[Full-disclosure] Special PenTest SE issue ready to download!

2012-01-02 Thread Maciej Kozuszek
Hi guys, The new special Social Engineering issue of PenTestMag is out! Free 27 pages teaser with full article by Chris Hadnagy available on our web: http://pentestmag.com/social-engineering-pentest-092012/ Enjoy reading! -- Maciej Kozuszek PenTest Magazine Product Manager Software Media Sp z

[Full-disclosure] [ MDVSA-2012:001 ] fcgi

2012-01-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:001 http://www.mandriva.com/security/ _

[Full-disclosure] [SECURITY] [DSA 2377-1] cyrus-imapd-2.2 security update

2012-01-02 Thread Nico Golde
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - --- Debian Security Advisory DSA-2377-1 secur...@debian.org http://www.debian.org/security/ Nico Golde Jan 1st, 2012

Re: [Full-disclosure] captcha

2012-01-02 Thread Nate Theis
Very carefully. On Jan 1, 2012 1:52 PM, "ebhakt" wrote: > > Hii guys, &g > > Hii guys, > I want to know the logic behind creating a captcha image > I know how the servers are designed and what the captcha security does!! > but how the captcha imagae is generated >> that's my main question !! > > A

Re: [Full-disclosure] captcha

2012-01-02 Thread Dave
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 01/01/2012 13:43, ebhakt wrote: > Hii guys, > I want to know the logic behind creating a captcha image > I know how the servers are designed and what the captcha security does!! > but how the captcha imagae is generated >> that's my main question !!

[Full-disclosure] [ MDVSA-2012:002 ] t1lib

2012-01-02 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2012:002 http://www.mandriva.com/security/ _

[Full-disclosure] INSECT Pro - Version 3.0 Released!

2012-01-02 Thread runlvl
Great news!!! This 2012 we released the new version of INSECT PRO INSECT Pro 3.0 - Ultimate is here! This penetration security auditing and testing software solution is designed to allow organizations of all sizes mitigate, monitor and manage the latest security threats vulnerabilities and impleme

[Full-disclosure] facebook

2012-01-02 Thread t0hitsugu
anyone else notice the apps.facebook.com/ tend to be prone to sql vulns? ie, https://apps.facebook.com/worldwide_dev/ while not logged in, and https://apps.facebook.com/worldwide_dev/%00 Due to them being apps, facebook I believe is not responsible for any security issues, but in this case there i

Re: [Full-disclosure] facebook

2012-01-02 Thread t0hitsugu
uh..wtf? On Jan 2, 2012 12:46 PM, wrote: > Ladies and gentleman, I will be unplugged from my email until the 17th of > January. > > In the mean time here's a video of a bunny opening your mail > http://www.youtube.com/watch?v=LMyaRmTwdKs > > Your mail will not be forwarded and I will contact you

Re: [Full-disclosure] facebook

2012-01-02 Thread Gage Bystrom
Yeah, just mark those as spam. People with auto reply when they are on a mailing list are dumb. And yeah FB has no responsibility over apps. Generally and sqli or what not is going to the app owners site, not FB so why should they care? On Jan 2, 2012 12:48 PM, "t0hitsugu" wrote: > uh..wtf? > On

Re: [Full-disclosure] facebook

2012-01-02 Thread Jeffrey Walton
On Mon, Jan 2, 2012 at 4:43 PM, Gage Bystrom wrote: > Yeah, just mark those as spam. People with auto reply when they are on a > mailing list are dumb. > > And yeah FB has no responsibility over apps. Generally and sqli or what not > is going to the app owners site, not FB so why should they care?

Re: [Full-disclosure] Nmap

2012-01-02 Thread Gage Bystrom
(I don't have the original, so ill qoute this guy) Nmap has an option to change how it determines if a host is up by attempting a port connection instead. I find this to be highly effective. Using a couple of standard ports are the best, such as 80, 21, etc. If you only have a few ports your searc

Re: [Full-disclosure] facebook

2012-01-02 Thread Valdis . Kletnieks
On Mon, 02 Jan 2012 12:47:37 PST, t0hitsugu said: > uh..wtf? > On Jan 2, 2012 12:46 PM, wrote: > > Ladies and gentleman, I will be unplugged from my email until the 17th of > > January. That should read: "Ladies and gentlemen, my email address will be available for social engineering and other a

Re: [Full-disclosure] facebook

2012-01-02 Thread James Condron
Yup... jc@egg:~$ dig TXT astalavista.com ; <<>> DiG 9.6-ESV-R4-P3 <<>> TXT astalavista.com ;; global options: +cmd ;; Got answer: ;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 6237 ;; flags: qr rd ra; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0 ;; QUESTION SECTION: ;astalavista.com.

Re: [Full-disclosure] INSECT Pro - Version 3.0 Released!

2012-01-02 Thread Dcdave
Do you really think anyone on this list would pay money for somebody else's pentesting product? I'm interested - please let me know if it works for you - I would love to get some free advertisement here, too! Dcdave -- A crust eaten in peace is better than a banquet partaken in anxiety. -Aesop

Re: [Full-disclosure] facebook

2012-01-02 Thread t0hitsugu
I'm more confused as to why he replied when I had messaged this board regarding facebook and sql errors, not him or anything to do with astalavista... On Jan 2, 2012 2:58 PM, "James Condron" wrote: > Yup... > > jc@egg:~$ dig TXT astalavista.com > > ; <<>> DiG 9.6-ESV-R4-P3 <<>> TXT astalavista.co

Re: [Full-disclosure] facebook

2012-01-02 Thread Valdis . Kletnieks
On Mon, 02 Jan 2012 18:39:56 PST, t0hitsugu said: > I'm more confused as to why he replied when I had messaged this board Because he has a stupid autoresponder that blabs out to the From: address without bothering to figure out if it's actually addressed to him personally, or if it's traffic to a

Re: [Full-disclosure] facebook

2012-01-02 Thread Raj Mathur (राज माथुर)
On Tuesday 03 Jan 2012, valdis.kletni...@vt.edu wrote: > On Mon, 02 Jan 2012 18:39:56 PST, t0hitsugu said: > > I'm more confused as to why he replied when I had messaged this > > board > > Because he has a stupid autoresponder that blabs out to the From: > address without bothering to figure out i

Re: [Full-disclosure] facebook

2012-01-02 Thread Valdis . Kletnieks
On Tue, 03 Jan 2012 10:37:24 +0530, "Raj Mathur (=?utf-8?b?4KSw4KS+4KSc?= =?utf-8?b?IOCkruCkvuCkpeClgeCksA==?=)" said: > 5) Check for the Precedence: Bulk or Precedence: List header. Perfectly correct, I was trying to remember which one I forgot, and missed that one. And so did the guy's auto-re