[Full-disclosure] Drive-by Pharming

2007-02-15 Thread Oliver Friedrichs
Everyone, I'm posting this on behalf of Zulfikar Ramzan who isn't subscribed to this list. We discovered a new potential threat that we term "Drive-by Pharming". An attacker can create a web page containing a simple piece of malicious JavaScript code. When the page is viewed, the code makes a lo

Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?

2007-02-13 Thread Oliver Friedrichs
: Oliver Friedrichs Cc: bugtraq@securityfocus.com; full-disclosure@lists.grok.org.uk Subject: RE: Solaris telnet vulnberability - how many on your network? On Mon, 12 Feb 2007, Oliver Friedrichs wrote: > > Am I missing something? This vulnerability is close to 10 years old. > It was in o

Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?

2007-02-13 Thread Oliver Friedrichs
Am I missing something? This vulnerability is close to 10 years old. It was in one of the first versions of Solaris after Sun moved off of the SunOS BSD platform and over to SysV. It has specifically to do with how arguments are processed via getopt() if I recall correctly. Oliver -Origin