Re: [Full-Disclosure] Internet Explorer valid JavaScript-file successfull load detection local file enumeration

2005-01-14 Thread Tom Koehler
Hi Berend-Jan, Tested with FireFox 1.0 (german) on Win2k (german fully patched): The script couldn't find my SysPath. IE could Have nice WE tom -- +++ Sparen Sie mit GMX DSL +++ http://www.gmx.net/de/go/dsl AKTION für Wechsler: DSL-Tarife ab 3,99 EUR/Monat + Startguthaben

RE:[Full-Disclosure] Animated Cursor Blue Screen?

2005-01-06 Thread Tom Koehler
Hi Nick, looks like 'Microsoft Windows Kernel ANI File Parsing Crash and DOS Vulnerability' for details see: http://www.securityfocus.com/archive/1/385340/2004-12-18/2004-12-24/0 hth tom -- +++ Sparen Sie mit GMX DSL +++ http://www.gmx.net/de/go/dsl AKTION für Wechsler: DSL-Tarife ab 3,99

Re: [Full-Disclosure] removing sasser

2004-05-12 Thread Tom Koehler
On 12 May 2004 at 1:22, Marcel Krause wrote: Hi Marcel Is ther a way to remove Sasser without downloading a full av-software? try mcaffee's stinger http://vil.nai.com/vil/stinger HtH tom -- NEU : GMX Internet.FreeDSL Ab sofort DSL-Tarif ohne Grundgebühr: http://www.gmx.net/dsl

[Full-Disclosure] RE: Windows XP explorer.exe heap overflow

2004-02-24 Thread Tom Koehler
WinXP SP1 (fully patched) german is vuln to AN00010_.wmf explorer.exe hogs 100% cpu speed. tom -- GMX ProMail (250 MB Mailbox, 50 FreeSMS, Virenschutz, 2,99 EUR/Monat...) jetzt 3 Monate GRATIS + 3x DER SPIEGEL +++ http://www.gmx.net/derspiegel +++

[Full-Disclosure] Windows 98 vulnerable to ASN.1

2004-02-20 Thread Tom Koehler
Hello List, i fixed the Win98 systems fine, renaming the dll and there were no problems even on production system (programming, database etc). Thanks Dan But i have two benighted lusers on Win Me and the msasn1.dll is obviously in use. Any ideas how to secure Win Me would be appreciated. Thanks

RE:[Full-Disclosure] http://federalpolice.com:article872@1075686747

2004-02-16 Thread Tom Koehler
Yes I got one too. I went to the site (under Linux) and it tries to download a file javautil.z1p (You know what extension) which is actualy an exe. Haven't found what it does yet but uses kerne32 and the routine GetProcAdress. Anyone?? greets tom I have been getting the below mail from numerous

Re:[Full-Disclosure] stcloader.exe / slmss.exe ??

2003-10-31 Thread Tom Koehler
James Bruce wrote Anyone seeing this file stcloader.exe (Nortons does not detect) downloading a slmss.exe file (which nortons detects as Downloader. Trojan) I just had 3 computers with it all around the same time. Stcloader.exe is the run part of the registry and in the system32 directory. After

Re:[Full-Disclosure] The msvidctl.dll in Windows XP

2003-10-09 Thread Tom Koehler
Hi Richard, On my Windows XP laptop, I found a large number of ActiveX controls in the system file msvidctl.dll which are marked safe for scripting. I've attached a list of the controls in this DLL. I'm really curious why this DLL is installed on my system in the first place since the laptop

Re:[Full-Disclosure] curious email

2003-08-15 Thread Tom Koehler
I see quite a lot of stuff like that coming at our mail system. I believe its called the nigera connection. The various storys have gained cult status in germany (http://www.nigeria-connection.de sorry page in german). The last one I remember is from last week supposedly coming from swizterland