Re: [Full-disclosure] Fuzzing and SEH

2010-11-05 Thread Gynvael Coldwind
Hey, (SEH -- I assume we're talking MS Windows) A debugger attached is one solution (since a debugger is notified of an exception before SEH is executed). PyDbg seems like a good idea, but it can be done easily using the debugger API of Win32API too (just forward all events except exceptions to

Re: [Full-disclosure] Fwd: [CASE:12632] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-11-05 Thread Tweedle Doh
On 5 October 2010 13:24, Shawn Merdinger shawn...@gmail.com wrote: HumanWare is tracking this as CASE:12632 It's been a month now ... Any word from the vendor (HumanWare) yet as to what the official remedy will be, and/or how this sorry flaw came to be shipped in a released product (build error

[Full-disclosure] [FG-VD-10-020]Adobe Flash Player Remote Memory corruption Vulnerability

2010-11-05 Thread xpzhang
[FG-VD-10-020]Adobe Flash Player Remote Memory corruption Vulnerability Fortinet Discovers Adobe Flash Player Vulnerability 2010.Nov.04 Summary: Fortinet's FortiGuard Labs has discovered a Memory corruption vulnerability in Adobe Flash Player(Flash10h.ocx), which may lead to arbitrary

[Full-disclosure] New version of ddosim - DDOS simulator

2010-11-05 Thread Adrian Furtuna
Dear All, I am pleased to present the new version of *ddosim* (v0.2) - the application layer DDOS simulator. Description DDOSIM simulates several zombie hosts (having random IP addresses) which create full TCP connections to the target server. After completing the connection, DDOSIM

Re: [Full-disclosure] Joomla 1.5.21 | Potential SQL Injection Flaws

2010-11-05 Thread YGN Ethical Hacker Group
This public disclosure has achieved its aim. Joomla! Team finally patched this hole. http://developer.joomla.org/security/news/9-security/10-core-security/323-20101101-core-sqli-info-disclosurevulnerabilities.html Upgrade to the latest Joomla! version (1.5.22 or later). 1. VULNERABILITY

[Full-disclosure] nSense-2010-003: Cisco Unified Communications Manager

2010-11-05 Thread Henri Lindberg
nSense Vulnerability Research Security Advisory NSENSE-2010-003 --- Affected Vendor:Cisco Systems, Inc Affected Product: Cisco Unified Communications Manager Platform: All Impact:

[Full-disclosure] pfsense xss issues.

2010-11-05 Thread dave b
Those who cannot learn from history are doomed to repeat it. - George Santayana http://cvstrac.pfsense.org/chngview?cn=20994 Comment: Make scripts XSS input safe. Date: 2008-Feb-11 23:33:24 (local) 2008-Feb-12 04:33:24 (UTC) So in 2010, pfsense 2 beta 4: ... xss - pkg_edit.php