[Full-disclosure] ZDI-11-085: Oracle Java XGetSamplePtrFromSnd Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-085: Oracle Java XGetSamplePtrFromSnd Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-085 February 15, 2011 -- CVE ID: CVE-2010-4462 -- CVSS: 7.5, (AV:N/AC:L/Au:N/C:P/I:P/A:P) -- Affected Vendors: Oracle -- Affected Products: Oracle Java Runtime

[Full-disclosure] [USN-1065-1] shadow vulnerability

2011-02-15 Thread Kees Cook
=== Ubuntu Security Notice USN-1065-1 February 15, 2011 shadow vulnerability CVE-2011-0721 === A security issue affects the following Ubuntu releases: Ubuntu 9.10 Ubuntu 10.04 L

Re: [Full-disclosure] MS Windows Server 2003 AD Pre-Auth BROWSER ELECTION Remote Heap Overflow

2011-02-15 Thread coderman
On Mon, Feb 14, 2011 at 8:00 AM, Pwned MSRC wrote: > > #MS Windows Server 2003 AD Pre-Auth BROWSER ELECTION Remote Heap Overflow > ... > #From dailydave: > [https://lists.immunityinc.com/pipermail/dailydave/201101

[Full-disclosure] ZDI-11-082: Oracle Java Runtime NTLM Authentication Information Leakage Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-082: Oracle Java Runtime NTLM Authentication Information Leakage Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-082 February 15, 2011 -- CVE ID: CVE-2010-4466 -- CVSS: 6.4, (AV:N/AC:L/Au:N/C:P/I:P/A:N) -- Affected Vendors: Oracle -- Affected Products: Oracle Java Run

[Full-disclosure] ZDI-11-086: Oracle Java Webstart Trusted JNLP Extension Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-086: Oracle Java Webstart Trusted JNLP Extension Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-086 February 15, 2011 -- CVE ID: CVE-2010-4463 -- CVSS: 9.7, (AV:N/AC:L/Au:N/C:C/I:C/A:P) -- Affected Vendors: Oracle -- Affected Products: Oracle Ja

[Full-disclosure] ZDI-11-084: Oracle Java Unsigned Applet Applet2ClassLoader Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-084: Oracle Java Unsigned Applet Applet2ClassLoader Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-084 February 15, 2011 -- CVE ID: CVE-2010-4452 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle J

[Full-disclosure] ZDI-11-083: Oracle Java Applet Clipboard Injection Remote Code Execution Vulnerability

2011-02-15 Thread ZDI Disclosures
ZDI-11-083: Oracle Java Applet Clipboard Injection Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-083 February 15, 2011 -- CVE ID: CVE-2010-4465 -- CVSS: 10, (AV:N/AC:L/Au:N/C:C/I:C/A:C) -- Affected Vendors: Oracle -- Affected Products: Oracle Java Run

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
I now also declare rule 34. On Tue, Feb 15, 2011 at 9:10 PM, Eyeballing Weev wrote: > You look really good in heels and a skirt, nice legs also. > > On 02/15/2011 04:08 PM, Kain, Rebecca (.) wrote: > > Of course that's where I got it from. A woman couldn't be *that* > > creative > > > > > > > __

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
I declare rule 31 on Rebecca. ( As you are a girl, and therefore are unaware of the rules of the internet, please may I direct your attention to http://encyclopediadramatica.com/Rules_of_the_Internet ) On Tue, Feb 15, 2011 at 9:08 PM, Kain, Rebecca (.) wrote: > Of course that's where I got it f

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
http://a1.l3-images.myspacecdn.com/images01/49/3fb5839feabb972e4b40c2807e328396/l.jpg Rule 34. Now. On Tue, Feb 15, 2011 at 9:13 PM, Cal Leeming [Simplicity Media Ltd] < cal.leem...@simplicitymedialtd.co.uk> wrote: > I now also declare rule 34. > > On Tue, Feb 15, 2011 at 9:10 PM, Eyeballing Wee

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Eyeballing Weev
You look really good in heels and a skirt, nice legs also. On 02/15/2011 04:08 PM, Kain, Rebecca (.) wrote: > Of course that's where I got it from. A woman couldn't be *that* > creative > > ___ Full-Disclosure - We believe in it. Charter: http://lists

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Kain, Rebecca (.)
Only if you call me "your little sudo" -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of Eyeballing Weev Sent: Tuesday, February 15, 2011 4:01 PM To: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disc

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Kain, Rebecca (.)
Of course that's where I got it from. A woman couldn't be *that* creative -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of Randal T. Rioux Sent: Tuesday, February 15, 2011 4:05 PM To: full-disclosure@list

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Randal T. Rioux
Thought this would be appropriate :-) http://xkcd.com/149/ On 2/15/2011 4:00 PM, Eyeballing Weev wrote: > What do you expect from a woman? > > Rebecca, kindly make me a sandwich > > On 02/15/2011 03:44 PM, Cal Leeming [Simplicity Media Ltd] wrote: >> I did apologise, no need to drag it out into

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Eyeballing Weev
How about under threat of receiving a shiner? On 02/15/2011 04:02 PM, Kain, Rebecca (.) wrote: > Only if you call me "your little sudo" > > ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Eyeballing Weev
What do you expect from a woman? Rebecca, kindly make me a sandwich On 02/15/2011 03:44 PM, Cal Leeming [Simplicity Media Ltd] wrote: > I did apologise, no need to drag it out into the yard and beat it with a > stick lol. > ___ Full-Disclosure - We bel

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
I did apologise, no need to drag it out into the yard and beat it with a stick lol. On Tue, Feb 15, 2011 at 8:33 PM, Kain, Rebecca (.) wrote: > > cool, thanks coderman > > If something's a private joke, I don't see why it needed to be aired > here, that's all. > > > -Original Message- >

[Full-disclosure] [USN-1064-1] OpenSSL vulnerability

2011-02-15 Thread Steve Beattie
=== Ubuntu Security Notice USN-1064-1 February 15, 2011 openssl vulnerability CVE-2011-0014 === A security issue affects the following Ubuntu releases: Ubuntu 10.04 LTS Ubuntu 1

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Kain, Rebecca (.)
cool, thanks coderman If something's a private joke, I don't see why it needed to be aired here, that's all. -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of coderman Sent: Tuesday, February 15, 2011 3:31

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread coderman
On Tue, Feb 15, 2011 at 7:48 AM, Eyeballing Weev wrote: > Wanna hang out later, Rebecca? I got some cocaine, LSD and pills that if > we get caught I will claim they are not mine and the police planted them > on us. poor eyeballer, must be bored silly. did you leech that correctional cctv feed ye

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-15 Thread Eyeballing Weev
Some guys pay more for women with "extra hardware". What are you doing later? ;-) > What the hell :) > I'm a man mate. > > Michele is like Michael. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-15 Thread Michele Orru
On Tue, Feb 15, 2011 at 12:25 AM, Eyeballing Weev wrote: > > > On Mon, Feb 14, 2011 at 4:54 PM, MustLive > wrote: >> >> Hello Michele! >> >> Few days ago I saw your advisory about Drupal's captcha. It's interesting >> advisory, but I have one note concerning it - your research is very close >> to

Re: [Full-disclosure] [AntiSnatchOr] Drupal <= 6.20 insecure Captcha defaults PoC

2011-02-15 Thread Michele Orru
2011/2/14 MustLive : > Hello Michele! > > Few days ago I saw your advisory about Drupal's captcha. It's interesting > advisory, but I have one note concerning it - your research is very close to > mine ;-) (it concerns similar holes which I found before you). I didn't found anything in FD or other

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread huj huj huj
wasnt meant that harshly :) was a simpsons quote 2011/2/15 Cal Leeming [Simplicity Media Ltd] < cal.leem...@simplicitymedialtd.co.uk> > Bit of an inside joke, sorry, should have kept it off the list! > > > On Tue, Feb 15, 2011 at 3:30 PM, Kain, Rebecca (.) wrote: > >> I haven't understood a word

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Eyeballing Weev
Wanna hang out later, Rebecca? I got some cocaine, LSD and pills that if we get caught I will claim they are not mine and the police planted them on us. On 02/15/2011 10:30 AM, Kain, Rebecca (.) wrote: > I haven't understood a word of this so far > __

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Kain, Rebecca (.)
I haven't understood a word of this so far From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of huj huj huj Sent: Tuesday, February 15, 2011 10:29 AM To: Cal Leeming [Simplicity Media Ltd] Cc: full-discl

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
Bit of an inside joke, sorry, should have kept it off the list! On Tue, Feb 15, 2011 at 3:30 PM, Kain, Rebecca (.) wrote: > I haven't understood a word of this so far > > > -- > *From:* full-disclosure-boun...@lists.grok.org.uk [mailto: > full-disclosure-boun...@lis

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread huj huj huj
hey funboys! get a room.. 2011/2/15 Cal Leeming [Simplicity Media Ltd] < cal.leem...@simplicitymedialtd.co.uk> > Come at me bro :D > > > On Tue, Feb 15, 2011 at 1:29 PM, Benji wrote: > >> fighting words. >> >> >> On Tue, Feb 15, 2011 at 1:27 PM, Cal Leeming [Simplicity Media Ltd] < >> cal.leem..

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
Come at me bro :D On Tue, Feb 15, 2011 at 1:29 PM, Benji wrote: > fighting words. > > > On Tue, Feb 15, 2011 at 1:27 PM, Cal Leeming [Simplicity Media Ltd] < > cal.leem...@simplicitymedialtd.co.uk> wrote: > >> I know right? >> >> First I hold myself back from posting your dox everywhere, and now

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Benji
Well check you out. On Tue, Feb 15, 2011 at 12:12 PM, Cal Leeming [Simplicity Media Ltd] < cal.leem...@simplicitymedialtd.co.uk> wrote: > Lol, I ain't touching this shit with a barge pole. > > On Mon, Feb 14, 2011 at 11:05 PM, wrote: > >> HI >> >> i extracted all attachments from the first 3 ema

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Benji
fighting words. On Tue, Feb 15, 2011 at 1:27 PM, Cal Leeming [Simplicity Media Ltd] < cal.leem...@simplicitymedialtd.co.uk> wrote: > I know right? > > First I hold myself back from posting your dox everywhere, and now this! > > On Tue, Feb 15, 2011 at 1:06 PM, Benji wrote: > >> Well check you ou

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
I know right? First I hold myself back from posting your dox everywhere, and now this! On Tue, Feb 15, 2011 at 1:06 PM, Benji wrote: > Well check you out. > > > On Tue, Feb 15, 2011 at 12:12 PM, Cal Leeming [Simplicity Media Ltd] < > cal.leem...@simplicitymedialtd.co.uk> wrote: > >> Lol, I ain'

[Full-disclosure] [ MDVSA-2011:028 ] openssl

2011-02-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:028 http://www.mandriva.com/security/ _

Re: [Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread Cal Leeming [Simplicity Media Ltd]
Lol, I ain't touching this shit with a barge pole. On Mon, Feb 14, 2011 at 11:05 PM, wrote: > HI > > i extracted all attachments from the first 3 emails, provided a dump of all > files categorized by type. > > Also you can spread the most significative files on anonymous/wikileaks > that i selec

[Full-disclosure] from hbgary: stuxnet, WL attack, Psyop and Anonymous trackdown

2011-02-15 Thread hbgary
HI i extracted all attachments from the first 3 emails, provided a dump of all files categorized by type. Also you can spread the most significative files on anonymous/wikileaks that i selected on the web page. http://xqz3u5drneuzhaeo.onion/users/hbgary/ It doesn't include attachment from gre