Re: [Full-disclosure] Google - (Pin via Postal Delivery) Information Disclosure - Video

2013-08-16 Thread Julius Kivimäki
So, what exactly is this advisory supposed to be about? The lack of your camera skills? Or perhaps about the fact that google sent you a letter? Oh, and I really wonder how you calculated your CVSS. The NVD calculator comes up with 0 for me. 2013/8/16 Vulnerability Lab

[Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Luther Blissett
Hello dear companions, Two days ago one of my tor exit nodes experienced something I'm now calling limestonenetworks DDoS on polipo ( $WAN_IP:8123 ), since all packets in the storm were flowing from a range of 514 different IP addresses, all of them inside limestonenetworks IP range and targeting

[Full-disclosure] bash-3.0-geinpeek shell sniffer release!

2013-08-16 Thread x90c
Hi forks! I release it. It's my old project to sniff keystroke on bash shell. x90c bash-3.0-geinpeek-0.2.tar.gz Description: GNU Zip compressed data #include stdio.h #include stdlib.h #include string.h #include unistd.h /* bash-3.0-geinpeek-0.2 auto installer ( install-0.2.c ) compile #

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Bart van Tuil
Luther, Is it just me, or is this ddos of 19045 packets in three hours a really, really sorry attempt at anything at all?? Even the peak of 30 pkts/sec wouldn't really disrupt -any- service on a modern system, or disrupt any self-respecting internet connection. I agree you shouldn't ignore the

[Full-disclosure] JoinSEC London - October

2013-08-16 Thread Ralf Braga
About the JoinSEC London Designed by Information Security professionals The Information Security has been one of the most increasing concerns worldwide. Everyday new attacks and counter attacks emerge, making it impossible for professionals to keep themselves up to date. The JoinSEC

[Full-disclosure] Advisory: Unfuddle.com - Open Redirection

2013-08-16 Thread LIAD Mizrachi
Advisory: Unfuddle.com - Open Redirection Author: Liad Mizrachi Vendor URL: http://unfuddle.com Status: Fixed == Vulnerability Description == Unfuddle offers secure, hosted software project management environment. When unauthenticated user tries

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jann Horn
On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: Hello dear companions, Two days ago one of my tor exit nodes experienced something I'm now calling limestonenetworks DDoS on polipo ( $WAN_IP:8123 ), since all DDoS? So you mean your systems were impacted by that? packets in

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jeffrey Walton
On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn j...@thejh.net wrote: On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: Hello dear companions, Two days ago one of my tor exit nodes experienced something I'm now calling limestonenetworks DDoS on polipo ( $WAN_IP:8123 ), since all

[Full-disclosure] t2'13: Challenge to be released 2013-09-07 10:00 EEST

2013-08-16 Thread Tomi Tuominen
It is that time of the year again - we’re pleased to announce the release of the t2’13 Challenge! Soon after t2’12 was over, we discovered that the conference had been infiltrated by an APT. Our best guess is that the APT pwned the laptop of one of the conference organizers and successfully

[Full-disclosure] CVE-2013-0526 IBM GCM16/32 Remote Command Execution.

2013-08-16 Thread Alejandro Alvarez
I. Product description The IBM 1754 GCM family provides KVM over IP and serial console management technology in a single appliance. II. Vulnerability information Impact: Command execution Remotely exploitable: yes CVE: 2013-0526 CVS Score: 8.5 III. Vulnerability details GCM16

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jann Horn
On Fri, Aug 16, 2013 at 01:37:54PM -0400, Jeffrey Walton wrote: On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn j...@thejh.net wrote: On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: Hello dear companions, Two days ago one of my tor exit nodes experienced something I'm now

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Jeffrey Walton
On Fri, Aug 16, 2013 at 4:30 PM, Jann Horn j...@thejh.net wrote: On Fri, Aug 16, 2013 at 01:37:54PM -0400, Jeffrey Walton wrote: On Fri, Aug 16, 2013 at 1:31 PM, Jann Horn j...@thejh.net wrote: On Thu, Aug 15, 2013 at 05:29:52PM -0300, Luther Blissett wrote: Hello dear companions, Two

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread adam
Jann, you know what's even worse than someone being a dick for no reason? Someone being a _stupid_ dick for no reason. In case you're unaware, the word massive was completely absent from this thread until YOU attempted to put it in someone elses' mouth. Beyond that, since you want to rip apart an

Re: [Full-disclosure] Who's behind limestonenetworks.com AKA DDoS on polipo(8123)

2013-08-16 Thread Stefan Jon Silverman
Title: Message +1 Regards, Stefan On 8/16/2013 2:49 PM, adam wrote: Jann, you know