<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>08 Feb  2012 10:13:44 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>Netbeans Jira Plugin does not check https certificates</title>
<description>Title: ------- Netbeans Jira Plugin does not check https certificates Disclosure Timeline: ----------------------------- [2012-01-02] Vulnerability r</description>
<pubDate>08 Feb  2012 07:21:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84940</link>
</item><item>
<title>Fwd: DVR Security Issue</title>
<description>I tried to report this to the vendor in 2009. SHODAN &amp;quot;OwnServer1.0&amp;quot;: Results 1 - 10 of about 11832 for OwnServer1.0 country:US. -Jason Ellison ----</description>
<pubDate>08 Feb  2012 01:21:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84935</link>
</item><item>
<title>[Announcement] ClubHack Magazine Issue 25, Feb 2012 Released</title>
<description>Dear All, ClubHack Magazine&amp;#039;s Issue-25, Feb 2012 is released. The theme for this issue is Network Exploitation and Security. This issue covers follo</description>
<pubDate>07 Feb  2012 21:25:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84934</link>
</item><item>
<title>Android Multiple Vulnerabilities</title>
<description>Android Multiple Vulnerabilities Author: www.80vul.com [Email:5up3rh3i#gmail.com] Release Date: 2012/2/8 References: http://www.80vul.com/android/a</description>
<pubDate>07 Feb  2012 20:36:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84933</link>
</item><item>
<title>Cyberoam Central Console v2.00.2 - File Include Vulnerability &amp;amp; Video</title>
<description>Title: ====== Cyberoam Central Console v2.00.2 - File Include Vulnerability  Date: ===== 2012-02-08  References: =========== http://www.vulnerabilit</description>
<pubDate>07 Feb  2012 15:24:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84937</link>
</item><item>
<title>posting xss notifications in sites vs software packages</title>
<description>What is the point of posting notifications of XSS vulnerabilities in specific web sites instead of alerts of xss vulns in specific software packages?</description>
<pubDate>07 Feb  2012 15:18:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84936</link>
</item><item>
<title>HITB2011KUL - Is The Pen Still Mightier Than The Sword</title>
<description>Title: ====== HITB2011KUL - Is The Pen Still Mightier Than The Sword  Date: ===== 2012-01-18  References: =========== Download:    http://www.vu</description>
<pubDate>07 Feb  2012 08:57:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84930</link>
</item><item>
<title>HITB2011KUL - Chip &amp;amp; PIN - Protocol Analysis EMV POS</title>
<description>Title: ====== HITB2011KUL - Chip &amp;amp; PIN - Protocol Analysis EMV POS  Date: ===== 2012-01-26  References: =========== Download:    http://www.vulne</description>
<pubDate>07 Feb  2012 08:56:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84929</link>
</item><item>
<title>HITB2011KUL - Mobile Malware Analysis</title>
<description>Title: ====== HITB2011KUL - Mobile Malware Analysis  Date: ===== 2012-02-06  References: =========== Download:    http://www.vulnerability-lab.co</description>
<pubDate>07 Feb  2012 08:56:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84928</link>
</item><item>
<title>HITB2011KUL - Post Memory Corruption Analysis</title>
<description>Title: ====== HITB2011KUL - Post Memory Corruption Analysis  Date: ===== 2012-01-26  References: =========== Download:    http://www.vulnerabilit</description>
<pubDate>07 Feb  2012 08:55:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84927</link>
</item><item>
<title>Video =&amp;gt; Google Service Reward #1 - ClickJacking Vulnerability</title>
<description>Title: ====== Google Service Reward #1 - ClickJacking Vulnerability  Date: ===== 2012-02-07  References: =========== Download:    http://www.vuln</description>
<pubDate>07 Feb  2012 08:38:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84926</link>
</item><item>
<title>Video =&amp;gt; Cyberoam Central Console v2.x - File Include Vulnerability</title>
<description>Title: ====== Cyberoam Central Console v2.x - File Include Vulnerability  Date: ===== 2012-02-05  References: =========== Download:    http://www</description>
<pubDate>07 Feb  2012 08:37:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84925</link>
</item><item>
<title>Dinama SMS Service - Persistent Web Vulnerability</title>
<description>Title: ====== Dinama SMS Service - Persistent Web Vulnerability  Date: ===== 2012-02-05  References: =========== http://www.vulnerability-lab.com/ge</description>
<pubDate>07 Feb  2012 08:36:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84924</link>
</item><item>
<title>Facebook Game Store - SQL Injection Vulnerability</title>
<description>Title: ====== Facebook Game Store - SQL Injection Vulnerability  Date: ===== 2012-02-04  References: =========== http://www.vulnerability-lab.com/ge</description>
<pubDate>07 Feb  2012 08:36:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84923</link>
</item><item>
<title>eFronts Community++ v3.6.10 - Cross Site Vulnerability</title>
<description>Title: ====== eFronts Community++ v3.6.10 - Cross Site Vulnerability  Date: ===== 2012-02-07  References: =========== http://www.vulnerability-lab.c</description>
<pubDate>07 Feb  2012 08:34:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84922</link>
</item><item>
<title>VolksBank Online Banking - Multiple Web Vulnerabilities</title>
<description>Title: ====== VolksBank Online Banking - Multiple Web Vulnerabilities  Date: ===== 2012-02-07  References: =========== http://www.vulnerability-lab.</description>
<pubDate>07 Feb  2012 08:32:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84921</link>
</item><item>
<title>SQL Injection Vulnerability in Batavi 1.1.2</title>
<description>Information -------------------- Name :  SQL Injection Vulnerability in Batavi Software :  Batavi 1.1.2 and possibly below. Vendor Homepage :  http</description>
<pubDate>07 Feb  2012 05:36:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84914</link>
</item><item>
<title>CVE-2012-0803: Apache CXF does not validate UsernameToken policies correctly</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  CVE-2012-0803: Apache CXF does not validate UsernameToken policies correctly Severity: Important Ven</description>
<pubDate>07 Feb  2012 02:39:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84913</link>
</item><item>
<title>Electronic Arts - Cross Site Scripting Vulnerability</title>
<description>Title: ====== Electronic Arts - Cross Site Scripting Vulnerability  Date: ===== 2012-02-06  References: =========== http://www.vulnerability-lab.co</description>
<pubDate>06 Feb  2012 16:37:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84916</link>
</item><item>
<title>Sun Microsystems (Print) - Cross Site Scripting Vulnerability</title>
<description>Title: ====== Sun Microsystems (Print) - Cross Site Scripting Vulnerability  Date: ===== 2012-02-01  References: =========== http://www.vulnerabilit</description>
<pubDate>06 Feb  2012 16:35:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84915</link>
</item><item>
<title>[SECURITY] [DSA 2403-2] php5 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>06 Feb  2012 11:21:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84912</link>
</item><item>
<title>[ MDVSA-2012:014 ] glpi</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>06 Feb  2012 11:03:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84906</link>
</item><item>
<title>TROOPERS12 - Welcome to Heidelberg.</title>
<description>Dear TROOPERS, We call for action for the fifth time in the history of our up-and-coming IT security conferences series. Experts from all around th</description>
<pubDate>06 Feb  2012 03:35:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84901</link>
</item><item>
<title>[SECURITY] [DSA 2405-1] apache2 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>06 Feb  2012 01:06:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84902</link>
</item><item>
<title>Exploit Pack - Hacking Microsoft Word and Excel</title>
<description>This video shows how to exploit a vulnerability in Microsoft Word and Excel by using Exploit Pack 2.1.7. Get you own copy of Exploit Pack from: http</description>
<pubDate>05 Feb  2012 19:25:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84897</link>
</item><item>
<title>NexorONE Online Banking - Multiple Cross Site Vulnerabilities</title>
<description>Title: ====== NexorONE Online Banking - Multiple Cross Site Vulnerabilities  Date: ===== 2012-02-04  References: =========== http://www.vulnerabilit</description>
<pubDate>05 Feb  2012 10:09:49 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84899</link>
</item><item>
<title>[SECURITY] [DSA 2404-1] xen-qemu-dm-4.0 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>05 Feb  2012 04:46:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84885</link>
</item><item>
<title>[SECURITY] [DSA 2384-2] cacti regression</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>04 Feb  2012 09:18:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84881</link>
</item><item>
<title>Advantech/Broadwin HMI/SCADA WebAccess universal network RPC exploit</title>
<description>New exploit for Broadwin/Advantexh HMI/SCADA was published by Zomb1E &amp;amp; amistox07. Exploit is used undocumented features of SCADA. See: http://fuzzyd00</description>
<pubDate>04 Feb  2012 02:42:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84892</link>
</item><item>
<title>[ MDVSA-2012:013 ] mozilla</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>03 Feb  2012 08:54:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84875</link>
</item><item>
<title>Vulnerability-lab.com XSS</title>
<description>Earlier today I tried to contact the people over at http://vulnerability-lab.com about an XSS vulnerability I found on their site (ironic) but it appe</description>
<pubDate>03 Feb  2012 07:21:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84873</link>
</item><item>
<title>MD5 for pre-release advisory / multiple vulnerabilities / Sonexis ConferenceManager</title>
<description>MD5 (20120203-SONEXIS-NETRAGARD.txt) = adde14f01f442022e40decba069e1f3e</description>
<pubDate>03 Feb  2012 06:22:34 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84872</link>
</item><item>
<title>can you answer this?</title>
<description>since no one could answer the last one how bout this. In my FW log Trust (our 10.0.0.0. network) to untrust picked this up: 2012-02-02 10:08:10 7.254</description>
<pubDate>03 Feb  2012 00:20:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84868</link>
</item><item>
<title>RFC 6528 on Defending against Sequence Number Attacks</title>
<description>Folks, FYI. (the RFC is available at: &amp;lt;http://www.rfc-editor.org/rfc/rfc6528.txt&amp;gt;) A new Request for Comments is now available in online RFC librari</description>
<pubDate>02 Feb  2012 20:59:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84856</link>
</item><item>
<title>BSides Detroit 12 Call For Presenters (CFP)</title>
<description>BSides Detroit 12 Call For Presenters (CFP) BSides Detroit (http://bit.ly/BSidesDetroit) brings the BSides community to a new level, to a place it ha</description>
<pubDate>02 Feb  2012 14:52:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84861</link>
</item><item>
<title>[SECURITY] [DSA 2403-1] php5 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>02 Feb  2012 13:29:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84860</link>
</item><item>
<title>Multiple vendor antivirus .kz archive format evasion/bypass vulnerability.</title>
<description>hello,  Multiple vendor antivirus .kz archive format evasion/bypass vulnerability.  DESCRIPTION .kz is a proprietary archive format from an Asian e</description>
<pubDate>02 Feb  2012 13:27:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84864</link>
</item><item>
<title>[SECURITY] [DSA 2402-1] iceape security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>02 Feb  2012 11:53:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84852</link>
</item><item>
<title>[SECURITY] [DSA 2400-1] iceweasel security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>02 Feb  2012 11:52:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84851</link>
</item><item>
<title>Key Internet operator VeriSign hit by hackers [DNS]</title>
<description>http://www.reuters.com/article/2012/02/02/us-hacking-verisign-idUSTRE8110Z820120202 http://www.msnbc.msn.com/id/46238729/ns/technology_and_science-sec</description>
<pubDate>02 Feb  2012 11:49:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84850</link>
</item><item>
<title>[SECURITY] [DSA 2401-1] tomcat6 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>02 Feb  2012 11:29:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84849</link>
</item><item>
<title>NASA Subdomains FCKEditor - Multiple Vulnerabilities</title>
<description>Title: ====== NASA Subdomains FCKEditor - Multiple Vulnerabilities  Date: ===== 2012-01-29  References: =========== http://vulnerability-lab.com/get</description>
<pubDate>02 Feb  2012 09:45:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84859</link>
</item><item>
<title>Achievo v1.4.3 - Multiple Web Vulnerabilities</title>
<description>Title: ====== Achievo v1.4.3 - Multiple Web Vulnerabilities  Date: ===== 2012-01-30  References: =========== http://www.vulnerability-lab.com/get_co</description>
<pubDate>02 Feb  2012 09:44:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84858</link>
</item><item>
<title>OSCommerce v3.0.2 - Persistent Cross Site Vulnerability</title>
<description>Title: ====== OSCommerce v3.0.2 - Persistent Cross Site Vulnerability  Date: ===== 2012-02-02  VL-ID: ===== 407  Introduction: ============= osCom</description>
<pubDate>02 Feb  2012 09:42:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84857</link>
</item><item>
<title>AoF and CSRF vulnerabilities in D-Link DAP 1150</title>
<description>Hello list! I want to warn you about new security vulnerabilities in D-Link DAP 1150 (Wi-Fi Access Point and Router). These are Abuse of Functionali</description>
<pubDate>02 Feb  2012 09:04:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84842</link>
</item><item>
<title>[ MDVSA-2012:012 ] apache</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>02 Feb  2012 07:48:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84841</link>
</item><item>
<title>GLSA (Gentoo Linux Security Advisory) publication changes</title>
<description>Like other Linux distribution vendors, Gentoo is currently CC&amp;#039;ing advisories to the full-disclosure and bugtraq mailing lists. Starting today, we wil</description>
<pubDate>02 Feb  2012 02:57:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84835</link>
</item><item>
<title>WG: hackers.it disappeared from google search results</title>
<description>Hello Davide, its working for me:   regards Heiko  Von:  David3 Gonnella &amp;lt;netevil@hackers.it&amp;gt; An:   full-disclosure@lists.grok.org.uk Datum</description>
<pubDate>02 Feb  2012 02:27:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84836</link>
</item><item>
<title>Chat Embeds -- How Evil Are They???</title>
<description>Folks:        An interesting subject that I have never seen discussed here     but one I want to put on the table....        Appar</description>
<pubDate>01 Feb  2012 23:28:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84830</link>
</item><item>
<title>[CAL-2012-0004] opera array integer overflow</title>
<description>CAL-2012-0004 opera array integer overflow  1 Affected Products ================= 11.60 and prior  2 Vulnerability Details ===================== Co</description>
<pubDate>01 Feb  2012 18:36:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84829</link>
</item><item>
<title>Fwd: IPv6 RA-Guard: Advice on the implementation (feedback requested)</title>
<description>Folks, We have talked about this one quite a few times (including &amp;lt;http://blog.si6networks.com/2011/09/router-advertisement-guard-ra-guard.html&amp;gt;). --</description>
<pubDate>01 Feb  2012 18:17:46 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84828</link>
</item><item>
<title>Fwd: RA-Guard: Advice on the implementation (feedback requested)</title>
<description>Folks, We have talked about this one quite a few times (including &amp;lt;http://blog.si6networks.com/2011/09/router-advertisement-guard-ra-guard.html&amp;gt;). --</description>
<pubDate>01 Feb  2012 18:17:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84827</link>
</item><item>
<title>hackers.it disappeared from google search results</title>
<description>Hello guys, Since few days my domain is out for first tests ..but today it is totally disappeared from Google search results.  Do you know how this</description>
<pubDate>01 Feb  2012 16:25:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84831</link>
</item><item>
<title>Tricky Shellcode</title>
<description>Can anyone help in solving what this shellcode does? \x31\xC0\x50\x68\x70\x79\x71\x78\x68\x72\x77\x27\x71\x68\x77\x79\x74\x74\x68\x25\x72\x25\x24\x68</description>
<pubDate>01 Feb  2012 12:57:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84823</link>
</item><item>
<title>Fun with Bitcoin, or how an exploit can hide in plain sight</title>
<description>So most people on here have probably heard of Bitcoin from somewhere, and most of you have probably got tired of it - but bear with me because this is</description>
<pubDate>01 Feb  2012 07:05:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84822</link>
</item><item>
<title>Sonexis ConferenceManager Exploit MD5 - 20120131</title>
<description>MD5 (soNoExis.rb.orig) = 6f0e38ef112f10cc1b1fe5437ef3970d</description>
<pubDate>31 Jan  2012 18:58:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84821</link>
</item><item>
<title>interesting need answer</title>
<description>i was working with cleaning up &amp;quot;any to any&amp;quot; on fw. ran across inside ips doing netbios (NS) , and one using port 4330 to 7.8.0.106, or .107. a who is</description>
<pubDate>31 Jan  2012 12:47:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84820</link>
</item><item>
<title>[SECURITY] [DSA 2399-2] php5 regression fix</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>31 Jan  2012 07:26:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84814</link>
</item><item>
<title>[SECURITY] [DSA 2399-1] php5 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>30 Jan  2012 23:22:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84813</link>
</item><item>
<title>VMSA-2012-0001 VMware ESXi and ESX updates to third party library and ESX Service Console</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  ----------------------------------------------------------------------          VMware Secur</description>
<pubDate>30 Jan  2012 22:57:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84811</link>
</item><item>
<title>[SECURITY] [DSA 2398-1] curl security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>30 Jan  2012 11:49:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84809</link>
</item><item>
<title>ZDI-12-020 : IBM SPSS VsVIEW6.ocx ActiveX Control Multiple Methods Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-020 : IBM SPSS VsVIEW6.ocx ActiveX Control Multiple Methods Remote Code Execution Vulnerability</description>
<pubDate>30 Jan  2012 10:34:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84807</link>
</item><item>
<title>ZDI-12-019 : IBM SPSS mraboutb.dll ActiveX Control SetLicenseInfoEx Method Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-019 : IBM SPSS mraboutb.dll ActiveX Control SetLicenseInfoEx Method Remote Code Execution Vulner</description>
<pubDate>30 Jan  2012 10:33:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84806</link>
</item><item>
<title>Advisory: sudo 1.8 Format String Vulnerability</title>
<description>Hi, FYI, see attached. cheers, joernchen -- joernchen ~ Phenoelit &amp;lt;joernchen@phenoelit.de&amp;gt; ~ C776 3F67 7B95 03BF 5344 http://www.phenoelit.de ~ A</description>
<pubDate>30 Jan  2012 05:56:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84801</link>
</item><item>
<title>Fw: Fw: honeypots</title>
<description>http://www.sans.org/security-resources/idfaq/honeypot3.php good paper on how to build your own and some links to commercial products.  Sorry for the</description>
<pubDate>30 Jan  2012 05:35:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84797</link>
</item><item>
<title>Fw: honeypots</title>
<description>winnie the pooh would know... (had to) bma  ----- Original Message ----- From: lallantada@tvazteca.com.mx To: J. von Balzac Cc: Full Disclosure ;</description>
<pubDate>30 Jan  2012 04:55:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84796</link>
</item><item>
<title>[ GLSA 201201-19 ] Adobe Reader: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 201201-19 - - -</description>
<pubDate>30 Jan  2012 04:45:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84795</link>
</item><item>
<title>[ GLSA 201201-18 ] bip: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 201201-18 - - -</description>
<pubDate>30 Jan  2012 04:44:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84794</link>
</item><item>
<title>This is when piracy/theft become expression of freedom</title>
<description>The thing that makes me laugh about all of this, and one of the key things I learned from reading Gibbon&amp;#039;s Decline &amp;amp; Fall is this: The number and fre</description>
<pubDate>29 Jan  2012 15:18:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84773</link>
</item><item>
<title>Exploit Pack - New video - Ultimate 2.1</title>
<description>Exploit Pack - New video! Release - Ultimate 2.1 Check it out! http://www.youtube.com/watch?v=4TrsFry13TU Exploit Pack Team http://exploitpack.com</description>
<pubDate>29 Jan  2012 14:40:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84774</link>
</item><item>
<title>[ MDVSA-2012:011 ] openssl</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Advi</description>
<pubDate>29 Jan  2012 11:25:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84771</link>
</item><item>
<title>Fw: Fw: when did piracy/theft become expressionoffreedom</title>
<description>from the wikipedia link... &amp;quot;An illegal prime is a kind of illegal number&amp;quot;  kind of? Just like pot is &amp;quot;kind of&amp;quot; illegal by the feds standards? just l</description>
<pubDate>29 Jan  2012 04:41:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84767</link>
</item><item>
<title>[SECURITY] [DSA 2397-1] icu security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>29 Jan  2012 04:38:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84768</link>
</item><item>
<title>Fw: when did piracy/theft become expression offreedom</title>
<description>Metallica used to encourage fans to record &amp;quot;bootlegs&amp;quot; and share with those who didnt/wouldnt/couldnt attend the shows. Now look at them:-( Metallica</description>
<pubDate>29 Jan  2012 03:35:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84765</link>
</item><item>
<title>google permit to remove the pictures from your blog if you link your gmail account with an android mobile phone</title>
<description>Could sound not so useful...fancy... what you want... but if you link a gmail account with a blog... on an android mobile phone... and you visit for</description>
<pubDate>28 Jan  2012 15:54:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84760</link>
</item><item>
<title>..twitter rights</title>
<description>is posting attacking us gov site, or exposing personal info of another on twitter a freedom on speech/full disclosure? Twitter is the main voice of a</description>
<pubDate>28 Jan  2012 10:39:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84747</link>
</item><item>
<title>FAA US Academy (AFS) - Auth Bypass Vulnerability</title>
<description>Title: ====== FAA US Academy (AFS) - Auth Bypass Vulnerability  Date: ===== 2012-01-28  References: =========== http://vulnerability-lab.com/get_con</description>
<pubDate>28 Jan  2012 04:43:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84786</link>
</item><item>
<title>ME Monitoring Manager v9.x; v10.x - Multiple Vulnerabilities</title>
<description>Title: ====== ME Monitoring Manager v9.x; v10.x - Multiple Vulnerabilities  Date: ===== 2012-01-27  References: =========== http://www.vulnerability</description>
<pubDate>28 Jan  2012 04:42:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84785</link>
</item><item>
<title>eBank IT Online Banking - Multiple Web Vulnerabilities</title>
<description>Title: ====== eBank IT Online Banking - Multiple Web Vulnerabilities  Date: ===== 2012-01-26  References: =========== http://www.vulnerability-lab.c</description>
<pubDate>28 Jan  2012 04:40:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84784</link>
</item><item>
<title>FatCat Auto SQLl Injector</title>
<description>This is an automatic SQL Injection tool called as FatCat, Use of FatCat for testing your web application and exploit your application more deeper. Fat</description>
<pubDate>28 Jan  2012 00:25:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84745</link>
</item><item>
<title>[ GLSA 201201-17 ] Chromium: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 201201-17 - - -</description>
<pubDate>27 Jan  2012 19:56:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84744</link>
</item><item>
<title>[ GLSA 201201-16 ] X.Org X Server/X Keyboard Configuration Database: Screen lock bypass</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 201201-16 - - -</description>
<pubDate>27 Jan  2012 13:59:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84740</link>
</item><item>
<title>honeypots</title>
<description>i am looking for a good honeypot  thanks</description>
<pubDate>27 Jan  2012 10:56:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84787</link>
</item><item>
<title>[SECURITY] [DSA 2396-1] qemu-kvm security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>27 Jan  2012 10:37:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84739</link>
</item><item>
<title>[SECURITY] [DSA 2395-1] wireshark security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>27 Jan  2012 10:10:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84737</link>
</item><item>
<title>Advisory: Remote Command Execution in Gitorious</title>
<description>Hi, FYI, see attached. cheers, joernchen -- joernchen ~ Phenoelit &amp;lt;joernchen@phenoelit.de&amp;gt; ~ C776 3F67 7B95 03BF 5344 http://www.phenoelit.de ~ A</description>
<pubDate>27 Jan  2012 09:50:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84735</link>
</item><item>
<title>[ GLSA 201201-15 ] ktsuss: Privilege escalation</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 201201-15 - - -</description>
<pubDate>27 Jan  2012 07:05:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84733</link>
</item><item>
<title>Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities</title>
<description>Title: ====== Fortigate UTM WAF Appliance - Multiple Web Vulnerabilities  Date: ===== 2012-01-27  References: =========== http://vulnerability-lab.c</description>
<pubDate>27 Jan  2012 05:52:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84734</link>
</item><item>
<title>Fw: when did piracy/theft become expression of freedom</title>
<description>when you enter piracy into google the 1st link is the piratebay... dictionary.com- 1. practice of a pirate; robbery or illegal violence at sea. 2. t</description>
<pubDate>27 Jan  2012 01:03:51 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84723</link>
</item><item>
<title>when did piracy/theft become expression of freedom</title>
<description>im going to the &amp;#039;benz dealer in the morning to express my 1st amendment right... The Somalians are learning the hard way that it just isnt so... bma</description>
<pubDate>27 Jan  2012 00:24:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84720</link>
</item><item>
<title>[SECURITY] [DSA 2394-1] libxml2 security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>26 Jan  2012 14:46:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84730</link>
</item><item>
<title>[HITB-Announce] Reminder: HITB2012AMS Call For Papers Closing Soon</title>
<description>This is a gentle reminder that the Call for Papers for the third annual HITBSecConf in Europe closes on the 18th of February! Send in your submissions</description>
<pubDate>26 Jan  2012 14:17:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84719</link>
</item><item>
<title>Multiple new vulnerabilities in Register Plus for WordPress</title>
<description>Hello list! I want to warn you about multiple new vulnerabilities in plugin Register Plus for WordPress. These are Cross-Site Scripting, Code Execut</description>
<pubDate>26 Jan  2012 11:07:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84717</link>
</item><item>
<title>Cisco Security Advisory: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA256 Cisco Security Advisory: Cisco IronPort Appliances Telnet Remote Code Execution Vulnerability Adviso</description>
<pubDate>26 Jan  2012 09:49:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84713</link>
</item><item>
<title>DNS bind attacks</title>
<description>I&amp;#039;m seeing a lot of hosts in my named logs (I mean log files, it&amp;#039;s not like I am naming my poop) ...ok... silly joke hehe So anyway, named bind is r</description>
<pubDate>26 Jan  2012 03:35:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84704</link>
</item><item>
<title>Re: Fuckloads...</title>
<description>i will destroy FD this year, mark these words.  On 26 January 2012 10:19, Richard Golodner &amp;lt;rgolodner@infratection.com&amp;gt; wrote: &amp;gt; On Thu, 2012-01-26</description>
<pubDate>25 Jan  2012 15:27:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84694</link>
</item><item>
<title>ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 ZDI-12-018 : Symantec PCAnywhere awhost32 Remote Code Execution Vulnerability http://www.zerodayinitiat</description>
<pubDate>25 Jan  2012 09:33:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84665</link>
</item><item>
<title>[SECURITY] [DSA-2393-1] bip security update</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------- Debian Security Advisory DS</description>
<pubDate>25 Jan  2012 07:56:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84670</link>
</item><item>
<title>NX Web Companion Spoofing Arbitrary Code Execution Vulnerability</title>
<description># Vuln Title: NX Web Companion Spoofing Arbitrary Code Execution # Vulnerability # Date: 25.01.2012 # Author: otr # Software Link: http://www.nomachin</description>
<pubDate>25 Jan  2012 07:43:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84676</link>
</item><item>
<title>Acolyte CMS v1.5 and v6.3 - SQL Injection Vulnerabilities</title>
<description>Title: ====== Acolyte CMS v1.5 and v6.3 - SQL Injection Vulnerabilities  Date: ===== 2012-01-25  References: =========== http://www.vulnerability-la</description>
<pubDate>25 Jan  2012 07:37:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/84669</link>
</item>
</channel>
</rss>

