Full Disclosure: by author

935 messages starting Oct 18 07 and ending Oct 10 07
Date index | Thread index | Author index


. /

password plugin for linux? . / (Oct 18)

31337

Re: DHS need to get on top of this right now 31337 (Oct 24)
Re: DHS need to get on top of this right now 31337 (Oct 23)
Re: DHS need to get on top of this right now 31337 (Oct 23)

3APA3A

3proxy 0.5.3j released (bugfix) 3APA3A (Oct 23)
Re: CallManager and OpeSer toll fraud and authentication forward attack 3APA3A (Oct 15)
Re: Tikiwiki 1.9.8 exploit ITW 3APA3A (Oct 12)
Re: TCP Hijacking (aka Man-in-the-Middle) 3APA3A (Oct 26)
Re: iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability 3APA3A (Oct 04)
Vulnerabilities digest 3APA3A (Oct 10)
Re: Microsoft Windows default ZIP handler bug 3APA3A (Oct 15)
Re: TCP Hijacking (aka Man-in-the-Middle) 3APA3A (Oct 26)
Re: TCP Hijacking (aka Man-in-the-Middle) 3APA3A (Oct 25)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype 3APA3A (Oct 08)
Re: PDF mailto exploit in the wild 3APA3A (Oct 23)

Aaron Katz

Re: spammer wades into US Presidential race Aaron Katz (Oct 30)
Re: spammer wades into US Presidential race Aaron Katz (Oct 28)
Re: spammer wades into US Presidential race Aaron Katz (Oct 31)

Adam Laurie

RFIDIOt release - version 0.1q Adam Laurie (Oct 30)

Adrian

Re: Spike in SSH scans Adrian (Oct 22)

Adrian P

BT Home Flub: Pwnin the BT Home Hub Adrian P (Oct 08)
Re: gnucitizen bt home hub latest, attacks wide spread, outages reported Adrian P (Oct 12)

Advisories ZATAZ

GranParadiso persistent connexion ? Advisories ZATAZ (Oct 11)
GranParadiso persistent connexion ? Advisories ZATAZ (Oct 11)

Aidan Thornton

Re: Original Photo Gallery Remote Command Execution Aidan Thornton (Oct 03)

alexandre jodoin

Re: Google Sacure (A. Jodoin) alexandre jodoin (Oct 26)
Re: Google Sacure (A. Jodoin) alexandre jodoin (Oct 26)

Alex Everett

Re: Remote Desktop Command Fixation Attacks Alex Everett (Oct 11)

A . L . M . Buxey

Re: Distributed SSH username/password brute forceattack A . L . M . Buxey (Oct 22)
Re: TCP Hijacking (aka Man-in-the-Middle) A . L . M . Buxey (Oct 26)

Anders B Jansson

Re: SSHatter 0.6 Anders B Jansson (Oct 07)
Re: Distributed SSH username/password brute forceattack Anders B Jansson (Oct 22)

Andreas Lindenblatt

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Andreas Lindenblatt (Oct 09)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Andreas Lindenblatt (Oct 09)

Andre Gironda

Re: Most Secure Browser Andre Gironda (Oct 17)
Re: Most Secure Browser Andre Gironda (Oct 18)

Andres Riancho

[TOOL] w3af - Web Application Attack and Audit Framework Andres Riancho (Oct 18)

Andrew Farmer

Re: rPSA-2007-0212-1 util-linux Andrew Farmer (Oct 12)
Re: Original Photo Gallery Remote Command Execution Andrew Farmer (Oct 04)
Re: Report to Recipient(s) Andrew Farmer (Oct 09)

Andy Davis

Cisco IOS LPD Remote Stack Overflow - updated Cisco patch link (changed at the last minute) Andy Davis (Oct 10)
High-Level Reverse Engineering whitepaper Andy Davis (Oct 01)
IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Andy Davis (Oct 10)
IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX Andy Davis (Oct 16)
Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Andy Davis (Oct 10)
Re: IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX Andy Davis (Oct 17)
Cisco IOS LPD Remote Stack Overflow Andy Davis (Oct 10)
IRM Discover More Vulnerabilities in Cisco IOS Andy Davis (Oct 23)
Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Andy Davis (Oct 10)
Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Andy Davis (Oct 10)

Anshuman G

Re: Testing DidTheyReadIt.com Anshuman G (Oct 01)

Anthony V . Vitale

Someone is impersonating Gadi Evron and spamming this list Anthony V . Vitale (Oct 20)

A. R.

sqlninja 0.2.1 released A. R. (Oct 07)
sqlninja 0.2.1 - fix! A. R. (Oct 08)

ascii

Original Photo Gallery Remote Command Execution ascii (Oct 02)

Asterisk Security Team

AST-2007-023 - SQL Injection Vulnerabilty in cdr_addon_mysql Asterisk Security Team (Oct 16)

avivra

Re: playing for fun with <=IE7 avivra (Oct 15)

Bernd Marienfeldt

Re: List of security conferences Bernd Marienfeldt (Oct 10)

Bernhard Mueller

SEC Consult SA-20071031-0 :: Perdition IMAP Proxy Format String Vulnerability Bernhard Mueller (Oct 31)
SEC Consult SA-20071012-0 :: Madwifi xrates element remote DOS Bernhard Mueller (Oct 12)

Bipin Gautam

password hash, funny myth in the industry! Bipin Gautam (Oct 16)

biz4rre

Re: PDF mailto exploit in the wild biz4rre (Oct 23)
0-day PDF exploit biz4rre (Oct 16)
0-day PDF exploit biz4rre (Oct 16)
Re: 0-day PDF exploit biz4rre (Oct 16)

Brandon S. Allbery KF8NH

Re: Fwd: Experience masturbation like never before. Brandon S. Allbery KF8NH (Oct 16)
Re: Holes in the firewall of Mac OS X Leopard Brandon S. Allbery KF8NH (Oct 29)

Brett Moore

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Brett Moore (Oct 09)

Brian Toovey

Re: Netscreen 5400 Brian Toovey (Oct 01)
password hash Brian Toovey (Oct 04)

Chris Benedict

Re: pdp is leaving us Chris Benedict (Oct 29)
Re: pdp is leaving us Chris Benedict (Oct 28)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco Unified Communications Manager Denial of Service Vulnerabilities Cisco Systems Product Security Incident Response Team (Oct 17)
Cisco Security Advisory: Multiple Vulnerabilities in Firewall Services Module Cisco Systems Product Security Incident Response Team (Oct 17)
Cisco Security Advisory: Cisco Unified Communications Web-based Management Vulnerability Cisco Systems Product Security Incident Response Team (Oct 17)
Cisco Security Advisory: Multiple Vulnerabilities in Cisco PIX and ASA Appliances Cisco Systems Product Security Incident Response Team (Oct 17)
Cisco Security Advisory: Cisco Wireless Control System Conversion Utility Adds Default Password Cisco Systems Product Security Incident Response Team (Oct 10)

clappymonkey

(no subject) clappymonkey (Oct 02)

cocoruder .

Re: 0-day PDF exploit cocoruder . (Oct 16)
Re: 0-day PDF exploit cocoruder . (Oct 17)

Collin R. Mulliner

simple dns rebinding protection with dnsmasq Collin R. Mulliner (Oct 22)

Core Security Technologies Advisories

CORE-2007-0928: Stack-based buffer overflow vulnerability in OpenBSD’s DHCP server Core Security Technologies Advisories (Oct 10)

C Q

Re: Remote Desktop Command Fixation Attacks C Q (Oct 14)
Re: Why criticize security researchers? On the recent PDP case. C Q (Oct 14)
Re: Remote Desktop Command Fixation Attacks C Q (Oct 14)

crazy frog crazy frog

Redirecting 404 error pages? crazy frog crazy frog (Oct 21)
Best TCP IP stack? crazy frog crazy frog (Oct 27)
Re: Fwd: I want to be with you crazy frog crazy frog (Oct 22)
Re: This list sucks crazy frog crazy frog (Oct 15)
Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques crazy frog crazy frog (Oct 10)
Re: IRM Discover More Vulnerabilities in Cisco IOS crazy frog crazy frog (Oct 23)
Re: DailyGadi: Cyberwar alert, mass disruption coming crazy frog crazy frog (Oct 21)
Re: Life cycle of a hacker by n3td3v crazy frog crazy frog (Oct 03)
Re: full-disclosure () hushmail com crazy frog crazy frog (Oct 15)
Re: Redirecting 404 error pages? crazy frog crazy frog (Oct 22)

cybergoth

Re: Distributed SSH username/password brute forceattack cybergoth (Oct 22)
CISSPs securing ur networks cybergoth (Oct 21)

Cyneox

Re: Is Your Kid Going to Jail Before College? Cyneox (Oct 10)

Damir Rajnovic

Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Damir Rajnovic (Oct 10)

Dancho Danchev

Assessing Malware Embedded Attack Campaigns Dancho Danchev (Oct 30)

Daniel Marsh

Re: Is this an attack? Daniel Marsh (Oct 14)

Daniel Sichel

Is this sane? Daniel Sichel (Oct 15)

dann frazier

[SECURITY] [DSA 1381-2] New Linux 2.6.18 packages fix several vulnerabilities dann frazier (Oct 12)
[SECURITY] [DSA 1381-1] New Linux 2.6.18 packages fix several vulnerabilities dann frazier (Oct 02)
[SECURITY] [DSA 1365-3] New id3lib3.8.3 packages fix denial of service dann frazier (Oct 02)

David Kierznowski

Hijacking Feeds with Feedburner David Kierznowski (Oct 03)

David Litchfield

SQL Injection Flaw in Oracle Workspace Manager David Litchfield (Oct 17)

don bailey

Re: TCP Hijacking (aka Man-in-the-Middle) don bailey (Oct 26)

donglesby

lol @ you donglesby (Oct 27)

Dragos Ruiu

In Memoriam: Jun-ichiro Hagino Dragos Ruiu (Oct 30)
PacSec 2007 Agenda (Tokyo 11-29/30) Dragos Ruiu (Oct 22)
PacSec 2007 Agenda (Tokyo 11-29/30) Dragos Ruiu (Oct 22)

Dude VanVinkle

ACHTUNG Dude VanVinkle (Oct 14)
Re: Zone-H.org: 10 reasons websites get hacked Dude VanVinkle (Oct 17)
Re: Fwd: Experience masturbation like never before. Dude VanVinkle (Oct 16)
!!! W4RN1NG N1GS und P1GZ !!! Dude VanVinkle (Oct 14)

Dude VanWinkle

Re: If internet goes down out of hours, we're screwed Dude VanWinkle (Oct 09)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Dude VanWinkle (Oct 09)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Dude VanWinkle (Oct 09)
Re: full-disclosure () hushmail com Dude VanWinkle (Oct 14)
Re: Flash that simulates virus scan Dude VanWinkle (Oct 31)
Re: full-disclosure () hushmail com Dude VanWinkle (Oct 14)
Re: If internet goes down out of hours, we're screwed Dude VanWinkle (Oct 09)
Re: spammer wades into US Presidential race Dude VanWinkle (Oct 30)
Re: Testing DidTheyReadIt.com Dude VanWinkle (Oct 01)
Re: full-disclosure () hushmail com Dude VanWinkle (Oct 13)
Re: full-disclosure () hushmail com Dude VanWinkle (Oct 13)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Dude VanWinkle (Oct 09)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Dude VanWinkle (Oct 06)
Re: Fwd: Experience masturbation like never before. Dude VanWinkle (Oct 16)
Re: Recall: UNSUBSCRIBE Dude VanWinkle (Oct 08)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Dude VanWinkle (Oct 07)

edison

How to use the tools rainbowrack 1.2-src edison (Oct 23)

edi.strosar

Vba32 AntiVirus v3.12.2 insecure file permissions edi.strosar (Oct 04)

eEye Advisories

EEYE: CA BrightStor ArcServe Backup Server Arbitrary Pointer Dereference eEye Advisories (Oct 11)

ekoparty

Ekoparty 3th. Edition 2007 CFP closed - Buenos Aires - Argentina. ekoparty (Oct 19)

endrazine

Re: The real motivations of vulnerability disclosure endrazine (Oct 03)

Epic

Re: DHS need to get on top of this right now Epic (Oct 24)

eric

Re: 0-day PDF exploit eric (Oct 17)

Eric Rachner

Re: The Death of Defence in Depth ? - An invitation to Hack.lu Eric Rachner (Oct 12)

fabio

Re: peace fabio (Oct 19)
peace fabio (Oct 18)

Fabio N Sarmento [ Gmail ]

0day Orkut XSS [ NEW! ] Fabio N Sarmento [ Gmail ] (Oct 12)

Fabio Pietrosanti

Who still trust filevault? Finally TrueCrypt for Mac OS X! Fabio Pietrosanti (Oct 09)
[Fwd: Google Groups: No such group] Fabio Pietrosanti (Oct 10)
Come on, let's do funding for Mac OS TrueCrypt porting ! Fabio Pietrosanti (Oct 20)
Getting TrueCrypt ported to Mac Os X! Fabio Pietrosanti (Oct 10)
Re: Come on, let's do funding for Mac OS TrueCrypt porting ! Fabio Pietrosanti (Oct 20)
Re: Come on, let's do funding for Mac OS TrueCrypt porting ! Fabio Pietrosanti (Oct 20)

Fabrizio

Re: UNSUBSCRIBE Fabrizio (Oct 09)
Re: Google Sacure Fabrizio (Oct 25)
MySpace URL redirection Fabrizio (Oct 26)

Fareeduddin Ahmad

Netscreen 5400 Fareeduddin Ahmad (Oct 01)

fdlist

Re: [+] Vulnerability in less version 394 and prior fdlist (Oct 30)

Felix 'FX' Lindner

Re: The Death of Defence in Depth ? - An invitation to Hack.lu Felix 'FX' Lindner (Oct 10)

Ferdinand Klinzer

Re: UNSUBSCRIBE Ferdinand Klinzer (Oct 09)

FistFuXXer

IBM Lotus Domino - IMAP4 Mailbox Name Stack Overflow Exploit FistFuXXer (Oct 27)

Florian Weimer

[SECURITY] [DSA 1387-1] New librpcsecgss packages fix arbitrary code execution Florian Weimer (Oct 15)

Foresight Linux Essential Announcement Service

FLEA-2007-0062-1 firefox Foresight Linux Essential Announcement Service (Oct 28)
FLEA-2007-0061-1 sun-jre sun-jdk Foresight Linux Essential Announcement Service (Oct 28)
FLEA-2007-0059-1 qt qt-tools Foresight Linux Essential Announcement Service (Oct 04)
FLEA-2007-0058-1 openssl openssl-scripts Foresight Linux Essential Announcement Service (Oct 03)
FLEA-2007-0060-1 initscripts Foresight Linux Essential Announcement Service (Oct 26)
FLEA-2007-0057-1 pidgin Foresight Linux Essential Announcement Service (Oct 03)

forever . b0rked

Re: CISSPs securing ur networks forever . b0rked (Oct 21)

fts_skw

List of security conferences fts_skw (Oct 10)

full-disclosure

Re: 0-day PDF exploit full-disclosure (Oct 17)
Re: Serious holes affecting SiteBar 3.3.8 full-disclosure (Oct 19)
Fwd: Experience masturbation like never before. full-disclosure (Oct 16)
Re: Remote Desktop Command Fixation Attacks full-disclosure (Oct 10)
Re: pdp architect, drraid, beastiality, and incest full-disclosure (Oct 16)
REALLY GOOD ARTICLE FROM SECURITYFOCUS full-disclosure (Oct 12)
Re: SSHatter 0.6 full-disclosure (Oct 07)
Re: Third-party patch for CVE-2007-3896, UPDATE NOW full-disclosure (Oct 17)
Re: peace full-disclosure (Oct 19)
Re: password plugin for linux? full-disclosure (Oct 18)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 10)
Re: Gmail 1.1.0 for BlackBerry remote DoS full-disclosure (Oct 19)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 05)
Re: Fwd: Experience masturbation like never before. full-disclosure (Oct 16)
Re: Netgear SSL312 XSS vulnerability full-disclosure (Oct 19)
Re: OMG - I just won the lottery! For real!!11! full-disclosure (Oct 17)
Re: Cross Site Hacking Browser Injection Attack Vulnerability Paradigms full-disclosure (Oct 20)
PhD Power in Efffect full-disclosure (Oct 19)
Re: 0-day PDF exploit full-disclosure (Oct 16)
Cross Site Hacking Browser Injection Attack Vulnerability Paradigms full-disclosure (Oct 20)
Re: are the NetBIOS-like hacking days over? - wide open citrix services on critical domains full-disclosure (Oct 07)
Re: extension for Firefox to force HTTPS always? full-disclosure (Oct 13)
Re: Madness? This is KWICKFIX!!!!!! full-disclosure (Oct 20)
Re: If internet goes down out of hours, we're screwed full-disclosure (Oct 09)
Re: Email Disclaimers...Legally Liable if breached? full-disclosure (Oct 11)
Re: extension for Firefox to force HTTPS always? full-disclosure (Oct 13)
Re: full-disclosure () hushmail com full-disclosure (Oct 14)
Re: 0-day PDF exploit full-disclosure (Oct 16)
Re: Most Secure Browser full-disclosure (Oct 17)
Re: XSS vulnerabilities on eBay, MySpace, CNN.com, etc full-disclosure (Oct 19)
Re: Tikiwiki 1.9.8 exploit ITW full-disclosure (Oct 12)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 05)
Re: Most Secure Browser full-disclosure (Oct 18)
Re: Fwd: Experience masturbation like never before. full-disclosure (Oct 16)
Re: SQL Injection Flaw in Oracle Workspace Manager full-disclosure (Oct 17)
Re: password hash full-disclosure (Oct 05)
Re: If internet goes down out of hours, we're screwed full-disclosure (Oct 09)
Fwd: To the list admin: address change. full-disclosure (Oct 17)
Re: password hash, funny myth in the industry! full-disclosure (Oct 16)
Re: [MailServer Notification]Content Filtering Notification full-disclosure (Oct 16)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 07)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. full-disclosure (Oct 19)
Re: pdp architect, drraid, beastiality, and incest full-disclosure (Oct 16)
Re: extension for Firefox to force HTTPS always? full-disclosure (Oct 12)
Re: If internet goes down out of hours, we're screwed full-disclosure (Oct 10)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. full-disclosure (Oct 19)
Re: Your email requires verification. full-disclosure (Oct 18)
Re: .aware eZine (beta edition) full-disclosure (Oct 18)
Re: full-disclosure () hushmail com full-disclosure (Oct 13)
Re: UNSUBSCRIBE full-disclosure (Oct 09)
Most Secure Browser full-disclosure (Oct 17)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 09)
Re: Fwd: Experience masturbation like never before. full-disclosure (Oct 16)
Re: extension for Firefox to force HTTPS always? full-disclosure (Oct 13)
Re: Zone-H.org: 10 reasons websites get hacked full-disclosure (Oct 18)
Re: Netgear SSL312 XSS vulnerability full-disclosure (Oct 19)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 07)
Re: Netgear SSL312 XSS vulnerability full-disclosure (Oct 18)
Re: Zone-H.org: 10 reasons websites get hacked full-disclosure (Oct 17)
Re: 0day: Hacking secured CITRIX from outside full-disclosure (Oct 10)
Re: full-disclosure () hushmail com full-disclosure (Oct 13)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. full-disclosure (Oct 19)
Re: peace full-disclosure (Oct 18)
Re: Remote Desktop Command Fixation Attacks full-disclosure (Oct 11)
Re: 0-day PDF exploit full-disclosure (Oct 16)
Re: Netscape Navigator 9.0 fixes several vulnerabilities full-disclosure (Oct 17)
Re: password plugin for linux? full-disclosure (Oct 19)
Re: Fwd: Experience masturbation like never before. full-disclosure (Oct 16)
Re: Creative spam full-disclosure (Oct 19)
Re: Did people power get rid of Gadi Evron from Full-Disclosure? full-disclosure (Oct 18)
Re: Email Disclaimers...Legally Liable ifbreached? full-disclosure (Oct 11)
Re: Vulnerabilities digest full-disclosure (Oct 10)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 09)
Re: Email Disclaimers...Legally Liable if breached? full-disclosure (Oct 11)
Re: full-disclosure () hushmail com full-disclosure (Oct 15)
Re: IRM Discover More Vulnerabilities in Cisco IOS full-disclosure (Oct 23)
Re: full-disclosure () hushmail com full-disclosure (Oct 14)
Re: password hash, funny myth in the industry! full-disclosure (Oct 16)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? full-disclosure (Oct 09)
Re: extension for Firefox to force HTTPS always? full-disclosure (Oct 13)
Fwd: I want to be with you full-disclosure (Oct 22)

gabriel rosenkoetter

Re: Email Disclaimers...Legally Liable if breached? gabriel rosenkoetter (Oct 10)

Gadi Evron

Fifty Hitler Gadi Evron (Oct 20)
DailyGadi: Rhino9 is back Gadi Evron (Oct 20)
Why? Gadi Evron (Oct 20)
SNOSOFT: Remote OpenSSH 0day! (yuck) Gadi Evron (Oct 20)
Perl or python: the debate Gadi Evron (Oct 20)
DailyGadi: Russian whores Gadi Evron (Oct 20)
DailyGadi: Cyberwar alert, mass disruption coming Gadi Evron (Oct 20)
My youth Gadi Evron (Oct 20)
Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus Gadi Evron (Oct 20)
Queers Gadi Evron (Oct 20)
DailyGadi: Rainbow tables Gadi Evron (Oct 20)
DailyGadi: Holocaust denial Gadi Evron (Oct 20)
Fifty Hitler Gadi Evron (Oct 20)
DailyGadi: My fro Gadi Evron (Oct 20)
DailyGadi: I hate you Gadi Evron (Oct 20)
DailyGadi: Transvestites Gadi Evron (Oct 20)
DailyGadi: Molested Gadi Evron (Oct 20)
Fifty Hitler Gadi Evron (Oct 20)
Damn trolls Gadi Evron (Oct 20)
French frogs jump over the fog Gadi Evron (Oct 20)

Gautam

Re: Testing DidTheyReadIt.com Gautam (Oct 01)

Gautam R. Singh

Re: Remote Desktop Command Fixation Attacks Gautam R. Singh (Oct 11)

gaz_sec

iPhone Safari zero day gaz_sec (Oct 06)

gboyce

Re: Remote Desktop Command Fixation Attacks gboyce (Oct 11)
Re: Remote Desktop Command Fixation Attacks gboyce (Oct 11)
Re: 0-day PDF exploit gboyce (Oct 19)

Geo.

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Geo. (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Geo. (Oct 06)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Geo. (Oct 06)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Geo. (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Geo. (Oct 07)

German

Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. German (Oct 19)

ghost

Re: SSHatter 0.6 ghost (Oct 07)

giovanni manunta

Net & System Security 2007 giovanni manunta (Oct 17)
Net & System Security 2007 giovanni manunta (Oct 17)

gjgowey

Re: Email Disclaimers...Legally Liable ifbreached? gjgowey (Oct 10)
Re: Report to Recipient(s) gjgowey (Oct 09)
Re: password hash gjgowey (Oct 04)
Re: Remote Desktop Command Fixation Attacks gjgowey (Oct 15)
Fw: News Delivery Report (Failure) gjgowey (Oct 08)
Re: are the NetBIOS-like hacking days over? - wideopen citrix services on critical domains gjgowey (Oct 07)
Re: Question re: Macro Virus behaviour gjgowey (Oct 07)
Re: UNSUBSCRIBE gjgowey (Oct 09)
Re: Email Disclaimers...Legally Liable if breached? gjgowey (Oct 10)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype gjgowey (Oct 07)
Re: iDefense Security Advisory 10.09.07:Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow gjgowey (Oct 10)
Re: extension for Firefox to force HTTPS always? gjgowey (Oct 12)
Re: full-disclosure () hushmail com gjgowey (Oct 14)
Re: Someone is impersonating Gadi Evron andspamming this list gjgowey (Oct 20)
Re: UNSUBSCRIBE gjgowey (Oct 09)
Re: The Death of Defence in Depth ? - Aninvitation to Hack.lu gjgowey (Oct 12)
Re: full-disclosure () hushmail com gjgowey (Oct 14)
Re: lol @ you gjgowey (Oct 27)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. gjgowey (Oct 19)
Re: UNSUBSCRIBE gjgowey (Oct 08)
Re: gnucitizen bt home hub latest, attacks wide spread, outages reported gjgowey (Oct 12)
Re: Remote Desktop Command Fixation Attacks gjgowey (Oct 11)
Re: extension for Firefox to force HTTPS always? gjgowey (Oct 12)
Fw: Someone is impersonating Gadi Evron andspamming this list gjgowey (Oct 21)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype gjgowey (Oct 07)
Fw: Google Groups: No such group gjgowey (Oct 08)

Glenn.Everhart

Re: DHS need to get on top of this right now Glenn.Everhart (Oct 24)

glopeda . com

[+] Vulnerability in less version 394 and prior glopeda . com (Oct 30)
Re: [+] Vulnerability in less version 394 and prior glopeda . com (Oct 31)

Glynn Clements

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Glynn Clements (Oct 07)

Gregory Boyce

Re: PDF mailto exploit in the wild Gregory Boyce (Oct 23)

Gregory Rubin

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Gregory Rubin (Oct 09)

Guasconi Vincent

Re: password plugin for linux? Guasconi Vincent (Oct 20)
Re: simple dns rebinding protection with dnsmasq Guasconi Vincent (Oct 23)

Gyan Chawdhary

Juniper JunOS gdb question Gyan Chawdhary (Oct 19)

Harry Hoffman

Re: extension for Firefox to force HTTPS always? Harry Hoffman (Oct 12)

Harry Muchow

Re: UNSUBSCRIBE Harry Muchow (Oct 08)

H D Moore

Cracking the iPhone (5 article series) H D Moore (Oct 22)

Hernan Ochoa

WifiZoo v1.2 release Hernan Ochoa (Oct 01)

hfli

CA BrightStor ARCServe BackUp Message Engine Remote Stack Overflow Vulnerability hfli (Oct 11)

iDefense Labs

iDefense Security Advisory 10.10.07: Kaspersky Web Scanner ActiveX Format String Vulnerability iDefense Labs (Oct 10)
iDefense Security Advisory 10.30.07: IBM AIX bellmail Stack Buffer Overflow Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability iDefense Labs (Oct 03)
iDefense Security Advisory 10.30.07: IBM AIX ftp domacro Parameter Buffer Overflow Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.30.07: IBM AIX lquerypv Stack Buffer Overflow Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.31.07: Symantec Altiris Deployment Solution TFTP/MTFTP Service Directory Traversal Vulnerability iDefense Labs (Oct 31)
iDefense Security Advisory 10.25.07: Trend Micro Tmxpflt.sys IOCTL 0xa0284403 Buffer Overflow Vulnerability iDefense Labs (Oct 25)
iDefense Security Advisory 10.02.07: Multiple Vendor X Font Server Multiple Vulnerabilities iDefense Labs (Oct 02)
iDefense Security Advisory 10.30.07: IBM AIX 5.2 crontab BSS Buffer Overflow Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.31.07: Macrovision InstallShield Update Service ActiveX Unsafe Method Vulnerability iDefense Labs (Oct 31)
iDefense Security Advisory 10.11.07: Multiple Vendor FLAC Library Multiple Integer Overflow Vulnerabilities iDefense Labs (Oct 11)
iDefense Security Advisory 10.30.07: IBM AIX swcons Local Arbitrary File Access Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.30.07: IBM AIX lqueryvg Stack Buffer Overflow Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.23.07: IBM Lotus Domino IMAP Buffer Overflow Vulnerability iDefense Labs (Oct 24)
Re: iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability iDefense Labs (Oct 04)
iDefense Security Advisory 10.23.07: IBM Lotus Notes Client TagAttributeListCopy Buffer Overflow Vulnerability iDefense Labs (Oct 24)
iDefense Security Advisory 10.30.07: IBM AIX dig dns_name_fromtext Integer Underflow Vulnerability iDefense Labs (Oct 30)
iDefense Security Advisory 10.09.07: Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow iDefense Labs (Oct 09)

imipak

Re: The Death of Defence in Depth ? - Aninvitation to Hack.lu imipak (Oct 10)

imul

Re: pdp is leaving us imul (Oct 29)
pdp architect, drraid, beastiality, and incest imul (Oct 15)
Re: MySpace URL redirection imul (Oct 27)
Re: are the NetBIOS-like hacking days over? - wide imul (Oct 08)

Ismail Dönmez

Re: extension for Firefox to force HTTPS always? Ismail Dönmez (Oct 12)

Ivan .

Ten ways to thwart Big Brother Ivan . (Oct 31)

jam

Re: spammer wades into US Presidential race jam (Oct 30)

James Lay

Spike in SSH scans James Lay (Oct 22)

James Matthews

Re: Testing DidTheyReadIt.com James Matthews (Oct 01)
Re: *****SPAM***** OMG - I just won the lottery! For real!!11! James Matthews (Oct 17)
Re: Is Your Kid Going to Jail Before College? James Matthews (Oct 10)
Re: UNSUBSCRIBE James Matthews (Oct 08)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype James Matthews (Oct 07)

James (njan) Eaton-Lee

Re: Remote Desktop Command Fixation Attacks James (njan) Eaton-Lee (Oct 15)

Jay Sulzberger

Re: UNSUBSCRIBE Jay Sulzberger (Oct 08)

Jeff Moss

Black Hat Tokyo + DC and Europe CfPs now open. Jeff Moss (Oct 08)

Jeffrey Denton

Re: [+] Vulnerability in less version 394 and prior Jeffrey Denton (Oct 31)

jeroen

Re: *****SPAM***** OMG - I just won the lottery! For real!!11! jeroen (Oct 17)

jf

Re: Flash that simulates virus scan jf (Oct 31)

jgffgjfgd rewrewrew

XSS vulnerabilities on eBay, MySpace, CNN.com, etc jgffgjfgd rewrewrew (Oct 19)

Jimby Sharp

Re: Firefox 2.0.0.7 has a very serious calculation bug Jimby Sharp (Oct 02)

Jim Harrison

Re: Remote Desktop Command Fixation Attacks Jim Harrison (Oct 11)

Jim Popovitch

Re: yahoo news been offline for hours Jim Popovitch (Oct 09)
Re: Google Sacure Jim Popovitch (Oct 26)

Joe Barr

Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. Joe Barr (Oct 19)

Joel Jaeggli

Re: ZDI-07-056: IBM DB2 DB2JDS Multiple Vulnerabilities Joel Jaeggli (Oct 10)

Joey Mengele

Re: full-disclosure () hushmail com Joey Mengele (Oct 16)
Re: iDefense Security Advisory 10.02.07: Sun Microsystems Solaris FIFO FS Information Disclosure Vulnerability Joey Mengele (Oct 05)
Re: full-disclosure () hushmail com Joey Mengele (Oct 15)
Re: Who still trust filevault? Finally TrueCrypt for Mac OS X! Joey Mengele (Oct 09)

John C. A. Bambenek, CISSP

Re: Remote Desktop Command Fixation Attacks John C. A. Bambenek, CISSP (Oct 11)
Re: This list sucks John C. A. Bambenek, CISSP (Oct 15)
Re: spammer wades into US Presidential race John C. A. Bambenek, CISSP (Oct 30)

John Cartwright

List Charter John Cartwright (Oct 16)

John Kinsella

Re: DHS need to get on top of this right now John Kinsella (Oct 24)
Re: DHS need to get on top of this right now John Kinsella (Oct 23)

john lokka

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype john lokka (Oct 09)

john myman

TheSersonFiles tomserson Tom Serson john myman (Oct 15)
tomserson tom serson full disclosure TheSersonFiles john myman (Oct 15)

jonasthambert

PHP File Sharing System 1.5.1 jonasthambert (Oct 13)

Jonathan Smith

Re: [+] Vulnerability in less version 394 and prior Jonathan Smith (Oct 30)

Jones, Jeff (Enterprise Security)

Recall: UNSUBSCRIBE Jones, Jeff (Enterprise Security) (Oct 08)
UNSUBSCRIBE Jones, Jeff (Enterprise Security) (Oct 08)

J. Oquendo

Re: Spike in SSH scans J. Oquendo (Oct 22)

Joshua Tagnore

Flash that simulates virus scan Joshua Tagnore (Oct 31)

Joxean Koret

How to subvert Oracle Database Vault Joxean Koret (Oct 28)
Inguma 0.0.5: Brute forcing and password cracking Joxean Koret (Oct 20)

jpk

Re: Netgear SSL312 XSS vulnerability jpk (Oct 19)

Juergen Schmidt

Holes in the firewall of Mac OS X Leopard Juergen Schmidt (Oct 29)
Re: Holes in the firewall of Mac OS X Leopard Juergen Schmidt (Oct 29)
URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Juergen Schmidt (Oct 05)

Juha-Matti Laurio

Netscape Navigator 9.0 fixes several vulnerabilities Juha-Matti Laurio (Oct 17)
Re: Google Sacure Juha-Matti Laurio (Oct 25)
Re: List of security conferences Juha-Matti Laurio (Oct 10)
Re: Google Sacure (A. Jodoin) Juha-Matti Laurio (Oct 26)
Re: Netscape Navigator 9.0 fixes several vulnerabilities Juha-Matti Laurio (Oct 17)
Re: UNSUBSCRIBE Juha-Matti Laurio (Oct 09)
Camino release 1.5.2 fixes several vulnerabilities Juha-Matti Laurio (Oct 22)
Zone-H.org: 10 reasons websites get hacked Juha-Matti Laurio (Oct 17)

Justin Klein Keane

Re: 0-day PDF exploit Justin Klein Keane (Oct 17)

Kanatoko

Java Applets can connect to other hosts using HTTP 302 redirection Kanatoko (Oct 02)
Re: Java Applets can connect to other hosts using HTTP 302 redirection Kanatoko (Oct 05)

kcope

Apache Tomcat Rem0Te FiLe DiscloSure ZeroDay (W3bd4v) kcope (Oct 14)

Kees Cook

[USN-528-1] MySQL vulnerabilities Kees Cook (Oct 10)
[USN-538-1] libpng vulnerabilities Kees Cook (Oct 25)
[USN-529-1] Tk vulnerability Kees Cook (Oct 11)
[USN-527-1] xen-3.0 vulnerability Kees Cook (Oct 09)
[USN-523-1] ImageMagick vulnerabilities Kees Cook (Oct 03)
[USN-533-1] util-linux vulnerability Kees Cook (Oct 22)
[USN-531-2] dhcp vulnerability Kees Cook (Oct 23)
[USN-526-1] debian-goodies vulnerability Kees Cook (Oct 04)
[USN-537-1] gnome-screensaver vulnerability Kees Cook (Oct 23)
[USN-534-1] OpenSSL vulnerability Kees Cook (Oct 22)
[USN-524-1] OpenOffice.org vulnerability Kees Cook (Oct 04)
[USN-501-2] Ghostscript vulnerability Kees Cook (Oct 22)
[USN-530-1] hplip vulnerability Kees Cook (Oct 12)
[USN-536-1] Thunderbird vulnerabilities Kees Cook (Oct 23)
[USN-532-1] nagios-plugins vulnerability Kees Cook (Oct 22)
[USN-531-1] dhcp vulnerability Kees Cook (Oct 22)
[USN-525-1] libsndfile vulnerability Kees Cook (Oct 04)
[USN-535-1] Firefox vulnerabilities Kees Cook (Oct 22)

kefka

Re: THE FIRESALE IS COMING!! kefka (Oct 20)

Kelly Robinson

Email Disclaimers...Legally Liable if breached? Kelly Robinson (Oct 10)
Re: Email Disclaimers...Legally Liable ifbreached? Kelly Robinson (Oct 10)
Is this an attack? Kelly Robinson (Oct 14)
OMG - I just won the lottery! For real!!11! Kelly Robinson (Oct 16)
Question re: Macro Virus behaviour Kelly Robinson (Oct 07)
Technology and your Security Program Kelly Robinson (Oct 11)

KJK::Hyperion

I made third-party patch for CVE-2007-3896 (Internet Explorer 7 invalid URI handling) KJK::Hyperion (Oct 14)
Third-party patch for CVE-2007-3896 (Internet Explorer 7 invalid URI handling) available KJK::Hyperion (Oct 13)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 06)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 09)
Re: I made third-party patch for CVE-2007-3896 (Internet Explorer 7 invalid URI handling) KJK::Hyperion (Oct 14)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 17)
Re: Third-party patch for CVE-2007-3896, UPDATE NOW KJK::Hyperion (Oct 17)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype KJK::Hyperion (Oct 07)

Kristian Erik Hermansen

extension for Firefox to force HTTPS always? Kristian Erik Hermansen (Oct 12)
Gmail 1.1.0 for BlackBerry remote DoS Kristian Erik Hermansen (Oct 19)
Re: extension for Firefox to force HTTPS always? Kristian Erik Hermansen (Oct 12)
Core Impact 7.5 Web App pen-testing framework, as good as the hype? Kristian Erik Hermansen (Oct 05)
Microsoft Windows default ZIP handler bug Kristian Erik Hermansen (Oct 15)
Re: Microsoft Windows default ZIP handler bug Kristian Erik Hermansen (Oct 15)
Re: extension for Firefox to force HTTPS always? Kristian Erik Hermansen (Oct 12)

kriz . Full-Disclosure

URI handling woes in Acrobat Reader, Netscape, Miranda, Skype kriz . Full-Disclosure (Oct 09)

Kurt Buff

Re: Email Disclaimers...Legally Liable if breached? Kurt Buff (Oct 11)

Kurt Dillard

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Kurt Dillard (Oct 06)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. Kurt Dillard (Oct 19)

Lamer Buster

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Lamer Buster (Oct 07)
Re: Life cycle of a hacker by n3td3v Lamer Buster (Oct 04)

Lars Eilebrecht

Call for Papers for Security Track at ApacheCon Europe 2008 Lars Eilebrecht (Oct 22)

Leif Ericksen

Re: spammer wades into US Presidential race Leif Ericksen (Oct 28)
Re: spammer wades into US Presidential race Leif Ericksen (Oct 29)

lists () syn-recon net

Re: pdp is leaving us lists () syn-recon net (Oct 28)

Lolek of TK53

Re: Netgear SSL312 XSS vulnerability Lolek of TK53 (Oct 18)

lsi

Re: spammer wades into US Presidential race lsi (Oct 30)
spammer wades into US Presidential race lsi (Oct 28)
Re: spammer wades into US Presidential race lsi (Oct 31)

Luigi Auriemma

Format string in the Doom 3 engine through PB Luigi Auriemma (Oct 01)
Format string in The Dawn of Time 1.69s beta4 Luigi Auriemma (Oct 05)
NULL pointer crash in World in Conflict 1.000 Luigi Auriemma (Oct 09)
Multiple vulnerabilities in Dropteam 1.3.3 Luigi Auriemma (Oct 05)
Format string in F.E.A.R. 1.08 through PB Luigi Auriemma (Oct 01)
Unexploitable buffer-overflow in America's Army 2.8.2 through PB Luigi Auriemma (Oct 01)
Two buffer-overflow in FSD V2.052 d9 and FSFDT V3.000 d9 Luigi Auriemma (Oct 01)
Clients buffer-overflow in Live for Speed 0.5X10 Luigi Auriemma (Oct 13)

Luiz Eduardo

Re: List of security conferences Luiz Eduardo (Oct 10)

lulzlulzluzluz

Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. lulzlulzluzluz (Oct 19)
Re: XSS vulnerabilities on eBay, MySpace, CNN.com, etc lulzlulzluzluz (Oct 19)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. lulzlulzluzluz (Oct 19)
Re: [MailServer Notification]Content Filtering Notification lulzlulzluzluz (Oct 19)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. lulzlulzluzluz (Oct 19)

Marcus Graf

Re: extension for Firefox to force HTTPS always? Marcus Graf (Oct 13)

Marcus Meissner

Re: rPSA-2007-0212-1 util-linux Marcus Meissner (Oct 12)

Marc Vilanova Vilasero

Marc Vilanova Vilasero está ausente de la oficina. Marc Vilanova Vilasero (Oct 19)

Mark Senior

Re: DHS need to get on top of this right now Mark Senior (Oct 24)
Re: password hash Mark Senior (Oct 05)

Martin Schulze

[SECURITY] [DSA 1386-1] New wesnoth packages fix denial of service Martin Schulze (Oct 15)
[SECURITY] [DSA 1386-2] New wesnoth packages fix denial of service Martin Schulze (Oct 15)

M . B . Jr .

Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? M . B . Jr . (Oct 05)
Re: 0day: Hacking secured CITRIX from outside M . B . Jr . (Oct 10)
Re: Someone is impersonating Gadi Evron and spamming this list M . B . Jr . (Oct 20)

M. Burnett

Re: Remote Desktop Command Fixation Attacks M. Burnett (Oct 11)

Michael Bann

Re: Google Sacure Michael Bann (Oct 25)

Michael Holstein

Re: Google Sacure (A. Jodoin) Michael Holstein (Oct 26)
Re: DHS need to get on top of this right now Michael Holstein (Oct 24)

Michael Neal Vasquez

Re: Flash that simulates virus scan Michael Neal Vasquez (Oct 31)

Michael Simpson

Re: Life cycle of a hacker by n3td3v Michael Simpson (Oct 03)

Mike Frantzen

Re: TCP Hijacking (aka Man-in-the-Middle) Mike Frantzen (Oct 25)

mike kemp

Open Text security contact mike kemp (Oct 31)

Mike Owen

Re: DHS need to get on top of this right now Mike Owen (Oct 24)

Moritz Muehlenhoff

[SECURITY] [DSA 1392-1] New xulrunner packages fix several vulnerabilities Moritz Muehlenhoff (Oct 20)
[SECURITY] [DSA 1396-1] New iceweasel packages fix several vulnerabilities Moritz Muehlenhoff (Oct 27)
[SECURITY] [DSA 1389-1] New zoph packages fix SQL injection Moritz Muehlenhoff (Oct 18)
[SECURITY] [DSA 1391-1] New icedove packages fix several vulnerabilities Moritz Muehlenhoff (Oct 19)
[SECURITY] [DSA 1385-1] New xfs packages fix arbitrary code execution Moritz Muehlenhoff (Oct 10)

Moritz Naumann

Tikiwiki 1.9.8 exploit ITW Moritz Naumann (Oct 11)

Morning Wood

Re: are the NetBIOS-like hacking days over? -wide open citrix services on critical domains Morning Wood (Oct 08)
Re: MySpace URL redirection Morning Wood (Oct 27)
Re: pdp architect, drraid, beastiality, and incest Morning Wood (Oct 16)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Morning Wood (Oct 08)
Re: MySpace URL redirection Morning Wood (Oct 28)

Mr Frog

The real motivations of vulnerability disclosure Mr Frog (Oct 02)

M. Shirk

RE: Marc Vilanova Vilasero está ausente de la oficina. M. Shirk (Oct 19)
Re: UNSUBSCRIBE M. Shirk (Oct 08)
Re: CISSPs securing ur networks M. Shirk (Oct 21)

mu-b

eXtremail(ly easy) remote roots mu-b (Oct 15)

Murray, Mike

RealPlayer vuln - versions affected? Murray, Mike (Oct 26)

Muskegon Whitehall

Re: lol @ you Muskegon Whitehall (Oct 28)
Re: "Hackers can divert Vonage calls: security firm" =>? Muskegon Whitehall (Oct 25)
Re: "Hackers can divert Vonage calls: security firm" =>? Muskegon Whitehall (Oct 25)

mynameisdrewpeacock

Re: Life cycle of a hacker by n3td3v mynameisdrewpeacock (Oct 04)

Nate McFeters

Re: pdp is leaving us Nate McFeters (Oct 27)

naveed

Re: Microsoft Windows default ZIP handler bug naveed (Oct 15)

NGSSoftware Insight Security Research

Untrusted Java applet can connect to localhost NGSSoftware Insight Security Research (Oct 30)
Heap overflow in RealPlayer ID3 tag parser NGSSoftware Insight Security Research (Oct 30)
Multiple SQL Injection Flaws in Oracle CTX_DOC package NGSSoftware Insight Security Research (Oct 17)
Oracle RDBMS TNS Data packet DoS NGSSoftware Insight Security Research (Oct 17)
Memory overwrites in JVM via malformed TrueType font NGSSoftware Insight Security Research (Oct 30)
Oracle TNS Listener DoS and/or remote memory inspection NGSSoftware Insight Security Research (Oct 17)
Oracle audit issue with XMLDB ftp service NGSSoftware Insight Security Research (Oct 17)
(no subject) NGSSoftware Insight Security Research (Oct 17)

Nick Boyce

Re: PDF mailto exploit in the wild Nick Boyce (Oct 23)
Re: PDF mailto exploit in the wild Nick Boyce (Oct 23)

Nick FitzGerald

Re: Flash that simulates virus scan Nick FitzGerald (Oct 31)
Re: MySpace URL redirection Nick FitzGerald (Oct 27)
Re: Email Disclaimers...Legally Liable if breached? Nick FitzGerald (Oct 10)
Re: Email Disclaimers...Legally Liable if breached? Nick FitzGerald (Oct 10)
Re: iDefense Security Advisory 10.09.07: Microsoft Windows Mail and Outlook Express NNTP Protocol Heap Overflow Nick FitzGerald (Oct 10)

Nicolas RUFF

Re: Microsoft Windows default ZIP handler bug Nicolas RUFF (Oct 31)

Nicolas Waisman

Immunity Debugger v1.2 Release Nicolas Waisman (Oct 01)

nigger johnson

Re: IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX nigger johnson (Oct 17)
Re: OMG - I just won the lottery! For real!!11! nigger johnson (Oct 17)

Nikolay Kichukov

Re: peace Nikolay Kichukov (Oct 18)
Re: password hash Nikolay Kichukov (Oct 06)

Noah Meyerhans

[SECURITY] [DSA 1390-1] New t1lib packages fix arbitrary code execution Noah Meyerhans (Oct 19)
[SECURITY] [DSA 1379-1] New openssl packages fix arbitrary code execution Noah Meyerhans (Oct 02)
[SECURITY] [DSA 1388-3] New dhcp packages fix arbitrary code execution Noah Meyerhans (Oct 30)
[SECURITY] [DSA 1379-2] New openssl packages fix arbitrary code execution Noah Meyerhans (Oct 10)

nocfed

Re: Distributed SSH username/password brute forceattack nocfed (Oct 23)

North, Quinn

Using GPUs to crack hashes North, Quinn (Oct 24)

Obscure

Re: Remote Desktop Command Fixation Attacks Obscure (Oct 11)
SIPVicious v0.2 - tools for auditing sip devices / PBXs Obscure (Oct 11)

Oliver

Re: TCP Hijacking (aka Man-in-the-Middle) Oliver (Oct 25)
Re: TCP Hijacking (aka Man-in-the-Middle) Oliver (Oct 31)
Re: TCP Hijacking (aka Man-in-the-Middle) Oliver (Oct 29)
TCP Hijacking (aka Man-in-the-Middle) Oliver (Oct 25)

Omar Santos

Re: Cisco IOS LPD Remote Stack Overflow Omar Santos (Oct 10)

Open Phugu

Re: 0day Orkut XSS [ NEW! ] Open Phugu (Oct 12)

Paul Craig

Cart32 Arbitrary File Download Vulnerability Paul Craig (Oct 04)

Paul Melson

Re: Remote Desktop Command Fixation Attacks Paul Melson (Oct 11)
Re: Technology and your Security Program Paul Melson (Oct 12)

Paul Ooi Cong Jen

Re: UNSUBSCRIBE Paul Ooi Cong Jen (Oct 09)

Paul Szabo

PDF mailto exploit in the wild Paul Szabo (Oct 23)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Paul Szabo (Oct 11)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Paul Szabo (Oct 06)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Paul Szabo (Oct 07)
Re: PDF mailto exploit in the wild Paul Szabo (Oct 23)

Pavel Kankovsky

Re: The Death of Defence in Depth ? - An invitation to Hack.lu Pavel Kankovsky (Oct 12)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Pavel Kankovsky (Oct 12)
Re: The Death of Defence in Depth ? - Aninvitation to Hack.lu Pavel Kankovsky (Oct 12)

pdp (architect)

are the NetBIOS-like hacking days over? - wide open citrix services on critical domains pdp (architect) (Oct 07)
Re: Remote Desktop Command Fixation Attacks pdp (architect) (Oct 15)
Remote Desktop Command Fixation Attacks pdp (architect) (Oct 10)
Re: full-disclosure () hushmail com pdp (architect) (Oct 15)
Re: full-disclosure () hushmail com pdp (architect) (Oct 15)
Re: Remote Desktop Command Fixation Attacks pdp (architect) (Oct 11)
0day: Hacking secured CITRIX from outside pdp (architect) (Oct 10)
Re: Remote Desktop Command Fixation Attacks pdp (architect) (Oct 11)
Re: Remote Desktop Command Fixation Attacks pdp (architect) (Oct 13)

Peter Besenbruch

Re: Someone is impersonating Gadi Evron and spamming this list Peter Besenbruch (Oct 20)
Re: Why criticize security researchers? On the recent PDP case. Peter Besenbruch (Oct 14)
Re: full-disclosure () hushmail com Peter Besenbruch (Oct 14)

Peter Dawson

Re: "Hackers can divert Vonage calls: security firm" =>? Peter Dawson (Oct 25)
Re: Zone-H.org: 10 reasons websites get hacked Peter Dawson (Oct 17)
Re: Life cycle of a hacker by n3td3v Peter Dawson (Oct 03)
Re: are the NetBIOS-like hacking days over? - wide open citrix services on critical domains Peter Dawson (Oct 08)
"Hackers can divert Vonage calls: security firm" =>? Peter Dawson (Oct 24)

Pete Simpson

Re: Remote Desktop Command Fixation Attacks Pete Simpson (Oct 12)

phantom

Re: List of security conferences phantom (Oct 10)

Philipp

Distributed SSH username/password brute force attack Philipp (Oct 22)

phioust

Re: This list sucks phioust (Oct 15)
Re: full-disclosure () hushmail com phioust (Oct 14)
Re: full-disclosure () hushmail com phioust (Oct 14)
Re: Someone is impersonating Gadi Evron and spamming this list phioust (Oct 20)
Re: the disappearance of the dog lover Petko D. Petkov phioust (Oct 20)
Re: DailyGadi: Russian whores phioust (Oct 20)
Re: pdp architect, drraid, beastiality, and incest phioust (Oct 16)
Re: Cross Site Hacking Browser Injection Attack Vulnerability Paradigms phioust (Oct 20)
A waste of "research" money phioust (Oct 07)
Re: full-disclosure () hushmail com phioust (Oct 14)
Re: Madness? This is KWICKFIX!!!!!! phioust (Oct 20)
Re: DailyGadi: Cyberwar alert, mass disruption coming phioust (Oct 20)
Re: 0-day PDF exploit phioust (Oct 16)
Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus phioust (Oct 19)
Re: Someone is impersonating Gadi Evron and spamming this list phioust (Oct 20)
Re: Madness? This is KWICKFIX!!!!!! phioust (Oct 20)
Re: password hash, funny myth in the industry! phioust (Oct 16)
Re: pdp architect, drraid, beastiality, and incest phioust (Oct 15)
Re: [MailServer Notification]Content Filtering Notification phioust (Oct 19)
Re: Someone is impersonating Gadi Evron and spamming this list phioust (Oct 20)
the disappearance of the dog lover Petko D. Petkov phioust (Oct 20)
Re: IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX phioust (Oct 16)
Re: This list sucks phioust (Oct 15)
Re: How to Handle ISPs Who Turn a Blind Eye to Criminal Activity? phioust (Oct 14)
Re: THE FIRESALE IS COMING!! phioust (Oct 20)
Re: the disappearance of the dog lover Petko D. Petkov phioust (Oct 20)
Re: Perl or python: the debate phioust (Oct 20)
Re: DailyGadi: Cyberwar alert, mass disruption coming phioust (Oct 20)
Re: THE FIRESALE IS COMING!! phioust (Oct 20)
THE FIRESALE IS COMING!! phioust (Oct 19)
Re: SSHatter 0.6 phioust (Oct 07)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. phioust (Oct 19)
Re: Someone is impersonating Gadi Evron and spamming this list phioust (Oct 20)
Re: Someone is impersonating Gadi Evron and spamming this list phioust (Oct 20)
Re: Come on, let's do funding for Mac OS TrueCrypt porting ! phioust (Oct 20)
Re: IRM Vendor Alerts: Six critical remote vulnerabilities in TIBCO SmartPGM FX phioust (Oct 17)
Re: DailyGadi: Cyberwar alert, mass disruption coming phioust (Oct 20)
Re: full-disclosure () hushmail com phioust (Oct 14)
Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus phioust (Oct 19)
Re: Come on, let's do funding for Mac OS TrueCrypt porting ! phioust (Oct 20)
Re: XSS vulnerabilities on eBay, MySpace, CNN.com, etc phioust (Oct 19)
Re: Jack Bauer Gets Jailed! phioust (Oct 11)
Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus phioust (Oct 20)

php0t

Re: DHS need to get on top of this right now php0t (Oct 24)

Pierre-Yves Rofes

[ GLSA 200710-13 ] Ampache: Multiple vulnerabilities Pierre-Yves Rofes (Oct 13)
[ GLSA 200710-12 ] T1Lib: Buffer overflow Pierre-Yves Rofes (Oct 12)
[ GLSA 200710-05 ] QGit: Insecure temporary file creation Pierre-Yves Rofes (Oct 07)
[ GLSA 200710-06 ] OpenSSL: Multiple vulnerabilities Pierre-Yves Rofes (Oct 07)
[ GLSA 200710-11 ] X Font Server: Multiple Vulnerabilities Pierre-Yves Rofes (Oct 12)
[ GLSA 200710-30 ] OpenSSL: Remote execution of arbitrary code Pierre-Yves Rofes (Oct 30)
[ GLSA 200710-14 ] DenyHosts: Denial of Service Pierre-Yves Rofes (Oct 13)
[ GLSA 200710-01 ] RPCSEC_GSS library: Buffer overflow Pierre-Yves Rofes (Oct 04)
[ GLSA 200710-15 ] KDM: Local privilege escalation Pierre-Yves Rofes (Oct 14)
[ GLSA 200710-16 ] X.Org X server: Composite local privilege escalation Pierre-Yves Rofes (Oct 14)
[ GLSA 200710-08 ] KOffice, KWord, KPDF, KDE Graphics Libraries: Stack-based buffer overflow Pierre-Yves Rofes (Oct 09)
[ GLSA 200710-09 ] NX 2.1: User-assisted execution of arbitrary code Pierre-Yves Rofes (Oct 09)

Piotr Bania

RealNetworks RealPlayer/RealOne Player/Helix Player Remote Heap Corruption Piotr Bania (Oct 25)
RealNetworks RealPlayer/RealOne Player/Helix Player Remote Memory Corruption Piotr Bania (Oct 25)

Praburaajan

CFP for HITBSecConf2008 - Dubai now open Praburaajan (Oct 22)
CFP for HITBSecConf2008 - Dubai now open Praburaajan (Oct 22)

professor buddha

Re: PhD Power in Efffect professor buddha (Oct 19)

Prohest

Re: DHS need to get on top of this right now Prohest (Oct 24)

Radu State

XSS and SQL injection via SIP (part 2) and toll fraud bonus Radu State (Oct 19)
Owning the internal network with SIP (part 1) and a Linksys Phone Radu State (Oct 09)
Re: CallManager and OpeSer toll fraud and authentication forward attack Radu State (Oct 15)
CallManager and OpeSer toll fraud and authentication forward attack Radu State (Oct 12)

Raphael Marichez

[ GLSA 200710-29 ] Sylpheed, Claws Mail: User-assisted remote execution of arbitrary code Raphael Marichez (Oct 25)
[ GLSA 200710-03 ] libvorbis: Multiple vulnerabilities Raphael Marichez (Oct 07)
[ GLSA 200710-18 ] util-linux: Local privilege escalation Raphael Marichez (Oct 18)
[ GLSA 200710-10 ] SKK Tools: Insecure temporary file creation Raphael Marichez (Oct 12)
[ GLSA 200710-04 ] libsndfile: Buffer overflow Raphael Marichez (Oct 07)
[ GLSA 200710-07 ] Tk: Buffer overflow Raphael Marichez (Oct 07)
[ GLSA 200710-20 ] PDFKit, ImageKits: Buffer overflow Raphael Marichez (Oct 18)
[ GLSA 200710-19 ] The Sleuth Kit: Integer underflow Raphael Marichez (Oct 18)
[ GLSA 200710-27 ] ImageMagick: Multiple vulnerabilities Raphael Marichez (Oct 24)
[ GLSA 200710-25 ] MLDonkey: Privilege escalation Raphael Marichez (Oct 24)
[ GLSA 200710-17 ] Balsa: Buffer overflow Raphael Marichez (Oct 16)
[ GLSA 200710-22 ] TRAMP: Insecure temporary file creation Raphael Marichez (Oct 20)
[ GLSA 200710-26 ] HPLIP: Privilege escalation Raphael Marichez (Oct 24)
[ GLSA 200710-23 ] Star: Directory traversal vulnerability Raphael Marichez (Oct 22)
[ GLSA 200710-28 ] Qt: Buffer overflow Raphael Marichez (Oct 25)
[ GLSA 200710-31 ] Opera: Multiple vulnerabilities Raphael Marichez (Oct 30)
[ GLSA 200710-02 ] PHP: Multiple vulnerabilities Raphael Marichez (Oct 07)
[ GLSA 200710-24 ] OpenOffice.org: Heap-based buffer overflow Raphael Marichez (Oct 23)
[ GLSA 200710-21 ] TikiWiki: Arbitrary command execution Raphael Marichez (Oct 20)

rattle

.aware eZine (beta edition) rattle (Oct 18)

Ray P

Re: Email Disclaimers...Legally Liable if breached? Ray P (Oct 10)
Re: Email Disclaimers...Legally Liable if breached? Ray P (Oct 13)
Re: Email Disclaimers...Legally Liable if breached? Ray P (Oct 11)

reepex

Re: spammer wades into US Presidential race reepex (Oct 28)
Re: Flash that simulates virus scan reepex (Oct 31)
Re: ifnet.it WEBIF XSS Vulnerability reepex (Oct 22)
Re: Google Sacure reepex (Oct 27)
Re: pdp is leaving us reepex (Oct 28)
Re: SAXON version 5.4 Multiple Path Disclosure Vulnerabilities reepex (Oct 29)
Re: MySpace URL redirection reepex (Oct 27)
Re: MySpace URL redirection reepex (Oct 28)
Re: TCP Hijacking (aka Man-in-the-Middle) reepex (Oct 25)
pdp is leaving us reepex (Oct 27)
Re: ZDI-07-063: RealPlayer RA Field Size File Processing Heap Oveflow Vulnerability reepex (Oct 31)
Re: IRM Discover More Vulnerabilities in Cisco IOS reepex (Oct 23)
Re: TCP Hijacking (aka Man-in-the-Middle) reepex (Oct 26)
Re: lol @ you reepex (Oct 27)
Re: ZDI-07-058: Oracle E-Business Suite SQL Injection Vulnerability reepex (Oct 31)
Re: Flash that simulates virus scan reepex (Oct 31)
Re: CISSPs securing ur networks reepex (Oct 21)
Re: Redirecting 404 error pages? reepex (Oct 21)
Re: Airscanner Mobile Security Advisory #07101401: Mobile-spy Victim/User Phone/SMS/URL Log Spoofing and Persistent XSS Injection reepex (Oct 23)

rembrandt

Re: Netgear SSL312 XSS vulnerability rembrandt (Oct 18)

Research

Miranda IM Multiple Buffer Overflow Vulnerabilities Research (Oct 23)

RISE Security

[RISE-2007002] Borland InterBase Multiple Buffer Overflow Vulnerabilities RISE Security (Oct 04)
[RISE-2007003] Firebird Relational Database Multiple Buffer Overflow Vulnerabilities RISE Security (Oct 04)

RMueller

Re: Marc Vilanova Vilasero est? ausente de RMueller (Oct 20)

Robert D. Holtz - Lists

Re: Best TCP IP stack? Robert D. Holtz - Lists (Oct 27)

Rodrigo Rubira Branco (BSDaemon)

Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Rodrigo Rubira Branco (BSDaemon) (Oct 10)
Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Rodrigo Rubira Branco (BSDaemon) (Oct 10)
Re: List of security conferences Rodrigo Rubira Branco (BSDaemon) (Oct 10)
Re: IRM Demonstrates Multiple Cisco IOS Exploitation Techniques Rodrigo Rubira Branco (BSDaemon) (Oct 10)

Roger A. Grimes

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Roger A. Grimes (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Roger A. Grimes (Oct 06)

Rosario Valotta

ANSA editorial system vulnerable Rosario Valotta (Oct 09)

rPath Update Announcements

rPSA-2007-0206-1 openssl openssl-scripts rPath Update Announcements (Oct 03)
rPSA-2007-0221-1 php php-mysql php-pgsql rPath Update Announcements (Oct 24)
rPSA-2007-0212-1 util-linux rPath Update Announcements (Oct 09)
rPSA-2007-0214-1 initscripts rPath Update Announcements (Oct 11)
rPSA-2007-0222-1 cpio tar rPath Update Announcements (Oct 23)
rPSA-2007-0203-1 rmake rmake-proxy rmake-repos rPath Update Announcements (Oct 02)
rPSA-2007-0209-1 elinks rPath Update Announcements (Oct 05)
rPSA-2007-0205-1 xorg-x11 xorg-x11-fonts xorg-x11-tools xorg-x11-xfs rPath Update Announcements (Oct 03)
rPSA-2007-0204-1 qt-x11-free rPath Update Announcements (Oct 03)
rPSA-2007-0225-2 firefox thunderbird rPath Update Announcements (Oct 30)
rPSA-2007-0220-1 ImageMagick rPath Update Announcements (Oct 19)
rPSA-2007-0219-1 libpng rPath Update Announcements (Oct 18)
rPSA-2007-0210-1 xen rPath Update Announcements (Oct 09)
rPSA-2007-0225-1 firefox rPath Update Announcements (Oct 26)

rpcxfsmd rpcxfsmd

Renaissance rpcxfsmd rpcxfsmd (Oct 14)
Why criticize security researchers? On the recent PDP case. rpcxfsmd rpcxfsmd (Oct 14)

rx8volution

Re: Using GPUs to crack hashes rx8volution (Oct 26)

S21sec Labs

S21SEC-038-en: Alcatel Omnivista 4760 Cross-Site Scripting S21sec Labs (Oct 18)
S21SEC-037-en: OPAL SIP Protocol Remote Denial of Service S21sec Labs (Oct 11)

scott

Re: the disappearance of the dog lover Petko D. Petkov scott (Oct 20)
Re: pdp architect, drraid, beastiality, and incest scott (Oct 15)
Re: lol @ you scott (Oct 27)
Re: pdp architect, drraid, beastiality, and incest scott (Oct 15)
Re: the disappearance of the dog lover Petko D. Petkov scott (Oct 20)
Re: Come on, let's do funding for Mac OS TrueCrypt porting ! scott (Oct 20)
Re: full-disclosure () hushmail com scott (Oct 14)
Re: pdp is leaving us scott (Oct 27)
Re: Flash that simulates virus scan scott (Oct 31)
Re: Google Sacure scott (Oct 25)
Re: Google Sacure scott (Oct 26)
Re: full-disclosure () hushmail com scott (Oct 13)
Re: MySpace URL redirection scott (Oct 27)
Re: full-disclosure () hushmail com scott (Oct 13)
Re: DHS need to get on top of this right now scott (Oct 23)
Re: Someone is impersonating Gadi Evron and spamming this list scott (Oct 20)
Re: Marc Vilanova Vilasero está ausente de la oficina. scott (Oct 19)

Secunia Research

Secunia Research: IPSwitch IMail Server IMail Client Buffer Overflow Secunia Research (Oct 30)
Secunia Research: CUPS IPP Tags Memory Corruption Vulnerability Secunia Research (Oct 31)
Secunia Research: IrfanView Palette File Importing Buffer Overflow Vulnerability Secunia Research (Oct 16)
Secunia Research: McAfee E-Business Server Auth Packet Handling Buffer Overflow Secunia Research (Oct 31)
Secunia Research: IBM Tivoli Storage Manager Client CAD Service Script Insertion Secunia Research (Oct 29)

security

[ MDKSA-2007:196 ] - Updated kernel packages fix multiple vulnerabilities and bugs security (Oct 15)
[ MDKSA-2007:195 ] - Updated kernel packages fix multiple vulnerabilities and bugs security (Oct 15)
[ MDKSA-2007:194 ] - Updated libvorbis packages fix vulnerabilities security (Oct 10)
[ MDKSA-2007:199 ] - Updated phpMyAdmin packages fix multiple vulnerabilities security (Oct 17)
[ MDKSA-2007:200 ] - Updated tk packages fix vulnerabilities security (Oct 18)
[ MDKSA-2007:198 ] - Updated util-linux packages fix vulnerability security (Oct 15)
[ MDKSA-2007:197 ] - Updated tar packages prevent buffer overflow security (Oct 15)
[ MDKSA-2007:191 ] - Updated libsndfile packages fix vulnerability security (Oct 01)
[ MDKSA-2007:201 ] - Updated hplip packages fix vulnerabilities security (Oct 22)
[ MDKSA-2007:202 ] - Updated Firefox packages fix multiple vulnerabilities security (Oct 23)
[ MDKSA-2007:193 ] - Updated openssl packages fix vulnerabilities security (Oct 04)
[ MDKSA-2007:192 ] - Updated mplayer packages fix vulnerability security (Oct 01)

SecurityResearch

SAXON version 5.4 SQL Injection Vulnerability SecurityResearch (Oct 29)
SAXON version 5.4 Multiple Path Disclosure Vulnerabilities SecurityResearch (Oct 29)
SAXON version 5.4 XSS Attack Vulnerability SecurityResearch (Oct 29)

Sergio Alvarez

Re: The Death of Defence in Depth ? - An invitation to Hack.lu Sergio Alvarez (Oct 10)

Seth Fogie

Airscanner Mobile Security Advisory #07101401: Mobile-spy Victim/User Phone/SMS/URL Log Spoofing and Persistent XSS Injection Seth Fogie (Oct 23)

Shadow

[PoC] DNS Recursion bandwidth amplification Shadow (Oct 23)

Shaun

Re: Spike in SSH scans Shaun (Oct 22)

silky

Re: extension for Firefox to force HTTPS always? silky (Oct 13)
Re: List of security conferences silky (Oct 10)
Re: !!! W4RN1NG N1GS und P1GZ !!! silky (Oct 14)
Re: Is this sane? silky (Oct 15)

SkyOut

ifnet.it WEBIF XSS Vulnerability SkyOut (Oct 22)
Netgear SSL312 XSS vulnerability SkyOut (Oct 13)

Slythers Bro

Re: Jack Bauer Gets Jailed! Slythers Bro (Oct 11)

. Solo

Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? . Solo (Oct 06)

Stack Smasher

Re: This list sucks Stack Smasher (Oct 15)

state

AST-2007-023: SQL Injection POC and details state (Oct 17)
AST-2007-023: SQL Injection POC and details state (Oct 17)
Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus state (Oct 19)

Stefan Esser

Advisory SE-2007-01: TikiWiki Remote PHP Code Evaluation Vulnerability Stefan Esser (Oct 29)
Advisory SE-2007-01: TikiWiki Remote PHP Code Evaluation Vulnerability Stefan Esser (Oct 29)

Steffan Baron

Re: [gentoo-announce] [ GLSA 200710-30 ] OpenSSL: Remote execution of arbitrary code Steffan Baron (Oct 31)

Stephan G.

Re: password hash, funny myth in the industry! Stephan G. (Oct 17)

Steve Bartman

Tom Serson Serious Business Steve Bartman (Oct 10)

Steve Kemp

[SECURITY] [DSA 1395-1] New xen-utils packages fix file truncation Steve Kemp (Oct 25)
[SECURITY] [DSA 1372-2] New ktorrent packages fix directory traversal Steve Kemp (Oct 23)
[SECURITY] [DSA 1362-2] New lighttpd packages fix buffer overflow Steve Kemp (Oct 07)
[SECURITY] [DSA 1393-1] New xfce4-terminal packages fix arbitrary command execution Steve Kemp (Oct 23)
[SECURITY] [DSA 1388-1] New dhcp packages fix arbitrary code execution Steve Kemp (Oct 18)
[SECURITY] [DSA 1379-1] New quagga packages fix denial of service Steve Kemp (Oct 03)
[SECURITY] [DSA 1380-1] New elinks packages fix information disclosure Steve Kemp (Oct 02)
[SECURITY] [DSA 1384-1] New xen-utils packages fix several vulnerabilities Steve Kemp (Oct 05)

Steven Adair

Re: Spike in SSH scans Steven Adair (Oct 22)
Re: If internet goes down out of hours, we're screwed Steven Adair (Oct 08)

subs07

Re: Distributed SSH username/password brute forceattack subs07 (Oct 22)

S/U/N

Creative spam S/U/N (Oct 19)
Re: UNSUBSCRIBE S/U/N (Oct 09)

sushil Agarwal

Re: UNSUBSCRIBE sushil Agarwal (Oct 08)

TAN Chew Keong

[vuln.sg] Adobe PageMaker Long Font-Name Buffer Overflow Vulnerability TAN Chew Keong (Oct 09)
[vuln.sg] IBM Lotus Notes Attachment Viewer Buffer Overflow Vulnerabilities TAN Chew Keong (Oct 23)

Taylor, Gord

FW: [Dailydave] Canada's Response to Black Hat - SecTor 2007 Taylor, Gord (Oct 16)

Team SHATTER

Team SHATTER Alert: Oracle Database Buffer overflow vulnerability in procedure DBMS_AQADM_SYS.DBLINK_INFO Team SHATTER (Oct 29)
Team SHATTER Alert: Oracle Database Buffer overflow vulnerability in function MDSYS.SDO_CS.TRANSFORM Team SHATTER (Oct 29)

TERRY HE

Re: RealPlayer vuln - versions affected? TERRY HE (Oct 26)

terry white

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype terry white (Oct 07)

The Asterisk Development Team

AST-2007-023: SQL Injection vulnerability in cdr_addon_mysql The Asterisk Development Team (Oct 16)
AST-2002-022: Buffer overflows in voicemail when using IMAP storage The Asterisk Development Team (Oct 10)

Thierry Zoller

Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 06)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 06)
The Death of Defence in Depth ? - An invitation to Hack.lu Thierry Zoller (Oct 09)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 09)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 07)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 06)
DidTheyReadit - Results Thierry Zoller (Oct 05)
Re: password hash, funny myth in the industry! Thierry Zoller (Oct 16)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 09)
Re: Testing DidTheyReadIt.com Thierry Zoller (Oct 01)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Thierry Zoller (Oct 11)
Re: The Death of Defence in Depth ? - An invitation to Hack.lu Thierry Zoller (Oct 10)

Thijs Kinkhorst

[SECURITY] [DSA 1389-2] New zoph packages fix SQL injection Thijs Kinkhorst (Oct 24)
[SECURITY] [DSA 1383-1] New gforge packages fix cross-site scripting Thijs Kinkhorst (Oct 05)
[SECURITY] [DSA 1394-1] New reprepro packages fix authentication bypass Thijs Kinkhorst (Oct 23)

Thor (Hammer of God)

Re: Remote Desktop Command Fixation Attacks Thor (Hammer of God) (Oct 12)
Re: Remote Desktop Command Fixation Attacks Thor (Hammer of God) (Oct 10)

Tim Brown

SSHatter 0.6 Tim Brown (Oct 06)
Serious holes affecting SiteBar 3.3.8 Tim Brown (Oct 18)

Timo Schoeler

Re: Jack Bauer Gets Jailed! Timo Schoeler (Oct 11)
Re: Recall: UNSUBSCRIBE Timo Schoeler (Oct 08)

Todd Manning

October Microsoft Tuesday Todd Manning (Oct 11)

tom skilling jr.

Richard Curtis State Rep R-La Center Spokane Washington tom skilling jr. (Oct 31)

Tremaine Lea

Re: Google Sacure Tremaine Lea (Oct 25)
Re: Google Sacure Tremaine Lea (Oct 25)

Troy

Re: Email Disclaimers...Legally Liable if breached? Troy (Oct 11)
Re: Email Disclaimers...Legally Liable if breached? Troy (Oct 11)
Re: Email Disclaimers...Legally Liable if breached? Troy (Oct 10)

TSRT

TPTI-07-17: CA BrightStor Hierarchical Storage Manager SQL Injection Vulnerabilities TSRT (Oct 02)
TPTI-07-18: EMC RepliStor Server Heap Overflow Vulnerability TSRT (Oct 10)
TPTI-07-16: CA BrightStor Hierarchical Storage Manager Buffer Overflow Vulnerabilities TSRT (Oct 02)

upb

Re: password hash, funny myth in the industry! upb (Oct 17)

Valdis . Kletnieks

Re: extension for Firefox to force HTTPS always? Valdis . Kletnieks (Oct 13)
Re: TCP Hijacking (aka Man-in-the-Middle) Valdis . Kletnieks (Oct 26)
Re: Fwd: Experience masturbation like never before. Valdis . Kletnieks (Oct 16)
Re: extension for Firefox to force HTTPS always? Valdis . Kletnieks (Oct 12)
Re: TCP Hijacking (aka Man-in-the-Middle) Valdis . Kletnieks (Oct 26)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Valdis . Kletnieks (Oct 05)
Re: UNSUBSCRIBE Valdis . Kletnieks (Oct 09)
Re: spammer wades into US Presidential race Valdis . Kletnieks (Oct 29)
Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus Valdis . Kletnieks (Oct 20)
Re: Flash that simulates virus scan Valdis . Kletnieks (Oct 31)
Re: If internet goes down out of hours, we're screwed Valdis . Kletnieks (Oct 08)
Re: Jack Bauer Gets Jailed! Valdis . Kletnieks (Oct 11)
Re: extension for Firefox to force HTTPS always? Valdis . Kletnieks (Oct 12)
Re: Email Disclaimers...Legally Liable ifbreached? Valdis . Kletnieks (Oct 11)
Re: password hash, funny myth in the industry! Valdis . Kletnieks (Oct 17)
Re: DHS need to get on top of this right now Valdis . Kletnieks (Oct 24)
Re: Remote Desktop Command Fixation Attacks Valdis . Kletnieks (Oct 11)
Re: [Full-disclosure] Marc Vilanova Vilasero está ausente de la oficina. Valdis . Kletnieks (Oct 19)
Re: Cross Site Hacking Browser Injection Attack Vulnerability Paradigms Valdis . Kletnieks (Oct 20)
Re: TCP Hijacking (aka Man-in-the-Middle) Valdis . Kletnieks (Oct 25)
Re: Firefox 2.0.0.7 has a very serious calculation bug Valdis . Kletnieks (Oct 01)
Re: password plugin for linux? Valdis . Kletnieks (Oct 18)
Re: Email Disclaimers...Legally Liable if breached? Valdis . Kletnieks (Oct 11)
Re: TCP Hijacking (aka Man-in-the-Middle) Valdis . Kletnieks (Oct 25)
Re: Core Impact 7.5 Web App pen-testing framework, as good as the hype? Valdis . Kletnieks (Oct 07)
Re: the disappearance of the dog lover Petko D. Petkov Valdis . Kletnieks (Oct 20)
Re: URI handling woes in Acrobat Reader, Netscape, Miranda, Skype Valdis . Kletnieks (Oct 07)
Re: password hash Valdis . Kletnieks (Oct 05)
Re: Fwd: I want to be with you Valdis . Kletnieks (Oct 22)

Valery Marchuk

Re: Distributed SSH username/password brute forceattack Valery Marchuk (Oct 22)
Re: gnucitizen bt home hub latest, attacks wide spread, outages reported Valery Marchuk (Oct 12)

Verhoeven Dimitri

Re: How to use the tools rainbowrack 1.2-src Verhoeven Dimitri (Oct 24)

Vic Vandal

CarolinaCon 2008 - Call For Papers/Speakers Vic Vandal (Oct 08)

Vincent Archer

Re: Distributed SSH username/password brute forceattack Vincent Archer (Oct 24)

Vlad Hackula

This list sucks Vlad Hackula (Oct 15)

wac

Re: Firefox 2.0.0.7 has a very serious calculation bug wac (Oct 01)
Re: Firefox 2.0.0.7 has a very serious calculation bug wac (Oct 01)

webby devil

Re: Google Sacure webby devil (Oct 27)

whupass

Re: Google Sacure whupass (Oct 25)
Re: Google Sacure whupass (Oct 25)
Re: Google Sacure whupass (Oct 26)
Google Sacure whupass (Oct 25)
Re: Google Sacure whupass (Oct 27)

Williams, James K

[CAID 35754]: CA Host-Based Intrusion Prevention System (CA HIPS) Server Vulnerability Williams, James K (Oct 19)
[CAID 35724, 35725, 35726]: CA BrightStor ARCserve Backup Multiple Vulnerabilities Williams, James K (Oct 11)

worried security

Re: MySpace URL redirection worried security (Oct 27)
Re: DHS need to get on top of this right now worried security (Oct 24)
How to Handle ISPs Who Turn a Blind Eye to Criminal Activity? worried security (Oct 13)
Re: The real motivations of vulnerability disclosure worried security (Oct 03)
Re: DHS need to get on top of this right now worried security (Oct 24)
yahoo news been offline for hours worried security (Oct 09)
Re: Life cycle of a hacker by n3td3v worried security (Oct 03)
Re: full-disclosure () hushmail com worried security (Oct 13)
Re: The real motivations of vulnerability disclosure worried security (Oct 03)
Re: full-disclosure () hushmail com worried security (Oct 13)
Re: Zone-H.org: 10 reasons websites get hacked worried security (Oct 18)
DHS need to get on top of this right now worried security (Oct 23)
Re: DailyGadi: Cyberwar alert, mass disruption coming worried security (Oct 20)
Did people power get rid of Gadi Evron from Full-Disclosure? worried security (Oct 17)
The facts behind big screen hacks worried security (Oct 06)
Re: Zone-H.org: 10 reasons websites get hacked worried security (Oct 17)
Re: DHS need to get on top of this right now worried security (Oct 23)
Re: gnucitizen bt home hub latest, attacks wide spread, outages reported worried security (Oct 12)
If internet goes down out of hours, we're screwed worried security (Oct 08)
Re: Google Sacure worried security (Oct 29)
Jack Bauer Gets Jailed! worried security (Oct 11)
Re: gnucitizen bt home hub latest, attacks wide spread, outages reported worried security (Oct 12)
Re: DailyGadi: Cyberwar alert, mass disruption coming worried security (Oct 20)
artificial intelligence worried security (Oct 20)
Is Your Kid Going to Jail Before College? worried security (Oct 08)
Re: full-disclosure () hushmail com worried security (Oct 13)
gnucitizen bt home hub latest, attacks wide spread, outages reported worried security (Oct 12)
Re: If internet goes down out of hours, we're screwed worried security (Oct 10)
pdp interview now online worried security (Oct 29)
Re: If internet goes down out of hours, we're screwed worried security (Oct 09)
Re: DailyGadi: Cyberwar alert, mass disruption coming worried security (Oct 20)
Re: DHS need to get on top of this right now worried security (Oct 23)
Re: DailyGadi: Cyberwar alert, mass disruption coming worried security (Oct 20)
Re: full-disclosure () hushmail com worried security (Oct 13)
Re: full-disclosure () hushmail com worried security (Oct 13)
Life cycle of a hacker by n3td3v worried security (Oct 03)
Re: full-disclosure () hushmail com worried security (Oct 13)
full-disclosure () hushmail com worried security (Oct 13)

xiaojunli.air

3proxy double free vulnerability xiaojunli.air (Oct 23)

Xo Plague

Re: Remote Desktop Command Fixation Attacks Xo Plague (Oct 11)

XSS Worm XSS Security Information Portal

[xssworm.com] Alert : XSS Worms - Cross-Site Scripting and Web 2.0 Application Security Blog XSS Worm XSS Security Information Portal (Oct 26)

yearsilent

Re: rPSA-2007-0212-1 util-linux yearsilent (Oct 12)

zdi-disclosures

ZDI-07-058: Oracle E-Business Suite SQL Injection Vulnerability zdi-disclosures (Oct 31)
ZDI-07-062: RealNetworks RealPlayer PLS File Memory Corruption Vulnerability zdi-disclosures (Oct 31)
ZDI-07-063: RealPlayer RA Field Size File Processing Heap Oveflow Vulnerability zdi-disclosures (Oct 31)
ZDI-07-059: Verity KeyView SDK Multiple File Format Parsing Vulnerabilities zdi-disclosures (Oct 31)
ZDI-07-055: Microsoft Windows DCERPC Authentication Denial of Service Vulnerability zdi-disclosures (Oct 10)
ZDI-07-061: RealNetworks RealPlayer SWF Processing Remote Code Execution Vulnerability zdi-disclosures (Oct 31)
ZDI-07-064: Novell Client Trust Heap Overflow Vulnerability zdi-disclosures (Oct 31)
ZDI-07-056: IBM DB2 DB2JDS Multiple Vulnerabilities zdi-disclosures (Oct 10)
ZDI-07-060: HP OpenView Radia Integration Server File System Exposure Vulnerability zdi-disclosures (Oct 31)
ZDI-07-057: Firebird process_packet() Remote Stack Overflow Vulnerability zdi-disclosures (Oct 10)