Full Disclosure: by author

194 messages starting Jan 02 14 and ending Jan 16 14
Date index | Thread index | Author index


アドリアンヘンドリック

Re: Securelist.com (Kaspersky) released a misleading information about Kelihos Botnet actual status アドリアンヘンドリック (Jan 02)

Alexandre De Oliveira

Hackito Ergo Sum 2014 CFP Alexandre De Oliveira (Jan 20)

Andrew Horton

Tool Update: Bing-ip2hosts version 0.4 Andrew Horton (Jan 01)

Anonymous

Re: Open phones for privacy/anonymity applications, Guardian Anonymous (Jan 06)

Asheesh Tripathi

Re: Romanian hacker unknown string Asheesh Tripathi (Jan 17)
Re: Romanian hacker unknown string Asheesh Tripathi (Jan 17)
Romanian hacker unknown string Asheesh Tripathi (Jan 17)
Re: Romanian hacker unknown string Asheesh Tripathi (Jan 17)

AusCERT

AusCERT2014 Call for Presentations and Tutorials AusCERT (Jan 07)

Bernhard Kuemel

"the Fairphone is fatally flawed for security" Bernhard Kuemel (Jan 04)

Bhavesh Naik

Targeted CSRF vulnerability on LinkedIn to delete posts [FIXED] Bhavesh Naik (Jan 01)

BlackArch Linux

BlackArch Linux BlackArch Linux (Jan 13)

Brandon Perry

Re: Making waves on Twitter! Brandon Perry (Jan 27)
Re: Making waves on Twitter! Brandon Perry (Jan 27)

Bzzz

Re: Open phones for privacy/anonymity applications, Guardian Bzzz (Jan 06)

Christian Catalano

[CVE-2013-6235] - Multiple Reflected XSS vulnerabilities in JAMon v2.7 Christian Catalano (Jan 24)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco TelePresence System Software Command Execution Vulnerability Cisco Systems Product Security Incident Response Team (Jan 22)
Cisco Security Advisory: Undocumented Test Interface in Cisco Small Business Devices Cisco Systems Product Security Incident Response Team (Jan 10)
Cisco Security Advisory: Cisco TelePresence Video Communication Server SIP Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team (Jan 22)
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Secure Access Control System Cisco Systems Product Security Incident Response Team (Jan 15)
Cisco Security Advisory: Cisco TelePresence ISDN Gateway D-Channel Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team (Jan 22)

coderman

Re: "the Fairphone is fatally flawed for security" coderman (Jan 04)
Re: Open phones for privacy/anonymity applications, Guardian coderman (Jan 01)
Re: SCADA StrangeLove 30C3 releases: all in one coderman (Jan 04)
Re: Open phones for privacy/anonymity applications, Guardian coderman (Jan 01)
Re: RFP: FOIA with privacy waivers[0] for oversight coderman (Jan 25)
Re: Open phones for privacy/anonymity applications, Guardian coderman (Jan 01)
Re: [SECURITY] [DSA 2833-1] openssl security update coderman (Jan 01)

conqu3r . zeng

[CVE-2014-1203] Eyou Mail System Remote Code Execution conqu3r . zeng (Jan 08)

Dan Ballance

Re: EE BrightBox router hacked - bares all if you ask nicely Dan Ballance (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Dan Ballance (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Dan Ballance (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Dan Ballance (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Dan Ballance (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Dan Ballance (Jan 16)

Daniel Corbe

Re: Open phones for privacy/anonymity applications, Guardian Daniel Corbe (Jan 07)

Daniël W . Crompton

Re: EE BrightBox router hacked - bares all if you ask nicely Daniël W . Crompton (Jan 16)

Daniel Wood

[CVE-2014-0647] Insecure Data Storage of User Data Elements in Starbucks v2.6.1 iOS mobile application Daniel Wood (Jan 14)
Re: [CVE-2014-0647] Insecure Data Storage of User Data Elements in Starbucks v2.6.1 iOS mobile application Daniel Wood (Jan 18)
Re: Ubuntu, duckduckgo, and additional info Daniel Wood (Jan 15)

dave

DDoS against Gamerfirst dave (Jan 21)

David Kennedy

Re: Making waves on Twitter! David Kennedy (Jan 27)
Re: Making waves on Twitter! David Kennedy (Jan 27)
Making waves on Twitter! David Kennedy (Jan 26)

David Nalley

Updated [CVE-2013-6398] CloudStack Virtual Router stop/start modifies firewall rules allowing additional access David Nalley (Jan 11)
Updated [CVE-2014-0031] CloudStack ListNetworkACL API discloses ACLs for other users David Nalley (Jan 11)

En.wooyun.org

[Wooyun] OVH a subsite Zabbix Sql injection En.wooyun.org (Jan 08)
[Wooyun] NVIDIA a SAP NETWEAVER remote command execution En.wooyun.org (Jan 08)

Fernando Gont

SI6 Networks' IPv6 Toolkit v1.5.2 released! Fernando Gont (Jan 17)

Florian Weimer

[SECURITY] [DSA 2849-1] curl security update Florian Weimer (Jan 31)

Fredrik Söderblom

[CVE-2013-6838] Enghouse Interactive IVR Pro (VIP2000) remote root authentication bypass Vulnerability Fredrik Söderblom (Jan 16)

freeman

CALL FOR PAPERS - NUIT DU HACK - 28/29 JUNE 2014 freeman (Jan 24)

Gabriel Weinberg

Re: Ubuntu, duckduckgo, and additional info Gabriel Weinberg (Jan 15)

Georgi Guninski

22 January 2014, SEA : M$ = 3 : 0 Georgi Guninski (Jan 21)
Microsoft Twitter accounts, blog hijacked by SEA Georgi Guninski (Jan 13)
Re: Where are you guys standing re: the (full) disclosure Georgi Guninski (Jan 08)

gold flake

Re: EE BrightBox router hacked - bares all if you ask nicely gold flake (Jan 16)

Hafez Kamal

[HITB-Announce] #HITB2014AMS Call for Papers - FINAL CALL Hafez Kamal (Jan 16)
[HITB-Announce] HITB Magazine Issue 10 Out Now Hafez Kamal (Jan 06)

halfdog

Re: FPU-state NULL-deref exploitation (was vm86 syscall kernel-panic and some more goodies waiting to be analyzed) halfdog (Jan 07)

Henri Salo

Re: Romanian hacker unknown string Henri Salo (Jan 17)

illwill

Re: Security is fun(ny) again illwill (Jan 09)

Ivan .Heca

How a teenager helpfully reported a government security flaw – and could be charged in return Ivan .Heca (Jan 23)

Jakub Jozwiak

[CVE-2014-1673] Check Point Session Authentication Agent vulnerability Jakub Jozwiak (Jan 27)

James Condron

Re: Romanian hacker unknown string James Condron (Jan 17)
Re: Romanian hacker unknown string James Condron (Jan 17)
Re: Romanian hacker unknown string James Condron (Jan 17)
Re: Romanian hacker unknown string James Condron (Jan 17)

Jean-Jamil Khalifé

0day - MuPDF Stack-based Buffer Overflow in xps_parse_color() Jean-Jamil Khalifé (Jan 21)

Jeffrey Walton

Re: EE BrightBox router hacked - bares all if you ask nicely Jeffrey Walton (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Jeffrey Walton (Jan 16)

John Cartwright

List Charter John Cartwright (Jan 13)

J. Oquendo

Security is fun(ny) again J. Oquendo (Jan 09)

Jordon Bedwell

Re: Ubuntu, duckduckgo, and additional info Jordon Bedwell (Jan 15)

Kenneth F. Belva

Re: Yahoo Bug Bounty Program Vulnerability #2 Open Redirect Kenneth F. Belva (Jan 13)

Lodewijk andré de la porte

Re: Open phones for privacy/anonymity applications, Guardian Lodewijk andré de la porte (Jan 01)

Luciano Bello

[SECURITY] [DSA 2831-1] puppet security update Luciano Bello (Dec 31)

Major Malfunction

DC4420 - London DEFCON - January meet - Tuesday 28th January 2014 Major Malfunction (Jan 27)

Marshall Whittaker

Sex links fail Marshall Whittaker (Jan 13)

Mikhail A. Utin

: EE BrightBox router hacked - bares all if you ask nicely Mikhail A. Utin (Jan 16)

Mohammad Hosein

Re: Microsoft Twitter accounts, blog hijacked by SEA Mohammad Hosein (Jan 13)

Moritz Muehlenhoff

[SECURITY] [DSA 2841-1] movabletype-opensource security update Moritz Muehlenhoff (Jan 11)
[SECURITY] [DSA 2837-1] openssl security update Moritz Muehlenhoff (Jan 07)
[SECURITY] [DSA 2835-1] asterisk security update Moritz Muehlenhoff (Jan 05)
[SECURITY] [DSA 2845-1] mysql-5.1 security update Moritz Muehlenhoff (Jan 17)
[SECURITY] [DSA 2842-1] libspring-java security update Moritz Muehlenhoff (Jan 13)
[SECURITY] [DSA 2846-1] libvirt security update Moritz Muehlenhoff (Jan 17)
[SECURITY] [DSA 2833-1] openssl security update Moritz Muehlenhoff (Jan 01)
[SECURITY] [DSA 2838-1] libxfont security update Moritz Muehlenhoff (Jan 07)

MustLive

Multiple vulnerabilities at president.gov.ua MustLive (Jan 19)
Dictatorial laws in Ukraine MustLive (Jan 24)
DAVOSET v.1.1.6 MustLive (Jan 24)
DAVOSET v.1.1.5 MustLive (Jan 01)

Nguyen Anh Quynh

Capstone 2.0 is released! Nguyen Anh Quynh (Jan 22)

Nicholas Lemonias.

Satellite Security - A story NASA would love to see. Nicholas Lemonias. (Jan 26)

Nicolas A. Economou

Sentinel beta version released Nicolas A. Economou (Jan 27)

NI @root

Oracle Reports Exploit - Remote Shell/Dump Passwords NI @root (Jan 28)

nullcon

[CTF] nullcon HackIM 2014 will start at 24-01-2014, when the clock will strike at 11:59 (+5:30 GMT) nullcon (Jan 23)
nullcon Blackshield Awards 2014 nullcon (Jan 09)

Omar Benbouazza

Rooted CON 2014 attendee registration is open! Omar Benbouazza (Jan 14)
Dates for the opening of registration for Rooted CON 2014 Omar Benbouazza (Jan 11)

Patrick O'Keeffe

Ubuntu, duckduckgo, and additional info Patrick O'Keeffe (Jan 18)

Pedro Luis Karrasquillo

Re: Where are you guys standing re: the (full) disclosure Pedro Luis Karrasquillo (Jan 10)
Re: ObamaCare California Admin Interface Exposed to Entire Internet + more! Pedro Luis Karrasquillo (Jan 13)

Pedro Ribeiro

[CVE -2014-1201] Lorex security DVD ActiveX control buffer overflow Pedro Ribeiro (Jan 10)
Re: [CVE -2014-1201] Lorex security DVD ActiveX control buffer overflow Pedro Ribeiro (Jan 10)
[CVE-2013-6040] MW6 Technologies ActiveX buffer overflows and remote code execution Pedro Ribeiro (Jan 22)

Pedro Worcel

Re: Chrome (and Safari) antiXSS filter bypass Pedro Worcel (Jan 24)

Pichaya Morimoto

pfSense 2.1 Privilege Escalation from less privileged users (LFI/RCE) Pichaya Morimoto (Jan 28)

Pivotal Security Team

CVE-2013-6429 Fix for XML External Entity (XXE) injection (CVE-2013-4152) in Spring Framework was incomplete Pivotal Security Team (Jan 15)
CVE-2013-6430 Possible XSS when using Spring MVC Pivotal Security Team (Jan 15)

Raphael Geissert

[SECURITY] [DSA 2844-1] djvulibre security update Raphael Geissert (Jan 15)
[SECURITY] [DSA 2836-1] devscripts security update Raphael Geissert (Jan 06)

Raymond Zhang

Fwd: Trustlook discovered Microsoft’s first high risk Android Vulnerability Raymond Zhang (Jan 24)

Salvatore Bonaccorso

[SECURITY] [DSA 2848-1] mysql-5.5 security update Salvatore Bonaccorso (Jan 23)
[SECURITY] [DSA 2834-1] typo3-src security update Salvatore Bonaccorso (Jan 01)
[SECURITY] [DSA 2831-2] puppet regression update Salvatore Bonaccorso (Jan 17)
[SECURITY] [DSA 2850-1] libyaml security update Salvatore Bonaccorso (Jan 31)
[SECURITY] [DSA 2847-1] drupal7 security update Salvatore Bonaccorso (Jan 20)
[SECURITY] [DSA 2832-1] memcached security update Salvatore Bonaccorso (Jan 01)
[SECURITY] [DSA 2843-1] graphviz security update Salvatore Bonaccorso (Jan 13)
[SECURITY] [DSA 2840-1] srtp security update Salvatore Bonaccorso (Jan 10)
[SECURITY] [DSA 2839-1] spice security update Salvatore Bonaccorso (Jan 08)

scadastrangelove

SCADA StrangeLove 30C3 releases: all in one scadastrangelove (Jan 04)

Scott Helme

EE BrightBox router hacked - bares all if you ask nicely Scott Helme (Jan 15)

Scott Parish

Remote Command Injection Vulnerability in SkyBlueCanvas CMS Scott Parish (Jan 24)

SEC Consult Vulnerability Lab

SEC Consult SA-20140122-0 :: Critical vulnerabilities in T-Mobile HOME NET Router LTE (Huawei B593u-12) SEC Consult Vulnerability Lab (Jan 22)

security

[ MDVSA-2014:023 ] hplip security (Jan 24)
[ MDVSA-2014:020 ] x11-server security (Jan 22)
[ MDVSA-2014:018 ] net-snmp security (Jan 22)
[ MDVSA-2014:009 ] librsvg security (Jan 17)
[ MDVSA-2014:016 ] spice security (Jan 22)
[ MDVSA-2014:013 ] libxfont security (Jan 21)
[ MDVSA-2014:012 ] nss security (Jan 20)
[ MDVSA-2014:021 ] perl-Proc-Daemon security (Jan 24)
[ MDVSA-2014:005 ] ejabberd security (Jan 16)
[ MDVSA-2014:017 ] net-snmp security (Jan 22)
[ MDVSA-2014:006 ] libxslt security (Jan 16)
[ MDVSA-2014:001 ] kernel security (Jan 13)
[ MDVSA-2014:024 ] graphviz security (Jan 24)
[ MDVSA-2014:011 ] java-1.7.0-openjdk security (Jan 20)
[ MDVSA-2014:014 ] php security (Jan 21)
[ MDVSA-2014:015 ] cups security (Jan 22)
[ MDVSA-2014:003 ] nrpe security (Jan 16)
[ MDVSA-2014:004 ] nagios security (Jan 16)
[ MDVSA-2014:008 ] openjpeg security (Jan 17)
[ MDVSA-2014:007 ] openssl security (Jan 17)
[ MDVSA-2014:002 ] bind security (Jan 16)
[ MDVSA-2014:022 ] augeas security (Jan 24)
[ MDVSA-2014:019 ] elinks security (Jan 22)
[ MDVSA-2014:010 ] memcached security (Jan 17)

Security Explorations

[SE-2013-01] Security vulnerabilities in Oracle Java Cloud Service Security Explorations (Jan 31)

security-news

[Security-news] SA-CONTRIB-2014-001 - Entity API - Access Bypass security-news (Jan 08)
[Security-news] PSA-2014-001 - Media - Access Bypass security-news (Jan 08)
[Security-news] SA-CONTRIB-2014-004 - Secure Cookie Data - Faulty Hashing security-news (Jan 22)
[Security-news] SA-CONTRIB-2014-006 - Language Switcher Dropdown - Open Redirect security-news (Jan 22)
[Security-news] SA-CORE-2014-001 - Drupal core - Multiple vulnerabilities security-news (Jan 15)
[Security-news] SA-CONTRIB-2014-002 - Anonymous Posting - Cross Site Scripting (XSS) security-news (Jan 15)
[Security-news] SA-CONTRIB-2014-008 - Tribune - Cross Site Scripting (XSS) security-news (Jan 29)
[Security-news] SA-CONTRIB-2014-005 - Leaflet - Access bypass security-news (Jan 22)
[Security-news] SA-CONTRIB-2014-003 - Doubleclick for Publishers DFP - Cross Site Scripting (XSS) security-news (Jan 22)
[Security-news] SA-CONTRIB-2014-007 - Services - Multiple access bypass vulnerabilities security-news (Jan 29)

Seth Arnold

Re: Ubuntu, duckduckgo, and additional info Seth Arnold (Jan 15)
Re: Ubuntu, duckduckgo, and additional info Seth Arnold (Jan 14)

shady . liu

[CVE-2013-6030]Emerson Network Power Avocent MergePoint Unity 2016 KVM switches contain a directory traversal vulnerability shady . liu (Jan 24)

silence_is_best

Re: Ubuntu, duckduckgo, and additional info silence_is_best (Jan 15)
Re: Ubuntu, duckduckgo, and additional info silence_is_best (Jan 15)
Ubuntu, duckduckgo, and additional info silence_is_best (Jan 14)

sixtyvividtails

Re: DoS vulnerability in Adobe Flash Player (BSOD) sixtyvividtails (Jan 06)

Stefan Schurtz

ssl.bing.com - Cross-site Scripting vulnerability Stefan Schurtz (Jan 25)
Yahoo Bug Bounty Program Vulnerability #2 Open Redirect Stefan Schurtz (Jan 11)
Re: Yahoo Bug Bounty Program Vulnerability #2 Open Redirect Stefan Schurtz (Jan 13)
Wordpress Plugin WP-Members Version 2.8.9 - Stored and reflected Cross-site Scripting vulnerabilities Stefan Schurtz (Jan 08)

Sullo

RVAsec 2014 CFP Sullo (Jan 27)

Thomas Pollet

ADV: IBM QRadar SIEM Thomas Pollet (Jan 24)

thomas . soete

Re: [Wooyun] OVH a subsite Zabbix Sql injection thomas . soete (Jan 09)

Tomaz Muraus

[CVE-2013-6480] Libcloud doesn't send scrub_data query parameter when destroying a DigitalOcean node Tomaz Muraus (Jan 01)

Tracy Reed

Re: EE BrightBox router hacked - bares all if you ask nicely Tracy Reed (Jan 16)

Trustwave Advisories

TWSL2014-002: Buffer Overflow Vulnerability in DaumGame ActiveX Trustwave Advisories (Jan 21)
TWSL2014-001: Multiple Vulnerabilities in Franklin Fueling's TS-550 evo Trustwave Advisories (Jan 21)

truthinallthings

Healthcare.gov noise truthinallthings (Jan 24)

Valdis . Kletnieks

Re: EE BrightBox router hacked - bares all if you ask nicely Valdis . Kletnieks (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Valdis . Kletnieks (Jan 16)

"VMware Security Response Center"

NEW : VMSA-2014-0001 - VMware Workstation, Player, Fusion, ESXi, ESX and vCloud Director address several security issues "VMware Security Response Center" (Jan 16)

Vulnerability Lab

Mozilla Bug Bounty #5 - WireTap Remote Web Vulnerability Vulnerability Lab (Jan 27)
SimplyShare v1.4 iOS - Multiple Web Vulnerabilities Vulnerability Lab (Jan 29)

vulns () 11paths com

Chrome (and Safari) antiXSS filter bypass vulns () 11paths com (Jan 22)

Whitehat Whistleblower

ObamaCare California Admin Interface Exposed to Entire Internet + more! Whitehat Whistleblower (Jan 10)

William Costa

Contact PSIRT Fortinet William Costa (Jan 24)

YOGESH PHADTARE

Collabtive Sql Injection YOGESH PHADTARE (Jan 15)

Yves-Alexis Perez

[SECURITY] [DSA 2826-2] denyhosts regression update Yves-Alexis Perez (Jan 24)

Źmicier Januszkiewicz

Re: EE BrightBox router hacked - bares all if you ask nicely Źmicier Januszkiewicz (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Źmicier Januszkiewicz (Jan 16)
Re: EE BrightBox router hacked - bares all if you ask nicely Źmicier Januszkiewicz (Jan 16)