|
Colapse all |
Post message
[SNS Advisory No.73] Usermin Cross-site Scripting Vulnerability 2004-06-11 snsadv lac co jp (snsadv) ---------------------------------------------------------------------- SNS Advisory No.73 Usermin Cross-site Scripting Vulnerability Problem first discovered on: Sun, 11 Apr 2004 Published on: Fri, 11 Jun 2004 ---------------------------------------------------------------------- Overview: ------- [ more ] [ reply ] MDKSA-2004:057 - Updated tripwire packages fix format string vulnerability 2004-06-08 Mandrake Linux Security Team (security linux-mandrake com) time 2004-06-17 Greg Obremski (obremski misplaced net) Sorry, but...if I'm to take anyone and anything on this list seriously, and I've been on this list for many years now...the LEAST any subscriber could do is keep their freaking time constant. There's no excuse for people in our profession to be 4 days behind as far as their computer's clock is co [ more ] [ reply ] Re: Unprivilegued settings for FreeBSD kernel variables 2004-06-18 blexim (blexim hush com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 >> I've already told you that there is no such threat, since the attack >> you describe can only be initiated by someone who already has >> unrestricted access. Please stop wasting everybody's time. > You are wrong. Unrestricted access means _really un [ more ] [ reply ] Script injection in DNSONE appliance 2004-06-19 c3rb3r (c3rb3r sympatico ca) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 TITLE: Security flaw in DNSONE appliance (http://www.infoblox.com) TYPE: Script injection over DHCP QUOTE from INFOBLOX: DNS One appliances are designed to provide the foundation for next-generation network identity services in a secure and easy-to- [ more ] [ reply ] Re: Caveat Lector: Beastie Boys Evil 2004-06-19 Hamilton Frail (h frail bigpond com) Assumming we are on a XP Pro box, does anyone know if the exe has the same effect on Admin, power user, and normal user accounts? or just more privilaged accounts such as Power users and/or Administrators?? More to the point, does anyone know what it is exactly doing to prevent the cd from being co [ more ] [ reply ] RE: Is predictable spam filtering a vulnerability? 2004-06-18 Lance James (lance james bakbone com) Your point on the Rejected messages is that it does happen. Reverse-NDR's are a real problem - and are a loophole since NDR is a smtp spec. On a second note, your comment on filters, (not involving the me2 spam filter companies) filters do not stop spam, and sometimes they are truly more detrimenta [ more ] [ reply ] RE: Antivirus/Trojan/Spyware scanners DoS! 2004-06-17 Security List (secfocuslist yahoo com) Hello, Here is what I have from TrendMicro IWSS v1 A virus (Compressed_Huge_File, Eicar_test_file, Eicar_test_file, Eicar_test_file, Eicar_test_file, Eicar_test_file, Eicar_test_file) was detected in file SERVER_dwn.zip in http traffic on 6/15/04 3:10:06 PM with action deleted taken. CPU on the s [ more ] [ reply ] Internet Scanner 7 Restriction Bypass Vulnerability 2004-06-19 Chris Hurley (churley assureddecisions com) RE: Is predictable spam filtering a vulnerability? 2004-06-18 Andrew Hunter (andiroohunter msn com) I think spam filters arn't the solution to the spam problem. If someone gets 200 spam emails aday then what use is a spam filter telling them the email was rejected? The user will end up not looking at the list of rejected emails because it's sooo big. Filtering certain works is also bad aswell [ more ] [ reply ] RE: Is predictable spam filtering a vulnerability? 2004-06-18 Romulo M. Cholewa (rmc rmc eti br) Greetings, spam filters are a really big concern for most customers we have. They sure hate spam, know that it statistically means that their employees will loose some time filtering it out, not to mention those evil spam that carry malicious code or point to malicious sites. Content filtering is [ more ] [ reply ] ircd-hybrid-7 / ircd-ratbox low-bandwidth DoS 2004-06-18 Erik Sperling Johansen (einride einride org) Name : ircd-hybrid-7/ircd-ratbox low-bandwidth DoS Date : June 14th 2004 Author : Erik Sperling Johansen <einride (at) einride (dot) org [email concealed]> Severity : Medium This has been tested on most the ircd versions currently used on EFNet. Other ircds may be affected. Affected: ircd-hybrid <=7.0.1 ircd-ra [ more ] [ reply ] |
|
Privacy Statement |
Hash: SHA1
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200406-15
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
[ more ] [ reply ]