New User, Welcome!     Login

<< Previous Next >>

transmission

Re: Pwnie Awards 2008

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Oracle RDBMS TNS Data packet DoS

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

[ MDVSA-2008:174 ] kernel

 Simple Internet Transition (SIT) tunnel interface, related to the
 pskb_may_pull and kfree_skb functions, and management of an skb
 reference count. (CVE-2008-2136)
 
 Integer overflow in the sctp_getsockopt_local_addrs_old function in
 net/sctp/socket.c in the Stream Control Transmission Protocol (sctp)
 functionality in the Linux kernel before 2.6.25.9 allows local users
 to cause a denial of service (resource consumption and system outage)
 via vectors involving a large addr_num field in an sctp_getaddrs_old
 data structure. (CVE-2008-2826)
 

Oracle Application Server PLSQL injection flaw

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

RE: Lateral SQL Injection Revisited - No Special Privs Required

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Editran editcp V4.1 R7 - Remote buffer overflow

                
.: [ INTRO ] :.

EDItran Communications Platform: this is the market standard for the Spanish financial sector in the area of communications. 
It comprises an exchange architecture between heterogeneous environments for data networks (tcp, x.25, x.28, LU6.2, SwiftNet) 
and the Internet. It is the only product homologated by BDE (Central Bank of Spain) for the transmission of Official Reporting.

This software which is commercialized by Indra, is highly deployed in the financial, inssurance and gubernamental environments.


.: [ TECHNICAL DESCRIPTION ] :.

Re: White Wolf Labs #080922-1: Exploitation Through ActiveSync 4.x

SF> Summary:

SF>      With the introduction of ActiveSync 4.x, Microsoft significantly
SF> altered how the Windows Mobile device communicates with the host PC.
SF> Specifically, ActiveSync 4.x implements RNDIS to facilitate the
SF> transmission of data between the Windows Mobile device and the host PC.
SF> The result is that a connected Windows Mobile device will have full
SF> TCP/IP access to the host PC over USB - regardless of whether or not the
SF> system is logged in or if the device is fully synced.

SF> Details:

RE: A more detailed description of the Jura F90 vulnerability.

> Fax +61 2 9993 9497
> http://www.bdo.com.au/
> 
> The information in this email and any attachments is confidential. If
> you are not the named addressee you must not read, print, copy,
> distribute, or use in any way this transmission or any information it
> contains. If you have received this message in error, please notify
the
> sender by return email, destroy all copies and delete it from your
> system.
> 

Re: facebook 'routing flaw'?

Homepage URL: http://www.suramya.com
-------------------------------------------------

************************************************************
Disclaimer:
Any errors in spelling, tact, or fact are transmission errors.
************************************************************



[ MDVSA-2008:220-1 ] kernel

 directory, which allows local users to cause a denial of service
 (overflow of the UBIFS orphan area) via a series of attempted file
 creations within deleted directories. (CVE-2008-3275)
 
 Integer overflow in the sctp_setsockopt_auth_key function in
 net/sctp/socket.c in the Stream Control Transmission Protocol (sctp)
 implementation in the Linux kernel 2.6.24-rc1 through 2.6.26.3 allows
 remote attackers to cause a denial of service (panic) or possibly have
 unspecified other impact via a crafted sca_keylength field associated
 with the SCTP_AUTH_KEY option. (CVE-2008-3525)
 

New tool and paper for Oracle forensics...

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Oracle audit issue with XMLDB ftp service

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

SQL Injection Flaw in Oracle Workspace Manager

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Heap overflow in RealPlayer ID3 tag parser

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

CSW Security Advisory 0002: Oral B SmartMonitor Information Disclosure Vulnerability and DoS

The trashbin feature of the SmartMonitor device does not overwrite deleted data.

III. ANALYSIS

Exploitation allows an attacker to gain sensitive information from the toothbrush. No authentication is required to reach the affected application. The attacker only needs to be able to monitor the wireless transmission.

The attacker can determine the users brushing habits. It is possible to report on the location of the mouth that is being brushed and the amount of time spent on each of four defined “quantrants”. 

An attacker could also conduct a serious DoS attack. Flooding the wireless communications causes the unit to stop responding. This can result in the following actions:
A.      A continued DoS could cause the bristle monitor to not send an end of life signal to the SmartMonitor system leaving the user to continue using an old toothbrush head which could eventually lead to dental failure. The failure to monitor the most effective head life could result in bristle failure.

Bypassing DBMS_ASSERT in certain situations

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: Manchester Technology Centre,
Oxford Road, Manchester, M1 7EF with Company Number 04225835 and

Oracle TNS Listener DoS and/or remote memory inspection

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Trigger Abuse of MDSYS.SDO_TOPO_DROP_FTBL in Oracle 10g R1 and R2

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: Manchester Technology Centre,
Oxford Road, Manchester, M1 7EF with Company Number 04225835 and

[ MDVSA-2010:015 ] roundcubemail

 Affected: Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

 Multiple vulnerabilities has been found and corrected in transmission:
 
 A number of dependency probles were discovered and has been corrected
 with this release (#56006).
 
 Cross-site request forgery (CSRF) vulnerability in Roundcube Webmail

Hacking Coffee Makers.

Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497
http://www.bdo.com.au/

The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.

Any views expressed in this message are those of the individual sender and not necessarily endorsed by BDO Kendalls. You may not rely on this message as advice unless subsequently confirmed by fax or letter signed by a Partner or Director of BDO Kendalls. It is your responsibility to scan this communication and any files attached for computer viruses and other defects. BDO Kendalls does not accept liability for any loss or damage however caused which may result from this communication or any files attached. A full version of the BDO Kendalls disclaimer, and our Privacy statement, can be found on the BDO Kendalls website at http://www.bdo.com.au/ or by emailing mailto:administrator@bdo.com.au.

BDO Kendalls is a national association of separate partnerships and entities. Liability limited by a scheme approved under Professional Standards Legislation.


Auto Manager admin.cgi Multiple Field XSS

vendor: interactivetools.com, inc.,
http://www.interactivetools.com/products/automanager/
product: Auto Manager
version: 2.52
script: admin.cgi
fields: Vehicle, Year, Price, Drive Train, Transmission, Body, Engine,
Description, Color, Miles

***

BugsNotHugs

A New Class of Vulnerability in Oracle: Lateral SQL Injection

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

=?us-ascii?Q?C4_SCADA_Security_Advisory_-_AREVA_e-terrahabitat_/_e-terrap?= =?us-ascii?Q?latform_Multiple_Vulnerabilities?=

Background
-----------------
Vendor product information, from www.areva-td.com :
AREVA T&D solution for real-time energy management systems; this suite of
software products can be configured to meet your specific needs and
business function. Transmission companies, Generation owners, Independent
System Operators and vertically integrated utilities can all benefit from
the
new features and functionality of e-terraplatform. All configurations of
eterraplatform
share a robust, portable and flexible foundation: highly available

White Wolf Labs #080922-1: Exploitation Through ActiveSync 4.x

Summary:

     With the introduction of ActiveSync 4.x, Microsoft significantly
altered how the Windows Mobile device communicates with the host PC.
Specifically, ActiveSync 4.x implements RNDIS to facilitate the
transmission of data between the Windows Mobile device and the host PC.
The result is that a connected Windows Mobile device will have full
TCP/IP access to the host PC over USB - regardless of whether or not the
system is logged in or if the device is fully synced.

Details:

[ MDVSA-2008:167 ] kernel

 Linux kernel 2.6.18, and possibly other versions, when running on
 AMD64 architectures, allows local users to cause a denial of service
 (crash) via certain ptrace calls. (CVE-2008-1615)
 
 Integer overflow in the sctp_getsockopt_local_addrs_old function in
 net/sctp/socket.c in the Stream Control Transmission Protocol (sctp)
 functionality in the Linux kernel before 2.6.25.9 allows local users
 to cause a denial of service (resource consumption and system outage)
 via vectors involving a large addr_num field in an sctp_getaddrs_old
 data structure. (CVE-2008-2826)
 

SharePoint 2007 ASP.NET Source Code Disclosure

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: Manchester Technology Centre,
Oxford Road, Manchester, M1 7EF with Company Number 04225835 and

Critical Vulnerability in SNMPc

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Windows 2000/XP/2003 win32k.sys SfnINSTRING local kernel Denial of Service Vulnerability

Win32k.sys in DispatchMessage when the last call to xxxDefWindowProc, this function in dealing with some 
Message, will call gapfnScSendMessage this function table function to process,
which under the deal 2000/xp/2003 0x4c No. message, there will be SfnINSTRING function called this function when the lParam is not empty, 
direct that the lParam is a memory pointer, and pull data directly from the address
despite the use of the function of the SEH, but as long as the kernel address transmission errors will still cause the system BSOD 


Exploit code: 

# Include "stdafx.h" 

Untrusted Java applet can connect to localhost

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

Memory overwrites in JVM via malformed TrueType font

information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

<<Previous Next>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!