[Full-disclosure] [ MDVSA-2011:132 ] pidgin

2011-09-06 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2011:132 http://www.mandriva.com/security/

Re: [Full-disclosure] Cybsec Advisory 2011 0901 Windows Script Host DLL Hijacking

2011-09-06 Thread Georgi Guninski
On Mon, Sep 05, 2011 at 07:50:51PM +, Thor (Hammer of God) wrote: Excellent points - one slight addition, though: In fact, the Windows Script Host software is mostly used to write system maintenance scripts, so it's obvious its scripts can't be restricted or they'd be useless.

[Full-disclosure] Globaleaks demo of the Prototype online! $ /etc/init.d/globaleaks start

2011-09-06 Thread Arturo Filastò
Hi All, We are pleased to announce the release of the GlobaLeaks Prototype Demo. You are all invited to take a look at it and try how it feels to a Node Administrator, Whistleblower and TULIP receiving target. You can reach the demo on http://demo.globaleaks.org/ GlobaLeaks is the first Open

[Full-disclosure] [SECURITY] [DSA 2298-2] apache2 regression fix

2011-09-06 Thread Stefan Fritsch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2298-2 secur...@debian.org http://www.debian.org/security/Stefan Fritsch September 05, 2011

[Full-disclosure] [SECURITY] [DSA 2300-2] nss security update

2011-09-06 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2300-2 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst September 5, 2011

[Full-disclosure] [SECURITY] [DSA 2301-1] rails security update

2011-09-06 Thread Luciano Bello
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2301-1 secur...@debian.org http://www.debian.org/security/ Luciano Bello September 5, 2011

Re: [Full-disclosure] [SECURITY] [DSA 2300-2] nss security update

2011-09-06 Thread Georgi Guninski
On Mon, Sep 05, 2011 at 10:15:22PM +0200, Thijs Kinkhorst wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2300-2 secur...@debian.org

Re: [Full-disclosure] [SECURITY] [DSA 2300-2] nss security update

2011-09-06 Thread Valdis . Kletnieks
On Tue, 06 Sep 2011 19:29:56 +0300, Georgi Guninski said: you appear to not be CVE(R) compliant. where is the CVE(R) id? https://cve.mitre.org/cgi-bin/cvekey.cgi?keyword=DigiNotar Right there. Hope that helps. i immediately request you get a CVE(R) id and repost this email!!!

[Full-disclosure] GeoClassifieds Lite Multiple vulnerabilities

2011-09-06 Thread Yassin Aboukir
- [+] Title: GeoClassifieds Lite Multiple vulnerabilities [+] Affected Version : v2.0.1 V2.0.3.1 V2.0.3.2 V2.0.4 [+] Software Link: http://geodesicsolutions.com/ [+] Tested on: Windows 7 Firefox [+] Date

[Full-disclosure] Permutation Oriented Programming - Part 2.

2011-09-06 Thread Nelson Brito
Just to let you know that new example codes and a demonstration video is now available. The new example codes is capable to bypass a MS08-078 workaround recommended by Microsoft, proving the power of a Permutation Oriented Programming approach. - Video:

[Full-disclosure] Site Vulnerabilities: myexgf.com

2011-09-06 Thread George Girtsou
Site Vulnerabilities: myexgf.com - Cross Site Scripting This vulnerability affects /cgi-bin/te/o.cgi. The impact of this vulnerability Malicious users may inject JavaScript, VBScript, ActiveX, HTML or Flash into a vulnerable application to fool a user in order to gather data from them. An

[Full-disclosure] New Bugs released today on vl

2011-09-06 Thread resea...@vulnerability-lab.com
Hallo, some new publications with technical details of today. For PoC resources (pictures, logs co) request - resea...@vulnerability-lab.com Skype 5.3.x 2.2.x 5.2.x - Persistent Software Vulnerability http://www.vulnerability-lab.com/get_content.php?id=182

[Full-disclosure] Cyberwar between Israel and Turkish Hacker

2011-09-06 Thread Mohit Kumar
Turkish hacker *TurkGuvenligi* hijacked some 350 Israeli websites on Sunday evening, launching a Domain Name System (DNS) attack on at least seven high-profile websiteshttp://www.thehackernews.com/2011/09/theregistercouk-biggest-news-site-got.html including The Telegraph, Acer, National

[Full-disclosure] Registry Decoder - Digital Forensics Tool

2011-09-06 Thread Mohit Kumar
Digital forensics deals with the analysis of artifacts on all types of digital devices. One of the most prevalent analysis techniques performed is that of the registry hives contained in Microsoft Windows operating systems. Registry Decoder was developed with the purpose of providing a single tool

[Full-disclosure] 20 Famous websites vulnerable to Cross Site Scripting (XSS) Attack

2011-09-06 Thread Mohit Kumar
Most of the biggest and Famous sites are found to be Vulnerable to XSS attack . Cross-site scripting (XSS) is a type of computer security vulnerability typically found in web applications which allow code injection by malicious web users into the web pages viewed by other users. Examples of such

[Full-disclosure] Malcon 2011 - Call for Papers

2011-09-06 Thread Mohit Kumar
Malcon is the worlds first platform bringing together Malware and Information Security Researchers from across the globe to share key research insights into building and containment of the next generation malwares . *Call for Papers:* Malcon 2011 are looking for new techniques, tool