Full Disclosure: by date

381 messages starting Sep 30 02 and ending Oct 31 02
Date index | Thread index | Author index


Monday, 30 September

Mostly Off Topic: Teach me how to hack etcetera. Charles Stevenson
Mostly Off Topic: Teach me how to hack etcetera. phc () hush com
KILL STRINGZ/EREBUS/PROPHET/BLACKFIST WEEK Charles Stevenson
NTFS exploit HggdH
Organization for Internet Safety (OIS) formally announced Steven M. Christey
Organization for Internet Safety (OIS) formally announced Isaak Bloodlore

Tuesday, 01 October

GLSA: fetchmail Daniel Ahlberg
GLSA: unzip Daniel Ahlberg
Organization for Internet Safety (OIS) formally announced Ben Laurie
Organization for Internet Safety (OIS) formally announced Georgi Guninski
GLSA: tar Daniel Ahlberg
Organization for Internet Safety (OIS) formally announced phc () hushmail com
THREATCON HITTING DANGEROUS LEVELS! zb0
Re: Organization for Internet Safety (OIS) formally announced Anonymous
Mostly Off Topic: Teach me how to hack etcetera. Matt Merhar
Mostly Off Topic: Teach me how to hack etcetera. shub () hushmail com
Mostly Off Topic: Teach me how to hack etcetera. Matt Merhar
GLSA: tar Gary E. Miller
Mostly Off Topic: Teach me how to hack etcetera. theblackfist () hushmail com
Organization for Internet Safety (OIS) form ally announced Ogle Ron (Rennes)
Totally Off Topic: Teach me how to measure my IQ Ka
Totally Off Topic: Teach me how to measure my IQ zan
Totally Off Topic: Teach me how to measure my IQ Ka
Totally Off Topic: Teach me how to measure my IQ zan
iDEFENSE Security Advisory 10.01.02: Sendmail smrsh bypass vulnerabilities David Endler
Totally Off Topic: Teach me how to measure my IQ Charles Stevenson
Totally Off Topic: Teach me how to measure my IQ zan
Totally Off Topic: Teach me how to measure my IQ Ka
Totally Off Topic: Teach me how to measure my IQ Charles Stevenson
Totally Off Topic: Teach me how to measure my IQ zan
Totally Off Topic: Teach me how to measure my IQ Charles Stevenson
Totally Off Topic: Teach me how to measure my IQ memetic-engineer () australia edu
RE:Brute Force brew-h4-h4: All your fucking base memetic-engineer () australia edu
Mostly Off Topic: Teach me how to hack etcetera. Isaak Bloodlore
Fwd: Brute Force brew-h4-h4 : All your fsking base ( free tzunami from .gov lies) theblackfist () hushmail com
Fwd: Brute Force brew-h4-h4 : All your fsking base ( free tzunami from .gov lies) Charles Stevenson
Fwd: Brute Force brew-h4-h4 : All your fsking base ( free tzunami from .gov lies) theblackfist () hushmail com
Fwd: Brute Force brew-h4-h4 : All your fsking base ( free tzunami from .gov lies) Charles Stevenson
suexec doesn't ignore links in safe_path Guy Cohen
MDKSA-2002:062 - postgresql update Mandrake Linux Security Team
MDKSA-2002:063 - fetchmail update Mandrake Linux Security Team
suexec doesn't ignore links in safe_path Niels Bakker
Fwd: Brute Force brew-h4-h4 : All your fsking base ( free tzunami from .gov lies) Charles Stevenson
suexec doesn't ignore links in safe_path Guy Cohen
suexec doesn't ignore links in safe_path Charles Stevenson
Good Bye! :] Charles Stevenson
suexec doesn't ignore links in safe_path White Vampire
Good Bye! :] << nice way to say " im owned" ( yes #parse. this is real) theblackfist () hushmail com
Organization for Internet Safety (OIS) formally announced sockz loves you
Do Terrorists Really Have More Fun? sockz loves you
Do Terrorists Really Have More Fun? John
Do Terrorists Really Have More Fun? memetic-engineer () australia edu
PHP execution vulnerability on www.neo-modus.com (direct connect homepage) burpz () gmx net

Wednesday, 02 October

Do Terrorists Really Have More Fun? sockz loves you
Do Terrorists Really Have More Fun? silvio () big net au
Do Terrorists Really Have More Fun? silvio () big net au
Do Terrorists Really Have More Fun? M L Lynch [ SotG ]
Apache 2 Cross-Site Scripting mattmurphy () kc rr com
Does Grandma Really Have More Fun? Steve
Do members of full-disclosure really have more fun? Ka
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability Orlando
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability David Endler
Do Terrorists Really Have More Fun? John
[PHC] FREE SECURITY BOOKS !!! [PHC] phc () hushmail com
[PHC] FREE SECURITY BOOKS !!! [PHC] phc () hush com
[PHC] FREE SECURITY BOOKS !!! [PHC] EPiC
R7-0004: Multiple Vendor Long ZIP Entry Filename Processing Issues Rapid 7 Security Advisories

Thursday, 03 October

GLSA: gv Daniel Ahlberg
[ESA-20021003-021] glibc: several security-related updates. EnGarde Secure Linux
[ESA-20021003-022] tar: directory traversal vulnerability. EnGarde Secure Linux
[ESA-20021003-023] fetchmail-ssl: buffer overflows and broken boundary checks. EnGarde Secure Linux
(no subject) Francisco Guerreiro
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability Orlando
(no subject) Schmehl, Paul L
GLSA: python Daniel Ahlberg
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability Ben Laurie
RE: (no subject) Anonymous
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability mutex () hushmail com
iDEFENSE Security Advisory 10.03.2002: Apache 1.3.x shared memory scoreboard vulnerabilities David Endler
Thor Larholm security advisory TL#004 Thor Larholm
BearShare Directory Traversal Issue Resurfaces Aviram Jenik
iDEFENSE Security Advisory: Idiots For Defense Matthew McGehrin
Hah now this redefines selling out. KF
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability Isaak Bloodlore
www.msnbc.com full-disclosure () lists netsys com
Mostly Off Topic: Teach me how to hack etcetera. matt merhar
i'm looking to start a fight... matt merhar
Hah now this redefines selling out. Phantasm
Hah now this redefines selling out. Kevin Finisterre
Hah now this redefines selling out. matt merhar
Hah now this redefines selling out. White Vampire
[RHSA-2002:197-06] Updated glibc packages fix vulnerabilities in resolver bugzilla () redhat com

Friday, 04 October

[RHSA-2002:175-16] Updated nss_ldap packages fix buffer overflow bugzilla () redhat com
[RHSA-2002:212-06] Updated packages fix PostScript and PDF security issue bugzilla () redhat com
iDEFENSE Security Advisory 10.02.2002: Net-SNMP DoS Vulnerability Ben Laurie
Hah now this redefines selling out. Georgi Guninski
Hah now this redefines selling out. matt merhar
Recent exploit disclosure & iDEFENSE Orlando
[SECURITY] [DSA 169-1] New tomcat packages fix unintended source code disclosure full-disclosure () lists netsys com
Cisco Security Advisory: Predefined Restriction Tables Allow Calls to International Operator Cisco Systems Product Security Incident Response Team
Recent exploit disclosure & iDEFENSE zen-parse () gmx de
Recent exploit disclosure & iDEFENSE Ka
Recent exploit disclosure & iDEFENSE Isaak Bloodlore
Recent exploit disclosure & iDEFENSE mz
Hah now this redefines selling out. Dave Wilson
striking semblance between blueboar and bugbear..... matt merhar
zen-parse () gmx de is not zen-parse () gmx net zen-parse

Saturday, 05 October

PHC = HFG.. same kids, different tune hushmail_cowards () hushmail com

Sunday, 06 October

Multiple vulnerabitilies in phpRank Jedi/Sector One
zen-parse () gmx de is not zen-parse () gmx net daniel.clemens
zen-parse () gmx de is not zen-parse () gmx net Florian Weimer
re: zen-parse () gmx de is not zen-parse () gmx net zen-parse

Monday, 07 October

zen-parse () gmx de is not zen-parse () gmx net Ben Laurie
zen-parse () gmx de is not zen-parse () gmx net Florian Weimer
SuSE Security Announcement: hylafax (SuSE-SA:2002:035) Thomas Biege
SuSE Security Announcement: mod_php4 (SuSE-SA:2002:036) Thomas Biege
zen-parse () gmx de is not zen-parse () gmx net Ben Laurie
zen-parse () gmx de is not zen-parse () gmx net Florian Weimer
SPIKE 2.7 Released: There's a party at my house, so bring the beer and follow me.... Dave Aitel
[ESA-20021007-024] apache: potential DoS, cross-site scripting, and buffer overflow vulnerabilities. EnGarde Secure Linux
[RHSA-2002:215-09] Updated fetchmail packages fix vulnerabilities bugzilla () redhat com
erm. new+improved www content silvio () big net au
NetBSD Security Advisory 2002-015: (another) buffer overrun in libc/libresolv DNS resolver NetBSD Security Officer
NetBSD Security Advisory 2002-019: Buffer overrun in talkd NetBSD Security Officer
NetBSD Security Advisory 2002-021: rogue vulnerability NetBSD Security Officer
NetBSD Security Advisory 2002-022: buffer overrun in pic(1) NetBSD Security Officer
NetBSD Security Advisory 2002-023: sendmail smrsh bypass vulnerability NetBSD Security Officer

Tuesday, 08 October

[SECURITY] [DSA 172-1] New tkmail packages fix insecure temporary file creation full-disclosure () lists netsys com
erm. new+improved www content matt merhar
[SECURITY] [DSA 169-1] New ht://Check packages fix cross site scripting problem full-disclosure () lists netsys com
[SECURITY] [DSA 171-1] New fetchmail packages fix buffer overflows full-disclosure () lists netsys com
List Charter John Cartwright
I like to make charters johnc () grok org uk

Wednesday, 09 October

I like to make charters John Cartwright
I like to make charters Nexus
[SECURITY] [DSA 173-1] New bugzilla packages fix privilege escalation full-disclosure () lists netsys com
MDKSA-2002:064 - kdelibs update Mandrake Linux Security Team
R7-0006: Oracle 8i/9i Listener SERVICE_CURLOAD Denial of Service Rapid 7 Security Advisories

Thursday, 10 October

Unix-Virus Mailing List silvio () big net au
FreeBSD Security Notice FreeBSD-SN-02:06 FreeBSD Security Advisories
Multiple XSS vulnerabilites in PHPNuke Bruno Morisson
9 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
4 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
7 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
2 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
6 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
5 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
3 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
8 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
10 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
1 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
12 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
13 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
22 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
21 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
19 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
17 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
14 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
20 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
24 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
25 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
30 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
33 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
39 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
35 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
41 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
47 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
48 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
57 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
60 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
59 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
65 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
72 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
74 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
82 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
86 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
96 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
95 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
112 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
119 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
130 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
125 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
131 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
136 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
151 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
150 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
146 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
166 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
173 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
180 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
185 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
187 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
179 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
196 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
204 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
214 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
212 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
217 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
221 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
227 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
233 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
239 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
243 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
250 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
251 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
256 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
261 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
265 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
276 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
267 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
280 Poot ze-a cheekee in de-a oofee! gobbles () hushmail com
3 Poot ze-a cheekee in de-a oofee! zan
8 Poot ze-a cheekee in de-a oofee! zan
12 Poot ze-a cheekee in de-a oofee! zan
3 Poot ze-a cheekee in de-a oofee! martin f krafft
10 Poot ze-a cheekee in de-a oofee! zan
[RHSA-2002:207-14] Updated packages fix PostScript and PDF security issue bugzilla () redhat com
60 Poot ze-a cheekee in de-a oofee! David Vincent
60 Poot ze-a cheekee in de-a oofee! Damian Gerow
MDKSA-2002:065 - unzip update Mandrake Linux Security Team
Outlook Express Remote Code Execution in Preview Pane (S/MIME) Aviram Jenik
MDKSA-2002:066 - tar update Mandrake Linux Security Team
60 yada yada *yawn* Nexus
Security Update: [CSSA-2002-SCO.40] OpenServer 5.0.5 OpenServer 5.0.6 : ypxfrd remote file access vulnerability please_reply_to_security () caldera com
Fw: Outlook Express Remote Code Execution in Preview Pane (S/MIME) HggdH
Outlook Express Remote Code Execution in Preview Pane (S/MIME) Nexus
Outlook Express Remote Code Execution in Preview Pane (S/MIME) Giordani Rodrigues
QRe: Outlook Express Remote Code Execution in Preview Pane (S/MIME) HggdH
Outlook Express Remote Code Execution in Pr eview Pane (S/MIME) David Vincent

Friday, 11 October

Outlook Express Remote Code Execution in Pr eview Pane (S/MIME) John.Airey () rnib org uk
[RHSA-2002:204-10] Updated squirrelmail packages close cross-site scripting vulnerabilities bugzilla () redhat com
60 Poot ze-a cheekee in de-a oofee! Thor Larholm
60 Poot ze-a cheekee in de-a oofee! Ron DuFresne
Administrivia - Regarding bulk mail John Cartwright
unsubscribe mchaaban () umich edu
60 Poot ze-a cheekee in de-a oofee! David Vincent
Administrivia - (Un)subscription requests John Cartwright
(no subject) blake () mc net
help Luis GARCIA
60 Poot ze-a cheekee in de-a oofee! Bruce Ediger
hushmail spam/abuse/mailbombing vulnerability demonstrated by Mr. Gobbles auto461767 () hushmail com
Security Update: [CSSA-2002-SCO.39] OpenServer 5.0.5 OpenServer 5.0.6 : Buffer Overflow in Multiple DNS Resolver Libraries please_reply_to_security () caldera com
How to reproduce the IIS Host Header DOS Joe Testa

Saturday, 12 October

Pyramid Research Project - atphttpd security adivisorie pyramid-rp () hushmail com
Pyramid Research Project - ghttpd security advisorie pyramid-rp () hushmail com
Pyramid Research Project - atphttpd security advisorie pyramid-rp () hushmail com
PHP Information Functions May Allow Cross-Site Scripting Matthew Murphy

Sunday, 13 October

GLSA: nss_ldap Daniel Ahlberg
Re: PHP Information Functions May Allow Cross-Site Scripting Matthew Murphy
GLSA: sendmail Daniel Ahlberg

Monday, 14 October

GLSA: net-snmp Daniel Ahlberg
CALL FOR PAPERS - SANTA DIED LAST YEAR staff
cypherpunk wargames jsyn
[SECURITY] [DSA 174-1] New heartbeat packages fix buffer overflows debian-security-announce
GLSA: heimdal Daniel Ahlberg
bombings in bali silvio
Re: bombings in bali Ron DuFresne
Gl1bC L1nuxThreadz ADV1SORY, was Re: bombings in bali silvio
Andrew.Wolhuter/Sandton/RMB is out of the office. Andrew . Wolhuter
Re: Andrew.Wolhuter/Sandton/RMB is out of the office. m
unsuscribe lcamtuf
unsuscribe lcamtuf
Re: unsuscribe Mark Renouf

Tuesday, 15 October

irc yarddog
GLSA: tomcat Daniel Ahlberg
GLSA: apache Daniel Ahlberg
[SECURITY] [DSA 175-1] New syslog-ng packages fix buffer overflow debian-security-announce
[RHSA-2002:196-09] Updated xinetd packages fix denial of service vulnerability bugzilla
iDEFENSE Security Advisory 10.15.02: DoS and Directory Traversal Vulnerabilities in WebServer 4 Everyone David Endler
MDKSA-2002:068 - apache update Mandrake Linux Security Team

Wednesday, 16 October

Fw: [VulnWatch] Internet Explorer : The D-Day Thor Larholm
iDEFENSE Security Advisory 10.16.02: Denial of Service in Sabre Desktop Reservation Client for Windows David Endler
[SECURITY] [DSA 176-1] New gv packages fix buffer overflow debian-security-announce
Re: CALL FOR PAPERS - SANTA DIED LAST YEAR sockz loves you
Re: bombings in bali sockz loves you
Cisco Security Advisory: Cisco CatOS Embedded HTTP Server Buffer Overflow Cisco Systems Product Security Incident Response Team
ABfrag / linux kernel vulns Mike Tone

Thursday, 17 October

GLSA: ggv Daniel Ahlberg
[RHSA-2002:205-15] New kernel fixes local security issues bugzilla
[RHSA-2002:210-06] New kernel 2.2 packages fix local vulnerabilities bugzilla
[RHSA-2002:206-12] New kernel fixes local security issues bugzilla
Re: CALL FOR PAPERS - SANTA DIED LAST YEAR phc
Re: ABfrag / linux kernel vulns ??? Ka
[ESA-20021016-025] syslog-ng buffer overflow in macro handling code EnGarde Secure Linux
[SECURITY] [DSA 178-1] New Heimdal packages fix remote command execution debian-security-announce
Re: ABfrag / linux kernel vulns KF
[SECURITY] [DSA 177-1] New PAM packages fix serious security violation in Debian/unstable debian-security-announce

Friday, 18 October

[RHSA-2002:192-13] Updated Mozilla packages fix security vulnerabilities bugzilla
SCAN Associates Advisory: perlbot 1.9.2 - Remote Command Execution guejez
SCAN Associates Advisory: Molly 0.5 - Remote Command Execution guejez
SCAN Associates Advisory: madhater perlbot 1.0 beta - Remote Command Execution guejez
[SECURITY] [DSA 179-1] New gnome-gv packages fix buffer overflow debian-security-announce
Re: Linux Kernel Exploits / ABFrag enigmatic-arcanum
[Immunity, Inc.]Vulnerability: RPC Service DoS (port 135/tcp) on Windows 2000 SP3 Dave Aitel
GLSA: tetex Daniel Ahlberg

Saturday, 19 October

ABfrag - *yawn* sockz loves you
Re: ABfrag - *yawn* silvio
Re: ABfrag - *yawn* silvio
Microsoft Secrets Tamer Sahin
GLSA: groff Daniel Ahlberg

Sunday, 20 October

NOCC: XSS Ulf Harnhammar
Re: [VulnWatch] NOCC: XSS Ulf Harnhammar
Re: [VulnWatch] NOCC: XSS ppp-design
Reproducing the MS DCE-RPC DOS. Joe Testa
kmMail XSS Ulf Harnhammar
iDEFENSE Security Advisory 10.21.02: Cross-Site Scripting Holes present in virtually all websites David Endler

Monday, 21 October

RE: iDEFENSE Security Advisory 10.21.02: Cross-Site Scripting Holes present in virtually all websites David Endler
[SECURITY] [DSA 180-1] New NIS packages fix information leak debian-security-announce
SuSE Security Announcement: postgresql (SuSE-SA:2002:038) Thomas Biege
Security Update: [CSSA-2002-SCO.41] UnixWare 7.1.1 Open UNIX 8.0.0 : rcp of /proc causes denial-of-service security
MDKSA-2002:069 - gv update Mandrake Linux Security Team
NetBSD Security Advisory 2002-026: Buffer overflow in kadmind daemon NetBSD Security Officer
NetBSD Security Advisory 2002-016: Insufficient length check in ESP authentication data NetBSD Security Officer
Re: Administrivia - Regarding bulk mail gobbles
Re: PHC = HFG.. same kids, different tune gobbles
7350reass - alleged *BSD remote kernel exploit rfclover

Tuesday, 22 October

Re: PHC = HFG.. same kids, different tune sockz loves you
[ESA-20021022-026] local kernel vulnerabilities EnGarde Secure Linux
[SECURITY] [DSA 181-1] New mod_ssl packages fix cross site scripting debian-security-announce
RE: 7350reass - alleged *BSD remote kernel expl oit David Vincent
Fw: [VulnWatch] Vulnerable cached objects in IE (9 advisories in 1) Thor Larholm
RE: 7350reass - alleged *BSD remote kernel exploit Janusz Niewiadomski
Re: RE: 7350reass - alleged *BSD remote kernel exploit Dave M. Wilson
Re: RE: 7350reass - alleged *BSD remote kernel exploit KF
RE: 7350reass (who's responsible) dev-null

Wednesday, 23 October

Re: RE: 7350reass (who's responsible) skyper
[SecurityOffice] Web Server 4 Everyone v1.28 Host Field Denial of Service Vulnerability Tamer Sahin
MDKSA-2002:070 - tetex update Mandrake Linux Security Team
Security Update: [CSSA-2002-036.0] Linux: remote buffer overflow in webalizer reverse lookup code security
R7-0007: IBM WebSphere Edge Server Caching Proxy Denial of Service Rapid 7 Security Advisories
R7-0008: IBM WebSphere Edge Server Caching Proxy Cross-Site Scripting Issues Rapid 7 Security Advisories

Thursday, 24 October

found with ABFrag.. david evlis reign
NetBSD Security Advisory 2002-025: trek(6) buffer overrun NetBSD Security Officer
GLSA: xfree Daniel Ahlberg
[RHSA-2002:223-07] Updated ypserv packages fixes memory leak bugzilla
GLSA: zope Daniel Ahlberg
[SecurityOffice] BadBlue Web Server v1.7 Protected File Access Vulnerability Tamer Sahin
[SecurityOffice] Liteserve Web Server v2.0 Authorization Bypass Vulnerability Tamer Sahin
[SecurityOffice] BRS WebWeaver Web Server v1.01 Protected File Access Vulnerability Tamer Sahin
RE: found with ABFrag.. Jason Barbour
Eweek OpenHack Challenge Cesar
Security Update: [CSSA-2002-037.0] Linux: various packet handling vunerabilities in ethereal security
MDKSA-2002:071 - kdegraphics update Mandrake Linux Security Team
MDKSA-2002:072 - mod_ssl update Mandrake Linux Security Team
iDEFENSE Security Advisory 10.24.02: Directory Traversal in SolarWinds TFTP Server David Endler
Security Update: [CSSA-2002-038.0] Linux: inn format string and insecure open vulnerabilities security
Re: ABfrag followup / WITHOUT ATTACHMENT enigmatic-arcanum

Friday, 25 October

RHL's xinetd-2.3.9 do no longer close TCP on internal daytime service Peter Bieringer
Re: found with ABFrag.. Guy Cohen
IPSwitch, Inc. WS_FTP Server dev-null

Saturday, 26 October

GLSA: kth-krb Daniel Ahlberg
GLSA: mod_ssl Daniel Ahlberg

Monday, 28 October

GLSA: ypserv Daniel Ahlberg
GLSA: krb5 Daniel Ahlberg
[SECURITY] [DSA 182-1] New kghostview packages fix buffer overflow debian-security-announce
Security Update: [CSSA-2002-040.0] Linux: uudecode performs inadequate checks on user-specified output files security
Security Update: [CSSA-2002-041.0] Linux: pam_ldap format string vulnerability security
"more" segfaults on Redhat 6.x Day Jay
more segfaults on Redhat 6.x when passing "/proc/misc" as a parameter Day Jay
Re: more segfaults on Redhat 6.x when passing "/proc/misc" as a parameter Pekka Savola

Tuesday, 29 October

Re: more segfaults on Redhat 6.x when passing "/proc/misc" as a parameter Dr. Peter Bieringer
Re: more segfaults on Redhat 6.x when passing "/proc/misc" as a parameter Pekka Savola
[ESA-20021029-027] mod_ssl cross-site scripting vulnerability. EnGarde Secure Linux
[ESA-20021029-028] syslog-ng: buffer overflow in macro handling code (UPDATED) EnGarde Secure Linux
[SECURITY] [DSA 183-1] New krb5 packages fix buffer overflow debian-security-announce
Security Update: [CSSA-2002-039.0] Linux: bzip2 file creation and symbolic link vulnerabilities security
MDKSA-2002:073 - krb5 update Mandrake Linux Security Team
sympatico.ca uses weak encryption on their billing server George Staikos
Security Update: [CSSA-2002-043.0] Linux: chfn (util-linux) temp file race vulnerability security

Wednesday, 30 October

XXE (Xml eXternal Entity) attack Gregory Steuck
GLSA: sharutils Daniel Ahlberg
[SECURITY] [DSA 184-1] New krb4 packages fix buffer overflow debian-security-announce
GLSA: pam_ldap Daniel Ahlberg

Thursday, 31 October

Response from CERT regarding Linux Slapper worm John . Airey
Re: Response from CERT regarding Linux Slapper worm Helmut Springer
SuSE Security Announcement: syslog-ng (SuSE-SA:2002:039) Sebastian Krahmer
SuSE Security Announcement: lprng/html2ps (SuSE-SA:2002:040) Sebastian Krahmer
[SECURITY] [DSA 185-1] New heimdal packages fix buffer overflows debian-security-announce
Cisco Security Advisory: Cisco ONS15454 and Cisco ONS15327 Vulnerabilities Cisco Systems Product Security Incident Response Team
CERIAS CISSP Preparation Workshop Matt Rose
MDKSA-2002:074 - mozilla update Mandrake Linux Security Team