[Full-disclosure] [SECURITY] [DSA 2251-1] subversion security update

2011-06-02 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2251-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst June 02, 2011

Re: [Full-disclosure] What's Inside: June 22 Webcast - State of SSL on the Internet - Register Now

2011-06-02 Thread McGhee, Eddie
Hi Thor, This is what I get when I click on the link.. The link you clicked on appears to be incomplete. If the link is very long and wraps across two lines, try copying both lines, one at a time, and pasting the full link into your browser's location box. If that doesn't work, please reply

Re: [Full-disclosure] Ra-Guard evasion (new Internet-Drafts)

2011-06-02 Thread Fernando Gont
Hi, Mark, On 06/01/2011 07:57 AM, Marc Heuse wrote: this surprised me for two things. First: Cisco was not aware. I mentioned this issue to at least one guy @ PSIRT. Nevertheless, it has to tell what it takes for a vendor to be aware. I have had some experience in the past in which I

[Full-disclosure] FFFjacking

2011-06-02 Thread .cCuMiNn.
Same web browsers allow to show directory index or content of text-based file in frame, when it is loaded via FILE protokol. It enables hijacking of informations from user's local disk by dragdrop methods. I call this technique FFFjacking (File From Frame hiJacking). Combination of Windows XP and

[Full-disclosure] Multi-Tech Systems MultiModem iSMS Multiple XSS Vulnerabilities

2011-06-02 Thread Nathan Power
Check out the latest security advisory: http://www.foofus.net/?p=319 Nathan Power www.securitypentest.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

Re: [Full-disclosure] COM Server-Based Binary Planting Proof OfConcept

2011-06-02 Thread ACROS Security Lists
It would hardly be worth mentioning otherwise. Cheers, Mitja -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of Dan Kaminsky Sent: Thursday, June 02, 2011 5:36 PM To: secur...@acrossecurity.com Cc:

Re: [Full-disclosure] find11.html

2011-06-02 Thread Henri Salo
On Tue, May 31, 2011 at 01:16:48PM +1000, Daniel Hood wrote: Anyone else seen this going around? I've got a couple of links coming through for this via hacked email accounts. Looks like its installing FakeAV. Links include: www [dot] epo4 [dot] com [slash] find11.html I can't seem to

Re: [Full-disclosure] COM Server-Based Binary Planting Proof OfConcept

2011-06-02 Thread Thor (Hammer of God)
But it *is* worth mentioning that you have to create the malicious dll file, copy it to the system, create folders etc, and all the other mumbo jumbo to exploit this in the default configuration. So, the answer to Dan's question is actually, no, you can't. Which brings into question the

Re: [Full-disclosure] COM Server-Based Binary Planting ProofOfConcept

2011-06-02 Thread Mitja Kolsek
Thor, the Online Proof of Concept section of the blog post points you to a *remote* exploit (without any warning) but let me repeat the link here: http://www.binaryplanting.com/demo/XP_2-click/test.html Visit this with IE8 on 32-bit Windows XP. Please find further information here:

Re: [Full-disclosure] COM Server-Based Binary Planting ProofOfConcept

2011-06-02 Thread Mitja Kolsek
Thor, the Online Proof of Concept section of the blog post points you to a *remote* exploit (without any warning) but let me repeat the link here: http://www.binaryplanting.com/demo/XP_2-click/test.html Visit this with IE8 on 32-bit Windows XP. Please find further information here:

[Full-disclosure] New CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-06-02 Thread MustLive
Hello list! I want to warn you about security vulnerabilities in ADSL modem Callisto 821+ (SI2000 Callisto821+ Router). These are Cross-Site Request Forgery and Cross-Site Scripting vulnerabilities. Which I've found in your modem. In April I've already drew attention of Ukrtelecom's

Re: [Full-disclosure] COM Server-Based Binary Planting ProofOfConcept

2011-06-02 Thread Dan Kaminsky
Two things: 1) Are you sure a stock build of Windows doesn't pop a security warning when right clicking the file:// IFRAME? You might have munged your test OS. 2) You're getting closer with this Send To stuff, but you're still socially engineering. Definitely better than classic please download

Re: [Full-disclosure] COM Server-Based Binary Planting ProofOfConcept

2011-06-02 Thread Thor (Hammer of God)
I'll call you on that. Set it up, send it out, and show us how many people IRL you can actually get this to be exploited on. Your assumptions that the majority will fall because of inherent casualness has no basis whatsoever, and it just more blah-blah-windows-blah-blah crap from the Windows

[Full-disclosure] AST-2011-007

2011-06-02 Thread Jonathan Rose
Asterisk Project Security Advisory - AST-2011-007 ++ | Product | Asterisk |

Re: [Full-disclosure] COM Server-Based Binary Planting ProofOfConcept

2011-06-02 Thread yati sagade
Hi, Nice revelations here. what we need to understand here is that the majority of Windows users there *will* fall for the remote exploit because of their inherent casualness(some actually think that 7 is the nicest OS ever made). I appreciate the efforts taken in finding these exploits,

[Full-disclosure] What are some top universities in Europe and States for Information Security

2011-06-02 Thread persuz9213x
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello List. I need some help What are some top Universities in information security in the world? Which one is the best? preferably in the States or U.K ? I know this sounds strange since most college dropouts are historically the best hackers

Re: [Full-disclosure] What are some top universities in Europe and States for Information Security

2011-06-02 Thread Justin Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Perdue has a top notch infosec program (check out http://www.cerias.purdue.edu/) and Carnegie Mellon hosts CERT (http://www.cert.org/) and has an excellent reputation. Ross Anderson teaches at Cambridge and working with him is extremely prestigious.

[Full-disclosure] [SECURITY] [DSA 2252-1] dovecot security update

2011-06-02 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2252-1 secur...@debian.org http://www.debian.org/security/Moritz Muehlenhoff June 02, 2011

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread t0hitsugu
While I make no claims of being a security professional, the abolute best thing you can do is look into schools that will lead to the prestigious CEH certification, highly vaued in the infosec community, which will teach you to use complex tools like sqlmap, nmap, and if youre skilled enough,

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread Cal Leeming
This is a joke, right? On Thu, Jun 2, 2011 at 11:29 PM, t0hitsugu tohits...@gmail.com wrote: While I make no claims of being a security professional, the abolute best thing you can do is look into schools that will lead to the prestigious CEH certification, highly vaued in the infosec

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread Benji
Wowa wowa steady there. Only nmap has a GUI and CLI is a bit eleet for full disclosure at this stage. We should probably be suggesting he take some of the blackhat courses offered at BlackHat HQ, the only real con with real hackers who hack and find xss. (tm) On Thu, Jun 2, 2011 at 11:29 PM,

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread Paul Heinlein
On Thu, 2 Jun 2011, Benji wrote: Wowa wowa steady there. Only nmap has a GUI and CLI is a bit eleet for full disclosure at this stage. We should probably be suggesting he take some of the blackhat courses offered at BlackHat HQ, the only real con with real hackers who hack and find xss.

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread Cal Leeming
Well.. that cleared that up, then. lol. On Thu, Jun 2, 2011 at 11:35 PM, Benji m...@b3nji.com wrote: Wowa wowa steady there. Only nmap has a GUI and CLI is a bit eleet for full disclosure at this stage. We should probably be suggesting he take some of the blackhat courses offered at BlackHat

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread Christian Sciberras
I thought you'd say Supreme Court Jester, for some reason or another. Chris. On Fri, Jun 3, 2011 at 12:39 AM, Paul Heinlein heinl...@madboa.com wrote: On Thu, 2 Jun 2011, Benji wrote: Wowa wowa steady there. Only nmap has a GUI and CLI is a bit eleet for full disclosure at this stage.

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread Benji
This caught my eye, maybe our friend can get some free online training from the gurus at sensepost https://twitter.com/sensepost/status/74049270814212097 On Thu, Jun 2, 2011 at 11:47 PM, Christian Sciberras uuf6...@gmail.comwrote: I thought you'd say Supreme Court Jester, for some reason or

Re: [Full-disclosure] COM Server-Based Binary Planting ProofOfConcept

2011-06-02 Thread Mitja Kolsek
Dan, 1) Are you sure a stock build of Windows doesn't pop a security warning when right clicking the file:// IFRAME? You might have munged your test OS. IE allows you to right-click on a folder (but not on a file or on the background) inside a file:// iframe without popping up a security

Re: [Full-disclosure] What are some top universities in Europe and States for Information Security

2011-06-02 Thread Jeffrey Walton
On Thu, Jun 2, 2011 at 12:22 PM, persuz92...@hush.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello List. I need some help What are some top Universities in information security in the world? Which one is the best?  preferably in the States or U.K ? I know this sounds

Re: [Full-disclosure] What are some of the top ...

2011-06-02 Thread t0hitsugu
You are correct; a *true* professional knows to use Cain and Able (but thats not something you'll learn at school) On Jun 2, 2011 3:33 PM, Cal Leeming c...@foxwhisper.co.uk wrote: This is a joke, right? On Thu, Jun 2, 2011 at 11:29 PM, t0hitsugu tohits...@gmail.com wrote: While I make no

[Full-disclosure] VMSA-2011-0009 VMware hosted product updates, ESX patches and VI , Client update resolve multiple security issues

2011-06-02 Thread VMware Security Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID:VMSA-2011-0009 Synopsis: VMware hosted product updates, ESX patches and VI Client update