Re: [Full-disclosure] New awstats.pl vulnerability?

2011-12-23 Thread xD 0x41
I am really curious as to the motivation of the parties deploying these types of scans. I understand that they would like to find vulnerable systems to compromise... but for what purpose? S dor what ? Mainly the smarter ones, are, not malign, non botters, and dont use these shit systems to make

Re: [Full-disclosure] CertificationMagazine - Blind SQL Injection Vulnerability

2011-12-23 Thread Tomy
http://www.vs-db.info/?p=593 MAY 2010 - Nice that you can find 1.5 YEARS old hole LOL! Tomy Wiadomość napisana przez resea...@vulnerability-lab.com w dniu 20 gru 2011, o godz. 17:08: > http://www.certmag.com/ Tomy supp...@vs-db.info ___ Full-Disc

Re: [Full-disclosure] Mobile Prank Hacktool

2011-12-23 Thread Larry W. Cashdollar
Looks like the link is unavailable.-- Larry C$On Dec 19, 2011, at 11:49 AM, Hacxx Under wrote:This is a tool that enable anyone to prank mobiles and land phones in portugal. You can choose calls or sms's. http://www.megaupload.com/?d=GKWWWMSY [Share the link, not the content] ___

Re: [Full-disclosure] OT: Firefox question / poll

2011-12-23 Thread metasansana
I would say usability, by the time it pops up the nasty is probably already done. --Original Message-- From: Charles Morris Sender: full-disclosure-boun...@lists.grok.org.uk To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] OT: Firefox question / poll Sent: Dec 20, 2011 13:4

[Full-disclosure] Facebook security bypassed with One single link

2011-12-23 Thread Anand Pandey
Affected Application: Facebook.com Exploit Platform: Remote Impact: Full Access to Facebook profile Severity: High Author: Anand Pandey Email: anandkpandey1 (at) gmail (dot) com Video: http://www.youtube.com/watch?v=9CtxQxyEf40 -

Re: [Full-disclosure] [SECURITY] [DSA 2368-1] lighttpd security update

2011-12-23 Thread MailPlus| David Hofstee
> For the testing distribution (squeeze), this problem will be fixed soon. isn't that wheezy? David -Oorspronkelijk bericht- Van: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] Namens Nico Golde Verzonden: woensdag 21 december 2011 1:25 Aan:

Re: [Full-disclosure] OT: Firefox question / poll

2011-12-23 Thread 夜神 岩男
On 12/21/2011 03:54 AM, metasans...@gmail.com wrote: > I would say usability, by the time it pops up the nasty is probably already > done. > --Original Message-- > From: Charles Morris > Sender: full-disclosure-boun...@lists.grok.org.uk > To: full-disclosure@lists.grok.org.uk > Subject: [F

Re: [Full-disclosure] Mobile Prank Hacktool

2011-12-23 Thread xD 0x41
hi Larry! Hope your doing well mate ;) , anyhow, here.. i did manage to get it via windows..maybe megaupload.com has blocks for lynx or other linux ? notsure and, not caring to test,..lol...anyhow, sanme file..enjoy, cheers. (Oh, id always run this with atleast a basic Sandbox, like sanboxie ,w

Re: [Full-disclosure] OT: Firefox question / poll

2011-12-23 Thread Valdis . Kletnieks
On Fri, 23 Dec 2011 21:32:38 +0900, =?UTF-8?B?5aSc56We44CA5bKp55S3?= said: > To begin with, most people click through the DANGER SCREEN warnings > about bad TLS certificates. With this in mind it is obvious that a > developer can't expect the average browser-using population to even know > what a

Re: [Full-disclosure] Mobile Prank Hacktool

2011-12-23 Thread Hacxx Under
New Link: http://www.filesonic.com/file/Ll1glMy Use it but do not abuse it... ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Sunny WebBox Default Password

2011-12-23 Thread Hacxx Under
Sunny Web Box is a device that has a web interface and it's used as a reader for solar energy microproducers. The default password is "SMA" The devices can be founfd using intitle: "Sunny WebBox" --- Hacked Boxes http://mariorodrigues.dynip.sapo.pt http://gisolar.cannondesign.com http://pvpi

[Full-disclosure] Automatic message post in PHP Classified

2011-12-23 Thread Hacxx Under
An inexisting captcha in the message form of PHP Classified allow the submition of messages automaticaly. It only require that the user register and validate an account and it can post ads automaticaly by using a script. Download: http://www.filesonic.com/file/zQJFzCv ___

Re: [Full-disclosure] CertificationMagazine - Blind SQL Injection Vulnerability Super vulnerability-lab hack

2011-12-23 Thread Tomy
vulnerability-lab.com ->>> Please STOP writing such a bullshits... "He also asked us multiple times for selling the dumps of hacked databases!? To answer that once more we are not interested in selling stolen information as said many times before. Why ?! Mainly due the fact that this is a cr

[Full-disclosure] Exploit Pack - Happy new year!

2011-12-23 Thread noreply
Exploit Pack Team is happy to announce that we reach a new frontier +20k active users and 15+ developers. We want to thank you all for this excelent years we hope to continue improving all our proyects. We have made a new roadmap for 2012 including a lot of bug fixing, new modules and features.

Re: [Full-disclosure] Sunny WebBox Default Password

2011-12-23 Thread Jeffrey Walton
On Fri, Dec 23, 2011 at 11:02 AM, Hacxx Under wrote: > Sunny Web Box is a device that has a web interface and it's used as a > reader for solar energy microproducers. > > The default password is "SMA" > > The devices can be founfd using intitle: "Sunny WebBox" > --- > Hacked Boxes > > http://m

[Full-disclosure] [ MDVSA-2011:192 ] mozilla

2011-12-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:192 http://www.mandriva.com/security/ _