Full Disclosure

Syndicate content
A lightly moderated high-traffic forum for disclosure of security information. Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue. The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip. Unfortunately, most of the posts are worthless drivel, so finding the gems takes patience.
Updated: 28 min 9 sec ago

Yet another (unpaid and unfixed) Paypal XSS

13 June, 2013 - 05:26

Posted by samuel alp on Jun 13

Hi People

Found a XSS on german Paypal website last week and reported it exactly 7
days ago.
Their response was one we very well know
Another researcher already discovered the bug.

So, someone else found the Vulnerability before me and reported it.
Fine, looks like I was too slow. I can live with that.

Now, i received an answer exactly 7 Days ago. That means they had more than
a week to fix this...

Re: Why PRISM kills the cloud | Computerworld Blogs

13 June, 2013 - 03:10

Posted by Justin Ferguson on Jun 13

There is nothing anywhere in any of US law, whether it be the bill of
rights or case law/judicial review which *modifies* those rights. More
over, you probably mean to reference the 4th amendment, not the 1st,
as having a given type of speech monitoring does not inhibit its
expression, but may/may not constitute an illegal search and seizure.

This will eventually be reviewed by SCOTUS, to which we will determine
whether its constitutional or...

Re: Security Analysis of IP video surveillance cameras

13 June, 2013 - 02:49

Posted by Marcos Agüero on Jun 13

But no everyone makes that public :)
I think that their teacher is fine not being on that report. (Hi Alex!)

El 12/06/13 16:05, Paul Ammann escribió:

[CVE-2013-3684] NextGEN Gallery 1.9.12 Arbitrary File Upload

13 June, 2013 - 02:47

Posted by Marcos Agüero on Jun 13

##############################################################

- S21Sec Advisory -

##############################################################

Title: NextGEN Gallery 1.9.12 Arbitrary File Upload
ID: S21SEC-046-en
CVE ID: CVE-2013-3684
Severity: High
Status: Fixed
History: 27.May.2013 Vulnerability discovered
28.May.2013 Vendor informed
12.Jun.2013 Fix...

[CVE-2013-1768] Apache OpenJPA security vulnerability

13 June, 2013 - 02:45

Posted by Jeremy Bauer on Jun 13

Severity: Important

Vendor: The Apache Software Foundation

Versions Affected:

OpenJPA 1.0.0 to 1.0.4
OpenJPA 1.1.0
OpenJPA 1.3.0
OpenJPA 1.2.0 to 1.2.2
OpenJPA 2.0.0 to 2.0.1
OpenJPA 2.1.0 to 2.1.1
OpenJPA 2.2.0 to 2.2.1

Description: Deserialization of a maliciously crafted OpenJPA object can
result in an executable file being written to the file system. An
attacker needs to discover an unprotected server program to exploit the
vulnerability....

Re: Why PRISM kills the cloud | Computerworld Blogs

13 June, 2013 - 02:44

Posted by Alexander Arlt on Jun 13

Am 06/12/2013 01:08 AM, schrieb Justin Ferguson:

Ah, I have the joy of knowing some of the fellows over there in Pullach
and actually... I'd really like to know, what they're doing for their
living... indeed... since it's mostly my tax money at work over there.

Guys, take a look from my perspective: At least you know what your tax
dollars are spent on...

Slideware of recent presentations about IPv6 security

12 June, 2013 - 18:45

Posted by Fernando Gont on Jun 12

Folks,

FYI, the slideware of two recent presentations is available online:

* "Security Assessment of IPv6 Networks and Firewalls", presented at the
German IPv6 Kongress (http://www.ipv6-kongress.de/) in Frankfurt/Main,
June 6-7, 2013.

Slideware available at:
<http://www.si6networks.com/presentations/ipv6kongress/mhfg-ipv6-kongress-ipv6-security-assessment.pdf>

We did this talk together with Marc Heuse. First time we presented...

Re: Why PRISM kills the cloud | Computerworld Blogs

12 June, 2013 - 17:00

Posted by Ivan .Heca on Jun 12

Thw commercial espionage angle is another interesting aspect of this

http://www.techdirt.com/articles/20130611/10014923405/is-us-using-prism-to-engage-commercial-espionage-against-germany-others.shtml

[Security-news] SA-CONTRIB-2013-052 - Display Suite - Cross Site Scripting (XSS)

12 June, 2013 - 14:09

Posted by security-news on Jun 12

View online: https://drupal.org/node/2017933

* Advisory ID: DRUPAL-SA-CONTRIB-2013-052
* Project: Display Suite [1] (third-party module)
* Version: 7.x
* Date: 2013-June-12
* Security risk: Moderately critical [2]
* Exploitable from: Remote
* Vulnerability: Cross Site Scripting

-------- DESCRIPTION
---------------------------------------------------------

Display Suite allows you to take full control over how your content is...

Re: Security Analysis of IP video surveillance cameras

12 June, 2013 - 09:17

Posted by Vitor Ventura on Jun 12

Did you report your findings to the vendors?

Re: Why PRISM kills the cloud | Computerworld Blogs

12 June, 2013 - 09:15

Posted by William Reyor on Jun 12

* are protected <-- fixed that for ya.

- William Reyor

Re: Security Analysis of IP video surveillance cameras

12 June, 2013 - 09:14

Posted by Paul Ammann on Jun 12

Doesn't everyone?

Re: Security Analysis of IP video surveillance cameras

12 June, 2013 - 09:12

Posted by Andrew Smith on Jun 12

Yikes.....

Re: Why PRISM kills the cloud | Computerworld Blogs

12 June, 2013 - 09:02

Posted by laurent gaffie on Jun 12

Freedom of speech and freedom of anonymous speech is protected by the first
amendment..

https://www.eff.org/issues/anonymity

2013/6/11 Philip Whitehouse <philip () whiuk com>

Re: Security Analysis of IP video surveillance cameras

12 June, 2013 - 07:29

Posted by Leif Nixon on Jun 12

Javier Repiso Sánchez <javier.repiso () hotmail com> writes:

So, as part of your Master's Thesis, you exploited surveillance cameras
belonging to random people on the Internet?

[ MDVSA-2013:172 ] wireshark

12 June, 2013 - 07:03

Posted by security on Jun 12

_______________________________________________________________________

Mandriva Linux Security Advisory MDVSA-2013:172
http://www.mandriva.com/en/support/security/
_______________________________________________________________________

Package : wireshark
Date : June 12, 2013
Affected: Business Server 1.0, Enterprise Server 5.0
_______________________________________________________________________

Problem...

Re: Why PRISM kills the cloud | Computerworld Blogs

12 June, 2013 - 06:29

Posted by Zenny on Jun 12

This has been came into public attendtion recently, but it has been
published earlier in March 2013 by Bruce Schneider (the twofish crypto
algo developer).

Read here:
https://www.schneier.com/blog/archives/2013/03/fbi_secretly_sp.html

Security Analysis of IP video surveillance cameras

12 June, 2013 - 06:28

Posted by Javier Repiso Sánchez on Jun 12

Dear sirs,

We are a group of students from the European University of Madrid who have made a security analysis of IP video
surveillance cameras as the final project of Security and Information Technology Master.

In total, we analyzed 9 different camera brands and we have found 14 vulnerabilities.

**Note that all the analysis we have done has been from cameras found through Google dorks and Shodan, so we have not
needed to purchase any of...

Re: Why PRISM kills the cloud | Computerworld Blogs

12 June, 2013 - 06:26

Posted by Pedro Worcel on Jun 12

Uhh, discount! That guy, what's his name, was a traitor anyway.

You just cannot believe people.

2013/6/12 Ivan .Heca <ivanhec () gmail com>