[Full-disclosure] [MOHSEP] Month Of Humorous Stefan Esser Photoshops - 0x01

2011-08-02 Thread Herr E Balls
Hello Internetizens, Welcome to our brand new sekurity proj3kt - the Month Of Humorous Stefan Esser Photoshops. I hope the title is self-explicating enough - if not just follow allong and I'm sure you'll get the drift :) Here is today's first post:

Re: [Full-disclosure] Telstra thompson gateway - root exploit (0day)

2011-08-02 Thread Auffret Patrice
Dear Mr secn3t, Thank you for porting this security issue to our attention. We will analyze your report about the aforementioned issue. For your information, Technicolor products security issues may be reported to the following address: security_at_technicolor.com. So for you future potential

[Full-disclosure] Samsung Galaxy Tab 10.1 blocked from sale in Australia

2011-08-02 Thread Ivan c
An Apple spokesperson told iTnews that it would continue to protect its design patents. This kind of blatant copying is wrong, and we need to protect Apple's intellectual property when companies steal our ideas.

Re: [Full-disclosure] Samsung Galaxy Tab 10.1 blocked from sale in Australia

2011-08-02 Thread Dave
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 02/08/2011 10:06, Ivan c wrote: An Apple spokesperson told iTnews that it would continue to protect its design patents. This kind of blatant copying is wrong, and we need to protect Apple's intellectual property when companies steal our ideas.

[Full-disclosure] Android Browser Cross-Application Scripting (CVE-2011-2357)

2011-08-02 Thread Roee Hay
= Android Browser Cross-Application Scripting (CVE-2011-2357) = 1) Background -- Android applications are executed in a sandbox environment, to ensure that no

[Full-disclosure] Wireshark - Difference between TimeFrames

2011-08-02 Thread Srinivas Naik
Hi, I'm looking for a wireshark/tshark filter which will calculate the difference between two time frames of Filtered live capture. Eg: Frame.time Thanks in advance Srinivas Naik ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Adium = 1.4.2 HTML/Javascript, XSS advisory

2011-08-02 Thread Levent Kayan
hello, bzzzt, lolday: http://www.noptrix.net/advisories/adium_inject.txt - next bug is coming (off-by-one) /* no comment */ cheers, noptrix -- Name: Levent 'noptrix' Kayan E-Mail: nopt...@lamergarten.net GPG key: 0x014652c0 Key fingerprint: ABEF 4B4B 5D93 32B8 D423 A623 823D 4162 0146 52C0

[Full-disclosure] Practical RTLO Unicode Spoofing

2011-08-02 Thread eSploit Guy
Hello List, Did a quick PoC on Right To Left Override (RTLO) spoofing under windows 7 few months back, thought of sharing. Any thoughts are appreciated. http://esploit.blogspot.com/2011/05/practical-rtlo-unicode-spoofing.html Thanks, Satyamhax http://esploit.blogspot.com

Re: [Full-disclosure] Samsung Galaxy Tab 10.1 blocked from sale in Australia

2011-08-02 Thread Jeffrey Walton
On Tue, Aug 2, 2011 at 5:06 AM, Ivan c ivann...@gmail.com wrote: An Apple spokesperson told iTnews that it would continue to protect its design patents. This kind of blatant copying is wrong, and we need to protect Apple's intellectual property when companies steal our ideas.

Re: [Full-disclosure] Multiple CSRF and XSS vulnerabilities in ADSL modem Callisto 821+

2011-08-02 Thread MustLive
Hello 0xd0! So, you could maybe have to think if the router has port 80 open and i assume a remote-service Yes, port 80 (and also 8008, as I wrote in my first advisory about Callisto 821+) is open, but it's accessible only from local - from local computer and LAN, and not from Internet (by

Re: [Full-disclosure] Why Block Mail-archive.com?

2011-08-02 Thread Sabahattin Gucukoglu
On 2 Aug 2011, at 22:02, Tony Oller wrote: On Sat, 23 Jul 2011 03:12:56 +0300 Sabahattin Gucukoglu m...@sabahattin-gucukoglu.com wrote: What have mail-archive.com done to you that you must block them in DNS, by setting up an empty authority zone for it? There is plenty of material on

[Full-disclosure] [Security Tool - Video] INSECT Pro 2.6.1 available

2011-08-02 Thread Juan Sacco
INSECT Pro 2.6.1 is worldwide available right now Check the new cool features: http://www.youtube.com/watch?v=EcgPMyjHVbQ * Run Faster: Because to make a good security testing is not enough * Load Better: Major graphical interface and optimisation features were implemented * Module Search: This

Re: [Full-disclosure] [Security Tool - Video] INSECT Pro 2.6.1 available

2011-08-02 Thread root
Dude you just released INSECT Pro 2.7 less than a week ago. I swear to god I'm being serious. On 08/02/2011 08:48 PM, Juan Sacco wrote: INSECT Pro 2.6.1 is worldwide available right now Check the new cool features: http://www.youtube.com/watch?v=EcgPMyjHVbQ * Run Faster: Because to make a