Full Disclosure: by date

452 messages starting Apr 01 10 and ending Apr 30 10
Date index | Thread index | Author index


Thursday, 01 April

Re: Clever DEP Trick Christoph Gruber
Zabbix <= 1.8.1 SQL Injection Dawid Golunski
Re: Advisory: Weak RNG in PHP session ID generation leads to session hijacking Pierre Pronchery
Advisory Optimal Archive 1.38 tecr0c
VMSA-2010-0006 ESX Service Console updates for samba and acpid VMware Security Team
Re: Introducing SecurityTube Questions! n3ptun3
Is Digital Due Process legit? n3ptun3
Re: Is Digital Due Process legit? Jeffrey Walton
Re: Victorinox Launches Super-Secure USB Stick Rohit Patnaik
Re: RFID DOS, DDOS Rohit Patnaik
The PDF-specific exploitation research cocoruder

Friday, 02 April

[TOOL] Version 0.2 of bing-ip2hosts released Andrew Horton
Vulnerability Centreon IT & Network Monitoring v2.1.5 Mehdi Mahdjoub - Sysdream IT Security Services
Re: Security system Haris Pilton
3rd CfP: ACCESS 2010 || September 20-25, 2010 - Valencia, Spain Sandra Sendra
3rd CfP: INTERNET 2010 || September 20-25, 2010 - Valencia, Spain Sandra Sendra
Re: Security system T Biehn
ZDI-10-033: Microsoft Internet Explorer TIME2 Behavior Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-034: Microsoft Internet Explorer Tabular Data Control ActiveX Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-035: Apple QuickTime genl Atom Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-036: Apple QuickTime H.263 PictureHeader Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-037: Apple QuickTime MJPEG Sample Dimensions Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-038: Apple QuickTime QDMC/QDM2 Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-039: Apple OS X Internet Enabled Disk Image Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-040: Apple QuickTime RLE Bit Depth Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-041: Apple QuickTime QDM2/QDCA Atom Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-042: Apple QuickTime MediaVideo Compressor Name Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-043: Apple QuickTime FlashPix NumberOfTiles Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-044: Apple QuickTime FLI LinePacket Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-045: Apple QuickTime MPEG-1 genl Atom Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-046: Mozilla Firefox Web Worker Array Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-047: Mozilla Firefox libpr0n imgContainer Bits-Per-Pixel Change Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-048: Mozilla Firefox nsTreeContentView Dangling Pointer Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-049: Mozilla Firefox PluginArray nsMimeType Dangling Pointer Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-050: Mozilla Firefox nsTreeSelection EventListener Remote Code Execution Vulnerability ZDI Disclosures
Re: Security system Michael Holstein
Non ZDI Post - EOM Rob Fuller
Re: Security system Benji
[CORELAN]-10-018 - TugZip 3.5 Lincoln
Apple patent lawyers fail to close ddtek, Defcon CTF goes on vulc@n
FileCache: tmp file permission vulnerability. bugs lists
Re: Security system Lupus Yonderboy
[SECURITY] [DSA 2026-1] New netpbm-free packages fix denial of service Giuseppe Iuculano
Vulnerabilities in HoloCMS MustLive
Re: FileCache: tmp file permission vulnerability. Vladimir Lettiev
Re: FileCache: tmp file permission vulnerability. paul . szabo

Saturday, 03 April

Sun D3VS SM0KiNG PoT AGAiN Kingcope
Re: Sun D3VS SM0KiNG PoT AGAiN Kingcope
CRiMiNAL M Kingcope
CRiMiNAL MiNDED - iSOWAR3Z SPLOiT Kingcope
Re: Sun D3VS SM0KiNG PoT AGAiN Christian Sciberras
Re: Sun D3VS SM0KiNG PoT AGAiN Kingcope
[SECURITY] [DSA 2027-1] New xulrunner packages fix several vulnerabilities Moritz Muehlenhoff
Check those default iPhone settings... Thor (Hammer of God)
[CORELAN-10-020] - ZipScan 2.2c .zip file Stack BoF Security

Sunday, 04 April

How to Detect Malware from Proxy Log(ISA,squid) information security
Re: Security system M.B.Jr.
[SECURITY] Zip Unzip v6 (.zip) 0day stack buffer overflow vulnerability Steven Seeley
Vulnerabilities in GunCMS and PhoenixCMS PHP Edition MustLive

Monday, 05 April

ZDI-10-051: Sun Java Runtime RMIConnectionImpl Privileged Context Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-052: Sun Java Runtime Environment XNewPtr Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-053: Sun Java Runtime Environment MIDI File metaEvent Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-054: Sun Java Runtime Environment JPEGImageReader stepX Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-055: Sun Java Runtime Environment Mutable InetAddress Socket Policy Violation Vulnerability ZDI Disclosures
ZDI-10-056: Sun Java Runtime Environment Trusted Methods Chaining Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-057: Sun Java Runtime Environment JPEGImageDecoderImpl Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-058: Apple Mac OS X ImageIO Framework JPEG2000 Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-059: Sun Java Runtime Environment JPEGImageEncoderImpl Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-060: Sun Java Runtime Environment MixerSequencer Invalid Array Index Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-061: Sun Java Runtime CMM readMabCurveData Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-062: Novell Netware NWFTPD RMD/RNFR/DELE Argument Parsing Remote Code Execution Vulnerabilities ZDI Disclosures
ZDI-10-063: Mozilla Firefox Cross Document DOM Node Moving Code Execution Vulnerability ZDI Disclosures
Miranda TLS MitM with XMPP/Jabber protocol Jan Schejbal
Re: RFID DOS, DDOS Jan Schejbal
Compliance Is Wasted Money, Study Finds Ivan .

Tuesday, 06 April

[SECURITY] [DSA 2028-1] New xpdf packages fix several vulnerabilities Luciano Bello
[SECURITY] [DSA 2029-1] New imlib2 packages fix arbitrary code execution Nico Golde
Vulnerabilities in TAK cms MustLive
Hack.lu 2010 CfP info
[SECURITY] - Jzip (.zip) Unicode bof Vulnerability Steven Seeley
ZDI-10-065: CA XOsoft xosoapapi.asmx Multiple Remote Code Execution Vulnerabilities ZDI Disclosures
ZDI-10-066: CA XOsoft Control Service entry_point.aspx Remote Code Execution Vulnerability ZDI Disclosures
CA20100406-01: Security Notice for CA XOsoft Kotas, Kevin J
ZDI-10-067: Apple QuickTime Pict BkPixPat Remote Code Execution Vulnerability ZDI Disclosures
CORE-2010-0323: XSS Vulnerability in NextGEN Gallery Wordpress Plugin CORE Security Technologies Advisories
[ MDVSA-2010:069 ] nss security
[USN-923-1] OpenJDK vulnerabilities Kees Cook
[USN-924-1] Kerberos vulnerabilities Kees Cook

Wednesday, 07 April

Re: Compliance Is Wasted Money, Study Finds Bert Knabe
[SECURITY] [DSA 2030-1] New mahara packages fix sql injection Nico Golde
fspro.net Lock My PC 4 backdoor password Bugs NotHugs
Re: fspro.net Lock My PC 4 backdoor password Juha-Matti Laurio
[Full-Disclosure] klout.com cookie vulnerability PoC Kenny Vaneetvelde
Re: Compliance Is Wasted Money, Study Finds John Morrison
Re: Compliance Is Wasted Money, Study Finds Keith Tomler
Re: Compliance Is Wasted Money, Study Finds J Roger
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
Netsparker Community Edition - Free web app scanner is out! Demo Delivery
Re: Compliance Is Wasted Money, Study Finds J Roger
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
Vulnerabilities in Dunia Soccer MustLive
Re: Compliance Is Wasted Money, Study Finds Stephen Mullins
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
Re: Compliance Is Wasted Money, Study Finds Tracy Reed
TCPDF Library Remote Code Execution Vulnerability Matthias -apoc- Hecker

Thursday, 08 April

DeepSec 2010 - Call for Papers and Experts DeepSec Conference
Re: Compliance Is Wasted Money, Study Finds Digital X
Foxit 3.2.0.303 and Before Command Execution PoC Peorth account
Re: why not a sandbox Marius
[HITB-Announce] FINAL CALL - CFP for HITBSecConf2010 Amsterdam Hafez Kamal
[USN-925-1] MoinMoin vulnerabilities Jamie Strandboge
Re: Vulnerabilities in TAK cms T Biehn
Vulnerabilities in CMS SiteLogic MustLive
www.Demolay.org - full disclosure sql injection vulnerability Malice Anonymous
Chain based SQL injection Владимир Воронцов
Re: Vulnerabilities in TAK cms Benji
[USN-926-1] ClamAV vulnerabilities Jamie Strandboge
[USN-624-2] Erlang vulnerability Jamie Strandboge

Friday, 09 April

VMSA-2010-0007 VMware hosted products, vCenter Server and ESX patches resolve multiple security issues VMware Security team
Java Deployment Toolkit Performs Insufficient Validation of Parameters Tavis Ormandy
Re: Java Deployment Toolkit Performs InsufficientValidation of Parameters Larry Seltzer
Secunia Research: Pulse CMS Arbitrary File Upload Vulnerability Secunia Research
Secunia Research: Pulse CMS Cross-Site Request Forgery Secunia Research
List Charter John Cartwright
Vulnerabilities in phpCOIN MustLive
Re: Vulnerabilities in phpCOIN Jan G.B.
Re: Vulnerabilities in phpCOIN Valdis . Kletnieks
Re: Vulnerabilities in phpCOIN Jan G.B.
LFI In Multi Profit Websites rockey killer
Re: Vulnerabilities in phpCOIN Christian Sciberras
Re: Vulnerabilities in phpCOIN Jeff Kell
ZDI-10-068: Apple QuickTime H.263 Array Index Parsing Remote Code Execution Vulnerability ZDI Disclosures
Re: Vulnerabilities in TAK cms T Biehn
Vulnerability in Tembria Server Monitor Security
[USN-927-1] NSS vulnerability Jamie Strandboge
[USN-921-1] Firefox 3.5 and Xulrunner vulnerabilities Jamie Strandboge
iDefense Security Advisory 04.09.10: VMware VMnc Codec Heap Overflow Vulnerability iDefense Labs
[USN-920-1] Firefox 3.0 and Xulrunner vulnerabilities Jamie Strandboge
Re: Compliance Is Wasted Money, Study Finds Tracy Reed
CVE-2009-4510: TANDBERG VCS Static SSH Host Keys VSR Advisories
CVE-2009-4511: TANDBERG VCS Arbitrary File Retrieval VSR Advisories
CVE-2009-4509: TANDBERG VCS Authentication Bypass VSR Advisories

Saturday, 10 April

Anthology of attacks via captchas MustLive
Secunia Research: VMWare VMnc Codec HexTile Encoding Buffer Overflow Secunia Research
Secunia Research: VMWare VMnc Codec HexTile Encoding Two Integer Truncation Vulnerabilities Secunia Research
Free Security Video Tutorials for beginners lists73
Re: Compliance Is Wasted Money, Study Finds Nick FitzGerald
Re: Free Security Video Tutorials for beginners netinfinity
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
Vulnerabilities in CMS SiteLogic MustLive
Re: Free Security Video Tutorials for beginners lists73
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks

Sunday, 11 April

HITBSecConf DUBAI 2010: Learn more about web attacks and stealth hacking laurent.oudot () tehtri-security com
[USN-927-2] NSS regression Jamie Strandboge
[USN-927-3] Thunderbird regression Jamie Strandboge

Monday, 12 April

[SECURITY] [DSA 2031-1] New krb5 packages fix denial of service Giuseppe Iuculano
[SECURITY] [DSA 2032-1] New libpng packages fix several vulnerabilities Giuseppe Iuculano
Re: Vulnerabilities in WordPress MustLive
[Tyr 2] Article Friendly File Inclusion Ch3Kan
Re: Anthology of attacks via captchas Jan G.B.

Tuesday, 13 April

ACROS Security: Local Binary Planting in VMware Tools for Windows (ASPR #2010-04-12-2) ACROS Lists
ACROS Security: Remote Binary Planting in VMware Tools for Windows (ASPR #2010-04-12-1) ACROS Lists
Insufficient Anti-automation and Denial of Service vulnerabilities in multiple systems MustLive
Simple RFID Spoofer sketch sketch
Advisory 01/2010: MyBB Password Reset Email BCC: Injection Vulnerability Stefan Esser
Re: ACROS Security: Remote Binary Planting in VMware Tools for Windows (ASPR #2010-04-12-1) Nam Nguyen
Advisory 02/2010: MyBB Password Reset Weak Random Numbers Vulnerability Stefan Esser
Advisory 02/2010: MyBB Password Reset Weak Random Numbers Vulnerability Stefan Esser
Best Wireless Sniffer for MAC OS X Justin Chang
Re: Best Wireless Sniffer for MAC OS X Cody Robertson
Re: Best Wireless Sniffer for MAC OS X KF (lists)
[ MDVSA-2010:070 ] firefox security
ZDI-10-069: Microsoft Office Publisher File Conversion TextBox Processing Buffer Overflow Vulnerability ZDI Disclosures
ZDI-10-070: Microsoft Windows Media Player Codec Retrieval Dangling Pointer Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-071: Adobe Reader TrueType Font Handling Remote Code Execution Vulnerability ZDI Disclosures
Re: Best Wireless Sniffer for MAC OS X David Maynor
Re: Vulnerabilities in CMS SiteLogic Henri Salo
Re: Best Wireless Sniffer for MAC OS X James Lay
ZDI-10-073: Sun Microsystems Directory Server DSML-over-HTTP Username Search Denial of Service Vulnerability ZDI Disclosures
ZDI-10-074: Sun Microsystems Directory Server Enterprise ASN.1 Parsing Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-075: Sun Microsystems Directory Server Enterprise DSML UTF-8 Denial of Service Vulnerability ZDI Disclosures
[ MDVSA-2010:071 ] krb5 security
Fortinet Advisory: Fortinet Discovers Multiple Microsoft Visio Vulnerabilities (MS10-028) liubing
Fortinet Advisory: Fortinet Discovers Multiple Adobe Reader / Acrobat Vulnerabilities (APSB10-09) liubing
Re: Insufficient Anti-automation and Denial of Service vulnerabilities in multiple systems Kaddeh

Wednesday, 14 April

Re: Insufficient Anti-automation and Denial of Service vulnerabilities in multiple systems Bogdan Calin
[ MDVSA-2010:072 ] cups security
Cisco Security Advisory: Cisco Secure Desktop ActiveX Control Code Execution Vulnerability Cisco Systems Product Security Incident Response Team
Re: Insufficient Anti-automation and Denial of Service vulnerabilities in multiple systems Henri Salo
[ MDVSA-2010:073 ] cups security
[ MDVSA-2010:073-1 ] cups security
ZDI-10-072: Cisco Secure Desktop CSDWebInstaller ActiveX Control Remote Code Execution Vulnerability ZDI Disclosures
ZDI-10-076: Apple Preview libFontParser SpecialEncoding Remote Code Execution Vulnerability ZDI Disclosures

Thursday, 15 April

[USN-928-1] Sudo vulnerability Jamie Strandboge
[ MDVSA-2010:074 ] kdebase security
Hackproofing Oracle Financials 11i & R12 Joxean Koret
[USN-890-6] CMake vulnerabilities Jamie Strandboge
[ MDVSA-2010:075 ] openoffice.org security
Imperva SecureSphere Web Application Firewall and Database Firewall Bypass Vulnerability Clear Skies Security
Re: Anthology of attacks via captchas MustLive
TELUS Security Labs VR - Adobe Reader U3D CLODMeshDeclaration Shading Count Memory Corruption TELUS Security Labs - Vulnerability Research
stratsec Security Advisory: SS-2010-004 Microsoft SMB Client Kernel Stack Overflow stratsec Research
Cert-Lexsi - Microsoft Windows Media Services MMS Buffer Overflow Vulnerability Fabien PERIGAUD
Secunia Research: Visualization Library DAT File Parsing Vulnerabilities Secunia Research
How to disable Java Deployment Toolkit Kristof Zelechovski
New project Vulnerable Sites Databse Tomy
Vulnerability in CB Captcha for Joomla and Mambo MustLive
[SECURITY] [DSA 2033-1] New ejabberd packages fix denial of service Sébastien Delafond
[CVE-2010-0432] Apache OFBiz Multiple XSS Vulnerabilities Lucas Apa
Re: Vulnerabilities in phpCOIN MustLive
Re: Vulnerability in CB Captcha for Joomla and Mambo Benji
Re: Vulnerabilities in phpCOIN Benji
[USN-929-1] irssi vulnerabilities Jamie Strandboge
CORELAN-10-025 Archive Searcher .zip Stack Overflow Security

Friday, 16 April

Turning SMB client side bug to server side laurent gaffie
Re: Best Wireless Sniffer for MAC OS X NOC
iDefense Security Advisory 04.15.10: Multiple Vendor AgentX++ Stack Buffer Overflow Vulnerability iDefense Labs
iDefense Security Advisory 04.15.10: Multiple Vendor AgentX++ Integer Overflow Vulnerability iDefense Labs
Re: Java Deployment Toolkit Performs Insufficient Validation of Parameters Nick Boyce
Re: How to disable Java Deployment Toolkit Nick Boyce

Saturday, 17 April

[ MDVSA-2010:077 ] nss_db security
[ MDVSA-2010:078 ] sudo security
[ MDVSA-2010:076 ] openssl security
[ MDVSA-2010:079 ] irssi security
[ MDVSA-2010:079 ] irssi security
[ MDVSA-2010:080 ] brltty security

Sunday, 18 April

Re: How to disable Java Deployment Toolkit Křištof Želechovski
[SECURITY] [DSA 2034-1] New phpmyadmin packages fix several vulnerabilities Thijs Kinkhorst
[SECURITY] [DSA-2035-1] New apache2 packages fix several issues Stefan Fritsch
[SECURITY] [DSA 2036-1] New jasper packages fix denial of service Thijs Kinkhorst
[SECURITY] [DSA 2037-1] New kdm packages fix privilege escalation Thijs Kinkhorst
Digivote replay attack D V
[ MDVSA-2010:081 ] apache-mod_auth_shadow security
[ MDVSA-2010:082 ] clamav security
New vulnerabilities in CMS SiteLogic MustLive
[SECURITY] [DSA 2038-1] New pidgin packages fix denial of service Thijs Kinkhorst

Monday, 19 April

Secunia Research: e107 Content Management Plugin Script Insertion Vulnerability Secunia Research
Secunia Research: e107 Avatar/Photograph Image File Upload Vulnerability Secunia Research
Deadline Extension: ACCESS 2010 || September 20-25, 2010 - Valencia, Spain Sandra Sendra
[CORELAN-10-026] TweakFS Zip Stack BOF Security
CompleteFTP v3.3.0 - Remote Memory Consumption DoS Mehdi Mahdjoub [SYSDREAM]
Deadline Extension: INTERNET 2010 || September 20-25, 2010 - Valencia, Spain Sandra Sendra
[USN-931-1] FFmpeg vulnerabilities Marc Deslauriers
[ MDVSA-2010:076-1 ] openssl security
[ MDVSA-2010:076-1 ] openssl security
[USN-932-1] KDM vulnerability Jamie Strandboge
[Tool] ReFrameworker 1.1 Erez Metula
sudoedit local privilege escalation through PATH manipulation Agazzini Maurizio
Security Training Classes at SyScan'10 Singapore - Registration Opens organiser () syscan org
Fixing vulnerabilities in captcha-scripts mentioned in my last advisories MustLive

Tuesday, 20 April

[CORELAN-10-027] - HP Operations Manager for Windows, Remote Execution of Arbitrary Code (srcvw4.dll and srcvw32.dll) Security
[ MDVSA-2010:083 ] emacs security
[CORELAN-10-028] - SpeedCommander 13.10 Memory Corruption DoS Security
Re: [Tool] ReFrameworker 1.1 T Biehn
[USN-929-2] irssi regression Jamie Strandboge
[ MDVSA-2010:070-1 ] firefox security

Wednesday, 21 April

Old school bugs in Intel compiler and debugger FLEXlm FlexNet DRM Marsh Ray
Cisco Security Advisory: Cisco Small Business Video Surveillance Cameras and Cisco 4-Port Gigabit Security Routers Authentication Bypass Vulnerability Cisco Systems Product Security Incident Response Team
ZDI-10-077: Adobe Download Manager Atlcom.get_atlcom ActiveX Control Remote Code Execution Vulnerability ZDI Disclosures
CORE-2010-0406 - User Invoices Persistent XSS Vulnerability in CactuShop CORE Security Technologies Advisories
London DEFCON April meet - DC4420 - Wed 28th April 2010 Major Malfunction
[CORELAN-10-029] - ZipGenius v6.3.1.2552 zgtips.dll Stack Buffer Overflow Security
IE8 img tag HiJacking Владимир Воронцов
We must work harder on cloud, says Microsoft Ivan .
Re: We must work harder on cloud, says Microsoft Jason Nada
Re: We must work harder on cloud, says Microsoft Ivan .
Re: We must work harder on cloud, says Microsoft Rohit Patnaik
Re: We must work harder on cloud, says Microsoft Rohit Patnaik
Amiro.CMS <= 5.4.4 SQL inj Владимир Воронцов

Thursday, 22 April

Please Welcome SuperFB ( and ignore this message ) PsychoBilly
Security-Assessment.com WhitePaper/Addendum: Cross Context Scripting with Firefox & Exploiting Cross Context Scripting vulnerabilities in Firefox Roberto Suggi Liverani
Bonsai Information Security - OS Command Injection in Cacti <= 0.8.7e Bonsai Information Security Advisories
Bonsai Information Security - SQL Injection in Cacti <= 0.8.7e Bonsai Information Security Advisories
Apache ActiveMQ is prone to source code disclosure vulnerability. SecPod Research
Secunia Research: imlib2 "IMAGE_DIMENSIONS_OK()" Logic Error Secunia Research
Call for participation -- Eth0:2010 Summer Mark Janssen
CVE or SUN bug number for http://lists.grok.org.uk/pipermail/full-disclosure/2010-April/074036.html Lode, Nilss
Vulnerabilities in NovaBoard MustLive
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Jcaptcha vulnerability hvazquez
Re: Please Welcome SuperFB ( and ignore this message ) Tonu Samuel
[Announcement] Introducing SecurityTube Tools section! netinfinity
Re: Amiro.CMS <= 5.4.4 SQL inj Henri Salo
Re: [Announcement] Introducing SecurityTube Toolssection! netinfinity
Re: IE8 img tag HiJacking T Biehn
Re: Amiro.CMS <= 5.4.4 SQL inj Henri Salo
Re: IE8 img tag HiJacking Dan Kaminsky
Re: CVE or SUN bug number for http://lists.grok.org.uk/pipermail/full-disclosure/2010-April/074036.html Theodore Pham
Re: IE8 img tag HiJacking Dan Kaminsky
Re: IE8 img tag HiJacking T Biehn
Re: IE8 img tag HiJacking Владимир Воронцов
CVE request: VLC <1.0.6 Multiple issues Henri Salo
Re: Bonsai Information Security - OS Command Injection in Cacti <= 0.8.7e Alberto Trivero
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
[HITB-Announce] HITBSecConf2009 - Malaysia Videos Released! Hafez Kamal
[HITB-Announce] HITBSecConf2010 - Dubai - Presentation Materials Hafez Kamal
[HITB-Announce] HITB eZine Issue 002 out now! Hafez Kamal
Amiro CMS<=5.4.4 PHP injection Владимир Воронцов

Friday, 23 April

Re: CVE or SUN bug number for http://lists.grok.org.uk/pipermail/full-disclosure/2010-April/074036.html Juha-Matti Laurio
MacOS X 10.6.3 filesystem hfs Denial of Service Vulnerability Maksymilian Arciemowicz
Re: Compliance Is Wasted Money, Study Finds Christopher Gilbert
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
[ MDVSA-2010:071 ] mozilla-thunderbird security
ZDI-10-078: Novell ZENworks Configuration Management UploadServlet Remote Code Execution Vulnerability ZDI Disclosures
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
Re: Compliance Is Wasted Money, Study Finds Stephen Mullins
Re: Compliance Is Wasted Money, Study Finds Michael Holstein
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
[CORELAN-10-30] - CommView Network Monitor And Analyzer v6.1 b644 - cv2k1.sys DoS (BSOD) Security
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Vulnerability in Referer for DataLife Engine MustLive
Re: We must work harder on cloud, says Microsoft Georgi Guninski
Re: Compliance Is Wasted Money, Study Finds Michael Holstein
[SECURITY] [DSA 2039-1] New cacti packages fix missing input sanitising Thijs Kinkhorst
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
Re: Compliance Is Wasted Money, Study Finds BMF
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Thor (Hammer of God)
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras

Saturday, 24 April

Re: Compliance Is Wasted Money, Study Finds Mike Hale
SQL Injection - www.glmees.org.br - A Masonic Grand Lodge m4l1c3
Re: Compliance Is Wasted Money, Study Finds Lyal Collins
hashdays 2010 - Call for Papers (#days CFP) hashdays CFP
[CORELAN-10-031] - ZipWrangler 1.2 .zip Stack Buffer Overflow Security
Beware !!!!!!! before opening this site-->miano.us/misc/ff_sucks.html information security
Re: Beware !!!!!!! before opening this site-->miano.us/misc/ff_sucks.html Christian Sciberras
Re: Beware !!!!!!! before opening this site-->miano.us/misc/ff_sucks.html mrx
HP System Management Homepage(SMH) | URL Redirection Abuse YGN Ethical Hacker Group

Sunday, 25 April

[CORELAN-10-032] - Easyzip 2000 .zip Stack BOF Security
t2'10: Call for Papers 2010 (Helsinki / Finland) Tomi Tuominen
[CORELAN-10-032] - Easyzip 2000 .zip Stack BOF Peter Van Eeckhoutte
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Nick FitzGerald
Re: Compliance Is Wasted Money, Study Finds Tracy Reed
Re: Compliance Is Wasted Money, Study Finds Nick FitzGerald
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
Re: Compliance Is Wasted Money, Study Finds Tracy Reed
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras

Monday, 26 April

Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
[CORELAN-10-032] - Easyzip 2000 .zip Stack BOF jeff smith
NovaStor NovaNet <= 13.0 issues mu-b
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Digital X
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: [CORELAN-10-032] - Easyzip 2000 .zip Stack BOF Benji
[USN-931-2] FFmpeg regression Marc Deslauriers
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Pieter de Boer
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
Team SHATTER Security Advisory - Oracle Database SQL Injection vulnerability in DBMS_CDC_PUBLISH.DROP_CHANGE_SOURCE Shatter
Re: Compliance Is Wasted Money, Study Finds Michel Messerschmidt
2010 Nmap/SecTools.org survey Henri Doreau

Tuesday, 27 April

Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Lyal Collins
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds wilder_jeff Wilder
Last Mile || InfoWare 2010 [ICCGI, ICWMC, INTERNET, ACCESS] September 20-25, 2010 - Valencia, Spain Sandra Sendra
[SECURITY] [DSA 2021-2] New spamass-milter packages fix regression Giuseppe Iuculano
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Lyal Collins
PoC for ZDI-10-078 tu canal amigo
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: 2010 Nmap/SecTools.org survey Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Honer, Lance
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Shaqe Wan
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
XSS in Drupal Better Formats Module Justin C. Klein Keane
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: Compliance Is Wasted Money, Study Finds Mike Hale
Re: XSS in Drupal Better Formats Module Henri Salo
Re: Compliance Is Wasted Money, Study Finds Christian Sciberras
Re: Compliance Is Wasted Money, Study Finds Michael Holstein
Re: Compliance Is Wasted Money, Study Finds Michael Holstein
Fun with FORTIFY_SOURCE Dan Rosenberg
Re: XSS in Drupal Better Formats Module Justin C. Klein Keane
Re: XSS in Drupal Better Formats Module Larry Seltzer
Re: Compliance Is Wasted Money, Study Finds Valdis . Kletnieks
Compliance Is Wasted Money, Study Finds J Roger
Re: Compliance Is Wasted Money, Study Finds J Roger
Re: Compliance Is Wasted Money, Study Finds Paul Schmehl
redefining research: vulnerability journalism J Roger
go public to avoid jail J Roger

Wednesday, 28 April

Re: Randi Harper aka Sektie demolished Sandy Vagina
Re: Randi Harper aka Sektie demolished Anders Klixbull
Re: Compliance Is Wasted Money, Study Finds Lyal Collins
Re: redefining research: vulnerability journalism Christopher Gilbert
Re: Compliance Is Wasted Money, Study Finds Michel Messerschmidt
[ MDVSA-2010:084 ] java-1.6.0-openjdk security
Re: Randi Harper aka Sektie demolished Andrew A
ZDI-10-079: Realnetworks Helix Server NTLM Authentication Invalid Base64 Remote Code Execution Vulnerability ZDI Disclosures
Re: Compliance Is Wasted Money, Study Finds Michael Holstein
[ MDVSA-2010:078-1 ] sudo security
[ MDVSA-2010:085 ] pidgin security
[ MDVSA-2009:332-1 ] gimp security
Deadline Extension: ACCESS 2010 || September 20-25, 2010 - Valencia, Spain Sandra Sendra
Israel IP range legit or false? james
[USN-933-1] PostgreSQL vulnerability Jamie Strandboge
A socio-psychological analysis of the first internet war (Estonia) Gadi Evron
Vuln Disclosure summarized (TTBOMA) Rob Fuller

Thursday, 29 April

Re: Vuln Disclosure summarized (TTBOMA) Sergio 'shadown' Alvarez
Re: Vuln Disclosure summarized (TTBOMA) Thierry Zoller
Re: Randi Harper aka Sektie demolished Anders Klixbull
Re: Vuln Disclosure summarized (TTBOMA) Valdis . Kletnieks
Impossible to Maintain Secure Session With Twitter.com Web Interface Chris Palmer
NT becoming pure microkernel iroz
TaskFreak 0.6.2 SQL Injection Vulnerability Justin C. Klein Keane
Off Topic: Information Security research paper help John Jacobs
Re: Off Topic: Information Security research paper help Valdis . Kletnieks
Re: Off Topic: Information Security research paper help Justin C. Klein Keane
Re: go public to avoid jail T Biehn
Facebook persistent XSS vulnerability on iPhone Jon Wedell
Re: go public to avoid jail Stephen Mullins
[ MDVSA-2010:086 ] kdegraphics security
Re: go public to avoid jail T Biehn
Re: NT becoming pure microkernel Nicolas RUFF
Vulnerabilities in CCMS MustLive
[ MDVSA-2010:087 ] poppler security
Interactive Linux Binary Analysis Tool Andrew Lyon
[USN-934-1] Netpbm vulnerability Jamie Strandboge
EUSecWest Amsterdam 2010 Call For Papers (short deadline May 5 - conf June 16/17) Dragos Ruiu

Friday, 30 April

Re: Interactive Linux Binary Analysis Tool Julien Reveret
Re: NT becoming pure microkernel iroz
[ MDVSA-2010:088 ] kernel security
Re: NT becoming pure microkernel Kaddeh
Re: Interactive Linux Binary Analysis Tool Kaddeh
Secunia Research: Internet Download Manager FTP Buffer Overflow Vulnerability Secunia Research