Re: [Full-disclosure] Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins to Temporarily Escalate Privileges and Login as Cached Domain Admin Accounts (2010-M$-002)

2010-12-13 Thread Jeremy SAINTOT
Correct me if I'm wrong, but here is what I think of that : A Domain user that is a Local admin of his workstation is different than a Domain user which is Domain Admin. Then, a local admin whose account is an AD account can run scripts *on his local machine* in the name of the domain admin.

Re: [Full-disclosure] Drive-by Pharming Threat

2007-02-20 Thread Jeremy Saintot
such as DNS servers (for this attack) and more. Regards, Jeremy Saintot ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] Analysis of Myspace passwords

2007-02-19 Thread Jeremy Saintot
Here is a short analysis of the passwords chosen by myspace users, that some guy has phished a few weeks ago. The analysis is based on a list of 36700 user passwords. The original file contained 56000+ lines, but I removed the blank passwords and those that were 20+ characters length,