<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Full Disclosure (fulldisclosure) Mailing List</title>
<link>http://seclists.org/#fulldisclosure</link>
<atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
<description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Iceman.Ro - new botnet to come</title><description>Posted by John Doe on Jul 3&lt;p&gt;


&lt;p&gt;
18:13 -!- IceMan` [~bb_at_IceMan&amp;#46;ro] has joined #root
&lt;br /&gt;
18:13 &amp;lt; pink_panther&amp;gt; Hello, friend
&lt;br /&gt;
18:13 &amp;lt; IceMan`&amp;gt; uh :)))))
&lt;br /&gt;
18:13 &amp;lt; pink_panther&amp;gt; We were just talking about you
&lt;br /&gt;
18:13 &amp;lt; L&amp;gt; hi there
&lt;br /&gt;
18:13 &amp;lt; IceMan`&amp;gt; eh i must close this ircd 2
&lt;br /&gt;
18:13 &amp;lt; IceMan`&amp;gt;...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0026.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0026.html</guid>
<pubDate>Fri, 3 Jul 2009 18:26:01 +0200</pubDate></item>
<item><title>[SECURITY] [DSA 1825-1] New nagios2nagios3 packages fix arbitrary code execution</title><description>Posted by Nico Golde on Jul 3&lt;p&gt;


&lt;p&gt;
&lt;p&gt;--------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA-1825-1                    security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                                 Nico Golde
&lt;br /&gt;
July 3rd, 2009                          ...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0025.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0025.html</guid>
<pubDate>Fri, 3 Jul 2009 17:46:14 +0200</pubDate></item>
<item><title>Re:  radware AppWall Web Application Firewall: Source code disclosure on management interface</title><description>Posted by Vladimir 3APA3A Dubrovin on Jul 3&lt;p&gt;


&lt;p&gt;
Dear Shaked  Vax,
&lt;br /&gt;
&lt;p&gt;&amp;nbsp;Are  you  sure  Radware  Team have analysed reflected attack via user&#39;s
&lt;br /&gt;
&amp;nbsp;browser  (AppWall  administrator visits malcrafted page, page redirects
&lt;br /&gt;
&amp;nbsp;his request to AppWall) before excluding remote vector?
&lt;br /&gt;
&lt;p&gt;--Thursday, July 2, 2009, 3:23:16 PM, you wrote to...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0024.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0024.html</guid>
<pubDate>Fri, 3 Jul 2009 16:58:13 +0400</pubDate></item>
<item><title>a simple race condition and how youd solve it</title><description>Posted by Gadi Evron on Jul 03&lt;p&gt;


&lt;p&gt;
A friend recently demonstrated on his blog a simple race condition he 
&lt;br /&gt;
encountered. He also challenged folks to solve the problem.
&lt;br /&gt;
&lt;p&gt;http://www.algorithm.co.il/blogs/index.php/programming/a-simple-race-condition/
&lt;br /&gt;
&lt;p&gt;There&#39;s an interesting discussion in the comments which is worth a quick 
&lt;br /&gt;
read.
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0023.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0023.html</guid>
<pubDate>Fri, 03 Jul 2009 03:25:23 +0300</pubDate></item>
<item><title>CVE-2008-3531</title><description>Posted by Patroklos Argyroudis on Jul 2&lt;p&gt;


&lt;p&gt;
/* 
&lt;br /&gt;
&amp;nbsp;* cve-2008-3531.c -- Patroklos Argyroudis, argp at domain census-labs.com
&lt;br /&gt;
&amp;nbsp;*
&lt;br /&gt;
&amp;nbsp;* Privilege escalation exploit for the FreeBSD-SA-08:08.nmount
&lt;br /&gt;
&amp;nbsp;* (CVE-2008-3531) vulnerability:
&lt;br /&gt;
&amp;nbsp;* 
&lt;br /&gt;
&amp;nbsp;* http://security.freebsd.org/advisories/FreeBSD-SA-08:08.nmount.asc
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0022.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0022.html</guid>
<pubDate>Thu, 2 Jul 2009 23:51:42 +0300</pubDate></item>
<item><title>phpMyAdmin exploited in masses</title><description>Posted by John Doe on Jul 3&lt;p&gt;


&lt;p&gt;
Hi.
&lt;br /&gt;
&lt;p&gt;Disclosing out of boredom and for the crawlers to archive.
&lt;br /&gt;
&lt;p&gt;Keywords: phpmyadmin, web, exploit, zavod, devitalia, mwstudio, szervernet,
&lt;br /&gt;
infotel, oodrive, iceman, romania, scriptkiddie.
&lt;br /&gt;
&lt;p&gt;An example of the phpmyadmin exploit used in masses without thinking.
&lt;br /&gt;
&lt;p&gt;IRC server: irc10.iceman.ro has...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0021.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0021.html</guid>
<pubDate>Fri, 3 Jul 2009 13:49:52 +0200</pubDate></item>
<item><title>One Click Ownage [White Paper and Scripts]</title><description>Posted by Ferruh Mavituna on Jul 3&lt;p&gt;


&lt;p&gt;
This is a different and more practical approach to get a reverse shell
&lt;br /&gt;
or code execution in SQL Injections (particularly in MSSQL). The idea
&lt;br /&gt;
is simple. Getting a reverse shell from an SQL Injection with one HTTP
&lt;br /&gt;
request without using an extra channel such as TFTP, FTP to upload the
&lt;br /&gt;
initial...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0020.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0020.html</guid>
<pubDate>Fri, 3 Jul 2009 11:50:50 +0100</pubDate></item>
<item><title>Re:  [Code-Crunchers] a simple race condition and how youd solve it</title><description>Posted by Phani on Jul 3&lt;p&gt;


&lt;p&gt;
I may be seriously wrong here; But how about implementing a simple bool
&lt;br /&gt;
cache as a check for cache result computation.
&lt;br /&gt;
&lt;p&gt;result = cache.select(input)
&lt;br /&gt;
if result:
&lt;br /&gt;
&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;return result
&lt;br /&gt;
resultcompute = cache.select(resultcompute)
&lt;br /&gt;
if (resultcompute == true) {
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0019.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0019.html</guid>
<pubDate>Fri, 3 Jul 2009 09:34:37 +0530</pubDate></item>
<item><title>Re:  [Code-Crunchers] a simple race condition and how youd solve it</title><description>Posted by Valdis.Kletnieks_at_vt.edu on Jul 02&lt;p&gt;


&lt;p&gt;
On Fri, 03 Jul 2009 11:01:34 +1000, silky said:
&lt;br /&gt;
&lt;p&gt;&amp;gt; Basically, you just need to check if you should still be computing,
&lt;br /&gt;
&amp;gt; and, at the end of computation, if your data is still &amp;quot;wanted&amp;quot;.
&lt;br /&gt;
&lt;p&gt;All that does is push the race condition around.  You *still* need to
&lt;br /&gt;
do some sort of locking...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0018.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0018.html</guid>
<pubDate>Thu, 02 Jul 2009 22:04:26 -0400</pubDate></item>
<item><title>Re:  [Code-Crunchers] a simple race condition and how youd solve it</title><description>Posted by silky on Jul 3&lt;p&gt;


&lt;p&gt;
On Fri, Jul 3, 2009 at 10:25 AM, Gadi Evron&amp;lt;ge_at_linuxbox&amp;#46;org&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; A friend recently demonstrated on his blog a simple race condition he
&lt;br /&gt;
&amp;gt; encountered. He also challenged folks to solve the problem.
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; ...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0017.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0017.html</guid>
<pubDate>Fri, 3 Jul 2009 11:01:34 +1000</pubDate></item>
<item><title>Soulseek 157 NS lt 13e amp 156.* Remote Direct Peer Search Code Execution</title><description>Posted by laurent gaffie on Jul 2&lt;p&gt;


&lt;p&gt;
Soulseek 157 NS &amp;lt; 13e &amp;amp; 156.* Remote Peer Search Code Execution
&lt;br /&gt;
=============================================
&lt;br /&gt;
- Release date: July 02, 2009
&lt;br /&gt;
- Discovered by: Laurent Gaffié ; http://g-laurent.blogspot.com/
&lt;br /&gt;
- Severity: critical
&lt;br /&gt;
=============================================
&lt;br /&gt;
&lt;p&gt;I....</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0016.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0016.html</guid>
<pubDate>Thu, 2 Jul 2009 20:27:59 -0400</pubDate></item>
<item><title>[ GLSA 200907-01 ] libwmf: User-assisted execution of arbitrary code</title><description>Posted by Alex Legler on Jul 02&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200907-01
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0015.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0015.html</guid>
<pubDate>Thu, 02 Jul 2009 21:36:57 +0200</pubDate></item>
<item><title>[ GLSA 200907-02 ] ModSecurity: Denial of Service</title><description>Posted by Alex Legler on Jul 02&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200907-02
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0014.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0014.html</guid>
<pubDate>Thu, 02 Jul 2009 21:38:32 +0200</pubDate></item>
<item><title>[USN-795-1] Nagios vulnerability</title><description>Posted by Marc Deslauriers on Jul 02&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-795-1              July 02, 2009
&lt;br /&gt;
nagios2, nagios3 vulnerability
&lt;br /&gt;
CVE-2009-2288
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following Ubuntu releases:
&lt;br /&gt;
&lt;p&gt;Ubuntu...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0013.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0013.html</guid>
<pubDate>Thu, 02 Jul 2009 14:29:06 -0400</pubDate></item>
<item><title>[USN-794-1] Perl vulnerability</title><description>Posted by Marc Deslauriers on Jul 02&lt;p&gt;


&lt;p&gt;
===========================================================
&lt;br /&gt;
Ubuntu Security Notice USN-794-1              July 02, 2009
&lt;br /&gt;
libcompress-raw-zlib-perl, perl vulnerability
&lt;br /&gt;
CVE-2009-1391
&lt;br /&gt;
===========================================================
&lt;br /&gt;
&lt;p&gt;A security issue affects the following Ubuntu...</description>
<link>http://seclists.org/fulldisclosure/2009/Jul/0012.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Jul/0012.html</guid>
<pubDate>Thu, 02 Jul 2009 14:27:30 -0400</pubDate></item>
</channel></rss>