Re: [Full-disclosure] Botnet using Plesk vulnerability and takedown

2013-06-09 Thread kai
my action supposed to be a counter-measure agains bad guys who could register that domain and host some bad code there. you know that kind of social engineering, right? - post some fake or real advisory on popular security forum/maillist - give a link to the "patch" - - get a lot of roots

Re: [Full-disclosure] Botnet using Plesk vulnerability and takedown

2013-06-08 Thread kai
tigation anyway. Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] DPI evasion

2012-12-17 Thread kai
H? or should we use some other technics/protocols? > P.S. you may be interested in i2p which has a bitTorrent like client. thanks for your suggestion, i know i2p (and a lot of info about darknets and deepweb), but it doesn't suit my needs. Cheers, Kai __

[Full-disclosure] DPI evasion

2012-12-17 Thread kai
Hi all, i have VPN with OpenSSL encryption and i use SSH-tunnel over VPN. is it enough to illegally share my illegal mp3's via illegal BitTorrent? Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-discl

Re: [Full-disclosure] MySQL (Linux) Database Privilege Elevation Zeroday Exploit

2012-12-05 Thread kai
file user.MYD?" but then... file_name cannot be an existing file, which among other things prevents files such as /etc/passwd and database tables from being destroyed. anyway we have Nvidia cards and Hashcat. Cheers, Kai connecting.. "; $link=mysql_connect("".$host.&quo

Re: [Full-disclosure] Checking out backdoor shells

2012-05-18 Thread Kai
he public_html or /var/www and modify the index of > the > page. -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] trixd00r v0.0.1 - Advanced and invisible TCP/IP based userland backdoor

2012-02-08 Thread Kai
: https://rdot.org/forum/showpost.php?p=15855&postcount=11 ? (russian language) if yes than 0.0.2 will be uberbeautiful. -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charte

Re: [Full-disclosure] when did piracy/theft become expression of freedom

2012-01-27 Thread Kai
Hello, http://img256.imageshack.us/img256/2527/1282302008370.jpg know the difference. -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http

Re: [Full-disclosure] Who's Behind the Koobface Botnet? - An OSINT Analysis

2012-01-09 Thread Kai
Hi, > zaebalinax.com is literally translated to "Gave up on Linux". just FYI it's not "zaeba linax" or whatever, but "zaebali nax" (where "nax" is short for "nahuy"), the translation would likely be "they've f*cked

Re: [Full-disclosure] looking for wpepro analog

2011-11-14 Thread Kai
Hi, On Mon, 14 Nov 2011 16:03:46 +0100, Guillaume Friloux wrote: > Hi, you can use ptrace(make your own app) or systemtap for that kind > of stuff. sorry, but i'm not a programmer. is there any known implementation of wpepro functional? -- C

[Full-disclosure] looking for wpepro analog

2011-11-14 Thread Kai
ext. -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Apache 2.2.17 exploit?

2011-10-04 Thread Kai
sorry if i'm talking about different thing. -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Apache 2.2.17 exploit?

2011-10-03 Thread Kai
have any other interesting odays? :) -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Semi 0day DNS Invalid Compression attack

2011-07-11 Thread Kai
7;CFLAGS=-fomit-frame-pointer -fmessage-length=0 -O2 -Wall -D_FORTIFY_SOURCE=2 -fstack-protector -funwind-tables -fasynchronous-unwind-tables -g -fno-strict-aliasing' 'LDFLAGS=-L/usr/lib' you said that packet was like > # 4500 002b 512f 4000

Re: [Full-disclosure] how to detect DDoS attack through HTTP response analysis(throuput)

2011-06-26 Thread Kai
Requested Page; etc. -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Apache 2.0.63 - 2.2.19 Remote Exploit Fake or not?

2011-06-17 Thread Kai
> Claiming to gain root through a service that most people do not run > as > root already makes me think that this fake. do not forget about mpm-itk, mpm-peruser and analogs, when we have to run apache as root. -- Cheers, Kai ___

Re: [Full-disclosure] CCAvenue.com Payment Gateway Vulnerable SQL Injection UPDATE

2011-05-06 Thread Kai
> adu_id adu_user adu_pwd adu_status dept_id remote_access mobile_number > . . . > Acc1041 Risk Risk A Acc lol, definitely a risky guy -- Cheers, Kai ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.or

Re: [Full-disclosure] Launched New Tool - RAR Password Unlocker

2011-03-29 Thread kai
Hi, is there any chance of seeing CUDA in action for the next versions? :) >> Installed executable is completely portable. why do we need installer then? distribute that tool as single executable. Cheers, Kai > We have just released new password reco

Re: [Full-disclosure] Linux kernel exploit

2010-12-08 Thread Kai
> Anyone tested this in sandbox yet? 00:37 linups:../expl/kernel > cat /etc/*release* openSUSE 11.3 (i586) VERSION = 11.3 00:37 linups:../expl/kernel > uname -r 2.6.34.4-0.1-desktop 00:37 linups:../expl/kernel > gcc _2.6.37.local.c -o test 00:37 linups:../expl/kernel > ./test [*] Failed to open