[Full-disclosure] Cisco Security Advisory: SIP Packet Reloads IOS Devices Not Configured for SIP

2007-01-31 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: SIP Packet Reloads IOS Devices Not Configured for SIP Advisory ID: cisco-sa-20070131-sip http://www.cisco.com/warp/public/707/cisco-sa-20070131-sip.shtml Revision 1.0 For Public Release 2007 Jan 31 0900 UTC (GMT

[Full-disclosure] 2007 Security OPUS CFP: Closed (Agenda included)

2007-01-31 Thread Sharkey
Security OPUS would like to thank all those who responded to the call for papers. At this time all selected authors have been notified. This year's conference will include the following presentations: Luis Miras - Automated Exploit Detection in Binaries: Finding exploitable vulnerabilities in

Re: [Full-disclosure] Defeating Microsoft Office Genuine Advantage (OGA) Check

2007-01-31 Thread Simon Roberts
- Original Message On 1/30/07, Debasis Mohanty [EMAIL PROTECTED] wrote: Some lame methods to defeat a lame attempt to *prevent* Piracy or illegal usage of software - http://hackingspirits.com/vuln-rnd/vuln-rnd.html -d I find it amusing that the author of this PoC code took the

Re: [Full-disclosure] PC/Laptop microphones - shut the mouth Valdis

2007-01-31 Thread Bardus Populus
It appears your ability to gather contextual clues is crap. It is clearly writtin in another language and run through a translator into English (hence the quirky phrases). Had YOU possessed a greater mastery of the English language you likely could have noticed this on your own and saved us the

[Full-disclosure] [SECURITY] [DSA 1255-1] New libgtop2 packages fix arbitrary code execution

2007-01-31 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1255-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff January 31st, 2007

[Full-disclosure] [SECURITY] [DSA 1256-1] New gtk+2.0 packages fix denial of service

2007-01-31 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1256-1[EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff January 31st, 2007

[Full-disclosure] [ GLSA 200701-28 ] thttpd: Unauthenticated remote file access

2007-01-31 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200701-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200701-26 ] KSirc: Denial of Service vulnerability

2007-01-31 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200701-26 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] [ GLSA 200701-27 ] ELinks: Arbitrary Samba command execution

2007-01-31 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200701-27 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] stompy the session stomper - tool availability

2007-01-31 Thread Michal Zalewski
On Sat, 27 Jan 2007, Michal Zalewski wrote: I'd like to announce the availability of 'stompy', a free tool to perform a fairly detailed black-box assessment of WWW session identifier generation algorithms. I'm genuinely surprised by the amount of (mostly positive ;-) feedback I got! Just an

Re: [Full-disclosure] PC/Laptop microphones

2007-01-31 Thread chedder1
Last i checked, the klan was defined as a terrorist organization... Fighting terrorism with more terrorism is very effective in eleminating terrorism. Also, do not forget peanuts kill many more americains each year, who is fighting the god damned peanuts! ... Damned peanuts On Tue, Jan 30,

Re: [Full-disclosure] Defeating Microsoft Office Genuine Advantage (OGA) Check

2007-01-31 Thread James Matthews
I use some of the same methods that the author uses the fact remains that securing a OS and it's downloads is like looking for a diamond in a beach! On 1/31/07, Simon Roberts [EMAIL PROTECTED] wrote: - Original Message On 1/30/07, Debasis Mohanty [EMAIL PROTECTED] wrote: Some lame