[Full-disclosure] stompy the session stomper - tool availability

2007-01-27 Thread Michal Zalewski
Hi all, I'd like to announce the availability of 'stompy', a free tool to perform a fairly detailed black-box assessment of WWW session identifier generation algorithms. Session IDs are commonly used to track authenticated users, and as such, whenever they're predictable or simply vulnerable to

[Full-disclosure] [SECURITY] [DSA 1252-1] New vlc packages fix arbitrary code execution

2007-01-27 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1252-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 27th, 2007

[Full-disclosure] [SECURITY] [DSA 1253-1] New Mozilla Firefox packages fix several vulnerabilities

2007-01-27 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1253-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze January 27th, 2006

[Full-disclosure] [ GLSA 200701-25 ] X.Org X server: Multiple vulnerabilities

2007-01-27 Thread Matthias Geerdsen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200701-25 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] stompy the session stomper - tool availability

2007-01-27 Thread Simon Smith
Very cool. On 1/27/07 7:29 AM, Michal Zalewski [EMAIL PROTECTED] wrote: Hi all, I'd like to announce the availability of 'stompy', a free tool to perform a fairly detailed black-box assessment of WWW session identifier generation algorithms. Session IDs are commonly used to track

[Full-disclosure] Circarigel / Tazowolf / YTvigilante

2007-01-27 Thread Belinda Williams
FULL-DISCLOSURE: Circarigel Youtube Steet Team partners with alt.sexual.abuse.recovery for great vigilante internet justice __ _ _ ___ _ _| |_ _ _| |__ ___ | || / _ \ || | _| || | '_ \/ -_) \_, \___/\_,_|\__|\_,_|_.__/\___| |__/