Re: [Full-disclosure] Randi Harper aka Sektie demolished

2010-04-29 Thread Anders Klixbull
lol seems to be? you should know better than seems since your email is in the gnaa ascii From: Andrew A [mailto:glutt...@gmail.com] Sent: 28. april 2010 16:57 To: Anders Klixbull Cc: Sandy Vagina; Gary Niger; full-disclosure@lists.grok.org.uk Subject: Re:

Re: [Full-disclosure] Vuln Disclosure summarized (TTBOMA)

2010-04-29 Thread Valdis . Kletnieks
On Thu, 29 Apr 2010 10:17:22 +0200, Thierry Zoller said: - Releasing at a conference = Probable court time. Under what legislation would that potentially be the case ? Ask Michael Lynn about that sometime. And Sklylarov ended up in jail for a while for saying 'Rot-13'. pgpTuzi8BVO1c.pgp

[Full-disclosure] Impossible to Maintain Secure Session With Twitter.com Web Interface

2010-04-29 Thread Chris Palmer
iSEC Partners Security Advisory - 2010-001-twitter https://www.isecpartners.com Twitter - Insecure session management Vendor: Twitter Vendor URL: http://www.twitter.com Severity: High (allows unauthorized hijacking of accounts) Author: Chris Palmer

[Full-disclosure] NT becoming pure microkernel

2010-04-29 Thread iroz
Microsoft has leaked information once again about NT becoming pure microkernel in a new step to make harder exploitation (they believe). The Redmond based company has revealed it's future plans for the NT operating system family. As you know, Windows NT is a Hybrid operating system as opossed

[Full-disclosure] TaskFreak 0.6.2 SQL Injection Vulnerability

2010-04-29 Thread Justin C. Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2010-1583 Vendor notified and product update released. Details of this report are also available at http://www.madirish.net/?article=456 Description of Vulnerability: - -- The Tirzen Framework

[Full-disclosure] Off Topic: Information Security research paper help

2010-04-29 Thread John Jacobs
I'm not the original author of this message, saw it pop-up on Snort-Sigs and as a graduate student myself I figured I'd give this guy a hand to get more visibility. I'm not so sure it's a troll. YMMV. -John Message below, unaltered: Hello Snort and Emerging Threats communities, this is

Re: [Full-disclosure] Off Topic: Information Security research paper help

2010-04-29 Thread Valdis . Kletnieks
On Thu, 29 Apr 2010 09:25:42 CDT, John Jacobs said: 1) Do you use Apple products for your Information Security duties, either exclusively. or occasionally? 2) Have you, at any point in your professional career (professional, being the key word, please do not respond with the context being

Re: [Full-disclosure] Off Topic: Information Security research paper help

2010-04-29 Thread Justin C. Klein Keane
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Successful troll is successful. -anon Or perhaps successful successful enumeration of infosec professionals susceptible to Apple 0-day will be successful? Or perhaps someone is just looking for a date? The inferences are limitless. Justin C. Klein

Re: [Full-disclosure] go public to avoid jail

2010-04-29 Thread Stephen Mullins
That might work if you went through some sort of official channels with a bill of sale and so forth. Claiming that you sold it to some guy on irc after a paypal payment cleared your account probably wouldn't be much of a defense in court. On Thu, Apr 29, 2010 at 12:05 PM, T Biehn

[Full-disclosure] [ MDVSA-2010:086 ] kdegraphics

2010-04-29 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:086 http://www.mandriva.com/security/

Re: [Full-disclosure] go public to avoid jail

2010-04-29 Thread T Biehn
But he was a verified paypal buyer, your honor. lols. -Travis On Thu, Apr 29, 2010 at 12:32 PM, Stephen Mullins steve.mullins.w...@gmail.com wrote: That might work if you went through some sort of official channels with a bill of sale and so forth. Claiming that you sold it to some guy on

Re: [Full-disclosure] NT becoming pure microkernel

2010-04-29 Thread Nicolas RUFF
Hello, Are you talking about the Midori [1]/Singularity [2] project that started in 2003? Or is there anything new? [1] http://en.wikipedia.org/wiki/Midori_(operating_system) [2] http://en.wikipedia.org/wiki/Singularity_(operating_system) Regards, - Nicolas RUFF

[Full-disclosure] Vulnerabilities in CCMS

2010-04-29 Thread MustLive
Hello Full-Disclosure! I want to warn you about security vulnerabilities in system CCMS - Clan Content Management System. In this advisory I'm continue to inform readers of mailing lists about vulnerable web applications which are using CaptchaSecurityImages.php. If you read Bugtraq you can saw

[Full-disclosure] [ MDVSA-2010:087 ] poppler

2010-04-29 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:087 http://www.mandriva.com/security/

[Full-disclosure] Interactive Linux Binary Analysis Tool

2010-04-29 Thread Andrew Lyon
I'm sure I once read about a tool for linux which could execute a binary and prompt for each particular library or system call to be approved or whitelisted by various attributes, I have searched everywhere but I can find no trace of it, I think it was posted to FD, any ideas? Andy