Re: [Full-disclosure] nginx exploit documentation, about a generic way to exploit Linux targets

2013-07-24 Thread Albert Puigsech Galicia
Hello everybody, Ioctl is needed to set the nginx socket blocking so another call to write(2) will read much more memory than it is possible with the default non-blocking connection of nginx. This vulnerability was published recently and it seems that many exploiters got stuck because the

[Full-disclosure] Where and how to report Dropbox vulnerabilities. (FUN)

2013-07-24 Thread MG
We have sent info about vulnerabilities using all forms, also direct e-mail supp...@dropbox.com, we had chat…. After 2 weeks we have got answer from robot: --- You can add a response by replying to this email. Please be sure to

[Full-disclosure] [ MDVSA-2013:198 ] libxml2

2013-07-24 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2013:198 http://www.mandriva.com/en/support/security/

Re: [Full-disclosure] nginx exploit documentation, about a generic way to exploit Linux targets

2013-07-24 Thread Albert Puigsech Galicia
Hello everybody, Ioctl is needed to set the nginx socket blocking so another call to write(2) will read much more memory than it is possible with the default non-blocking connection of nginx. This vulnerability was published recently and it seems that many exploiters got stuck because the

Re: [Full-disclosure] Where and how to report Dropbox vulnerabilities. (FUN)

2013-07-24 Thread MG
@Feighen @ Malte Batram I was trying also all these…(security… etc…) Support via chat - requested to send info to support@ regards, Maciej Gojny Wiadomość napisana przez Feighen Oosterbroek feig...@gmail.com w dniu 24 lip 2013, o godz. 11:56: Hey Maciej Not too sure if you've tried any

Re: [Full-disclosure] Where and how to report Dropbox vulnerabilities. (FUN)

2013-07-24 Thread Mysterie
Hello, I've contact them a few time by e-mail (secur...@dropbox.com) without problems. https://www.dropbox.com/terms : If you have any questions about security on our website, you can view our Security Overview Page or contact us at secur...@dropbox.com They even have a greetz page

Re: [Full-disclosure] Top Information Security Consultants to Hire -- WANTED

2013-07-24 Thread Gary Baribault
That does sound more likely Gary B On 07/23/2013 07:55 PM, Daniël W. Crompton wrote: I think he's collecting the names of people he can direct market to. D. On 24 July 2013 01:04, valdis.kletni...@vt.edu mailto:valdis.kletni...@vt.edu wrote: On Mon, 22 Jul 2013 21:23:08 -0500,

Re: [Full-disclosure] Top Information Security Consultants to Hire -- WANTED

2013-07-24 Thread Vulnerability Lab
http://www.evolution-sec.com International Team, Top Researchers and Consultants, Certified Consultants, Public References and Information. ~bkm -- VULNERABILITY LABORATORY RESEARCH TEAM DOMAIN: www.vulnerability-lab.com CONTACT: resea...@vulnerability-lab.com

Re: [Full-disclosure] Where and how to report Dropbox vulnerabilities. (FUN)

2013-07-24 Thread Feighen Oosterbroek
Hey Maciej Not too sure if you've tried any of the security type addresses as listed by rfc2142 http://www.ietf.org/rfc/rfc2142.txt 4. NETWORK OPERATIONS MAILBOX NAMES Operations addresses are intended to provide recourse for customers, providers and others who are experiencing

Re: [Full-disclosure] Top Information Security Consultants to Hire -- WANTED

2013-07-24 Thread Julius Kivimäki
Why am I not surprised vulnlab is the first one to post here to advertise themselves? 2013/7/24 Vulnerability Lab resea...@vulnerability-lab.com http://www.evolution-sec.com International Team, Top Researchers and Consultants, Certified Consultants, Public References and Information. ~bkm

[Full-disclosure] Phishing Google Wallet and Paypal by abusing WhatsApp

2013-07-24 Thread Curesec Research Team
Hi List, please find the vulnerability description within this post. Cheers, Curesec Research Team Reference: https://cureblog.de/2013/07/phishing-google-wallet-and-paypal-by-abusing-whatsapp/ Phishing Google Wallet and Paypal by abusing WhatsApp -=Introduction=- WhatsApp is one of the

[Full-disclosure] [Security-news] SA-CONTRIB-2013-060 - Scald - Cross Site Scripting (XSS)

2013-07-24 Thread security-news
View online: https://drupal.org/node/2049415 * Advisory ID: DRUPAL-SA-CONTRIB-2013-060 * Project: Scald [1] (third-party module) * Version: 6.x, 7.x * Date: 2013-July-24 * Security risk: Moderately critical [2] * Exploitable from: Remote * Vulnerability: Cross Site Scripting

[Full-disclosure] Cisco Security Advisory: Multiple Vulnerabilities in the Cisco Video Surveillance Manager

2013-07-24 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Cisco Security Advisory: Multiple Vulnerabilities in the Cisco Video Surveillance Manager Advisory ID: cisco-sa-20130724-vsm Revision 1.0 For Public Release 2013 July 24 16:00 UTC (GMT

[Full-disclosure] iPic Sharp v1.2.1 Wifi iOS - Persistent Foldername Web Vulnerability

2013-07-24 Thread Vulnerability Lab
Title: == iPic Sharp v1.2.1 Wifi iOS - Persistent Foldername Web Vulnerability Date: = 2013-07-24 References: === http://www.vulnerability-lab.com/get_content.php?id=1031 VL-ID: = 1031 Common Vulnerability Scoring System: 3.6

Re: [Full-disclosure] Top Information Security Consultants to Hire -- WANTED

2013-07-24 Thread Bob iPhone Kim
OK... guys... I figured out a simple way to organize and get you on the Top 100 Infosec Consultants List at: - http://sparkah.com/top-infosec-information-security-and-network-security-consultants-in-the-world/ Just add your name, url, and avatar to this google docs form and I'll just copy-paste

Re: [Full-disclosure] Top Information Security Consultants to Hire -- WANTED

2013-07-24 Thread Gary Baribault
You're not too terribly quick are you??? Gary B On 07/24/2013 06:31 PM, Bob iPhone Kim wrote: OK... guys... I figured out a simple way to organize and get you on the Top 100 Infosec Consultants List at: -

[Full-disclosure] CVE-2013-3665 - AutoCAD DWG-AC1021 Memory Corruption

2013-07-24 Thread Felipe Manzano
Upgrade your autocad or DWG relatred software: Original advisory: http://usa.autodesk.com/adsk/servlet/ps/dl/item?id=21972896linkID=9240618siteID=123112 Title: AutoCAD DWG-AC1021 Heap Corruption Product: Autodesk AutoCAD Advisory ID: BINA-20130724 CVE

Re: [Full-disclosure] Top Information Security Consultants to Hire -- WANTED

2013-07-24 Thread Tweedle Doh
On Wed, Jul 24, 2013 at 11:40 PM, Gary Baribault g...@baribault.net wrote: On 07/24/2013 06:31 PM, Bob iPhone Kim wrote: OK... guys... I figured out a simple way to organize and get you on the Top 100 Infosec Consultants List You're not too terribly quick are you??? He's a SEO Marketing