Re: [Full-disclosure] security industry software license

2008-10-15 Thread AaRoNg11
On Wed, Oct 15, 2008 at 7:37 AM, AaRoNg11 [EMAIL PROTECTED] wrote: Society doesn't care, just n3td3v :P Why does society care about doing this? Or is it just that you can't figure out how to use it, so you don't want others to have access to it? -- Aaron Goulden -- Aaron Goulden

[Full-disclosure] OpenVAS 2.0 Begins Public Beta Phase

2008-10-15 Thread Michael Wiegand
Hello, In late September 2008, the OpenVAS[1] developer team released the 2.0-beta1 version of OpenVAS, the Open Vulnerability Assessment System for network security scanning. The intended audience for this beta release are experienced users interested in upcoming features as well as developers

[Full-disclosure] [ MDVSA-2008:212 ] libxml2

2008-10-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:212 http://www.mandriva.com/security/

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
we don't know if metasploit is already passing the download data to the government, i mean, do they have a privacy policy on their web site? nope. we just need to make that download data useful. ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Tool release: iaxscan-0.02

2008-10-15 Thread nnp
Fairly self explanatory to be honest. iaxscan is a Python based scanner for detecting live IAX/2 hosts and then enumerating (by bruteforce) users on those hosts. It does so, in an obvious fashion, by sending valid IAX/2 requests and monitoring responses. Being UDP based it has all the advantages

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
i have recieved a tip off that says metasploit has no privacy policy and folks downloading from metasploit are possibly being dhs'd. we know that the authorities has set up, http://news.cnet.com/8301-1009_3-10066001-83.html, websites in the past to catch out the bad guys. my informant also says,

[Full-disclosure] [ MDVSA-2008:213 ] dbus

2008-10-15 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2008:213 http://www.mandriva.com/security/

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
i was joking i dont have an informant who told me that stuff, but i thought it was pretty funny anyway. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
metasploit http://metasploit.com/ should get a privacy policy though, if they want to be taken seriously by the kiddies... On Wed, Oct 15, 2008 at 9:47 PM, n3td3v [EMAIL PROTECTED] wrote: i was joking i dont have an informant who told me that stuff, but i thought it was pretty funny anyway.

Re: [Full-disclosure] security industry software license

2008-10-15 Thread Valdis . Kletnieks
On Wed, 15 Oct 2008 22:16:01 BST, n3td3v said: metasploit http://metasploit.com/ should get a privacy policy though, if they want to be taken seriously by the kiddies... But *you* already seem to be taking it seriously. And I doubt that HD Moore cares whether the other kiddies take it

Re: [Full-disclosure] security industry software license

2008-10-15 Thread Valdis . Kletnieks
On Wed, 15 Oct 2008 21:15:16 BST, n3td3v said: i have recieved a tip off that says metasploit has no privacy policy and folks downloading from metasploit are possibly being dhs'd. Do the world a favor, and use whatever grey stuff hasn't leaked out of your cranial cavity and *think* for a

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
On Wed, Oct 15, 2008 at 10:28 PM, [EMAIL PROTECTED] wrote: On Wed, 15 Oct 2008 21:15:16 BST, n3td3v said: i have recieved a tip off that says metasploit has no privacy policy and folks downloading from metasploit are possibly being dhs'd. Do the world a favor, and use whatever grey stuff

Re: [Full-disclosure] security industry software license

2008-10-15 Thread vulcanius
If you're going to continue having conversations with yourself I highly recommend switching to an IM client. It will provide you with more immediate gratification and the rest of us with peace and quiet and relevance. But whatever, I just remembered Gmail can filter, silly me. Goodbye n3td3v and

[Full-disclosure] Multiple Flash Authoring Heap Overflows - Malformed SWF Files

2008-10-15 Thread Paul Craig
Multiple Flash Authoring Heap Overflows - Malformed SWF Files Vendor Website: http://www.adobe.com Affected Versions: Adobe Flash Professional CS3/Flash MX2004 Vendor Notified. July 2008 Public Disclosure.

[Full-disclosure] visiodays

2008-10-15 Thread Thomas Pollet
Hello, There are huge amounts of memory corruption issues in visio. To find them you can use any fuzzer on any vsd file. To make things easy: 1) copy the fuzzed files to your webserver 2) attach a debugger to IE 3) use the html below. (Also, running an activex fuzzer on the visio viewer

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
I never had a conversation with myself, its called *adding a bit more on*. On Wed, Oct 15, 2008 at 10:44 PM, vulcanius [EMAIL PROTECTED] wrote: If you're going to continue having conversations with yourself I highly recommend switching to an IM client. It will provide you with more immediate

[Full-disclosure] [USN-656-1] CUPS vulnerabilities

2008-10-15 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-656-1 October 15, 2008 cupsys vulnerabilities CVE-2008-1722, CVE-2008-3639, CVE-2008-3640, CVE-2008-3641 === A security issue affects the

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
On Wed, Oct 15, 2008 at 10:28 PM, [EMAIL PROTECTED] wrote: On Wed, 15 Oct 2008 22:16:01 BST, n3td3v said: metasploit http://metasploit.com/ should get a privacy policy though, if they want to be taken seriously by the kiddies... But *you* already seem to be taking it seriously. And I

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
he can't advertise his latest software as *evil deeds* without a privacy policy, it sounds a bit *entrapment*. i was suprised though when i went to the metasploit site, scanned the footer of all the pages on his site with my eyes, and saw no privacy statement/policy. i don't care if hd moore and

Re: [Full-disclosure] security industry software license

2008-10-15 Thread n3td3v
no privacy policy on metasploit web site = bad news for script kiddies. rejoice! On Thu, Oct 16, 2008 at 12:43 AM, n3td3v [EMAIL PROTECTED] wrote: he can't advertise his latest software as *evil deeds* without a privacy policy, it sounds a bit *entrapment*. i was suprised though when i went

Re: [Full-disclosure] security industry software license

2008-10-15 Thread Biz Marqee
Dude, do you ever just shut the fuck up? Even though the content of your emails is of null value, it must take time to write all this junk so I am thinking you must have some severe anxiety issues, agoraphobia or are just plain old demented to consistently write whatever bullshit comes into your

Re: [Full-disclosure] security industry software license

2008-10-15 Thread Elazar Broad
So take it up with him like a man and not on our inboxes... On Tue, 14 Oct 2008 08:51:33 -0400 n3td3v [EMAIL PROTECTED] wrote: On Tue, Oct 14, 2008 at 1:28 PM, M. B. Jr. [EMAIL PROTECTED] wrote: And by the way, why insistently and specifically targeting Metasploit? i don't like hd moore