<rss version="2.0"><channel><title>Full Disclosure (fulldisclosure) Mailing List</title>
<link>http://seclists.org/#fulldisclosure</link>
<description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>Re:  Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution</title><description>Posted by Jan Min on Jul 25&lt;p&gt;


&lt;p&gt;
2008/7/25 Robert Buchholz &amp;lt;rbu_at_gentoo&amp;#46;org&amp;gt;:
&lt;br /&gt;
&amp;gt; On Friday 18 July 2008, Jan Min&aacute;&#x159; wrote:
&lt;br /&gt;
&amp;gt; ...
&lt;br /&gt;
&amp;gt;&amp;gt; 3. Vulnerability
&lt;br /&gt;
&amp;gt;&amp;gt;
&lt;br /&gt;
&amp;gt;&amp;gt; During the build process, a temporary file with a predictable name is
&lt;br /&gt;
&amp;gt;&amp;gt; created in the ``/tmp&#39;&#39; directory.  This code is run...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0431.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0431.html</guid>
<pubDate>Fri, 25 Jul 2008 03:16:00 +0100</pubDate></item>
<item><title>Re:  Vim: Insecure Temporary File Creation During Build: Arbitrary Code Execution</title><description>Posted by Robert Buchholz on Jul 25&lt;p&gt;


&lt;p&gt;
On Friday 18 July 2008, Jan Min&aacute;&oslash; wrote:
&lt;br /&gt;
...
&lt;br /&gt;
&amp;gt; 3. Vulnerability
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; During the build process, a temporary file with a predictable name is
&lt;br /&gt;
&amp;gt; created in the ``/tmp&#39;&#39; directory.  This code is run when Vim is
&lt;br /&gt;
&amp;gt; being build with Python support:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; src/configure.in:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0430.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0430.html</guid>
<pubDate>Fri, 25 Jul 2008 03:17:08 +0200</pubDate></item>
<item><title>Re:  Pen Test forums?</title><description>Posted by Ivan . on Jul 25&lt;p&gt;


&lt;p&gt;
pen-test_at_securityfocus&amp;#46;com
&lt;br /&gt;
&lt;p&gt;subscribe at securityfocus.com
&lt;br /&gt;
&lt;p&gt;cheers
&lt;br /&gt;
Ivan
&lt;br /&gt;
&lt;p&gt;On Fri, Jul 25, 2008 at 8:51 AM, blah &amp;lt;blah_at_blakogre&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Looking for some active pen-test forums to bounce scenarios around,
&lt;br /&gt;
&amp;gt; with a good amount of traffic and solid members.  does it...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0429.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0429.html</guid>
<pubDate>Fri, 25 Jul 2008 09:05:54 +1000</pubDate></item>
<item><title>Pen Test forums?</title><description>Posted by blah on Jul 24&lt;p&gt;


&lt;p&gt;
Looking for some active pen-test forums to bounce scenarios around,
&lt;br /&gt;
with a good amount of traffic and solid members.  does it exist?
&lt;br /&gt;
googling didn&#39;t turn up much.
&lt;br /&gt;
&lt;p&gt;thanks
&lt;br /&gt;</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0428.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0428.html</guid>
<pubDate>Thu, 24 Jul 2008 15:51:47 -0700</pubDate></item>
<item><title>Re:  DNS spoofing issue. Thoughts on potential exploits</title><description>Posted by list-fulldisclosure_at_pwns.ms on Jul 24&lt;p&gt;


&lt;p&gt;
&amp;gt; What is always required is a machine where the user has the ability to write
&lt;br /&gt;
&amp;gt; packets to the network with any IP. This usually means super user access.
&lt;br /&gt;
&amp;gt; It is difficult in most cases to send udp packets with forged IP since
&lt;br /&gt;
&amp;gt; routers will not accept them. That is why it is...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0427.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0427.html</guid>
<pubDate>Thu, 24 Jul 2008 22:06:30 +0000</pubDate></item>
<item><title>Kaminsky corroborates the DNS vuln. discovered and published by Flake</title><description>Posted by Kristo pher on Jul 25&lt;p&gt;


&lt;p&gt;
In a webcast today, security researcher Dan Kaminsky corroborated the discovery made and published by Halvar Flake [1] . Kudos to Halvar for envisaging such a critical vulnerability and for his subsequent publication which made the Interwebs a much safer place. Other researchers should get their...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0426.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0426.html</guid>
<pubDate>Fri, 25 Jul 2008 00:43:17 +0400</pubDate></item>
<item><title>Re:  DNS spoofing issue. Thoughts on potential exploits</title><description>Posted by Troy Xyz on Jul 24&lt;p&gt;


&lt;p&gt;
I am now posting some analysis I wrote on the subject right after my last
&lt;br /&gt;
post.
&lt;br /&gt;
Since the exploits are now available too, this should primarily be helpful
&lt;br /&gt;
to the good guys.
&lt;br /&gt;
I wrote this without full details of the exploit, but it shoud all be
&lt;br /&gt;
pertinent nonetheless.
&lt;br /&gt;
It might help in some...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0425.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0425.html</guid>
<pubDate>Thu, 24 Jul 2008 23:41:45 +0300</pubDate></item>
<item><title>Re:  SPAM from Tobesecurity.com</title><description>Posted by Robert Holgstad on Jul 24&lt;p&gt;


&lt;p&gt;
and by telling us about this insignificant event aren&#39;t you spamming for
&lt;br /&gt;
them?
&lt;br /&gt;
&lt;p&gt;On Thu, Jul 24, 2008 at 11:55 AM, Arturo &#39;Buanzo&#39; Busleiman &amp;lt;
&lt;br /&gt;
buanzo_at_buanzo&amp;#46;com.ar&amp;gt; wrote:
&lt;br /&gt;
&lt;p&gt;&amp;gt; -----BEGIN PGP SIGNED MESSAGE-----
&lt;br /&gt;
&amp;gt; Hash: SHA512
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Hi people, just to let other...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0424.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0424.html</guid>
<pubDate>Thu, 24 Jul 2008 12:08:38 -0500</pubDate></item>
<item><title>Re:  ladies</title><description>Posted by Dale Harris on Jul 24&lt;p&gt;


&lt;p&gt;
A self fulfilled prophecy it sound like to me.
&lt;br /&gt;
&lt;p&gt;On Thu, Jul 24, 2008 at 6:51 AM, Professor Micheal Chatner
&lt;br /&gt;
&amp;lt;mchatner_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; Stop wasting your time and use your skills to bring chaos and
&lt;br /&gt;
&amp;gt; devastation to an already useless community of the mentally defected
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0423.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0423.html</guid>
<pubDate>Thu, 24 Jul 2008 12:58:07 -0400</pubDate></item>
<item><title>SPAM from Tobesecurity.com</title><description>Posted by Arturo Buanzo Busleiman on Jul 24&lt;p&gt;


&lt;p&gt;
&lt;p&gt;Hi people, just to let other forum/blog/wiki admins out there that some people from tobesecurity.com
&lt;br /&gt;
is spamming.
&lt;br /&gt;
&lt;p&gt;http://foros.buanzo.com.ar/viewtopic.php?p=2118#p2118
&lt;br /&gt;
http://foros.buanzo.com.ar/viewtopic.php?f=20&amp;amp;t=520
&lt;br /&gt;
&lt;p&gt;I own a forum with .com.ar domain, and I got spam from an individual...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0422.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0422.html</guid>
<pubDate>Thu, 24 Jul 2008 13:55:07 -0300</pubDate></item>
<item><title>Re:  Comments on: DNS exploit code is in the wild</title><description>Posted by Valdis.Kletnieks_at_vt.edu on Jul 24&lt;p&gt;


&lt;p&gt;
On Thu, 24 Jul 2008 16:17:08 BST, n3td3v said:
&lt;br /&gt;
&lt;p&gt;&amp;gt; This whole HD Moore savior of info sec thing has gone on long enough,
&lt;br /&gt;
&amp;gt; its time to see him for what he is and get him slammed up in jail
&lt;br /&gt;
&amp;gt; along with his counterpart |)ruid.
&lt;br /&gt;
&lt;p&gt;I&#39;ll point out that you happen to live in the country that...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0421.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0421.html</guid>
<pubDate>Thu, 24 Jul 2008 12:56:24 -0400</pubDate></item>
<item><title>Re:  Comments on: DNS exploit code is in the wild</title><description>Posted by MadHat Unspecific on Jul 24&lt;p&gt;


&lt;p&gt;
n3td3v wrote:
&lt;br /&gt;
&amp;gt; On Thu, Jul 24, 2008 at 3:43 PM, MadHat Unspecific
&lt;br /&gt;
&amp;gt; &amp;lt;madhat_at_unspecific&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;&amp;gt; Technically |)ruid of CAU released the code.  HD was just listed as
&lt;br /&gt;
&amp;gt;&amp;gt; co-author and it was released on the CAU website as a CAU exploit.  As far
&lt;br /&gt;
&amp;gt;&amp;gt; as...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0420.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0420.html</guid>
<pubDate>Thu, 24 Jul 2008 10:44:05 -0500</pubDate></item>
<item><title>Re:  Comments on: DNS exploit code is in the wild</title><description>Posted by n3td3v on Jul 24&lt;p&gt;


&lt;p&gt;
On Thu, Jul 24, 2008 at 3:43 PM, MadHat Unspecific
&lt;br /&gt;
&amp;lt;madhat_at_unspecific&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Technically |)ruid of CAU released the code.  HD was just listed as
&lt;br /&gt;
&amp;gt; co-author and it was released on the CAU website as a CAU exploit.  As far
&lt;br /&gt;
&amp;gt; as you know HD didn&#39;t tell |)ruid...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0419.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0419.html</guid>
<pubDate>Thu, 24 Jul 2008 16:17:08 +0100</pubDate></item>
<item><title>Signs of compromised DNS?</title><description>Posted by James Lay on Jul 24&lt;p&gt;


&lt;p&gt;
Anyone have any idea what signs would be if a DNS server is compromised?
&lt;br /&gt;
Been seeing:
&lt;br /&gt;
&lt;p&gt;08:39:28 homebox named[27]: client *.*.143.11#10053: query (cache)
&lt;br /&gt;
&#39;gmail.com/ANY/IN&#39; denied
&lt;br /&gt;
08:40:30 homebox named[27]: client *.*143.11#10053: query (cache)
&lt;br /&gt;
&#39;hotmail.com/ANY/IN&#39; denied
&lt;br /&gt;
&lt;p&gt;Coming in to my...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0418.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0418.html</guid>
<pubDate>Thu, 24 Jul 2008 08:41:55 -0600</pubDate></item>
<item><title>Re:  Comments on: DNS exploit code is in the wild</title><description>Posted by Ray P on Jul 24&lt;p&gt;


&lt;p&gt;
Holding back would be security through obscurity now that the details are available. I&#39;ve gotten three emails today from security lists with different exploit code in them.
&lt;br /&gt;
&lt;p&gt;Ray
&lt;br /&gt;
&lt;p&gt;&amp;gt; Date: Thu, 24 Jul 2008 15:21:01 +0100
&lt;br /&gt;
&amp;gt; From: xploitable_at_gmail&amp;#46;com
&lt;br /&gt;
&amp;gt; To:...</description>
<link>http://seclists.org/fulldisclosure/2008/Jul/0417.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Jul/0417.html</guid>
<pubDate>Thu, 24 Jul 2008 14:27:15 +0000</pubDate></item>
</channel></rss>