[Full-disclosure] [ MDVSA-2012:109 ] libxslt

2012-07-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:109 http://www.mandriva.com/security/ _

[Full-disclosure] [ MDVSA-2012:108 ] php

2012-07-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:108 http://www.mandriva.com/security/ _

[Full-disclosure] [SECURITY] [DSA 2508-1] kfreebsd-8 security update

2012-07-23 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2508-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez July 22, 2012

[Full-disclosure] NESSUS ANDROID APP - stores login info in plain text

2012-07-23 Thread seclists
Nessus app for android version 1.0.1 app allows user to save nessus server info IP/username/password. app saves this info to /sdcard/servers.id this file can be viewed with notepad and password is right there in plain text. this means any app on the system can see that info and possibly trans

Re: [Full-disclosure] Linux - Indicators of compromise

2012-07-23 Thread Scott Solmonson
It seems that English isn't your first language, so no problem with the confusion- "don't isolate, monitor spread tactics, perceptually contain and then analyse." Isolation in an INFOSEC sense means actual measures to stop actual actions. The short version looks like "we've got all the informatio