Re: [Full-disclosure] 0day for sell

2007-08-29 Thread Juergen Marester
My previous e-mail was serious. Sorry if it's not correct to tell about that here. Anyway, since last week I also sell IE7 and Mozilla 0days. But, no problem, I will stop post here, and unsubscribe me from this list. For any interest, please mail me to this adress. Good bye and have a good day.

Re: [Full-disclosure] 0day for sell

2007-08-29 Thread Juergen Marester
My previous e-mail was serious. Sorry if it's not correct to tell about that here. Anyway, since last week I also sell IE7 and Mozilla 0days. But, no problem, I will stop post here, and unsubscribe me from this list. For any interest, please mail me to this adress. Good bye and have a good day.

[Full-disclosure] informative...

2007-08-29 Thread withak
http://www.belkin.com/search/?q='sid=2 -- Click for a free comparison on healthcare coverage and save 100's. http://tagline.hushmail.com/fc/Ioyw6h4d8cVbP3WrHvHiKzqvSEtshDBPtbZ7jmuLIw10GYhmtUej8U/ ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] informative...

2007-08-29 Thread Fabrizio
And even more informative http://www.belkin.com/search/?q=%3cscript%3ealert('XSS')%3c%2fscript%3esid=1 fabrizio http://www.staticrez.org On 8/28/07, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: http://www.belkin.com/search/?q='sid=2 -- Click for a free comparison on healthcare coverage

Re: [Full-disclosure] informative...

2007-08-29 Thread Fabrizio
Try some of these ;) http://www.google.com/search?hl=enq=inurl%3Asearchresults.jsp%3FbtnG=Search Fabrizio On 8/29/07, Andrea Purificato - bunker [EMAIL PROTECTED] wrote: Il giorno mer, 29/08/2007 alle 09.31 -0400, Fabrizio ha scritto: And even more informative

Re: [Full-disclosure] informative...

2007-08-29 Thread Andrea Purificato - bunker
Il giorno mer, 29/08/2007 alle 09.31 -0400, Fabrizio ha scritto: And even more informative http://www.belkin.com/search/?q=%3cscript%3ealert('XSS')%3c%2fscript% 3esid=1 [Informative 2] It seems a common practice, otherwise they were warned months ago, but no answer...

Re: [Full-disclosure] n.runs-SA-2007.027 - Sophos Antivirus UPX parsing Arbitrary CodeExecution Advisory

2007-08-29 Thread Valdis . Kletnieks
On Tue, 28 Aug 2007 15:49:31 PDT, Blue Boar said: I remember people being all paranoid about the DMCA. They were worried security researchers would be sued for trying to release vulnerability information. But since that turned out to be unfounded, I guess we don't have to worry about the

Re: [Full-disclosure] informative...

2007-08-29 Thread Fabio Pietrosanti (naif)
... http://seclists.org/fulldisclosure/2007/Jul/0504.html ... comments? Fabrizio wrote: Try some of these ;) http://www.google.com/search?hl=enq=inurl%3Asearchresults.jsp%3FbtnG=Search http://www.google.com/search?hl=enq=inurl%3Asearchresults.jsp%3FbtnG=Search Fabrizio

Re: [Full-disclosure] n.runs-SA-2007.027 - Sophos Antivirus UPX parsing Arbitrary CodeExecution Advisory

2007-08-29 Thread Simon Smith
I LOVE THE DMCA! Kevin Finisterre (lists) wrote: heh who would do such a thing? Guess we all get to wait and see who the first Guinea pig is gonna be. Hope germany has an EFF / Granick floating around to fight off some of this nonsense. -KF On Aug 28, 2007, at 6:49 PM, Blue Boar

[Full-disclosure] EnterpriseDB Advanced Server 8.2 Unitialized Pointer

2007-08-29 Thread Joxean Koret
EnterpriseDB Advanced Server 8.2 Unitialized Pointer Product Description: EnterpriseDB is a (comercial) relational database management system based on PostgreSQL. Vulnerable Versions: EnterpriseDB Advanced Server 8.2 in all supported

[Full-disclosure] Cisco Security Advisory: XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page

2007-08-29 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: XSS and SQL Injection in Cisco CallManager/Unified Communications Manager Logon Page Advisory ID: cisco-sa-20070829-ccm http://www.cisco.com/warp/public/707/cisco-sa-20070829-ccm.shtml Revision 1.0 For Public Release 2007

Re: [Full-disclosure] informative...

2007-08-29 Thread Andrea Purificato - bunker
On Wednesday 29 August 2007, Fabio Pietrosanti (naif) wrote: http://seclists.org/fulldisclosure/2007/Jul/0504.html comments? Hi Fabio, I fully agree with you, but i have less trouble than you speaking about this type of vulnerability after reporting the XSS to the owner. If nobody replies to

[Full-disclosure] Multiple vulnerabilities in Doomsday 1.9.0-beta5.1

2007-08-29 Thread Luigi Auriemma
### Luigi Auriemma Application: Doomsday http://www.doomsdayhq.com http://www.dengine.net http://sourceforge.net/projects/deng/ Versions: =

[Full-disclosure] sqlninja 0.1.3 released

2007-08-29 Thread A. R.
Hello, fellow security enthusiasts, a new version of sqlninja is out at sourceforge ! Introduction sqlninja is a tool to exploit SQL Injection vulnerabilities on a web application that uses Microsoft SQL Server as its back-end. Its main goal is to provide a remote shell on the

[Full-disclosure] [SECURITY] [DSA 1361-1] New postfix-policyd packages fix arbitrary code execution

2007-08-29 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1361[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp August 29th, 2007

[Full-disclosure] [SECURITY] [DSA 1362-1] New lighttpd packages fix several vulnerabilities

2007-08-29 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1362[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp August 29th, 2007

[Full-disclosure] Multiple improper file path handling issues

2007-08-29 Thread edi.strosar
= Team Intell Security Advisory TISA2007-09-Public - Multiple improper file path handling issues

[Full-disclosure] Multiple eScan products insecure file permissions

2007-08-29 Thread edi.strosar
= Team Intell Security Advisory TISA2007-13-Public - Multiple eScan products insecure file permissions

[Full-disclosure] [USN-507-1] tcp-wrappers vulnerability

2007-08-29 Thread Kees Cook
=== Ubuntu Security Notice USN-507-1August 30, 2007 tcp-wrappers vulnerability https://launchpad.net/bugs/135332 === A security issue affects the following Ubuntu releases:

[Full-disclosure] Point, Click ... Eavesdrop: How the FBI Wiretap Net Operates

2007-08-29 Thread Ivan .
http://www.wired.com/politics/security/news/2007/08/wiretap ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Point, Click ... Eavesdrop: How the FBI Wiretap Net Operates

2007-08-29 Thread Kevin Finisterre (lists)
Great... Sprint's incompetent ass running a secure network for eavesdropping. How ironic these goons can't even keep a handle on things down in Kansas City, now this. Lauren Proctor you still out there buddy? Sprint Security spreads lies -KF On Aug 29, 2007, at 9:27 PM, Ivan .

Re: [Full-disclosure] Point, Click ... Eavesdrop: How the FBI Wiretap Net Operates

2007-08-29 Thread Kevin Finisterre (lists)
What you mean like Jerry Franke ? The name is Toby btw... and they are not name drops .. they are call outs. -KF On Aug 30, 2007, at 12:02 AM, Joey Mengele wrote: Dear List, On Wed, 29 Aug 2007 23:22:27 -0400 Kevin Finisterre (lists) [EMAIL PROTECTED] wrote: Great... Sprint's incompetent