[Full-disclosure] TinyBrowser Upload Shell Vulnerability

2012-12-14 Thread MustLive
Hello guys! I'll draw your attention to one exploit at 1337day.com (and other their domains): http://1337day.com/exploit/19732. I've wrote to 1337day.com about it already at 19.11.2012. So it should concern every list, which posted that exploit from 1337day.com. This is AFU vulnerability in TinyB

Re: [Full-disclosure] [btrfs] is vulnerable to a hash-DoS attack

2012-12-14 Thread Jeffrey Walton
On Thu, Dec 13, 2012 at 8:20 AM, Pascal Junod (Mailing Lists) wrote: > Hello folk, > > The btrfs file system, part of the linux kernel, is vulnerable to a > trivial hash-DoS attack. More details can be found here: > > http://crypto.junod.info/2012/12/13/hash-dos-and-btrfs/ Kosta's comment was funn

[Full-disclosure] Security Alert CVE-2012-6329: TWiki MAKETEXT Variable Allows Arbitrary Shell Command Execution

2012-12-14 Thread Peter Thoeny
This security advisory alerts you of a potential security issue with TWiki installations: The %MAKETEXT{}% TWiki variable allows arbitrary shell command execution. The problem is caused by an underlying security issue in the Locale::Maketext CPAN module. * Vulnerable Software Version * A

[Full-disclosure] Paypal Core Bug Bounty #3 - Persistent Web Vulnerability

2012-12-14 Thread Vulnerability Lab
Title: == Paypal Core Bug Bounty #3 - Persistent Web Vulnerability Date: = 2012-12-12 References: === http://www.vulnerability-lab.com/get_content.php?id=635 VL-ID: = 635 Common Vulnerability Scoring System: 4 Introduction:

[Full-disclosure] Paypal Bug Bounty #34 - Redirect Web Vulnerability

2012-12-14 Thread Vulnerability Lab
Title: == Paypal Bug Bounty #34 - Redirect Web Vulnerability Date: = 2012-12-12 References: === http://www.vulnerability-lab.com/get_content.php?id=718 VL-ID: = 718 Common Vulnerability Scoring System: 2.2 Introduction:

Re: [Full-disclosure] Google's robots.txt handling

2012-12-14 Thread Julius Kivimäki
United States law is opt-in for Fortune 500 companies. 2012/12/14 Jeffrey Walton > On Thu, Dec 13, 2012 at 7:52 AM, Philip Whitehouse > wrote: > > I restate my email's second point. > > > > Google is indexing robots.txt because (from all the examples I can see) > > robots.txt doesn't contain a