[TZO-28-2009] - Avira Antivir generic RAR,CAB,ZIP

2009-05-29 Thread Thierry Zoller
From the low-hanging-fruit-department Avira Antivir generic RAR,CAB,ZIP,LH evasion CHEAP Plug : You are

Re: PHP Nuke v.8.0 (referer) SQL Injection

2009-05-29 Thread a
Is it not the same as http://milw0rm.com/exploits/3346 ?

(whitepaper) Microsoft WPAD Technology Weaknesses [PTResearch Team]

2009-05-29 Thread srublev
WPAD (Web Proxy Auto Discovery) is a method used by web clients to automatically locate a browser configuration file used to connect through proxy. Successful attack on WPAD guarantees attackers full access on user data sent to Internet which could allow stealing critical data like passwords or

Re: [InterN0T] Achievo 1.3.4 - XSS Vulnerability

2009-05-29 Thread security
In regards to the previous researchers i found out this vulnerability and another has already been disclosed. http://www.securityfocus.com/bid/31326/info (ver 1.3.2) http://secunia.com/advisories/31973/ (ver. 1.3.2) However, i can confirm that the vulnerability below still exists in the newest

Re: [InterN0T] AdPeeps 8.5d1 - XSS and HTML Injection Vulnerabilities

2009-05-29 Thread support
Ad Peeps (www.adpeeps.com) has confirmed that this has been patched in their next release 8.5d2. Users will be e-mailed and advised to update within 24 hours.

Re: Re: [InterN0T] AMember 3.1.7 - Multiple Vulnerabilities

2009-05-29 Thread security
InterN0T is about Hacking. (if you have seen the introduction) To me, Hacking is primarily about learning how and why things works as they do and if they can be changed (improved or abused in this case) and of course, sharing what you find out so the community can benefit from it! Afterwards,

VMSA-2009-0007 VMware Hosted products and ESX and ESXi patches resolve security issues

2009-05-29 Thread VMware Security team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID: VMSA-2009-0007 Synopsis: VMware Hosted products and ESX and ESXi patches resolve

SonicWALL SSL-VPN Appliance Format String Vulnerability

2009-05-29 Thread Patrick Webster
aushack.com - Vulnerability Advisory --- Release Date: 29-May-2009 Software: SonicWALL - SSL-VPN Remote Access http://www.sonicwall.com/ Description: SonicWALL SSL VPN appliances provide small and mid-size organizations an easy-to-use, secure and

Whitepaper

2009-05-29 Thread Jared DeMott
Hi all, If you plan to take my Application Security: For Hackers and Developers at ShakaCon, BlackHat, ToorCon, and others; I finally got off my can and finished the prerequisite white paper. It can be found here: