Re: [Full-disclosure] SANS PHP Port Scanner Remote Code Execution

2013-03-07 Thread Andrew King
Has anyone considered that loads of stuff is shipped bugged? I mean it's not like they hosted it on their site executable. It's also not like we're talking about vsftpd where it's installed for a legitimate purpose on millions if not billions of PCs. The million eyeball test and trolling a

Re: [Full-disclosure] The Mystery of the Duqu Framework

2012-03-19 Thread Andrew King
I think EVERYONE said it was a C implementation + something to get it to C. The interesting part that they glossed over, was the randomness in how arguments were passed. They specifically left that part out of the solved analysis. Just my 2 cents. On Mon, Mar 19, 2012 at 8:59 PM,

[Full-disclosure] audio may be NSFW...just something I've been playing with

2012-03-12 Thread Andrew King
if you're a fan of securitytube: http://www.securitytube.net/video/2943 If you're not: http://vimeo.com/aking1012/rid Either way, It could be considered interesting. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Writing Self Modifying Code

2011-12-05 Thread Andrew King
On Wed, Nov 30, 2011 at 1:30 PM, Adam Behnke adam () infosecinstitute com wrote: Hello full disclosureites, a new tutorial is available at InfoSec Institute ... Your thoughts? who was this content plagiarized from? I wrote it. It wasn't plagarized from anywhere.