[Openvas-discuss] Drupal core - Highly critical - Remote Code Execution(Drupalgeddon2) Vulnerability

2018-03-29 Thread Antu Sanadi
Hello All, Drupal has released patches for highly critical vulnerability(SA-CORE-2018-002) for all supported and non-supported versions of Drupal CMS and CVE identifier has assigned the CVE-2018-7600. The vulnerability allows an attacker to execute arbitrary code in the main component of the sy

[Openvas-discuss] "Are you dead?" Really?

2018-03-29 Thread Andrew Robinson
Running an openvas scan with printer scanning enabled CAN result in several pages containing the string “are you dead?” being printed. In this case, in a hospital, in the ob/gyn suite. Not good. I’ve searched through the NVTs and can’t find where this string is sourced. Does anyone know? _

Re: [Openvas-discuss] "Are you dead?" Really?

2018-03-29 Thread Christian Fischer
Hi, On 29.03.2018 19:48, Andrew Robinson wrote: > I’ve searched through the NVTs and can’t find where this string is sourced. > Does anyone know? looks like this string is sent if a NVT is calling the "end_denial()" function defined here: https://github.com/greenbone/gvm-libs/blob/v8.0.10/nasl/

Re: [Openvas-discuss] Private or Corporate CAs

2018-03-29 Thread Alex Smirnoff
Could you elaborate, exactly how weak hash could matter for self-signed certificate? Without vague references like "if you don't want to trust the NSA and NIST". I do not see any of those organisations stating that weak hash is dangerous for a situation where signature itself is irrelevant. On Fri

Re: [Openvas-discuss] Private or Corporate CAs

2018-03-29 Thread Reindl Harald
Am 29.03.2018 um 20:29 schrieb Alex Smirnoff: Could you elaborate, exactly how weak hash could matter for self-signed certificate? Without vague references like "if you don't want to trust the NSA and NIST". I do not see any of those organisations stating that weak hash is dangerous for a situa

Re: [Openvas-discuss] "Are you dead?" Really?

2018-03-29 Thread Reindl Harald
the new enigmail autocrypt is a piece of shit in the thunerbird preview aithout anigmail you see only the large header with no scrollbars and only when you reply or open the message in a new window you can see the content Am 29.03.2018 um 20:29 schrieb Christian Fischer: Hi, On 29.03.2018 1