Ethical Hacking Learn to find vulnerabilities before the bad guys do! Gain real world hands on hacking experience in our state of the art hacking lab. Course designed and taught by expert instructors with years of penetration testing experience. 12 student maximum in every class. Certification attempt included in every package. | Computer Forensics Training at InfoSec Institute Gain the in-demand skills of a certified computer examiner, learn to recover trace data left behind by fraud, theft, and cybercrime perpetrators. Discover the source of computer crime and abuse at your organization so that it never happens again. All of our class sizes are guaranteed to be 12 students or less to facilitate one-on-one interaction with one of our expert instructors. |

| Subject: | [Full-Disclosure] RS-2004-1: SquirrelMail "Content-Type" XSS vulnerability |
|---|---|
| Date: | Sun, 30 May 2004 03:15:44 +0200 |
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Hello, I discovered a new XSS vuln in SquirrelMail which is quite dangerous since it could be exploited simply by sending a specially crafted mail to the victim. The victim only has to read the email in order to trigger the exploit. This bug is present in latest versions (as well as older ones). I also noticed that latest Debian stable distro ships a very old version of SquirrelMail, which is vulnerable to several old XSS bugs (in addition to the new one). Detailed info is included in attached advisory. Just in case of problems with the attachment, you can download it from my site: http://www.rs-labs.com/adv/RS-Labs-Advisory-2004-1.txt Finally, I'd like to publicly state that somebody is using my nickname (RoMaNSoFt) for mass-defacing PHP-Nuke sites (and some other nasty actions like claiming to be the author of docs written by me) in a clear attempt to incriminate myself. I'm not either a defacer, neither a cracker. So please, don't mistake that script-kiddie with the real RoMaNSoFt. Contact me for additional information or if you've been affected/attacked by this likely Moroccan kiddie. Regards from Spain, --Roman - -- PGP Fingerprint: 09BB EFCD 21ED 4E79 25FB 29E1 E47F 8A7D EAD5 6742 [Key ID: 0xEAD56742. Available at KeyServ] -----BEGIN PGP SIGNATURE----- Version: PGPfreeware 6.5.8 for non-commercial use <http://www.pgp.com> iQA/AwUBQLh7SOR/in3q1WdCEQL4kgCgjiwOlryda2lDHgszFmg3pX6tlrIAoLhR 34XnlOcYqsDDAv3Xl2A/5rzj =Gz6D -----END PGP SIGNATURE-----
RS-Labs-Advisory-2004-1.txt
Description: Text document
| <Prev in Thread] | Current Thread | [Next in Thread> |
|---|---|---|
| ||
| Previous by Date: | RE: [Full-Disclosure] Re: EnderUNIX Security Anouncement (Isoqlog and Spamguard), Simon Lorentsen |
|---|---|
| Next by Date: | RE: [Full-Disclosure] An anatomy of a PGP Joe Job, Aditya, ALD [Aditya Lalit Deshmukh] |
| Previous by Thread: | [Full-Disclosure] Re: EnderUNIX Security Anouncement (Isoqlog and Spamguard), Aycan iRiCAN |
| Next by Thread: | [Full-Disclosure] difference ;), Kovács László |
| Indexes: | [Date] [Thread] [Top] [All Lists] |