[Full-disclosure] Seeker Advisory Sep11: Insecure Redirect in Microsoft SharePoint Portal

2011-09-13 Thread Irene Abezgauz
Seeker Research Center Security Advisory This vulnerability was discovered by Seeker(r) Automatic Run-Time Application Security Testing Solution bDisclosed By Irene Abezgauz, September 13th, 2011 = I. Overview = An Insecure Redirect vulnerability has been identified in

Re: [Full-disclosure] Apache Killer

2011-09-13 Thread GloW - XD
Aha this is exactly what me and kcope were discussing, and he pointed out that size exactly (however he did not know how to replicate to get to it i think),he mentioned the bucket size being able to be pushed to the exact amount you just said then, wich is alone enough to really reak some havoc on

Re: [Full-disclosure] Apache Killer

2011-09-13 Thread Javier Bassi
On Mon, Sep 12, 2011 at 11:26 PM, xD 0x41 wrote: > I know this topic is OLD but, i just wonder and, also having spoken to kcope > re this myself, discussed the size of each bucket wich can be made to > stupendous amounts and using a different vector, ok, instead of Range:bytes= > , picture a GET re

[Full-disclosure] Update: Vulnerability in plugins for Typepad, RapidWeaver, Habari, DasBlo, eZ Publish, EE, Serendipity, Social Web CMS, PHP-Fusion, Magento and Sweetcron

2011-09-13 Thread MustLive
Hello list! One update concerning Cross-Site Scripting vulnerability in multiple plugins for different engines (in plugins for Typepad, RapidWeaver, Habari, DasBlo, eZ Publish, EE, Serendipity, Social Web CMS, PHP-Fusion, Magento and Sweetcron, which all are ports of WP-Cumulus). Which I wrote

Re: [Full-disclosure] Apache Killer

2011-09-13 Thread xD 0x41
I know this topic is OLD but, i just wonder and, also having spoken to kcope re this myself, discussed the size of each bucket wich can be made to stupendous amounts and using a different vector, ok, instead of Range:bytes= , picture a GET request with as was shown in the code is there, you "Reques

[Full-disclosure] Seeker Advisory Sep11: Reflected Cross Site Scripting in Microsoft SharePoint Portal

2011-09-13 Thread Irene Abezgauz
Seeker Research Center Security Advisory This vulnerability was discovered by SeekerĀ® Automatic Run-Time Application Security Testing Solution Disclosed By Irene Abezgauz, September 13th, 2011 = I. Overview = A Cross Site Scripting vulnerability has been identified in Microsoft