[Full-disclosure] Recon 2012 - Call For Papers - June 14-16, 2012 - Montreal, Quebec

2012-02-28 Thread cfp2012
`-,_ `. \ | | / .'_,-' ,,__ `-,_ `. \ | | / .' _,-' __,, ''--..__ `-,_.-"-._ ,-' __..--'' ... ''--..__.' `.__..--'' ___ /

Re: [Full-disclosure] pidgin OTR information leakage

2012-02-28 Thread Rich Pieri
On Feb 27, 2012, at 2:37 PM, Michele Orru wrote: > I think you didn't understood the content of the advisory. > If there are 10 non-root users in an Ubuntu machine for example, > if user 1 is using pidgin with OTR compiled with DBUS, then user 2 to 10 > can see what user 1 pidgin conversation. Th

Re: [Full-disclosure] Best DoS Tool

2012-02-28 Thread Ramo
What about LOIC? An unknown number of Anonymous can't be wrong! Sent from Android. Because Android is a boss. On Feb 27, 2012 9:17 PM, "Manuel Moreno" wrote: > Hi List!! > > I made some research about DoS Tools for my regulars PenTesting. What is > considered the best tool for DoS? I made some t

Re: [Full-disclosure] pidgin OTR information leakage

2012-02-28 Thread Dimitris Glynos
On 02/27/2012 11:23 PM, devn...@vonage.com wrote: > > I believe that clarification is in order. Indeed it is. The original post mentions a same-user attack vector which is very misleading as to what the real problem here is. And it boils down to this: Once a process sends private info over DBUS

[Full-disclosure] Symantec Career Site Down?

2012-02-28 Thread dr_250
Is Symantec so scared now? In case you don't know, Symantec had been running an unsupported version of Peoplesoft eRecruit comfortably for many years while telling other people to keep their patches up-to-date. Dr 250 ___ Full-Disclosure - We believe in

Re: [Full-disclosure] pidgin OTR information leakage

2012-02-28 Thread Dimitris Glynos
On 02/28/2012 12:14 AM, Dimitris Glynos wrote: > On 02/27/2012 11:23 PM, devn...@vonage.com wrote: >> >> I believe that clarification is in order. > > Indeed it is. The original post mentions a same-user attack > vector which is very misleading as to what the real problem here is. > > And it boil

Re: [Full-disclosure] Best DoS Tool

2012-02-28 Thread rancor
LOIC is old... HOIC is their new toy 2012/2/27 Ramo : > What about LOIC? An unknown number of Anonymous can't be wrong! > > Sent from Android. Because Android is a boss. > > On Feb 27, 2012 9:17 PM, "Manuel Moreno" wrote: >> >> Hi List!! >> >> I made some research about DoS Tools for my regulars

Re: [Full-disclosure] Best DoS Tool

2012-02-28 Thread rancor
I just thought we where name dropping stuff =( 2012/2/28 Julius Kivimäki : > I hope you guys are not seriously suggesting these. > > -- Edelleenlähetetty viesti -- > Lähettäjä: rancor > Päiväys: 28. helmikuuta 2012 13.28 > Aihe: Re: [Full-disclosure] Best DoS Tool > Vastaanott

Re: [Full-disclosure] Best DoS Tool

2012-02-28 Thread Julius Kivimäki
I hope you guys are not seriously suggesting these. -- Edelleenlähetetty viesti -- Lähettäjä: rancor Päiväys: 28. helmikuuta 2012 13.28 Aihe: Re: [Full-disclosure] Best DoS Tool Vastaanottaja: Ramo Kopio: full-disclosure@lists.grok.org.uk LOIC is old... HOIC is their new toy

Re: [Full-disclosure] Best DoS Tool

2012-02-28 Thread Julius Kivimäki
Oh, in that case he should totally use while true; do wget target; done 28. helmikuuta 2012 14.07 rancor kirjoitti: > I just thought we where name dropping stuff =( > > > > > > 2012/2/28 Julius Kivimäki : > > I hope you guys are not seriously suggesting these. > > > > -- Edelleenlähetett

[Full-disclosure] ImgPals Photo Host Version 1.0 Admin Account Disactivation

2012-02-28 Thread CorryL
-=[ADVISORY---]=- ImgPals Photo Host Version 1.0 STABLE Author: Corrado Liotta Aka CorryL [corry...@gmail.com] -=[---]=- -=[+] Application: ImgPals Photo Host -=[+] Version: 1.0 STABLE -=[+] Vendor's URL: http://www

Re: [Full-disclosure] Best DoS Tool

2012-02-28 Thread PsychoBilly
hping3 --flood [[ Manuel Moreno ]] @ [[ 27/02/2012 04:35 ]]-- > Hi List!! > > I made some research about DoS Tools for my regulars PenTesting. What is > considered the best tool for DoS? I made some test with scapy with god > results. >

[Full-disclosure] [ MDVSA-2012:023-1 ] libvpx

2012-02-28 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:023-1 http://www.mandriva.com/security/ _

[Full-disclosure] [ MDVSA-2012:024 ] ruby

2012-02-28 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:024 http://www.mandriva.com/security/ _

[Full-disclosure] [ MDVSA-2012:025 ] samba

2012-02-28 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:025 http://www.mandriva.com/security/ _

[Full-disclosure] [SECURITY] [DSA 2420-1] openjdk-6 security update

2012-02-28 Thread Florian Weimer
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2420-1 secur...@debian.org http://www.debian.org/security/Florian Weimer February 28, 2012