Re: [Full-disclosure] yahoomail dom based xss vulnerability

2010-06-15 Thread pratul agrawal
Its working Bro.  I think u had done some mistakes so u try it again with check that javascript execution feature is enable in your browser. and bro for execution of script it is must to use proper syntax that contain special characters. just put scriptalert(123)script  in the New Folder field

Re: [Full-disclosure] yahoomail dom based xss vulnerability

2010-06-15 Thread Benji
Sup bro I waz checkin owt ur javascriptz skriptz and waz wonderin if u cud explain how diz shiz werks. Peaze. Sent from my iPhone On 15 Jun 2010, at 09:18, pratul agrawal pratu...@yahoo.com wrote: Its working Bro. I think u had done some mistakes so u try it again with check that

Re: [Full-disclosure] Introducing TGP...

2010-06-15 Thread Nid
Hi Timothy TGP – “Thor’s Godly Privacy” 06/13/10 v1.1.06 it does things a bit differently – differently in a way that can change the way you work with your encrypted data. At the simplest level, this is done by encrypting data into byte arrays, and then converting those byte arrays into

Re: [Full-disclosure] Introducing TGP...

2010-06-15 Thread rembrandt
On Mon, 14 Jun 2010 21:40:30 + Thor (Hammer of God) t...@hammerofgod.com wrote: Hey Nid - -Original Message- From: Nid [mailto:nidfulld...@googlemail.com] Sent: Monday, June 14, 2010 11:18 AM To: Thor (Hammer of God) Cc: full-disclosure@lists.grok.org.uk Subject: Re:

[Full-disclosure] FreeBSD 8.1-Prerelease Had been PWN????

2010-06-15 Thread Nyetnyet
Dear, all Is it true that FreeBSD 8.1-Prerelease had been pwn? I've seen this video and hell yeah its kind of local root on FreeBSD 8.1. Any information or disclosure about this??? The video : http://www.youtube.com/watch?v=H57LIcRqxlo Regards Chiko McCormick

Re: [Full-disclosure] Introducing TGP...

2010-06-15 Thread Thor (Hammer of God)
The SHA256 hashing of the private key may not result in authenticity assurances on the key (if I'm reading it correctly). I believe that's an Athenticate-then-Encrypt scheme, and the details of the interactions in AtE can be tricky. I had an opportunity to sleep on this, so here's my two

[Full-disclosure] [SECURITY] [DSA 2054-2] New bind9 packages fix cache poisoning

2010-06-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 2054-2secur...@debian.org http://www.debian.org/security/ Martin Schulze June 15th, 2010

Re: [Full-disclosure] Patriotic botnet with Orange's HADOPI software

2010-06-15 Thread no no
Malware like The service (cdtsvc) doesn't allow configuration change : if the user changes the service config, it is instantly reset to default values : restart when killed, user cannot stop it manually This behaviour is bypassable : create the following registry key and the

Re: [Full-disclosure] yahoomail dom based xss vulnerability

2010-06-15 Thread pratul agrawal
Thanks Brother,   See, how this occurred, Basically in most of the cases Developers  Simply design a APIs and when the client request for any page this APIs gets Stored in the Client side. its main task is to takes the user input and shows the result immediately  to the