Re: [Full-disclosure] Orkut exploit

2006-06-28 Thread Ademar Gonzalez
On 6/28/06, nocfed <[EMAIL PROTECTED]> wrote: In what way is this an "Orkut exploit" as the subject of the mail describes? This is more of an "Idiot exploit"... yeah, i agree is an idiot exploit, English is not my first language and that was the best subject i could come up with. but don'

[Full-disclosure] Orkut exploit

2006-06-28 Thread Ademar Gonzalez
Don't know if you guys have seen this. Just got it in my gmail account, it tries to execute the file scrapbook.exe from : http://www.yourfreespace.net/users/orkut2/scrapbook/scrapbook.exe Karpesky says is Trojan-Spy.Win32.Banker.anv attached is the original emai. ciao ciao ademar

Re: [Full-disclosure] Strange Emails -- What are they?

2006-06-07 Thread Ademar Gonzalez
On 6/7/06, Pam Patterson <[EMAIL PROTECTED]> wrote: Ademar Gonzalez wrote: > On 6/7/06, Simon Smith <[EMAIL PROTECTED]> wrote: >> ok, that makes sense... will greylisting counter this? > > don't think graylisting will have much effect, each bot sending a fe

Re: [Full-disclosure] Strange Emails -- What are they?

2006-06-07 Thread Ademar Gonzalez
On 6/7/06, Simon Smith <[EMAIL PROTECTED]> wrote: ok, that makes sense... will greylisting counter this? don't think graylisting will have much effect, each bot sending a few mails. ademar ___ Full-Disclosure - We believe in it. Charter: http://lis

Re: [Full-disclosure] Files keep appearing

2006-06-02 Thread Ademar Gonzalez
Hi Stephen . On 6/2/06, Stephen Johnson <[EMAIL PROTECTED]> wrote: I keep having a phishing website appear on my web server. They keep showing up in a Resources folder of one of the sites that I host. I have gone through the logs and I am not seeing any connections. I deleted the files thi

[Full-disclosure] [Advisory] ~ x Thu Mar 16 02:49:04 EST 2006 x ~ Heap Overflow in Dantz Retrospect

2006-03-16 Thread ademar . gonzalez
[Advisory] ~ x Thu Mar 16 02:49:04 EST 2006 x ~ Heap Overflow in Dantz Retrospect + 8===D DESCRIPTION + It is possible to make Dantz Retrospect crash or run arbitrary code by the use of malformed input. + 8===D WORKAROUND + This advisory had no workarounds. + CONTACT + Ademar Gonzalez

Re: [Full-disclosure] (no subject)

2005-09-28 Thread Ademar Gonzalez
Hi Aditya On 9/28/05, Aditya Deshmukh <[EMAIL PROTECTED]> wrote: > Recently 2 days ago I saw this in a compromised system. > > > Both this file and cpshost.dll were deleted from C:\InetPub\scripts > This file was recovered but I was unable to recover cpshost.dll > > > Anyone know what is this