<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Full Disclosure (fulldisclosure) Mailing List</title>
<link>http://seclists.org/#fulldisclosure</link>
<atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
<description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>[SECURITY] [DSA 1677-1] New CUPS packages fix arbitrary code execution</title><description>Posted by Martin Schulze on Dec 2&lt;p&gt;


&lt;p&gt;
&lt;p&gt;--------------------------------------------------------------------------
&lt;br /&gt;
Debian Security Advisory DSA 1677-1                    security_at_debian&amp;#46;org
&lt;br /&gt;
http://www.debian.org/security/                             Martin Schulze
&lt;br /&gt;
December 2nd, 2008                      ...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0049.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0049.html</guid>
<pubDate>Tue,  2 Dec 2008 22:09:10 +0100 (CET)</pubDate></item>
<item><title>Re:  Sonicwall license servers down .. all customers affected</title><description>Posted by James Matthews on Dec 2&lt;p&gt;


&lt;p&gt;
I am sure Sonic wall is going to lose many customers and other companies
&lt;br /&gt;
should learn and not put DRM in their products. I hope this will teach them.
&lt;br /&gt;
&lt;p&gt;On Tue, Dec 2, 2008 at 9:36 PM, Elazar Broad &amp;lt;elazar_at_hushmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&lt;p&gt;&amp;gt; -----BEGIN PGP SIGNED MESSAGE-----
&lt;br /&gt;
&amp;gt; Hash: SHA1
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0048.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0048.html</guid>
<pubDate>Tue, 2 Dec 2008 22:08:34 +0200</pubDate></item>
<item><title>Re:  Project Chroma: A color code for the state ofcyber security</title><description>Posted by Elazar Broad on Dec 02&lt;p&gt;


&lt;p&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;On Tue, 02 Dec 2008 11:50:46 -0500 rholgstad &amp;lt;rholgstad_at_gmail&amp;#46;com&amp;gt;
&lt;br /&gt;
wrote:
&lt;br /&gt;
&amp;gt;Mike C wrote:
&lt;br /&gt;
&amp;gt;&amp;gt; On Mon, Dec 1, 2008 at 5:27 PM, rholgstad &amp;lt;rholgstad_at_gmail&amp;#46;com&amp;gt;
&lt;br /&gt;
&amp;gt;wrote:
&lt;br /&gt;
&amp;gt;&amp;gt;
&lt;br /&gt;
&amp;gt;&amp;gt;&amp;gt; and how does making a color based on these inputs protect
&lt;br /&gt;
...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0047.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0047.html</guid>
<pubDate>Tue, 02 Dec 2008 14:29:22 -0500</pubDate></item>
<item><title>Re:  Sonicwall license servers down .. all customers affected</title><description>Posted by Elazar Broad on Dec 02&lt;p&gt;


&lt;p&gt;
&lt;p&gt;I stopped using SonicWall when I learned I had to purchase a whole
&lt;br /&gt;
new device for a customer that just wanted to add a few more
&lt;br /&gt;
machines to their network, instead of bumping the license like most
&lt;br /&gt;
&amp;quot;normal&amp;quot; vendors.
&lt;br /&gt;
&lt;p&gt;On Tue, 02 Dec 2008 14:14:43 -0500 IT Security
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0046.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0046.html</guid>
<pubDate>Tue, 02 Dec 2008 14:36:12 -0500</pubDate></item>
<item><title>Sonicwall license servers down .. all customers affected</title><description>Posted by IT Security on Dec 2&lt;p&gt;


&lt;p&gt;
&amp;nbsp;Sonicwall (makers of various security products) has had their license
&lt;br /&gt;
manager (server) go haywire overnight and it&#39;s &amp;quot;reset&amp;quot; (meaning invalidated)
&lt;br /&gt;
the licenses on all of their email security products. This means customers
&lt;br /&gt;
can&#39;t login to their own systems (a good case against...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0045.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0045.html</guid>
<pubDate>Tue, 2 Dec 2008 14:14:43 -0500</pubDate></item>
<item><title>Re:  More proof that Microsoft products are probably backdoored</title><description>Posted by Ureleet on Dec 2&lt;p&gt;


&lt;p&gt;
all speculation:
&lt;br /&gt;
&lt;p&gt;no 1 knows 4 sure.
&lt;br /&gt;
&lt;p&gt;http://it.slashdot.org/article.pl?sid=07/12/17/1754257&amp;amp;from=rss
&lt;br /&gt;
&lt;p&gt;http://www.cnn.com/TECH/computing/9909/03/windows.nsa.02/
&lt;br /&gt;
&lt;p&gt;http://www.theforbiddenknowledge.com/hardtruth/nsa_backdoor_windows.htm
&lt;br /&gt;
&lt;p&gt;c how i did that n3td3v?  i posted links, nd talked about...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0044.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0044.html</guid>
<pubDate>Tue, 2 Dec 2008 13:11:18 -0500</pubDate></item>
<item><title>Re:  Project Chroma: A color code for the state ofcyber security</title><description>Posted by Ureleet on Dec 2&lt;p&gt;


&lt;p&gt;
mike c, u r now in the same group as n3td3v.  congratulations 4 being
&lt;br /&gt;
a moron, doing repetitive work, and suggesting nonsensical material.
&lt;br /&gt;
&lt;p&gt;nice idea.  especially if it hadnt already been done.  10x over. o,
&lt;br /&gt;
and u werent the lead of it.
&lt;br /&gt;
&lt;p&gt;plug urself much?
&lt;br /&gt;
&lt;p&gt;how about u plug ur n3td3v group 2?
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0043.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0043.html</guid>
<pubDate>Tue, 2 Dec 2008 13:08:53 -0500</pubDate></item>
<item><title>[ GLSA 200812-07 ] Mantis: Multiple vulnerabilities</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-07
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0042.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0042.html</guid>
<pubDate>Tue, 2 Dec 2008 18:55:03 +0100</pubDate></item>
<item><title>Re:  Project Chroma: A color code for the state ofcyber security</title><description>Posted by vulcanius on Dec 2&lt;p&gt;


&lt;p&gt;
*Sorry for my double posting to you Chris.
&lt;br /&gt;
&lt;p&gt;All this solution does is take up their resources and piss off the users who
&lt;br /&gt;
then find ways to get rid of it or circumvent the useless thing. In the case
&lt;br /&gt;
of Mike C this means they&#39;ll be disabling whatever security software is in
&lt;br /&gt;
place that uses it.
&lt;br /&gt;
&lt;p&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0041.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0041.html</guid>
<pubDate>Tue, 2 Dec 2008 12:47:07 -0500</pubDate></item>
<item><title>[ GLSA 200812-06 ] libxml2: Multiple vulnerabilities</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-06
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0040.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0040.html</guid>
<pubDate>Tue, 2 Dec 2008 18:42:03 +0100</pubDate></item>
<item><title>[ GLSA 200812-05 ] libsamplerate: User-assisted execution of arbitrary code</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-05
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0039.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0039.html</guid>
<pubDate>Tue, 2 Dec 2008 18:40:19 +0100</pubDate></item>
<item><title>[ GLSA 200812-02 ] enscript: User-assisted execution of arbitrary code</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-02
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0038.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0038.html</guid>
<pubDate>Tue, 2 Dec 2008 18:28:07 +0100</pubDate></item>
<item><title>[ GLSA 200812-04 ] lighttpd: Multiple vulnerabilities</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-04
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0037.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0037.html</guid>
<pubDate>Tue, 2 Dec 2008 18:33:06 +0100</pubDate></item>
<item><title>[ GLSA 200812-01 ] OptiPNG: User-assisted execution of arbitrary code</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-01
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0036.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0036.html</guid>
<pubDate>Tue, 2 Dec 2008 18:25:54 +0100</pubDate></item>
<item><title>[ GLSA 200812-03 ] IPsec-Tools: racoon Denial of Service</title><description>Posted by Robert Buchholz on Dec 2&lt;p&gt;


&lt;p&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;
Gentoo Linux Security Advisory                           GLSA 200812-03
&lt;br /&gt;
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -
&lt;br /&gt;...</description>
<link>http://seclists.org/fulldisclosure/2008/Dec/0035.html</link><guid isPermaLink="true">http://seclists.org/fulldisclosure/2008/Dec/0035.html</guid>
<pubDate>Tue, 2 Dec 2008 18:30:56 +0100</pubDate></item>
</channel></rss>