Re: [Full-disclosure] How I become Vice President of Security at Yahoo! 1999-2005.

2010-02-19 Thread Randal T. Rioux
Decent attempt at trolling. Some beginner mistakes, but the message was relayed as intended (I'm sure). Comments inline. On Fri, February 19, 2010 6:45 pm, John Q Public wrote: > -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 > > Greetings. > > I've been holding this one back for a while. It's been

Re: [Full-disclosure] How I become Vice President of Security at Yahoo! 1999-2005.

2010-02-19 Thread Valdis . Kletnieks
On Fri, 19 Feb 2010 23:45:05 GMT, John Q Public said: > Eventually, I was promoted up Vice President of Security at Yahoo! > and made nearly six figures a year. Which would explain why Yahoo security looks like the kind you'd expect to get when even the VP is making under $100K. pgpecJdl4EMcK.p

[Full-disclosure] Request for feedback on TCP security (IETF effort)

2010-02-19 Thread Fernando Gont
Hello, folks, I've just posted a revision of the "Security Assessment of the Transmision Control Protocol (TCP)" IETF Internet-Draft. It's available at the usual places (including: http://tools.ietf.org/id/draft-ietf-tcpm-tcp-security-01.txt). (It is a derivative of the CPNI TCP-security document

Re: [Full-disclosure] How I become Vice President of Security at Yahoo! 1999-2005.

2010-02-19 Thread BMF
Pass the dutchie... On Fri, Feb 19, 2010 at 3:45 PM, John Q Public wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > Greetings. > > I've been holding this one back for a while. It's been eating at my > skin. > > I was just an intern at the time, but I'd get the mail, copy the > text, d

[Full-disclosure] How I become Vice President of Security at Yahoo! 1999-2005.

2010-02-19 Thread John Q Public
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Greetings. I've been holding this one back for a while. It's been eating at my skin. I was just an intern at the time, but I'd get the mail, copy the text, delete his mail, and send the mail to my supervisor, authored by me. I still remember the fri

Re: [Full-disclosure] Why

2010-02-19 Thread Christian Sciberras
@Jonny - No, I meant that you should write books. My mistake. Obviously. On Fri, Feb 19, 2010 at 11:26 PM, Benji wrote: > Where should I send the cheque so that the funds may be released? > > On Fri, Feb 19, 2010 at 10:24 PM, Jonathan Barningham > wrote: >> >> -BEGIN PGP SIGNED MESSAGE-

Re: [Full-disclosure] Why

2010-02-19 Thread Benji
Where should I send the cheque so that the funds may be released? On Fri, Feb 19, 2010 at 10:24 PM, Jonathan Barningham wrote: > -BEGIN PGP SIGNED MESSAGE- > Hash: SHA1 > > man > > someone please help me > > On Fri, 19 Feb 2010 22:08:43 + Jonathan Barningham > wrote: > >I mean to say

Re: [Full-disclosure] Why

2010-02-19 Thread Jonathan Barningham
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I was waiting for Valdis to chime in here. He always brings in the comic relief when needed. Yeah, I get some therapeutic warmth from having n3td3v around. He's like a magical actor who is here just to entertain us. But seriously, any ideas as to wh

Re: [Full-disclosure] Why

2010-02-19 Thread Valdis . Kletnieks
On Fri, 19 Feb 2010 22:24:25 GMT, Jonathan Barningham said: > someone please help me > > On Fri, 19 Feb 2010 22:08:43 + Jonathan Barningham wrote: ^^ Fish. Barrel. Shotgun. Though to your credit, you have the whole "everybody is

Re: [Full-disclosure] Why

2010-02-19 Thread Jonathan Barningham
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Eh, it's not that "far out". Are you saying I sound like a liar? Kinda like a Joseph Smith or L Ron Hubbard? 'Pretty down to earth dude right here. And I hate to lie or be unethical. It's a philosophically entrenched sin. If that's what you're trying

Re: [Full-disclosure] Why

2010-02-19 Thread BMF
Or Vogon poetry? On Fri, Feb 19, 2010 at 2:09 PM, Christian Sciberras wrote: > @Jonny - Hmm, talented. Ever thought about writing books? > > On Fri, Feb 19, 2010 at 10:57 PM, Thor (Hammer of God) > wrote: >> Vivisected like string cheese? >> >>> -Original Message- >>> From: full-disclosu

Re: [Full-disclosure] Why

2010-02-19 Thread Jonathan Barningham
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 man someone please help me On Fri, 19 Feb 2010 22:08:43 + Jonathan Barningham wrote: >I mean to say, my life is being vivisected. They are pulling my >life apart in layers like string cheese. > >It's quite uncomfortable. > >On Fri, 19 Feb 2010 2

Re: [Full-disclosure] Why

2010-02-19 Thread Christian Sciberras
@Jonny - Hmm, talented. Ever thought about writing books? On Fri, Feb 19, 2010 at 10:57 PM, Thor (Hammer of God) wrote: > Vivisected like string cheese? > >> -Original Message- >> From: full-disclosure-boun...@lists.grok.org.uk [mailto:full- >> disclosure-boun...@lists.grok.org.uk] On Beh

Re: [Full-disclosure] Why

2010-02-19 Thread Jonathan Barningham
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I mean to say, my life is being vivisected. They are pulling my life apart in layers like string cheese. It's quite uncomfortable. On Fri, 19 Feb 2010 21:57:52 + "Thor (Hammer of God)" wrote: >Vivisected like string cheese? > >> -Original Me

[Full-disclosure] [ MDVSA-2010:044 ] mysql

2010-02-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:044 http://www.mandriva.com/security/

Re: [Full-disclosure] Why

2010-02-19 Thread Thor (Hammer of God)
Vivisected like string cheese? > -Original Message- > From: full-disclosure-boun...@lists.grok.org.uk [mailto:full- > disclosure-boun...@lists.grok.org.uk] On Behalf Of Jonathan Barningham > Sent: Friday, February 19, 2010 1:51 PM > To: full-disclosure@lists.grok.org.uk > Subject: Re: [Ful

Re: [Full-disclosure] Why

2010-02-19 Thread Jonathan Barningham
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello. I used to be online friends with a subject of an FBI investigation. (Not saying who for my safety) I suppose I could be of assistance in his arrest and prosecution, however, they didn't approach me that way. They approached me years after I c

Re: [Full-disclosure] [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2010-001

2010-02-19 Thread David Byrne
While discussion of the vulnerability is great, it would be nice for us to retain some credit; the advisory represents the culmination of a lot of research work. The PDF that accompanies the hacking-lab movie is basically just a copy & paste from our advisory with no attribution. Anyone that goe

[Full-disclosure] [SECURITY] [DSA-2002-1] New polipo packages fix denial of service

2010-02-19 Thread Stefan Fritsch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2002-1 secur...@debian.org http://www.debian.org/security/ Stefan Fritsch February 19, 2010

[Full-disclosure] [SECURITY] [DSA-2001-1] New php5 packages fix multiple vulnerabilities

2010-02-19 Thread Raphael Geissert
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2001-1 secur...@debian.org http://www.debian.org/security/ Raphael Geissert February 19, 2010

[Full-disclosure] ZDI-10-019: Mozilla Firefox showModalDialog Cross-Domain Scripting Vulnerability

2010-02-19 Thread ZDI Disclosures
ZDI-10-019: Mozilla Firefox showModalDialog Cross-Domain Scripting Vulnerability http://www.zerodayinitiative.com/advisories/ZDI-10-019 February 19, 2010 -- CVE ID: CVE-2009-3988 -- Affected Vendors: Mozilla Firefox -- Affected Products: Mozilla Firefox 3.0.x -- TippingPoint(TM) IPS Customer Pr

[Full-disclosure] [ MDVSA-2010:043 ] libtheora

2010-02-19 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:043 http://www.mandriva.com/security/

[Full-disclosure] ACM.ORG website has serious data leak again

2010-02-19 Thread the hacker
a serious data leak has been found on acm.org - full member information including postal address and mail address can be extracted from the website. In addition to that the data can also be modified acm.org CEO John White has been informed more than 24 hours ago via email about this problem, bu

[Full-disclosure] [TOOL RELEASE] ENGR SQL FingerprintT [Version 1.00.0006]

2010-02-19 Thread Nelson Brito
.:[ Software Description This is a tool that performs version fingerprinting on Microsoft SQL Server 2000, 2005 and 2008, using well known techniques based on several public tools that identifies the SQL Version. The strength of this tool is that it uses probabilistic algorithm to identify the ver

[Full-disclosure] trying to find more Firefox 0day

2010-02-19 Thread exploit dev
Hi there, I have posted some brief notes about. If you are interested http://extraexploit.blogspot.com/2010/02/firefox-36-0day-trying-to-find-more.html feedback are welcome. -- http://extraexploit.blogspot.com ___ Full-Disclosure - We believe in it. C

Re: [Full-disclosure] [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2010-001

2010-02-19 Thread Ivan Buetler
Hi all, There is an ongoing conversation about a potential XSS with ViewState of the .NET framework. However, some were not able to reproduce the issue and therefore we decided to prepare a short and high resolution movie. http://www.hacking-lab.com/download/ Regards Ivan -Original Me

[Full-disclosure] Adobe & the Ancient vulnerabilities

2010-02-19 Thread Thomas Kristensen
Binary Analysis of latest Adobe patch uncovers ancient vulnerabilities: http://secunia.com/blog/76 -- Kind regards, Thomas Kristensen CSO Use WSUS to Deploy 3rd Party Patches - Download BETA http://secunia.com/vulnerability_scanning/corporate/wsus_3rd_third_party_patching/ Follow us on twitter

[Full-disclosure] SQL injection vulnerability in Amelia CMS

2010-02-19 Thread Maciej Gojny
# Title: [SQL injection vulnerability in Amelia CMS] # Date: [10.02.2010] # Author: [Ariko-Security] # Software Link: [http://www.ameliadesign.eu/] # Version: [ALL] # Tested on: [freebsd / ubuntu] { Ariko-Security - Advisory #3/2/2010 } = SQL injection vulnerabili

Re: [Full-disclosure] help fuzzing/finding Horn CNF formula

2010-02-19 Thread Jeff Williams
Ask Jeremy Brown, he's a pro. http://jbrownsec.blogspot.com/ 2010/2/19 Georgi Guninski > > i know i am dumb. > > i am looking for a HORN CNF that is SAT if and only if |x != y| ($x \ne y$) > for boolean x,y. > > using the Horn constraints in [1] (at most k '1's) + the sought > inequality/nega

[Full-disclosure] help fuzzing/finding Horn CNF formula

2010-02-19 Thread Georgi Guninski
i know i am dumb. i am looking for a HORN CNF that is SAT if and only if |x != y| ($x \ne y$) for boolean x,y. using the Horn constraints in [1] (at most k '1's) + the sought inequality/negation, it might be possible to encode Exact Sat (XSAT) to fast Horn CNF (md5 preimage falls in this case