[Full-disclosure] seriously?

2011-04-05 Thread Ian French
hello all. came across this example of poor security. what do you think? http://www.sidneysdeptstore.com/lib/shared_components/WS_FTP.LOG ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

[Full-disclosure] VMWare Manage Subscriptions - Info Disclosure

2011-04-05 Thread p8x
Hi all, Not really sure if this is an intended feature but I decided to unsubscribe from the VMWare Newsletters that get sent out today. You get sent to the following address to unsubscribe: http://info.vmware.com/content/opt-out?elq=[UNIQUE ID] The ID provided in the URL looks like it is to

Re: [Full-disclosure] seriously?

2011-04-05 Thread Benji
Welcome to the internet, circa 1830 On Tue, Apr 5, 2011 at 1:43 AM, Ian French tohits...@gmail.com wrote: hello all. came across this example of poor security. what do you think? http://www.sidneysdeptstore.com/lib/shared_components/WS_FTP.LOG ___

Re: [Full-disclosure] seriously?

2011-04-05 Thread Juha-Matti Laurio
http://lists.grok.org.uk/pipermail/full-disclosure/2004-August/025323.html Juha-Matti Benji [m...@b3nji.com] wrote: Welcome to the internet, circa 1830 On Tue, Apr 5, 2011 at 1:43 AM, Ian French tohits...@gmail.com wrote: hello all. came across this example of poor security. what do you

Re: [Full-disclosure] seriously?

2011-04-05 Thread Michael Lenz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 It's rather stupid to make logfiles world-readable and -accessible, but should *we* care? Drop them a mail and tell them (how) to fix it. Yours, Michael On 05.04.2011 02:43, Ian French wrote: hello all. came across this example of poor

[Full-disclosure] WhatWeb v0.4.7 Released. Performance enhancements and bug fixes

2011-04-05 Thread Andrew Horton
Version 0.4.7 of WhatWeb is now released. This is a stability release with performance enhancements and a few bug fixes. .$$$ $. .$$$ $. $$. .$$$ $$$ .$$. .$$. $$. .$$$. .$$. $ $$ $$$ $ $$ $$$ $ $$. $

[Full-disclosure] [ MDVSA-2011:065 ] logrotate

2011-04-05 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:065 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2011:066 ] rsync

2011-04-05 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:066 http://www.mandriva.com/security/

[Full-disclosure] [USN-1105-1] Linux kernel vulnerabilities

2011-04-05 Thread Kees Cook
=== Ubuntu Security Notice USN-1105-1April 05, 2011 linux vulnerabilities CVE-2010-4075, CVE-2010-4076, CVE-2010-4077, CVE-2010-4158, CVE-2010-4162, CVE-2010-4163, CVE-2010-4164, CVE-2010-4242, CVE-2010-4258, CVE-2010-4346