[Full-disclosure] XSS Vulnerability in Tracks 1.7.2

2011-03-29 Thread Netsparker Advisories
Information Name : XSS vulnerability in Tracks Software : Tracks 1.7.2. Vendor Hompeage : http://getontracks.org/ Vulnerability Type : Cross-Site Scripting Severity : High Researcher : Mesut Timur mesut [at] mavitunasecurity [dot] com Advisory Reference : NS-11-003

[Full-disclosure] XSS Vulnerability in EnanoCms 1.1.7 1.1.6

2011-03-29 Thread Netsparker Advisories
Information Name : XSS vulnerability in EnanoCms Software : All versions prior to and including 1.1.7 and 1.0.6 are affected. Vendor Hompeage : http://www.enanocms.org Vulnerability Type : Cross-Site Scripting Severity : High Researcher : Mesut Timur mesut [at]

[Full-disclosure] CFP ISSA Ireland Security Conference 2011

2011-03-29 Thread John Sheppard
Dear All, A call for papers has been issued for the ISSA Ireland Security Conference (IISC) 2011 being held on 11th and 12th of May 2011 in The Royal College of Physicians Ireland on Kildare Street, Dublin. The conference will focus on a wide range of topics, from Technical and Operational

Re: [Full-disclosure] Vulnerabilities in *McAfee.com

2011-03-29 Thread Pablo Ximenes
FIY http://it.slashdot.org/story/11/03/28/209230/McAfees-Website-Full-of-Security-Holes Pablo Ximenes http://ximen.es/ http://twitter.com/pabloximenes 2011/3/28 Pablo Ximenes pa...@ximen.es: blog post about this: http://ximen.es/?p=469 Please, don't throw stones at me. []'s Pablo

[Full-disclosure] itunes.apple.com owned by webapp malicious host

2011-03-29 Thread matador matador
Enjoy! :) http://www.google.com/search?q=lizamoon.com+site%3Aapple.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Hello

2011-03-29 Thread Rémon Schopmeijer
I just subscribed to the mailing list J Wanted to say hi. Greetings, Anthraxium-64 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Adobe Omniture: Cookie-Forcing Issue

2011-03-29 Thread Tom Keetch
Hi All, Adobe have yet to set a fix date for this cookie forcing issue I found in their Omniture product. If the affected plug-in is installed on a HTTPS protected site, then by setting a malicious cookie for the insecure domain, it is possible to hijack secure connections to the domain by

[Full-disclosure] [USN-1094-1] Libvirt vulnerability

2011-03-29 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-1094-1March 29, 2011 libvirt vulnerability CVE-2011-1146 === A security issue affects the following Ubuntu releases: Ubuntu 9.10 Ubuntu 10.04

Re: [Full-disclosure] Adobe Omniture: Cookie-Forcing Issue

2011-03-29 Thread Stefano Di Paola
Hey Tom, I don't know how you researched and find the issue. Funny is that I found it some weeks ago as well with a not-yet-released-tool-for-finding-DOMXss called DOMInator, but I decided to wait a bit to understand if it was exploitable and in which conditions. The only thing I can tell you is

[Full-disclosure] [USN-1095-1] Quagga vulnerabilities

2011-03-29 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1095-1March 29, 2011 quagga vulnerabilities CVE-2010-1674, CVE-2010-1675 === A security issue affects the following Ubuntu releases: Ubuntu

[Full-disclosure] [USN-1096-1] Subversion vulnerability

2011-03-29 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1096-1March 29, 2011 subversion vulnerability CVE-2011-0715 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS

[Full-disclosure] [USN-1097-1] Tomcat vulnerabilities

2011-03-29 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1097-1March 29, 2011 tomcat6 vulnerabilities CVE-2010-3718, CVE-2011-0013, CVE-2011-0534 === A security issue affects the following Ubuntu

[Full-disclosure] [USN-1098-1] vsftpd vulnerability

2011-03-29 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-1098-1March 29, 2011 vsftpd vulnerability CVE-2011-0762 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu

[Full-disclosure] Launched New Tool - RAR Password Unlocker

2011-03-29 Thread Nagareshwar Talekar
Hi all, We have just released new password recovery tool - RarPasswordUnlocker - FREE tool to recover the password of protected RAR files. It is created by Neeraj who is leading contributor on SecurityXploded.com For more details download visit RarPasswordUnlocker http://bit.ly/ft8i5k --

Re: [Full-disclosure] itunes.apple.com owned by webapp malicious host

2011-03-29 Thread Cal Leeming
Unconfirmed, seems to escape fine for me. On Tue, Mar 29, 2011 at 3:22 PM, matador matador m4t4d...@gmail.com wrote: Enjoy! :) http://www.google.com/search?q=lizamoon.com+site%3Aapple.com ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Launched New Tool - RAR Password Unlocker

2011-03-29 Thread kai
Hi, is there any chance of seeing CUDA in action for the next versions? :) Installed executable is completely portable. why do we need installer then? distribute that tool as single executable. Cheers, Kai We have just released new password recovery tool - RarPasswordUnlocker

Re: [Full-disclosure] Launched New Tool - RAR Password Unlocker

2011-03-29 Thread Jo Galara
How does it work? Bruteforce? On 03/29/2011 09:12 PM, Nagareshwar Talekar wrote: Hi all, We have just released new password recovery tool - RarPasswordUnlocker - FREE tool to recover the password of protected RAR files. It is created by Neeraj who is leading contributor on

[Full-disclosure] [SECURITY] [DSA 2206-1] New mahara packages fix several vulnerabilities

2011-03-29 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 2206-1secur...@debian.org http://www.debian.org/security/ Martin Schulze March 29th, 2011

Re: [Full-disclosure] Launched New Tool - RAR Password Unlocker

2011-03-29 Thread Andrew Farmer
On 2011-03-29, at 12:29, k...@rhynn.net wrote: is there any chance of seeing CUDA in action for the next versions? :) Ha ha ha, no. (See below.) Installed executable is completely portable. why do we need installer then? distribute that tool as single executable. Because without the

[Full-disclosure] [SECURITY] [DSA 2207-1] tomcat5.5 security update

2011-03-29 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2207-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff March 30, 2011

[Full-disclosure] INSECT Pro 2.5 Release - Web scanner tool

2011-03-29 Thread runlvl
Insecurity Research is happy to announce the release of version 2.5, get it now while is still hot ! Insect Pro 2.5 is a penetration security auditing and testing software solution designed to allow organizations of all sizes mitigate, monitor and manage the latest security threats

[Full-disclosure] INSECT Pro 2.5 Release - Web scanner tool

2011-03-29 Thread runlvl
Insecurity Research is happy to announce the release of version 2.5, get it now while is still hot ! Insect Pro 2.5 is a penetration security auditing and testing software solution designed to allow organizations of all sizes mitigate, monitor and manage the latest security threats

[Full-disclosure] about http://twitter.com/yuange1975

2011-03-29 Thread yuange
http://twitter.com/yuange1975到底是谁?有意混淆视听不说,现在竟然我的照片都用上了. 不管出于什么目的,希望好自为之. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by

[Full-disclosure] VMSA-2011-0006 VMware vmrun utility local privilege escalation

2011-03-29 Thread VMware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID: VMSA-2011-0006 Synopsis: VMware vmrun utility local privilege escalation Issue date:2011-03-29