Re: [Full-disclosure] ICMP Security Vulnerabilities - NEW (cough)

2005-07-15 Thread Chad Loder
Vic, Maybe you need to read (not skim) Fernando's draft? The title is ICMP Attacks Against TCP, and let me emphasize the TCP part. I find it interesting that you've gone through the trouble of writing a 10 page email in which you seem to be claiming partial credit for someone else's work, but

[Full-disclosure] [ GLSA 200507-14 ] Mozilla Firefox: Multiple vulnerabilities

2005-07-15 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Dunceor .
well they seem to only publish old articles, articles i guess they dont got authorization to publish. On 7/15/05, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: Sumy wrote: [...] Don't worry if you have at least a floppy rescue disk under hand,you can root it ;-) ) The problem with the new

[Full-disclosure] Foundstone security contact?

2005-07-15 Thread Found Security
Hi! While for obvious reasons, there's a several people working in the security field at Foundstone, it's not easy to tell whom to contact for their own security holes. Would someone know? Thanks in advance, Fart Pimpson

RE: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Lauro, John
6.2? What is that??? Latest kernel is 2.6... This is true of the default install of almost every Unix-like OS including Solaris and, and ever Windows OS including Windows 2003 (although the files you have to alter are different in Windows). (Of course with windows you generally need at least

Re: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Dan Becker
Boot this http://www.trinux.org/ then mount the drive ... chroot to the drives root and run passwd its not a complicated process On 7/14/05, Sumy [EMAIL PROTECTED] wrote: You have lost your root password on your linux box and now you consider formatting everythign to regain control? Your

Re: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Rik Bobbaers
On Friday 15 July 2005 02:23, Sumy wrote: You have lost your root password on your linux box and now you consider formatting everythign to regain control? Your admin is a moron that leaves the server available physically for everybody? You wanna test your Linux box? Don't worry if you have

Re: [Full-disclosure] thunderbird privacy...

2005-07-15 Thread Steve Kudlak
[EMAIL PROTECTED] wrote: Hi, Adam Neale wrote: My understanding is, to remove these items for good you compact the folder, this is done by right clicking the folder and selecting Compact This Folder, then its gone for good. confirmed for thunderbird 1.0.2/WinXP. GTi

Re: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Harry de Grote
On Friday 15 July 2005 02:23, Sumy wrote: You have lost your root password on your linux box and now you consider formatting everythign to regain control? Your admin is a moron that leaves the server available physically for everybody? You wanna test your Linux box? Don't worry if you have

[Full-disclosure] [ GLSA 200507-15 ] PHP: Script injection through XML-RPC

2005-07-15 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Nicolas CARTRON
On Friday 15 July 2005 13:04, Lauro, John wrote: 6.2? What is that??? Latest kernel is 2.6... Perhaps RH 6.2 ? ;) ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia

[Full-disclosure] Compromising pictures of Microsoft Internet Explorer!

2005-07-15 Thread Michal Zalewski
Synopsis: - Well, not really. Instead, at the risk of boring you to death, I'd like to report on a casual 30-minute experiment I've conducted of recent. This experiment resulted in identifying a potential remote code execution path in Microsoft Internet Explorer, plus some other

Re: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Ron
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 _Linux_ doesn't have a version 10, either. Linux IS the kernel, which the versions are 2.x (2.4.* and 2.6.* usually). Maybe you're talking about a specific distribution? In which case, that's a pretty inconsistant numbering system to use since Red

RE: [Full-disclosure] Rooting Linux with a floppy

2005-07-15 Thread Eric Paynter
On Fri, July 15, 2005 8:47 am, James Longstreet said: On Fri, 15 Jul 2005, Lauro, John wrote: 6.2? What is that??? Latest kernel is 2.6... No, not kernel 6.2, LINUX 6.2. You know, that old version. Linux 10 has been out for months. This is sadly funny in a pathetic sort of way...

[Full-disclosure] Why Vulnerability Databases can't do everything

2005-07-15 Thread Steven M. Christey
Regarding a particular vulnerability database, Xavier Beaudouin [EMAIL PROTECTED] said: They push advisory without testing and respect the usual way to inform developper as it should. (name omitted simply because it could have been about any vuln database.) No doubt a lot of what I'm about to

[Full-disclosure] [ GLSA 200507-16 ] dhcpcd: Denial of Service vulnerability

2005-07-15 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200507-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [FLSA-2005:158149] Updated mozilla packages fix security issues

2005-07-15 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mozilla packages fix security issues Advisory ID: FLSA:158149 Issue date:2005-07-15 Product: Red Hat Linux, Fedora Core Keywords:

[Full-disclosure] [FLSA-2005:152925] Updated mysql packages fix security issues

2005-07-15 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated mysql packages fix security issues Advisory ID: FLSA:152925 Issue date:2005-07-15 Product: Red Hat Linux, Fedora Core Keywords:

[Full-disclosure] [FLSA-2005:152917] Updated curl packages fix a security issue

2005-07-15 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated curl packages fix a security issue Advisory ID: FLSA:152917 Issue date:2005-07-15 Product: Red Hat Linux, Fedora Core Keywords:

[Full-disclosure] [FLSA-2005:152841] Updated openssl packages fix security issues

2005-07-15 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated openssl packages fix security issues Advisory ID: FLSA:152841 Issue date:2005-07-15 Product: Red Hat Linux, Fedora Core Keywords:

[Full-disclosure] [FLSA-2005:152838] Updated gd packages fix security issues

2005-07-15 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated gd packages fix security issues Advisory ID: FLSA:152838 Issue date:2005-07-15 Product: Red Hat Linux, Fedora Core Keywords:

[Full-disclosure] [FLSA-2005:152769] Updated kdelibs/kdebase packages fix security issues

2005-07-15 Thread Marc Deslauriers
- Fedora Legacy Update Advisory Synopsis: Updated kdelibs/kdebase packages fix security issues Advisory ID: FLSA:152769 Issue date:2005-07-15 Product: Red Hat Linux, Fedora Core