[Full-Disclosure] Advisory 07/2004: CVS remote vulnerability

2004-05-19 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 e-matters GmbH www.e-matters.de -= Security Advisory =- Advisory: CVS remote vulnerability Release Date: 2004/05/19 Last Modified: 2004/05/19 Author: Stefan

[Full-Disclosure] Advisory 06/2004: libneon date parsing vulnerability

2004-05-19 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 e-matters GmbH www.e-matters.de -= Security Advisory =- Advisory: libneon date parsing vulnerability Release Date: 2004/05/19 Last Modified: 2004/05/19

Re: [Full-Disclosure] Slowly down the drain

2004-05-19 Thread Jason Coombs
Aloha, Paul. The list will pick up when there isn't so much competition for people's limited bad news attention span. Real fear gets in the way of meaningful work (and discussion) -- we need a happy middle ground where there's just the right amount of fear but enough optimism to provide us

[Full-Disclosure] Advisory 08/2004: Subversion remote vulnerability

2004-05-19 Thread Stefan Esser
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 e-matters GmbH www.e-matters.de -= Security Advisory =- Advisory: Subversion remote vulnerability Release Date: 2004/05/19 Last Modified: 2004/05/19 Author:

[Full-Disclosure] [SECURITY] [DSA 505-1] New cvs packages fix remote exploit

2004-05-19 Thread debian-security-announce
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 505-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze May 19th, 2004

[Full-Disclosure] [SECURITY] [DSA 506-1] New neon packages fix buffer overflow

2004-05-19 Thread debian-security-announce
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 506-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze May 19th, 2004

[Full-Disclosure] FreeBSD Security Advisory FreeBSD-SA-04:10.cvs

2004-05-19 Thread FreeBSD Security Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 = FreeBSD-SA-04:10.cvsSecurity Advisory The FreeBSD Project Topic:

[Full-Disclosure] SUSE Security Announcement: cvs (SuSE-SA:2004:013)

2004-05-19 Thread Sebastian Krahmer
-BEGIN PGP SIGNED MESSAGE- __ SUSE Security Announcement Package:cvs Announcement-ID:SuSE-SA:2004:013 Date: Wed May 19

[Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread A.H.
By Jesper M. Johansson, Ph.D., CISSP, MCSE, MCP+I Security Program Manager Microsoft Corporation: You cant clean a compromised system by using some vulnerability remover. Lets say you had a system hit by Blaster. A number of vendors (including Microsoft) published vulnerability removers for

[Full-Disclosure] [SECURITY] [DSA 507-1] New cadaver packages fix buffer overflow

2004-05-19 Thread debian-security-announce
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 507-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze May 19th, 2004

[Full-Disclosure] Re: Buffer Overflow in ActivePerl ?

2004-05-19 Thread Curt Sampson
On Wed, 19 May 2004, Nick FitzGerald wrote: However, there is not likely to be a privilege escalation here unless perhaps a script processor on a web server can be cajoled into doing something with this? Not terribly likely; system() in perl forks a new process, potentially executing a

[Full-Disclosure] [ GLSA 200405-09 ] ProFTPD Access Control List bypass vulnerability

2004-05-19 Thread Kurt Lieber
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200405-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread Paul Fraser
And written by a Microsoft employee, to boot. On Wed, 19 May 2004 10:26 pm, Troels Bay wrote: Wow, that's pretty amazing. Now one can't trust somewhat 50% of all Microsoft Computers. That's rather fun, wouldn't you say? On May 19, 2004, at 14:11, A.H. wrote: By Jesper M. Johansson,

Re: [Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread Troels Bay
Wow, that's pretty amazing. Now one can't trust somewhat 50% of all Microsoft Computers. That's rather fun, wouldn't you say? On May 19, 2004, at 14:11, A.H. wrote: By Jesper M. Johansson, Ph.D., CISSP, MCSE, MCP+I Security Program Manager Microsoft Corporation: You cant clean a compromised system

Re: [Full-Disclosure] Strange ldap Behavior.

2004-05-19 Thread Aaron Gee-Clough
stephane nasdrovisky wrote: Soderland, Craig wrote: ETHER: Destination = 0:0:5e:0:1:1, U.S. Department of Defense This mac looks familiar for me,isn't it the mac address used by vrrp ID 1? Isn't your default gateway a nokia firewall (or was,in which case you should reconfigure some

Re: [Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread Dave Howe
Troels Bay wrote: Now one can't trust somewhat 50% of all Microsoft Computers. you trusted that many before? :) Honestly though, it isn't a total writeoff. Your data may well have been compromised - so you need to run a validation exercise after copying to a clean system but before even

Re: [Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread Troels Bay
[warning, rather offtopic] No I really didn't, I'm not a windows-user. I escaped from that nightmare some months ago, and getting fonder and fonder of it every day. One day I happened to surf some pretty nasty sites, and then I found out how easy it is to compromise a windows-computer remotely.

Re: [Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread Harlan Carvey
I have to apologize, as I didn't see the original post in my inbox...could someone forward it to me? Now one can't trust somewhat 50% of all Microsoft Computers. you trusted that many before? :) Honestly though, it isn't a total writeoff. Your data may well have been compromised - so

[Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread Jianqiang Xin
hi, all: In our research project, we need to generate background traffic. One of the problem is how to use one or two machines to simulate hundreds of machines? Is there any open source project for this? Thanks very much for your help. By the way, does anyone happen to know any good project

Re: [Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread Maxime Ducharme
Hi, I suggest netwox from Laurent Constantin : http://www.laurentconstantin.com/en/netw/netwox/ for virtual machines take a look at option 80 on the options list : http://www.laurentconstantin.com/common/netw/netwox/download/v5/toollist.txt I'd spawn as many netwox processes as needed. I

[Full-Disclosure] Ph0rum phorum_uriauth replay attack

2004-05-19 Thread Konstantin Gavrilenko
Arhont Ltd.- Information Security Arhont Advisory by: Konstantin Gavrilenko (http://www.arhont.com) Advisory: Ph0rum phorum_uriauth replay attack Class: design bug ? Version:4.3.7 Model Specific: Other version might have the same bug

RE: [Full-Disclosure] Agobot author is a pacifist?

2004-05-19 Thread Aditya, ALD [Aditya Lalit Deshmukh]
Hmmm...compulsory national service...what a cheap way of getting a labour force. I'm mixed on my views on this - on the one hand having this labour force is a good thing, and a younger me could have definately done with having some discipline and structure, but then again reports of

Re: [Full-Disclosure] Slowly down the drain

2004-05-19 Thread Calum
On Tuesday 18 May 2004 15:41, Paul Schmehl wrote: Am I the only one who thinks that this list is slowly descending into complete worthlessness? It's amazing. The kiddies tried to destroy it early on and failed. So then the members of the list did the job for them. Worthless topic after

Re: [Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread p00p
On Wed, May 19, 2004 at 09:38:23AM -0500, Jianqiang Xin wrote: hi, all: In our research project, we need to generate background traffic. One of the problem is how to use one or two machines to simulate hundreds of machines? Is there any open source project for this? I don't know much about

Re: [Full-Disclosure] Strange ldap Behavior.

2004-05-19 Thread Valdis . Kletnieks
On Wed, 19 May 2004 09:10:19 EDT, Aaron Gee-Clough said: Yes, it is a VRRP address. The RFC for VRRP (at http://www.faqs.org/rfcs/rfc2338.html ) says: The virtual router MAC address associated with a virtual router is an IEEE 802 MAC Address in the following format:

Re: [Full-Disclosure] Slowly down the drain

2004-05-19 Thread Paolo Mattiangeli
Since I've signed up, I've ended up deleting massive threads. For example, the send money to the Sasser author one They have nothing to do with security vulnerability disclosure. Now I just read subjects. If it gets any worse, I'll unsubscribe. I quite agree with all this. Except for the

[Full-Disclosure] MDKSA-2004:048 - Updated cvs packages fix remotely exploitable vulnerability

2004-05-19 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandrakelinux Security Update Advisory ___ Package name: cvs Advisory ID:

Re: [Full-Disclosure] I Got Hacked. Now What Do I Do?

2004-05-19 Thread A.H.
On Wed, 19 May 2004 10:26 pm, Troels Bay wrote: Wow, that's pretty amazing. Sorry, but i am puzzled :-P ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] [ GLSA 200405-10 ] Icecast denial of service vulnerability

2004-05-19 Thread Thierry Carrez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200405-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[Full-Disclosure] [OpenPKG-SA-2004.023] OpenPKG Security Advisory (subversion)

2004-05-19 Thread OpenPKG
: Affected Packages: Corrected Packages: OpenPKG CURRENT = subversion-1.0.2-20040518 = subversion-1.0.3-20040519 OpenPKG 2.0 = subversion-1.0.0-2.0.1= subversion-1.0.0-2.0.2 OpenPKG 1.3 N.A. N.A. Dependent Packages: none Description

Re: [Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread Vladimir Parkhaev
Quoting [EMAIL PROTECTED] ([EMAIL PROTECTED]): But, these might help: http://tcpreplay.sourceforge.net/ There is always DIY (do it yourself) option. http://www.perl.com -- .signature: No such file or directory ___ Full-Disclosure - We believe in

[Full-Disclosure] MDKSA-2004:049 - Updated libneon packages fix heap variable overflow issues

2004-05-19 Thread Mandrake Linux Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandrakelinux Security Update Advisory ___ Package name: libneon Advisory ID:

RE: [Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread full-disclosure
In our research project, we need to generate background traffic. One of the problem is how to use one or two machines to simulate hundreds of machines? Is there any open source project for this? Thanks very much for your help. By the way, does anyone happen to know any good project for background

[Full-Disclosure] [OpenPKG-SA-2004.022] OpenPKG Security Advisory (cvs)

2004-05-19 Thread OpenPKG
Packages: Corrected Packages: OpenPKG CURRENT = cvs-1.12.7-20040414 = cvs-1.12.8-20040519 OpenPKG 2.0 = cvs-1.12.5-2.0.1 = cvs-1.12.5-2.0.2 OpenPKG 1.3 = cvs-1.12.1-1.3.4 = cvs-1.12.1-1.3.5 Dependent Packages: none Description: Stefan Esser

[Full-Disclosure] agobot source code

2004-05-19 Thread Ben Timby
Anyone have this available for me to download? I tried googling, and kazaa to no avail. Thanks. ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] [ GLSA 200405-11 ] KDE URI Handler Vulnerabilities

2004-05-19 Thread Thierry Carrez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200405-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[Full-Disclosure] SGI ProPack 3: Kernel Update #1 - Security and other fixes

2004-05-19 Thread SGI Security Coordinator
-BEGIN PGP SIGNED MESSAGE- __ SGI Security Advisory Title : SGI ProPack 3: Kernel Update #1 - Security and other fixes Number: 20040504-01-U Date : May 19, 2004

Re: [Full-Disclosure] C# Web application security scanner

2004-05-19 Thread Michael Schaefer
Seems a tall order But don't send it off list, something like this would benefit us all I should think M [EMAIL PROTECTED] wrote: Can anyone give me the source code to a good web application security scanner written in C# so I can start my own company? Drop me an email with a link or code off of

[Full-Disclosure] SGI ProPack v2.4: Kernel Update #4 - Security and other fixes

2004-05-19 Thread SGI Security Coordinator
-BEGIN PGP SIGNED MESSAGE- __ SGI Security Advisory Title : SGI ProPack v2.4: Kernel Update #4 - Security and other fixes Number: 20040505-01-U Date : May 19, 2004

Re: [Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread ryan
If you're looking for paravirtualization tools, I would suggest looking at VServer (http://www.linux-vserver.org/) or Xen (http://www.cl.cam.ac.uk/Research/SRG/netos/xen/). Ryan On Wed, 19 May 2004 07:38:23 -0700 Jianqiang Xin [EMAIL PROTECTED] wrote: hi, all: In our research project, we need

SV: [Full-Disclosure] Is there any open source project support virtual machines

2004-05-19 Thread Anders Palm
I would recommend you to take a look at the linux-vserver project (http://www.linux-vserver.org/). It's a very clever way to run vm's without having to actually install a whole bunch of OS'es on the hosts. It can utilize most of the hosts system files, require very little resources, and are very

[Full-Disclosure] [OpenPKG-SA-2004.024] OpenPKG Security Advisory (neon)

2004-05-19 Thread OpenPKG
:no Affected Releases: Affected Packages: Corrected Packages: OpenPKG CURRENT = neon-0.24.5-20040414 = neon-0.24.6-20040519 = subversion-1.0.2-20040518 = subversion-1.0.3-20040519 = cadaver-0.22.1-20040415 = cadaver-0.22.2-20040519

Re: [Full-Disclosure] agobot source code

2004-05-19 Thread Nick FitzGerald
Ben Timby [EMAIL PROTECTED] wrote: Anyone have this available for me to download? I tried googling, and kazaa to no avail. Recall: Agobot == Gaobot == Gobot == Polybot == Phatbot ...at least for some variants of one or other and depending on which virus scanners you are familiar with...

RE: [Full-Disclosure] C# Web application security scanner

2004-05-19 Thread Aditya, ALD [Aditya Lalit Deshmukh]
[EMAIL PROTECTED] wrote: Can anyone give me the source code to a good web application security scanner written in C# so I can start my own company? Drop me an email with a link or code off of the list please. since u are starting your own company, i would be very happy to write one