Andrew Clover | 1 Apr 2004 23:03
Favicon

Re: internet-explorer: bug or feature?

<ko5 <at> hush.com> wrote:

 >   about:<script>alert('*plopp*');</script>

 > a small alert popps up and says me '*plopp*', so it seems, that i can
 > inject any code i want.

Originally reported here:

   http://www.doxdesk.com/personal/posts/bugtraq/20010819-ie.html

This was eventually fixed in IE6 SP1, after it was discovered that due 
to a parsing error this could be abused to execute in the security 
context of any target domain.

 > i am not sure if its what the 'about:'-construct is for

It was just another random pointless feature. IE has a lot of these. 
Sometimes they prove a security liability and very occasionally they get 
removed, but no-one seems to have thought of not including them in the 
first place.

--

-- 
Andrew Clover
mailto:and <at> doxdesk.com
http://www.doxdesk.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html
(Continue reading)

please_reply_to_security | 1 Apr 2004 01:44
Favicon

OpenLinux: util-linux could leak sensitive data


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

			SCO Security Advisory

Subject:		OpenLinux: util-linux could leak sensitive data
Advisory number: 	CSSA-2004-016.0
Issue date: 		2004 March 30
Cross reference:	sr889555 fz528943 erg712558 CAN-2004-0080
______________________________________________________________________________

1. Problem Description

	The login program in util-linux 2.11 and earlier uses a pointer
	after it has been freed and reallocated, which could cause login
	to leak sensitive data. 

	The Common Vulnerabilities and Exposures project (cve.mitre.org) 
	has assigned the name CAN-2004-0080 to this issue.

2. Vulnerable Supported Versions

	System				Package
	----------------------------------------------------------------------
	OpenLinux 3.1.1 Server		prior to util-linux-2.12-1.i386.rpm
	OpenLinux 3.1.1 Workstation	prior to util-linux-2.12-1.i386.rpm

(Continue reading)

please_reply_to_security | 1 Apr 2004 01:44
Favicon

OpenLinux: vim arbitrary commands execution through modelines


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

			SCO Security Advisory

Subject:		OpenLinux: vim arbitrary commands execution through modelines
Advisory number: 	CSSA-2004-015.0
Issue date: 		2004 March 30
Cross reference:	sr889557 fz528946 erg712560 CAN-2002-1377
______________________________________________________________________________

1. Problem Description

	vim 6.0 and 6.1, and possibly other versions, allows attackers
	to execute arbitrary commands using the libcall feature in
	modelines, which are not sandboxed but may be executed when
	vim is used as an editor for other products such as mutt. 
	
	The Common Vulnerabilities and Exposures project (cve.mitre.org)
	has assigned the name CAN-2002-1377 to this issue.

2. Vulnerable Supported Versions

	System				Package
	----------------------------------------------------------------------
	OpenLinux 3.1.1 Server		prior to vim-6.2-1.i386.rpm
					prior to vim-X11-6.2-1.i386.rpm
(Continue reading)

please_reply_to_security | 1 Apr 2004 01:45
Favicon

UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : perl unsafe Safe compartment


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

______________________________________________________________________________

			SCO Security Advisory

Subject:		UnixWare 7.1.3 Open UNIX 8.0.0 UnixWare 7.1.1 : perl unsafe Safe compartment
Advisory number: 	SCOSA-2004.1
Issue date: 		2004 March 29
Cross reference: 	sr887197 fz528449 erg712495 CAN-2002-1323
______________________________________________________________________________

1. Problem Description

	Safe.pm 2.0.7 and earlier, when used in Perl 5.8.0 and
	earlier, may allow attackers to break out of safe compartments
	in (1) Safe::reval or (2) Safe::rdo using a redefined  <at> _
	variable, which is not reset between successive calls. 
	
	The Common Vulnerabilities and Exposures project (cve.mitre.org)
	has assigned the name CAN-2002-1323 to this issue.

2. Vulnerable Supported Versions

	System				Binaries
	----------------------------------------------------------------------
	UnixWare 7.1.3 		/usr/gnu/lib/perl5/i386-svr4/5.00404/Safe.pm	
	Open UNIX 8.0.0 	/usr/gnu/lib/perl5/i386-svr4/5.00404/Safe.pm
(Continue reading)

Tobias Weisserth | 1 Apr 2004 02:10
Picon

Re: Security Hole in HTTP (RFC1945) - Browser-Spoofing

Hi Ron,

Is this a serious question?!
 _     ___  _
| |   / _ \| |
| |  | | | | |
| |__| |_| | |___
|_____\___/|_____|

Am Do, den 01.04.2004 schrieb Ron Stiemer um 00:54:
> Hi List,
> 
> can anybody confirm this, or is it just an april's fool joke ?

Just look at the link (-> in 10 Jahren...).

> http://www.heise.de/security/news/meldung/46175

I'll swallow my mouse (wireless) if this is not an April's fool joke.

> sorry, text is in german

No problem.

regards,
Tobias

--

-- 
***************************************************
   ____  _____
(Continue reading)

Maarten | 1 Apr 2004 01:57

Re: Bugfinder Being Indicted As Criminal ("Counterfeiter") in France

On Wednesday 31 March 2004 22:20, Drew Copley wrote:
> http://www.guillermito2.net/archives/2004_03_25e.html
>
> [thanks to AJ 'Effin' Reznor]
>
> [Disclaimer: I don't know who has seen this already, and I do not
> pretend to know the full facts of the case. -- Drew ]

Yeah, the story hit Slashdot too.  So better be quick, before the server 
succombs to the load of the masses... 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Bruce Martins | 1 Apr 2004 02:32

RE: Addressing Cisco Security Issues

Cisco wouldn't be the first nor the last to do that, with all gear if
you have to buy support to get patches and other software or firmware
updates, but to be fair to Cisco TAC they are normally very helpful and
put you in contact with the right person to help you out. 

-----Original Message-----
From: Jason Dodson [mailto:mindchild <at> yahoo.com] 
Sent: Monday, March 29, 2004 2:36 PM
To: Geo.; full-disclosure <at> lists.netsys.com; bugtraq <at> securityfocus.com
Subject: Re: Addressing Cisco Security Issues

I have had a similar run-around with AT&T Broadband and Sprint a while
back, pertaining to a DoS attack my organization was experiencing. Not
to dive into details, to resolve the issue, I got them both on the line
in a 3-way conversation, and it was taken care of in less then 5
minutes.
They didn't seem to eager to shrug off the responsibility to someone
else, when that someone else was right there on the phone.

Jason Dodson

--- "Geo." <geoincident1 <at> getinfo.org> wrote:
> I have to post this because I consider this to be a security issue in 
> it's own right.
> 
> Recently there were a number of exploits released for cisco equipment,

> among the affected equipment were the 677 and 678 consumer DSL routers

> of which there are millions in use.
(Continue reading)

futureworlds | 1 Apr 2004 02:04
Picon

Re: Bugfinder Being Indicted As Criminal ("Counterfei France

At 12:20 PM 3/31/2004 -0800, Drew Copley wrote:
>http://www.guillermito2.net/archives/2004_03_25e.html

>
>Excerpt:

>...
>
> In march 2002, I published on my website a long analysis about this
>software. This webpage showed how the program worked, demonstrated a few
>security flaws, and some tests with real viruses.

Guillermito is the infamous Vx'er Spanska.

http://groups.google.com/groups?q=spanska+guillermito&hl=en&lr=&ie=UTF-8&oe=UTF-8&tab=ng&sa=N

http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=spanska+guillermito

http://www.google.com/search?hl=en&ie=UTF-8&oe=UTF-8&q=spanska+virus

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html

Ron Stiemer | 1 Apr 2004 03:29
Picon

AW: Security Hole in HTTP (RFC1945) -Browser-Spoofing

Hi,

yes, this was a serious question...
but thanks for you answer :)

ja, stimmt hätte ich selber drauf kommen können, aber man weiß ja nie was
heutzutage so alles im netz passiert...aber den begriff
browser-in-the-middle gibt es anscheinend tatsächlich...sagt zumindest
google...

Gruß,
-Ron

-----Ursprüngliche Nachricht-----
Von: full-disclosure-admin <at> lists.netsys.com
[mailto:full-disclosure-admin <at> lists.netsys.com]Im Auftrag von Tobias
Weisserth
Gesendet: Donnerstag, 1. April 2004 02:11
An: full-disclosure <at> lists.netsys.com
Betreff: Re: [Full-Disclosure] Security Hole in HTTP (RFC1945)
-Browser-Spoofing

Hi Ron,

Is this a serious question?!
 _     ___  _
| |   / _ \| |
| |  | | | | |
| |__| |_| | |___
|_____\___/|_____|
(Continue reading)

Paul Schmehl | 1 Apr 2004 05:24
Favicon

Re: Bugfinder Being Indicted As Criminal ("Counterfeiter") in France

--On Wednesday, March 31, 2004 12:20 PM -0800 Drew Copley 
<dcopley <at> eeye.com> wrote:

> http://www.guillermito2.net/archives/2004_03_25e.html
>
Just one more reason not to travel to France.....

I'm becoming convinced that the EU bureaucrats are determined to stiffle 
the world to death.

Paul Schmehl (pauls <at> utdallas.edu)
Adjunct Information Security Officer
The University of Texas at Dallas
AVIEN Founding Member
http://www.utdallas.edu

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Gmane