[Full-disclosure] Another Microsoft (and other) IPv6 security issue: sniffer detection

2011-04-14 Thread Marc Heuse
Hi folks, another neat security issue with IPv6 which can be also exploited on IPv4-only LANs. It is possible to identify hosts on the local LAN which are sniffing. But before spoiling the details, a short rant. Skip it if you don't care. I am mad at Microsoft how they ignore severe but local LAN

[Full-disclosure] cPassMan v1.82 Arbitrary File Download - SOS-11-004

2011-04-14 Thread Lists
Sense of Security - Security Advisory - SOS-11-004 Release Date. 15-Apr-2011 Last Update. - Vendor Notification Date. 7-Mar-2011 Product. Collaborative Passwords Manager (cPassMan) Platform. Independent (PHP) Affect

[Full-disclosure] ZDI-11-104: (Pwn2Own) Webkit CSS Text Element Count Remote Code Execution Vulnerability

2011-04-14 Thread ZDI Disclosures
ZDI-11-104: (Pwn2Own) Webkit CSS Text Element Count Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-104 April 14, 2011 -- CVE ID: CVE-2011-1290 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: WebKit -- Affected Products: WebKit WebKit --

[Full-disclosure] ZDI-11-135: (Pwn2Own) WebKit WBR Tag Removal Remote Code Execution Vulnerability

2011-04-14 Thread ZDI Disclosures
ZDI-11-135: (Pwn2Own) WebKit WBR Tag Removal Remote Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-11-135 April 14, 2011 -- CVE ID: CVE-2011-1344 -- CVSS: 9, (AV:N/AC:L/Au:N/C:P/I:P/A:C) -- Affected Vendors: WebKit -- Affected Products: WebKit WebKit -- TippingP

[Full-disclosure] Hullo how are ya

2011-04-14 Thread Phil
to my friends:I'm never one to recommend a service unless its really something phenomenal but I have been taking this stuff that my doctor recommended for fat loss and I've lost 8 pounds in a week. Two of my friends who just began using it also lost seven pounds each. http://minnitrim.com P.S. that

Re: [Full-disclosure] Vulnerabilities in Mimbo Pro theme for WordPress

2011-04-14 Thread Michele Orru
/italian/ eh bona con sti advisory di merda. hai rotto il cazzo mustlive. ma non ti senti un noob ad usare acunetix e riportare le vulnerabilita? e poi sempre sulla stessa roba cristo... non farmi aggiungere una regola anti-spam per il tuo indirizzo di merda.

[Full-disclosure] Vulnerabilities in Mimbo Pro theme for WordPress

2011-04-14 Thread MustLive
Hello list! I want to warn you about Cross-Site Scripting, Full path disclosure, Abuse of Functionality and Denial of Service vulnerabilities in Mimbo Pro theme for WordPress. It's commercial theme for WP by developer of TimThumb. - Affected products: -

[Full-disclosure] [USN-1110-1] KDE-Libs vulnerabilities

2011-04-14 Thread Jamie Strandboge
== Ubuntu Security Notice USN-1110-1 April 14, 2011 kde4libs vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives: -

[Full-disclosure] Recon 2011 - Accepted Talks , Training, Call For Papers Reminder - July 8 to 10, 2011 - Montreal, Quebec

2011-04-14 Thread hfortier
++ + + + + + + + \ / + _- _+_ - ,__ _=..

[Full-disclosure] Hacking The Trading Floor Talk code wanted

2011-04-14 Thread James Kerry
Hi, I am desperately trying to access the code for this talk ?! Can someone please advice where I could possible find this info ? http://www.slideshare.net/iffybird_099/hacking-the-trading-floor-7613988 Kind Regards, J Kerry MSc, CCIE, CCNA Rapport Capital Technologies

[Full-disclosure] 300 Comparative Tests Driven Against Suricata and Snort

2011-04-14 Thread Sebastien Damaye
For years, Snort (developed and maintained by SourceFire) has been the de facto standard for open source Intrusion Detection/Prevention Systems (IDS/IPS). Its engine combines the benefits of signatures, protocols, and anomaly-based inspection and has become the most widely deployed IDS/IPS in the w