Member Login

Login
No account yet? Register
 

Search

Tell your friends about the Arcane Security Portal.

Search The Web


Who's Online

Bugtraq
Bugtraq (bugtraq) Mailing List
The premier general security mailing list. Vulnerabilities are often announced here first, so check frequently!

  • Re: Oracle 10g Dynamic Monitoring Services XSS servletSpy
    Posted by dstinbox_at_gmail.com on Sep 5

    ('binary' encoding is not supported, stored as-is) I ran accross your post,
    can you tell me how to harden the config file against this
     
    would this do it ?
     
    <Directory "<Directory "E:\infra\ ...">
    ...

  • Google Chrome 0.2.149.27 SaveAs Function Buffer Overflow Vulnerability
    Posted by Security Vulnerability Research Team on Sep 5

    We (SVRT-Bkis) have just discovered vulnerability in Google Chrome
    0.2.149.27. This is a Critical Buffer Overflow Vulnerability permiting
    hacker to perform a remote attack and take complete control of the affected
    system.

    We have submitted this Vulnerability to Google. They confirmed and...

  • Re: Has anyone implemented quotdouble forward DNSquot?
    Posted by Steven Bakker on Sep 05

    On Thu, 2008-09-04 at 15:34 +0200, Ansgar -59cobalt- Wiechers wrote:

    > It was pointed out to me in private that, of course, you can have
    > multiple PTR records mapping one address to different names. My bad.
    >
    > However, since oftentimes (colocation scenarios for instance)...

  • Re: XCon 2008 Call for Paper
    Posted by Sowhat on Sep 5

    If you have any questions, comments, please shoot against Casper ;)
    Though I am happy to forward it.

    On Fri, Sep 5, 2008 at 4:40 PM, Sowhat <smaillist_at_gmail.com> wrote:
    > Got couple of emails with comments (language mistakes) and questions,
    > Thanks guys!
    >
    >...

  • Re: XCon 2008 Call for Paper
    Posted by Sowhat on Sep 5

    Got couple of emails with comments (language mistakes) and questions,
    Thanks guys!

    Actually XCon is held by XFOCUS guys (Casper and others), they wrote
    it up and I was just helping to post the CFP.

    If you have any questions regarding the schedule, the conferences,
    the hotel, etc.

    Welcome...

  • XCon 2008 Call for Paper
    Posted by Sowhat on Sep 5

    XCon 2008 Call for Paper

          Nov. 18th – 19th, 2008, Beijing, PRC (http://xcon.xfocus.net)

          XCon is wholeheartedly expecting papers from those who are
    passionate about information security technique and their
    participation and...

  • Risky Chrome (The perfect cleartext password offering )
    Posted by quakerdoomer_at_fmguy.com on Sep 5

    ('binary' encoding is not supported, stored as-is) Google Chrome : The perfect password offering ( Tested on pair.com Webmail, might work on
    others as well with Google Chrome 0.2.149.27)
     
    Chrome stores saves passwords in CLEAR TEXT.
     
    1 ] Goto webmail.pair.com
    ...

  • rPSA-2008-0268-1 libtiff
    Posted by rPath Update Announcements on Sep 04

    rPath Security Advisory: 2008-0268-1
    Published: 2008-09-04
    Products:
        rPath Linux 1
        rPath Linux 2

    Rating: Major
    Exposure Level Classification:
        Indirect User Deterministic Unauthorized Access
    Updated Versions:
    ...

  • Re: Zen Cart lt 1.3.8a SQL Injection
    Posted by Ian Wilson on Sep 05

    Hi,

    Just wanted to say thanks to James and Gulftech for the manner in which
    they worked with the Zen Cart developers in identifying and fixing this
    Exploit.

    Ian C Wilson
    Zen Cart Development Team

    GulfTech Security Research wrote:
    >...

  • other google chrome crash
    Posted by jplopezy_at_gmail.com on Sep 4

    ('binary' encoding is not supported, stored as-is) another proof of concept of how to break the google chrome, there is not much detail in reality.

    the result of error in ollydbg is:

    Access violation when reading [00000000]

    nigun effect obviously does not cause "dangerous" but it is...

  • [security bulletin] HPSBMA02361 SSRT080119 rev.1 - HP OpenView Select Identity Connectors running on Windows, Local Information Disclosure
    Posted by security-alert_at_hp.com on Sep 05

    SUPPORT COMMUNICATION - SECURITY BULLETIN

    Document ID: c01531379
    Version: 1

    HPSBMA02361 SSRT080119 rev.1 - HP OpenView Select Identity Connectors running on Windows, Local Information Disclosure

    NOTICE: The information in this Security Bulletin should be acted upon as soon as possible.

    ...

  • [ MDVSA-2008:186 ] python
    Posted by security_at_mandriva.com on Sep 04

     _______________________________________________________________________

     Mandriva Linux Security Advisory MDVSA-2008:186
     http://www.mandriva.com/security/
     _______________________________________________________________________

     Package :...

  • Multiple MicroWorld products insecure directory permissions
    Posted by Edi Strosar on Sep 04

    =========================================================================

            Multiple MicroWorld products insecure directory permissions

    =========================================================================

      Release date:...

  • [ GLSA 200809-02 ] dnsmasq: Denial of Service and DNS spoofing
    Posted by Robert Buchholz on Sep 4

    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    Gentoo Linux Security Advisory GLSA 200809-02
    - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
    ...

  • Re: Has anyone implemented quotdouble forward DNSquot?
    Posted by Ansgar -59cobalt- Wiechers on Sep 4

    On 2008-09-03 Ansgar Wiechers wrote:
    > On 2008-08-30 Duncan Simpson wrote:
    >> Double reverse DNS, which checks the name found using reverse DNS
    >> matches the IP adrdess enquired about is now common. I was wondering
    >> wether about has applied the same technique to...