Re: [Full-disclosure] so gay huh?

2007-11-19 Thread rchrafe
Richard Golodner wrote: > You think those are professional conferences? Those are script > children parties for retards that can't get laid. LOL -- Like my, RCHRAFE didn't know this. > Come to a Homeland > Security meeting Our affiliates are members of several. > or a National Security brie

Re: [Full-disclosure] so gay huh?

2007-11-19 Thread rchrafe
Richard Golodner wrote: > Please come and introduce yourself to me at any Info-Sec conference > or convention so we can meet face to face. We will see what is up then. > Richard Golodner > Mr Golodner, I'm currently unaware as to why you want us to come an

Re: [Full-disclosure] Multiple stack-based buffer overflows in dxmsft.dll

2007-11-19 Thread Elazar Broad
I did not see this: http://www.milw0rm.com/exploits/4251, my apologies, please ignore my last post... ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia

[Full-disclosure] Large Scale MySpace Phishing Attack

2007-11-19 Thread Dancho Danchev
In need of a "creative phishing campaign of the year"? Try this, perhaps the largest phishing attack spoofing MySpace and collecting all the login details at a central location, that's been active for over a month, and continues to be. A Chinese phishing group has come up with legitimate looking My

Re: [Full-disclosure] How to become a Computer Security Professional ?

2007-11-19 Thread rchrafe
XSS Worm XSS Security Information Portal wrote: > #!/bin/sh > > # 0day exploit for Paul Schmehl > # based on information provided by Paul Schmehl > # [EMAIL PROTECTED] > # > > echo pauls > /hack/edu/utdallas.edu/known.addresses > > googledump.pl --email-addresses --contex

Re: [Full-disclosure] How to become a Computer Security Professional ?

2007-11-19 Thread rchrafe
Richard Golodner wrote: > Get a good job where you can find best security practices being used > and learn from others who have been in the field. You will develop your own > set of tools and ideas, but the concepts are almost always the same. Defense > in depth is a good idea and it works. >

Re: [Full-disclosure] How to become a Computer Security Professional ?

2007-11-19 Thread rchrafe
worried security wrote: > On Nov 17, 2007 1:08 PM, Meef <[EMAIL PROTECTED]> wrote: > >> What are the steps to follow to become a computer security professional ?, >> > > Sorry, you will never make it to professionalism as you broke the > first and most important rule. > > NEVER POST ON A PU

[Full-disclosure] The Call to Reason

2007-11-19 Thread rchrafe
“The Call to Reason.” By the rhcrafe Senior seat of officials. BEHOLD AND WITNESS, those who read this document, this which is the official PROCLAMATION and LETTER OF INTENT concerning the future of RCHRAFE and RCHRAFE member states; the words within are no less than the movement of RCHRAFE from it

[Full-disclosure] Tha Manual.

2007-11-19 Thread rchrafe
Tha manual. We do not care about you, or your affilates. We are in position, and a new army has emerged. The first of a set of manuals, being provided as follows shall be provided wherein those who maintain an interest in the power of the simplicity of man. The Manual Written by d4rk1v4n, part

[Full-disclosure] [ MDKSA-2007:228 ] - Updated cups packages fix vulnerabilities

2007-11-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:228 http://www.mandriva.com/security/ ___

[Full-disclosure] [ MDKSA-2007:227 ] - Updated poppler packages fix vulnerabilities

2007-11-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:227 http://www.mandriva.com/security/ ___

[Full-disclosure] Multiple stack-based buffer overflows in dxmsft.dll

2007-11-19 Thread Elazar Broad
There are multiple stack overflows in dxmsft.dll version 6.3.2900.3199(Image DirectX Transforms). This DLL exposes DirectX Image Transform objects which are safe for scripting. The issue is with the Color property of certain objects, so I am assuming this property is inherited from a base interf

[Full-disclosure] rPSA-2007-0242-1 php5 php5-cgi php5-mysql php5-pear php5-pgsql php5-soap php5-xsl

2007-11-19 Thread rPath Update Announcements
rPath Security Advisory: 2007-0242-1 Published: 2007-11-19 Products: rPath Appliance Platform Linux Service 1 rPath Linux 1 Rating: Minor Exposure Level Classification: Remote Deterministic Denial of Service Updated Versions: [EMAIL PROTECTED]:1/5.2.5-1-1 [EMAIL PROTECTED]:1/5.

[Full-disclosure] H2HC Materials

2007-11-19 Thread Rodrigo Rubira Branco (BSDaemon)
For those who have interest in better know about H2HC conference, the presentation materials are now online at http://www.h2hc.org.br/repositorio.php cya, Rodrigo (BSDaemon). -- http://www.kernelhacking.com/rodrigo Kernel Hacking: If i really know, i can hack GPG KeyID: 1FCEDEA1

[Full-disclosure] [ MDKSA-2007:226 ] - Updated kernel packages fix multiple vulnerabilities and bugs

2007-11-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:226 http://www.mandriva.com/security/ ___

[Full-disclosure] [ GLSA 200711-28 ] Perl: Buffer overflow

2007-11-19 Thread Pierre-Yves Rofes
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200711-28 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - -

[Full-disclosure] Wordpress Cookie Authentication Vulnerability

2007-11-19 Thread Steven J. Murdoch
Wordpress Cookie Authentication Vulnerability Original release date: 2007-11-19 Last revised: 2007-11-19 Latest version: http://www.cl.cam.ac.uk/users/sjm217/advisories/wordpress-cookie-auth.txt CVE ID: Source: Steven J. Murdoch Systems Affected: Wordp

[Full-disclosure] [ MDKSA-2007:225 ] - Updated net-snmp packages fix remote denial of service vulnerability

2007-11-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDKSA-2007:225 http://www.mandriva.com/security/ ___