lists.openwall.net | lists / announce owl-users owl-dev john-users john-dev passwdqc-users yescrypt popa3d-users / oss-security kernel-hardening musl sabotage tlsify passwords / crypt-dev xvendor / Bugtraq Full-Disclosure linux-kernel linux-netdev linux-ext4 linux-hardening linux-cve-announce PHC | |
Open Source and information security mailing list archives
| ||
|
Message-ID: <CAM75b+VCWoR8C8CX9ZMprO3_eDZFJ=DMLbLan+hgNyQ3akaNjw@mail.gmail.com> Date: Mon, 4 Aug 2014 13:26:03 -0400 From: Nathan Power <np@...uritypentest.com> To: fulldisclosure@...lists.org Subject: [FD] Microsoft Exchange Multiple Vulnerabilities Exchange Multiple Internal IP Disclosures ------------------------------------------ Advisory: http://foofus.net/?p=758 http://www.securitypentest.com/2014/08/exchange-multiple-internal-ip.html Autodiscover Enumeration Vulnerability ------------------------------------------ Advisory: http://foofus.net/?p=793 http://www.securitypentest.com/2014/08/autodiscover-enumeration-vulnerab ility.html CAS Authentication Timing Attack ------------------------------------------ Advisory: http://foofus.net/?p=784 http://www.securitypentest.com/2014/08/cas-authentication-timing-attack. html POC video: http://www.securitypentest.com/2014/08/owa-timing-attack-poc.html Tools ------------------------------------------ http://foofus.net/?p=804 _______________________________________________ Sent through the Full Disclosure mailing list http://nmap.org/mailman/listinfo/fulldisclosure Web Archives & RSS: http://seclists.org/fulldisclosure/