[Full-disclosure] Lazy bum approach to security

2008-11-29 Thread andrew . wallace
On Wed, Nov 26, 2008 at 5:49 PM, Mike C <[EMAIL PROTECTED]> wrote: > I'm sure theres no reason to doubt that. The fact remains full-disclosure is > where it all happens. You're taking yourself into a false sense of security there. If you sit on a mailing list like full-disclosure and expect everyt

[Full-disclosure] Security industry software license

2008-11-29 Thread andrew . wallace
I think we should push for this so that attack platforms that are designed for penetration testers aren't used by the bad guys. I've already outlined the details, but the government can scrap that and work out their own details to how the scheme should work. Although I have no doubt in my mind we c

Re: [Full-disclosure] Security industry software license

2008-11-29 Thread Kurt Buff
On Sat, Nov 29, 2008 at 10:17 AM, andrew. wallace <[EMAIL PROTECTED]> wrote: > Now what the DHS need to do > if they want to counter hackers and cyber terrorism is to focus on > worth while things like developing a security industry software > license scheme that vets everybody using software and

Re: [Full-disclosure] Security industry software license

2008-11-29 Thread andrew . wallace
On Sat, Nov 29, 2008 at 7:32 PM, Kurt Buff <[EMAIL PROTECTED]> wrote: > On Sat, Nov 29, 2008 at 10:17 AM, andrew. wallace > <[EMAIL PROTECTED]> wrote: > >> Now what the DHS need to do >> if they want to counter hackers and cyber terrorism is to focus on >> worth while things like developing a secu

Re: [Full-disclosure] Security industry software license

2008-11-29 Thread Kurt Buff
On Sat, Nov 29, 2008 at 11:52 AM, andrew. wallace <[EMAIL PROTECTED]> wrote: > On Sat, Nov 29, 2008 at 7:32 PM, Kurt Buff <[EMAIL PROTECTED]> wrote: >> On Sat, Nov 29, 2008 at 10:17 AM, andrew. wallace >> <[EMAIL PROTECTED]> wrote: >> >>> Now what the DHS need to do >>> if they want to counter hac

Re: [Full-disclosure] Security industry software license

2008-11-29 Thread Kurt Buff
On Sat, Nov 29, 2008 at 11:52 AM, andrew. wallace <[EMAIL PROTECTED]> wrote: > On Sat, Nov 29, 2008 at 7:32 PM, Kurt Buff <[EMAIL PROTECTED]> wrote: >> On Sat, Nov 29, 2008 at 10:17 AM, andrew. wallace >> <[EMAIL PROTECTED]> wrote: >> >>> Now what the DHS need to do >>> if they want to counter hac

[Full-disclosure] [SECURITY] [DSA 1673-1] New wireshark packages fix several vulnerabilities

2008-11-29 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1673-1 [EMAIL PROTECTED] http://www.debian.org/security/ Moritz Muehlenhoff November 29, 2008

[Full-disclosure] Indian allegations alarm Pakistan

2008-11-29 Thread n3td3v
Indian-Pakistan war is about to kick off folks... http://news.bbc.co.uk/1/hi/world/south_asia/7757031.stm ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://sec

Re: [Full-disclosure] Security industry software license

2008-11-29 Thread j-f sentier
Oh well. Let's reverse this, the problem is not metasploit, because metasploit is not a 0days finder. Metasploit is develloped for well know vulnerability, and it's intended for penetration purpose. So if some lazy sys-admin doesn't patch them software, it's close to them own fault if they get hija

Re: [Full-disclosure] Lazy bum approach to security

2008-11-29 Thread Some Guy Posting To Full Disclosure
Hi I agree with you. It's just these 'underground communities' tend to be a bunch of kiddies playing with milworm, bots, and asking help with basic programming. Where's the original ideas, the research, and the worth-while discussion? I guess I described an extreme scenario, but you get the pict

Re: [Full-disclosure] Indian allegations alarm Pakistan

2008-11-29 Thread Raj Mathur
On Sunday 30 Nov 2008, n3td3v wrote: > Indian-Pakistan war is about to kick off folks... > > http://news.bbc.co.uk/1/hi/world/south_asia/7757031.stm I know it's not going to happen, but can I request you once again shut the fuck up about events that you have no clue about? At least try to keep y

Re: [Full-disclosure] Security industry software license

2008-11-29 Thread Some Guy Posting To Full Disclosure
Just to summarise what's been said and what I think so we can get back on topic, and conclude something: No-one hacks using metasploit! Go back to 2003. Terrorists with metasploit! What to you have a picture in your head of Mr. Jihad Bigbeard using metasploit to shutdown a powergrid? Reasons Why

Re: [Full-disclosure] Indian allegations alarm Pakistan

2008-11-29 Thread Mike C
On Sun, Nov 30, 2008 at 7:39 AM, Raj Mathur <[EMAIL PROTECTED]> wrote: > On Sunday 30 Nov 2008, n3td3v wrote: > > Indian-Pakistan war is about to kick off folks... > > > > http://news.bbc.co.uk/1/hi/world/south_asia/7757031.stm > > I know it's not going to happen, but can I request you once again

[Full-disclosure] Project Chroma: A color code for the state of cyber security

2008-11-29 Thread Mike C
Hi, It is time to take an example from Homeland Security and define codes of color for cyber-warfare threat levels. I propose the following: Green level: There is negligible threat to online security. Yellow level : There is a minimal level of threat, and this must be monitored and contained. Ora

Re: [Full-disclosure] Indian allegations alarm Pakistan

2008-11-29 Thread n3td3v
On Sun, Nov 30, 2008 at 5:25 AM, Mike C <[EMAIL PROTECTED]> wrote: > > > On Sun, Nov 30, 2008 at 7:39 AM, Raj Mathur <[EMAIL PROTECTED]> wrote: >> >> On Sunday 30 Nov 2008, n3td3v wrote: >> > Indian-Pakistan war is about to kick off folks... >> > >> > http://news.bbc.co.uk/1/hi/world/south_asia/775

Re: [Full-disclosure] Indian allegations alarm Pakistan

2008-11-29 Thread Mike C
On Sun, Nov 30, 2008 at 11:11 AM, n3td3v <[EMAIL PROTECTED]> wrote: > On Sun, Nov 30, 2008 at 5:25 AM, Mike C <[EMAIL PROTECTED]> wrote: >> >> >> On Sun, Nov 30, 2008 at 7:39 AM, Raj Mathur <[EMAIL PROTECTED]> wrote: >>> >>> On Sunday 30 Nov 2008, n3td3v wrote: >>> > Indian-Pakistan war is about to