Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-26 Thread news
Le jeudi 25 février 2010 23:43:54, Mark Shuttleworth a écrit : > We're bringing social interaction from the web, into the desktop. We're > breathing life back into the city center, as it were. We're making the > desktop more human. This is our mission, our reason for loving what we > do. I'm sorry

[Full-disclosure] [USN-905-1] sudo vulnerabilities

2010-02-26 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-905-1 February 26, 2010 sudo vulnerabilities CVE-2010-0426, CVE-2010-0427 === A security issue affects the following Ubuntu releases: Ubuntu 6.06

[Full-disclosure] John Young of Cryptome on Infowars with Alex Jones

2010-02-26 Thread John Q Public
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Alex Jones is a Hal Turner like intel-asset. He runs this gig out of Austin, TX called infowars. Kind of a conspiracy-minded, rightwing news portal. Think about the waco/ruby ridge typo culture. Stuff that the gov monitors very closely. I don't know

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-26 Thread John Q Public
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Well considering the tone I used, Frankly, I'm surprised you even dignified that. I don't always speak in such a tone. It's just the atmosphere of the scene here. I want my system here to be pure and free. No blogcruft. Remember how XP and Vista woul

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-26 Thread Daniel Llewellyn
On Thu, Feb 25, 2010 at 22:43, Mark Shuttleworth wrote: > On 25/02/10 22:28, John Q Public wrote: > > Ubuntu one? Chatroom accounts? Online, Invisible? You're turning > the default Ubuntu into your huge autistic chatroom. > > > We're bringing social interaction from the web, into the desktop

Re: [Full-disclosure] WinXP IE .HLP file 0day

2010-02-26 Thread Maurycy Prodeus
> There are loads of known vulns in winhlp32.exe, particularly in the > decompression routines.  That's why it was removed from Vista, and why > .hlp files are considered to be dangerous file formats. .HLP == executable According to http://en.wikipedia.org/wiki/WinHelp : "A rather security critic

Re: [Full-disclosure] Mozilla firefox 3.6 unpatched phishing vulnerability

2010-02-26 Thread Daniel Veditz
bugsban...@hushmail.com wrote: > ...Unpatched bug since Mozilla firefox 3.0... > > Mozilla "INsecurity team" remember, security through obscurity just > DOESN'T WORK... > Locking down bugzilla advisories even the 2 years old ones is > unnecessary and lame. Care to expand on "locking down" and "

Re: [Full-disclosure] WinXP IE .HLP file 0day

2010-02-26 Thread Peter Ferrie
> Rather funny than scary: > http://isec.pl/vulnerabilities10.html There are loads of known vulns in winhlp32.exe, particularly in the decompression routines. That's why it was removed from Vista, and why .hlp files are considered to be dangerous file formats. ___

[Full-disclosure] WinXP IE .HLP file 0day

2010-02-26 Thread Maurycy Prodeus
Rather funny than scary: http://isec.pl/vulnerabilities10.html cheers! ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-26 Thread Clement Gamé
I must admit that this is crap. I don't blame the ubuntu team for wanting to integegrate this kind of tools in the default base packages, Since ubuntu is mainly designed for the masses. Nevertheless i will remove them ( the ubuntu one client as well ) in my upcoming lucid lynx fork ( www.shado

Re: [Full-disclosure] Fwd: steathbomb

2010-02-26 Thread Michael Holstein
> anyone see this and know about it? How it works and good detection? > > http://www.brickhousesecurity.com/pc-computer-spy.html > autorun.inf is how it installs itself. once installed, it works like any other rootkit spyware (screen grabs, keystroke/window logger, etc). Cheers, Michael Hol

Re: [Full-disclosure] Fwd: steathbomb

2010-02-26 Thread Robert Portvliet
It uses i-bots, nano i-bots to be exact ;) On Fri, Feb 26, 2010 at 7:35 AM, RandallM wrote: > anyone see this and know about it? How it works and good detection? > > http://www.brickhousesecurity.com/pc-computer-spy.html > > -- > been great, thanks > RandyM > a.k.a System > > _

[Full-disclosure] getPlus insufficient domain name validation vulnerability

2010-02-26 Thread Akita Software Security
getPlus insufficient domain name validation vulnerability Yorick Koster, April 2009

[Full-disclosure] [ MDVSA-2010:050 ] apache-mod_security

2010-02-26 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:050 http://www.mandriva.com/security/

[Full-disclosure] Fwd: steathbomb

2010-02-26 Thread RandallM
anyone see this and know about it? How it works and good detection? http://www.brickhousesecurity.com/pc-computer-spy.html -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosu

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-26 Thread Rafael Moraes
LOL It was funny! 2010/2/25 Mark Shuttleworth > On 25/02/10 22:28, John Q Public wrote: > > wtf is this. > > A centralized identity system? > > In an open source operating system? By default? > > You're going overboard here. You're just a rich trustfunder and > your proles are afraid to say

[Full-disclosure] SyScan'10 CALL FOR PAPERS

2010-02-26 Thread tho...@syscan.org
*SyScan'10 CALL FOR PAPERS* *ABOUT SYSCAN'10* This year, SyScan'10 will be held in the 4 exciting cities of Singapore, Hangzhou, Taipei and Ho Chi Minh City. Details are as follows: */SyScan'10 Singapore /*date: 17 – 18 June 2010 */SyScan'10 HangZhou /*date: 10 - 11 July 2010 */SyScan'10 Taipei

Re: [Full-disclosure] EasyJet is storing user passwords in the clear

2010-02-26 Thread Sai Emrys
On Thu, Feb 25, 2010 at 2:57 PM, Dan Kaminsky wrote: > That's 20% with a work effort of effectively 0 per password with a single > dictionary.  Spend a few minutes of brute force on each pass and the success > rate grows. Of course. Which is why I said it depends on what you consider "minimal". ;

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-26 Thread Mark Shuttleworth
On 25/02/10 22:28, John Q Public wrote: > wtf is this. > > A centralized identity system? > > In an open source operating system? By default? > > You're going overboard here. You're just a rich trustfunder and > your proles are afraid to say you're making a huge error. Just a tip: when you're givi

Re: [Full-disclosure] EasyJet is storing user passwords in the clear

2010-02-26 Thread Sai Emrys
Dan - >    I see where you're coming from, but what are the most recent statistics > on the effectiveness of hash cracking?  Isn't it something like 70% of the > passwords in the field can be cracked with a minimal amount of brute > forcing? Of course this depends on what you mean by "minimal". h