<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>13 Feb  2012 01:41:14 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>On Sat, Feb 11, 2012 at 2:23 PM, &amp;lt;farthvader@hush.ai&amp;gt; wrote: &amp;gt; _________________________________________________________________________ &amp;gt; &amp;quot;Use Tomat</description>
<pubDate>12 Feb  2012 14:42:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85023</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>They should at least consider providing an option to disable the static pin only or disable it after an hour if the future is activated by the user.</description>
<pubDate>12 Feb  2012 14:30:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85022</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>Interesting. Do you know if they stop advertising WPS support after they disable it? On Sun, Feb 12, 2012 at 10:11 AM, Rob Fuller &amp;lt;jd.mubix@gmail.co</description>
<pubDate>12 Feb  2012 13:55:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85021</link>
</item><item>
<title>[ MDVSA-2012:017 ] firefox</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>12 Feb  2012 12:23:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85020</link>
</item><item>
<title>Re: Trustwave and Mozilla</title>
<description>On Sun, 12 Feb 2012 05:54:30 EST, Jeffrey Walton said: &amp;gt; For what its worth, pinning the certificate can usually remediate &amp;gt; these sorts of MitM atta</description>
<pubDate>12 Feb  2012 07:55:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85019</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>I&amp;#039;ve tested a 6 models of Linksys, all of them appear to disable WPS completely as soon as a single wireless setting is set. I assume this would be th</description>
<pubDate>12 Feb  2012 07:11:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85018</link>
</item><item>
<title>Re: Iran is doing ip-and-port filtering of SSL</title>
<description>In case the OP hasn&amp;#039;t seen this: http://boingboing.net/2012/02/10/iran-attacks-internet-access-o.html https://lists.torproject.org/pipermail/tor-talk</description>
<pubDate>12 Feb  2012 07:02:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85017</link>
</item><item>
<title>Re: [Off-Spanish] Webinario gratuito - Ataques DoS en latino america</title>
<description>Agree.  -- &amp;#039;Wag More, Bark Less&amp;#039; - Jen and Bren, CloudStar &amp;#039;Did you ever feel like God has a finger on the Reset button, waiting?&amp;#039; - dccdave &amp;quot;using w</description>
<pubDate>12 Feb  2012 05:53:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85016</link>
</item><item>
<title>Trustwave and Mozilla</title>
<description>Hi All, https://www.infoworld.com/d/security/trustwave-admits-issuing-man-in-the-middle-digital-certificate-185972 In case folks are interested in t</description>
<pubDate>12 Feb  2012 02:54:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85009</link>
</item><item>
<title>Re: Iran is doing ip-and-port filtering of SSL</title>
<description>maybe it&amp;#039;s time to get the old school substitution code books out. http://www.forbes.com/sites/andygreenberg/2012/02/10/as-iran-cracks-down-online-to</description>
<pubDate>12 Feb  2012 01:13:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85008</link>
</item><item>
<title>Re: Iran is doing ip-and-port filtering of SSL</title>
<description>thought they filtered specific URLs, but now they filter all SSL (to defeat VPNs, Tor, etc). On 2012-02-11 9:51 PM, &amp;quot;Robert Kim App and Facebook Marke</description>
<pubDate>11 Feb  2012 22:58:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85015</link>
</item><item>
<title>Re: Iran is doing ip-and-port filtering of SSL</title>
<description>On Sun, Feb 12, 2012 at 00:50, Robert Kim App and Facebook Marketing &amp;lt;evdo.hsdpa@gmail.com&amp;gt; wrote: &amp;gt; Hasn&amp;#039;t Iran and China always been filtering? I&amp;#039;m</description>
<pubDate>11 Feb  2012 21:56:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85013</link>
</item><item>
<title>Re: Iran is doing ip-and-port filtering of SSL</title>
<description>Hasn&amp;#039;t Iran and China always been filtering? Do VPNs work in this case? On Thu, Feb 9, 2012 at 9:54 AM, Sai &amp;lt;sai@saizai.com&amp;gt; wrote: &amp;gt; I have pretty</description>
<pubDate>11 Feb  2012 21:50:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85007</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps	vulnerability.</title>
<description>_________________________________________________________________________ &amp;quot;Use Tomato-USB OS on them.&amp;quot; _______________________________________________</description>
<pubDate>11 Feb  2012 13:23:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85012</link>
</item><item>
<title>eFront Community++ v3.6.10 - SQL Injection Vulnerability</title>
<description>Title: ====== eFront Community++ v3.6.10 - SQL Injection Vulnerability  Date: ===== 2012-02-11  References: =========== http://www.vulnerability-lab</description>
<pubDate>11 Feb  2012 10:53:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85011</link>
</item><item>
<title>Yahoo! Messenger v11.5 - Buffer Overflow Vulnerability</title>
<description>Title: ====== Yahoo! Messenger v11.5 - Buffer Overflow Vulnerability  Date: ===== 2012-02-11  References: =========== http://www.vulnerability-lab.c</description>
<pubDate>11 Feb  2012 10:51:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85010</link>
</item><item>
<title>Re: [Off-Spanish] Webinario gratuito - Ataques DoS en latino america</title>
<description>It should be marked as spam. We do not care about &amp;quot;exploitpack.com&amp;quot; ... do not send more message with this business. On 2/10/12, runlvl &amp;lt;runlvl@gmai</description>
<pubDate>11 Feb  2012 08:58:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85014</link>
</item><item>
<title>[Announcement] ClubHack Mag - Call for Articles</title>
<description>Hello All, ClubHack Magazine is seeking submissions for next issue, Issue 26 - March 2012. Topics:- 1. Web App Sec 2. OS Exploitation and Security 3</description>
<pubDate>10 Feb  2012 22:22:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85004</link>
</item><item>
<title>Re: Iran is doing ip-and-port filtering of SSL</title>
<description>See my post @ https://plus.google.com/u/0/103112149634414554669/posts/PT3eEF4u415 to stay updated. Copying over update: - Further testing done. Conc</description>
<pubDate>10 Feb  2012 17:44:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85006</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>On Fri, Feb 10, 2012 at 4:33 PM, &amp;lt;Valdis.Kletnieks@vt.edu&amp;gt; wrote: &amp;gt; On Fri, 10 Feb 2012 14:41:37 EST, Dan Kaminsky said: &amp;gt; &amp;gt; &amp;gt; According to the Reave</description>
<pubDate>10 Feb  2012 13:43:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85003</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>On Fri, 10 Feb 2012 14:41:37 EST, Dan Kaminsky said: &amp;gt; According to the Reaver people, DD-WRT doesn&amp;#039;t support WPS at all :) The sort of people that</description>
<pubDate>10 Feb  2012 13:33:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85002</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps	vulnerability.</title>
<description>Waidaminnit... Didn&amp;#039;t you try to sell me a belkin the other day? Conflict of interest there Sent from my BlackBerry® wireless device -----Original M</description>
<pubDate>10 Feb  2012 12:01:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85001</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>According to the Reaver people, DD-WRT doesn&amp;#039;t support WPS at all :) On Fri, Feb 10, 2012 at 2:00 PM, Zach C. &amp;lt;fxchip@gmail.com&amp;gt; wrote: &amp;gt; Solution:</description>
<pubDate>10 Feb  2012 11:41:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85000</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>Solution: use DD-WRT? Or is that vulnerable too? (Or are there worse problems? :)) On Feb 10, 2012 10:12 AM, &amp;quot;Dan Kaminsky&amp;quot; &amp;lt;dan@doxpara.com&amp;gt; wrote:</description>
<pubDate>10 Feb  2012 11:00:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84999</link>
</item><item>
<title>[ MDVSA-2012:016 ] glpi</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>10 Feb  2012 11:00:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84998</link>
</item><item>
<title>New Android Malware Botnet Reversed/Uncovered</title>
<description>Hello, one of InfoSec Institute&amp;#039;s security researchers reverse engineered a new botnet that is active for the Android platform. RootSmart has some uni</description>
<pubDate>10 Feb  2012 10:56:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84997</link>
</item><item>
<title>[Off-Spanish] Webinario gratuito - Ataques DoS en latino america</title>
<description>Fecha y hora: Sabado, Febrero 11 2012 - 18:00 PM ( Hora Argentina GMT - 3:00 ) En el webinario veremos de forma practica y teorica como se ejecutan l</description>
<pubDate>10 Feb  2012 10:24:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84996</link>
</item><item>
<title>Multiple CSRF, DoS and XSS vulnerabilities in D-Link DAP 1150</title>
<description>Hello list! I want to warn you about new security vulnerabilities in D-Link DAP 1150 (Wi-Fi Access Point and Router). These are Cross-Site Request</description>
<pubDate>10 Feb  2012 10:21:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84995</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>&amp;quot;Fixing a vulnerability like this with all the bureoucratic, QA and legal process wouldn&amp;#039;t take no more than 2 weeks&amp;quot; If bureaucratic, QA, and legal</description>
<pubDate>10 Feb  2012 10:11:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84994</link>
</item><item>
<title>Yahoo Messenger - Buffer Overflow Vulnerability [Video]</title>
<description>Title: ====== Yahoo Messenger - Buffer Overflow Vulnerability [Video]  Date: ===== 2012-02-10  References: =========== Download:    http://www.vu</description>
<pubDate>10 Feb  2012 09:41:17 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/85005</link>
</item><item>
<title>Zen-Cart Admin CSRF/XSRF - Delete / Disable Products | UPS-2011-0018 | CVE-2011-4403</title>
<description>*Advisory Information* Title: Zen-Cart Admin CSRF/XSRF - Delete / Disable Products Date published: 2012-02-10 01:59:45 AM upSploit Ref: UPS-2011-0018</description>
<pubDate>10 Feb  2012 08:10:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84993</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>On Fri, 10 Feb 2012 07:40:03 GMT, farthvader@hush.ai said: &amp;gt; Don&amp;#039;t buy Linksys Routers they are vulnerable to Wifi unProtected &amp;gt; Setup Pin registrar</description>
<pubDate>10 Feb  2012 08:06:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84991</link>
</item><item>
<title>CubeCart 3.0.20 (3.0.x) and lower | Open URL Redirection Vulnerability</title>
<description>1. OVERVIEW The CubeCart 3.0.20 and lower versions are vulnerable to Open URL Redirection.  2. BACKGROUND CubeCart is an &amp;quot;out of the box&amp;quot; ecommerce</description>
<pubDate>10 Feb  2012 08:01:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84992</link>
</item><item>
<title>Re: Bug 718066 - [meta] Add feature to submit	anonymous product metrics to Mozilla</title>
<description>Hi, I can imagine that developers want to have a clue what they need to repair. I only have a problem the way they do it and the way my behavior is e</description>
<pubDate>10 Feb  2012 07:52:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84990</link>
</item><item>
<title>Re: Bug 718066 - [meta] Add feature to submit anonymous product metrics to Mozilla</title>
<description>On Fri, 10 Feb 2012 03:51:53 GMT, Nick Boyce said: &amp;gt; OT: They should just make FF quality high and the design impeccable - &amp;quot;Quality high&amp;quot; is always a</description>
<pubDate>10 Feb  2012 06:48:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84989</link>
</item><item>
<title>Linux Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities</title>
<description>Title: ====== Kloxo LxCenter Server CP v6.1.10 - Multiple Web Vulnerabilities  Date: ===== 2012-02-10  References: =========== http://www.vulnerabil</description>
<pubDate>10 Feb  2012 06:25:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84988</link>
</item><item>
<title>Re: Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>Use Tomato-USB OS on them.  A.  On Fri, 10 Feb 2012 07:40:03 +0000, farthvader@hush.ai wrote: Don&amp;#039;t buy Linksys Routers they are vulnerable to Wifi</description>
<pubDate>10 Feb  2012 05:48:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84987</link>
</item><item>
<title>Re: Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities</title>
<description>http://www.indianapolissuperbowl.com/view-release.php?id=42 2012/2/10 research@vulnerability-lab.com &amp;lt;research@vulnerability-lab.com&amp;gt; &amp;gt; Title: &amp;gt; ===</description>
<pubDate>10 Feb  2012 04:56:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84986</link>
</item><item>
<title>Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities</title>
<description>Title: ====== Indianapolis Superbowl 2012 - SQL Injection Vulnerabilities  Date: ===== 2012-02-06  VL-ID: ===== 418  Abstract: ========= Alexander</description>
<pubDate>10 Feb  2012 03:28:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84984</link>
</item><item>
<title>Astaro Security Gateway - bypass using whitelist domain pattern weakness</title>
<description>*Advisory Information* Title: Astaro Security Gateway - bypass using whitelist domain pattern weakness upSploit Ref: UPS-2011-0041  *Advisory Summ</description>
<pubDate>10 Feb  2012 03:00:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84985</link>
</item><item>
<title>Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities</title>
<description>Title: ====== Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities  Date: ===== 2012-02-09  References: =========== http://www.vulnerability-la</description>
<pubDate>10 Feb  2012 02:55:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84983</link>
</item><item>
<title>Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities</title>
<description>Title: ====== Dolibarr CMS v3.2.0 Alpha - SQL Injection Vulnerabilities  Date: ===== 2012-02-09  References: =========== http://www.vulnerability-la</description>
<pubDate>10 Feb  2012 02:54:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84982</link>
</item><item>
<title>OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities</title>
<description>Title: ====== OnxShop CMS v1.5.0 - Multiple Web Vulnerabilities  Date: ===== 2012-02-08  References: =========== http://www.vulnerability-lab.com/ge</description>
<pubDate>10 Feb  2012 02:53:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84981</link>
</item><item>
<title>Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities</title>
<description>Title: ====== Dolibarr CMS v3.2.0 Alpha - File Include Vulnerabilities  Date: ===== 2012-02-07  References: =========== http://www.vulnerability-lab</description>
<pubDate>10 Feb  2012 02:51:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84980</link>
</item><item>
<title>CVE-2012-1037: GLPI &amp;lt;= 0.80.61 LFI/RFI</title>
<description>CVE-2012-1037: GLPI &amp;lt;= 0.80.61 LFI/RFI Severity: Important Vendor: GLPI - http://www.glpi-project.org Versions Affected ================= All vers</description>
<pubDate>10 Feb  2012 02:40:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84979</link>
</item><item>
<title>Celebrate with PenTest Magazine</title>
<description>Celebrate with PenTest Magazine To celebrate the transformation of PenTest StarterKit edition into Auditing &amp;amp; Standards PenTest, we&amp;#039;ve decided to gi</description>
<pubDate>10 Feb  2012 02:32:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84977</link>
</item><item>
<title>Re: posting xss notifications in sites vs software packages</title>
<description>Well....in Germany...our law regarding security in general is very, very vague. It basically says that you have to go to prison if you produce or pub</description>
<pubDate>10 Feb  2012 02:21:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84978</link>
</item><item>
<title>Linksys Routers still Vulnerable to Wps vulnerability.</title>
<description>Don&amp;#039;t buy Linksys Routers they are vulnerable to Wifi unProtected Setup Pin registrar Brute force attack. No patch or workaround exist at the making o</description>
<pubDate>09 Feb  2012 23:40:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84976</link>
</item><item>
<title>Re: Bug 718066 - [meta] Add feature to submit anonymous product metrics to Mozilla</title>
<description>On Wed, Feb 8, 2012 at 9:12 PM, . . &amp;lt;kerdezdmeg@gmail.com&amp;gt; wrote: &amp;gt; &amp;gt; https://bugzilla.mozilla.org/show_bug.cgi?id=718066 &amp;gt; &amp;gt; what the hell is this?!</description>
<pubDate>09 Feb  2012 19:51:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84975</link>
</item><item>
<title>What&amp;#039;s up with the ImmunityInc forums?</title>
<description>Hey, anyone know why it&amp;#039;s taking so long for the ImmunityInc forums to come back up? It&amp;#039;s been weeks, man. __________________________________________</description>
<pubDate>09 Feb  2012 15:45:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84974</link>
</item><item>
<title>eFront Community++ v3.6.10 - Multiple Web Vulnerabilities</title>
<description>Title: ====== eFront Community++ v3.6.10 - Multiple Web Vulnerabilities  Date: ===== 2012-02-09  References: =========== http://www.vulnerability-la</description>
<pubDate>09 Feb  2012 10:01:12 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84973</link>
</item><item>
<title>[SECURITY] CVE-2011-4367 Apache MyFaces information disclosure vulnerability</title>
<description>-------------------------------------------------------------------------------------------------- CVE-2011-4367: Apache MyFaces information disclosu</description>
<pubDate>09 Feb  2012 07:54:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84972</link>
</item><item>
<title>List Charter</title>
<description>[Full-Disclosure] Mailing List Charter John Cartwright &amp;lt;johnc@grok.org.uk&amp;gt;  - Introduction &amp;amp; Purpose - This document serves as a charter for the [F</description>
<pubDate>09 Feb  2012 07:43:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84971</link>
</item><item>
<title>Creating backdoors using SQL Injection</title>
<description>An InfoSec Institute Review on Creating backdoors using SQL Injection:   http://resources.infosecinstitute.com/backdoor-sql-injection/   A novel t</description>
<pubDate>09 Feb  2012 07:39:44 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84970</link>
</item><item>
<title>Drupal Finder Module Multiple Vulnerabilities</title>
<description>Vulnerability Report Description of Vulnerability: ----------------------------- Drupal (http://drupal.org) is a robust content management system (CM</description>
<pubDate>09 Feb  2012 06:04:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84968</link>
</item><item>
<title>[ MDVSA-2012:015 ] wireshark</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>09 Feb  2012 05:58:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84969</link>
</item><item>
<title>[SECURITY] [DSA 2407-1] cvs security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>09 Feb  2012 05:05:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84966</link>
</item><item>
<title>[SECURITY] [DSA 2406-1] icedove security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>09 Feb  2012 04:07:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84965</link>
</item><item>
<title>Re: posting xss notifications in sites vs software packages</title>
<description>Typically if you are in the US, are testing a server in the US owned by a company headquartered in the US it is legal to find Reflective XSS so long a</description>
<pubDate>08 Feb  2012 21:05:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84963</link>
</item><item>
<title>Re: posting xss notifications in sites vs software packages</title>
<description>On Wed, 08 Feb 2012 17:30:18 +0100, Info said: &amp;gt; A general question: is it legal to search for XSS vulnerabilities on &amp;gt; custom websites ? Yes. No. Ma</description>
<pubDate>08 Feb  2012 18:23:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84962</link>
</item><item>
<title>Vulnerability in Novell website.</title>
<description>Hello :-)  I sent email stating the problem for the company, waited a few days and got no response, so I&amp;#039;m making the vulnerability public:  Scan da</description>
<pubDate>08 Feb  2012 17:10:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84964</link>
</item><item>
<title>Iran is doing ip-and-port filtering of SSL</title>
<description>I have pretty definitive proof that Iran is doing ip-and-port based filtering of SSL. Filtering is being done by 217.218.154.250 after a hop through</description>
<pubDate>08 Feb  2012 16:54:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84961</link>
</item><item>
<title>Re: trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor</title>
<description>I was working on a backdoor kernel land, using netfilter =] Kind regards,  On Wed, Feb 8, 2012 at 10:17 PM, Levent Kayan &amp;lt;levonkayan@gmx.net&amp;gt; wrote:</description>
<pubDate>08 Feb  2012 16:15:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84957</link>
</item><item>
<title>InfoSec Southwest 2012 Speakers and Agenda</title>
<description>Hello, It is my pleasure to announce InfoSec Southwest 2012&amp;#039;s final speaker selections. The following lectures will be given at this year&amp;#039;s conferen</description>
<pubDate>08 Feb  2012 14:24:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84956</link>
</item><item>
<title>Re: trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor</title>
<description>On 02/08/12 22:55, Kryton Jones wrote: &amp;gt; Is this something like Port Knocking ?? you can see that kinda as port knocking yes. &amp;gt; &amp;gt; http://en.wikipedi</description>
<pubDate>08 Feb  2012 14:17:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84955</link>
</item><item>
<title>Re: trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor</title>
<description>privet, On 02/08/12 23:03, Kai wrote: &amp;gt; Hello, &amp;gt; &amp;gt;&amp;gt; trixd00r is an advanced and invisible userland backdoor based on TCP/IP &amp;gt;&amp;gt; for UNIX systems. It</description>
<pubDate>08 Feb  2012 14:16:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84954</link>
</item><item>
<title>Re: trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor</title>
<description>Hello, &amp;gt; trixd00r is an advanced and invisible userland backdoor based on &amp;gt; TCP/IP &amp;gt; for UNIX systems. It consists of a server and a client. The ser</description>
<pubDate>08 Feb  2012 14:03:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84953</link>
</item><item>
<title>Re: trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor</title>
<description>Is this something like Port Knocking ?? http://en.wikipedia.org/wiki/Port_knocking  On 09/02/2012, at 8:29 AM, Levent Kayan wrote: &amp;gt; Hi there, &amp;gt; &amp;gt;</description>
<pubDate>08 Feb  2012 13:55:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84960</link>
</item><item>
<title>trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor</title>
<description>Hi there, description =========== trixd00r is an advanced and invisible userland backdoor based on TCP/IP for UNIX systems. It consists of a server a</description>
<pubDate>08 Feb  2012 13:29:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84952</link>
</item><item>
<title>Bug 718066 - [meta] Add feature to submit anonymous product metrics to Mozilla</title>
<description>https://bugzilla.mozilla.org/show_bug.cgi?id=718066 what the hell is this?! _______________________________________________ Full-Disclosure - We bel</description>
<pubDate>08 Feb  2012 13:12:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84967</link>
</item><item>
<title>ZDI-12-031 : Novell iPrint Server attributes-natural-language Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-031 : Novell iPrint Server attributes-natural-language Remote Code Execution Vulnerability http:</description>
<pubDate>08 Feb  2012 09:46:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84951</link>
</item><item>
<title>ZDI-12-030 : IBM Rational Rhapsody BBFlashBack.Recorder.1 TestCompatibilityRecordMode Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-030 : IBM Rational Rhapsody BBFlashBack.Recorder.1 TestCompatibilityRecordMode Remote Code Execu</description>
<pubDate>08 Feb  2012 09:45:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84950</link>
</item><item>
<title>ZDI-12-029 : IBM Rational Rhapsody BBFlashBack.Recorder.1 InsertMarker Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-029 : IBM Rational Rhapsody BBFlashBack.Recorder.1 InsertMarker Remote Code Execution Vulnerabil</description>
<pubDate>08 Feb  2012 09:44:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84949</link>
</item><item>
<title>ZDI-12-028 : IBM Rational Rhapsody BBFlashBack.FBRecorder.1 Control Multiple Remote Code Execution Vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-028 : IBM Rational Rhapsody BBFlashBack.FBRecorder.1 Control Multiple Remote Code Execution Vuln</description>
<pubDate>08 Feb  2012 09:42:05 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84948</link>
</item><item>
<title>ZDI-12-027 : IBM SPSS VsVIEW6.ocx ActiveX Control SaveDoc Method Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-027 : IBM SPSS VsVIEW6.ocx ActiveX Control SaveDoc Method Remote Code Execution Vulnerability ht</description>
<pubDate>08 Feb  2012 09:40:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84946</link>
</item><item>
<title>ZDI-12-026 : IBM SPSS ExportHTML.dll ActiveX Control Render Method Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-026 : IBM SPSS ExportHTML.dll ActiveX Control Render Method Remote Code Execution Vulnerability</description>
<pubDate>08 Feb  2012 09:38:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84945</link>
</item><item>
<title>ZDI-12-025 : EMC Networker indexd.exe Opcode 0x01 Parsing Remote Code Execution</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-025 : EMC Networker indexd.exe Opcode 0x01 Parsing Remote Code Execution http://www.zerodayiniti</description>
<pubDate>08 Feb  2012 09:36:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84944</link>
</item><item>
<title>ZDI-12-024 : Total Defense Suite UNC Management Web Service uncsp_ViewReportsHomepage SQL Injection Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-024 : Total Defense Suite UNC Management Web Service uncsp_ViewReportsHomepage SQL Injection Vul</description>
<pubDate>08 Feb  2012 09:32:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84943</link>
</item><item>
<title>ZDI-12-023 : Total Defense Suite UNC Management Web Service Database Credentials Disclosure Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-023 : Total Defense Suite UNC Management Web Service Database Credentials Disclosure Vulnerabili</description>
<pubDate>08 Feb  2012 09:31:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84942</link>
</item><item>
<title>ZDI-12-022 : Total Defense Suite UNC Management Console ExportReport SQL Injection Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-022 : Total Defense Suite UNC Management Console ExportReport SQL Injection Vulnerability http:/</description>
<pubDate>08 Feb  2012 09:29:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84947</link>
</item><item>
<title>ZDI-12-021 : Adobe Reader BMP Resource Signedness Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-021 : Adobe Reader BMP Resource Signedness Remote Code Execution Vulnerability http://www.zeroda</description>
<pubDate>08 Feb  2012 09:21:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84941</link>
</item><item>
<title>Re: posting xss notifications in sites vs	software packages</title>
<description>A general question: is it legal to search for XSS vulnerabilities on custom websites ? Julien  On 02/08/2012 04:37 PM, Packet Storm wrote: &amp;gt; On Tue</description>
<pubDate>08 Feb  2012 08:30:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84959</link>
</item><item>
<title>Re: posting xss notifications in sites vs	software packages</title>
<description>On Tue, Feb 07, 2012 at 06:18:24PM -0500, b wrote: &amp;gt; What is the point of posting notifications of XSS vulnerabilities in &amp;gt; specific web sites instead</description>
<pubDate>08 Feb  2012 07:37:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84939</link>
</item><item>
<title>Netbeans Jira Plugin does not check https certificates</title>
<description>Title: ------- Netbeans Jira Plugin does not check https certificates Disclosure Timeline: ----------------------------- [2012-01-02] Vulnerability r</description>
<pubDate>08 Feb  2012 07:21:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84940</link>
</item><item>
<title>Re: posting xss notifications in sites vs software packages</title>
<description>On Tue, Feb 7, 2012 at 4:18 PM, b &amp;lt;b@advisoryalerts.com&amp;gt; wrote: &amp;gt; What is the point of posting notifications of XSS vulnerabilities in &amp;gt; specific web</description>
<pubDate>08 Feb  2012 06:13:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84958</link>
</item><item>
<title>Re: posting xss notifications in sites vs software packages</title>
<description>Typically you will run into instances where a website is employing a custom CMS/plugin/module/whatever and as such there may not be a specific softwar</description>
<pubDate>08 Feb  2012 05:55:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84938</link>
</item><item>
<title>Fwd: DVR Security Issue</title>
<description>I tried to report this to the vendor in 2009. SHODAN &amp;quot;OwnServer1.0&amp;quot;: Results 1 - 10 of about 11832 for OwnServer1.0 country:US. -Jason Ellison ----</description>
<pubDate>08 Feb  2012 01:21:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84935</link>
</item><item>
<title>[Announcement] ClubHack Magazine Issue 25, Feb 2012 Released</title>
<description>Dear All, ClubHack Magazine&amp;#039;s Issue-25, Feb 2012 is released. The theme for this issue is Network Exploitation and Security. This issue covers follo</description>
<pubDate>07 Feb  2012 21:25:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84934</link>
</item><item>
<title>Android Multiple Vulnerabilities</title>
<description>Android Multiple Vulnerabilities Author: www.80vul.com [Email:5up3rh3i#gmail.com] Release Date: 2012/2/8 References: http://www.80vul.com/android/a</description>
<pubDate>07 Feb  2012 20:36:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84933</link>
</item><item>
<title>Cyberoam Central Console v2.00.2 - File Include Vulnerability &amp;amp; Video</title>
<description>Title: ====== Cyberoam Central Console v2.00.2 - File Include Vulnerability  Date: ===== 2012-02-08  References: =========== http://www.vulnerabilit</description>
<pubDate>07 Feb  2012 15:24:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84937</link>
</item><item>
<title>posting xss notifications in sites vs software packages</title>
<description>What is the point of posting notifications of XSS vulnerabilities in specific web sites instead of alerts of xss vulns in specific software packages?</description>
<pubDate>07 Feb  2012 15:18:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84936</link>
</item><item>
<title>Re: Exploit Pack - Hacking Microsoft Word and Excel</title>
<description>http://www.sendspace.com/file/f8pexd // insectpro when he rmd the other one, i just uploaded it again :-) and i wilm d so, until this product, is pu</description>
<pubDate>07 Feb  2012 12:05:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84932</link>
</item><item>
<title>Re: Vulnerability-lab.com XSS</title>
<description>His story seemed rather odd and BS to begin with so thanks for cleaning that up for much entertainment and ownage. Excellent day to you good sir. On</description>
<pubDate>07 Feb  2012 09:26:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84931</link>
</item><item>
<title>HITB2011KUL - Is The Pen Still Mightier Than The Sword</title>
<description>Title: ====== HITB2011KUL - Is The Pen Still Mightier Than The Sword  Date: ===== 2012-01-18  References: =========== Download:    http://www.vu</description>
<pubDate>07 Feb  2012 08:57:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84930</link>
</item><item>
<title>HITB2011KUL - Chip &amp;amp; PIN - Protocol Analysis EMV POS</title>
<description>Title: ====== HITB2011KUL - Chip &amp;amp; PIN - Protocol Analysis EMV POS  Date: ===== 2012-01-26  References: =========== Download:    http://www.vulne</description>
<pubDate>07 Feb  2012 08:56:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84929</link>
</item><item>
<title>HITB2011KUL - Mobile Malware Analysis</title>
<description>Title: ====== HITB2011KUL - Mobile Malware Analysis  Date: ===== 2012-02-06  References: =========== Download:    http://www.vulnerability-lab.co</description>
<pubDate>07 Feb  2012 08:56:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84928</link>
</item><item>
<title>HITB2011KUL - Post Memory Corruption Analysis</title>
<description>Title: ====== HITB2011KUL - Post Memory Corruption Analysis  Date: ===== 2012-01-26  References: =========== Download:    http://www.vulnerabilit</description>
<pubDate>07 Feb  2012 08:55:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84927</link>
</item><item>
<title>Video =&amp;gt; Google Service Reward #1 - ClickJacking Vulnerability</title>
<description>Title: ====== Google Service Reward #1 - ClickJacking Vulnerability  Date: ===== 2012-02-07  References: =========== Download:    http://www.vuln</description>
<pubDate>07 Feb  2012 08:38:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84926</link>
</item><item>
<title>Video =&amp;gt; Cyberoam Central Console v2.x - File Include Vulnerability</title>
<description>Title: ====== Cyberoam Central Console v2.x - File Include Vulnerability  Date: ===== 2012-02-05  References: =========== Download:    http://www</description>
<pubDate>07 Feb  2012 08:37:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84925</link>
</item><item>
<title>Dinama SMS Service - Persistent Web Vulnerability</title>
<description>Title: ====== Dinama SMS Service - Persistent Web Vulnerability  Date: ===== 2012-02-05  References: =========== http://www.vulnerability-lab.com/ge</description>
<pubDate>07 Feb  2012 08:36:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84924</link>
</item>
</channel>
</rss>

