[Full-disclosure] [ GLSA 200903-30 ] Opera: Multiple vulnerabilities

2009-03-16 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-30 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [USN-734-1] FFmpeg vulnerabilities

2009-03-16 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-734-1 March 16, 2009 ffmpeg, ffmpeg-debian vulnerabilities CVE-2008-4610, CVE-2008-4866, CVE-2008-4867, CVE-2009-0385 === A security issue affe

[Full-disclosure] [USN-738-1] GLib vulnerability

2009-03-16 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-738-1 March 16, 2009 glib2.0 vulnerability CVE-2008-4316 === A security issue affects the following Ubuntu releases: Ubuntu 7.10 Ubuntu 8.04 L

Re: [Full-disclosure] Google to base ads on surfing behaviour

2009-03-16 Thread Nick FitzGerald
Bipin Gautam wrote: > google is evil : http://news.zdnet.co.uk/internet/0,100097,39625962,00.htm That's news?8-) > "These ads will associate categories of interest " say sports, > gardening, cars, pets " with your browser, based on the types of sites > you visit and the pages you view,"

[Full-disclosure] [USN-736-1] GStreamer Good Plugins vulnerabilities

2009-03-16 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-736-1 March 16, 2009 gst-plugins-good0.10 vulnerabilities CVE-2009-0386, CVE-2009-0387, CVE-2009-0397 === A security issue affects the followin

[Full-disclosure] [ GLSA 200903-29 ] BlueZ: Arbitrary code execution

2009-03-16 Thread Pierre-Yves Rofes
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200903-29 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [USN-737-1] libsoup vulnerability

2009-03-16 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-737-1 March 16, 2009 libsoup vulnerability CVE-2009-0585 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.

[Full-disclosure] [USN-733-1] evolution-data-server vulnerability

2009-03-16 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-733-1 March 16, 2009 evolution-data-server vulnerability CVE-2009-0587 === A security issue affects the following Ubuntu releases: Ubuntu 6.06

[Full-disclosure] [USN-735-1] GStreamer Base Plugins vulnerability

2009-03-16 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-735-1 March 16, 2009 gst-plugins-base0.10 vulnerability CVE-2009-0586 === A security issue affects the following Ubuntu releases: Ubuntu 8.10

[Full-disclosure] w32 SEH omelet shellcode stage

2009-03-16 Thread Berend-Jan Wever
Hey all, I'm releasing some code for a technique which I call "omelet shellcode" that may be useful in some exploits. It is similar to egg-hunt shellcode, but will search user-land address space for multiple smaller eggs and recombine them into one larger block of shellcode and execute it. This is

Re: [Full-disclosure] SSL MiTM on Windows

2009-03-16 Thread Francisco J . Gómez Rodríguez
"Odysseus Proxy" = http://www.darknet.org.uk/2006/10/odysseus-proxy-for-mitm-attacks-testing-security-of-web-applications/ "Arpspoof windows port" = http://sourceforge.net/projects/arpspoof/ try: "Odysseus Proxy" + "Arpspoof windows port" except Error: try again! :( On Mon, Mar 16, 2009 at 1

[Full-disclosure] YSTS 3.0 - Call for Papers

2009-03-16 Thread Luiz Eduardo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 The call for papers for YSTS 3.0 is now open! The 3th edition will be happening on June, 22nd 2009 in Sao Paulo, Brazil. INTRODUCTION YSTS is a very unique event dedicated to the top-notch information Security Society in Brazil, bringing legendary s

[Full-disclosure] Google to base ads on surfing behaviour

2009-03-16 Thread Bipin Gautam
google is evil : http://news.zdnet.co.uk/internet/0,100097,39625962,00.htm "These ads will associate categories of interest — say sports, gardening, cars, pets — with your browser, based on the types of sites you visit and the pages you view," ... As with any other cookie, this tracking file c

Re: [Full-disclosure] SSL MiTM on Windows

2009-03-16 Thread BlackHawk
tryed this? http://www.oxid.it/cain.html ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] SSL MiTM on Windows

2009-03-16 Thread Mohammad Hosein
i'm looking for a decent alternative for ettercap capable of running on Vista+ and support sniff in bridge mode to conduct MiTM on ssl & ssh . suggestions ?and while we are at it anyone ever successfully run ettercap on Vista or 2K8 on bridge mode with recent winpcaps ?

Re: [Full-disclosure] The BBC acquired a botnet, but was it legal? - Update

2009-03-16 Thread James Matthews
No it's not acceptable! But they seem to do what ever suits them! On Mon, Mar 16, 2009 at 12:52 AM, Ivan . wrote: > According to Struan Robertson, a technology lawyer with Pinsent > Masons, in a posting on Out-Law.com, the BBC's statement that the > activity would only be illegal if those behind