<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>25 Nov  2009 10:37:50 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Re: Some shit going on in seclist</title>
<description>&amp;gt; I guess this is an email list. This guy -/ Day Jay, has put up this &amp;gt; vulnerability up on seclist, stating that it relates to microsoft iis &amp;gt; 6.0, w</description>
<pubDate>25 Nov  2009 10:00:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70918</link>
</item><item>
<title>Onapsis Research: SAP Security In-Depth Vol. I</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear colleague, The first volume of the Onapsis&amp;#039; SAP Security In-Depth publication has been released.</description>
<pubDate>25 Nov  2009 08:53:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70917</link>
</item><item>
<title>[ GLSA 200911-05 ] Wireshark: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-05 - - -</description>
<pubDate>25 Nov  2009 07:39:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70916</link>
</item><item>
<title>[resent] [ GLSA 200911-04 ] dstat: Untrusted search path</title>
<description>Due to an oversight on my part, the original email has not been signed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gento</description>
<pubDate>25 Nov  2009 07:14:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70915</link>
</item><item>
<title>[ GLSA 200911-04 ] dstat: Untrusted search path</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-04 - - -</description>
<pubDate>25 Nov  2009 07:10:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70914</link>
</item><item>
<title>[ GLSA 200911-03 ] UW IMAP toolkit: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-03 - - -</description>
<pubDate>25 Nov  2009 05:24:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70913</link>
</item><item>
<title>9/11 pager messages released by Wikileaks</title>
<description>http://911.wikileaks.org/ &amp;quot;From 3AM on Wednesday November 25, 2009, until 3AM the following day (US east coast time), WikiLeaks is releasing over hal</description>
<pubDate>25 Nov  2009 03:54:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70912</link>
</item><item>
<title>Re: Some shit going on in seclist</title>
<description>2009/11/24 Tyler Durten &amp;lt;ty13rdurt3n@gmail.com&amp;gt;: &amp;gt; I guess this is an email list. This guy - Day Jay, has put up this &amp;gt; vulnerability up on seclist, s</description>
<pubDate>25 Nov  2009 03:48:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70911</link>
</item><item>
<title>Re: UK jails schizophrenic for refusal to decrypt files</title>
<description>To me, the Brits - sorry, their government - are more and more turning into fascists. What, if somebody has &amp;#039;really&amp;#039; forgotten his password or lost h</description>
<pubDate>25 Nov  2009 03:41:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70910</link>
</item><item>
<title>Re: more on that</title>
<description>So youre whining about a 4 year old post? lol and who uses an exploit without changing the shellcode anyway ________________________________ From: f</description>
<pubDate>25 Nov  2009 03:15:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70909</link>
</item><item>
<title>Re: Some shit going on in seclist</title>
<description>you have lost your homedir, or what? well, this is very stupid and pretty badly obfuscated, but I wonder how many scriptkiddies have been temporary su</description>
<pubDate>25 Nov  2009 03:11:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70908</link>
</item><item>
<title>Re: PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>&amp;gt; &amp;gt; Thanks for the good description and test results, Bogdan. Thank you very much Moritz.  &amp;gt;&amp;gt; Proof of concept &amp;gt;&amp;gt; ----------------- &amp;gt;&amp;gt; I&amp;#039;m not goin</description>
<pubDate>25 Nov  2009 01:35:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70900</link>
</item><item>
<title>rPSA-2009-0156-1 sun-jdk sun-jre</title>
<description>rPath Security Advisory: 2009-0156-1 Published: 2009-11-24 Products:   rPath Appliance Platform Linux Service 2   rPath Linux 1   rPath Linux 2</description>
<pubDate>24 Nov  2009 15:58:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70905</link>
</item><item>
<title>rPSA-2009-0155-1 httpd mod_ssl</title>
<description>rPath Security Advisory: 2009-0155-1 Published: 2009-11-24 Products:   rPath Appliance Platform Linux Service 2   rPath Linux 2 Rating: Major Exp</description>
<pubDate>24 Nov  2009 15:57:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70904</link>
</item><item>
<title>rPSA-2009-0154-1 httpd mod_ssl</title>
<description>rPath Security Advisory: 2009-0154-1 Published: 2009-11-24 Products:   rPath Appliance Platform Linux Service 1   rPath Linux 1 Rating: Major Exp</description>
<pubDate>24 Nov  2009 15:56:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70903</link>
</item><item>
<title>UK jails schizophrenic for refusal to decrypt files</title>
<description>The first person jailed under draconian UK police powers that Ministers said were vital to battle terrorism and serious crime has been identified by T</description>
<pubDate>24 Nov  2009 14:48:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70899</link>
</item><item>
<title>[SECURITY] [DSA 1939-1] New libvorbis packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>24 Nov  2009 14:41:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70902</link>
</item><item>
<title>Vulnerabilities in WP-Cumulus for WordPress</title>
<description>Hello Full-Disclosure! I want to warn you about security vulnerabilities in plugin WP-Cumulus for WordPress. These are Full path disclosure and Cros</description>
<pubDate>24 Nov  2009 13:56:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70901</link>
</item><item>
<title>more on that</title>
<description>And this is what I&amp;#039;m talking about: http://seclists.org/fulldisclosure/2005/Apr/412</description>
<pubDate>24 Nov  2009 13:41:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70907</link>
</item><item>
<title>Re: PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>Bogdan Calin wrote: &amp;gt; Description &amp;gt; ------------ &amp;gt; PHP version 5.3.1 was just released. This release contains a patch for a &amp;gt; denial of service condit</description>
<pubDate>24 Nov  2009 13:40:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70898</link>
</item><item>
<title>Some shit going on in seclist</title>
<description>I guess this is an email list. This guy -* Day Jay, has put up this vulnerability up on seclist, stating that it relates to microsoft iis 6.0, when it</description>
<pubDate>24 Nov  2009 13:40:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70906</link>
</item><item>
<title>Hackers to CSOs (H2CSO) - Free Online Subscription</title>
<description>Hackers to CSO (H2CSO) is a debate between CSOs and important hackers organized by the joint between Check Point and the TV Decision (a brazilian tele</description>
<pubDate>24 Nov  2009 12:53:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70897</link>
</item><item>
<title>Remote DoS condition in harbour.pl</title>
<description>Versions of harbour.pl (up to and including build 1941) are vulnerable to a remote Denial of Service attack. Spamming &amp;quot;zeroes&amp;quot; (null packets) to port</description>
<pubDate>24 Nov  2009 06:58:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70896</link>
</item><item>
<title>Re: New Paper: MitM Attacks against the chipTAN	comfort Online Banking System</title>
<description>Sorry list if this arrives twice, I got stuck in the moderation queue because I used the wrong email address. Hi Thierry, Thierry Zoller &amp;lt;Thierry@Zo</description>
<pubDate>24 Nov  2009 06:47:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70893</link>
</item><item>
<title>[USN-861-1] libvorbis vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-861-1     November 24, 2009 libvorbis vulnerabilities CVE-</description>
<pubDate>24 Nov  2009 06:31:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70892</link>
</item><item>
<title>Re: New Paper: MitM Attacks against the chipTAN	comfort Online Banking System</title>
<description>Hi Thierry, Thierry Zoller &amp;lt;Thierry@Zoller.lu&amp;gt; wrote: &amp;gt; MITM is used rather vaguely in this paper. Are the proposed &amp;gt; techniques working i</description>
<pubDate>24 Nov  2009 06:18:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70895</link>
</item><item>
<title>Re: New Paper: MitM Attacks against the chipTAN comfort Online Banking System</title>
<description>Thierry Zoller wrote: &amp;lt;&amp;lt;snip&amp;gt;&amp;gt; &amp;gt; For sake of allowing proper risk assessment by technically less &amp;gt; trained persons - one should coin a better te</description>
<pubDate>24 Nov  2009 05:03:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70891</link>
</item><item>
<title>Re: New Paper: MitM Attacks against the chipTAN comfort Online Banking System</title>
<description>Hi, Thank you for the information. MITM is used rather vaguely in this paper. Are the proposed techniques working in an MITM situation - w</description>
<pubDate>24 Nov  2009 04:57:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70890</link>
</item><item>
<title>New Paper: MitM Attacks against the chipTAN comfort Online Banking	System</title>
<description>Abstract ======== ChipTAN comfort is a new system which is supposed to securely authorise online banking transactions by means of a trusted device. It</description>
<pubDate>24 Nov  2009 03:50:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70889</link>
</item><item>
<title>Executing arbitrary PHP code on OpenX &amp;lt;= 2.8.1</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi, OpenX adserver version 2.8.1 and lower is vulnerable to remote code execution. To be exploited,</description>
<pubDate>24 Nov  2009 03:02:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70888</link>
</item><item>
<title>Quick.Cart and Quick.CMS CSRF Vulnerabilities</title>
<description>Systems Affected: Quick.Cart 3.4 (other versions untested), Quick.CMS 2.4 (other versions untested) Severity: Medium Vendor: http://opensolution.org/</description>
<pubDate>23 Nov  2009 15:23:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70894</link>
</item><item>
<title>CORE-2009-0910: Autodesk Maya Script Nodes Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:43:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70887</link>
</item><item>
<title>CORE-2009-0909: Autodesk 3DS Max Application Callbacks Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:42:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70886</link>
</item><item>
<title>CORE-2009-0908: Autodesk SoftImage Scene TOC Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>23 Nov  2009 11:41:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70885</link>
</item><item>
<title>Re: Millions of PDF invisibly embedded with your internal disk paths</title>
<description>Hi Juha-Matti, Thanks for contributing to this thread. I did play a lot with the pdf queries and the simple query you mentioned gives many false posi</description>
<pubDate>23 Nov  2009 01:37:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70883</link>
</item><item>
<title>[SECURITY] [DSA 1938-1] New php-mail packages fix insufficient input sanitising</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>22 Nov  2009 23:40:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70884</link>
</item><item>
<title>Fwd: ICMPv4/IP fuzzer prototype.</title>
<description>Hell no random.randrang -&amp;gt; randrange(_) rtfm. and yeah u&amp;#039;r welcome.  2009/11/23 Andrew Farmer &amp;lt;andfarm@gmail.com&amp;gt; On 22 Nov 2009, at 19:48, lauren</description>
<pubDate>22 Nov  2009 22:09:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70882</link>
</item><item>
<title>Re: ICMPv4/IP fuzzer prototype.</title>
<description>On 22 Nov 2009, at 19:48, laurent gaffie wrote: &amp;gt; Should be kweel for UTesting &amp;gt; http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-proto</description>
<pubDate>22 Nov  2009 22:02:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70881</link>
</item><item>
<title>[Bkis-13-2009] e107 Multiple Vulnerabilities</title>
<description>[Bkis-13-2009] e107 Multiple Vulnerabilities 1. General Information e107 is a free content management system (CMS) written in PHP language and is av</description>
<pubDate>22 Nov  2009 21:19:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70880</link>
</item><item>
<title>ICMPv4/IP fuzzer prototype.</title>
<description>Should be kweel for UTesting http://g-laurent.blogspot.com/2009/11/releasing-icmpv4ip-fuzzer-prototype.html Enjoy.</description>
<pubDate>22 Nov  2009 19:48:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70879</link>
</item><item>
<title>Climategate: how the MSM reported the greatest scandal in modern science - Telegraph Blogs</title>
<description>hackers providing a public service...... http://blogs.telegraph.co.uk/news/jamesdelingpole/100017451/climategate-how-the-msm-reported-the-greatest-sc</description>
<pubDate>22 Nov  2009 14:44:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70878</link>
</item><item>
<title>Re: Millions of PDF invisibly embedded with your internal disk paths</title>
<description>The local path is being disclosed with a simple query too without putting .HTM/.MHT to the string: http://www.google.com/search?hl=en&amp;amp;q=filetype%3Apdf</description>
<pubDate>22 Nov  2009 14:26:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70877</link>
</item><item>
<title>Millions of PDF invisibly embedded with your internal disk paths</title>
<description>Millions of PDF invisibly embedded with your internal disk paths ---------------------------------------------------------------- I found an interest</description>
<pubDate>22 Nov  2009 12:14:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70876</link>
</item><item>
<title>HITB Security Conference 2010 Dubai Call for Papers</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 The Call for Papers for HITB Security Conference 2010 Dubai is now open! Talks that are more technical</description>
<pubDate>22 Nov  2009 06:13:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70875</link>
</item><item>
<title>Vulnerabilities in plugins for WordPress</title>
<description>Hello Full-Disclosure! I want to tell you about different vulnerabilities in plugins for WordPress. About some of them there were posts to Bugtraq li</description>
<pubDate>21 Nov  2009 13:25:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70874</link>
</item><item>
<title>[ MDVSA-2009:302 ] php</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>21 Nov  2009 08:08:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70872</link>
</item><item>
<title>[SECURITY] [DSA 1937-1] New gforge packages fix cross-site scripting</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>20 Nov  2009 21:30:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70873</link>
</item><item>
<title>Re: Pussy and the right to free speech.</title>
<description>http://www.kurtgreenbaum.com/ http://www.kurtgreenbaumisapussy.com/ Damn. This dudes getting some serious blowback. Why didn&amp;#039;t someone take DidKurtG</description>
<pubDate>20 Nov  2009 20:57:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70871</link>
</item><item>
<title>[ MDVSA-2009:301 ] kernel</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>20 Nov  2009 16:29:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70870</link>
</item><item>
<title>ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability</title>
<description>ZDI-09-085: Hewlett-Packard Operations Manager Server Backdoor Account Code Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09</description>
<pubDate>20 Nov  2009 15:15:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70869</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>&amp;gt; (Remember - in this case, contacting the school&amp;#039;s network provider would &amp;gt; *not* have found the user, because the network provider just provides &amp;gt; a</description>
<pubDate>20 Nov  2009 13:38:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70868</link>
</item><item>
<title>VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -----------------------------------------------------------------------          VMware Sec</description>
<pubDate>20 Nov  2009 12:56:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70867</link>
</item><item>
<title>Pussy and the right to free speech.</title>
<description>This whole thing is ridiculous. Kurt Greenbaum is an idiot. What kind of question is that in the first place? Only and idiot would post â€œwhatâ€</description>
<pubDate>20 Nov  2009 11:10:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70866</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>On Fri, 20 Nov 2009 01:42:08 +0100, netinfinity said: &amp;gt; necessary to submit the post. If this fails then you should conntact &amp;gt; the ISP of the &amp;quot;spamme</description>
<pubDate>20 Nov  2009 06:11:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70865</link>
</item><item>
<title>PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>Description ------------ PHP version 5.3.1 was just released. This release contains a patch for a denial of service condition we&amp;#039;ve reported on 27 Oct</description>
<pubDate>20 Nov  2009 04:03:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70864</link>
</item><item>
<title>n3td3v / Andrew Wallace&amp;#039;s psychological profile</title>
<description>Earlier this year, a very well educated FD member posted the psychological profile of Mr. Wallace. (Found here: http://seclists.org/fulldisclosure/200</description>
<pubDate>19 Nov  2009 19:40:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70863</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>Feel free to share your feelings with Greenbaum&amp;#039;s boss: Kevin Mowbray Phone: 314-340-8970 E-mail: kmowbray@post-dispatch.com --- mrx &amp;lt;mrx@propergand</description>
<pubDate>19 Nov  2009 18:25:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70862</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>Mr. Kurt Greenbaum made a mistake. Privacy violated, because there are other mechanism&amp;#039;s like baninig the IP, email or whatever is necessary to submi</description>
<pubDate>19 Nov  2009 16:42:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70861</link>
</item><item>
<title>SecurityReason: KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz</description>
<pubDate>19 Nov  2009 16:26:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70860</link>
</item><item>
<title>SecurityReason: Opera 10.01 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ Opera 10.01 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz and sp</description>
<pubDate>19 Nov  2009 16:25:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70859</link>
</item><item>
<title>SecurityReason: K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz and</description>
<pubDate>19 Nov  2009 16:23:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70858</link>
</item><item>
<title>SecurityReason: SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 [ SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution) ] Author: Maksymilian Arciemowicz an</description>
<pubDate>19 Nov  2009 16:17:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70857</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 No problem regarding the personal post, I have made the same mistake myself. I also see what you mean</description>
<pubDate>19 Nov  2009 16:16:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70856</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>They&amp;#039;re ORs, unfortunately. The language is unclear but it seems to be one of those infernal boilerplate pieces of shit that basically invalidate the</description>
<pubDate>19 Nov  2009 15:56:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70855</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Michael Holstein wrote: &amp;gt;&amp;gt; What Greenbaum did was against the privacy policy of the site: &amp;gt;&amp;gt; &amp;gt; &amp;gt; You s</description>
<pubDate>19 Nov  2009 14:23:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70854</link>
</item><item>
<title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>&amp;gt; &amp;gt; What Greenbaum did was against the privacy policy of the site: &amp;gt; You seem to be missing the part where the comment was removed (several times) a</description>
<pubDate>19 Nov  2009 14:02:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70853</link>
</item><item>
<title>Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
<description>I smell a lawsuit coming on for our friend Greenbaum. &amp;quot;ReadWriteWeb has an article up today discussing an incident in which a school employee lost hi</description>
<pubDate>19 Nov  2009 12:38:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70852</link>
</item><item>
<title>Re: Impersonation is a against the law.</title>
<description>stopped reading full-disclosure about a year ago, most of the discussions was about netdev. now resumed my subscription: still a lot of talks about n</description>
<pubDate>19 Nov  2009 08:02:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70851</link>
</item><item>
<title>Re: Impersonation is a against the law.</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 &amp;lt;snip&amp;gt; With all due respect, can we please not encourage: kaibelf, Mr Appelbaum, GOBBLES, Jack Bauer,</description>
<pubDate>19 Nov  2009 06:31:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70849</link>
</item><item>
<title>Re: Impersonation is a against the law.</title>
<description>On Thu, 19 Nov 2009 00:20:54 GMT, kaibelf said: &amp;gt; n3td3v began to think he was being followed in real life such was &amp;gt; the psychological impact of a g</description>
<pubDate>19 Nov  2009 06:06:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70848</link>
</item><item>
<title>Re: Impersonation is a against the law.</title>
<description>STOP THAT BULLSHIT! It&amp;#039;s not funny anymore. kaibelf escreveu: &amp;gt; List, &amp;gt; &amp;gt; It has come to my attention that my client is being impersonated. &amp;gt; &amp;gt; Secu</description>
<pubDate>19 Nov  2009 04:57:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70850</link>
</item><item>
<title>Re: Impersonation is a against the law.</title>
<description>2009/11/19 kaibelf &amp;lt;jdl@mac.hush.com&amp;gt; &amp;gt; List, &amp;gt; &amp;gt; It has come to my attention that my client is being impersonated. &amp;gt; &amp;gt; Your false statements doesn&amp;#039;t</description>
<pubDate>19 Nov  2009 04:43:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70846</link>
</item><item>
<title>Auto Manager admin.cgi Multiple Field XSS</title>
<description>vendor: interactivetools.com, inc., http://www.interactivetools.com/products/automanager/ product: Auto Manager version: 2.52 script: admin.cgi fields</description>
<pubDate>19 Nov  2009 00:03:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70845</link>
</item><item>
<title>AssetsSoSimple supplier_admin.php Supplier Field XSS</title>
<description>product: AssetsSoSimple version tested: 0.33 vendor URL: http://assetssosimple.sourceforge.net/ script: supplier_admin.php field: Supplier ooo BugsN</description>
<pubDate>19 Nov  2009 00:01:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70844</link>
</item><item>
<title>Foxit Reader vulnerability has been fixed</title>
<description>Hello There, This is Grace Wu from Foxit Corporation. We had noticed the Foxit Reader vulnerability posted at http://seclists.org/fulldisclosure/2009</description>
<pubDate>18 Nov  2009 23:36:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70847</link>
</item><item>
<title>[USN-860-1] Apache vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-860-1     November 19, 2009 apache2 vulnerabilities CVE-20</description>
<pubDate>18 Nov  2009 22:40:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70843</link>
</item><item>
<title>Impersonation is a against the law.</title>
<description>List, It has come to my attention that my client is being impersonated. Securityfocus slandered n3td3v in 2006 causing him to drop out of universit</description>
<pubDate>18 Nov  2009 16:20:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70842</link>
</item><item>
<title>CORE-2009-1027: IBM SolidDB invalid error code vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1    Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>18 Nov  2009 10:23:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70841</link>
</item><item>
<title>Secunia Research: RhinoSoft Serv-U TEA Decoding Buffer Overflow</title>
<description>======================================================================            Secunia Research 18/11/2009      - RhinoSoft Serv-U</description>
<pubDate>18 Nov  2009 07:49:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70840</link>
</item><item>
<title>TLS / SSLv3 vulnerability explained (DRAFT)</title>
<description>Dear List, This paper explains the vulnerability for a broader audience and summarizes the information that is currently available. The document is p</description>
<pubDate>18 Nov  2009 06:42:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70839</link>
</item><item>
<title>DEFCON London - DC4420 - NO MEETING this Thursday! 19th November 2009</title>
<description>what it says on the tin... i regret to inform you that there will be no meeting this month due to repeated let-downs with the current venue... inst</description>
<pubDate>18 Nov  2009 06:24:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70838</link>
</item><item>
<title>SUSE Security Announcement: openssl (SUSE-SA:2009:057)</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ______________________________________________________________________________</description>
<pubDate>18 Nov  2009 00:56:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70837</link>
</item><item>
<title>[ GLSA 200911-02 ] Sun JDK/JRE: Multiple vulnerabilites</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-02 - - -</description>
<pubDate>17 Nov  2009 14:59:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70836</link>
</item><item>
<title>CORE-2009-0814: HP Openview NNM 7.53 Invalid DB Error Code vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1    Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>17 Nov  2009 14:13:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70835</link>
</item><item>
<title>[SECURITY] [DSA 1936-1] New libgd2 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>17 Nov  2009 12:52:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70833</link>
</item><item>
<title>Re: The cyber security intelligence community will never be the same</title>
<description>On Tue, Nov 17, 2009 at 11:48 AM, Sam Haldorf &amp;lt;sahalderf@ymail.com&amp;gt; wrote: &amp;gt; my name is andrew wallace &amp;gt; &amp;quot;You&amp;#039;re a loony.&amp;quot; - King Arthur</description>
<pubDate>17 Nov  2009 12:15:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70830</link>
</item><item>
<title>FDSpam. EFFector 22.33: International Activists Launch New Website to Gather and Share Copyright Knowledge</title>
<description>I realised that though security isn&amp;#039;t mentioned at all -there&amp;#039;s plenty here that gets shouted about on Full Disc on off-topic threads. (Paul, Valdis,</description>
<pubDate>17 Nov  2009 11:51:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70832</link>
</item><item>
<title>The cyber security intelligence community will never be the same</title>
<description>n3td3v prepares to leave the internet after having completed work on n3td3v-0pen0wn.sh  n3td3v has had it with the games done by you jackasses in th</description>
<pubDate>17 Nov  2009 11:48:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70829</link>
</item><item>
<title>Secunia Research: Gimp PSD Image Parsing Integer Overflow Vulnerability</title>
<description>======================================================================            Secunia Research 17/11/2009    - Gimp PSD Image Parsi</description>
<pubDate>17 Nov  2009 06:05:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70828</link>
</item><item>
<title>Metasploit Framework 3.3 Released</title>
<description>We are excited to announce the immediate availability of version 3.3 of the Metasploit Framework. This release includes 446 exploits, 216 auxiliary mo</description>
<pubDate>17 Nov  2009 05:57:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70827</link>
</item><item>
<title>[SECURITY] [DSA 1935-1] New gnutls23/gnutls26 packages fix SSL certificate	verification weakness</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - -------------------------------------------------------------------------- Debian Security Advisory D</description>
<pubDate>17 Nov  2009 05:46:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70831</link>
</item><item>
<title>iAWACS 2010 CFP</title>
<description>Second International Alternative Workshop on          Aggressive Computing and Security          iAWACS 2010: the Revelation Editi</description>
<pubDate>17 Nov  2009 01:40:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70824</link>
</item><item>
<title>Re: Microsoft confirms first Windows 7 zero-day bug</title>
<description>On Mon, Nov 16, 2009 at 10:00 PM, Ivan . &amp;lt;ivanhec@gmail.com&amp;gt; wrote: &amp;gt; http://computerworld.co.nz/news.nsf/scrt/E9592E1A9719742ACC25766F0066B38D It re</description>
<pubDate>16 Nov  2009 22:38:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70823</link>
</item><item>
<title>Microsoft confirms first Windows 7 zero-day bug</title>
<description>http://computerworld.co.nz/news.nsf/scrt/E9592E1A9719742ACC25766F0066B38D</description>
<pubDate>16 Nov  2009 22:00:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70822</link>
</item><item>
<title>Re: George Bush&amp;#039;s immature self-styled approach at counterterrorism is an intelligence nightmare</title>
<description>full-disclosure-request@lists.grok.org.uk wrote: &amp;gt; Send Full-Disclosure mailing list submissions to &amp;gt;  3. George Bush&amp;#039;s immature, self-styled appro</description>
<pubDate>16 Nov  2009 16:19:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70821</link>
</item><item>
<title>[ MDVSA-2009:158-2 ] pango</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>16 Nov  2009 14:34:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70820</link>
</item><item>
<title>[SECURITY] [DSA-1934-1] New apache2 packages fix several issues</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>16 Nov  2009 11:30:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70826</link>
</item><item>
<title>[ MDVSA-2009:158-1 ] pango</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>16 Nov  2009 06:33:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70819</link>
</item><item>
<title>Troopers 2010 security conference, CfP</title>
<description>Once more, it will be Troopers time.  This year, again, _everybody_ involved in the event (speakers and attendees) enjoyed themselves and could sign</description>
<pubDate>16 Nov  2009 03:43:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70818</link>
</item><item>
<title>Re: Full-Disclosure Digest, Vol 57, Issue 17</title>
<description>I am not a number, I am a free man! Sent via BlackBerry by AT&amp;amp;T -----Original Message----- From: full-disclosure-request@lists.grok.org.uk Date: Fri,</description>
<pubDate>15 Nov  2009 17:03:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70817</link>
</item>
</channel>
</rss>
