<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>24 Jul  2008 12:45:23 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>SPAM from Tobesecurity.com</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Hi people, just to let other forum/blog/wiki admins out there that some people from tobesecurity.com</description>
<pubDate>24 Jul  2008 09:55:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62763</link>
</item><item>
<title>Signs of compromised DNS?</title>
<description>Anyone have any idea what signs would be if a DNS server is compromised? Been seeing: 08:39:28 homebox named[27]: client *.*.143.11#10053: query (cac</description>
<pubDate>24 Jul  2008 07:41:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62759</link>
</item><item>
<title>Comments on: DNS exploit code is in the wild</title>
<description>by n3td3v July 24, 2008 6:59 AM I guess HD Moore doesn&amp;#039;t like Dan Kaminsky very much since he told people like HD Moore not to release such code unt</description>
<pubDate>24 Jul  2008 07:21:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62757</link>
</item><item>
<title>ladies</title>
<description>Ladies of the internet. We salute you. How does it feel having a low self-esteem. How does it feel to not have a life worth living. Notice these are</description>
<pubDate>24 Jul  2008 03:51:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62755</link>
</item><item>
<title>[SECURITY] [DSA 1616-1] new clamav packages fix denial of service</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>24 Jul  2008 00:36:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62754</link>
</item><item>
<title>CAU-EX-2008-0003: Kaminsky DNS Cache Poisoning Flaw Exploit for	Domains</title>
<description>____   ____   __  __           /  \  /  \  | | | |     ----====####/ /\__\##/ /\ \##| |##| |####====----</description>
<pubDate>23 Jul  2008 20:48:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62753</link>
</item><item>
<title>CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning Flaw Exploit</title>
<description>____   ____   __  __           /  \  /  \  | | | |     ----====####/ /\__\##/ /\ \##| |##| |####====----</description>
<pubDate>23 Jul  2008 16:34:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62752</link>
</item><item>
<title>[ MDVSA-2008:154 ] - Updated xemacs packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>23 Jul  2008 16:29:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62751</link>
</item><item>
<title>[tool] SDT Cleaner 1.0</title>
<description>Hello! You can find it here: http://oss.coresecurity.com/projects/sdtcleaner.html Package: http://oss.coresecurity.com/repo/SDTCleaner-v1.0.zip  Wh</description>
<pubDate>23 Jul  2008 15:49:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62749</link>
</item><item>
<title>[ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>23 Jul  2008 14:56:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62748</link>
</item><item>
<title>DNS forward only: why does it help?</title>
<description>As a workaround, it is recommended to set DNS servers to forward only. Can someone explain why that helps? Cannot responses from the forwarder be spoo</description>
<pubDate>23 Jul  2008 14:28:15 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62747</link>
</item><item>
<title>[SECURITY] [DSA 1615-1] New xulrunner packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Jul  2008 13:33:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62744</link>
</item><item>
<title>[SECURITY] [DSA 1614-1] New iceweasel packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Jul  2008 13:07:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62743</link>
</item><item>
<title>[USN-628-1] PHP vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-628-1       July 23, 2008 php5 vulnerabilities CVE-2007</description>
<pubDate>23 Jul  2008 12:39:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62742</link>
</item><item>
<title>[SECURITY] [DSA 1540-3] New lighttpd packages fix regression</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>23 Jul  2008 11:59:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62746</link>
</item><item>
<title>Is the security industry like a lemon market?</title>
<description>This pair of essays were written in 4 hours the night before they were due for last year&amp;#039;s Cyber Security Awareness Week at Polytechnic University. Th</description>
<pubDate>23 Jul  2008 11:40:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62740</link>
</item><item>
<title>Vim: Flawed Fix of Arbitrary Code Execution Vulnerability in filetype.vim</title>
<description>1. SUMMARY Product : Vim -- Vi IMproved Version : Tested with Vim 7.2b.10, filetype.vim 2008-07-17 Impact  : Arbitrary code execution Wherefrom: L</description>
<pubDate>23 Jul  2008 11:29:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62739</link>
</item><item>
<title>Vulnerability Report: EMC Centera Universal Access</title>
<description>adMERITia Vulnerability Report Vulnerability Information Vendor: EMC˛ Product: Centera Universal Access Version: CUA4.0_4735.p4 Vulnerability Type:</description>
<pubDate>23 Jul  2008 10:09:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62745</link>
</item><item>
<title>Pin Pop... (ATM Pins?)</title>
<description>&amp;gt; I have a buddy that is soliciting for help researching PIN numbers  &amp;gt; used in &amp;gt; ATM&amp;#039;s and things of that nature. He is in need of data-sets for  &amp;gt;</description>
<pubDate>22 Jul  2008 20:10:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62729</link>
</item><item>
<title>AST-2008-011: Traffic amplification in IAX2 firmware provisioning system</title>
<description>Asterisk Project Security Advisory - AST-2008-011   +------------------------------------------------------------------------+  |   Product</description>
<pubDate>22 Jul  2008 16:16:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62727</link>
</item><item>
<title>AST-2008-010: Asterisk IAX &amp;#039;POKE&amp;#039; resource exhaustion</title>
<description>Asterisk Project Security Advisory - AST-2008-010   +------------------------------------------------------------------------+  |    Product</description>
<pubDate>22 Jul  2008 16:15:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62726</link>
</item><item>
<title>[ MDVSA-2008:152 ] - Updated wireshark packages fix denial of service vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>22 Jul  2008 16:07:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62725</link>
</item><item>
<title>[USN-627-1] Dnsmasq vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-627-1       July 22, 2008 dnsmasq vulnerability CVE-200</description>
<pubDate>22 Jul  2008 09:37:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62710</link>
</item><item>
<title>PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profile page</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profile page Vulnerability found: 25/06/2008</description>
<pubDate>22 Jul  2008 08:59:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62713</link>
</item><item>
<title>PR08-15: Several Webroot Disclosures on Moodle</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-15: Several Webroot Disclosures on Moodle Vulnerability found: 20/06/2008 Vendor informed: 25/06</description>
<pubDate>22 Jul  2008 08:48:39 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62715</link>
</item><item>
<title>PR08-13: Persistent Cross-site Scripting (XSS) on Moodle via blog entry title</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 PR08-13: Persistent Cross-site Scripting (XSS) on Moodle via blog entry title Vulnerability found: 20/</description>
<pubDate>22 Jul  2008 08:46:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62714</link>
</item><item>
<title>Re: help: I need to crack my box (Lucio Crusca)</title>
<description>&amp;gt; razi garbie wrote: &amp;gt; &amp;gt;&amp;gt; Are you sure that a 0day is even needed? perhaps its a rather old &amp;gt;&amp;gt; kernel thats locally exploitable? &amp;gt;&amp;gt; shell# uname -r &amp;gt;</description>
<pubDate>22 Jul  2008 04:09:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62697</link>
</item><item>
<title>Dan Kaminsky wants podcast with n3td3v</title>
<description>---------- Forwarded message ---------- From: Dan Kaminsky &amp;lt;dan@doxpara.com&amp;gt; Date: Sun, Jul 20, 2008 at 7:16 AM Subject: you know... To: xploitable@gm</description>
<pubDate>22 Jul  2008 01:09:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62695</link>
</item><item>
<title>[SECURITY] [DSA 1613-1] new libgd2 packages fix multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>22 Jul  2008 00:01:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62712</link>
</item><item>
<title>The cat is indeed out of the bag</title>
<description>from chargen 19/udp by ecopeland 0. The cat is out of the bag. Yes, Halvar Flake figured out the flaw Dan Kaminsky will announce at Black Hat. 1.</description>
<pubDate>21 Jul  2008 19:36:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62716</link>
</item><item>
<title>[ MDVSA-2008:151 ] - Updated libxslt packages fix buffer overflow vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>21 Jul  2008 18:49:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62691</link>
</item><item>
<title>NULL pointer in ZDaemon 1.08.07</title>
<description>#######################################################################                Luigi Auriemma Application: ZDaemon</description>
<pubDate>21 Jul  2008 16:02:21 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62687</link>
</item><item>
<title>Kaminsky&amp;#039;s DNS Issue Leaked?</title>
<description>It appears matasano posted an explanation of Dan Kaminsky&amp;#039;s DNS issue to their blog today, but looks like it may have been yanked back down. My googl</description>
<pubDate>21 Jul  2008 15:56:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62688</link>
</item><item>
<title>[ GLSA 200807-12 ] BitchX: Multiple vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>21 Jul  2008 15:08:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62686</link>
</item><item>
<title>help: I need to crack my box</title>
<description>Believe it or not, I have a linux box (mine, yes it&amp;#039;s mine) I need to own... the problem is that it phisically resides a few 100km from here and someo</description>
<pubDate>21 Jul  2008 13:47:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62689</link>
</item><item>
<title>[ GLSA 200807-11 ] PeerCast: Buffer overflow</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>21 Jul  2008 12:52:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62685</link>
</item><item>
<title>[ GLSA 200807-10 ] Bacula: Information disclosure</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisor</description>
<pubDate>21 Jul  2008 11:08:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62684</link>
</item><item>
<title>[SECURITY] [DSA 1612-1] New ruby1.8 packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>21 Jul  2008 10:29:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62682</link>
</item><item>
<title>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 NULL-Pointer reference Denial of Service Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 NULL-Pointer reference Denial of Service Vulnerability http://www.fortiguardcenter.com/advis</description>
<pubDate>21 Jul  2008 06:49:25 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62678</link>
</item><item>
<title>FGA-2008-16: EMC Dantz Retrospect 7 backup Server Authentication Module Weak Password Hash Arithmetic Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Server Authentication Module Weak Password Hash Arithmetic Vulnerability http://www.fortiguardcenter.com/ad</description>
<pubDate>21 Jul  2008 06:47:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62679</link>
</item><item>
<title>EMC Dantz Retrospect 7 backup Client PlainText Password Hash Disclosure Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Client PlainText Password Hash Disclosure Vulnerability http://www.fortiguardcenter.com/advisory/FGA-2008-1</description>
<pubDate>21 Jul  2008 06:45:55 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62681</link>
</item><item>
<title>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 Remote Memory corruption Vulnerability</title>
<description>FGA-2008-16: EMC Dantz Retrospect 7 backup Client 7.5.116 Remote Memory corruption Vulnerability http://www.fortiguardcenter.com/advisory/FGA-2008-16.</description>
<pubDate>21 Jul  2008 06:44:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62680</link>
</item><item>
<title>2600 Last Hope Conference NYC</title>
<description>Hi all, I checked out the Last Hope Conf this weekend and it was friggin sweet, anyone else checked it out and if so what talks you like? Sent from m</description>
<pubDate>20 Jul  2008 18:06:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62675</link>
</item><item>
<title>[White Paper] Abusing HTML 5 Structured Client-side Storage</title>
<description>The aim of this white paper is to analyze security implications of the  new HTML 5 client-side storage technology, showing how different  attacks ca</description>
<pubDate>20 Jul  2008 17:32:26 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62674</link>
</item><item>
<title>[ MDVSA-2008:150 ] - Updated mysql packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>19 Jul  2008 16:06:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62672</link>
</item><item>
<title>[ MDVSA-2008:149 ] - Updated mysql packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>19 Jul  2008 12:42:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62670</link>
</item><item>
<title>Torvalds attacks IT industry &amp;#039;security circus&amp;#039;</title>
<description>The maker of Linux was right, &amp;quot;In an e-mail to the Linux kernel developer mailing list, Torvalds said a section of the security industry was dedicate</description>
<pubDate>19 Jul  2008 11:27:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62669</link>
</item><item>
<title>Oracle Database Local Untrusted Library Path Vulnerability</title>
<description>Oracle Database Local Untrusted Library Path Vulnerability ---------------------------------------------------------- The Oracle July 2008 Critical P</description>
<pubDate>19 Jul  2008 08:08:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62667</link>
</item><item>
<title>rPSA-2008-0231-1 bind bind-utils</title>
<description>rPath Security Advisory: 2008-0231-1 Published: 2008-07-19 Products:   rPath Linux 2 Rating: Major Exposure Level Classification:   Remote System</description>
<pubDate>19 Jul  2008 07:31:24 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62668</link>
</item><item>
<title>Fwd: Stop The 70% Lie</title>
<description>---------- Forwarded message ---------- From: n3td3v &amp;lt;xploitable@gmail.com&amp;gt; Date: Sat, Jul 19, 2008 at 12:13 AM Subject: Re: Stop The 70% Lie To: The</description>
<pubDate>18 Jul  2008 18:56:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62665</link>
</item><item>
<title>rPSA-2008-0230-1 bind bind-utils</title>
<description>rPath Security Advisory: 2008-0230-1 Published: 2008-07-18 Products:   rPath Linux 1 Rating: Major Exposure Level Classification:   Remote System</description>
<pubDate>18 Jul  2008 12:56:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62662</link>
</item><item>
<title>AFK from full-disclosure</title>
<description>I am reachable 0nly @ two addresses from now on: http://www.milw0rm.com http://www.com-winner.com Thanks n3td3v</description>
<pubDate>18 Jul  2008 10:58:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62666</link>
</item><item>
<title>AFK from fool-disclosure</title>
<description>I am reachable 0nly @ two addresses: http://www.milw0rm.com http://www.com-winner.com Thanks n3td3v  Signed, KingCope</description>
<pubDate>18 Jul  2008 10:13:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62663</link>
</item><item>
<title>Lateral SQL Injection Revisited - No Special Privs Required</title>
<description>At the end of April 2008 I published a paper about a new class of flaw in Oracle entitled &amp;quot;Lateral SQL Injection&amp;quot;.  The paper can be found here: http</description>
<pubDate>18 Jul  2008 07:03:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62658</link>
</item><item>
<title>[ MDVSA-2008:148 ] - Updated Firefox packages fix vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>17 Jul  2008 17:51:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62655</link>
</item><item>
<title>Re: [funsec] Stop The 70% Lie</title>
<description>On Thu, 17 Jul 2008, The Security Community wrote: &amp;gt; http://70percenters.googlepages.com/ &amp;gt; &amp;gt; &amp;quot;The FBI estimates that about 70 percent of all computer</description>
<pubDate>17 Jul  2008 17:18:11 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62656</link>
</item><item>
<title>Stop The 70% Lie</title>
<description>http://70percenters.googlepages.com/ &amp;quot;The FBI estimates that about 70 percent of all computer security breaches are perpetrated by insiders.&amp;quot; For ye</description>
<pubDate>17 Jul  2008 16:29:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62654</link>
</item><item>
<title>Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution</title>
<description>1. Summary Product : Vim -- Vi IMproved Versions : 5.0--current, possibly older; 4.6 and 3.0 not vulnerable Impact  : Arbitrary code execution Wher</description>
<pubDate>17 Jul  2008 15:54:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62653</link>
</item><item>
<title>ZDI-08-044: Mozilla Firefox CSSValue Array Memory Corruption Vulnerability</title>
<description>ZDI-08-044: Mozilla Firefox CSSValue Array Memory Corruption Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-08-044 July 17, 2008 -- CV</description>
<pubDate>17 Jul  2008 12:17:58 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62648</link>
</item><item>
<title>ZDI-08-043: Sun Java Web Start vm args Stack Buffer Overflow</title>
<description>ZDI-08-043: Sun Java Web Start vm args Stack Buffer Overflow http://www.zerodayinitiative.com/advisories/ZDI-08-043 July 17, 2008 -- Affected Vendors</description>
<pubDate>17 Jul  2008 12:17:41 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62650</link>
</item><item>
<title>ZDI-08-042: Sun Java Web Start Sandbox Bypass Vulnerability</title>
<description>ZDI-08-042: Sun Java Web Start Sandbox Bypass Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-08-042 July 17, 2008 -- Affected Vendors:</description>
<pubDate>17 Jul  2008 12:17:22 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62649</link>
</item><item>
<title>DNS spoofing issue. Thoughts on potential exploits</title>
<description>Hi, I am troubled by these kinds of solutions which only help administrators with standard distributions. Any kind of deviation from the norm, and it</description>
<pubDate>17 Jul  2008 08:59:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62645</link>
</item><item>
<title>[USN-623-1] Firefox vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-623-1       July 17, 2008 firefox vulnerabilities CVE-2</description>
<pubDate>17 Jul  2008 08:10:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62644</link>
</item><item>
<title>ekoparty security trainings (2008) announcement</title>
<description>ekoparty 4th edition - www.ekoparty.com.ar Information Security/Insecurity Conference. October 2 and 3, 2008 Ciudad Autonoma de Buenos Aires - Argenti</description>
<pubDate>16 Jul  2008 21:16:56 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62635</link>
</item><item>
<title>n3td3v</title>
<description>I&amp;#039;m sick of your punk-ass shit. Why don&amp;#039;t you go fag up some other list. Go back to slashdot you pussy nerd. Quit faggin up my email inbox you queer.</description>
<pubDate>16 Jul  2008 19:02:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62634</link>
</item><item>
<title>Oracle DB security contact email address?</title>
<description>Anyone have it? _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure</description>
<pubDate>16 Jul  2008 16:22:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62632</link>
</item><item>
<title>Oracle Portal XSS fixed by CPU July 2008</title>
<description>Class: Input Validation Error Risk: Low Remote: Yes Oracle has just released CPU July 2008 critical patch that fixes a flaw which allows code inject</description>
<pubDate>16 Jul  2008 15:26:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62629</link>
</item><item>
<title>rPSA-2008-0035-1 httpd mod_ssl</title>
<description>rPath Security Advisory: 2008-0035-1 Published: 2008-07-16 Products:   rPath Appliance Platform Linux Service 1   rPath Linux 1 Rating: Minor Exp</description>
<pubDate>16 Jul  2008 13:43:10 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62628</link>
</item><item>
<title>Traversing Dan&amp;#039;s directory - DNS statistics right from the source</title>
<description>Hi, if you want to see some graphs on how many DNS servers are fixed at the moment (or rather, how many are not) based on statistics I got right from</description>
<pubDate>16 Jul  2008 12:54:35 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62624</link>
</item><item>
<title>IETF Internet-Draft on TCP Port randomization</title>
<description>Folks, We are currently working on a revision of our port randomization IETF Internet-Draft. The current version is available at: http://www.ietf.</description>
<pubDate>16 Jul  2008 12:23:28 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62622</link>
</item><item>
<title>[SECURITY] [DSA 1611-1] New afuse packages fix privilege escalation</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>16 Jul  2008 12:18:32 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62627</link>
</item><item>
<title>[SECURITY] [DSA 1544-2] New pdns-recursor packages fix predictable randomness</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>16 Jul  2008 12:09:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62619</link>
</item><item>
<title>n.runs-SA-2008.003 - Quicktime - Arbitrary Code Execution (remote)</title>
<description>n.runs AG http://www.nruns.com/               security(at)nruns.com n.runs-SA-2008.003                      16-Jul</description>
<pubDate>16 Jul  2008 09:14:16 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62618</link>
</item><item>
<title>Linux&amp;#039;s unofficial security-through-coverup policy</title>
<description>Hi all, I doubt many of you are following the &amp;quot;discussions&amp;quot; (if they can be called that) that have been going on on LWN for the past couple weeks r</description>
<pubDate>16 Jul  2008 06:44:37 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62617</link>
</item><item>
<title>n.runs-SA-2008.002 - F-Prot Out-of-Bound Memory Access DoS (remote)</title>
<description>n.runs AG http://www.nruns.com/               security(at)nruns.com n.runs-SA-2008.002                     16-Jul-2</description>
<pubDate>16 Jul  2008 05:11:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62616</link>
</item><item>
<title>Arbitrary code execution in Netrw version 127, Vim 7.2b</title>
<description>1. Summary Product : Vim -- Vi IMproved, Netrw Version : Tested with Vim 7.2b, Netrw 127 Impact  : Arbitrary code execution Wherefrom: Local, poss</description>
<pubDate>16 Jul  2008 04:53:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62615</link>
</item><item>
<title>Vim: Improper Implementation of shellescape()/Arbitrary Code Execution</title>
<description>1. Summary Product : Vim -- Vi IMproved Version : &amp;gt;= 7.2a.013; tested with 7.2b Impact  : Arbitrary code execution Wherefrom: Local, possibly remo</description>
<pubDate>16 Jul  2008 04:53:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62614</link>
</item><item>
<title>[ MDVSA-2008:147 ] - Updated pcre packages fix vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>15 Jul  2008 23:57:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62609</link>
</item><item>
<title>OwnTheBox @ DC16: Pwning for dollars</title>
<description>OwnTheBox, now in year 0x01, continues its hallowed tradition of creating temporary autonomous zones comprised of random people asking to be haxored</description>
<pubDate>15 Jul  2008 22:25:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62608</link>
</item><item>
<title>[USN-625-1] Linux kernel vulnerabilities</title>
<description>=========================================================== Ubuntu Security Notice USN-625-1       July 15, 2008 linux, linux-source-2.6.15/20/</description>
<pubDate>15 Jul  2008 19:04:18 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62610</link>
</item><item>
<title>[ MDVSA-2008:146 ] - Updated poppler packages fix arbitrary code execution vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>15 Jul  2008 16:58:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62595</link>
</item><item>
<title>everything</title>
<description>is pointless. lets all overdose and die. _______________________________________________ Full-Disclosure - We believe in it. Charter: http://lists.g</description>
<pubDate>15 Jul  2008 15:57:03 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62590</link>
</item><item>
<title>iDefense Security Advisory 07.15.08: Oracle Database Local Untrusted Library Path Vulnerability</title>
<description>iDefense Security Advisory 07.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 15, 2008 I. BACKGROUND Oracle Database Server is a fa</description>
<pubDate>15 Jul  2008 15:12:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62585</link>
</item><item>
<title>iDefense Security Advisory 07.15.08: Oracle Database DBMS_AQELM Package Buffer Overflow Vulnerability</title>
<description>iDefense Security Advisory 07.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 15, 2008 I. BACKGROUND Oracle Database Server is a fa</description>
<pubDate>15 Jul  2008 15:11:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62584</link>
</item><item>
<title>iDefense Security Advisory 07.15.08: Oracle Internet Directory Pre-Authentication LDAP DoS Vulnerability</title>
<description>iDefense Security Advisory 07.15.08 http://labs.idefense.com/intelligence/vulnerabilities/ Jul 15, 2008 I. BACKGROUND Internet Directory is Oracle&amp;#039;s</description>
<pubDate>15 Jul  2008 15:10:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62586</link>
</item><item>
<title>[ GLSA 200807-09 ] Mercurial: Directory traversal</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200807-09 - - -</description>
<pubDate>15 Jul  2008 15:08:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62583</link>
</item><item>
<title>Oracle Application Server PLSQL injection flaw</title>
<description>NGSSoftware Insight Security Research Advisory Name: PLSQL Injection in Oracle Application Server Systems Affected: Oracle Application Server 9.0.4.3</description>
<pubDate>15 Jul  2008 13:24:06 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62582</link>
</item><item>
<title>[SECURITY] [DSA 1569-3] New cacti packages fix regression</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>15 Jul  2008 12:05:33 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62588</link>
</item><item>
<title>Kaminsky DNS bug leaked</title>
<description>Dino Dai Zovi finally spilled the beans: http://twitter.com/dinodaizovi/statuses/858981957 _______________________________________________ Full-Discl</description>
<pubDate>15 Jul  2008 11:17:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62574</link>
</item><item>
<title>[SECURITY] [DSA 1610-1] New gaim packages fix execution of arbitrary code</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>15 Jul  2008 10:46:45 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62571</link>
</item><item>
<title>[SECURITY] [DSA 1609-1] New lighttpd packages fix multiple DOS issues</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>15 Jul  2008 10:39:09 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62572</link>
</item><item>
<title>Re: DNS Cache Dan Kamikaze (Actual Exploit	Discussion)</title>
<description>Ureleet wrote: &amp;gt; there can be no actual exploit discussion unless you have dan on the &amp;gt; thread. dan? &amp;gt; &amp;gt; On Sun, Jul 13, 2008 at 3:50 PM, eugaaa@gmai</description>
<pubDate>15 Jul  2008 07:28:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62567</link>
</item><item>
<title>Kon-Boot v.1.0 - booting-time ultimate linux hacking utility ; )</title>
<description>Hello,  Kon-Boot is an prototype piece of software which allows to change contents of a linux kernel on the fly (while booting). In the current com</description>
<pubDate>15 Jul  2008 03:27:29 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62565</link>
</item><item>
<title>[ MDVSA-2008:145 ] - Updated bluez/bluez-utils packages fix SDP packet parsing vulnerability</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1  _______________________________________________________________________  Mandriva Linux Security Adv</description>
<pubDate>14 Jul  2008 21:48:00 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62557</link>
</item><item>
<title>Open Security Foundation To Maintain Attrition.org&amp;#039;s Data Loss Database - Open Source</title>
<description>RICHMOND, VA, July 14, 2008 - The Open Security Foundation (OSF) is pleased to announce that the DataLossDB (also known as the Data Loss Database -</description>
<pubDate>14 Jul  2008 20:55:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62566</link>
</item><item>
<title>[USN-624-1] PCRE vulnerability</title>
<description>=========================================================== Ubuntu Security Notice USN-624-1       July 15, 2008 pcre3 vulnerability CVE-2008-</description>
<pubDate>14 Jul  2008 19:06:08 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62555</link>
</item><item>
<title>Pwnie Awards: Nominations, delayed?</title>
<description>I&amp;#039;ve been waiting all day to hear who the nominees are for the Pwnie Awards 2008. It says on http://pwnie-awards.org/2008/ the website &amp;quot;Jul 14: nomin</description>
<pubDate>14 Jul  2008 14:55:14 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62550</link>
</item><item>
<title>Flaw in eMule 0.49: it exposes the OS user account name when it sends the shared files list</title>
<description>eMule 0.49 and previous versions could expose the OS user account name when it sends the shared files list. When an user asks for the shared files lis</description>
<pubDate>14 Jul  2008 12:05:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62548</link>
</item><item>
<title>iPhone ActivSync/iTunes flaw</title>
<description>FYI: Looks like the &amp;quot;Enforce password on device&amp;quot; Group Policy setting is lost if you do an iPhone software restore and then re-sync your mail settings</description>
<pubDate>14 Jul  2008 10:07:01 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62547</link>
</item><item>
<title>DeepSec 2008 - Last call for submissions</title>
<description>== DeepSec IDSC 2008 - CfP ends tomorrow - Last chance to submit == The DeepSec In-Depth Security Conference reminds all interested speakers to submi</description>
<pubDate>14 Jul  2008 03:13:23 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/62545</link>
</item>
</channel>
</rss>
