[Full-disclosure] PHP multipart/form-data denial of service

2009-11-20 Thread Bogdan Calin
Description PHP version 5.3.1 was just released. This release contains a patch for a denial of service condition we've reported on 27 October 2009. The problem is related with PHP's handling of RFC 1867 (Form-based File Upload in HTML). When you send a POST request to a PHP script

Re: [Full-disclosure] Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.

2009-11-20 Thread Valdis . Kletnieks
On Fri, 20 Nov 2009 01:42:08 +0100, netinfinity said: necessary to submit the post. If this fails then you should conntact the ISP of the spammer based on the IP. Unfortunately, that's exactly what *did* happen. Although for *home* users, the 'ISP' is the person to complain to, for

[Full-disclosure] Pussy and the right to free speech.

2009-11-20 Thread yuri . nate
This whole thing is ridiculous. Kurt Greenbaum is an idiot. What kind of question is that in the first place? Only and idiot would post “what’s the strangest thing you’ve ever eaten” and not expect some obvious remarks. And what’s wrong with pussy? Eating pussy is good! I LOVE eating

[Full-disclosure] VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components

2009-11-20 Thread VMware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - --- VMware Security Advisory Advisory ID: VMSA-2009-0016 Synopsis: VMware vCenter and ESX update release and vMA patch release

Re: [Full-disclosure] Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.

2009-11-20 Thread Michael Holstein
(Remember - in this case, contacting the school's network provider would *not* have found the user, because the network provider just provides a connection and bandwidth. Any login records/etc are at the *school*, not the provider). Vladis .. not sure about that school since it was K12,

[Full-disclosure] ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability

2009-11-20 Thread ZDI Disclosures
ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-085 November 20, 2009 -- CVE ID: CVE-2009-3843 -- Affected Vendors: Hewlett-Packard -- Affected Products: Hewlett-Packard OpenView Operations

[Full-disclosure] [ MDVSA-2009:301 ] kernel

2009-11-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:301 http://www.mandriva.com/security/

Re: [Full-disclosure] Pussy and the right to free speech.

2009-11-20 Thread Sam Haldorf
http://www.kurtgreenbaum.com/ http://www.kurtgreenbaumisapussy.com/ Damn. This dudes getting some serious blowback. Why didn't someone take DidKurtGreenbaumRapeAndMurderAYoungGirlIn1990.com? --- yuri.n...@hushmail.com yuri.n...@hushmail.com schrieb am Fr, 20.11.2009: Von: