[Full-disclosure] [ MDVA-2009:027 ] kernel

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVA-2009:027 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:044 ] firefox

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:044 http://www.mandriva.com/security/

Re: [Full-disclosure] [SCADASEC] 11. Re: SCADA Security - Software fee's

2009-02-20 Thread Smoking Gun
On Thu, Feb 19, 2009 at 7:15 PM, simon_lists wrote: > Joshua, >I understand why you wrote what you did but you're wrong. Let me > explain... > >Today the security industry is a confused and immature place. Most > vendors offer half assed services that sell for half assed prices.

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-20 Thread Jordan Bray
On Thu, 19 Feb 2009 23:38:37 EST, T Biehn said: > God Valdis, > Dont concentrate on the mundane, the core issue is the unpredictable nature > of it. > You have them all coordinate reading the news at 12:00 AM GMT. > You build some silly algorithm that ensures they pick the right article. Right, s

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-20 Thread T Biehn
Valdis. No. There's nothing complicated about it - it's dead simple. Who needs a botnet available 24/7? The registrars are all down at the same time? Why does it have to be domains? Perhaps the bots pick a range of IPs to scan based on the news... any bots with IPs falling into this range become C&

Re: [Full-disclosure] [SCADASEC] 11. Re: SCADA Security - Software fee's

2009-02-20 Thread Adriel T. Desautels
Hi Loki On Feb 20, 2009, at 9:24 AM, Smoking Gun wrote: > On Thu, Feb 19, 2009 at 7:15 PM, simon_lists > wrote: > >> Joshua, >> I understand why you wrote what you did but you're wrong. Let >> me >> explain... >> >> Today the security industry is a confused and immature >> pla

Re: [Full-disclosure] [SCADASEC] 11. Re: SCADA Security - Software fee's

2009-02-20 Thread Smoking Gun
On Fri, Feb 20, 2009 at 9:44 AM, Adriel T. Desautels wrote: > Hi Loki > This would be the second time I ask you publicly, is that all you have to offer? Surely you or Simon can come together and offer a meaningful response to my previous post. For those in the United States, you have the show Gho

[Full-disclosure] New version of webshag is available !

2009-02-20 Thread SaD
Webshag 1.10 has been released! This new version provides several feature enhancements as well as some bug-fixes. For those who don't know it, webshag is a free, multi-threaded, multi-platform web server audit tool. Written in Python, it gathers commonly useful functionalities for web server audit

[Full-disclosure] [ MDVSA-2009:046 ] dia

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:046 http://www.mandriva.com/security/

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-20 Thread Gary E. Miller
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yo Travis! On Thu, 19 Feb 2009, T Biehn wrote: > You know how the current amateur botnet offerings are basing domain lists > off the current time to allow the 'good guys' to prepare? > > Why not base the seed off something like a news RSS feed? Or h

[Full-disclosure] [ MDVSA-2009:045 ] php

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:045 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:047 ] vim

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:047 http://www.mandriva.com/security/

Re: [Full-disclosure] Oh Yeah, botnet communications

2009-02-20 Thread T Biehn
Yeah man you get the point. Even if they do reverse it, you can digitally sign each of the commands, so if a bot hunter even got the balls to 'break the law' and send the rm command they'd fail. It's about eliminating their lead time, right now they can just put controls in with registrars to dis

[Full-disclosure] [ MDVSA-2009:048 ] epiphany

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:048 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:049 ] pycrypto

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:049 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:050 ] python-pycrypto

2009-02-20 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:050 http://www.mandriva.com/security/