[Full-disclosure] Open Text security contact

2007-10-31 Thread mike kemp
Hello list, Anyone have a security contact at Open Text Corporation (www.opentext.com)? Many thanks, clappymonkey (Michael Kemp) ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by

[Full-disclosure] Potenetially way OT: New rant

2007-08-21 Thread mike kemp
Dear all, Please forgive the potentially off topic post, but please find below a link to a recent article / rant about the sorry state of the security 'industry'. Hope it proves of use and generates some debate: http://www.informit.com/articles/article.aspx?p=770363 Many thanks. Michael Kemp (cla

[Full-disclosure] RIM BlackBerry Pearl 8100 Browser DoS

2007-03-12 Thread mike kemp
RIM BlackBerry Pearl 8100 Browser DoS -- 12 March 2007 Summary: A vulnerability has been discovered that could impact upon the availability of the BlackBerry 8100 Wireless handheld (v4.2.0.51). It is possible for a remote attacker to construct a WML page that contains an overly long string v

[Full-disclosure] Denial Of Service in Internet Explorer for MS Windows Mobile 5.0

2007-02-09 Thread mike kemp
Denial Of Service in Internet Explorer for MS Windows Mobile 5.0 - Date of Release: 09/02/2007 Description: A vulnerability exists in Internet Explorer for Microsoft Windows Mobile 5.0 (for smart phone and pocket PC) that impacts up

[Full-disclosure] Potentially OT: AJAX article

2006-11-27 Thread mike kemp
Dear all, Please forgive the potentially off topic post, but please find below a link to a recent article concerning AJAX security I composed for Heise UK / c't, in the sincere hopes that it proves useful to anyone still even remotely interested in much hyped Web 2.0 technologies (or DHTML...) M

[Full-disclosure] Multiple vulnerabilities in TK8 Safe v.3.0.5

2006-07-02 Thread mike kemp
Multiple vulnerabilities in TK8 Safe v.3.0.5 July 3, 2006 Summary:TK8 Safe (www.tk8.com) is a password management application, which stores authentication details (and other sensitive data) in encrypted local folders. A number of issues have been discovered in version 3.0.5 of the application