<?xml version="1.0" encoding="UTF-8"?>
<rdf:RDF xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns="http://purl.org/rss/1.0/" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:syn="http://purl.org/rss/1.0/modules/syndication/" xmlns:admin="http://webns.net/mvcb/">
  <channel rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure">
    <title>gmane.comp.security.full-disclosure</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure</link>
    <description/>
    <syn:updatePeriod>hourly</syn:updatePeriod>
    <syn:updateFrequency>1</syn:updateFrequency>
    <syn:updateBase>1901-01-01T00:00+00:00</syn:updateBase>
    <items>
      <rdf:Seq>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85861"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85860"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85859"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85858"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85857"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85856"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85854"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85853"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85852"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85851"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85850"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85849"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85848"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85846"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85844"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85843"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85842"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85841"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85840"/>
        <rdf:li rdf:resource="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85839"/>
      </rdf:Seq>
    </items>
    <image rdf:resource="http://gmane.org/img/gmane-25t.png"/>
    <textinput rdf:resource=""/>
  </channel>
  <image rdf:about="http://gmane.org/img/gmane-25t.png">
    <title>Gmane</title>
    <url>http://gmane.org/img/gmane-25t.png</url>
    <link>http://gmane.org</link>
  </image>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85861">
    <title>Re: Info about attack trees</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85861</link>
    <description>&lt;pre&gt;Here's the best info on attack trees:
http://3.bp.blogspot.com/-P_enGjuZU0I/TxFdFfD1A5I/AAAAAAAABKs/DTzpNDG4THc/s1600/ent_isengard_small.jpg
[Description: Description: Description: Description: Description: Description: Description: Description: Description: TimSig]

Timothy "Thor"  Mullen
www.hammerofgod.com
Thor's Microsoft Security Bible&amp;lt;http://www.amazon.com/Thors-Microsoft-Security-Bible-Collection/dp/1597495727&amp;gt;


From: full-disclosure-bounces&amp;lt; at &amp;gt;lists.grok.org.uk [mailto:full-disclosure-bounces&amp;lt; at &amp;gt;lists.grok.org.uk] On Behalf Of Urlan
Sent: Friday, May 25, 2012 9:45 AM
To: Federico De Meo
Cc: full-disclosure&amp;lt; at &amp;gt;lists.grok.org.uk
Subject: Re: [Full-disclosure] Info about attack trees

Federico,

Check this out: http://cwe.mitre.org/top25/
2012/5/25 Federico De Meo &amp;lt;adegod&amp;lt; at &amp;gt;gmail.com&amp;lt;mailto:adegod&amp;lt; at &amp;gt;gmail.com&amp;gt;&amp;gt;
Hello everybody, I'm new to this maling-list and to security in general.
I'm here to learn and I'm starting with a question :)

I'm looking for some informations about attack trees usage in web application a&lt;/pre&gt;</description>
    <dc:creator>Thor (Hammer of God</dc:creator>
    <dc:date>2012-05-25T17:12:41</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85860">
    <title>Re: Info about attack trees</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85860</link>
    <description>&lt;pre&gt;Federico,

Check this out: http://cwe.mitre.org/top25/

2012/5/25 Federico De Meo &amp;lt;adegod&amp;lt; at &amp;gt;gmail.com&amp;gt;




&lt;/pre&gt;</description>
    <dc:creator>Urlan</dc:creator>
    <dc:date>2012-05-25T16:44:54</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85859">
    <title>Info about attack trees</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85859</link>
    <description>&lt;pre&gt;Hello everybody, I'm new to this maling-list and to security in general.
I'm here to learn and I'm starting with a question :)

I'm looking for some informations about attack trees usage in web application analysis.

For my master thesis I decided to study the usage of this formalism in order to reppresent attacks to a web applications. 
I need a lot of use cases from which to start learning common attacks which can help building a proper tree.


I've already read the OWASP top 10 vulnerabilities an I'm familiar with XSS, SQLi, ecc. however I've no clue on how to combine them together in order to perform the steps needed to attack a system. I'm looking for some examples and maybe to some famous attacks from which I can understand which steps are performed and how commons vulnerabilities can being combined together. Any help is really appreciated.


-------------------
Federico.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosur&lt;/pre&gt;</description>
    <dc:creator>Federico De Meo</dc:creator>
    <dc:date>2012-05-25T08:58:08</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85858">
    <title>GreHack 2012 - Call For Papers (CFP)</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85858</link>
    <description>&lt;pre&gt;*GreHack 2012* 2nd Call For Papers
http://ensiwiki.ensimag.fr/index.php/GreHack-2012-english
GreHack 2012 conference will be held in Grenoble (French Alps), France
and brings together students, academia, industry and gov in order to
exchange knowledge around emerging issues in the security + hacking
world.
During the night, a Capture The Flag will take place.


*Suggested Topics (not limited to)*
http://ensiwiki.ensimag.fr/index.php/GreHack_2012-Call_For_Presentation-english
- Track: ethical and legal
  -- greyhat hacking: a consumer advance, or a risque for worlwide security?
  -- current state of laws relative to cyber-security and hacking +
justified suggestions of modifications

- Track: technical
  -- Hadopi: why is it a technical and legal failure? how to exploit
in memory vulnerabilities of Hadopi approved software?

  -- In Memory Vulnerabilities
    --- Windows 8: heap analysis, kernel structures and new memory protections
    --- Exploit Corner: come present us your last sploit!

  -- Hardcore Pene&lt;/pre&gt;</description>
    <dc:creator>Fabien DUCHENE</dc:creator>
    <dc:date>2012-05-24T23:19:46</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85857">
    <title>CFP: Hacktivity 2012, October 12-13, Budapest,Hungary</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85857</link>
    <description>&lt;pre&gt;Hi,

Hacktivity is the largest IT Security Festival in CEE region which
will be held between October 12-13 2012 in Budapest, Hungary.

Hacktivity festival traditionally brings together the official and
alternative representatives of information security profession with
all those interested in the area, in an informal, yet educational, and
usually deep into the technical form.

We are seeking submissions for both two days conference track &amp;amp; 40
minutes "Hello workshops" in the
following areas:

mobile device vulnerabilities, hardware hacking,  attack vectors of
telecommunication networks, network security, security of operating
systems, browser based attacks, misuse of popular applications,
database security,  information gathering from business applications,
malicious and mobile codes, hacking tools, information warfare,
cyber-crime, hacker subculture, social engineering, digital forensics
etc.

We had a privilege to welcome as a speaker in the pas years: Bruce
Schneier, Peter Szor, Joe McCray, Alex Kornbrust&lt;/pre&gt;</description>
    <dc:creator>Attila Bartfai</dc:creator>
    <dc:date>2012-05-24T20:55:04</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85856">
    <title>Malware.lu - analysis and pownage of hespesnetbotnet</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85856</link>
    <description>&lt;pre&gt;Hi,
  a message to announce the creation of http://www.malware.lu few days ago. It is a repository of malware and technical analyses. The goal of the project is to provide samples and technical analyses to security researchers.

  To celebrate the creation an article about the analysis of a botnet (called herpesnet) and the pownage of this botnet ;) : http://code.google.com/p/malware-lu/wiki/en_analyse_herpnet

RootBSD.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

&lt;/pre&gt;</description>
    <dc:creator>rootbsd&lt; at &gt;r00ted.com</dc:creator>
    <dc:date>2012-05-25T07:17:11</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85854">
    <title>ResEdit Buffer Overflow Vulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85854</link>
    <description>&lt;pre&gt;Product Link: http://www.resedit.net/

Affected version: 1.5.11-win32

Type of vulnerabilities: Buffer Overflow.

For Further information:
http://waleedassar.blogspot.com/2012/05/resedit-named-entries-two-buffer.html

POCs:
http://code.google.com/p/ollytlscatch/downloads/detail?name=ResEdit_POC1.exe
http://code.google.com/p/ollytlscatch/downloads/detail?name=ResEdit_POC2.exe


N.B. Not much efforts have been made into these POCs. They just crash the
application but code execution is possible.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/&lt;/pre&gt;</description>
    <dc:creator>Walied Assar</dc:creator>
    <dc:date>2012-05-24T19:54:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85853">
    <title>[SECURITY] [DSA 2480-1] request-tracker3.8security update</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85853</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

- -------------------------------------------------------------------------
Debian Security Advisory DSA-2480-1                   security&amp;lt; at &amp;gt;debian.org
http://www.debian.org/security/                        Moritz Muehlenhoff
May 24, 2012                           http://www.debian.org/security/faq
- -------------------------------------------------------------------------

Package        : request-tracker3.8
Vulnerability  : several
Problem type   : remote
Debian-specific: no
CVE ID         : CVE-2011-2082 CVE-2011-2083 CVE-2011-2084 CVE-2011-2085 
                 CVE-2011-4458 CVE-2011-4459 CVE-2011-4460

Several vulnerabilities were discovered in Request Tracker, an issue
tracking system:

CVE-2011-2082

   The vulnerable-passwords scripts introduced for CVE-2011-0009
   failed to correct the password hashes of disabled users.

CVE-2011-2083

   Several cross-site scripting issues have been discovered.

CVE-2011-2084

   Password hashes could be disclosed by p&lt;/pre&gt;</description>
    <dc:creator>Moritz Muehlenhoff</dc:creator>
    <dc:date>2012-05-24T17:37:03</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85852">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85852</link>
    <description>&lt;pre&gt;Certainly.  In fact, if anyone else wants to help perform the test on behalf of HoG, please let me know and I'll officially write up a change order to specify additional resources.

[Description: Description: Description: Description: Description: Description: Description: Description: Description: TimSig]

Timothy "Thor"  Mullen
www.hammerofgod.com
Thor's Microsoft Security Bible&amp;lt;http://www.amazon.com/Thors-Microsoft-Security-Bible-Collection/dp/1597495727&amp;gt;


From: full-disclosure-bounces&amp;lt; at &amp;gt;lists.grok.org.uk [mailto:full-disclosure-bounces&amp;lt; at &amp;gt;lists.grok.org.uk] On Behalf Of Giles Coochey
Sent: Thursday, May 24, 2012 2:38 AM
To: full-disclosure&amp;lt; at &amp;gt;lists.grok.org.uk
Subject: Re: [Full-disclosure] Certificacion - Profesional Pentester

On 23/05/2012 20:26, Thor (Hammer of God) wrote:
Hell Juan.  As per the conditions of the contract I forwarded, I am pleased to see that you have given me full permission to assess any systems of yours I feel are within scope.  I'm copying in FD again so they can all be witness to the f&lt;/pre&gt;</description>
    <dc:creator>Thor (Hammer of God</dc:creator>
    <dc:date>2012-05-24T17:15:25</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85851">
    <title>VMDK Has Left the Building . Some Nasty AttacksAgainst VMware vSphere 5 Based Cloud Infrastructures</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85851</link>
    <description>&lt;pre&gt;List,

some of you might find this interesting:

http://www.insinuator.net/2012/05/vmdk-has-left-the-building/


have a good one

Enno


&lt;/pre&gt;</description>
    <dc:creator>Enno Rey</dc:creator>
    <dc:date>2012-05-24T16:40:20</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85850">
    <title>CVE-2012-2216 - Social Engine Multiples Vulnerabilities (XSS and CSRF)</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85850</link>
    <description>&lt;pre&gt;Social Engine 4.2.2 Multiples Vulnerabilities
Earlier versions are also possibly vulnerable.

INFORMATION

Product: Social Engine 4.2.2
Remote-Exploit: yes
Vendor-URL: http://www.socialengine.net/
Discovered by: Tiago Natel de Moura aka "i4k"
Discovered at: 10/04/2012
CVE Notified: 10/04/2012
CVE Number: CVE-2012-2216

OVERVIEW

Social Engine versions 4.2.2 is vulnerable to XSS and CSRF.

INTRODUCTION

SocialEngine is a PHP-based white-label social networking service
platform, that provides features similar to a social network on a user's
website. Main features include administration of small-to-mid scale
social networks, some customization abilities, unencrypted code,
multilingual capability, and modular plugin/widget compatibility. There
is a range of templates and add-ons available to extend the basic
features already included in the SocialEngine core.

VULNERABILITY DESCRIPTION

== Persistent XSS in music upload. ==

CWE-79: http://cwe.mitre.org/data/definitions/79.html
The software does not neutralize o&lt;/pre&gt;</description>
    <dc:creator>Tiago Natel de Moura</dc:creator>
    <dc:date>2012-05-24T07:04:48</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85849">
    <title>[ MDVSA-2012:081 ] firefox</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85849</link>
    <description>&lt;pre&gt;-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

 _______________________________________________________________________

 Mandriva Linux Security Advisory                         MDVSA-2012:081
 http://www.mandriva.com/security/
 _______________________________________________________________________

 Package : firefox
 Date    : May 24, 2012
 Affected: Enterprise Server 5.0
 _______________________________________________________________________

 Problem Description:

 Security issues were identified and fixed in mozilla firefox:
 
 Mozilla developers identified and fixed several memory safety
 bugs in the browser engine used in Firefox and other Mozilla-based
 products. Some of these bugs showed evidence of memory corruption
 under certain circumstances, and we presume that with enough effort
 at least some of these could be exploited to run arbitrary code
 (CVE-2012-0468, CVE-2012-0467).
 
 Using the Address Sanitizer tool, security researcher Aki Helin from
 OUSPG found that IDBKeyRange of indexedDB re&lt;/pre&gt;</description>
    <dc:creator>security&lt; at &gt;mandriva.com</dc:creator>
    <dc:date>2012-05-24T14:48:00</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85848">
    <title>Kingcopes AthCon 2012 Slides &amp; Notes</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85848</link>
    <description>&lt;pre&gt;Hello lists,

you can view my slides &amp;amp; notes for my talk entitled "Uncovering
Zero-Days and advanced fuzzing" held at AthCon 2012 at the following
places:

http://www.isowarez.de/

http://kingcope.wordpress.com/

Cheerio,

/Kingcope

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

&lt;/pre&gt;</description>
    <dc:creator>HI-TECH .</dc:creator>
    <dc:date>2012-05-24T11:21:51</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85846">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85846</link>
    <description>&lt;pre&gt;Is your final report going to be public?

&lt;/pre&gt;</description>
    <dc:creator>Giles Coochey</dc:creator>
    <dc:date>2012-05-24T09:37:31</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85844">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85844</link>
    <description>&lt;pre&gt;http://www.reactiongifs.com/wp-content/uploads/2011/05/THISGONBGUD.gif

On May 23, 2012, at 6:42 PM, Alex Buie &amp;lt;abuie&amp;lt; at &amp;gt;kwdservices.com&amp;gt; wrote:


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

&lt;/pre&gt;</description>
    <dc:creator>Zach C.</dc:creator>
    <dc:date>2012-05-24T02:41:23</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85843">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85843</link>
    <description>&lt;pre&gt;This is gonna be fun.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

&lt;/pre&gt;</description>
    <dc:creator>Alex Buie</dc:creator>
    <dc:date>2012-05-24T01:42:16</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85842">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85842</link>
    <description>&lt;pre&gt;On Wed, 23 May 2012 19:26:15 -0000, "Thor (Hammer of God)" said:
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/&lt;/pre&gt;</description>
    <dc:creator>valdis.kletnieks&lt; at &gt;vt.edu</dc:creator>
    <dc:date>2012-05-24T01:14:26</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85841">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85841</link>
    <description>&lt;pre&gt;On 23/05/2012 21:26, Thor (Hammer of God) wrote :
Finally something interesting on this list.
So are we.
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/&lt;/pre&gt;</description>
    <dc:creator>leToff</dc:creator>
    <dc:date>2012-05-23T21:16:32</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85840">
    <title>[Security-news] SA-CONTRIB-2012-085 - BrowserID -MultipleVulnerabilities</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85840</link>
    <description>&lt;pre&gt;View online: http://drupal.org/node/1597414

  * Advisory ID: DRUPAL-SA-CONTRIB-2012-085
  * Project: BrowserID (Mozilla Persona) [1] (third-party module)
  * Version: 7.x
  * Date: 2012-May-23
  * Security risk: Critical [2]
  * Exploitable from: Remote
  * Vulnerability: Cross Site Request Forgery (results in Privilege
    Escalation)

-------- DESCRIPTION  
---------------------------------------------------------

CVE: Requested
The BrowserID module provides integration with BrowserID (also known as
Mozilla Persona) -- a Mozilla project that lets users of your site quickly
and easily log in without needing to remember a password specific to your
site.

The module did not sufficiently validate requests for authentication to log
in, potentially allowing a Cross Site Request Forgery (CSRF) attack and
introducing the possibility that logging in to a malicious site with
BrowserID could give that site the ability to log in to other websites using
your BrowserID identity.

-------- VERSIONS AFFECTED  
---------&lt;/pre&gt;</description>
    <dc:creator>security-news&lt; at &gt;drupal.org</dc:creator>
    <dc:date>2012-05-23T20:23:54</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85839">
    <title>Re: Certificacion - Profesional Pentester</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85839</link>
    <description>&lt;pre&gt;Other way around.  I’ll be sending HIM a  bill.  Which, based on our contract, I will be able to pay on his behalf ☺

From: Peter Dawson [mailto:slash.pd&amp;lt; at &amp;gt;gmail.com]
Sent: Wednesday, May 23, 2012 12:50 PM
To: Thor (Hammer of God)
Cc: Juan Sacco; full-disclosure&amp;lt; at &amp;gt;lists.grok.org.uk
Subject: Re: [Full-disclosure] Certificacion - Profesional Pentester

yes thats true ..but lets not 4get one needs to forkup $150/- before you can finger their servers
2012/5/23 Thor (Hammer of God) &amp;lt;thor&amp;lt; at &amp;gt;hammerofgod.com&amp;lt;mailto:thor&amp;lt; at &amp;gt;hammerofgod.com&amp;gt;&amp;gt;
Hell Juan.  As per the conditions of the contract I forwarded, I am pleased to see that you have given me full permission to assess any systems of yours I feel are within scope.  I’m copying in FD again so they can all be witness to the fact you acting in a manner consistent with the terms of my contract, and that you have given me full permission to do as I wish with any aspect of your network without repercussions.

I’m looking forward to it!  Thank you.

[Descript&lt;/pre&gt;</description>
    <dc:creator>Thor (Hammer of God</dc:creator>
    <dc:date>2012-05-23T20:33:53</dc:date>
  </item>
  <item rdf:about="http://permalink.gmane.org/gmane.comp.security.full-disclosure/85838">
    <title>[Security-news] SA-CONTRIB-2012-084 - Search API- Cross SiteScripting (XSS)</title>
    <link>http://permalink.gmane.org/gmane.comp.security.full-disclosure/85838</link>
    <description>&lt;pre&gt;View online: http://drupal.org/node/1597364

  * Advisory ID: DRUPAL-SA-CONTRIB-2012-084
  * Project: Search API [1] (third-party module)
  * Version: 7.x
  * Date: 2012-May-23
  * Security risk: Moderately critical [2]
  * Exploitable from: Remote
  * Vulnerability: Cross Site Scripting

-------- DESCRIPTION  
---------------------------------------------------------

CVE: Requested
This module enables you to build searches using a wide range of features,
data sources and backends.

The module doesn't sufficiently sanitize user input in some cases when
throwing exceptions or logging errors. This enables attackers to insert
arbitrary data into a page by manipulating its URL. Users would have to open
such a manipulated URL to see the changed content.

This is only possible in some setups of Search API, specifically when users
can manually enter field identifiers in some way – e.g., through an exposed
Views sort or with the old Facets module.

-------- VERSIONS AFFECTED  
------------------------------------&lt;/pre&gt;</description>
    <dc:creator>security-news&lt; at &gt;drupal.org</dc:creator>
    <dc:date>2012-05-23T20:24:33</dc:date>
  </item>
  <textinput rdf:about="http://search.gmane.org/?group=$group=gmane.comp.security.full-disclosure">
    <title>Search Engine</title>
    <description>Search the mailing list at Gmane</description>
    <name>query</name>
    <link>http://search.gmane.org/?group=$group=gmane.comp.security.full-disclosure</link>
  </textinput>
</rdf:RDF>

