|
Colapse all |
Post message
[CLA-2003:771] Conectiva Security Announcement - anonftp 2003-10-24 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : anonftp SUMMARY : Remote denial of service vu [ more ] [ reply ] Internet Explorer and Opera local zone restriction bypass 2003-10-24 Mindwarper * (mindwarper linuxmail org) Internet Explorer and Opera local zone restriction bypass. =--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--=--= ---------------------- Vendor Information: ---------------------- Homepage : http://www.microsoft.com Vendor : informed Mailed advisory: 23/10/03 Vender Response : None yet ---- [ more ] [ reply ] HTML Help API - Privilege Escalation 2003-10-24 Brett Moore (brett moore security-assessment com) ===================================================================== = HTML Help API - Privilege Escalation = = Tested against: = HTML Help Control Version 5.2.3735.1 = = brett.moore (at) security-assessment (dot) com [email concealed] = http://www.security-assessment.com = = Originally posted: October 24th, 2003 =========== [ more ] [ reply ] (Fw) : mIRC 6.12 (latest) DCC Exploit 2003-10-23 K-OTiK Security (Special-Alerts k-otik com) this news was found on irchelp, DCC Exploit Affecting mIRC 6.12 : another exploit was identified which can crash even the recently released version 6.12. It only seems to affect people who minimize DCC get dialog windows (manually or by default), and then open those windows to get a file with a [ more ] [ reply ] Shatter XP 2003-10-23 xenophi1e (oliver lavery sympatico ca) Intro ----- Brett Moore from Security Assesment put me onto this one. XP's Visual Styles, the feature that makes various controls in Windows XP look a less dated, also introduce a new shatter type vulnerability into the OS. Vuln ------- Applications which have the new XPified appearan [ more ] [ reply ] CensorNet: Cross Site Scripting Vulnerability 2003-10-22 Richard Maudsley (maudr001 rbwm org) Hello, A cross site scripting vulnerability exists in the CensorNet Proxy Service (www.censornet.com) that allows scripting (and html) to be passed to the cgi script and displayed in the web browser. Exploit: http://SERVER/cgi-bin/dansguardian.pl?DENIEDURL=</a><script>alert('Count er-Strike__server [ more ] [ reply ] [LSD] Security vulnerability in SUN's Java Virtual Machine implementation 2003-10-23 Last Stage of Delirium (contact lsd-pl net) Hello, We have found a security vulnerability in the SUN's implementation of the Java Virtual Machine, which affects the following SDK and JRE releases: - SDK and JRE 1.4.1_03 and earlier - SDK and JRE 1.3.1_08 and earlier - SDK and JRE 1.2.2_015 and earlier. SUN was informed about this iss [ more ] [ reply ] "Local" and "Remote" considered insufficient 2003-10-22 Steven M. Christey (coley mitre org) (2 replies) In a recent post, Florian Weimer said: >> PACKAGE : ircd >> SUMMARY : Local denial of service vulnerability > >Actually it's *remote* in the usual terminology on this list. > >[snip] > >When IRC server developers talk about "local vulnerabilities" >vs. "remote vulnerabilities", they mean the d [ more ] [ reply ] Re: "Local" and "Remote" considered insufficient 2003-10-23 Ejovi Nuwere (ejovi ejovi net) (1 replies) [CLA-2003:769] Conectiva Security Announcement - sane 2003-10-22 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : sane SUMMARY : Vulnerabilities in saned and i [ more ] [ reply ] Re: Web Wiz Forums ver. 7.01 2003-10-22 bruce webwizguide info In-Reply-To: <18150849207.20031022004135 (at) hex.net (dot) ru [email concealed]> >Received: (qmail 24988 invoked from network); 21 Oct 2003 22:17:00 -0000 >Received: from outgoing3.securityfocus.com (205.206.231.27) > by mail.securityfocus.com with SMTP; 21 Oct 2003 22:17:00 -0000 >Received: from lists2.securityfocus.com [ more ] [ reply ] [CLA-2003:768] Conectiva Security Announcement - fileutils 2003-10-22 Conectiva Updates (secure conectiva com br) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ -- CONECTIVA LINUX SECURITY ANNOUNCEMENT - ------------------------------------------------------------------------ -- PACKAGE : fileutils SUMMARY : Denial of service vulnera [ more ] [ reply ] Re: IE6 CSS-Crash 2003-10-22 xenophi1e (oliver lavery sympatico ca) In-Reply-To: <1066826686.3696.32.camel@falcon> >Hi, >the following HTML/JS/CSS-Code crashes IE6 immediately through a >combination of: >1. textarea in table in div >2. css:overflow-y:hidden >3. changing the scrollbar-base-color >4. moving the div This looks like a benign crash to me. On [ more ] [ reply ] IE6 CSS-Crash 2003-10-22 Andreas Boeckler (abo netlands de) Hi, the following HTML/JS/CSS-Code crashes IE6 immediately through a combination of: 1. textarea in table in div 2. css:overflow-y:hidden 3. changing the scrollbar-base-color 4. moving the div I think IE tries to move the native OS-scrollbar-widget, which is not in place. If point 3 is removed, th [ more ] [ reply ] mah-jong[v1.4]: server/client remote buffer overflow exploit. 2003-10-22 Vade 79 (v9 fakehalo deadpig org) did an audit of mah-jong after seeing something about a debian advisory...the bug(s) found weren't mentioned, but were fixed in the overall (giant) patch for mah-jong, which is provided on debian's website(1.4-2 patch). anyways, here is an exploit for the bug(s) found. original reference: ht [ more ] [ reply ] MS03-046 Microsoft Exchange 2000 Heap Overflow 2003-10-22 H D Moore (sflist digitaloffense net) On October 15th, Microsoft released an advisory stating that both Exchange 5.5 and Exchange 2000 were vulnerable to a denial of service attack in the code which processes extended verb requests. This advisory also stated that Exchange 2000 was vulnerable to a buffer overrun that would allow a re [ more ] [ reply ] Web Wiz Forums ver. 7.01 2003-10-21 HEX (hex hex net ru) Informations : °°°°°°°°°°°° Language : ASP Bugged Version : Web Wiz Forums ver. 7.01 (and less ?) Patched version : none Website : http://www.webwizforums.com Problems : Permanent XSS Objects : °°°°°°° - forum_members.asp - members.asp - pm_buddy_list.asp Exploits : °°°°°°°° http://[TARGET]/forum [ more ] [ reply ] IE6 & Java 1.4.2_02 applet: Hardware stress on floppy drive 2003-10-21 Marc Schoenefeld (schonef uni-muenster de) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hi, be prepared that your IE6 will be blocked if you run the java plugin (any 1.4.x including 1.4.2_02) with the following applet: http://www.illegalaccess.org/exploits/java/applet/MyFloppySucks.html Of course this only work when you have a drive a:. [ more ] [ reply ] OpenServer 5.0.5 : Insecure creation of files in /tmp 2003-10-21 security sco com To: announce (at) lists.caldera (dot) com [email concealed] bugtraq (at) securityfocus (dot) com [email concealed] full-disclosure (at) lists (dot) n [email concealed] etsys.com -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ________________________________________________________________________ ______ SCO Security Advisory Subject: OpenServer 5.0.5 : Insecure creation of fil [ more ] [ reply ] SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version 2003-10-21 Sintelli SINTRAQ (sintraq sintelli com) SQL Injection Vulnerability in FuzzyMonkey MyClassifieds SQL Version 18 October 2003 Original Advisory http://www.sintelli.com/adv/sa-2003-04-myclassified.pdf Background My Classifieds SQL is a Perl/CGI/MySQL script which will quickly and easily allow the hosting of a classifieds forum on a websit [ more ] [ reply ] Immunix Secured OS 7+ fetchmail update 2003-10-20 Immunix Security Team (security immunix com) ----------------------------------------------------------------------- Immunix Secured OS Security Advisory Packages updated: fetchmail, fetchmailconf Affected products: Immunix OS 7+ Bugs fixed: CAN-2002-1365, CAN-2003-0792, CAN-2003-0790 Date: Fri Oct 17 2003 Advisory ID: IMNX-2003-7+-023-0 [ more ] [ reply ] RE: IE remote code execution 2003-10-20 Thor Larholm (thor pivx com) A default Windows 98SE installation is several years behind in patches. This does not reproduce on any IE browser that has been patched the last year or so. If in doubt about your IE patch level apply the latest cumulative patch MS03-040, which can be found at http://www.microsoft.com/technet/sec [ more ] [ reply ] Cross Site Java applets 2003-10-20 Marc Schoenefeld (schonef uni-muenster de) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cross-Site Java breaks Sandbox Isolation for Unsigned Applets ============================================================= Product : Java Plugin Version : 1.4.2_01 OS : Win32 (should apply for other OSs too) URL : http://java.sun.com Foun [ more ] [ reply ] Multiple SQL Injection Vulnerabilities in DeskPRO 2003-10-20 Aviram Jenik (aviram beyondsecurity com) Multiple SQL Injection Vulnerabilities in DeskPRO ------------------------------------------------------------------------ - Article reference: http://www.securiteam.com/unixfocus/6R0052K8KM.html SUMMARY DeskPRO (http://www.deskpro.com) is "an integrated script to manage your customer sales and [ more ] [ reply ] |
|
Privacy Statement |
the AES algorithm: Rijndael...
Since then I have not heard any more about it, so I
was wondering what the latest thoughts on this method
are ? Is is currently being researched, etc, etc...
-- Michael
XLS Attack: http://www.minrank.org/aes/#AESb
[ more ] [ reply ]