New User, Welcome!     Login

Next Page >>

Best Regards

RE: MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]

also I've found this vulnerability 1 year ago during a pt and work fine 
with url obfuscation. I've read that with owa 2007 this vulnerability is

patched but I don't have tried yet.

Best regards,
Piergiorgio


Giuseppe Gottardi ha scritto:
> Davide, let me comfort you...

Re: Fwd: 0-DAY XSS of cforms II is now fixed after a year and four months (was Re: cforms WordPress Plugin Cross Site Scripting Vulnerability - CVE-2010-3977)

If you have further questions, I'm glad to help.



Best Regards,



Rodrigo.


Re: MS Office 2007: Digital Signature does not protect Meta-Data

once a document is signed.

I also agree, that the severity of this is open to discussion, and
invite anybody interested in this discussion to contact me directly.

Best Regards,
Henrich C. Phls

> -----Ursprngliche Nachricht-----
> Von: Henrich C. Poehls [mailto:poehls@informatik.uni-hamburg.de] 
> Gesendet: Freitag, 14. Dezember 2007 12:08

Re: [Full-disclosure] MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]

> Hi all,
> also I've found this vulnerability 1 year ago during a pt and work fine
> with url obfuscation. I've read that with owa 2007 this vulnerability is
> patched but I don't have tried yet.
>
> Best regards,
> Piergiorgio
>
>
> Giuseppe Gottardi ha scritto:
>> Davide, let me comfort you...

Plesk 8.6.0 authentication flaw allows to gain virtual user priviledges

taken in a timely manner by Parallels.

I can provide root login to the test system on request, just need to 
negotiate a timeframe because it's running in a VM behind a NAT router.

Best Regards,
    Felix Buenemann
---snip---

Best Regards,
    Felix Buenemann

Re: MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]

Hi all,
also I've found this vulnerability 1 year ago during a pt and work fine 
with url obfuscation. I've read that with owa 2007 this vulnerability is 
patched but I don't have tried yet.

Best regards,
Piergiorgio


Giuseppe Gottardi ha scritto:
> Davide, let me comfort you...

Re: Re: MS OWA 2003 Redirection Vulnerability - [MSRC 7368br]

I found this vulnerability 1 year ago during a penetration test
activity and I never reported before for my negligence :-)

https://owa/CookieAuth.dll?GetLogon?url=%2Fexchweb%2Fbin%2Fredir.asp%3FURL%3Dhttp%3A%2F%2Fwww.google.it&reason=0

Best regards,
oveRet


On ven, 2008-10-17 at 21:07 +0200, Davide Del Vecchio wrote:
Hi,

Folder Lock <= 5.9.5 Local Password Information Disclosure

        }    
    }
}


Best Regards,
Charalambous Glafkos ( nowayout )
__________________________________________
ASTALAVISTA - the hacking & security community
www.astalavista.com
www.astalavista.net

VLC Player M3U file ftp:// URI Handler Remote Stack Buffer Overflow

#Hi to all Indian Hacker$, Andhra/ Telangana Hacker$ ;)
# Praveen Darshanam
#############END PYTHON###########################
Hi to all Indian Hacker$, Andhra/ Telangana Hacker$ ;)

Best Regards,
Praveen Darshanam,
Security Researcher



Re: [Aria-Security.com] vBulletin multiple XSS

If an admin makes a new custom template with custom html code, then that admin can put <script>alert('omg xss')</script> if he wants to. It's simply just functionality not bugs.

I hope you understand my concern and why it is important for me to say that this is not a bug.


Best Regards,
MaXe - InterN0T.net



Improper Authentication Mechanism in 3Com Wireless8760 Dual Radio 11a/b/g Poe Access Point

FYI

Waiting for your review

Best Regards

Yossi Yakubov



HP-UX, IBM AIX, SGI IRIX Remote Vulnerability - CVE-2010-1039

This vulnerability was discovered and exploited by Rodrigo Rubira Branco from Check Point Vulnerability Discovery Team (VDT).



Best Regards,
 
Rodrigo.
 
--
Rodrigo Rubira Branco

Re: Re: Re: Apache Server HTML Injection and UTF-7 XSS Vulnerability

It is not apache issue. You recrive 403 status, so charset is set in Header. Charset should not be in meta tags. Issue exist, when apache send response without charset in header AND meta tags. Probably you are using old browser without standard settings.



Best Regards,
Maksymilian Arciemowicz
securityreason.com



Re: MULTIPLE REMOTE SQL INJECTION VULNERABILITIES---MIM:InfiniX v1.2.003--->

you can find bug fixed version on:
http://sourceforge.net/projects/infinix/ 

Thanks.

Best Regards,
rbk



Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome

The best way to defend against any Cross Site Scripting attacks is to sanitize all inputs and outputs properly on your website and perhaps run NoScript as an extra safety precaution as well.

If it was possible to execute system() commands directly through the browser and not javascript nor html then that would be a vulnerability since One could almost do anything with a malicious site, if the input in this example to this function wouldn't be sanitized of course.


Best Regards,
MaXe

> To bypass protection from JavaScript code execution via refresh header it's
> needed to use data: URI, which will be containing requisite JS code.
> [...] After I informed Mozilla, they declined to fix this vulnerability.

Internet Explorer Uninitialized Memory Corruption Vulnerability - CVE-2010-3331

This vulnerability was discovered and researched by Rodrigo Rubira Branco from Check Point Vulnerability Discovery Team (VDT).




Best Regards,
 
Rodrigo.
 
--
Rodrigo Rubira Branco

Adobe Shockwave Player Memory Corruption Vulnerability - CVE-2010-2868

This vulnerability was discovered and researched by Rodrigo Rubira Branco from Check Point Vulnerability Discovery Team (VDT).



Best Regards,
 
Rodrigo.
 
--
Rodrigo Rubira Branco

H2CSO (Hackers to CSO) debate second edition - Free Live Streaming

opportunity to send questions to the moderated painel and to have access
to the video recording afterwards.



Best Regards,

Rodrigo.



Re: PHP filesystem attack vectors

like include "..\..\..\..\..\..\../../../../../etc/passwd"

We do not guarantee that it still works.

-- 
Best Regards,
------------------------
pub   1024D/A6986BD6 2008-08-22
uid                  Maksymilian Arciemowicz (cxib) <cxib@securityreason.com>
sub   4096g/0889FA9A 2008-08-22


Re: All China, All The Time

Hey thor,
I would love if you had something for IPtables to do this.

Best Regards,

Lawrence Pingree

On Jan 13, 2010, at 12:28 PM, "Thor (Hammer of God)" <thor@hammerofgod.com> wrote:

With all the hubbub around China yet again, I would like to remind you of the utilities available at Hammer of God that allow one to completely block any or all traffic to or from China or any other country in the world via ISA/TMG.  

Multiple XSS in DigiDomain

Discovered  By Linux_Drox

LeZr.Com

Best Regards ,,,



Microsoft Internet Information Services 5.0/6.0 FTP SERVER DENIAL OF SERVICE ("Stack Exhaustion")

If the ftp service is set to "manual" startup in services control
manager the service
needs to be restarted manually.
IIS 5.0 and 6.0 were tested and are affected.

Best Regards,

Nikolaos Rangos



Re: function sleep() in all versions of PHP

It is possible to make DoS (block all sockets/memory exe.). (more in Xploit magazin)
Reason: Use PHP via a CGI interpreter with RLimit* directives.
Anyone how use PHP as an in-process script interpreter, can be dangerous.

Best Regards,
Maksymilian Arciemowicz
securityreason.com
http://securityreason.com/key/Arciemowicz.Maksymilian.gpg



Adobe Shockwave Player Memory Corruption Vulnerability - CVE-2010-4089

This vulnerability was discovered by Michael Golub and researched by Rodrigo Rubira Branco from Check Point Vulnerability Discovery Team (VDT).



Best Regards,
 
Rodrigo.
 
--
Rodrigo Rubira Branco

Call for Papers: EC2ND 2010

which will be held in Berlin, Germany, October 28-29, 2010.

Please feel free to distribute this announcement. We apologize 
if you receive multiple copies of this message.

Best Regards,

The EC2ND 2010 Organization Committee


                        *  *  *  *  *  *

H2HC 2009 Videos Available!

up in Cancun on 3rd of December for a special H2HC edition in Mexico
with simultaneous translations for ALL the talks between English-Spanish.



Best Regards,



Rodrigo (BSDaemon).


Cisco IOS XSS/CSRF Vulnerability

http://192.168.1.2/exec/"><iframe
src="http://192.168.1.2/level/15/configure/-/hostname/BUGGY/CR">



Best Regards,

Zloss



Re: SecurityReason: PHP 5.2.6 SAPI php_getuid() overload

> 

php_getuid() is a abstract function for php.

-- 
Best Regards,
------------------------
pub   1024D/A6986BD6 2008-08-22
uid                  Maksymilian Arciemowicz (cxib)
<cxib@securityreason.com>
sub   4096g/0889FA9A 2008-08-22

Re: URL spoofing bug involving Firefox's error pages and document.write

I tested it earlier and your proof of concept works 100%.

Very nice find :-)


Best Regards,
MaXe



Adobe Shockwave Player Memory Corruption Vulnerability - CVE-2010-4087

This vulnerability was discovered by Michael Golub and researched by Rodrigo Rubira Branco from Check Point Vulnerability Discovery Team (VDT).



Best Regards,
 
Rodrigo.
 
--
Rodrigo Rubira Branco

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!