<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>23 Jul  2008 23:37:14 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>CAU-EX-2008-0003: Kaminsky DNS Cache Poisoning Flaw Exploit for	Domains</title>
<description>____   ____   __  __           /  \  /  \  | | | |     ----====####/ /\__\##/ /\ \##| |##| |####====----</description>
<pubDate>23 Jul  2008 20:48:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62753</link>
</item><item>
<title>CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning Flaw Exploit</title>
<description>____   ____   __  __           /  \  /  \  | | | |     ----====####/ /\__\##/ /\ \##| |##| |####====----</description>
<pubDate>23 Jul  2008 16:34:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62752</link>
</item><item>
<title>[ MDVSA-2008:154 ] - Updated xemacs packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>23 Jul  2008 16:29:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62751</link>
</item><item>
<title>[ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>23 Jul  2008 16:27:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62750</link>
</item><item>
<title>[tool] SDT Cleaner 1.0</title>
<description>Hello! You can find it here: http://oss.coresecurity.com/projects/sdtcleaner.html Package: http://oss.coresecurity.com/repo/SDTCleaner-v1.0.zip  Wh</description>
<pubDate>23 Jul  2008 15:49:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62749</link>
</item><item>
<title>[ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>23 Jul  2008 14:56:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62748</link>
</item><item>
<title>DNS forward only: why does it help?</title>
<description>As a workaround, it is recommended to set DNS servers to forward only. Can someone explain why that helps? Cannot responses from the forwarder be spoo</description>
<pubDate>23 Jul  2008 14:28:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62747</link>
</item><item>
<title>[SECURITY] [DSA 1615-1] New xulrunner packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Jul  2008 13:33:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62744</link>
</item><item>
<title>[SECURITY] [DSA 1614-1] New iceweasel packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Jul  2008 13:07:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62743</link>
</item><item>
<title>[USN-628-1] PHP vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-628-1       July 23, 2008 php5 vulnerabilities CVE-2007</description>
<pubDate>23 Jul  2008 12:39:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62742</link>
</item><item>
<title>Re: Is the security industry like a lemon market?</title>
<description>This should play nicer with some auto-linking code: http://isis.poly.edu/csaw/ Sorry about that! -- Dan Guido _____________________________________</description>
<pubDate>23 Jul  2008 12:14:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62741</link>
</item><item>
<title>[SECURITY] [DSA 1540-3] New lighttpd packages fix regression</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Jul  2008 11:59:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62746</link>
</item><item>
<title>Is the security industry like a lemon market?</title>
<description>This pair of essays were written in 4 hours the night before they were due for last year&amp;#039;s Cyber Security Awareness Week at Polytechnic University. Th</description>
<pubDate>23 Jul  2008 11:40:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62740</link>
</item><item>
<title>Vim: Flawed Fix of Arbitrary Code Execution Vulnerability in filetype.vim</title>
<description>1. SUMMARY Product : Vim -- Vi IMproved Version : Tested with Vim 7.2b.10, filetype.vim 2008-07-17 Impact  : Arbitrary code execution Wherefrom: L</description>
<pubDate>23 Jul  2008 11:29:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62739</link>
</item><item>
<title>Vulnerability Report: EMC Centera Universal Access</title>
<description>adMERITia Vulnerability Report Vulnerability Information Vendor: EMC² Product: Centera Universal Access Version: CUA4.0_4735.p4 Vulnerability Type:</description>
<pubDate>23 Jul  2008 10:09:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62745</link>
</item><item>
<title>Re: Nominate Dan Kaminsky for Most Overhyped BugPwnie Award</title>
<description>mcwidget wrote: &amp;gt; Given how easy it appears to be to redirect a client to a malicious web server, &amp;gt; The web != the Internet. Think of POP and IMAP.</description>
<pubDate>23 Jul  2008 08:29:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62738</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>On Wed, Jul 23, 2008 at 10:57 AM, mokum von Amsterdam &amp;lt;smokum@gmail.com&amp;gt; wrote: &amp;gt; &amp;gt; Are you not supposed to keep DNS issues under your hat and disclo</description>
<pubDate>23 Jul  2008 08:15:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62737</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>On Wed, Jul 23, 2008 at 4:22 PM, Robert McKay &amp;lt;robert@mckay.com&amp;gt; wrote: &amp;gt; &amp;gt; &amp;gt; On Tue, Jul 22, 2008 at 3:36 AM, &amp;lt;monsieur.aglie@hushmail.com&amp;gt; wrote: &amp;gt;&amp;gt;</description>
<pubDate>23 Jul  2008 07:57:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62736</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>On Tue, Jul 22, 2008 at 3:36 AM, &amp;lt;monsieur.aglie@hushmail.com&amp;gt; wrote: &amp;gt; from chargen 19/udp by ecopeland &amp;gt; &amp;gt; 0. &amp;gt; &amp;gt; The cat is out of the bag. Yes, H</description>
<pubDate>23 Jul  2008 07:22:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62735</link>
</item><item>
<title>Re: Nominate Dan Kaminsky for Most Overhyped Bug Pwnie Award</title>
<description>&amp;gt; &amp;gt; Hi Sandy Vagina, &amp;gt; &amp;gt; Looks like they did a U-turn after realising how over hyped the bug &amp;gt; actually is. &amp;gt; &amp;gt; n3td3v &amp;gt; So the Cat&amp;#039;s out of the bag</description>
<pubDate>23 Jul  2008 05:39:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62734</link>
</item><item>
<title>Re: AFK from fool-disclosure</title>
<description>afk-47 is the tool don&amp;#039;t make act the motherfuckin fool</description>
<pubDate>23 Jul  2008 04:28:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62733</link>
</item><item>
<title>Re: Nominate Dan Kaminsky for Most Overhyped Bug Pwnie Award</title>
<description>On Fri, Jul 11, 2008 at 9:22 PM, Sandy Vagina &amp;lt;bigsandyvagina@gmail.com&amp;gt; wrote: &amp;gt; &amp;gt; n3td3v wrote: &amp;gt; &amp;gt; Please nominate Mr.DNS aka Dan Kaminsky for Most</description>
<pubDate>23 Jul  2008 02:00:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62732</link>
</item><item>
<title>Re: AFK from fool-disclosure</title>
<description>we care we really do ________________________________ From: full-disclosure-bounces@lists.grok.org.uk [mailto:full-disclosure-bounces@lists.grok.org</description>
<pubDate>23 Jul  2008 00:57:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62731</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>Paul Schmehl wrote: &amp;gt; So call your customer up and walk him through rebooting, going into single &amp;gt; user mode and changing the password. Ahahah, I ha</description>
<pubDate>22 Jul  2008 23:46:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62730</link>
</item><item>
<title>Pin Pop... (ATM Pins?)</title>
<description>&amp;gt; I have a buddy that is soliciting for help researching PIN numbers  &amp;gt; used in &amp;gt; ATM&amp;#039;s and things of that nature. He is in need of data-sets for  &amp;gt;</description>
<pubDate>22 Jul  2008 20:10:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62729</link>
</item><item>
<title>Re: Dan Kaminsky wants podcast with n3td3v</title>
<description>On Tue, Jul 22, 2008 at 8:25 PM, Maxime Ducharme &amp;lt; mducharme@cybergeneration.com&amp;gt; wrote: &amp;gt; &amp;gt; &amp;gt; ROFL agreed :-) &amp;gt; &amp;gt; &amp;gt; &amp;gt;     +-------------------+</description>
<pubDate>22 Jul  2008 18:30:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62728</link>
</item><item>
<title>AST-2008-011: Traffic amplification in IAX2 firmware provisioning system</title>
<description>Asterisk Project Security Advisory - AST-2008-011   +------------------------------------------------------------------------+  |   Product</description>
<pubDate>22 Jul  2008 16:16:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62727</link>
</item><item>
<title>AST-2008-010: Asterisk IAX &amp;#039;POKE&amp;#039; resource exhaustion</title>
<description>Asterisk Project Security Advisory - AST-2008-010   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>22 Jul  2008 16:15:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62726</link>
</item><item>
<title>[ MDVSA-2008:152 ] - Updated wireshark packages fix denial of service vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>22 Jul  2008 16:07:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62725</link>
</item><item>
<title>Re: Dan Kaminsky wants podcast with n3td3v</title>
<description>&amp;gt; ROFL agreed :-) &amp;gt; &amp;gt; &amp;gt; &amp;gt;     +-------------------+       .:\:\:/:/:. &amp;gt;     |  PLEASE DO NOT  |      :.:\:\:/:/:.: &amp;gt;</description>
<pubDate>22 Jul  2008 14:20:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62720</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>i would be happy if i would be able to cname recursion to make shure i&amp;#039;m alive. old.issue.com.google.com. .. :p _____________________________________</description>
<pubDate>22 Jul  2008 13:59:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62724</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>oh no, my god! the cat is alive! it successfully recursed the cname=? stupid=? may be, or is not. let the cache make his decision.  ______________</description>
<pubDate>22 Jul  2008 13:51:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62722</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>the cat is dead. it fails to sucsessfully recurse the cname. ;)  _______________________________________________ Full-Disclosure - We believe in it.</description>
<pubDate>22 Jul  2008 13:30:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62721</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>but the cat is dead, cos it forgot to cname the recursion. ;) _______________________________________________ Full-Disclosure - We believe in it. Cha</description>
<pubDate>22 Jul  2008 13:19:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62723</link>
</item><item>
<title>Re: Dan Kaminsky wants podcast with n3td3v</title>
<description>ROFL agreed :-)       +-------------------+       .:\:\:/:/:.           |  PLEASE DO NOT  |      :.:\:\:/:/:.:</description>
<pubDate>22 Jul  2008 12:25:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62719</link>
</item><item>
<title>Re: Dan Kaminsky wants podcast with n3td3v</title>
<description>Le Tue, 22 Jul 2008 10:18:55 -0400, Ureleet &amp;lt;ureleet@gmail.com&amp;gt; a osé(e) écrire : &amp;gt; sad. isnt it? dan is clearly making fun of u, and u think he wan</description>
<pubDate>22 Jul  2008 12:10:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62718</link>
</item><item>
<title>Re: The cat is indeed out of the bag</title>
<description>On 7/21/08 8:36 PM, &amp;quot;monsieur.aglie@hushmail.com&amp;quot; &amp;lt;monsieur.aglie@hushmail.com&amp;gt; wrote: &amp;gt; from chargen 19/udp by ecopeland 0. The cat is out of the</description>
<pubDate>22 Jul  2008 11:50:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62717</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  hi, i think you should reinstall that box! when &amp;quot;someone&amp;quot; gets root on it, it is more likely he/she i</description>
<pubDate>22 Jul  2008 10:42:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62711</link>
</item><item>
<title>[USN-627-1] Dnsmasq vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-627-1       July 22, 2008 dnsmasq vulnerability CVE-200</description>
<pubDate>22 Jul  2008 09:37:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62710</link>
</item><item>
<title>Re: Nominate Dan Kaminsky for Most Overhyped Bug Pwnie Award</title>
<description>you&amp;#039;ve agreed w/ some of his posts? y&amp;#039;mean you&amp;#039;ve actually been reading all that shit that he types? someone mustn&amp;#039;t have anything better to do other</description>
<pubDate>22 Jul  2008 09:33:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62708</link>
</item><item>
<title>Re: AFK from fool-disclosure</title>
<description>that&amp;#039;s cool. it&amp;#039;s not like he was worth anything to this list anywayz. thx netdev for your assistance in douching this list. On Tue, Jul 22, 2008 at</description>
<pubDate>22 Jul  2008 09:27:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62709</link>
</item><item>
<title>Re: Dan Kaminsky wants podcast with n3td3v</title>
<description>On Tue, Jul 22, 2008 at 3:18 PM, Ureleet &amp;lt;ureleet@gmail.com&amp;gt; wrote: &amp;gt; sad. isnt it? dan is clearly making fun of u, and u think he wants to &amp;gt; be ur f</description>
<pubDate>22 Jul  2008 09:21:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62707</link>
</item><item>
<title>PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profile page</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profile page Vulnerability found: 25/06/2008</description>
<pubDate>22 Jul  2008 08:59:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62713</link>
</item><item>
<title>PR08-15: Several Webroot Disclosures on Moodle</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-15: Several Webroot Disclosures on Moodle Vulnerability found: 20/06/2008 Vendor informed: 25/06</description>
<pubDate>22 Jul  2008 08:48:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62715</link>
</item><item>
<title>PR08-13: Persistent Cross-site Scripting (XSS) on Moodle via blog entry title</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-13: Persistent Cross-site Scripting (XSS) on Moodle via blog entry title Vulnerability found: 20/</description>
<pubDate>22 Jul  2008 08:46:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62714</link>
</item><item>
<title>Re: Nominate Dan Kaminsky for Most Overhyped Bug Pwnie Award</title>
<description>nate, he doesn&amp;#039;t have a job in the security industry. so he&amp;#039;s made that we do. On Wed, Jul 16, 2008 at 2:40 AM, Nate McFeters &amp;lt;nate.mcfeters@gmail.c</description>
<pubDate>22 Jul  2008 08:08:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62706</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>On Tue, 22 Jul 2008 10:51:48 +0200, Lucio Crusca said: &amp;gt; tried looking for &amp;quot;2.6.24-1-686 exploit&amp;quot; and &amp;quot;2.6.24-1-686 poc&amp;quot; but I can&amp;#039;t &amp;gt; find anything.</description>
<pubDate>22 Jul  2008 07:50:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62705</link>
</item><item>
<title>Re: help: I need to crack my box (Lucio Crusca)</title>
<description>you suck. On Tue, Jul 22, 2008 at 7:09 AM, nigel &amp;lt;nigel@hardwick.demon.co.uk&amp;gt; wrote: &amp;gt;&amp;gt; razi garbie wrote: &amp;gt;&amp;gt; &amp;gt;&amp;gt;&amp;gt; Are you sure that a 0day is even ne</description>
<pubDate>22 Jul  2008 07:24:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62704</link>
</item><item>
<title>Re: Kaminsky&amp;#039;s DNS Issue Leaked?</title>
<description>oh noez, run for the hills, oh wait. turn off recursive dns where u dont need it. On Mon, Jul 21, 2008 at 6:56 PM, natron &amp;lt;shiftnato@gmail.com&amp;gt; wrot</description>
<pubDate>22 Jul  2008 07:24:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62703</link>
</item><item>
<title>Re: n3td3v</title>
<description>its been fagged up, and you want to add to it, instead of help making it better? On Thu, Jul 17, 2008 at 5:33 AM, n3td3v &amp;lt;xploitable@gmail.com&amp;gt; wrote</description>
<pubDate>22 Jul  2008 07:21:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62702</link>
</item><item>
<title>Re: AFK from fool-disclosure</title>
<description>cause he is tired of reading ur bullshit, so he quit fd. i dont blame him. On Fri, Jul 18, 2008 at 9:48 PM, n3td3v &amp;lt;xploitable@gmail.com&amp;gt; wrote: &amp;gt; O</description>
<pubDate>22 Jul  2008 07:20:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62701</link>
</item><item>
<title>Re: Dan Kaminsky wants podcast with n3td3v</title>
<description>sad. isnt it? dan is clearly making fun of u, and u think he wants to be ur friend and podcast w/ u. wow. On Tue, Jul 22, 2008 at 4:09 AM, n3td3v &amp;lt;x</description>
<pubDate>22 Jul  2008 07:18:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62699</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>--On Tuesday, July 22, 2008 09:35:03 +0200 Lucio Crusca &amp;lt;lucio@sulweb.org&amp;gt; wrote: &amp;gt; Alex Howells wrote: &amp;gt; &amp;gt;&amp;gt; Probably not and I can&amp;#039;t think anyone h</description>
<pubDate>22 Jul  2008 07:09:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62700</link>
</item><item>
<title>Re: help: I need to crack my box (Lucio Crusca)</title>
<description>&amp;gt; razi garbie wrote: &amp;gt; &amp;gt;&amp;gt; Are you sure that a 0day is even needed? perhaps its a rather old &amp;gt;&amp;gt; kernel thats locally exploitable? &amp;gt;&amp;gt; shell# uname -r &amp;gt;</description>
<pubDate>22 Jul  2008 04:09:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62697</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>http://www.milw0rm.com/exploits/5092 2008/7/22 Lucio Crusca &amp;lt;lucio@sulweb.org&amp;gt;: &amp;gt; razi garbie wrote: &amp;gt; &amp;gt;&amp;gt; Are you sure that a 0day is even needed? pe</description>
<pubDate>22 Jul  2008 02:00:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62698</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>razi garbie wrote: &amp;gt; Are you sure that a 0day is even needed? perhaps its a rather old &amp;gt; kernel thats locally exploitable? &amp;gt; shell# uname -r 2.6.24-1</description>
<pubDate>22 Jul  2008 01:51:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62696</link>
</item><item>
<title>Dan Kaminsky wants podcast with n3td3v</title>
<description>---------- Forwarded message ---------- From: Dan Kaminsky &amp;lt;dan@doxpara.com&amp;gt; Date: Sun, Jul 20, 2008 at 7:16 AM Subject: you know... To: xploitable@gm</description>
<pubDate>22 Jul  2008 01:09:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62695</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>Alex Howells wrote: &amp;gt; Probably not and I can&amp;#039;t think anyone hiding a 0-day is going to &amp;gt; release it for this. Sorry. No 0-day needed here, Lenny does</description>
<pubDate>22 Jul  2008 00:35:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62693</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>Are you sure that a 0day is even needed? perhaps its a rather old kernel thats locally exploitable? shell# uname -r and then go google. 2008/7/22 Ale</description>
<pubDate>22 Jul  2008 00:29:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62694</link>
</item><item>
<title>[SECURITY] [DSA 1613-1] new libgd2 packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>22 Jul  2008 00:01:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62712</link>
</item><item>
<title>The cat is indeed out of the bag</title>
<description>from chargen 19/udp by ecopeland 0. The cat is out of the bag. Yes, Halvar Flake figured out the flaw Dan Kaminsky will announce at Black Hat. 1.</description>
<pubDate>21 Jul  2008 19:36:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62716</link>
</item><item>
<title>[ MDVSA-2008:151 ] - Updated libxslt packages fix buffer overflow vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>21 Jul  2008 18:49:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62691</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>2008/7/21 Lucio Crusca &amp;lt;lucio@sulweb.org&amp;gt;: &amp;gt; Believe it or not, I have a linux box (mine, yes it&amp;#039;s mine) I need to own... &amp;gt; the problem is that it phi</description>
<pubDate>21 Jul  2008 16:50:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62692</link>
</item><item>
<title>Re: help: I need to crack my box</title>
<description>--On Monday, July 21, 2008 22:47:26 +0200 Lucio Crusca &amp;lt;lucio@sulweb.org&amp;gt; wrote: &amp;gt; Believe it or not, I have a linux box (mine, yes it&amp;#039;s mine) I need</description>
<pubDate>21 Jul  2008 16:21:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62690</link>
</item><item>
<title>NULL pointer in ZDaemon 1.08.07</title>
<description>#######################################################################                Luigi Auriemma Application: ZDaemon</description>
<pubDate>21 Jul  2008 16:02:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62687</link>
</item><item>
<title>Kaminsky&amp;#039;s DNS Issue Leaked?</title>
<description>It appears matasano posted an explanation of Dan Kaminsky&amp;#039;s DNS issue to their blog today, but looks like it may have been yanked back down. My googl</description>
<pubDate>21 Jul  2008 15:56:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62688</link>
</item><item>
<title>[ GLSA 200807-12 ] BitchX: Multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>21 Jul  2008 15:08:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62686</link>
</item><item>
<title>help: I need to crack my box</title>
<description>Believe it or not, I have a linux box (mine, yes it&amp;#039;s mine) I need to own... the problem is that it phisically resides a few 100km from here and someo</description>
<pubDate>21 Jul  2008 13:47:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62689</link>
</item><item>
<title>[ GLSA 200807-11 ] PeerCast: Buffer overflow</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>21 Jul  2008 12:52:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62685</link>
</item><item>
<title>[ GLSA 200807-10 ] Bacula: Information disclosure</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>21 Jul  2008 11:08:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62684</link>
</item><item>
<title>[SECURITY] [DSA 1612-1] New ruby1.8 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>21 Jul  2008 10:29:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62682</link>
</item><item>
<title>Re: Pwnie Awards 2008</title>
<description>OOPS!: By question I landed on the Server Side Bug Nomination List Again. Thanks for riding this Ceremony. kcope / eliteb0y / Nikos  OOPS I did it</description>
<pubDate>21 Jul  2008 09:07:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62683</link>
</item><item>
<title>Re: Pwnie Awards 2008</title>
<description>Hey Alexandr, I see I&amp;#039;m invited to award Brett his pwnie for his SQL flaw if he wins. I&amp;#039;d be more than happy to - after all one bug over 3 years means</description>
<pubDate>21 Jul  2008 07:58:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62676</link>
</item><item>
<title>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 NULL-Pointer reference Denial of Service Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 NULL-Pointer reference Denial of Service Vulnerability http://www.fortiguardcenter.com/advis</description>
<pubDate>21 Jul  2008 06:49:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62678</link>
</item><item>
<title>FGA-2008-16: EMC Dantz Retrospect 7 backup Server Authentication Module Weak Password Hash Arithmetic Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Server Authentication Module Weak Password Hash Arithmetic Vulnerability http://www.fortiguardcenter.com/ad</description>
<pubDate>21 Jul  2008 06:47:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62679</link>
</item><item>
<title>EMC Dantz Retrospect 7 backup Client PlainText Password Hash Disclosure Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Client PlainText Password Hash Disclosure Vulnerability http://www.fortiguardcenter.com/advisory/FGA-2008-1</description>
<pubDate>21 Jul  2008 06:45:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62681</link>
</item><item>
<title>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 Remote Memory corruption Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 Remote Memory corruption Vulnerability http://www.fortiguardcenter.com/advisory/FGA-2008-16.</description>
<pubDate>21 Jul  2008 06:44:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62680</link>
</item><item>
<title>2600 Last Hope Conference NYC</title>
<description>Hi all, I checked out the Last Hope Conf this weekend and it was friggin sweet, anyone else checked it out and if so what talks you like? Sent from m</description>
<pubDate>20 Jul  2008 18:06:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62675</link>
</item><item>
<title>[White Paper] Abusing HTML 5 Structured Client-side Storage</title>
<description>The aim of this white paper is to analyze security implications of the  new HTML 5 client-side storage technology, showing how different  attacks ca</description>
<pubDate>20 Jul  2008 17:32:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62674</link>
</item><item>
<title>Re: List Charter</title>
<description>Ureleet wrote: &amp;gt; how about enforcement of these guidelines? how about just keeping it unmoderated? _______________________________________________ F</description>
<pubDate>20 Jul  2008 10:05:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62673</link>
</item><item>
<title>[ MDVSA-2008:150 ] - Updated mysql packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>19 Jul  2008 16:06:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62672</link>
</item><item>
<title>Re: Oracle Database Local Untrusted Library Path Vulnerability</title>
<description>It is reported to Oracle since 2004 by open3s and affects others libs. The workaround is very simple but it is &amp;quot;under investigation / being fixed in</description>
<pubDate>19 Jul  2008 15:10:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62677</link>
</item><item>
<title>Re: Torvalds attacks IT industry &amp;#039;security circus&amp;#039;</title>
<description>On Sat, Jul 19, 2008 at 7:34 PM, php0t &amp;lt;php0t@zorro.hu&amp;gt; wrote: &amp;gt; &amp;gt; If I didn&amp;#039;t feel you were moving towards being-serious-about-it, i&amp;#039;d give &amp;gt; you a c</description>
<pubDate>19 Jul  2008 13:40:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62671</link>
</item><item>
<title>[ MDVSA-2008:149 ] - Updated mysql packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>19 Jul  2008 12:42:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62670</link>
</item><item>
<title>Torvalds attacks IT industry &amp;#039;security circus&amp;#039;</title>
<description>The maker of Linux was right, &amp;quot;In an e-mail to the Linux kernel developer mailing list, Torvalds said a section of the security industry was dedicate</description>
<pubDate>19 Jul  2008 11:27:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62669</link>
</item><item>
<title>Oracle Database Local Untrusted Library Path Vulnerability</title>
<description>Oracle Database Local Untrusted Library Path Vulnerability ---------------------------------------------------------- The Oracle July 2008 Critical P</description>
<pubDate>19 Jul  2008 08:08:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62667</link>
</item><item>
<title>rPSA-2008-0231-1 bind bind-utils</title>
<description>rPath Security Advisory: 2008-0231-1 Published: 2008-07-19 Products:   rPath Linux 2 Rating: Major Exposure Level Classification:   Remote System</description>
<pubDate>19 Jul  2008 07:31:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62668</link>
</item><item>
<title>Fwd: Stop The 70% Lie</title>
<description>---------- Forwarded message ---------- From: n3td3v &amp;lt;xploitable@gmail.com&amp;gt; Date: Sat, Jul 19, 2008 at 12:13 AM Subject: Re: Stop The 70% Lie To: The</description>
<pubDate>18 Jul  2008 18:56:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62665</link>
</item><item>
<title>Re: AFK from fool-disclosure</title>
<description>On Fri, Jul 18, 2008 at 6:13 PM, Kingcope Kingcope &amp;lt;kcope2@googlemail.com&amp;gt; wrote: &amp;gt; I am reachable &amp;gt; 0nly @ two addresses: &amp;gt; &amp;gt; http://www.milw0rm.com</description>
<pubDate>18 Jul  2008 18:48:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62664</link>
</item><item>
<title>rPSA-2008-0230-1 bind bind-utils</title>
<description>rPath Security Advisory: 2008-0230-1 Published: 2008-07-18 Products:   rPath Linux 1 Rating: Major Exposure Level Classification:   Remote System</description>
<pubDate>18 Jul  2008 12:56:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62662</link>
</item><item>
<title>AFK from full-disclosure</title>
<description>I am reachable 0nly @ two addresses from now on: http://www.milw0rm.com http://www.com-winner.com Thanks n3td3v</description>
<pubDate>18 Jul  2008 10:58:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62666</link>
</item><item>
<title>AFK from fool-disclosure</title>
<description>I am reachable 0nly @ two addresses: http://www.milw0rm.com http://www.com-winner.com Thanks n3td3v  Signed, KingCope</description>
<pubDate>18 Jul  2008 10:13:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62663</link>
</item><item>
<title>Re: [Dailydave] Linux&amp;#039;s unofficial security-through-coverup policy</title>
<description>motivation to commit crime is well documented. Loads of hardwork must never result in a crime because of a silly error. I understand that no solution</description>
<pubDate>18 Jul  2008 09:23:57 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62661</link>
</item><item>
<title>Re: [Dailydave] Linux&amp;#039;s unofficial security-through-coverup policy</title>
<description>On Fri, 18 Jul 2008 21:07:47 +0530, Joel Jose said: &amp;gt; abetting the crime. But a GUI crash is always less severe. People can &amp;gt; quickly loose trust in</description>
<pubDate>18 Jul  2008 09:08:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62660</link>
</item><item>
<title>Re: [Dailydave] Linux&amp;#039;s unofficial security-through-coverup policy</title>
<description>if ppl stop giving &amp;quot;special&amp;quot; consideration to security, the quality of security enforcement could come down. Ideally we like to &amp;quot;clean&amp;quot; all bugs. But</description>
<pubDate>18 Jul  2008 08:37:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62659</link>
</item><item>
<title>Lateral SQL Injection Revisited - No Special Privs Required</title>
<description>At the end of April 2008 I published a paper about a new class of flaw in Oracle entitled &amp;quot;Lateral SQL Injection&amp;quot;.  The paper can be found here: http</description>
<pubDate>18 Jul  2008 07:03:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62658</link>
</item><item>
<title>Re: Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution</title>
<description>On Fri, Jul 18, 2008 at 00:54, Jan Mináø &amp;lt;rdancer@rdancer.org&amp;gt; wrote: &amp;gt; The attacker has to create the temporary file &amp;gt; ``/tmp/Makefile-conf&amp;lt;PID&amp;gt;&amp;#039;&amp;#039; b</description>
<pubDate>18 Jul  2008 00:38:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62657</link>
</item><item>
<title>[ MDVSA-2008:148 ] - Updated Firefox packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>17 Jul  2008 17:51:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62655</link>
</item><item>
<title>Re: [funsec] Stop The 70% Lie</title>
<description>On Thu, 17 Jul 2008, The Security Community wrote: &amp;gt; http://70percenters.googlepages.com/ &amp;gt; &amp;gt; &amp;quot;The FBI estimates that about 70 percent of all computer</description>
<pubDate>17 Jul  2008 17:18:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62656</link>
</item><item>
<title>Stop The 70% Lie</title>
<description>http://70percenters.googlepages.com/ &amp;quot;The FBI estimates that about 70 percent of all computer security breaches are perpetrated by insiders.&amp;quot; For ye</description>
<pubDate>17 Jul  2008 16:29:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62654</link>
</item>
</channel>
</rss>
