New User, Welcome!     Login

Next Page >>

Sydney Australia

RE: A more detailed description of the Jura F90 vulnerability.

Direct : +61 2 9286 5497
Craig.Wright@bdo.com.au
+61 417 683 914

BDO Kendalls (NSW-VIC) Pty. Ltd.
Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497
http://www.bdo.com.au/

The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.

RE: A more detailed description of the Jura F90 vulnerability.

> Direct : +61 2 9286 5497
> Craig.Wright@bdo.com.au
> +61 417 683 914
> 
> BDO Kendalls (NSW-VIC) Pty. Ltd.
> Level 19, 2 Market Street Sydney NSW 2000
> GPO BOX 2551 Sydney NSW 2001
> Fax +61 2 9993 9497
> http://www.bdo.com.au/
> 
> The information in this email and any attachments is confidential. If

Web Design Sydney (news-item.php?id) (news-item.php?newsid) Remote SQL injection Vulnerability

################################  IRANIAN THE BEST HACKERS IN THE WORLD ##################
#################### ####################
##
## Remote SQL injection Vulnerability
##
## Web Design Sydney (news-item.php?id) (news-item.php?newsid)
##                           
###############################################################
###############################################################
###############################################################
###############################################################

OSI Security: CheckPoint Firewall VPN - Information Disclosure

12-Mar-2012 - Disclosure.

About OSI Security:

OSI Security is an independent network and computer security auditing
and consulting company based in Sydney, Australia. We provide internal
and external penetration testing, vulnerability auditing and wireless
site audits, vendor product assessments, secure network design,
forensics and risk mitigation services.

We can be found at http://www.osisecurity.com.au/

Re: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

other I found.)

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

"originally gs" or "Debian special".

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



OSI Security: Squiz Matrix - User Account Enumeration

12-Dec-2011 - Disclosure.

About OSI Security:

OSI Security is an independent network and computer security auditing
and consulting company based in Sydney, Australia. We provide internal
and external penetration testing, vulnerability auditing and wireless
site audits, vendor product assessments, secure network design,
forensics and risk mitigation services.

We can be found at http://www.osisecurity.com.au/

Re: Samba Remote Zero-Day Exploit

extensions" (which I had set to non-default "no" to help Mac clients).

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

Mathemtica /tmp access would be a better idea. Will look into a patch
soon.

- Vikram

On Sat, Apr 14, 2012 at 6:28 PM,  <paul.szabo@sydney.edu.au> wrote:
> The problem reported for Mathematica became worse at version 8.0.4,
> present for the command-line interface "math" also.
>
> Cheers,
>

OSI Security: Elitecore Cyberoam UTM - Authenticated Cross-Site Scripting Vulnerability

20-Jun-2011 - Disclosure.

About OSI Security:

OSI Security is an independent network and computer security auditing
and consulting company based in Sydney, Australia. We provide internal
and external penetration testing, vulnerability auditing and wireless
site audits, vendor product assessments, secure network design,
forensics and risk mitigation services.

We can be found at http://www.osisecurity.com.au/

JFreeChart - Path Disclosure vulnerability

17-Jun-2011 - Disclosure.

About OSI Security:

OSI Security is an independent network and computer security auditing
and consulting company based in Sydney, Australia. We provide internal
and external penetration testing, vulnerability auditing and wireless
site audits, vendor product assessments, secure network design,
forensics and risk mitigation services.

We can be found at http://www.osisecurity.com.au/

Re: XSS in Oracle default fcgi-bin/echo

Maybe, contact me off-list so I can provide PoC?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Squiz Matrix - Cross-Site Scripting Vulnerability

responding to, and addressing, these issues.

About OSI Security:

OSI Security is an independent network and computer security auditing
and consulting company based in Sydney, Australia. We provide internal
and external penetration testing, vulnerability auditing and wireless
site audits, vendor product assessments, secure network design,
forensics and risk mitigation services.

We can be found at http://www.osisecurity.com.au/

Re: Ghostscript 8.64 executes random code at startup

a proof-of-concept demo?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Hacking Coffee Makers.

Direct : +61 2 9286 5497
Craig.Wright@bdo.com.au
+61 417 683 914

BDO Kendalls (NSW-VIC) Pty. Ltd.
Level 19, 2 Market Street Sydney NSW 2000
GPO BOX 2551 Sydney NSW 2001
Fax +61 2 9993 9497
http://www.bdo.com.au/

The information in this email and any attachments is confidential. If you are not the named addressee you must not read, print, copy, distribute, or use in any way this transmission or any information it contains. If you have received this message in error, please notify the sender by return email, destroy all copies and delete it from your system.

Re: Ghostscript 8.64 executes random code at startup

"protection" against just ./Encoding is not enough.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



XSS in Oracle default fcgi-bin/echo

  http://www.thisisahmed.com/tia/ohs/ohshardening.html

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

Yes, precisely: that is why I called it any.ps.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Sorry to blow your assumption: sent to Oracle, ages ago, first thing.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

should behave as a dup().

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

Wolfram.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: /proc filesystem allows bypassing directory permissions on Linux

matter for debate (by opinionated people) is whether it should be fixed.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Yes, but... seems not all echo's get a Referer passed to them.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Regards,
Riyaz Walikar


On 10/14/10, paul.szabo@sydney.edu.au <paul.szabo@sydney.edu.au> wrote:
> Dear Thor,
>
> Amazing how people claim being logical ... sure sign they aren't!
>
>> ... Irrespective of the method you choose to validate "bona-fide"

Re: /proc filesystem allows bypassing directory permissions on Linux

are not cached??!!

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: Ghostscript 8.64 executes random code at startup

also.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Re: [Full-disclosure] Samba Remote Zero-Day Exploit

Is that vendor Samba?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Mathematica8.0.4 on Linux /tmp/MathLink vulnerability

present for the command-line interface "math" also.

Cheers,

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia


---

http://lists.grok.org.uk/pipermail/full-disclosure/2010-May/074548.html

Re: Samba Remote Zero-Day Exploit

No please, do not dumb it down.

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



RE: [Full-disclosure] XSS in Oracle default fcgi-bin/echo

Were not those obvious to right-thinking people?

Cheers, Paul

Paul Szabo   psz@maths.usyd.edu.au   http://www.maths.usyd.edu.au/u/psz/
School of Mathematics and Statistics   University of Sydney    Australia



Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!