[Full-disclosure] [SECURITY] [DSA 1231-1] New gnupg packages fix arbitrary code execution

2006-12-09 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1231-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff December 9th, 2006

Re: [Full-disclosure] Linksys WIP 330 VoIP wireless phone crash from Nmap scan

2006-12-09 Thread Collin R. Mulliner
what about doing some investigation? Like figuring out which protocol and port the crash relates to. Then send some random stuff to that port and see what happens. You could find some real interesting stuff... see http://www.mulliner.org/pocketpc/ Collin On Wed, 2006-12-06 at 10:40 -0800, Shawn

Re: [Full-disclosure] iDefense Security Advisory 12.08.06: Sophos Antivirus CHM File Heap Overflow Vulnerability

2006-12-09 Thread Damian Put
Hi, There are some PoC if someone's interested... Sophos Antivirus CHM File Heap Overflow Vulnerability http://overflow.pl/poc/sophos_chunkheap.chm Sophos Antivirus CHM Chunk Name Length Memory Corruption Vulnerability http://overflow.pl/poc/sophos_namelen.chm Multiple Vendor Antivirus RAR

[Full-disclosure] (no subject)

2006-12-09 Thread Ēriks
Open source ERP and e-commerce package OFBIZ has an XSS vulnerability in the forum functionality. This was initially posted on Ofbiz JIRA issue tracking system (https://issues.apache.org/jira/browse/OFBIZ-178) on 22/Aug/06. I last verified it in revision 469895 (1/Nov/06), and it was still

Re: [Full-disclosure] Google pageranked 4 doamin on sale...

2006-12-09 Thread Dude VanWinkle
whoops! 0Crap, I guess pagerank isnt based on content as I thought it was.. http://www.webworkshop.net/pagerank.html sorry bout that. So, correct me if I am wrong, but according to pagerank: if you have a reciprocal link with microsoft.com about patches, this increases your rank and because of

[Full-disclosure] [SECURITY] [DSA 1232-1] New clamav packages fix denial of service

2006-12-09 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1232-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff December 9th, 2006

Re: [Full-disclosure] Call For Participants For A Research Study Of Hacker Culture

2006-12-09 Thread Alessio L.R. Pennasilico
On Fri, 2006-12-08 at 08:32 -0800, Thomas Holt wrote: Greetings, My name is Tom Holt, and I am an Assistant Professor at the University of North Carolina at Charlotte. I am currently conducting a study of hackers and hacking and am seeking interested men and women who may be willing to

Re: [Full-disclosure] Google pageranked 4 doamin on sale...

2006-12-09 Thread Louis Wang
That's ok.. 2006/12/9, Dude VanWinkle [EMAIL PROTECTED]: whoops! 0Crap, I guess pagerank isnt based on content as I thought it was.. http://www.webworkshop.net/pagerank.html sorry bout that. So, correct me if I am wrong, but according to pagerank: if you have a reciprocal link with

Re: [Full-disclosure] Call For Participants For A Research Study Of Hacker Culture

2006-12-09 Thread Matthew Flaschen
Andrew Farmer wrote: On 08 Dec 06, at 12:47, Evan Stawnyczy wrote: ^ My name is Evan ($LastNameNotDisclosed$). Nice job with the last-name-non-disclosure. Nice crack! ;) Matt signature.asc Description: OpenPGP digital signature

[Full-disclosure] PostgreSQL and Informix Function Fuzzing Tool

2006-12-09 Thread Joxean Koret
Hi to all! After the Oracle PL/SQL fuzzing tool I decided to write the same for PostgreSQL and Informix. Attached goes the 2 function/stored procedure fuzzers I wrote. The unique interesting thinks I found were in PostgreSQL but, as the PostgreSQL Team say, they are more annoyances than

Re: [Full-disclosure] Linksys WIP 330 VoIP wireless phone crash from Nmap scan

2006-12-09 Thread Shawn Merdinger
Hi, Yup, if one has the phone and cares to give free vendor QA that's a tactic to consider. As you know, determining the *exact* cause of the crash can be a tricky thing. For instance, the Milw0rm SYN flood exploit that targeted port 80 on the Cisco 7940 seemed to hose the web server, which