<?xml version="1.0" encoding="iso-8859-1" ?>
<?xml-stylesheet title="XSL_formatting" type="text/xsl" href="/images/lists/rssstyle2.xsl"?>
<rss version="2.0">
<channel>
<title>Full Disclosure | Full-Disclosure</title>
<description>Mailing List Archive by Gossamer Threads</description>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<language>en-us</language>
<copyright>(c) Gossamer Threads Inc. All rights reserved.</copyright>
<lastBuildDate>25 Nov  2009 20:16:33 -0800</lastBuildDate>
<ttl>120</ttl>
<image>
<title>Gossamer Threads | Full Disclosure | Full-Disclosure</title>
<width>75</width>
<height>23</height>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/</link>
<url>http://www.gossamer-threads.com/images/lists/rss_logo.jpg</url>
</image>
<item>
<title>[SECURITY] [DSA 1941-1] New poppler packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>25 Nov  2009 14:37:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70923</link>
</item><item>
<title>need advice on adtmt cookie</title>
<description>Since using the virtual software McAfee web and email scanner I have noticed a lot of blocks of the adtmt cookie (seen as an unwanted program) but see</description>
<pubDate>25 Nov  2009 13:18:38 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70922</link>
</item><item>
<title>Re: {Spam?} [funsec] nasty infection from following link if anyone is interested</title>
<description>On Wed, Nov 25, 2009 at 2:19 PM, Alex Lanstein &amp;lt;ALanstein@fireeye.com&amp;gt; wrote: &amp;gt; That was yesterdays (or the day befores?) zeus/zbot campaign, fwiw &amp;gt; &amp;gt;</description>
<pubDate>25 Nov  2009 12:55:36 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70921</link>
</item><item>
<title>Re: [funsec] nasty infection from following link if anyone is interested</title>
<description>Your modifications doesn&amp;#039;t prevent your link to be clickable in all mail clients. Please use methods http : // and/or archive1329101302 . heddasq nex</description>
<pubDate>25 Nov  2009 12:16:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70920</link>
</item><item>
<title>nasty infection from following link if anyone is interested</title>
<description>one of my sales people fell for a &amp;quot;someone posted a picture of you&amp;quot; emails. Got a real nasty that came with, according to malwarebytes, &amp;quot;Pawnd.bot an</description>
<pubDate>25 Nov  2009 10:54:31 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70919</link>
</item><item>
<title>Re: Some shit going on in seclist</title>
<description>&amp;gt; I guess this is an email list. This guy -/ Day Jay, has put up this &amp;gt; vulnerability up on seclist, stating that it relates to microsoft iis &amp;gt; 6.0, w</description>
<pubDate>25 Nov  2009 10:00:50 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70918</link>
</item><item>
<title>Onapsis Research: SAP Security In-Depth Vol. I</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Dear colleague, The first volume of the Onapsis&amp;#039; SAP Security In-Depth publication has been released.</description>
<pubDate>25 Nov  2009 08:53:53 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70917</link>
</item><item>
<title>[ GLSA 200911-05 ] Wireshark: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-05 - - -</description>
<pubDate>25 Nov  2009 07:39:04 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70916</link>
</item><item>
<title>[resent] [ GLSA 200911-04 ] dstat: Untrusted search path</title>
<description>Due to an oversight on my part, the original email has not been signed. - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gento</description>
<pubDate>25 Nov  2009 07:14:30 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70915</link>
</item><item>
<title>[ GLSA 200911-04 ] dstat: Untrusted search path</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-04 - - -</description>
<pubDate>25 Nov  2009 07:10:20 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70914</link>
</item><item>
<title>[ GLSA 200911-03 ] UW IMAP toolkit: Multiple vulnerabilities</title>
<description>- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory              GLSA 200911-03 - - -</description>
<pubDate>25 Nov  2009 05:24:42 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70913</link>
</item><item>
<title>9/11 pager messages released by Wikileaks</title>
<description>http://911.wikileaks.org/ &amp;quot;From 3AM on Wednesday November 25, 2009, until 3AM the following day (US east coast time), WikiLeaks is releasing over hal</description>
<pubDate>25 Nov  2009 03:54:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70912</link>
</item><item>
<title>Re: Some shit going on in seclist</title>
<description>2009/11/24 Tyler Durten &amp;lt;ty13rdurt3n@gmail.com&amp;gt;: &amp;gt; I guess this is an email list. This guy - Day Jay, has put up this &amp;gt; vulnerability up on seclist, s</description>
<pubDate>25 Nov  2009 03:48:47 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70911</link>
</item><item>
<title>Re: UK jails schizophrenic for refusal to decrypt files</title>
<description>To me, the Brits - sorry, their government - are more and more turning into fascists. What, if somebody has &amp;#039;really&amp;#039; forgotten his password or lost h</description>
<pubDate>25 Nov  2009 03:41:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70910</link>
</item><item>
<title>Re: more on that</title>
<description>So youre whining about a 4 year old post? lol and who uses an exploit without changing the shellcode anyway ________________________________ From: f</description>
<pubDate>25 Nov  2009 03:15:48 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70909</link>
</item><item>
<title>Re: Some shit going on in seclist</title>
<description>you have lost your homedir, or what? well, this is very stupid and pretty badly obfuscated, but I wonder how many scriptkiddies have been temporary su</description>
<pubDate>25 Nov  2009 03:11:02 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70908</link>
</item><item>
<title>Re: PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>&amp;gt; &amp;gt; Thanks for the good description and test results, Bogdan. Thank you very much Moritz.  &amp;gt;&amp;gt; Proof of concept &amp;gt;&amp;gt; ----------------- &amp;gt;&amp;gt; I&amp;#039;m not goin</description>
<pubDate>25 Nov  2009 01:35:59 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70900</link>
</item><item>
<title>rPSA-2009-0156-1 sun-jdk sun-jre</title>
<description>rPath Security Advisory: 2009-0156-1 Published: 2009-11-24 Products:   rPath Appliance Platform Linux Service 2   rPath Linux 1   rPath Linux 2</description>
<pubDate>24 Nov  2009 15:58:27 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70905</link>
</item><item>
<title>rPSA-2009-0155-1 httpd mod_ssl</title>
<description>rPath Security Advisory: 2009-0155-1 Published: 2009-11-24 Products:   rPath Appliance Platform Linux Service 2   rPath Linux 2 Rating: Major Exp</description>
<pubDate>24 Nov  2009 15:57:43 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70904</link>
</item><item>
<title>rPSA-2009-0154-1 httpd mod_ssl</title>
<description>rPath Security Advisory: 2009-0154-1 Published: 2009-11-24 Products:   rPath Appliance Platform Linux Service 1   rPath Linux 1 Rating: Major Exp</description>
<pubDate>24 Nov  2009 15:56:52 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70903</link>
</item><item>
<title>UK jails schizophrenic for refusal to decrypt files</title>
<description>The first person jailed under draconian UK police powers that Ministers said were vital to battle terrorism and serious crime has been identified by T</description>
<pubDate>24 Nov  2009 14:48:19 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70899</link>
</item><item>
<title>[SECURITY] [DSA 1939-1] New libvorbis packages fix several vulnerabilities</title>
<description>-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 - ------------------------------------------------------------------------ Debian Security Advisory DSA</description>
<pubDate>24 Nov  2009 14:41:13 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70902</link>
</item><item>
<title>Vulnerabilities in WP-Cumulus for WordPress</title>
<description>Hello Full-Disclosure! I want to warn you about security vulnerabilities in plugin WP-Cumulus for WordPress. These are Full path disclosure and Cros</description>
<pubDate>24 Nov  2009 13:56:40 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70901</link>
</item><item>
<title>more on that</title>
<description>And this is what I&amp;#039;m talking about: http://seclists.org/fulldisclosure/2005/Apr/412</description>
<pubDate>24 Nov  2009 13:41:54 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70907</link>
</item><item>
<title>Re: PHP &amp;quot;multipart/form-data&amp;quot; denial of service</title>
<description>Bogdan Calin wrote: &amp;gt; Description &amp;gt; ------------ &amp;gt; PHP version 5.3.1 was just released. This release contains a patch for a &amp;gt; denial of service condit</description>
<pubDate>24 Nov  2009 13:40:07 -0800</pubDate>
<link>http://www.gossamer-threads.com/lists/fulldisc/full-disclosure/70898</link>
</item>
</channel>
</rss>
