[Full-disclosure] Orkut Vulnerability

2007-02-06 Thread Fabio Neves Sarmento [ Gmail ]
Anyone knows if orkut have a news XSS or SQL Injections vulnerability's? ( always have a new xss ) -- + Cordialmente, + Fábio N Sarmento + Analista de Sistemas PL + Vox Line Contact Center + http://www.voxline.com.br + fabior2 [at] gmail.com + 55 11 9978 2646

[Full-disclosure] PS Information Leak on HP True64 Alpha OSF1 v5.1 1885

2007-02-06 Thread Andrea \bunker\ Purificato
[After months of silence from the HP Software Security Response Team] -Type: Information leak -Risk: low -Author: Andrea bunker Purificato - http://rawlab.mindcreations.com -Description: the ps command (also /usr/ucb/ps) on HP OSF1 v5.1 Alpha, developed without an eye to security, allows

Re: [Full-disclosure] Informix SQL injection

2007-02-06 Thread Zed Qyves
From database hackers handbook courtesy of David Litchfield - First create your temptable via standard SQL. INSERT INTO temptable (name,conts) VALUES ('resultsfile', FILETOCLOB('/tmp/result', 'server'))

[Full-disclosure] rPSA-2007-0025-1 postgresql postgresql-server

2007-02-06 Thread rPath Update Announcements
rPath Security Advisory: 2007-0025-1 Published: 2007-02-06 Products: rPath Linux 1 Rating: Major Exposure Level Classification: Local User Deterministic Vulnerability Updated Versions: postgresql=/[EMAIL PROTECTED]:devel//1/8.1.7-0.1-1 postgresql-server=/[EMAIL

[Full-disclosure] Bluepill's Rutkowska was or is a Man ?!

2007-02-06 Thread weirdstuff68
I found this in deleted edits on english Wikipedia on Bluepill Vista backdoor security researcher Joanna Rutkowska: http://www.rutkowska.yoyo.pl What is going on ? Is that true ? Any one knows ? -- Earn While You Learn Advance your career with an accredited online degree. Flexible...

[Full-disclosure] (offtopic) Re: Bluepill's Rutkowska was or is a Man ?!

2007-02-06 Thread 3APA3A
Dear [EMAIL PROTECTED], --Tuesday, February 6, 2007, 2:17:55 AM, you wrote to full-disclosure@lists.grok.org.uk: whc I found this in deleted edits on english Wikipedia on Bluepill whc Vista backdoor security researcher Joanna Rutkowska: whc http://www.rutkowska.yoyo.pl whc What is going

Re: [Full-disclosure] PS Information Leak on HP Tru64 Alpha OSF1 v5.1 1885

2007-02-06 Thread Andrea \bunker\ Purificato
On mar, 2007-02-06 at 12:44 +0100, Andrea bunker Purificato wrote: -Code: http://rawlab.mindcreations.com/codes/exp/nix/osf1true64ps.ksh Sorry, dyslexic typo :-) http://rawlab.mindcreations.com/codes/exp/nix/osf1tru64ps.ksh -- Andrea bunker Purificato

Re: [Full-disclosure] (offtopic) Re: Bluepill's Rutkowska was or is aMan ?!

2007-02-06 Thread Lindley James R
The only organ of interest on this list is the one between your ears. JimL -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of 3APA3A Sent: Tuesday, February 06, 2007 9:54 AM To: [EMAIL PROTECTED] Cc: full-disclosure@lists.grok.org.uk Subject:

Re: [Full-disclosure] Bluepill's Rutkowska was or is a Man ?!

2007-02-06 Thread Michal Zalewski
On Tue, 6 Feb 2007 [EMAIL PROTECTED] wrote: What is going on ? Is that true ? Any one knows ? That dude is clearly quite determined to debate this like a matter of (inter?)national security, on Wikipedia and elsewhere, but it is getting oddly inappropriate. Get a life and let go. /mz

[Full-disclosure] [USN-419-1] Samba vulnerabilities

2007-02-06 Thread Kees Cook
=== Ubuntu Security Notice USN-419-1 February 06, 2007 samba vulnerabilities CVE-2007-0452, CVE-2007-0454 === A security issue affects the following Ubuntu releases: Ubuntu

[Full-disclosure] [USN-420-1] KDE library vulnerability

2007-02-06 Thread Kees Cook
=== Ubuntu Security Notice USN-420-1 February 06, 2007 kdelibs vulnerability CVE-2007-0537 === A security issue affects the following Ubuntu releases: Ubuntu 5.10 Ubuntu 6.06

Re: [Full-disclosure] Every MS Exploit

2007-02-06 Thread Aaron Gray
I believe there are more than one exploit for each MS patch. Aaron - Original Message - From: [EMAIL PROTECTED] To: full-disclosure@lists.grok.org.uk Sent: Tuesday, February 06, 2007 5:31 AM Subject: [Full-disclosure] Every MS Exploit Project to find exploits for every MS Security

[Full-disclosure] Security Contact at Network Physics

2007-02-06 Thread Xyberpix
Hey All, Anyone got a contact at Network Physics at all? http://www.networkphysics.com Any help on this one would be greatly appreciated. Cheers, X ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] [USN-417-2] PostgreSQL 8.1 regression

2007-02-06 Thread Martin Pitt
=== Ubuntu Security Notice USN-417-2 February 06, 2007 postgresql-8.1 regression https://launchpad.net/bugs/83505 === A security issue affects the following Ubuntu releases:

[Full-disclosure] How To Force Your ISP to Stop Child Porn

2007-02-06 Thread Robert Kim Wireless Internet Advisor
Team, The FBI is currently working on tracing the origins of a video where a 2 month old baby is being raped. The source ISP is not cooperating. This is common. If you want your isp to reveal the whereabouts of child abusers, put yourself on the map at http://www.child-safe-isp.com hopefully, a

[Full-disclosure] AP report: Hackers attack key Net traffic computers

2007-02-06 Thread Juha-Matti Laurio
According to http://seattlepi.nwsource.com/business/1700AP_Internet_Attacks.html Experts said the unusually powerful attacks lasted for hours but passed largely unnoticed by most computer users, a testament to the resiliency of the Internet. Public CERT sources are pointing to this TEAM

Re: [Full-disclosure] Bluepill's Rutkowska was or is a Man ?!

2007-02-06 Thread nnp
Could it be that something on wikipedia wasn't 100% fact! Omg, how could it lie to us like some sort of publicly editable doodling board oh wait :P On 2/6/07, Michal Zalewski [EMAIL PROTECTED] wrote: On Tue, 6 Feb 2007 [EMAIL PROTECTED] wrote: What is going on ? Is that true ? Any one

Re: [Full-disclosure] How To Force Your ISP to Stop Child Porn

2007-02-06 Thread Loptr Chaote
On 2/6/07, Robert Kim Wireless Internet Advisor [EMAIL PROTECTED] wrote: Team, The FBI is currently working on tracing the origins of a video where a 2 month old baby is being raped. The source ISP is not cooperating. This is common. If you want your isp to reveal the whereabouts of child

[Full-disclosure] [ MDKSA-2007:035 ] - Updated gd packages fix DoS vulnerability.

2007-02-06 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:035 http://www.mandriva.com/security/

[Full-disclosure] [ MDKSA-2007:036 ] - Updated libwmf packages fix embedded gd DoS vulnerability.

2007-02-06 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:036 http://www.mandriva.com/security/

[Full-disclosure] [ MDKSA-2007:037 ] - Updated postgresql packages address multiple vulnerabilities

2007-02-06 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:037 http://www.mandriva.com/security/

[Full-disclosure] [ MDKSA-2007:038 ] - Updated php packages to address multiple issues

2007-02-06 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:038 http://www.mandriva.com/security/

Re: [Full-disclosure] AP report: Hackers attack key Net traffic computers

2007-02-06 Thread James Matthews
Yes they hit the .org servers! Maybe this is a little wake up call for all the people that don't put money into computer security! On 2/6/07, Juha-Matti Laurio [EMAIL PROTECTED] wrote: According to http://seattlepi.nwsource.com/business/1700AP_Internet_Attacks.html Experts said the unusually

Re: [Full-disclosure] How To Force Your ISP to Stop Child Porn

2007-02-06 Thread James Matthews
This is great when something normal comes up they stop it however for movies and songs not! WTF On 2/6/07, Loptr Chaote [EMAIL PROTECTED] wrote: On 2/6/07, Robert Kim Wireless Internet Advisor [EMAIL PROTECTED] wrote: Team, The FBI is currently working on tracing the origins of a video

Re: [Full-disclosure] (offtopic) Re: Bluepill's Rutkowska was or is aMan ?!

2007-02-06 Thread bambam
Which is, presumably, your nose. On 2/6/07, Lindley James R [EMAIL PROTECTED] wrote: The only organ of interest on this list is the one between your ears. JimL -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of 3APA3A Sent: Tuesday, February 06,

[Full-disclosure] Alibaba Alipay Remote Code Execute Vulnerability-0DAY

2007-02-06 Thread ruder cocoruder
Alibaba Alipay Remote Code Execute Vulnerability by cocoruder(frankruder_at_hotmail.com) http://ruder.cdut.net Summary: Alipay is China’s leading online payment service, and a division of Alibaba.com. It enables individuals and businesses to securely, easily and quickly send and receive

[Full-disclosure] [SECURITY] [DSA 1258-1] New Mozilla Firefox packages fix several vulnerabilities

2007-02-06 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 1258-1[EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze February 7th, 2007