[Full-disclosure] Packetshaper Touch password cipher cracking

2008-12-11 Thread Frédéric Charpentier
hi all ;) I am looking for a technical security contact at Packeteer / Bluecoat. cheers, fred. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Two windows exploits in the wild

2008-12-11 Thread James Matthews
One IE exploit and One Wordpad http://it.slashdot.org/it/08/12/10/206216.shtml On a more interesting note i feel that slashdot should screen there writers better Here is a quote that i saw *The exploit is a typical heap overflow that appears to be exploiting something in the XML parser.' *Try to

Re: [Full-disclosure] Packetshaper Touch password cipher cracking

2008-12-11 Thread Kelly, Tom
[EMAIL PROTECTED] Tom Frédéric Charpentier wrote: hi all ;) I am looking for a technical security contact at Packeteer / Bluecoat. cheers, fred. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] 21 Million German bank accounts stolen - but accounts are still more secure than many other ones

2008-12-11 Thread Martin Salfer
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Hello, English readers might wonder why Germans usually don't use cheques: because they're too expensive and insecure. Everybody prefers electronic money transfers (Überweisung) as those are for free and well protected. And direct debits or

[Full-disclosure] Secunia Research: CA ARCserve Backup RPC handle_t Argument Vulnerability

2008-12-11 Thread Secunia Research
== Secunia Research 11/12/2008 - CA ARCserve Backup RPC handle_t Argument Vulnerability - == Table of Contents Affected

[Full-disclosure] FW: 21 Million German bank accounts stolen - but accounts are still more secure than many other ones

2008-12-11 Thread Viktor Larionov
P.S. By baking trojans, I meant trojans injecting additional payment information into your bank transfers - e.g. you make 5 payments, but the trojan makes also the sixth one, still browser with the help of a trojan displays you only 5 of them. You press accept - and you'r done. Correct me if I'm

Re: [Full-disclosure] 21 Million German bank accounts stolen - but accounts are still more secure than many other ones

2008-12-11 Thread Viktor Larionov
Dear Martin of good old Germany, You are absolutely correct on the poor security and other things...but you actually should keep in mind, that US internet banking, as far as I am concerned by the amount and complexity of operations is way behind Germany and Europe in general. In example, US

[Full-disclosure] Checkpoint Sources plus SPLAT Remote Root Exploit.

2008-12-11 Thread CheckPoint Power
Hello world, Checkpoint VPN1 is currently one of the most comercial wide used firewall in the market. Checkpoints products are currently protecting (hehe right...) from medium and small business to highest corporative and government systems. Secure Plataform is a linux based system, developed

Re: [Full-disclosure] FD subject line/name of org suggestion...

2008-12-11 Thread Phillip Partipilo
Could try a separate folder and using rules to segregate FD emails. There really arent *that* many emails, I mean, compared to nearly insane volume of ntsysadmin or activedir. On Dec 11, 2008, at 1:54 AM, - o z - wrote: Hi everyone! Is it just me, or is it normal for everyone else

Re: [Full-disclosure] Browser Security Handbook

2008-12-11 Thread de gracia carron, jose angel (ext)
Asi es Google ha publicado un Manual de Seguridad del navegador accesible para todo el publico con la esperanza de ayudar a hacer la Web un lugar más seguro. El manual consta de unas 60 páginas donde podemos encontrar amplio conjunto de características de seguridad y características de uso

Re: [Full-disclosure] FD subject line/name of org suggestion...

2008-12-11 Thread Valdis . Kletnieks
On Thu, 11 Dec 2008 10:39:51 EST, Phillip Partipilo said: Could try a separate folder and using rules to segregate FD emails. There really arent *that* many emails, I mean, compared to nearly insane volume of ntsysadmin or activedir. Are they worse than linux-kernel, which is averaging

Re: [Full-disclosure] We're letting the bad guys win

2008-12-11 Thread Valdis . Kletnieks
On Wed, 10 Dec 2008 08:51:27 GMT, n3td3v said: This is a serious mailing list not one where there are kids fooling around, they would be too scared to post here because of the military, government and intelligence services who are HUMINT subscribed. You have that backwards. The kids fooling

[Full-disclosure] Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities

2008-12-11 Thread Rafel Ivgi
Aspect9: Internet Explorer 8.0 Beta 2 Anti-XSS Filter Vulnerabilities Release Date: December 11, 2008 Date Reported: October 5, 2008 Severity: Medium-High (Execute scripts, Turning Protection Off, Transfer data Cross Domains) Vendor: Microsoft Systems Affected: Windows Platform with Internet

Re: [Full-disclosure] FD subject line/name of org suggestion...

2008-12-11 Thread James Matthews
This is quite simple to do on Gmail. All you need to do is open any full-disclosure email. Then click on show details and select filter messages from this mailing list. On Thu, Dec 11, 2008 at 6:10 PM, [EMAIL PROTECTED] wrote: On Thu, 11 Dec 2008 10:39:51 EST, Phillip Partipilo said: Could

Re: [Full-disclosure] Two windows exploits in the wild

2008-12-11 Thread don bailey
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On a more interesting note i feel that slashdot should screen there writers better Here is a quote that i saw /The exploit is a typical heap overflow that appears to be exploiting something in the XML parser.' /Try to have someone that knows what

Re: [Full-disclosure] FD subject line/name of org suggestion...

2008-12-11 Thread - o z - .
From: nytrok...@gmail.com Subject: Re: [Full-disclosure] FD subject line/name of org suggestion... This is quite simple to do on Gmail. All you need to do is open any full-disclosure email. Then click on show details and select filter messages from this mailing list. On Thu, Dec 11,

[Full-disclosure] Jobless techies turning to crime

2008-12-11 Thread Ivan .
Both PricewaterhouseCoopers (PwC) and security vendor Finjan are forecasting that the recession will fuel a significant rise in insider fraud and cyber crime in 2009. http://www.silicon.com/financialservices/0,3800010322,39363838,00.htm ___

[Full-disclosure] rPSA-2008-0336-1 tshark wireshark

2008-12-11 Thread rPath Update Announcements
rPath Security Advisory: 2008-0336-1 Published: 2008-12-11 Products: rPath Linux 1 Rating: Minor Exposure Level Classification: Indirect Deterministic Denial of Service Updated Versions: tshark=conary.rpath@rpl:1/1.0.5-0.1-1 wireshark=conary.rpath@rpl:1/1.0.5-0.1-1 rPath

Re: [Full-disclosure] Jobless techies turning to crime

2008-12-11 Thread James Matthews
These people have skills that can be used for good or bad. Everyone has to eat and i feel that these people should look into starting a new company or creating a website and blogging about there former workplace. On Fri, Dec 12, 2008 at 2:00 AM, Ivan . ivan...@gmail.com wrote: Both