Re: [Full-disclosure] phpMyAdmin 3.x Conditional Session Manipulation

2011-08-04 Thread Henri Salo
On Sun, Jul 24, 2011 at 06:10:00PM +0200, Mango wrote: ### phpMyAdmin 3.x Conditional Session Manipulation ###[ Advisory from

[Full-disclosure] CAT Version 1 Released - Web App Testing Tool

2011-08-04 Thread Context IS - Disclosure
Context App Tool (CAT) Version 1 has been released. http://cat.contextis.com CAT is a tool for manual web application penetration testing and includes the following features: - Request Repeater – Used for repeating a single request - Proxy – Classic Inline proxy -

Re: [Full-disclosure] CAT Version 1 Released - Web App Testing Tool

2011-08-04 Thread -= Glowing Sex =-
Very nice to see, and very resourceful website, thanks! This is, a very nice tool for those who have problems with Linux, and it seems to run Ok, i am playing with the sdk atm but, only thing i dislike, is .net code,but i assume with time, and, for such a great first rls, this tool can go far :-)

[Full-disclosure] Agnitio Security Code Review Tool v2.0 released

2011-08-04 Thread David Rook
Hi, I've released an update to Agnitio which I hope will help people carryout security focused code reviews and find vulnerabilities in the source code they are reviewing. The major changes in v2.0 are listed below: 1) Basic code analysis module with rules for analysing Android and iOS

Re: [Full-disclosure] VBulletin adminCP Cross Site Scripting

2011-08-04 Thread Henri Salo
On Wed, Aug 03, 2011 at 06:37:32PM +0600, HAroon . wrote: *Advisory Information* Title: vBulletin Cross Site Scripting Vulnerability Date published: 02-08-2011 Vendors contacted: vBulletin team *Vulnerability Information* Class: XSS flaw Vulnerable page: Admin Login Page

Re: [Full-disclosure] CAT Version 1 Released - Web App Testing Tool

2011-08-04 Thread Valdis . Kletnieks
On Thu, 04 Aug 2011 01:45:16 BST, Context IS - Disclosure said: CAT is a tool for manual web application penetration testing and includes t he following features: Sounds at least potentially interesting. A few questions: - CAT uses Internet Explorer's rendering engine for accurate

Re: [Full-disclosure] your sig (was Re: new anon tool)

2011-08-04 Thread -= Glowing Sex =-
No. But thanks for asking, and i dont have a 'sig'. On 5 August 2011 01:13, tandernam tander...@gmail.com wrote: 10001000100000 +1 = omg i just found oprah winfrey! mind explaining your signature? ___ Full-Disclosure - We believe in it.

[Full-disclosure] Sophos Antivirus Review

2011-08-04 Thread Tavis Ormandy
List, I've prepared a paper to accompany a presentation at blackhat las vegas discussing Sophos Antivirus design. It might be of interest to those evaluating or deploying Sophos Antivirus. http://lock.cmpxchg8b.com/Sophail.pdf I've also created some tools to help understand and dump Sophos

Re: [Full-disclosure] APOLOGIES FOR MISTAKEN IDENTITY: OMKAR BELKHEDE

2011-08-04 Thread Robert Kim App and Facebook Marketing
Huh? Am i missing something? On Wed, Aug 3, 2011 at 11:52 AM, Wonder Universe wondersoftheunivers...@gmail.com wrote: The content of the previous email is not true. It was posted by mistake from this account. I do not know this person and it was just a case of mistaken identity. OMKAR