[Full-Disclosure] Re: XDICT Buffer OverRun Vulnerability,funny :-) (Sowhat .)

2004-11-02 Thread Sowhat .
I am sorry ,I forgot to declare that XDCIT 2005 will not hangup the system,and it will silently shutdown itself ,and need more than 300 'A' ,according to one of my friend's test. XDICT 2003 with 88 'A' will surely hangup the system. On Tue, 2 Nov 2004 12:01:06 +0800, [EMAIL PROTECTED] [EMAIL

Re: [Full-Disclosure] GWB Can't keep his own campaign certificates straight

2004-11-02 Thread David Maynor
OH man!! I missed the part in the debates where GW mentioned his sysadmined his own machines. Your statment is as dumb as the people that are finding any connection to prove Kerry will win: you know in 1992 and 1996 the sun rose in the east and set in the west and Clinton won. On Nov 2nd the sun

Re: [Full-Disclosure] MSIE IFRAME and FRAME tag NAME property bufferoverflow PoC exploit (was: python does mangleme (with IE bugs!))

2004-11-02 Thread morning_wood
bindshell success ( html run from local ) connect from remote success... this is NASTY if shellcode modified this will do reverse or exe drop i assume good work, Donnie Werner ___ Full-Disclosure - We believe in it. Charter:

[Full-Disclosure] [ GLSA 200411-04 ] Speedtouch USB driver: Privilege escalation vulnerability

2004-11-02 Thread Luke Macken
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-04 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] [ GLSA 200411-03 ] Apache 1.3: Buffer overflow vulnerability in mod_include

2004-11-02 Thread Matthias Geerdsen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-03 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-Disclosure] OT-POLITICAL: (Was: www.georgewbush.com)

2004-11-02 Thread Andrew
And don't forget to read some of the comments, like: Wow is this misleading Jim Grady -- 10/28/04 Summing it up, Bush wasn't included in the score, and being pro tech doesn't mean you'd vote the way their scoring system says you should. At 01:17 AM 11/2/2004, Nancy Kramer wrote: Continuing in

Rv: [Full-Disclosure] MSIE IFRAME and FRAME tag NAME property bufferoverflow PoC exploit (was: python does mangleme (with IE bugs!))

2004-11-02 Thread Elia Florio
Good job, the xploit works on both my : IE 6.0.2800.1106 ENGLISH with SHDOCVW.DLL version 6.0.2800.1400 IE 6.0.2800.1106 ITALIAN with SHDOCVW.DLL version 6.0.2800.1584 Tested on both Win XP Professional - SP1 with latest October patch installed. The overflow occurs in this point of SHDOCVW.DLL

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread Barry Fitzgerald
Paul Schmehl wrote: Here's a suggestion for you. Google for Oil for Food. Once you're done reading, come back here and tell us how Germany, France and Russia were *not* in bed with Sadaam, buying oil at great discounts in exchange for weapons sales and other favors - in material violation of

[Full-Disclosure] Source Code Club announces Cisco Pix

2004-11-02 Thread larry hobbles
Pix is now available for purchase, see: alt.gap.international.sales @ http://groups.google.com for more details. SCC ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] [SECURITY] [DSA 581-1] New xpdf packages fix arbitrary code execution

2004-11-02 Thread debian-security-announce
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 581-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze November 2nd, 2004

[Full-Disclosure] Cisco Security Advisory: Vulnerability in Cisco Secure Access Control Server EAP-TLS Authentication

2004-11-02 Thread Cisco Systems Product Security Incident Response Team
at http://www.cisco.com/warp/public/707/cisco-sa-20041102-acs-eap-tls.shtml. Affected Products = Vulnerable Products - --- Only version 3.3.1 of the Cisco Secure ACS for Windows and Cisco Secure ACS Solution Engine is affected by the vulnerability described

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread Barry Fitzgerald
Dean Brooks wrote: The Oil for Food program, however, was truly a scandal. There would never have been ANY situation where Germany or France would have voted to approve the war. No matter how badly Iraq would have been violating sanctions (which they were doing for years), there would have been

Re: Rv: [Full-Disclosure] MSIE IFRAME and FRAME tag NAME property bufferoverflow PoC exploit (was: python does mangleme (with IE bugs!))

2004-11-02 Thread Mihai Novitchi
Hello Elia, Tuesday, November 2, 2004, 3:32:45 PM, you wrote: EF PS: after testing the xploit, Windows increased the swap EF file dimension sayin' VM memory too low, is this a side-effect of EF exploit? This is a side effect. The JS used in the PoC allocates a lot of memory to make sure that

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread J.A. Terranson
On Tue, 2 Nov 2004, Barry Fitzgerald wrote: Paul Schmehl wrote: Here's a suggestion for you. Google for Oil for Food. Once you're done reading, come back here and tell us how Germany, France and Russia were *not* in bed with Sadaam, buying oil at great discounts in exchange for

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread Dean Brooks
On Tue, Nov 02, 2004 at 10:23:08AM -0500, Barry Fitzgerald wrote: Meanwhile, Cheney was busy developing Halliburton's business in other parts of the world. It is a false dichotomy that we have to choose between our commercial and other interests, he told the [public policy research

[Full-Disclosure] [ GLSA 200411-05 ] libxml2: Remotely exploitable buffer overflow

2004-11-02 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-05 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread yossarian
1982? Well, the CIA sure has a lucky hand in picking its staff Now I understand why you lot feel so insecure. 1982 just after the republicans traded arms for hostages in Iran to get reagan in - arranged by Papa Bush. I can now understand his anger. - Original Message - From: Paul

[Full-Disclosure] [ GLSA 200411-06 ] MIME-tools: Virus detection evasion

2004-11-02 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-06 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] Microsoft ISA Server Authentication Bypassing

2004-11-02 Thread Debasis Mohanty
Vulnerability Microsoft ISA Server Authentication Bypassing Description This weakness is tested in a network environment where Microsoft ISA server is configured as an Internet proxy server and the users are required to provide appropriate user name and the password to access the internet. In

Re: [Full-Disclosure] OT-POLITICAL: (Was: www.georgewbush.com)

2004-11-02 Thread yossarian
Interesting - who said that DMCA or the Communications Decency Act or the Patriot Act were tech friendly? These three are at best pro-certain unmentionable tech companies, but basically against the free flow of information, which many consider a condition sin qua non for tech development. Probably

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread Mike
I agree. Go away. On Tue, 02 Nov 2004 14:56:58 -0500, KF_lists [EMAIL PROTECTED] wrote: And to sum this all up... its fine for you all to STFU and take this thread to your private mail spools. Unless you are telling us about how Halliburton uses QPOP exploits to root the UN... NO ONE

Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-02 Thread KF_lists
And to sum this all up... its fine for you all to STFU and take this thread to your private mail spools. Unless you are telling us about how Halliburton uses QPOP exploits to root the UN... NO ONE CARES!@@# Until Dick Cheney can type cc -o shutthefuckup shutthefuckup.c; ./shutthefuckupI

[Full-Disclosure] ERRATA: [ GLSA 200411-01 ] ppp: No denial of service vulnerability

2004-11-02 Thread Luke Macken
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200411-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-Disclosure] How secure is PHP ?

2004-11-02 Thread Dan Margolis
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Gary E. Miller wrote: Saying PHP in insecure is like saying C is insecure. Until their is a programmer involved, writing bad code, there is no problem. Just like C if the programmer carefully validates and contrains ALL input then the program is

[Full-Disclosure] Re: Voxcards

2004-11-02 Thread Felipe Lima
Does anyone know anything about this? Voxcards.com.br is a brazilian company that has many online cards for u to send to your friends so that they receive it by email. So i almost have been caught by this spam. The link goes to voxcards.org and prompts you to download voxcards.exe. Can anyone

Re: [Full-Disclosure] OT-POLITICAL: (Was: www.georgewbush.com)

2004-11-02 Thread jesse michael
On Tue, Nov 02, 2004 at 08:12:46PM +0100, yossarian wrote: Interesting - who said that DMCA or the Communications Decency Act or the Patriot Act were tech friendly? These three are at best pro-certain unmentionable tech companies, but basically against the free flow of information, which many

Re: [Full-Disclosure] OT-POLITICAL: (Was: www.georgewbush.com)

2004-11-02 Thread Steve Ames
On Tue, Nov 02, 2004 at 08:12:46PM +0100, yossarian wrote: Interesting - who said that DMCA or the Communications Decency Act or the Patriot Act were tech friendly? These three are at best pro-certain unmentionable tech companies, but basically against the free flow of information, which many

Re: [Full-Disclosure] OT-POLITICAL: (Was: www.georgewbush.com)

2004-11-02 Thread Valdis . Kletnieks
On Tue, 02 Nov 2004 20:12:46 +0100, yossarian said: Interesting - who said that DMCA or the Communications Decency Act or the Patriot Act were tech friendly? Please note that the DMCA (in addition to the infamous circumvention clause), *also* included the ISP safe-harbor exemptions in 17 USC

[Full-Disclosure] Should the industry be expecting a hacker response to election results?

2004-11-02 Thread n3td3v
Do you think if bush gets back in that hackers have something ready to launch against internet targets? Are security firms ready for a major internet incident? Are the major dot-coms got staff working late incase something occurs? Is this realistic or is my drama filled imagination getting the

Re: [Full-Disclosure] Should the industry be expecting a hacker response to election results?

2004-11-02 Thread J.A. Terranson
On Tue, 2 Nov 2004, n3td3v wrote: Do you think if bush gets back in that hackers have something ready to launch against internet targets? No. Are security firms ready for a major internet incident? No need. Are the major dot-coms got staff working late incase something occurs?

[Full-Disclosure] How to clear contents of protected storage - Windows 2000

2004-11-02 Thread Danny
After running: http://ntsecurity.nu/toolbox/pstoreview/ ...there are a bunch of INETCOMM Server passwords I want to clear out. Any idea on how to complete this? Thank you, ...D ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-Disclosure] Should the industry be expecting a hacker response to election results?

2004-11-02 Thread KF_lists
Here in Ohio the fabulous swing state we have evil hax0rs sp00fing snail mail from elections officials. Several Ohio residents received mail yesterday and today stating: Due to poll overcrowding, the Ohio polls have been extended into Wednesday. You can vote tomorrow from 9am to 9pm. This is

[Full-Disclosure] [USN-16-1] perl vulnerabilities

2004-11-02 Thread Martin Pitt
=== Ubuntu Security Notice USN-16-1 November 02, 2004 perl vulnerabilities CAN-2004-0976 === A security issue affects the following Ubuntu releases: Ubuntu 4.10 (Warty

Re: [Full-Disclosure] Dominos web access testing

2004-11-02 Thread Nicob
Le jeu 07/10/2004 à 14:39, Frederic Charpentier a écrit : I've already try a specialized script called Domino Hunter. It'is based on the basic .nsf file list and LotusDomino commands like '?OpenDocument'. Same thing for dominodig : http://sourceforge.net/projects/dominodig/ I

Re: [Full-Disclosure] How secure is PHP ?

2004-11-02 Thread Gary E. Miller
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yo Dan! On Tue, 2 Nov 2004, Dan Margolis wrote: That's not strictly correct. Having PHP installed on a web server can introduce vulnerabilities, regardless of whether PHP scripts running are vulnerbale, but having a C compiler installed would

[Full-Disclosure] Gmail fixed

2004-11-02 Thread RandallM
6. Google blocks Gmail exploit By: John Leyden, The Register Google has fixed a flaw in its high-profile webmail service, Gmail, which created a possible route for hackers to gain full access to a user's email account simply by knowing their user name. http://www.securityfocus.com/news/9843

Re: [Full-Disclosure] How secure is PHP ?

2004-11-02 Thread Morgan Reed
First I'd recommend reading some guides on securing PHP, MySQL and Apache. PHP itself CAN be (relatively) secure but only if it's configured correctly, the same goes for Apache, it's like the old saying never build a house on shifting sand (or something to that effect) a the most secure PHP web

[Full-Disclosure] CSS in E-Mails possible E-Mail-Validity Check for Spammers?

2004-11-02 Thread plonk
This might be a minor problem in times of e-mail-collecting viruses and massive hijacking of SOHO-PCs. Still I wonder what you think about this: Mozilla Mail 1.7.1 (W98) and 1.7.3 (W98) (didn't check different versions) automatically load CSS-files which are linked from within an html-page sent