[Full-Disclosure] Windows Improper Token Validation -Exploit-

2005-01-10 Thread Cesar
Enjoy!!;) Cesar. __ Do you Yahoo!? Take Yahoo! Mail with you! Get it on your mobile phone. http://mobile.yahoo.com/maildemo // Impersonation POC Exploit // Works on Win2k all service packs // by Cesar Cerrudo (sqlsec>atdoth

[Full-Disclosure] QNX crrtrap arbitrary file read/write vulnerability [RLSA_06-2004]

2005-01-06 Thread Julio Cesar Fort
*** rfdslabs security advisory *** Title: QNX crrtrap arbitrary file read/write vulnerability [RLSA_06-2004] Versions: QNX RTOS 2.4, 4.25, 6.1.0, 6.2.0 (+ Update Patch A) Vendor: http://www.qnx.com Date: Dec 11 2004 Author: Julio Cesar Fort 1. Introduction crrtrap is a tool to detect video

[Full-Disclosure] Need Kerio security contact

2004-10-15 Thread Cesar
Anyone knows Kerio security contact email? Thanks. Cesar. ___ Do you Yahoo!? Declare Yourself - Register online to vote today! http://vote.yahoo.com ___ Full-Disclosure - We believe in it. Charter: http

[Full-Disclosure] QNX BUG FESTIVAL -- [RLSA_02-2004] QNX Photon multiple buffer overflows

2004-09-13 Thread Julio Cesar Fort
*** rfdslabs security advisory *** Title: QNX Photon multiple buffer overflows [RLSA_02-2004] Versions: QNX RTP 6.1 (possibly others) Vendor: QNX Software Systems <http://www.qnx.com> Date: 13 Sep 2004 Author: Julio Cesar Fort 1. Introduction QNX Photon microGUI is the windowing sys

[Full-Disclosure] QNX BUG FESTIVAL -- [RLSA_03-2004] QNX ftp client format string bug

2004-09-13 Thread Julio Cesar Fort
*** rfdslabs security advisory *** Title: QNX ftp client format string bug [RLSA_03-2004] Versions: QNX RTP 6.1 (possibly others) Vendor: http://www.qnx.com Date: 13 Sep 2004 Author: Julio Cesar Fort 1. Introduction "QNX Software Systems has provided OS technology, development tools, an

[Full-Disclosure] QNX BUG FESTIVAL -- [RLSA_04-2004] QNX crrtrap possible race condition

2004-09-13 Thread Julio Cesar Fort
*** rfdslabs security advisory *** Title: QNX crrtrap possible race condition vulnerability [RLSA_04-2004] Versions: QNX RTP 6.1 (possibly others) Vendor: http://www.qnx.com Date: Sep 13 2004 Author: Julio Cesar Fort 1. Introduction crrtrap is a tool to detect video hardware and starts the

[Full-Disclosure] [RLSA_01-2004] QNX PPPoEd local root vulnerabilities

2004-09-03 Thread Julio Cesar Fort
*** rfdslabs security advisory *** Title: QNX PPPoEd local root vulnerabilities [RLSA_01-2004] Versions: QNX RTP 6.1 (possibly others) Vendor: http://www.qnx.com Date: 02 Sep 2004 Author: Julio Cesar Fort 1. Introduction PPPoEd daemon is used to provide a PPPoE connection, such as DSL, for

Re: [Full-Disclosure] [SHATTER Team Security Alert] Multiple vulnerabilities in Oracle Database Server

2004-09-03 Thread Cesar
Most of the vulns are almost one year old. We don't steal anything. BTW: finding vulns in Oracle products is like fishing in a pool full of fishes. Not big deal. Cesar. --- xbud <[EMAIL PROTECTED]> wrote: > Actually this sounds like someone stole Litchfield's > re

[Full-Disclosure] Yahoo! Web Mail DOS

2004-08-05 Thread Cesar
Can anyone at Yahoo! with clues email me at sqlsec>athttp://promotions.yahoo.com/new_mail ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] Microsoft Windows Utility Mnanager Exploit II

2004-07-14 Thread Cesar
Bad Design + Bad Coding - QA = APMT APMT = application patched many times Cesar. __ Do you Yahoo!? Yahoo! Mail is new and improved - Check it out! http://promotions.yahoo.com/new_mail//by Cesar Cerrudo sqlsec>atNULL Sleep(

Re: [Full-Disclosure] Heap Overflow in Oracle 9iAS / 10g Application Server Web Cache

2004-04-08 Thread Cesar
Here you can see how Oracle is very serious about security and that Oracle really cares about their customers, ONE YEAR TO FIX A REMOTE VULNERABILITY!! ORACLE=UNBREAKABLE? FBI and CIA still running Oracle? ;) Cesar. --- Ioannis Migadakis <[EMAIL PROTECTED]>

Re: [Full-Disclosure] Symantec, McAfee and Panda ActiveX controls

2004-04-07 Thread Cesar
http://www.blackhat.com/presentations/win-usa-04/bh-win-04-cerrudo/bh-win-04-cerrudo.pdf BTW: ActiveX is a dangerous technology, take a look at the ActiveX you have installed, audit them and you will be afraid of what you find. Cesar. --- Thomas Kristensen <[EMAIL PROTECTED]> wrote: > Hi Rafel

Re: [Full-Disclosure] Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow

2004-02-05 Thread Cesar
I forgot, i'm serious the +60 issues are true and are not fixed yet. So if you are running Oracle database then be careful, and remember to start complaining to Oracle!!!. Cesar. --- Cesar <[EMAIL PROTECTED]> wrote: > Don't worry, Oracle sucks, probably they won't say

Re: [Full-Disclosure] Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow

2004-02-05 Thread Cesar
p of Patchset 3 (9.2.0.4). If you (all people) don't understand don't worry i also don't understand much this Oracle patch stuff:), but if you are paying to get the patches and support then it should be easy, shouldn't be? Cesar. --- Chris Anley <[EMAIL PROTECTED]

Re: [Full-Disclosure] Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow

2004-02-05 Thread Cesar
i'm curious, Why you didn't posted those advisories to public mailing lists? Cesar. --- Chris Anley <[EMAIL PROTECTED]> wrote: > Hey Cesar. > > These are known bugs. > > We (NGS) found and reported them last year. As you > say, Oracle has > alr

[Full-Disclosure] Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow

2004-02-05 Thread Cesar
Security Advisory Name: Oracle Database 9ir2 Interval Conversion Functions Buffer Overflow. System Affected : Oracle Database 9ir2, previous versions could be affected too. Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:02/05/04 Advisory Number:CC020401

[Full-Disclosure] Annoying IE bug

2003-12-10 Thread Cesar
Given that most of you like to play with IE stuff, try this: Copy and paste the next in IE addres bar, then hit Enter: javascript:open('javascript:open(location)') Nice? Cesar. __ Do you Yahoo!? New Yahoo! Photos - easier uploading and sha

[Full-Disclosure] News from the future

2003-11-08 Thread Cesar
said a Microsoft spokeman. This seems incredible? i don't think so. PS: sorry, i'm not a good writer. Cesar. __ Do you Yahoo!? Protect your identity with Yahoo! Mail AddressGuard http://antispam.yahoo.com/whatsnewfree __

Re: [Full-Disclosure] Re: Gates: 'You don't need perfect code' for good security

2003-10-31 Thread Cesar
tware is trusted, so SHUT UP. PS: Hey Bill, do you use Outlook for e-mails? I bet you use a text only e-mail client, you don't want anyone hacking you, or is your personal computer running Linux? :) Cesar. __ Do you Yahoo!? Exclusive Video Premi

[Full-Disclosure] Microsoft Local Troubleshooter ActiveX control buffer overflow

2003-10-16 Thread Cesar
Security Advisory Name: Microsoft Local Troubleshooter ActiveX control buffer overflow. System Affected : Microsoft Windows 2000 (all versions). Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:10/16/03 Advisory Number:CC100309 Legal Notice: This Advisory is

[Full-Disclosure] Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow

2003-09-23 Thread Cesar
Security Advisory Name: Microsoft Biztalk Server ISAPI HTTP Receive function buffer overflow System Affected : Microsoft BizTalk Server 2002 Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:05/05/03 Advisory Number:CC040301 Legal Notice: This Advisory is

[Full-Disclosure] Microsoft Biztalk Server DTA vulnerable to SQL injection

2003-09-23 Thread Cesar
Security Advisory Name: Microsoft Biztalk Server Document Tracking and Admnistration vulnerable to SQL injection System Affected : BizTalk Server 2000 and BizTalk Server 2002 Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:05/05/03 Advisory Number:CC040302

[Full-Disclosure] Microsoft Biztalk Server documentation and repository sites weak permissions

2003-09-18 Thread Cesar
Security Advisory Name: Microsoft Biztalk Server documentation and repository sites weak permissions. System Affected : Microsoft Biztalk Server 2000 and Microsoft Biztalk Server 2002. Severity : Medium Remote exploitable : Yes Author:Cesar Cerrudo. Date:09/18/03 Advisory Number

[Full-Disclosure] Another Yahoo! ActiveX hole

2003-09-16 Thread Cesar
Root%\Downloaded Program Files\ -Right Click on: YInstStarter Class -Left Click: Remove I thought Yahoo! was serious about security!!! Doh!!! i have Yahoo! emails accounts:) To reproduce the overflow just copy and paste the following: Cesar. __ Do you Yahoo!? Yaho

[Full-Disclosure] Yahoo! Webcam ActiveX control buffer overflow.

2003-09-16 Thread Cesar
Security Advisory Name: Yahoo! Webcam ActiveX control buffer overflow. Systems Affected : Yahoo! Messenger, Yahoo! Chat Severity : High Remote exploitable : Yes Author:Cesar Cerrudo (Cleaning Internet of dangerous ActiveX :)) Date: 09/16/03 Advisory Number:CC090307 Legal Notice

Re: [Full-Disclosure] Vulnerability Disclosure Debate

2003-08-14 Thread Cesar
There is not need for debate, just ignore OIS and do what you think is correct. Cesar. --- gridrun <[EMAIL PROTECTED]> wrote: > Vulnerability Disclosure Debate > by gridrun on 8/07/03 > > The security alliance around Microsoft is trying to > push its "reasonable

Re: SV: [Full-Disclosure] The French BUGTRAQ

2003-07-25 Thread Cesar
Here is what it looks like The Analysis of LSD's Buffer Overrun in Windows RPC Interface http://www.xfocus.org/documents/200307/2.html Cesar. --- Peter Kruse <[EMAIL PROTECTED]> wrote: > Hi, > > From the code: > RPC DCOM overflow Vulnerability discoveried by LSD >

Re: [Full-Disclosure] Does your IE6 crash with these "URLs"?

2003-07-17 Thread Cesar
It crashed my Win2K IE ver 6.0.2800.1106 Cesar. --- Martin <[EMAIL PROTECTED]> wrote: > Hi, > > I have a question. I would like to know, if you can > also crash > IE6, when typing the following "URL": > > ftp*://? > > I have also tried from HTML lik

[Full-Disclosure] Microsoft JET Database Engine 4.0 buffer overflow.

2003-07-14 Thread Cesar
Security Advisory Name: Microsoft JET Database Engine 4.0 buffer overflow. System Affected : Microsoft SQL Server 2000, SQL Server 7 & MSDE. All software using MS Jet Engine Service Pack 6 (and prior?) are vulnerable. Severity : High Remote exploitable : Yes Author:Cesar Cerrudo.

[Full-Disclosure] Trend Micro ActiveX Multiple Overflows

2003-07-11 Thread Cesar
fied by US government??? JOIN NOW AND GET A NEW Microsoft JET engine UNDISCLOSED BUG AFFECTING SQL SERVER!!! NEW SECURITY LIST!!!: For people interested in SQL Server security, vulnerabilities, SQL injection, etc. Join at: [EMAIL PROTECTED] http://groups.yahoo.com/group/sqlserversecurity/ Cesar Cerrudo.

[Full-Disclosure] Microsoft Commerce Server, SQL Server login password weak permissions

2003-07-02 Thread Cesar
Security Advisory Name: Microsoft Commerce Server, administrative SQL Server login password weak permissions. System Affected : Microsoft Commerce Server 2002 (not tested in Commerce Server 2000 but it could be vulnerable) Severity : High Remote exploitable : Yes Author:Cesar Cerrudo

RE: [Full-Disclosure] Microsoft Cries Wolf ( again )

2003-07-01 Thread Cesar
Code will always have bugs, humans are not perfect, but risks can be reduced if companies would be more "responsable" and if they would spend more time, resources, money in testing their software before releasing it. Cesar. --- Mike Fratto <[EMAIL PROTECTED]> wrote: >

Re: [Full-Disclosure] RE: [Symantec Security Advisor] Symantec Security Check ActiveX Buffer Overflow

2003-06-30 Thread Cesar
Anyone want to exploit the bug? Symantec is very happy to help attackers: http://enterprisesecurity.symantec.com/SecurityServices/content.cfm?ArticleID=682&EID=";>alert() Cesar. --- Jason Coombs <[EMAIL PROTECTED]> wrote: > Aloha, Symantec Security. > > Two q

Re: [Full-Disclosure] RE: [Symantec Security Advisor] Symantec Security Check ActiveX Buffer Overflow

2003-06-25 Thread Cesar
ck for the statement "Publisher authenticity verified by VeriSign". This statement guarantees that the control has not been tampered with since being signed by Symantec. Can Symantec define what is safe? Cesar. --- Jason Coombs <[EMAIL PROTECTED]> wrote: > Aloha, Symantec Sec

Re: [Full-Disclosure] Symantec ActiveX control buffer overflow

2003-06-24 Thread Cesar
ead by example about the 30-day grace period and all that ... It took me 1 minute to find the bug, i wonder if Symatec is a security company they should be more serious, shouldn't they?. Cesar. --- Georgi Guninski <[EMAIL PROTECTED]> wrote: > Cesar wrote: > > Vendor Status : &

Re: [Full-Disclosure] (Updated) Symantec ActiveX control buffer overflow

2003-06-23 Thread Cesar
ected : Symantec Security Check service. Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:06/23/03 Advisory Number:CC060304 Overview: Symantec has a free online service for virus and security scan called Symantec Security Check. To access this servi

[Full-Disclosure] Symantec ActiveX control buffer overflow

2003-06-22 Thread Cesar
Security Advisory Name: Symantec ActiveX control buffer overflow. Systems Affected : Symantec Security Check service. Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:06/23/03 Advisory Number:CC060304 Overview: Symantec has a free online service for virus and

Re: [Full-Disclosure] public comment period for the Draft Security Vulnerability Reporting and Responding Process (OISAFETY)

2003-06-05 Thread Cesar
Sorry, but it sucks. They forgot to add: Section 10.1 If the finder doesn't follow this, he will be prosecuted and nobody in the security community will like him. Anyone with me? Cesar. --- Craig Ozancin <[EMAIL PROTECTED]> wrote: > The Organization for Internet Safety

[Full-Disclosure] Yahoo! Audio Conferencing ActiveX control buffer overflow

2003-06-02 Thread Cesar
Security Advisory Name: Yahoo! Audio Conferencing ActiveX control buffer overflow. Systems Affected : Yahoo! Chat, Yahoo! Messanger. Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:06/01/03 Advisory Number:CC060303 Legal Notice: This Advisory is Copyright (c

[Full-Disclosure] Microsoft Biztalk Server DTA vulnerable to SQL injection

2003-05-05 Thread Cesar
Security Advisory Name: Microsoft Biztalk Server Document Tracking and Admnistration vulnerable to SQL injection System Affected : BizTalk Server 2000 and BizTalk Server 2002 Severity : High Remote exploitable : Yes Author:Cesar Cerrudo. Date:05/05/03 Advisory Number:CC040302

Re: [Full-Disclosure] Latest MS SQL Server vulnerabilities revealed.

2003-04-30 Thread Cesar
providers. Cesar. --- Michael - <[EMAIL PROTECTED]> wrote: > > After reading your papers I must say it was quite > interesting and it introduce quite a few new ideas. > However, most of them (at leat in your paper found > at > http://www.app

Re: [Full-Disclosure] FW: Security in a Connected World

2003-01-24 Thread Cesar
ducts? Because they only care were the money is. Cesar. --- Georgi Guninski <[EMAIL PROTECTED]> wrote: > For me this is pure marketing propaganda without any > confirmation from reality. > Just look at the number and severity of bugs - any > change after this hype? > From this

[Full-Disclosure] Eweek OpenHack Challenge

2002-10-24 Thread Cesar
upid challenge. Cesar. __ Do you Yahoo!? Y! Web Hosting - Let the expert host your web site http://webhosting.yahoo.com/ ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclo