[Full-disclosure] Nikto 2.1.0 released

2009-10-18 Thread david lodge
It's final time to stop procrastinating: Nikto 2.1.0 is here! (Available from http://cirt.net/nikto2) This version has gone through significant rewrites under the hood to how Nikto works, to make it more expandable and usable. Changes include: * Rewrite to the plugin engine allowing more control

Re: [Full-disclosure] I miss Netdev.

2009-10-18 Thread Freddie Vicious
That's lame... I don't think anyone miss n3td3v. On Fri, Oct 16, 2009 at 7:03 AM, Steven James vomithatst...@yahoo.comwrote: Awww... My self esteem. :,( Message: 14 Date: Thu, 15 Oct 2009 07:00:40 -0400 From: McGhee, Eddie eddie.mcg...@ncr.com Subject: Re: [Full-disclosure] I miss

[Full-disclosure] insecure elements in https protected pages

2009-10-18 Thread Mohammad Hosein
in a certain web application e.g gmail there are times the whole communication is secured by ssl and sometimes there are insecure elements that raise questions . i'm not a web professional . how to find these insecure elements ? and how to evaluate if these elements are the results of a successful

Re: [Full-disclosure] insecure elements in https protected pages

2009-10-18 Thread G. D. Fuego
On Oct 18, 2009, at 6:03 PM, Mohammad Hosein mhta...@gmail.com wrote: in a certain web application e.g gmail there are times the whole communication is secured by ssl and sometimes there are insecure elements that raise questions . i'm not a web professional . how to find these insecure

[Full-disclosure] In-depth research on the recent PDF zero-day exploit (CVE-2009-3459)

2009-10-18 Thread cocoruder
Hi there, Just want to let you know, the Fortinet's FortiGuard Global Security Research Team has provided an in-depth research on the recent PDF zero-day exploit (CVE-2009-3459). http://www.fortiguard.com/analysis/pdfanalysis.html Taking a look back over this 0-day attack as a whole, each