[Full-disclosure] [SECURITY] [DSA 791-1] New maildrop packages fix arbitrary group mail command execution

2005-08-29 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 791-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze August 30th, 2005

[Full-disclosure] [SECURITY] [DSA 790-1] New phpldapadmin packages fix unauthorised access

2005-08-29 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 790-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze August 30th, 2005

[Full-disclosure] No one else seeing the new MS05-039 worm yet?

2005-08-29 Thread Vic Vandal
This has been going around since early Monday afternoon. Symantec and other AV vendors have had code since then, and no details STILL. I guess one can call it the Katrina worm until something better comes along. Details: - Exploits MS05-039, but also MS04-011 and MS03-026. - Scans on port 5000 a

Re: [Full-disclosure] Re: The Wireless Networking Excuse

2005-08-29 Thread Valdis . Kletnieks
On Mon, 29 Aug 2005 21:33:06 CDT, womber said: > It is an interesting point. I have thought about it myself in the > context of having my personal access point open to the public and if > someone hopped on and downloaded something. > Would I be resposible if they tracked it back to my AP? Anybody

Re: [Full-disclosure] Re: The Wireless Networking Excuse

2005-08-29 Thread fd
On Mon, 29 Aug 2005, womber wrote: > On 8/29/05, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > > Has anyone examined the idea of using a public hotspot on a local > > network to shield BSA, RIAA, MPAA lawsuits? Since the tracking > > stops at the public facing IP, who is to say it wasn't some

[Full-disclosure] BNBT EasyTracker Remote Denial of Service Vulnerability

2005-08-29 Thread Sowhat .
BNBT EasyTracker Remote Denial of Service Vulnerability by Sowhat Last Update:2005.08.30 http://secway.org/advisory/AD20050830.txt Vendor: http://bnbteasytracker.sourceforge.net/ Product Affected: 7.7r3.2004.10.27 and below Overview: BNBT was written by Trevor Hogan. BNBT is a complete port of the

[Full-disclosure] Re: The Wireless Networking Excuse

2005-08-29 Thread womber
On 8/29/05, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > Has anyone examined the idea of using a public hotspot on a local > network to shield BSA, RIAA, MPAA lawsuits? Since the tracking > stops at the public facing IP, who is to say it wasn't some > freeloader downloading the warez? > > Ju

[Full-disclosure] Re: Xcon2005 papers released (alert7)

2005-08-29 Thread liudieyu
finally it's online. :-) btw, got audio/video files? i suppose you recorded it all, right? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] The Wireless Networking Excuse

2005-08-29 Thread yahoo123456
Has anyone examined the idea of using a public hotspot on a local network to shield BSA, RIAA, MPAA lawsuits? Since the tracking stops at the public facing IP, who is to say it wasn't some freeloader downloading the warez? Just looking for some feedback on this one... Concerned about your p

[Full-disclosure] SimplePHPBlog Arbitrary File Deletion and Sample Exploit

2005-08-29 Thread 'ken'@FTU
SimplePHPBlog has a vulnerability in its comment_delete_cgi.php. The PHP script allows for the arbitrary deletion of files. Please see following link for a perl script to demonstrate the exploit: http://www.ftusecurity.com/pub/sphpblog_vulns (Please add .pl extension as my ISP server preprocesse

[Full-disclosure] MDKSA-2005:155 - Updated apache2 packages fix integer overflow vulnerability

2005-08-29 Thread Mandriva Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Update Advisory ___ Package name: apache2 Advisory ID:

[Full-disclosure] Re: Chung's Donut Shop Release: Hacking Sprint PCS Vision

2005-08-29 Thread Steven Smith
On 8/29/05, ara rhea <[EMAIL PROTECTED]> wrote: Hi my mom has a sprint pcs phone.Its a sanyo 8300.and i cant feger out the pass word .cause when u go to sprint pcs .com u put in ur phone number than ur pass word and i dont no it. and i was woundreing if u can help me please When |-|4X0ring

[Full-disclosure] iDEFENSE Security Advisory 08.29.05: Symantec AntiVirus 9 Corporate Edition Local Privilege Escalation Vulnerability

2005-08-29 Thread iDEFENSE Labs
Symantec AntiVirus 9 Corporate Edition Local Privilege Escalation Vulnerability iDEFENSE Security Advisory 08.29.05 www.idefense.com/application/poi/display?id=298&type=vulnerabilities August 29, 2005 I. BACKGROUND Symantec AntiVirus 9 Corporate Edition is an enterprise quality Anti-Virus solu

[Full-disclosure] iDEFENSE Security Advisory 08.29.05: Adobe Version Cue VCNative Arbitrary File Overwrite Vulnerability

2005-08-29 Thread iDEFENSE Labs
Adobe Version Cue VCNative Arbitrary File Overwrite Vulnerability iDEFENSE Security Advisory 08.29.05 www.idefense.com/application/poi/display?id=297&type=vulnerabilities August 29, 2005 I. BACKGROUND Adobe Version Cue is a software version tracking system for Adobe products distributed with Ad

[Full-disclosure] iDEFENSE Security Advisory 08.29.05: Adobe Version Cue VCNative Arbitrary Library Loading Vulnerability

2005-08-29 Thread iDEFENSE Labs
Adobe Version Cue VCNative Arbitrary Library Loading Vulnerability iDEFENSE Security Advisory 08.29.05 www.idefense.com/application/poi/display?id=296&type=vulnerabilities August 29, 2005 I. BACKGROUND Adobe Version Cue is a software version tracking system for Adobe products distributed with A

Re: [Full-disclosure] J. A. Terranson

2005-08-29 Thread John Smith
I agree. Please stop. Perhaps we could have a count of the 'ayes' to determine whether the list members wish to participate in the drama. > I think the real issue here is that the rest of us really don't care.  If you have a problem with someone, great.  But telling us about it > doesn't make you a

Re: [Full-Disclosure] Chung's Donut Shop Release: Hacking Sprint PCS Vision

2005-08-29 Thread Valdis . Kletnieks
On Sun, 28 Aug 2005 21:25:18 PDT, ara rhea said: > Hi my mom has a sprint pcs phone.Its a sanyo 8300.and i cant feger out the > pass word .cause when u go to sprint pcs .com u put in ur phone number than ur > pass word and i dont no it. and i was woundreing if u can help me please There's probabl

Re: [Full-disclosure] Eric Scher - "Ball-less" Poster Boy

2005-08-29 Thread Valdis . Kletnieks
On Sun, 28 Aug 2005 16:06:13 CDT, "J.A. Terranson" said: > > On Sun, 28 Aug 2005 [EMAIL PROTECTED] wrote: > > > 867-5309. My receptionist Jenny will most likely answer the phone. > > IIRC, they actually auctioned off this number recently, didnt they? One of them, anyhow. Remember that each ar

[Full-disclosure] Multiple vulnerabilities in BFCommand & Control for Battlefield 1942 and Vietnam

2005-08-29 Thread Luigi Auriemma
### Luigi Auriemma Application: BFCommand & Control Server Manager http://www.bfcommandcontrol.org Versions: BFCC <= 1.22_A BFVCC <= 2.14_B BFVCCDaemon

Re: [Full-disclosure] J. A. Terranson

2005-08-29 Thread Micheal Espinola Jr
I think the real issue here is that the rest of us really don't care.  If you have a problem with someone, great.  But telling us about it doesn't make you any more important in our eyes.  In fact, everyone involved in this tit-for-tat is coming off looking very unprofessional.   On 8/29/05, J.A.

[Full-disclosure] Land Down Under 801 And Prior Multiple SQL Injection Vulnerabilities

2005-08-29 Thread h4cky0u
TITLE: == Land Down Under 801 And Prior Multiple SQL Injection Vulnerabilities SEVERITY: = Medium SOFTWARE: == Land Down Under version 801 and prior Support Website : http://www.neocrome.net INFO: = Land Down Under is a multiple portal system which includes many d

Re: [Full-disclosure] J. A. Terranson

2005-08-29 Thread J.A. Terranson
On Sun, 28 Aug 2005, ghost wrote: > J.A.,. give up computers, go play in a sandbox. Did you just admit to > threatening to mailbomb someone? lol. Bzzdt. This dude calls me up and starts asking if I'm going to. Out of the blue - like I said psycho central. My first response was to tell him to

Re: [Full-disclosure] RE: Example firewall script (iptables)

2005-08-29 Thread Anders B Jansson
Maybe you'd get more informative and less 'get a clue!' answers if you rephrased and explained your question a little. For one, what in the world is a firewall script? I'd guess it's firewall rules you're talking about. Second, in what scenario? Corporate firewall, SME, personal, school? Witho

[Full-disclosure] Julie Terranson

2005-08-29 Thread winsoc
Julie Terranson this is a woman lol wutz up luv not getting any ? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Re: JA

2005-08-29 Thread Exibar
I don't know about y'all, but if I was admin of a public ISP (or whatever), I wouldn't want to give anyone the idea that I'm smarter than everyone on the list that's just begging to be hacked/defaced/owned/etc exibar - Original Message - From: "Bardus Populus" <[EMAIL PROTECTED]

[Full-disclosure] [SECURITY] [DSA 788-1] New kismet packages fix arbitrary code execution

2005-08-29 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 788-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze August 29th, 2005

Re: [Full-disclosure] Really ODD 12 byte UDP attempts

2005-08-29 Thread James Lay
On Sun, 28 Aug 2005 23:44:25 -0400 Michael Hale <[EMAIL PROTECTED]> wrote: > I agree - Unix style traceroute probably responsible. See: > > http://www.tech-faq.com/unix-windows-traceroute.shtml > > On 8/28/05, Blue Boar <[EMAIL PROTECTED]> wrote: > > James Lay wrote: > > > Aug 28 06:57:01 kerne

RE: [Full-disclosure] RE: Example firewall script (iptables)

2005-08-29 Thread Bernardo Martín
Anybody have more information about bad example firewall script?? -Mensaje original- De: Bernardo Martín [mailto:[EMAIL PROTECTED] Enviado el: lunes, 29 de agosto de 2005 14:01 Para: Full Disclosure Asunto: RE: [Full-disclosure] RE: Example firewall script I look for bad rules set

RE: [Full-disclosure] RE: Example firewall script

2005-08-29 Thread Bernardo Martín
I look for bad rules set to learn a little more. I thought that my question was interesting because here there are many people who knows about this. Can you recommend me any web or any book? Thanks -Mensaje original- De: James Tucker [mailto:[EMAIL PROTECTED] Enviado el: sábado, 27

[Full-disclosure] Secunia Research: SqWebMail HTML Emails Script Insertion Vulnerability

2005-08-29 Thread Secunia Research
== Secunia Research 29/08/2005 - SqWebMail HTML Emails Script Insertion Vulnerability - == Table of Contents Affected Software...

[Full-Disclosure] Chung's Donut Shop Release: Hacking Sprint PCS Vision

2005-08-29 Thread ara rhea
Hi my mom has a sprint pcs phone.Its a sanyo 8300.and i cant feger out the pass word .cause when u go to sprint pcs .com u put in ur phone number than ur pass word and i dont no it. and i was woundreing if u can help me please___ Full-Disclosure - We beli

Re: [Full-disclosure] J. A. Terranson

2005-08-29 Thread Joxean Koret
Welcome to Full-Disclosure "Flames Festival" EPISODE 1; THE PHANTOM MENACE!! Hay que joderse papito! > YOU initiated) begging me not to *mailbomb* you? What kind of psycho shit > is *that*? Fucktard. > > For the record dipshit - I now fucking OWN you. You are MY cat toy. My > personal

Re: [Full-disclosure] J. A. Terranson

2005-08-29 Thread Atte Peltomaki
> I get it. This is a place where he gets to feel like a big man. A tough > guy. Fine. Whatever floats his boat. While I'm not taking a stand in this issue, I would like to point out that there are quite a few people on this list who push their egos by putting down other people. Remember: Arguin