[Full-Disclosure] Re: Online Script Decoder

2004-12-07 Thread Paul Szabo
GreyMagic Security [EMAIL PROTECTED] kindly made an online decoder available at http://www.greymagic.com/security/tools/decoder/ On occasions it may be more useful to have a local decoder: I often use the following perl script. Cheers, Paul Szabo - [EMAIL PROTECTED] http

[Full-Disclosure] RE: For your pleasure

2004-11-18 Thread Paul Szabo
generated with the cracked version of Sound Forge 4.5. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe

[Full-Disclosure] Eudora 6.2 attachment spoof

2004-11-13 Thread Paul Szabo
. Some cases remain un-fixed, as Eudora developers know and admit privately. One such example below. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia #!/usr/bin/perl -- use MIME::Base64

[Full-Disclosure] Windows file I/O not internationalized

2004-10-14 Thread Paul Szabo
. Is this a known bug or feature? If so, does anyone know a workaround? Otherwise, does this have security implications? Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

[Full-Disclosure] Eudora 6.2.0.7 attachment spoof

2004-10-10 Thread Paul Szabo
. Not so. Harmless demo below. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia #!/usr/bin/perl -- use MIME::Base64; print From: me\n; print To: you\n; print Subject: Eudora 6.2.0.7

[Full-Disclosure] RE: Unchecked buffer in mstask.dll

2004-07-14 Thread Paul Szabo
. Is this related to IconHandler, and is it exploitable? Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe

RE: [Full-Disclosure] How big is the danger of IE?

2004-07-08 Thread Paul Szabo
warning in http://www.kb.cert.org/vuls/id/323070 but it was toned down after the release of MS04-013.) I do not read that as advice on product choice, just a statement of the technical inadequacy of IE. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School

[Full-Disclosure] Eudora 6.1.2 attachment spoof

2004-07-06 Thread Paul Szabo
Eudora 6.1.2 for Windows was released on 21 June 2004. The release notes http://www.eudora.com/download/eudora/windows/6.1.2/RelNotes.txt say: SECURITY Fixed case where attachments could be spoofed via base64 encoded (plain-text, inline) MIME parts. Not so. Harmless demo below. Cheers, Paul

[Full-Disclosure] Eudora 6.1.1 attachment spoof, LaunchProtect

2004-05-20 Thread Paul Szabo
with LaunchProtect (the X - X.exe dichotomy issue) is not fixed either (rather it seems un-fixed). Please see http://www.maths.usyd.edu.au:8000/u/psz/securepc.html#Eudoraxx for more details and history. Harmless demo below. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u

Re: [Full-Disclosure] Gnumeric and Applix can modify locked Excel files?

2004-05-20 Thread Paul Szabo
, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] Eudora file URL buffer overflow

2004-05-06 Thread Paul Szabo
will crash Eudora.\n\n; print The following plain-text converted by Eudora into a clickable URL\n; print http://www.maths.usyd.edu.au:8000/u/psz/securepc.html#Eudoraxx\n;; print is for comparison: the user can hardly tell them apart.\n\n; Cheers, Paul Szabo - [EMAIL PROTECTED] http

RE: [Full-Disclosure] Microsoft's Explorer and Internet Explorer long share name buffer overflow.

2004-04-28 Thread Paul Szabo
this is fixed in W2kSP4; or maybe that KB article refers to a different problem: it say the error should be Access Violation, I got Program Error. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006

[Full-Disclosure] Eudora 6.1 is evil

2004-04-19 Thread Paul Szabo
=41414141 iopl=0 nv up ei ng nz ac pe cy # cs=001b ss=0023 ds=0023 es=0023 fs=0038 gs= efl=00010293 # 41414141 ?? ??? print Attachment Converted\r: , Ax300,\n\n; --- Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School

[Full-Disclosure] Eudora 6.0.3 nested MIME DoS

2004-04-13 Thread Paul Szabo
Eudora 6.0.3 for Windows will crash if sent a MIME message nested more than 2000 levels deep. Due to the presence of the [EudoraDir]\spool\*.RCV file, users may find it difficult to recover from this DoS situation. Demo below. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au

[Full-Disclosure] Eudora 6.0.3 attachment spoof, LaunchProtect

2004-03-18 Thread Paul Szabo
Eudora 6.0.3 for Windows was released recently. Though known for years, the spoofing of attachments is still not fixed; the problem with LaunchProtect is not fixed either. Spoofing demo (essentially identical to 6.0.1 version) below. Cheers, Paul Szabo - [EMAIL PROTECTED] http

Re: [Full-Disclosure] Ancient Trivia: +++ath0

2004-03-17 Thread Paul Szabo
at the end of September 1998, maybe it would be useful to look in the archives?) Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full

RE: [inbox] Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Paul Szabo
: uuencoded blocks, or those within incomplete Content-type: message/partial bits. Within those limitations, it is a great idea to keep an organization free from common attacks. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics

Re: [Full-Disclosure] Re: E-Mail viruses

2004-03-05 Thread Paul Szabo
environments. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full

Re: [Full-Disclosure] Partial Solution to SUID Problems

2003-12-06 Thread Paul Szabo
use something like that to chown or chmod the pty they just allocated. Turning the suid bit off prevents your pty from being owned by you so you cannot set safe permissions, and are vulnerable to echo badcommand yourpty. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u

Re: [Full-Disclosure] Antivirus Software Solutions?

2003-11-27 Thread Paul Szabo
want some traditional AV on your desktops; any reasonably well supported product should do. For some more blurb/details please see http://www.maths.usyd.edu.au:8000/u/psz/pc/virus.html Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics

Re: [Full-Disclosure] Potentially new Virus

2003-11-25 Thread Paul Szabo
, about 10 hours ago. The EXE seems dated 23 Nov, so this is a new virus; no wonder the AV vendors do not yet know about it; you may wish to send your sample to them for analysis. (Each new virus is an example where traditional AV fails to protect...) Cheers, Paul Szabo - [EMAIL PROTECTED] http

[Full-Disclosure] Eudora 6.0.1 LaunchProtect

2003-11-24 Thread Paul Szabo
warning. Harmless demo below. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia --- #!/usr/bin/perl -- use MIME::Base64; print From: me\n; print To: you\n; print Subject: Eudora 6.0.1

[Full-Disclosure] Eudora 6.0.1 attachment spoof

2003-11-12 Thread Paul Szabo
Eudora 6.0.1 for Windows was released recently. The buffer overflow (and code execution) with long spoofed attachment names seems to be fixed; the spoofing itself is not, though it was known for years. Spoofing demo (essentially identical to 6.0 version) below. Cheers, Paul Szabo - [EMAIL

[Full-Disclosure] MS03-048: Thor and unpatched?

2003-11-11 Thread Paul Szabo
or some joke?) Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full

[Full-Disclosure] Re: Internet Explorer and Opera local zone restriction bypass

2003-10-30 Thread Paul Szabo
(or the desktop or C:\) be patched also? Avenues of exploitation, not using Flash, will be found. Fix IE, or else. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

[Full-Disclosure] RE: Internet Explorer and Opera local zone restriction bypass

2003-10-30 Thread Paul Szabo
will just choose a different mechanism. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http

[Full-Disclosure] Re: Internet Explorer and Opera local zone restriction bypass

2003-10-25 Thread Paul Szabo
. ... I doubt we will see any malicious use of the local file redirection variation you found. My favourite store-arbitrary-local-file application is Eudora: it pre-extracts attachments into files in a known location. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz

[Full-Disclosure] Eudora 6.0 attachment spoof, exploit

2003-09-12 Thread Paul Szabo
2003. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia --- #!/usr/bin/perl -- use MIME::Base64; print From: me\n; print To: you\n; print Subject: Eudora 6.0 on Windows exploit\n; print

Re: AW: [Full-Disclosure] 9/11 virus

2003-09-11 Thread Paul Szabo
://www.maths.usyd.edu.au:8000/u/psz/securepc.html#Eudoraxx Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe

RE: [Full-Disclosure] Re: Filtering sobig with postfix

2003-08-21 Thread Paul Szabo
all might be a good thing; beware of those you let through. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe

RE: [Full-Disclosure] Administrivia: Testing Emergency Virus Filter..

2003-08-20 Thread Paul Szabo
is a perversion. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full

Re: [Full-Disclosure] f-prot not catching mimail ?

2003-08-14 Thread Paul Szabo
the HTML file it contains, that may be the result of some configuration option. By default, F-PROT only lists infected files ... But ... I did use the -LIST option, and normally (for innocent ZIP archives) I get the files listed, see below (and in my earlier post). Cheers, Paul Szabo

Re: [Full-Disclosure] New Windows worm?

2003-08-14 Thread Paul Szabo
://www.securityfocus.com/archive/1/330886 Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http

RE: [Full-Disclosure] Microsoft urging users to buy Harware Firewalls

2003-08-14 Thread Paul Szabo
, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] f-prot not catching mimail ?

2003-08-06 Thread Paul Szabo
been fixed. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full

Re: [Full-Disclosure] f-prot not catching mimail ?

2003-08-03 Thread Paul Szabo
unpack?). Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia --- $ f-prot virus/mimail -ai -archive -packed -list Virus scanning report - 4 August 2003 @ 7:26 F-PROT ANTIVIRUS Program

[Full-Disclosure] Re: [SEC-LABS] Win32 Device Drivers Communication ...

2003-08-02 Thread Paul Szabo
install) be exploited? Maybe the CON: driver where we have some control over the output? I apologize if these are stupid questions. Thanks, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

[Full-Disclosure] Acroread 5.0.7 buffer overflow

2003-07-09 Thread Paul Szabo
Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] Re: [sec-labs] Adobe Acrobat Reader =5.0.7 Buffer Overflow Vulnerability + PoC code

2003-07-07 Thread Paul Szabo
has not been specified. Do you want to configure Weblink Prefrences? I set the browser to mozilla and had no luck with the overflow... just a mozilla mail with a HUGE mail to: line. Set your browser to Netscape, not Mozilla. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au

[Full-Disclosure] Eudora 5.2.1 buffer overflow DoS

2003-06-20 Thread Paul Szabo
: Exception.log says Exception code: c005 ACCESS_VIOLATION Fault address: 77e873bc 01:63bc C:\WINNT\system32\KERNEL32.DLL Registers: EAX: EBX: ECX:00412e35 .. (only ECX seems controllable). (Tested with Eudora 5.2.1 on Windows 2000.) Cheers, Paul Szabo - [EMAIL PROTECTED] http

[Full-Disclosure] Re: -10Day CERT Advisory on PDF Files

2003-06-15 Thread Paul Szabo
, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] S-plus /tmp usage

2003-01-05 Thread Paul Szabo
+ rmdir /tmp/F$$ exec $target but Sqpe would still be open to races as it repeatedly open()s and unlink()s that file. A proper fix will have to come from the vendor. SIGNATURE Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics

[Full-Disclosure] Matlab /tmp usage

2002-12-22 Thread Paul Szabo
/$$a ! EVAL_ASSIGNS=$EVAL_ASSIGNS$lhs=''$rhs';' ;; *.c) # c source file. cfiles='1' SIGNATURE Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006

[Full-Disclosure] MS02-065 vulnerability

2002-11-22 Thread Paul Szabo
be undone by a Web page or email. Just as exploitable after the patch. Is this what Microsoft calls responsible disclosure? Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia PS: The above

[Full-Disclosure] Eudora 5.2 attachment spoof

2002-11-13 Thread Paul Szabo
what MIME boundary we use, a bare spoofed attachment line is NOT prefixed with #? Attachment Converted: c:\winnt\system32\calc.exe Never mind that the text comes out all funny... Any other tricks we can play? Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz