Re: [Full-disclosure] Going "underground", living out of backpack, etc?

2010-02-28 Thread Christian Sciberras
Start by not touching any kind of digital device. You wouldn't know how many chinese have put tracking/spy bugs inside them. Or how many modified NSA backdoors, for the matter. Using a PC probably increases risk by 1000%. On Mon, Mar 1, 2010 at 5:49 AM, Simon Garfinkle wrote: > -BEGIN PGP

[Full-disclosure] Going "underground", living out of backpack, etc?

2010-02-28 Thread Simon Garfinkle
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hello. I am interested in getting some advice from you security professionals (white hat and black hat) about going underground. I am sick of big brother, I love independence, I was to experience the world and have no commitments. I am just sick of

[Full-disclosure] [SECURITY] [DSA 2004-1] New Linux 2.6.24 packages fix several vulnerabilities

2010-02-28 Thread dann frazier
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2004-1secur...@debian.org http://www.debian.org/security/ Dann Frazier February 27, 2010 h

Re: [Full-disclosure] Yahoo! UK and US Hiring Security and Risk management experts

2010-02-28 Thread Henri Torgemane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Yes. To clarify, this post was meant to be satirical. It was not written by an employee at Yahoo. I apologize for mentioning age. (In the United States, you're not allowed to mention age, creed, gender, etc. in terms of hiring new guys) However, I ha

Re: [Full-disclosure] Two MSIE 6.0/7.0 NULL pointer crashes

2010-02-28 Thread Marsh Ray
On 2/28/2010 2:22 PM, Pavel Kankovsky wrote: > On Sun, 24 Jan 2010, Dan Kaminsky wrote: >> Nah, it's actually a lot worse. You have to start thinking in terms of >> state explosion -- having turing complete access to even some of the >> state of a remote system creates all sorts of new states that,

Re: [Full-disclosure] Fwd: steathbomb

2010-02-28 Thread T Biehn
Alzo see: USB DMA. On Fri, Feb 26, 2010 at 8:29 AM, McGhee, Eddie wrote: > Its simply using USB autorun to launch and install itself, not sure how much > it is picked up but tbh you could build one yourself possibly with the > features you need, just look into getting some decent bot source and

Re: [Full-disclosure] Yahoo! UK and US Hiring Security and Risk management experts

2010-02-28 Thread mark seiden
yet another nice troll with a stylistic stench of n3td3v about it, judging by the fanciful misconceptions surrounding a kernel of truth (and the phony attribution to someone to whom he's taken an unreasonable disliking...) it's true that yahoo is hiring security people, though, typically not as

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-28 Thread Mark Shuttleworth
On 26/02/10 19:55, John Q Public wrote: > Well considering the tone I used, Frankly, I'm surprised you even > dignified that. I don't always speak in such a tone. It's just the > atmosphere of the scene here. > > I want my system here to be pure and free. No blogcruft. > > Remember how XP and Vista

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-28 Thread Michael
The error of the future: "srry ur computar doent werks lolz. brb gng two teh bathrm" On Fri, Feb 26, 2010 at 5:15 PM, wrote: > Le jeudi 25 février 2010 23:43:54, Mark Shuttleworth a écrit : > >> We're bringing social interaction from the web, into the desktop. We're >> breathing life back into

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-28 Thread Jean-Christophe Baptiste
Le jeudi 25 février 2010 23:43:54, Mark Shuttleworth a écrit : > We're bringing social interaction from the web, into the desktop. We're > breathing life back into the city center, as it were. We're making the > desktop more human. This is our mission, our reason for loving what we > do. I'm sorry

[Full-disclosure] Orbital Viewer v1.04 (.orb) 0day Local Universal SEH Overflow Exploit

2010-02-28 Thread Steven Seeley
http://www.corelan.be:8800/index.php/forum/security-advisories/corelan-10-011-orbital-viewer-orb-buffer-overflow/ Kind regards, Steven Seeley (mr_me) _ View photos of singles in your area!

Re: [Full-disclosure] Fwd: steathbomb

2010-02-28 Thread McGhee, Eddie
Its simply using USB autorun to launch and install itself, not sure how much it is picked up but tbh you could build one yourself possibly with the features you need, just look into getting some decent bot source and go from there, would save the 130 dollars imo. Plenty source code out there to

Re: [Full-disclosure] Fwd: stealthbomb

2010-02-28 Thread Dan Yefimov
On 26.02.2010 15:35, RandallM wrote: > anyone see this and know about it? How it works and good detection? > > http://www.brickhousesecurity.com/pc-computer-spy.html > I doubt very much in that. The matter is that USB hardware is able to transfer data only when host requests that, IOW it is the ho

[Full-disclosure] Watch out weev... Honeytrap.

2010-02-28 Thread Cron Solo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Andrew Auerheimer (Weev) was contacted by a honeytrap at a bar who tried to seduce him. Weev has previously alluded that it might be FBI (probably counterintelligence). This is actually only a "maybe". Who says weev hasn't attracted this attention of

[Full-disclosure] [SECURITY] [DSA 2004-1] New samba packages fix several vulnerabilities

2010-02-28 Thread Moritz Muehlenhoff
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2004-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff February 28, 2010

Re: [Full-disclosure] Two MSIE 6.0/7.0 NULL pointer crashes

2010-02-28 Thread Christian Sciberras
"Sometimes the vulnerability itself is a functional requirement (or considered to be one of them). Has anyone mentioned ActiveX?" Or NPAPI for the matter. Really, other then the automated-after-user-accept-installation they're both the same. On Sun, Feb 28, 2010 at 9:22 PM, Pavel Kankovsky < p...@

Re: [Full-disclosure] Two MSIE 6.0/7.0 NULL pointer crashes

2010-02-28 Thread Pavel Kankovsky
On Sun, 24 Jan 2010, Dan Kaminsky wrote: It took me more than one month to write this response? Ouch! > > When you discover the program is designed too badly to be > > maintained, the best strategy is to rewrite it. > No question. And how long do you think that takes? It depends. Probably in t

Re: [Full-disclosure] Get WinScanX Pro for FREE or $10 dollars for the month of February (only 5 days left!)

2010-02-28 Thread sunjester
I've seen better on planetsourcecode.com haha -- Founder/Activist http://fusecurity.com/ | "Free Security Technology" ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia