Full Disclosure: by date

496 messages starting Feb 02 08 and ending Feb 29 08
Date index | Thread index | Author index


Saturday, 02 February

Re: Southwest Airlines Ticket Silliness Adam Chesnutt
Re: A friendly request on behalf of Bart Cilfone coderman
Re: A friendly request on behalf of Bart Cilfone coderman
Re: Southwest Airlines Ticket Silliness coderman
[ MDVSA-2008:031 ] - security
Re: Southwest Airlines Ticket Silliness Warren Myers
Re: Southwest Airlines Ticket Silliness nate . mcfeters
Re: Southwest Airlines Ticket Silliness Joey Mengele
Re: undersea cable cut and internet problem! coderman
Re: undersea cable cut and internet problem! crazy frog crazy frog
Re: Southwest Airlines Ticket Silliness Adam Chesnutt
[ MDVSA-2008:033 ] - Updated ruby-gnome2 packages fix arbitrary code execution vulnerability security
The Everything Development System - SQL Injection sub
[ MDVSA-2008:032 ] - Updated boost packages fix DoS vulnerabilities security
Re: undersea cable cut and internet problem! gmaggro
Re: Southwest Airlines Ticket Silliness Kevin Finisterre (lists)
Re: undersea cable cut and internet problem! worried security
Re: Southwest Airlines Ticket Silliness Adam Chesnutt
Re: Southwest Airlines Ticket Silliness Kevin Finisterre (lists)
Re: Southwest Airlines Ticket Silliness Joey Mengele
Re: Southwest Airlines Ticket Silliness worried security
Re: A friendly request on behalf of Bart Cilfone James Matthews

Sunday, 03 February

Re: undersea cable cut and internet problem! worried security
FaceBook/Aurigma Image/PhotoUploader Buffer Overflow Elazar Broad
Yahoo! JukeBox MediaGrid ActiveX Control AddBitmap() Buffer Overflow Elazar Broad

Monday, 04 February

Re: Southwest Airlines Ticket Silliness North, Quinn
Re: Southwest Airlines Ticket Silliness Derek Buelna
[OPENADS-SA-2008-001] Openads 2.4.2 vulnerability fixed Matteo Beccati
[USN-574-1] Linux kernel vulnerabilities Jamie Strandboge
Immunity Debugger v1.4 Release Nicolas Waisman
CORE-2008-0122: MPlayer arbitrary pointer dereference CORE Security Technologies Advisories
CORE-2007-1218: MPlayer 1.0rc2 buffer overflow vulnerability CORE Security Technologies Advisories
iDefense Security Advisory 01.31.08: IBM Informix Dynamic Server SQLIDEBUG File Creation Vulnerability iDefense Labs
iDefense Security Advisory 01.31.08: IBM Informix Dynamic Server onedcu File Creation Vulnerability iDefense Labs
Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities carl hardwick
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities Rob Thompson
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities steve menard
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities reepex
Socket termination in FTP Log Server 7.9.14.0 Luigi Auriemma
Multiple vulnerabilities in WinCom LPD Total 3.0.2.623 Luigi Auriemma
Multiple vulnerabilities in SAPlpd 6.28 Luigi Auriemma
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities Juha-Matti Laurio
[USN-575-1] Apache vulnerabilities Jamie Strandboge
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities Larry Seltzer
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities Rob Thompson
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities Joey Mengele
Re: Southwest Airlines Ticket Silliness Joey Mengele
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities scott
[ MDVSA-2008:034 ] - Updated emacs packages fix vulnerabilities security

Tuesday, 05 February

[SECURITY] [DSA 1486-1] New gnatsweb packages fix cross-site scripting Steve Kemp
[SECURITY] [DSA 1480-1] New poppler packages fix several vulnerabilities Moritz Muehlenhoff
[SECURITY] [DSA 1481-1] New python-cherrypy packages fix denial of service Moritz Muehlenhoff
CYBSEC Security Advisory: Arbitrary file overwrite in Documentum Administrator / Documentum Webtop CYBSEC Advisories
[ MDVSA-2008:035 ] - Updated libcdio packages fix DoS vulnerability security
[SECURITY] [DSA 1482-1] New squid packages fix denial of service Moritz Muehlenhoff
Acroread 8.1.2: why? Paul Szabo

Wednesday, 06 February

rPSA-2008-0040-1 mysql mysql-bench mysql-server rPath Update Announcements
JaPCrypt Gerardo Di Giacomo
Re: JaPCrypt coderman
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities coderman
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities coderman
What makes Yahoo! a good merger candidate? Vincent van Scherpenseel
Re: Firefox 2.0.0.12 SSL Spoofing and Domain Guessing vulnerabilities coderman
Re: JaPCrypt T Biehn
Re: JaPCrypt T Biehn
Re: JaPCrypt Gerardo Di Giacomo
Re: JaPCrypt coderman
Re: What makes Yahoo! a good merger candidate? Ferdinand Klinzer
Re: Acroread 8.1.2: why? Juha-Matti Laurio
Re: JaPCrypt Valdis . Kletnieks
Re: JaPCrypt Epic
Re: JaPCrypt Valdis . Kletnieks
Re: What makes Yahoo! a good merger candidate? Paul Schmehl
Re: JaPCrypt Christoph Gruber
Re: What makes Yahoo! a good merger candidate? Valdis . Kletnieks
Re: What makes Yahoo! a good merger candidate? Paul Schmehl
Re: What makes Yahoo! a good merger candidate? Harry Hoffman
Re: JaPCrypt Gerardo Di Giacomo
rPSA-2008-0043-1 icu rPath Update Announcements
Re: What makes Yahoo! a good merger candidate? worried security
MyNews 1.6.X HTML/JS Injection Vulnerability SkyOut
iDefense Security Advisory 02.04.08: Hewlett-Packard Network Node Manager Topology Manager Service DoS Vulnerability iDefense Labs
Re: What makes Yahoo! a good merger candidate? Harry Hoffman
Chat vulnerabilities in TinTin++ 1.97.9 Luigi Auriemma
Logs visualization in WS_FTP Server Manager 6.1.0.0 Luigi Auriemma
ZDI-08-003: Symantec Backup Exec Remote File Upload Vulnerability zdi-disclosures
rPSA-2008-0046-1 gd rPath Update Announcements
[SECURITY] [DSA 1483-1] New net-snmp packages fix denial of service vulnerability Noah Meyerhans
[Professional IT Security Providers - Exposed] Layer 9 Corporation ( D ) secreview
[ MDVSA-2008:036 ] - Updated CUPS packages fix SNMP vulnerability security
Re: [Professional IT Security Providers - Exposed] Layer 9 Corporation ( D ) J. Oquendo
[ GLSA 200802-01 ] SDL_image: Two buffer overflow vulnerabilities Raphael Marichez
[ GLSA 200802-02 ] Doomsday: Multiple vulnerabilities Pierre-Yves Rofes
Re: MyNews 1.6.X HTML/JS Injection Vulnerability reepex
Re: What makes Yahoo! a good merger candidate? Tonnerre Lombard

Thursday, 07 February

Indian Antivirus Website is infected with Virus...SmartCOP Antivirus ! Antivirus Taneja
Re: What makes Yahoo! a good merger candidate? Christian Kujau
Re: What makes Yahoo! a good merger candidate? Paul Schmehl
Re: What makes Yahoo! a good merger candidate? Chris 'Chipper' Chiapusio
Checkpoint SecuRemote/Secure Client NGX Auto Local Logon Vulnerability Michael Neal Vasquez
Re: Checkpoint SecuRemote/Secure Client NGX Auto Local Logon Vulnerability Rodrigo Rubira Branco (BSDaemon)
Re: What makes Yahoo! a good merger candidate? admin
Re: What makes Yahoo! a good merger candidate? Valdis . Kletnieks
[ MDVSA-2008:037 ] - Updated libcdio packages fix DoS vulnerability security
Multiple vulnerabilities in Ipswitch Instant Messaging 2.0.8.1 Luigi Auriemma
iDefense Security Advisory 02.07.08: IBM DB2 Universal Database db2pd Arbitrary Library Loading Vulnerability iDefense Labs
iDefense Security Advisory 02.07.08: IBM DB2 Universal Database Administration Server Memory Corruption Vulnerability iDefense Labs
Worldnic DNS servers poisoned? James Lay
Re: MyNews 1.6.X HTML/JS Injection Vulnerability Fredrick Diggle
Adobe Reader/Acrobat Remote PDF Print Silently Vulnerability cocoruder
[ MDVSA-2008:038 ] - Updated gd packages fix buffer overflow vulnerability security
[ MDVSA-2008:039 ] - Updated netpbm packages fix buffer overflow vulnerability security
[ MDVSA-2008:040 ] - Updated SDL_image packages fix vulnerabilities security
[ MDVSA-2008:041 ] - Updated tk packages fix buffer overflow vulnerability security
[USN-576-1] Firefox vulnerabilities Jamie Strandboge
[ MDVSA-2008:042 ] - Updated Qt4 packages fix vulnerability in QSslSocket security

Friday, 08 February

Re: Worldnic DNS servers poisoned? Florian Weimer
ASUS Eee PC rooted out of the box RISE Security
[SECURITY] [DSA 1487-1] New libexif packages fix several vulnerabilities Moritz Muehlenhoff
Serendipity Freetag-plugin XSS vulnerability Research
Re: ASUS Eee PC rooted out of the box reepex
cyber armageddon due feb 10 worried security
Re: ASUS Eee PC rooted out of the box Stack Smasher
Re: ASUS Eee PC rooted out of the box Stack Smasher
Re: ASUS Eee PC rooted out of the box Joey Mengele
Re: ASUS Eee PC rooted out of the box reepex
Re: ASUS Eee PC rooted out of the box reepex
Re: ASUS Eee PC rooted out of the box A . L . M . Buxey
Re: ASUS Eee PC rooted out of the box keith
Re: cyber armageddon due feb 10 worried security
Re: ASUS Eee PC rooted out of the box Valdis . Kletnieks
Re: ASUS Eee PC rooted out of the box reepex
Re: ASUS Eee PC rooted out of the box Erik Harrison
NULL byte writing in Emerald, RadiusNT/X and Air Marshal Luigi Auriemma
Re: ASUS Eee PC rooted out of the box Erik Harrison
Re: ASUS Eee PC rooted out of the box reepex
Re: ASUS Eee PC rooted out of the box RISE Security
rPSA-2008-0048-1 kernel rPath Update Announcements
Re: ASUS Eee PC rooted out of the box Simon Smith
Re: cyber armageddon due feb 10 DUDE DUDERINO
Re: ASUS Eee PC rooted out of the box Simon Smith
Break Captcha to send sms at Movistar Colombia, Movistar Ecuador and Comcel Colombia Camilo
[ NNSquad ] Verizon's access via their provided Actiontec MoCa router (fwd) Jay Sulzberger
Re: [ NNSquad ] Verizon's access via their provided Actiontec MoCa router (fwd) coderman
Some Hashes Open Phugu
Re: Some Hashes Maxim
Re: Some Hashes Joey Mengele
iDefense Security Advisory 02.08.08: Adobe Reader and Acrobat JavaScript Insecure Method Exposure Vulnerability iDefense Labs
iDefense Security Advisory 02.08.08: Adobe Reader Security Provider Unsafe Libary Path Vulnerability iDefense Labs
Re: Some Hashes scott
[SECURITY] [DSA 1488-1] New phpbb2 packages fix several vulnerabilities Thijs Kinkhorst
rPSA-2008-0051-1 firefox rPath Update Announcements

Saturday, 09 February

iDefense Security Advisory 02.08.08: Adobe Reader and Acrobat Multiple Stack-based Buffer Overflow Vulnerabilities iDefense Labs
Firefox 2.0.0.12 information leak vulnerability carl hardwick
Re: ASUS Eee PC rooted out of the box SilentRunner
Re: ASUS Eee PC rooted out of the box Joey Mengele
Re: ASUS Eee PC rooted out of the box reepex
Re: ASUS Eee PC rooted out of the box Simon Smith
Re: ASUS Eee PC rooted out of the box Static Rez
Re: ASUS Eee PC rooted out of the box worried security
Re: ASUS Eee PC rooted out of the box keith
Re: back to high value targets coderman

Sunday, 10 February

scientology-- Josh Gorbin
Firefox URI Spoofing Revisited carl hardwick
[SECURITY] [DSA 1484-1] New xulrunner packages fix several vulnerabilities Moritz Muehlenhoff
[SECURITY] [DSA 1485-1] New icedove packages fix several vulnerabilities Moritz Muehlenhoff
[SECURITY] [DSA 1489-1] New iceweasel packages fix several vulnerabilities Moritz Muehlenhoff
[SECURITY] [DSA 1490-1] New tk8.3 packages fix arbitrary code execution Moritz Muehlenhoff
[SECURITY] [DSA 1491-1] New tk8.4 packages fix arbitrary code execution Moritz Muehlenhoff
[SECURITY] [DSA 1492-1] New wml packages fix denial of service Moritz Muehlenhoff
[SECURITY] [DSA 1493-1] New sdl-image1.2 packages fix arbitrary code execution Moritz Muehlenhoff
List Charter John Cartwright

Monday, 11 February

uk needs dedicated e-crime unit and lolz for web trolls worried security
[SECURITY] [DSA 1494-1] New linux-2.6 packages fix privilege escalation Florian Weimer
Dude VanWinkle's Death Jonathan Glass
Re: ASUS Eee PC rooted out of the box Valdis . Kletnieks
Re: Dude VanWinkle's Death Joey Mengele
Multiple vulnerabilities in EztremeZ-IP File and Printer Server 5.1.2x15 Luigi Auriemma
Format string and DoS in Opium OPI and cyanPrintIP servers 4.10.x Luigi Auriemma
Format string and buffer-overflow in Lst Network Print Server 9.4.2 build 105 Luigi Auriemma
Re: Dude VanWinkle's Death Paul Schmehl
Re: Dude VanWinkle's Death Simon Smith
Re: Dude VanWinkle's Death Simon Smith
Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 Luigi Auriemma
Re: Dude VanWinkle's Death Keith Kilroy
Re: Dude VanWinkle's Death Joey Mengele
Re: Dude VanWinkle's Death Simon Smith
Re: Dude VanWinkle's Death Ronald MacDonald
DEATH OF AN INTERNET ROCKSTAR dudevanwinkle
Re: Dude VanWinkle's Death Geoffrey Gowey
Re: Dude VanWinkle's Death worried security
Re: Dude VanWinkle's Death dudevanwinkle
Re: Dude VanWinkle's Death worried security
Re: Dude VanWinkle's Death Abilash Praveen
Re: Dude VanWinkle's Death dudevanwinkle
in Memory of Dude VanWinkle / Justin Plazzo Gadi Evron
Re: Dude VanWinkle's Death Randal T. Rioux
Brute force attack - need your advice Abilash Praveen
Re: Brute force attack - need your advice dudevanwinkle
Re: Brute force attack - need your advice Paul Schmehl
Re: Brute force attack - need your advice Peter Dawson
Re: in Memory of Dude VanWinkle / Justin Plazzo Abilash Praveen
Re: Brute force attack - need your advice Valdis . Kletnieks
Re: Brute force attack - need your advice dudevanwinkle
Re: Brute force attack - need your advice Peter Dawson
[ GLSA 200802-03 ] Horde IMP: Security bypass Pierre-Yves Rofes
Re: Dude VanWinkle's Death Geoffrey Gowey
ZDI-08-005: Novell Client NWSPOOL.DLL EnumPrinters Stack Overflow Vulnerability zdi-disclosures
ZDI-08-004: Adobe AcrobatReader Javascript for PDF Integer Overflow Vulnerability zdi-disclosures
[ GLSA 200802-04 ] Gallery: Multiple vulnerabilities Pierre-Yves Rofes
Re: RIP Dude VanWinkle Kristian Erik Hermansen
Re: in Memory of Dude VanWinkle / Justin Plazzo scott
Re: in Memory of Dude VanWinkle / Justin Plazzo Jared DeMott
Re: [inbox] in Memory of Dude VanWinkle / Justin Plazzo Exibar
Re: [inbox] in Memory of Dude VanWinkle / JustinPlazzo Richard Golodner
Re: Dude VanWinkle's Death Andrew A
Re: Dude VanWinkle's Death Nick FitzGerald
[ MDVSA-2008:043 ] - Updated kernel packages fix multiple vulnerabilities and bugs security
Re: in Memory of Dude VanWinkle / Justin Plazzo Andrew A
FLEA-2008-0001-1 firefox Foresight Linux Essential Announcement Service
Re: Brute force attack - need your advice Tonnerre Lombard
CSA-L03: Linux kernel vmsplice unchecked user-pointer dereference Wojciech Purczynski

Tuesday, 12 February

FLEA-2008-0002-1 python Foresight Linux Essential Announcement Service
Re: Brute force attack - need your advice Keith Kilroy
FLEA-2008-0004-1 rsync Foresight Linux Essential Announcement Service
FLEA-2008-0003-1 nss_ldap Foresight Linux Essential Announcement Service
FLEA-2008-0005-1 e2fsprogs Foresight Linux Essential Announcement Service
FLEA-2008-0006-1 tetex tetex-dvips tetex-fonts Foresight Linux Essential Announcement Service
Re: Brute force attack - need your advice Abilash Praveen
FLEA-2008-0007-1 gd Foresight Linux Essential Announcement Service
Re: Brute force attack - need your advice A . L . M . Buxey
Re: Brute force attack - need your advice Keith Kilroy
Re: Brute force attack - need your advice T Biehn
[ MDVSA-2008:044 ] - Updated kernel packages fix multiple vulnerabilities and bugs security
death of "Dude" brings out the "Rude" Randy Mueller
Re: Brute force attack - need your advice Abilash Praveen
Re: Brute force attack - need your advice Tonnerre Lombard
Re: Brute force attack - need your advice Michael Simpson
Re: [inbox] in Memory of Dude VanWinkle / Justin Plazzo Joey Mengele
Re: Brute force attack - need your advice keith
Re: in Memory of Dude VanWinkle / Justin Plazzo Prohest
Re: [funsec] in Memory of Dude VanWinkle / Justin Plazzo Chris Blask
Re: Brute force attack - need your advice Keith Kilroy
Re: [funsec] RIP Dude VanWinkle Blanchard_Michael
Article: FaceBook ImageUploader4.1.OCX Stack Buffer Overflow Vulnerability Dror
i tried but the whitehouse were having none of it worried security
Re: Brute force attack - need your advice Tonnerre Lombard
Re: Brute force attack - need your advice Keith Kilroy
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 jfvanmeter
Re: [funsec] in Memory of Dude VanWinkle / Justin Plazzo dudevanwinkle
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 Luigi Auriemma
Re: in Memory of Dude VanWinkle / Justin Plazzo dudevanwinkle
rPSA-2008-0052-1 kernel rPath Update Announcements
Re: Brute force attack - need your advice dudevanwinkle
FaceBook ImageUploader4.1.OCX Stack Buffer Overflow Vulnerability Dror
Re: in Memory of Dude VanWinkle / Justin Plazzo Valdis . Kletnieks
Re: Brute force attack - need your advice Valdis . Kletnieks
Re: Brute force attack - need your advice Valdis . Kletnieks
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 jfvanmeter
iDefense Security Advisory 02.12.08: ClamAV libclamav PE File Integer Overflow Vulnerability iDefense Labs
Re: Brute force attack - need your advice Simon Smith
Re: [funsec] in Memory of Dude VanWinkle / Justin Plazzo Simon Smith
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 Luigi Auriemma
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 jfvanmeter
[USN-577-1] Linux kernel vulnerability Jamie Strandboge
Unicode buffer-overflow in RPM Remote Print Manager 4.5.1.11 Luigi Auriemma
Directory traversal and DoS in WinIPDS G52-33-021 Luigi Auriemma
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 jfvanmeter
Re: in Memory of Dude VanWinkle / Justin Plazzo Andrew A
Re: in Memory of Dude VanWinkle / Justin Plazzo evilrabbi
Re: in Memory of Dude VanWinkle / Justin Plazzo Fredrick Diggle
Re: in Memory of Dude VanWinkle / Justin Plazzo Geoffrey Gowey
Re: ASUS Eee PC rooted out of the box Fredrick Diggle
Disrespecting the respectable Dude VanWinkle / Justin Plazzo, illegal? Simon Smith
Re: Brute force attack - need your advice Simon Smith
Re: [inbox] in Memory of Dude VanWinkle / Justin Plazzo Paul Schmehl
Re: [funsec] in Memory of Dude VanWinkle / Justin Plazzo Ag. System Administrator
Re: Disrespecting the respectable Dude VanWinkle / Justin Plazzo, illegal? Paul Schmehl
Re: Disrespecting the respectable Dude VanWinkle / Justin Plazzo, illegal? J. Oquendo
Re: Directory traversal in SafeNet Sentinel Protection and Key Server 7.4.1.0 Luigi Auriemma
[ GLSA 200802-05 ] Gnumeric: User-assisted execution of arbitrary code Pierre-Yves Rofes
Cacti 0.8.7a Multiple Vulnerabilities s4tan
[ GLSA 200802-06 ] scponly: Multiple vulnerabilities Pierre-Yves Rofes
Re: Disrespecting the respectable Dude VanWinkle / Justin Plazzo, illegal? Simon Smith
Re: Disrespecting the respectable Dude VanWinkle / Justin Plazzo, illegal? J. Oquendo
Re: [funsec] death of "Dude" brings out the "Rude" Blue Boar
Re: Disrespecting the respectable Dude VanWinkle / Justin Plazzo, illegal? Simon Smith
[SECURITY] [DSA 1495-1] New nagios-plugins packages fix several vulnerabilities Moritz Muehlenhoff
[SECURITY] [DSA 1496-1] New mplayer packages fix arbitrary code execution Moritz Muehlenhoff
TROLLS WITH NOT RESPECT Randy Mueller
Re: TROLLS WITH NOT RESPECT Valdis . Kletnieks
Re: TROLLS WITH NOT RESPECT Andrew A
iDefense Security Advisory 02.12.08: Microsoft Office Works Converter Heap Overflow Vulnerability iDefense Labs
iDefense Security Advisory 02.12.08: Microsoft Office Works Converter Stack-based Buffer Overflow Vulnerability iDefense Labs
ZDI-08-006: Microsoft Internet Explorer SVG animateMotion.by Code Execution Vulnerability zdi-disclosures
iDefense Security Advisory 02.12.08: Microsoft Internet Explorer Property Memory Corruption Vulnerability iDefense Labs
iDefense Security Advisory 02.12.08: Adobe Flash Media Server 2 Multiple Integer Overflow Vulnerabilities iDefense Labs
iDefense Security Advisory 02.12.08: Adobe Flash Media Server 2 Memory Corruption Vulnerability iDefense Labs
Re: TROLLS WITH NOT RESPECT Fredrick Diggle

Wednesday, 13 February

rPSA-2008-0054-1 tk rPath Update Announcements
rPSA-2008-0059-1 openldap openldap-clients openldap-servers rPath Update Announcements
QuickTime <= 7.4.1 QTPlugin.ocx Multiple Remote Stack Overflow laurent gaffie
MS08-011/CVE-2008-0108 exploit. chujwamwdupe chujwamwdupe
[SECURITY] [DSA 1494-2] New linux-2.6 packages fix privilege escalation dann frazier
Re: rPSA-2008-0052-1 kernel gregory
OpenCA XSRF (CVE-2008-0556) Alexander Klink
Re: in Memory of Dude VanWinkle / Justin Plazzo - o s g o -
Cisco Security Advisory: SQL injection in Cisco Unified Communications Manager Cisco Systems Product Security Incident Response Team
Cisco Security Advisory: Cisco Unified IP Phone Overflow and Denial of Service Vulnerabilities Cisco Systems Product Security Incident Response Team
rPSA-2008-0061-1 SDL_image rPath Update Announcements
rPSA-2008-0063-1 boost rPath Update Announcements
Pouring one out for my homie the Dude Captain McShanks
JSPWiki Multiple Vulnerabilities Trancer
[ GLSA 200802-07 ] Pulseaudio: Privilege escalation Pierre-Yves Rofes
[USN-578-1] Linux kernel vulnerabilities Jamie Strandboge
Re: rPSA-2008-0052-1 kernel Tonnerre Lombard

Thursday, 14 February

Digitalarmaments a fake orginazation? Arjun srivastav
Re: ASUS Eee PC rooted out of the box Tonu Samuel
Analysis of MS08-006 / Demo of MS08-007 H D Moore
DOINGSOFT-2008-02-11 - IPDiva VPN SSL Brute force attack eagle
DOINGSOFT-2008-02-11-002 IP Diva VPN SSL many XSS attacks eagle
[ GLSA 200802-08 ] Boost: Denial of Service Raphael Marichez
[ MDVSA-2008:045 ] - Updated MPlayer packages fix a few vulnerabilities security
Re: in Memory of Dude VanWinkle / Justin Plazzo Byron Sonne
Re: in Memory of Dude VanWinkle / Justin Plazzo Peter Dawson
[MU-200802-01] Multiple Remote Arbitrary Execution Vulnerabilities in Mplayer noreply

Friday, 15 February

Firefox 2.0.0.12 IFrame overflow vulnerability carl hardwick
Re: Firefox 2.0.0.12 IFrame overflow vulnerability Randal, Phil
[INFIGO-2008-02-13]: SOPHOS Email Security Appliance Cross Site Scripting Vulnerability infocus
let's name something after dude vanwinkle worried security
Sami FTP Server 2.0.* Multiple Remote Vulnerabilities lorenzo
Re: Sami FTP Server 2.0.* Multiple Remote Vulnerabilities lorenzo
Rosoft Media Player 4.1.8 Remote Buffer Overflow ( .M3U) lorenzo
Re: Rosoft Media Player 4.1.8 Remote Buffer Overflow ( .M3U) reepex
Re: Rosoft Media Player 4.1.8 Remote Buffer Overflow ( .M3U) Captain McShanks
Re: Rosoft Media Player 4.1.8 Remote Buffer Overflow ( .M3U) reepex
Re: let's name something after dude vanwinkle Andrew A
Re: Rosoft Media Player 4.1.8 Remote Buffer Overflow ( .M3U) Fredrick Diggle
Re: let's name something after dude vanwinkle Fredrick Diggle
[ MDVSA-2008:046 ] - Updated xine-lib package fixes arbitrary code execution vulnerability security
Re: in Memory of Dude VanWinkle / Justin Plazzo Fredrick Diggle
Re: let's name something after dude vanwinkle reepex
Re: Firefox 2.0.0.12 IFrame overflow vulnerability Daniel Veditz
Re: let's name something after dude vanwinkle Joey Mengele

Saturday, 16 February

Re: Rosoft Media Player 4.1.8 Remote Buffer Overflow ( .M3U) securfrog
rPSA-2008-0056-1 mailman rPath Update Announcements
Finnish thought police censors site about censorship! Markus Jansson
[SECURITY] [DSA 1497-1] New clamav packages fix several vulnerabilities Moritz Muehlenhoff
Re: let's name something after dude vanwinkle Andrew A
Re: let's name something after dude vanwinkle Joey Mengele
Re: let's name something after dude vanwinkle Shyaam
Re: let's name something after dude vanwinkle worried security

Sunday, 17 February

[SECURITY] [DSA 1495-2] New nagios-plugins packages fix regression Moritz Muehlenhoff
SCADA Security Corruption Ghost Rider
Re: SCADA Security Corruption Peter Dawson
Re: SCADA Security Corruption Ghost Rider
Re: SCADA Security Corruption beenthere
Re: SCADA Security Corruption worried security
About the Hybrid Rainbow. New overpowered method combining hybrid attack and popular precalculation technique. Odley Mike
Re: SCADA Security Corruption Bryan L. Singer
Re: SCADA Security Corruption Fredrick Diggle

Monday, 18 February

Re: let's name something after dude vanwinkle Darkie Duck
RUXCON 2008 CALL FOR PAPERS cfp
Apple iPhoto v4.0.3 DPAP Server Denial of Service Exploit David Wharton
Call for Papers: First IEEE International Workitorial on Steganography - "Vision of the Unseen" wjs3

Tuesday, 19 February

Re: let's name something after dude vanwinkle infolookup
Re: let's name something after dude vanwinkle Darkie Duck
Re: let's name something after dude vanwinkle Fredrick Diggle
network management shadow floating
Re: network management Valdis . Kletnieks
[SECURITY] [DSA 1498-1] New libimager-perl packages fix arbitrary code execution Steve Kemp
Anyone else seeing this? Joey Mengele
Re: Anyone else seeing this? Simon Smith
[ MDVSA-2007:047 ] - Updated Thunderbird packages fix multiple vulnerabilities security
[SECURITY] [DSA 1499-1] New pcre3 packages fix arbitrary code execution Florian Weimer
NULL pointer crash in freeSSHd 1.20 Luigi Auriemma
Two heap overflow in Foxit WAC Server 2.0 Build 3503 Luigi Auriemma
Access violation and limited informations disclosure in webcamXP 3.72.440.0 Luigi Auriemma
Multiple buffer-overflow in NowSMS v2007.06.27 Luigi Auriemma
ZyXEL Gateways Vulnerability Research: http://www.procheckup.com/Hacking_ZyXEL_Gateways.pdf ProCheckUp Research
Wordpress more secure than SSH Abel Cheung

Wednesday, 20 February

Re: Anyone else seeing this? Fredrick Diggle
Re: Tarot Guillaume Sicard
DO NOT USE logsurfer configuration recommended by DFN CERT kcope
Re: Tarot Slythers Bro
Re: Tarot S/U/N
Advisory SE-2008-01: PunBB Blind Password Recovery Vulnerability Stefan Esser
Heap overflow in Sybase MobiLink 10.0.1.3629 Luigi Auriemma
two (not critical) bugs in libnids 1.22 michele dallachiesa
iDefense Security Advisory 02.19.08: EMC RepliStor Multiple Heap Overflow Vulnerabilities iDefense Labs
Re: iDefense Security Advisory 02.19.08: EMC RepliStor Multiple Heap Overflow Vulnerabilities iDefense Labs
ZDI-08-007: Symantec VERITAS Storage Foundation Administrator Service Heap Overflow Vulnerability zdi-disclosures
Re: *** OFF LIST *** Re: in Memory of Dude VanWinkle / Justin Plazzo Byron Sonne
iDefense Security Advisory 02.20.08: Symantec Veritas Storage Foundation Scheduler Service DoS Vulnerability iDefense Labs
[ MDVSA-2008:046-1 ] - Updated xine-lib package fixes arbitrary code execution vulnerability security
Re: *** OFF LIST *** Re: in Memory of Dude VanWinkle / Justin Plazzo Andrew A

Thursday, 21 February

Announce: RFIDIOt credit card sub-module: ChAP.py Adam Laurie
Tool release: extract Windows credentials from registry hives Brendan Dolan-Gavitt
Advisory advisories
Cisco and Vocera wireless LAN VoIP devices don't check certificates George Ou
[USN-579-1] Qt vulnerability Jamie Strandboge
[USN-580-1] libcdio vulnerability Jamie Strandboge
Re: Cisco and Vocera wireless LAN VoIP devices don't check certificates JxT
VMSA-2008-0003 Moderate: Updated aacraid driver and samba and python service console updates VMware Security team
[SECURITY] [DSA 1500-1] New splitvt packages fix privilege escalation Steve Kemp
round and round they go Elazar Broad
Re: round and round they go, keys in ram are ripe for picking... coderman
[ GLSA 200802-09 ] ClamAV: Multiple vulnerabilities Pierre-Yves Rofes
Malicious Advertisements Serving Domains Dancho Danchev
Re: Cisco and Vocera wireless LAN VoIP devices don't check certificates George Ou
[SECURITY] [DSA 1501-1] New dspam packages fix information disclosure Thijs Kinkhorst
[USN-581-1] PCRE vulnerability Kees Cook

Friday, 22 February

CanSecWest 2008 Mar 26-28 Dragos Ruiu
Re: Tool release: extract Windows credentials from registry hives wac
Re: round and round they go niclas
Re: round and round they go matthew wollenweber
[SECURITY] [DSA 1502-1] New wordpress packages fix multiple vulnerabilities Noah Meyerhans
On Topic Off Topic: How To Behave On An Internet Forum Gadi Evron
Citrix MetaFrame web manager remote XSS Handrix
Re: On Topic Off Topic: How To Behave On An Internet Forum Peter Besenbruch
Re: On Topic Off Topic: How To Behave On An Internet Forum Peter Dawson
Re: round and round they go, keys in ram are ripe for picking... Michael Holstein
Re: round and round they go Jay
Re: round and round they go, keys in ram are ripe for picking... coderman
Re: On Topic Off Topic: How To Behave On An Internet Forum worried security
Multiple vulnerabilities in Double-Take 5.0.0.2865 Luigi Auriemma
[ MDVSA-2008:048 ] - Updated Firefox packages fix multiple vulnerabilities security
Re: let's name something after dude vanwinkle worried security
Re: let's name something after dude vanwinkle Erik Harrison
Re: let's name something after dude vanwinkle guiness . stout
Re: round and round they go niclas
Re: let's name something after dude vanwinkle scott
Re: round and round they go Jay
[SECURITY] [DSA 1503-1] New Linux kernel 2.4.27 packages fix several issues dann frazier
[SECURITY] [DSA 1504-1] New Linux kernel 2.6.8 packages fix several issues dann frazier
[SECURITY] [DSA 1505-1] New alsa-driver packages fix kernel memory leak dann frazier

Saturday, 23 February

Re: round and round they go niclas
Re: [ MDVSA-2008:048 ] - Updated Firefox packages fix multiple vulnerabilities Scott
[ GLSA 200802-10 ] Python: PCRE Integer overflow Robert Buchholz
Re: let's name something after dude vanwinkle worried security

Sunday, 24 February

[SECURITY] [DSA 1506-1] New iceape packages fix several vulnerabilities Moritz Muehlenhoff
[SECURITY] [DSA 1507-1] New turba2 packages fix permission testing Steve Kemp
Security contact at Safeway US Sebastian Wolfgarten
Re: Security contact at Safeway US Been There
Re: Security contact at Safeway US Static Rez
Re: Security contact at Safeway US Fredrick Diggle
Cisco confirms vulnerability in 7921 Wi-Fi IP phone George Ou

Monday, 25 February

S21SEC-040-en: Infinite invalid authentication attempts possible in BEA WebLogic Server S21sec labs
[ MDVSA-2008:049 ] - Updated nss_ldap package fixes race condition allowing user data theft security
CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation Core Security Technologies Advisories
CORE-2007-0930 Path Traversal vulnerability in VMware's shared folders implementation Core Security Technologies Advisories
Format string and buffer-overflow in SurgeMail 38k4 Luigi Auriemma
NULL pointer in SurgeFTP 2.3a2 Luigi Auriemma
Move Networks Quantum Streaming Player UploadLogs() Buffer Overflow Elazar Broad

Tuesday, 26 February

Backend Cross Site Scripting (XSS) in Serendipity (S9Y) 1.2.1, CVE-2008-0124 Hanno Böck
clustering question shadow floating
Re: clustering question Michael Holstein
Good afternoon lemmings! lulz
[SECURITY] [DSA 1508-1] New diatheke packages fix arbirary shell command execution Thijs Kinkhorst
[SECURITY] [DSA 1509-1] New koffice packages fix multiple vulnerabilities Noah Meyerhans
Re: clustering question Bill Stout
[ MDVSA-2008:050 ] - Updated cups packages fix multiple vulnerabilities security
[ MDVSA-2008:051 ] - Updated cups packages fix vulnerabilities security
[ GLSA 200802-12 ] xine-lib: User-assisted execution of arbitrary code Robert Buchholz
[ GLSA 200802-11 ] Asterisk: Multiple vulnerabilities Pierre-Yves Rofes
iDefense Security Advisory 02.26.08: Symantec Scan Engine 5.1.2 RAR File Denial of Service Vulnerability iDefense Labs
iDefense Security Advisory 02.26.08: Symantec Scan Engine 5.1.2 RAR File Buffer Overflow Vulnerability iDefense Labs
iDefense Security Advisory 02.26.08: Mozilla Thunderbird MIME External-Body Heap Overflow Vulnerability iDefense Labs

Wednesday, 27 February

Symark PowerBroker: Local Privilege Escalation vulnerability Greg Sinclair
XSS Vulnerability in AuthentiX Chris Castaldo
rtpbreak 1.3 is out! michele dallachiesa
CFP - ekoparty 4th edition ekoparty
[SECURITY] [DSA 1510-1] New ghostscript packages fix arbitrary code execution Thijs Kinkhorst
Buffer-overflow in the passwords handling of Trend Micro OfficeScan 8.0 and possibly other products Luigi Auriemma
CORE-2008-0130: VLC media player chunk context validation error Core Security Technologies Advisories
[ MDVSA-2008:052 ] - Updated cacti packages fix multiple vulnerabilities security
[ MDVSA-2008:053 ] - Updated pcre packages fix vulnerability security
Fwd: Home Office Laptop 'Bought On Ebay' worried security
Re: Home Office Laptop 'Bought On Ebay' worried security

Thursday, 28 February

Re: Buffer-overflow in the passwords handling of Trend Micro OfficeScan 8.0 and possibly other products Raymond_Villafania
Urulu 2.1 Blind SQL Injection Vulnerability (CVE-2008-0385) Daniel Roethlisberger
new crimeware package Peter Dawson
[ MDVSA-2008:054 ] - Updated dbus packages fix vulnerability security
rPSA-2008-0086-1 pcre rPath Update Announcements
rPSA-2008-0084-1 lighttpd rPath Update Announcements
rPSA-2008-0082-1 espgs rPath Update Announcements
rPSA-2008-0088-1 am-utils rPath Update Announcements
[ MDVSA-2008:055 ] - Updated ghostscript packages fix arbitrary code execution vulnerability security

Friday, 29 February

Canon Multi Function Devices vulnerable to FTP bounce attack Nate Johnson
Release: Pass-The-Hash toolkit v1.3 Hernan Ochoa
rPSA-2008-0091-1 cups rPath Update Announcements
rPSA-2008-0092-1 tshark wireshark rPath Update Announcements
rPSA-2008-0093-1 thunderbird rPath Update Announcements
rPSA-2008-0094-1 kernel rPath Update Announcements
[USN-582-1] Thunderbird vulnerabilities Jamie Strandboge
[ MDVSA-2008:056 ] - Updated gnumeric packages fix vulnerability security