<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
    <pubDate>Fri, 20 Nov 2009 21:45:17 GMT</pubDate>
    <lastBuildDate>Fri, 20 Nov 2009 21:45:17 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/232</link>
    <description>&lt;p&gt;Posted by Michael Holstein on Nov 20&lt;/p&gt;Vladis .. not sure about that school since it was K12, but in both your &lt;br&gt;
case and mine .. we *are* the ISP (insofar as we have our own ASN and &lt;br&gt;
valid info on whois).&lt;br&gt;
&lt;br&gt;
If K12 is done there like I've seen in a lot of other places, they &lt;br&gt;
probably have a consortium that provides connectivity and each &lt;br&gt;
institution has a CIDR block within the consortium's AS .. and I'm sure &lt;br&gt;
the school had some web-nazi appliance that made it a few-clicks of a &lt;br&gt;
mouse...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 21:39:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/232</guid>
  </item>
  <item>
    <title>VMSA-2009-0016 VMware vCenter and ESX update release and vMA patch release address multiple security issue in third party components</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/231</link>
    <description>&lt;p&gt;Posted by VMware Security Team on Nov 20&lt;/p&gt;-----------------------------------------------------------------------&lt;br&gt;
                   VMware Security Advisory&lt;br&gt;
&lt;br&gt;
Advisory ID:       VMSA-2009-0016&lt;br&gt;
Synopsis:          VMware vCenter and ESX update release and vMA patch&lt;br&gt;
                   release address multiple security issue in third&lt;br&gt;
                   party components&lt;br&gt;
Issue date:        2009-11-20&lt;br&gt;
Updated on:        2009-11-20 (initial release of advisory)&lt;br&gt;
CVE numbers:       --- JRE ---...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 20:57:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/231</guid>
  </item>
  <item>
    <title>Pussy and the right to free speech.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/230</link>
    <description>&lt;p&gt;Posted by yuri . nate on Nov 20&lt;/p&gt;This whole thing is ridiculous.  Kurt Greenbaum is an idiot.  What &lt;br&gt;
kind of question is that in the first place?  Only and idiot would &lt;br&gt;
post “what’s the strangest thing you’ve ever eaten” and not expect &lt;br&gt;
some obvious remarks.  And what’s wrong with pussy?  Eating pussy &lt;br&gt;
is good!  I LOVE eating pussy!  All they guys I know, along with &lt;br&gt;
several women I know love to eat pussy.  I eat pussy.  You eat &lt;br&gt;
pussy.  Everyone eats pussy.  That’s...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 19:55:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/230</guid>
  </item>
  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media,	St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/229</link>
    <description>&lt;p&gt;Posted by Valdis . Kletnieks on Nov 20&lt;/p&gt;On Fri, 20 Nov 2009 01:42:08 +0100, netinfinity said:&lt;br&gt;
&lt;br&gt;
Unfortunately, that's exactly what *did* happen.  Although for *home*&lt;br&gt;
users, the 'ISP' is the person to complain to, for organizations that run&lt;br&gt;
their own networks (like many businesses and schools, etc) the proper place&lt;br&gt;
to complain is the network management of that organization.   He contacted&lt;br&gt;
the admins of the school's network, and said &amp;quot;One of your users is being&lt;br&gt;
a bozo&amp;quot;.  The...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 14:11:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/229</guid>
  </item>
  <item>
    <title>PHP &quot;multipart/form-data&quot; denial of service</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/228</link>
    <description>&lt;p&gt;Posted by Bogdan Calin on Nov 20&lt;/p&gt;Description&lt;br&gt;
------------&lt;br&gt;
PHP version 5.3.1 was just released. This release contains a patch for a&lt;br&gt;
denial of service condition we've reported on 27 October 2009. The&lt;br&gt;
problem is related with PHP's handling of RFC 1867 (Form-based File&lt;br&gt;
Upload in HTML).&lt;br&gt;
&lt;br&gt;
When you send a POST request to a PHP script with the content-type of&lt;br&gt;
&amp;quot;multipart/form-data&amp;quot; and include a list of files in that request, PHP&lt;br&gt;
will create a temporary file for each file from...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 12:10:45 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/228</guid>
  </item>
  <item>
    <title>n3td3v / Andrew Wallace's psychological profile</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/227</link>
    <description>&lt;p&gt;Posted by Sam Haldorf on Nov 19&lt;/p&gt;Earlier this year, a very well educated FD member posted the psychological profile of Mr. Wallace. (Found here: &lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://seclists.org/fulldisclosure/2009/Jan/415&quot;&gt;http://seclists.org/fulldisclosure/2009/Jan/415&lt;/a&gt; ) Interesting to view in retrospect, because I find it depicts him to a &lt;br&gt;
T.&lt;br&gt;
&lt;br&gt;
This profile is almost like an instruction set for n3td3v's life. A self-fulfilling prophecy if you will.&lt;br&gt;
&lt;br&gt;
An eery example: Anyone here remember how n3td3v posted as full-censorship a few months ago claiming to...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 03:47:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/227</guid>
  </item>
  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media,	St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/226</link>
    <description>&lt;p&gt;Posted by Sam Haldorf on Nov 19&lt;/p&gt;No problem regarding the personal post, I have made the same mistake myself.&lt;br&gt;
&lt;br&gt;
I also see what you mean regarding the language of the privacy statement.&lt;br&gt;
&amp;quot;unauthorised use&amp;quot; could be interpreted as any use that has not been given explicit approval before the fact.&lt;br&gt;
&lt;br&gt;
Weasel words imho.&lt;br&gt;
&lt;br&gt;
And Mr Holstein if this was the point you were trying to make, I accept it.&lt;br&gt;
&lt;br&gt;
regards&lt;br&gt;
mrx&lt;br&gt;
&lt;br&gt;
dramacrat wrote:&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 02:32:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/226</guid>
  </item>
  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media,	St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/225</link>
    <description>&lt;p&gt;Posted by netinfinity on Nov 19&lt;/p&gt;Mr.  Kurt Greenbaum made a mistake. Privacy violated, because there&lt;br&gt;
are other mechanism's like baninig the IP, email or whatever is&lt;br&gt;
necessary to submit the post. If this fails then you should conntact&lt;br&gt;
the ISP of the &amp;quot;spammer&amp;quot; based on the IP.&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 00:52:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/225</guid>
  </item>
  <item>
    <title>SecurityReason: KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/224</link>
    <description>&lt;p&gt;Posted by Maksymilian Arciemowicz on Nov 19&lt;/p&gt;[ KDE KDELibs 4.3.3 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- KDELibs 4.3.3&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/74&quot;&gt;http://securityreason.com/achievement_securityalert/74&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
KDELibs is a collection of libraries built on top of...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 00:51:03 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/224</guid>
  </item>
  <item>
    <title>SecurityReason: Opera 10.01 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/223</link>
    <description>&lt;p&gt;Posted by Maksymilian Arciemowicz on Nov 19&lt;/p&gt;[ Opera 10.01 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- Opera 10.01&lt;br&gt;
- Opera 10.10 Beta&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/73&quot;&gt;http://securityreason.com/achievement_securityalert/73&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
Opera is a Web browser and Internet suite...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 00:48:53 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/223</guid>
  </item>
  <item>
    <title>SecurityReason: K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/222</link>
    <description>&lt;p&gt;Posted by Maksymilian Arciemowicz on Nov 19&lt;/p&gt;[ K-Meleon 1.5.3 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- K-Meleon 1.5.3&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/72&quot;&gt;http://securityreason.com/achievement_securityalert/72&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
K-Meleon is an extremely fast, customizable,...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 00:47:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/222</guid>
  </item>
  <item>
    <title>SecurityReason: SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution)</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/221</link>
    <description>&lt;p&gt;Posted by Maksymilian Arciemowicz on Nov 19&lt;/p&gt;[ SeaMonkey 1.1.8 Remote Array Overrun (Arbitrary code execution) ]&lt;br&gt;
&lt;br&gt;
Author: Maksymilian Arciemowicz and sp3x&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://SecurityReason.com&quot;&gt;http://SecurityReason.com&lt;/a&gt;&lt;br&gt;
Date:&lt;br&gt;
- Dis.: 07.05.2009&lt;br&gt;
- Pub.: 20.11.2009&lt;br&gt;
&lt;br&gt;
CVE: CVE-2009-0689&lt;br&gt;
Risk: High&lt;br&gt;
Remote: Yes&lt;br&gt;
&lt;br&gt;
Affected Software:&lt;br&gt;
- SeaMonkey 1.1.18&lt;br&gt;
&lt;br&gt;
Fixed in:&lt;br&gt;
- SeaMonkey 2.0&lt;br&gt;
&lt;br&gt;
NOTE: Prior versions may also be affected.&lt;br&gt;
&lt;br&gt;
Original URL:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://securityreason.com/achievement_securityalert/71&quot;&gt;http://securityreason.com/achievement_securityalert/71&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
--- 0.Description ---&lt;br&gt;
The SeaMonkey project is...&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 00:45:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/221</guid>
  </item>
  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/220</link>
    <description>&lt;p&gt;Posted by mrx on Nov 19&lt;/p&gt;No problem regarding the personal post, I have made the same mistake myself.&lt;br&gt;
&lt;br&gt;
I also see what you mean regarding the language of the privacy statement.&lt;br&gt;
&amp;quot;unauthorised use&amp;quot; could be interpreted as any use that has not been given explicit approval before the fact.&lt;br&gt;
&lt;br&gt;
Weasel words imho.&lt;br&gt;
&lt;br&gt;
And Mr Holstein if this was the point you were trying to make, I accept it.&lt;br&gt;
&lt;br&gt;
regards&lt;br&gt;
mrx&lt;br&gt;
&lt;br&gt;
dramacrat wrote:&lt;br&gt;</description>
    <pubDate>Fri, 20 Nov 2009 00:15:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/220</guid>
  </item>


  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media,	St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/219</link>
    <description>&lt;p&gt;Posted by dramacrat on Nov 19&lt;/p&gt;They're ORs, unfortunately. The language is unclear but it seems to be one&lt;br&gt;
of those infernal boilerplate pieces of shit that basically invalidate the&lt;br&gt;
assurances as to privacy.&lt;br&gt;
&lt;br&gt;
You could still probably press the suit. &amp;quot;Unauthorised use&amp;quot; has recently&lt;br&gt;
been defined and redefined, it's an evolving piece of law and if you have&lt;br&gt;
the resources to get a jury trial they'll *want* to find in favor of the&lt;br&gt;
plaintiff, which is more important than you...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 23:57:25 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/219</guid>
  </item>
  <item>
    <title>Re: Meet Kurt Greenbaum, Director of Social Media, St. Louis Post-Dispatch, Reports commenter to employer.</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/218</link>
    <description>&lt;p&gt;Posted by mrx on Nov 19&lt;/p&gt;Michael Holstein wrote:&lt;br&gt;
&lt;br&gt;
So what? Ban the IP address. Admittedly a childish comment but the site is hardly one that is frequented by children.&lt;br&gt;
imho Mr K. Greenbaum should be fired and sued.&lt;br&gt;
&lt;br&gt;
And Mr Holstein you seem to be using your quote above out of context...&lt;br&gt;
&lt;br&gt;
Compliance with Legal Process&lt;br&gt;
We may disclose personal information if we or one of our affiliated companies is required by law to disclose personal &lt;br&gt;
information, or if we&lt;br&gt;
believe in good...&lt;br&gt;</description>
    <pubDate>Thu, 19 Nov 2009 22:27:43 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/218</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
