[Full-disclosure] [SECURITY] [DSA 2058-1] New glibc packages fix several vulnerabilities

2010-06-11 Thread Aurelien Jarno
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2058-1 secur...@debian.org http://www.debian.org/security/ Aurelien Jarno June 10, 2010

Re: [Full-disclosure] RDP, can it be done safely?

2010-06-11 Thread musnt live
Hello Full Disclosure, I'd like to warn you about a bonehead group of software developers. One group of boneheads are in complex in state in US is that called in Redmond. With exploit in hand to be released in future I give you to PoC:

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Tavis Ormandy
Susan, this is what is called full disclosure, and my response was relevant. I will not answer anymore uninformed questions on this topic. Thanks, Tavis. On Thu, Jun 10, 2010 at 09:02:37AM -0700, Susan Bradley wrote: I'm not asking about disclosure. I'm asking what happened to the level of

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Thu, Jun 10, 2010 at 12:18 PM, Susan Bradley sbrad...@pacbell.netwrote: Nope Mr. Live, other than dealing with .NET updates and a 982331 that keeps wanting to have UAC turned off on some Win7/Vistas to get installed, this is just my normal calm, try to also consider the consumers and

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Thu, Jun 10, 2010 at 12:59 PM, Christian Sciberras uuf6...@gmail.comwrote: Susan, if you want my advise, don't even bother with Mr Live. Cheers. Hello Full Disclosure, I will now speak to you about chauvinism. For starters here Mrs. Susan chose to call me Mr. not knowing the identity of

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Tavis Ormandy
On Thu, Jun 10, 2010 at 07:02:03PM +0200, Thomas Kristensen wrote: Tavis, Nice find, but during our analysis we discovered that your hotfix unfortunately is inadequate. For more information see: http://secunia.com/blog/103/ Patches are, of course, welcome. Thanks, Tavis. --

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Tavis Ormandy
On Thu, Jun 10, 2010 at 07:21:48PM +0200, Tavis Ormandy wrote: On Thu, Jun 10, 2010 at 07:02:03PM +0200, Thomas Kristensen wrote: Tavis, Nice find, but during our analysis we discovered that your hotfix unfortunately is inadequate. For more information see:

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Jhfjjf Hfdsjj
Hey just wanted to say that my default installation of Windows 7 doesnt seem vulnerable~no hcp protocol handler. Just thought some people would like to take note :) - Original Message From: Tavis Ormandy tav...@cmpxchg8b.com To: full-disclosure@lists.grok.org.uk Cc:

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Bud Spencer
Hello list, The included POC seems to work fine with IE7 or IE8 installed, however I am not able to run any javascript code on a clean XP SP2 with IE6. Does that mean that you require a newer browser to use the defer trick?, is machines with IE6 for a change unaffected? I see that Tavis says

Re: [Full-disclosure] Hacxx Anti Malware for Windows XP

2010-06-11 Thread Geoff Plourde
don't make me say it On Mon, Jun 7, 2010 at 7:33 AM, Harry Behrens ha...@behrens.com wrote: at least he's got chuzpe..;-) netinfinity wrote: *Hacxx Anti Malware for Windows XP blocks virus and worms using known filenames. To install it simply visit http:///antimalware.x10.bz and click

Re: [Full-disclosure] Hacxx Anti Malware for Windows XP

2010-06-11 Thread huj huj huj
say what ese 2010/6/11 Geoff Plourde geoff.plou...@gmail.com don't make me say it On Mon, Jun 7, 2010 at 7:33 AM, Harry Behrens ha...@behrens.com wrote: at least he's got chuzpe..;-) netinfinity wrote: *Hacxx Anti Malware for Windows XP blocks virus and worms using known filenames.

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Christian Sciberras
In my humble opinion, he could have waited a couple more days just in case Microsoft decided to do the unprecedented. In which case, I progressive change of policies at Microsoft are better than a couple of users getting hacked from pron sites... Cheers. On Thu, Jun 10, 2010 at 8:20 PM, Benjamin

[Full-disclosure] [ MDVSA-2010:114 ] dhcp

2010-06-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:114 http://www.mandriva.com/security/

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread John Jacobs
Consequently, in my humble opinion I think there should be less focus on the emotional interaction between Microsoft and Travis' findings. Of course it's easy for me to assert this; when I wake up in the morning I don't have the same challenges of wading through a soup of emotional fog and

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Thu, Jun 10, 2010 at 12:16 PM, Tavis Ormandy tav...@cmpxchg8b.com wrote: I will not answer anymore uninformed questions on this topic. Riddle me this Tavis. For why not responsible disclosure you put millions of Microsoft customers at risk. Hello list, I'd like to warn you about reckless

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Benjamin Franz
On 06/11/2010 02:40 AM, Christian Sciberras wrote: In my humble opinion, he could have waited a couple more days just in case Microsoft decided to do the unprecedented. In which case, I progressive change of policies at Microsoft are better than a couple of users getting hacked from pron

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Benji
because when she gets 0wn3d she can be all like 'ruh roh, well, 0day can happen to anyone' On Fri, Jun 11, 2010 at 4:01 PM, Benjamin Franz jfr...@freerun.com wrote: On 06/11/2010 02:40 AM, Christian Sciberras wrote: In my humble opinion, he could have waited a couple more days just in case

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread T Biehn
It's a good thing I ran that anti-hacker script!!! On Fri, Jun 11, 2010 at 11:28 AM, Benji m...@b3nji.com wrote: because when she gets 0wn3d she can be all like 'ruh roh, well, 0day can happen to anyone' On Fri, Jun 11, 2010 at 4:01 PM, Benjamin Franz jfr...@freerun.com wrote: On

Re: [Full-disclosure] Hacxx Anti Malware for Windows XP

2010-06-11 Thread Valdis . Kletnieks
On Fri, 11 Jun 2010 11:06:47 +0200, huj huj huj said: say what ese Most English transliterations of the Yiddish spell it chutzpah rather than chuzpe. And the Yiddish 'ch' is closer to an aspirated h than the standard English 'ch as in chicken'. pgpBO3hXnSjd9.pgp Description: PGP signature

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Fri, Jun 11, 2010 at 11:28 AM, Benji m...@b3nji.com wrote: because when she gets 0wn3d she can be all like 'ruh roh, well, 0day can happen to anyone' Hello list. I'd like to warn you about Susan Bradley. I've seen her pictures and for its you must be desperate to want to own her.

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Fri, Jun 11, 2010 at 12:03 PM, T Biehn tbi...@gmail.com wrote: It's a good thing I ran that anti-hacker script!!! It's a good thing there is to be a local bomb squad near me. http://www.cbc.ca/world/story/2005/06/13/canadian-bomb050613.html ___

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread T Biehn
Totally, I'd work on getting a dog too. On Jun 11, 2010 12:20 PM, musnt live musntl...@gmail.com wrote: On Fri, Jun 11, 2010 at 12:03 PM, T Biehn tbi...@gmail.com wrote: It's a good thing I ran that a... It's a good thing there is to be a local bomb squad near me.

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Fri, Jun 11, 2010 at 1:06 PM, T Biehn tbi...@gmail.com wrote: Totally, I'd work on getting a dog too. On Jun 11, 2010 12:20 PM, musnt live musntl...@gmail.com wrote: On Fri, Jun 11, 2010 at 12:03 PM, T Biehn tbi...@gmail.com wrote: It's a good thing I ran that a... It's a good thing

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Fri, Jun 11, 2010 at 1:43 PM, T Biehn tbi...@gmail.com wrote: Maybe you can call twice and get both of them really upset? Maybe I will. Would she let me sit on her bed? http://images.realogyfg.com/j/2/5/15907460/62A47ADD-C353-4F73-94FB-742937D88A0B-6.jpg Oh n00z all this information for on

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread musnt live
On Fri, Jun 11, 2010 at 1:53 PM, T Biehn tbi...@gmail.com wrote: So far so good. You've been able to go from t biehn - Travis Biehn - Bomber Article (parent's names, city, state, country) - whitepages.com (Address and Phone number) - (not clear on your jump here, did you google their name or

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread T Biehn
So far so good. You've been able to go from t biehn - Travis Biehn - Bomber Article (parent's names, city, state, country) - whitepages.com (Address and Phone number) - (not clear on your jump here, did you google their name or for the address?) Real estate listings. Now to pull the SS and CC #'s

[Full-disclosure] [ MDVSA-2010:115 ] perl

2010-06-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:115 http://www.mandriva.com/security/

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Benji
You're just jealous I had the intuition to protect myself. Sent from my iPhone On 11 Jun 2010, at 17:03, T Biehn tbi...@gmail.com wrote: It's a good thing I ran that anti-hacker script!!! On Fri, Jun 11, 2010 at 11:28 AM, Benji m...@b3nji.com wrote: because when she gets 0wn3d she can be all

[Full-disclosure] [ MDVSA-2010:116 ] perl

2010-06-11 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2010:116 http://www.mandriva.com/security/

[Full-disclosure] My private key

2010-06-11 Thread Thor (Hammer of God)
This is my private key. I'll explain later. ?xml version=1.0? !--TGP - Thor's Godly Privacy: KeyFob XML Document-- KeyFobsKeyFobNameTGP FobNamePrivateTest/FobName PublicKey/PublicKey

[Full-disclosure] Test two

2010-06-11 Thread Thor (Hammer of God)
Sorry, more of my rantings... ?xml version=1.0? !--TGP - Thor's Godly Privacy: Encrypted Container XML Document-- TGPContainer