Re: [Full-disclosure] Apache 2.0.63 - 2.2.19 Remote Exploit Fake or not?

2011-06-17 Thread Kai
Claiming to gain root through a service that most people do not run as root already makes me think that this fake. do not forget about mpm-itk, mpm-peruser and analogs, when we have to run apache as root. -- Cheers, Kai ___ Full-Disclosure

Re: [Full-disclosure] Apache 2.0.63 - 2.2.19 Remote Exploit Fake or not?

2011-06-17 Thread decoder
On 06/17/2011 11:56 AM, Kai wrote: Claiming to gain root through a service that most people do not run as root already makes me think that this fake. do not forget about mpm-itk, mpm-peruser and analogs, when we have to run apache as root. True, and I cannot really say how many people use

Re: [Full-disclosure] xp sp3 remote bof

2011-06-17 Thread elfius
Thanks for the advice guys. I've received quite a few interesting offers from some rather shady sounding people (as well as public messages here), and I've begun to realise how much this is worth. So for the time being anyway I think I'll keep it for a rainy day. Cheers again for the input. ciao,

Re: [Full-disclosure] xp sp3 remote bof [from FD digest 76:33]

2011-06-17 Thread SMiller
elfius elf...@gmail.com wrote: Thanks for the advice guys. I've received quite a few interesting offers from some rather shady sounding people (as well as public messages here), and I've begun to realise how much this is worth. So for the time being anyway I think I'll keep it for a rainy day.

[Full-disclosure] [ MDVSA-2011:110 ] gimp

2011-06-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:110 http://www.mandriva.com/security/

[Full-disclosure] DoS, CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-06-17 Thread MustLive
Hello list! I want to warn you about new security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). These are Denial of Service, Cross-Site Request Forgery and Cross-Site Scripting vulnerabilities. In April I've already drew attention of Ukrtelecom's representative (and

Re: [Full-disclosure] DoS, CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-06-17 Thread Valdis . Kletnieks
On Fri, 17 Jun 2011 19:06:52 +0300, MustLive said: Hello list! I want to warn you about new security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). Dear MustLive: Please check the configuration of your MUA - your copy of Outlook Express appears to have posted this

Re: [Full-disclosure] DoS, CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-06-17 Thread p8x
On 18/06/2011 12:17 AM, valdis.kletni...@vt.edu wrote: On Fri, 17 Jun 2011 19:06:52 +0300, MustLive said: Hello list! I want to warn you about new security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). Dear MustLive: Please check the configuration of your MUA -

[Full-disclosure] Computer Security For Noobs

2011-06-17 Thread Damian Johnstone
Hey List I started up a website a little while ago. Basically, it's supposed to be analysis of computer security news and vulnerabilities, for people who aren't completely familiar with computer security already. Its likely to be a bit beneath the people on this list but I'd like it if you could

[Full-disclosure] CFP: IEEE GLOBECOM 2011 - Smart Communication Protocols Algorithms (SCPA 2011)

2011-06-17 Thread Sandra Sendra
Apologies for crossposting CALL FOR PAPERS - Smart Communication Protocols and Algorithms (SCPA 2011) December 5-9, 2011, Huston, Texas (USA) In conjunction with Globecom 2011 http://scpa.it.ubi.pt/ Selected papers will be invited to the Special Issue on

Re: [Full-disclosure] xp sp3 remote bof [from FD digest 76:33]

2011-06-17 Thread Ray Jertop
Hi, I would think that the behaviour is slightly odd. His first communication started out giving the impression that his intention was to responsibly disclose the issue to the affected vendor but that he was simply unaware as to how to do so and would simply like instruction on the best

[Full-disclosure] Lutz

2011-06-17 Thread RandallM
I think they are putz. -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] lutz

2011-06-17 Thread RandallM
is it the face of anonymous -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] lutz

2011-06-17 Thread RandallM
are they not owning? the bully in school? causing fear? no one able to stand? is this not interesting what the internet is coming to.. -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Lutz and Laws

2011-06-17 Thread RandallM
Only God has created the perfect laws that none have not broken. Man has created in his finite way shadows of these. But not perfect. But they are laws to regulate the good of all. Lutz, you have screwed these in you perhaps well meaning beginning way. Not for the good of others but have harmed

Re: [Full-disclosure] Lutz and Laws

2011-06-17 Thread Zach C.
Can I have some of what you're having? On Jun 17, 2011 8:37 PM, RandallM randa...@fidmail.com wrote: Only God has created the perfect laws that none have not broken. Man has created in his finite way shadows of these. But not perfect. But they are laws to regulate the good of all. Lutz, you

Re: [Full-disclosure] xp sp3 remote bof

2011-06-17 Thread coderman
On Thu, Jun 16, 2011 at 11:49 AM, elfius elf...@gmail.com wrote: Hi guys, ... I have a somewhat stable remote bof poc for xp sp3 (which I'm not going to go into detail about), and I've signed up to this list to ask the security community what I should do. 100 bitcoins to drop it on this list.