<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Bugtraq | Bugtraq</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>13 Feb  2012 03:52:10 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Bugtraq | Bugtraq</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>rPSA-2008-0018-1 mysql mysql-bench mysql-server</title>
<description>rPath Security Advisory: 2008-0018-1 Published: 2008-01-17 Products:   rPath Linux 1 Rating: Major Exposure Level Classification:   Local Determi</description>
<pubDate>17 Jan  2008 07:32:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26774</link>
</item><item>
<title>[SECURITY] [DSA 1465-1] New apt-listchanges packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>17 Jan  2008 06:38:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26771</link>
</item><item>
<title>[security bulletin] HPSBMA02133 SSRT061201 rev.7 - HP Oracle for OpenView (OfO) Critical Patch Update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c00727143 Version: 7 HPSBMA02133 SSRT061201 re</description>
<pubDate>17 Jan  2008 05:30:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26770</link>
</item><item>
<title>Clever Copy &amp;lt;=3.0 Multiple Remote Vulnerabilities</title>
<description>####################################################################  #                                 #  #</description>
<pubDate>17 Jan  2008 00:54:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26777</link>
</item><item>
<title>PHPEchoCMS Multible remote vulnerabilitis</title>
<description>Hello,, PHPEchoCMS Multible remote vulnerabilitis Discovered By : HACKERS PAL Copy rights : HACKERS PAL Website : http://www.soqor.net Email Address</description>
<pubDate>16 Jan  2008 21:07:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26773</link>
</item><item>
<title>JoomlaFlash Component Multiple Remote File Inclusion</title>
<description>Autore: Smasher Sito: http://warwolfz.altervista.org Tipo: Remote File Inclusion Rischio: Alto A remote attacker can gain access to your website thro</description>
<pubDate>16 Jan  2008 16:06:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26772</link>
</item><item>
<title>[ MDVSA-2008:016 ] - Updated apache 2.2.x packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>16 Jan  2008 15:30:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26775</link>
</item><item>
<title>[USN-570-1] boost vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-570-1      January 16, 2008 boost vulnerabilities CVE-200</description>
<pubDate>16 Jan  2008 14:45:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26768</link>
</item><item>
<title>Re: [CVE-2007-2449] Apache Tomcat XSS vulnerabilities in the JSP examples</title>
<description>Hello, I inputed the example string from IE and Firefox, but it doesn&amp;#039;t work. The Tomcat version is 5.5.23.  It just displayed what I typed. ... Req</description>
<pubDate>16 Jan  2008 14:40:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26776</link>
</item><item>
<title>[ MDVSA-2008:015 ] - Updated apache 2.0.x packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>16 Jan  2008 14:29:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26769</link>
</item><item>
<title>[ MDVSA-2008:014 ] - Updated apache 1.3.x packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>16 Jan  2008 14:16:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26767</link>
</item><item>
<title>Gradman &amp;lt;= 0.1.3 (agregar_info.php?tabla=) Local File Inclusion Exploit</title>
<description>[+] Info: [~] Software: Gradman &amp;lt;= 0.1.3 [~] HomePage: http://gradman.xe1ido.com.mx/ [~] Exploit: Local File Inclusion [High] [~] Where: agregar_info</description>
<pubDate>16 Jan  2008 13:11:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26766</link>
</item><item>
<title>SQL scalar function to convert big int to dot notation</title>
<description>For those of you logging ISA (or whatever) to SQL, you&amp;#039;ll have no doubt noted that the source and destination IP&amp;#039;s are logged as long integers, and no</description>
<pubDate>16 Jan  2008 12:20:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26764</link>
</item><item>
<title>[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10</title>
<description>[waraxe-2008-SA#062] - Multiple Sql Injections in MyBB 1.2.10 =============================================================================== Author:</description>
<pubDate>16 Jan  2008 12:19:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26762</link>
</item><item>
<title>[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10</title>
<description>[waraxe-2008-SA#061] - Remote Code Execution in MyBB 1.2.10 =============================================================================== Author: J</description>
<pubDate>16 Jan  2008 12:18:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26765</link>
</item><item>
<title>TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability</title>
<description>TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability http://dvlabs.tippingpoint.com/advisory/TPTI-08-02 January 16, 2008 -- CVE ID:</description>
<pubDate>16 Jan  2008 12:12:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26763</link>
</item><item>
<title>Country by Country Computer Sets now available for ISA 2004</title>
<description>I&amp;#039;ve updated the HoG site to include Country-by-country sets for ISA 2004 for those still using that version of the product. http://hammerofgod.com/d</description>
<pubDate>16 Jan  2008 12:00:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26761</link>
</item><item>
<title>Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5</title>
<description>#######################################################################                Luigi Auriemma Applications: BitTorrent and uTo</description>
<pubDate>16 Jan  2008 10:47:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26760</link>
</item><item>
<title>mcGuestbook v1.2 Remote File Inc.</title>
<description>Author: BLaSTER a.K.a Gokhan Title: mcGuestbook v1.2 Remote File Inc. Download: http://www.hotscripts.com/jump.php?listing_id=13439&amp;amp;jump_type=1 Contac</description>
<pubDate>16 Jan  2008 10:44:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26759</link>
</item><item>
<title>Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow Document ID:</description>
<pubDate>16 Jan  2008 08:15:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26758</link>
</item><item>
<title>RichStrong CMS (showproduct.asp?cat=) Remote SQL Injection Exploit</title>
<description>[+] Info: [~] Software: RichStrong CMS [~] HomePage: http://www.hzrich.cn [~] Exploit: Remote Sql Injection [High] [~] Where: showproduct.asp?cat= [~</description>
<pubDate>16 Jan  2008 03:36:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26748</link>
</item><item>
<title>[DSECRG-08-003] blogcms 4.2.1b Multiple Security Vulnerabilities</title>
<description>Digital Security Research Group [DSecRG] Advisory    #DSECRG-08-003  Application:          Blogcms Versions Affected:       Blogc</description>
<pubDate>16 Jan  2008 03:02:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26747</link>
</item><item>
<title>[DSECRG-08-002] Local File Include in arias 0.99-6</title>
<description>Digital Security Research Group [DSecRG] Advisory    #DSECRG-08-002  Application:          aria-0.99-6 (Web based ERP) Versions Affected</description>
<pubDate>16 Jan  2008 02:37:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26753</link>
</item><item>
<title>Re: what is this?</title>
<description>Just to add to what has already passed, Security Focus has put up this article regarding this issue. http://www.securityfocus.com/news/11501 ys On 1</description>
<pubDate>16 Jan  2008 00:57:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26745</link>
</item><item>
<title>cPanel Hosting Manager (dohtaccess.html)</title>
<description>Aria-Security Team http://Aria-Security.Net ----------------------------------- Vendor: http://cPanel.com cPanel Hosting Manager (dohtaccess.html) Cro</description>
<pubDate>15 Jan  2008 20:09:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26750</link>
</item><item>
<title>[Aria-Security.Net] Real Estate Web SQL Injection</title>
<description>Aria-Security Team, http://Aria-Security.net ------------------------------- Shout Outs: Vendor: http://www.site2nite.com/ Google Search: Website Dev</description>
<pubDate>15 Jan  2008 19:42:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26756</link>
</item><item>
<title>8e6 Technologies R3000 Internet Filter Bypass by Request Split</title>
<description>8e6 Technologies R3000 Internet Filter Bypass by Request Split  Product: 8e6 Technologies R3000 Internet Filter http://www.8e6.com/network-security/</description>
<pubDate>15 Jan  2008 18:55:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26755</link>
</item><item>
<title>[SECURITY] [DSA 1464-1] New syslog-ng packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>15 Jan  2008 15:47:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26746</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: Apple QuickTime Macintosh Resource Processing Heap Corruption Vulnerability</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND Quicktime is Apple&amp;#039;s media pla</description>
<pubDate>15 Jan  2008 15:15:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26757</link>
</item><item>
<title>TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption Vulnerability</title>
<description>TPTI-08-01: Apple Quicktime Image File IDSC Atom Memory Corruption  Vulnerability http://www.zerodayinitiative.com/advisories/TPTI-08-01.html January</description>
<pubDate>15 Jan  2008 15:02:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26754</link>
</item><item>
<title>rPSA-2008-0017-1 libxml2</title>
<description>rPath Security Advisory: 2008-0017-1 Published: 2008-01-15 Products:   rPath Appliance Platform Linux Service 1   rPath Linux 1 Rating: Minor Exp</description>
<pubDate>15 Jan  2008 14:54:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26752</link>
</item><item>
<title>rPSA-2008-0016-1 postgresql postgresql-server</title>
<description>rPath Security Advisory: 2008-0016-1 Published: 2008-01-15 Products:   rPath Linux 1 Rating: Minor Exposure Level Classification:   Remote Determ</description>
<pubDate>15 Jan  2008 14:53:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26751</link>
</item><item>
<title>rPSA-2008-0015-1 cairo</title>
<description>rPath Security Advisory: 2008-0015-1 Published: 2008-01-15 Products:   rPath Linux 1 Rating: Major Exposure Level Classification:   Indirect User</description>
<pubDate>15 Jan  2008 14:52:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26749</link>
</item><item>
<title>Re: Defeating audio captcha systems</title>
<description>Dear Jos?e M. Palazon Romero, This  approach  is  not  new,  it  was  demonstrated by ShAnKaR &amp;lt;shankar_(at)_shankar.name&amp;gt; against Simple Mac</description>
<pubDate>15 Jan  2008 14:33:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26744</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer Multiple Untrusted Loop Bounds Vulnerabilities</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:18:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26743</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver Multiple Untrusted Pointer Offset Vulnerabilities</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:12:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26742</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTServer Multiple Untrusted Pointer Vulnerabilities</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:04:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26741</link>
</item><item>
<title>iDefense Security Advisory 01.15.08: TIBCO SmartSockets RTserver Heap Overflow Vulnerability</title>
<description>iDefense Security Advisory 01.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jan 15, 2008 I. BACKGROUND TIBCO SmartSockets is a messag</description>
<pubDate>15 Jan  2008 11:01:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26740</link>
</item><item>
<title>Re: Linksys WRT54 GL - Session riding (CSRF)</title>
<description>On Mon, 14 Jan 2008 12:58:17 CST, Jan Heisterkamp said: &amp;gt; &amp;gt; A malicious link executing unnoticed by the administrator may open the firewall. &amp;gt; &amp;gt; The</description>
<pubDate>15 Jan  2008 10:14:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26739</link>
</item><item>
<title>Re: Linksys WRT54 GL - Session riding (CSRF)</title>
<description>&amp;gt; The catch is that this exploit don&amp;#039;t work unnoticed, because the admin &amp;gt; get notification in the browser that there has occured an error with the &amp;gt;</description>
<pubDate>15 Jan  2008 10:08:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26738</link>
</item><item>
<title>Re[2]: what is this?</title>
<description>---&amp;gt; figure out why my antivirus randomly popsup?i The exploit is served first time you load an infected page and then very infrequently after that (</description>
<pubDate>15 Jan  2008 09:26:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26737</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>nope i dont thnk it has to do with user agent.i have tried with IE,Firefox but nothing.though when u change ip it shows the stuff.so i think its ip ba</description>
<pubDate>15 Jan  2008 09:24:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26736</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>On Tue, 15 Jan 2008, crazy frog crazy frog wrote: &amp;gt; nick, &amp;gt; ur not getting my point,the url is techicorner.com/{random string &amp;gt; here},i have already m</description>
<pubDate>15 Jan  2008 09:22:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26735</link>
</item><item>
<title>Re[2]: what is this?</title>
<description>Good point, it could be an unknown kernel hole.  However it could and be a privilege escalation scenario through the application layer .. maybe PHP,</description>
<pubDate>15 Jan  2008 08:41:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26726</link>
</item><item>
<title>Re[2]: what is this?</title>
<description>Jamie, the servers are definately &amp;#039;rooted&amp;#039; - as in, root access required for what the exploit does ie. it&amp;#039;s dug itself deep into the kernel and you c</description>
<pubDate>15 Jan  2008 08:36:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26728</link>
</item><item>
<title>RE: what is this?</title>
<description>@Dennis: &amp;lt;quote&amp;gt; (...) From all reports so far it does not appear to be a kernel vulnerability (as some of the affected servers were using latest ker</description>
<pubDate>15 Jan  2008 08:33:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26734</link>
</item><item>
<title>Re: what is this?</title>
<description>On 15/01/2008, Denis &amp;lt;sp23@internode.on.net&amp;gt; wrote: &amp;gt; This is a very serious new threat affecting Linux servers and thousands &amp;gt; of boxes have been com</description>
<pubDate>15 Jan  2008 08:28:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26733</link>
</item><item>
<title>Pipe to FOR Crashes CMD</title>
<description>Pipe the output of a command to FOR in (), and you crash the Windows Vista Windows Command Processor (CMD.exe) with a DEP violation. I expect it works</description>
<pubDate>15 Jan  2008 07:41:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26732</link>
</item><item>
<title>MicroNews Admin Direct Access vulnerability</title>
<description># MicroNews Authentication Bypass # Homepage: http://phptoys.com/ # Download: http://www.phptoys.com/download.php?view.31 # Found by Xcross87 | xcross</description>
<pubDate>15 Jan  2008 07:33:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26731</link>
</item><item>
<title>Max&amp;#039;s File Uploader File Upload Vulnerability</title>
<description># Max&amp;#039;s File Uploader File Upload Vulnerability # Homepage: http://www.phpf1.com/ # Download: http://www.phpf1.com/download.html?item=9 # Dork: intitl</description>
<pubDate>15 Jan  2008 07:12:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26730</link>
</item><item>
<title>[security bulletin] HPSBST02304 SSRT080003 rev.1 - Storage Management Appliance (SMA), Microsoft Patch Applicability MS08-001 to MS08-002</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01325239 Version: 1 HPSBST02304 SSRT080003 re</description>
<pubDate>15 Jan  2008 06:10:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26712</link>
</item><item>
<title>[security bulletin] HPSBUX02303 SSRT071468 rev.1 - HP-UX Running X Font Server (xfs) Software, Remote Execution of Arbitrary Code</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 SUPPORT COMMUNICATION - SECURITY BULLETIN Document ID: c01323725 Version: 1 HPSBUX02303 SSRT071468 re</description>
<pubDate>15 Jan  2008 06:09:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26711</link>
</item><item>
<title>Article DashBoard all version SQL Injection Vulnerability</title>
<description>########################################################################## # ArticleDashBoard all version SQL Injection Vulnerability        #</description>
<pubDate>15 Jan  2008 05:36:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26729</link>
</item><item>
<title>SecurityReason - Apache (mod_status) Refresh Header - Open Redirector (XSS)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [SecurityReason - Apache (mod_status) Refresh Header - Open Redirector (XSS)] Author: sp3x Date: - -</description>
<pubDate>15 Jan  2008 00:33:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26727</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>nick, ur not getting my point,the url is techicorner.com/{random string here},i have already mentioned it in previous posts. i have read the link sent</description>
<pubDate>15 Jan  2008 00:26:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26725</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>crazy frog crazy frog wrote: &amp;gt; well, &amp;gt; i received many response but no one is perfact.i checked the files and &amp;gt; didn&amp;#039;t find anything embeded in my sc</description>
<pubDate>14 Jan  2008 22:45:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26724</link>
</item><item>
<title>Re: what is this?</title>
<description>well, i received many response but no one is perfact.i checked the files and didn&amp;#039;t find anything embeded in my scripts or pages.still i have to figur</description>
<pubDate>14 Jan  2008 22:12:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26723</link>
</item><item>
<title>Exploiting the SpamBam plugin for wordpress</title>
<description>The attached exploit demonstrates that the WordPress SpamBam plugin can be bypassed due to relying on the client for security. Vulnerable software: S</description>
<pubDate>14 Jan  2008 22:01:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26721</link>
</item><item>
<title>Defeating audio captcha systems</title>
<description>Hi all, Some days ago I wrote an advisory which demonstrates how the Peter&amp;#039;s Math Antispam Spinoff plugin for wordpress (http://www.theblog.ca/math-a</description>
<pubDate>14 Jan  2008 22:01:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26719</link>
</item><item>
<title>Re: what is this?</title>
<description>This is a very serious new threat affecting Linux servers and thousands of boxes have been compromised since December 2007. Each box serving the nast</description>
<pubDate>14 Jan  2008 21:16:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26718</link>
</item><item>
<title>[USN-569-1] libxml2 vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-569-1      January 14, 2008 libxml2 vulnerability CVE-200</description>
<pubDate>14 Jan  2008 16:13:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26717</link>
</item><item>
<title>FreeBSD Security Advisory FreeBSD-SA-08:02.libc</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ============================================================================= FreeBSD-SA-08:02.libc</description>
<pubDate>14 Jan  2008 15:09:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26716</link>
</item><item>
<title>FreeBSD Security Advisory FreeBSD-SA-08:01.pty</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ============================================================================= FreeBSD-SA-08:01.pty</description>
<pubDate>14 Jan  2008 15:09:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26715</link>
</item><item>
<title>[ MDVSA-2008:013 ] - Updated python packages fix vulnerability in imageop module</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>14 Jan  2008 15:04:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26714</link>
</item><item>
<title>[ MDVSA-2008:012 ] - Updated python packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>14 Jan  2008 14:56:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26713</link>
</item><item>
<title>Country by Country ISA Computer Sets</title>
<description>Recently, David Litchfield asked me to help him out a bit with a research project he was working on by having me set up a network capture in my DMZ to</description>
<pubDate>14 Jan  2008 14:20:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26720</link>
</item><item>
<title>Re: what is this?</title>
<description>&amp;gt; Hi, &amp;gt; &amp;gt; Recently on opening one of my site,my antivirus pops up saying that it &amp;gt; has found on malicious script.the url is random and i have managed</description>
<pubDate>14 Jan  2008 13:46:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26708</link>
</item><item>
<title>Re[2]: [Full-disclosure] what is this?</title>
<description>Dear Jose Nazario,  JN&amp;gt; te file you sent here contains a bunch of embeded nulls (every other JN&amp;gt; character is 00). stripping those out reveals .</description>
<pubDate>14 Jan  2008 13:39:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26707</link>
</item><item>
<title>[USN-568-1] PostgreSQL vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-568-1      January 14, 2008 postgresql vulnerabilities CV</description>
<pubDate>14 Jan  2008 13:31:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26709</link>
</item><item>
<title>RE: what is this?</title>
<description>Looks like the local name is actually more random: var name = &amp;quot;c:\\win&amp;quot;+GetRandString(4)+&amp;quot;.exe&amp;quot;; Kinda dumb though, as any non-admin class user won&amp;#039;</description>
<pubDate>14 Jan  2008 11:09:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26700</link>
</item><item>
<title>Re: Linksys WRT54 GL - Session riding (CSRF)</title>
<description>&amp;gt; A malicious link executing unnoticed by the administrator may open the firewall. The catch is that this exploit don&amp;#039;t work unnoticed, because the a</description>
<pubDate>14 Jan  2008 10:58:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26722</link>
</item><item>
<title>[SECURITY] [DSA 1463-1] New postgresql-7.4 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>14 Jan  2008 10:51:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26706</link>
</item><item>
<title>ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow Vulnerability</title>
<description>ZDI-08-001: IBM Tivoli Storage Manager Express Backup Server Heap Overflow  Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-08-001.htm</description>
<pubDate>14 Jan  2008 10:51:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26705</link>
</item><item>
<title>Re: Linksys WRT54 GL - Session riding (CSRF)</title>
<description>&amp;gt; | Isn&amp;#039;t your exploit somewhat complicated? Just put &amp;gt; | &amp;gt; | &amp;lt;img &amp;gt; src=&amp;quot;http://192.0.2.1/level/15/configure/-/enable/secret/mypassword&amp;quot;/&amp;gt; &amp;gt; | &amp;gt; |</description>
<pubDate>14 Jan  2008 09:31:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26699</link>
</item><item>
<title>Re: Garment Center (index.cgi) Local File Inclusion</title>
<description>Forgot... The Dork: &amp;quot;This site designed and managed by: garmentcenter.net&amp;quot; filetype:cgi</description>
<pubDate>14 Jan  2008 09:13:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26702</link>
</item><item>
<title>Binn SBuilder (nid) Remote Blind Sql Injection Vulnerabily</title>
<description>[+] Info: [~] Software: Binn SBuilder [~] HomePage: http://www.cms.ge/ [~] Exploit: Blind Sql Injection [High] [~] Where: full_text.php?nid= [~] Bug</description>
<pubDate>14 Jan  2008 08:59:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26701</link>
</item><item>
<title>Re: what is this?</title>
<description>Apologies I should clarify. In this attack legitimate pages on a site are first populated with html tags embedding Javascript like so &amp;lt;script langua</description>
<pubDate>14 Jan  2008 07:59:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26696</link>
</item><item>
<title>Re: what is this?</title>
<description>yep ther eis one yahoo messenger exploit too. On Jan 14, 2008 9:14 PM, Jose Nazario &amp;lt;jose@monkey.org&amp;gt; wrote: &amp;gt; On Sun, 13 Jan 2008, crazy frog crazy</description>
<pubDate>14 Jan  2008 07:56:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26695</link>
</item><item>
<title>Re: what is this?</title>
<description>On Sun, 13 Jan 2008, crazy frog crazy frog wrote: &amp;gt; http://secgeeks.com/what.zip &amp;gt; password is 12345 &amp;gt; can somebody guide/help me what is this and ho</description>
<pubDate>14 Jan  2008 07:44:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26692</link>
</item><item>
<title>Re: what is this?</title>
<description>Looks like your site was compromised along with several hundred others in the last day or so. A full account is up on http://blog.trendmicro.com/e-co</description>
<pubDate>14 Jan  2008 07:44:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26694</link>
</item><item>
<title>Re: what is this?</title>
<description>Well, was this embedded at your page source code? Or the link was just posted to it ? Its using some apple quicktime exploit to drop probably some bot</description>
<pubDate>14 Jan  2008 07:29:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26697</link>
</item><item>
<title>Re: [Full-disclosure] Buffer-overflow in Quicktime Player 7.3.1.70</title>
<description>Marcello Barnaba (void) &amp;lt;vjt@openssl.it&amp;gt; wrote: &amp;gt; By the way, even with &amp;quot;Transport setup&amp;quot; -&amp;gt; &amp;quot;Automatic&amp;quot;, the software &amp;gt; doesn&amp;#039;t crash nor loops after</description>
<pubDate>14 Jan  2008 06:56:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26686</link>
</item><item>
<title>F5 BIG-IP Web Management List Search XSS</title>
<description>F5 BIG-IP Web Management List Search XSS  Product: F5 BIG-IP http://www.f5.com/products/big-ip/  The F5 BIG-IP web management interface contains a c</description>
<pubDate>14 Jan  2008 06:36:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26678</link>
</item><item>
<title>SQID v0.3 - SQL Injection Digger.</title>
<description>SQL injection digger is a command line program that looks for SQL injections and common errors in websites. This version now can perform the following</description>
<pubDate>14 Jan  2008 06:17:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26685</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>hmm.thanks everyone for the suggestions. On Jan 14, 2008 5:22 PM, Nick FitzGerald &amp;lt;nick@virus-l.demon.co.uk&amp;gt; wrote: &amp;gt; 3APA3A wrote: &amp;gt; &amp;gt; &amp;gt; Dear crazy</description>
<pubDate>14 Jan  2008 05:56:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26684</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>3APA3A wrote: &amp;gt; Dear crazy frog crazy frog, &amp;gt; &amp;gt;  Clear your computer from trojan, change FTP password for you site &amp;gt;  hosting access, becau</description>
<pubDate>14 Jan  2008 03:52:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26683</link>
</item><item>
<title>Re: [Full-disclosure] what is this?</title>
<description>Dear crazy frog crazy frog,  Clear your computer from trojan, change FTP password for you site  hosting access, because it&amp;#039;s stolen, access</description>
<pubDate>14 Jan  2008 01:34:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26682</link>
</item><item>
<title>RE: Linksys WRT54 GL - Session riding (CSRF)</title>
<description>Ok, and what does it change...there are still the same vulnerabilities in their equipment. Should we stop checking and publishing them just because so</description>
<pubDate>13 Jan  2008 23:20:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26680</link>
</item><item>
<title>Re: what is this?</title>
<description>more,its not a java script,looks like a html page[.notice the &amp;lt;html&amp;gt; and &amp;lt;body&amp;gt; tag n the file] there is also a random function,which generate the ran</description>
<pubDate>13 Jan  2008 09:33:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26677</link>
</item><item>
<title>[SECURITY] [DSA 1462-1] New hplip packages fix privilege escalation</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 09:14:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26675</link>
</item><item>
<title>[SECURITY] [DSA 1461-1] New libxml2 packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 08:57:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26710</link>
</item><item>
<title>what is this?</title>
<description>Hi, Recently on opening one of my site,my antivirus pops up saying that it has found on malicious script.the url is random and i have managed to get</description>
<pubDate>13 Jan  2008 08:01:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26676</link>
</item><item>
<title>[SECURITY] [DSA 1460-1] New postgresql-8.1 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 07:45:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26681</link>
</item><item>
<title>[SECURITY] [DSA 1459-1] New gforge packages fix SQL injection</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>13 Jan  2008 07:07:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26693</link>
</item><item>
<title>Hacking The Interwebs</title>
<description>http://www.gnucitizen.org/blog/hacking-the-interwebs When the victim visits a malicious SWF file, a 4 step ATTACK will silently execute in the backgr</description>
<pubDate>13 Jan  2008 00:27:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26704</link>
</item><item>
<title>Re: Buffer-overflow in Quicktime Player 7.3.1.70</title>
<description>On Jan 11, 2008, at 10:14 PM, Luigi Auriemma wrote:  &amp;gt; Now talking about you, Marcello, the problem you had is just with  &amp;quot;your&amp;quot; &amp;gt; same computer/ne</description>
<pubDate>12 Jan  2008 14:41:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26703</link>
</item><item>
<title>[ MDVSA-2008:009-1 ] - Updated autofs packages fix insecure hosts configuration</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>12 Jan  2008 14:06:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26679</link>
</item><item>
<title>Garment Center (index.cgi) Local File Inclusion</title>
<description>[+] Discovered by Smasher [+] WarWolfz Crew. [+] http://warwolfz.altervista.org/ Hey wassup....i&amp;#039;ve found a vulnerability in Garmentcenter in index.</description>
<pubDate>12 Jan  2008 08:44:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26674</link>
</item><item>
<title>Safari 2 Denial of Service</title>
<description>##############################################################            - S21Sec Advisory - ############################################</description>
<pubDate>12 Jan  2008 07:30:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26671</link>
</item><item>
<title>Re: Buffer-overflow in Quicktime Player 7.3.1.70</title>
<description>&amp;gt; Uhmmm I imagine you are the same Marcello of yesterday, right? &amp;gt; ... Rationally my mail didn&amp;#039;t want to be a personal attack, unfortunately yesterda</description>
<pubDate>12 Jan  2008 05:33:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/bugtraq/bugtraq/26698</link>
</item>
</channel>
</rss>

