New User, Welcome!     Login

Next Page >>

Best Wishes

LedgerSMB < 1.2.8, SQL-Ledger 2.x Multiple SQL Injection Issues

issues in that application.  Our official recommendation for
SQL-Ledger users is to restrict access to database relations to the
least privelege necessary.  While this does not entirely solve the
issues, it does limit the damage considerably.

Best Wishes,
Chris Travers



CVE-2009-3583, confirming problem and adding info

If anyone is still using LedgerSMB 1.1.x, this is an excellent reason
to upgrade.....

I can confirm this problem for the versions mentioned.

Best Wishes,
Chris Travers



Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera

vendors about many vulnerabilities, which I'll disclose in the future. So
they are informed for long time in advance :-). And so you have no need to
worry, because with every day they become more and more "informed long time
ago" and have more and more days to fix these holes.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

SQL-Ledger patch update for SQL injection

I haven't been been able to find a CVE listing for this yet.  Secunia
has assigned this the id of SA45649 for LedgerSMB.  I expect to send a
full disclosure email discussing the vulnerability in a week.

Best Wishes,
Chris Travers



Re: DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome

Also I wrote to Ruben Reguero two days ago, and told him that it was strange
that in Firefox 3.5 he had no problems (with this exploit). And maybe he has
last Firefox 3.5.1. After that he answered me and confirmed it.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

> -----Original Message-----

Re: e107 latest download link is backdoored

> http://e107.org/e107_files/downloads/e107_v0.7.17_full.zip

Looks like the e107 team has removed this file, and reviewing the code
in the cvs repository this code does not appear there.

Best Wishes,
Chris Travers



Re: DoS vulnerability in Google Chrome

P.S.

Different people have different signatures ;-). It's like: show me your
signature and I'll tell you who you are.

Best wishes & regards,
Eugene Dokukin aka MustLive
Security auditor and security researcher
http://websecurity.com.ua

----- Original Message ----- 

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome and Opera

> they are informed for long time in advance :-). And so you have no need to
> worry, because with every day they become more and more "informed long 
> time
> ago" and have more and more days to fix these holes.
>
> Best wishes & regards,
> MustLive
> Administrator of Websecurity web site
> http://websecurity.com.ua
>
> ----- Original Message ----- 

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

> doubts received all my letters in 2007-2010 and would receive all future
> letters. But as said, I'll not be more informing them about DoS holes. 
> This
> decision I made in August 2009 and it's final decision.
>
> Best wishes & regards,
> MustLive
> Administrator of Websecurity web site
> http://websecurity.com.ua
>
> ----- Original Message ----- 

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

3. Admins of web sites.
4. Developers of the browsers.

Which must give you a ground for thoughts.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Belong Site Builder 0.1b Bypass Admincp

# For Contact : RxH@HotMail.iT

# Note : Alwayse Don,t See In The Top To Feeling Pain In Your Neck !!!

Best Wishes

_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/

BLOG:CMS 4.2.1.c (DIR_PLUGINS) Multiple Remote File Include

# For Contact : RxH@HotMail.iT

# Note : Alwayse Don,t See In The Top To Feeling Pain In Your Neck !!!

Best Wishes

_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/


Re: [Webappsec] Paper: Weaning the Web off of Session Cookies

I do think we need some sort of HTTP status or other header
information that would tell a browser to clear the auth cache and not
try again.

Best Wishes,
Chris Travers



Re: Vulnerabilities in Dunia Soccer

> every admin and web developer a chance to fix (I use advanced responsible
> disclosure in 99%). And in most cases they just do lame things, like
> ignoring and not fixing, or badly fixing, or hiddenly fixing without
> thanking me, like it was with securityfocus.com in 2006 and many others.
>
> Best wishes & regards,
> MustLive
> Administrator of Websecurity web site
> http://websecurity.com.ua
>
> ----- Original Message ----- From: "Susan Bradley" <sbradcpa@pacbell.net>

LedgerSMB 1.3.0 released, includes anti-XSRF framework

If anyone is listing
http://secunia.com/advisories/cve_reference/CVE-2009-3580/ as open,
now would be a good time to close it.  Any further XSRF
vulnerabilities should probably have their own advisories.

Best Wishes,
Chris Travers
LedgerSMB Core Team
Metatron Technology Consulting



Full disclosure for SA45649, SQL Injection in LedgerSMB and SQL-Ledger

ensuring that sql injection issues do not pose the privilege
escalation issues that are present in prior versions.  Thus the impact
of an attack like this is greatly limited.  The impact on the
pre-releases should be seen as moderate.

Best Wishes,
Chris Travers



Re: Vulnerability in CB Captcha for Joomla and Mambo

in last advisories (that have this hole). But concerning CB Captcha if it
works in Joomla 1.0 and Mambo, it doesn't work in Joomla 1.5, because it
uses another method to work with sessions and for it another code must be
used (for clearing of session).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

aliboard Beta Upload Shell From ControlPanel

# For Contact : RxH@HotMail.iT

# Note : Yesterday I Help You !! Tomorrow Fuck Me !!! Fuck All Snitches !!! But Do You Know What !!! That,s Is My Mistake

Best Wishes

_________________________________________________________________
Express yourself instantly with MSN Messenger! Download today it's FREE!
http://messenger.msn.click-url.com/go/onm00200471ave/direct/01/


Re: DoS vulnerability in Google Chrome

P.S.

Different people have different signatures ;-). It's like: show me your
signature and I'll tell you who you are.

Best wishes & regards,
Eugene Dokukin aka MustLive
Security auditor and security researcher
http://websecurity.com.ua

----- Original Message ----- 

Re: Vulnerabilities in Dunia Soccer

every admin and web developer a chance to fix (I use advanced responsible
disclosure in 99%). And in most cases they just do lame things, like
ignoring and not fixing, or badly fixing, or hiddenly fixing without
thanking me, like it was with securityfocus.com in 2006 and many others.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Re: Vulnerability in 3D user cloud for Joomla

3D user cloud for Joomla (mod_democbusr3dcloud, mod_cbusr3dcloud and
mod_usr3dcloud). It's commercial module with three versions - one free (demo
version) and two paid ones. And the hole in 3D user cloud module (in all its
versions) is still not fixed.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

> 3. Admins of web sites.
> 4. Developers of the browsers.
>
> Which must give you a ground for thoughts.
>
> Best wishes & regards,
> MustLive
> Administrator of Websecurity web site
> http://websecurity.com.ua
>
> ----- Original Message ----- From: "Susan Bradley" <sbradcpa@pacbell.net>

Re: DoS vulnerabilities in Firefox, Internet Explorer, Opera and Chrome

powerful enough, then this attack on IE8 and even on IE6 and IE7 can be not
so effective (because it's resource consumption in case of IE as I wrote),
as it can be at not powerful computers. And many people in the world have
not so powerful computers.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

More information on CVE-2009-3580

significant burdens on employees so the proper value should be
determined by each customer.  The current default value (3600) which
sets the default value to one hour is way to high though.  This issue
will be documented as an issue in future versions of LedgerSMB.

Best Wishes,
Chris Travers



Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

Thanks, I don't need help with informing browser vendors. They with no
doubts received all my letters in 2007-2010 and would receive all future
letters. But as said, I'll not be more informing them about DoS holes. This
decision I made in August 2009 and it's final decision.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Re: DoS vulnerability in Google Chrome

As I wrote before, my IE6 isn't affected by that hole in Chrome. Does your
IE7 is affected by my Chrome exploit, or only by your AIM exploit? Because
if there is mentioned hole, then it must be affected by both exploits.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Re: Insufficient Authentication vulnerability in Acer notebooks

different versions of Vista as with XP, where XP Home and XP Professional
have different situations with default admin accounts. Which leads to
vulnerability in XP Home. So I'm planning to investigate different versions
of Windows Vista to be sure.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Re: Insufficient Authentication vulnerability in Acer notebooks

> have different situations with default admin accounts. Which leads to
> vulnerability in XP Home. So I'm planning to investigate different 
> versions
> of Windows Vista to be sure.
>
> Best wishes & regards,
> MustLive
> Administrator of Websecurity web site
> http://websecurity.com.ua
>
> ----- Original Message ----- From: "Susan Bradley" <sbradcpa@pacbell.net>

Re: Saved XSS vulnerability in Internet Explorer

(http://securityvulns.ru/Udocument911.html) and Cross-browser Code Execution
via XSS (http://securityvulns.ru/Udocument941.html), which I wrote in 2008
concerning this kind of vulnerabilities in browsers. How the attack can be
elevated from XSS to CE.

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua

----- Original Message ----- 

Vulnerabilities in SimpNews

http://site/simpnews/news.php?layout=%3Cscript%3Ealert(document.cookie)%3C/script%3E

http://site/simpnews/news.php?lang=en&layout=layout2&sortorder=%22%3E%3Cscript%3Ealert(document.cookie)%3C/script%3E

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua



Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!