[Full-disclosure] [SECURITY] [DSA 2553-1] iceweasel security update

2012-09-24 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2553-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff September 24, 2012

[Full-disclosure] giochionline.ilgiornale.it is vulnerable to base64 xss

2012-09-24 Thread tig3rhack
giochionline.ilgiornale.it is vulnerable to attack base64 xss below the POC: http://giochionline.ilgiornale.it/wp-content/plugins/special-recent-posts/lib/phpimage.php?file=dW5kZWZpbmVkMTxTY1JpUHQgPnByb21wdCg5MjExMTUpPC9TY1JpUHQ%2b&height=100&rotation=no&width=100 info: http://tig3rblog.wordpress

[Full-disclosure] "Dell Data Protection | Access" for Windows contains and installs outdated, superfluous and vulnerable system components and 3rd party components/drivers

2012-09-24 Thread Stefan Kanthak
Hi @ll the current version of Dell's Data Protection | Access (DDPA) software for Windows (Build 2.2.3.008 from 2012-06-14, released August 2012) contains and installs several outdated, superfluous and vulnerable Windows system components as well as outdated and vulnerable 3rd party components

Re: [Full-disclosure] samba exploit - remote root colonel 0day

2012-09-24 Thread paul . szabo
Dear KD, > Massive 0day hide all your printers. > http://pastebin.com/AwpsBWVQ That webpage says: ... targets = ... "samba_3.6.3-debian6" ... (and older), and CVE-2012-1182 was fixed in 3.6.4 in April. Does this issue affect current Samba 3.6.8? Thanks, Paul Paul Szabo p...@maths.usyd.edu.a

[Full-disclosure] [SECURITY] [DSA 2551-1] isc-dhcp security update

2012-09-24 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2551-1 secur...@debian.org http://www.debian.org/security/Nico Golde September 23, 2012

[Full-disclosure] samba exploit - remote root colonel 0day

2012-09-24 Thread kd
Massive 0day hide all your printers. http://pastebin.com/AwpsBWVQ *# finding targets 4 31337z:*# gdb /usr/sbin/smbd `ps auwx | grep smbd | grep -v grep | head -n1 | awk '{ print $2 }'` ___ Full-Disclosure - We believe in it. Charter: http