CVE-2012-3287: md5crypt is no longer considered safe

2012-06-08 Thread phk
The LinkedIn password incompetence has resulted in a number of just use md5crypt and you'll be fine pieces of advice on the net. Since I no longer consider this to be the case, I have issued an official statement, as the author of md5crypt, to the opposite effect:

Re: Mybb 1.6.8 Sql Injection Vulnerabilitiy

2012-06-08 Thread Henri Salo
On Thu, Jun 07, 2012 at 10:51:06AM +, a...@irist.ir wrote: a bug in Mybb 1.6.8 that allows to us to occur a Sql Injection on a Remote machin. # # Exploit Title : Mybb 1.6.8 Sql Injection

Re: Mybb 1.6.8 Sql Injection Vulnerabilitiy

2012-06-08 Thread Henri Salo
On Thu, Jun 07, 2012 at 10:51:06AM +, a...@irist.ir wrote: a bug in Mybb 1.6.8 that allows to us to occur a Sql Injection on a Remote machin. # # Exploit Title : Mybb 1.6.8 Sql Injection

[SECURITY] [DSA 2487-1] openoffice.org security update

2012-06-08 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2487-1 secur...@debian.org http://www.debian.org/security/Florian Weimer June 07, 2012

[SECURITY] [DSA 2489-1] iceape security update

2012-06-08 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2489-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst June 7, 2012

[SECURITY] [DSA 2490-1] nss security update

2012-06-08 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2490-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst June 7, 2012

[SECURITY] [DSA 2488-1] iceweasel security update

2012-06-08 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2488-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst June 7, 2012

Analysis: Vast IPv6 address space actually enables IPv6 attacks

2012-06-08 Thread Fernando Gont
Folks, TechTarget has published an article I've authored for them, entitled Analysis: Vast IPv6 address space actually enables IPv6 attacks. The aforementioned article is available at: http://searchsecurity.techtarget.com/tip/Analysis-Vast-IPv6-address-space-actually-enables-IPv6-attacks (FWIW,

Re: Analysis: Vast IPv6 address space actually enables IPv6 attacks

2012-06-08 Thread Fernando Gont
Folks, FWIW, the full article is available at the URL below (you don't need to subscribe... just scroll the window down). CHeers, Fernando On 06/08/2012 07:32 AM, Fernando Gont wrote: Folks, TechTarget has published an article I've authored for them, entitled Analysis: Vast IPv6 address