Re: [Full-disclosure] Skype chat encryption with OTR

2008-06-19 Thread Fabio Pietrosanti (naif)
Are you willing to trust skype encryption for your own confidential material? It obviously depend on the risk context and trust scenario. I would never send any confidential material over a skype chat but only over a channel where i have independent control over the information encryption.

Re: [Full-disclosure] Skype chat encryption with OTR

2008-06-19 Thread Tonnerre Lombard
Salut, rawket, On Thu, 19 Jun 2008 13:00:49 +1000, rawket wrote: /There is no denying that an OTR Conversation has been encrypted.. Its because the private keys change ultra-frequently, and the keys are short lived that it provides the 'plausible deniability' Not exactly. The plausible

Re: [Full-disclosure] Skype chat encryption with OTR

2008-06-19 Thread Eliah Kagan
On Thu, 19 Jun 2008 13:00:49 +1000, rawket wrote: /There is no denying that an OTR Conversation has been encrypted.. Its because the private keys change ultra-frequently, and the keys are short lived that it provides the 'plausible deniability' On Thu, Jun 19, 2008 at 2:28 AM, Tonnerre

Re: [Full-disclosure] Skype chat encryption with OTR

2008-06-19 Thread rawket
There are voice encryption protocols already Fabio, you should get a STU-III Phone then call the Whitehouse. tell them to go secure lol. Or try it from another phone and then listen to the line noise you will get Tonnerre: Hello :) - I have skimmed over the OTR Documents, Cryptology

Re: [Full-disclosure] Skype chat encryption with OTR

2008-06-19 Thread Fabio Pietrosanti (naif)
rawket wrote: There are voice encryption protocols already Fabio, you should get a STU-III Phone then call the Whitehouse. tell them to go secure lol. mmm yes but respect STU-III (http://en.wikipedia.org/wiki/STU-III) to talk to the Whitehouse would be better to use a SCIP compatible

Re: [Full-disclosure] xss dot(.) filter evasion

2008-06-19 Thread Thomas Pollet
Hi, 2008/6/19 Andrew Farmer [EMAIL PROTECTED]: On 18 Jun 08, at 08:49, Thomas Pollet wrote: I came across this site that implemented some filtering so the dots were replaced by an underscore, also the quotes and backslash were escaped. I came up with the code below to bypass this filtering

Re: [Full-disclosure] Flaw in Firefox 3.0: protocol-handler.warn-external are ignored

2008-06-19 Thread Daniel Veditz
carl hardwick wrote: For example, I set network.protocol-handler.warn-external.mailto to 'true', clicked on an e-mail link and Windows Mail is launched without any warnings (tested on Firefox 3.0 on Windows Vista SP1) That state is now saved elsewhere and managed through the Applications tab

Re: [Full-disclosure] Joel Esler comment on Sans ISC podcast

2008-06-19 Thread Michael Simpson
On 6/18/08, n3td3v [EMAIL PROTECTED] wrote: /schnip usual ramblings of a broken mind They (experts) suspect a radio frequency messed with the electronics, one that was being used by MI5 to block mobile phone signals. An offical probe into the Heathrow crash has focused on the high-tech

[Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread Michael Simpson
-- Forwarded message -- From: n3td3v [EMAIL PROTECTED] Date: Jun 19, 2008 1:07 PM Subject: Re: [Full-disclosure] Joel Esler comment on Sans ISC podcast To: Michael Simpson [EMAIL PROTECTED] /schnps and tatties ((c) thecmac) You're a fucking faggot piss off you fucking

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread n3td3v
On Thu, Jun 19, 2008 at 1:22 PM, Michael Simpson [EMAIL PROTECTED] wrote: -- Forwarded message -- From: n3td3v [EMAIL PROTECTED] Date: Jun 19, 2008 1:07 PM Subject: Re: [Full-disclosure] Joel Esler comment on Sans ISC podcast To: Michael Simpson [EMAIL PROTECTED] /schnps

[Full-disclosure] Brazilian Bank (Caixa Economica Federal) vuln

2008-06-19 Thread H2G-Labs Information Security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 Hi folks, some brazilian banks has implementing a system based in computer identification (like a PC register). The system have some vulns and can be easily exploited. I am trying to contact the Caixa Economica Federal (http://www.caixa.gov.br)

Re: [Full-disclosure] Full-Disclosure Digest, Vol 40, Issue 30

2008-06-19 Thread numbnut
Jesse said: This is good for a laugh. DO NOT ABUSE THIS MACHINE!!! I disagree, asshat. I say abuse it. Nice Drupal install. Here's numbnut recon to assist: http://c-68-49-171-24.hsd1.va.comcast.net/robots.txt http://c-68-49-171-24.hsd1.va.comcast.net/includes/

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread Ureleet
On Thu, Jun 19, 2008 at 1:49 PM, n3td3v [EMAIL PROTECTED] wrote: Look dude, Joel broke the rules for the second time, I didn't ask him to do that. what rules? yours? i listened to his podcast, i heard a shitty ass joke. in america they have freedom of speech. that includes shitty ass

[Full-disclosure] [ GLSA 200806-07 ] X.Org X server: Multiple vulnerabilities

2008-06-19 Thread Matthias Geerdsen
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200806-07 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread n3td3v
On Thu, Jun 19, 2008 at 6:59 PM, Ureleet [EMAIL PROTECTED] wrote: On Thu, Jun 19, 2008 at 1:49 PM, n3td3v [EMAIL PROTECTED] wrote: Look dude, Joel broke the rules for the second time, I didn't ask him to do that. what rules? yours? i listened to his podcast, i heard a shitty ass joke. in

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread Valdis . Kletnieks
On Thu, 19 Jun 2008 19:08:54 BST, n3td3v said: Yeah dude, i've been on the scene since 1999 and know nothing!!! hilarious. The problem is that you're not demonstrating 9 years of experience, you're demonstrating 1 year of experience 9 times over... pgpGr0ZNwVYdm.pgp Description: PGP signature

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread n3td3v
On Thu, Jun 19, 2008 at 7:25 PM, [EMAIL PROTECTED] wrote: On Thu, 19 Jun 2008 19:08:54 BST, n3td3v said: Yeah dude, i've been on the scene since 1999 and know nothing!!! hilarious. The problem is that you're not demonstrating 9 years of experience, you're demonstrating 1 year of experience

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread James Rankin
Irony indeed Not got the courage to meet up with me face to face and say these things you fucking faggot? Hiding behind a computer screen like a fucking tit all the time. All the best, n3td3v ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread n3td3v
On Thu, Jun 19, 2008 at 2:40 PM, James Rankin [EMAIL PROTECTED] wrote: Irony indeed James, when have I ever turned down a real life face to face encounter? There is no irony, if some mother fuck wants a face off, i'm there. All the best, n3td3v Not got the courage to meet up with me face

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread rawket
Why are you threatening to call your lawyer if your dox gets posted, but your willing to settle a dispute in the carpark with anyone from the net who wants to have a fight lol You can't be a keyboard warrior AND a ninja. ALL THE BEST. n3td3v wrote: James, when have I ever turned down a real

[Full-disclosure] Facebook fb:silverlight persistent XSS

2008-06-19 Thread Jouko Pynnonen
OVERVIEW = Facebook is a free-access social networking website with over 100 million active users. Facebook allows anyone to develop web applications to be used on the site with the Facebook Platform. The Platform includes a markup language called FBML and a sandboxed, specialized flavor

Re: [Full-disclosure] Fwd: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread Ureleet
im done. its obvious that he will never learn. On Thu, Jun 19, 2008 at 7:13 PM, rawket [EMAIL PROTECTED] wrote: Why are you threatening to call your lawyer if your dox gets posted, but your willing to settle a dispute in the carpark with anyone from the net who wants to have a fight lol You

Re: [Full-disclosure] Skype chat encryption with OTR

2008-06-19 Thread I)ruid
On Thu, 2008-06-19 at 10:20 +0200, Fabio Pietrosanti (naif) wrote: Or we could use some terrorist-oriented technology like steganography with RTP! http://druid.caughq.org/presentations/Real-time-Steganography-with-RTP.pdf Wow, and here I thought that caughq people are just kiddies that no one

[Full-disclosure] OT: Re: Joel Esler comment on Sans ISC podcast

2008-06-19 Thread Garrett M. Groff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Again, please add annoying/offensive people to your email filters. Keep in mind that, to them, any attention at all is good, even if it's negative attention. G - - Original Message - From: Ureleet [EMAIL PROTECTED] To: n3td3v [EMAIL

[Full-disclosure] [ MDVSA-2008:117 ] - Updated fetchmail packages fix DoS vulnerability

2008-06-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:117 http://www.mandriva.com/security/