<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>08 Nov  2009 16:47:50 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>[ MDVSA-2009:295 ] apache</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>08 Nov  2009 13:20:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70747</link>
</item><item>
<title>[SECURITY] [DSA 1932-1] New pidgin packages fix arbitrary code execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 11:47:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70746</link>
</item><item>
<title>[SECURITY] [DSA 1931-1] New NSPR packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>08 Nov  2009 02:07:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70744</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 7, 2009 4:06:42 PM -0600 mikelitoris@hushmail.com wrote: &amp;gt; &amp;gt;&amp;gt; But to gather intelligence about what terrorists are up to, even &amp;gt; if a U</description>
<pubDate>07 Nov  2009 17:52:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70745</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>&amp;gt; But to gather intelligence about what terrorists are up to, even if a US citizen is involved, should not require a warrant. This is all well and g</description>
<pubDate>07 Nov  2009 14:06:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70742</link>
</item><item>
<title>Re: How to receive SPAM mail</title>
<description>If you want to be spammed, join full-disclosure. 2009/11/7 Michael Holstein &amp;lt;michael.holstein@csuohio.edu&amp;gt; &amp;gt; &amp;gt; &amp;gt; I have a SPAM filter and virus fire</description>
<pubDate>07 Nov  2009 14:05:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70743</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 7, 2009 11:24:55 AM -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt; On Fri, 06 Nov 2009 23:42:45 CST, Paul Schmehl said: &amp;gt;&amp;gt; communications as we</description>
<pubDate>07 Nov  2009 11:51:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70739</link>
</item><item>
<title>Linux 2.6.x fs/pipe.c local root exploit (CVE-2009-3547)</title>
<description>For those who were not yet aware, there is at least 3 public exploits since 11/05/2009 for CVE-2009-3547 targeting *all* linux kernels from 2.6.0 to 2</description>
<pubDate>07 Nov  2009 11:37:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70740</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 7, 2009 11:20:31 AM -0600 Rohit Patnaik &amp;lt;quanticle@gmail.com&amp;gt; wrote: &amp;gt; The direction of the association doesn&amp;#039;t matter. It doesn&amp;#039;t mat</description>
<pubDate>07 Nov  2009 11:31:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70738</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Fri, 06 Nov 2009 23:42:45 CST, Paul Schmehl said: &amp;gt; communications as well. Under existing law (if you believe that FISA &amp;gt; applies) they would ha</description>
<pubDate>07 Nov  2009 09:24:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70737</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>The direction of the association doesn&amp;#039;t matter. It doesn&amp;#039;t matter if the &amp;quot;terrorist&amp;quot; is contacting me, or if I&amp;#039;m contacting the terrorist. In either</description>
<pubDate>07 Nov  2009 09:20:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70736</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 6, 2009 10:10:56 PM -0600 Rohit Patnaik &amp;lt;quanticle@gmail.com&amp;gt; wrote: &amp;gt; If it is so clear that a US citizen is involved in terrorism an</description>
<pubDate>06 Nov  2009 21:42:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70735</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>If it is so clear that a US citizen is involved in terrorism and is communicating with terrorists beyond our borders, then why is it so hard for the N</description>
<pubDate>06 Nov  2009 20:10:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70734</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 6, 2009 6:07:17 PM -0600 Rohit Patnaik &amp;lt;quanticle@gmail.com&amp;gt; wrote: &amp;gt; &amp;gt; You say that claims about the NSA conducting warrantless wireta</description>
<pubDate>06 Nov  2009 18:56:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70733</link>
</item><item>
<title>[SECURITY] [DSA 1930-1] New drupal6 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>06 Nov  2009 16:46:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70741</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Fri, Nov 6, 2009 at 1:25 PM, Paul Schmehl &amp;lt;pschmehl_lists@tx.rr.com&amp;gt;wrote: &amp;gt; --On Friday, November 06, 2009 10:46:39 -0600 Valdis.Kletnieks@vt.edu</description>
<pubDate>06 Nov  2009 16:07:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70731</link>
</item><item>
<title>Re: How to receive SPAM mail</title>
<description>&amp;gt; I have a SPAM filter and virus firewall testing. &amp;gt; So, I want to get the real SPAM is sent to a specific email address. &amp;gt; What better way is there a</description>
<pubDate>06 Nov  2009 13:46:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70730</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On Friday, November 06, 2009 10:46:39 -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt; On Thu, 05 Nov 2009 21:47:41 CST, Paul Schmehl said: &amp;gt;&amp;gt; &amp;gt; Getting back</description>
<pubDate>06 Nov  2009 11:25:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70729</link>
</item><item>
<title>How to receive SPAM mail</title>
<description>Hi Full-disclosure I have a SPAM filter and virus firewall testing. So, I want to get the real SPAM is sent to a specific email address. What better</description>
<pubDate>06 Nov  2009 11:11:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70728</link>
</item><item>
<title>Re: MySQL trick for SQL injection</title>
<description>--On Friday, November 06, 2009 10:55:26 -0600 Tim &amp;lt;tim-security@sentinelchicken.org&amp;gt; wrote: &amp;gt; &amp;gt;&amp;gt; &amp;gt; INTO OUTFILE is a dangerous routine (as you&amp;#039;ve cl</description>
<pubDate>06 Nov  2009 11:03:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70727</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yo Paul! On Thu, 05 Nov 2009 21:47:41 CST, Paul Schmehl said: &amp;gt; &amp;gt; Getting back on topic, it is well-kn</description>
<pubDate>06 Nov  2009 09:01:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70726</link>
</item><item>
<title>Re: MySQL trick for SQL injection</title>
<description>&amp;gt; &amp;gt; INTO OUTFILE is a dangerous routine (as you&amp;#039;ve clearly demonstrated), but that &amp;gt; &amp;gt; privilege must be specifically granted to a user before it&amp;#039;s p</description>
<pubDate>06 Nov  2009 08:55:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70725</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Thu, 05 Nov 2009 21:47:41 CST, Paul Schmehl said: &amp;gt; &amp;gt; Getting back on topic, it is well-known, and proven, that the NSA has &amp;gt; &amp;gt; surveillence facili</description>
<pubDate>06 Nov  2009 08:46:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70724</link>
</item><item>
<title>Re: Argentinean Arnet isp webmail</title>
<description>Confirmed, thanks and POP3 too: c:\&amp;gt;telnet pop3.arnet.com.ar 110 +OK user P0*****4241@arnet.com.ar +OK please, send your password pass P0*****4241</description>
<pubDate>06 Nov  2009 08:38:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70723</link>
</item><item>
<title>Re: MySQL trick for SQL injection</title>
<description>On Fri, 06 Nov 2009 10:04:54 CST, Paul Schmehl said: &amp;gt; What privileges did the user who performed the select have? &amp;gt; &amp;gt; INTO OUTFILE is a dangerous ro</description>
<pubDate>06 Nov  2009 08:37:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70722</link>
</item><item>
<title>Re: MySQL trick for SQL injection</title>
<description>--On Friday, November 06, 2009 06:55:22 -0600 Vladimir Vorontsov &amp;lt;vladimir.vorontsov@onsec.ru&amp;gt; wrote: &amp;gt; &amp;gt; Good day! &amp;gt; &amp;gt; I recently encountered a pro</description>
<pubDate>06 Nov  2009 08:04:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70721</link>
</item><item>
<title>[ GLSA 200911-01 ] Horde: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-01 - - -</description>
<pubDate>06 Nov  2009 05:36:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70720</link>
</item><item>
<title>MySQL trick for SQL injection</title>
<description>Good day! I recently encountered a problem with the implementation of SQL injection.  I wanted to write a file with the code interpreter to execute</description>
<pubDate>06 Nov  2009 04:55:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70719</link>
</item><item>
<title>Re: Hash</title>
<description>Taunting other people&amp;#039;s english skills work better when your own english isn&amp;#039;t broken :) -----Original Message----- From: full-disclosure-bounces@lis</description>
<pubDate>06 Nov  2009 03:06:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70717</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 5, 2009 10:03:31 PM -0600 Chris &amp;lt;r0ck@operamail.com&amp;gt; wrote: &amp;gt;&amp;gt; &amp;gt;&amp;gt; Sure, because we all know those rat bastards at the NSA and all those</description>
<pubDate>05 Nov  2009 20:56:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70732</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>Don&amp;#039;t bother. Paul couldn&amp;#039;t see the obvious if someone whacked him in the head with it. An artifact from the 1950s era where government can do no wr</description>
<pubDate>05 Nov  2009 20:07:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70705</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>&amp;gt; ----- Original Message ----- &amp;gt; From: &amp;quot;Paul Schmehl&amp;quot; &amp;lt;pschmehl_lists@tx.rr.com&amp;gt; &amp;gt; To: &amp;quot;full-disclosure&amp;quot; &amp;lt;full-disclosure@lists.grok.org.uk&amp;gt; &amp;gt; Subject</description>
<pubDate>05 Nov  2009 20:03:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70704</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>some background http://www.wired.com/dangerroom/2009/03/breaking-cyber/ http://news.cnet.com/8301-13578_3-10046097-38.html http://www.wired.com/threa</description>
<pubDate>05 Nov  2009 19:53:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70703</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 5, 2009 9:12:29 PM -0600 Chris &amp;lt;r0ck@operamail.com&amp;gt; wrote: &amp;gt; &amp;gt; &amp;gt; and someone could sue you for burying your head up your ass. &amp;gt; Fortunat</description>
<pubDate>05 Nov  2009 19:47:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70702</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>Why is it that Valdis has something to say about everything? I see you on NANOG, full-disclosure, outages, and more. &amp;gt; ----- Original Message -----</description>
<pubDate>05 Nov  2009 19:13:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70701</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>&amp;gt; ----- Original Message ----- &amp;gt; From: &amp;quot;Paul Schmehl&amp;quot; &amp;lt;pschmehl_lists@tx.rr.com&amp;gt; &amp;gt; To: &amp;quot;full-disclosure&amp;quot; &amp;lt;full-disclosure@lists.grok.org.uk&amp;gt; &amp;gt; Subject</description>
<pubDate>05 Nov  2009 19:12:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70700</link>
</item><item>
<title>[ MDVSA-2009:294 ] firefox</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>05 Nov  2009 16:52:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70698</link>
</item><item>
<title>[SECURITY] [DSA 1929-1] New Linux 2.6.18 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 16:51:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70716</link>
</item><item>
<title>Using Blended Browser Threats involving Chrome to steal files on your computer</title>
<description>For complete post with images, please visit http://securethoughts.com/2009/11/using-blended-browser-threats-involving-ch rome-to-steal-files-on-your-c</description>
<pubDate>05 Nov  2009 16:47:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70699</link>
</item><item>
<title>[SECURITY] [DSA 1928-1] New Linux 2.6.24 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 14:03:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70715</link>
</item><item>
<title>SSL/TLS MiTM PoC</title>
<description>It might not work with up-to-date OpenSSL. Fixing that is left as an exercise for the reader. -- Pavel Kankovsky aka Peak             /</description>
<pubDate>05 Nov  2009 13:54:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70697</link>
</item><item>
<title>Re: Dark side of bookmarks</title>
<description>Hello Aras! As correctly note S/U/N (http://lists.grok.org.uk/pipermail/full-disclosure/2009-November/071323.html) I wrote enough PoCs (for different</description>
<pubDate>05 Nov  2009 13:54:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70706</link>
</item><item>
<title>[USN-855-1] libhtml-parser-perl vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-855-1     November 05, 2009 libhtml-parser-perl vulnerabil</description>
<pubDate>05 Nov  2009 12:28:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70696</link>
</item><item>
<title>[USN-854-1] GD library vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-854-1     November 05, 2009 libgd2 vulnerabilities CVE-200</description>
<pubDate>05 Nov  2009 11:30:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70695</link>
</item><item>
<title>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability</title>
<description>ZDI-09-081: Hewlett-Packard Power Manager Administration Web Server Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-08</description>
<pubDate>05 Nov  2009 10:08:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70712</link>
</item><item>
<title>CORE-2009-0912: Blender .blend Project Arbitrary Command Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1     Core Security Technologies - CoreLabs Advisory      http://www.coresecurity.com/corelabs/</description>
<pubDate>05 Nov  2009 09:12:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70694</link>
</item><item>
<title>[SECURITY] [DSA 1927-1] New Linux 2.6.26 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ---------------------------------------------------------------------- Debian Security Advisory DSA-1</description>
<pubDate>05 Nov  2009 08:21:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70714</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>&amp;gt; &amp;gt; Its evil. Making people believe that someone is dead, publicly, and placing &amp;gt; obituaries online shows no regard for the thoughts &amp;amp; feelings of the</description>
<pubDate>05 Nov  2009 07:10:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70693</link>
</item><item>
<title>[Bkis-12-2009] eoCMS SQL injection vulnerability - Bkis Report</title>
<description>eoCMS SQL injection vulnerability 1. General information eoCMS is an open source code software which is used to develop Internet forum (http://eocm</description>
<pubDate>04 Nov  2009 21:22:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70692</link>
</item><item>
<title>Exp1oit for Serv-U 9.0.0.5 new bug</title>
<description>hi,  I have written a piece of code to demonstrate the new serv-u bug.  Attached please find the source code for Win2k3 SP2 + DEP. Perhaps you shoul</description>
<pubDate>04 Nov  2009 19:41:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70691</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 4, 2009 8:03:10 PM -0600 &amp;quot;Gary E. Miller&amp;quot; &amp;lt;gem@rellim.com&amp;gt; wrote: &amp;gt; &amp;gt; -----BEGIN PGP SIGNED MESSAGE----- &amp;gt; Hash: SHA1 &amp;gt; &amp;gt; Yo Paul! &amp;gt; &amp;gt;</description>
<pubDate>04 Nov  2009 19:19:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70690</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 4, 2009 8:48:41 PM -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt; On Wed, 04 Nov 2009 17:42:37 CST, Paul Schmehl said: &amp;gt;&amp;gt; You and millions of o</description>
<pubDate>04 Nov  2009 19:17:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70689</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>&amp;quot;There are people at the end of the computers. Don&amp;#039;t ever forget it.&amp;quot; Did you and them get your degree from the same university of trolls? &amp;gt; &amp;gt; I have</description>
<pubDate>04 Nov  2009 19:17:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70688</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>http://www.youtube.com/watch?v=WourPs56Shc On Thu, Nov 5, 2009 at 1:48 PM, &amp;lt;Valdis.Kletnieks@vt.edu&amp;gt; wrote: &amp;gt; On Wed, 04 Nov 2009 17:42:37 CST, Paul</description>
<pubDate>04 Nov  2009 19:04:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70687</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Wed, 04 Nov 2009 17:42:37 CST, Paul Schmehl said: &amp;gt; You and millions of others love to conflate those issues with warrantless &amp;gt; surveillance of US</description>
<pubDate>04 Nov  2009 18:48:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70686</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yo Paul! On Wed, 4 Nov 2009, Paul Schmehl wrote: &amp;gt; Please cite one proven instance where surveillance</description>
<pubDate>04 Nov  2009 18:03:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70685</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Paul Schmehl wrote: &amp;gt; --On Wednesday, November 04, 2009 16:36:12 -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt;</description>
<pubDate>04 Nov  2009 17:21:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70684</link>
</item><item>
<title>CONFidence 2.0, schedule online, last time to register.</title>
<description>Dear Madame/Sir, CONFidence is the one of the most technical conference in Eastern Europe. You can find videos from the latest edition here: http://2</description>
<pubDate>04 Nov  2009 17:13:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70713</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>Did you and them get your degree from the same university of trolls? I have mistaken nothing for nothing. Fuck you.  --- On Thu, 5/11/09, frank^2 &amp;lt;f</description>
<pubDate>04 Nov  2009 17:07:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70683</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>On Wed, Nov 4, 2009 at 4:13 PM, Micheal Turner &amp;lt;wh1t3h4t3@yahoo.co.uk&amp;gt; wrote: &amp;gt; Its evil. Making people believe that someone is dead, publicly, and pl</description>
<pubDate>04 Nov  2009 16:50:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70682</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>Its evil. Making people believe that someone is dead, publicly, and placing obituaries online shows no regard for the thoughts &amp;amp; feelings of the perso</description>
<pubDate>04 Nov  2009 16:13:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70681</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On Wednesday, November 04, 2009 16:36:12 -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt; On Wed, 04 Nov 2009 14:08:59 CST, Paul Schmehl said: &amp;gt;&amp;gt; Please cite</description>
<pubDate>04 Nov  2009 15:42:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70680</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>On Wed, Nov 4, 2009 at 1:58 PM, Micheal Turner &amp;lt;wh1t3h4t3@yahoo.co.uk&amp;gt; wrote: &amp;gt; It seems the whole thing was a Hoax rumor put about by people who I ca</description>
<pubDate>04 Nov  2009 15:08:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70679</link>
</item><item>
<title>Argentinean Arnet isp webmail</title>
<description>Moderate vulnerability in argentinean ARNET isp webmail. well, there is some kind of weakened authentication on the webmail of Arnet (webmail.arnet.</description>
<pubDate>04 Nov  2009 15:00:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70718</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Wed, 04 Nov 2009 14:08:59 CST, Paul Schmehl said: &amp;gt; Please cite one proven instance where surveillance was done on anyone without a &amp;gt; FISA warrant</description>
<pubDate>04 Nov  2009 14:36:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70677</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>http://twitter.com/str0ke It has happened for rgod an now with str0ke.. in both case they are alive, and in both case there are idiots/trolls who cla</description>
<pubDate>04 Nov  2009 14:29:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70678</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>It seems the whole thing was a Hoax rumor put about by people who I can only describe as pure evil. Glad to know he is fine.  --- On Wed, 4/11/09, we</description>
<pubDate>04 Nov  2009 13:58:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70676</link>
</item><item>
<title>AST-2009-009: Cross-site AJAX request vulnerability</title>
<description>Asterisk Project Security Advisory - AST-2009-009   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>04 Nov  2009 12:12:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70673</link>
</item><item>
<title>AST-2009-008: SIP responses expose valid usernames</title>
<description>Asterisk Project Security Advisory - AST-2009-008   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>04 Nov  2009 12:12:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70672</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>&amp;gt; I seriously doubt the FBI will be wiretapping anyone on this list that isn&amp;#039;t &amp;gt; doing something illegal. If you&amp;#039;re innocent, you have nothing to fe</description>
<pubDate>04 Nov  2009 12:10:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70671</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On Wednesday, November 04, 2009 13:21:02 -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt; &amp;gt; George W Bush and company went to jail for the maximum sentence fo</description>
<pubDate>04 Nov  2009 12:08:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70670</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On Wednesday, November 04, 2009 12:59:09 -0600 &amp;quot;Gary E. Miller&amp;quot; &amp;lt;gem@rellim.com&amp;gt; wrote: &amp;gt; &amp;gt; -----BEGIN PGP SIGNED MESSAGE----- &amp;gt; Hash: SHA1 &amp;gt; &amp;gt; Yo</description>
<pubDate>04 Nov  2009 12:00:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70669</link>
</item><item>
<title>ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability</title>
<description>ZDI-09-080: Sun Java Runtime Environment JPEGImageReader Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-080 November 4</description>
<pubDate>04 Nov  2009 11:50:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70711</link>
</item><item>
<title>ZDI-09-079: Sun Java Runtime AWT setBytePixels Heap Overflow Vulnerability</title>
<description>ZDI-09-079: Sun Java Runtime AWT setBytePixels Heap Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-079 November 4, 2009 --</description>
<pubDate>04 Nov  2009 11:50:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70710</link>
</item><item>
<title>ZDI-09-078: Sun Java Runtime AWT setDifflCM Stack Overflow Vulnerability</title>
<description>ZDI-09-078: Sun Java Runtime AWT setDifflCM Stack Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-078 November 4, 2009 -- A</description>
<pubDate>04 Nov  2009 11:50:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70709</link>
</item><item>
<title>ZDI-09-077: Sun Java Web Start Arbitrary Command Execution Vulnerability</title>
<description>ZDI-09-077: Sun Java Web Start Arbitrary Command Execution Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-077 November 4, 2009 -- A</description>
<pubDate>04 Nov  2009 11:50:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70708</link>
</item><item>
<title>ZDI-09-076: Sun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability</title>
<description>ZDI-09-076: Sun Java HsbParser.getSoundBank Stack Buffer Overflow Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-076 November 4, 200</description>
<pubDate>04 Nov  2009 11:50:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70707</link>
</item><item>
<title>[SECURITY] [DSA 1926-1] New TYPO3 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>04 Nov  2009 11:33:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70675</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Wed, 04 Nov 2009 12:30:25 CST, Paul Schmehl said: &amp;gt; No, nor did I state that. I said that illegal wiretapping will get thrown out &amp;gt; of court and</description>
<pubDate>04 Nov  2009 11:21:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70668</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Yo Paul! On Wed, 4 Nov 2009, Paul Schmehl wrote: &amp;gt; No. But I can distinguish between an American cit</description>
<pubDate>04 Nov  2009 10:59:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70667</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>&amp;gt; I said that illegal wiretapping will get thrown out &amp;gt; of court and the perpetrators jailed. That&amp;#039;s a separate issue from whether or &amp;gt; not agents</description>
<pubDate>04 Nov  2009 10:52:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70666</link>
</item><item>
<title>Context IS Advisory - Autocomplete Data Theft in Mozilla Firefox</title>
<description>===============================ADVISORY=============================== Name:        Autocomplete Data Theft in Mozilla Firefox Systems Affecte</description>
<pubDate>04 Nov  2009 10:35:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70674</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On Tuesday, November 03, 2009 22:52:28 -0600 Valdis.Kletnieks@vt.edu wrote: &amp;gt; On Tue, 03 Nov 2009 22:13:24 CST, Paul Schmehl said: &amp;gt;&amp;gt; Of course, wi</description>
<pubDate>04 Nov  2009 10:30:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70665</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On Tuesday, November 03, 2009 22:39:06 -0600 Holt Sorenson &amp;lt;hso@nosneros.net&amp;gt; wrote: &amp;gt; &amp;gt; On Tue, Nov 03, 2009 at 10:13:24PM -0600, Paul Schmehl wr</description>
<pubDate>04 Nov  2009 10:28:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70664</link>
</item><item>
<title>Interactive HTTP GET and POST Shell -- R.I.P str0ke</title>
<description>Nothing new here, but thought this might be useful to some people...Tries to maintain current working directory when you use &amp;#039;cd&amp;#039;. http://codepad.o</description>
<pubDate>04 Nov  2009 05:41:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70662</link>
</item><item>
<title>Re: Apple ptrace panic PoC - R.I.P str0ke</title>
<description>A very sad news indeed.  On Wed, Nov 4, 2009 at 6:49 PM, Micheal Turner &amp;lt;wh1t3h4t3@yahoo.co.uk&amp;gt;wrote: &amp;gt; We are mourning a good friend today. I first</description>
<pubDate>04 Nov  2009 05:39:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70661</link>
</item><item>
<title>Apple ptrace panic PoC - R.I.P str0ke</title>
<description>We are mourning a good friend today. I first begun talking to str0ke when I started publishing exploit codes onto this mailing list, he would always b</description>
<pubDate>04 Nov  2009 05:19:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70660</link>
</item><item>
<title>Secunia Research: IBM Tivoli Storage Manager CAD Service Buffer Overflow</title>
<description>======================================================================            Secunia Research 04/11/2009    - IBM Tivoli Storage</description>
<pubDate>04 Nov  2009 04:35:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70663</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Tue, Nov 3, 2009 at 20:13, Paul Schmehl &amp;lt;pschmehl_lists@tx.rr.com&amp;gt; wrote: &amp;gt; --On November 4, 2009 12:55:45 PM +1100 &amp;quot;Ivan .&amp;quot; &amp;lt;ivanhec@gmail.com&amp;gt; wr</description>
<pubDate>03 Nov  2009 21:50:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70658</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Tue, 03 Nov 2009 22:13:24 CST, Paul Schmehl said: &amp;gt; Of course, without a warrant they can&amp;#039;t wiretap anything. Furthermore &amp;gt; every warrant to wire</description>
<pubDate>03 Nov  2009 20:52:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70659</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Tue, Nov 3, 2009 at 8:13 PM, Paul Schmehl &amp;lt;pschmehl_lists@tx.rr.com&amp;gt; wrote: &amp;gt; Of course, without a warrant they can&amp;#039;t wiretap anything. good troll</description>
<pubDate>03 Nov  2009 20:46:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70657</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>On Tue, Nov 03, 2009 at 10:13:24PM -0600, Paul Schmehl wrote: &amp;gt;Of course, without a warrant they can&amp;#039;t wiretap anything. Furthermore &amp;gt;every warrant</description>
<pubDate>03 Nov  2009 20:39:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70656</link>
</item><item>
<title>Re: How Prosecutors Wiretap Wall Street</title>
<description>--On November 4, 2009 12:55:45 PM +1100 &amp;quot;Ivan .&amp;quot; &amp;lt;ivanhec@gmail.com&amp;gt; wrote: &amp;gt; The answer is both more mundane and more alarming. Prosecutors are &amp;gt; us</description>
<pubDate>03 Nov  2009 20:13:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70655</link>
</item><item>
<title>How Prosecutors Wiretap Wall Street</title>
<description>The answer is both more mundane and more alarming. Prosecutors are using the FBI&amp;#039;s massive surveillance system, DCSNet, which stands for Digital Colle</description>
<pubDate>03 Nov  2009 17:55:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70654</link>
</item><item>
<title>Bractus SunTrack Multiple XSS</title>
<description>Vendor: Bractus (http://bract.us) Product: SunTrack (http://bract.us/demo/login.jsp) Multiple stored XSS vulnerabilities exist in the Bractus SunTrac</description>
<pubDate>03 Nov  2009 16:21:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70652</link>
</item><item>
<title>e-Courier Tracking Site Multiple Script UserGUID Parameter XSS</title>
<description>Vendor: e-Courier (http://www.ecouriersoftware.com/) Product: CMS Tracking Site Issue: Cross-Site Scripting. Description: Nearly all pages include the</description>
<pubDate>03 Nov  2009 16:20:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70653</link>
</item><item>
<title>Re: KCSEC-00000001-ServUWebClient</title>
<description>If you are about to exploit this bug with ollydbg and a /SafeSEH scanner plug-in which could be found at: http://www.openrce.org/downloads/details/24</description>
<pubDate>03 Nov  2009 15:57:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70651</link>
</item><item>
<title>[ MDVSA-2009:293 ] squidGuard</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>03 Nov  2009 10:31:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70650</link>
</item><item>
<title>[ MDVSA-2009:292 ] wireshark</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>03 Nov  2009 08:16:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70647</link>
</item><item>
<title>ZDI-09-075: Novell eDirectory LDAP Null Base DN Denial of Service Vulnerability</title>
<description>ZDI-09-075: Novell eDirectory LDAP Null Base DN Denial of Service Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-09-075 November 2, 200</description>
<pubDate>02 Nov  2009 15:32:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70648</link>
</item>
</channel>
</rss>
