Re: [Full-disclosure] [framework] Looking for a method to get a PDF version of Metasploit Unleashed

2011-05-20 Thread Giles Coochey
On Thu, May 19, 2011 22:42, Jérémie Vincke wrote: > > > Hi all, > > I'm new and very interested in the Metasploit project. > > I'd like to get a PDF version of the Metasploit Unleashed ressource. I've > been spending hours on their site and on Hackers for Charity, but I can't > help to find out how

Re: [Full-disclosure] find11.html

2011-05-31 Thread Giles Coochey
On Tue, May 31, 2011 05:16, Daniel Hood wrote: > Anyone else seen this going around? > > I've got a couple of links coming through for this via hacked email > accounts. Looks like its installing FakeAV. > > Links include: > www [dot] epo4 [dot] com [slash] find11.html > Redirects to safetylife2011.

[Full-disclosure] LulzSec

2011-06-21 Thread Giles Coochey
http://www.guardian.co.uk/uk/2011/jun/21/hackers-lulzsec-arrest-essex-census ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] 0day Full disclosure: American Express

2011-10-11 Thread Giles Coochey
On Mon, October 10, 2011 19:58, Rack911 Security Lists wrote: > American express also utilizing case-insensitive password storing. > We have been informed by American Express that they will be carrying out maintenance to their authorisation system on Sunday 16 October 2011, between 02:00 and 03:00

Re: [Full-disclosure] Fwd: Rate Stratfor's Incident Response

2012-01-12 Thread Giles Coochey
On Thu, January 12, 2012 10:47, doc mombasa wrote: > ok obviously you never worked for a big corporate entity :) > sure standing up to them is fine > after shouting about the bug for 4 months i thought bah why bother its > their asses not mine > just going in and fixing a bug without the mandate is

Re: [Full-disclosure] Rate Stratfor's Incident Response

2012-01-12 Thread Giles Coochey
On 12/01/2012 18:12, Laurelai wrote: *Laurelai* I know its a strange spelling but it is spelled correctly in my email address, and its than not that. Committing arson is not comparable to a digital intrusion, no lives are lost and any enterprise system worth speaking of has backup systems so ve

Re: [Full-disclosure] Rate Stratfor's Incident Response

2012-01-12 Thread Giles Coochey
On 12/01/2012 23:30, Byron Sonne wrote: Hello, Bad analogy. Closer would be if you have a house that's got a driveway on a public street, and you claim it's not breaking and entering if you walk up the driveway, try the doorknob, find it unlocked, and let yourself in without the permission of

Re: [Full-disclosure] Rate Stratfor's Incident Response

2012-01-13 Thread Giles Coochey
+1 to the below. The days where you could hood-wink a judge and say you were just playing on the computer are over. Get with it. On Fri, January 13, 2012 11:57, Ferenc Kovacs wrote: > On Thu, Jan 12, 2012 at 10:46 PM, Benjamin Kreuter > wrote: > >> On Thu, 12 Jan 2012 16:06:53 -0500 >> valdis.kle

Re: [Full-disclosure] VNC viewers: Clipboard of host automatically sent to remote machine

2012-01-24 Thread Giles Coochey
On 2012-01-24 13:34, Ben Bucksch wrote: > Affected Products: GNOME Vinagre and many other VNC viewers > > Reproduction: > 1. On your trusted desktop (e.g. Linux), open a text editor > 2. Type "My password", select the text, and hit Ctrl-C > 3. Open a Vinagre VNC connection to a remote host, e.g. ru

Re: [Full-disclosure] VNC viewers: Clipboard of host automatically sent to remote machine

2012-01-24 Thread Giles Coochey
On 24/01/2012 16:06, Ben Bucksch wrote: On 24.01.2012 16:32, Giles Coochey wrote: Many viewers, including RealVNC have the option to disable the shared clipboard. Check your preferences. Indeed. But Vinagre doesn't. Even then, that is not sufficient, as explained in length. I'm

Re: [Full-disclosure] VNC viewers: Clipboard of host automatically sent to remote machine

2012-01-24 Thread Giles Coochey
On 24/01/2012 19:20, Ben Bucksch wrote: On 24.01.2012 20:08, Giles Coochey wrote: I have seen this is an often requested feature Yes, I understand. It can be highly useful. That's why I proposed to make a "Paste" button in the main toolbar (probably with a keyboard shortcut, too

Re: [Full-disclosure] is my ISP lying or stupid?

2012-03-21 Thread Giles Coochey
On 2012-03-18 16:09, James Condron wrote: > > The routers of an ISP are sorta DHCP in the sense that the IPs are > dynamic- DHCP really works as one network whereas an ISP switch will > have a series of /30 vlans for obvious reasons. Getting an IP and > connection is more complex than that but alre

Re: [Full-disclosure] Certificacion - Profesional Pentester

2012-05-24 Thread Giles Coochey
On 23/05/2012 20:26, Thor (Hammer of God) wrote: Hell Juan. As per the conditions of the contract I forwarded, I am pleased to see that you have given me full permission to assess any systems of yours I feel are within scope. I'm copying in FD again so they can all be witness to the fact yo

Re: [Full-disclosure] NSA Cyber security program [ maybe off-topic ]

2012-06-06 Thread Giles Coochey
On 02/06/2012 12:54, Jack Slade wrote: http://www.opm.gov/oca/12tables/indexgs.asp This is the site of the Federal pay scale. It generally matches what NSA pays, though NSA uses a little different schedule. If you scroll down to the Washington DC area list you'll see the adjusted scale for wh

Re: [Full-disclosure] Linux - Indicators of compromise

2012-07-17 Thread Giles Coochey
on channels, as has IP protocol 41 (IPv6 encapsulation over IPv4) and IP protocol 47 (GRE). -- Regards, Giles Coochey, CCNA, CCNAS NetSecSpec Ltd +44 (0) 7983 877438 http://www.coochey.net http://www.netsecspec.co.uk gi...@coochey.net smime.p7s Description: S/MIME Cry

Re: [Full-disclosure] Linux - Indicators of compromise

2012-07-19 Thread Giles Coochey
On 17/07/2012 18:58, Григорий Братислава wrote: On Mon, Jul 16, 2012 at 10:35 AM, Giles Coochey wrote: On 16/07/2012 14:48, Gary Baribault wrote: I suggest one of the first answers was the good one, intercept the traffic routed to the internet with TCPDump. Filter out the normal traffic and

Re: [Full-disclosure] Linux - Indicators of compromise

2012-07-25 Thread Giles Coochey
On 18/07/2012 13:10, Григорий Братислава wrote: On Wed, Jul 18, 2012 at 3:18 AM, Giles Coochey wrote: Is you have much more to worry than is ICMP/GRE tunnels. Is I send to Broadcast and I am is on your network, how do you is plan to pinpoint who I am when is everyone see broadcast By your

Re: [Full-disclosure] AxMan ActiveX fuzzing <== Memory Corruption PoC

2012-08-01 Thread Giles Coochey
g.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/ -- Regards, Giles Coochey, CCNA, CCNAS NetSecSpec Ltd +44 (0) 7983 877438 http://www.coochey.net http://www.netsecspec.co.uk gi...@coochey.net smime.p7s Description: S/MIME Cryptographic Signature ___

Re: [Full-disclosure] GIMP Scriptfu Python Remote Command Execution

2012-08-19 Thread Giles Coochey
ens a TCP port, un-authenticated and un-encrypted and allows execution to run in the context of the server. As mentioned, the GIMP Dev team say it is a feature that wasn't designed with security in mind, so if you were to use it, you would be advised to wrap it. -- Regards, Giles Coo

Re: [Full-disclosure] DakaRand

2012-08-20 Thread Giles Coochey
On 20/08/2012 16:32, Dan Kaminsky wrote: On Mon, Aug 20, 2012 at 8:29 AM, Paul Schmehl mailto:pschmehl_li...@tx.rr.com>> wrote: --On August 20, 2012 2:22:28 AM -0700 Dan Kaminsky mailto:d...@doxpara.com>> wrote: May I ask what FreeBSD's entropy sources are? I'm surpri