RE: [Full-Disclosure] Awake a modem with AT commands

2005-02-25 Thread Syed Imran Ali
Hmmm, As far as I think you can only awake a dialup modem, if u gains access of the pc. Otherwise to bind a shell on a modem you need to initialize it first and establish a connection with it. I don't know if you specifically asked for DSL or Cable modems or what you exactly wanna do with it. As

[Full-Disclosure] Novell/Ximian Evolution multiple text attachments DoS

2005-02-25 Thread Kristian Hermansen
== =Analysis= == I just wanted to inform users of Ximian Evolution 2.0 software that there exists a way to temporarily DoS the local application and/or machine by attaching an absurd amount of .ezm files to a normal email. It seems that Evolution tries to int

Re: [Full-Disclosure] More T-Mobile fall out...

2005-02-25 Thread security curmudgeon
: What appears to be a home made porn staring former Limp Bizkit front man : Fred Durst is circling the internet today : : ..this appears to be more fall out from the T-mobile hack : First news article I have seen covering it : : http://www.drudgereport.com/flash3fd.htm http://news.com.com/Li

[Full-Disclosure] More T-Mobile fall out...

2005-02-25 Thread pingywon
What appears to be a home made porn staring former Limp Bizkit front man Fred Durst is circling the internet today   ...this appears to be more fall out from the T-mobile hack   Links: www.illmob.org   http://eight-ball.org/fred/   First news article I have seen covering it   http://www.drud

[Full-Disclosure] Knet <= 1.04c Buffer Overflow Bug

2005-02-25 Thread CorryL
-=[ADVISORY---]=- -=[ ]=- -=[ Knet <= 1.04c ]=- -=[ ]=

[Full-Disclosure] Re: Firescrolling [Firefox 1.0]

2005-02-25 Thread Stan Bubrouski
looked at: http://www.mozilla.org/projects/security/known-vulnerabilities.html Are you sure its fixed??? -sb Beauford, Jason wrote: That sucked. Fortunately: http://www.mozilla.org/products/firefox/releases/ jmb -Original Message- From: mikx [mailto:[EMAIL PROTECTED] Sent: Friday, Febru

[Full-Disclosure] RE: Firescrolling [Firefox 1.0]

2005-02-25 Thread Andrade, Leonardo F. Buonsanti de \(BR - IT Brazil\)
Yes. It works on Firefox 1.0 -Original Message- From: Eric McCarty [mailto:[EMAIL PROTECTED] Sent: sexta-feira, 25 de fevereiro de 2005 14:37 To: mikx; full-disclosure@lists.netsys.com; bugtraq@securityfocus.com; [EMAIL PROTECTED] Subject: RE: Firescrolling [Firefox 1.0] Confirmed Exploi

[Full-Disclosure] [ GLSA 200502-30 ] cmd5checkpw: Local password leak vulnerability

2005-02-25 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200502-30 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Re: [Full-Disclosure] PivX Solutions

2005-02-25 Thread Danny
On Fri, 25 Feb 2005 20:17:44 + GMT, Jason Coombs <[EMAIL PROTECTED]> wrote: > Regarding PivX Solutions, > > Anyone who has any information about PivX Solutions, please contact me as > soon as possible. > Don't you work for PivX? What information could you be looking for? ...D

Re: Fw: [Full-Disclosure] Google Search and Gmail Correlation

2005-02-25 Thread Esler, Joel CNTR/Sytex
IIRC, only if you turn on the "advanced features" J On Fri, 2005-02-25 at 15:46 -0500, Nancy Kramer wrote: If you run the Google Toolbar they do know where you have been surfing on the web. They do record it. That's how you "pay" for the Toolbar. Your theory sounds correct to me. Rega

[Full-Disclosure] wireless internet spying wifi hotpots and ATMS

2005-02-25 Thread bob wireless internet evdo & wifi hotspot guy
as far as video cameras... look over your shoulder especially closed ATM rooms... cover your pin EVEN IF NOBODY IS AROUND... X Robert Kim, Wireless Internet Wifi Hotspot Advisor http://evdo-coverage.com http://wireless-internet-broadband-service.com https://evdo.sslpowered.com/wi

[Full-Disclosure] PivX Solutions

2005-02-25 Thread Jason Coombs
Regarding PivX Solutions, Anyone who has any information about PivX Solutions, please contact me as soon as possible. Thanks. Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-chart

Re: Fw: [Full-Disclosure] Google Search and Gmail Correlation

2005-02-25 Thread bob wireless internet evdo & wifi hotspot guy
Google has all kinds of info... they are probably the most powerful entity on this planet... i looked up google's zeitgiest and the ratio of Kerry vs. Bush Searches BEFORE the election was the margin by which Bush WON... PREDICTIVE??? absolutely. X Robert Kim, Wireless Internet Wi

Re: Fw: [Full-Disclosure] Google Search and Gmail Correlation

2005-02-25 Thread Nancy Kramer
If you run the Google Toolbar they do know where you have been surfing on the web. They do record it. That's how you "pay" for the Toolbar. Your theory sounds correct to me. Regards, Nancy Kramer Webmaster http://www.americandreamcars.com Free Color Picture Ads for Collector Cars One of the T

Re: [Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread Esler, Joel CNTR/Sytex
While I agree that his is an issue.  However I don't feel it's a security issue.  It's more a "fix the driver damn it issue"...  If you can go through all the trouble to set up a camera, or physically sit and see a few seconds worth of XFree Blink..  You most likely have physical access anywa

Re: [Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread phased
If someone has access to your machine, and can make it crash so they can see what you were doing, someone mentioned this is local infomation disclosure... they could just look over your shoulder while you were using the machine or install a mini camera someplace in the room, zoom in on your monit

[Full-Disclosure] RE: Firescrolling [Firefox 1.0]

2005-02-25 Thread Beauford, Jason
That sucked. Fortunately: http://www.mozilla.org/products/firefox/releases/ jmb -Original Message- From: mikx [mailto:[EMAIL PROTECTED] Sent: Friday, February 25, 2005 3:11 AM To: full-disclosure@lists.netsys.com; bugtraq@securityfocus.com; [EMAIL PROTECTED] Subject: Firescrolling [Fir

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread Stan Bubrouski
bkfsec wrote: Stan Bubrouski wrote: That seems like a pretty unhelpful solution. Say the system crashes? Or KDE or X crash? The same problem will still exist. With this solution someone could intentionally crash your machine to avoid those routines from running. I'm not trying to put you dow

[Full-Disclosure] iDEFENSE Security Advisory 02.25.05: WU-FTPD File Globbing Denial of Service Vulnerability

2005-02-25 Thread idlabs-advisories
WU-FTPD File Globbing Denial of Service Vulnerability iDEFENSE Security Advisory 02.25.05 www.idefense.com/application/poi/display?id=207&type=vulnerabilities February 25, 2005 I. BACKGROUND WU-FTPD is an ftp daemon for Unix systems developed at Washington University. More information is availa

[Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread Stan Bubrouski
Riad S. Wahby wrote: Stan Bubrouski <[EMAIL PROTECTED]> wrote: With this solution someone could intentionally crash your machine to avoid those routines from running. I'm not trying to put you down or anything, in fact I probably know less about video related stuff than most on the list, this j

[Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread Stan Bubrouski
Riad S. Wahby wrote: Stan Bubrouski <[EMAIL PROTECTED]> wrote: Umm I didn't offer a solution at all? Are you making a statement or asking a question? Umm more like wondering what you're talking about. I clearly said I wasn't wise enough to devise a solution for this... which is why I sa

[Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread Riad S. Wahby
Stan Bubrouski <[EMAIL PROTECTED]> wrote: > Umm I didn't offer a solution at all? Are you making a statement or asking a question? > I clearly said I wasn't wise enough to devise a solution for this... > which is why I said I'll leave a solution to the experts... It's fairly obvious that you ei

[Full-Disclosure] RE: Firescrolling [Firefox 1.0]

2005-02-25 Thread Eric McCarty
Confirmed Exploit works in Firefox 1.0, however on a side note Microsoft Anti-spyware prevented the script from executing. Eric McCarty Systems Administrator Internet Security Officer -Original Message- From: mikx [mailto:[EMAIL PROTECTED] Sent: Friday, February 25, 2005 12:11 AM T

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread KF (lists)
I have cc'd a link for the FD-archive on this thread to the [EMAIL PROTECTED] alias... I will let you know if and when they respond. -KF Cassidy Macfarlane wrote: Yeah. In fact, imho, this should have moved off to the Xfree dev list a few posts ago.. I trust the OP or someone along the line has f

[Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread Riad S. Wahby
Stan Bubrouski <[EMAIL PROTECTED]> wrote: > With this solution someone could intentionally crash your machine to > avoid those routines from running. I'm not trying to put you down or > anything, in fact I probably know less about video related stuff than > most on the list, this just doesn't seem

Re: [Full-Disclosure] phpWebSite-0.10.0_exploit

2005-02-25 Thread Colin . Scott
Well I cant get this to work. The annoucements module doesnt allow non-graphics extensions so the PHP file doesnt get uploaded. Regards, Colin. tjomka

[Full-Disclosure] CIS WebServer Directory Traversal Bug

2005-02-25 Thread CorryL
-=[ x0n3-h4ck Italian Security Team ]=- /*Advisories*\ /* Application: CIS WebServer Vendor's Url: www.cisindia.net Version: 3.5.13 Platforms: Windows Bug: Directory Traversal Exploitation: Remote Author: CorryL [EMAIL PROTECTED] www.x0n3-h4ck.org *\ {Description} CIS WebServer is a

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread bkfsec
Stan Bubrouski wrote: Michael Holstein wrote: Seems like an easy fix would be to write a routine into KDM to write 4-5 seconds worth of something benign (like the KDE logo in different spots) to the screen before logout/shutdown (note how 2000/XP already do this with the 'preparing to shutdown'

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread Stan Bubrouski
Michael Holstein wrote: Seems like an easy fix would be to write a routine into KDM to write 4-5 seconds worth of something benign (like the KDE logo in different spots) to the screen before logout/shutdown (note how 2000/XP already do this with the 'preparing to shutdown' screen? Maybe there's

RE: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread Cassidy Macfarlane
Yeah. In fact, imho, this should have moved off to the Xfree dev list a few posts ago.. I trust the OP or someone along the line has fwd'ed this thread to their list I remember this from Red Hat years ago...It's always been around, bout time they (Xfree)fixed it. -Original Message- F

[Full-Disclosure] [USN-85-1] Gaim vulnerabilities

2005-02-25 Thread Martin Pitt
=== Ubuntu Security Notice USN-85-1 February 25, 2005 gaim vulnerabilities CAN-2005-0208, CAN-2005-0472, CAN-2005-0473 === A security issue affects the following Ubuntu release

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread bkfsec
[EMAIL PROTECTED] wrote: I don't think this is at all easily solvable - when the X server starts up, the card is probably in console mode using the VGA emulation, which is pretty brain-dead and doesn't touch much of the card memory (when you have 32M or 64M on-card, that 640x480 gets lonely sitting

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread Michael Holstein
All kidding aside, this seems to be a real security issue. Your system shouldn't be showing unauthorized users what you were doing. It should properly flush the memory. Seems like an easy fix would be to write a routine into KDM to write 4-5 seconds worth of something benign (like the KDE logo in

[Full-Disclosure] (no subject)

2005-02-25 Thread Yeh Durpe
___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] Re: Xfree86 video buffering?

2005-02-25 Thread Riad S. Wahby
James Tucker <[EMAIL PROTECTED]> wrote: > Is it not possible to switch processing modes without switching video modes? > Could a fast(er) operation, such as a blank intermediate pallete be > loaded to 'wash out' all coloured pixels on the screen? It seems like worrying about this at startup is the

Re: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread James Tucker
On Thu, 24 Feb 2005 23:26:36 -0500, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > I don't think this is at all easily solvable - when the X server starts up, > the > card is probably in console mode using the VGA emulation, which is pretty > brain-dead and doesn't touch much of the card memory (w

RE: [Full-Disclosure] Please help me update my address book on Ringo

2005-02-25 Thread Michael Scheidell
Can't be spam Original email used Habeas :-) (wouldn't ringo using habaes violate habeas's TOS? X-Habeas-SWE-1: winter into spring X-Habeas-SWE-2: brightly anticipated X-Habeas-SWE-3: like Habeas SWE (tm) X-Habeas-SWE-4: Copyright 2002 Habeas (tm) X-Habeas-SWE-5: Sender Warranted Email (SWE) (tm

AW: [Full-Disclosure] Google Search and Gmail Correlation

2005-02-25 Thread Tim Hecktor
Hello, Most of the URL's google finds are pointing to ip Adresses. The people seem to be to Lazy to set up a subdomain for their cam's because it will be a part of a frameset on their website And the url would not bee seen anyway. I just greped one example, the camera reached under axis_64ddf3.a

Fw: [Full-Disclosure] Google Search and Gmail Correlation

2005-02-25 Thread Colin . Scott
A little OT but I was pondering the other day about something. Remember the Axis network camera "inurl" search that exposed internet facing LAN cameras? Well I noticed that lots of those cameras are configured on high ports. 7000 for example. Now, I wondered how Google gets those cameras into its

[Full-Disclosure] Narmacil project : The super worms : does it already exist?

2005-02-25 Thread khaalel
Hello Since a few month, I've been working on viruses (especially about the evolution of viruses) and I started to create a small theory (that I called Narmacil) about advanced viruses that I will post here. My goal is not to help viruses makers but to show how viruses can evolve and which methods

[Full-Disclosure] Firescrolling [Firefox 1.0]

2005-02-25 Thread mikx
__Summary Remember my Internet Explorer "scrollbar exploit" based on http-equiv's "What a Drag"? When will people ever learn that "unusual user interaction" can be hidden by common tasks... Let's combine fireflashing, firetabbing, xul and javascript to run arbitrary code by dragging a scrollbar

RE: [Full-Disclosure] Xfree86 video buffering?

2005-02-25 Thread Allan
So the RAM should be flushed during shutdown .. (as early in the shutdown procedure as possible, I'd say). Trying to do this during the boot sequence is useless. You could make a special 'bootdisk' that would show you the contents of the videoram. This would also make it available for longer then t