Full Disclosure: by author

580 messages starting Jan 22 11 and ending Jan 18 11
Date index | Thread index | Author index


AAA

Re: IGNOU website – SQL Injection & Weak Authentication Vulnerabilities AAA (Jan 22)
Re: vsworld.com - SQL Injection Vulnerability AAA (Jan 19)

Aaron

Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Aaron (Jan 13)
Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Aaron (Jan 14)

ACROS Security Lists

ASPR #2011-01-11-1: Remote Binary Planting in Multiple F-Secure Products ACROS Security Lists (Jan 11)

Adrien Kunysz

Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Adrien Kunysz (Jan 14)

Alejandro Canovas

Last two weeks | ENERGY 2011 || May 22-27, 2011 - Venice, Italy Alejandro Canovas (Jan 12)

Alejandro Canovas Solbes

Last Mile: ENERGY 2011 || May 22-27, 2011 - Venice, Italy Alejandro Canovas Solbes (Jan 23)
IMMM 2011 || July 17-22, 2011 - Bournemouth, UK Alejandro Canovas Solbes (Jan 20)

Aliaksandr Hartsuyeu

www.eVuln.com : "id" SQL Injection in WikLink Aliaksandr Hartsuyeu (Jan 06)
www.eVuln.com : "elimina" SQL Injection vulnerability in Alguest Aliaksandr Hartsuyeu (Jan 14)
www.eVuln.com : SQL Injection in WikLink Aliaksandr Hartsuyeu (Jan 03)

Andrea Purificato

[ACM, Ariadne Content Manager] unauth. SQL injection + user enumeration Andrea Purificato (Jan 03)

Andres Riancho

[TOOL] w3af 1.0-rc5 release: Better, Stronger, Faster. Andres Riancho (Jan 19)

Andrew Auernheimer

Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Andrew Auernheimer (Jan 01)
Re: [Full-disclosure] Camp Terror: Andrew Auernheimer’s Desert Klan Meetings Andrew Auernheimer (Jan 04)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Andrew Auernheimer (Jan 01)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Andrew Auernheimer (Jan 01)

Andrew DeFilippis

Re: [VIDEO] Keylogger, RecordMic and Shell Andrew DeFilippis (Jan 27)

Andrew Farmer

Re: sourceforge entry point seems still active. Andrew Farmer (Jan 25)

Andrew Kirch

http://security.goatse.fr/gaping-hole-exposed Andrew Kirch (Jan 26)
Re: Harvard.edu LFI Andrew Kirch (Jan 31)

andrew wiggin

Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement andrew wiggin (Jan 02)
Re: Getting root, the hard way andrew wiggin (Jan 06)
Re: Getting Off the Patch (is pointing out obvious) andrew wiggin (Jan 18)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement andrew wiggin (Jan 02)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement andrew wiggin (Jan 02)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement andrew wiggin (Jan 02)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement andrew wiggin (Jan 02)

ascii

Re: Oddities of PHP file access in Windows ®. Cheat-sheet [maybe 0day] ascii (Jan 21)

Asterisk Security Team

AST-2011-001: Stack buffer overflow in SIP channel driver Asterisk Security Team (Jan 18)

Benji

Re: Andrew "trelane" Kirch EXPOSED Benji (Jan 28)
Re: Input not sanitized in Emerson network power Benji (Jan 31)
Re: /etc/passwd corruption Benji (Jan 25)
Re: In Pro Domo Benji (Jan 31)

bk

Re: Path to IT Security bk (Jan 18)

Bob Smith

rpgrevolution.com SQL Injection Bob Smith (Jan 13)

BugTraq BugTraq

www.eVuln.com : "fold" and "site" SQL Injections in WikLink BugTraq BugTraq (Jan 10)

Cal Leeming [Simplicity Media Ltd]

Re: Mentioning of my consultancy on mailing lists Cal Leeming [Simplicity Media Ltd] (Jan 02)
Re: Getting Off the Patch (is pointing out obvious) Cal Leeming [Simplicity Media Ltd] (Jan 17)
Re: Vulnerability discloses PIN used in Microsoft Excel secure printing Cal Leeming [Simplicity Media Ltd] (Jan 31)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 19)
Re: Fwd: IBM DeveloperWorks Pwned and Defaced Cal Leeming [Simplicity Media Ltd] (Jan 09)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 19)
IBM DeveloperWorks Pwned and Defaced Cal Leeming [Simplicity Media Ltd] (Jan 08)
Re: Career Criminal Andrew Auernheimer / Weev Is In Jail Right Now Cal Leeming [Simplicity Media Ltd] (Jan 19)
Re: [VIDEO] Keylogger, RecordMic and Shell Cal Leeming [Simplicity Media Ltd] (Jan 26)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 19)
Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Cal Leeming [Simplicity Media Ltd] (Jan 10)
Re: IBM DeveloperWorks Pwned and Defaced Cal Leeming [Simplicity Media Ltd] (Jan 08)
Re: http://security.goatse.fr/gaping-hole-exposed Cal Leeming [Simplicity Media Ltd] (Jan 26)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 18)
Re: Path to IT Security Cal Leeming [Simplicity Media Ltd] (Jan 20)
Re: [VIDEO] Keylogger, RecordMic and Shell Cal Leeming [Simplicity Media Ltd] (Jan 26)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 19)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 17)
Re: Harvard.edu LFI Cal Leeming [Simplicity Media Ltd] (Jan 31)
Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Cal Leeming [Simplicity Media Ltd] (Jan 07)
Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Cal Leeming [Simplicity Media Ltd] (Jan 10)
Re: Getting Off the Patch Cal Leeming [Simplicity Media Ltd] (Jan 17)
Re: Harvard.edu LFI Cal Leeming [Simplicity Media Ltd] (Jan 31)
(off topic) windows + debian + WinSCP + chroot'd shell + timestamp + SCP + SFTP + keep remote directory up to date Cal Leeming [Simplicity Media Ltd] (Jan 19)
Re: "Hacker attacks won't hurt your company brand" Cal Leeming [Simplicity Media Ltd] (Jan 21)

cats

gatech.edu, multiple remote SQL injection vulnerabilities cats (Jan 14)

Champ Clark III [Softwink]

Charter.net Security Contact. Champ Clark III [Softwink] (Jan 14)

Charles Hooper

Re: Multiple Vulnerabilities in Mingle Forum (WordPress Plugin) Charles Hooper (Jan 08)
Multiple Vulnerabilities in Mingle Forum (WordPress Plugin) Charles Hooper (Jan 08)

Chase,Philip B

Vulnerability found in SplashID 5.5 Chase,Philip B (Jan 21)

Christian Sciberras

Re: Oddities of PHP file access in Windows (R). Cheat-sheet [maybe 0day] Christian Sciberras (Jan 12)
Re: Getting Off the Patch Christian Sciberras (Jan 17)
Re: www.google.com xss vulnerability Using mhtml Christian Sciberras (Jan 26)
Re: Getting Off the Patch Christian Sciberras (Jan 19)
Re: Andrew "trelane" Kirch EXPOSED Christian Sciberras (Jan 31)
Re: Getting Off the Patch Christian Sciberras (Jan 19)
Re: Path to IT Security Christian Sciberras (Jan 18)
Re: Multiple Vulnerabilities in Mingle Forum (WordPress Plugin) Christian Sciberras (Jan 08)
Re: Oddities of PHP file access in Windows (R). Cheat-sheet [maybe 0day] Christian Sciberras (Jan 13)
Re: Getting Off the Patch Christian Sciberras (Jan 18)
Re: Travel letter from Craig S. Wright Christian Sciberras (Jan 31)
Re: [Full-disclosure] Camp Terror: Andrew Auernheimer’s Desert Klan Meetings Christian Sciberras (Jan 04)
Re: Vulnerability discloses PIN used in Microsoft Excel secure printing Christian Sciberras (Jan 31)
Re: I find a bug Christian Sciberras (Jan 19)
Re: I find a bug Christian Sciberras (Jan 19)
Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Christian Sciberras (Jan 10)
Re: Getting Off the Patch (is pointing out obvious) Christian Sciberras (Jan 18)
Re: I find a bug Christian Sciberras (Jan 18)
Re: Getting Off the Patch Christian Sciberras (Jan 14)
Re: [USN-1042-2] PHP5 regression Christian Sciberras (Jan 13)

Cisco Systems Product Security Incident Response Team

Cisco Security Advisory: Cisco Content Services Gateway Vulnerabilities Cisco Systems Product Security Incident Response Team (Jan 26)

coderman

Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement coderman (Jan 18)
Re: Getting Off the Patch coderman (Jan 18)
Re: Path to IT Security coderman (Jan 20)
Re: Getting Off the Patch coderman (Jan 18)
Re: ESFS - The encrypted steganography filesystem coderman (Jan 13)
Re: Career Criminal Andrew Auernheimer / Weev Is In Jail Right Now coderman (Jan 18)

Context IS - Disclosure

Avaya Aura AES - Authorisation Bypass Context IS - Disclosure (Jan 06)

CORE Security Technologies Advisories

[CORE-2010-1001] Cisco WebEx .atp and .wrf Overflow Vulnerabilities CORE Security Technologies Advisories (Jan 31)

Cor Rosielle

Re: Getting Off the Patch Cor Rosielle (Jan 13)
Re: Getting Off the Patch Cor Rosielle (Jan 19)
Re: Getting Off the Patch Cor Rosielle (Jan 19)
Re: Getting Off the Patch Cor Rosielle (Jan 19)

cpolish

Re: Getting Off the Patch cpolish (Jan 19)
Re: GNU libc/regcomp(3) Multiple Vulnerabilities cpolish (Jan 08)

cyber flash

Google Caching For Fun And Profit cyber flash (Jan 31)

Dan Kaminsky

Re: Amusing xss against some lexmark printers Dan Kaminsky (Jan 05)

dann frazier

[SECURITY] [DSA 2153-1] linux-2.6 security update dann frazier (Jan 31)

Dan Rosenberg

Getting root, the hard way Dan Rosenberg (Jan 05)

Dan Tulovsky

Re: Remedy for Getting Off is Patch Dan Tulovsky (Jan 16)

Darren McDonald

Athena SSL Cipher Check v0.6.2 Darren McDonald (Jan 05)

Dave Aitel

Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Dave Aitel (Jan 17)

dave b

Amusing xss against some lexmark printers dave b (Jan 05)
SmoothWall Express 3.0 csrf / xss dave b (Jan 16)

Dave Nett

OpenBSD CBC backdoor Dave Nett (Jan 01)
Re: Is Security Disclosure Dave Nett (Jan 01)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Dave Nett (Jan 01)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Dave Nett (Jan 01)

David Rook

Agnitio Security Code Review Tool v1.1 released David Rook (Jan 03)

Digit Security Research

Silicon Graphics Inc (SGI) - IRIX - Local Kernel Memory Disclosure/Denial of Service Digit Security Research (Jan 10)

dink

Seeking info on CVE-2011-0348 dink (Jan 26)

Dragos

Re: Final Penultimate last Call for Papers for CanSecWest 2011 (deadline Jan. 17th, conf March 9-11) Dragos (Jan 13)

Dragos Ruiu

Final Penultimate last Call for Papers for CanSecWest 2011 (deadline Jan. 17th, conf March 9-11) Dragos Ruiu (Jan 13)

Ed Murphy

Vulnerability discloses PIN used in Microsoft Excel secure printing Ed Murphy (Jan 31)

E. Kellinis

Taking advantage of File Descriptor exhaustion bugs E. Kellinis (Jan 20)

Emanuel dos Reis Rodrigues

Re: I find a bug Emanuel dos Reis Rodrigues (Jan 19)
Re: I find a bug Emanuel dos Reis Rodrigues (Jan 18)

Emilien Girault

Hack In Paris 2011 Call For Papers Emilien Girault (Jan 21)

Emmanuel Apreko

Path to IT Security Emmanuel Apreko (Jan 18)

exploit dev

Re: sourceforge entry point seems still active. exploit dev (Jan 25)
Re: sourceforge entry point seems still active. exploit dev (Jan 30)
Re: sourceforge entry point seems still active. exploit dev (Jan 25)
Egypt Telecom AS isolation - BGPlay show it ? exploit dev (Jan 28)
sourceforge entry point seems still active. exploit dev (Jan 22)
Re: sourceforge entry point seems still active. exploit dev (Jan 28)
Re: sourceforge entry point seems still active. exploit dev (Jan 25)

Eyeballing Weev

Re: Career Criminal Andrew Auernheimer / Weev Is In Jail Right Now Eyeballing Weev (Jan 18)
Re: [VIDEO] Keylogger, RecordMic and Shell Eyeballing Weev (Jan 25)

Fabio Pietrosanti (naif)

ZORG, new C++ and Java ZRTP implementation public release Fabio Pietrosanti (naif) (Jan 12)

Ferdinand Klinzer

Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Ferdinand Klinzer (Jan 08)

Fernando Gont

IETF RFC on Port Randomization Fernando Gont (Jan 21)
IETF RFC on "the implementation of the TCP urgent mechanism" Fernando Gont (Jan 25)
[CFP] LACSEC 2011: 6th Network Security Event for Latin America and the Caribbean Fernando Gont (Jan 25)

Florian Weimer

[SECURITY] [DSA 2122-2] New glibc packages fix privilege escalation Florian Weimer (Jan 11)

Gary Baribault

Re: Path to IT Security Gary Baribault (Jan 19)
Re: Path to IT Security Gary Baribault (Jan 18)

George Capehart

Re: Fwd: Re "getting off the patch" George Capehart (Jan 17)

George Hedfors

world's worst hacker? George Hedfors (Jan 31)

Georgi Guninski

Re: I find a bug Georgi Guninski (Jan 19)
Re: I find a bug Georgi Guninski (Jan 19)
Re: Path to IT Security Georgi Guninski (Jan 20)
Re: I find a bug Georgi Guninski (Jan 19)
Re: I find a bug Georgi Guninski (Jan 19)
Re: I find a bug Georgi Guninski (Jan 19)

ghost

Re: [Full-Disclosure] http://security.goatse.fr/gaping-hole-exposed (is a troll) ghost (Jan 28)

Giuseppe Iuculano

[SECURITY] [DSA-2143-1] New mysql-dfsg-5.0 packages fix several vulnerabilities Giuseppe Iuculano (Jan 14)

Glenn Everhart

Fwd: Re "getting off the patch" Glenn Everhart (Jan 14)

gold flake

Re: Oddities of PHP file access in Windows (R). Cheat-sheet [maybe 0day] gold flake (Jan 13)

Gregg Reynolds

Re: Final Penultimate last Call for Papers for CanSecWest 2011 (deadline Jan. 17th, conf March 9-11) Gregg Reynolds (Jan 14)

Guofei Gu

Call for Papers: RAID'11 Guofei Gu (Jan 14)

Hack Talk

Harvard.edu LFI Hack Talk (Jan 31)
Re: Harvard.edu LFI Hack Talk (Jan 31)

Hafez Kamal

[HITB-Announce] Reminder: HITB2011AMS - Call for Papers closes on the 18th of Feb Hafez Kamal (Jan 30)

halfdog

/etc/passwd corruption halfdog (Jan 25)
Re: GNU libc/regcomp(3) Multiple Vulnerabilities halfdog (Jan 11)
Proc filesystem and SUID-Binaries halfdog (Jan 22)

Harry Behrens

Re: I find a bug Harry Behrens (Jan 18)

HI-TECH .

In Pro Domo HI-TECH . (Jan 26)
FreeBSD local denial of service - forced reboot HI-TECH . (Jan 28)
Sun Microsystems SunScreen Firewall Root Exploit HI-TECH . (Jan 22)

Howdy Ho

Re: Path to IT Security Howdy Ho (Jan 23)

huj huj huj

Re: http://security.goatse.fr/gaping-hole-exposed huj huj huj (Jan 28)
Re: News for Mankind huj huj huj (Jan 24)
Re: Getting Off the Patch (is pointing out obvious) huj huj huj (Jan 18)
Re: Getting Off the Patch (is pointing out obvious) huj huj huj (Jan 18)
Re: Getting Off the Patch (is pointing out obvious) huj huj huj (Jan 19)
Re: Go away anonymous huj huj huj (Jan 28)
Re: Career Criminal Andrew Auernheimer / Weev Is In Jail Right Now huj huj huj (Jan 19)

IEhrepus

Re: www.google.com xss vulnerability Using mhtml IEhrepus (Jan 26)
Hacking with mhtml protocol handler IEhrepus (Jan 15)
Re: www.google.com xss vulnerability Using mhtml IEhrepus (Jan 27)
Re: Hacking with mhtml protocol handler IEhrepus (Jan 15)
Re: www.google.com xss vulnerability Using mhtml IEhrepus (Jan 28)
Re: Hacking with mhtml protocol handler IEhrepus (Jan 21)
www.google.com xss vulnerability Using mhtml IEhrepus (Jan 26)

imipak

"Hacker attacks won't hurt your company brand" imipak (Jan 21)

j00ru

Windows Kernel-mode GS Cookies subverted (paper) j00ru (Jan 12)

Jack Ryan

Re: In Pro Domo Jack Ryan (Jan 31)

Jacky Jack

Re: [VIDEO] Keylogger, RecordMic and Shell Jacky Jack (Jan 26)
Re: Google persistent xss and another security bug Jacky Jack (Jan 06)

Jacqui Caren-home

Re: Fwd: Re "getting off the patch" Jacqui Caren-home (Jan 16)

Jamie Riden

Re: I find a bug Jamie Riden (Jan 18)

Jamie Strandboge

[USN-1044-1] D-Bus vulnerability Jamie Strandboge (Jan 18)
[USN-1039-1] AppArmor update Jamie Strandboge (Jan 06)
[USN-1040-1] Django vulnerabilities Jamie Strandboge (Jan 06)
[USN-1046-1] Sudo vulnerability Jamie Strandboge (Jan 20)
[USN-1036-1] CUPS update Jamie Strandboge (Jan 06)
[USN-1037-1] ifupdown update Jamie Strandboge (Jan 06)

Jan Lehnardt

CVE-2010-3854: Apache CouchDB Cross Site Scripting Issue Jan Lehnardt (Jan 31)

Jeffrey Walton

Re: sourceforge entry point seems still active. Jeffrey Walton (Jan 25)
Re: Getting Off the Patch Jeffrey Walton (Jan 19)

John Cartwright

List Charter John Cartwright (Jan 11)

John Horn

Re: Andrew Auernheimer aka weev accused ofpeddling kiddie porn, sexual blackmail against woman John Horn (Jan 10)

John Jacobs

Re: /etc/passwd corruption John Jacobs (Jan 25)

John R. Dennison

Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman John R. Dennison (Jan 07)

Jonathan Medina

Re: world's worst hacker? Jonathan Medina (Jan 31)

Joshua Gimer

PRTG V8.1.2.1809 XSS Bugs in login.htm and error.htm Joshua Gimer (Jan 26)

Juan Sacco

Re: [VIDEO] Keylogger, RecordMic and Shell Juan Sacco (Jan 26)
Re: [VIDEO] Keylogger, RecordMic and Shell Juan Sacco (Jan 27)
Re: [VIDEO] Keylogger, RecordMic and Shell Juan Sacco (Jan 26)

Jubei Trippataka

Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Jubei Trippataka (Jan 09)

Juha-Matti Laurio

Re: Fwd: IBM DeveloperWorks Pwned and Defaced Juha-Matti Laurio (Jan 09)
Re: www.google.com xss vulnerability Using mhtml Juha-Matti Laurio (Jan 30)

Justin Klein Keane

Re: Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability Justin Klein Keane (Jan 14)
Re: Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability Justin Klein Keane (Jan 13)
Drupal Panels 5.x-1.2 XSS Vulnerability Justin Klein Keane (Jan 31)
Drupal Custom Pagers Module XSS Justin Klein Keane (Jan 31)

Kees Cook

[USN-1038-1] dpkg vulnerability Kees Cook (Jan 06)
[USN-1041-1] Linux kernel vulnerabilities Kees Cook (Jan 10)
[USN-1009-2] GNU C Library vulnerability Kees Cook (Jan 11)

Kevin Killgore

Chatango Group Chat Web-Application Cross-Site Request Forgery Vulnerability Kevin Killgore (Jan 03)

Kevin Lynn

Re: [Full-Disclosure] http://security.goatse.fr/gaping-hole-exposed (is a troll) Kevin Lynn (Jan 27)

Konrad Rieck

Call for Papers: DIMVA 2011 - Extended Deadline Jan 21 Konrad Rieck (Jan 12)

Laurelai Storm

Re: I find a bug Laurelai Storm (Jan 18)
Re: I find a bug Laurelai Storm (Jan 19)
Re: I find a bug Laurelai Storm (Jan 19)
Re: I find a bug Laurelai Storm (Jan 18)
Re: I find a bug Laurelai Storm (Jan 19)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Laurelai Storm (Jan 01)
Re: I find a bug Laurelai Storm (Jan 19)

laurent gaffie

Re: Multiple vulnerabilities in SimpGB laurent gaffie (Jan 26)
Re: www.google.com xss vulnerability Using mhtml laurent gaffie (Jan 27)

Laurent OUDOT at TEHTRI-Security

[TEHTRI-Security] CVE-2010-2599: Update your BlackBerry Laurent OUDOT at TEHTRI-Security (Jan 21)

Leon Kaiser

Re: [Full-Disclosure] http://security.goatse.fr/gaping-hole-exposed (is a troll) Leon Kaiser (Jan 28)
Re: http://security.goatse.fr/gaping-hole-exposed Leon Kaiser (Jan 27)
Re: [Full-Disclosure] http://security.goatse.fr/gaping-hole-exposed (is a troll) Leon Kaiser (Jan 28)
Andrew "trelane" Kirch EXPOSED Leon Kaiser (Jan 28)

Luca Carettoni

NetSupport Manager Agent Remote Buffer Overflow (Linux, Solaris, Mac, ...) Luca Carettoni (Jan 08)
IBM WebSphere Arbitrary File Retrieval via "Logging and Tracing" Luca Carettoni (Jan 07)

Maciej Gojny

Re: IBM DeveloperWorks Pwned and Defaced Maciej Gojny (Jan 09)

Madhur Ahuja

Input not sanitized in Emerson network power Madhur Ahuja (Jan 31)

mad . men

Travel letter from Craig S. Wright mad . men (Jan 31)

Major Malfunction

London DEFCON - DC4420 - Tuesday 25th January 2011 - SOCIAL Major Malfunction (Jan 21)

Maksymilian Arciemowicz

Re: GNU libc/regcomp(3) Multiple Vulnerabilities Maksymilian Arciemowicz (Jan 11)
GNU libc/regcomp(3) Multiple Vulnerabilities Maksymilian Arciemowicz (Jan 07)

Marc Deslauriers

[USN-1045-2] util-linux update Marc Deslauriers (Jan 19)
[USN-1051-1] HPLIP vulnerability Marc Deslauriers (Jan 25)
[USN-1045-1] FUSE vulnerability Marc Deslauriers (Jan 19)
[USN-1047-1] AWStats vulnerability Marc Deslauriers (Jan 25)
[USN-1035-1] Evince vulnerabilities Marc Deslauriers (Jan 05)
[USN-1048-1] Tomcat vulnerability Marc Deslauriers (Jan 25)

Mario Vilas

Re: [CORE-2010-1001] Cisco WebEx .atp and .wrf Overflow Vulnerabilities Mario Vilas (Jan 31)
Re: [VIDEO] Keylogger, RecordMic and Shell Mario Vilas (Jan 27)

Mark Stanislav

'Seo Panel' Cookie-Rendered Persistent XSS Vulnerability (CVE-2010-4331) Mark Stanislav (Jan 15)

Marsh Ray

The OpenBSD IPsec-Stuxnet connection. Marsh Ray (Jan 16)
Re: Path to IT Security Marsh Ray (Jan 20)

Martin Schulze

[SECURITY] [DSA 2151-1] New OpenOffice.org packages fix several vulnerabilities Martin Schulze (Jan 26)

mason vrobel

Re: Full-Disclosure Digest, Vol 70, Issue 72 mason vrobel (Jan 01)

Meadow

Re: Path to IT Security Meadow (Jan 21)

Michael Holstein

Re: Vulnerability discloses PIN used in Microsoft Excel secure printing Michael Holstein (Jan 31)
Re: Vulnerability discloses PIN used in Microsoft Excel secure printing Michael Holstein (Jan 31)

Michael Krymson

Re: Getting Off the Patch Michael Krymson (Jan 19)

Michal Zalewski

Re: www.google.com xss vulnerability Using mhtml Michal Zalewski (Jan 26)
Announcing cross_fuzz, a potential 0-day in circulation, and more Michal Zalewski (Jan 01)
Re: www.google.com xss vulnerability Using mhtml Michal Zalewski (Jan 26)
Re: www.google.com xss vulnerability Using mhtml Michal Zalewski (Jan 28)

Mike Hale

Re: Andrew Auernheimer (aka weev) wants his victim's to masturbate for him Mike Hale (Jan 07)
Re: IBM DeveloperWorks Pwned and Defaced Mike Hale (Jan 08)

Moritz Muehlenhoff

[SECURITY] [DSA 2152-1] hplip security update Moritz Muehlenhoff (Jan 27)
[SECURITY] [DSA 2146-1] Security update for mydms Moritz Muehlenhoff (Jan 16)
[SECURITY] [DSA 2148-1] Security update for tor Moritz Muehlenhoff (Jan 17)
[SECURITY] [DSA 2144-1] Security update for wireshark Moritz Muehlenhoff (Jan 14)
[SECURITY] [DSA 2155-1] freetype security update Moritz Muehlenhoff (Jan 30)
[SECURITY] [DSA 2145-1] Security update for libsmi Moritz Muehlenhoff (Jan 15)

MustLive

RCE and CSRF vulnerabilities in CMS WebManager-Pro MustLive (Jan 30)
Vulnerabilities in xAjax and xajax_jquery_plugin MustLive (Jan 20)
Vulnerabilities in MC Content Manager MustLive (Jan 15)
Cross-Site Scripting vulnerability in Joostina MustLive (Jan 08)
Full path disclosure and SQL Injection vulnerabilities in MC Content Manager MustLive (Jan 23)
Re: Cross-Site Scripting vulnerability in Joostina MustLive (Jan 14)
Fw: Vulnerability in widget Flash Tag Cloud for Blogsa and other ASP.NET engines MustLive (Jan 18)
Multiple vulnerabilities in SimpGB MustLive (Jan 26)
Vulnerabilities in Adobe ColdFusion MustLive (Jan 28)
XSS and IAA vulnerabilities in PHP-Nuke MustLive (Jan 12)

Nagareshwar Talekar

Updated Dll Hijack Auditor v2.5 - Little Smart Tool to Audit against 'Dll Hijack Vulnerability' Nagareshwar Talekar (Jan 26)
Exposing the Google Password Storage Mechanism & Encryption Secrets Nagareshwar Talekar (Jan 18)

Nathan Power

PayPal Send Money Cross-Site Scripting Vulnerability Nathan Power (Jan 03)

Nelson Brito

[TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Nelson Brito (Jan 12)
Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Nelson Brito (Jan 14)
Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC Nelson Brito (Jan 16)

news

Re: Getting root, the hard way news (Jan 06)

Nico Golde

[SECURITY] [DSA 2149-1] Security update for dbus Nico Golde (Jan 21)

nix

NiX Brute Forcer 1.1.0 update has been released nix (Jan 23)
[SECURITY] NiX Anti-proxy/fraud API nix (Jan 13)

NSO Research

NSOADV-2010-010: DATEV Multiple Applications DLL Hijacking Vulnerability NSO Research (Jan 20)

nullcon

nullcon Goa Dwitiya security Conference 25-26th Feb 2011 nullcon (Jan 28)

Onapsis Research Labs

[Onapsis Security Advisory 2011-001] SAP Management Console Unauthenticated Service Restart Onapsis Research Labs (Jan 12)
[Onapsis Security Advisory 2011-002] SAP Management Console Information Disclosure Onapsis Research Labs (Jan 12)

Paul Cheng

Re: Is Security Disclosure Paul Cheng (Jan 01)

Paul Schmehl

Re: Getting Off the Patch Paul Schmehl (Jan 14)
Re: Path to IT Security Paul Schmehl (Jan 19)

paul . szabo

Mathematica8 on Linux /tmp/MathLink vulnerability paul . szabo (Jan 03)
Re: Amusing xss against some lexmark printers paul . szabo (Jan 05)
Re: [VIDEO] IE CVE-2010-3962 paul . szabo (Jan 18)

Pawel Gawinek

Polycom SoundPoint IP DoS Pawel Gawinek (Jan 26)

Pedro Joaquín

Huawei HG default WEP generator Pedro Joaquín (Jan 25)

Pete Herzog

Re: Getting Off the Patch Pete Herzog (Jan 14)
Re: Getting Off the Patch Pete Herzog (Jan 14)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Getting Off the Patch Pete Herzog (Jan 11)
Re: Getting Off the Patch Pete Herzog (Jan 14)
Re: Getting Off the Patch Pete Herzog (Jan 13)
Re: Getting Off the Patch Pete Herzog (Jan 14)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 14)
Re: Getting Off the Patch Pete Herzog (Jan 17)
Re: Getting Off the Patch Pete Herzog (Jan 13)

peter

Re: Harvard.edu LFI peter (Jan 31)

Peter Maxwell

Re: ESFS - The encrypted steganography filesystem Peter Maxwell (Jan 13)

Pete Smith

Re: Getting Off the Patch Pete Smith (Jan 19)
Re: Getting Off the Patch Pete Smith (Jan 19)

Phil

Re: Getting Off the Patch Phil (Jan 19)

phocean

Re: Getting Off the Patch phocean (Jan 14)
Re: Getting Off the Patch phocean (Jan 14)
Re: Getting Off the Patch phocean (Jan 18)
Re: Getting Off the Patch phocean (Jan 14)
Re: Getting Off the Patch phocean (Jan 17)
Re: Getting Off the Patch phocean (Jan 14)
Re: Mentioning of my consultancy on mailing lists phocean (Jan 02)
Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman phocean (Jan 08)
Re: Getting Off the Patch phocean (Jan 14)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement phocean (Jan 02)

Pradip Sharma

IGNOU website – SQL Injection & Weak Authentication Vulnerabilities Pradip Sharma (Jan 22)
Re: News for Mankind Pradip Sharma (Jan 23)
vsworld.com - SQL Injection Vulnerability Pradip Sharma (Jan 19)

Procmail

Re: Getting Off the Patch Procmail (Jan 18)

R0me0 ***

Re: [VIDEO] Keylogger, RecordMic and Shell R0me0 *** (Jan 25)

Rakesh Nagekar

Re: vsworld.com - SQL Injection Vulnerability Rakesh Nagekar (Jan 20)

RandallM

Go away anonymous RandallM (Jan 28)

Raphael Geissert

[SECURITY] [DSA-2142-1] New dpkg packages fix directory traversal Raphael Geissert (Jan 06)

Robert Święcki

Re: Path to IT Security Robert Święcki (Jan 20)

Rob Fuller

Re: [VIDEO] Keylogger, RecordMic and Shell Rob Fuller (Jan 25)

Roger

Re: [VIDEO] Keylogger, RecordMic and Shell Roger (Jan 25)

Roger Casteele

Re: Getting Off the Patch Roger Casteele (Jan 16)
Re: Is Security Disclosure Roger Casteele (Jan 01)

runlvl

[VIDEO] Keylogger, RecordMic and Shell runlvl (Jan 25)
Re: [VIDEO] Keylogger, RecordMic and Shell runlvl (Jan 25)
New tool for penetration testing!!! runlvl (Jan 16)
[VIDEO] IE CVE-2010-3962 runlvl (Jan 18)
Insect Pro 2.0 - New features! ( Screenshot, Keylogger and webcam capture ) runlvl (Jan 20)
Re: [VIDEO] Keylogger, RecordMic and Shell runlvl (Jan 26)
Re: Insect Pro 2.0 - New features! ( Screenshot, Keylogger and webcam capture ) runlvl (Jan 21)
Re: [VIDEO] Keylogger, RecordMic and Shell runlvl (Jan 25)
Re: [VIDEO] Keylogger, RecordMic and Shell runlvl (Jan 25)
Re: Free Download of Insect Pro 2.0 (Was: Re: [VIDEO] Keylogger, RecordMic and Shell) runlvl (Jan 27)
Insect Pro 2.0 Release runlvl (Jan 19)
Re: [VIDEO] Keylogger, RecordMic and Shell runlvl (Jan 25)
[VIDEO] IE CVE-2010-3962 runlvl (Jan 16)
Insect Pro 2.0 Release runlvl (Jan 15)
Fwd: Insect Pro 2.0 - New features! ( Screenshot, Keylogger and webcam capture ) runlvl (Jan 20)

Ryan Sears

Re: http://security.goatse.fr/gaping-hole-exposed Ryan Sears (Jan 26)
Re: [VIDEO] Keylogger, RecordMic and Shell Ryan Sears (Jan 25)

Sal Rinder

Re: Hacking with mhtml protocol handler Sal Rinder (Jan 16)
Re: sourceforge entry point seems still active. Sal Rinder (Jan 31)

Sean Lam

RoomWizard Default Password and Sync Connector Credential Leak [CVE-2010-0214] Sean Lam (Jan 06)

SecuBox fRoGGz

Malformed Package Appfix files - Local Persistent Denial Of Service SecuBox fRoGGz (Jan 28)

security

[ MDVSA-2011:006 ] subversion security (Jan 14)
[ MDVSA-2011:013 ] hplip security (Jan 19)
[ MDVSA-2011:002 ] wireshark security (Jan 09)
[ MDVSA-2011:017 ] tetex security (Jan 21)
[ MDVSA-2011:000 ] phpmyadmin security (Jan 05)
[ MDVSA-2011:014 ] ccid security (Jan 20)
[ MDVSA-2011:011 ] opensc security (Jan 15)
[ MDVSA-2011:003 ] MHonArc security (Jan 10)
[ MDVSA-2011:008 ] perl-CGI security (Jan 14)
[ MDVSA-2011:004 ] php-phar security (Jan 10)
[ MDVSA-2011:007 ] wireshark security (Jan 14)
[ MDVSA-2011:001 ] dhcp security (Jan 07)
[ MDVSA-2011:005 ] evince security (Jan 13)
[ MDVSA-2011:006 ] subversion security (Jan 14)
[ MDVSA-2011:009 ] gif2png security (Jan 14)
[ MDVSA-2011:016 ] t1lib security (Jan 21)
[ MDVSA-2011:015 ] pcsc-lite security (Jan 20)
[ MDVSA-2011:018 ] sudo security (Jan 21)
[ MDVSA-2011:012 ] mysql security (Jan 17)
[ MDVSA-2011:010 ] xfig security (Jan 15)
[ MDVSA-2011:019 ] libuser security (Jan 26)

sec yun

Google persistent xss and another security bug sec yun (Jan 06)

Shatter

TeamSHATTER Security Advisory: Oracle Database Vault Administrator web console vulnerable to Cross-site request forgery Shatter (Jan 21)
Team SHATTER Security Advisory: OracleRemExecService command execution via named pipe vulnerability Shatter (Jan 21)
TeamSHATTER Security Advisory: Oracle Database Vault Administrator web console Session ID disclosure Shatter (Jan 21)

shawn Davison

Re: Getting root, the hard way shawn Davison (Jan 06)

Shawn Merdinger

Re: Travel letter from Craig S. Wright Shawn Merdinger (Jan 31)

Shinnok

Re: IBM DeveloperWorks Pwned and Defaced Shinnok (Jan 08)
Fwd: IBM DeveloperWorks Pwned and Defaced Shinnok (Jan 09)
IBM DeveloperWorks Pwned and Defaced Shinnok (Jan 08)

Shyaam

Re: Agnitio Security Code Review Tool v1.1 released Shyaam (Jan 03)

Srinivas Naik

News for Mankind Srinivas Naik (Jan 23)

srl

Re: Getting root, the hard way srl (Jan 06)

Stefan Behte

[ GLSA 201101-07 ] Prewikka: password disclosure Stefan Behte (Jan 16)
[ GLSA 201101-06 ] IO::Socket::SSL: Certificate validation error Stefan Behte (Jan 16)
[ GLSA 201101-05 ] OpenAFS: Arbitrary code execution Stefan Behte (Jan 16)

Stefan Fritsch

[SECURITY] [DSA-2154-2] exim4 regression fix Stefan Fritsch (Jan 31)
[SECURITY] [DSA-2154-1] exim4 security update Stefan Fritsch (Jan 31)
[SECURITY] [DSA-2141-1] New openssl packages fix protocol design flaw Stefan Fritsch (Jan 06)
[SECURITY] [DSA-2141-2] New nss packages fix protocol design flaw Stefan Fritsch (Jan 06)
[SECURITY] [DSA-2141-4] New lighttpd packages fix regression Stefan Fritsch (Jan 13)
[SECURITY] [DSA-2140-1] New libapache2-mod-fcgid packages fixes stack overflow Stefan Fritsch (Jan 06)
[SECURITY] [DSA-2141-1] New apache2 packages add backward compatibility option Stefan Fritsch (Jan 06)

StenoPlasma @ www.ExploitDevelopment.com

Lomtec ActiveWeb Professional 3.0 CMS Allows Arbitrary File Upload and Execution as SYSTEM in ColdFusion (2010-WEB-002) (CERT VU#528212) StenoPlasma @ www.ExploitDevelopment.com (Jan 26)

Steve Beattie

[USN-1043-1] Little CMS vulnerability Steve Beattie (Jan 12)
[USN-1042-2] PHP5 regression Steve Beattie (Jan 13)
[USN-1052-1] OpenJDK vulnerability Steve Beattie (Jan 26)
[USN-1042-1] PHP vulnerabilities Steve Beattie (Jan 11)

Steve Kemp

[SECURITY] [DSA-2156-1] pcscd security update Steve Kemp (Jan 31)
[SECURITY] [DSA 2147-1] Security update for pimd Steve Kemp (Jan 16)

Steve Pinkham

Re: [VIDEO] Keylogger, RecordMic and Shell Steve Pinkham (Jan 26)
Re: [VIDEO] Keylogger, RecordMic and Shell Steve Pinkham (Jan 26)
Re: [VIDEO] Keylogger, RecordMic and Shell Steve Pinkham (Jan 25)
Re: [VIDEO] Keylogger, RecordMic and Shell Steve Pinkham (Jan 26)
Re: [VIDEO] Keylogger, RecordMic and Shell Steve Pinkham (Jan 26)
Re: [VIDEO] Keylogger, RecordMic and Shell Steve Pinkham (Jan 25)
Free Download of Insect Pro 2.0 (Was: Re: [VIDEO] Keylogger, RecordMic and Shell) Steve Pinkham (Jan 27)

stormrider

Re: ESFS - The encrypted steganography filesystem stormrider (Jan 13)
Re: ESFS - The encrypted steganography filesystem stormrider (Jan 13)

Team LOX

Fwd: Evading AV Signature--Derailing the Anti virus Team LOX (Jan 04)

TELUS Security Labs - Vulnerability Research

TELUS Security Labs VR - Symantec Antivirus Intel Alert Handler Service Denial of Service TELUS Security Labs - Vulnerability Research (Jan 31)
TELUS Security Labs VR - Symantec Alert Management System HNDLRSVC Arbitrary Command Execution TELUS Security Labs - Vulnerability Research (Jan 31)
TELUS Security Labs VR - Novell ZENworks Handheld Management ZfHIPCND.exe Buffer Overflow TELUS Security Labs - Vulnerability Research (Jan 31)

Thijs Kinkhorst

[SECURITY] [DSA 2150-1] request-tracker3.6 security update Thijs Kinkhorst (Jan 23)

Thor (Hammer of God)

Re: Getting Off the Patch Thor (Hammer of God) (Jan 14)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 14)
Re: Insect Pro 2.0 - New features! ( Screenshot, Keylogger and webcam capture ) Thor (Hammer of God) (Jan 20)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 14)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 17)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 17)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 17)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 17)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 18)
Re: Andrew "trelane" Kirch EXPOSED Thor (Hammer of God) (Jan 31)
Re: Vulnerability discloses PIN used in Microsoft Excel secure printing Thor (Hammer of God) (Jan 31)
Re: "Hacker attacks won't hurt your company brand" Thor (Hammer of God) (Jan 22)
Re: Vulnerability discloses PIN used in Microsoft Excel secure printing Thor (Hammer of God) (Jan 31)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 19)
Re: Travel letter from Craig S. Wright Thor (Hammer of God) (Jan 31)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 14)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 17)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 19)
Re: Path to IT Security Thor (Hammer of God) (Jan 19)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 14)
Re: Travel letter from Craig S. Wright Thor (Hammer of God) (Jan 31)
Re: Getting Off the Patch Thor (Hammer of God) (Jan 18)

Tim

Re: Getting Off the Patch Tim (Jan 14)
Re: Getting Off the Patch Tim (Jan 11)

Tim Brown

[OVSA20110118] OpenVAS Manager Vulnerable To Command Injection Tim Brown (Jan 25)

Tim Sammut

[ GLSA 201101-03 ] libvpx: User-assisted execution of arbitrary code Tim Sammut (Jan 14)
[ GLSA 201101-09 ] Adobe Flash Player: Multiple vulnerabilities Tim Sammut (Jan 21)
[ GLSA 201101-01 ] gif2png: User-assisted execution of arbitrary code Tim Sammut (Jan 05)
[ GLSA 201101-08 ] Adobe Reader: Multiple vulnerabilities Tim Sammut (Jan 21)
[ GLSA 201101-02 ] Tor: Remote heap-based buffer overflow Tim Sammut (Jan 14)

Tobias Heinlein

[ GLSA 201101-04 ] aria2: Directory traversal Tobias Heinlein (Jan 15)

Tomás Touceda

Re: ESFS - The encrypted steganography filesystem Tomás Touceda (Jan 13)
Re: ESFS - The encrypted steganography filesystem Tomás Touceda (Jan 13)
ESFS - The encrypted steganography filesystem Tomás Touceda (Jan 13)
Re: ESFS - The encrypted steganography filesystem Tomás Touceda (Jan 13)

Tracy Reed

Re: Getting Off the Patch Tracy Reed (Jan 19)

Troy Aerojam

Re: Andrew "trelane" Kirch EXPOSED Troy Aerojam (Jan 31)

Valdis . Kletnieks

Re: Getting Off the Patch Valdis . Kletnieks (Jan 19)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 18)
Re: Final Penultimate last Call for Papers for CanSecWest 2011 (deadline Jan. 17th, conf March 9-11) Valdis . Kletnieks (Jan 13)
Re: www.google.com xss vulnerability Using mhtml Valdis . Kletnieks (Jan 27)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 14)
Re: Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Valdis . Kletnieks (Jan 08)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 20)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 18)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 19)
Re: Path to IT Security Valdis . Kletnieks (Jan 20)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 14)
Re: Camp Terror: Andrew Auernheimer’s Desert Klan Meetings Valdis . Kletnieks (Jan 04)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 14)
Re: Google Caching For Fun And Profit Valdis . Kletnieks (Jan 31)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 11)
Re: Getting Off the Patch Valdis . Kletnieks (Jan 14)
Re: "Hacker attacks won't hurt your company brand" Valdis . Kletnieks (Jan 21)

Victor Rigo

Camp Terror: Andrew Auernheimer’s Desert Klan Meetings Victor Rigo (Jan 04)
Re: Career Criminal Andrew Auernheimer has Violent Ideations of Law Enforcement Victor Rigo (Jan 01)
Re: Andrew Auernheimer (aka weev) wants his victim's to masturbate for him Victor Rigo (Jan 07)
Andrew Auernheimer aka weev accused of peddling kiddie porn, sexual blackmail against woman Victor Rigo (Jan 07)
Andrew Auernheimer (aka weev) wants his victim's to masturbate for him Victor Rigo (Jan 07)

Vic Vandal

CarolinaCon-VII/2011 - Call for Papers/Presenters Vic Vandal (Jan 05)
Re: Getting Off the Patch Vic Vandal (Jan 12)

VMware Security Team

VMSA-2011-0001 VMware ESX third party updates for Service Console packages glibc, sudo, and openldap VMware Security Team (Jan 04)

VSR Advisories

OpenOffice.org Multiple Memory Corruption Vulnerabilities VSR Advisories (Jan 26)

wac

Re: sourceforge entry point seems still active. wac (Jan 30)

Walikar Riyaz Ahemed Dawalmalik

Multiple CSRF Vulnerabilities in Openfire 3.6.4 Administrative Section Walikar Riyaz Ahemed Dawalmalik (Jan 06)
Multiple XSS Vulnerabilities in Openfire 3.6.4 Administrative Section Walikar Riyaz Ahemed Dawalmalik (Jan 06)

Williams, James K

CA20101231-01: Security Notice for CA ARCserve D2D (updated) Williams, James K (Jan 27)

yersinia

Re: [Dailydave] [TOOL RELEASE] T50 Sukhoi PAK FA Mixed Packet Injector v2.45r-H2HC yersinia (Jan 19)

YGN Ethical Hacker Group

Re: Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability YGN Ethical Hacker Group (Jan 13)
phpMyAdmin 3.4.x, 3.4.0 beta 2 <= Stored Cross Site Scripting (XSS) Vulnerability YGN Ethical Hacker Group (Jan 26)
Re: Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability YGN Ethical Hacker Group (Jan 13)
Multiple Web Applications | Full Path Disclosure YGN Ethical Hacker Group (Jan 27)
Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability YGN Ethical Hacker Group (Jan 05)
Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability YGN Ethical Hacker Group (Jan 13)
Geeklog 1.7.1 <= Cross Site Scripting Vulnerability YGN Ethical Hacker Group (Jan 03)
Re: Joomla! 1.0.x ~ 1.0.15 | Cross Site Scripting (XSS) Vulnerability YGN Ethical Hacker Group (Jan 07)
Vanilla Forums 2.0.16 <= Cross Site Scripting Vulnerability YGN Ethical Hacker Group (Jan 27)
Re: Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability YGN Ethical Hacker Group (Jan 13)
Drupal 5.x, 6.x <= Stored Cross Site Scripting Vulnerability YGN Ethical Hacker Group (Jan 13)

Yigit Turgut

Re: www.google.com xss vulnerability Using mhtml Yigit Turgut (Jan 26)

yuange

Exploit technical challenges yuange (Jan 01)
Re: ms04-006 exploit challenges yuange (Jan 02)

Zach C

Re: Getting Off the Patch Zach C (Jan 11)
Re: [Full-Disclosure] http://security.goatse.fr/gaping-hole-exposed (is a troll) Zach C (Jan 28)
Re: Getting Off the Patch Zach C (Jan 13)
Re: Getting Off the Patch Zach C (Jan 14)

ZDI Disclosures

ZDI-11-025: Novell GroupWise Internet Agent REQUEST-STATUS Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 25)
ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability ZDI Disclosures (Jan 31)
ZDI-11-032: Symantec Intel Alert Originator Service iao.exe Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-11-030: Symantec AMS Intel Alert Handler Modem String Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-11-027: Novell GroupWise Internet Agent TZID Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 26)
ZDI-11-029: Symantec AMS Intel Alert Handler Service CreateProcess Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-11-019: Oracle GoldenGate Veridata Server XML SOAP Request Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-020: Oracle Beehive voice-servlet Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-003: HP OpenView Network Node Manager jovgraph.exe displayWidth Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-010: Hewlett-Packard OpenView Network Node Manager nnmRptConfig.exe nameParams/text1 Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-015: HP Mercury Loadrunner Agent Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-018: Oracle Database and Enterprise Manager Grid Control Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-026: Novell Zenworks Handheld Management ZfHIPCnd.exe Opcode 2 Remote Code Execution Vulnerability ZDI Disclosures (Jan 26)
ZDI-11-014: Red Hat OpenJDK IcedTea6 ClassLoader Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-013: Symantec Web Gateway Management Interface USERNAME Blind SQL Injection Remote Code Execution Vulnerability ZDI Disclosures (Jan 12)
ZDI-11-008: Hewlett-Packard OpenView Network Node Manager nnmRptConfig.exe nameParams Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-007: Hewlett-Packard OpenView Network Node Manager nnmRptConfig.exe data_select1 Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-021: Icon Labs Iconfidant SSL Server Key Length Remote Code Execution Vulnerability ZDI Disclosures (Jan 20)
ZDI-11-016: Oracle Real User Experience Insight rsynclogdird SQL Injection Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-011: Hewlett-Packard OpenView Network Node Manager nnmRptConfig.exe schd_select1 Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-004: HP OpenView Network Node Manager ovutil.dll stringToSeconds Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-023: Citrix Provisioning Services streamprocess.exe Remote Code Execution Vulnerability ZDI Disclosures (Jan 20)
ZDI-11-006: Hewlett-Packard Network Node Manager OVutil.dll Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-009: Hewlett-Packard OpenView Network Node Manager nnmRptConfig.exe schdParams/nameParams Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-012: Hewlett-Packard OpenView Network Node Manager nnmRptConfig.exe Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-005: HP OpenView Network Node Manager ovas.exe Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-024: Hewlett-Packard Data Protector Cell Manager Remote Code Execution Vulnerabilities ZDI Disclosures (Jan 20)
ZDI-11-037: Symantec IM Manager Administrative Interface IMAdminSchedTask.asp Eval Code Injection Remote Code Execution Vulnerability ZDI Disclosures (Jan 31)
ZDI-11-036: IBM DB2 db2dasrrm receiveDASMessage Remote Code Execution Vulnerability ZDI Disclosures (Jan 31)
ZDI-11-035: IBM DB2 db2dasrrm validateUser Remote Code Execution Vulnerability ZDI Disclosures (Jan 31)
ZDI-11-031: Symantec AMS Intel Alert Handler Pin Number Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-11-017: Oracle Audit Vault av.action Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-033: Realplayer vidplin.dll AVI Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-10-301: Trend Micro Control Manager Server-agent Communication Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-034: HP OpenView Performance Insight Server Backdoor Account Code Execution Vulnerability ZDI Disclosures (Jan 31)
ZDI-11-033: Realplayer vidplin.dll AVI Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-11-027: Novell GroupWise Internet Agent TZID Parsing Remote Code Execution Vulnerability ZDI Disclosures (Jan 26)
ZDI-11-024: Hewlett-Packard Data Protector Cell Manager Remote Code Execution Vulnerabilities ZDI Disclosures (Jan 20)
ZDI-11-028: Symantec AMS Intel Alert Service AMSSendAlertAct Remote Code Execution Vulnerability ZDI Disclosures (Jan 27)
ZDI-11-001: Microsoft Data Access Components DSN Overflow Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-002: Microsoft Internet Explorer MSADO CacheSize Remote Code Execution Vulnerability ZDI Disclosures (Jan 11)
ZDI-11-014: Red Hat OpenJDK IcedTea6 ClassLoader Remote Code Execution Vulnerability ZDI Disclosures (Jan 18)
ZDI-11-024: Hewlett-Packard Data Protector Cell Manager Remote Code Execution Vulnerabilities ZDI Disclosures (Jan 20)

Владимир Воронцов

Re: Oddities of PHP file access in Windows (R). Cheat-sheet [maybe 0day] Владимир Воронцов (Jan 12)
Re: Oddities of PHP file access in Windows ®. Cheat-sheet [maybe 0day] Владимир Воронцов (Jan 21)
Oddities of PHP file access in Windows ®. Cheat-sheet [maybe 0day] Владимир Воронцов (Jan 12)

Григорий Братислава

MSNLVADV-2010-001 Security Advisory Григорий Братислава (Jan 21)
Re: Getting root, the hard way Григорий Братислава (Jan 05)
Re: Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 18)
Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 17)
Remedy for Getting Off is Patch Григорий Братислава (Jan 14)
Re: Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 17)
Re: Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 18)
Re: Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 18)
Re: Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 18)
Re: Getting Off the Patch Григорий Братислава (Jan 17)
Re: Getting Off the Patch (is pointing out obvious) Григорий Братислава (Jan 18)
Free Dancho Movement Григорий Братислава (Jan 17)
Re: The OpenBSD IPsec-Stuxnet connection. Григорий Братислава (Jan 17)
Re: Getting root, the hard way Григорий Братислава (Jan 05)

我是王子

I find a bug 我是王子 (Jan 18)