Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal.

2004-10-09 Thread Mary Landesman
Again, there's the problem with perception. I don't interpret Jan's post as whining about the insecurity of the Internet per se. To me, it appears he is simply noting, quite correctly IMO, that there is an idiotic notion prevailing that somehow, because the Internet *is* insecure, that it gives

Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayervulnerabilities

2004-10-09 Thread Jason Coombs PivX Solutions
0. (The primordial sin) The vulnerable product is released ... ... Vendors must work much harder to avoid releasing ... code ... Absolutely correct. Vendors who release code are the core problem. Vendors should not release code, they should release its source. Where this is not done,

SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit @ http://home.zccn.net/mm2004

2004-10-09 Thread Peter Kruse
Hi, Hex verified its hxxp://home.zccn.net/mm2004/mu/nc.jpg with payload @ hxxp://home.zccn.net/mm2004/mu/msmsgs.exe infected by netsnake.h trojan (http://www.google.com.sg/search?hl=enq=netsnake.h) Indeed. The malware, refered to in the jpg-exploit, was hosted as msmsgs.exe (Netsnake-H) and has

[Full-Disclosure] Re: Yet another IE aperture

2004-10-09 Thread Georgi Guninski
i didn't notice you have disclosed this (or a very similar to it bug). besides me more than 5 people tested variations of the testcase and it worked for all of them. can you comment on this testcases: http://www.guninski.com/where_do_you_want_billg_to_go_today_1_demo2.html

Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal.

2004-10-09 Thread Cedric Blancher
Le ven 08/10/2004 à 20:09, Harry Hoffman a écrit : Umm, should the Paladin of Security have weak locks? ;-) His Holy Cyber-Blade of Justice should prevent them all through its 100 feet radius area of evil protection... -- http://www.netexit.com/~sid/ PGP KeyID: 157E98EE FingerPrint:

[Full-Disclosure] Re: Yet another IE aperture

2004-10-09 Thread Aviv Raff
By opening html in IE it is possible to read at least well formed xml from arbitrary servers. The info then may be transmitted. Can you clarify what is the security issue with reading information of other servers from the web browser? Am I missing the point here? -- Aviv Raff

Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal.

2004-10-09 Thread Vasil Kolev
, 2004-10-08 23:52, morning_wood : phood 4 th0ugh7, last i heard being on the internet was voluntary... ( whether you are a person or business enity and many successfull business have no internet presence ) if i am correct... being on the the internet is not manditory to conduct life

[Full-Disclosure] [ GLSA 200410-06 ] CUPS: Leakage of sensitive information

2004-10-09 Thread Kurt Lieber
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200410-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit @ http://home.zccn.net/mm2004

2004-10-09 Thread Willem Koenings
hi, Hex verified its hxxp://home.zccn.net/mm2004/mu/nc.jpg with payload @ hxxp://home.zccn.net/mm2004/mu/msmsgs.exe infected by netsnake.h trojan (http://www.google.com.sg/search?hl=enq=netsnake.h) Indeed. The malware, refered to in the jpg-exploit, was hosted as msmsgs.exe

Re: [Full-Disclosure] mysql password cracking

2004-10-09 Thread ppatters
On Fri, 2004-10-08 at 16:03, David Hane wrote: I'm wondering how dangerous it is to allow a user on a mysql db to view the grants for another user. Could they take the encrypted password data and possibly crack it? If they can, how easy is it? I periodically export the mysql database with the

[Full-Disclosure] Re: Yet another IE aperture

2004-10-09 Thread GreyMagic Security
can you comment on this testcases: http://www.guninski.com/where_do_you_want_billg_to_go_today_1_demo2.html http://www.guninski.com/where_do_you_want_billg_to_go_today_1_demo.html Interesting, both your exploit code as well as the exploit code we provide in the advisory (Exploit section) do

Re: [Full-Disclosure] mysql password cracking

2004-10-09 Thread Willem Koenings
hi, I'm wondering how dangerous it is to allow a user on a mysql db to view the grants for another user. Could they take the encrypted password data and possibly crack it? If they can, how easy is it? on certain condition it's quite easy, if you have a hash: test.exe 57510426775c5b0f

SV: SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit @ http://home.zccn.net/mm2004

2004-10-09 Thread Peter Kruse
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, i wouldn't say so: \wget -vv home.zccn.net/mm2004/mu/msmsgs.exe --16:45:13-- http://home.zccn.net/mm2004/mu/msmsgs.exe = `msmsgs.exe' Resolving home.zccn.net... 218.89.171.197 Connecting to home.zccn.net[218.89.171.197]:80...

Re: [Full-Disclosure] Re: Jkuperus jkuperus@planet.nl

2004-10-09 Thread Vince Able
Can anyone tell me why this idiot keeps trying to send the group kiddies script worms/viruses. Why doesn't the moderators remove this losers account. - Original Message - From: Jkuperus To: Full-disclosure Sent: Saturday, October 09, 2004 1:14 AM Subject:

Re: [Full-Disclosure] Re: Jkuperus jkuperus@planet.nl

2004-10-09 Thread Remko Lodder
Vince Able wrote: Can anyone tell me why this idiot keeps trying to send the group kiddies script worms/viruses. Why doesn't the moderators remove this losers account. I am sorry to interupt, but did it ever occured to you that he might not be the actual sender of the stuff? There are many

Re: [SPAM] Re: [Full-Disclosure] Re: Jkuperus jkuperus@planet.nl

2004-10-09 Thread Hugo van der Kooij
On Sat, 9 Oct 2004, Vince Able wrote: Can anyone tell me why this idiot keeps trying to send the group kiddies script worms/viruses. Why doesn't the moderators remove this losers account. If you had bothered to read the Received: headers you would know it was quite likely (99.9%) not from

[Full-Disclosure] [ GLSA 200410-07 ] ed: Insecure temporary file handling

2004-10-09 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200410-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] [ GLSA 200410-08 ] ncompress: Buffer overflow

2004-10-09 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200410-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] [FLSA-2004:2068] Updated httpd packages fix security issues

2004-10-09 Thread Marc Deslauriers
--- Fedora Legacy Update Advisory Synopsis: Updated httpd packages fix security issues Advisory ID: FLSA:2068 Issue date:2004-10-09 Product: Red Hat Linux, Fedora Core Keywords:

Re: [VIRUS!] [SPAM] [Full-Disclosure] Re: Msg reply

2004-10-09 Thread Hugo van der Kooij
On Sat, 9 Oct 2004, Bugzilla wrote: Warning: This message has had one or more attachments removed If anyone want to bother the sender. He/She lives at 69.87.155.66 and happens to have a case of Bagle.AF (Or whatever your favorite scanner wants to call it.) Hugo. -- I hate

Re: [Full-Disclosure] Re: Jkuperus jkuperus@planet.nl

2004-10-09 Thread James Riden
Vince Able [EMAIL PROTECTED] writes: Can anyone tell me why this idiot keeps trying to send the group kiddies script worms/viruses. Even on a list like bugtraq, you're likely to get PoCs and worse sent - you probably shouldn't read a security list on a platform which you think may be

[Full-Disclosure] [ GLSA 200410-09 ] LessTif: Integer and stack overflows in libXpm

2004-10-09 Thread Luke Macken
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200410-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] List Charter

2004-10-09 Thread John Cartwright
[Full-Disclosure] Mailing List Charter John Cartwright [EMAIL PROTECTED] and Len Rose [EMAIL PROTECTED] Introduction Purpose -- This document serves as a charter for the [Full-Disclosure] mailing list hosted at lists.netsys.com. The list was created on 9th July 2002 by

[Full-Disclosure] New auditor security collection 081004-01 released

2004-10-09 Thread Max Moser
Hi there, again it is time to announce a major release of the Auditor Security Collection, the most advanced, penetration testing focused, linux live system. Grab your copy at my website http://www.remote-exploit.org. With this new release major feature enhancements where performed. See our