|
Colapse all |
Post message
RE: Microsoft Outlook Express EML file Crash vulnerability 2004-04-13 Kamran Muzaffer (kmahmed cyber net pk) XSS, Admin Access via Cookie and File Upload vulnerability in NewsPHP. 2004-04-12 Manuel Lopez (mantra gulo org) #Title: XSS, Admin Access via Cookie and File Upload vulnerability in NewsPHP. #Software: NewsPHP (All versions) #Vendor: http://www.newsphp.com #Underlying OS: All #Description: NewsPHP is a perfect solution for creating web publishing system, like an online magazine, newspaper, TV/Radio o [ more ] [ reply ] Microsoft Internet Explorer BMP file memory DoS vulnerability 2004-04-11 Arman Nayyeri (arman-n Phreaker net) (2 replies) Microsoft Internet Explorer BMP file memory DoS vulnerability ============================================================= Title: Microsoft Internet Explorer BMP file memory DoS vulnerability Vuln Name: 58 bytes BMP vs 51,539,607,528 GB memory Date: Sunday, April 11, 2004 Software: [ more ] [ reply ] RE: Microsoft Internet Explorer BMP file memory DoS vulnerability 2004-04-13 Alan W. Rateliff, II (lists rateliff net) new strange worm 2004-04-12 Alex Gen (alexei h spray se) http://www.mikenoels.net/matrix.swf/index1.html (do _not_ open.) Found a new sort of worm, at least I didn't find any information about this on any securitysite; Creates a registry entry \HKEY_CURRENT_USER\Software\Microsoft\Search Assistant\ACMru\5603 and adds a file called "umcss.exe" to C [ more ] [ reply ] [waraxe-2004-SA#016 - Cross-Site Scripting aka XSS in phpnuke 6.x-7.2 part 3] 2004-04-12 Janek Vind (come2waraxe yahoo com) [CLA-2004:837] Conectiva Security Announcement - mod_python 2004-04-12 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : mod_python SUMMARY : Remote denial of service [ more ] [ reply ] Microsoft Outlook Express EML file Crash vulnerability 2004-04-11 Arman Nayyeri (arman-n Phreaker net) Microsoft Outlook Express EML file Crash vulnerability ====================================================== Title: Microsoft Outlook Express EML file Crash vulnerability HappyName: Who Send? Date: Sunday, April 11, 2004 Software: Outlook Express 6.0 (i guess perior versions are vu [ more ] [ reply ] [CLA-2004:838] Conectiva Security Announcement - squid 2004-04-12 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : squid SUMMARY : ACL bypass vulnerability DATE [ more ] [ reply ] [waraxe-2004-SA#018 - Admin-level authentication bypass in phpnuke 6.x-7.2] 2004-04-12 Janek Vind (come2waraxe yahoo com) BID 7482, bug in OpenSSH (Still in FreeBSD-STABLE) 2004-04-12 Felipe Neuwald (felipe neuwald loreno com br) Hello Folks, I tested only versions OpenSSH_3.5p1 (FreeBSD-STABLE), but it also work on other versions, as published May 01, 2003. Ok, let's talk about it. First, the /etc/ssh/sshd_config file: <cut> PermitRootLogin no <cut> As you can see above, is not allowed to root login on that system. Fine. N [ more ] [ reply ] [waraxe-2004-SA#017 - User-level authentication bypass in phpnuke 6.x-7.2] 2004-04-12 Janek Vind (come2waraxe yahoo com) Multiple Vulnerabilities In Tiki CMS/Groupware [ TikiWiki ] 2004-04-11 JeiAr (security gulftech org) UPDATE: Cisco Security Notice: Dictionary Attack on Cisco LEAP Vulnerability 2004-04-12 Cisco Systems Product Security Incident Response Team (psirt cisco com) Citadel/UX 6.20 fixes local permissions vulnerability 2004-04-12 error citadel org (IO ERROR) Citadel/UX Security Advisory 2004-01 1. Topic: Updated Citadel/UX package fixes permissions problem which could allow local users direct access to the Citadel/UX database. 2. Relevant releases/architectures: Citadel/UX 5.00 - 6.14, all architectures 3. Problem description: Citadel/UX is a hig [ more ] [ reply ] Possible DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow. 2004-04-12 Nikita V. Youshchenko (yoush cs msu su) Hello. We faced a bug (?) in Linux kernel causing different misbehaviours on our server. After exploration, it seems that we found some security implications of this issue. When a process exits, it's parent is notified by SIGCHLD, and finished child is kept in process table in "zombie" state u [ more ] [ reply ] Monit <= 4.2 Remote Root Exploit 2004-04-11 Eye on Security India (eos-india linuxmail org) /* * THE EYE ON SECURITY RESEARCH GROUP - INDIA * * http://www.eos-india.net/poc/305monit.c * Remote Root Exploit for Monit <= 4.2 * Vulnerability: Buffer overflow in handling of Basic Authentication informations. * Server authenticates clients through: * Authentication: Basic Base64Encode[Us [ more ] [ reply ] Backdoor in X-Micro WLAN 11b Broadband Router 2004-04-10 RISKO Gergely (xmicro risko hu) Backdoor in the X-Micro WLAN 11b Broadband Router FCC ID: RAFXWL-11BRRG Firmware Version: 1.2.2, 1.2.2.3 (probably others too) Remote: yes, easily expoitable Type: administration password, which always works The following username and password works in every case, even if you set an other password [ more ] [ reply ] RE: Full-Disclosure is now ILLEGAL in France ! (Vulnerabilties, Technical details, Exploits ...) 2004-04-10 Amer Karim (amerk nautilis-sys com) Sorry mate - you're confusing English common law and the Napoleonic Code. Under the former, a person is presumed innocent until proven guilty, placing the burden of proof on the accuser. Under the latter, a person is presumed guilty until proven otherwise, and implicitly places the burden of proof [ more ] [ reply ] ANNOUNCE: SecLegal mailing list 2004-04-09 Thor Larholm (thor pivx com) There's often a lot of discussions on security mailing lists about the legality of security research, proof-of-concept exploits, penetration testing, war-driwing, reverse engineering, lack of vendor notification, patent issues, copy protection circumvention and much more. Currently, France it outl [ more ] [ reply ] |
|
Privacy Statement |
is too low as most of the mail servers, these days, are
blocking/dropping blank-From-address emails.
-----Original Message-----
From: Arman Nayyeri [mailto:arman-n (at) Phreaker (dot) net [email concealed]]
Sent: Sunday, April 11, 2004 11:08 AM
To: bugtra
[ more ] [ reply ]