Re: [Full-disclosure] iPhone data protection flaw

2010-05-19 Thread Gregor Schneider
On Wed, May 19, 2010 at 12:22 AM, comex wrote: > On Mon, May 17, 2010 at 6:28 AM, Bernd Marienfeldt wrote: > > I'm not sure how it's done on Linux, but in general the iPhone pairs > with computers and refuses to talk to to an unpaired computer if there > is a passcode lock.  You might only be abl

Re: [Full-disclosure] iPhone data protection flaw

2010-05-18 Thread Gregor Schneider
On Tue, May 18, 2010 at 11:39 AM, wrote: > > The fact that most devices do it doesn't mean it's not a security flaw. > -1 AFAIK the USB-protocol does not contain any authorization / authentication-mechanism: http://www.beyondlogic.org/usbnutshell/usb3.htm Please correct me if I'm wrong... Ch

Re: [Full-disclosure] iPhone data protection flaw

2010-05-18 Thread Gregor Schneider
Bernd, IIRC, the iPhone gets mounted, however, you'll only have access to pictures & videos (3gs). I wouldn't consider that a security flaw - this behaviour is standard for almost any device being mounted via USB. Question: iPhone OS 3.1.3? Jailbreaked / original firmware? I'll check it tonight

Re: [Full-disclosure] anybody know good service for cracking md5? 6A9-4CD

2010-02-05 Thread Gregor Schneider
2010/2/4 Thor (Hammer of God) : > It's actually "you're," but I never bothered correcting him, even though > having it in his signature was kind of bad. > Whoops - I've grabbed that signature ages ago and it never occured to me that there was a typo - anyhow, will correct that somewhen. But inste

Re: [Full-disclosure] anybody know good service for cracking md5? 6A9-4CD

2010-02-04 Thread Gregor Schneider
2010/2/4 McGhee, Eddie : > "because your paranoid," > uhm, well, i believe being paranoid is a useful attitude when following this list gregor -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key available @ http://pg

Re: [Full-disclosure] anybody know good service for cracking md5? 6A9-4CD

2010-02-04 Thread Gregor Schneider
2010/2/4 netinfinity : > And why are my reply's spam??? - beacuse of your fullquotes - because you're hijacking a thread -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key available @ http://pgpkeys.pca.dfn.de:11371 @ h

Re: [Full-disclosure] e107 latest download link is backdoored

2010-01-26 Thread Gregor Schneider
Seems as if e107.org now is spreading some bad stuff: Virus/Spyware Mal/ObfJS-CB! - at least that's what Sophos is telling me Wondering why the admins of e107.org still keep this site up & running - the site should have been taken down right after they saw that it ws compromised. Irresponsib

Re: [Full-disclosure] iiscan results - a closer look

2010-01-22 Thread Gregor Schneider
FYI: Here's a brief analysis of the IISCAN-ops: http://blog.sucuri.net/2010/01/closer-look-at-iiscan.html Cheers Gregor -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key available @ http://pgpkeys.pca.dfn.de:11371 @

Re: [Full-disclosure] iiscan results - a closer look

2010-01-19 Thread Gregor Schneider
Hm, wondering if I should allow a China based company to scan any f my servers just my 2 cents... -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key available @ http://pgpkeys.pca.dfn.de:11371 @ http://pgp.mit.edu:11

Re: [Full-disclosure] Fwd: All China, All The Time

2010-01-14 Thread Gregor Schneider
2010/1/13 Christian Sciberras : > > That reminded me on China's Green Dam Project (GDYP) [ ... ] > Not only that, it had serious security flaws, 2 of which allowed > remote execution. flaw? must be kidding - that was a feature... cheers gregor -- just because your paranoid, doesn't mean they're

Re: [Full-disclosure] IE 0day for sale

2009-12-12 Thread Gregor Schneider
2009/12/12 Jeff Williams : > And the question is now: > should the Mossad, NSA, etc be considered as bad guys ? > that is a definately YES gregor -- just because your paranoid, doesn't mean they're not after you... gpgp-fp: 79A84FA526807026795E4209D3B3FE028B3170B2 gpgp-key available @ http://pgpk

Re: [Full-disclosure] Some shit going on in seclist

2009-11-25 Thread Gregor Schneider
2009/11/24 Tyler Durten : > I guess this is an email list. This guy - Day Jay, has put up this > vulnerability up on seclist, stating that it relates to microsoft iis 6.0, > when it actually deletes the user's home folder. This is total shit, and if > you (Day Jay), think that this is ultral33t, kn

Re: [Full-disclosure] UK jails schizophrenic for refusal to decrypt files

2009-11-25 Thread Gregor Schneider
To me, the Brits - sorry, their government - are more and more turning into fascists. What, if somebody has 'really' forgotten his password or lost his key? Jail for amnesia? besides, everybody has the right to refuse to answer - meaning the freedom of his / her mind. Today, a computer often has