[Full-disclosure] Php gif upload thumbnail creation remote exploit

2011-06-18 Thread HI-TECH .
This technique describes how to exploit apps which encode pictures during a Php upload. Embedding Php code inside gif files which are uploaded is a known technique to execute arbitrary code on a Apache Php installation. Now what can one do when the code which uploads the file processes and encodes

[Full-disclosure] Typo3 extensions Remote exploit to be released soon

2011-06-18 Thread HI-TECH .
I said be careful what you wish for cause you just might get it, and if you get it then you just might not know what to do with it cause it might just come back on you tenfold. -kc ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/

Re: [Full-disclosure] xp sp3 remote bof

2011-06-18 Thread Thor (Hammer of God)
Meh. It's not worth hen shit on a pump handle without some details. Your claim of "quite a few offers" doesn't really make much sense either. You initially claim that you're new here, and to the scene in general, and that you need MSFT's security alias. But even as a noob, you claim to have

[Full-disclosure] The SIV mode of operation result in data leakage with small messages (<= blocksize) when the authentication part of the key is discovered and how to get data from CMAC

2011-06-18 Thread klondike
Hi guys, After some small research I found that at times (when the authentication key is known and the amount of authenticated data is smaller or equal to the block size) it can be possible to recover data from CMAC, this vulnerability can affect in a similar way to the AES SIV mode of operation.

Re: [Full-disclosure] xp sp3 remote bof [from FD digest 76:33]

2011-06-18 Thread -= Glowing Sex =-
all i can say to this is hahahahahaha , this is what FD has become, why are you all so surpirsed?? lol... elfius, good stuff :) On 18 June 2011 00:45, Ray Jertop wrote: > Hi, > > I would think that the behaviour is slightly odd. > > His first communication started out giving the impression tha

[Full-disclosure] Blackhat sponsoring the Hack Cup 2011: New winner prizes!

2011-06-18 Thread Nicolas Waisman
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Now that we have all the groups set (http://www.hack-cup.com/fixture-2011), we are happy to announce the sponsorship of BlackHat for this year's Hack Cup. Immunity and BlackHat are throwing in a some cool prizes for the winner: 5 tickets for BlackHat a