Re: [Full-disclosure] Apple IOS security issue pre-advisory record

2012-03-24 Thread Dave
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 24/03/2012 05:44, valdis.kletni...@vt.edu wrote: > On Sat, 24 Mar 2012 00:52:45 -, Dave said: >> I am not an expert so please, for my education, correct me if I am wrong. >> Is it not so much the request, but what the request is made with? > >

Re: [Full-disclosure] Apple IOS security issue pre-advisory record

2012-03-24 Thread john doe
Gentlemen, I must say that beyond the raw results the reactions are also very interesting because I think this actually IS what I called "community behavior". Clics and votes are just one "reaction" type, and those clever and smart comments are another one. Maybe much more important to understand

Re: [Full-disclosure] Apple IOS security issue pre-advisory record

2012-03-24 Thread Valdis . Kletnieks
On Sat, 24 Mar 2012 10:26:48 -, Dave said: > Doesn't the the -e, robots=off, --page-requisites and -H wget directives > enable > one to collect all the necessary files that are called from a page? No, not *all* the files, for the same reason that if you visit a page with NoScript enabled, yo

[Full-disclosure] CVE-2012-0037: libraptor - XXE in RDF/XML File Interpretation (Multiple office products affected)

2012-03-24 Thread VSR Advisories
CVE Candidate: CVE-2012-0037 Reference: http://www.vsecurity.com/resources/advisory/20120324-1/ =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= Product Description ~-~ "Raptor is a free software / Open Source C library that provides a s

Re: [Full-disclosure] Apple IOS security issue pre-advisory record

2012-03-24 Thread Dave
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 24/03/2012 15:53, valdis.kletni...@vt.edu wrote: > On Sat, 24 Mar 2012 10:26:48 -, Dave said: > >> Doesn't the the -e, robots=off, --page-requisites and -H wget directives >> enable >> one to collect all the necessary files that are called fro

[Full-disclosure] [SECURITY] [DSA 2440-1] libtasn1-3 security update

2012-03-24 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2440-1 secur...@debian.org http://www.debian.org/security/Florian Weimer March 24, 2012