[Full-disclosure] How a teenager helpfully reported a government security flaw – and could be charged in return

2014-01-23 Thread Ivan .Heca
In Australia, individuals who report critical security flaws face potential legal action, while corporations who fail to report data breaches to paying customers go unpunished

Re: [Full-disclosure] WordPress User Account Information Leak / Secunia Advisory SA23621

2013-07-04 Thread Ivan Carlos
Can't you open a new bt about this issue? Regards, Em 04/07/2013 10:16, Sven Kieske svenkie...@gmail.com escreveu: Hi, the mentioned User account Enumeration Weakness stated in Advisory https://secunia.com/advisories/23621/ still exists in the actual version 3.5.2 . The corresponding trac

Re: [Full-disclosure] Why PRISM kills the cloud | Computerworld Blogs

2013-06-12 Thread Ivan .Heca
Thw commercial espionage angle is another interesting aspect of this http://www.techdirt.com/articles/20130611/10014923405/is-us-using-prism-to-engage-commercial-espionage-against-germany-others.shtml On 13/06/2013 3:08 AM, Michael Hallgren m.hallg...@free.fr wrote:

Re: [Full-disclosure] Why PRISM kills the cloud | Computerworld Blogs

2013-06-11 Thread Ivan .Heca
Maybe all is forgiven if they discount enough http://www.networkworld.com/news/2013/061113-google-amazon-cloud-270730.html?hpg1=bn A Canadian and what appears to be a British subject discussing the not so finer points of American legislation. I'm sure at some point the irony will become apparent.

[Full-disclosure] Why PRISM kills the cloud | Computerworld Blogs

2013-06-10 Thread Ivan .Heca
http://m.blogs.computerworld.com/cloud-storage/22305/why-prism-kills-cloud ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Why PRISM kills the cloud | Computerworld Blogs

2013-06-10 Thread Ivan .Heca
-services/icloud/en/terms.html Le 2013-06-10 19:46, Ivan .Heca ivan...@gmail.com a écrit : http://m.blogs.computerworld.com/cloud-storage/22305/why-prism-kills-cloud ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk

Re: [Full-disclosure] cloudsafe365 for wordpress: file disclosure

2012-08-28 Thread Ivan Carlos
I suppose that's fixed, or they just disabled the plugin itselfon his wp Ivan Carlos CISO, Consultant +55 (11) 98112-0666 www.icarlos.net -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of Henri Salo Sent

[Full-disclosure] Tech journalists: Stop hyping unproven security tools

2012-08-12 Thread Ivan .Heca
*Cui bono * http://paranoia.dubfire.net/2012/07/tech-journalists-stop-hyping-unproven.html?utm_source=Contextlyutm_medium=RelatedLinksutm_campaign=AroundWeb ouch http://blog.alexanderhiggins.com/2012/08/10/experts-idiots-war-security-165251/ ___

[Full-disclosure] hacking FB Ads

2012-08-01 Thread Ivan .Heca
interesting bit of research “A couple months ago, when we were preparing to launch the new Limited Run, we started to experiment with Facebook ads. Unfortunately, while testing their ad system, we noticed some very strange things. Facebook was charging us for clicks, yet we could only verify

[Full-disclosure] Congress Capitulates To TSA; Refuses To Let Bruce Schneier Testify

2012-03-26 Thread Ivan .Heca
http://yro.slashdot.org/story/12/03/26/2221246/congress-capitulates-to-tsa-refuses-to-let-bruce-schneier-testify ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

[Full-disclosure] Stakeout: how the FBI tracked and busted a Chicago Anon

2012-03-07 Thread Ivan .Heca
*Yesterday, we learned that one of the top members of LulzSec (Sabu) had been an FBI informant for almost 6 monthshttp://tech.slashdot.org/story/12/03/06/1437241/lulzsec-leader-sabu-unmasked-arrested-and-caught-collaborating, and that this confidant of the LulzSec leader 'anarchaos' had given the

Re: [Full-disclosure] Full disclosure is arrest of Sabu

2012-03-06 Thread Ivan .Heca
http://gizmodo.com/5890825/lulzsec-leader-betrays-all-of-anonymous On Wed, Mar 7, 2012 at 10:43 AM, Sanguinarious Rose sanguiner...@occultusterra.com wrote: lol, as far as I know she didn't accuse nenolod of a botnet, you did and said he built the botnet for her from what it looks like to me.

Re: [Full-disclosure] Carrier IQ for your phone

2011-12-13 Thread Ivan .Heca
http://www.gizmodo.com.au/2011/12/carrier-iq-explains-what-it-does-with-your-data/ On Wed, Dec 14, 2011 at 9:06 AM, coderman coder...@gmail.com wrote: On Sat, Dec 3, 2011 at 4:14 AM, Alan J. Wylie shyyqvfpybf...@wylie.me.uk wrote: ... Interesting response from Carrier IQ in a long article

Re: [Full-disclosure] Carrier IQ for your phone

2011-12-13 Thread Ivan .Heca
another nice one http://www.techdirt.com/blog/wireless/articles/20111213/00271717060/fbi-admits-that-it-uses-carrier-iq-law-enforcement-purposes-wont-say-how.shtml On Wed, Dec 14, 2011 at 10:19 AM, coderman coder...@gmail.com wrote: On Tue, Dec 13, 2011 at 2:50 PM, Ivan .Heca ivan...@gmail.com

[Full-disclosure] Researchers Uncover 'Massive Security Flaws' In Amazon Cloud

2011-11-06 Thread Ivan .
http://www.crn.com/news/cloud/231901911/researchers-uncover-massive-security-flaws-in-amazon-cloud.htm;jsessionid=kT0u8aBKblF5Y14-kIidtA**.ecappj03 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-16 Thread Ivan .
15 Mind-Blowing Facts About Wealth And Inequality In America http://www.businessinsider.com/facts-about-inequality-in-america-2011-11?op=1 On Sat, Oct 15, 2011 at 12:58 PM, Laurelai laure...@oneechan.org wrote: On 10/14/2011 8:21 PM, Christian Sciberras wrote: You think I'm biting that?

[Full-disclosure] Meet the Guy Who Snitched on Occupy Wall Street to the FBI and NYPD

2011-10-16 Thread Ivan .
http://gawker.com/5850054/meet-the-guy-who-snitched-on-occupy-wall-street-to-the-fbi-and-nypd ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Two Remote Code Execution Vulnerabilities in Internet Explorer

2011-10-13 Thread Ivan Fratric
### Vulnerability 1: Internet Explorer Select Element Remote Code Execution ### Original advisory:

Re: [Full-disclosure] Possible German Governmental Backdoor found (R2D2)

2011-10-13 Thread Ivan .
interesting *DigiTask Remote Forensic Spyware * http://cryptome.org/0005/michaelthomas.pdf On Fri, Oct 14, 2011 at 11:38 AM, valdis.kletni...@vt.edu wrote: On Thu, 13 Oct 2011 14:44:32 PDT, Andrew Wallace said: No, they started moderating the list January 2009. --- Andrew Wallace

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-13 Thread Ivan .
don't feed the trolls http://whatreallyhappened.com/ On Fri, Oct 14, 2011 at 2:53 PM, Laurelai laure...@oneechan.org wrote: On 10/13/2011 7:11 PM, Christian Sciberras wrote: So if they cause damage for profit that makes it ok? No. But it's certainly better than doing damage without

Re: [Full-disclosure] [OT] the nigger said: American people understand that not everybody's been following the rules

2011-10-12 Thread Ivan .
fast and furious http://www.youtube.com/watch?v=IC2C2lIwNSA On Wed, Oct 12, 2011 at 5:51 PM, Christian Sciberras uuf6...@gmail.comwrote: Darren's and indeed many other people's lame excuse is that they're too humble to be greedy. As if! If anything, most people are greedier than that 1%. The

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-12 Thread Ivan .
http://endoftheamericandream.com/archives/fast-and-furious-22-shocking-facts-about-the-scandal-that-could-bring-down-the-obama-administration On Thu, Oct 13, 2011 at 10:33 AM, David Alanis can...@dalan.us wrote: Quoting Paul Schmehl pschmehl_li...@tx.rr.com: The thing these stupid people

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-12 Thread Ivan .
http://www.businessinsider.com/what-wall-street-protesters-are-so-angry-about-2011-10?op=1 On Thu, Oct 13, 2011 at 10:29 AM, Ivan . ivan...@gmail.com wrote: http://endoftheamericandream.com/archives/fast-and-furious-22-shocking-facts-about-the-scandal-that-could-bring-down-the-obama

Re: [Full-disclosure] [OT] the nigger said: American people understand that not everybody's been following the rules

2011-10-12 Thread Ivan .
://www.telegraph.co.uk/news/worldnews/northamerica/usa/8816656/Colorado-empties-popular-lake-to-pay-its-water-bill.html and so on. Your tax $$$ go to bailouts On Thu, Oct 13, 2011 at 10:20 AM, Ivan . ivan...@gmail.com wrote: fast and furious http://www.youtube.com/watch?v=IC2C2lIwNSA On Wed

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-12 Thread Ivan .
do your own research, read your own shit, make your own decisions 2011/10/13 夜神 岩男 supergiantpot...@yahoo.co.jp On 10/13/2011 08:53 AM, Jeffrey Walton wrote: On Wed, Oct 12, 2011 at 7:47 PM, Ivan .ivan...@gmail.com wrote: http://www.businessinsider.com/what-wall-street-protesters-are-so

Re: [Full-disclosure] [OT] the nigger said: American people understand that not everybody's been following the rules

2011-10-06 Thread Ivan .
MSNBC labels AP ‘inherently racist’ for accurate translation of Obama speech http://investmentwatchblog.com/msnbc-labels-ap-inherently-racist-for-accurate-translation-of-obama-speech/ some 1% on the list *Chicago Traders Respond To Protesters With Signs Reading ‘We Are The

[Full-disclosure] VPN provider helped track down alleged LulzSec member

2011-09-26 Thread Ivan .
http://www.h-online.com/security/news/item/VPN-provider-helped-track-down-alleged-LulzSec-member-1349666.html ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

Re: [Full-disclosure] Vulnerabilities in GlobalWoW

2011-09-01 Thread Ivan Carlos
C'mon... isn't that (gaming non-licensed server over a patented application) illegal? Reporting vulns on counterfeit applications is useless. Ivan Carlos CISO, Consultant +55 (11) 8112-0666 www.icarlos.net -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full

Re: [Full-disclosure] DEF CON 19 - hackers get hacked!

2011-08-11 Thread Ivan .
*A German technology researcher on Wednesday showed global mobile makers and technology firms how General Packet Radio Servicehttp://en.wikipedia.org/wiki/General_Packet_Radio_Servicecan easily be tapped, intercepted, and decrypted with an average mobile phone and a few applications. According to

[Full-disclosure] Samsung Galaxy Tab 10.1 blocked from sale in Australia

2011-08-02 Thread Ivan c
An Apple spokesperson told iTnews that it would continue to protect its design patents. This kind of blatant copying is wrong, and we need to protect Apple's intellectual property when companies steal our ideas.

[Full-disclosure] A pound of flesh: how Cisco's unmitigated gall derailed one man's life

2011-07-21 Thread Ivan .
Buy Juniper! http://arstechnica.com/tech-policy/news/2011/07/a-pound-of-flesh-how-ciscos-unmitigated-gall-derailed-one-mans-life.ars ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

Re: [Full-disclosure] Sony: No firewall and no patches

2011-05-10 Thread Ivan .
doesn't it also mandate the encryption of CC info? requirement 4 Encrypting and Storing Credit Card Data plenty of reports that the data was not encrypted, and also plenty that say it was. On Tue, May 10, 2011 at 4:40 PM, Tracy Reed tr...@ultraviolet.org wrote: On Tue, May 10, 2011 at

Re: [Full-disclosure] Sony: No firewall and no patches

2011-05-10 Thread Ivan .
Ill throw this into the mixer while on topic of FWs The TCP Split Handshake: Practical Effects on Modern Network Equipment http://nmap.org/misc/split-handshake.pdf On Wed, May 11, 2011 at 10:18 AM, Thor (Hammer of God) t...@hammerofgod.com wrote: I would be extremely interested to learn

Re: [Full-disclosure] Facebook

2011-05-03 Thread Ivan .
it's the law, specifically CALEA http://en.wikipedia.org/wiki/Communications_Assistance_for_Law_Enforcement_Act On Wed, May 4, 2011 at 9:19 AM, Javier Bassi javierba...@gmail.com wrote: On Tue, May 3, 2011 at 7:51 PM, Daniel Clemens daniel.clem...@packetninjas.net wrote: Prove it! You clearly

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-28 Thread Ivan .
and now tom tom as well http://crave.cnet.co.uk/cartech/tomtom-admits-to-sending-your-routes-and-speed-information-to-the-police-50003618/ On Thu, Apr 28, 2011 at 9:35 AM, Ivan . ivan...@gmail.com wrote: stevie says it just a bug, a patented bug http://gawker.com/?_escaped_fragment_=5795442

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-27 Thread Ivan .
://news.cnet.com/8301-31921_3-20057329-281.html On Tue, Apr 26, 2011 at 8:12 PM, Ivan . ivan...@gmail.com wrote: Interesting write up, and apparently old news If you have jailbroken your phone, just use cydia and search for tool 'Untrackerd' to fix this issue. This background process reset the file

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-26 Thread Ivan .
Interesting write up, and apparently old news https://alexlevinson.wordpress.com/2011/04/21/3-major-issues-with-the-latest-iphone-tracking-discovery/ On Fri, Apr 22, 2011 at 1:59 PM, mark seiden m...@seiden.com wrote: yes, that's right. on one of the forensics lists someone pointed out

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-26 Thread Ivan .
M$ are in the love in http://news.cnet.com/8301-31921_3-20057329-281.html On Tue, Apr 26, 2011 at 8:12 PM, Ivan . ivan...@gmail.com wrote: Interesting write up, and apparently old news https://alexlevinson.wordpress.com/2011/04/21/3-major-issues-with-the-latest-iphone-tracking-discovery

Re: [Full-disclosure] Got an iPhone or 3G iPad? Apple is recording your moves

2011-04-25 Thread Ivan .
. *A*: Oh yes they do. We don't track anyone. The info circulating around is false. Sent from my iPhone http://www.macrumors.com/2011/04/25/steve-jobs-on-ios-location-issue-we-dont-track-anyone/ On Sun, Apr 24, 2011 at 9:16 AM, Ivan . ivan...@gmail.com wrote: http://www.guardian.co.uk/technology

Re: [Full-disclosure] Got an iPhone or 3G iPad? Apple is recording your moves

2011-04-23 Thread Ivan .
http://www.guardian.co.uk/technology/2011/apr/22/iphone-android-location-based-services On Sat, Apr 23, 2011 at 1:51 AM, andrew.wallace andrew.wall...@rocketmail.com wrote: On Fri, Apr 22, 2011 at 3:29 PM, mark seiden m...@seiden.com wrote: i'm more worried about private parties tracking

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-21 Thread Ivan .
Its maker, Israel-based Cellbrite, says it can copy all the content in a cell phone -- including contacts, text messages, call history, and pictures -- within a few minutes. Even deleted texts and other data can be restored by UFED 2.0, the latest version of the product, it says.

[Full-disclosure] Got an iPhone or 3G iPad? Apple is recording your moves

2011-04-20 Thread Ivan .
All iPhones appear to log your location to a file called consolidated.db. This contains latitude-longitude coordinates along with a timestamp. The coordinates aren't always exact, but they are pretty detailed. There can be tens of thousands of data points in this file, and it appears the

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-20 Thread Ivan .
the Police can slurp it up with there new toy http://www.thenewspaper.com/news/34/3458.asp On Thu, Apr 21, 2011 at 10:34 AM, Marcio B. Jr. marcio.barb...@gmail.com wrote: On Wed, Apr 20, 2011 at 4:41 PM, Michael Holstein michael.holst...@csuohio.edu wrote: Pretty scary btw. I hope

Re: [Full-disclosure] iPhone Geolocation storage

2011-04-20 Thread Ivan .
welcome to Ameristan I guess On Thu, Apr 21, 2011 at 10:45 AM, Zach C. fxc...@gmail.com wrote: That only seems to apply to Android 3.x, which is not even the most prevalent Android version in the wild. In fact, I think it can only be found on tablets at present, and presumably Google will

Re: [Full-disclosure] Best Buy and Privacy?

2011-02-04 Thread [lesh] Ivan Nikolic
Hey, don't you people have private information laws that deal with this sort of stuff? In europe, someone can't store your private information if you haven't explicitly allowed its storage and usage scenarios, let alone send it to third party. Also, they have responsibility to keep your data

Re: [Full-disclosure] Evilgrade 2.0 - the update explotation framework is back

2010-10-31 Thread [lesh] Ivan Nikolic
Hm, I'm new to this list. so I find this a bit strange. Christian, Vladis, are you the same person? what are your motives? do you really believe the things you are saying? you seem to be just generally negative, jumping from point to point and being very silly. Just signing the update packages

Re: [Full-disclosure] African ISP SekuritY

2010-10-27 Thread [lesh] Ivan Nikolic
difference between breach and hack is that you say breach when you'd like to sound cool and james-bondy. a person that breaches has one of those tight microphone-headphone things and is handsome. while a person that hacks just has a greasy hair. can you please explain me the definition based

Re: [Full-disclosure] CYBSEC Advisory#2010-0605 InterScan Web Security 5.0 Arbitrary File Upload

2010-06-25 Thread Ivan
Hi Moritz, it's just a typing mistake. Thanks for the advice Kind regards, Ivan On Thu, Jun 24, 2010 at 4:53 PM, Moritz Hoffmann mor...@antiguru.de wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 06/23/2010 04:40 PM, Cybsec - Security Systems wrote: Direct execution of arbitrary

[Full-disclosure] No anti-virus software? No internet connection

2010-06-21 Thread Ivan .
Security is as easy as that.. http://www.news.com.au/technology/no-anti-virus-software-no-internet-connection/story-e6frfro0-1225882656490 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted

Re: [Full-disclosure] No anti-virus software? No internet connection

2010-06-21 Thread Ivan .
yep, your tax $$$ at work Don't forget there Internet filter as well.. With these rocket scientist running the show, what's there to worry about http://blogs.news.com.au/techblog/index.php/news/comments/finally_theres_protection_against_spams_and_scams On Tue, Jun 22, 2010 at 2:32 PM, Jubei

[Full-disclosure] The Strange and Consequential Case of Bradley Manning, Adrian Lamo and WikiLeaks

2010-06-20 Thread Ivan .
http://www.informationclearinghouse.info/article25767.htm ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Apple's Worst Security Breach: 114, 000 iPad Owners Exposed,

2010-06-09 Thread Ivan .
http://gawker.com/5559346/apples-worst-security-breach-114000-ipad-owners-exposed ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Web Browsers Leave 'Fingerprints' Behind as You Surf the Net

2010-05-19 Thread Ivan .
Interesting research http://www.eff.org/press/archives/2010/05/13 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] We must work harder on cloud, says Microsoft

2010-04-21 Thread Ivan .
Funny stuff... Nirvana in a cloud context would be for customers to trust Microsoft just as they trust their bank or utility company. Building that mentality will take time. It's going to be incumbent upon us to establish that confidence with our customers,” he said during a visit to Sydney.

Re: [Full-disclosure] We must work harder on cloud, says Microsoft

2010-04-21 Thread Ivan .
as Microsoft has done with software, I can see Microsoft CloudSoft coming soon. Date: Thu, 22 Apr 2010 09:03:26 +1000 From: ivan...@gmail.com To: full-disclosure@lists.grok.org.uk; security-bas...@securityfocus.com Subject: [Full-disclosure] We must work harder on cloud, says Microsoft Funny stuff

[Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-06 Thread Ivan .
For those who don't frequent slashdot... Enterprises are spending huge amounts of money on compliance programs related to PCI-DSS, HIPAA and other regulations, but those funds may be misdirected in light of the priorities of most information security programs, a new study has found. A paper

[Full-disclosure] Cryptome Spying guides as a Digital Forensic Resource

2010-03-02 Thread Ivan .
For those who missed all the action http://blogs.sans.org/computer-forensics/2010/03/02/cryptome-spying-guides-as-a-digital-forensic-resource/ *Microsoft* – http://cryptome.org//isp-spy/microsoft-spy.zip *Paypal* – http://cryptome.org/isp-spy/paypal-spy.zip *MySpace* –

[Full-disclosure] ACTA internet enforcement chapter leaks

2010-02-23 Thread Ivan .
http://www.boingboing.net/2010/02/21/acta-internet-enforc.html http://craphound.com/acta_digital_chapter-1.pdf ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

Re: [Full-disclosure] [WEB SECURITY] Trustwave's SpiderLabs Security Advisory TWSL2010-001

2010-02-19 Thread Ivan Buetler
Hi all, There is an ongoing conversation about a potential XSS with ViewState of the .NET framework. However, some were not able to reproduce the issue and therefore we decided to prepare a short and high resolution movie. http://www.hacking-lab.com/download/ Regards Ivan -Original

[Full-disclosure] Google baulks at Conroy's call to censor YouTube

2010-02-10 Thread Ivan .
Conroy said applying ISP filters to high-traffic sites such as YouTube would slow down the internet, so we're currently in discussions with Google about ... how we can work this through. What we're saying is, well in Australia, these are our laws and we'd like you to apply our laws, Conroy said.

[Full-disclosure] Internet attack defense: License and registration please...

2010-02-01 Thread Ivan .
Your documents please? http://government.zdnet.com/?p=6934 ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] U.S. enables Chinese hacking of Google

2010-01-26 Thread Ivan .
http://edition.cnn.com/2010/OPINION/01/23/schneier.google.hacking/index.html ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] All China, All The Time

2010-01-19 Thread Ivan .
Now, by analyzing the software used in the break-ins against Google and dozens of other companies, Joe Stewart, a malware specialist with SecureWorks, a computer security company based in Atlanta, said he determined the main program used in the attack contained a module based on an unusual

[Full-disclosure] Network flaw causes scary Web error

2010-01-17 Thread Ivan .
Would be fun to try and replicate this A Georgia mother and her two daughters logged onto Facebook from mobile phones last weekend and wound up in a startling place: strangers' accounts with full access to troves of private information. The glitch -- the result of a routing problem at the

Re: [Full-disclosure] All China, All The Time

2010-01-14 Thread Ivan .
Interesting article on zdnet, talking about the targeting of the lawful intercept system at Google …they [hackers] apparently were able to access a system used to help Google comply with search warrants by providing data on Google users, said a source familiar with the situation, who spoke on

[Full-disclosure] TSA Logo Contest - Schneier

2010-01-11 Thread Ivan .
http://www.schneier.com/blog/archives/2010/01/tsa_logo_contes.html ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] The Great Aussie Firewall is dead: Long live the firewall

2009-12-16 Thread Ivan .
http://www.theregister.co.uk/2009/12/15/australian_censorship_measures/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Decaf anyone?

2009-12-14 Thread Ivan .
http://www.wired.com/threatlevel/2009/12/decaf-cofee/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Revenge of the Computer Nerds

2009-12-09 Thread Ivan .
But the real action (and the evidence for chicanery) is in the computer code obtained from the CRU. Our own computer guru Marc Sheppard, writing for American Thinker here and here, was one of the first to offer an accurate diagnosis of this fraudulent method of computer programming. Analyzing the

Re: [Full-disclosure] Revenge of the Computer Nerds

2009-12-09 Thread Ivan .
-artificial-correction-flap-looks.html (Bonus points:  Check the dates) On Wed, Dec 9, 2009 at 4:25 PM, Ivan . ivan...@gmail.com wrote: But the real action (and the evidence for chicanery) is in the computer code obtained from the CRU. Our own computer guru Marc Sheppard, writing

[Full-disclosure] Climate-Gate:A SysAdmin’s Perspective

2009-12-07 Thread Ivan .
http://www.smalldeadanimals.com/FOIA_Leaked/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Software developer looks at CRU code

2009-12-06 Thread Ivan .
CRU's programming 'below commercial standards' http://news.bbc.co.uk/2/hi/programmes/newsnight/8395514.stm On Mon, Dec 7, 2009 at 11:21 AM, Paul Schmehl pschmehl_li...@tx.rr.com wrote: --On December 6, 2009 3:46:49 PM -0800 Thor (Hammer of God) t...@hammerofgod.com wrote: No provision for

[Full-disclosure] In the thick of it: how the Digital Economy bill is trying to kill open Wi-Fi networks

2009-12-02 Thread Ivan .
http://www.guardian.co.uk/technology/2009/nov/30/open-wi-fi-digital-economy-bill-government ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Microsoft: ‘Piracy no long er poses a threat to us’

2009-12-02 Thread Ivan .
In a recent interview, managing director of Microsoft Philippines Inc., John Bessey, has claimed that piracy no longer poses a threat to the software giant. http://freakbits.com/microsoft-piracy-no-longer-poses-a-threat-to-us-1202 ___ Full-Disclosure -

[Full-disclosure] Feds ‘Pinged’ Sprint GPS D ata 8 Million Times Over a Year

2009-12-01 Thread Ivan .
http://www.wired.com/threatlevel/2009/12/gps-data/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Software developer looks at CRU code

2009-11-30 Thread Ivan .
just ask Al of the Gore about his carbon trading exchange he setup with Ken Lay of Enron fame as advisor... http://www.youtube.com/watch?v=UjHAB62xKXI On Tue, Dec 1, 2009 at 11:13 AM, Rohit Patnaik quanti...@gmail.com wrote: Right, but you said that the global warming folks are asking for

Re: [Full-disclosure] Software developer looks at CRU code

2009-11-30 Thread Ivan .
watch the video, but the Al of the Gore bit is at 1.40 in http://www.youtube.com/watch?v=VebOTc-7shU On Tue, Dec 1, 2009 at 3:40 PM, Paul Schmehl pschmehl_li...@tx.rr.comwrote: --On Monday, November 30, 2009 6:13 PM -0600 Rohit Patnaik quanti...@gmail.com wrote: Right, but you said that

[Full-disclosure] Symantec Online Store Hacked

2009-11-29 Thread Ivan .
http://news.softpedia.com/news/Symantec-Online-Store-Hacked-127726.shtml ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Software developer looks at CRU code

2009-11-29 Thread Ivan .
http://www.youtube.com/watch?v=sYxk7pnmMFwfeature=related ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Microsoft Windows TCP/IP Timestamps Code Execution Vulnerability

2009-11-27 Thread Ivan Security
to code execution?. 2009/11/27 webDEViL w3bd3...@gmail.com That's what binary diffing is all about. Sent from my iPhone On Nov 27, 2009, at 7:59 AM, Ivan Security ivanch...@gmail.com wrote: Hi list, Has anyone more details about this vulnerability?. The advisory just say

Re: [Full-disclosure] Microsoft Windows TCP/IP Timestamps Code Execution Vulnerability

2009-11-27 Thread Ivan Security
information. I'm testing this issue against a Windows Vista Ultimate SP1. I could patch it and then compare the corresponding binary files. Following your guesses i can start to try something buggy. Thanks. Regards, Ivan. 2009/11/27 valdis.kletni...@vt.edu On Fri, 27 Nov 2009 12:27:29 -0300, Ivan

[Full-disclosure] Microsoft Windows TCP/IP Timestamps Code Execution Vulnerability

2009-11-26 Thread Ivan Security
like to know a bit more in order to test it and make some research. Regards, Ivan. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] UK jails schizophrenic for refusal to decrypt files

2009-11-24 Thread Ivan .
The first person jailed under draconian UK police powers that Ministers said were vital to battle terrorism and serious crime has been identified by The Register as a schizophrenic science hobbyist with no previous criminal record. His crime was a persistent refusal to give counter-terrorism

[Full-disclosure] Climategate: how the MSM rep orted the greatest scandal in modern science – Telegraph Blogs

2009-11-22 Thread Ivan .
hackers providing a public service.. http://blogs.telegraph.co.uk/news/jamesdelingpole/100017451/climategate-how-the-msm-reported-the-greatest-scandal-in-modern-science/ ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Microsoft confirms first Windows 7 zero-day bug

2009-11-16 Thread Ivan .
http://computerworld.co.nz/news.nsf/scrt/E9592E1A9719742ACC25766F0066B38D ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Spying on Americans: Obama Endorses Bush Era Warrantless Wiretapping

2009-11-10 Thread Ivan .
In a Court filing late Friday night, the Obama Administration attempted to dress up in new clothes its embrace of one of the worst Bush Administration positions--that courts cannot be allowed to review the National Security Agency's massive, well-documented program of warrantless surveillance. In

[Full-disclosure] UK surveillance plan to go ahead

2009-11-10 Thread Ivan .
The Home Office says it will push ahead with plans to ask communications firms to monitor all internet use. http://news.bbc.co.uk/2/hi/uk_news/politics/8350660.stm ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] How Prosecutors Wiretap Wall Street

2009-11-05 Thread Ivan .
some background http://www.wired.com/dangerroom/2009/03/breaking-cyber/ http://news.cnet.com/8301-13578_3-10046097-38.html http://www.wired.com/threatlevel/2008/06/senate-debates/ http://www.lawandsecurity.org/publications/ForTheRecord/NSA_jan_07.pdf and the list goes on ahh the land of the

Re: [Full-disclosure] How Prosecutors Wiretap Wall Street

2009-11-04 Thread Ivan .
http://www.youtube.com/watch?v=WourPs56Shc On Thu, Nov 5, 2009 at 1:48 PM, valdis.kletni...@vt.edu wrote: On Wed, 04 Nov 2009 17:42:37 CST, Paul Schmehl said: You and millions of others love to conflate those issues with warrantless surveillance of US citizens for the purpose of obtaining

[Full-disclosure] How Prosecutors Wiretap Wall Street

2009-11-03 Thread Ivan .
The answer is both more mundane and more alarming. Prosecutors are using the FBI's massive surveillance system, DCSNet, which stands for Digital Collection System Network. According to Wired magazine, this system connects FBI wiretapping rooms to switches controlled by traditional land-line

[Full-disclosure] H D Moore sells Metasploit: Open source project in commercial hands

2009-10-22 Thread Ivan .
http://risky.biz/metasploit_sold ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] H D Moore sells Metasploit: Open source project in commercial hands

2009-10-22 Thread Ivan .
quick, wget the whole site before it all goes commercial ;-p On Fri, Oct 23, 2009 at 11:08 AM, James Lay j...@slave-tothe-box.netwrote: *From: *Rohit Patnaik quanti...@gmail.com *Date: *Thu, 22 Oct 2009 18:52:57 -0500 *To: *Ivan . ivan...@gmail.com *Cc: *Full-disclosure full-disclosure

[Full-disclosure] Yahoo! apologises for lap dance at hack event

2009-10-20 Thread Ivan .
yahoo rocks! http://www.brisbanetimes.com.au/technology/technology-news/yahoo-apologises-for-lap-dance-at-hack-event-20091021-h7sr.html ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

[Full-disclosure] Web-monitoring software gathers data on kid chats

2009-09-08 Thread Ivan .
Parents who install a leading brand of software to monitor their kids' online activities may be unwittingly allowing the company to read their children's chat messages — and sell the marketing data gathered. Software sold under the Sentry and FamilySafe brands can read private chats conducted

Re: [Full-disclosure] Free wlan sniffer for vista

2009-08-22 Thread Ivan .
track down ngsniff, not sure if it works on vista. no packet driver required http://osdir.com/ml/security.penetration/2002-11/msg00028.html On Sat, Aug 22, 2009 at 5:09 PM, Peter van Hooft ho...@natlab.research.philips.com wrote: Hi Tk, I would recommend grabbing WinTcpdum and the WinPcap

[Full-disclosure] Dirtiest Web Sites of Summer 2009

2009-08-19 Thread Ivan .
http://safeweb.norton.com/dirtysites ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Former British cop 'has bank details of 40 million people'

2009-07-24 Thread Ivan .
http://www.news.com.au/technology/story/0,28348,25828444-5014239,00.html ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Sniffing Browser History Without Javascript

2009-06-14 Thread Ivan .
Interesting! http://it.slashdot.org/story/09/06/13/2125211/Sniffing-Browser-History-Without-Javascript http://www.making-the-web.com/misc/sites-you-visit/nojs/ ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Kaminsky: MS security assessment tool is a 'game changer'

2009-03-22 Thread Ivan .
In case anyone missed it http://www.theregister.co.uk/2009/03/20/microsoft_crash_tool/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] The BBC acquired a botnet, but was it legal? - Update

2009-03-15 Thread Ivan .
According to Struan Robertson, a technology lawyer with Pinsent Masons, in a posting on Out-Law.com, the BBC's statement that the activity would only be illegal if those behind it had criminal intent is not true. Robertson said The BBC appears to have broken the Computer Misuse Act by causing

  1   2   >