Re: [Full-disclosure] DefCon 17 CTF packet captures online

2009-09-08 Thread dreyer
What about the promised CTF stats? :) Cheers, 2009/9/7 Holt Sorenson h...@nosneros.net We have just finished the last bits in getting the DefCon 17 CTF packet captures online. Snag them from: http://ddtek.biz/ 3 ur sheep and mom too, ddtek -- Holt Sorenson h...@nosneros.net

Re: [Full-disclosure] Microsoft Internet Information Server ftpd zeroday

2009-09-08 Thread Thierry Zoller
Hi Kingcope, Thanks to a hint by Petar on the G-SEC blog [1] it appears that the very same bug was present in IIS3 and IIS4 and discovered by eeye in 1999 : http://research.eeye.com/html/advisories/published/AD19990124.html Microsoft IIS (Internet Information Server) FTP service contains a

[Full-disclosure] [scip_Advisory 4021] IBM Lotus Notes 8.5 RSS Widget Privilege Escalation

2009-09-08 Thread Marc Ruef
IBM Lotus Notes 8.5 RSS Widget Privilege Escalation scip AG Vulnerability ID 4021 (09/08/2009) http://www.scip.ch/?vuldb.4021 I. INTRODUCTION Lotus Notes is a client-server, collaborative application developed and sold by IBM Software Group. More information is available on the official

[Full-disclosure] This is n3td3v and Gary McKinnon's lawyer. My client's have asburger syndrome.

2009-09-08 Thread Central Security District of UK [MI7.5]
I just go off the phone with intelligence MI7 and the CIB (Upgraded from CIA++, super savage secret) have relayed to me in code that n3td3v security is coming back stronger than ever. Over in Langley we know that n3td3v has the finest security tactics. Super fortified servers. Ultra mega

[Full-disclosure] On the subject of security researcher n3td3v, Gary McKinnon Autistic rockstar felon

2009-09-08 Thread Central Security District of UK [MI7.5]
I just go off the phone with intelligence MI7 and the CIB (Upgraded from CIA++, super sexy savage secret) have relayed to me in code that n3td3v security is coming back stronger than ever. Over in Langley we know that n3td3v has the finest security tactics. Super fortified servers. Ultra

[Full-disclosure] [ MDVSA-2009:225 ] qt4

2009-09-08 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:225 http://www.mandriva.com/security/

[Full-disclosure] [USN-828-1] PAM vulnerability

2009-09-08 Thread Kees Cook
=== Ubuntu Security Notice USN-828-1 September 08, 2009 pam vulnerability https://launchpad.net/bugs/410171 === A security issue affects the following Ubuntu releases: Ubuntu

[Full-disclosure] Web-monitoring software gathers data on kid chats

2009-09-08 Thread Ivan .
Parents who install a leading brand of software to monitor their kids' online activities may be unwittingly allowing the company to read their children's chat messages — and sell the marketing data gathered. Software sold under the Sentry and FamilySafe brands can read private chats conducted

Re: [Full-disclosure] Web-monitoring software gathers data on kid chats

2009-09-08 Thread dramacrat
hahahaha oh man, that's grand. 2009/9/9 Ivan . ivan...@gmail.com Parents who install a leading brand of software to monitor their kids' online activities may be unwittingly allowing the company to read their children's chat messages — and sell the marketing data gathered. Software sold

Re: [Full-disclosure] Web-monitoring software gathers data on kid chats

2009-09-08 Thread Rohit Patnaik
Yeah, I saw that on Slashdot the other day, and I thought it was pretty hilarious. Ironic isn't it, that the very company one hires to protect their kids from exploitation is the one that is exploiting the kids? --Rohit Patnaik dramacrat wrote: hahahaha oh man, that's grand. 2009/9/9 Ivan .

Re: [Full-disclosure] Web-monitoring software gathers data on kid chats

2009-09-08 Thread Rafal M. Los
This is either (a) slipped into the EULA or (b) illegal. If (a) then it's another case of people just not reading the EULA, and while I know these things are complicated when it comes to something as critical as your children... READ THE EULA. If it's (b) then someone's going to jail,

[Full-disclosure] 4f: The File Format Fuzzing Framework

2009-09-08 Thread Krakow Labs
Krakow Labs Development 4f: The File Format Fuzzing Framework 4f is a file format fuzzing framework. 4f uses modules which are specifications of the targeted binary or text file format that tell it how to fuzz the target application. If 4f detects a crash, it will log crucial information