[Full-disclosure] Cisco Unified Operations Manager Multiple Vulnerabilities - SOS-11-006

2011-05-18 Thread Lists
Sense of Security - Security Advisory - SOS-11-006 Release Date. 18-May-2011 Last Update. - Vendor Notification Date. 28-Feb-2011 Product. Cisco Unified Operations Manager Common Services Framework Help

[Full-disclosure] Governments Websites Pwned !!

2011-05-18 Thread aryan hacky
_ _ _ ___ _ _ / \ _ __ | |_(_)|_ _|_ __ | |_ _ __ _ _ __| | ___ _ __ ___ / _ \ | '_ \| __| |_| || '_ \| __| '__| | | |/ _` |/ _ \ '__/ __| / ___ \| | | | |_| |_| || | | | |_| | | |_| | (_| | __/ | \__ \ /_/ \_\_| |_|\__|_|

[Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread tehseen sagar
Greetings, I would like to know is there any local root exploit exist for linux kernel 2011 . I have seen such video on securitytube and youtube . I wonder is there any POC so such thing available so I can analyze and test it in my lab environment . Looking forward for your kind

[Full-disclosure] XSS vulnerability in TWiki 5.0.2

2011-05-18 Thread Netsparker Advisories
Information --- Name : XSS vulnerability in TWiki Software : TWiki 5.0.1 and possibily below. Vendor Hompeage : http://twiki.org/ Vulnerability Type : Cross-Site Scripting Severity : High Researcher : Mesut Timur mesut [at] mavitunasecurity [dot] com Advisory

[Full-disclosure] SUSE Security Announcement: flash-player (SUSE-SA:2011:025)

2011-05-18 Thread Thomas Biege
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 __ SUSE Security Announcement Package:flash-player Announcement ID:SUSE-SA:2011:025 Date:

[Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Joxean Koret
Sorry men, there is no exploit for Linux Kernel(TM) 2011. But you have exploits for Linux XP. I would like to know is there any local root exploit exist for linux kernel 2011 . signature.asc Description: This is a digitally signed message part ___

[Full-disclosure] Vivek's latest wireless challange - $50 up for grabs

2011-05-18 Thread corpus.defero
http://www.securitytube.net/video/1884 Just posted ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Governments Websites Pwned !!

2011-05-18 Thread Cal Leeming
Welcome to 101 of stay out of jail.. Todays topic is: How not to piss off the govt. :| On Wed, May 18, 2011 at 8:54 AM, aryan hacky aryan.ha...@gmail.com wrote: _ _ _ ___ _ _ / \ _ __ | |_(_)|_ _|_ __ | |_ _ __ _ _ __| | ___ _ __ ___

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Cal Leeming
linux kernel 2011?? what the fuck are you talking about? On Wed, May 18, 2011 at 10:41 AM, Joxean Koret joxeanko...@yahoo.es wrote: Sorry men, there is no exploit for Linux Kernel(TM) 2011. But you have exploits for Linux XP. I would like to know is there any local root exploit exist for

[Full-disclosure] [ MDVSA-2011:091 ] perl

2011-05-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:091 http://www.mandriva.com/security/

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Paul Heinlein
On Wed, 18 May 2011, Joxean Koret wrote: Sorry men, there is no exploit for Linux Kernel(TM) 2011. But you have exploits for Linux XP. This is so true, and it's maddening because those same exploits were also present in Linux OS 9. You won't have to dig hard to find them. I would like to

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread phocean
On Wed, 18 May 2011 07:04:32 -0700 (PDT), Paul Heinlein wrote: On Wed, 18 May 2011, Joxean Koret wrote: Sorry men, there is no exploit for Linux Kernel(TM) 2011. But you have exploits for Linux XP. This is so true, and it's maddening because those same exploits were also present in Linux

[Full-disclosure] [ MDVSA-2011:092 ] perl-IO-Socket-SSL

2011-05-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:092 http://www.mandriva.com/security/

Re: [Full-disclosure] Cisco Unified Operations Manager Multiple Vulnerabilities - SOS-11-006

2011-05-18 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Hello, This is the Cisco PSIRT response to the vulnerabilities that were discovered and reported to Cisco Systems by Brett Gervasoni of Sense of Security, regarding multiple vulnerabilities in Cisco Unified Operations Manager (CuOM). We greatly

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread John Jacobs
Apologies in advance for thread-jacking but does someone happen to have a spare GNU/Linux CD-Key for sale?  I'm having some issues with Linux Genuine Advantage for Linux Kernel 2011 Home Edition.  I did recently change my motherboard and evidently it was an OEM license and LGA went crazy.

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Joxean Koret
But they don't work if EMET for Linux OS 9 is installed. El mié, 18-05-2011 a las 07:04 -0700, Paul Heinlein escribió: This is so true, and it's maddening because those same exploits were also present in Linux OS 9. You won't have to dig hard to find them. signature.asc Description: This is

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Mario Vilas
Hi, just a quick question, do those exploits you mention work in a jailbroken device? I'm running Linux Leopard lOS 4.3 on my iAndroid tablet. On Wed, May 18, 2011 at 11:41 AM, Joxean Koret joxeanko...@yahoo.es wrote: Sorry men, there is no exploit for Linux Kernel(TM) 2011. But you have

[Full-disclosure] DOMinator - The DOMXss Analyzer Tool - is finally public

2011-05-18 Thread Stefano Di Paola
What is DOMinator? DOMinator is a Firefox based software for analysis and identification of DOM Based Cross Site Scripting issues (DOMXss). It is the first runtime tool which can help security testers to identify DOMXss. How it works? It uses dynamic runtime tainting model on strings and can

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread root
You can only jailbreak FreeBSD devices. On 05/18/2011 01:37 PM, Mario Vilas wrote: Hi, just a quick question, do those exploits you mention work in a jailbroken device? I'm running Linux Leopard lOS 4.3 on my iAndroid tablet. On Wed, May 18, 2011 at 11:41 AM, Joxean Koret

[Full-disclosure] [ MDVSA-2011:093 ] gnome-screensaver

2011-05-18 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:093 http://www.mandriva.com/security/

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Stephen
This made my morning :D On 18/05/11 19:11, Joxean Koret wrote: Sorry men, there is no exploit for Linux Kernel(TM) 2011. But you have exploits for Linux XP. I would like to know is there any local root exploit exist for linux kernel 2011 . ___

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread Kevin Wilcox
On Wed, May 18, 2011 at 13:59, root ro...@fibertel.com.ar wrote: You can only jailbreak FreeBSD devices. FreeBSD is dead. Netcraft confirms it. kmw ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Governments Websites Pwned !!

2011-05-18 Thread tc
Didn't you already fael that class Cal? On Wed, May 18, 2011 at 6:03 PM, Cal Leeming c...@foxwhisper.co.uk wrote: Welcome to 101 of stay out of jail.. Todays topic is: How not to piss off the govt. :| On Wed, May 18, 2011 at 8:54 AM, aryan hacky aryan.ha...@gmail.com wrote: _

Re: [Full-disclosure] DOMinator - The DOMXss Analyzer Tool - is finally public

2011-05-18 Thread IEhrepus
hi DOMinator can't work on firefox 3.6.17? hitest 2011/5/18 Stefano Di Paola wi...@wisec.it What is DOMinator? DOMinator is a Firefox based software for analysis and identification of DOM Based Cross Site Scripting issues (DOMXss). It is the first runtime tool which can help security

Re: [Full-disclosure] DOMinator - The DOMXss Analyzer Tool - is finally public

2011-05-18 Thread Stefano Di Paola
Hey IEhrepus Il giorno mer, 18/05/2011 alle 20.34 -0700, IEhrepus ha scritto: DOMinator can't work on firefox 3.6.17? DOMinator consists in a core and an extension. The core is Firefox with some custom c/c++ code in order to add taint flag to JSStrings and deal with taint propagation. So,

Re: [Full-disclosure] Linux kernel 2011 local root does it exist

2011-05-18 Thread gold flake
As long as there are postmen and this stratospheric level of discussion on FD, there is zest in life. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -