Re: [Full-disclosure] Facebook name extraction based on email/wrong password + POC

2010-08-12 Thread werew01f
Don't seems to work on my system. No user name or picture was displayed. On Wed, Aug 11, 2010 at 5:01 PM, Atul Agarwal wrote: > Hello all, > > Sometime back, I noticed a strange problem with Facebook, I had > accidentally entered wrong password in Facebook, and it showed my first and > last nam

Re: [Full-disclosure] Wing FTP Server - Cross Site Scripting Vulnerability

2010-06-07 Thread werew01f
Discussion with the wftpserver.com support. This vulnerability was not consider critical as it requires authenticated login to exploit. But it will be fixed on the next release in about a month time. On Wed, Jun 2, 2010 at 5:35 PM, werew01f wrote: > Security Advisory: Wing FTP Server - Cr

[Full-disclosure] Wing FTP Server - Cross Site Scripting Vulnerability

2010-06-02 Thread werew01f
w01f.blogspot.com E-mail: hack [dot] werew01f [at] gmail [dot] com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] D-Link DI-724P+ Router - Cross Site Scripting Vulnerability

2010-05-19 Thread werew01f
execute in a user's browser session. The vulnerable URL: http://192.168.0.1/wlap.htm (the default admin IP is 192.168.0.1). Researcher Info: Discovered by: w01f Website: http://labs-werew01f.blogspot.com E-mail: hack [dot] werew01f [at]