<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>A &lt;a href=&quot;http://seclists.org/fulldisclosure/2010/Mar/459&quot;&gt;lightly moderated&lt;/a&gt; high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately, most of the posts are worthless drivel, so finding the gems takes patience.</description>
    <pubDate>Wed, 16 May 2012 16:30:10 GMT</pubDate>
    <lastBuildDate>Wed, 16 May 2012 16:30:10 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: The story of the Linux kernel 3.x...</title>
    <link>http://seclists.org/fulldisclosure/2012/May/142</link>
    <description>&lt;p&gt;Posted by Tavis Ormandy on May 16&lt;/p&gt;Adam Zabrocki &amp;lt;pi3 () pi3 com pl&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
You must be doing something unusual, are these stock kernels?&lt;br&gt;
&lt;br&gt;
Those distributions all have good security teams who certainly understand&lt;br&gt;
what CONFIG_COMPAT_VDSO does, and would not enable it.&lt;br&gt;
&lt;br&gt;
Tavis.&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 16:27:03 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/142</guid>
  </item>
  <item>
    <title>Re: Trigerring Java code from a SVG image</title>
    <link>http://seclists.org/fulldisclosure/2012/May/141</link>
    <description>&lt;p&gt;Posted by Nicolas Grégoire on May 16&lt;/p&gt;Agreed. Uploading a SVG chameleon (SVG file triggering a XSLT&lt;br&gt;
transformation) to a website allows to display nearly arbitrary content&lt;br&gt;
if the file is called directly. This is similar to the WXR upload&lt;br&gt;
feature abused by the MSVR team in order to XSS the Wordpress.com&lt;br&gt;
website (as presented at 27C3).&lt;br&gt;
&lt;br&gt;
Mario&amp;apos;s research have shown some weird behavior in Opera. There&amp;apos;s an&lt;br&gt;
online demo of SVG files loaded via &amp;lt;img&amp;gt; and starting some...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 14:55:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/141</guid>
  </item>
  <item>
    <title>Video tutorial: Stack-Based Buffer Overflow</title>
    <link>http://seclists.org/fulldisclosure/2012/May/140</link>
    <description>&lt;p&gt;Posted by Juan Sacco on May 16&lt;/p&gt;I&amp;apos;ve made a video  tutorial about buffer overflows take a look and share it&lt;br&gt;
if you like it!&lt;br&gt;
&lt;br&gt;
Video tutorial: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.youtube.com/watch?v=yPKCSXK8ZYo&quot;&gt;http://www.youtube.com/watch?v=yPKCSXK8ZYo&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
Enjoy!&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 14:41:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/140</guid>
  </item>
  <item>
    <title>Re: Trigerring Java code from a SVG image</title>
    <link>http://seclists.org/fulldisclosure/2012/May/139</link>
    <description>&lt;p&gt;Posted by Krzysztof Kotowicz on May 16&lt;/p&gt;Kind of. You can still do some stuff from &amp;lt;img&amp;gt; in Opera.&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://kotowicz.net/opera/&quot;&gt;http://kotowicz.net/opera/&lt;/a&gt;&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 14:39:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/139</guid>
  </item>
  <item>
    <title>Re: The story of the Linux kernel 3.x...</title>
    <link>http://seclists.org/fulldisclosure/2012/May/138</link>
    <description>&lt;p&gt;Posted by Adam Zabrocki on May 16&lt;/p&gt;Hi Tavis,&lt;br&gt;
&lt;br&gt;
I&amp;apos;ve checked with the same result:&lt;br&gt;
&lt;br&gt;
*) Fedora 16&lt;br&gt;
*) latest Ubuntu&lt;br&gt;
*) latest Suse&lt;br&gt;
&lt;br&gt;
Best regards,&lt;br&gt;
Adam Zabrocki&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 14:36:54 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/138</guid>
  </item>
  <item>
    <title>[PRE-SA-2012-03] Linux kernel: Buffer overflow in	HFS plus filesystem</title>
    <link>http://seclists.org/fulldisclosure/2012/May/137</link>
    <description>&lt;p&gt;Posted by Timo Warns on May 16&lt;/p&gt;PRE-CERT Security Advisory&lt;br&gt;
==========================&lt;br&gt;
&lt;br&gt;
* Advisory: PRE-SA-2012-03&lt;br&gt;
* Released on: 10 May 2012&lt;br&gt;
* Affected product: Linux Kernel 3.3.x &amp;lt;= 3.3.4&lt;br&gt;
                                 2.6.x &amp;lt;= 2.6.35.13&lt;br&gt;
* Impact: code execution / privilege escalation&lt;br&gt;
* Origin: HFS plus file system&lt;br&gt;
* Credit: Timo Warns (PRESENSE Technologies GmbH)&lt;br&gt;
* CVE Identifier: CVE-2012-2319&lt;br&gt;
&lt;br&gt;
Summary&lt;br&gt;
-------&lt;br&gt;
&lt;br&gt;
The Linux kernel contains a vulnerability in the driver...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 14:04:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/137</guid>
  </item>
  <item>
    <title>Re: Trigerring Java code from a SVG image</title>
    <link>http://seclists.org/fulldisclosure/2012/May/136</link>
    <description>&lt;p&gt;Posted by Dan Kaminsky on May 16&lt;/p&gt;Anything from &amp;lt;img&amp;gt; in any browser?&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 10:31:20 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/136</guid>
  </item>
  <item>
    <title>Re: The story of the Linux kernel 3.x...</title>
    <link>http://seclists.org/fulldisclosure/2012/May/135</link>
    <description>&lt;p&gt;Posted by Tavis Ormandy on May 16&lt;/p&gt;Adam Zabrocki &amp;lt;pi3 () pi3 com pl&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
You must be using CONFIG_COMPAT_VDSO, it&amp;apos;s rarely used unless you need&lt;br&gt;
compatibility with an ancient libc that was released during the narrow&lt;br&gt;
window where the vdso was mapped at a static location.&lt;br&gt;
&lt;br&gt;
Any libc released since ~2006 would never need it, and will determine the&lt;br&gt;
vdso location at runtime from auxv.&lt;br&gt;
&lt;br&gt;
If any distribution ships a kernel with this option enabled, then you&amp;apos;ve&lt;br&gt;
found a...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:53:39 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/135</guid>
  </item>
  <item>
    <title>Re: Trigerring Java code from a SVG image</title>
    <link>http://seclists.org/fulldisclosure/2012/May/134</link>
    <description>&lt;p&gt;Posted by Michele Orru on May 16&lt;/p&gt;Mario Heiderich did a lot of research on that, he found so many bugs&lt;br&gt;
that allowed&lt;br&gt;
to embed Javascript in SVG images.&lt;br&gt;
&lt;br&gt;
Nice stuff Nick btw,&lt;br&gt;
&lt;br&gt;
Cheers&lt;br&gt;
antisnatchor&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:25:49 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/134</guid>
  </item>
  <item>
    <title>Re: Trigerring Java code from a SVG image</title>
    <link>http://seclists.org/fulldisclosure/2012/May/133</link>
    <description>&lt;p&gt;Posted by Dan Kaminsky on May 16&lt;/p&gt;Yeah, there&amp;apos;s a bunch of wild stuff in SVG.  The browsers ignore most of&lt;br&gt;
it, AFAIK.  I think Firefox is the only browser to even consider&lt;br&gt;
ForeignObjects (which let you throw HTML back into SVG).&lt;br&gt;
&lt;br&gt;
Probably the most interesting SVG thing is how they either do or don&amp;apos;t have&lt;br&gt;
script access, depending on whether or not they&amp;apos;re loaded as &amp;lt;img&amp;gt;&amp;apos;s.  It&lt;br&gt;
would be problematic indeed if &amp;lt;img src=&amp;quot;foo.jpg&amp;quot;&amp;gt; could...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:13:29 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/133</guid>
  </item>
  <item>
    <title>JW player xss security flaw</title>
    <link>http://seclists.org/fulldisclosure/2012/May/132</link>
    <description>&lt;p&gt;Posted by WooYun on May 16&lt;/p&gt;&amp;quot;LongTail Video is a New York-based startup that has pioneered the web&lt;br&gt;
video market. Our flagship product the - JW Player - is active on over&lt;br&gt;
one million websites and streams billions of videos each month.&amp;quot;&lt;br&gt;
&lt;br&gt;
Someone has reported a xss security flaw of JW Player on wooyun,much&lt;br&gt;
more information here:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wooyun.org/bugs/wooyun-2010-07166&quot;&gt;http://www.wooyun.org/bugs/wooyun-2010-07166&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
from: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.wooyun.org/whitehats/gainover&quot;&gt;http://www.wooyun.org/whitehats/gainover&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
a example here:...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:07:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/132</guid>
  </item>
  <item>
    <title>struts csrf token bypass</title>
    <link>http://seclists.org/fulldisclosure/2012/May/131</link>
    <description>&lt;p&gt;Posted by WooYun on May 16&lt;/p&gt;hi&lt;br&gt;
&lt;br&gt;
someone report a security flaw of struts on wooyun,it allow you bypass&lt;br&gt;
the struts&amp;apos;s csrf protection without XSS&lt;br&gt;
&lt;br&gt;
much more information here:&lt;br&gt;
&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://zone.wooyun.org/content/205&quot;&gt;http://zone.wooyun.org/content/205&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
:)&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:05:22 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/131</guid>
  </item>
  <item>
    <title>The story of the Linux kernel 3.x...</title>
    <link>http://seclists.org/fulldisclosure/2012/May/130</link>
    <description>&lt;p&gt;Posted by Adam Zabrocki on May 16&lt;/p&gt;The story of the Linux kernel 3.x...&lt;br&gt;
&lt;br&gt;
In 2005 everybody was exited about possibility of bypass ASLR on all&lt;br&gt;
Linux 2.6 kernels because of the new concept called VDSO (Virtual&lt;br&gt;
Dynamic Shared Object). More information about this story can be found&lt;br&gt;
at the following link:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.trilithium.com/johan/2005/08/linux-gate/&quot;&gt;http://www.trilithium.com/johan/2005/08/linux-gate/&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
In short, VDSO was mmap&amp;apos;ed by the kernel in the user space memory always&lt;br&gt;
at the same fixed address. Because of that...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:03:52 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/130</guid>
  </item>
  <item>
    <title>SEC-T 2012 CFP and Challenge</title>
    <link>http://seclists.org/fulldisclosure/2012/May/129</link>
    <description>&lt;p&gt;Posted by olle on May 16&lt;/p&gt;TL;DR&lt;br&gt;
Submit here: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://sec-t.org/2012/cfp.html&quot;&gt;http://sec-t.org/2012/cfp.html&lt;/a&gt;&lt;br&gt;
Crack this: &lt;a  rel=&quot;nofollow&quot; href=&quot;http://youtu.be/rMqZW0fFThc&quot;&gt;http://youtu.be/rMqZW0fFThc&lt;/a&gt;&lt;br&gt;
TL;DR&lt;br&gt;
&lt;br&gt;
CFP for the 5th annual SEC-T conference in Stockholm, Sweden is open!&lt;br&gt;
This year the conference is held on the 13th and 14th of September.&lt;br&gt;
&lt;br&gt;
Don&amp;apos;t forget to try your hand at the challenge, this year harder than&lt;br&gt;
ever and produced in cooperation with the one and only Fairlight crew.&lt;br&gt;
Winner gets a free ticket to the conference and infinite glory!!!11...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:02:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/129</guid>
  </item>
  <item>
    <title>Trigerring Java code from a SVG image</title>
    <link>http://seclists.org/fulldisclosure/2012/May/128</link>
    <description>&lt;p&gt;Posted by Nicolas Grégoire on May 16&lt;/p&gt;Hello,&lt;br&gt;
&lt;br&gt;
SVG is a XML-based file format for static or animated images. Some SVG&lt;br&gt;
specifications (like  SVG 1.1 and SVG Tiny 1.2) allow to trigger some&lt;br&gt;
Java code when the SVG file is opened.&lt;br&gt;
&lt;br&gt;
Given that I had to look at these features for a customer, I developed&lt;br&gt;
some PoC codes which are now available online:&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.agarri.fr/docs/batik-evil.svg&quot;&gt;http://www.agarri.fr/docs/batik-evil.svg&lt;/a&gt;&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.agarri.fr/docs/batik-evil.jar&quot;&gt;http://www.agarri.fr/docs/batik-evil.jar&lt;/a&gt;&lt;br&gt;
&lt;br&gt;
I published a more detailed article on my blog:...&lt;br&gt;</description>
    <pubDate>Wed, 16 May 2012 09:00:46 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2012/May/128</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>

