[Full-disclosure] [ MDVSA-2011:099 ] libzip

2011-05-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:099 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2011:100 ] cyrus-imapd

2011-05-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:100 http://www.mandriva.com/security/

[Full-disclosure] DUOC.cl full dump exposes passwords, users, emails, phones, etc ...

2011-05-24 Thread allownobody
Title: Hushmail Express allownob...@hushmail.com has sent you a secure email using Hushmail. To read it, please visit the following web page: https://www.hushmail.com/express/6XDVLHR7 Frequently Asked Questions: Why did I receive this email? You have received this email because

[Full-disclosure] NNT Change Tracker - Hard-Coded Encryption Key

2011-05-24 Thread Dennis Brunnen
Background -- NNT Change Tracker Enterprise is a commercial product created by UK-based New Net Technologies, and is designed to detect changes to PC, server and network device configurations. The central component 'Core Server' is sent change data from 'Remote Angels' that monitor remote

[Full-disclosure] Drupal Webform Module Multiple Vulnerabilities

2011-05-24 Thread Justin Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Vulnerability Report Original Date of Vendor Notification: April 19, 2011 15:15 (GMT - 4:00) Description of Vulnerability: - - Drupal (http://drupal.org) is a robust content management system (CMS) written in PHP and

[Full-disclosure] [SECURITY] [DSA 2239-1] libmojolicious-perl security update

2011-05-24 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2239-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff May 24, 2011

[Full-disclosure] [SECURITY] [DSA 2241-1] qemu-kvm security update

2011-05-24 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2241-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff May 24, 2011

[Full-disclosure] CORE-2010-0908: Lotus Notes XLS viewer malformed BIFF record heap overflow

2011-05-24 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - Corelabs Advisory http://corelabs.coresecurity.com/ Lotus Notes XLS viewer malformed BIFF record heap overflow 1. *Advisory Information* Title: Lotus Notes XLS viewer malformed BIFF record heap overflow

[Full-disclosure] MySql Password Auditor v1.0 Released

2011-05-24 Thread Nagareshwar Talekar
Hi all, MysqlPasswordAuditor is the FREE tool to Recover or Audit Mysql passwords. It can support both local as well as remote Mysql server. In addition to recovering your lost/forgotten passwords, it can also help you to audit Mysql database server setup in an corporate environment by

Re: [Full-disclosure] MySql Password Auditor v1.0 Released

2011-05-24 Thread Tracy Reed
On Wed, May 25, 2011 at 03:30:18AM +0530, Nagareshwar Talekar spake thusly: In addition to recovering your lost/forgotten passwords, it can also help you to audit Mysql database server setup in an corporate environment by discovering the weak password configurations. What a nice euphemism. :)

[Full-disclosure] My comments on comodobr.com

2011-05-24 Thread Hgkdfhklj Jdhglkjfdhg
    I have to agree with Comodo president and CEO, Melih Abdulhayoglu.           In fact, anyone that can use sqlmap or pangolin and knows how to google for filetype:php inurl:prod could have found that sqli.     However the same way the security perimeter of the mainframe _should_ be extended

[Full-disclosure] International Master In Computer Security and Cyberwarfare

2011-05-24 Thread Mastere NIS
Our master “*Network and Information security*” (NIS) program is a springboard to a variety of exciting careers in security information ranging from computer network administrator, IT security expert or cyberwarfare expert for the Department of Defense to security officer in charge of the IT

[Full-disclosure] E-mail address spoofing with RLO

2011-05-24 Thread Wouter Coekaerts
E-mail address spoofing with RLO - http://wouter.coekaerts.be/2011/email-rlo Introduction = When we reply to an e-mail, the address we see in the To-field serves a purpose beyond getting our answer back to original sender. We attach a meaning to these addresses. If we see

[Full-disclosure] CVE-2011-1938 PHP socket_connect() stack buffer overflow

2011-05-24 Thread Marek Kroemeke
Hi there, This is a quick writeup about some fun with apache based on CVE-2011-1938 that was disclosed yesterday. While the first POC was literally just a trivial POC - the second one was written for self-educational purposes (we leared quite a lot which is the most important thing) and we hope

[Full-disclosure] Cookiejacking attack technique

2011-05-24 Thread Rosario Valotta
Hi, last week, in two security conferences I showed a new attack technique called Cookiejacking that allows to steal session cookies without any XSS vulnerability. https://www.swisscyberstorm.com/speakers/valotta http://conference.hackinthebox.org/hitbsecconf2011ams/?page_id=1388 All previous

Re: [Full-disclosure] International Master In Computer Security and Cyberwarfare

2011-05-24 Thread Valdis . Kletnieks
On Mon, 23 May 2011 16:10:02 +0200, Mastere NIS said: Our master *Network and Information security* (NIS) program is a springboard to a variety of exciting careers in security information ranging from computer network administrator, IT security expert or cyberwarfare expert for the Department