New User, Welcome!     Login

Next Page >>

security community

RE: [Full-disclosure] Fwd: Websense 6.3.1 Filtering Bypass

-----Original Message-----
From: full-disclosure-bounces@lists.grok.org.uk
[mailto:full-disclosure-bounces@lists.grok.org.uk] On Behalf Of The
Security Community
Sent: Wednesday, December 12, 2007 3:32 PM
To: bugtraq@securityfocus.com; Full-Disclosure
Subject: [Full-disclosure] Fwd: Websense 6.3.1 Filtering Bypass

Mr. HinkyDink would like to share the following with the Security

[CAL-2012-0004] opera array integer overflow

we still insist on that  it is a security issue or not should accord to 
root cause of this bug instead of is it exploitable or not. because you 
think it is unexploitable, someone can exploit it via deeply research.

So if most people of Security Community think this is a security issue,
please assign to a CVE number.


3 Analysis
=========

Fwd: Websense 6.3.1 Filtering Bypass

Mr. HinkyDink would like to share the following with the Security Community...

---------- Forwarded message ----------
From:  <dink@mrhinkydink.com>
Date: Dec 12, 2007 6:05 PM
Subject: Websense 6.3.1 Filtering Bypass
To: thesecuritycommunity@gmail.com




SyScan'08 Call For Paper/Training

*About SyScan'08*
The Symposium on Security for Asia Network aims to be a very different 
security conference from the rest of the security conferences that the 
information security community in Asia has come to be so familiar and 
frustrated with.
SyScan is a non-product, non-vendor biased security conference. It is 
the aspiration of SyScan to congregate in Asia the best security experts 
in their various fields, to share their research, discovery and 
experience with all security enthusiasts in Asia.


Folder Lock <= 5.9.5 Local Password Information Disclosure

 * (HKEY_CURRENT_USER\Software\Microsoft\Windows\QualityControl) without proper encryption. 
 * This can be exploited to disclose the encrypted _pack password of the user which is ROT-25 and reversed.
 * 
 * Sample Output:
 * 
 * ASTALAVISTA the hacking & security community
 * Folder Lock <= 5.9.5 Decrypter v2.0
 * ---------------------------------
 * Encrypted Password: :3<k_^62`4T-
 * Decrypted Password: ,S3_15]^j;29
 * 

[CFP] Kiwicon 2k7 - Call For Papers

This is the call for presenters for the inaugural Kiwicon.

[WTF?]

Kiwicon '07 will be a largely informal conference, organised by the 
security community for the security community. It will be held in 
Wellington, New Zealand, on the weekend of the 17th and 18th of 
November, 2007.

It will focus on sharing information; ideas, code, and catching up with 
other like-minded people from around New Zealand (and further abroad).

Secunia Research: Microsoft Excel Record Parsing Array Indexing Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: InduSoft ISSymbol ActiveX Control Buffer Overflow Vulnerabilities

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: GIGABYTE Dldrv2 ActiveX Control Array Indexing Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Call for Papers - you Sh0t the Sheriff 4 - Security Conference, Brazil

INTRODUCTION

you sh0t the Sheriff is a very unique event dedicated to bringing cutting
edge topics to the top-notch Information Security Community in Brazil.

yStS mixes the highest quality presentations and speakers from all over the
globe, covering diverse topics in information security.

Our goal is to help attendees understand the current state of the

Secunia Research: Bournal Insecure Temporary Files Security Issue

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

WebStudio CMS 'pageid' Blind SQL Injection

Credits:

Charalambous Glafkos
Email:  glafkos (at) astalavista (dot) com
___________________________________________
ASTALAVISTA - the hacking & security community
www.astalavista.com
www.astalavista.net



Secunia Research: Autonomy Keyview EML Reader Buffer Overflows

relevant to their specific system configuration:

http://corporate.secunia.com/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/

Secunia believes that it is important to support the community and to

Secunia Research: Blue Coat K9 Web Protection "Referer" Header Buffer Overflow

relevant to their specific system configuration:

http://corporate.secunia.com/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/

Secunia believes that it is important to support the community and to

Secunia Research: TomatoCMS "q" SQL Injection Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Microsoft PowerPoint Freelance Layout Parsing Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Free Download Manager metalink "name" Directory Traversal

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

[ISecAuditors Security Advisories] Tikiwiki CMS is vulnerable to path traversal attack

Tikiwiki (Tiki) is a Free Software (LGPL) Content Management System
solution that unifies many features like wikis, forums, blogs,
articles, galleries, mapserver, link directory.

This software is massively used in the World Wide Web, and has been
audited by the security community for years.

III. DESCRIPTION
-------------------------
It is possible to get the first 1000 bytes from an arbitrary file
trough the tiki-listmovies.php script.

Secunia Research: ACDSee Products Image and Archive Plug-ins Buffer Overflows

relevant to their specific system configuration:

http://corporate.secunia.com/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/

Secunia believes that it is important to support the community and to

DeepSec 2008 - Last call for submissions

two days of trainings, covering the latest topics in network and IT security.
All speakers will be invited to a social event with dinner on the first day
of the conference. Don't miss this, be part of the community and have a drink!

The DeepSec conference is a meeting place for the academic community,
businesses, industry and security community. It offers a neutral ground to
exchange ideas and experiences, thus making it a unique event trying to
present the best research and experience from the fields' leading experts.


Submission:

Secunia Research: Orbit Downloader Long URL Parsing Buffer Overflow

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Foxit Reader JBIG2 Symbol Dictionary Processing Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Adobe Shockwave Player Integer Overflow Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Microsoft Office TIFF Image Converter Endian Conversion Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Microsoft Office TIFF Image Converter Two Buffer Overflows

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: IPSwitch IMail Server IMail Client Buffer Overflow

relevant to their specific system configuration:

http://corporate.secunia.com/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/

Secunia believes that it is important to support the community and to

Call for Papers -YSTS V - Security Conference, Brazil

ABOUT THE CONFERENCE

you Sh0t the Sheriff is a very unique, one-day, event dedicated to
bringing cutting edge talks to the top-notch professionals of the
Information Security Community in Brazil.

The conference’s main goal is to bring the attendees to the most
up-to-date state of the information security world by mixing
professionals and topics from different Infosec segments of the
market.

Secunia Research: IrfanView Palette File Importing Buffer Overflow Vulnerability

relevant to their specific system configuration:

http://corporate.secunia.com/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/

Secunia believes that it is important to support the community and to

Secunia Research: Autonomy Keyview Ichitaro Object Reconstruction Logic Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Secunia Research: Microsoft Outlook Content Parsing Integer Underflow Vulnerability

relevant to their specific system configuration:

http://secunia.com/advisories/business_solutions/

Secunia also provides a publicly accessible and comprehensive advisory
database as a service to the security community and private 
individuals, who are interested in or concerned about IT-security.

http://secunia.com/advisories/

Secunia believes that it is important to support the community and to

Next Page>>

Copyright © 1995-2012 LinuxRocket.net. All rights reserved.

Nearly all of LinuxRocket's features are free. Be kind and donate to the cause!