[Full-disclosure] review: magic_quotes_gpc=on bypass project in 2006

2013-08-19 Thread x90c
I got a project to bypass the sql injection limitation of magic_quotes_gpc=on in php.ini. and I share the project and web private exploit on the irc. It's an review of the research. - advisory: http://www.x90c.org/advisories/::CVE-2006-2486 - discussion: http://x90c.blogspot.kr/2013/08/magicquotes

[Full-disclosure] [PSA-2013-0819-1] Oracle Java BytePackedRaster.verify() Signed Integer Overflow

2013-08-19 Thread fulldis
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 +--+ | Packet Storm Advisory 2013-0819-1| | http://packetstormsecurity.com/ | +

Re: [Full-disclosure] Full-Disclosure Digest, Vol 102, Issue 26

2013-08-19 Thread Jean D'Elboux Diogo
As Alex said about icmpv6, MS has patched this month a vulnerability in the Windows TCP/IP stack for IPv6: "A few ICMPv6 packets with Router Advertisements requests can cause a Denial of Service vulnerability reminiscent of the famous Ping-of-Death" [1] [1] https://community.qualys.com/blogs/l

[Full-disclosure] ACCDE and macros

2013-08-19 Thread Yuhong Bao
In Access 2003, the warnings shown when using Medium security level was useless unless you used digital signatures, because there was no way to open databases with macros disabled and because they always appear. This changed in Access 2007, when they added support for opening MDB/ACCDB with uns

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-19 Thread Jordon Bedwell
On Sun, Aug 18, 2013 at 3:56 PM, wrote: > (a) Because 75% of the Internet doesn't allow spoofing of source addresses, > and (b) Although there's a chance that one machine throwing 3,000 SYN > packets a second will show up on somebody's network monitor, you're never > going to see 3,000 network mo

[Full-disclosure] [SECURITY] [DSA 2738-1] ruby1.9.1 security update

2013-08-19 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2738-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst August 18, 2013

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-19 Thread Daniel Corbe
Not very subtle, but effective. Because you know the alternative would be to pick up the phone and call them. Stefan Jon Silverman writes: > Can I have my mid-90's ping-of-death back??? was incredibly useful for getting > people (on internal corporate networks) to call the helpdesk when their

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-19 Thread Alex
fragmented icmpv6 if they use windows Am 2013-08-19 06:35, schrieb Stefan Jon Silverman: > Can I have my mid-90's ping-of-death back??? was incredibly useful for > getting people (on internal corporate networks) to call the helpdesk when > their desktops were going DNS-crazy or otherwise sh