BugTraq Mode:
(Page 1598 of 1748)  < Prev  1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603  Next >
XLS Attack on AES (Rijndael) 2003-10-24
latte1 hushmail com
I read, some time ago, about a new form of attack on
the AES algorithm: Rijndael...

Since then I have not heard any more about it, so I
was wondering what the latest thoughts on this method
are ? Is is currently being researched, etc, etc...

-- Michael

XLS Attack: http://www.minrank.org/aes/#AESb

[ more ]  [ reply ]
[CLA-2003:771] Conectiva Security Announcement - anonftp 2003-10-24
Conectiva Updates (secure conectiva com br)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- ------------------------------------------------------------------------
--

PACKAGE : anonftp
SUMMARY : Remote denial of service vu

[ more ]  [ reply ]
Internet Explorer and Opera local zone restriction bypass 2003-10-24
Mindwarper * (mindwarper linuxmail org)
Internet Explorer and Opera local zone restriction bypass.
=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=

----------------------
Vendor Information:
----------------------

Homepage : http://www.microsoft.com
Vendor : informed
Mailed advisory: 23/10/03
Vender Response : None yet

----

[ more ]  [ reply ]
HTML Help API - Privilege Escalation 2003-10-24
Brett Moore (brett moore security-assessment com)
=====================================================================
= HTML Help API - Privilege Escalation
=
= Tested against:
= HTML Help Control Version 5.2.3735.1
=
= brett.moore (at) security-assessment (dot) com [email concealed]
= http://www.security-assessment.com
=
= Originally posted: October 24th, 2003
===========

[ more ]  [ reply ]
(Fw) : mIRC 6.12 (latest) DCC Exploit 2003-10-23
K-OTiK Security (Special-Alerts k-otik com)


this news was found on irchelp, DCC Exploit Affecting mIRC 6.12 :

another exploit was identified which can crash even the recently released version 6.12. It only seems to affect people who minimize DCC get dialog windows (manually or by default), and then open those windows to get a file with a

[ more ]  [ reply ]
Shatter XP 2003-10-23
xenophi1e (oliver lavery sympatico ca)


Intro

-----

Brett Moore from Security Assesment put me onto this one. XP's Visual Styles, the feature that makes various controls in Windows XP look a less dated, also introduce a new shatter type vulnerability into the OS.

Vuln

-------

Applications which have the new XPified appearan

[ more ]  [ reply ]
CensorNet: Cross Site Scripting Vulnerability 2003-10-22
Richard Maudsley (maudr001 rbwm org)
Hello,

A cross site scripting vulnerability exists in the CensorNet Proxy Service
(www.censornet.com) that allows scripting (and html) to be passed to the
cgi script and displayed in the web browser.

Exploit:
http://SERVER/cgi-bin/dansguardian.pl?DENIEDURL=</a><script>alert('Count
er-Strike__server

[ more ]  [ reply ]
[LSD] Security vulnerability in SUN's Java Virtual Machine implementation 2003-10-23
Last Stage of Delirium (contact lsd-pl net)

Hello,

We have found a security vulnerability in the SUN's implementation of the Java
Virtual Machine, which affects the following SDK and JRE releases:
- SDK and JRE 1.4.1_03 and earlier
- SDK and JRE 1.3.1_08 and earlier
- SDK and JRE 1.2.2_015 and earlier.

SUN was informed about this iss

[ more ]  [ reply ]
"Local" and "Remote" considered insufficient 2003-10-22
Steven M. Christey (coley mitre org) (2 replies)

In a recent post, Florian Weimer said:

>> PACKAGE : ircd
>> SUMMARY : Local denial of service vulnerability
>
>Actually it's *remote* in the usual terminology on this list.
>
>[snip]
>
>When IRC server developers talk about "local vulnerabilities"
>vs. "remote vulnerabilities", they mean the d

[ more ]  [ reply ]
Re: "Local" and "Remote" considered insufficient 2003-10-23
Eric Knight (eric swordsoft com)
Re: "Local" and "Remote" considered insufficient 2003-10-23
Ejovi Nuwere (ejovi ejovi net) (1 replies)
Re: "Local" and "Remote" considered insufficient 2003-10-23
Florian Weimer (fw deneb enyo de)
[CLA-2003:769] Conectiva Security Announcement - sane 2003-10-22
Conectiva Updates (secure conectiva com br)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- ------------------------------------------------------------------------
--

PACKAGE : sane
SUMMARY : Vulnerabilities in saned and i

[ more ]  [ reply ]
Re: Web Wiz Forums ver. 7.01 2003-10-22
bruce webwizguide info
In-Reply-To: <18150849207.20031022004135 (at) hex.net (dot) ru [email concealed]>

>Received: (qmail 24988 invoked from network); 21 Oct 2003 22:17:00 -0000

>Received: from outgoing3.securityfocus.com (205.206.231.27)

> by mail.securityfocus.com with SMTP; 21 Oct 2003 22:17:00 -0000

>Received: from lists2.securityfocus.com

[ more ]  [ reply ]
[CLA-2003:768] Conectiva Security Announcement - fileutils 2003-10-22
Conectiva Updates (secure conectiva com br)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- ------------------------------------------------------------------------
--
CONECTIVA LINUX SECURITY ANNOUNCEMENT
- ------------------------------------------------------------------------
--

PACKAGE : fileutils
SUMMARY : Denial of service vulnera

[ more ]  [ reply ]
Re: IE6 CSS-Crash 2003-10-22
xenophi1e (oliver lavery sympatico ca)
In-Reply-To: <1066826686.3696.32.camel@falcon>

>Hi,

>the following HTML/JS/CSS-Code crashes IE6 immediately through a

>combination of:

>1. textarea in table in div

>2. css:overflow-y:hidden

>3. changing the scrollbar-base-color

>4. moving the div

This looks like a benign crash to me. On

[ more ]  [ reply ]
IE6 CSS-Crash 2003-10-22
Andreas Boeckler (abo netlands de)
Hi,
the following HTML/JS/CSS-Code crashes IE6 immediately through a
combination of:
1. textarea in table in div
2. css:overflow-y:hidden
3. changing the scrollbar-base-color
4. moving the div

I think IE tries to move the native OS-scrollbar-widget, which is not in
place.

If point 3 is removed, th

[ more ]  [ reply ]
mah-jong[v1.4]: server/client remote buffer overflow exploit. 2003-10-22
Vade 79 (v9 fakehalo deadpig org)


did an audit of mah-jong after seeing something about a debian advisory...the bug(s) found weren't mentioned, but were fixed in the overall (giant) patch for mah-jong, which is provided on debian's website(1.4-2 patch). anyways, here is an exploit for the bug(s) found.

original reference:

ht

[ more ]  [ reply ]
MS03-046 Microsoft Exchange 2000 Heap Overflow 2003-10-22
H D Moore (sflist digitaloffense net)
On October 15th, Microsoft released an advisory stating that both Exchange
5.5 and Exchange 2000 were vulnerable to a denial of service attack in
the code which processes extended verb requests. This advisory also
stated that Exchange 2000 was vulnerable to a buffer overrun that would
allow a re

[ more ]  [ reply ]
Web Wiz Forums ver. 7.01 2003-10-21
HEX (hex hex net ru)
Informations :
°°°°°°°°°°°°
Language : ASP
Bugged Version : Web Wiz Forums ver. 7.01 (and less ?)
Patched version : none
Website : http://www.webwizforums.com
Problems : Permanent XSS

Objects :
°°°°°°°
- forum_members.asp
- members.asp

- pm_buddy_list.asp

Exploits :
°°°°°°°°
http://[TARGET]/forum

[ more ]  [ reply ]
IE6 & Java 1.4.2_02 applet: Hardware stress on floppy drive 2003-10-21
Marc Schoenefeld (schonef uni-muenster de)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Hi,

be prepared that your IE6 will be blocked if you
run the java plugin (any 1.4.x including 1.4.2_02)
with the following applet:

http://www.illegalaccess.org/exploits/java/applet/MyFloppySucks.html

Of course this only work when you have a drive a:.

[ more ]  [ reply ]
OpenServer 5.0.5 : Insecure creation of files in /tmp 2003-10-21
security sco com

To: announce (at) lists.caldera (dot) com [email concealed] bugtraq (at) securityfocus (dot) com [email concealed] full-disclosure (at) lists (dot) n [email concealed]
etsys.com

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

________________________________________________________________________
______

SCO Security Advisory

Subject: OpenServer 5.0.5 : Insecure creation of fil

[ more ]  [ reply ]
SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version 2003-10-21
Sintelli SINTRAQ (sintraq sintelli com)
SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version
18 October 2003

Original Advisory
http://www.sintelli.com/adv/sa-2003-04-myclassified.pdf

Background
My Classifieds SQL is a Perl/CGI/MySQL script which will quickly and easily
allow the hosting of a classifieds forum on a websit

[ more ]  [ reply ]
Immunix Secured OS 7+ fetchmail update 2003-10-20
Immunix Security Team (security immunix com)
-----------------------------------------------------------------------
Immunix Secured OS Security Advisory

Packages updated: fetchmail, fetchmailconf
Affected products: Immunix OS 7+
Bugs fixed: CAN-2002-1365, CAN-2003-0792, CAN-2003-0790
Date: Fri Oct 17 2003
Advisory ID: IMNX-2003-7+-023-0

[ more ]  [ reply ]
RE: IE remote code execution 2003-10-20
Thor Larholm (thor pivx com)
A default Windows 98SE installation is several years behind in patches.

This does not reproduce on any IE browser that has been patched the last
year or so.

If in doubt about your IE patch level apply the latest cumulative patch
MS03-040, which can be found at

http://www.microsoft.com/technet/sec

[ more ]  [ reply ]
Gast Arbeiter Privilege Escalation 2003-10-20
natok hush com
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- - - ------------------------------------------------------------
NATOK security labs natok at hush.com
October 20st, 2003 Privilege Escalation
- - - --------------------------------------------------

[ more ]  [ reply ]
Cross Site Java applets 2003-10-20
Marc Schoenefeld (schonef uni-muenster de)
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Cross-Site Java breaks Sandbox Isolation for Unsigned Applets
=============================================================

Product : Java Plugin
Version : 1.4.2_01
OS : Win32 (should apply for other OSs too)
URL : http://java.sun.com
Foun

[ more ]  [ reply ]
Multiple SQL Injection Vulnerabilities in DeskPRO 2003-10-20
Aviram Jenik (aviram beyondsecurity com)
Multiple SQL Injection Vulnerabilities in DeskPRO
------------------------------------------------------------------------
-

Article reference:
http://www.securiteam.com/unixfocus/6R0052K8KM.html

SUMMARY

DeskPRO (http://www.deskpro.com) is "an integrated script to manage your
customer sales and

[ more ]  [ reply ]
(Page 1598 of 1748)  < Prev  1593 1594 1595 1596 1597 1598 1599 1600 1601 1602 1603  Next >


 

Privacy Statement
Copyright 2010, SecurityFocus