[Full-disclosure] [USN-1122-2] Thunderbird vulnerabilities

2011-05-05 Thread Micah Gersten
== Ubuntu Security Notice USN-1122-2 May 05, 2011 thunderbird vulnerabilities == A security issue affects these releases of Ubuntu and its derivatives:

[Full-disclosure] Leakdirectory: call for contribution

2011-05-05 Thread Fabio Pietrosanti (naif)
Hi guys, we setup a wiki-based directory of leaksites and transparency ecosystem available on: http://leakdirectory.org We would be pleased to have contribution in working on the wiki and on the project. Anonymous contributions are welcome, the wiki is open for editing. -naif

Re: [Full-disclosure] Facebook

2011-05-05 Thread Cal Leeming
+1. General rule of the thumb (which has served me well), is that the govt + company who holds your info, can do whatever they want. Laws are bent and broken every single day by these people in charge. Sucks, I know, but that's the world we live in, I'm afraid ;/ On Wed, May 4, 2011 at 1:46 PM,

[Full-disclosure] conservative.ca SQLi

2011-05-05 Thread Sig Heil
http://www.conservative.ca/index.php?section_copy_id=21257ï http://www.conservative.ca/index.php?section_copy_id=21257%C3%AF ¿½ion_i' AND (SELECT 3997 FROM(SELECT COUNT(*),CONCAT(CHAR(58,119,108,121,58),(SELECT (CASE WHEN (3997=3997) THEN 1 ELSE 0

[Full-disclosure] conservative.ca SQLi

2011-05-05 Thread Sig Heil
http://www.conservative.ca/index.php?section_copy_id=21257ï http://www.conservative.ca/index.php?section_copy_id=21257%C3%AF ¿½ion_i' AND (SELECT 3997 FROM(SELECT COUNT(*),CONCAT(CHAR(58,119,108,121,58),(SELECT (CASE WHEN (3997=3997) THEN 1 ELSE 0

Re: [Full-disclosure] Facebook

2011-05-05 Thread Stephen
Amish not being in the regular databases cause they don't use technology (i.e., like Facebook, or any of the other databases mentioned previously). A better way to word It wouldn't just be a selective subset but pretty much who, where, when and probably why without too many non-Amish exceptions.

[Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Ryan Sears
Hey all, Early this morning the folks over at LastPass decided to issue a warning about a potential security issue based on the fact that they detected some anomalies in their logs. http://blog.lastpass.com/2011/05/lastpass-security-notification.html Basically the post outlines the fact that

[Full-disclosure] t2'11: Call for Papers 2011 (Helsinki / Finland)

2011-05-05 Thread Tomi Tuominen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 # t2'11 - Call For Papers # Helsinki, Finland October 27 - 28, 2011 We are pleased to announce the annual t2'11 infosec conference, which will take place in Helsinki, Finland, from October

Re: [Full-disclosure] Latvenergo RIGAS HES-2 HACKED!

2011-05-05 Thread Zhang Xinghu
Screenshot from Latvenergo Valmeria substation Router: http://imageshack.us/photo/my-images/864/111nk.png/___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

[Full-disclosure] Filezilla Password Decryptor Released !

2011-05-05 Thread Nagareshwar Talekar
Hi all, FileZillaPasswordDecryptor is the FREE tool to quick scan and recover stored FTP login passwords by FileZilla - most popular FTP client software. For more details and download visit, http://securityxploded.com/filezilla-password-decryptor.php -- With Regards Nagareshwar Talekar

[Full-disclosure] PR10-13: Multiple XSS and Authentication flaws within BMC Remedy Knowledge Management

2011-05-05 Thread research
PR10-13: Multiple XSS and Authentication flaws within BMC Remedy Knowledge Management Vulnerability found: 17th July 2010 Vendor informed: Vulnerability fixed: Severity: High Description: BMC Remedy Knowledge Management provides service desk analysts with a knowledge base of easy-to-find

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Benji
They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full reinstall. On Thu, May 5, 2011 at 11:39 AM, Ryan Sears rdse...@mtu.edu wrote: Hey all, Early this morning the folks over at LastPass decided to issue a warning about a potential

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Nick Boyce
On Thu, May 5, 2011 at 9:09 PM, Benji m...@b3nji.com wrote: They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full reinstall. From http://blog.lastpass.com/2011/05/lastpass-security-notification.html : We're rebuilding the boxes in

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Benji
Sorry, completely missed that part. My bad. On Thu, May 5, 2011 at 10:35 PM, Nick Boyce nick.bo...@gmail.com wrote: On Thu, May 5, 2011 at 9:09 PM, Benji m...@b3nji.com wrote: They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full

[Full-disclosure] 0dayz on the 0day

2011-05-05 Thread Infant Overflow
Oh SNAP! SpongeBob got pwnd! http://pastebin.com/X9SBeH2c Shoutz to Pops, Elmo, my girl Dora, Handy M, and Thomas the Mother f'n Train ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

Re: [Full-disclosure] Stuxnet

2011-05-05 Thread Cal Leeming
? On Wed, May 4, 2011 at 10:40 PM, huj huj huj datski...@gmail.com wrote: thank you 2011/5/4 Cal Leeming c...@foxwhisper.co.uk Lol huj, this conversation is over. On 04/05/2011 11:16, huj huj huj wrote: if there were any justice in the world people like you would be infertile

[Full-disclosure] rfxn tools.. anyone tried them?

2011-05-05 Thread Cal Leeming
Just came across this: http://www.rfxn.com/projects/ APF (Advanced Policy Firewall)http://www.rfxn.com/projects/advanced-policy-firewall/ BFD (Brute Force Detection)http://www.rfxn.com/projects/brute-force-detection/ IRSYNC (Incremental

Re: [Full-disclosure] Lastpass Security Issue

2011-05-05 Thread Cal Leeming
+1 reason why people should never used centralized password / form storage tbh. On Thu, May 5, 2011 at 10:09 PM, Benji m...@b3nji.com wrote: They've said nothing about what they're going to do to the server with said anomaly. Wouldnt be happy until a full reinstall. On Thu, May 5, 2011 at

[Full-disclosure] Security Advisory: DNS BIND Security Advisory: RRSIG Queries Can Trigger Server Crash When Using Response Policy Zones

2011-05-05 Thread Barry Greene
-BEGIN PGP SIGNED MESSAGE- Hash: SHA256 Note: https://www.isc.org/CVE-2011-1907 is the authoritative source for this Security Advisory. Please check the source for any updates. Summary: When a name server is configured with a response policy zone (RPZ), queries for type RRSIG can

[Full-disclosure] VMSA-2011-0008 VMware vCenter Server and vSphere Client security vulnerabilities

2011-05-05 Thread VMware Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - VMware Security Advisory Advisory ID: VMSA-2011-0008 Synopsis: VMware vCenter Server and vSphere Client security

Re: [Full-disclosure] Facebook

2011-05-05 Thread Jeffrey Walton
On Wed, May 4, 2011 at 8:55 AM, Cal Leeming c...@foxwhisper.co.uk wrote: +1. General rule of the thumb (which has served me well), is that the govt + company who holds your info, can do whatever they want. Laws are bent and broken every single day by these people in charge. Sucks, I know, but