Re: [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-20 Thread state
Selon phioust [EMAIL PROTECTED]: On 10/20/07, lulzlulzluzluz [EMAIL PROTECTED] wrote: security is serious business. plz do not joke like that phioust: xss0day - x-ssh0day, see serious. Only drraid has ssh 0day On 10/19/07, Radu State [EMAIL PROTECTED] wrote: my $hex

Re: [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-20 Thread phioust
On 10/20/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Yeap, Ph.d use Eiffel and Lisp. Only when we want to be understood by a larger community, we go to Perl and reach down. Please dont reach down to us next time because your perl makes us cry. Also do you hack up iterative loops in

Re: [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-20 Thread Gadi Evron
-- Powered by Outblaze ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-20 Thread Valdis . Kletnieks
On Sat, 20 Oct 2007 12:27:40 CDT, phioust said: Also do you hack up iterative loops in lisp too or do you know how to use a macro? Iterative loops. Lisp. You slay me. pgpZx9ukpq8qM.pgp Description: PGP signature ___ Full-Disclosure - We

[Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-19 Thread Radu State
In a previous post (http://seclists.org/fulldisclosure/2007/Oct/0174.html) , we have seen how XSS injection can be performed over SIP to inject malicious JavaScript into the browser of an user that check the call history of his phone. In this post, we will detail how XSS injection can be

Re: [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-19 Thread phioust
LOL XSS PDP ALERT !!! THEY ARE STEALING YOUR RESEARCH! On 10/19/07, Radu State [EMAIL PROTECTED] wrote: In a previous post (http://seclists.org/fulldisclosure/2007/Oct/0174.html) , we have seen how XSS injection can be performed over SIP to inject malicious JavaScript into the

Re: [Full-disclosure] XSS and SQL injection via SIP (part 2) and toll fraud bonus

2007-10-19 Thread phioust
On 10/20/07, lulzlulzluzluz [EMAIL PROTECTED] wrote: security is serious business. plz do not joke like that phioust: xss0day - x-ssh0day, see serious. Only drraid has ssh 0day On 10/19/07, Radu State [EMAIL PROTECTED] wrote: my $hex = ''; for (my $i = 0; $i