Re: [Full-disclosure] Facebook Attach EXE Vulnerability

2011-10-29 Thread Nathan Power
That was the original program I was participating in. Facebook has agreed to pay me a bounty for this bug. Nathan Power www.securitypentest.com On Fri, Oct 28, 2011 at 7:17 PM, Ulises2k wrote: > You know this? ;) > https://www.facebook.com/whitehat/bounty/ > > > > On Fr

Re: [Full-disclosure] Facebook Attach EXE Vulnerability

2011-10-28 Thread Nathan Power
I would also like to note this vulnerability was reported responsibly in regards to full disclosure. http://en.wikipedia.org/wiki/Full_disclosure Nathan Power www.securitypentest.com On Fri, Oct 28, 2011 at 1:38 PM, Nathan Power wrote: > I was basically told that Facebook didn't see

Re: [Full-disclosure] Facebook Attach EXE Vulnerability

2011-10-28 Thread Nathan Power
they seem to have been able to reproduce the bug. Nathan Power www.securitypentest.com On Fri, Oct 28, 2011 at 11:18 AM, Pablo Ximenes wrote: > Not fixed yet. At least not yesterday when I checked. > > Nathan, didn't Facebook ask for some time to fix this bug after the

[Full-disclosure] Facebook Attach EXE Vulnerability

2011-10-27 Thread Nathan Power
book-attach-exe-vulnerability.html Enjoy :) Nathan Power www.securitypentest.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] DEFCON Travelers.. Don't just go

2011-07-27 Thread Nathan Power
I discovered a way to get free internets at airports. Below is the article and a video. Enjoy :) Article: http://www.securitypentest.com/2011/07/defcon-travelers-dont-just-go-boingo.html Video: http://www.securitypentest.com/2011/07/boingo-pwnage.html Nathan Power www.securitypentest.com

[Full-disclosure] Multi-Tech Systems MultiModem iSMS Multiple XSS Vulnerabilities

2011-06-02 Thread Nathan Power
Check out the latest security advisory: http://www.foofus.net/?p=319 Nathan Power www.securitypentest.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

[Full-disclosure] Trustwave – Security begins with Trust, then you get 0wned!

2011-05-26 Thread Nathan Power
An updated Trustwave WebDefend advisory has been posted http://www.foofus.net/?p=290 Nathan Power www.securitypentest.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by

[Full-disclosure] Trustwave WebDefend Privilege Escalation Vulnerability

2011-04-26 Thread Nathan Power
ability to the Vendor -- 7. Credits: Discovered by Nathan Power www.securitypentest.com -- ___ Full-Disclosure - We believe in it. C

[Full-disclosure] Unidesk ReportingService Forceful Browsing Vulnerability

2011-03-25 Thread Nathan Power
covered by Nathan Power www.securitypentest.com -- ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secu

Re: [Full-disclosure] Facebook URL Redirect Vulnerability

2011-03-03 Thread Nathan Power
rmat. http://apps.facebook.com/truthsaboutu/track.php?r=http%3A%2F%2F1208929384 Also when you post a link on Facebook, 'apps.facebook.com' is the only text displayed to the user. Nathan Power www.securitypentest.com On Wed, Mar 2, 2011 at 2:38 PM, Andrew Farmer wrote: > On 2011-03-02, at 06

Re: [Full-disclosure] Facebook URL Redirect Vulnerability

2011-03-03 Thread Nathan Power
This rule can be subverted because of the content keyword. Below is an example: http://apps.facebook.com/truthsaboutu/track.php?a=a&r=http://www.securitypentest.com Add two content keywords 'track.php?' and 'r=' Nathan Power www.securitypentest.com On Mon, Feb 2

Re: [Full-disclosure] Facebook URL Redirect Vulnerability

2011-03-03 Thread Nathan Power
with a URL redirect, CSRF, phishing (fake fb login), and browser exploits (javascript zombie,0days,etc). How would you have written the impact section? To be clear - I was trying to make a point when determining the impact, once you click on a bad link, bad things will happen. Nathan Power

[Full-disclosure] Facebook URL Redirect Vulnerability

2011-02-28 Thread Nathan Power
5. Solution: None -- 6. Time Table: 2/27/2011 Reported Vulnerability to the Vendor ------ 7. Credits: Discovered by N

[Full-disclosure] PayPal Send Money Cross-Site Scripting Vulnerability

2011-01-03 Thread Nathan Power
ility 7. Credits: Discovered by Nathan Power www.securitypentest.com ___ Full-Disclosure - We believe in it. Charter: