<?xml version="1.0" encoding="ISO-8859-1"?>
<rss version="0.92">
<channel>
     <title>FullDisclosure at insecure.org</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/date.html</link>
     <description>Latest posts to fulldisclosure with detailed descriptions</description>
     <managingEditor>fyodor@NOSPAMinsecure.org (fyodor)</managingEditor>
     <webMaster>djeaux@NOSPAMdjeaux.com (djeaux)</webMaster>
     <generator>Scythe 2.10</generator>
     <lastBuildDate>Thu, 24 Jul 2008 01:50:04 PDT</lastBuildDate>
     <image>
          <url>http://www.djeaux.com/images/scraped_88x31.png</url>
          <title>fulldisclosure at insecure.org</title>
          <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul</link>
          <description>FullDisclosure scraped from insecure.org</description>
     </image>
     <language>en-us</language>

<item>
     <title>CAU-EX-2008-0003: Kaminsky DNS Cache Poisoning Flaw Exploit for	Domains</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0412.html</link>
     <author>druid@NOSPAMcaughq.org (Iruid)</author>
     <pubDate>Wed, 23 Jul 2008 22:48:38 -0500</pubDate>
     <description>&#47; \ &#47; \ &#47; &#47;\\##&#47; &#47;\ \## ## \ \&#47; &#47;# ## # ## \&#47; \&#47; Computer Academic Underground Exploit Code &#47; Exploit ID: CAU-EX-2008-0003 Release Date: 2008.07.23 Title: bailiwickeddomain.rb Description: Kaminsky DNS Cache Poisoning Flaw Exploit for Domains Tested: BIND 9.4.1-9.4.2 ...</description>
</item>
 
<item>
     <title>CAU-EX-2008-0002: Kaminsky DNS Cache Poisoning Flaw Exploit</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0411.html</link>
     <author>druid@NOSPAMcaughq.org (Iruid)</author>
     <pubDate>Wed, 23 Jul 2008 18:34:26 -0500</pubDate>
     <description>&#47; \ &#47; \ &#47; &#47;\\##&#47; &#47;\ \## ## \ \&#47; &#47;# ## # ## \&#47; \&#47; Computer Academic Underground Exploit Code &#47; Exploit ID: CAU-EX-2008-0002 Release Date: 2008.07.23 Title: bailiwickedhost.rb Description: Kaminsky DNS Cache Poisoning Flaw Exploit Tested: BIND 9.4.1-9.4.2 ...</description>
</item>
 
<item>
     <title>[ MDVSA-2008:154 ] - Updated xemacs packages fix vulnerability</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0410.html</link>
     <author>security@NOSPAMmandriva.com (security_at_mandriva.com)</author>
     <pubDate>Wed, 23 Jul 2008 17:29:00 -0600</pubDate>
     <description>Mandriva Linux Security Advisory MDVSA-2008:154 Package : xemacs Date : July 23, 2008 Affected: Corporate 3.0 Problem Description: A vulnerability in xemacs was found where an attacker could provide a group of files containing local variable definitions and arbitrary ...</description>
</item>
 
<item>
     <title>[ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0409.html</link>
     <author>security@NOSPAMmandriva.com (security_at_mandriva.com)</author>
     <pubDate>Wed, 23 Jul 2008 17:27:00 -0600</pubDate>
     <description>Mandriva Linux Security Advisory MDVSA-2008:153 Package : emacs Date : July 23, 2008 Affected: 2007.1, 2008.0, 2008.1, Corporate 3.0, Corporate 4.0 Problem Description: A vulnerability in emacs was found where an attacker could provide ...</description>
</item>
 
<item>
     <title>[tool] SDT Cleaner 1.0</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0408.html</link>
     <author>lists@NOSPAMcorest.com (Nahuel C. Riva)</author>
     <pubDate>Wed, 23 Jul 2008 19:49:33 -0300</pubDate>
     <description>Hello! You can find it here: Package: What is the SDT Cleaner? SDT Cleaner is a tool that intends to clean the SSDT (system service descriptor table) from hooks. * The SDT Cleaner allows you to clean hooks installed by Anti-Virus and Firewalls. ...</description>
</item>
 
<item>
     <title>[ MDVSA-2008:153 ] - Updated emacs packages fix vulnerability</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0407.html</link>
     <author>security@NOSPAMmandriva.com (security_at_mandriva.com)</author>
     <pubDate>Wed, 23 Jul 2008 15:56:00 -0600</pubDate>
     <description>Mandriva Linux Security Advisory MDVSA-2008:153 Package : emacs Date : July 23, 2008 Affected: 2007.1, 2008.0, 2008.1, Corporate 3.0, Corporate 4.0 Problem Description: A vulnerability in emacs was found where an attacker could provide ...</description>
</item>
 
<item>
     <title>DNS forward only: why does it help?</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0406.html</link>
     <author>psz@NOSPAMmaths.usyd.edu.au (Paul Szabo)</author>
     <pubDate>Thu, 24 Jul 2008 07:28:15 +1000</pubDate>
     <description>As a workaround, it is recommended to set DNS servers to forward only. Can someone explain why that helps? Cannot responses from the forwarder be spoofed same as normal query responses? Is it that &quot;glue RRs&quot; from forwarders are discarded; or that source ports of forwarded requests are ...</description>
</item>
 
<item>
     <title>[SECURITY] [DSA 1540-3] New lighttpd packages fix regression</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0405.html</link>
     <author>thijs@NOSPAMdebian.org (Thijs Kinkhorst)</author>
     <pubDate>Wed, 23 Jul 2008 20:59:43 +0200</pubDate>
     <description>- Debian Security Advisory DSA-1540-3 securityatdebian&#46;org Thijs Kinkhorst July 23, 2008 - Package : lighttpd Vulnerability : denial of service Problem type : remote Debian-specific: no CVE Id(s) : CVE-2008-1531 This update fixes a regression in lighttpd introduced in DSA-1540, ...</description>
</item>
 
<item>
     <title>Vulnerability Report: EMC Centera Universal Access</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0404.html</link>
     <author>Aaron.Brown@NOSPAMadmeritia.de (Aaron Brown)</author>
     <pubDate>Wed, 23 Jul 2008 19:09:27 +0200</pubDate>
     <description>adMERITia Vulnerability Report Vulnerability Information Vendor: EMC˛ Product: Centera Universal Access Version: CUA4.04735.p4 Vulnerability Type: Software Flaw Vulnerability: SQL Injection ...</description>
</item>
 
<item>
     <title>[SECURITY] [DSA 1615-1] New xulrunner packages fix several vulnerabilities</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0403.html</link>
     <author>jmm@NOSPAMdebian.org (Moritz Muehlenhoff)</author>
     <pubDate>Wed, 23 Jul 2008 22:33:58 +0200</pubDate>
     <description>- Debian Security Advisory DSA-1615-1 securityatdebian&#46;org Moritz Muehlenhoff July 23, 2008 - Package : xulrunner Vulnerability : several Problem type : local&#47;remote Debian-specific: no CVE ID : CVE-2008-2785 CVE-2008-2798 CVE-2008-2799 CVE-2008-2800 CVE-2008-2801 CVE-2008-2802 CVE-2008-2803 CVE-2008-2805 CVE-2008-2807 CVE-2008-2808 CVE-2008-2809 CVE-2008-2811 CVE-2008-2933 ...</description>
</item>
 
<item>
     <title>[SECURITY] [DSA 1614-1] New iceweasel packages fix several vulnerabilities</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0402.html</link>
     <author>jmm@NOSPAMdebian.org (Moritz Muehlenhoff)</author>
     <pubDate>Wed, 23 Jul 2008 22:07:11 +0200</pubDate>
     <description>- Debian Security Advisory DSA-1614-1 securityatdebian&#46;org Moritz Muehlenhoff July 23, 2008 - Package : iceweasel Vulnerability : several Problem-Type : remote Debian-specific: no CVE ID : CVE-2008-2785 CVE-2008-2933 Several remote vulnerabilities have been discovered in the Iceweasel ...</description>
</item>
 
<item>
     <title>[USN-628-1] PHP vulnerabilities</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0401.html</link>
     <author>jamie@NOSPAMcanonical.com (Jamie Strandboge)</author>
     <pubDate>Wed, 23 Jul 2008 15:39:07 -0400</pubDate>
     <description>Ubuntu Security Notice USN-628-1 July 23, 2008 php5 vulnerabilities CVE-2007-4782, CVE-2007-4850, CVE-2007-5898, CVE-2007-5899, CVE-2008-0599, CVE-2008-1384, CVE-2008-2050, CVE-2008-2051, CVE-2008-2107, CVE-2008-2108, CVE-2008-2371, CVE-2008-2829 A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu 7.04 Ubuntu 7.10 Ubuntu 8.04 LTS ...</description>
</item>
 
<item>
     <title>Re:  Is the security industry like a lemon market?</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0400.html</link>
     <author>dguido@NOSPAMgmail.com (Daniel Guido)</author>
     <pubDate>Wed, 23 Jul 2008 15:14:15 -0400</pubDate>
     <description>This should play nicer with some auto-linking code: Sorry about that! -- Dan Guido Full-Disclosure - We believe in it. Charter: Hosted and sponsored by Secunia - </description>
</item>
 
<item>
     <title>Is the security industry like a lemon market?</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0399.html</link>
     <author>dguido@NOSPAMgmail.com (Daniel Guido)</author>
     <pubDate>Wed, 23 Jul 2008 14:40:03 -0400</pubDate>
     <description>This pair of essays were written in 4 hours the night before they were due for last year's Cyber Security Awareness Week at Polytechnic University. They were intended to answer the question, &quot;Is the security industry like a lemon market?&quot; as first brought up in a Wired ...</description>
</item>
 
<item>
     <title>Vim: Flawed Fix of Arbitrary Code Execution Vulnerability in filetype.vim</title>
     <link>http://www.seclists.org/lists/fulldisclosure/2008/Jul/0398.html</link>
     <author>rdancer@NOSPAMrdancer.org (Jan MinĂˇĹ™)</author>
     <pubDate>Wed, 23 Jul 2008 19:29:01 +0100</pubDate>
     <description>1. SUMMARY Product : Vim -- Vi IMproved Version : Tested with Vim 7.2b.10, filetype.vim 2008-07-17 Impact : Arbitrary code execution Wherefrom: Local and remote CVE : CVE-2008-2712 Original : This is an update of a previous advisory[1]. Vim patch 7.1.300 which ...</description>
</item>
 
</channel>
</rss>
