Re: [Full-disclosure] Save XP

2008-01-29 Thread Vincent Archer
e about what applications you run, not what the system under them is. -- Vincent Archer ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] High Value Target Selection

2007-12-03 Thread Vincent Archer
". Took us two months of careful negotiation to explain in words of no more than 5 letters that when we said backup in case of cut lines, we really meant it. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Deny All - 23, rue Notre Dame des V

Re: [Full-disclosure] Standing Up Against German Laws - Project HayNeedle

2007-11-12 Thread Vincent Archer
e number, which is also recorded. > Besides that, there is an explicit statement [2] that forbids > recording contents or data related to the visited web pages. Yes, because that is considered wiretapping, which requires a judge to determine if you have enough cause to warrant the breach of

Re: [Full-disclosure] Distributed SSH username/password brute forceattack

2007-10-24 Thread Vincent Archer
trol on people's private keys and thus cannot enforce passphrases on those keys. You can unknowingly lower your security by moving to a key-based login, because some people who would type a password to log-in will not bother securing their passphrases if they are forced to use a private key. --

Re: [Full-disclosure] Linux big bang theory....

2007-05-28 Thread Vincent Archer
le. Any expansion breaks down the proved state by introducing external unvalidated states, and you're back to square one. Being able to validate the integrity of a system requires *at least* the entire potential system, which is why systems in general cannot self-prove: they require more th

Re: [Full-disclosure] Linux big bang theory....

2007-05-21 Thread Vincent Archer
cation from the hosting component of the hosted one. Or the hammer approach of erasing the state of the system after use, and rolling it back to a "proven" safe and stable one. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47

Re: [Full-disclosure] Apache/PHP REQUEST_METHOD XSS Vulnerability

2007-04-25 Thread Vincent Archer
dy repeated in this thread), the legal methods are well defined as being of type "token". And tokens can't include characters like <, (, or ". And that's where apache fails: it lets you use additional methods, sure, but it also doesn't validate anything - even though

Re: [Full-disclosure] Apache/PHP REQUEST_METHOD XSS Vulnerability

2007-04-25 Thread Vincent Archer
or Apache. Not with PHP. But I would agree with the original programmer that apache is in fault here. Apache should have done the expected work, and validated that the request was standards-compliant. It didn't, and that opens up a huge chasm in which plenty of problems, vulnerabilities and others, ma

Re: [Full-disclosure] Why Microsoft should make windows open source

2007-04-10 Thread Vincent Archer
the whole Windows OS paradigm obsolete... that's where the Microsoft momentum can falter. That, or major blunders. Microsoft has enough resources to survive most of anything... but you can survive as the number 2 or 3, or #5 guy on the market. Survival is not dominance. -- Vincent ARCHER [EMAI

Re: [Full-disclosure] Solaris telnet vulnberability - how many on your network?

2007-02-12 Thread Vincent Archer
ng available on solaris 10 years ago, I think). > Anyone else running Solaris? We do, and we confirm. The info is spreading like wildfire, and justifiably so - I thought this bug category (-fuser) was squashed last with AIX over 10 years ago. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0

Re: [Full-disclosure] Anonymizing RFI Attacks Through Google

2006-11-27 Thread Vincent Archer
vestigate from there. That adds Google as an additional cut-out and delays any investigation. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Deny All - 23, rue Notre Dame des Victoires - 75002 Paris - France

Re: [Full-disclosure] Removing the NIC cable = EoP?

2006-10-03 Thread Vincent Archer
k profile, and default to it when unable to fetch the profile - I'm sure the sysadmins added fancy tricks to destroy any local profile once you've logged out, and the building of the account profile when you log in for "the first time" is where the drop to admin happens. -- Vin

Re: [Full-disclosure] MiTM with https there are any tools ?

2006-03-06 Thread Vincent Archer
L key used by the server, you can use the ssldump utility ( http://www.rtfm.com/ssldump/ ) to decrypt a tcpdump capture of the SSL traffic. Ettercap looks like it has the ssldump feature integrated, but, again, you do need to have the SSL key of the server to decipher the session. -- Vincent

Re: [Full-disclosure] Spy Agency Mined Vast Data Trove and other tales

2006-01-02 Thread Vincent Archer
he secret, and as everyone knows, two persons can keep a secret only if one of them is dead). And that's almost as dangerous to american interests as NSA being unable to spy on them. -- Vincent Archer Email: [EMAIL PRO

Re: [Full-disclosure] IT security professionals in demand in 2006

2005-12-07 Thread Vincent Archer
d the book 2 nights before the test to take the practice > >exams. Scored a 92 on the exam and put the book away. We were given 6 hours * He scored 92 on the practice in the book. Then took the real exam. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 49 96 Fax : +33 (0)1 4

Re: [Full-disclosure] FW: [MailServer Notification] Your .zip file has been blocked from entering the ScanSoft email environment.

2005-12-05 Thread Vincent Archer
it a new attachment. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 49 96 Fax : +33 (0)1 40 07 47 27 Deny All - 23, rue Notre Dame des Victoires - 75002 Paris - France ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disc

Re: [Full-disclosure] Call to participate: GNessUs security scanner

2005-10-11 Thread Vincent Archer
t be removed from the non-GPL version of Nessus. That's what Arnaud points out: there is very very few parts of Nessus that were contributed by the outside community. Once those parts are gone, "Nessus 3.0" can go on, even if it shares 95% of its code with the GPL Nessus 2.2.5 initi

Re: FW: [Full-disclosure] looking for a HTTPS redirect server

2005-05-20 Thread Vincent Archer
ften fails because it assumes that the client always speaks directly to the server, without any alteration to content, connection and timing, and sometimes this assumption fails. If that's the case, you're out of luck. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax :

Re: [Full-disclosure] Another PayPal phishing scam

2005-05-03 Thread Vincent Archer
a half, and has been used to post to about four of the security mailing lists I'm subscribed to. So, be patient. You'll have your fill quickly. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Deny All - 23

Re: [Full-disclosure] Reuters: Microsoft to give holes info to UncleSam first - responsible vendor notification may not be a good idea anymore...

2005-03-14 Thread Vincent Archer
of system: "ubiquitous law enforcement" (Vinge, being moderately libertarian, of course views that as The Ultimate Evil) -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Attention !!! A compter du 29 mars, Deny All change d'adresse : 23 rue

Re: [Full-disclosure] Publishing exploit code ruled illegal in France?

2005-03-11 Thread Vincent Archer
r programs. Or to find out how the firewall work, so you can control it or supplement it). Reverse engineering and publishing your findings is not automatic. That's where consumer protection laws start to interfere with IP, and that's where lawyers start earning their fees. At least, it&#

Re: [Full-disclosure] Reverse dns

2005-03-10 Thread Vincent Archer
dding a host" & "Adding Gateways") -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Deny All - 5, rue Scribe - 75009 Paris - France www.denyall.com ___ Full-Disclosure - We believe in

Re: [Full-disclosure] Publishing exploit code ruled illegal in France?

2005-03-10 Thread Vincent Archer
neering on it. You can lawfully reverse engineer software you legitimately own, but not the one you don't. -- Vincent ARCHER [EMAIL PROTECTED] Tel : +33 (0)1 40 07 47 14 Fax : +33 (0)1 40 07 47 27 Deny All - 5, rue Scribe - 75009 Paris - France www.denyall.com _