[Full-Disclosure] UPDATE: [ GLSA 200410-30 ] GPdf, KPDF, KOffice: Vulnerabilities in included xpdf

2004-11-06 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security AdvisoryGLSA 200410-30:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] UPDATE: [ GLSA 200410-20 ] Xpdf, CUPS: Multiple integer overflows

2004-11-06 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security AdvisoryGLSA 200410-20:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] Win32.Grams - E-Gold Account Siphoner

2004-11-06 Thread Joe Stewart
I've written up an analysis of the Win32.Grams trojan. It differs from previous E-Gold phishing trojans in that it doesn't steal credentials; it uses the victim's own browser to siphon all the E-Gold (well, almost all, it leaves them .004 grams) directly from their account to another E-Gold

RE: [Full-Disclosure] Norton AntiVirus 2004/2005 Scripting Vulnerability Pt.3 (Includes PoC VBScript Code)

2004-11-06 Thread RandallM
Daniel told me: --__--__-- Message: 4 Date: Wed, 03 Nov 2004 20:09:02 -0500 From: Daniel Milisic [EMAIL PROTECTED] To: [EMAIL PROTECTED], [EMAIL PROTECTED] Subject: [Full-Disclosure] Norton AntiVirus 2004/2005 Scripting Vulnerability Pt.3 (Includes PoC VBScript Code) Hi All, I have major

Re: [Full-Disclosure] Re: getting administrator rights on win2003 machine?

2004-11-06 Thread nicolas vigier
On Thu, 28 Oct 2004, Valentin Höbel wrote: Hi folks, I'm at a boarding school in germany and we have a kind of internet terminal there with win2003 running on the computers. My question is: Is there a way of getting administrative privileges ? I used a RPC Exploit before but now the

[Full-Disclosure] [ GLSA 200411-10 ] Gallery: Cross-site scripting vulnerability

2004-11-06 Thread Luke Macken
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security AdvisoryGLSA 200411-10:01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] [ GLSA 200411-11 ] ImageMagick: EXIF buffer overflow

2004-11-06 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security AdvisoryGLSA 200411-11:01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] Linux problem, steal of IP and traffinc redirection could bypass a firewall

2004-11-06 Thread NetExpress
Hi, I am wondering why linux do not recognize if someone steal it's IP, this could be a serious security problem. infact linux, Instead of Windows and freebsd and other operative system, when boot or give up a virtual IP on an interface do not send gratious arp but only ask for the gateway arp

[Full-Disclosure] Resources consumption in 602 Lan Suite 2004.0.04.0909

2004-11-06 Thread Luigi Auriemma
### Luigi Auriemma Application: 602 Lan Suite http://www.software602.com/products/ls/ Versions: = 2004.0.04.0909 Platforms:Windows Bugs: A] resources consumption

[Full-Disclosure] re; Suslix.B

2004-11-06 Thread Paul
Thanks for the responses. I wasn't able to take a copy of the malware to send for analysis/identification as I was dealing with the client by phone. He found the file Jim Duggan named deleted it in Safe Mode.AVG now reports the machine as clean. So, thanks Jim. P.S. I did ask the client to send