Re: [Full-disclosure] Re: kiddie porn warning [was: Fwd: Re: montspace -- child porn (site still up)]

2006-04-20 Thread Steve Kudlak
This is an example of politicos gone wild. What funtionally happens is that when some hot button issue comes down the pike every politico wants to be seen as having done something about whatever the big scary thing is. In the 1950s and the early 1960s it was Communism and Communist

[Full-disclosure] RE: Microsoft DNS resolver: deliberately sabotaged hosts-file lookup

2006-04-20 Thread Nick FitzGerald
Mario Contestabile wrote: Fyi, Any NT app can bypass the local hosts file using DnsQuery(...,..., DNS_QUERY_NO_HOSTS_FILE, ...); Any NT app ??? http://msdn.microsoft.com/library/en-us/dns/dns/ dnsquery.asp?frame=true ... Windows 2000 Server and Windows 2000 Professional: This

[Full-disclosure] SUSE Security Announcement: Mozilla Firefox, Mozilla Suite various problems (SUSE-SA:2006:021)

2006-04-20 Thread Marcus Meissner
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 __ SUSE Security Announcement Package:MozillaFirefox,mozilla Announcement ID:SUSE-SA:2006:021 Date:

Re: [Full-disclosure] selling ms office bug

2006-04-20 Thread Valdis . Kletnieks
On Wed, 19 Apr 2006 23:19:32 +0200, [EMAIL PROTECTED] said: auction is up for whitehat industry only, proof required. Somebody can prove themselves a black hat pretty easily. But how do you prove your hat is white and not grey? pgpqY6oUP5rda.pgp Description: PGP signature

Re: [Full-disclosure] Gary McKinnon

2006-04-20 Thread Don Ankney
On Apr 14, 2006, at 10:30 AM, bkfsec wrote: Truth be told, more people hate the current republican party than like it. If everyone who could have voted would have voted, it would be a landslide victory for the left. This is especially true if people were to vote along ideological lines

Re: [Full-disclosure] selling ms office bug

2006-04-20 Thread Robert Waters
On 4/20/06, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: On Wed, 19 Apr 2006 23:19:32 +0200, [EMAIL PROTECTED] said: auction is up for whitehat industry only, proof required. Somebody can prove themselves a black hat pretty easily. But how do you prove your hat is white and not grey? ...

[Full-disclosure] Sql Injection in BookMark4u

2006-04-20 Thread (M.o.H.a.J.a.L.i)
site: http://bookmark4u.sourceforge.net/ Hello i found a vulnerability in bookmark4u that u can use to make sql injections... the following PoC changes the admin password: [code] form action='' method='post' trtd align='center' input type='hidden' name='sqlcmd' value=# add a administrator

[Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread n3td3v
For legal reasons this is not a Secunia advisory. Any republication of this advisory to the Secunia website or to attach the Secunia URL to the bottom of my advisory via the Full-Disclosure mailing list is bad pratice. I'm

RE: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread fractalg
Dude, SHUT THE FUCK UP !!! I think we are all tired of this crap you brought to the list. Yes, I know that replying isn't the best idea, but this is really getting annoying... Now, SHUT THE FUCK UP, pretty please ??? -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Morning Wood
When you subscribe at grok.org.uk, you are not made aware that Secunia is affiliated with the mailing list and fails to warn users that a Secunia URL will be placed at the bottom of a user or company disclosure. what you fail to see is... we don't care. Further, any information a researcher

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread n3td3v
On 4/20/06, Morning Wood [EMAIL PROTECTED] wrote: Since you are hellbent on leather here... your oh so loved Securityfocus / Bugtraq does the same thing. Many of my own advisories are put on Bugtraq without me submitting directly. I guess http://www.osvdb.org is just as guilty? Perhaps

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Morning Wood
No, Mlw0rm tells you who discovered the vulnerability, as do other sites. Although Secunia tell you it was all their work. I bet you would be pretty pissed if you post one of your XSS or SQL injection, and it appears on the Secunia website the next day saying Secunia FOUND. WRONG WRONG WRONG

Re: [Full-disclosure] kiddie porn warning [was: Fwd: Re: montspace -- child porn (site still up)]

2006-04-20 Thread Steve Kudlak
Gadi Evron wrote: Gary E. Miller wrote: And how long did it take that mole to pop back up? Tompa.com is already back on the air. Montspace.com is not back up yet, but that was just Guys, please refrain from going to that site or downloading it. In some western countries just having CP

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread gboyce
On Thu, 20 Apr 2006, n3td3v wrote: On 4/20/06, Morning Wood [EMAIL PROTECTED] wrote: Since you are hellbent on leather here... your oh so loved Securityfocus / Bugtraq does the same thing. Many of my own advisories are put on Bugtraq without me submitting directly. I guess http://www.osvdb.org

[Full-disclosure] Cisco PIX TCP COnnection

2006-04-20 Thread Julie S. Lin
Hi I would like more info on this DOS. I am using PiX515e version 6.3(3) is there a fix yet? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread A . L . M . Buxey
Hi, If they are rewording advisories, then they are revealing information which was not secret. Assuming that they are in fact claiming the discovery as their own (I haven't checked this myself), I'd consider that dishonest, but I don't know it would be considered a copyright violation.

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Mike Owen
On 4/20/06, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: as for this list being sponsored by Secunia. did n3td3v not actually READ the list at all before subscribing or posting to it? who wouldn't take such preliminary cautions? alan The list was purchased by Secunia a year or so ago.

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread n3td3v
On 4/20/06, Morning Wood [EMAIL PROTECTED] wrote: You are mad because you have never once had any information disimenated by any security site, why? Cuz you dont do any research, find vulns, write exploits or have disclosed anything worthy of publication. Further, because of your continued

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Brian Eaton
On 4/20/06, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: as for this list being sponsored by Secunia. did n3td3v not actually READ the list at all before subscribing or posting to it? who wouldn't take such preliminary cautions? A troll? ___

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Morning Wood
You think? I have setup a webpage to tell you what I think of you and everyone else. http://geocities.com/n3td3v who doubts me. One time I added you to Yahoo Messenger thinking you were a friend but you just walk all over me like everyone else. Screw you man thats right, YOU added me ( i never

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Andrew A
Correction: You have never attained respect from anyone.On 4/20/06, Morning Wood [EMAIL PROTECTED] wrote:I may not have produced the most ground breaking exploits and vulns, but I have something you will never atain, and that is RESPECT. ___

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread c.e. gene c.
my outlook on this whole thing of all the bitching that has been posted to this list for the last few months. Don't get me wrong on this? I always open my FD list folder when I need to take a break from my real work. And enjoy a few laughs from some of the post here! the link below is about the

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread Morning Wood
Correction: You have never attained respect from anyone. since you are a bantown troll, I will just disregard you bai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by

RE: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread y0himba
The amazing part is that with all the combined intelligence here, you people fall for his tricks. By replying to n3td3v, you give him what he wants, attention. Even this will give him satisfaction. Just ignore him, kill file him, whatever, but don't reply, it makes him even more trollish.

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread c.e. gene c.
my outlook on this whole thing of all the bitching that has been posted to this list for the last few months. Don't get me wrong on this? I always open my FD list folder when I need to take a break from my real work. And enjoy a few laughs from some of the post here! the link below is about the

[Full-disclosure] [SecuriWeb 2006.1] directory traversal in [EMAIL PROTECTED] and ARI

2006-04-20 Thread François Harvey
ID : 2006.1 Product : ARI (Asterisk Recording Interface) http://www.littlejohnconsulting.com/?q=node/11 [EMAIL PROTECTED] Distribution http://asteriskathome.sourceforge.net/ Affected product : = 0.7.15

[Full-disclosure] [ GLSA 200604-10 ] zgv, xzgv: Heap overflow

2006-04-20 Thread Sune Kloppenborg Jeppesen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200604-10 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Google Groups e-mail disclosure in plain text

2006-04-20 Thread 0x80
n3td3v is a kid and a troll. But you my stupid dumb fucking fuck need to check yourself before you lip off about shit you know nothing about. you have no clue who I am and no clue what I have or have not done. you on the other hand. bah... too easy.. On Wed, 19 Apr 2006 06:09:30 -0700

Re: [Full-disclosure] selling ms office bug

2006-04-20 Thread 0x80
You open a file and shellcode runs? Wow... hey guys I have a executable to sell.. all you need to do is get the user to open it and the code runs compromising the system... sigh.. On Wed, 19 Apr 2006 14:19:32 -0700 [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: auction is up for whitehat

Re: [Full-disclosure] selling ms office bug

2006-04-20 Thread 0x80
Why not just say that it is either the unpatched PPT bug or the Visio one that has been known by others. Unless of course you have a 1337 Excel one again On Wed, 19 Apr 2006 14:24:31 -0700 [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: forgot to mention so the format of the file is popular ,

Re: [Full-disclosure] Secunia illegal spam and advisory republication

2006-04-20 Thread 0x80
PURCHASED... So how do y'all who post real information here feel about someone else making money off of your work. Nice community resource.. On Thu, 20 Apr 2006 14:45:57 -0700 Mike Owen [EMAIL PROTECTED] wrote: On 4/20/06, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: as for this list