[Full-disclosure] Presentation of Message-ID Fingerprinting Tool

2009-09-14 Thread Marc Ruef
Hello, Within penetration tests client-oriented attacks become more and more important. I have created a script which is able to determine the mail client from the message-id which is included in an email. Midfp (Message-ID Fingerprinter) is going to analyze the structure of the message-id and

Re: [Full-disclosure] PakBugs.Com Report

2009-09-14 Thread TheLearner
I wanna be the very best Like no one ever was To catch them is my real test My criminal justice training is my cause I will travel across the lands searching far and wide with pokemon to understand THE POWER THAT'S INSIDE POKEMON gotta catch em all (it's you and me) YOU KNOW ITS MY TEST IN ME

Re: [Full-disclosure] Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D.

2009-09-14 Thread Randal T. Rioux
It's fun :-) On Mon, September 14, 2009 12:14 pm, D-vice wrote: You wrote an exploit in java *head explodes* On Mon, Sep 14, 2009 at 6:02 AM, Randal T. Rioux ra...@procyonlabs.comwrote: After testing my version of the exploit (using Java instead of Python) I tried it against a

Re: [Full-disclosure] Plain Text Password Disclosure vulnerability in rediff mail

2009-09-14 Thread D-vice
To Dan, being well known is now the same as having your ass handed to ya by the like of me Think about it, its like you saying I'm jealous of Bush becouse he is was the president and Im not I'm not retarded, I don't envy epic fails On Fri, Sep 11, 2009 at 6:27 PM, valdis.kletni...@vt.edu

[Full-disclosure] PakBugs.Com Report

2009-09-14 Thread full-censorship
Rohit Patnaik quanti...@gmail.com wrote: We know that the FBI and the CIA can't even catch Osama bin Laden in Pakistan. Do you really think they're going to bother with small- time credit card skimmers? according to research though its the *small-time* skimmers funding the *big-time* terror

Re: [Full-disclosure] Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D.

2009-09-14 Thread D-vice
You wrote an exploit in java *head explodes* On Mon, Sep 14, 2009 at 6:02 AM, Randal T. Rioux ra...@procyonlabs.comwrote: After testing my version of the exploit (using Java instead of Python) I tried it against a Windows Server 2008 R2 installation - it went down.

[Full-disclosure] [SECURITY] [DSA 1883-2] New nagios2 packages fix regression

2009-09-14 Thread Steffen Joeris
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1883-2 secur...@debian.org http://www.debian.org/security/ Giuseppe Iuculano September 14, 2009

[Full-disclosure] [SECURITY] [DSA 1885-1] New xulrunner packages fix several vulnerabilities

2009-09-14 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1885-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff September 14, 2009

[Full-disclosure] [SECURITY] [DSA 1886-1] New iceweasel packages fix several vulnerabilities

2009-09-14 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1886-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff September 14, 2009

Re: [Full-disclosure] Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D.

2009-09-14 Thread r1d1nd1rty
Oh WOW! More exploit code ported to Java!! Hello Randy, Not everyone would have gone to all the trouble you did for me and I want you to know how much I appreciate it. It seems that you are always going above and beyond the call of duty. No wonder so many people are happy and proud to call

Re: [Full-disclosure] PakBugs.Com Report

2009-09-14 Thread Rohit Patnaik
We know that the FBI and the CIA can't even catch Osama bin Laden in Pakistan. Do you really think they're going to bother with small-time credit card skimmers? --Rohit Patnaik TheLearner wrote: I wanna be the very best Like no one ever was To catch them is my real test My criminal

[Full-disclosure] [SECURITY] [DSA 1884-1] New nginx packages fix arbitrary code execution

2009-09-14 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-1884-1secur...@debian.org http://www.debian.org/security/ Nico Golde September 14th, 2009

[Full-disclosure] Distribution of passwords between man and women

2009-09-14 Thread Tõnu Samuel
Hi all kind of bad people in this list. Want to share weird thing I discovered today: Men have MUCH worse passwords than females. There is a user database where men to woman ratio is 5.2:1 but men but use last name more often as password. Ratio is 6.2:1. When it somes to bad password like 123456,

[Full-disclosure] [USN-830-1] OpenSSL vulnerability

2009-09-14 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-830-1 September 14, 2009 openssl vulnerability CVE-2009-2409 === A security issue affects the following Ubuntu releases: Ubuntu 6.06 LTS Ubuntu

[Full-disclosure] [USN-831-1] OpenEXR vulnerabilities

2009-09-14 Thread Marc Deslauriers
=== Ubuntu Security Notice USN-831-1 September 14, 2009 openexr vulnerabilities CVE-2009-1720, CVE-2009-1721, CVE-2009-1722 === A security issue affects the following Ubuntu

Re: [Full-disclosure] Windows Vista/7 : SMB2.0 NEGOTIATE PROTOCOL REQUEST Remote B.S.O.D.

2009-09-14 Thread Randal T. Rioux
Scratch that - the version of 2008 I had wasn't an official R2 release. So original reports still hold. It didn't crash my R2 build 7600. Laurent, et al, has this been tried against an Itanium machine? Just curious. Nobody at work will let me test the exploit against their Itanium servers. Randy

[Full-disclosure] Plain Text Password Disclosure vulnerability in rediff mail

2009-09-14 Thread full-censorship
D-vice lord@gmail.com wrote: To Dan, being well known is now the same as having your ass handed to ya by the like of me now that we banned n3td3v can we ban dan kaminsky as well? ;) ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Hack-Mail.net or similar site

2009-09-14 Thread mamo
On Sat, Sep 12, 2009 at 7:08 PM, Andrew Farmer andf...@gmail.com wrote: So, in other words, they're spoofing From addresses for profit. Clever. I never tried them. I will just for fun (with my email address). Perhaps they are doing something more smart (like brute forcing with dictionary, use

Re: [Full-disclosure] Hack-Mail.net or similar site

2009-09-14 Thread maxigas
From: mamo mam...@gmail.com Subject: Re: [Full-disclosure] Hack-Mail.net or similar site Date: Mon, 14 Sep 2009 23:20:24 +0200 On Sat, Sep 12, 2009 at 7:08 PM, Andrew Farmer andf...@gmail.com wrote: So, in other words, they're spoofing From addresses for profit. Clever. I never tried them.

[Full-disclosure] [ MDVSA-2009:233 ] kernel

2009-09-14 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:233 http://www.mandriva.com/security/

[Full-disclosure] Andrew Aurenheimer aka weev gets tree'd

2009-09-14 Thread GOBBLES
___ ___ _ | __ | | |__] |__] ||___ [__ |__] |__| |__] |__] |___ |___ ___] _ _ ___ _ ___ _ |__| |\ | | \ | | \ | | | | \| |__/_| |__/ |___ Presents = Meet the exposed Andrew

Re: [Full-disclosure] Andrew Aurenheimer aka weev gets tree'd

2009-09-14 Thread Andrew A
lol buddy i put my name in my own fuckin' blog its not like youve discovered some big secret also, i lol that it took the worlds most well funded law enforcement agency working at the behest of the one true arm of satan just to dox me. you dudes are sad. lets smoke crack and kill jews. On Mon,

Re: [Full-disclosure] Andrew Aurenheimer aka weev gets tree'd

2009-09-14 Thread Valdis' Mustache
Herr Evron, Ms. Alder, and Dr. Krawetz: While your valiant effort at cyberimpersonation is quite laudable, it should be noted that mastery of ASCII graphics beyond the level of the System V banner command is one (admittedly, non-lexicographically fingerprintable) integral hallmark of the departed

Re: [Full-disclosure] Andrew Aurenheimer aka weev gets tree'd

2009-09-14 Thread GOBBLES
*grins like chesire cat* *spins you around* Oh weev, you try too hard. You hold on to vanity like a 13 year old girl. That's what your friends say. Or at least people who think are your friend. I've been in contact with hep, sherrod degrippo, oclet and tehdely about what a flatout nutter you

Re: [Full-disclosure] Andrew Aurenheimer aka weev gets tree'd

2009-09-14 Thread Andrew A
.. _ .' `. /\) / / / / /\ \ \ / \ _ \ \/ /\ \ (/\ \ / \ \ \ \ / \ (Y ) \ \/ /\ \ \ / \ \ \/ / / / / ( Y) GADI EVRON GONNA CALL THE JIZZTAPO ON ME On Mon, Sep 14, 2009 at 11:37 PM, Valdis'

Re: [Full-disclosure] Hack-Mail.net or similar site

2009-09-14 Thread Augusto Pereyra
I think this service is fake. To make some portal like this only you need a php form with the following fields: Account to Hack, Account to send password Some client fill this form and three days later the server send a spoofed mail acting like they have the password of the account requested in

Re: [Full-disclosure] Andrew Aurenheimer aka weev gets tree'd

2009-09-14 Thread Valdis' Mustache
Adrian, Godwin be damned, I must know! You can't sincerely be a racist or anti-semite in this day and age, can you? Which is the fool, your spectators, or you? My hairs bristle in anticipation at your answer. Your Humble Servant, La moustache de Valdis On 9/14/09, Andrew A glutt...@gmail.com