[Full-disclosure] Launched Orbit Downloader Password Decryptor

2011-05-27 Thread SecurityXploded Group
Hi all, Today we have launched yet another password tool in fact our 71st tool, Orbit Password Decryptor - Free Orbit Downloader Password Recovery Tool. It helps you to instantly recover account passwords of premium download site such as Rapidshare.com, Megaupload etc from Orbit Downloader. Apar

[Full-disclosure] [SECURITY] [DSA 2244-1] bind9 security update

2011-05-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2244-1 secur...@debian.org http://www.debian.org/security/Florian Weimer May 27, 2011

[Full-disclosure] [SECURITY] [DSA 2243-1] unbound security update

2011-05-27 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2243-1 secur...@debian.org http://www.debian.org/security/Florian Weimer May 27, 2011

Re: [Full-disclosure] Online Base64 Decoder & Encoder with ASCII/Hex Output

2011-05-27 Thread Cal Leeming
Delivery to the following recipient failed permanently: cont...@securityxploded.com Technical details of permanent failure: Google tried to deliver your message, but it was rejected by the recipient domain. We recommend contacting the other email provider for further information about the cau

Re: [Full-disclosure] Online Base64 Decoder & Encoder with ASCII/Hex Output

2011-05-27 Thread Cal Leeming
>From a web developer / designer point of view, this page looks quite awful, jumps around the place when you click submit, and doesn't have a very nice feel to it :( On Thu, May 26, 2011 at 5:46 PM, SecurityXploded Group < cont...@securityxploded.com> wrote: > Hi all, > > Here is one of our new o

Re: [Full-disclosure] Online Base64 Decoder & Encoder with ASCII/Hex Output

2011-05-27 Thread Peter Ferrie
> Here is one of our new online tools, Base64 Decoder & Encoder. Apart > from attractive, easy to use interface, it shows output in both ASCII > & HEX format. Which model do you use? Standard? PHP? IE/Outlook? OMG they can all decode the crafted input differently! sigh. __

[Full-disclosure] Viewpoint: Security implications of IPv6

2011-05-27 Thread Fernando Gont
Folks, CPNI (http://www.cpni.gov.uk) has published the "Security implications of IPv6" viewpoint document, which is basically an excerpt of a technical report on which I have been working during the last couple of years, and we'll be published anytime soon. The viewpoint is available at:

[Full-disclosure] [SECURITY] CVE-2011-1077: Apache Archiva Multiple XSS vulnerability

2011-05-27 Thread Deng Ching
CVE-2011-1077: Apache Archiva Multiple XSS vulnerability Severity: High Vendor: The Apache Software Foundation Versions Affected: Archiva 1.3.0 - 1.3.4 The unsupported versions Archiva 1.0 - 1.2.2 are also affected. Description: The multiple XSS issues found are both Stored (Persistent) and Ref

[Full-disclosure] [SECURITY] CVE-2011-1026: Apache Archiva Multiple CSRF vulnerability

2011-05-27 Thread Deng Ching
CVE-2011-1026: Apache Archiva Multiple CSRF vulnerability Severity: High Vendor: The Apache Software Foundation Versions Affected: Archiva 1.3.0 - 1.3.4 The unsupported versions Archiva 1.0 - 1.2.2 are also affected. Description: An attacker can build a simple html page containing a hidden Imag

[Full-disclosure] CfP: ICSEA 2011 || October 23-28, 2011 - Barcelona, Spain

2011-05-27 Thread Cristina Pascual
INVITATION: = Please consider to contribute to and/or forward to the appropriate groups the following opportunity to submit and publish original scientific results. Note that the submission deadline of June 1st, 2011 is approaching. In addition, authors of selected papers will be

Re: [Full-disclosure] BIND Security Advisory CVE-2011-1910

2011-05-27 Thread bernhard . koppensteiner
Hello, since I am using SLES 11, which comes with BIND 9.5 I am wondering if this version of Bind is also affected.___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - ht

Re: [Full-disclosure] Trustwave – Security begins with Trust, then you get 0wned!

2011-05-27 Thread Cal Leeming
lmao nice. On Thu, May 26, 2011 at 5:25 PM, Nathan Power wrote: > An updated Trustwave WebDefend advisory has been posted > http://www.foofus.net/?p=290 > > > > Nathan Power > www.securitypentest.com > > ___ > Full-Disclosure - We believe in it. > Chart

Re: [Full-disclosure] MySql Password Auditor v1.0 Released

2011-05-27 Thread Charles Skoglund
On 5/26/11 11:12 PM, "PEra" wrote: > On 05/25/2011 12:57 AM, Tracy Reed wrote: >> If anyone wanted to write a real tool for auditing mysql they would look at >> query logs and generate a list of least-privilege permissions each user needs >> and identify database users with overly broad permission