Re: [Full-disclosure] Fwd: London Autistic Rights Movement - demonstration in support of Gary McKinnon - 4pm Sunday 28th September 2008, US Embassy, Grosvenor Square, London

2008-09-25 Thread n3td3v
On Wed, Sep 24, 2008 at 5:05 PM, [EMAIL PROTECTED] wrote: On Wed, 24 Sep 2008 01:01:39 BST, n3td3v said: I'm not saying you're a secret service agent, but there is also no proof to say you aren't. Geez dude. Take your meds like you're supposed to, will ya? Robert Lemos didn't give me

[Full-disclosure] Google Docs (HTML code) Multiple Cross Site Scripting Vulnerabilities

2008-09-25 Thread Alfredo Melloni
Google Docs (HTML code) Multiple Cross Site Scripting Vulnerabilities I. Background: Google Docs is an online application which makes possibile to Create and share your work online. You can use it to create Documents, Presentations, Spreadsheets and Forms. II. Description: Multiple cross site

[Full-disclosure] Caixa Economica Federal (CEF) USERNAME BruteForce

2008-09-25 Thread Empresário TecBR
O Clube dos Macacos (CDM) orgulhosamente apresenta... .:[CEF USERNAME BruteForce]:. Como todos ja sabem, o sistema de InternetBank da Caixa Economica Federal (CEF) possui varias vulnerabilidades. Uma delas, permite que atacantes efetuem ataques do tipo BruteForce para descobrir nomes de usuario

[Full-disclosure] Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120

2008-09-25 Thread Fabian Fingerle
Cross Site Scripting (XSS) Vulnerabilitiy in flatpress 0.804, CVE-2008-4120 References http://www.datensalat.eu/~fabian/cve/CVE-2008-4120-flatpress.html http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-4120 http://www.flatpress.org/ Description FlatPress is an open-source

[Full-disclosure] [USN-645-3] Firefox and xulrunner regression

2008-09-25 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-645-3 September 25, 2008 firefox-3.0, xulrunner-1.9 regression https://launchpad.net/bugs/270429 === A security issue affects the following

[Full-disclosure] SQL Injection in EasyRealtorPRO 2008

2008-09-25 Thread SmOk3
Original article: http://www.davidsopas.com/2008/09/sql-injection-in-easyrealtorpro/ EasyRealtorPRO 2008 provides you with all features you need to setup your own business oriented real estate website on your own domain name. Our support team will install the script on your server and then you

[Full-disclosure] Worldwide SQL Protocol Advisory

2008-09-25 Thread Security Teem
+-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-++-+ TSUH-SecuritySecurity Advisory Topic: Multiple SQL Injections Announced: 2008-09-25 Credits:UberDuberHax0rx Affects:Teh Interweb I. Background TeamSuperUber

[Full-disclosure] [ GLSA 200809-17 ] Wireshark: Multiple Denials of Service

2008-09-25 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -

[Full-disclosure] [ GLSA 200809-18 ] ClamAV: Multiple Denials of Service

2008-09-25 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -

[Full-disclosure] [ GLSA 200809-16 ] Git: User-assisted execution of arbitrary code

2008-09-25 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200809-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -

[Full-disclosure] CA Service Desk Multiple Cross-Site Scripting Vulnerabilities

2008-09-25 Thread Williams, James K
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Title: CA Service Desk Multiple Cross-Site Scripting Vulnerabilities CA Advisory Date: 2008-09-24 Reported By: Open Security Foundation Impact: A remote attacker can conduct cross-site scripting attacks. Summary: CA Service Desk contains

[Full-disclosure] [USN-647-1] Thunderbird vulnerabilities

2008-09-25 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-647-1 September 26, 2008 mozilla-thunderbird, thunderbird vulnerabilities CVE-2008-3835, CVE-2008-4058, CVE-2008-4059, CVE-2008-4060, CVE-2008-4061, CVE-2008-4062, CVE-2008-4063, CVE-2008-4064,

[Full-disclosure] OFFTOPIC - moderated subset of list is back

2008-09-25 Thread moderated-security
Apologies for the off topic post. Send flames directly to me, not to full-disclosure please. For those of you like me who can't stand the incessant noise and smell of monkeys flinging poop at each other I've started running a moderated version of full-disclosure again. Currently 152 email