<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
    <pubDate>Tue, 09 Feb 2010 15:15:16 GMT</pubDate>
    <lastBuildDate>Tue, 09 Feb 2010 15:15:16 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>XSS in mtvindia.com</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/138</link>
    <description>&lt;p&gt;Posted by sachin shinde on Feb 09&lt;/p&gt;XSS is present in mtvindia.com&lt;br&gt;
&lt;br&gt;
url:&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mtvindia.com/vjhunt/about.php&quot;&gt;http://www.mtvindia.com/vjhunt/about.php&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
in this page under phone # XSS is present.&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 15:06:31 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/138</guid>
  </item>
  <item>
    <title>Hacktics Advisory Feb09: XSS in Oracle E-Business	Suite</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/137</link>
    <description>&lt;p&gt;Posted by Ofer Maor on Feb 09&lt;/p&gt;Hacktics Research Group Security Advisory&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.hacktics.com/#view=Resources%7CAdvisory&quot;&gt;http://www.hacktics.com/#view=Resources%7CAdvisory&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
By Gil Cohen, Hacktics.&lt;br&gt;
9-Feb-2010&lt;br&gt;
&lt;br&gt;
===========&lt;br&gt;
I. Overview&lt;br&gt;
===========&lt;br&gt;
During a penetration test performed by Hacktics' experts, certain&lt;br&gt;
vulnerabilities were identified in an Oracle E-Business Suite deployment.&lt;br&gt;
Further research has identified that a web interface showing user errors are&lt;br&gt;
vulnerable to reflected cross site scripting attacks. &lt;br&gt;
&lt;br&gt;
A friendly...&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 13:04:09 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/137</guid>
  </item>
  <item>
    <title>Baidu XSS Zero Day</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/136</link>
    <description>&lt;p&gt;Posted by Beatyou Man on Feb 09&lt;/p&gt;Baidu.com is the bigest search engineen provider in China. After&lt;br&gt;
been hacked by Iran Cyberarmy. There is another vulnerbility been found on index.baidu.com.&lt;br&gt;
&lt;br&gt;
Description of Vulnerability:&lt;br&gt;
&lt;br&gt;
-----------------------------&lt;br&gt;
&lt;br&gt;
There is a XSS vulnerability exist on baidu.com which found by a Internet user.&lt;br&gt;
&lt;br&gt;
Impact:&lt;br&gt;
&lt;br&gt;
-------&lt;br&gt;
&lt;br&gt;
No more repeat about such types of vulnerabilities&lt;br&gt;
&lt;br&gt;
Mitigating factors:&lt;br&gt;
&lt;br&gt;
-------------------&lt;br&gt;
&lt;br&gt;
Proof of concept:&lt;br&gt;
&lt;br&gt;
-----------------...&lt;br&gt;</description>
    <pubDate>Tue, 09 Feb 2010 10:08:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/136</guid>
  </item>


  <item>
    <title>[ MDVSA-2010:034 ] kernel</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/135</link>
    <description>&lt;p&gt;Posted by security on Feb 08&lt;/p&gt; _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Mandriva Linux Security Advisory                         MDVSA-2010:034&lt;br&gt;
 &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.mandriva.com/security/&quot;&gt;http://www.mandriva.com/security/&lt;/a&gt;&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Package : kernel&lt;br&gt;
 Date    : February 8, 2010&lt;br&gt;
 Affected: 2009.0, Enterprise Server 5.0&lt;br&gt;
 _______________________________________________________________________&lt;br&gt;
&lt;br&gt;
 Problem Description:&lt;br&gt;
&lt;br&gt;
 Some...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 19:14:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/135</guid>
  </item>
  <item>
    <title>Re: about jit and dep+aslr</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/134</link>
    <description>&lt;p&gt;Posted by Christian Sciberras on Feb 08&lt;/p&gt;That's a Google feature!! (remembering the Google&amp;lt;-&amp;gt;China issue ;) )&lt;br&gt;
&lt;br&gt;
2010/2/8 Thor (Hammer of God) &amp;lt;Thor () hammerofgod com&amp;gt;:&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 16:27:35 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/134</guid>
  </item>
  <item>
    <title>Re: about jit and dep+aslr</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/133</link>
    <description>&lt;p&gt;Posted by Thor (Hammer of God) on Feb 08&lt;/p&gt;Well, *I* made the mistake of trying to be witty with one of those &amp;quot;google translate&amp;quot; Chinese tags and it didn't go so &lt;br&gt;
well for me.  I ended up offending a couple of people and got a few &amp;quot;Sun your mother&amp;quot; emails myself. :)&lt;br&gt;
&lt;br&gt;
t&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 16:25:56 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/133</guid>
  </item>
  <item>
    <title>Re: about jit and dep+aslr</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/132</link>
    <description>&lt;p&gt;Posted by Christian Sciberras on Feb 08&lt;/p&gt;Is it so difficult to do some translation prior, just as Larry did?&lt;br&gt;
Sure, some members on FD are gits, but please do respect the rest, will you?&lt;br&gt;
&lt;br&gt;
Regards,&lt;br&gt;
Chistian Sciberras.&lt;br&gt;
&lt;br&gt;
2010/2/8 Larry Seltzer &amp;lt;larry () larryseltzer com&amp;gt;:&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 16:14:47 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/132</guid>
  </item>
  <item>
    <title>Re: about jit and dep+aslr</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/131</link>
    <description>&lt;p&gt;Posted by Larry Seltzer on Feb 08&lt;/p&gt;Google translates this as “Sun your mother!”&lt;br&gt;
&lt;br&gt;
Larry Seltzer&lt;br&gt;
Contributing Editor, PC Magazine&lt;br&gt;
&lt;br&gt;
larry_seltzer () ziffdavis com &lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://blogs.pcmag.com/securitywatch/&quot;&gt;http://blogs.pcmag.com/securitywatch/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
From: full-disclosure-bounces () lists grok org uk [&lt;a  rel=&quot;nofollow&quot; href=&quot;mailto:full-disclosure-bounces&quot;&gt;mailto:full-disclosure-bounces&lt;/a&gt; () lists grok org uk] On Behalf Of &lt;br&gt;
yuange&lt;br&gt;
Sent: Monday, February 08, 2010 10:30 AM&lt;br&gt;
To: vpn.1.fanatic () gmail com; charles.skoglund () bitsec se&lt;br&gt;
Cc: full-disclosure&lt;br&gt;
Subject: Re: [Full-disclosure]...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 16:02:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/131</guid>
  </item>
  <item>
    <title>Re: about jit and dep+aslr</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/130</link>
    <description>&lt;p&gt;Posted by yuange on Feb 08&lt;/p&gt;   太阳你妈妈!&lt;br&gt;
&lt;br&gt;
Date: Mon, 8 Feb 2010 14:48:06 +1100&lt;br&gt;
Subject: Re: [Full-disclosure] about jit and dep+aslr&lt;br&gt;
From: vpn.1.fanatic () gmail com&lt;br&gt;
To: charles.skoglund () bitsec se&lt;br&gt;
CC: yuange1975 () hotmail com; ravi.borgaonkar () gmail com; full-disclosure () lists grok org uk&lt;br&gt;
&lt;br&gt;
No u.&lt;br&gt;
&lt;br&gt;
Yuange - opt out you useless dogshit.&lt;br&gt;
&lt;br&gt;
2010/2/5 Charles Skoglund &amp;lt;charles.skoglund () bitsec se&amp;gt;&lt;br&gt;
&lt;br&gt;
Ravi stop being a douchebag&lt;br&gt;
&lt;br&gt;
My native language is not...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 15:35:05 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/130</guid>
  </item>
  <item>
    <title>[Hacking Event] Night Da Hack 2010 : Call For	Proposals</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/129</link>
    <description>&lt;p&gt;Posted by m . mahdjoub on Feb 08&lt;/p&gt;- Night Da Hack 2010&lt;br&gt;
&lt;br&gt;
Date: June 19-20 2010&lt;br&gt;
Time: 4 PM - 7 AM&lt;br&gt;
Location: Paris, France&lt;br&gt;
&lt;br&gt;
What is Night da Hack? &lt;br&gt;
“Night da Hack” comes from a rough translation from French “Nuit du Hack”. Started in 2003 by Hackerz Voice team, and &lt;br&gt;
inspired by world famous DEF CON, “Nuit du Hack” is one of the oldest French underground hacking conference.&lt;br&gt;
&lt;br&gt;
Around computer security related talks, workshops and contests, Night da Hack aims at bringing...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 13:49:30 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/129</guid>
  </item>
  <item>
    <title>CORELAN-10-010 - GeFest Web HomeServer v1.0 Remote Directory Traversal Vulnerability</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/128</link>
    <description>&lt;p&gt;Posted by Security on Feb 08&lt;/p&gt;|------------------------------------------------------------------|&lt;br&gt;
|                         __               __                      |&lt;br&gt;
|   _________  ________  / /___ _____     / /____  ____ _____ ___  |&lt;br&gt;
|  / ___/ __ \/ ___/ _ \/ / __ `/ __ \   / __/ _ \/ __ `/ __ `__ \ |&lt;br&gt;
| / /__/ /_/ / /  /  __/ / /_/ / / / /  / /_/  __/ /_/ / / / / / / |&lt;br&gt;
| \___/\____/_/   \___/_/\__,_/_/ /_/   \__/\___/\__,_/_/ /_/ /_/  |&lt;br&gt;
|...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 13:36:19 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/128</guid>
  </item>
  <item>
    <title>Re: Samba Remote Zero-Day Exploit</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/127</link>
    <description>&lt;p&gt;Posted by Stefan Kanthak on Feb 08&lt;/p&gt;Dan Kaminsky wrote on February 06, 2010 6:43 PM:&lt;br&gt;
&lt;br&gt;
OUCH!&lt;br&gt;
No, creating junctions (as well as the Vista introduced symlinks)&lt;br&gt;
DOESN'T need admin rights!&lt;br&gt;
&lt;br&gt;
[snip]&lt;br&gt;
&lt;br&gt;
Stefan&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 10:22:13 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/127</guid>
  </item>
  <item>
    <title>The true power of cache</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/126</link>
    <description>&lt;p&gt;Posted by MustLive on Feb 08&lt;/p&gt;Hello participants of Full-Disclosure!&lt;br&gt;
&lt;br&gt;
As I wrote in January in my article The true power of cache&lt;br&gt;
(&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.webappsec.org/lists/websecurity/archive/2010-02/msg00024.html&quot;&gt;http://www.webappsec.org/lists/websecurity/archive/2010-02/msg00024.html&lt;/a&gt;),&lt;br&gt;
the cache of search engines can be useful tool in skilful hands. There are&lt;br&gt;
many possibilities of using of cache for hackers.&lt;br&gt;
&lt;br&gt;
Possibilities of cache of search engines:&lt;br&gt;
&lt;br&gt;
1. Search for vulnerabilities of the site in cache.&lt;br&gt;
2. Search for vulnerabilities of the site in snippet....&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 10:07:59 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/126</guid>
  </item>
  <item>
    <title>Vulnerability in Tagcloud for DataLife Engine</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/125</link>
    <description>&lt;p&gt;Posted by MustLive on Feb 08&lt;/p&gt;Hello Full-Disclosure!&lt;br&gt;
&lt;br&gt;
I want to warn you about Cross-Site Scripting vulnerability in Tagcloud&lt;br&gt;
plugin for DataLife Engine (DLE). Which I found at 07.01.2010.&lt;br&gt;
&lt;br&gt;
It is similar to XSS vulnerability in 3D Cloud for Joomla&lt;br&gt;
(&lt;a  rel=&quot;nofollow&quot; href=&quot;http://websecurity.com.ua/3883/&quot;&gt;http://websecurity.com.ua/3883/&lt;/a&gt;). About millions of flash files&lt;br&gt;
tagcloud.swf which are vulnerable to XSS attacks I mentioned in my article&lt;br&gt;
XSS vulnerabilities in 34 millions flash files&lt;br&gt;
(...&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 10:06:40 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/125</guid>
  </item>
  <item>
    <title>XSS vulnerability in NEW orkut.</title>
    <link>http://seclists.org/fulldisclosure/2010/Feb/124</link>
    <description>&lt;p&gt;Posted by sachin shinde on Feb 08&lt;/p&gt;hi,&lt;br&gt;
&lt;br&gt;
XSS is present in NEW orkut(NEW only) profile page under &amp;quot;cuisines&amp;quot; text.&lt;br&gt;
please see attached image.&lt;br&gt;
&lt;br&gt;
regards,&lt;br&gt;</description>
    <pubDate>Mon, 08 Feb 2010 09:33:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2010/Feb/124</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
