[ MDVSA-2012:064 ] openssl0.9.8

2012-04-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:064 http://www.mandriva.com/security/

RuggedCom - Backdoor Accounts in my SCADA network? You don't say...

2012-04-24 Thread jc
Title: Undocumented Backdoor Access to RuggedCom Devices Author:jc Organization: JC CREW Date: April 23, 2012 CVE: CVE-2012-1803 Background: RuggedCom is one of a handful of networking vendors who capitalize on the market for Industrial Strength and Hardened

[security bulletin] HPSBUX02768 SSRT100664 rev.1 - CIFS Server (Samba), Remote Cross Site Request Forgery (CSRF), Denial of Service (DoS)

2012-04-24 Thread security-alert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c03297338 Version: 1 HPSBUX02768 SSRT100664 rev.1 - CIFS Server (Samba), Remote Cross Site Request Forgery (CSRF), Denial of Service (DoS) NOTICE: The information in this Security Bulletin

New IETF I-D: Security Implications of IPv6 on IPv4 networks

2012-04-24 Thread Fernando Gont
Folks, We've published a new IETF I-D entitled Security Implications of IPv6 on IPv4 networks. The I-D is available at: http://www.ietf.org/id/draft-gont-opsec-ipv6-implications-on-ipv4-nets-00.txt The Abstract of the I-D is: cut here This document discusses the security

RE: McAfee Web Gateway URL Filtering Bypass

2012-04-24 Thread Jim Harrison
?? I'm unclear - exactly how does an ICMP echo cycle have anything to do with the apparent disparity between the host portion of the CONNECT URI and the contents of the host header? I can see the logic in : 1. comparing the HOST header to the host portion of the CONNECT URI 2. resolving either

PHP Ticket System Beta 1 'p' SQL Injection

2012-04-24 Thread Thomas Richards
# Exploit Title: PHP Ticket System Beta 1 'p' SQL Injection # Date: 04/16/12 # Author: G13 # Twitter: @g13net # Software Site: http://sourceforge.net/projects/phpticketsystem/ # Version: Beta 1 # Category: webapp (php) # # Description # PHP Ticket System is a small PHP MySQL trouble