Re: [Full-disclosure] Gauss is out !

2012-08-09 Thread J. Oquendo
On 8/9/2012 9:43 AM, Peter Dawson wrote: > > Dubbed Gauss, the virus may also be capable of attacking critical > infrastructure and was built in the same laboratories as Stuxnet, the > computer worm widely believed to have been used by the United States > and Israel to attack Iran's nuclear prog

Re: [Full-disclosure] Hacker Highschool v2

2012-08-09 Thread Peter Dawson
not sure. I think its lesson on how2 pwn the troll n bully l! On Thu, Aug 9, 2012 at 4:16 PM, Benji wrote: > ah fantastic, a lesson on trolling and bullying. what a valuable > service you are providing. > > On Thu, Aug 9, 2012 at 8:19 PM, Pete Herzog wrote: > > Hi, > > > > Version 2 of Hacker H

Re: [Full-disclosure] Hacker Highschool v2

2012-08-09 Thread Benji
ah fantastic, a lesson on trolling and bullying. what a valuable service you are providing. On Thu, Aug 9, 2012 at 8:19 PM, Pete Herzog wrote: > Hi, > > Version 2 of Hacker Highschool (www.hackerhighschool.org) is wrapping > up. We will begin publishing/replacing each lesson as we finish it. Of >

[Full-disclosure] List Charter

2012-08-09 Thread John Cartwright
[Full-Disclosure] Mailing List Charter John Cartwright - Introduction & Purpose - This document serves as a charter for the [Full-Disclosure] mailing list hosted at lists.grok.org.uk. The list was created on 9th July 2002 by Len Rose, and is primarily concerned with security issues and the

[Full-disclosure] Hacker Highschool v2

2012-08-09 Thread Pete Herzog
Hi, Version 2 of Hacker Highschool (www.hackerhighschool.org) is wrapping up. We will begin publishing/replacing each lesson as we finish it. Of course we can always use more dedicated experts to contribute which would speed the whole process up. More details on the project are available in a

[Full-disclosure] How well does Microsoft support (and follow) their mantra "keep your PC updated"?

2012-08-09 Thread Stefan Kanthak
Hi @ll, for years not only Microsoft tells computer users throughout the world "keep your PC updated" again and again. How well does Microsoft support this mantra with their very own products? How well does Microsoft follow this mantra in their own premises? Short answer: rather poor! Longe

[Full-disclosure] Fwd: [TSCM-L] {6221} Domain Awareness System

2012-08-09 Thread j f
While this is slightly OT, I'm sure many readers would find it interesting. Two emails; overview in the first, a bunch of copy/pastes of stratfor emails in the second. Cheers. -- Forwarded message -- From: Justin Ferguson Date: Thu, Aug 9, 2012 at 7:29 AM Subject: Re: [TSCM-L] {6

[Full-disclosure] [ MDVSA-2012:128 ] bash

2012-08-09 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:128 http://www.mandriva.com/security/ _

[Full-disclosure] Gauss is out !

2012-08-09 Thread Peter Dawson
Dubbed Gauss, the virus may also be capable of attacking critical infrastructure and was built in the same laboratories as Stuxnet, the computer worm widely believed to have been used by the United States and Israel to attack Iran's nuclear program, Kaspersky Lab said on Thursday. http://www.reuter

[Full-disclosure] Arasism (IR) CMS - File Upload Vulnerability

2012-08-09 Thread Vulnerability Lab
Title: == Arasism (IR) CMS - File Upload Vulnerability Date: = 2012-07-12 References: === http://www.vulnerability-lab.com/get_content.php?id=657 VL-ID: = 657 Common Vulnerability Scoring System: 6.5 Abstract: = The Laborato

[Full-disclosure] Flogr v2.5.6 & v2.3 - Cross Site Script Vulnerabilities

2012-08-09 Thread Vulnerability Lab
Title: == Flogr v2.5.6 & v2.3 - Cross Site Script Vulnerabilities Date: = 2012-07-11 References: === http://www.vulnerability-lab.com/get_content.php?id=656 VL-ID: = 656 Common Vulnerability Scoring System: 2 Introduction: =

Re: [Full-disclosure] htaccess files should not be used for security restrictions

2012-08-09 Thread Jason Hellenthal
Thank you for the article. All-in-all I find it to be more centric to the design of the software or beit in this case PHP apps and not as the subject suggests ".htaccess" files. There are way too many "get-ritch-quick" upcoming PHP scripters out there that are not aware or even nearly knowledgea