Re: [Full-Disclosure] A new TCP/IP blind data injection technique?

2003-12-14 Thread Valdis . Kletnieks
On Sat, 13 Dec 2003 03:35:25 MST, Michael Gale <[EMAIL PROTECTED]> said: > For example the BorderWare Firewall will not accept fragmented packets, > they are working on a firewall function that when fragmented packets > arrive. It will save the first piece plus all frags until the final one > is

Re: [Full-Disclosure] A new TCP/IP blind data injection technique?

2003-12-14 Thread Michal Zalewski
On Sat, 13 Dec 2003, Michael Gale wrote: > Well then .. I am happy that non of the firewalls I use accept or pass > fragments packets. I would be willing to assume you are confused. Can you provide any references that would confirm this observation? -- - bash$ :(){ :|:&}

[Full-Disclosure] Finjan Software Discovers a New Critical Vulnerability In Yahoo E-mail Service

2003-12-14 Thread Menashe Eliezer
Yahoo E-mail Service Vulnerability Release Date:  December 10, 2003 Severity: Critical (Potential web-based e-mail worm) Systems Affected: Other web-based e-mail systems may be vulnerable. Internet Explorer and any software application used for reading Yahoo e-mail messages. Status: Yahoo,Ex

[Full-Disclosure] lftp buffer overflows

2003-12-14 Thread Härnhammar, Ulf
lftp buffer overflows - PROGRAM: lftp VENDOR: Alexander V. Lukyanov et al. HOMEPAGE: http://lftp.yar.ru/ VULNERABLE VERSIONS: 2.3.0, 2.4.9, 2.6.6, 2.6.7, 2.6.8, 2.6.9, probably all versions inbetween IMMUNE VERSIONS: 2.6.10, older versions with my patch applied * PROGRAM DES

[Full-Disclosure] Breaking the checksum (a new TCP/IP blind data injection technique)

2003-12-14 Thread Michal Zalewski
First, let me apologize to all readers of the list who have no particular interest in the subject; I should not have generated so many posts, and I solemnly swear this is the last one. I posted my first thoughts on the subject perhaps a bit prematurely, and agreed with Nick Cleaton's response to my

[Full-Disclosure] Saddam Hussein Captured

2003-12-14 Thread Gideon Rasmussen, CISSP, CFSO, CFSA, SCSA
http://www.cnn.com/2003/WORLD/meast/12/14/sprj.irq.main/index.html U.S.: 'We got him' Coalition captures Saddam, 'talkative,' in raid near Tikrit Sunday, December 14, 2003 Posted: 10:10 AM EST (1510 GMT) TIKRIT, Iraq (CNN) -- After nine months of scurrying from house to house, Saddam Hu

Re: [Full-Disclosure] Saddam Hussein Captured

2003-12-14 Thread Gideon Rasmussen, CISSP, CFSO, CFSA, SCSA
I apologize. I was excited. In the future, I'll keep to the list's charter. Gideon Gideon T. Rasmussen CISSP, CFSO, CFSA, SCSA Boca Raton, FL Henrik Persson wrote: On Sun, 2003-12-14 at 16:58, Gideon Rasmussen, CISSP, CFSO, CFSA, SCSA wrote: *snip* Just what the heck does this have to do

Re: [Full-Disclosure] Saddam Hussein Captured

2003-12-14 Thread KF
I was expecting some fake IE link, some XSS or something along those lines . Tis no joke. =] -KF Gideon Rasmussen, CISSP, CFSO, CFSA, SCSA wrote: http://www.cnn.com/2003/WORLD/meast/12/14/sprj.irq.main/index.html U.S.: 'We got him' Coalition captures Saddam, 'talkative,' in raid near Tikrit Su

RE: [Full-Disclosure] Saddam Hussein Captured

2003-12-14 Thread Poof
Thanks, I read that when I woke up. Anyhow, please don't send HTML email to the list- Many people don't have outlook* to read the blob that results. Also, what does this have to do with this list? ^^ (Sorry. Heh) From: [EMAIL PROTECTED] [mailto:[EMAIL PRO

[Full-Disclosure] Get admin rights using Doro (pdf creator)

2003-12-14 Thread Ramon Kukla
Hi, a few days ago i discovered a bug in Doro. Doro is a free tool to create pdf files from any windows program. After installing Doro you have a new printer called 'Doro PDF Writer'. If you select 'Print' the spooler calls the printer filter 'doro.dll'. The 'doro.dll' then starts 'doro.exe' and a

[Full-Disclosure] GLSA: Malformed dcc send requests in xchat-2.0.6 lead to a denial of service

2003-12-14 Thread Kurt Lieber
--- GENTOO LINUX SECURITY ANNOUNCEMENT 200312-06 --- GLSA:200312-06 Package: net-irc/xchat Summary: Malformed dcc send requests in xchat-

RE: [Full-Disclosure] Saddam Hussein Captured

2003-12-14 Thread Poof
Actually, what I asked is what it had to do with the list. The point I was trying to make is why is he sending HTML email. Anyhow, yes, I'm sure it'll affect the computers/security in some way- However currently that way isn't evident. When it is... Sure post away. Otherwise... You could post any