[Full-disclosure] Internet attacks against Georgian web sites

2008-08-11 Thread Gadi Evron
In the last days news and government web sites in Georgia suffered DDoS attacks. While these attacks seem to affect the Georgian Internet, it is still there. Facts: 1. There are botnet attacks against .ge websites. 2. These attacks affect the .ge Internet infrastructure, but it's reachable. 3.

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Paul Ferguson [EMAIL PROTECTED] wrote: -- Gadi Evron [EMAIL PROTECTED] wrote: In the last days news and government web sites in Georgia suffered DDoS attacks. While these attacks seem to affect the Georgian Internet, it is still there. One

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Gadi Evron [EMAIL PROTECTED] wrote: In the last days news and government web sites in Georgia suffered DDoS attacks. While these attacks seem to affect the Georgian Internet, it is still there. Also, I wish to say: It is clear that there

[Full-disclosure] Inguma version 0.0.9 released

2008-08-11 Thread Joxean Koret
Hi, A new release of Inguma is available for download. This release fixes a bunch of bugs in about all parts of Inguma. In this version 6 new modules were added: dnsspoof, fakearp, dtspc, jsfuzz, ikescan and unicornscan. In the exploits section you will notice a bunch of new exploits. Just DOS

Re: [Full-disclosure] Internet justice delivered, criminals panic and run in despair

2008-08-11 Thread Valdis . Kletnieks
On Sun, 10 Aug 2008 08:30:07 PDT, alan shimel said: These people, who claim to protect Internet infrastructure, who claim hacking does not mean breaking into systems. The same people who have never experienced breaking into a system with PaX, mprotect restrictions, 16 bit ASLR, and RBAC

[Full-disclosure] anyone developing a secure telephony application for GSM CSD?

2008-08-11 Thread Fabio Pietrosanti (naif)
I would like to enter in contact with all the guys here that worked/developed on encrypted/secure telephony apps. Would like to start a community based platform for who worked/is working on this kind of technology in order to establish a standardization and interoperability path. No, i am not

[Full-disclosure] Surf Jack - HTTPS will not save you

2008-08-11 Thread Sandro Gauci
Say hello to a new security tool called Surf Jack which demonstrates a security flaw found in various public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set the Cookie secure flag. Tool: http://surfjack.googlecode.com/ Short paper:

Re: [Full-disclosure] Internet attacks against Georgian web sites

2008-08-11 Thread n3td3v
On Saturday Gadi Evron to Paul Ferguson said: http://linuxbox.org/pipermail/funsec/2008-August/018032.html I don't believe this is cyber warefare. Political tensions lead to cyber fans. I doubt RBN. let's not make this a story. Thanks for sharing! Interesting, Gadi. Big U-turn from

[Full-disclosure] George Ledin virus material training Request.

2008-08-11 Thread Jun...
Hi, I'm interested in George Ledin's, material training. http://www.newsweek.com/id/150465 Can someone send me any mail contact or direct link to download? Gracias. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread John C. A. Bambenek, GCIH, CISSP
I haven't looked terribly closely but the cyber attacks don't seem to match up with what I would consider military objectives... there are plenty of nationalists that come crawling out of the woodwork during events like this. If the attacks are targetted more at military objectives then I'd say

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread n3td3v
Gadi Evron has connections with the Israeli government and probably Mossad, how do we know its not the Israeli government behind these attacks? Think about the sudden U-turn I was talking about that Gadi Evron did on this particular security incident, one minute he was downplaying it, the next he

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread Valdis . Kletnieks
On Mon, 11 Aug 2008 18:58:11 BST, n3td3v said: 1) Full-Disclosure is run by MI5/6. 2) Securityfocus Bugtraq is run by FBI/CIA. 3) Funsec is run by Mossad. No, that's just what THEY want you to believe. I'd tell you what is really going on, but this is an insecure channel and there's been

[Full-disclosure] [ GLSA 200808-11 ] UUDeview: Insecure temporary file creation

2008-08-11 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200808-11 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - -

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread Robert Marquardt
On Aug 11, 2008, at 8:54 PM, [EMAIL PROTECTED] wrote: On Mon, 11 Aug 2008 18:58:11 BST, n3td3v said: 1) Full-Disclosure is run by MI5/6. 2) Securityfocus Bugtraq is run by FBI/CIA. 3) Funsec is run by Mossad. No, that's just what THEY want you to believe. I'd tell you what is really

[Full-disclosure] [ MDVSA-2008:165 ] perl

2008-08-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:165 http://www.mandriva.com/security/

Re: [Full-disclosure] [funsec] Internet attacks against Georgian web sites

2008-08-11 Thread n3td3v
On Mon, Aug 11, 2008 at 7:54 PM, [EMAIL PROTECTED] wrote: I'd tell you what is really going on, but this is an insecure channel I'll tell you what's really going on, Gadi Evron is partaking in information warfare via the mailing lists on behalf of the Israeli government. Note: This thread

[Full-disclosure] rPSA-2008-0249-1 openldap openldap-clients openldap-servers

2008-08-11 Thread rPath Update Announcements
rPath Security Advisory: 2008-0249-1 Published: 2008-08-11 Products: rPath Appliance Platform Linux Service 2 rPath Linux 2 Rating: Severe Exposure Level Classification: Remote Deterministic Denial of Service Updated Versions: [EMAIL PROTECTED]:2/2.4.11-1-0.1 [EMAIL

[Full-disclosure] rPSA-2008-0247-1 gvim vim vim-minimal

2008-08-11 Thread rPath Update Announcements
rPath Security Advisory: 2008-0247-1 Published: 2008-08-11 Products: rPath Appliance Platform Linux Service 2 rPath Linux 2 Rating: Minor Exposure Level Classification: Indirect Deterministic Unauthorized Access Updated Versions: [EMAIL PROTECTED]:2/7.1.326-0.2-1 [EMAIL

Re: [Full-disclosure] Team SHATTER Security Advisory: SQL Injection in Oracle Database (DBMS_DEFER_SYS.DELETE_TRAN)

2008-08-11 Thread Team SHATTER
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The DBA role in Oracle Database is not the same as SYSDBA privilege, which is granted to SYS. There are many things that a user granted the DBA role can't do - the most important being the ability to alter SYS owned objects. This is true on databases

Re: [Full-disclosure] what happened to fd??.. even eff cant save it??.

2008-08-11 Thread coderman
On Sun, Aug 10, 2008 at 3:45 AM, Joel Jose [EMAIL PROTECTED] wrote: if fd is outlawed.. you idiot. fd is not announcing existence of your sploit to the world, scant on detail, in some kind of white hat tease days, weeks, even months ahead of disclosure. fd is dropping the bomb out of the blue

Re: [Full-disclosure] Surf Jack - HTTPS will not save you

2008-08-11 Thread coderman
On Mon, Aug 11, 2008 at 4:03 AM, Sandro Gauci [EMAIL PROTECTED] wrote: Say hello to a new security tool called Surf Jack which demonstrates a security flaw found in various public sites. The proof of concept tool allows testers to steal session cookies on HTTP and HTTPS sites that do not set

[Full-disclosure] [PLSA 2008-21] Ruby: Multiple Vulnerabilities

2008-08-11 Thread Pınar Yanardağ
Pardus Linux Security Advisory 2008-21[EMAIL PROTECTED] Date: 2008-08-12 Severity: 3 Type: Remote

[Full-disclosure] [PLSA 2008-22] Php: Multiple Overflows

2008-08-11 Thread Pınar Yanardağ
Pardus Linux Security Advisory 2008-22[EMAIL PROTECTED] Date: 2008-08-12 Severity: 2 Type: Remote

[Full-disclosure] Ukraine?

2008-08-11 Thread Drop Drop
Hello. Is there any security research companies in Ukraine? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/