[Full-disclosure] [SECURITY] [DSA 2827-1] libcommons-fileupload-java security update

2013-12-23 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2827-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso December 24, 2013

[Full-disclosure] [SECURITY] [DSA 2826-1] denyhosts security update

2013-12-23 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2826-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez December 22, 2013

[Full-disclosure] CVSphoto.com Stores Passwords Unhashed

2013-12-23 Thread Alex Buie
I don't have the human bandwidth to deal with yelling at CVS for this right now, but figured I'd make a ML post about it if someone wants to do so. The email I got is here: http://i.imgur.com/bII9iGw.png Please feel free to try creating an account yourself and "forgetting" your password. -a

Re: [Full-disclosure] Fwd: NS1 ssh bad attempts

2013-12-23 Thread silence_is_best
Looks like someone hosed the input field in a scanning/brute-force app and it passed the error as an input valuewonder if the second 003 was cut off as 0034 is ASCII ". On 12/21/2013 at 4:01 AM, "Gary Baribault" wrote:Drunk typing or an attempt using a vuln? Anyone seen this? It's an attempt

[Full-disclosure] Merry Christmas and all the best in the new year

2013-12-23 Thread Georgi Guninski
Merry Christmas and all the best in the new year Cheers, ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Vulnerabilities in Dewplayer

2013-12-23 Thread MustLive
Hello list! I want to inform you about vulnerabilities in Dewplayer. These are Content Spoofing and Cross-Site Scripting vulnerabilities. There are near 422 000 web sites with dewplayer.swf in Google's index. And it's just one file name and there are other file names of this player (such as d

[Full-disclosure] Security by destruction

2013-12-23 Thread Jerome Athias
Hi I would like to know if you guys have links/background about a "security by destruction principle"? This question follows the behavior observed recently by a bank (I won't reveal tHiS Big bank name), multiple times (including but not limited to my case) where they simply block, retain and destr

[Full-disclosure] [ MDVSA-2013:301 ] nss

2013-12-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:301 http://www.mandriva.com/en/support/security/ __

[Full-disclosure] [ MDVSA-2013:300 ] asterisk

2013-12-23 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:300 http://www.mandriva.com/en/support/security/ __