<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
    <pubDate>Fri, 19 Mar 2010 15:00:28 GMT</pubDate>
    <lastBuildDate>Fri, 19 Mar 2010 15:00:28 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Vulnerability Httpdx v1.5.3b</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/333</link>
    <description>&lt;p&gt;Posted by Mehdi Mahdjoub - Sysdream IT Security Services on Mar 19&lt;/p&gt;Program          : Httpdx v1.5.3b&lt;br&gt;
PoC              : Remote Crash Service (if http.log=1)&lt;br&gt;
Homepage         : &lt;a  rel=&quot;nofollow&quot; href=&quot;http://sourceforge.net/projects/httpdx/&quot;&gt;http://sourceforge.net/projects/httpdx/&lt;/a&gt;&lt;br&gt;
Found by         : Jonathan Salwan&lt;br&gt;
This Advisory    : Jonathan Salwan&lt;br&gt;
Contact          : j.salwan () sysdream com&lt;br&gt;
&lt;br&gt;
//----- Application description&lt;br&gt;
 &lt;br&gt;
Single-process HTTP1.1/FTP server; no threads or processes started per&lt;br&gt;
connection, runs with only few threads. Includes directory listing,&lt;br&gt;
virtual...&lt;br&gt;</description>
    <pubDate>Fri, 19 Mar 2010 14:47:36 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/333</guid>
  </item>


  <item>
    <title>CA20100318-01: Security Notice for CA ARCserve	Backup</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/332</link>
    <description>&lt;p&gt;Posted by Kotas, Kevin J on Mar 18&lt;/p&gt;CA20100318-01: Security Notice for CA ARCserve Backup&lt;br&gt;
&lt;br&gt;
Issued: March 18, 2010&lt;br&gt;
&lt;br&gt;
CA's support is alerting customers to security risks with CA ARCserve&lt;br&gt;
Backup. The version of JRE shipped with ARCserve Backup is&lt;br&gt;
potentially susceptible to multiple vulnerabilities and has also&lt;br&gt;
reached end of life. Support is providing JRE 1.6 upgrades as&lt;br&gt;
remediation.&lt;br&gt;
&lt;br&gt;
Risk Rating&lt;br&gt;
&lt;br&gt;
High&lt;br&gt;
&lt;br&gt;
Platform&lt;br&gt;
&lt;br&gt;
Windows&lt;br&gt;
&lt;br&gt;
Affected Products&lt;br&gt;
&lt;br&gt;
CA ARCserve Backup r12.5&lt;br&gt;
CA ARCserve Backup...&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 22:03:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/332</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/331</link>
    <description>&lt;p&gt;Posted by Rafael Moraes on Mar 18&lt;/p&gt;I have no doubt, just give them some time to think about it.&lt;br&gt;
&lt;br&gt;
2010/3/18 Fetch, Brandon &amp;lt;bfetch () tpg com&amp;gt;&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 20:02:42 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/331</guid>
  </item>
  <item>
    <title>Re: SecurityFocus to partially shut down</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/330</link>
    <description>&lt;p&gt;Posted by Georgi Guninski on Mar 18&lt;/p&gt;hope you are right.&lt;br&gt;
i doubt i will cry much if i bother to go to their funeral :)&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 19:51:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/330</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/329</link>
    <description>&lt;p&gt;Posted by Fetch, Brandon on Mar 18&lt;/p&gt;But wait!  That &amp;quot;paper fingerprint&amp;quot; can be captured and added to the RFID data already saved!&lt;br&gt;
&lt;br&gt;
*tongue firmly in cheek*&lt;br&gt;
&lt;br&gt;
No one would be devious enough to duplicate or forge &amp;quot;secured&amp;quot; RFID data in our passports now would they?&lt;br&gt;
&lt;br&gt;
-----Original Message-----&lt;br&gt;
From: full-disclosure-bounces () lists grok org uk [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:full-disclosure-bounces&quot;&gt;mailto:full-disclosure-bounces&lt;/a&gt; () lists grok org uk] On Behalf Of T &lt;br&gt;
Biehn&lt;br&gt;
Sent: Thursday, March 18, 2010 2:15 PM&lt;br&gt;
To: james...&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 19:02:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/329</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/328</link>
    <description>&lt;p&gt;Posted by T Biehn on Mar 18&lt;/p&gt;So your proposition is that the passport manufacturers all use laser&lt;br&gt;
beams on each passport they create and that this whitelist be somehow&lt;br&gt;
distributed to each and every airport and border check-point?&lt;br&gt;
&lt;br&gt;
lol.&lt;br&gt;
&lt;br&gt;
How bout we just let them get PKI right first.&lt;br&gt;
&lt;br&gt;
-Travis&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 18:15:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/328</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA-2018-1] New php5 packages fix	null pointer dereference</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/327</link>
    <description>&lt;p&gt;Posted by Raphael Geissert on Mar 18&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-2018-1                  security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                         Raphael Geissert&lt;br&gt;
March 18, 2010                        &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : php5&lt;br&gt;
Vulnerability  : DoS (crash)&lt;br&gt;
Problem type   : remote...&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 17:28:44 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/327</guid>
  </item>
  <item>
    <title>AboCMS SQL injection (abocms.ru)</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/326</link>
    <description>&lt;p&gt;Posted by Владимир Воронцов on Mar 18&lt;/p&gt;[ONSEC-10-003] AboCMS SQL inj&lt;br&gt;
Target: AboCMS &amp;lt;= 5.4 (fixpack unknown)&lt;br&gt;
Type: SQL инъекция&lt;br&gt;
Rist: Medium&lt;br&gt;
Find date: 12.03.2010&lt;br&gt;
Report date: 12.03.2010&lt;br&gt;
Fix date: 17.03.2010&lt;br&gt;
Author: Vladimir Vorontsov&lt;br&gt;
OnSec Russian Security Group (onsec [dot] ru)&lt;br&gt;
Original links: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://onsec.ru/vuln?id=19&quot;&gt;http://onsec.ru/vuln?id=19&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
In the popular content management system AboCMS version 5.2 found a&lt;br&gt;
critical vulnerability. Errors allow an attacker to modify the query syntax&lt;br&gt;
to the...&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 17:07:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/326</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/325</link>
    <description>&lt;p&gt;Posted by Byron Sonne on Mar 18&lt;/p&gt;All technology and software is crap... it can't prevent anything from&lt;br&gt;
happening as long as humans are involved.&lt;br&gt;
&lt;br&gt;
If a man can make it, a man can break it... and if not, there's always&lt;br&gt;
rubber-hose cryptanalysis.&lt;br&gt;
&lt;br&gt;
Security _is_ snake oil&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 17:05:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/325</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/324</link>
    <description>&lt;p&gt;Posted by james o' hare on Mar 18&lt;/p&gt;They used false British passports, and you wonder why we want to have&lt;br&gt;
these technologies?&lt;br&gt;
&lt;br&gt;
Andrew&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 16:04:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/324</guid>
  </item>
  <item>
    <title>[USN-915-1] Thunderbird vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/323</link>
    <description>&lt;p&gt;Posted by Marc Deslauriers on Mar 18&lt;/p&gt;===========================================================&lt;br&gt;
Ubuntu Security Notice USN-915-1             March 18, 2010&lt;br&gt;
thunderbird vulnerabilities&lt;br&gt;
CVE-2009-0689, CVE-2009-2463, CVE-2009-3072, CVE-2009-3075,&lt;br&gt;
CVE-2009-3077, CVE-2009-3376, CVE-2009-3983, CVE-2010-0163&lt;br&gt;
===========================================================&lt;br&gt;
&lt;br&gt;
A security issue affects the following Ubuntu releases:&lt;br&gt;
&lt;br&gt;
Ubuntu 8.04 LTS&lt;br&gt;
Ubuntu 8.10&lt;br&gt;
Ubuntu 9.04&lt;br&gt;
Ubuntu 9.10&lt;br&gt;
&lt;br&gt;
This...&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 15:37:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/323</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/322</link>
    <description>&lt;p&gt;Posted by T Biehn on Mar 18&lt;/p&gt;Ridiculous.&lt;br&gt;
Generate some valid, non-far-fetched use-cases to justify this if I'm wrong.&lt;br&gt;
&lt;br&gt;
-Travis&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 15:36:23 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/322</guid>
  </item>
  <item>
    <title>Re: Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/321</link>
    <description>&lt;p&gt;Posted by james o' hare on Mar 18&lt;/p&gt;As long as it stops The Mossad going to Dubai and assassinating people&lt;br&gt;
in hotel rooms, then I'm all for it.&lt;br&gt;
&lt;br&gt;
Andrew&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 15:21:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/321</guid>
  </item>
  <item>
    <title>Fingerprinting Paper with Laser</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/320</link>
    <description>&lt;p&gt;Posted by Gadi Evron on Mar 18&lt;/p&gt;I saw this release today, and just had to share it with anyone I could find.&lt;br&gt;
&lt;br&gt;
&amp;quot;Every paper, plastic, metal and ceramic surface is microscopically &lt;br&gt;
different and has its own 'fingerprint'. Professor Cowburn's LSA system &lt;br&gt;
uses a laser to read this naturally occurring 'fingerprint'. The &lt;br&gt;
accuracy of measurement is often greater than that of DNA with a &lt;br&gt;
reliability of at least one million trillion.&amp;quot;&lt;br&gt;
&lt;br&gt;
I love it when old technologies and...&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 15:17:41 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/320</guid>
  </item>
  <item>
    <title>Re: FW: Your email has been selected	(n3td3v/andrew wallace spam) lulz.</title>
    <link>http://seclists.org/fulldisclosure/2010/Mar/319</link>
    <description>&lt;p&gt;Posted by james o' hare on Mar 18&lt;/p&gt;Thanks for letting me know, I've forwarded it to SOCA.&lt;br&gt;
&lt;br&gt;
Andrew&lt;br&gt;</description>
    <pubDate>Thu, 18 Mar 2010 15:15:06 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Mar/319</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
