Re: [Full-disclosure] Linux - Indicators of compromise

2012-07-25 Thread Giles Coochey
On 18/07/2012 13:10, Григорий Братислава wrote: On Wed, Jul 18, 2012 at 3:18 AM, Giles Coochey gi...@coochey.net wrote: Is you have much more to worry than is ICMP/GRE tunnels. Is I send to Broadcast and I am is on your network, how do you is plan to pinpoint who I am when is everyone see

[Full-disclosure] [ MDVSA-2012:111 ] libgdata

2012-07-25 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:111 http://www.mandriva.com/security/

Re: [Full-disclosure] Linux - Indicators of compromise

2012-07-25 Thread Григорий Братислава
On Wed, Jul 25, 2012 at 7:04 AM, Giles Coochey gi...@coochey.net wrote: On 18/07/2012 13:10, Григорий Братислава wrote: If you broadcast using a MAC address you are on the same subnet, layer 2. On a wired network I don't really care whether you spoofed your mac address or not, you still

[Full-disclosure] [Security-news] SA-CONTRIB-2012-115 - Gallery formatter - Cross Site Scripting (XSS)

2012-07-25 Thread security-news
View online: http://drupal.org/node/1700578 * Advisory ID: DRUPAL-SA-CONTRIB-2012-115 * Project: Gallery formatter [1] (third-party module) * Version: 7.x * Date: 2012-July-25 * Security risk: Moderately critical [2] * Exploitable from: Remote * Vulnerability: Cross Site Scripting

[Full-disclosure] [Security-news] SA-CONTRIB-2012-116 - Subuser Cross Site Request Forgery (CSRF) and Access Bypass

2012-07-25 Thread security-news
View online: http://drupal.org/node/1700584 * Advisory ID: DRUPAL-SA-CONTRIB-2012-116 * Project: Subuser [1] (third-party module) * Version: 6.x * Date: 2012-July-25 * Security risk: Less critical [2] * Exploitable from: Remote * Vulnerability: Access bypass, Cross Site Request

[Full-disclosure] [Security-news] SA-CONTRIB-2012-117 - Location - Access Bypass

2012-07-25 Thread security-news
View online: http://drupal.org/node/1700588 * Advisory ID: DRUPAL-SA-CONTRIB-2012-117 * Project: Location [1] (third-party module) * Version: 6.x, 7.x * Date: 2012-July-25 * Security risk: Moderately critical [2] * Exploitable from: Remote * Vulnerability: Access bypass

[Full-disclosure] [Security-news] SA-CONTRIB-2012-118 - Secure Login - Open Redirect

2012-07-25 Thread security-news
View online: http://drupal.org/node/1700594 * Advisory ID: DRUPAL-SA-CONTRIB-2012-118 * Project: Secure Login [1] (third-party module) * Version: 7.x * Date: 2012-July-25 * Security risk: Less critical [2] * Exploitable from: Remote * Vulnerability: Open Redirect