|
Colapse all |
Post message
Local file retrieving in QNX Internet Appliance Toolkit http-daemon (web.server) 2003-06-22 Michael Bemmerl (security astrobox net) Linux /proc sensitive information disclosure 2003-06-20 Paul Starzetz (paul starzetz de) Hello, attached a simple prrof of concept for the /proc filesystem disclosing sensitive information. I noticed that opening an entry from /proc/self/ and keeping the file open while executing a setuid binary prevents the opened proc entry from changing the ownership from the initial user to the [ more ] [ reply ] Intrusec 55808 Trojan Analysis 2003-06-20 David J. Meltzer (djm intrusec com) Intrusec Alert: 55808 Trojan Analysis Initial Release: 6/19/03 4:30PM EDT Latest Update: 6/19/03 11:13PM EDT - Corrected analysis regarding use of sequence numbers to change IP address. - Added reference to alternate name "Stumbler" given to trojan by Internet Security Systems subsequent to the re [ more ] [ reply ] HP-UX pcltotiff 2003-06-20 security-alert hp com -----BEGIN PGP SIGNED MESSAGE----- A bugtraq posting on July 9, 2003 mentions a vulnerability in pcltotiff on HP-UX 10.XX. This is the subject of the security bulletin HPSBUX0104-149. The main points are: PROBLEM: /opt/sharedprint/bin/pcltotiff has unsafe permissions. PLATFORM: HP9000 Series [ more ] [ reply ] [SECURITY] [DSA-325-1] New eldav packages fix insecure temporary file creation 2003-06-19 Matt Zimmerman (mdz debian org) phpBB password disclosure by sql injection 2003-06-19 Rick (rikul bellsouth net) Hi There is sql injection vuln in phpBB. The variable "topic_id" is passed directly from GET to sql query in /viewtopic.php. It can be used to get md5 passwords for users. I am attaching details and proof of concept code. I've only tested this on mysql 4 and pgsql at my home machines so I might h [ more ] [ reply ] SurfControl Web Filter for Microsoft ISA Server Vulnerability 2003-06-19 thomas adams (tgadams bellsouth net) Multiple buffer overflows and XSS in Kerio MailServer 2003-06-18 David F.Madrid (conde0 telefonica net) Issue : Multiple buffer overflows and XSS in Kerio MailServer Version affected 5.6.3 ( last in kerio website ) Vendor status : Vendor was notified Description : Kerio develop a mail server with support for Imap , Pop3, Smtp and SSL protocols . Besides , it includes a webmail . This webmail is [ more ] [ reply ] [SECURITY] [DSA-316-3] New jnethack packages fix buffer overflow, incorrect permissions 2003-06-17 Matt Zimmerman (mdz debian org) MDKSA-2003:069 - Updated BitchX packages fix DoS vulnerability 2003-06-17 Mandrake Linux Security Team (security linux-mandrake com) PALM DESKTOP SOFTWARE / WIN 2000 2003-06-17 Scott R. Patronik (scottrp localnet com) (1 replies) If a Win NT/2000 Workstation is locked, and a Palm Cradle is connected with Palm Desktop Software running, information can still be retrieved and loaded into the Palm device from the PC without logging into the workstation. Scott R. Patronik scottrp (at) localnet (dot) com [email concealed] --------------------------------- [ more ] [ reply ] ConnecTalk Security Advisory: Qpopper leaks information during authentication 2003-06-18 Marc Lafortune (mlafortune connectalk com) (2 replies) ======================================================================== ===== ConnecTalk Inc. Security Advisory Topic: Qpopper leaks information during authentication Vendor: Eudora Product: qpopper 4.0.4 and qpopper 4.0.5 Note: other versions have not been tested. Problem f [ more ] [ reply ] Re: ConnecTalk Security Advisory: Qpopper leaks information during authentication ** Forget this one... ** 2003-06-19 Marc Lafortune (mlafortune connectalk com) Re: ConnecTalk Security Advisory: Qpopper leaks information during authentication 2003-06-18 Justin Wheeler (jwheeler datademons com) ASP replacement for ISM.DLL available 2003-06-18 Michael Howard (mikehow microsoft com) In an effort to provide customers with greater defense in depth, Microsoft has released an Active Server Pages (ASP) replacement for the Internet Information Server 4 and Internet Information Services 5 change password capability, ISM.DLL. This new script code no longer runs as SYSTEM, therefore red [ more ] [ reply ] Resolution of Issue - Compaq Insight Manager - related to Bugtraq ID 2500 2003-06-18 Brewis, Mark (mark brewis eds com) Following considerable investigations by the HP Team responsible for the CIM Agents component in Compaq Insight Manager, it has been agreed that this is not an issue with CIM, and I am happy to state that this bugtraq post, regarding ftp over CIM, should be withdrawn. A combination of testing archi [ more ] [ reply ] Re: CuteFTP 5.0 XP, Buffer Overflow 2003-06-18 robert globalscape com In-Reply-To: <20030206045629.9764.qmail (at) mail.securityfocus (dot) com [email concealed]> Re: thread below, the new LIST defect and long URL buffer overflow defect have been fixed in version 5.0.2 (released June 9th). This version is available at: http://www.globalscape.com/cuteftp and ftp://ftp.cuteftp.com/pub/cuteftp [ more ] [ reply ] Re: [Full-Disclosure] Cross-Site Scripting in Unparsable XML Files (GM#013-IE) 2003-06-17 jelmer (kuper237 planet nl) (1 replies) hi greymagic, First off i can't reproduce this on my fully patched ie6 Second you should be able to have ie render any html page as a xml file like this <object type="application/xml" data="http://www.yahoo.com" width="500" height="500"> </object> Generaly html files are not well formed xml so i [ more ] [ reply ] Re: [Full-Disclosure] Cross-Site Scripting in Unparsable XML Files (GM#013-IE) 2003-06-17 Kevin Spett (kspett spidynamics com) MIPSPro Compiler Predictable Temp File vulnerability 2003-06-17 SGI Security Coordinator (agent99 sgi com) Portmon file arbitrary read/write access vulnerability 2003-06-17 David Hancock (dmhancoc us ibm com) [slackware-security] 2.4.21 kernels available (SSA:2003-168-01) 2003-06-18 Slackware Security Team (security slackware com) -----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [slackware-security] 2.4.21 kernels available (SSA:2003-168-01) Precompiled Linux 2.4.21 kernels and source packages are now available for Slackware 9.0 and -current. These provide an improved version of the ptrace fix that had been applied to 2.4.2 [ more ] [ reply ] MHFTPD vulnerability 2003-06-18 Frank Denis (j 42-networks com) Product : MidHosting FTPd Date : 06/18/2003 Author : Frank Denis <j (at) 42-networks (dot) com [email concealed]> ------------------------[ Product description ]------------------------ MidHosting FTPd is an FTP server designed for hosting servers, based upon virtual ftpd with support for chroot, virtual users and o [ more ] [ reply ] |
|
Privacy Statement |
(web.server)
Vendor-URL: http://www.qnx.com
Description:
--====--
I recently found a 3,5"-disk labeled with QNX-demo on my desk. This is
the "Take the 1.44M Web Challenge!"-disk I got it in 1998. I couldn't find
the demo on the q
[ more ] [ reply ]