|
Colapse all |
Post message
[MajorSecurity #23] BLOG:CMS <= 4.0.0j - XSS and cookie disclosure 2006-07-21 admin majorsecurity de Re: ExtCalendar Mambo Module <= v2( extcalendar.php ) Remote File Include Vulnerabilities 2006-07-19 matdhule gmail com new shell bypass safe mode 2006-07-18 d3nger hotmail com i programing scripit for passing the safe mode the code <head> <meta http-equiv="Content-Language" content="en-us"> <title></title> <body bgcolor="#000000" text="#00FF00"> <b> <font size=-2 face=verdana color=white> <a bookmark="minipanel" style="font-weight: normal; color: #dadada; font [ more ] [ reply ] New CVE identifiers for separate PowerPoint 0-day issues assigned 2006-07-17 Juha-Matti Laurio (juha-matti laurio netti fi) New CVE documents have been published recently to clarify the existence of several 0-day type issues in Microsoft PowerPoint. These are based to three PoCs posted to Bugtraq on Saturday 15th July. CVE-2006-3655 - Unspecified vulnerability in mso.dll allows executing arbitrary code CVE-2006-3656 - [ more ] [ reply ] SolpotCrew Advisory #3 - com_trade Remote File Inclusion (mosConfig_absolute_path) 2006-07-21 mail sipplah com #############################SolpotCrew Community################################ # # com_trade Remote File Inclusion (mosConfig_absolute_path) # # original advisory : http://solpotcrew.org/adv/BlueSpy-adv-com_trade.txt # ################################################################### [ more ] [ reply ] RE: $100 plus several of my books if you can crack my Windows password hashes. 2006-07-18 Michael Scheidell (scheidell secnap net) (1 replies) You probably are who you say you are, and you probably own the accounts these passwords are from, but could not someone post a bunch of NTLM hashes and ask the world to crack them for him? Even if he dint' own the accounts? So, is this a social engineering test as well? [ more ] [ reply ] RE: $100 plus several of my books if you can crack my Windows password hashes. 2006-07-19 Roger A. Grimes (roger banneretcs com) [SECURITY] [DSA 1119-1] New hiki packages fix denial of service 2006-07-22 joey infodrom org (Martin Schulze) [SECURITY] [DSA 1118-1] New Mozilla packages fix several vulnerabilities 2006-07-22 joey infodrom org (Martin Schulze) Low security hole affecting IPCalc's CGI wrapper 2006-07-22 Tim Brown (timb nth-dimension org uk) Hi, I believe I've found a low level security hole relating to the way IPCalc's CGI wrapper sanitises input, which allows Javascript injection. Hole is considered low since IPCalc's CGI wrapper has no privileged functionality, however of course it might be possible to use it as a vector to atta [ more ] [ reply ] [MajorSecurity #24] Fire-Mouse TopList <=v1.1 - Cross Site Scripting 2006-07-22 admin majorsecurity de [MajorSecurity #24] Fire-Mouse TopList <=v1.1 - Cross Site Scripting ------------------------------------------------------------------------ ---------------- Software: Fire-Mouse TopList v1.1 Version: 1.1 Type: Cross site scripting Vendor: Fire-Mouse.com Page: http://www.fire-mouse. [ more ] [ reply ] [MajorSecurity #25] Advanced Guestbook 2.4 for phpBB - Multiple XSS and SQL-Injection Vulnerabilities 2006-07-22 admin majorsecurity de [MajorSecurity #25] Advanced Guestbook 2.4 for phpBB - Multiple XSS and SQL-Injection Vulnerabilities ------------------------------------------------------------------------ ---------------- Software: Advanced Guestbook for phpBB Version: 2.4 Type: Cross site scripting + SQL Injection M [ more ] [ reply ] Microsoft Internet Explorer DOS Vulnerability 2006-07-22 SnoBmsn Hotmail de Microsoft Internet Explorer Content-Type Denial Of Service Vulnerability -\Vulnerable: Microsoft Internet Explorer 6.0 SP2 Microsoft Internet Explorer 6.0 SP1 Microsoft Internet Explorer 6.0 - Microsoft Windows 2000 Advanced Server SP2 - Microsoft Windows 2000 Advanced Server SP2 - Microsof [ more ] [ reply ] about bid 17404 2006-07-21 crack rome com Hallo If you modify the code in bid 17404 in such a way: win = window.open('http://server/prova.zip','new') pause (2000) the user will see the page opening of correct site, and then download alert from original file site (server) Obviusly the alert form show the real, but if no dns resolu [ more ] [ reply ] Re: AFCommerce Shopping Cart 2006-07-20 contact afcommerce com Hi, thank you for reporting this problem. I am Paul, the author of the software, so I would like to do everything possible to correct this issue. The free version of my software is not open source, and not that the encryption is protecting it very well, I'm sure a good hacker could crack the encrypt [ more ] [ reply ] RE: $100 plus several of my books if you can crack my Windows password hashes. 2006-07-19 Roger A. Grimes (roger banneretcs com) I'm saying if faced with increasing the strength of my passwords, I value length over complexity. Case in point, a large city I consult for said they are moving their passwords from 5 character minimum to 8 characters and complex. (yeah, I had to stop coughing too...but 5 character minimums aren't [ more ] [ reply ] Re: [EEYEB-20060227] D-Link Router UPNP Stack Overflow 2006-07-21 kala_z hotmail com (1 replies) iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability 2006-07-21 labs-no-reply (labs-no-reply idefense com) (1 replies) Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability iDefense Security Advisory 07.20.06 http://www.idefense.com/application/poi/display?type=vulnerabilities July 20, 2006 I. BACKGROUND Solaris is a UNIX operating system developed by Sun Microsystems. II. DESCRIPTION Local [ more ] [ reply ] Re: [Full-disclosure] iDefense Security Advisory 07.20.06: Sun Microsystems Solaris sysinfo() Kernel Memory Disclosure Vulnerability 2006-07-21 Micheal Turner (wh1t3h4t3 yahoo co uk) MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php) 2006-07-21 AG Spider (ag-spider hotmail com) Title : MiniBB Forum <= 1.5a Remote File Include (search.php-whosOnline.php) ######################################################################## ####### Discovered By :::: {{AG-Spider & KaBaRa.HaCk .eGy}} ------------------------------------------------------------------------ ----- Affected [ more ] [ reply ] |
|
Privacy Statement |
> passwords up to 8 chars can easily (within hours) be cracked and known.
> Once someone can uncover an admin password all bets are off.
>
If someone is able to obtain the hashes, bets were off a long time
ago, no? As for at
[ more ] [ reply ]