|
Colapse all |
Post message
Remote crash of Half-Life servers and clients (versions before the 07 July 2004) 2004-07-12 Luigi Auriemma (aluigi autistici org) MSIE Similar Method Name Redirection Cross Site/Zone Scripting Vulnerability 2004-07-11 Paul (paul greyhats cjb net) Note: This vulnerability and many more can be found at http://www.greyhats.cjb.net SimliarMethodNameRedir Automatic Remote Compromise [Tested] IEXPLORE.EXE file version 6.0.2800.1106 MSHTML.DLL file version 6.00.2800.1400 Microsoft Windows XP sp2 [Discussion] At first I thought this [ more ] [ reply ] MSOE Javascript Execution Vulnerability 2004-07-11 Paul (paul greyhats cjb net) Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net Outlook Express Window Opener Script Execution Vulnerability [Tested] Microsoft Outlook Express version 6.0.2800.1123. Microsoft Windows XP sp2 [Discussion] Microsoft Outlook Express is prone [ more ] [ reply ] Re: HijackClick 3 2004-07-12 http-equiv (at) excite (dot) com [email concealed] (1 malware com) <!-- Microsoft just disabled those functions from being called when the mouse button is down and called it patched. No more hijackclick, right? Wrong. --> This is absolutely fantastic Paul, with a patented double-click of the mouse we can remotely take over the target's computer: Just sub [ more ] [ reply ] MOZILLA: SHELL can execute remote EXE program 2004-07-09 liudieyu umbrella name SUBJ: MOZILLA: SHELL can execute remote EXE program DATE: 2004/07/09 FROM: Liu Die Yu <liudieyu AT umbrella D0T name> ############################################################ [START] Advisory ############################################################ COPYRIGHT --------- This Advisory is Co [ more ] [ reply ] RE: MSIE Download Window Filename + Filetype Spoofing Vulnerability 2004-07-12 Drew Copley (dcopley eEye com) This is an open bug. (One which is rather disturbing, so I am not sure why Microsoft has chosen to not fix it.) Date: 21 October 2001 http://www.guninski.com/popspoof.html "Demonstration: Image moving over download/open dialog: http://www.guninski.com/opf2.html " > -----Original Message-- [ more ] [ reply ] HijackClick 3 2004-07-11 Paul (paul greyhats cjb net) Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net HijackClick 3!!! Took the name from Liu Die Yu :) [Tested] IEXPLORE.EXE file version 6.0.2800.1106 MSHTML.DLL file version 6.00.2800.1400 Microsoft Windows XP sp2 [Discussion] The HijackCli [ more ] [ reply ] I small poem in JScript 2004-07-11 Berend-Jan Wever (skylined edup tudelft nl) I just wrote a small poem in JScript: <SCRIPT language="javascript"> MSIE = window.open; // for hackers to come in for (every_bug_found in MSIE) { /* there are zillions more hiden */ } </SCRIPT> Ok, so it doen't rhyme... but it is another null-pointer exception DoS in MSIE 6.0sp1 (fully patc [ more ] [ reply ] Media Preview Script Execution Vulnerability 2004-07-11 Paul (paul greyhats cjb net) Note: This vulnerability as well as several more can be found at http://www.geryhats.cjb.net Media Preview Script Execution Vulnerability [Tested] MSDXM.DLL file version 6.4.09.1128 Microsoft Windows 2000 [Discussion] By using the windows media player control, media can be played in [ more ] [ reply ] MSIE Download Window Filename + Filetype Spoofing Vulnerability 2004-07-11 Paul (paul greyhats cjb net) Note: This vulnerability as well as several more can be found at http://www.greyhats.cjb.net Download Window Filename + Filetype Spoofing Vulnerability [Tested] IEXPLORE.EXE file version 6.0.2800.1106 MSHTML.DLL file version 6.00.2800.1400 Microsoft Windows XP sp2 [Discussion] When [ more ] [ reply ] [BUGZILLA] Multiple vulnerabilities in Bugzilla 2.16.5 and 2.17.7 2004-07-10 David Miller (justdave bugzilla org) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Bugzilla Security Advisory July 10, 2004 Summary ======= Bugzilla is a Web-based bug-tracking system, used by a large number of software projects. This advisory covers security bugs that have recently been discovered and fixed in the Bugzilla code: I [ more ] [ reply ] [ GLSA 200407-10 ] rsync: Directory traversal in rsync daemon 2004-07-12 Kurt Lieber (klieber gentoo org) Re: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!] 2004-07-10 Bipin Gautam (visitbipin hotmail com) In-Reply-To: <40EEE9C0.4040108 (at) mojohosting (dot) com [email concealed]> >The same thing happens with classic mail bombs like 42.zip, NAV can't >handle them. > >Alan Parks 42.zip was a arc. BOMB and a different story... It's similar to my WinRar advisory that date back, 2003. Well, within few seconds... after t [ more ] [ reply ] [tool] p0f 2.0.4 is out 2004-07-10 Michal Zalewski (lcamtuf coredump cx) I am proud to announce the availability of p0f 2.0.4, a passive OS fingerprinter (and more). Since 2.0.1 (announced here over a year ago), p0f has gained features such as: - RST+ACK (connection refused) fingerprinting, - Official SYN+ACK (outgoing connection) fingerprinting support, - Sophist [ more ] [ reply ] current leading bots used in drone armies [June/July 2004] 2004-07-08 Gadi Evron (gadie cbs gov il) [For the list of the most used Trojan horses in drone armies for June/July, 2004, please skip to the end of this email message.] I figured a list of this nature once in a while (maybe quarterly or monthly depending on the changing threats) can be useful to some administrators who wish to actively c [ more ] [ reply ] Covert Channels allow Cross-Site-Java in Microsoft VM 2004-07-10 Marc Schoenefeld (schonef uni-muenster de) (1 replies) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi y'all, I have not found the contact address for microsoft jvm security issues, therefore maybe someone who reads bugtraq can forward this: in the Microsoft (R) VM for Java, 5.0 Release 5.0.0.3810 the implementation of some core system classes allows [ more ] [ reply ] Re: Covert Channels allow Cross-Site-Java in Microsoft VM 2004-07-11 Siva Subbu (sivasub23 hotmail com) (1 replies) Re: Covert Channels allow Cross-Site-Java in Microsoft VM 2004-07-11 Marc Schoenefeld (schonef uni-muenster de) MDKSA-2004:067 - Updated ethereal packages fix multiple vulnerabilities 2004-07-09 Mandrake Linux Security Team (security linux-mandrake com) RE: Microsoft Word Email Object Data Vulnerability 2004-07-09 Drew Copley (dcopley eEye com) How did you find this? Did someone email this to you? Did you discover this variation? (Being that the original bug was mine, I have some interest in a new variation being exploited by spammers... especially if it was genuinely found in the wild.) And, why is Microsoft ignoring this bug? If you f [ more ] [ reply ] RE: Norton AntiVirus Denial Of Service Vulnerability [Part: !!!] 2004-07-09 Eric McCarty (eric lawmpd com) Norton Antivirus 2004 Confirmed Vulnerable, Pegged CPU on a 3ghz machine for indefinate amount of time scanning. Eric -----Original Message----- From: Bipin Gautam [mailto:visitbipin (at) hotmail (dot) com [email concealed]] Sent: Thursday, July 08, 2004 5:47 PM To: bugtraq (at) securityfocus (dot) com [email concealed] Subject: Norton AntiVirus Denial [ more ] [ reply ] Re: Microsoft Word Email Object Data Vulnerability 2004-07-09 http-equiv (at) excite (dot) com [email concealed] (1 malware com) <!-- Outlook 2000 and 2003 allow execution of remote web pages specified within the data property of OBJECT tags when there is no closing /OBJECT --> This reminds me of something I saw the other day. The following and a variety of variations will work in Outlook Express [probably IE as wel [ more ] [ reply ] CYBSEC - Security Advisory: Denial of Service in IBM WebSphereEdge Server 2004-07-08 Leandro Meiners (lmeiners cybsec com) The following advisory is also available in pdf for download at http://www.cybsec.com/vuln/IBM-WebSphere-Edge-Server-DOS.pdf CYBSEC S.A. www.cybsec.com Advisory Name: Denial of Service in WebSphere Edge Server. Vulnerability Class: Denial of Service Release Date: June 2nd 2004 Affected Application [ more ] [ reply ] MOZILLA: execute local file and its fix 2004-07-09 liudieyu umbrella name yet another important message appeared at fd, but not at bugtraq: http://seclists.org/lists/fulldisclosure/2004/Jul/0333.html it leads to: http://www.mozilla.org/security/shell.html you guys must monitor fd :-P it cost me$$ N months to turn off codeBase - a smiliar issue in IE, but mozilla made [ more ] [ reply ] Microsoft Word Email Object Data Vulnerability 2004-07-08 James C. Slora, Jr. (james slora phra com) ============================================== Microsoft Word Email Object Data Vulnerability ============================================== ============================================== Summary: ============================================== Outlook 2000 and 2003 allow execution of remote web pa [ more ] [ reply ] |
|
Privacy Statement |
#######################################################################
Luigi Auriemma
Application: Half-Life engine
http://half-life.sierra.com
http://www.steampowered.com
Versions: before the 07 July 2004 (both Steam and not-Steam)
P
[ more ] [ reply ]