New User, Welcome!     Login

Next Page >>

Internet community

IETF RFC on Port Randomization

This document is a product of the Transport Area Working Group Working
Group of the IETF.


BCP: This document specifies an Internet Best Current Practices for the
Internet Community, and requests discussion and suggestions for
improvements. Distribution of this memo is unlimited.

This announcement is sent to the IETF-Announce and rfc-dist lists.
To subscribe or unsubscribe, see
  http://www.ietf.org/mailman/listinfo/ietf-announce

PR07-44: XSS on RSA Authentication Agent login page

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community  for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited  or changed in any way, is
attributed to Procheckup, and provided such reproduction and/or
distribution is performed for non-commercial purposes.



Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

>> ignore to fix the holes (especially DoS holes, which were only fixed few
>> times by Google and one time by Microsoft, and not in IE, but in Outlook,
>> and 99% of cases were completely ignored). Taking that into account last
>> year I decided from 2010 never inform browser vendors about DoS holes in
>> their browsers. And this time it was an exclusion (just one). In any case
>> due to full disclosure the Internet community will be knowing about the
>> vulnerabilities in browsers which I found and will be knowing the real
>> state
>> of security of browsers. It was another leitmotif of my advisory.
>>
>> So this time I informed browser developers and users about these issues.

PR07-42: Webroot disclosure on Juniper Networks Secure Access 2000

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the 
Internet community for the purpose of alerting them to problems, if and 
only if, the Bulletin is not edited or changed in any way, is attributed 
to Procheckup, and provided such reproduction and/or distribution is 
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not 

PR07-38: XSS on sIFR

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the 
Internet community for the purpose of alerting them to problems, if and 
only if, the Bulletin is not edited or changed in any way, is attributed 
to Procheckup, and provided such reproduction and/or distribution is 
performed for non-commercial purposes. Any other use of this information 
is prohibited. Procheckup is not liable for any misuse of this 
information by any third party.

(CFP) LACSEC 2012: 7th Network Security Event for Latin America and the Caribbean

LACNIC (http://www.lacnic.net) is the international organization based
in (Uruguay) that is responsible for administrating IP address space,
Reverse Resolution, Autonomous System Numbers and other resources for
the region of Latin America and the Caribbean on behalf of the Internet
community.

The ?7th Network Security Event for Latin America and the Caribbean?
will be held in Quito, Ecuador, within the framework of LACNIC's
seventeenth annual meeting (LACNIC XVII). This is a public call for
presentations for that event.

PR10-13: Multiple XSS and Authentication flaws within BMC Remedy Knowledge Management

Legal:
Copyright 2010 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR10-03: Authenticated Cross-Site Scripting (XSS) within the Apache Axis2 administration console

Legal:

Copyright 2010 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR07-31: Unauthenticated SQL Injection, XSS on Login Page and Username Enumeration on DPSnet Case Progress

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited  or changed in any way, is
attributed to Procheckup, and provided such reproduction and/or
distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR06-12: XSS on BEA Plumtree Foundation and AquaLogic Interaction portals

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the 
Internet community for the purpose of alerting them to problems, if and 
only if, the Bulletin is not edited or changed in any way, is attributed 
to Procheckup, and provided such reproduction and/or distribution is 
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not 

PR08-21: Cross-site Request Forgery (CSRF) on Novell GroupWise WebAccess allows email theft and other attacks

Legal:

Copyright 2009 ProCheckUp Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if the Bulletin is not changed or edited in any way, is attributed
to ProCheckUp indicating this web page URL, and provided such
reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. ProCheckUp is not

Re: DoS vulnerabilities in Firefox, Internet Explorer, Chrome, Opera and other browsers

> ignore to fix the holes (especially DoS holes, which were only fixed few
> times by Google and one time by Microsoft, and not in IE, but in Outlook,
> and 99% of cases were completely ignored). Taking that into account last
> year I decided from 2010 never inform browser vendors about DoS holes in
> their browsers. And this time it was an exclusion (just one). In any case
> due to full disclosure the Internet community will be knowing about the
> vulnerabilities in browsers which I found and will be knowing the real 
> state
> of security of browsers. It was another leitmotif of my advisory.
>
> So this time I informed browser developers and users about these 

XSS with mod_perl perl_status utility

Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the Internet community for the purpose of alerting them to problems, if and only if, the Bulletin is not edited or changed in any way, is attributed to Procheckup, and provided such reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not liable for any misuse  of this information by any third party.



PR08-24: Proxim Tsunami MP.11 2411 vulnerable to SNMP Injection

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited
or changed in any way, is attributed to Procheckup, and provided such
reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR08-09: Unauthenticated File Retrieval on Sun Java System Identity Manager "ext" parameter

Legal:

Copyright 2008 ProCheckUp Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if the Bulletin is not changed or edited in any way, is attributed
to ProCheckUp indicating this web page URL, and provided such
reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. ProCheckUp is not

PR08-16: CSRF (Cross-site Request Forgery) on Moodle edit profile page

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

http://www.procheckup.com/vulnerability_manager/vulnerabilities/pr10-04

Legal
Copyright 2010 ProCheckUp Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR08-13: Persistent Cross-site Scripting (XSS) on Moodle via blog entry title

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR08-15: Several Webroot Disclosures on Moodle

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

PR09-17: Juniper Secure Access seriers (Juniper IVE) authenticated XSS & REDIRECTION

Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to
problems, if and only if, the Bulletin is not edited or changed in any
way, is attributed to Procheckup, and provided such
reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

Various Orion application application server example pages are vulnerable to XSS.

Legal:

Copyright 2009 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the Internet community for the purpose of alerting them to problems, if and only if, the Bulletin is not edited or changed in any way, is attributed to Procheckup, and provided such reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not liable for any misuse of this information by any third party.




Re: Cross-Site Scripting vulnerability in Mozilla, Firefox and Chrome

there will be no site to close, and no site to block with antifishing
lists). And there are a lot of vulnerable redirectors in Internet.

I planned to write an article about JavaScript Execution attacks in
different browsers via different redirectors to draw attention of Internet
community to this problem. Didn't write it in last two weeks, but I'd do it
in near time.

Best wishes & regards,
MustLive
Administrator of Websecurity web site

PR10-11: Multiple XSS injection vulnerabilities and a offsite redirection flaw within HP System Management Homepage (Insight Manager)

Legal:

Copyright 2010 ProCheckUp Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to

problems, if and only if the Bulletin is not changed or edited in any
way, is attributed to ProCheckUp indicating this web page URL, and
provided such reproduction and/or distribution


[CFP] LACSEC 2011: 6th Network Security Event for Latin America and the Caribbean

LACNIC (http://www.lacnic.net) is the international organization based
in (Uruguay) that is responsible for administrating IP address space,
Reverse Resolution, Autonomous System Numbers and other resources for
the region of Latin America and the Caribbean on behalf of the Internet
community.

The “6th Network Security Event for Latin America and the Caribbean”
will be held in Cancun, Mexico, within the framework of LACNIC's
fifteenth annual meeting (LACNIC XV). This is a public call for
presentations for that event.

LACSEC 2012 Agenda (May 6-11, 2012, Quito, Ecuador)

LACNIC (http://www.lacnic.net) is the international organization based
in Montevideo (Uruguay) that is responsible for administrating the IP
address space, Reverse Resolution, Autonomous System Numbers and other
resources for the region of Latin America and the Caribbean on behalf of
the Internet community.

The "7th Network Security Event for Latin America and the Caribbean"
(LACSEC 2012) will be held in Quito, Ecuador, within the framework of
LACNIC's seventeenth annual meeting (LACNIC XVII).


PR08-01: Several XSS, a cross-domain redirect and a webroot disclosure on Spyce - Python Server Pages (PSP)

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the 
Internet community for the purpose of alerting them to problems, if and 
only if, the Bulletin is not edited or changed in any way, is attributed 
to Procheckup, and provided such reproduction and/or distribution is 
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not 

PR07-44: XSS on RSA Authentication Agent login page

Legal:

Copyright 2008 Procheckup Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community  for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited  or changed in any way, is
attributed to Procheckup, and provided such reproduction and/or
distribution is performed for non-commercial purposes.



PR08-19: XSS on Cisco IOS HTTP Server

Legal:

Copyright 2009 ProCheckUp Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if the Bulletin is not changed or edited in any way, is attributed
to ProCheckUp indicating this web page URL, and provided such
reproduction and/or distribution is performed for non-commercial purposes.

Any other use of this information is prohibited. ProCheckUp is not

Re: Comments re ISC's announcement on bind9 security

> It's a text published by ISC as a follow up to the bind9 predictable id saga.
>
> Particularly the following statement is funny, and shows complete lack
> of understanding of the terminology and of the problem space:
>
> 'ISC would like to assure the Internet community that this is much
> less an issue of using "extremely weak crypto" as it has been
> described, than the use of a random number generator that did not
> provide sufficient randomness.'
>
> My understanding is that they used a pseudo random number generator in

PR10-14 Unauthenticated command execution within Mitel's AWC (Mitel Audio and Web Conferencing)

Legal
Copyright 2010 ProCheckUp Ltd. All rights reserved.

Permission is granted for copying and circulating this Bulletin to the
Internet community for the purpose of alerting them to problems, if and
only if, the Bulletin is not edited or changed in any way, is attributed
to Procheckup, and provided such reproduction and/or distribution is
performed for non-commercial purposes.

Any other use of this information is prohibited. Procheckup is not

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!