Re: [Full-disclosure] FFSpy, a firefox malware PoC

2009-05-26 Thread Shell Code
On Wed, May 20, 2009 at 6:12 AM, saphex sap...@gmail.com wrote: I think this is interesting, http://myf00.net/?p=18 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by

Re: [Full-disclosure] FFSpy, a firefox malware PoC

2009-05-26 Thread James Matthews
On the iPhone a new app came out called MobileSpy. Designed to secretly record all activity on the iPhone. OMG The iPhone now has spyware etc. No the user must 1. Jailbreak his phone 2. Download and install the Mobilespy application. Recently a person told me that stupidity is a capital crime.

[Full-disclosure] [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-26 Thread Thierry Zoller
From the low-hanging-fruit-department Firefox et al. Denial of Service - All versions supporting SVG CHEAP Plug :

Re: [Full-disclosure] [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-26 Thread Thierry Zoller
Hi Sub, S does not work on firefox 3.0.10, tested Reproduced the bug on 3.0.10 prior to posting. -- http://blog.zoller.lu Thierry Zoller ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted

Re: [Full-disclosure] FFSpy, a firefox malware PoC

2009-05-26 Thread David Blanc
On Tue, May 26, 2009 at 8:38 PM, Shell Code technobus...@gmail.com wrote: I would appreciate if you post replies to the list instead of sending it only to me. My comments inline. On Tue, May 26, 2009 at 5:10 PM, saphex sap...@gmail.com wrote: I fail to understand what is new or interesting in

[Full-disclosure] SEC Consult SA-20090525-1 :: Nortel Contact Center Manager Server Password Disclosure Vulnerability

2009-05-26 Thread Bernhard Mueller
SEC Consult Security Advisory 20090525-1 == title: Nortel Contact Center Manager Server Password Disclosure program: Nortel Contact Center Manager Server vulnerable version:

[Full-disclosure] SEC Consult SA-20090525-4 :: SonicOS Format String Vulnerability

2009-05-26 Thread Bernhard Mueller
SEC Consult Security Advisory 20090525-4 == title: SonicOS Format String Vulnerability program: SonicWALL Global VPN Client vulnerable version: PRO 4100 SonicOS 4.0.0.2-51e Standard and Enhanced

[Full-disclosure] [ GLSA 200905-08 ] NTP: Remote execution of arbitrary code

2009-05-26 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200905-08 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-disclosure] SEC Consult SA-20090525-3 :: SonicWALL Global VPN Client Local Privilege Escalation Vulnerability

2009-05-26 Thread Bernhard Mueller
SEC Consult Security Advisory 20090525-3 == title: SonicWALL Global VPN Client Local Privilege Escalation Vulnerability program: SonicWALL Global VPN Client vulnerable version: Global VPN

[Full-disclosure] SEC Consult SA-20090525-2 :: SonicWALL Global Security Client Local Privilege Escalation Vulnerability

2009-05-26 Thread Bernhard Mueller
SEC Consult Security Advisory 20090525-2 == title: SonicWALL Global Security Client Local Privilege Escalation Vulnerability program: SonicWALL Global Security Client

[Full-disclosure] SEC Consult SA-20090525-0 :: Nortel Contact Center Manager Server Authentication Bypass Vulnerability

2009-05-26 Thread Bernhard Mueller
SEC Consult Security Advisory 20090525-0 == title: Nortel Contact Center Manager Server Authentication Bypass program: Nortel Contact Center Manager Server vulnerable version:

Re: [Full-disclosure] FFSpy, a firefox malware PoC

2009-05-26 Thread Shell Code
I would appreciate if you post replies to the list instead of sending it only to me. My comments inline. On Tue, May 26, 2009 at 5:10 PM, saphex sap...@gmail.com wrote: I fail to understand what is new or interesting in this POC. If a person with malicious intent gains so much access to a

[Full-disclosure] Addendum : [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-26 Thread Thierry Zoller
For those that failed to reproduce, try naming the POC file with an XHTML extension. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] FFSpy, a firefox malware PoC

2009-05-26 Thread saphex
ok On Tue, May 26, 2009 at 4:08 PM, Shell Code technobus...@gmail.com wrote: I would appreciate if you post replies to the list instead of sending it only to me. My comments inline. On Tue, May 26, 2009 at 5:10 PM, saphex sap...@gmail.com wrote: I fail to understand what is new or

Re: [Full-disclosure] FFSpy, a firefox malware PoC

2009-05-26 Thread saphex
ok On Tue, May 26, 2009 at 4:30 PM, David Blanc davidblanc1...@gmail.com wrote: On Tue, May 26, 2009 at 8:38 PM, Shell Code technobus...@gmail.com wrote: I would appreciate if you post replies to the list instead of sending it only to me. My comments inline. On Tue, May 26, 2009 at 5:10 PM,

[Full-disclosure] [IMF 2009] 3rd Call - Deadline Extended

2009-05-26 Thread Oliver Goebel
Dear all, the deadline for the submission of papers has been extended. Accepted papers will be published in IEEE Computer Society's Conference Proceedings Series and be available in the IEEE online Digital Library. Please excuse possible cross-postings.

[Full-disclosure] Drupal 6 Content Access Module XSS

2009-05-26 Thread Justin Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Details of this disclosure have been posted at http://lampsecurity.org/drupal_6_content_access_xss Vendor Notified: 05/19/2009 Description of Vulnerability: - - Drupal (http://drupal.org) is a robust content management