Re: [Full-disclosure] [SECURITY] [DSA 2502-1] python-crypto security update

2012-06-25 Thread BMF
ly secure way to share the entropy with all of my VMs where it is really needed. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] FW: Curso online - Profesional pentesting - Promocion ( 25% de descuento )

2012-05-20 Thread BMF
Actually, this Juan Sacco assclown has been pissing me off too. I'm in some group with him on linkedin and getting his messages. I keep flagging them as spam. I wish I knew how to get him to stop emailing and messaging me. Juan: Knock it off, you disaffected deleterious douchenozzle. On Sat, May

Re: [Full-disclosure] phpMyBible 0.5.1 Mutiple XSS

2012-04-22 Thread BMF
On Sun, Apr 22, 2012 at 9:32 PM, Laurelai wrote: > On 4/22/12 10:56 PM, BMF wrote: >> Ezekiel 23:20 >> > Its Ezekiel 25:17.. It sounded cool when he said it in the movie but I've never found any Bible that actually goes anything like what he said. Besides, I'm

Re: [Full-disclosure] phpMyBible 0.5.1 Mutiple XSS

2012-04-22 Thread BMF
Ezekiel 23:20 On Sun, Apr 22, 2012 at 12:59 PM, Thor (Hammer of God) wrote: > You dropped a FD on the BIBLE??  Dude, you're going straight to Hacker Hell!   > :) > > > > Timothy "Thor"  Mullen > www.hammerofgod.com > Thor's Microsoft Security Bible > > > > -Original Message- > From: full-

Re: [Full-disclosure] Full-Disclosure Digest, Vol 83, Issue 21

2012-01-17 Thread BMF
ly recent incident of "twiddle the URL" which got someone prosecuted and will be familiar to some here... http://simonhunt.wordpress.com/2011/01/19/two-charged-with-data-theft-from-june-10s-att-hack/ BMF ___ Full-Disclosure - We believe i

Re: [Full-disclosure] Rate Stratfor's Incident Response

2012-01-12 Thread BMF
On Thu, Jan 12, 2012 at 4:17 PM, Jeffrey Walton wrote: > Is it a house, or is it a public store like Walmart or Home Depot? And thus begins the inexorable failure of the "computer security is like physical security" analogy... BMF ___ Fu

Re: [Full-disclosure] how i stopped worrying and loved the backdoor

2010-12-25 Thread BMF
it came out. I am quite familiar with turbulent boundary layers. Nobody sells hardware (hard drives, in this case) which actually implements the technique. All of my original queries still stand. BMF ___ Full-Disclosure - We believe in it. Charter: http:

Re: [Full-disclosure] how i stopped worrying and loved the backdoor

2010-12-24 Thread BMF
Firmware Hub chip that nobody seems to use anymore. I have heard of people pointing webcams at lava lamps and such to get random numbers. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and s

Re: [Full-disclosure] how i stopped worrying and loved the backdoor

2010-12-24 Thread BMF
mewhere and attach it via USB to my entropy server host then install a package with a config file on all of my machines pointing to the entropy host. But so far I know of no such thing. Do you? BMF ___ Full-Disclosure - We believe in it. Ch

Re: [Full-disclosure] Default SSL Keys in Multiple Routers

2010-12-20 Thread BMF
V200's for corp VPN access. They are configured with a shared secret. Wouldn't they use DH with the built in private key to exchange the shared secret which would make the VPN traffic itself vulnerable? Looks like you have the 210 but not the 200 but I bet your tool could pull out

Re: [Full-disclosure] Allegations regarding OpenBSD IPSEC

2010-12-15 Thread BMF
rue. All we will ever be able to say is "We haven't found it yet." BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] OpenBSD Paradox

2010-12-15 Thread BMF
2010/12/15 musnt live : > What is this time to stop the press! This fake broken English schtick is really stupid and annoying. Knock it off. In the meantime you are kill filed. I suggest everyone else do the same as nothing useful has ever come of this person.

Re: [Full-disclosure] wikileaks still under attack, pressure revved up

2010-10-21 Thread BMF
top dude at the Pentagon is playing it down. Who ya gonna believe? Unless someone can point to a verified leaked document online which says "Mohammed Jihad Dirka Dirka who lives at told us Osama is in that house over there" or some such I can't believe such information

Re: [Full-disclosure] Gödel and kernel backdoors

2010-09-18 Thread BMF
es and even that is hit and miss. Antivirus as a protection method is dead. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] [GOATSE SECURITY] Clench: Goatse's way to say "screw you" to certificate authorities

2010-09-08 Thread BMF
On Wed, Sep 8, 2010 at 12:12 PM, Christian Sciberras wrote: > Call me paranoid, but I stick to the #1 rule of never ever trusting the > public. That is what is good about WoT. You can set the policy on who to trust. You can trust only yourself, certain people, or $BIGCORP if that is what you wan

Re: [Full-disclosure] [GOATSE SECURITY] Clench: Goatse's way to say "screw you" to certificate authorities

2010-09-08 Thread BMF
to line the pockets of assholes who want $10-50 for > pushing a button. Amen. This is why we should use and support web of trust style systems. CA Cert for SSL. GPG for most other things. BMF ___ Full-Disclosure - We believe in it

Re: [Full-disclosure] Reliable reports on attacks on medical software and IT-systems available?

2010-08-10 Thread BMF
On Tue, Aug 10, 2010 at 2:03 PM, halfdog wrote: > Possible answers might be (sorted by probability): * There is no money in harming or killing patients. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclos

Re: [Full-disclosure] targetted SSH bruteforce attacks

2010-06-17 Thread BMF
4 --rttl --name SSH -j LOG iptables -A INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 4 --rttl --name SSH -j DROP BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charte

Re: [Full-disclosure] Stealthier Internet access

2010-05-25 Thread BMF
erally > a one-in-a-million shot that anything incriminating is in the sector. If Bipim is storing his nekked self-portraits on the HD it is very possible that something incriminating would be stored entirely within the one bad sector. BMF ___ Full-Disclos

Re: [Full-disclosure] Windows' future (reprise)

2010-05-15 Thread BMF
've been running it on a day to day basis on my desktop since 1994 and have never once gotten a virus. I have been active in the community since then and I have never met anyone who got one. So... BMF ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Windows' future (reprise)

2010-05-15 Thread BMF
e off cost. Been a few years now. Business is looking good. > Obvious "predictions," ignorant assumptions, and a total lack of any true > understanding of business computing. Yep, "troll." Trollish but not entirely wrong. BMF ___ Fu

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-23 Thread BMF
On Fri, Apr 23, 2010 at 3:33 PM, Christian Sciberras wrote: > 4) I've looked into whether it was into our best interest to use PCI. (it > was decided that it wasn't worth the trouble) > At that time, I knew about PCI but not its details, at which point we got > someone to explain in detail for us.

Re: [Full-disclosure] Weev's Mugshot

2010-04-06 Thread BMF
On Mon, Apr 5, 2010 at 8:36 PM, Scarf Pride Worldwide wrote: > Allegedly he "obstructed justice" by giving a false name.. most likely > didn't put money in the parking meter at the synagogue He doesn't look very Jewish to me. ___ Full-Disclosure - We b

Re: [Full-disclosure] Going "underground", living out of backpack, etc?

2010-03-08 Thread BMF
I could use a blow. Simon, you are welcome to use my couch. On second thought, nevermind. The sort of douche who would ask for lifestyle advice on an alleged "security" mailing list which consists almost entirely of trolls and computer illiterates probably couldn't use my couch without hurting him

Re: [Full-disclosure] How I become Vice President of Security at Yahoo! 1999-2005.

2010-02-19 Thread BMF
hough. I > just had to get it off my chest. > > Thank you so much, if you read this list. You've touched my life. Your mom. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Why

2010-02-19 Thread BMF
Or Vogon poetry? On Fri, Feb 19, 2010 at 2:09 PM, Christian Sciberras wrote: > @Jonny - Hmm, talented. Ever thought about writing books? > > On Fri, Feb 19, 2010 at 10:57 PM, Thor (Hammer of God) > wrote: >> Vivisected like string cheese? >> >>> -Original Message- >>> From: full-disclosu

Re: [Full-disclosure] FREE STEPHEN WATT !!!

2010-01-21 Thread BMF
FREE THE HYDROXYL RADICALS BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] The cyber security intelligence community will never be the same

2009-11-17 Thread BMF
On Tue, Nov 17, 2009 at 11:48 AM, Sam Haldorf wrote: > my name is andrew wallace > "You're a loony." - King Arthur ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

Re: [Full-disclosure] Microsoft confirms first Windows 7 zero-day bug

2009-11-16 Thread BMF
On Mon, Nov 16, 2009 at 10:00 PM, Ivan . wrote: > http://computerworld.co.nz/news.nsf/scrt/E9592E1A9719742ACC25766F0066B38D It reminds me of a newborn baby's first poop: You knew it would happen sooner or later. BMF ___ Full-Disclosure - We

Re: [Full-disclosure] So weev...

2009-10-02 Thread BMF
On Fri, Oct 2, 2009 at 5:14 PM, GOBBLES wrote: > Not about putting your stuff into the alleged suspect's mother. Also: Isn't it way late to start using words like "alleged"? You have already definitively stated that he has done the deeds. What's the point? ___

Re: [Full-disclosure] So weev...

2009-10-02 Thread BMF
On Fri, Oct 2, 2009 at 5:14 PM, GOBBLES wrote: > This is about fighting crime. Not about putting your stuff into the alleged > suspect's mother. > > Please have some sense of courtesy and professionalism. Bwahahahha...someone who posts other peoples dirty laundry and pics of his family and goes b

Re: [Full-disclosure] So weev...

2009-10-02 Thread BMF
On Fri, Oct 2, 2009 at 4:57 PM, GOBBLES wrote: > There is a strong likelihood chance we can get Andrew into prison for his > criminal activity. > Sweet! I love to send people to Federal "Pound me in the ass" Prison! While Bubba is fudgin' this "weev" character I can be fudgin' his momma! ___

Re: [Full-disclosure] Chargebacks and credit card frauds

2009-09-21 Thread BMF
e we don't have > any more fraudulent order, and would appreciate any pointer or insights into > this matter. Any theories, insights, or information would be very useful. > You are fucked. Thank Microsoft. BMF ___ Full-Disclosure - We believe

Re: [Full-disclosure] Andrew Auerenheimer aka weev gets tree'd

2009-09-16 Thread BMF
" of security exploits or at least good security discussion. Instead what I got was full disclosure of how idiotic skr1p7 k1dd13z can be. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html H

Re: [Full-disclosure] Nipper licensing

2009-09-02 Thread BMF
xing it > up > to do everything that Nipper does - and a little more. > Was Nipper not available as source and licensed so it could be forked in an event such as this? If not, consider it an object lesson in free as in beer vs free as in speech. BMF ___

Re: [Full-disclosure] Think Drupal was FLOSS and non-profit? Think again.

2009-09-01 Thread BMF
nough to keep people away from it, much less any trademark issues. BMF ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/