[Full-disclosure] mazur.harvard.edu database leak

2011-11-30 Thread sinep
Noticed this getting passed around twitter and decided to share in case you guys haven't seen it. http://blog.hacktalk.net/mazur-harvard-edu-database-leak/ ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] New FREE security tool!

2011-11-30 Thread Mario Vilas
Hi, I'm afraid all the download links in that webpage seem to be broken, except for the Windows installer (which has a different version number than the rest of the downloads). Also, the github repository where you're hosting the source code appears to be empty. Cheers, -Mario On Wed, Nov 30,

[Full-disclosure] Voxsmart VoxRecord Control Centre - Blind SQLi and auth. bypass

2011-11-30 Thread Piotr Duszynski
=== VoxRecord Control Centre - version 2.7 Blind SQLi and auth. bypass === Affected Software : Voxsmart - VoxRecord Control Centre v. 2.7 Severity :

[Full-disclosure] Serv-U Remote

2011-11-30 Thread HI-TECH .
I m better than TESO! CONFIDENTIAL SOURCE MATERIALS! [*][*] Serv-U FTP Server Jail Break 0day Discovered By Kingcope Year 2011 [*][*] Affected: 220 Serv-U FTP Server

[Full-disclosure] Writing Self Modifying Code

2011-11-30 Thread Adam Behnke
Hello full disclosureites, a new tutorial is available at InfoSec Institute review from Andrew King on writing self modifying code. This is part one of a three part series: http://resources.infosecinstitute.com/writing-self-modifying-code-part-1/ In subsequent parts, Andrew will demonstrate how

Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread noreply
Hello there! The exploit roaringbeast will be added to Exploit pack Authors name and code/license will be respected and it will be ported to Python with minimal modifications The code will be uploaded to Exploit Pack Git Repo and will be available to all our users Thank you and

[Full-disclosure] [SECURITY] [DSA 2355-1] clearsilver security update

2011-11-30 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2355-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff November 30, 2011

Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread HI-TECH .
Hi lists, sorry if I offended anyone with by referring to teso, I really like teso as you might also. all this happend because I was drunk hehe : I hope you enjoy this release! Am 30. November 2011 20:32 schrieb HI-TECH . isowarez.isowarez.isowa...@googlemail.com: /* KCOPE2011 - x86/amd64 bsd

Re: [Full-disclosure] Writing Self Modifying Code

2011-11-30 Thread upb
groundbreaking! On Wed, Nov 30, 2011 at 11:30 PM, Adam Behnke a...@infosecinstitute.com wrote: Hello full disclosureites, a new tutorial is available at InfoSec Institute review from Andrew King on writing self modifying code. This is part one of a three part series:

Re: [Full-disclosure] FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit

2011-11-30 Thread root
If you want to respect the license of this code you cannot include the exploit in your software. All rights reserved means you cannot include it in other products, actually nobody can except the author. You should ask the author for permission to redistribute the exploit or re-implement it.

[Full-disclosure] XSSer v1.6 -beta- aka Grey Swarm! released.

2011-11-30 Thread psy
Hi list, There is released a new version of *XSSer* (v1.6-beta-) - the cross site scripter framework. Take a look to the XSSer website to see new features implemented, screenshots, documentation, etc... http://xsser.sf.net You can download original code directly from here:

Re: [Full-disclosure] Wordpress plugin BackWPup Remote and Local Code Execution Vulnerability - SOS-11-003

2011-11-30 Thread Henri Salo
On Mon, Mar 28, 2011 at 03:10:39PM +1100, Lists wrote: Sense of Security - Security Advisory - SOS-11-003 Release Date. 28-Mar-2011 Last Update. - Vendor Notification Date. 25-Mar-2010 Product. Wordpress Plugin BackWPup

[Full-disclosure] Is FD no longer unmoderated?

2011-11-30 Thread David Blanc
A colleague of mine subscribed to FD recently and tried posting to it but every time he gets this message: Is being held until the list moderator can review it for approval. The reason it is being held: Post to moderated list Either the message will get posted to the list, or you will

Re: [Full-disclosure] Is FD no longer unmoderated?

2011-11-30 Thread Valdis . Kletnieks
On Thu, 01 Dec 2011 07:49:28 +0530, David Blanc said: A colleague of mine subscribed to FD recently and tried posting to it but every time he gets this message: n3td3v, is that your sock puppet? :) The *list* isn't moderated. However, several *people* are, and they for the most part know who

Re: [Full-disclosure] New FREE security tool!

2011-11-30 Thread Gino
Seems to have Juan Succo written all over it On 11/30/11 1:49 AM, Mario Vilas wrote: Hi, I'm afraid all the download links in that webpage seem to be broken, except for the Windows installer (which has a different version number than the rest of the downloads). Also, the github

Re: [Full-disclosure] Is FD no longer unmoderated?

2011-11-30 Thread Stefan Weimar
Hi, Am 01. Dezember schrieb David Blanc: A colleague of mine subscribed to FD recently and tried posting to it but every time he gets this message: Is he using a different mail adress than that one he used to subscribe to FD? Cheers, Stefan -- make -it ./work GnuPG-Key: B96CF8D2