[Full-disclosure] what can be done with botnet CC's? (fwd)

2006-08-13 Thread Gadi Evron
Hi guys, here is a forward of my follow-up to the previous message. Gadi. -- Forwarded message -- Date: Sat, 12 Aug 2006 13:12:30 -0500 (CDT) From: Gadi Evron [EMAIL PROTECTED] To: botnets@whitestar.linuxbox.org Subject: what can be done with botnet CC's? In my last

RE: [Full-disclosure] Concurrency-related vulnerabi lities in browsers -expect problems

2006-08-13 Thread Larry Seltzer
... Larry Seltzer reports from the scene. [EMAIL PROTECTED] Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blog.eweek.com/blogs/larry%5Fseltzer/ Contributing Editor, PC Magazine [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED]

Re: [Full-disclosure] what can be done with botnet CC's? (fwd)

2006-08-13 Thread Dude VanWinkle
On 8/13/06, Gadi Evron [EMAIL PROTECTED] wrote: Hi guys, here is a forward of my follow-up to the previous message. Gadi. -- Forwarded message -- Date: Sat, 12 Aug 2006 13:12:30 -0500 (CDT) From: Gadi Evron [EMAIL PROTECTED] To: botnets@whitestar.linuxbox.org Subject:

Re: [Full-disclosure] what can be done with botnet CC's?

2006-08-13 Thread J. Oquendo
- Forwarded message from Gadi Evron [EMAIL PROTECTED] - From: Gadi Evron [EMAIL PROTECTED] To: botnets@whitestar.linuxbox.org Subject: what can be done with botnet CC's? I work on this [CC] for 30 days, only to find out one of you took it down. -- US Federal Agent, two days ago,

Re: [Full-disclosure] Getting rid of Gadi Evron and Dude VanWinkle

2006-08-13 Thread vodka hooch
Peter Besenbruch [EMAIL PROTECTED] wrote: vodka hooch wrote: hi for months now we've had to put upA piece of advice: Don't speak for others unless the others tell you it's OK to do so.no sir we spek own mind not need permission ;) now its time to shut up how do i setup my gmail?Let's

Re: [Full-disclosure] Getting rid of Gadi Evron and Dude VanWinkle

2006-08-13 Thread Eliah Kagan
On 8/13/06, vodka hooch wrote: no sir full dis for exploits no off topic security chats about botnets etc From the list charter at http://lists.grok.org.uk/full-disclosure-charter.html: Any information pertaining to vulnerabilities is acceptable, for instance announcement and discussion

Re: [Full-disclosure] Getting rid of Gadi Evron and Dude VanWinkle

2006-08-13 Thread vodka hooch
John Dietz [EMAIL PROTECTED] wrote:I personally have nothing against either of the individuals you mentioned, but in the interest of Full Disclosure and Freedom of Information I put together a quick little step-by-step on setting up a filter to blacklist an individual in GMail. Please forgive

[Full-disclosure] Multiple buffer-overflows in libmusicbrainz 2.1.2

2006-08-13 Thread Luigi Auriemma
### Luigi Auriemma Application: libmusicbrainz http://musicbrainz.org/doc/libmusicbrainz Versions: = 2.1.2 and = SVN 8406 (current SVN) Platforms:Windows, *nix, *BSD, Mac and

Re: Re[2]: [Full-disclosure] JavaScript get Internal Address (thanks to DanBUK)

2006-08-13 Thread Pavel Kankovsky
On Sat, 12 Aug 2006, H D Moore wrote: 1) Create a metasploit payload for communicating with shell/meterpreter via DNS queries and replies. This will not be a 'small' payload by any means, but should be feasible for all DCERPC and browser bug exploits. nstx code fits into 20 kB. Not small

Re: [Full-disclosure] Getting rid of Gadi Evron and Dude VanWinkle

2006-08-13 Thread vodka hooch
Eliah Kagan [EMAIL PROTECTED] wrote:On 8/13/06, vodka hooch wrote: no sir full dis for exploits no off topic security chats about botnets etcFrom the list charter at http://lists.grok.org.uk/full-disclosure-charter.html:"Any information pertaining to vulnerabilities is acceptable, forinstance

Re: [Full-disclosure] Getting rid of Gadi Evron and Dude VanWinkle

2006-08-13 Thread Peter Dawson
thats seems to be MERIT issue, take it up with those mod's . FD is still FD.. theres nowhining in here ! On 8/13/06, vodka hooch [EMAIL PROTECTED] wrote: Eliah Kagan [EMAIL PROTECTED] wrote: On 8/13/06, vodka hooch wrote: no sir full dis for exploits no off topic security chats about

[Full-disclosure] RE: ANNOUNCING: 3rd Annual US OWASP AppSec Conference - Oct 16-18 2006 - Seattle, WA

2006-08-13 Thread Dave Wichers
Many more details for the OWASP conference have been settled and are now available on the OWASP site, including: 1) Most of the agenda is set: See: http://www.owasp.org/index.php/OWASP_AppSec_Seattle_2006/Agenda 2) Conference hotel discounts have been negotiated and I'd strongly recommend making