursday 10 February 2011 00:12:10, Matteo Ignaccolo ha scritto: > Secure Network - Security Research Advisory > > Vuln name: Linksys WAP610N Unauthenticated Access With Root Privileges > Systems affected: WAP610N (Firmware Version: 1.0.01

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-14 Thread Eyeballing Weev
On Mon, Feb 14, 2011 at 4:54 PM, MustLive wrote: > Hello Michele! > > Few days ago I saw your advisory about Drupal's captcha. It's interesting > advisory, but I have one note concerning it - your research is very close > to > mine ;-) (it concerns similar holes which I found before you). > Quit

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-14 Thread MustLive
Hello Michele! Few days ago I saw your advisory about Drupal's captcha. It's interesting advisory, but I have one note concerning it - your research is very close to mine ;-) (it concerns similar holes which I found before you). First, you are talking Drupal captcha and saying that Drupal <= 6.20

[Full-disclosure] [USN-1063-1] QEMU vulnerability

2011-02-14 Thread Kees Cook
=== Ubuntu Security Notice USN-1063-1 February 14, 2011 qemu-kvm vulnerability CVE-2011-0011 === A security issue affects the following Ubuntu releases: Ubuntu 9.10 Ubuntu 10.04

[Full-disclosure] [SECURITY] [DSA 2161-2] OpenJDK security update

2011-02-14 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2161-2 secur...@debian.org http://www.debian.org/security/Florian Weimer February 14, 2011

[Full-disclosure] [SECURITY] [DSA 2163-1] python-django security update

2011-02-14 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2163-1 secur...@debian.org http://www.debian.org/security/Nico Golde February 14, 2011

[Full-disclosure] Security of themes for WordPress

2011-02-14 Thread MustLive
Hello participants of Mailing List. In 2009 I already told you about security of plugins for WordPress (http://lists.grok.org.uk/pipermail/full-disclosure/2009-November/071553.html). And from that time I've updated that list of vulnerable plugins. And now I'll tell you about different vulnerabilit

Re: [Full-disclosure] iDefense Security Advisory 02.08.11: Microsoft Windows Picture and Fax Viewer Library

2011-02-14 Thread jatin.chowdhry
Hello, Can any one help out by providing the way to monitor it through the SIEM tool if this vulnerability is being exploited inside the network. It will be really helpful for me. Regards, Jatin From: labs-no-reply [mailto:labs-no-re...@ivcp.vrsn.com] Sent: We

[Full-disclosure] MS Windows Server 2003 AD Pre-Auth BROWSER ELECTION Remote Heap Overflow

2011-02-14 Thread Pwned MSRC
#MS Windows Server 2003 AD Pre-Auth BROWSER ELECTION Remote Heap Overflow #Release date: 2011-02-14 #Anonymous Comment: Apologies if this puts a downer on the MSRC valentines day sausage fest #Author: Cupidon-3005

[Full-disclosure] [SECURITY] [DSA 2162-1] openssl security update

2011-02-14 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2162-1 secur...@debian.org http://www.debian.org/security/Nico Golde February 14, 2011

Re: [Full-disclosure] High performance exception/traceback reporting system

2011-02-14 Thread Daniƫl W . Crompton
On 14 February 2011 09:04, Cal Leeming [Simplicity Media Ltd] < cal.leem...@simplicitymedialtd.co.uk> wrote: <...snipped for brevity...> > I'd never heard of SIEM before, after looking on wikipedia I came across > "NitroSecurity" SIEM which sure does look interesting. I'm gonna have a > flick thro

[Full-disclosure] [ MDVSA-2011:026 ] phpmyadmin

2011-02-14 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:026 http://www.mandriva.com/security/ _

[Full-disclosure] Released Stream Armor v1.5 - Smart Tool to Scan & Clean Malicious Streams !

2011-02-14 Thread Nagareshwar Talekar
Hi all, Stream Armor v1.5 is released today. StreamArmor is the sophisticated tool for discovering hidden alternate data streams (ADS) as well as clean them completely from the system. Few main features * Advanced stream file type detection * Auto Threat Analysis * Online Threat Verification

Re: [Full-disclosure] High performance exception/traceback reporting system

2011-02-14 Thread Cal Leeming [Simplicity Media Ltd]
Oh, having support for XMPP/AMQP would be extremely nice, ideally I'd want to try and make it compatible with as many different messaging systems as possible. On top of this, each supported language would have a library containing out-of-the-box functions which has every type of messaging/transpor