Full Disclosure: by author

561 messages starting Apr 18 11 and ending Apr 01 11
Date index | Thread index | Author index


アドリアンヘンドリック

Re: MSA-2524375 fraudulent digital certification updates on Windows Phone アドリアンヘンドリック (Apr 18)

Abhijeet Patil

ClubHack Magazine Issue 15-April 2011 released Abhijeet Patil (Apr 17)
[Annoucement] ClubHack Magazine - Call for Articles Abhijeet Patil (Apr 19)

ACM CCS 2011

[ACM CCS'11] Reminder: Deadline Approaching (May 6, 2011) ACM CCS 2011 (Apr 25)

ACROS Security Lists

Microsoft Patches Binary Planting Issues In Various Vendors' Products ACROS Security Lists (Apr 13)

Adam Behnke

Reversing x64 TDSS at InfoSec Institute Adam Behnke (Apr 20)
Default config bug leaves 394, 000 computers open proxies Adam Behnke (Apr 26)
SLAAC Attack - 0day Windows Network Interception Configuration Vulnerability Adam Behnke (Apr 04)

Adam Laurie

Re: DC4420 - London DEFCON - April meet - Wednesday 20th April 2011 Adam Laurie (Apr 04)

advisories

Insomnia : ISVA-110427.2 - Up.Time Administration Interface Authentication Bypass Vulnerability advisories (Apr 27)
Insomnia : ISVA-110427.1 - IGSS ODBC Service Remote Overflow Vulnerability advisories (Apr 27)

Albert Sunseri

Re: seriously? Albert Sunseri (Apr 06)
Re: Gomez eats the weak Albert Sunseri (Apr 23)

Andrew Farmer

Re: Multiple vulnerabilities in MyBB Andrew Farmer (Apr 23)

Andrew Horton

WhatWeb v0.4.7 Released. Performance enhancements and bug fixes Andrew Horton (Apr 05)

ascii

Re: SLAAC Attack - 0day Windows Network Interception Configuration Vulnerability ascii (Apr 04)

astera

B-Sides Vienna | NinjaCon 11 Call For Participation astera (Apr 27)

Asterisk Security Team

AST-2011-006: Asterisk Manager User Shell Access Asterisk Security Team (Apr 21)
AST-2011-005: File Descriptor Resource Exhaustion Asterisk Security Team (Apr 21)

Atul Agarwal

Re: ITSEC vendor presentation for dummies Atul Agarwal (Apr 08)

Beatyou Man

Unbelivable, Pangolin 3.2.3 free edition released Beatyou Man (Apr 23)
Re: Unbelivable, Pangolin 3.2.3 free edition released Beatyou Man (Apr 24)

Benji

Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Benji (Apr 17)
Re: psnhack - playstation network hack Benji (Apr 30)
Re: Barracuda backdoor Benji (Apr 28)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Benji (Apr 17)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Benji (Apr 17)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Benji (Apr 17)
Re: seriously? Benji (Apr 05)
Re: psnhack - playstation network hack Benji (Apr 29)
Re: itunes.apple.com owned by webapp malicious host Benji (Apr 01)
Re: Barracuda backdoor Benji (Apr 29)
Re: itunes.apple.com owned by webapp malicious host Benji (Apr 01)

BGA

Re: Stress Testing Tools BGA (Apr 28)

Bgr R

Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Bgr R (Apr 17)

bk

Re: Barracuda backdoor bk (Apr 29)
Re: Barracuda backdoor bk (Apr 28)
Re: Barracuda backdoor bk (Apr 28)
Re: Barracuda backdoor bk (Apr 29)

Brandon Enright

Re: Cipher detection Brandon Enright (Apr 08)

Brandon Matthews

Re: iPhone Geolocation storage Brandon Matthews (Apr 21)

Brian Anderson

Re: Computer name should match with your real identity? Brian Anderson (Apr 29)
Re: Got an iPhone or 3G iPad? Apple is recording your moves Brian Anderson (Apr 22)

Cal Leeming

Re: guess what this does.. Cal Leeming (Apr 13)
Re: password.incleartext.com Cal Leeming (Apr 07)
Re: guess what this does.. Cal Leeming (Apr 18)
Re: guess what this does.. Cal Leeming (Apr 13)
Re: The US Government Officially Confirms the Existence of Extraterrestrial Civilizations Cal Leeming (Apr 01)
Re: Barracuda backdoor Cal Leeming (Apr 29)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Cal Leeming (Apr 19)
Re: Barracuda backdoor Cal Leeming (Apr 29)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Cal Leeming (Apr 17)
Re: Google Search Feature Exploitation Scenario Cal Leeming (Apr 12)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Cal Leeming (Apr 29)
Re: password.incleartext.com Cal Leeming (Apr 07)
Re: guess what this does.. Cal Leeming (Apr 13)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Cal Leeming (Apr 29)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Cal Leeming (Apr 18)
Re: Barracuda backdoor Cal Leeming (Apr 29)
Re: guess what this does.. Cal Leeming (Apr 13)
guess what this does.. Cal Leeming (Apr 12)
Re: Google Search Feature Exploitation Scenario Cal Leeming (Apr 13)
Re: Computer name should match with your real identity? Cal Leeming (Apr 29)
Re: password.incleartext.com Cal Leeming (Apr 07)
Re: Vulnerabilities in *McAfee.com Cal Leeming (Apr 01)
Re: password.incleartext.com Cal Leeming (Apr 07)
Re: Google Search Feature Exploitation Scenario Cal Leeming (Apr 12)
Re: Pangolin spam Cal Leeming (Apr 29)
Re: The US Government Officially Confirms the Existence of Extraterrestrial Civilizations Cal Leeming (Apr 01)
Re: iPhone Geolocation storage Cal Leeming (Apr 21)
Re: guess what this does.. Cal Leeming (Apr 13)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Cal Leeming (Apr 18)
Unbelivable, Pangolin 3.2.3 free edition released Cal Leeming (Apr 25)
Re: guess what this does.. Cal Leeming (Apr 13)
Re: iPhone Geolocation storage Cal Leeming (Apr 21)
Re: Barracuda backdoor Cal Leeming (Apr 29)
Re: Cipher detection Cal Leeming (Apr 07)

Call for papers

CFP: Extended deadline for i-Society 2011 Call for papers (Apr 17)

Charles Polisher

Re: Disabling iPhone Tracking ? Do it Yourself (DiT?DiY) Charles Polisher (Apr 27)

Chris Evans

Re: Facebook URL redirection issue Chris Evans (Apr 03)

Chris M

Re: guess what this does.. Chris M (Apr 13)

Christian Sciberras

Re: guess what this does.. Christian Sciberras (Apr 13)
Re: iPhone Geolocation storage Christian Sciberras (Apr 29)
Re: guess what this does.. Christian Sciberras (Apr 13)
Re: guess what this does.. Christian Sciberras (Apr 13)
Re: Disabling iPhone Tracking ? Do it Yourself (DiT?DiY) Christian Sciberras (Apr 27)
Re: iPhone Geolocation storage Christian Sciberras (Apr 28)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Christian Sciberras (Apr 17)
Re: ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability Christian Sciberras (Apr 01)
Re: Barracuda backdoor Christian Sciberras (Apr 28)
Re: guess what this does.. Christian Sciberras (Apr 12)
Re: Nuclear Strike on Libya (XSS) Christian Sciberras (Apr 17)
Re: [Full-disclosure] Code Execution vulnerability в WordPress Christian Sciberras (Apr 29)
Re: Facebook URL redirection issue Christian Sciberras (Apr 03)

Christopher Truncer

Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Christopher Truncer (Apr 12)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco Wireless LAN Controllers Denial of Service Vulnerability Cisco Systems Product Security Incident Response Team (Apr 27)
Cisco Security Advisory: Multiple Vulnerabilities in Cisco Unified Communications Manager Cisco Systems Product Security Incident Response Team (Apr 27)

CnCxzSec衰仔

Re: inject sql in utn.edu.ar CnCxzSec衰仔 (Apr 23)

coderman

infosec rot (was Re: Gomez eats the weak) coderman (Apr 24)
Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) coderman (Apr 06)
Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) coderman (Apr 06)

Context IS - Disclosure

Whitepaper: Assessing Cloud Node Security Context IS - Disclosure (Apr 01)

corpus.defero

Re: Barracuda backdoor corpus.defero (Apr 28)
Re: Barracuda backdoor corpus.defero (Apr 28)

Csirt, Star

Re: Computer name should match with your real identity? Csirt, Star (Apr 29)

ctruncer

Requesting/Reserving CVE Question ctruncer (Apr 28)

CYBSEC Labs

Cybsec Advisory 2011 0403 OracleJSP Demos Reflected XSS CYBSEC Labs (Apr 20)
CYBSEC Advisory 2011 0401 Cross-Site Scripting (XSS) in Blackberry WebDesktop CYBSEC Labs (Apr 13)
Cybsec Advisory 2011 0402 Multiple XSSs in Oracle JD Edwards EnterpriseOne CYBSEC Labs (Apr 20)

Dan Becker

Re: The US Government Officially Confirms the Existence of Extraterrestrial Civilizations Dan Becker (Apr 01)

Daniel Clemens

CVE-2010-0216 MediaCast Password Dump Vulnerability Daniel Clemens (Apr 25)

Dan Kaminsky

Re: Plumber Injection Attack in Bowser's Castle Dan Kaminsky (Apr 01)

darthludi

Re: iPhone Geolocation storage darthludi (Apr 21)

david.klein () Ipfocus com au

Re: Google Search Feature Exploitation Scenario david.klein () Ipfocus com au (Apr 12)

dink

Insecure Defaults In PPLiveAV Client dink (Apr 19)

EC-Council USA

Announcing TakeDownCon Dallas - May 14-19 - Dallas, TX EC-Council USA (Apr 08)

Esteban Cañizal

Re: INSECT Pro 2.5 Release - Web scanner tool Esteban Cañizal (Apr 01)
Re: INSECT Pro 2.5 Release - Web scanner tool Esteban Cañizal (Apr 01)

fb1h2s Hack 2 Secure

Microsoft Windows shmedia.dll Division By Zero, Explore.exe DOS exploit . fb1h2s Hack 2 Secure (Apr 04)

fernando

Re: inject sql in utn.edu.ar fernando (Apr 23)

Flavio do Carmo Junior aka waKKu

[DCA-2011-0010] TOTVS Microsiga Protheus ERP - Memory Corruption Flavio do Carmo Junior aka waKKu (Apr 13)

Florian Weimer

[SECURITY] [DSA 2220-1] Request Tracker security update Florian Weimer (Apr 19)
[SECURITY] [DSA 2224-1] openjdk-6 security update Florian Weimer (Apr 20)
[SECURITY] [DSA 2223-1] doctrine security update Florian Weimer (Apr 20)

Fly, Kate

ZDI-11-114: RealNetworks Helix Server x-wap-profile Format String Remote Code Execution Vulnerability Fly, Kate (Apr 01)

Gary Baribault

Re: BEGIN PGP PRIVATE KEY BLOCK Gary Baribault (Apr 30)

Gaurang Pandya

Re: Stress Testing Tools Gaurang Pandya (Apr 28)

Georgi Guninski

how would browser vendors deal with $O(10^k)$ fake certs? Georgi Guninski (Apr 10)

ghost

Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient ghost (Apr 28)

-= Glowing Doom =-

Re: guess what this does.. -= Glowing Doom =- (Apr 13)
Re: Computer name should match with your real identity? -= Glowing Doom =- (Apr 29)
Re: Stress Testing Tools -= Glowing Doom =- (Apr 29)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient -= Glowing Doom =- (Apr 29)
Re: [Full-disclosure] Code Execution vulnerability в WordPress -= Glowing Doom =- (Apr 29)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient -= Glowing Doom =- (Apr 29)

gold flake

Re: Insect Pro - Looking for partners gold flake (Apr 20)

Guy

Re: Computer name should match with your real identity? Guy (Apr 29)

hack.lu 2011 information team

hack.lu 2011 CFP hack.lu 2011 information team (Apr 21)

Hacxx 20

Analise Viral Hacxx 20 (Apr 18)

Hafez Kamal

[HITB-Announce] HITBSecConf2011 - Malaysia Call for Papers Now Open Hafez Kamal (Apr 04)

Hanno Böck

O2 classic router: persistent cross site scripting (XSS) and cross site request forgery (CSRF) Hanno Böck (Apr 07)
phplist: cross site request forgery (CSRF), CVE-2011-0748 Hanno Böck (Apr 07)

Hartley, Christopher J.

Re: Barracuda backdoor Hartley, Christopher J. (Apr 29)

Hashdays CFP

hashdays 2011 - Call for Papers (#days CFP) Hashdays CFP (Apr 28)

Henri Lindberg

nSense-2011-001: VeryPDF pdf2tif Henri Lindberg (Apr 13)

Henri Salo

Re: Requesting/Reserving CVE Question Henri Salo (Apr 28)
Re: New vulnerabilities in eSitesBuilder Henri Salo (Apr 17)
Re: Multiple vulnerabilities in MyBB Henri Salo (Apr 27)

Hernan Ochoa

Windows Credentials Editor (WCE) v1.2 release Hernan Ochoa (Apr 18)

hfortier

Recon 2011 - Accepted Talks , Training, Call For Papers Reminder - July 8 to 10, 2011 - Montreal, Quebec hfortier (Apr 14)

huj huj huj

Re: guess what this does.. huj huj huj (Apr 18)
Re: guess what this does.. huj huj huj (Apr 18)

Ian French

seriously? Ian French (Apr 05)

ichib0d crane

Re: Cipher detection ichib0d crane (Apr 08)
Re: Barracuda backdoor ichib0d crane (Apr 28)
Re: Gomez eats the weak ichib0d crane (Apr 23)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient ichib0d crane (Apr 28)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient ichib0d crane (Apr 28)

IEhrepus

Gmail login status detect IEhrepus (Apr 09)

Inc leartext

password.incleartext.com Inc leartext (Apr 01)
Re: password.incleartext.com Inc Leartext (Apr 07)

injec7or hell

Re: inject sql in utn.edu.ar injec7or hell (Apr 23)
inject sql in mecon.gov.ar injec7or hell (Apr 24)
inject sql in buenosaires.gov.ar injec7or hell (Apr 21)
inject sql in juventud.gov.ar injec7or hell (Apr 25)
inject SQL in ddrr.poderjudicial.gob.bo injec7or hell (Apr 25)
inject sql in mininterior.gov.ar injec7or hell (Apr 23)
inject sql in utn.edu.ar injec7or hell (Apr 22)

Ivan .

Re: iPhone Geolocation storage Ivan . (Apr 27)
Re: Got an iPhone or 3G iPad? Apple is recording your moves Ivan . (Apr 25)
Re: iPhone Geolocation storage Ivan . (Apr 20)
Re: iPhone Geolocation storage Ivan . (Apr 26)
Re: iPhone Geolocation storage Ivan . (Apr 28)
Re: Got an iPhone or 3G iPad? Apple is recording your moves Ivan . (Apr 23)
Re: iPhone Geolocation storage Ivan . (Apr 26)
Got an iPhone or 3G iPad? Apple is recording your moves Ivan . (Apr 20)
Re: iPhone Geolocation storage Ivan . (Apr 20)
Re: iPhone Geolocation storage Ivan . (Apr 20)

Jacqui Caren-home

Re: Unbelivable, Pangolin 3.2.3 free edition released Jacqui Caren-home (Apr 25)
Re: Unbelivable, Pangolin 3.2.3 free edition released Jacqui Caren-home (Apr 30)
Re: Unbelivable, Pangolin 3.2.3 free edition released Jacqui Caren-home (Apr 25)

Jaime Lloret Mauri

Call for workshop proposals: The 4th IEEE International Conference on Cyber, Physical, and Social Computing (CPSCom 2011) Jaime Lloret Mauri (Apr 17)

James Kerry

Hacking The Trading Floor Talk code wanted James Kerry (Apr 14)

James Lay

Re: Barracuda backdoor James Lay (Apr 28)

Jamie Cameron

Re: [webmin-devel] XSS in Webmin 1.540 + exploit for privilege escalation Jamie Cameron (Apr 25)

Jamie Strandboge

[USN-1110-1] KDE-Libs vulnerabilities Jamie Strandboge (Apr 14)
[USN-1114-1] KDENetwork vulnerability Jamie Strandboge (Apr 18)

Jav Angelo

Decrypting the password of encrypted pdf Jav Angelo (Apr 13)

Javier Bassi

Re: Facebook URL redirection issue Javier Bassi (Apr 03)
Re: Google Search Feature Exploitation Scenario Javier Bassi (Apr 13)
XSS in Webmin 1.540 + exploit for privilege escalation Javier Bassi (Apr 23)

Jeffrey Walton

Re: Got an iPhone or 3G iPad? Apple is recording your moves Jeffrey Walton (Apr 25)
Re: Disabling iPhone Tracking ? Do it Yourself (DiT?DiY) Jeffrey Walton (Apr 25)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Jeffrey Walton (Apr 17)
Re: iPhone Geolocation storage Jeffrey Walton (Apr 21)
Re: BSD derived RFC3173 IPComp encapsulation will expand arbitrarily nested payload Jeffrey Walton (Apr 01)
Re: iPhone Geolocation storage Jeffrey Walton (Apr 20)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Jeffrey Walton (Apr 17)

John Belushae

Re: Vulnerabilities in MaxSite Anti Spam Image for WordPress John Belushae (Apr 01)

John Cartwright

List Charter John Cartwright (Apr 12)

John Jacobs

Re: Insect Pro - Looking for partners John Jacobs (Apr 19)

Jonathan Waldo

Cisco ACS 1121 Appliance BMC default credentials Jonathan Waldo (Apr 03)

J. Oquendo

Microsoft VISTA TCP/IP heap buffer underflow J. Oquendo (Apr 01)

Juan Sacco

Insect Pro - Advisory 2011 0427 Persistent Cross-Site Scripting (XSS) in xMatters AlarmPoint Juan Sacco (Apr 28)
Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Juan Sacco (Apr 28)

Juha-Matti Laurio

Re: seriously? Juha-Matti Laurio (Apr 05)

Justin Klein Keane

Cisco Linksys WRT54G XSS Vulnerability Justin Klein Keane (Apr 28)

Kees Cook

[USN-1105-1] Linux kernel vulnerabilities Kees Cook (Apr 05)
[USN-1116-1] Kerberos vulnerability Kees Cook (Apr 19)
[USN-1115-1] language-selector vulnerability Kees Cook (Apr 19)
[USN-1119-1] Linux kernel (OMAP4) vulnerabilities Kees Cook (Apr 20)
[USN-1117-1] PolicyKit vulnerability Kees Cook (Apr 19)

kiran Maraju

Facebook URL redirection issue kiran Maraju (Apr 03)

kitetoa () kitetoa com

Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED kitetoa () kitetoa com (Apr 17)

Kotas, Kevin J

CA20110413-01: Security Notice for CA Total Defense Kotas, Kevin J (Apr 13)
CA20110426-01: Security Notice for CA Arcot WebFort Versatile Authentication Server Kotas, Kevin J (Apr 26)

kralor

Re: INSECT Pro 2.5.1 released kralor (Apr 11)

ksha

Re: XSS on NIC Chile ksha (Apr 21)
Multiple XSS+XSRF found at Movistar Chile ksha (Apr 26)

Laurent OUDOT at TEHTRI-Security

Disabling iPhone Tracking ? Do it Yourself (DiT?DiY) Laurent OUDOT at TEHTRI-Security (Apr 25)

Leon Kaiser

Re: Google Search Feature Exploitation Scenario Leon Kaiser (Apr 12)

Lists

Windows Synchronization Object Vulnerabilites in Antivirus Suites Lists (Apr 19)
cPassMan v1.82 Arbitrary File Download - SOS-11-004 Lists (Apr 14)
Re: Computer name should match with your real identity? lists (Apr 29)

Major Malfunction

DC4420 - London DEFCON - April meet - Wednesday 22nd April 2011 Major Malfunction (Apr 04)
Re: DC4420 - London DEFCON - April meet - Wednesday 20th April 2011 Major Malfunction (Apr 04)
Re: DC4420 - London DEFCON - April meet - Wednesday 20th April 2011 Major Malfunction (Apr 18)

Maksim . Filenko

Re: The US Government Officially Confirms the Existence of Extraterrestrial Civilizations Maksim . Filenko (Apr 01)
Re: password.incleartext.com Maksim . Filenko (Apr 06)
Re: Cipher detection Maksim . Filenko (Apr 08)
Cipher detection Maksim . Filenko (Apr 07)

Manichattan at gotham.us

Re: Insect Pro - Looking for partners Manichattan at gotham.us (Apr 19)

Marc Deslauriers

[USN-1120-1] tiff vulnerability Marc Deslauriers (Apr 21)
[USN-1108-1] DHCP vulnerability Marc Deslauriers (Apr 11)
[USN-1113-1] Postfix vulnerabilities Marc Deslauriers (Apr 18)
[USN-1107-1] x11-xserver-utils vulnerability Marc Deslauriers (Apr 06)
[USN-1108-2] DHCP vulnerability Marc Deslauriers (Apr 19)
[USN-1104-1] FFmpeg vulnerabilities Marc Deslauriers (Apr 04)
[USN-1109-1] GIMP vulnerabilities Marc Deslauriers (Apr 13)
[USN-1102-1] tiff vulnerability Marc Deslauriers (Apr 04)
[USN-1125-1] PCSC-Lite vulnerability Marc Deslauriers (Apr 27)
[USN-1124-1] rsync vulnerability Marc Deslauriers (Apr 27)
[USN-1103-1] tex-common vulnerability Marc Deslauriers (Apr 04)
[USN-1118-1] OpenSLP vulnerability Marc Deslauriers (Apr 20)

Marc Heuse

Another Microsoft (and other) IPv6 security issue: sniffer detection Marc Heuse (Apr 14)
ICMPv6 Router Announcement flooding denial of service affecting multiple systems Marc Heuse (Apr 06)

Marcio B. Jr.

Re: iPhone Geolocation storage Marcio B. Jr. (Apr 20)
Re: iPhone Geolocation storage Marcio B. Jr. (Apr 20)
Re: iPhone Geolocation storage Marcio B. Jr. (Apr 20)

Marcus Meissner

Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) Marcus Meissner (Apr 06)
Re: Requesting/Reserving CVE Question Marcus Meissner (Apr 28)

Mario López Jiménez

Maia Mailguard is affected by a XSS vulnerability in version 1.0.2a Mario López Jiménez (Apr 07)

Mario Vilas

Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Mario Vilas (Apr 28)
Re: password.incleartext.com Mario Vilas (Apr 06)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Mario Vilas (Apr 28)
Re: INSECT Pro 2.5 Release - Web scanner tool Mario Vilas (Apr 01)

Mark Jenkins

Plone CVE-2011-0720 details Mark Jenkins (Apr 18)

mark seiden

Re: iPhone Geolocation storage mark seiden (Apr 21)
Re: Got an iPhone or 3G iPad? Apple is recording your moves mark seiden (Apr 22)

Mark Thomas

[SECURITY] CVE-2011-1475 Apache Tomcat information disclosure Mark Thomas (Apr 06)
[SECURITY] CVE-2011-1183 Apache Tomcat security constraint bypass Mark Thomas (Apr 06)

Marsh Ray

Re: how would browser vendors deal with $O(10^k)$ fake certs? Marsh Ray (Apr 13)
Re: Barracuda backdoor Marsh Ray (Apr 28)

matador matador

Re: itunes.apple.com owned by webapp malicious host matador matador (Apr 01)
Re: itunes.apple.com owned by webapp malicious host matador matador (Apr 01)
Re: itunes.apple.com owned by webapp malicious host matador matador (Apr 01)

McGhee, Eddie

Re: ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability McGhee, Eddie (Apr 01)
Re: The US Government Officially Confirms the Existence of Extraterrestrial Civilizations McGhee, Eddie (Apr 01)
Re: The US Government Officially Confirms the Existence of Extraterrestrial Civilizations McGhee, Eddie (Apr 01)
Re: I got hacked McGhee, Eddie (Apr 01)

Micah Gersten

[USN-1121-1] firefox vulnerabilities Micah Gersten (Apr 29)
[USN-1101-1] Qt vulnerabilities Micah Gersten (Apr 01)
[USN-1106-1] NSS vulnerabilities Micah Gersten (Apr 06)
[USN-1112-1] Firefox and Xulrunner vulnerabilities Micah Gersten (Apr 29)
[USN-1123-1] xulrunner-1.9.1 vulnerabilities Micah Gersten (Apr 29)

Michael Holstein

Re: iPhone Geolocation storage Michael Holstein (Apr 21)
Re: iPhone Geolocation storage Michael Holstein (Apr 20)
Re: Computer name should match with your real identity? Michael Holstein (Apr 29)

Michael Lenz

Re: seriously? Michael Lenz (Apr 05)

Michal Zalewski

Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Michal Zalewski (Apr 12)
Re: Got an iPhone or 3G iPad? Apple is recording your moves Michal Zalewski (Apr 21)
Re: INSECT Pro 2.5.1 released Michal Zalewski (Apr 12)

Michele Orru

Re: Vulnerabilities in Mimbo Pro theme for WordPress Michele Orru (Apr 14)
Re: iPhone Geolocation storage Michele Orru (Apr 20)

Milan Berger

Re: Code Execution vulnerability в WordPress Milan Berger (Apr 30)

Miroslav Stampar

[Tool] sqlmap 0.9 released Miroslav Stampar (Apr 11)

Moritz Muehlenhoff

[SECURITY] [DSA 2227-1] iceape security update Moritz Muehlenhoff (Apr 30)
[SECURITY] [DSA 2222-1] tinyproxy security update Moritz Muehlenhoff (Apr 20)
[SECURITY] [DSA 2221-1] Mojolicious security update Moritz Muehlenhoff (Apr 19)
[SECURITY] [DSA 2211-1] vlc security update Moritz Muehlenhoff (Apr 06)
[SECURITY] [DSA 2209-1] tgt security update Moritz Muehlenhoff (Apr 02)
[SECURITY] [DSA 2225-1] asterisk security update Moritz Muehlenhoff (Apr 26)
[SECURITY] [DSA 2226-1] libmodplug security update Moritz Muehlenhoff (Apr 26)

MustLive

Re: Multiple vulnerabilities in MyBB MustLive (Apr 25)
Re: Multiple vulnerabilities in MyBB MustLive (Apr 27)
Vulnerabilities in Mimbo Pro theme for WordPress MustLive (Apr 14)
Re: Vulnerabilities in *McAfee.com MustLive (Apr 06)
Vulnerabilities in The Gazette Edition theme for WordPress MustLive (Apr 11)
Code Execution vulnerability в WordPress MustLive (Apr 29)
Vulnerabilities in multiple themes and components for Joomla MustLive (Apr 24)
AoF, IAA, XML Injection and XSS vulnerabilities in MyBB MustLive (Apr 02)
Vulnerabilities in Live Wire 2.0 and Live Wire Style themes for WordPress MustLive (Apr 12)
Multiple vulnerabilities in MyBB MustLive (Apr 22)
Vulnerabilities in multiple themes for Drupal MustLive (Apr 17)
XSS, AoF and IAA vulnerabilities in PHP-Nuke MustLive (Apr 16)
Vulnerabilities in Live Wire Edition theme for WordPress MustLive (Apr 09)
Re: Vulnerabilities in MaxSite Anti Spam Image for WordPress MustLive (Apr 01)
Vulnerabilities in TimThumb and multiple themes for WordPress MustLive (Apr 13)
Vulnerabilities in MyBB MustLive (Apr 01)
Re: New vulnerabilities in eSitesBuilder MustLive (Apr 19)
Vulnerabilities in multiple themes for ExpressionEngine MustLive (Apr 20)

Nagareshwar Talekar

Released Asterisk Password Spy ! Nagareshwar Talekar (Apr 02)

Nathan Power

Trustwave WebDefend Privilege Escalation Vulnerability Nathan Power (Apr 26)

Nelson Brito

[TOOL RELEASE] T50 - an Experimental Mixed Packet Injector ( v5.3) Nelson Brito (Apr 25)

Nelson Elhage

Plumber Injection Attack in Bowser's Castle Nelson Elhage (Apr 01)

Netragard Advisories

[NETRAGARD-20110910 SECURITY ADVISORY] [Sonexis ConferenceManager Blind SQL Injection Vulnerability] [ http://www.netragard.com ] Netragard Advisories (Apr 10)
[NETRAGARD-20110910 (Corrected) SECURITY ADVISORY] [Sonexis ConferenceManager Blind SQL Injection Vulnerability] [ http://www.netragard.com ] Netragard Advisories (Apr 10)

Netsparker Advisories

XSS Vulnerability in Redmine 1.0.1 to 1.1.1 Netsparker Advisories (Apr 06)

Nick Boyce

Re: Cisco Linksys WRT54G XSS Vulnerability Nick Boyce (Apr 29)

Nick FitzGerald

Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) Nick FitzGerald (Apr 06)
Re: Google Search Feature Exploitation Scenario Nick FitzGerald (Apr 09)
Re: Google Search Feature Exploitation Scenario Nick FitzGerald (Apr 12)
Re: Google Search Feature Exploitation Scenario Nick FitzGerald (Apr 12)

Nico Golde

[SECURITY] [DSA 2213-1] x11-xserver-utils security update Nico Golde (Apr 08)
[SECURITY] [DSA 2217-1] dhcp3 security update Nico Golde (Apr 11)
[SECURITY] [DSA 2216-1] isc-dhcp security update Nico Golde (Apr 11)
[SECURITY] [DSA 2214-1] ikiwiki security update Nico Golde (Apr 08)
[SECURITY] [DSA 2218-1] vlc security update Nico Golde (Apr 12)
[SECURITY] [DSA 2212-1] tmux security update Nico Golde (Apr 08)
[SECURITY] [DSA 2215-1] gitolite security update Nico Golde (Apr 09)

Nima Talebi

Re: WhatWeb v0.4.7 Released. Performance enhancements and bug fixes Nima Talebi (Apr 06)

nix

Re: iPhone Geolocation storage nix (Apr 27)
Re: Got an iPhone or 3G iPad? Apple is recording your moves nix (Apr 21)
WordPress.com root level compromise nix (Apr 13)

Oliver Goebel

[IMF 2011] Call for Participation Oliver Goebel (Apr 12)

Onapsis Research Labs

[Onapsis Security Advisory 2011-007] Oracle JD Edwards JDENET Kernel Shutdown Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-006] Oracle JD Edwards JDENET Kernel Denial of Service Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-003] SAP WebAS ITS Mobile Start Service Multiple Vulnerabilities Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-012] Oracle JD Edwards JDENET Firewall Bypass Onapsis Research Labs (Apr 28)
[Onapsis Security Advisory 2011-004] SAP WebAS ITS Mobile Test Service Multiple Vulnerabilities Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-009] Oracle JD Edwards JDENET SawKernel Remote Password Disclosure Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-011] Oracle JD Edwards JDENET Buffer Overflow Onapsis Research Labs (Apr 28)
[Onapsis Security Advisory 2011-008] Oracle JD Edwards JDENET Kernel Shutdown Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-013] Oracle JD Edwards JDENET USRBROADCAST Denial of Service Onapsis Research Labs (Apr 28)
[Onapsis Security Advisory 2011-005] SAP Enterprise Portal Path Disclosure Onapsis Research Labs (Apr 27)
[Onapsis Security Advisory 2011-010] Oracle JD Edwards JDENET Remote Logging Deactivation Onapsis Research Labs (Apr 28)

Oscar

Re: Stress Testing Tools Oscar (Apr 28)

Oscar Marques

Re: Insect Pro - Looking for partners Oscar Marques (Apr 19)

p8x

VMWare Manage Subscriptions - Info Disclosure p8x (Apr 05)

Patrick R

Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Patrick R (Apr 18)

Paul Schmehl

Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Paul Schmehl (Apr 19)

Pavel Kankovsky

Re: how would browser vendors deal with $O(10^k)$ fake certs? Pavel Kankovsky (Apr 17)
Re: how would browser vendors deal with $O(10^k)$ fake certs? Pavel Kankovsky (Apr 10)

Peter Osterberg

Re: password.incleartext.com Peter Osterberg (Apr 07)
Re: Pangolin spam Peter Osterberg (Apr 29)
Re: password.incleartext.com Peter Osterberg (Apr 06)

Pete Smith

Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Pete Smith (Apr 12)
Re: INSECT Pro 2.5.1 released Pete Smith (Apr 11)

phil

Re: Insect Pro - Looking for partners phil (Apr 19)
Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) phil (Apr 12)
Re: Computer name should match with your real identity? phil (Apr 29)
Hullo how are ya Phil (Apr 14)

Pietro de Medici

Anonymous Rulez Pietro de Medici (Apr 23)

Psuedo Hahaha Fairy

Gomez eats the weak Psuedo Hahaha Fairy (Apr 22)

R0me0 ***

Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient R0me0 *** (Apr 29)

Rain Liu

Re: Unbelivable, Pangolin 3.2.3 free edition released Rain Liu (Apr 25)

Raj Mathur (राज माथुर)

Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Raj Mathur (राज माथुर) (Apr 12)
Re: Pangolin spam Raj Mathur (राज माथुर) (Apr 29)

rancor

Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) rancor (Apr 12)

rdsears

Re: INSECT Pro 2.5 Release - Web scanner tool rdsears (Apr 01)

Rob Nelson

Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Rob Nelson (Apr 17)

Romain Bourdy

Re: password.incleartext.com Romain Bourdy (Apr 06)
Re: password.incleartext.com Romain Bourdy (Apr 06)

rPath Update Announcements

rPSA-2011-0013-1 openssl openssl-scripts rPath Update Announcements (Apr 11)
rPSA-2011-0014-1 httpd mod_ssl rPath Update Announcements (Apr 11)

runlvl

Insect Pro - Looking for partners runlvl (Apr 19)
INSECT Pro 2.5.1 released runlvl (Apr 11)

Ryan Sears

ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) Ryan Sears (Apr 06)
Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Ryan Sears (Apr 12)

sandeep l337

Add URL to Google.com Captcha Bypass sandeep l337 (Apr 11)

satyam pujari

Re: Google Search Feature Exploitation Scenario satyam pujari (Apr 10)
BEGIN PGP PRIVATE KEY BLOCK satyam pujari (Apr 30)
Re: Google Search Feature Exploitation Scenario satyam pujari (Apr 12)
Re: psnhack - playstation network hack satyam pujari (Apr 29)
psnhack - playstation network hack satyam pujari (Apr 29)
Google Search Feature Exploitation Scenario satyam pujari (Apr 09)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED satyam pujari (Apr 18)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED satyam pujari (Apr 19)
Google URL Redirection satyam pujari (Apr 08)
Re: Google Search Feature Exploitation Scenario satyam pujari (Apr 12)
Re: psnhack - playstation network hack satyam pujari (Apr 30)

Seanybob

Warning - t00ls.org hidden callback in shells Seanybob (Apr 06)
Re: Warning - t00ls.org hidden callback in shells Seanybob (Apr 26)

Sebastien Damaye

pytbull, IDS/IPS Testing Framework Sebastien Damaye (Apr 29)
300 Comparative Tests Driven Against Suricata and Snort Sebastien Damaye (Apr 14)

SEC Consult Vulnerability Lab

SEC Consult SA-20110407-0 :: Libmodplug ReadS3M Stack Overflow SEC Consult Vulnerability Lab (Apr 07)

Sec Tools

Stress Testing / DoS Tools comparison Sec Tools (Apr 29)
Stress Testing Tools Sec Tools (Apr 27)

security

[ MDVSA-2011:070 ] gdm security (Apr 08)
[ MDVSA-2011:078 ] libtiff security (Apr 23)
[ MDVSA-2011:077 ] krb5 security (Apr 22)
[ MDVSA-2011:062 ] ffmpeg security (Apr 01)
[ MDVSA-2011:073 ] dhcp security (Apr 11)
[ MDVSA-2011:064 ] libtiff security (Apr 04)
[ MDVSA-2011:059 ] ffmpeg security (Apr 01)
[ MDVSA-2011:066 ] rsync security (Apr 05)
[ MDVSA-2011:065 ] logrotate security (Apr 05)
[ MDVSA-2011:069 ] php security (Apr 08)
[ MDVSA-2011:075 ] kdelibs4 security (Apr 20)
[ MDVSA-2011:071 ] kdelibs4 security (Apr 08)
[ MDVSA-2011:063 ] xmlsec1 security (Apr 04)
[ MDVSA-2011:074 ] qt4 security (Apr 12)
Nuclear Strike on Libya (XSS) security (Apr 17)
[ MDVSA-2011:076 ] xrdb security (Apr 21)
[ MDVSA-2011:067 ] subversion security (Apr 06)
[ MDVSA-2011:079 ] firefox security (Apr 30)
[ MDVSA-2011:061 ] ffmpeg security (Apr 01)
[ MDVSA-2011:072 ] gwenhywfar security (Apr 08)
[ MDVSA-2011:060 ] ffmpeg security (Apr 01)
[ MDVSA-2011:058 ] quagga security (Apr 01)
[ MDVSA-2011:068 ] firefox security (Apr 07)

security curmudgeon

Re: New vulnerabilities in eSitesBuilder security curmudgeon (Apr 17)

SecurityXploded Group

Released Xfire Password Decryptor – Xfire Password Recovery Software SecurityXploded Group (Apr 25)
JDownloader Password Decryptor - New Tool from SecurityXploded SecurityXploded Group (Apr 18)
Released Pcprox RFID Reader – New Tool for reading RFID/HID Card SecurityXploded Group (Apr 22)
Launched IDM Password Decryptor ! SecurityXploded Group (Apr 21)
Released Pcprox RFID Reader – New Tool for reading RFID/HID Card SecurityXploded Group (Apr 24)

SecurityXploded Inc

Launched DirectoryScanner - Free Directory Server fingerprinting tool SecurityXploded Inc (Apr 17)

sec yun

MS mhtml patch bypass sec yun (Apr 19)

Shinnok

Re: Stress Testing Tools Shinnok (Apr 29)

Shlomi Narkolayev

[WEB SECURITY] Secure Browsing Announcement: Comitari released new version which includes support for Firefox Shlomi Narkolayev (Apr 13)

Slatki4ka Slatki4ka

Re: bcwars.com & pokerrpg.com hacked 200k Email and Plain text passwords Slatki4ka Slatki4ka (Apr 02)

SMiller

Re: persistent tracking playas WAS: Got an iPhone or 3G iPad? Apple is recording your moves [Full-Disclosure Digest, Vol 74, Issue 43] SMiller (Apr 25)
iPhone Geolocation storage: Levinson write-up [Re: Full-Disclosure Digest, Vol 74, Issue 47] SMiller (Apr 26)

Steve Beattie

[USN-1126-1] PHP vulnerabilities Steve Beattie (Apr 29)

Steven Pinkham

Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Steven Pinkham (Apr 12)
Re: Unbelivable, Pangolin 3.2.3 free edition released Steven Pinkham (Apr 24)
Re: Unbelivable, Pangolin 3.2.3 free edition released Steven Pinkham (Apr 25)

Steve Pinkham

Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Steve Pinkham (Apr 12)

StrawHat

new facebook and twitter flaw StrawHat (Apr 07)

taneja . security

Computer name should match with your real identity? taneja . security (Apr 29)

Tavis Ormandy

BSD derived RFC3173 IPComp encapsulation will expand arbitrarily nested payload Tavis Ormandy (Apr 01)
Re: BSD derived RFC3173 IPComp encapsulation will expand arbitrarily nested payload Tavis Ormandy (Apr 01)

T Biehn

Re: password.incleartext.com T Biehn (Apr 06)

Teófilo Couto

Re: Stress Testing Tools Teófilo Couto (Apr 29)

Terrence Miltner

New malware research posted on Resources at InfoSec Institute Terrence Miltner (Apr 27)

the nlhcrew

Re: Anonymous Rulez the nlhcrew (Apr 23)

Thijs Kinkhorst

[SECURITY] [DSA 2210-1] tiff security update Thijs Kinkhorst (Apr 03)
[SECURITY] [DSA 2219-1] xmlsec1 security update Thijs Kinkhorst (Apr 18)

Thor (Hammer of God)

Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Thor (Hammer of God) (Apr 17)
Re: psnhack - playstation network hack Thor (Hammer of God) (Apr 30)
Re: password.incleartext.com Thor (Hammer of God) (Apr 06)
Re: Got an iPhone or 3G iPad? Apple is recording your moves Thor (Hammer of God) (Apr 21)
Re: Cipher detection Thor (Hammer of God) (Apr 07)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Thor (Hammer of God) (Apr 17)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Thor (Hammer of God) (Apr 17)
Re: iPhone Geolocation storage Thor (Hammer of God) (Apr 20)
Re: Vulnerabilities in MaxSite Anti Spam Image for WordPress Thor (Hammer of God) (Apr 01)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Thor (Hammer of God) (Apr 17)
Re: Microsoft VISTA TCP/IP heap buffer underflow Thor (Hammer of God) (Apr 01)
Re: password.incleartext.com Thor (Hammer of God) (Apr 06)
iPhone Geolocation storage Thor (Hammer of God) (Apr 20)

Tim

Re: Cipher detection Tim (Apr 07)
Re: Cipher detection Tim (Apr 08)
Re: Announcement posts and the charter (was Re: INSECT Pro 2.5.1 released) Tim (Apr 12)

Tim Brown

Re: Medium severity flaw in Konqueror Tim Brown (Apr 12)
Medium severity flaw in Konqueror Tim Brown (Apr 11)

Timo Warns

[PRE-SA-2011-03] Denial-of-service vulnerability in EFI partition handling code of the Linux kernel Timo Warns (Apr 13)

TinKode InSecurity

European Space Agency (ESA.INT) Hacked by TinKode TinKode InSecurity (Apr 18)

Tomy

Vulnerable Sites Database Highlights april 2011 Tomy (Apr 21)

Tõnu Samuel

Re: Barracuda backdoor Tõnu Samuel (Apr 28)
Re: Barracuda backdoor Tõnu Samuel (Apr 29)
Re: Barracuda backdoor Tõnu Samuel (Apr 29)
Re: Barracuda backdoor Tõnu Samuel (Apr 29)
Re: Barracuda backdoor Tõnu Samuel (Apr 28)
Barracuda backdoor Tõnu Samuel (Apr 28)

TOR

Re: Pangolin spam TOR (Apr 29)
WWWroot spring cleaning of neglected files TOR (Apr 01)

Valdis . Kletnieks

Re: iPhone Geolocation storage Valdis . Kletnieks (Apr 29)
Re: Barracuda backdoor Valdis . Kletnieks (Apr 28)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Valdis . Kletnieks (Apr 17)
Re: Vulnerabilities in MaxSite Anti Spam Image for WordPress Valdis . Kletnieks (Apr 01)
Re: Cipher detection Valdis . Kletnieks (Apr 07)
Re: password.incleartext.com Valdis . Kletnieks (Apr 07)
Re: Insect Pro - Advisory 2011 0428 - Zero Day - Heap Buffer Overflow in xMatters APClient Valdis . Kletnieks (Apr 28)
Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) Valdis . Kletnieks (Apr 06)
Re: SLAAC Attack - 0day Windows Network Interception Configuration Vulnerability Valdis . Kletnieks (Apr 04)
Re: Barracuda backdoor Valdis . Kletnieks (Apr 28)
Re: Gomez eats the weak Valdis . Kletnieks (Apr 22)
Re: password.incleartext.com Valdis . Kletnieks (Apr 06)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Valdis . Kletnieks (Apr 17)
Re: Florida Power & Light Company (FPL) Fort Sumner Wind turbine Control SCADA was HACKED Valdis . Kletnieks (Apr 17)
Re: BEGIN PGP PRIVATE KEY BLOCK Valdis . Kletnieks (Apr 30)
Re: Barracuda backdoor Valdis . Kletnieks (Apr 29)
Re: ISC DHCP Client [3.0.x to 4.2.x] Arbitrary Command Execution (CVE-2011-0997) Valdis . Kletnieks (Apr 06)
Re: Google Search Feature Exploitation Scenario Valdis . Kletnieks (Apr 12)

Valery Marchuk

The US Government Officially Confirms the Existence of Extraterrestrial Civilizations Valery Marchuk (Apr 01)
The US Government Officially Confirms the Existence of Extraterrestrial Civilizations Valery Marchuk (Apr 01)
Re: I got hacked Valery Marchuk (Apr 01)

Vincent Danen

Re: Medium severity flaw in Konqueror Vincent Danen (Apr 11)

VMware Security Team

VMSA-2011-0007 VMware ESXi and ESX Denial of Service and third party updates for Likewise components and ESX Service Console VMware Security Team (Apr 28)

vulc@n ddtek

Defcon CTF moves to the Rio for 2011 and HBGary is awarded contract to clean CTF sheep stalls! vulc@n ddtek (Apr 02)
Defcon CTF moves to the Rio for 2011 and HBGary is awarded contract to clean CTF sheep stalls! vulc@n ddtek (Apr 02)

Williams, James K

CA20110420-01: Security Notice for CA SiteMinder Williams, James K (Apr 20)
CA20110420-02: Security Notice for CA Output Management Web Viewer Williams, James K (Apr 20)

Xavier Mertens

Re: Stress Testing Tools Xavier Mertens (Apr 27)

xpo xpo

USBsploit 0.6b - added: Autosploit CLI and customized infections of the original EXE and PDF USB files xpo xpo (Apr 03)

YGN Ethical Hacker Group

java.com | Arbitrary URL Redirect Vulnerability YGN Ethical Hacker Group (Apr 23)

Z

Re: ITSEC vendor presentation for dummies Z (Apr 09)
ITSEC vendor presentation for dummies Z (Apr 08)

Zach C.

Re: Multiple vulnerabilities in MyBB Zach C. (Apr 25)
Re: iPhone Geolocation storage Zach C. (Apr 20)
Re: Unbelivable, Pangolin 3.2.3 free edition released Zach C. (Apr 25)
Re: Multiple vulnerabilities in MyBB Zach C. (Apr 27)
Re: iPhone Geolocation storage Zach C. (Apr 20)
Re: Plumber Injection Attack in Bowser's Castle Zach C. (Apr 01)
Re: [ MDVSA-2011:074 ] qt4 Zach C. (Apr 12)

ZDI Disclosures

ZDI-11-143: Cisco Unified CallManager xmldirectorylist.jsp SQL Injection Vulnerability ZDI Disclosures (Apr 28)
ZDI-11-152: HP Data Protector Backup Client Service GET_FILE Directory Traversal Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-117: McAfee Firewall Reporter GeneralUtilities.pm isValidClient Authentication Bypass Vulnerability ZDI Disclosures (Apr 11)
ZDI-11-041: (0day) Multiple Browser Node Processing Stack Overflow Vulnerability ZDI Disclosures (Apr 01)
ZDI-11-146: HP Data Protector Backup Client Service EXEC_SCRIPT Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-131: CA Total Defense Suite NonAssignedUserList Stored Procedure SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-115: IBM solidDB solid.exe Authentication Bypass Remote Code Execution Vulnerability ZDI Disclosures (Apr 01)
ZDI-11-126: CA Total Defense Suite Heartbeat Web Service Remote Code Execution Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-125: Microsoft Office PowerPoint PersistDirectoryEntry Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-124: Microsoft PowerPoint TimeColorBehaviorContainer Floating Point Record Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-150: HP Data Protector Backup Client Service omniiaputil Message Processing Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-121: Microsoft Office XP Data Validation Record Parsing Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-132: CA Total Defense Suite UNC Management Console DeleteReportLayout SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-133: CA Total Defense Suite UNC Management Console DeleteReports SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-145: HP Data Protector Backup Client Service GET_FILE Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-116: Novell File Reporter Agent XML Parsing Remote Code Execution Vulnerability ZDI Disclosures (Apr 04)
ZDI-11-135: (Pwn2Own) WebKit WBR Tag Removal Remote Code Execution Vulnerability ZDI Disclosures (Apr 14)
ZDI-11-118: Novell ZENworks Asset Management Path Traversal File Overwrite Remote Code Execution Vulnerability ZDI Disclosures (Apr 11)
ZDI-11-120: Microsoft Office Excel RealTimeData Record Parsing Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-148: HP Data Protector Backup Client Service stutil Message Processing Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-138: Webkit Undefined DOM Prototype Attach Remote Code Execution Vulnerability ZDI Disclosures (Apr 19)
ZDI-11-151: HP Data Protector Backup Client Service bm Message Processing Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-136: IBM Tivoli Directory Server ibmslapd.exe SASL Bind Request Remote Code Execution Vulnerability ZDI Disclosures (Apr 18)
ZDI-11-128: CA Total Defense Suite UnassignFunctionalUsers Stored Procedure SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-147: HP Data Protector Backup Client Service EXEC_INTEGUTIL Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-139: Webkit Anonymous Frame Remote Code Execution Vulnerability ZDI Disclosures (Apr 19)
ZDI-11-122: RealNetworks RealPlayer OpenURLInDefaultBrowser Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-144: HP Data Protector Backup Client Service EXEC_BAR Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-129: CA Total Defense Suite UnassignAdminRoles Stored Procedure SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-134: CA Total Defense Suite UNC Management Console RegenerateReport SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-149: HP Data Protector Backup Client Service HPFGConfig Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-137: Oracle Application Server Authentication Bypass Remote Code Execution Vulnerability ZDI Disclosures (Apr 19)
ZDI-11-127: CA Total Defense Suite UNCWS Web Service getDBConfigSettings Credential Disclosure Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-119: (Pwn2Own) Microsoft Internet Explorer onPropertyChange Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-123: Microsoft PowerPoint TimeCommandBehaviorContainer Remote Code Execution Vulnerability ZDI Disclosures (Apr 12)
ZDI-11-130: CA Total Defense Suite UNC Management Console DeleteFilter SQL Injection Vulnerability ZDI Disclosures (Apr 13)
ZDI-11-153: Embarcadero Interbase connect Request Parsing Remote Code Execution Vulnerability ZDI Disclosures (Apr 29)
ZDI-11-104: (Pwn2Own) Webkit CSS Text Element Count Remote Code Execution Vulnerability ZDI Disclosures (Apr 14)
ZDI-11-140: Webkit Detached Body Element Remote Code Execution Vulnerability ZDI Disclosures (Apr 19)

Zerial.

Fiberhome HG-110 (adsl/router) vulnerabilities Zerial. (Apr 08)
Re: Fiberhome HG-110 (adsl/router) vulnerabilities Zerial. (Apr 10)
Re: XSS on NIC Chile Zerial. (Apr 20)
XSS on NIC Chile Zerial. (Apr 20)

Григорий Братислава

Re: Vulnerabilities in MaxSite Anti Spam Image for WordPress Григорий Братислава (Apr 01)