dev.emsdn.com

Join About
Home SITEMAP Most Recent

Security

Class Localtion: Home »» Security [Programming]
Security(Security list covers insecure websites, how to find and prevent phishing, reporting vulnerabilities, and using encryption.) under "Programming"


Escaping LDAP queries

Hi all,I'm looking for methods to properly escape LDAP queries in a Javaenvironment. From the RFC's it appears that both the distinguishedname (DN) and the search filter have their own sets of meta-characters. In the case of performing the query through JNDI, it isalso necessary to esc

Escalation of privileges in Outpost and Lavasoft Firewalls-Unusual ShellExecute behavior

Vulnerable Products: Firewall Pro ver. 3.51.759.6511 (462)And Lavasoft Personal Firewall ver. 1.0.543.5722 (433)Summary of problem: The firewall runs its windows under a SYSTEM context.A user with lower privileges than SYSTEM could locate the (open folder) control on someof these windows, termin

escalating privileges with named pipes

Dear /dev/null,You can try this one:DigitalScream, Windows named pipes exploitationIn addition to explanations there are references to real-world exploits., May 12, 2006, 6:16:11 PM, you wrote to full-disclosure (AT) lists (DOT) grok.org.uk:dnHello list,dndoes anyone know a practical example of

escalating privileges with named pipes

Hello list,does anyone know a practical example of named pipe attack to escalateprivileges in Windows environment? I'm trying to learn more about named pipeattacks so any link/paper suggestion would be much appreciated (I alreadyfound "Discovering and Exploiting Named Pipe Security Flaws fo

ESB Considerations?

PGP SIGNED MESSAGEHash: SHA1Hi List,I am in a situation where I need to consider an enterprise ESB. Arethere any special considerations or potential weaknesses I should beaware of? Is this question too vague?Any thoughts appreciated!- -d PGP SIGNATUREVersion: GnuPG v1.4.1 (Darwin)/JggP+FrLLAjyC

Error while logging snort output to mysql

Hi all,Has any one tried running snort with mysql version 5.1? I get the followingerror when I start snort after configuring it to send logs to mysql.database: compiled support for ( mysql odbc )database: configured to use mysqldatabase: user = snortuserdatabase: password is setdatabase: databas

Error when snort logs to mysql

Hi all,I am running the following configurationsnort=DBCmysql=5.0.17.S=Windows XP professional sp2I am getting the following error when I run snortThe default logging mode is now PCAP, use "-K ascii" to activatethe old default logging mode.database: mysql_error: Incorrect datetime value: '2