Re: [Full-disclosure] what is this?

2008-01-16 Thread auto71278
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 >No, he's Nick Fitzgerald, one of the foremost experts in the world >on malware, Dear Paul, sorry for the delay in answering to your e-mail but Hermione and I were attending an important class here at Hogwarts. Anyway, now I’m completely at your disp

[Full-disclosure] Hardware-based full disk encryption

2008-01-16 Thread Frank Sanders
Can any one recommend such system ? What are the Pros and Cons and from which vendor(s) do you know that they already integrated it with which security model ? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-char

Re: [Full-disclosure] Hardware-based full disk encryption

2008-01-16 Thread coderman
On Jan 16, 2008 4:53 AM, Frank Sanders <[EMAIL PROTECTED]> wrote: > Can any one recommend such system ? ingredients: - c7 core with padlock crypto engine (8+GBytes/sec AES throughput, no crypto penalty) - loop-aes multi-key-v3 with key scrubbing and padlock acceleration in loonix kernel - read onl

Re: [Full-disclosure] Hardware-based full disk encryption

2008-01-16 Thread Fredrick Diggle
also keep all moneys in mattress bank. is only safe place and interest is good. On Jan 16, 2008 9:38 AM, coderman <[EMAIL PROTECTED]> wrote: > On Jan 16, 2008 4:53 AM, Frank Sanders <[EMAIL PROTECTED]> wrote: > > Can any one recommend such system ? > > ingredients: > - c7 core with padlock crypto

[Full-disclosure] Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow

2008-01-16 Thread Cisco Systems Product Security Incident Response Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Cisco Security Advisory: Cisco Unified Communications Manager CTL Provider Heap Overflow Document ID: 100345 Advisory ID: cisco-sa-20080116-cucmctl http://www.cisco.com/warp/public/707/cisco-sa-20080116-cucmctl.shtml Revision 1.0 For Public

Re: [Full-disclosure] Hardware-based full disk encryption

2008-01-16 Thread Elazar Broad
Cryptsetup with LUKS is an option, you could build a custom kernel and initrd and put it on a UFD... Elazar On Wed, 16 Jan 2008 10:38:37 -0500 coderman <[EMAIL PROTECTED]> wrote: >On Jan 16, 2008 4:53 AM, Frank Sanders <[EMAIL PROTECTED]> >wrote: >> Can any one recommend such system ? > >ingre

[Full-disclosure] Peers static overflow in BitTorrent 6.0 and uTorrent 1.7.5

2008-01-16 Thread Luigi Auriemma
### Luigi Auriemma Applications: BitTorrent and uTorrent http://www.bittorrent.com http://www.utorrent.com Versions: BitTorrent <= 6.0 (build 5535) uTorr

[Full-disclosure] TPTI-08-02: Cisco Call Manager CTLProvider Heap Overflow Vulnerability

2008-01-16 Thread DVLabs
3 191A4 E9+ jmp loc_405FFF This will continue until heap chunks are overwritten at the users control, which can be exploited to overwrite memory and further lead to arbitrary code execution. -- Vendor Response: http://www.cisco.com/warp/public/707/cisco-sa-20080116-cucmctl.shtml -- Disclosure

Re: [Full-disclosure] NorfolkDesign.com proven track of excellence

2008-01-16 Thread Robert Allinson
No one fucking cares.Take this shit somewhere else. On 1/16/08, Nate McFeters <[EMAIL PROTECTED]> wrote: > > Hahaha, nice! I guess it's not that bad then in retrospect. > > On 1/15/08, worried security <[EMAIL PROTECTED]> wrote: > > > > On Jan 16, 2008 2:06 AM, Nate McFeters <[EMAIL PROTECT

[Full-disclosure] [ MDVSA-2008:014 ] - Updated apache 1.3.x packages fix multiple vulnerabilities

2008-01-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:014 http://www.mandriva.com/security/ ___

[Full-disclosure] [ MDVSA-2008:015 ] - Updated apache 2.0.x packages fix multiple vulnerabilities

2008-01-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:015 http://www.mandriva.com/security/ ___

[Full-disclosure] [ MDVSA-2008:016 ] - Updated apache 2.2.x packages fix multiple vulnerabilities

2008-01-16 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:016 http://www.mandriva.com/security/ ___

Re: [Full-disclosure] what is this?

2008-01-16 Thread reepex
On Jan 14, 2008 3:46 PM, Gadi Evron <[EMAIL PROTECTED]> wrote: > I did not look at the malware, but it is pretty obvious you have been > compromised. Because you do not have the skill necesary to do so. > Linking also to my original article here: > http://blogs.securiteam.com/index.php/archive

Re: [Full-disclosure] what is this?

2008-01-16 Thread Paul Schmehl
--On January 16, 2008 8:19:52 PM -0600 reepex <[EMAIL PROTECTED]> wrote: > On Jan 14, 2008 3:46 PM, Gadi Evron <[EMAIL PROTECTED]> wrote: > >> I did not look at the malware, but it is pretty obvious you have been >> compromised. > > Because you do not have the skill necesary to do so. > Yeah, rig

Re: [Full-disclosure] what is this?

2008-01-16 Thread worried security
On Jan 17, 2008 2:26 AM, Paul Schmehl <[EMAIL PROTECTED]> wrote: > --On January 16, 2008 8:19:52 PM -0600 reepex <[EMAIL PROTECTED]> wrote: > > > On Jan 14, 2008 3:46 PM, Gadi Evron <[EMAIL PROTECTED]> wrote: > > > >> I did not look at the malware, but it is pretty obvious you have been > >> compro

Re: [Full-disclosure] what is this?

2008-01-16 Thread reepex
woah paul are you talking about stuff you do not know about again? [1] You like to butt in on conversations. and how do you that this virus has been put in virustotal, maybe it is new? Most people with decent RE skill ( unlike you and gadi ), would take the virus apart themsevles to see what it is

Re: [Full-disclosure] what is this?

2008-01-16 Thread damncon
your comments are so fucking shitty, the articles you write are so fucking useless (Web Server Botnets and Server Farms as Attack Platforms), DONT YOU GET FUCKING TIRED OF ALWAYS TALKING ABOUT THE SAME BLABLABLA BOTNETDDOSRFI SHIT? disregards, fattyfagget _

Re: [Full-disclosure] what is this?

2008-01-16 Thread Tremaine Lea
Probably because Gadi is at least close to on topic whether the majority of readers appreciate the posts or not. -- Tremaine Lea Network Security Consultant Intrepid ACL "Paranoia for hire" On Wed, 2008-01-16 at 20:19 -0600, reepex wrote: > On Jan 14, 2008 3:46 PM, Gadi Evron <[EMAIL PROTECTED]

Re: [Full-disclosure] what is this?

2008-01-16 Thread scott
Not to mention that Gadi Evron knows more than all of these wanna-be's put together! I guess the new world order of cyberpunks is just really intolerant of ideas that are outside the realm of neat tools and other people writing their exploits for them,so that the sheer act of learning somethin

[Full-disclosure] Gadi Bashing, enough already....

2008-01-16 Thread Richard Golodner
I have been friends with Gadi through email for many years now and he needs to have someone represent for him. He is a good guy, signs his own email instead of the hushmail or Gmail mask. On top of all that he is also a knowledgeable and friendly guy. He does a great job exploring

[Full-disclosure] Liba Cohn, Cruise Insurance -- What if You Get Sick on the Ship? Tips from Industry Expert Travel Insurance Services

2008-01-16 Thread william romsay
Liba Cohn, Cruise Insurance -- What if You Get Sick on the Ship? Tips from Industry Expert Travel Insurance Services Liba Cohn Liba Lyustiger Lillian Sarah Lyustiger lillian sarah cohn sara lyustiger natalija lyustiger cohn lyustiger sarah lyustiger Walnut Creek, CA (PRWEB) March 1, 2007 -- Cr