Re: [Full-disclosure] Its time to break the news to Ureleet

2008-11-27 Thread Mike C
Hey n3td3v/ureleet, Lets keep working on the offline resolution of the personal issues here, before we continue back on the mailing list. This will be for the better of security research industry. -- MC On Thu, Nov 27, 2008 at 3:27 AM, n3td3v <[EMAIL PROTECTED]> wrote: > Its time to break the n

Re: [Full-disclosure] Browser Rider v20081124 is out.

2008-11-27 Thread Mike C
Just noting that I was contacted offline by the author of this tool, and informed that the project will have regular updates. those looking forward to it's progress will be glad. -- MC ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.or

Re: [Full-disclosure] Fwd: Comment on: 2 engineers from China sentenced for espionage

2008-11-27 Thread Mike C
This is just to inform the list that I'm in the process of discussions with the quoted individuals offline, and have made progress in increasing the signal to noise ratio of the full-disclosure mailing list. (As to the current progress, we're discussing if the rival list n3td3v on google groups ma

Re: [Full-disclosure] n3td3v has been tracked to Slough, UK

2008-11-27 Thread Michael Simpson
> I'm being targeted by some Blackhat group called Ureleet, I think he > hates white hats. He's trying to ruin my career by talking about > copyrights etc. If he makes allegations against me publicly, then i've > got to respond publicly to the allegations. > What career is that then? Do you reall

Re: [Full-disclosure] month of not replying to n3td3v

2008-11-27 Thread Mike C
Hi John/List, This is highly unnecessary. As I've already informed the list, I'm in discussions with n3td3v and other parties for a speedy resolution to some of the FD issues. Exercises like the one you've outline are meant to fail, and increase the signal to noise ratio. These games are best kept

Re: [Full-disclosure] URLs with hexcode-obscured IPs still work?

2008-11-27 Thread Joerg Mayer
On Wed, Nov 26, 2008 at 11:38:52PM +0100, niclas wrote: > Today I received a phishing mail containing a link which obscures the > IP-address as a hexadecimal number. The URL looks like this: > > http:// 0x ded 6d8a1/www.paypal.com/int ... /index.htm > > (Spaces added to circumvent phishing filters.

[Full-disclosure] [USN-680-1] Samba vulnerability

2008-11-27 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-680-1 November 27, 2008 samba vulnerability CVE-2008-4314 === A security issue affects the following Ubuntu releases: Ubuntu 8.10 This advisory

Re: [Full-disclosure] Microsoft takes 7 years to 'solve' a problem?!

2008-11-27 Thread Eric Rachner
I'd say that the DNS TID problem was a much more solvable problem than the problem Microsoft has with NTLM: At least with the TID issue, a fix was identified that did not break interoperability with legacy systems. No such luck with NTLM. Since the only "fix" identified so far is completely d

Re: [Full-disclosure] n3td3v has been tracked to Slough, UK

2008-11-27 Thread Ureleet
what makes u think i m a group? just because u think u r a group, and u r 1 person doesn't make me schizophrenic 2. On Wed, Nov 26, 2008 at 6:49 PM, n3td3v <[EMAIL PROTECTED]> wrote: > On Wed, Nov 26, 2008 at 11:22 PM, niclas <[EMAIL PROTECTED]> wrote: >>> no one gives a flying fuck about the pis

Re: [Full-disclosure] n3td3v has been tracked to Slough, UK

2008-11-27 Thread Ureleet
mikie, u said it. On Thu, Nov 27, 2008 at 6:19 AM, Michael Simpson <[EMAIL PROTECTED]> wrote: >> I'm being targeted by some Blackhat group called Ureleet, I think he >> hates white hats. He's trying to ruin my career by talking about >> copyrights etc. If he makes allegations against me publicly,

Re: [Full-disclosure] month of not replying to n3td3v

2008-11-27 Thread Ureleet
mike c, u r as naive as u r stupid. On Thu, Nov 27, 2008 at 8:22 AM, Mike C <[EMAIL PROTECTED]> wrote: > Hi John/List, > > This is highly unnecessary. As I've already informed the list, I'm in > discussions with n3td3v and other parties for a speedy resolution to some of > the FD issues. Exercises

Re: [Full-disclosure] Fwd: Changes to the n3td3v mailing list group because of copyright concerns

2008-11-27 Thread Ureleet
just write original shit. u can quote other articles, but u have to write original shit surrounding it. anyone can post. anyone can critize. u cant cut and paste. On Wed, Nov 26, 2008 at 8:51 PM, n3td3v <[EMAIL PROTECTED]> wrote: > -- Forwarded message -- > From: n3td3v <[EMAIL

Re: [Full-disclosure] Its time to break the news to Ureleet

2008-11-27 Thread Ureleet
stfu. On Thu, Nov 27, 2008 at 2:53 AM, Mike C <[EMAIL PROTECTED]> wrote: > Hey n3td3v/ureleet, > > Lets keep working on the offline resolution of the personal issues here, > before we continue back on the mailing list. This will be for the better of > security research industry. > > -- > MC > > On

Re: [Full-disclosure] Updates for SSH Tectia plaintext recovery vulnerability released

2008-11-27 Thread Ureleet
like i said, so because every1 else is doing it, u r going 2 do it too? yeah, thats a good legal argument. let me know what happens when u try that excuse against the police when u say u were going as fast as every1 else. On Wed, Nov 26, 2008 at 4:43 PM, n3td3v <[EMAIL PROTECTED]> wrote: > As th

Re: [Full-disclosure] Worried about getting sued by Cnet

2008-11-27 Thread Ureleet
n3td3v, just because every1 else is doing it, does not make u allowed 2 do it. if u r a white hat, do the right thing and write original material. if u have some. On Wed, Nov 26, 2008 at 5:44 PM, n3td3v <[EMAIL PROTECTED]> wrote: > Now that Ureleet has told me im breaking the law I don't know wh

Re: [Full-disclosure] Worried about getting sued by Cnet

2008-11-27 Thread Ureleet
ah yes, we'll take legal advice from a guy on FD. noted. On Thu, Nov 27, 2008 at 2:51 AM, Mike C <[EMAIL PROTECTED]> wrote: > I have previously had long discussions with a lawyer friend, who has assured > me that it is quite alright for copyrighted material to be quoted for > critical analysis. T

Re: [Full-disclosure] does the aim service save chat session details?

2008-11-27 Thread Ureleet
use otr. On Wed, Nov 26, 2008 at 4:04 PM, AMILABS <[EMAIL PROTECTED]> wrote: > Thanks Andrew, according to AOL policy and terms of use et. al. > > "Your AIM information, including the contents of your online communications, > may be accessed and disclosed in response to legal process (for example,

Re: [Full-disclosure] Worried about getting sued by Cnet

2008-11-27 Thread Ureleet
just post original material. the fact is that u *could* be sued for lost revenue and violation of license. if u blog it, or write it, u could then make an argument, but blatant copy n pasting is just plain wrong. On Wed, Nov 26, 2008 at 6:17 PM, n3td3v <[EMAIL PROTECTED]> wrote: > Gadi Evron don

Re: [Full-disclosure] does the aim service save chat sessiondetails?

2008-11-27 Thread infolookup
How about you and Netdev email each other off list that would help my spam folder greatly. P.S Happy Turkey day! Sent from my Verizon Wireless BlackBerry -Original Message- From: Ureleet <[EMAIL PROTECTED]> Date: Thu, 27 Nov 2008 11:55:16 To: AMILABS<[EMAIL PROTECTED]> Cc: Subject: Re

Re: [Full-disclosure] does the aim service save chat sessiondetails?

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 12:16 PM, <[EMAIL PROTECTED]> wrote: > How about you and Netdev email each other off list that would help my spam > folder greatly. > > P.S Happy Turkey day! > Sent from my Verizon Wireless BlackBerry > how about u read what the topic is, and what i wrote, and learn how 2

[Full-disclosure] FAO John Cartwright

2008-11-27 Thread n3td3v
I urge you to ban [EMAIL PROTECTED] from full-disclosure with immediate effect. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread vulcanius
How about we take a vote on who needs to be removed instead. On Thu, Nov 27, 2008 at 12:45 PM, n3td3v <[EMAIL PROTECTED]> wrote: > I urge you to ban [EMAIL PROTECTED] from full-disclosure with immediate > effect. > > ___ > Full-Disclosure - We believe i

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread vulcanius
That's pretty much guaranteed. But then maybe John would be forced to finally take action and remove the two people around which 96% of the trouble on FD revolves. For that, I'd be willing to deal with the chaos. On Thu, Nov 27, 2008 at 1:54 PM, Bill Reyor <[EMAIL PROTECTED]> wrote: > Sounds like

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread andrew . wallace
I am a serious security researcher who runs the n3td3v security group, don't remove me. I think its obvious to everyone who should be removed. I am not going to stand for my reputation to be smeared a minute longer by aliases. On Thu, Nov 27, 2008 at 7:07 PM, vulcanius <[EMAIL PROTECTED]> wrote: >

Re: [Full-disclosure] Microsoft takes 7 years to 'solve' a problem?!

2008-11-27 Thread Eric Rachner
I'd say that the DNS TID problem was a much more solvable problem than the problem Microsoft has with NTLM: At least with the TID issue, a fix was identified that did not break interoperability with legacy systems. No such luck with NTLM. Since the only "fix" identified so far is completely d

[Full-disclosure] SecurityReason : PHP 5.2.6 dba_replace() destroying file

2008-11-27 Thread Maksymilian Arciemowicz
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [ SecurityReason.com PHP 5.2.6 dba_replace() destroying file ] Author: Maksymilian Arciemowicz http://securityreason.com Date: - - Written: 10.11.2008 - - Public: 28.11.2008 SecurityReason Research SecurityAlert Id: 58 SecurityRisk: Medium Affected

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 12:45 PM, n3td3v <[EMAIL PROTECTED]> wrote: > I urge you to ban [EMAIL PROTECTED] from full-disclosure with immediate > effect. funny. i asked him 2 do the same thing 2 u about 6 months ago. i c where that got us. ___ Full-Di

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 1:32 PM, vulcanius <[EMAIL PROTECTED]> wrote: > How about we take a vote on who needs to be removed instead. ill leave if he does. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 12:45 PM, n3td3v <[EMAIL PROTECTED]> wrote: > I urge you to ban [EMAIL PROTECTED] from full-disclosure with immediate > effect. y u want me banned anyway? scared? ___ Full-Disclosure - We believe in it. Charter: http://lists.g

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread infolookup
On Thu, Nov 27, 2008 at 12:45 PM, n3td3v <[EMAIL PROTECTED]> wrote: > I urge you to ban [EMAIL PROTECTED] from full-disclosure with immediate > effect. funny. i asked him 2 do the same thing 2 u about 6 months ago. i c where that got us. - Like I said email

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 6:19 PM, andrew. wallace <[EMAIL PROTECTED]> wrote: > I am a serious security researcher who runs the n3td3v security group, > don't remove me. I think its obvious to everyone who should be > removed. I am not going to stand for my reputation to be smeared a > minute longer

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread andrew . wallace
You're the one who can't type properly because you're too scared people will identify you. On Fri, Nov 28, 2008 at 1:35 AM, Ureleet <[EMAIL PROTECTED]> wrote: > y u want me banned anyway? scared? > ___ Full-Disclosure - We believe in it. Charter: http:

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
> Like I said email off list.but the funny thing is I would vote against > you if I had to, all you do is complaint the lease you can do is post some > news articles.. fair enuff. i can c that. dont blame u. when this is all over, ill happily retire. until that time, whatever that ti

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread andrew . wallace
Do I look scared from someone who can't even type properly or use his real name? I think we all know who the scared one is and it isn't me. On Fri, Nov 28, 2008 at 1:35 AM, Ureleet <[EMAIL PROTECTED]> wrote: > y u want me banned anyway? scared? > ___ F

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 8:48 PM, andrew. wallace <[EMAIL PROTECTED]> wrote: > Do I look scared from someone who can't even type properly or use his > real name? I think we all know who the scared one is and it isn't me. wtf does my typing style have 2 do w/ shit? matter of fact, ur right, im scar

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 8:42 PM, andrew. wallace <[EMAIL PROTECTED]> wrote: > You're the one who can't type properly because you're too scared > people will identify you. least of my problems kid. is this email alias u, or not? we've seen about 3 or 4 differnet "n3tdev" aliases over teh years.

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread andrew . wallace
To clear the air you would type properly and use your real name. On Fri, Nov 28, 2008 at 1:35 AM, Ureleet <[EMAIL PROTECTED]> wrote: > prove this is u. > > o, and what have u researched again? just to clear the air. > > ___ > Full-Disclosure - We believ

Re: [Full-disclosure] FAO John Cartwright

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 8:56 PM, andrew. wallace <[EMAIL PROTECTED]> wrote: > To clear the air you would type properly and use your real name. deflecting again i c. fuck typing. fuck u and fuck my real name. matter of fact, fuck ur real name. i dont give a shit. we know who u r, and we really

[Full-disclosure] im so done.

2008-11-27 Thread Ureleet
n3td3v/andrew wallace of the uk u r a waste of time. a waste of air. i m done w/ u. u wont admit u know nothing, u dont do anything worth a thing. u dont do anything original hell, u dont even blog original shit. if ur goal was 2 get me to leave, u win. im out. i think ive proved my point.

Re: [Full-disclosure] im so done.

2008-11-27 Thread don bailey
> so, for now, i am gone. n3td3v, u r a disgrace 2 the community by > calling urself 1 of us. > I really wish you would stay. You and n3td3v are destroying the full-disclosure community. That's a good thing. Keep bantering, please. Also, change your e-mail address every few weeks so people have

Re: [Full-disclosure] im so done.

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 9:30 PM, don bailey <[EMAIL PROTECTED]> wrote: > You and n3td3v are destroying > the full-disclosure community. That's a good thing. now, *there* is a good topic 4 discussion! ___ Full-Disclosure - We believe in it. Charter: htt

Re: [Full-disclosure] im so done.

2008-11-27 Thread Mike C
On Fri, Nov 28, 2008 at 8:00 AM, don bailey <[EMAIL PROTECTED]> wrote: > > so, for now, i am gone. n3td3v, u r a disgrace 2 the community by > > calling urself 1 of us. > > > > I really wish you would stay. You and n3td3v are destroying > the full-disclosure community. That's a good thing. Keep >

Re: [Full-disclosure] im so done.

2008-11-27 Thread don bailey
> n3td3v has agreed to use his real name, and ureleet is thus lesser > pissed. We'll have to wait and see on the change in the content that is > posted, and my hope is that full disclosure's SNR will drastically improve. > Full-Disclosure is doomed. You can not apply diplomacy to someone that t

Re: [Full-disclosure] im so done.

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 10:00 PM, Mike C <[EMAIL PROTECTED]> wrote: > No, > > It took a lot of effort on my part for all this to happen, and the > discussions have paid off. Big thanks to all who've pinged me online for my > diplomatic efforts. wait, lets b entirely clear. u didnt do a damn thin

Re: [Full-disclosure] im so done.

2008-11-27 Thread Ureleet
On Thu, Nov 27, 2008 at 10:07 PM, don bailey <[EMAIL PROTECTED]> wrote: > Full-Disclosure is doomed. You can not apply diplomacy to > someone that thinks you and the community you belong to > are a joke. so u think that fulld is bad? y? ___ Full-Disc

Re: [Full-disclosure] im so done.

2008-11-27 Thread don bailey
Ureleet wrote: > so u think that fulld is bad? y? > I'll leave you and n3td3v to argue the possibilities. I sure hope Valdis will also chime in with *long* *interesting* *arguments* relevant to *modern* *day* perceptions on *real* *life* *security*. D _

Re: [Full-disclosure] im so done.

2008-11-27 Thread Noel Butler
On Fri, 2008-11-28 at 13:07, don bailey wrote: > > n3td3v has agreed to use his real name, and ureleet is thus lesser > > pissed. We'll have to wait and see on the change in the content that is > > posted, and my hope is that full disclosure's SNR will drastically improve. > > > > Full-Disclos

Re: [Full-disclosure] im so done.

2008-11-27 Thread megistos triskataratos
TBH, i have joined those mailing lists for a reason... when it comes to something out of topic and ridiculous enough, I DONT ANSWER (but right now im fed up :@). I think you should all do the same.. IMHO this keeps going because someone replies what if only 2-4 people spoke on such matters? Th