[Full-disclosure] Russell Harding MacOS X SoftwareUpdate Vulnerability Advisory Missing In Action in Bugtraq Archive

2007-07-21 Thread Jason Coombs
Dear Symantec, As long as we're burning digital books to mitigate our civil liability, perhaps we could do a good job of it next time? Quietly disappearing Russell Harding's advisory from the BugTraq archive didn't resolve your potential liability for distributing links to material that

[Full-disclosure] Fw: [IACIS-L] Statement by Defense Expert

2007-06-06 Thread Jason Coombs
Sent from my Verizon Wireless BlackBerry -Original Message- From: Jason Coombs [EMAIL PROTECTED] Date: Wed, 6 Jun 2007 04:13:33 To:[EMAIL PROTECTED] Cc:[EMAIL PROTECTED],[EMAIL PROTECTED] Subject: RE: [IACIS-L] Statement by Defense Expert Dave_on_the_run [EMAIL PROTECTED] wrote

[Full-disclosure] ZoneEdit.com Forcing Pop-Unders on WebForward-Configured Domains

2006-06-12 Thread Jason Coombs
Problem: DNS service ZoneEdit.com now owned by MyDomains.com has started forcing JavaScript pop-Unders onto users' browsers when the domain owner uses the ZoneEdit WebForward feature. References: www.zoneedit.com www.mydomains.com/support.php www.casalemedia.com/contact.html Details:

[Full-disclosure] Seeking Anyone Harmed by Jason Coombs

2006-04-26 Thread Jason Coombs
AM To: [EMAIL PROTECTED] Subject: Re: [HTCC] Expert Info Sought I am helping the Yuma County Attorney's Office with a case. The other side has noticed an expert named Jason Coombs, who has offices in CA, HI, and New Zealand. He is the director of forensics for PivX. If anyone has had any

[Full-disclosure] Fw: You have been unsubscribed from the Full-Disclosure mailing list

2006-03-17 Thread Jason Coombs
[Full-Disclosure] is dead. Long live full disclosure. -Original Message- From: [EMAIL PROTECTED] Date: Sat, 18 Mar 2006 00:01:39 To:[EMAIL PROTECTED] Subject: You have been unsubscribed from the Full-Disclosure mailing list For quality control purposes please send mail to [EMAIL

Re: [Full-disclosure] Filtering Latest Spam Run (radio.toad.com)

2006-03-16 Thread Jason Coombs
Don Bailey wrote: Stop interrupting the spam, I'm trying to read. The spam attacks would never have gotten through if Len Rose were still in charge of FD. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Filtering Latest Spam Run (radio.toad.com)

2006-03-16 Thread Jason Coombs
[EMAIL PROTECTED] wrote: And I would have never shot hot steamy load of man juice inside you if you were not fucking faggot uh huh, and now we know the spam kiddie responsible. I pay by the KB to receive all your junk, so you can expect a lawsuit in the near future. Send your address for

Re: [Full-disclosure] HTTP AUTH BASIC monowall

2006-03-16 Thread Jason Coombs
key. SSL does not implement any reasonable trust mechanism today because Verisign dumbed it down in order to create a universal mechanism to tax the Internet. Best, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-disclosure] HTTP AUTH BASIC monowall

2006-03-16 Thread Jason Coombs
that are complicated so they can learn secret voodoo business trade secrets and grow new business ventures. People who really want security already have it, so distrust anyone who claims to be able to sell it to you. Regards, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] For Sale: Security Vulnerability DatabaseCompany

2006-03-09 Thread Jason Coombs
a URL would be offensive to me, so it's probably a good thing you weren't the one hired to help the company in question locate a buyer. Best, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

[Full-disclosure] Re: How hackers cause damage... was Vulnerabilites in new laws on computer hacking

2006-02-23 Thread Jason Coombs
generating machine would kill 75% of the existing computer industry. I say let 'em die. Give us secure computing, and may every company that intentionally harms people for profit die a horrible and painful death that takes as many of its investors with it as possible in the process! Sincerely, Jason

[Full-disclosure] Re: How hackers cause damage... was Vulnerabilites in new laws on computer hacking

2006-02-23 Thread Jason Coombs
of their knowledge of the problem. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Compromised hosts lists

2006-02-20 Thread Jason Coombs
found in their possession appears to incriminate their computer (and by extension, the computer owner) as a tool of the alleged crime. I'd like a better history of compromised hosts for this purpose, and suggest that botnet operators be required to publish their logs. ;-) Regards, Jason Coombs

Re: [Full-disclosure] Fun with Foundstone

2006-02-14 Thread Jason Coombs
[EMAIL PROTECTED] wrote: https://download.foundstone.com/?o=^2155 Now that's just plain sloppy. But at least it's SSL-secured. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored

Re: [Full-disclosure] On the 0-day term

2006-02-13 Thread Jason Coombs
modern information security. I do not see how any organization can believe itself to be adequately secured when the simple ability to prove security measures are working, and quickly determine the precise method of failure when they break down, essentially does not exist today. Sincerely, Jason

Re: [Full-disclosure] blocking Google Desktop

2006-02-11 Thread Jason Coombs
J.A. Terranson wrote: Invite the idiot in the white house, I hear he's feeling unloved today :-) Do you mean: invite the idiot in the white house ? Or do you mean: invite the idiot in the white house ? My favorite stupid hacker trick in the white house: getting POTUS to call you by your

Re: [Full-disclosure] NSA tracking open source security tools

2006-02-04 Thread Jason Coombs
information security tricks from Microsoft. Who in their right mind would focus their attention on software version numbers and think that makes for better security? Somebody tell the NSA they need to keep track of hash codes instead. Regards, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] Secure Delete for Windows

2006-01-17 Thread Jason Coombs
J.A. Terranson wrote: An exe? No source??? Just setup.exe Are you crazy? That's the way Microsoft does it, and you've got your trusty Anti-Virus software to protect you, right? So what's the problem? ___ Full-Disclosure - We believe in it.

Re: [Full-disclosure] Secure Delete for Windows

2006-01-17 Thread Jason Coombs
, and also refuse to disclose the source code so that we can compile the code ourselves and therefore at least know where our machine code came from and what its source looks like, then you're the one who needs to stfu and go promptly out of business before you hurt somebody. Best, Jason Coombs

Re: [Full-disclosure] Security Bug in MSVC

2006-01-17 Thread Jason Coombs
of vulnerability that was hinted at by Microserfs a few months ago... The attacks are launched by way of source code distributions rather than binary code. Sweet As. Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-disclosure] Secure Delete for Windows

2006-01-17 Thread Jason Coombs
, aren't you? good luck with that... Give me bugs that are well-understood and keep your stinking patches to yourself. we don't need no stinking patches. Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-disclosure] Steve Gibson smokes crack?

2006-01-13 Thread Jason Coombs
the situation nor alert any customer to the risk. This smells to me like a whole slew of intentional backdoors, and I don't smoke anything. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk

Re: [Full-disclosure] Steve Gibson smokes crack?

2006-01-13 Thread Jason Coombs
for writing the bad code and deploying flawed architectures over and over again through the years. Perhaps Microsoft has bothered to look into this by now, and has quietly dismissed the perpetrators. Beware of ex-Microsoft programmers. Regards, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] you can now be arrested for being annoying onthe 'net

2006-01-10 Thread Jason Coombs
Where do you want the United States to go today? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] A CALL FOR FULL-DISCLOSURE TO BECOME AMODERATEDLIST

2005-12-18 Thread Jason Coombs
, failure, and decisions of the business do not reflect directly on any one person, not even its CEO and founder. There is always more to the story, for anyone who can think clearly and can pay attention long enough to comprehend complex information. Can you? Regards, Jason Coombs [EMAIL PROTECTED

[Full-disclosure] Re: Guidance Software Customer Database Hacked?

2005-12-18 Thread Jason Coombs
. Regards, Jason Coombs [EMAIL PROTECTED] -Original Message- From: dave kleiman [EMAIL PROTECTED] Date: Sun, 18 Dec 2005 11:23:38 To:[EMAIL PROTECTED] Cc:'Samuel Norris' [EMAIL PROTECTED] Subject: RE: Guidance Software Customer Database Hacked? Samuel, Inline.. Dave

Re: [Full-disclosure] A CALL FOR FULL-DISCLOSURE TO BECOME AMODERATEDLIST

2005-12-17 Thread Jason Coombs
attached wherever you go, because wherever you go, there you are. Cheers, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] A CALL FOR FULL-DISCLOSURE TO BECOME A MODERATED

2005-12-15 Thread Jason Coombs
. Regards, Jason Coombs [EMAIL PROTECTED] Sent from my BlackBerry wireless handheld. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Looking for a job in OrangeCounty California, honestly

2005-12-07 Thread Jason Coombs
If you're looking for honest work then Orange County may not be the right place to live. Regards, Jason Coombs [EMAIL PROTECTED] Sent from my BlackBerry wireless handheld. -Original Message- From: Day Jay [EMAIL PROTECTED] Date: Wed, 7 Dec 2005 10:20:19 To:full-disclosure

Re: [Full-disclosure] Looking for a job in OrangeCounty California, honestly

2005-12-07 Thread Jason Coombs
on, Jay. Cheers, Jason Coombs [EMAIL PROTECTED] Sent from my BlackBerry wireless handheld. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [lists] Re: [Full-disclosure] IT security professionals in demandin 2006

2005-12-05 Thread Jason Coombs
Commercial pressures are just as harmful to security as are complexity and ignorance. Regards, Jason Coombs [EMAIL PROTECTED] Sent from my BlackBerry wireless handheld. -Original Message- From: Curt Purdy [EMAIL PROTECTED] Date: Mon, 5 Dec 2005 17:30:38 To:'wilder_jeff Wilder' [EMAIL

Re: [Full-disclosure] Re: Your One-Stop Site For Sony Lawsuit Info

2005-11-22 Thread Jason Coombs
to society. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Re: Your One-Stop Site For Sony Lawsuit Info

2005-11-22 Thread Jason Coombs
instructs said programmer to author said spyware will ever have personal criminal liability for giving said instruction. If you don't like the world you live in, change it or get out. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We

[Full-disclosure] Anyone interested in UNFAIRDISCLOSURE.COM

2005-11-07 Thread Jason Coombs
UNFAIRDISCLOSURE.NET UNFAIRDISCLOSURE.INFO and, FULL-DISCLOSURE.INFO Cheers, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Careless Law Enforcement Computer Forensics Lacking InfoSec Expertise Causes Suicides

2005-10-01 Thread Jason Coombs
this misuse of computer evidence, and whatever that something is, it is clear that only an information security organization is going to be able to explain it to law enforcement and legislators. Regards, Jason Coombs [EMAIL PROTECTED] -- http://news.independent.co.uk/uk/legal/article316391.ece 30

Re: [Full-disclosure] Forensic help?

2005-09-11 Thread Jason Coombs
://www.getdata.com/ http://www.mountimage.com/ Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] [Fwd: MM - #$%@ Kill Google!]

2005-09-08 Thread Jason Coombs
When will somebody get around to the important job of killing Microsoft? Original Message Subject:MM - #$%@ Kill Google! Date: Thu, 8 Sep 2005 18:58:17 UT From: Michael Robertson[EMAIL PROTECTED] To: [EMAIL PROTECTED] If this message is not displaying

[Full-disclosure] Re: Computer forensics to uncover illegal internet use

2005-09-02 Thread Jason Coombs
of an 'electronic crime against a child' should find out the answer to this question before they decide to try to report it to anyone. Wipe your drives and get on with life. It is not your job to protect electronic children from virtual harm. Sincerely, Jason Coombs [EMAIL PROTECTED] P.S. Tobin, does

Re: [Full-disclosure] RE: Example firewall script

2005-08-27 Thread Jason Coombs
, Jason Coombs [EMAIL PROTECTED] -Original Message- From: J.A. Terranson [EMAIL PROTECTED] Date: Sat, 27 Aug 2005 15:38:11 To:[EMAIL PROTECTED] [EMAIL PROTECTED] Cc:Full-Disclosure Full-Disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] RE: Example firewall script

[Full-disclosure] talk.google.com

2005-08-24 Thread Jason Coombs
http://www.google.com/talk/ Anyone looked at Google Talk? Yet another exposed endpoint... Let's bring all those vulnerable processors together in one place so they're easier to find? Hmm. When will users demand something fundamentally safer to use? Regards, Jason Coombs [EMAIL PROTECTED

[Full-disclosure] Sensitive Information Disclosure Vulnerability in Kinetics Kiosk Product

2005-08-18 Thread Jason Coombs
so as not to display such script errors. Furthermore, the use of an IP address that is outside of the RFC 1918 private subnet address range appears very irresponsible. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe

[Full-disclosure] Re: MS not telling enough

2005-08-18 Thread Jason Coombs
performing a forensic review of IIS 5.0 -- you'll find my analysis contained within my book about IIS security: http://www.science.org/jcoombs/ http://www.forensics.org/IIS_Security_and_Programming_Countermeasures.pdf Best, Jason Coombs [EMAIL PROTECTED] -Original Message- From: Kurt

Re: [Full-disclosure] Re: pnp worm unknown variant - post infectionactions

2005-08-17 Thread Jason Coombs
of convictions overturned, and prisoners released, based on faulty computer forensic evidence, that will make wrongful convictions based on faulty DNA evidence seem insignificant by comparison. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full

Re: [Full-disclosure] Re: pnp worm unknown variant - post infectionactions

2005-08-17 Thread Jason Coombs
must know something that the general public doesn't know, and their knowledge must be proof of your guilt, right? Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure

Re: [Full-disclosure] [Fwd: Re: Global CompuSearch]

2005-08-17 Thread Jason Coombs
Paul Schmehl wrote: Is there a compelling reason for posting this pissing contest to the list? Yes, there is, Paul. But you weren't paying attention, as usual. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter

Re: [Full-disclosure] Disney Down?

2005-08-17 Thread Jason Coombs
, and will remain so, by something other than the worms' code -- where the victim won't even bother to investigate that possibility because they feel like the worm was the incident. Regards, Jason Coombs [EMAIL PROTECTED] -Original Message- From: Larry Seltzer [EMAIL PROTECTED] Date: Wed

Re: [Full-disclosure] Re: It's not that simple...

2005-08-17 Thread Jason Coombs
/technet/security/bulletin/MS05-039.mspx Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Re: It's not that simple...

2005-08-17 Thread Jason Coombs
Kurt Seifried wrote: Actually it really is that simple. Disabling Null sessions is entirely possible, quite easy, and doesn't break a lot (at least in my previous Then why doesn't Microsoft provide these instructions in the workarounds section of the vulnerability announcement? Are you

Re: [Full-disclosure] Re: It's not that simple...

2005-08-17 Thread Jason Coombs
job for them? No way. It's painful that I'm not able to stop using their crap software entirely, and I wish they would just go away. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

Re: [Full-disclosure] Re: pnp worm unknown variant - post infection actions

2005-08-16 Thread Jason Coombs
. Not that this hasn't already been happening as a result of porn-related spyware and adware, but is this the first porn worm? Cheers, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

[Full-disclosure] Re: Global CompuSearch

2005-08-16 Thread Jason Coombs
No statement made by me with respect to Mr. Lawson has been false. Mr. Lawson *IS* an incompetent computer forensic expert who misrepresents his work as something that it is not. The facts prove this beyond any doubt. Good luck in your lawsuit. Sincerely, Jason Coombs [EMAIL PROTECTED

[Full-disclosure] [Fwd: Re: Global CompuSearch]

2005-08-16 Thread Jason Coombs
Original Message Subject: Re: Global CompuSearch Date: Tue, 16 Aug 2005 15:02:10 -1000 From: Jason Coombs [EMAIL PROTECTED] Reply-To: [EMAIL PROTECTED] To: Matthew Ries [EMAIL PROTECTED] CC: Marcus Lawson [EMAIL PROTECTED] I have also reviewed the emails that you have sent

Re: [Full-disclosure] [Fwd: Re: Global CompuSearch]

2005-08-16 Thread Jason Coombs
VIA MAIL AND EMAIL [EMAIL PROTECTED] Mr. Jason Coombs 59-088 Kamehameha Hwy. Haleiwa, HI 96712 Re: Global CompuSearch, L.L.C. Dear Mr. Coombs: Our firm has been retained by Global CompuSearch, L.L.C., to address the false and slanderous statements that you have made to various third

Re: [Full-disclosure] Re: Help put a stop to incompetent computerforensics

2005-08-12 Thread Jason Coombs
thought and then publish the arbitrary text and call it a 'dictionary' should be shot. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored

Re: [Full-disclosure] responsible disclosure explanation (anexample of the fallacy of idealistic thought)

2005-08-11 Thread Jason Coombs
to marketing efforts, lobbyist campaigns to get new legislation enacted, and disinformation spread by self-interested bad people. (I know you're not one of them) Sincerely, Jason Coombs [EMAIL PROTECTED] “A Trojan is malicious code that gives an attacker future unauthorized access to a computer

Re: [Full-disclosure] Re: Help put a stop to incompetent computer forensics

2005-08-10 Thread Jason Coombs
than by planting a Trojan, so there needs to be a distinction between the two. Cheers, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored

Re: [Full-disclosure] Re: Help put a stop to incompetent computer forensics

2005-08-10 Thread Jason Coombs
. Nobody today would avoid using the term spyware just because the term Trojan was the way in which that malware would have been labeled in the past. As I said, everyone I know understands what a Trojan is, and their understanding is not what you suggest it should be. Sincerely, Jason Coombs

Re: [Full-disclosure] Re: Help put a stop to incompetent computer forensics

2005-08-10 Thread Jason Coombs
not include the broader definition. That causes a real problem, in practice, since if the anti-Trojan doesn't stop spyware then how can spyware be a Trojan? Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-disclosure] Re: Help put a stop to incompetent computer forensics

2005-08-10 Thread Jason Coombs
to the infected box. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] responsible disclosure

2005-08-09 Thread Jason Coombs
. You and people like you are evil and you must be stopped. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] responsible disclosure

2005-08-09 Thread Jason Coombs
Solutions appeared to be stealing money from investors. My intervention saved your job, you dickweed. It also saved your company. The investors who backed you now control your company. Do you think that happened by accident? Shit, you're a gigantic moron. Sincerely, Jason Coombs [EMAIL

[Full-disclosure] Operation Site-Key computer forensic searches ruled illegal

2005-08-09 Thread Jason Coombs
detail? Thank you kindly, Jason Coombs [EMAIL PROTECTED] -- Stale warrants doom porn cases Exclusive: Searches that turned up images of children ruled illegal 09:55 PM CDT on Wednesday, July 13, 2005 By ROBERT THARP / The Dallas Morning News When Dallas police and federal agents wrapped up

Re: [Full-disclosure] responsible disclosure explanation

2005-08-08 Thread Jason Coombs
are today. Stupid fucks. See: http://www.wired.com/news/technology/0,1282,68435,00.html http://www.granick.com/blog/ http://www.granick.com/blog/lynncomplaint.pdf Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter

[Full-disclosure] [Fwd: CCO Locksmith - Automated Reply]

2005-08-04 Thread Jason Coombs
to their old e-mail address... Practically-speaking, Cisco has little choice but to personally phone every single member, or dump their entire registration database and force the users to re-apply for new member accounts. This automatic password reset thing is fatally-flawed. Regards, Jason

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-08-01 Thread Jason Coombs
on the Internet? maybe you should go reread the wiretap act. Wiretap Act doesn't apply to stored electronic communications. Kohl's owns all of those communications, whether stored temporarily in RAM or stored persistently to a hard drive. Regards, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-07-29 Thread Jason Coombs
least any possible criminal charges against Lynn dropped. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-07-29 Thread Jason Coombs
the pointed question Why did Cisco do this? It renders their product permanently defective, and here's the proof. Somebody needs to explain this clearly to the FBI. Cisco should be criminally prosecuted for telling lies to their customers and for abuse of process. Regards, Jason Coombs [EMAIL

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-07-29 Thread Jason Coombs
statements to the press, then Lynn willfully gave up that protection prior to his disclosure. Now that is truly patriotic and brave, to sacrifice oneself in order to demonstrate that there are holes in the criminal justice system... Regards, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-07-29 Thread Jason Coombs
ahead of time, before they deploy a product, what code that product should be allowed to execute. Do you think there is no way in hardware to limit the code that gets executed? Maybe you should join the FBI. Sincerely, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] Cisco Message Mike Lynn's controversial Cisco Security Presentation

2005-07-29 Thread Jason Coombs
Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-07-29 Thread Jason Coombs
this engineering challenge, presumably because it would cut into profits. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] Cisco Message Mike Lynn's controversial Cisco Security Presentation

2005-07-29 Thread Jason Coombs
secrets. However, techworld.com is a UK-based publisher, apparently, and so should be fine until a UK court concurs with the U.S. court's granting of the injunction. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter

Re: [Full-disclosure] Cisco Message Mike Lynn's controversial Cisco Security Presentation

2005-07-29 Thread Jason Coombs
J.A. Terranson wrote: On Fri, 29 Jul 2005, Jason Coombs wrote: reverse engineered. *millions* of copies of these secrets in general circulation. Nobody can assert with a straight face that anything about Lynn's presentation is not completely and totally within the public view

Re: [Full-disclosure] Cisco IOS Shellcode Presentation

2005-07-29 Thread Jason Coombs
[EMAIL PROTECTED] wrote: On Fri, 29 Jul 2005 15:02:51 -1000, Jason Coombs said: redesign, fundamentally, the turing machine so that before each operation is performed a verification step is employed to ensure that Ahem. No. You *can't* ensure it (although you *can* do things like bounds

Re: [Full-disclosure] Cisco Message Mike Lynn's controversial Cisco Security Presentation

2005-07-29 Thread Jason Coombs
and we'll see how well you are able to convince the court that you did not engage in espionage because the material was no longer a trade secret. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-disclosure] Our Industry Is Seriously Ethics Impaired

2005-07-27 Thread Jason Coombs
of a single file of source code? How much more complicated do you need to make it in order to feel safe? 3Com needs it to be so complicated that a 'Digital Vaccine' is required in order to make you feel healthy again. Bull. Crap. Lies. Regards, Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] iDEFENSE/VeriSign - VCP Program Changes

2005-07-26 Thread Jason Coombs
fancy trick to convince the shareholders to keep the faith and not dump the stock. Obviously, buying iDEFENSE makes VeriSign far more valuable. Hoorah! Who do you want the stock market to eat, today? Regards, Jason Coombs [EMAIL PROTECTED] ___ Full

Re: [Full-disclosure] Why Vulnerability Databases can't do everything

2005-07-16 Thread Jason Coombs
the Nokia 770 Linux Internet Tablet until the neocomputer industry emerges. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

[Full-disclosure] Re: Tools accepted by the courts

2005-07-05 Thread Jason Coombs
CSI and visions of fat bank accounts have deceived everyone temporarily...) Please get a clue before you hurt somebody. Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure

Re: [Full-disclosure] Publishing exploit code - what is it good for

2005-06-30 Thread Jason Coombs
waste of time and money, and they only help the bad guys on all sides of the bellum omnium contra omnes. The good guys get what they need by reading glossy print magazines. Regards, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe

Re: [Full-disclosure] Jack Szeszycki

2005-06-29 Thread Jason Coombs
[EMAIL PROTECTED] wrote: On Thu, 30 Jun 2005 04:00:40 +0930, [EMAIL PROTECTED] said: I will respond to your email when I return. If, of course, the e-mail is still there when Jack returns. ;) Does this form a binding contract? You may be able to sue Jack if he doesn't respond.

Re: [Full-disclosure] Internet Explorer / Outlook / Microsoft Office private exploit request

2005-06-16 Thread Jason Coombs
I'll pay more than they will. Contact me instead. Jason Coombs [EMAIL PROTECTED] metesi wrote: Dear All, for ethical penetration testing purpose we need to get a client-side undisclosed vulnerability for windows platform. We are interested in: - internet explorer - outlook - microsoft

[Full-disclosure] FBI San Diego, Drug Investigations and 9/11

2005-06-10 Thread Jason Coombs
negative consequences of expanding the power of law enforcement to act in secret in order to comply with our country's senseless mandates that compel us to create as many prisoners as possible. Sincerely, Jason Coombs [EMAIL PROTECTED] http://www.science.org/jcoombs

[Full-disclosure] Circumventing SSSS Screening and No-Fly List

2005-06-08 Thread Jason Coombs
unwise. ;-) Would you suggest debriefing TSA at the airport at one's destination upon arrival? Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted

[Full-disclosure] [Fwd: The New World of Work]

2005-05-19 Thread Jason Coombs
hahahaha! Over time, software will learn what information people use -- and what they don't want to know -- and will adjust its behavior and its output accordingly. ... very funny. Original Message Subject:The New World of Work Date: Thu, 19 May 2005 10:53:29 -0700

Re: [Full-disclosure] Firefox Remote Compromise Leaked

2005-05-08 Thread Jason Coombs
such a secret even if you could, is moronic and it's wrong-headed. Sincerely, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] Re: Case ID 51560370 - Notice ofClaimedInfringement

2005-04-08 Thread Jason Coombs
that any person above the mental age of 14 has no trouble understanding when the facts are presented clearly? Cheers, Jason Coombs [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Re: [Full-disclosure] I need uh Qwik-Fix please sho 'nuff!

2005-04-08 Thread Jason Coombs
I'm glad you wrote again, 'Lor'. You missed the press release? Or maybe you fail to comprehend good news when you see it. I'll send a copy of the press release. Please let us all know what you think. Sincerely, Jason Coombs [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED

[Full-disclosure] Lotus Fund Acquires Controlling Interest in PIVX Solutions

2005-04-08 Thread Jason Coombs
Lotus Fund Acquires Controlling Interest in PIVX Solutions From Co-Founders; Seeks to Leverage Company's Unique Windows Security Technology NEWPORT BEACH, Calif.--(BUSINESS WIRE)--April 7, 2005--PIVX Solutions, Inc. (OTCBB:PIVX), the leader in next generation Windows Host-Based Intrusion

Re: [Full-disclosure] How to Report a Security Vulnerability toMicrosoft

2005-04-08 Thread Jason Coombs
the truth. MICROSOFT: STOP THE WAR! NO MORE SECRETS! Regards, and best wishes, Jason Coombs [EMAIL PROTECTED] -Original Message- From: Georgi Guninski [EMAIL PROTECTED] Date: Fri, 8 Apr 2005 23:17:08 To:full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] How to Report

Re: [Full-disclosure] Lotus Fund Acquires Controlling Interest in PIVX Solutions

2005-04-08 Thread Jason Coombs
[EMAIL PROTECTED] wrote: What is this a press release mailing list? Full-pivx-disclosure? So it's okay for anonymous cowards who want to perpetrate financial crimes to post nonsense to the list, but I'm not allowed to? Nice. Jason Coombs [EMAIL PROTECTED

Re: [Full-disclosure] Re: Case ID 51560370 - Notice of ClaimedInfringement

2005-04-07 Thread Jason Coombs
by absolutes. By design, and by intent, the world is not a level playing field - if you are a consumer, a renter, and a worker then you are a slave to producers, owners, and employers. Live with it, or don't, but to live while grossly misunderstanding it is truly absurd. Regards, Jason Coombs [EMAIL

Re: [Full-disclosure] Re: Case ID 51560370 - Notice of ClaimedInfringement

2005-04-07 Thread Jason Coombs
'Security' is ENTIRELY philosophical. Go use a dictionary. You'll learn something. Jason Coombs [EMAIL PROTECTED] -Original Message- From: Thierry Zoller [EMAIL PROTECTED] Date: Fri, 8 Apr 2005 01:25:42 To:Jason Coombs [EMAIL PROTECTED] Cc:full-disclosure@lists.grok.org.uk Subject: Re

Re: [Full-disclosure] I need uh Qwik-Fix please sho 'nuff!

2005-04-05 Thread Jason Coombs
specialist firm. Reacting to problems rather than preparing for them forensically is a mistake nobody can afford to make today. Sincerely, Jason Coombs [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] Date: Tue, 5 Apr 2005 02:07:44 To:full-disclosure@lists.grok.org.uk Subject

Re: [Full-disclosure] I need uh Qwik-Fix please sho 'nuff!

2005-04-05 Thread Jason Coombs
specialist firm. Reacting to problems rather than preparing for them forensically is a mistake nobody can afford to make today. Sincerely, Jason Coombs [EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] Date: Tue, 5 Apr 2005 02:07:44 To:full-disclosure@lists.grok.org.uk Subject

[Full-disclosure] Re: [ISN] How To Save The Internet

2005-03-21 Thread Jason Coombs
profit from victims by causing them unnecessary problems and then selling inadequate fixes. Sincerely, Jason Coombs [EMAIL PROTECTED] [1] MSDN Security Developer Center: Execution Protection http://msdn.microsoft.com/security/productinfo/XPSP2/memoryprotection/execprotection.aspx [7] Why Was Intel

[Full-disclosure] Re: choice-point screw-up and secure hashes

2005-03-19 Thread Jason Coombs
suggesting that companies should encrypt the information they store in databases. That would have taken too few words to recommend, and if it's that easy to solve the underlying problem, who will hire you? Cheers, Jason Coombs [EMAIL PROTECTED] -Original Message- From: Atom Smasher [EMAIL

Re: [Full-disclosure] Re: choice-point screw-up and secure hashes

2005-03-19 Thread Jason Coombs
reverse hashing By reverse hashing you mean defeating the protection by forward hashing all possible SSNs, presumably. -Original Message- From: [EMAIL PROTECTED] Date: Sat, 19 Mar 2005 17:38:09 To:Atom Smasher [EMAIL PROTECTED] Cc:Jason Coombs [EMAIL PROTECTED], Full-Disclosure

[Full-disclosure] Re: choice-point screw-up and secure hashes

2005-03-18 Thread Jason Coombs
Good job! You've reduced by 99% the number of people who understand that the SSN is still being stored as plaintext in the database. This should result in 100% efficacy for defense against lawsuits and other complex liability that would otherwise arise out of pure neglect and incompetency. I

Re: [Full-disclosure] Fwd: NDA SOX?

2005-03-12 Thread Jason Coombs
what you believe is right, and get advice from legal counsel but don't forget that they are just making an educated guess about how a jury or a judge will respond, or interpret the law. Your attorney is not you, and it is not their decision to make in the end. Sincerely, Jason Coombs [EMAIL

  1   2   >