Re: [Full-disclosure] iPhone Security Settings

2007-07-01 Thread Stephen Hildrey
Fabio Pietrosanti (naif) wrote: > root:XUU7aqfpey51o:0:0::0:0:System Administrator:/var/root:/bin/sh > mobile:/smx7MYTQIi2M:501:0::0:0:Mobile User:/var/mobile:/bin/sh Nice find. Even my AMD 4200+ can cope with that... $ john pw Loaded 2 passwords with 2 different salts (Standard DES [64/64 BS]) a

Re: [Full-disclosure] iPhone Security Settings

2007-07-01 Thread Erik Tews
Am Montag, den 02.07.2007, 00:07 +0200 schrieb Fabio Pietrosanti (naif): > There are a couple of user with their password: > > root:XUU7aqfpey51o:0:0::0:0:System Administrator:/var/root:/bin/sh > mobile:/smx7MYTQIi2M:501:0::0:0:Mobile User:/var/mobile:/bin/sh > > Does someone have some time to ar

Re: [Full-disclosure] iPhone Security Settings

2007-07-01 Thread Fabio Pietrosanti (naif)
The file is a zip file. It's interesting to note the encrypted DMG image "694-5262-39.dmg" of 82MB . It ask for a password. Instead the 15MB file "694-5259-38.dmg" it's not a DMG image and it's not encrypted (strings 694-5259-38.dmg | less) . Some selected information to have an idea of what's

[Full-disclosure] [ GLSA 200707-01 ] Firebird: Buffer overflow

2007-07-01 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200707-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [SECURITY] [DSA 1328-1] New unicon-imc2 packages fix buffer overflow

2007-07-01 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1328[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp July 01, 2007 - -

[Full-disclosure] [SECURITY] [DSA 1327-1] New gsambad packages fix unsafe temporary files

2007-07-01 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1327[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp July 01, 2007 - -

[Full-disclosure] [SECURITY] [DSA 1326-1] New fireflier-server packages fix unsafe temporary files

2007-07-01 Thread Steve Kemp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1326[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp July 01, 2007 - ---

Re: [Full-disclosure] DOS on phrack?

2007-07-01 Thread Jeff MacDonald
On Sunday 01 July 2007 12:17 am, scott wrote: > Possibly because I am a paranoid phreak who thinks security is a way to > get around this problem? > well, posting that a website is under an attack without any evidence is a little skimp on details, particularly for this list, don't you think? I w

Re: [Full-disclosure] iPhone Security Settings

2007-07-01 Thread Kevin Finisterre (lists)
While you are at it... http://appldnld.apple.com.edgesuite.net/content.info.apple.com/iPhone/ 061-3538.20070629.B7vXa/iPhone1,1_1.0_1A543a_Restore.ipsw -KF On Jun 29, 2007, at 8:10 PM, John Smith wrote: > http://www.andrew.cmu.edu/user/xsk/iPhoneSecuritySettings.html > > John > > _

Re: [Full-disclosure] blackhat talk pulled inexplicably (at the risk of violating MONBACOPL)

2007-07-01 Thread bambam
All interesting thoughts too. I hope we get to know at some point in the fullness of time, I bet it will be an engaging story whatever happened. I love a bit of gossip. (Damn monbacopl). On 6/29/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > On Fri, 29 Jun 2007 16:50:16 BST, bambam said: > >

[Full-disclosure] Landing Securls.com

2007-07-01 Thread pdp (architect)
http://www.gnucitizen.org/blog/landing-securlscom In the last couple of months the GNUCITIZEN group has been secretively working on projects of various nature. We've jump started blogsecurity.net, the only organization that deals with web blog security exclusively, and we also introduced great imp

[Full-disclosure] iPhone Security Settings

2007-07-01 Thread John Smith
http://www.andrew.cmu.edu/user/xsk/iPhoneSecuritySettings.html John ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] SMF 1.1.2

2007-07-01 Thread Павел Ххххххх
Hi! Меня очень сильно заинтересовала инфа о PHP injection в форумах Simle machines forum (SMF 1.1.2). Нельзя ли узнать подробней об этой уязвимости ? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

[Full-disclosure] How to compromise a Microosft site using SQL injection

2007-07-01 Thread Security Admin (NetSec)
http://www.zone-h.org/content/view/14780/31/ Has the explanation, and a place to upload the HOW-TO video (with test explanation) from the hacker, http://www.unbase.com/n/5725974396 Better than any class I have taken on Web application security. It is nice to know that SQL Server 2005 h

[Full-disclosure] phrack / n3td3v

2007-07-01 Thread HACK THE GOV
hey hey, is there a connection between these people?curious. we've ruled out gobbles is n3td3v but maybe phrack is n3td3v or n3td3v is phrack. yours hackthegov ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disc

Re: [Full-disclosure] Rutkowska faces ‘100% unde tectable malware’ challenge, teasing?

2007-07-01 Thread wac
Blah blah blah. Please someone tell Rokowska that we know about what she calls "blue pill" since we where little kids. It was exposed *years ago* (1995 to be exact > 12 years) by Mark A. Ludwig in his Giant Book of Computer viruses Page 391 from American Eagle Publications, Inc. Chapter "Protecte

Re: [Full-disclosure] DOS on phrack?

2007-07-01 Thread scott
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Possibly because I am a paranoid phreak who thinks security is a way to get around this problem? Or just maybe I should have added...or just down for maintenance?...to my original post.That way smart asses like yourself wouldn't need to waste their ti