Re: [Full-disclosure] exploitation ideas under memory pressure

2013-05-22 Thread You Got Pwned
Hey Tavis, very interesting work! You're right: the list ist getting worse every year. So keep going!!! 2013/5/20 Tavis Ormandy tav...@cmpxchg8b.com On Fri, May 17, 2013 at 05:44:58PM -0700, Tavis Ormandy wrote: On Fri, May 17, 2013 at 02:26:10PM -0700, Tavis Ormandy wrote: The

Re: [Full-disclosure] Sony PS3 Firmware v4.31 - Code Execution Vulnerability

2013-05-22 Thread Julius Kivimäki
So, wanna tell me what exactly is critical about you being able to inject marquee tags into your savefile names? 2013/5/21 Vulnerability Lab resea...@vulnerability-lab.com Title: == Sony PS3 Firmware v4.31 - Code Execution Vulnerability Date: = 2013-05-12 References:

[Full-disclosure] Pentesting Distributions or Projects for Raspberry Pi

2013-05-22 Thread Jay Turla
Hey there guys, Do you know other projects, distributions, and installer kits for Raspberry PI aside from the distributions and kits mentioned in this article: http://resources.infosecinstitute.com/pentesting-distributions-and-installer-kits-for-your-raspberry-pi/ ? I am very much interested in

Re: [Full-disclosure] Sony PS3 Firmware v4.31 - Code Execution Vulnerability

2013-05-22 Thread Milan Berger
Hi, So, wanna tell me what exactly is critical about you being able to inject marquee tags into your savefile names? didn't test the POC yet, but I guess the fun is here: [PERSISTENT INJECTED SYSTEM COMMAND OR CODE!] Injecting system commands.. -- Kind Regards Milan Berger

[Full-disclosure] [SECURITY] [DSA 2670-1] request-tracker3.8 security update

2013-05-22 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2670-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso May 22, 2013

[Full-disclosure] [SECURITY] [DSA 2671-1] request-tracker4 security update

2013-05-22 Thread Salvatore Bonaccorso
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 - - Debian Security Advisory DSA-2671-1 secur...@debian.org http://www.debian.org/security/ Salvatore Bonaccorso May 22, 2013

[Full-disclosure] [SECURITY] [DSA 2672-1] kfreebsd-9 security update

2013-05-22 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2672-1 secur...@debian.org http://www.debian.org/security/Florian Weimer May 22, 2013