Re: [Full-disclosure] Hacktics Advisory Dec09: Oracle eBusiness Suite - Multiple Vulnerabilities Allow Remote Takeover

2009-12-14 Thread Freddie Vicious
, Hacktics Chairman, OWASP Israel Web: www.hacktics.com ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ -- Best wishes, Freddie

Re: [Full-disclosure] Gadi Evron: SecuriTeam: The Mossad: IE 0day for sale

2009-12-12 Thread Freddie Vicious
in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ -- Best wishes, Freddie Vicious http://twitter.com/viciousf ___ Full-Disclosure - We believe in it. Charter: http

[Full-disclosure] IE 0day for sale

2009-12-11 Thread Freddie Vicious
Hello list, I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :) -- Best wishes, Freddie Vicious http://twitter.com/viciousf ___ Full

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Freddie Vicious
Mr. Valdis Kletniesks, I'll provide proof only for serious bidders. As I said, no bullshit please. On Fri, Dec 11, 2009 at 6:38 PM, valdis.kletni...@vt.edu wrote: On Fri, 11 Dec 2009 18:23:54 +0200, Freddie Vicious said: I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6

Re: [Full-disclosure] I miss Netdev.

2009-10-18 Thread Freddie Vicious
___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ -- Best wishes, Freddie Vicious http://twitter.com/viciousf ___ Full

Re: [Full-disclosure] Remote buffer overflow in httpdx

2009-10-16 Thread Freddie Vicious
wishes, Freddie Vicious http://twitter.com/viciousf ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Remote buffer overflow in httpdx

2009-10-12 Thread Freddie Vicious
Can't reproduce it too (XPSP3 En + httpdx 1.4.0)... On Fri, Oct 9, 2009 at 8:49 AM, dr_...@hushmail.com wrote: this didn't seem to work for me. Test system XPSP3 + httpdx 1.4.0. Definitely causes a crash but the retn/offsets must not be universal? -- Best wishes, Freddie Vicious http

Re: [Full-disclosure] Exploiting memory corruption vulnerabilities on Internet Explorer 8

2009-10-03 Thread Freddie Vicious
be bypassed on x86, there's just nothing public at the moment. Cheers, SkyLined Berend-Jan Wever berendjanwe...@gmail.com http://skypher.com/SkyLined On Thu, Oct 1, 2009 at 6:44 PM, Freddie Vicious fred.vici...@gmail.comwrote: Yes, I am aware of the JVM and the Flash AVM heap spray

[Full-disclosure] Exploiting memory corruption vulnerabilities on Internet Explorer 8

2009-10-01 Thread Freddie Vicious
/exploits/8969 -- Best wishes, Freddie Vicious ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Microsuck delaying patch for SMB2 on purpose?

2009-10-01 Thread Freddie Vicious
-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ -- Best wishes, Freddie Vicious ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] Exploiting memory corruption vulnerabilities on Internet Explorer 8

2009-10-01 Thread Freddie Vicious
. Application specific techniques are also common when third party extensions are involved. -- __ Jared D. DeMott Principal Security Researcher -- Best wishes, Freddie Vicious http://twitter.com/viciousf

Re: [Full-disclosure] So weev...

2009-10-01 Thread Freddie Vicious
- ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ -- Best wishes, Freddie Vicious http://twitter.com/viciousf ___ Full-Disclosure - We believe

[Full-disclosure] For sale - Microsoft Internet Explorer 0day

2009-09-28 Thread Freddie Vicious
MS Internet Explorer 0day exploit for sale - remote code execution via memory corruption. Serious offers only - fred.vici...@gmail.com -- Best wishes, Freddie Vicious ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full