HI-TECH . | 1 Oct 2010 02:41

full disclosure my dear (Microsoft IIS 6.0 Denial of Service)

vulnerability description is attached to this email.

/Kingcope

Attachment (Microsoft IIS 6 DoS.pdf): application/pdf, 115 KiB
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
THOTCON Announce | 1 Oct 2010 03:29
Favicon

THOTCON 0x2 - Call For Papers is Open -> 10.01.10

****************************************
***BEGIN THOTCON TRANSMISSION***********

What: THOTCON 0x2
When: 04.22.11
Where: TOP_SECRET
Call For Papers Opens: 10.01.10
Call for Papers Closes: 01.01.11
More Info: <http://www.thotcon.org>

*** ABOUT ******************************
THOTCON (pronounced \ˈthȯt\ and taken from THree - One - Two) is a small
venue hacking conference based in Chicago IL, USA. This is a non-profit,
non-commercial event looking to provide the best conference possible on
a very limited budget.

This is the 2nd year for THOTCON. Last year was a sold out event with 
world-class speakers and talks. The conference will again be held at a 
bar (for 10 hours). If the thought of speaking in front of smiling drunk 
hackers is terrifying, this con is not for you.

This year we'll be expanding the attendance to 300 and 10 talks.

*** WHEN / WHERE ***********************
The conference will be held in Chicago, IL USA on 04.22.11.

It will be held at a location only to be disclosed to attendees and
speakers during the week before the event. It WILL be in the City of
Chicago and close to a CTA train stop, accessible by bus, cab, and even
a rickshaw.

*** FORMAT *****************************
The event will be a single track.

There will be ten (10) 45 minute talks selected.

Topics we are interested in: retro computing, forensics, robotics,
physical security, 0days, application hacking, wireless, malware
development/research, hackerspaces, The Muppets, Penguins, zombies,
attack detection, the number 7, online game hacking, consumer device
hacking, beer, and bananas [foster].

*** SPEAKER PERKS **********************
Speakers will be given free admission to the conference as well as one
(1) free attendee badge (to bring a guest). In addition, speakers who
give their presentation as planned, will be given a THOTCON life-time
attendance badge. This means you will be given free entry to every
future THOTCON event for life.

You will also have access to the THOTCON VIP Lounge. This means you will
have access to free stuff and other highly discounted stuff all day. We
don't have anything else to give, except you can tell your mom and your
friends you spoke at the THOTCON.

*** HOW TO SUBMIT **********************
If you are interested in speaking at this event, please send your
completed speaker application <http://www.thotcon.org/cfp.html> to
cfp <at> thotcon.org.

Once we receive your submission, you will get an email back within 48-72
hours. If you do not hear back from us, please resend.

The CFP will close on 01.01.11 or when we feel we have 10 outstanding
talks. We anticipate having all speakers selected by 02.01.11.

Note: We will not accept CFP submissions as PDF attachments. No need to 
get fancy on us.

Visit: <http://www.thotcon.org/cfp.html> for more information.

*** Tickets ****************************
Tickets will officially go on sale on 11.01.10 (yep, that's 3.1.2 for
those playing along at home).

There is a Secret Pre-Sale going on right now. If you would to like to
pick up a discounted ticket, crack this code: FAW2GlImKsT3BL8yKQF=

Visit: <http://tickets.thotcon.org> for more information.

*** T-Shirt ****************************
Last year the THOTCON t-shirt was designed by an attendee. We are going
to continue that tradition. Design us a t-shirt and we'll give you a VIP
pass to the conference ($225.00 USD value). Email your design to
contests <at> thotcon.org

Visit: <http://www.thotcon.org/contests.html> for more information.

*** Sponsors ***************************
If you happen to work for a company that likes to sponsor cons, we could
use your help. We are not looking for actual conference sponsors, but 
Saturday night (04.23.11), we're having a party for attendees and
speakers. We are looking for 5 sponsors at $1,000.00 USD each to cover
the cost of the party. Email sponsors <at> thotcon.org to become a sponsor.

Visit: <http://www.thotcon.org/sponsors.html> for more information.

****************************************

info <at> thotcon.org
http://www.thotcon.org
twitter:  <at> thotcon

***END THOTCON TRANSMISSION*************
****************************************

dGhvdGNvbjB4Mg==

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Jacky Jack | 1 Oct 2010 11:23
Picon

Re: full disclosure my dear (Microsoft IIS 6.0 Denial of Service)

Are you trying to Pwn$$$$$ G33ks here?

On Fri, Oct 1, 2010 at 8:41 AM, HI-TECH .
<isowarez.isowarez.isowarez <at> googlemail.com> wrote:
> vulnerability description is attached to this email.
>
> /Kingcope
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Benji | 1 Oct 2010 11:27
Favicon

Re: full disclosure my dear (Microsoft IIS 6.0 Denial of Service)

geeks - the only ones that could ever possibly care about a DOS.

On Fri, Oct 1, 2010 at 10:23 AM, Jacky Jack <jacksonsmth698 <at> gmail.com> wrote:
> Are you trying to Pwn$$$$$ G33ks here?
>
>
> On Fri, Oct 1, 2010 at 8:41 AM, HI-TECH .
> <isowarez.isowarez.isowarez <at> googlemail.com> wrote:
>> vulnerability description is attached to this email.
>>
>> /Kingcope
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

pepelotas | 1 Oct 2010 12:11
Picon

rfi by iframe xss in high school

http://hacking-avanzado.blogspot.com/2010/09/rfi-en-la-universidad-autonoma-de.html

Eduardo Abril
Security Consultant
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Manu Quintans | 1 Oct 2010 13:55
Picon

Re: rfi by iframe xss in high school

http://www.sutran.es/blog_hiperhidrosis/?p=128&preview=true

Que te parece? 

On Fri, Oct 1, 2010 at 12:11 PM, <b>pepelotas</b> <pepelotas123 <at> gmail.com> wrote:
http://hacking-avanzado.blogspot.com/2010/09/rfi-en-la-universidad-autonoma-de.html

Eduardo Abril
Security Consultant

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



--
► Manu Quintans
► mail: mquintans <at> gmail.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
MustLive | 1 Oct 2010 21:06
Picon

Multiple vulnerabilities in WordPress 2 and 3

Hello Full-Disclosure!

I want to warn you about Cross-Site Scripting, Full path disclosure,
Information Leakage, Directory Traversal, Arbitrary File Deletion and Denial
of Service vulnerabilities in WordPress.

For all these attacks it's needed to have access to admin account, or to
have account with rights for working with plugins. Or to attack admin or
other user with required rights via XSS, to find out token which designed to
protect against CSRF attacks.

So users of WordPress don't need to worry much about these holes (if to not
allow above-mentioned requirements). But these vulnerabilities will come in
useful to security researchers at access to admin panel or at existence of
XSS at the site. So it's better for WP developers to fix them.

-------------------------
Affected products:
-------------------------

Checked in WordPress 2.0.11, 2.6.2, 2.7, 2.8, 2.9.2, 3.0.1. Versions 2.0.х
are not vulnerable, because they have not such functionality. Vulnerable to
different vulnerabilities are WordPress 2.6 - 3.0.1 and potentially previous
versions.

----------
Details:
----------

While commenting XSS vulnerability in WordPress 3.0.1
(http://www.securityfocus.com/archive/1/513250), I mentioned additional
information concerning XSS vulnerability. These nuances concern and to
below-mentioned vulnerabilities. It's possible to attack as via parameter
checked[0], as via checked[1] and so on, and also via checked[]. In versions
WP 2.7 and higher it's possible to use parameter action=delete-selected, and
in versions 2.8 and higher it's also possible to use parameter
action2=delete-selected.

XSS (WASC-08):

As I pointed out in above-mentioned letter, in WordPress 2.6.x Cross-Site
Scripting attack is conducting differently. And there is almost no benefit
from this XSS.

For attack it's needed to send POST request to
http://site/wp-admin/plugins.php with parameters _wpnonce equal token's
value, delete-selected equal "Delete" and checked[] equal <body
onload=alert(document.cookie)>.

Vulnerable are WordPress 2.6.x and potentially previous versions.

Full path disclosure (WASC-13):

For attack it's needed to send POST request to
http://site/wp-admin/plugins.php with parameters _wpnonce equal token's
value, delete-selected equal "Delete" and checked[] equal "1".

Vulnerable are WordPress 2.6.x and potentially previous versions.

Full path disclosure (WASC-13):

http://site/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action=delete-selected&checked[]=1

http://site/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action2=delete-selected&checked[]=1

Vulnerable are WordPress 2.7 - 3.0.1 (for parameter action2 - 2.8 and
higher).

Full path disclosure (WASC-13):

http://site/wp-admin/plugins.php

Full path is shown at page with plugins.

Vulnerable are WordPress 2.6 - 2.7.1.

Information Leakage (WASC-13) + Directory Traversal (WASC-33):

At page (in list under the link "Click to view entire list of files which
will be deleted") the list of files in current folder and subfolders is
shown.

In folder http://site/wp-content/plugins/:

http://site/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action=delete-selected&checked[]=

http://site/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action2=delete-selected&checked[]=

In folder http://site/wp-content/:

http://site/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action=delete-selected&checked[]=../1

http://site/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action2=delete-selected&checked[]=../1

Vulnerable are WordPress 2.7 - 3.0.1 (for parameter action2 - 2.8 and
higher). And also WordPress 2.6.х. In versions 2.6.х it's needed to send
appropriate POST request to http://site/wp-admin/plugins.php (as mentioned
above).

Arbitrary File Deletion (WASC-42) + DoS (WASC-10):

If to send above-mentioned request with parameter verify-delete=1, then it's
possible to delete files and folders in current folder and subfolders.
Taking into account Directory Traversal it's possible to delete as all
plugins, as all other files in other folders, including it's possible to
conduct DoS attack on the site (if to delete important files of WP). E.g.
with request checked[]=../../1 it's possible to delete the whole site.

http://site/wordpress-2.9.2/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action=delete-selected&checked[]=../1&verify-delete=1

http://site/wordpress-2.9.2/wp-admin/plugins.php?_wpnonce=e0dc6c722b&action2=delete-selected&checked[]=../1&verify-delete=1

Vulnerable are WordPress 2.7 - 3.0.1 (for parameter action2 - 2.8 and
higher). And also WordPress 2.6.х. In versions 2.6.х it's needed to send
appropriate POST request to http://site/wp-admin/plugins.php (as mentioned
above).

------------
Timeline:
------------

2010.08.14 - found the vulnerabilities.
2010.09.30 - disclosed at my site. As I already wrote many times to security
mailing lists (http://www.securityfocus.com/archive/1/510274), starting from
2008 I never more inform WP developers about vulnerabilities in WordPress.

I mentioned about these vulnerabilities at my site
(http://websecurity.com.ua/4575/).

Best wishes & regards,
MustLive
Administrator of Websecurity web site
http://websecurity.com.ua 

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
security | 1 Oct 2010 21:26

[ MDVSA-2010:191 ] mailman


 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2010:191
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : mailman
 Date    : October 1, 2010
 Affected: 2008.0, 2009.0, 2009.1, 2010.0, 2010.1, Corporate 4.0,
           Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

 Multiple vulnerabilities has been found and corrected in mailman:

 Multiple cross-site scripting (XSS) vulnerabilities in GNU Mailman
 before 2.1.14rc1 allow remote authenticated users to inject arbitrary
 web script or HTML via vectors involving (1) the list information
 field or (2) the list description field (CVE-2010-3089).

 Packages for 2008.0 and 2009.0 are provided as of the Extended
 Maintenance Program. Please visit this link to learn more:
 http://store.mandriva.com/product_info.php?cPath=149&products_id=490

 The updated packages have been patched to correct these issues.
 _______________________________________________________________________

 References:

 http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2010-3089
 _______________________________________________________________________

 Updated Packages:

 Mandriva Linux 2008.0:
 e08b1d9a020747ab70982e13a105bb48  2008.0/i586/mailman-2.1.9-2.2mdv2008.0.i586.rpm 
 749c76d1c7e7f4282b7ffbae1e442763  2008.0/SRPMS/mailman-2.1.9-2.2mdv2008.0.src.rpm

 Mandriva Linux 2008.0/X86_64:
 e3bc59b996c69c2721a712ebb794921f  2008.0/x86_64/mailman-2.1.9-2.2mdv2008.0.x86_64.rpm 
 749c76d1c7e7f4282b7ffbae1e442763  2008.0/SRPMS/mailman-2.1.9-2.2mdv2008.0.src.rpm

 Mandriva Linux 2009.0:
 21de029e60fc9b80988dff7898ca8658  2009.0/i586/mailman-2.1.11-1.1mdv2009.0.i586.rpm 
 f97873131d08c4325a898ab7a715351d  2009.0/SRPMS/mailman-2.1.11-1.1mdv2009.0.src.rpm

 Mandriva Linux 2009.0/X86_64:
 7c163192b300d72f301383c395da3b66  2009.0/x86_64/mailman-2.1.11-1.1mdv2009.0.x86_64.rpm 
 f97873131d08c4325a898ab7a715351d  2009.0/SRPMS/mailman-2.1.11-1.1mdv2009.0.src.rpm

 Mandriva Linux 2009.1:
 8ca5797ee931ade6c4756a044e9e9ac6  2009.1/i586/mailman-2.1.12-1.1mdv2009.1.i586.rpm 
 73ac7c0336096a0ee1cbf24520220c27  2009.1/SRPMS/mailman-2.1.12-1.1mdv2009.1.src.rpm

 Mandriva Linux 2009.1/X86_64:
 f750f959be5916b1995391ccdcebb769  2009.1/x86_64/mailman-2.1.12-1.1mdv2009.1.x86_64.rpm 
 73ac7c0336096a0ee1cbf24520220c27  2009.1/SRPMS/mailman-2.1.12-1.1mdv2009.1.src.rpm

 Mandriva Linux 2010.0:
 a68bf17fb97f611aa5fd07edbfd25622  2010.0/i586/mailman-2.1.12-3.1mdv2010.0.i586.rpm 
 db0d3c48e664467c204d46fb9d5d86c8  2010.0/SRPMS/mailman-2.1.12-3.1mdv2010.0.src.rpm

 Mandriva Linux 2010.0/X86_64:
 32b176fd2c1f8185ae061ca48020211f  2010.0/x86_64/mailman-2.1.12-3.1mdv2010.0.x86_64.rpm 
 db0d3c48e664467c204d46fb9d5d86c8  2010.0/SRPMS/mailman-2.1.12-3.1mdv2010.0.src.rpm

 Mandriva Linux 2010.1:
 e83ec834da21aaa9ac825b9dcca38066  2010.1/i586/mailman-2.1.13-1.1mdv2010.1.i586.rpm 
 23adc2d02aa602f4195d2133b86e68da  2010.1/SRPMS/mailman-2.1.13-1.1mdv2010.1.src.rpm

 Mandriva Linux 2010.1/X86_64:
 e93de69f9cccc6d208190ec865b29cd2  2010.1/x86_64/mailman-2.1.13-1.1mdv2010.1.x86_64.rpm 
 23adc2d02aa602f4195d2133b86e68da  2010.1/SRPMS/mailman-2.1.13-1.1mdv2010.1.src.rpm

 Corporate 4.0:
 309605c757131162e730e8d2e77a0331  corporate/4.0/i586/mailman-2.1.6-6.4.20060mlcs4.i586.rpm 
 3284f4a4621bd7a6d59ffe9173787a99  corporate/4.0/SRPMS/mailman-2.1.6-6.4.20060mlcs4.src.rpm

 Corporate 4.0/X86_64:
 28250e366a8fab9c50d8e3964d593c9b 
corporate/4.0/x86_64/mailman-2.1.6-6.4.20060mlcs4.x86_64.rpm 
 3284f4a4621bd7a6d59ffe9173787a99  corporate/4.0/SRPMS/mailman-2.1.6-6.4.20060mlcs4.src.rpm

 Mandriva Enterprise Server 5:
 6d2706e0f8f9001a673c8141eed8638d  mes5/i586/mailman-2.1.11-1.1mdvmes5.1.i586.rpm 
 f45434df800279721a685123da24af21  mes5/SRPMS/mailman-2.1.11-1.1mdvmes5.1.src.rpm

 Mandriva Enterprise Server 5/X86_64:
 3d512d16b23e2bd2af6d9380376dd83c  mes5/x86_64/mailman-2.1.11-1.1mdvmes5.1.x86_64.rpm 
 f45434df800279721a685123da24af21  mes5/SRPMS/mailman-2.1.11-1.1mdvmes5.1.src.rpm
 _______________________________________________________________________

 To upgrade automatically use MandrivaUpdate or urpmi.  The verification
 of md5 checksums and GPG signatures is performed automatically for you.

 All packages are signed by Mandriva for security.  You can obtain the
 GPG public key of the Mandriva Security Team by executing:

  gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98

 You can view other update advisories for Mandriva Linux at:

  http://www.mandriva.com/security/advisories

 If you want to report vulnerabilities, please contact

  security_(at)_mandriva.com
 _______________________________________________________________________

 Type Bits/KeyID     Date       User ID
 pub  1024D/22458A98 2000-07-10 Mandriva Security Team
  <security*mandriva.com>
ZDI Disclosures | 1 Oct 2010 22:10

ZDI-10-189: Novell eDirectory Server Malformed Index Denial of Service Vulnerability

ZDI-10-189: Novell eDirectory Server Malformed Index Denial of Service Vulnerability
http://www.zerodayinitiative.com/advisories/ZDI-10-189
October 1, 2010

-- CVSS:
7.8, (AV:N/AC:L/Au:N/C:N/I:N/A:C)

-- Affected Vendors:
Novell

-- Affected Products:
Novell eDirectory

-- TippingPoint(TM) IPS Customer Protection:
TippingPoint IPS customers have been protected against this
vulnerability by Digital Vaccine protection filter ID 9971. 
For further product information on the TippingPoint IPS, visit:

    http://www.tippingpoint.com

-- Vulnerability Details:
This vulnerability allows attackers to deny services on vulnerable
installations of Novell eDirectory. Authentication is not required in
order to trigger this vulnerability.

The flaw exists within Novell's eDirectory Server's NCP implementation
which binds, by default, to TCP port 524. While handling a malformed
request, the application explicitly trusts a field when translating it
to an index into a table of counters. If this index is too large, the
application will set a value outside the array and the ndsd process will
become unresponsive resulting in an inability to authenticate to that
server.

-- Vendor Response:
Novell has issued an update to correct this vulnerability. More
details can be found at:

http://www.novell.com/support/viewContent.do?externalId=7006389&amp;sliceId=2

-- Disclosure Timeline:
2009-04-28 - Vulnerability reported to vendor
2010-10-01 - Coordinated public release of advisory

-- Credit:
This vulnerability was discovered by:
    * 1c239c43f521145fa8385d64a9c32243

-- About the Zero Day Initiative (ZDI):
Established by TippingPoint, The Zero Day Initiative (ZDI) represents 
a best-of-breed model for rewarding security researchers for responsibly
disclosing discovered vulnerabilities.

Researchers interested in getting paid for their security research
through the ZDI can find more information and sign-up at:

    http://www.zerodayinitiative.com

The ZDI is unique in how the acquired vulnerability information is
used. TippingPoint does not re-sell the vulnerability details or any
exploit code. Instead, upon notifying the affected product vendor,
TippingPoint provides its customers with zero day protection through
its intrusion prevention technology. Explicit details regarding the
specifics of the vulnerability are not exposed to any parties until
an official vendor patch is publicly available. Furthermore, with the
altruistic aim of helping to secure a broader user base, TippingPoint
provides this vulnerability information confidentially to security
vendors (including competitors) who have a vulnerability protection or
mitigation product.

Our vulnerability disclosure policy is available online at:

    http://www.zerodayinitiative.com/advisories/disclosure_policy/

Follow the ZDI on Twitter:

    http://twitter.com/thezdi

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

HI-TECH . | 1 Oct 2010 22:11

Re: full disclosure my dear (Microsoft IIS 6.0 Denial of Service)

Hello list,
looks like this bug is covered by MS10-065 ('IIS Repeated Parameter
Request Denial of Service Vulnerability') as tests by VUPEN have
shown.
from vupen on twitter:
"We analyzed the MS IIS 0day disclosed by  <at> kingcope and we confirmed
that it is NOT a 0D. This is the DoS fixed in MS10-065"
I personally have looked into MS10-065 by binary diffing but was
unaware that the PoC exploits the same bug.
Now at least you can test your server for the bug. Thanks to vupen for
pointing this out.
Regards,
Kingcope

2010/10/1 Benji <me <at> b3nji.com>
>
> geeks - the only ones that could ever possibly care about a DOS.
>
> On Fri, Oct 1, 2010 at 10:23 AM, Jacky Jack <jacksonsmth698 <at> gmail.com> wrote:
> > Are you trying to Pwn$$$$$ G33ks here?
> >
> >
> > On Fri, Oct 1, 2010 at 8:41 AM, HI-TECH .
> > <isowarez.isowarez.isowarez <at> googlemail.com> wrote:
> >> vulnerability description is attached to this email.
> >>
> >> /Kingcope
> >>
> >> _______________________________________________
> >> Full-Disclosure - We believe in it.
> >> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >> Hosted and sponsored by Secunia - http://secunia.com/
> >>
> >
> > _______________________________________________
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
> >

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Gmane