[Full-Disclosure] MS IE User's Authentication Details (userid/password) Sharing Issue

2004-12-12 Thread Debasis Mohanty
I would like to highlight an issue with IE which I have verified with Microsoft before posting it here. This issue of IE has got very limited security implications. I have also included the reply from Microsoft in this post for reference. The details of this IE issue can be found below: Microso

[Full-Disclosure] NetWare Screensaver Authentication Bypass From The Local Console

2004-12-12 Thread Adam Gray
Novacoast Security Advisory Novell Netware 5/5.1/6.0/6.5 Vulnerability Synopsis: Novacoast has discovered a vulnerability in the Novell NetWare Operating System screen saver software. The vulnerability allows a local attacker to bypass authentication and access the system console. Descripti

[Full-Disclosure] List Charter

2004-12-12 Thread John Cartwright
[Full-Disclosure] Mailing List Charter John Cartwright <[EMAIL PROTECTED]> and Len Rose <[EMAIL PROTECTED]> Introduction & Purpose -- This document serves as a charter for the [Full-Disclosure] mailing list hosted at lists.netsys.com. The list was created on 9th July 2002

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-12 Thread Florian Weimer
* Valdis Kletnieks: > It's still applying band-aids to a hemophiliac rather than supplying > them with clotting factor. The only *sustainable* long-term solution is > to use software that was designed with a sane security model, so there's > no *need* for a separate A/V product. It's not just so