Re: CORE-2009-01515 - WordPress Privileges Unchecked in admin.php and Multiple Information

2015-08-19 Thread paul . szabo
Is that issue related? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Mathematica10.0.0 on Linux /tmp/MathLink vulnerability

2014-08-27 Thread paul . szabo
The problem reported for Mathematica is present still at version 10.0.0 for the GUI interface (the command-line interface may be safe). Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Mathematica9.0.1 on Linux /tmp/MathLink vulnerability

2013-02-08 Thread paul . szabo
The problem reported for Mathematica is present still at version 9.0.1, both for the GUI and for the command-line interface. Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia --- http

utempter allows fake host setting

2012-10-09 Thread paul . szabo
utempter add checking who psz pts/29 Oct 4 11:48 (xyz) r00t pts/0Jan 1 01:02 (xyz.com) doing utempter del checking who DONE psz@bari:~$ Please see also: http://bugs.debian.org/329156 http://bugs.debian.org/330907 Cheers, Paul Paul Szabo p

Re: Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

2012-04-17 Thread paul . szabo
will need to be implemented by Wolfram. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

2012-04-16 Thread paul . szabo
The problem reported for Mathematica became worse at version 8.0.4, present for the command-line interface math also. Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia --- http

XSS in Oracle default fcgi-bin/echo

2011-03-23 Thread paul . szabo
. Another interesting reference: http://www.thisisahmed.com/tia/ohs/ohshardening.html Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Mathematica8 on Linux /tmp/MathLink vulnerability

2011-01-04 Thread paul . szabo
The problem that was reported as below for Mathematica7, is present also/still in (the free trial version of) Mathematica8. Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia --- I wrote

Re: RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

2010-10-19 Thread paul . szabo
Dear An, Referrer: scriptalert(1)/script Yes, but... seems not all echo's get a Referer passed to them. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

2010-10-19 Thread paul . szabo
-bin/echo that I tested, were already patched against the one you mention, but vulnerable to that other I found.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

2010-10-15 Thread paul . szabo
wrong assumptions, and jump to conclusions: - Not anyone, but bona-fide ones only. - I do not own an Oracle site to test. Were not those obvious to right-thinking people? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

2010-10-15 Thread paul . szabo
not own an over-inflated ego. ... or simply send the code to Oracle and ask them ... Sorry to blow your assumption: sent to Oracle, ages ago, first thing. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University

Re: XSS in Oracle default fcgi-bin/echo

2010-10-13 Thread paul . szabo
off-list so I can provide PoC? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

XSS in Oracle default fcgi-bin/echo

2010-10-08 Thread paul . szabo
://download.oracle.com/docs/cd/B14099_19/core.1012/b13999/checklist.htm#BABIBCIC Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Ghostscript 8.64 executes random code at startup

2010-05-31 Thread paul . szabo
or /usr/bin/ps2ascii . Also, crappy coding for GS_EXECUTABLE=gs. Am not sure if these are originally gs or Debian special. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Ghostscript 8.64 executes random code at startup

2010-05-28 Thread paul . szabo
, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Ghostscript 8.64 executes random code at startup

2010-05-27 Thread paul . szabo
: chdir(/tmp/) execve(..., gs, ... -dSAFER, ... any.ps, ...) So gv is careful to use -dSAFER but does not know about -P-. I notified bug...@gnu.org about this, see http://bugs.debian.org/583316 also. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Re: Ghostscript 8.64 executes random code at startup

2010-05-26 Thread paul . szabo
./Encoding is not enough. Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Ghostscript 8.64 executes random code at startup

2010-05-26 Thread paul . szabo
Dear Krzysztof, ... it is dangerous to do cd /tmp; gs any.ps What is in the file any.ps? You are exposed ... without feeding *anything* to Ghostscript ... Yes, precisely: that is why I called it any.ps. Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u

Mathematica on Linux /tmp/MathLink vulnerability

2010-05-14 Thread paul . szabo
of pretty interface. Notified supp...@wolfram.com on 7 May 2010, was assigned [TS 16194]. Cheers, Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Samba Remote Zero-Day Exploit

2010-02-08 Thread paul . szabo
into a path ... I never noticed such support documented: references please? ... and it really does need to keep him there. You cannot break out of shares with wide links = no. ... Samba is supposed to match Windows semantics in general. No please, do not dumb it down. Cheers, Paul Paul Szabo p

Re: Samba Remote Zero-Day Exploit

2010-02-08 Thread paul . szabo
to the whole filesystem (where the user has UNIX rights). I also wonder about the interaction with the setting of unix extensions (which I had set to non-default no to help Mac clients). Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics

Re: [Full-disclosure] Samba Remote Zero-Day Exploit

2010-02-08 Thread paul . szabo
installation, as per default, is not vulnerable. - Several distributions run with vulnerable settings per default if there is a misconfiguration it is part of the vendor. Is that vendor Samba? Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Re: Samba Remote Zero-Day Exploit

2010-02-08 Thread paul . szabo
be useful... would surely be a few lines of code only, so if you want to submit a patch to the Samba team... or just patch your own servers (as I do, see http://www.maths.usyd.edu.au/u/psz/samba/). Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School

Re: Samba Remote Zero-Day Exploit

2010-02-08 Thread paul . szabo
] are provided for ease of use, users are encouraged to create symlinks to other interesting places e.g. NFS-mounted directories.) Cheers, Paul Paul Szabo p...@maths.usyd.edu.au http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

/bin/login gives root to group utmp

2008-12-01 Thread Paul Szabo
, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability

2008-05-19 Thread Paul Szabo
... There is no problem to trick the victim and force him to change the encoding of his browser by little social engineering. See https://bugzilla.mozilla.org/show_bug.cgi?id=408457 about how this can be better exploited. Cheers, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School

/bin/ls with gid=0 in Debian linux-ftpd

2007-02-21 Thread Paul Szabo
into running anything, nor are there any interesting objects thusly accessible. Would become a root hole if someone finds a way to execute anything from /bin/ls (as started from ftpd). Please see http://bugs.debian.org/384454 for details. Cheers, Paul Szabo [EMAIL PROTECTED] http

Re: [Full-disclosure] Firefox focus stealing vulnerability (possibly other browsers)

2007-02-12 Thread Paul Szabo
https://bugzilla.mozilla.org/show_bug.cgi?id=258875 and further references therein. Cheers, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: [Full-disclosure] IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])

2006-10-03 Thread Paul Szabo
and every webpage... Cheers, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: [Full-disclosure] IE UXSS (Universal XSS in IE, was Re: Microsoft Internet Information Services UTF-7 XSS Vulnerability [MS06-053])

2006-10-03 Thread Paul Szabo
Seems that I was wrong and Brian Eaton [EMAIL PROTECTED] was right: default apache installations seem to return an explicit charset in their error message. (Now I cannot explain how I convinced myself otherwise.) Then there is no Universal XSS against default Apache webservers... Cheers, Paul

Re: Browser bugs hit IE, Firefox today (SANS)

2006-07-05 Thread Paul Szabo
of the through the frames collection will give you a reference to the document object inside the thirdparty domain ... Sorry, but I cannot follow. Could you please show an example? Thanks, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics

Re: Vm ware 0day dos exploit by n00b.

2006-06-20 Thread Paul Szabo
execution (shellcode in that name, for VMware on UNIX where bits of it run as root)? Cheers, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Re: Internet Explorer Phishing mouseover issue

2006-02-18 Thread Paul Szabo
Restricted Zone Status Bar Spoofing http://secunia.com/advisories/11273/ (known, unpatched, since 2004). Cheers, Paul Szabo [EMAIL PROTECTED] http://www.maths.usyd.edu.au/u/psz/ School of Mathematics and Statistics University of SydneyAustralia

Acroread 5.0.7 buffer overflow

2003-07-10 Thread Paul Szabo
Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

Re: Eudora 5.2.1 attachment spoof

2003-05-27 Thread Paul Szabo
. Tested with Eudora 5.2.1 on Windows 2000. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

S-plus /tmp usage

2003-01-06 Thread Paul Szabo
+ rmdir /tmp/F$$ exec $target but Sqpe would still be open to races as it repeatedly open()s and unlink()s that file. A proper fix will have to come from the vendor. SIGNATURE Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics

Re: d_path() truncating excessive long path name vulnerability

2002-11-28 Thread Paul Szabo
nothing relevant in the Changelogs at http://www.kernel.org/ . Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

Eudora 5.2 attachment spoof

2002-11-13 Thread Paul Szabo
what MIME boundary we use, a bare spoofed attachment line is NOT prefixed with #? Attachment Converted: c:\winnt\system32\calc.exe Never mind that the text comes out all funny... Any other tricks we can play? Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz

Re: Compaq mount patch broken

2002-09-04 Thread Paul Szabo
. This problem was caused by me attempting to install the latest security patch by hand, without the required megapatch. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

[Full-Disclosure] Compaq mount patch broken

2002-09-03 Thread Paul Szabo
puzzled: why patch /sbin/mount or /usr/bin/csh if they are not setuid? Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia ___ Full-Disclosure - We

Eudora attachment spoof

2002-08-08 Thread Paul Szabo
-ascii Content-Transfer-Encoding: base64 SGVsbG8Kc3RyYW5nZXIK --- Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

Re: Acrobat reader 5.05 temp file insecurity

2002-07-04 Thread Paul Szabo
still be vulnerable. I have no Mac to test.) (See also http://www.securityfocus.com/bid/3225 .) Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics and Statistics University of Sydney 2006 Australia

RE: More Office XP problems

2002-04-08 Thread Paul Szabo
: http://www.microsoft.com/technet/security/bulletin/ms01-028.asp Malformed RTF Control Word: http://www.microsoft.com/technet/security/bulletin/ms00-005.asp installed. Cheers, Paul Szabo - [EMAIL PROTECTED] http://www.maths.usyd.edu.au:8000/u/psz/ School of Mathematics

Announcing ptyfix

2001-05-01 Thread Paul Szabo
only on Compaq Tru64 UNIX (DEC OSF/1) machines. Please feel free to adapt this software to other operating systems. The ptyfix package is available from http://www.maths.usyd.edu.au:8000/u/psz/securedu.html#xterm or http://www.maths.usyd.edu.au:8000/u/psz/du/ptyfix.tgz Paul Szabo - [EMAIL PROTECTED