[Full-disclosure] cpanel exploit

2006-09-29 Thread Todd Burroughs
Anyone have any info on this cpanel exploit. I have a friend who found it pretty open to full user level acess, but not root. I'm curious to know what the hole is/was. http://www.thewhir.com/marketwatch/092706_Web_Hosts_Hit_by_Hackers.cfm http://news.netcraft.com/archives/2006/09/23/hostgator_

[Full-disclosure] Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow)

2006-03-25 Thread Todd Burroughs
On Fri, 24 Mar 2006, Gadi Evron wrote: On Thu, 23 Mar 2006, Claus Assmann wrote: It took Sendmail a mounth to fix this. A mounth. No. It took sendmail a week to fix this. The rest of the time was used to coordinate the release with all the involved vendors etc. There are a few choices, full