[Full-Disclosure] [ GLSA 200412-25 ] CUPS: Multiple vulnerabilities

2004-12-28 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200412-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-Disclosure] IE sp2 and Mozilla Firefox DoS.

2004-12-28 Thread phased
Probably because there is a simple solution, close the browser, end of problem. -Original Message- From: bipin gautam [EMAIL PROTECTED] To: full-disclosure@lists.netsys.com Date: Mon, 27 Dec 2004 10:24:14 -0800 (PST) Subject: [Full-Disclosure] IE sp2 and Mozilla Firefox DoS. There is

[Full-Disclosure] [ GLSA 200412-26 ] ViewCVS: Information leak and XSS vulnerabilities

2004-12-28 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200412-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] Re: Windows (XP SP2) Remote code execution with parameters

2004-12-28 Thread ShredderSub7
Unfortunately, my site with the PoC of CMDExe (Remote code execution with parameters) hosted by FreeWebs is for the moment down, too much bandwith used (a limit of 100 MB). The bandwith of this sitewill normallybe resetted on the 6th of Januari 2005. But then you just have to wait for seeing this

Re: [Full-Disclosure] IE sp2 and Mozilla Firefox DoS.

2004-12-28 Thread morning_wood
even Microsoft publishes PoC for browser DoS ( multi platform too ) see: http://msdn.microsoft.com/library/default.asp?url=/library/en-us/dninstj/html/privacyforbrowserusers.asp -- / snip / -- var big_string = double me up!; while (true) { big_string = big_string + big_string; // 20

[Full-Disclosure] RE: hhctrl.ocx is not installed by default in all SP1s but is on all SP2.

2004-12-28 Thread Tim ShredderSub7
Sorry, forgot to mention this. The website (http://www.freewebs.com/shreddersub7/expl-discuss.htm)is updated now. I couldn't respond earlier because Microsoft has shutted down my Hotmail account ([EMAIL PROTECTED] doesn't work anymore) and therefore I lost all my mails, including the ones from

Re: [Full-Disclosure] List of worm and trojan files

2004-12-28 Thread GuidoZ
Assuming the attacker is competent, the only way to clean a deeply compromised machine is to reformat the drive and start from scratch. The truly paranoid will question whether just formatting the drive is sufficient. This isn't necessarily the case. While it will get the system up and going

Re: [Full-Disclosure] And you're proud of this Mike Evanchick?

2004-12-28 Thread Jason
Is there a specific reason this link is attempting to redirect through a Microsoft OWA system? Would you be associated with Microsoft in any way or just attempting to cause heavy load or what??? Elle Chicka wrote: You so proudly posted this:

RE: [Full-Disclosure] Insecurity in Finnish parlament (computers)

2004-12-28 Thread Todd Towles
The NSA has bigger fish to worry about than Finland. =) Sorry -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Markus Jansson Sent: Sunday, December 26, 2004 10:17 AM To: James Tucker Cc: full-disclosure@lists.netsys.com Subject: Re:

[Full-Disclosure] Re: Insecurity in Finnish parlament (computers)

2004-12-28 Thread Markus Jansson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 (SORRY FOR SENDING THIS MESSAGE TWICE, I THOUGHT IT WAS BETTER RETAIN THE ORIGINAL SUBJECT LINE...Im not sure was I able to cancel the previous message) On Thu, 23 Dec 2004 02:55:00 -0800 =?iso-8859- 1?Q?Mustaj=E4rvi_Olli?= [EMAIL PROTECTED]

[Full-Disclosure] Re: new phpBB worm affects 2.0.11

2004-12-28 Thread Adam
The request for this one (even against a non phpBB scripts) appears to look like this: GET