[Full-disclosure] [SECURITY] [DSA 2279-1] libapache2-mod-authnz-external security update

2011-07-19 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2279-1 secur...@debian.org http://www.debian.org/security/Steffen Joeris July 19, 2011

[Full-disclosure] full-disclosure@lists.grok.org.uk full-disclosure@lists.grok.org.uk,

2011-07-19 Thread cyber netron
= # Exploit Title : Neudimenxion CMS SQL Injection # Date : 17 July 2011 # Author : Netrondoank aka netron # Platform/Tested on: Linux # myweb : http://www.ilmuhacker.org # Version : none # Software Link: : http://www.neudimenxion.com/ # dork

[Full-disclosure] Neudimenxion CMS SQL Injection

2011-07-19 Thread cyber netron
= # Exploit Title : Neudimenxion CMS SQL Injection # Date : 17 July 2011 # Author : Netrondoank aka netron # Platform/Tested on: Linux # myweb : http://www.ilmuhacker.org # Version : none # Software Link: : http://www.neudimenxion.com/ # dork

[Full-disclosure] Centralia Sql Injenction

2011-07-19 Thread cyber netron
# Exploit : Centralia Sql Injenction# Date : 16 July 2011# Author : Netrondoank# Version : n/a# Googel DorK : inurl:showcat.asp?id=# Home : www.indotek.or.id# Email: edik@gmail.com ###[+] Exploit [1] Centralia (showcat.asp?/display.asp?) Sql

[Full-disclosure] Call for Papers: ICITST-2011

2011-07-19 Thread Call for papers
Apologies for cross-postings. Please send it to interested colleagues and students. Thanks! CALL FOR PAPERS *** The 6th International Conference for Internet Technology and Secured Transactions

Re: [Full-disclosure] Possible Code Execution vulnerability in WordPress ?

2011-07-19 Thread Henri Salo
On Sun, Jul 03, 2011 at 01:46:30PM +0200, Marc Manthey wrote: hello list, Sorry this is my first post to this list because i am really worried about a wordpress vulnerability and someone on this list might use wordpress aswell and could give me some advice what todo. I am using

[Full-disclosure] It's just getting worse

2011-07-19 Thread Thor (Hammer of God)
Not only was there a critical flaw in the forensic software, but after the designer reported incorrect findings, the prosecution decided to keep it a secret. http://www.msnbc.msn.com/id/43807133/ns/us_news-the_new_york_times/?GT1=43001 Pursuant to my earlier post about an encryption case,

[Full-disclosure] [SECURITY] [DSA 2280-1] libvirt security update

2011-07-19 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2280-1 secur...@debian.org http://www.debian.org/security/Steffen Joeris July 19, 2011

[Full-disclosure] innerHTML allocation size overflow crashes some browsers

2011-07-19 Thread Susam Pal
If we try to consume more memory than available by constructing a long string, most browsers seem to handle this gracefully. For example, Firefox logs an allocation size overflow error in the JavaScript console for the following code: var a = 'a' for (var i = 0; i 100; i++) { a += a }

[Full-disclosure] Hacked servers mining for bitcoins?

2011-07-19 Thread Robin
Had to deal with a server today that had been hacked (still running realVNC 4.0, so there's that lovely bypass exploit released 4 years ago). This server was an exchange/domain controller for a small business. Not much seemed to have been done to it. From the looks of it, all the attacker had

Re: [Full-disclosure] Hacked servers mining for bitcoins?

2011-07-19 Thread Zach C.
Hmm -- that's interesting. I wonder if it would be possible/feasible to build a botnet in this fashion that would overtake legitimate bitcoin nodes in terms of CPU power. (You probably know what would happen then) On Jul 19, 2011 12:11 PM, Robin ro...@rbsec.net wrote: Had to deal with a server

Re: [Full-disclosure] Hacked servers mining for bitcoins?

2011-07-19 Thread Chris M
Yes, it is well known that certain individuals are using compromised *nix servers particularly to run bitcoin miners into pools. Its only been happening for.. a long time. On Tue, Jul 19, 2011 at 8:20 PM, Zach C. fxc...@gmail.com wrote: Hmm -- that's interesting. I wonder if it would be

Re: [Full-disclosure] Hacked servers mining for bitcoins?

2011-07-19 Thread Peter Dawson
I think that Bitcoin to (linden$ ) L$ | USD is another method of morphing the economics to support real vector values. Bitcoin's design allows for pseudonymous ownership and transfers and thereby making it attractive space to begin with. Plus with an overall growth anticpated to be approx $21M,

[Full-disclosure] H2HC Brazil (Hackers 2 Hackers Conference) 8th Edition - Call for Papers

2011-07-19 Thread Rodrigo Rubira Branco (BSDaemon)
CALL FOR PAPERS - Hackers 2 Hackers Conference 8th edition The call for papers for H2HC 8th edition is now open. H2HC is a hacker conference taking place in Sao Paulo, Brazil, from 29 to 30 October 2011. [ - Introduction - ] For the eighth consecutive year and past success we have been having,

Re: [Full-disclosure] It's just getting worse

2011-07-19 Thread Jeffrey Walton
On Tue, Jul 19, 2011 at 12:14 PM, Thor (Hammer of God) t...@hammerofgod.com wrote: Not only was there a critical flaw in the forensic software, but after the designer reported incorrect findings, the prosecution decided to keep it a secret.

[Full-disclosure] Oracle Sun GlassFish Enterprise Server Stored XSS Vulnerability - Security Advisory - SOS-11-009

2011-07-19 Thread Lists
Sense of Security - Security Advisory - SOS-11-009 Release Date. 19-Jul-2011 Last Update. - Vendor Notification Date. 23-Mar-2011 Product. Oracle Sun GlassFish Enterprise Server Platform.