Full Disclosure: by author

213 messages starting May 29 14 and ending May 15 14
Date index | Thread index | Author index


Alberto Guglielmo

Re: TrueCrypt Alberto Guglielmo (May 29)

Alexander Lashkov

Registration for PHDays Online Competitions is Now Open Alexander Lashkov (May 09)

Alexandre Herzog

JavaMail SMTP Header Injection via method setSubject [CSNC-2014-001] Alexandre Herzog (May 19)

Alfie John

Re: TrueCrypt? Alfie John (May 30)

Allen D

Re: US cybercrime laws being used to target security researchers | Technology | The Guardian Allen D (May 30)

Alton Blom

Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Alton Blom (May 01)

Andrew Case

The 2014 Volatility Plugin Contest is now live! Andrew Case (May 29)

Anthony Fontanez

TrueCrypt? Anthony Fontanez (May 29)
FW: All of .mil tld is down Anthony Fontanez (May 19)

Barkley, Peter

Re: TrueCrypt? Barkley, Peter (May 29)

Ben Campbell

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Ben Campbell (May 21)

Bogdan-Stefan Rotariu

Re: What do you think of Trollc? Bogdan-Stefan Rotariu (May 28)

Brandon Perry

Re: [KIS-2014-06] Dotclear <= 2.6.2 (Media Manager) Unrestricted File Upload Vulnerability Brandon Perry (May 21)
Re: TrueCrypt 7.1 repos on GitHub - forking starting point Brandon Perry (May 30)
Re: What do you think of Trollc? Brandon Perry (May 28)
Moar F5 fun in iControl API Brandon Perry (May 07)
A small project: metafang Brandon Perry (May 09)
HP Release Control Authenticated Privilege Escalation and XXE Brandon Perry (May 16)
Re: What do you think of Trollc? Brandon Perry (May 27)
F5 BIG-IQ authed arbitrary user password change Brandon Perry (May 01)
Re: F5 BIG-IQ authed arbitrary user password change Brandon Perry (May 02)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Brandon Perry (May 01)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Brandon Perry (May 01)

Brandon Vincent

Re: OpenSSH Vulnerabilities Brandon Vincent (May 06)

Brian M. Waters

Re: What do you think of Trollc? Brian M. Waters (May 29)

Christian Mayer

Re: A way to trigger CVE-2014-1322 (userspace read kernel pointer)? Christian Mayer (May 20)

CIURANA EUGENE (pr3d4t0r - Full Disclosure)

Full disk encryption for OS X alternative to TrueCrypt CIURANA EUGENE (pr3d4t0r - Full Disclosure) (May 29)
Re: Full disk encryption for OS X alternative to TrueCrypt CIURANA EUGENE (pr3d4t0r - Full Disclosure) (May 29)
Re: Full disk encryption for OS X alternative to TrueCrypt CIURANA EUGENE (pr3d4t0r - Full Disclosure) (May 29)
Re: TrueCrypt? CIURANA EUGENE (pr3d4t0r - Full Disclosure) (May 29)
Re: Full disk encryption for OS X alternative to TrueCrypt CIURANA EUGENE (pr3d4t0r - Full Disclosure) (May 29)
TrueCrypt 7.1 repos on GitHub - forking starting point CIURANA EUGENE (pr3d4t0r - Full Disclosure) (May 30)

coderaptor

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe coderaptor (May 21)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe coderaptor (May 22)

coderman

pervasive vulnerabilities in offensive mindset - haughty hubris coderman (May 08)
Re: project unicorn exploitable index coderman (May 13)
Re: project unicorn exploitable index coderman (May 14)

Curesec Research Team

Heartbleed client side analysis tool published Curesec Research Team (May 05)

Daniel Wood

Re: So You Like Pain and Vulnerability Management? New Article. Daniel Wood (May 14)

Dave Warren

Re: Discussion: Teamviewer "Feature" or "Bug"? Dave Warren (May 08)

Dawid Golunski

check_dhcp - Nagios Plugins <= 2.0.1 Arbitrary Option File Read Dawid Golunski (May 15)

Dennis E. Hamilton

Re: TrueCrypt? Dennis E. Hamilton (May 29)

devel

OpenSSH Vulnerabilities devel (May 06)
Re: OpenSSH Vulnerabilities devel (May 06)

Dolev Farhi

Cobbler Arbitrary File Read CVE-2014-3225 Dolev Farhi (May 14)
FD - Multiple stored XSS in FOG imaging deployment system CVE-2014-3111 Dolev Farhi (May 14)

Edge

[CVE-2014-3749] Construtiva CIS Manager CMS POST SQLi Edge (May 15)

Egidio Romano

[KIS-2014-06] Dotclear <= 2.6.2 (Media Manager) Unrestricted File Upload Vulnerability Egidio Romano (May 21)
[KIS-2014-05] Dotclear <= 2.6.2 (XML-RPC Interface) Authentication Bypass Vulnerability Egidio Romano (May 21)
[KIS-2014-07] Dotclear <= 2.6.2 (categories.php) SQL Injection Vulnerability Egidio Romano (May 21)
Re: [KIS-2014-06] Dotclear <= 2.6.2 (Media Manager) Unrestricted File Upload Vulnerability Egidio Romano (May 22)

feer james

CVE Request ---- SOAPpy 0.12.5 Multiple Vulnerabilities feer james (May 05)

Felipe Daragon

Lua Web Application Security Vulnerabilities Felipe Daragon (May 26)

Henri Salo

TrueCrypt Henri Salo (May 29)

HHeilemann

Discussion: Teamviewer "Feature" or "Bug"? HHeilemann (May 08)

Inokii Security Advisory

Information Exposure via SNMP on ARRIS / Motorola SBG6580 Cable Modem Gateway Inokii Security Advisory (May 18)

Ivan .Heca

US cybercrime laws being used to target security researchers | Technology | The Guardian Ivan .Heca (May 29)

James Healy

Re: TrueCrypt? James Healy (May 29)

James Lay

Re: Full disk encryption for OS X alternative to TrueCrypt James Lay (May 29)

James Renken

SSH key cloning problem in OnApp templates James Renken (May 08)

Jeff Costlow

Re: F5 BIG-IQ authed arbitrary user password change Jeff Costlow (May 04)

Jeffrey Paul

Re: What do you think of Trollc? Jeffrey Paul (May 29)

Jeffrey Walton

Re: TrueCrypt? Jeffrey Walton (May 29)
Re: Full disk encryption for OS X alternative to TrueCrypt Jeffrey Walton (May 30)
Re: TrueCrypt? Jeffrey Walton (May 30)
Re: What do you think of Trollc? Jeffrey Walton (May 29)
Re: What do you think of Trollc? Jeffrey Walton (May 28)
Re: TrueCrypt? Jeffrey Walton (May 30)
Re: What do you think of Trollc? Jeffrey Walton (May 28)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Jeffrey Walton (May 01)

Jeff Sergeant

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Jeff Sergeant (May 21)

JK

Re: TrueCrypt? JK (May 29)

jkmac

XSS - find.searchhub.org, opencms version9 and others jkmac (May 20)
UPS Web/SNMP-Manager CS121 authentication bypass, credentials leak, ... jkmac (May 15)

Joachim Jakobs

security of the fairphone Joachim Jakobs (May 07)

John Menerick

Re: What do you think of Trollc? John Menerick (May 28)

Joshua Rogers

SQL Injection on eBay subdomain Joshua Rogers (May 24)

Julius Kivimäki

Re: OpenSSH Vulnerabilities Julius Kivimäki (May 06)
Re: What do you think of Trollc? Julius Kivimäki (May 27)

Justin Bull

Re: TrueCrypt? Justin Bull (May 30)
Re: TrueCrypt? Justin Bull (May 29)
OAuth 2.0 and OpenID vulnerable to Covert Redirect Justin Bull (May 02)
Re: TrueCrypt? Justin Bull (May 29)
Re: TrueCrypt 7.1 repos on GitHub - forking starting point Justin Bull (May 30)

Keira Cran

Re: A way to trigger CVE-2014-1322 (userspace read kernel pointer)? Keira Cran (May 21)

Keith I Myers

Re: Discussion: Teamviewer "Feature" or "Bug"? Keith I Myers (May 08)
Re: AirDroid Lock Screen Bypass Keith I Myers (May 15)

laalaa

2 security bugs in Dlink router DIR-605L laalaa (May 20)

laurent gaffie

Microsoft DHCP INFORM Configuration Overwrite laurent gaffie (May 29)

Levi (levi0x0)

sb0x-project 2.0.1rc3 Release Announcement Levi (levi0x0) (May 27)

Levon Kayan

Hyperion PE crypter: new version 1.1 Levon Kayan (May 09)

LSE Leading Security Experts GmbH (Security Advisories)

LSE Leading Security Experts GmbH - LSE-2014-05-21 - Check_MK - Arbitrary File Disclosure Vulnerability LSE Leading Security Experts GmbH (Security Advisories) (May 28)

Lucius Rizzo

Re: OpenSSH Vulnerabilities Lucius Rizzo (May 06)

Mad Hax

Zamfoo Multiple Arbitrary Command Executions Mad Hax (May 02)

Manu Carus

Re: JavaMail SMTP Header Injection via method setSubject [CSNC-2014-001] Manu Carus (May 30)

Mario Vilas

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Mario Vilas (May 21)

Mark Thomas

[SECURITY] CVE-2014-0096 Apache Tomcat information disclosure Mark Thomas (May 27)
[SECURITY] CVE-2014-0097 Apache Tomcat information disclosure Mark Thomas (May 27)
[SECURITY] CVE-2014-0119 Apache Tomcat information disclosure Mark Thomas (May 27)
[SECURITY] CVE-2014-0095 Apache Tomcat denial of service Mark Thomas (May 27)
Re: [SECURITY] CVE-2014-0099 Apache Tomcat information disclosure Mark Thomas (May 27)
[SECURITY] CVE-2014-0075 Apache Tomcat denial of service Mark Thomas (May 27)

Martin Boßlet

Re: Ruby OpenSSL private key spoofing ~ CVE-2014-2734 with PoC Martin Boßlet (May 02)

Martin von Gagern

eInstruction Workspace sudo vulnerability Martin von Gagern (May 14)

Mateusz Lenik

Re: Full disk encryption for OS X alternative to TrueCrypt Mateusz Lenik (May 30)

Matteo Beccati

[REVIVE-SA-2014-001] Revive Adserver 3.0.5 fixes CSRF vulnerability Matteo Beccati (May 15)

Matthew Daley

Re: [oss-security] CVE-2014-0196: Linux kernel pty layer race condition memory corruption Matthew Daley (May 12)
Re: [oss-security] CVE-2014-0196: Linux kernel pty layer race condition memory corruption Matthew Daley (May 12)

Michael Cramer

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Michael Cramer (May 22)
Re: TrueCrypt? Michael Cramer (May 30)
Re: TrueCrypt? Michael Cramer (May 30)

Michael Wisniewski

AirDroid Lock Screen Bypass Michael Wisniewski (May 15)

Michal Zalewski

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Michal Zalewski (May 21)
Re: What do you think of Trollc? Michal Zalewski (May 28)
Re: What do you think of Trollc? Michal Zalewski (May 28)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Michal Zalewski (May 21)
Re: What do you think of Trollc? Michal Zalewski (May 27)
Re: What do you think of Trollc? Michal Zalewski (May 29)

Mike Cramer

Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Mike Cramer (May 01)
Re: TrueCrypt? Mike Cramer (May 29)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Mike Cramer (May 01)
Re: TrueCrypt? Mike Cramer (May 30)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Mike Cramer (May 01)
Re: Full disk encryption for OS X alternative to TrueCrypt Mike Cramer (May 29)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Mike Cramer (May 01)

MustLive

LE, BF and IAA vulnerabilities in Catapulta I.W. Edition MustLive (May 31)
Multiple vulnerabilities in Flexolio for WordPress MustLive (May 04)
Backdoored Web Application v.1.0.1 MustLive (May 30)
CS and XSS vulnerabilities in DZS Video Gallery for WordPress MustLive (May 28)

nkukard+fulldisclosure

Re: Zamfoo Multiple Arbitrary Command Executions nkukard+fulldisclosure (May 04)

Not EcksKaySeeDee

Re: TrueCrypt? Not EcksKaySeeDee (May 31)
Re: TrueCrypt? Not EcksKaySeeDee (May 30)

Pedro Ribeiro

Re: So You Like Pain and Vulnerability Management? New Article. Pedro Ribeiro (May 13)
[CVE-2014-1603] XSS in GetSimple CMS 3.3.1 Pedro Ribeiro (May 12)

Pete Herzog

So You Like Pain and Vulnerability Management? New Article. Pete Herzog (May 12)

Philip Cheong

Re: TrueCrypt? Philip Cheong (May 29)
What do you think of Trollc? Philip Cheong (May 27)
Re: TrueCrypt? Philip Cheong (May 30)

Portcullis Advisories

CVE-2014-3446 - Unauthenticated Blind SQL Injection in BSS Continuity CMS Portcullis Advisories (May 20)
CVE-2014-2046 - Unauthenticated Credential And Configuration Retrieval In Broadcom Ltd PIPA C211 Portcullis Advisories (May 13)
CVE-2014-3449 - Insufficient ACLs in BSS Continuity CMS Portcullis Advisories (May 20)
CVE-2014-3445 - Unauthenticated Backup and Password Disclosure in HandsomeWeb SOS Webpages Portcullis Advisories (May 27)
CVE-2014-3448 - Remote Code Execution Via Unauthenticated File Upload in BSS Continuity CMS Portcullis Advisories (May 20)
CVE-2014-3447 - Remote Denial Of Service in BSS Continuity CMS Portcullis Advisories (May 20)
CVE-2014-3450 - Privilege Escalation in Panda Security Portcullis Advisories (May 20)

Project Un1c0rn

Project Un1c0rn : Communications and GPG Key Project Un1c0rn (May 20)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Project Un1c0rn (May 21)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Project Un1c0rn (May 21)

Prototype This

Re: Discussion: Teamviewer "Feature" or "Bug"? Prototype This (May 08)

rage

rcrypt packer/crypter writeup and POC tool rage (May 21)

rai

Mac OS X stack_chk_guard not always safe from overwrite rai (May 15)
A way to trigger CVE-2014-1322 (userspace read kernel pointer)? rai (May 20)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe rai (May 22)

RedTeam Pentesting GmbH

[RT-SA-2014-003] Metadata Information Disclosure in OrbiTeam BSCW RedTeam Pentesting GmbH (May 08)
[RT-SA-2014-005] SQL Injection in webEdition CMS File Browser Installer Script RedTeam Pentesting GmbH (May 28)
[RT-SA-2014-004] Remote Command Execution in webEdition CMS Installer Script RedTeam Pentesting GmbH (May 28)

Reindl Harald

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Reindl Harald (May 21)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Reindl Harald (May 21)

Roberto Garcia Amoriz

XSS on Vmware Site Roberto Garcia Amoriz (May 27)

Roberto Martelloni

Re: What do you think of Trollc? Roberto Martelloni (May 28)

Ron Gutierrez

CVE-2014-3004 - Castor Library Default Config could lead to XML External Entity (XXE) Attacks Ron Gutierrez (May 27)

Savio Bot

Re: [oss-security] CVE-2014-0196: Linux kernel pty layer race condition memory corruption Savio Bot (May 12)

scadastrangelove

Emerson DeltaV Vulnerabilities/Fixes scadastrangelove (May 26)
Too Smart Grid in da Cloud scadastrangelove (May 05)

Scott Arciszewski

CodeIgniter <= 2.1.4 and Kohana <= 3.2.3, 3.3.2 - Timing Attacks and Object Injection Scott Arciszewski (May 12)
Re: What do you think of Trollc? Scott Arciszewski (May 27)
Re: What do you think of Trollc? Scott Arciszewski (May 29)

SEC Consult Vulnerability Lab

SEC Consult SA-20140508-0 :: Multiple critical vulnerabilities in AVG Remote Administration SEC Consult Vulnerability Lab (May 08)
SEC Consult SA-20140521-0 :: Multiple critical vulnerabilities in CoSoSys Endpoint Protector 4 SEC Consult Vulnerability Lab (May 21)
SEC Consult SA-20140528-0 :: Root Backdoor & Unauthenticated access to voice recordings in NICE Recording eXpress SEC Consult Vulnerability Lab (May 28)

secuip

Re: TrueCrypt? secuip (May 29)

Sergey Shekyan

CVE-2014-1849 Foscam Dynamic DNS predictable credentials vulnerability Sergey Shekyan (May 08)

Sergio Conde Gómez

Re: TrueCrypt? Sergio Conde Gómez (May 29)

Serguei Mokhov

Fwd: Call for papers for SAC 2014 Serguei Mokhov (May 24)

shady.liu

CVE-2014-3719 SQL Injection Vulnerability shady.liu (May 15)
[CVE-2014-3719] ALEPH500 (Integrated library management system) SQL Injection shady.liu (May 15)
Re: [CVE-2014-3719] ALEPH500 (Integrated librarymanagement system) SQL Injection shady.liu (May 18)

Solar Designer

Re: [oss-security] CVE-2014-0196: Linux kernel pty layer race condition memory corruption Solar Designer (May 12)

Stefan Kanthak

Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Stefan Kanthak (May 20)
Defense in depth -- the Microsoft way (part 15): unquoted arguments in 120 (of 462) command lines Stefan Kanthak (May 29)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Stefan Kanthak (May 06)
Beginners error: Piriform's Crap Cleaner^W runs rogue program C:\Program.exe Stefan Kanthak (May 06)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Stefan Kanthak (May 21)
Defense in depth -- the Microsoft way (part 16): our developers and their QA dont follow our own security recommendations Stefan Kanthak (May 31)
How to use the vulnerable flash player plugin installed with Adobe Reader XI (and other Adobe products) Stefan Kanthak (May 29)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Stefan Kanthak (May 01)
Beginners error: Synaptics touchpad driver delivered via Windows Update executes rogue program C:\Program.exe with system privileges during installation Stefan Kanthak (May 08)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Stefan Kanthak (May 21)
Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Stefan Kanthak (May 16)

Stefan Schurtz

reg.ebay.com - Cross-site Scripting vulnerability Stefan Schurtz (May 26)

Tavis Ormandy

Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Tavis Ormandy (May 20)
Windows 8 Touch Injection API doesn't handle memory pressure Tavis Ormandy (May 22)
NULL page mitigations on Windows 8 x86 Tavis Ormandy (May 21)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Tavis Ormandy (May 21)
Re: Beginners error: Hewlett-Packards driver software executes rogue binary C:\Program.exe Tavis Ormandy (May 21)

Thomas Hibbert

Accellion SFTP Satellite Remote Root Code Execution Thomas Hibbert (May 25)

Timothy D. Morgan

XML Schema, DTD, and Entity Attacks: A Compendium of Known Techniques Timothy D. Morgan (May 21)

Tomi Tuominen

t2'14: Call for Papers 2014 (Helsinki / Finland) Tomi Tuominen (May 19)

Tyler Nighswander

Re: OpenSSH Vulnerabilities Tyler Nighswander (May 06)

Ubani Balogun

Drupal Flag 7.x-3.5 Module Vulnerability report: Arbitrary code execution due to improper input handling in flag importer Ubani Balogun (May 09)

uname -a

Re: TrueCrypt? uname -a (May 30)
Re: TrueCrypt? uname -a (May 29)

Vinny Troia

PHP-FPM and PHP-CGI - Denial of Service POC Vinny Troia (May 05)

Vulnerability Lab

Paypal Inc Bug Bounty #109 MOS - Bypass & Persistent Vulnerability Vulnerability Lab (May 14)

Walter Cuestas

Bizagi BPM Suite contains multiple vulnerabilities Walter Cuestas (May 29)

Walt Williams

Re: Beginners error: iTunes for Windows runs rogue program C:\Program.exe when opening associated files Walt Williams (May 01)

William Costa

Fortinet Fortiweb 5.1 contains a cross-site request forgery vulnerability (CVE-2014-3115) William Costa (May 07)
XSS Attacks vulnerability in InterScan Messaging Security Virtual Appliance 8.5.1.1516 (Zero-DAY) William Costa (May 29)

Williams, James K

CA20140413-01: Security Notice for OpenSSL Heartbleed Vulnerability Williams, James K (May 16)

wola4

project unicorn exploitable index wola4 (May 09)
Re: project unicorn exploitable index wola4 (May 13)
Re: project unicorn exploitable index wola4 (May 15)

xxx

CVE-2014-3718] ALEPH500 (Integrated library management system) Cross Site Scripting Vulnerability xxx (May 15)