Full Disclosure: by date

511 messages starting Dec 01 11 and ending Dec 31 11
Date index | Thread index | Author index


Thursday, 01 December

PHP Inventory 1.3.1 Remote (Auth Bypass) SQL Injection Vulnerability Schurtz, Stefan
[SECURITY] [DSA 2354-1] cups security update Yves-Alexis Perez
Client aproach Miguel Lopes
Re: New FREE security tool! Samuel Lavitt
News issue of PenTest Magazine - 21 pages of free content. Maciej Kozuszek
Infosys TCS Wipro like companies don't know security basics? Wonder Guy
Re: New FREE security tool! Stefan Edwards
Re: New FREE security tool! Mario Vilas
Re: Client aproach Ferenc Kovacs
Re: Infosys TCS Wipro like companies don't know security basics? Valdis . Kletnieks
Re: New FREE security tool! Christopher Truncer
Re: Client aproach Thor (Hammer of God)
Re: Client aproach Peter Dawson
Re: Infosys TCS Wipro like companies don't know security basics? TAS
Large password list Addy Yeow
Re: Large password list Fabio Pietrosanti (naif)
Re: New FREE security tool! noreply
Re: New FREE security tool! xD 0x41
Re: Writing Self Modifying Code coderman
Multiple vulnerabilities in RoundCube MustLive
[SECURITY] [DSA 2356-1] openjdk-6 security update Florian Weimer
Re: Is FD no longer unmoderated? Nick Boyce
Re: New FREE security tool! ghost
InfoSec Southwest 2012 CFP I)ruid
Re: FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit Jason Hellenthal
Re: Infosys TCS Wipro like companies don't know security basics? phyco.rootelement phyco.rootelement
Re: Client aproach Miguel Lopes
Re: Client aproach Miguel Lopes
Re: Client aproach Chris L
Re: Infosys TCS Wipro like companies don't know security basics? Wonder Guy
FreeBSD ftpd & ProFTPd on FreeBSD exploit in Action [HACKTRO] :> HI-TECH .
Re: FreeBSD ftpd & ProFTPd on FreeBSD exploit in Action [HACKTRO] :> xD 0x41
International Checkout Philippe Meunier
SANS AppSec 2012 CFP reminder SANS AppSec CFP
Re: Large password list Addy Yeow
Re: Large password list adam
Re: Large password list Benji
Re: Large password list adam
Re: Large password list xD 0x41
Re: Large password list xD 0x41
Re: Large password list adam
Re: New FREE security tool! Antony widmal
Re: Large password list Gary Baribault
Re: New FREE security tool! xD 0x41
Re: Large password list Valdis . Kletnieks
Re: FreeBSD ftpd and ProFTPd on FreeBSD remote r00t exploit Michal Zalewski
Re: Large password list Sanguinarious Rose
Re: Large password list xD 0x41
Re: New FREE security tool! Sanguinarious Rose
Re: New FREE security tool! xD 0x41
Re: New FREE security tool! xD 0x41
Re: Large password list xD 0x41

Friday, 02 December

Re: Voxsmart VoxRecord Control Centre - Blind SQLi and auth. bypass Piotr Duszynski
Re: Large password list Mario Vilas
Re: Voxsmart VoxRecord Control Centre - Blind SQLi and auth. bypass Michele Orru
Carrier IQ for your phone Kain, Rebecca (.)
Re: Large password list Travis Biehn
Re: Large password list Travis Biehn
Re: Large password list Jeffrey Walton
Re: Large password list Charles Morris
Re: Large password list Gage Bystrom
Re: Large password list GloW - XD
Re: Large password list Valdis . Kletnieks
Re: Large password list Charles Morris
Re: Large password list Ferenc Kovacs
fast and somewhat reliable cache timing Michal Zalewski
VSFTPD Remote Heap Overrun (low severity) HI-TECH .
Re: Large password list Charles Morris

Saturday, 03 December

Re: Is FD no longer unmoderated? Bipin Gautam
Re: fast and somewhat reliable cache timing Michele Orru
Re: Carrier IQ for your phone Alan J. Wylie
Indexed blind SQL injection Nam Nguyen
Re: fast and somewhat reliable cache timing xD 0x41
Re: fast and somewhat reliable cache timing xD 0x41
Vulnerabilities in Zeema CMS MustLive

Sunday, 04 December

Re: fast and somewhat reliable cache timing Michal Zalewski
Re: Vulnerabilities in Zeema CMS Henri Salo
[SECURITY] [DSA 2357-1] evince security update Yves-Alexis Perez
Recruiting Troopers - Call for Papers, March 21-22 2012 Enno Rey
Re: Indexed blind SQL injection Владимир Воронцов
Re: Carrier IQ for your phone coderman
Re: fast and somewhat reliable cache timing xD 0x41
Re: Carrier IQ for your phone Dave

Monday, 05 December

Re: Large password list Nate Theis
Re: Writing Self Modifying Code Andrew King
Re: Large password list Alessandro Tagliapietra
Re: Large password list xD 0x41
one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized Dan Ballance
Re: one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized Gage Bystrom
Re: one of my servers has been compromized Ferenc Kovacs
Re: one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized Chris M
Re: one of my servers has been compromized Christophe Garault
Re: one of my servers has been compromized mitchell
Re: one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized John Jacobs
Re: one of my servers has been compromized Michael Wood
Re: one of my servers has been compromized Tim
Re: one of my servers has been compromized John Jacobs
Re: one of my servers has been compromized Dave
Re: one of my servers has been compromized James Condron
Re: one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized Tim
Re: one of my servers has been compromized John Jacobs
Re: one of my servers has been compromized Paul Schmehl
Re: one of my servers has been compromized Tim
Re: one of my servers has been compromized Paul Schmehl
Re: one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized John Jacobs
[SECURITY] [DSA 2358-1] openjdk-6 security update Florian Weimer
Re: one of my servers has been compromized Gage Bystrom
Re: one of my servers has been compromized Javier Bassi
C|Net Download.Com is now bundling Nmap with malware! Michael Wood
Re: C|Net Download.Com is now bundling Nmap with malware! nix
Re: one of my servers has been compromized Aris Adamantiadis
Re: one of my servers has been compromized Dan Ballance
Re: one of my servers has been compromized Larry W. Cashdollar
[CVE-2011-4343] Apache MyFaces information disclosure vulnerability Leonardo Uribe
Re: one of my servers has been compromized Larry W. Cashdollar
Re: one of my servers has been compromized Josh Yavor
Re: one of my servers has been compromized sam
Re: one of my servers has been compromized Dan Ballance
Re: one of my servers has been compromized John Jacobs
Backdoor in EPractize Labs Online Subscription Manager from epractizelabs.com Jan van Niekerk

Tuesday, 06 December

Re: one of my servers has been compromized Guillaume Friloux
Fwd: Backdoor in EPractize Labs Online Subscription Manager from epractizelabs.com Jan van Niekerk
Re: one of my servers has been compromized Lucio Crusca
Re: one of my servers has been compromized BH
Re: one of my servers has been compromized Gage Bystrom
Re: one of my servers has been compromized Lucio Crusca
prosec white powder
FB privacy breach - view PRIVATE Facebook photos Peter Dawson
OMIGOD CIQ HACKING THE WORLD. Christian Sciberras
Re: one of my servers has been compromized Kerem Erciyes
Re: prosec Thor (Hammer of God)
Re: prosec adam
Re: FB privacy breach - view PRIVATE Facebook photos Lamar Spells
Re: FB privacy breach - view PRIVATE Facebook photos darway yohansen
Re: FB privacy breach - view PRIVATE Facebook photos adam
Re: Carrier IQ for your phone Georgi Guninski
Re: Carrier IQ for your phone Jeff Kell
Re: one of my servers has been compromized Valdis . Kletnieks
Re: one of my servers has been compromized Valdis . Kletnieks
Re: one of my servers has been compromized Paul Schmehl
Re: one of my servers has been compromized Gage Bystrom
Re: prosec Ferenc Kovacs
Re: one of my servers has been compromized Gage Bystrom
Re: one of my servers has been compromized Paul Schmehl
[SECURITY] [DSA 2359-1] mojarra security update Florian Weimer
Re: prosec Ac1d B1tch3z
Re: prosec Ac1d B1tch3z
Re: prosec xD 0x41
[SECURITY] [DSA 2360-1] Two month advance notification for upcoming end-of-life for Debian oldstable Moritz Muehlenhoff
Re: one of my servers has been compromized John Jacobs
Re: one of my servers has been compromized Charles Morris
Re: one of my servers has been compromized Gage Bystrom
Re: OMIGOD CIQ HACKING THE WORLD. Christian Sciberras
Re: one of my servers has been compromized Valdis . Kletnieks
Re: one of my servers has been compromized Gage Bystrom
Re: one of my servers has been compromized Valdis . Kletnieks
Re: OMIGOD CIQ HACKING THE WORLD. Jeffrey Walton
Re: one of my servers has been compromized Charles Morris
Re: one of my servers has been compromized John Jacobs
Re: one of my servers has been compromized Gage Bystrom
Re: distributing passwords to users Gage Bystrom

Wednesday, 07 December

Re: distributing passwords to users Gage Bystrom
Re: distributing passwords to users Gage Bystrom
Re: FB privacy breach - view PRIVATE Facebook photos Lamar Spells
Re: Carrier IQ for your phone security+lists
Re: distributing passwords to users Martijn Broos
Re: Carrier IQ for your phone Dave
PenTest mag Olga Głowala
Re: OMIGOD CIQ HACKING THE WORLD. Pablo Ximenes
Re: OMIGOD CIQ HACKING THE WORLD. Dan Rosenberg
Re: OMIGOD CIQ HACKING THE WORLD. Pablo Ximenes
Re: OMIGOD CIQ HACKING THE WORLD. Dan Rosenberg
Re: FB privacy breach - view PRIVATE Facebook photos Peter Dawson
Re: OMIGOD CIQ HACKING THE WORLD. Pablo Ximenes
Re: OMIGOD CIQ HACKING THE WORLD. Dan Rosenberg
Re: OMIGOD CIQ HACKING THE WORLD. Pablo Ximenes
Re: one of my servers has been compromized Paul Schmehl
[ MDVSA-2011:181 ] proftpd security
Re: one of my servers has been compromized Gage Bystrom
Google open redirect secure poon
Re: Google open redirect Michele Orru
Re: PenTest mag Dave
Re: PenTest mag xD 0x41
Re: PenTest mag Gage Bystrom
Re: PenTest mag Gage Bystrom
[SECURITY] [DSA 2361-1] chasen security update Florian Weimer
Re: PenTest mag GloW - XD
Re: PenTest mag Gage Bystrom
Re: PenTest mag xD 0x41
Re: PenTest mag Gage Bystrom
Re: one of my servers has been compromized Paul Schmehl
XSS, SQLi and IL vulnerabilities in Zeema CMS MustLive
Re: PenTest mag Dave
Re: one of my servers has been compromized Gage Bystrom
ZDI-11-340 : Apple Quicktime Font Table Signed Length Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-341 : Cisco WebEx Player WRF Type 0 Parsing Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-342 : Novell ZENworks Asset Management Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-343 : RealNetworks RealPlayer mp4arender esds channel count Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-345 : TrendMicro Control Manager CmdProcessor.exe AddTask Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-344 : RealNetworks RealPlayer RV20 Decoding Remote Code Execution Vulnerability ZDI Disclosures
Re: PenTest mag xD 0x41
Re: PenTest mag Tomy
Re: PenTest mag Gage Bystrom
Re: PenTest mag Tomy
Re: PenTest mag xD 0x41
Re: PenTest mag Gage Bystrom
Re: PenTest mag Ferenc Kovacs
Re: PenTest mag Gage Bystrom
Re: PenTest mag xD 0x41
Re: PenTest mag xD 0x41
Re: PenTest mag Gage Bystrom
Re: PenTest mag Gage Bystrom
[HITB-Announce] HITB2012AMS Call For Papers Now Open Hafez Kamal
Re: Google open redirect Nick FitzGerald
Re: Google open redirect Michal Zalewski
Re: Google open redirect Luis Santana
Re: Google open redirect Michal Zalewski

Thursday, 08 December

Re: Google open redirect Michal Zalewski
Re: Google open redirect Dave
Re: Google open redirect Michal Zalewski
Re: Google open redirect Tavis Ormandy
Restorepoint Remote root command execution vulnerability - CVE-2011-4201 CVE-2011-4202 Tavaris Desamito
DDIVRT-2011-38 KnowledgeTree login.php Blind SQL Injection ddivulnalert
[Fwd: Updates on Download.Com caught adding malware to Nmap installer] mutin
Evilgrade pwning Java updates since 2007.. Francisco Amato
0A29-11-2 : Privilege escalation vulnerability in HP Application Lifestyle Management (ALM) Platform v11 0a29 40
Re: DDIVRT-2011-38 KnowledgeTree login.php Blind SQL Injection James Condron
Re: [Fwd: Updates on Download.Com caught adding malware to Nmap installer] Gage Bystrom
Re: FB privacy breach - view PRIVATE Facebook photos Peter Dawson
Re: Google open redirect Charles Morris
Re: Google open redirect Benji
[TEHTRI-Security] Ultra quick dummy PHP hacking challenge for FD readers Laurent OUDOT at TEHTRI-Security
Re: Google open redirect Charles Morris
Re: Google open redirect Benji
Re: Google open redirect Charles Morris
Re: Google open redirect Charles Morris
Re: Google open redirect Pablo Ximenes
Re: Google open redirect Pablo Ximenes
Re: Google open redirect Charles Morris
VLAN Hacking Tutorial at InfoSec Institute Adam Behnke
Re: Google open redirect Michal Zalewski
Re: Google open redirect Pablo Ximenes
Re: Google open redirect Valdis . Kletnieks
Re: Google open redirect Gage Bystrom
[ MDVSA-2011:182 ] dhcp security
Re: Google open redirect Pablo Ximenes
Re: Google open redirect Valdis . Kletnieks
DC4420 - London DEFCON - 13 December 2011 Major Malfunction
AST-2011-013: Possible remote enumeration of SIP endpoints with differing NAT settings Asterisk Security Team
AST-2011-014: Remote crash possibility with SIP and the “automon” feature enabled Asterisk Security Team
Re: Google open redirect secure poon
Re: Minimum Syslog Level Needed for Court Trial Gage Bystrom

Friday, 09 December

Re: Minimum Syslog Level Needed for Court Trial xD 0x41
Re: Minimum Syslog Level Needed for Court Trial tc
Re: Minimum Syslog Level Needed for Court Trial xD 0x41
Re: Minimum Syslog Level Needed for Court Trial Ferenc Kovacs
Re: VLAN Hacking Tutorial at InfoSec Institute Memory Vandal
Re: VLAN Hacking Tutorial at InfoSec Institute Bob Dobbs
List Charter John Cartwright
CA20111208-01: Security Notice for CA SiteMinder Williams, James K
Re: Minimum Syslog Level Needed for Court Trial Charles Morris
Re: Full-Disclosure Digest, Vol 82, Issue 20 t0hitsugu
Re: Minimum Syslog Level Needed for Court Trial phocean
Re: VLAN Hacking Tutorial at InfoSec Institute Nate Theis
Re: Google open redirect Marsh Ray
Re: Minimum Syslog Level Needed for Court Trial Andrew D Kirch
Re: Google open redirect Michal Zalewski
Re: Google open redirect Valdis . Kletnieks
Re: Google open redirect Dave
Fwd: VSFTPD Remote Heap Overrun (low severity) HI-TECH .
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) GloW - XD
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) GloW - XD

Saturday, 10 December

[SECURITY] [DSA 2362-1] acpid security update Moritz Muehlenhoff
Re: Google open redirect Tavis Ormandy
[CFP] FRHACK Africa 2012 Call For Papers Jerome Athias
silly PoCs continue: X-Frame-Options give you less than expected Michal Zalewski
Re: silly PoCs continue: X-Frame-Options give you less than expected xD 0x41
Re: silly PoCs continue: X-Frame-Options give you less than expected Dave
[ MDVSA-2011:183 ] pidgin security
Re: silly PoCs continue: X-Frame-Options give you less than expected Christian Sciberras
Re: silly PoCs continue: X-Frame-Options give you less than expected Michal Zalewski

Sunday, 11 December

Re: [TEHTRI-Security] Ultra quick dummy PHP hacking challenge for FD readers Laurent OUDOT at TEHTRI-Security
Re: Vulnerabilities in ADSL modem Callisto 821+ MustLive
Re: silly PoCs continue: X-Frame-Options give you less than expected Christian Sciberras
Re: silly PoCs continue: X-Frame-Options give you less than expected Michal Zalewski
Vulnerabilities in D-Link DSL-500T ADSL Router MustLive
Re: Google open redirect Marsh Ray

Monday, 12 December

Re: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Call for Papers -YSTS 6 - Security Conference, Brazil Luiz Eduardo
zFTPServer Suite 6.0.0.52 'rmdir' Directory Traversal Schurtz, Stefan
Re: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Fwd: VSFTPD Remote Heap Overrun (low severity) HI-TECH .
Re: Google open redirect Charles Morris
Vulnerabilities in D-Link DAP 1150 MustLive
[ MDVSA-2011:184 ] krb5 security
Re: Minimum Syslog Level Needed for Court Trial Jacqui Caren
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
[ MDVSA-2011:185 ] libcap security
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Compromised site using BitCoin James Lay
Firefox forensics with SQLite Manager at InfoSec Institute Adam Behnke
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Valdis . Kletnieks
[ MDVSA-2011:186 ] nfs-utils security
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Valdis . Kletnieks
New awstats.pl vulnerability? Lamar Spells
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) lists
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Valdis . Kletnieks
Re: New awstats.pl vulnerability? Grandma Eubanks
Re: New awstats.pl vulnerability? Bruce Ediger
Re: New awstats.pl vulnerability? Nikolay Kichukov

Tuesday, 13 December

Re: Firefox forensics with SQLite Manager at InfoSec Institute Fabio
Secunia Research: Winamp AVI Parsing Two Integer Overflow Vulnerabilities Secunia Research
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Daniel J Walsh
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Daniel J Walsh
Re: New awstats.pl vulnerability? Lamar Spells
Secunia Research: Sterling Trader Data Processing Buffer Overflow Vulnerability Secunia Research
Exploiting glibc __tzfile_read integer overflow to buffer overflow and vsftpd Ramon de C Valle
Re: Exploiting glibc __tzfile_read integer overflow to buffer overflow and vsftpd HI-TECH .
Two other Google open redirects Riyaz Walikar
Re: Two other Google open redirects R0me0 ***
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Daniel J Walsh
vsFTPd remote code execution HI-TECH .
Re: Two other Google open redirects Nate Theis
Re: vsFTPd remote code execution Dan Rosenberg
Re: vsFTPd remote code execution HI-TECH .
Re: vsFTPd remote code execution Ramon de C Valle
Re: vsFTPd remote code execution Dan Rosenberg
Re: Two other Google open redirects Nick FitzGerald
Re: vsFTPd remote code execution HI-TECH .
ZDI-11-346 : Microsoft Office 2007 Office Art Shape Record Hierarchy Parsing Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-347 : Microsoft Office Word Hidden Border Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-348 : HP OpenView NNM nnmRptConfig.exe nameParams Remote Code Execution Vulnerability ZDI Disclosures
Re: vsFTPd remote code execution HI-TECH .
Re: Carrier IQ for your phone coderman
Re: Two other Google open redirects Tavis Ormandy
BF, XSS, IAA and CSRF vulnerabilities in poMMo MustLive
Re: Carrier IQ for your phone Ivan .Heca
Re: Carrier IQ for your phone coderman
Re: Google open redirect Marsh Ray
Re: Carrier IQ for your phone Ivan .Heca
Re: Google open redirect Tavis Ormandy
Re: Fwd: VSFTPD Remote Heap Overrun (low severity) Ramon de C Valle
Re: vsFTPd remote code execution Chris Evans

Wednesday, 14 December

Physical Security Krzysztof Marczyk
0A29-11-3 : Cross-Site Scripting vulnerabilities in Nagios XI < 2011R1.9 0a29 40
0A29-11-4 : Privilege escalation vulnerabilities in Nagios XI installer < 2011R1.9 0a29 40

Thursday, 15 December

[RT-SA-2011-005] Owl Intranet Engine: Authentication Bypass RedTeam Pentesting GmbH
[RT-SA-2011-006] Owl Intranet Engine: Information Disclosure and Unsalted Password Hashes RedTeam Pentesting GmbH
New IETF I-D on "Stable Privacy Addresses" Fernando Gont
Re: vsFTPd remote code execution HI-TECH .
More on exploiting glibc __tzfile_read integer overflow to buffer overflow and vsftpd Ramon de C Valle
New IETF I-Ds on Fragmentation-related security issues Fernando Gont
[Announcement] ClubHack Mag Issue 23- December 2011 Released Abhijeet Patil
Mobile Phone Spyware CarrierIQ Redux Anonymous Remailer (austria)
PmWiki <= 2.2.34 (pagelist) foo net
[ MDVSA-2011:187 ] php-pear security
Re: vsFTPd remote code execution xD 0x41
[ MDVSA-2011:188 ] libxml2 security
Seotoaster SQL-Injection Admin Login Bypass Schurtz, Stefan

Friday, 16 December

X server wrapper permission bypass (CVE-2011-4613) vladz
[ MDVSA-2011:189 ] jasper security
[SECURITY] [DSA 2363-1] tor security update Moritz Muehlenhoff
Re: New awstats.pl vulnerability? Lamar Spells
Re: vsFTPd remote code execution Rodrigo Rubira Branco (BSDaemon)

Saturday, 17 December

Re: vsFTPd remote code execution Chris Evans

Sunday, 18 December

Novell Sentinel Log Manager <=1.2.0.1 Path Traversal Andrea Fabrizi
Re: pytbull update! Sébastien Damaye
Content Papst CMS v2011.2 - Multiple Web Vulnerabilities research () vulnerability-lab com
appRain CMF v0.1.5 - Multiple Web Vulnerabilities research () vulnerability-lab com
Pure-ftpd question J. von Balzac
[SECURITY] [DSA 2364-1] xorg security update Moritz Muehlenhoff
[SECURITY] [DSA 2365-1] dtc security update Moritz Muehlenhoff
CS and XSS vulnerabilities in Zeema CMS MustLive
Syhunt: Time-Based Blind NoSQL Injection Felipe M. Aragon

Monday, 19 December

[ MDVSA-2011:191 ] libarchive security
[ MDVSA-2011:190 ] libarchive security
SEC Consult SA-20111219-0 :: Client-side remote arbitrary file upload in SecCommerce SecSigner Java Applet SEC Consult Vulnerability Lab
SEC Consult SA-20111219-1 :: Multiple vulnerabilities in WhatsApp SEC Consult Vulnerability Lab
[SECURITY] [DSA 2367-1] asterisk security update Moritz Muehlenhoff
Attempted exploits against phpAlbum (common with Joomla, etc.) Lamar Spells
Slides of our "Hacking IPv6 Networks" training at DEEPSEC 2011 Fernando Gont
Mobile Prank Hacktool Hacxx Under
ZDI-11-350 : Enterasys NetSight nssyslogd PRI Remote Code Execution Vulnerability ZDI Disclosures
CSRF, DT and AB vulnerabilities in D-Link DSL-500T ADSL Router MustLive

Tuesday, 20 December

NiX API CLI/Online version - A powerful free IP Reputation Lookup API nix
OT: Firefox question / poll Charles Morris
Re: OT: Firefox question / poll Christian Sciberras
Re: OT: Firefox question / poll Jeffrey Walton
Fwd: Re: OT: Firefox question / poll Dave
Re: Fwd: Re: OT: Firefox question / poll John Adams
TWSL2011-018: Authentication Bypass Vulnerability in IBM TS3100/TS3200 Web User Interface Trustwave Advisories
post-XSS landscape Michal Zalewski
Re: OT: Firefox question / poll coderman

Wednesday, 21 December

Access & Retrieve Dlink clients information [Tutorial] Hacxx Under
Make "adjustments" to a Dlink router [Tutorial] Hacxx Under

Thursday, 22 December

[MATTA-2011-001] pfSense x509 Insecure Certificate Creation Florent Daigniere
Re: Fwd: Re: OT: Firefox question / poll Georgi Guninski
Re: OT: Firefox question / poll Marcio B. Jr.
Re: OT: Firefox question / poll Dan Kaminsky
ZDI-11-351 : WellinTech KingView HistoryServer.exe Opcode 3 Parsing Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-352 : HP Managed Printing Administration jobAcct Multiple Vulnerabilities ZDI Disclosures
ZDI-11-353 : HP Managed Printing Administration MPAUploader.dll Remote Code Execution Vulnerability ZDI Disclosures
ZDI-11-354 : HP Managed Printing Administration jobDelivery Multiple Vulnerabilities ZDI Disclosures
Drupal SuperCron 6.x-1.3 XSS Vulnerability Justin Klein Keane
[SECURITY] [DSA 2370-1] unbound security update Florian Weimer
Re: OT: Firefox question / poll coderman
Re: OT: Firefox question / poll Michal Zalewski
Kaspersky IS&AV 2011/12 - Memory Corruption Vulnerability research () vulnerability-lab com
[SECURITY] [DSA 2366-1] mediawiki security update Jonathan Wiltshire
AirOS remote root 0day sd
Tiki Wiki CMS Groupware Stored Cross-Site-Scripting Schurtz, Stefan
Cyberoam UTM Appliance - SQL Injection Vulnerability research () vulnerability-lab com
SpamTitan v5.08 - Multiple Web Vulnerabilities research () vulnerability-lab com
CertificationMagazine - Blind SQL Injection Vulnerability research () vulnerability-lab com
Kaspersky IS&AV 2011/12 - Memory Corruption Vulnerability research () vulnerability-lab com
[SECURITY] [DSA 2381-] lighttpd security update Nico Golde
[SECURITY] [DSA 2368-1] lighttpd security update Nico Golde
Whois Cart Billing - Multiple Web Vulnerabilities research () vulnerability-lab com
Re: OT: Firefox question / poll Michal Zalewski
Certificate Spoofing in Google Chrome for Android MustLive
[SECURITY] [DSA 2369-1] libsoup2.4 security update Nico Golde
TWSL2011-019: Cross-Site Scripting Vulnerability in phpMyAdmin Trustwave Advisories
Using Facebook as a proxy R00T_ATI
Re: New awstats.pl vulnerability? Lamar Spells
Re: New awstats.pl vulnerability? james

Friday, 23 December

Re: New awstats.pl vulnerability? xD 0x41
Re: CertificationMagazine - Blind SQL Injection Vulnerability Tomy
Re: Mobile Prank Hacktool Larry W. Cashdollar
Re: OT: Firefox question / poll metasansana
Facebook security bypassed with One single link Anand Pandey
Re: [SECURITY] [DSA 2368-1] lighttpd security update MailPlus| David Hofstee
Re: OT: Firefox question / poll 夜神 岩男
Re: Mobile Prank Hacktool xD 0x41
Re: OT: Firefox question / poll Valdis . Kletnieks
Re: Mobile Prank Hacktool Hacxx Under
Sunny WebBox Default Password Hacxx Under
Automatic message post in PHP Classified Hacxx Under
Re: CertificationMagazine - Blind SQL Injection Vulnerability Super vulnerability-lab hack Tomy
Exploit Pack - Happy new year! noreply
Re: Sunny WebBox Default Password Jeffrey Walton
[ MDVSA-2011:192 ] mozilla security

Saturday, 24 December

[SECURITY] [DSA 2371-1] jasper security update Moritz Muehlenhoff
AirOS remote root 0day Christopher Granger
Using hardware to attack software Forristal, Jeff
Re: CertificationMagazine - Blind SQL Injection Vulnerability research () vulnerability-lab com
Re: Sunny WebBox Default Password Larry W. Cashdollar
Re: CertificationMagazine - Blind SQL Injection Vulnerability Tomy
Re: CertificationMagazine - Blind SQL Injection Vulnerability Super vulnerability-lab hack Thor (Hammer of God)
Re: CertificationMagazine - Blind SQL Injection Vulnerability Super vulnerability-lab hack james
Re: Using hardware to attack software Gage Bystrom
Re: AirOS remote root 0day sd

Sunday, 25 December

Lighttpd Proof of Concept code for CVE-2011-4362 Adam Zabrocki
vulnerability-lab - lulz lab arikomember
[SECURITY] [DSA 2372-1] heimdal security update Florian Weimer
[SECURITY] [DSA 2373-1] inetutils security update Florian Weimer
vulnerability-lab - lulz lab yo man

Monday, 26 December

[SECURITY] [DSA 2374-1] openswan security update Moritz Muehlenhoff
[SECURITY] [DSA 2375-1] krb5. krb5-appl security update Florian Weimer
Vulnerabilities in plugins for MODx CMS, XOOPS, uCoz, Magento and DSP CMS MustLive
Re: Vulnerabilities in plugins for MODx CMS, XOOPS, uCoz, Magento and DSP CMS Antony widmal

Tuesday, 27 December

[ MDVSA-2011:193 ] squid security
[ MDVSA-2011:194 ] icu security
Re: Using hardware to attack software Gage Bystrom
Re: Using hardware to attack software coderman
Do: Re: Mi: Using hardware to attack software coderman
Re: Using hardware to attack software coderman
Re: Using hardware to attack software Valdis . Kletnieks

Wednesday, 28 December

n.runs-SA-2011.004 - web programming languages and platforms - DoS through hash table security
[ MDVSA-2011:195 ] krb5-appl security
[ MDVSA-2011:196 ] ipmitool security
Paid VIP Dyndns account Hacxx Under

Thursday, 29 December

WiFi Protected Setup attack code posted Craig Heffner
Akiva Webboard 8.x SQL Injection + Plaintext Passwords. Alexander Fuchs
Re: Using hardware to attack software Forristal, Jeff
Re: WiFi Protected Setup attack code posted Gage Bystrom
Re: WiFi Protected Setup attack code posted Dan Kaminsky
Re: n.runs-SA-2011.004 - web programming languages and platforms - DoS through hash table sd
Re: n.runs-SA-2011.004 - web programming languages and platforms - DoS through hash table adam
Re: n.runs-SA-2011.004 - web programming languages and platforms - DoS through hash table Jan Schejbal
Multiple new vulnerabilities in Register Plus Redux for WordPress MustLive
Re: n.runs-SA-2011.004 - web programming languages and platforms - DoS through hash table coderman

Friday, 30 December

[ MDVSA-2011:197 ] php security
[SECURITY] [DSA 2376-1] ipmitool security update Thijs Kinkhorst
[SECURITY] [DSA 2263-2] movabletype-opensource security update Thijs Kinkhorst
Winn Guestbook v2.4.8c Stored XSS tom
DoS in TI Golden Gateway MXP Debug Application will
SEC Consult SA-20111230-0 :: Critical authentication bypass in Microsoft ASP.NET Forms - CVE-2011-3416 SEC Consult Vulnerability Lab
Re: Vulnerabilities in plugins for MODx CMS, XOOPS, uCoz, Magento and DSP CMS MustLive
INSECT Pro - Version 3.0 Released! runlvl
Re: INSECT Pro - Version 3.0 Released! Gage Bystrom
Re: INSECT Pro - Version 3.0 Released! root

Saturday, 31 December

[FG-VD-11-007]IBM Lotus Notes/Domino Server Remote Denial of Service Vulnerability noreply-secresearch () fortinet com
[SECURITY] [DSA 2376-2] ipmitool security update Thijs Kinkhorst
XSS and IAA vulnerabilities in Register Plus Redux for WordPress MustLive
Re: [FG-VD-11-007]IBM Lotus Notes/Domino Server Remote Denial of Service Vulnerability Jim Elkins
Re: INSECT Pro - Version 3.0 Released! R0me0 ***
Re: INSECT Pro - Version 3.0 Released! David
Re: INSECT Pro - Version 3.0 Released! Valdis . Kletnieks
[ MDVSA-2011:198 ] phpmyadmin security
Re: INSECT Pro - Version 3.0 Released! R0me0 ***
Re: INSECT Pro - Version 3.0 Released! coderman