Re: [Full-disclosure] OpenID/Debian PRNG/DNS Cache poisoning advisory

2008-08-12 Thread Clausen, Martin (DK - Copenhagen)
You could use the SSL Blacklist plugin (http://codefromthe70s.org/sslblacklist.asp) for Firefox or heise SSL Guardian (http://www.heise-online.co.uk/security/Heise-SSL-Guardian--/features/11 1039/) for IE to do this. If presented with a Debian key the show a warning. The blacklists are implemented

Re: [Full-disclosure] Where's Slashdot.org???

2005-05-12 Thread dk
wait a sec... Did you just mean that your .mil DNS is borked? 'Doh. :) -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] The best hacker ever !

2005-04-28 Thread dk
if someone falls for it. ;| -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2005-04-26 Thread dk
brilliant Stan, you really though this one though. -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] [INetCop Security Advisory] Snmppd potentially format string vulnerability.

2005-04-25 Thread dk
events surrounding Japanese American treatment during WWII. If it is also customary for other Asian Countries to censor history from their population; then your best move is to start your reform at home then reach abroad. -- dk ___ Full-Disclosure - We

Re: [Full-disclosure] FIXED CODE - IIS 6 Remote Buffer Overflow Exploit (was broken)

2005-04-20 Thread dk
Day Jay wrote: Sorry, the previous code was broken. Definitely `borken'... I didn't even see one /etc/passwd file in here! Less obvious calls may catch more habitual FD code runners next time dude. [think: ret=(int *)&ret+2;(*ret)=(int)shellcod

Re: [Full-disclosure] How to Report a Security VulnerabilitytoMicrosoft

2005-04-19 Thread dk
e attached. HAHAHAH! Cute Pic.. Besides, if *ALL* my grandmother (god rest her soul) wanted to do is "turn on her her computer and check her email" then a custom Linux setup is the clear winner anyway. -- dk ___ Full-Disclosure - We believe

Re: [Full-disclosure] Microsoft April Security Bulletin Webcast BS

2005-04-13 Thread dk
true too, right? (Developers, Developers, Developers) Heheheh -- Sorry, too much sugar this afternoon. -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] How to Report a Security VulnerabilitytoMicrosoft

2005-04-12 Thread dk
tend to "Do it right" when all these interest align nicely, as they sometimes do (e.g. electronic crimes). When they do not is when we see the flames from users/consumers. MS can improve, and they should. -- dk ___ Full-Disclosure - W

Re: [Full-disclosure] How to Report a Security VulnerabilitytoMicrosoft

2005-04-12 Thread dk
take their time on the simple fixs too most times. -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] linux bugs (survival stories)?

2005-04-12 Thread dk
ion (PaX, etc..) or forums. -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Re: Case ID 51560370 - Notice of ClaimedInfringement

2005-04-08 Thread dk
ie... Modding the p2p app to falsely match specific remote chunks against crafted local files seems an easier route than trying to find collisions. :) Then again, it would break the swarming feature of what ever app you modded & 'prolly be br

Re: [Full-disclosure] Reverse engineering the Windows TCP stack

2005-04-04 Thread dk
ndows retries several times (SYN) even when RST has been received. My Linux don't. I would believe that is incorrect behavior, no? (for the win32 box) -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-ch

Re: [Full-disclosure] Secure Data Deletion Idea?

2005-03-31 Thread dk
ase abandon this "get-rich-quick" idea and look into late night real-estate infomercials. ;) BTW: My hammer and acetylene torch are much more effective and I'll do it for half-price of what John will charge; Honest! No returns or refunds though. :) -- dk _

Re: [Full-disclosure] Hacked: Who Else Is Using Your Computer?

2005-03-30 Thread dk
ay! (tm)". You know; the ones that inevitably cover how kids talked and acted in the 80's but published in the 90's. (etc, etc) >;/ -- dk ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Microsoft GhostBuster Opinions

2005-03-18 Thread dk
h might be in order. ;-) http://www.l0t3k.org/biblio/kernel/english/runtime-kernel-kmem-patching.txt http://www.phrack.org/show.php?p=58&a=7 http://www.l0t3k.org/security/docs/rootkit/ ... -- dk ___ Full-Disclosure - We believe in it.