[Full-disclosure] W3af ninja training class in NYC

2009-05-27 Thread Michelangelo Sidagni
NopSec and Bonsai Information Security presents w3af Ninja Training Class June 17th / 18th 2009 NopSec, Inc. SOC 155 Water St., Brooklyn, NY 11201 USA For Information and Registration visit: http://tinyurl.com/w3afnyctraining Introduction Internet security threats are migrating from

[Full-disclosure] iKAT - The Interactive Kiosk Attack Tool v2.0 Released - http://ikat.ha.cked.net

2009-05-27 Thread Paul Craig
Last year at Defcon 16 I released iKAT v1.0, the Interactive Kiosk Attack tool. Those who went to Defcon and saw the hacked kiosks at the riverra, may realize just how effective iKAT was on the day. (http://www.mr337.com/blog/wp-content/uploads/2008/08/terminalhacking.jpg) The concept is very

Re: [Full-disclosure] iKAT - The Interactive Kiosk Attack Tool v2.0 Released - http://ikat.ha.cked.net

2009-05-27 Thread Sebastian Krahmer
On Wed, May 27, 2009 at 09:01:33PM +1200, Paul Craig wrote: [...] On a final note, the 'iKAT Girl' as some people call her ( the iKAT logo) , is a common point of contention people like to email me about. Apparently a half naked girl plucking a thong out of her ass is not acceptable when

Re: [Full-disclosure] Addendum : [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Jim Parkhurst
If I understand the process, saving the text at [IV. Proof of concept] (following the ~~~... to an .XHTML file, and launch the file using Firefox, I should lose functionality (Browser doesn't respond any longer to any user input, all tabs are no longer accessible, your work if any (hail to the

Re: [Full-disclosure] Addendum : [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Thierry Zoller
Hi Jim, Read again: Affected : All Firefox versions that support SVG. Then think about what version of Firefox you are using. JP If I understand the process, saving the text at [IV. Proof of JP concept] (following the ~~~... to an .XHTML file, and launch the JP file using Firefox, I should lose

[Full-disclosure] [ GLSA 200905-09 ] libsndfile: User-assisted execution of arbitrary code

2009-05-27 Thread Alex Legler
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200905-09 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Addendum : [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Stuart Dunkeld
On Wed, May 27, 2009 at 7:38 PM, Thierry Zoller thie...@zoller.lu wrote: Hi Jim, Read again: Affected : All Firefox versions that support SVG. Then think about what version of Firefox you are using. SVG (including circle) was originally implemented in Firefox 1.5 -

Re: [Full-disclosure] Addendum : [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Vladimir '3APA3A' Dubrovin
Dear Jim Parkhurst, It may depend on video card and video drivers and/or amount of memory/video memory. 9 years ago there was vulnerability in Internet explorer with displaying scaled image: http://securityvulns.com/advisories/ie5freeze.asp

Re: [Full-disclosure] [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Thierry Zoller
Hi Michal, Yep, positive, welcome to the world of rediscovery, sad that the bugs seems to been known since 2007. Speak about Mozilla being the fastest to patch. Ticket has now been marked as duplicate of that one. -- http://blog.zoller.lu Thierry Zoller

[Full-disclosure] [ MDVSA-2009:123 ] opensc

2009-05-27 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:123 http://www.mandriva.com/security/

Re: [Full-disclosure] [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Michal Zalewski
Bugzilla entry: https://bugzilla.mozilla.org/show_bug.cgi?id=465615 Isn't that a duplicate of Guninski's bug from 2007? https://bugzilla.mozilla.org/show_bug.cgi?id=393832 /mz ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Addendum : [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Jim Parkhurst
Silly me. Since 1. There was no version specific information provided by the OP (I looked for that) -and- 2. you tell me that SVG [whatever that is] (including circle) was originally implemented in Firefox 1.5 -and- 3. There is no documentation that SVG has /not/ been removed from Firefox -and-

Re: [Full-disclosure] [TZO-26-2009] Firefox (all?) Denial of Service through unclamped loop (SVG)

2009-05-27 Thread Chris Evans
On Wed, May 27, 2009 at 12:03 PM, Thierry Zoller thie...@zoller.lu wrote: Hi Michal, Yep, positive, welcome to the world of rediscovery, sad that the bugs seems to been known since 2007. Speak about Mozilla being the fastest to patch. Ticket has now been marked as duplicate of that one.

[Full-disclosure] [TZO-27-2009] Firefox Denial of Service (Keygen)

2009-05-27 Thread Thierry Zoller
From the very-low-hanging-fruit-department Firefox Denial of Service (KEYGEN) Release mode: Forced release. Ref

Re: [Full-disclosure] [TZO-27-2009] Firefox Denial of Service (Keygen)

2009-05-27 Thread Jeremy Brown
Looks like somebody's been using a browser fuzzer :) On Wed, May 27, 2009 at 9:14 PM, Thierry Zoller thie...@zoller.lu wrote:              From the very-low-hanging-fruit-department                   Firefox Denial of