PHP vulnerabilities

Date July 19, 2007

Ubuntu Security Notice USN-485-1 July 17, 2007
php5 vulnerabilities
CVE-2007-1864, CVE-2007-2728
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.
The problem can be corrected by upgrading your system to the
following package [...]

Dovecot vulnerability

Date July 19, 2007

Ubuntu Security Notice USN-487-1 July 17, 2007
dovecot vulnerability
CVE-2007-2231
A security issue affects the following Ubuntu releases:
Ubuntu 6.06 LTS
Ubuntu 6.10
Ubuntu 7.04
This advisory also applies to the corresponding versions of
Kubuntu, Edubuntu, and Xubuntu.

Updating Live Security CD

Date July 19, 2007

Say I want to add a few packages or updates to the latest Backtrack
LiveCD, such as Wireshark or Firefox 2, what is the best way to
accomplish that?
Is there a way to slipstream additional files onto the LiveCD, or can
I save changes onto a USB drive or something like that?
Any help would be greatly appreciated!
Best regards,
John
BackTrack [...]

After a long time

Date July 19, 2007

After a long time we are back with a new design. Just want to let you know the readers that comments just insulting that the bug or exploit is not working have been ignored. This is a discussion I would like you to see the date of the posting and don’t insult.
[...]

SQL Injection Attacks by Example

Date December 4, 2005

A customer asked that we check out his intranet site, which was used by the company’s employees and customers. This was part of a larger security review, and though we’d not actually used SQL injection to penetrate a network before, we were pretty familiar with the general concepts. We were completely successful in this engagement, [...]

Sql Injection and My Sql

Date December 4, 2005

Dear List,
I would like to know if there is any tutorial which describes sql injection in context of My Sql. I feel that the errors returned by mysql when performing a sql injection are less revealing then that returned by other DBs.
Thanks
404
- While it’s not DB specific, the paper “SQL Injection Attacks by Example”
by [...]