Re: Messenger/Hotmail passwords at risk

2001-07-16 Thread gregory duchemin
hello >The claim that he makes is surely interesting. I tried running the md5crack >on my system which is a linux6.1 Intel pentium 3 733 MHz and I was able to >get around 1/100 of what he claims. Although he uses a 1GHz AMD can the >performances be so different ??? try without -v/-V (verbose),

Messenger/hotmail MITM exploit

2001-07-15 Thread gregory duchemin
he wishes to open it anyway. Guess what should be a typical user behavior ? ;) this script need the useful arptool from Cristiano Lincoln Mattos and our favorite web server (for hotmail spoofing and fake messenger update) use it for educationnal purpose only. cheers, Gregory Duchemin

APOP passwords at risk

2001-07-10 Thread gregory duchemin
hello >This is the exact same thing APOP does - server sends a string, client >appends password to string, takes MD5 hash and sends back. If your >cracker is what you say it is (I haven't checked) then APOP should be >just as vulnerable. > >Greetz, Peter yep, looking briefly at the rfc 1939, i f

Re: Small TCP packets == very large overhead == DoS?

2001-07-09 Thread gregory duchemin
hello, know if the TCP silly window syndrome might be used too ? Uploading/downloading files byte per byte to/from a remote ftp server with a stupid window size of one byte may generate a very high overhead. My tanenbaum book say that Clark solution consists in avoiding sender (attacker) from

Messenger/Hotmail passwords at risk

2001-07-09 Thread gregory duchemin
y as possible. Finally, never never trust hotmail and any other web based free accounts for you very own mails. Gregory Duchemin Security Consultant NEUROCOM CANADA 1001 Bd Maisonneuve Ouest, Suite 200 Montreal Quebec H

Microsoft has just fixed hotmail/css hole

2001-01-30 Thread gregory duchemin
Microsoft has finally patched today the css/div hole in hotmail. Absolute positionning in 'style' is now filtered with static. Others web based mailers, sites with bookmark, forum etc ... should quickly do the same. Above, the original mail from wouter Westerveld who informed me. Cheers

hotmail css/div exploit: new version

2001-01-30 Thread gregory duchemin
s activity. Have a nice day === Gregory Duchemin - Security Consultant - NEUROCOM CANADA 1001 bd Maisonneuve Ouest - suite 200 H3A 3C8 Montreal - Quebec - CANADA [EMAIL PROTECTED] _ Get Your Private, Free E

spoofing hotmail with css (exploit)

2001-01-28 Thread gregory duchemin
abuse and copyright violation. did work fine with MSIE, would need some little changes to work on Netscape. Be warnned when hotmail ask u next time ;) Cheers, Gregory Duchemin http://c3rber.multimania.com/merci.txt" method="G

Wingate 4.1.1, new year 's bug: UPDATE

2001-01-26 Thread gregory duchemin
ck), just use the IP address your really need !. Have a nice day, === Gregory Duchemin -- Security consultant NEUROCOM CANADA 1001 bd maisonneuve Ouest, suite 200 Montreal, Quebec, H3A 3C8 Canada [EMAIL PROTECTED] === hi bugtraqers wingate 4.1.1

Hotmail spoofing with css

2001-01-24 Thread gregory duchemin
rial was needed. == horsemail.com == Have a nice day, = Gregory Duchemin NEUROCOM CANADA 1001 bd Maisonneuve Ouest - suite 200 Montreal(Quebec) H3A 3C8 CANADA [EMAIL PROTECTED] ;) _ Get Your Priva

OfficeScan TrendMicro: admin for everybody !

2000-03-16 Thread Gregory Duchemin
ion between clients, web based-server and admin workstation. But that 's not enough, they may use session id concept for cgi access too. regards, == Gregory Duchemin Network and security engineer http://www.securite-internet.com NEUROCOM ==

NEUROCOM: Nashuatec D445/435 vulnerabilities updated

1999-11-17 Thread gregory duchemin
g in a possible denial of service attack. Have a nice day ****** Gregory Duchemin Security & networks Engineer Email: [EMAIL PROTECTED] http://www.securite-internet.com

NEUROCOM: Nashuatec printer, 3 vulnerabilities found

1999-10-14 Thread gregory duchemin
onymously. The last one is a denial of service with an icmp redirect storm against the printer ip stack. Use winfreez.c to test it. The printer 'll not respond anymore during the attack. Have a nice day, Gregory Duchemin. - NEUROCOM http://www.neurocom.com 179/181 Av

mini-sql Buffer Overflow

1999-09-30 Thread gregory duchemin
al Linux exploit for w3-auth Authentication module from mini-sql package Gregory Duchemin Aka c3RbeR Neurocom -- Mai 1999 E-mail: [EMAIL PROTECTED] ** / #include #include #include #include #include #include #define GREEN "

buggy msql again (v2.0.11)

1999-09-08 Thread gregory duchemin
trary code. i'm going to write an exploit. Have a nice day --- Gregory Duchemin - [EMAIL PROTECTED] Security Engineer NEUROCOMhttp://www.neurocom.com/ 179/181 avenue Charles de Gaulle 92200 Neuilly Sur Seine Tel: 01.41.43.84.84 Fax: 01.41.43.84.80

Stupid bug in W3-msql

1999-08-18 Thread gregory duchemin
ory in your site, ok...in this case, u don't matter with this bug Otherwise, don't put your .htpasswd files under apache root (change your link in .htaccess) and contact quickly Hughes Technology. have a nice day Gregory Duchemin (security engineer) Neurocom 179-181 Av Charles De Gaulle 92200 Neuilly Sur Seine