Re: [Full-disclosure] Drive-by Pharming Threat

2007-02-19 Thread mikeiscool
does perl run in your browser? On 2/20/07, Gaurang Pandya <[EMAIL PROTECTED]> wrote: > just wondering why cant simple perl script be used > instead?? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html

Re: [Full-disclosure] Financial firms warned of Qaeda cyber attack

2006-12-03 Thread mikeiscool
On 12/3/06, Dude VanWinkle <[EMAIL PROTECTED]> wrote: > On 12/3/06, Matthew Flaschen <[EMAIL PROTECTED]> wrote: > > Or, realize that no one lost money in 9/11, even those who had banks in > > the World Trade Center. Why? Every bank has multiple redundant > > backups, including offsite storage. >

Re: [Full-disclosure] Financial firms warned of Qaeda cyber attack

2006-12-03 Thread mikeiscool
I lost money. On 12/3/06, Matthew Flaschen <[EMAIL PROTECTED]> wrote: > Or, realize that no one lost money in 9/11, even those who had banks in > the World Trade Center. Why? Every bank has multiple redundant > backups, including offsite storage. > > Matthew Flaschen > > TheGesus wrote: > > Conc

Re: [Full-disclosure] Ask for spam...

2006-10-13 Thread mikeiscool
On 10/13/06, Louis Wang <[EMAIL PROTECTED]> wrote: > Hi Guys: > I'm doing research on AntiSpam personally, I need a lot of spam > samples. I have try a lot to incur spam, but to now, I can only get > about 300 spam per day. > Could anybody kind to help me with spam collection? I use > [EMAI

Re: [Full-Disclosure] RE: Patching networks redux (fwd)

2006-08-22 Thread mikeiscool
this raises a good question though. why _aren't_ i learning spanish. i don't have a good answer to this. my recommendation would be to commence the learning of spanish immediately. i know i will. -- mic ___ Full-Disclosure - We believe in it. Charter:

[Full-disclosure] Re: JavaScript Lazy Authorization Forcer and Visited Link Scaner

2006-08-15 Thread mikeiscool
i discovered this first! well, maybe. but the site where i talked about it is now gone :) anyway, it really doesn't need to be so complicated with creating a new 'style' section; just use the a:visited selector. a { margin-left: 1px; } a:visited { margin-left: 2px; } then check for the margi

Re: [Full-disclosure] LOL HY

2006-08-15 Thread mikeiscool
On 8/15/06, Matt Burnett <[EMAIL PROTECTED]> wrote: What the fuck is my problem? I had to dl ~1MB of shitty porn, which prevents me from having 1.5 seconds more of decent high quality porn. Thats my fucking problem. Now the real question is what the fuck is your problem? If its so easy to not re

Re: [Full-disclosure] LOL HY

2006-08-15 Thread mikeiscool
you just can't grasp the idea of fd can you matt. it is _so_ easy not to read these messages. what the fuck is your problem? don't you remember the simpsons? *just don't look, just don't look* -- mic ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Top sites for Application security news

2006-08-10 Thread mikeiscool
On 8/11/06, KT <[EMAIL PROTECTED]> wrote: what are they? I am tasked with keeping up on application security news. Here are few I can think of, but I am sure there are more securityfocus.com owasp.org rootsecure/osvdb/cert/etc.. -- mic ___ Full-Di

Re: [Full-disclosure] NNTP and Yahoo IM conflict

2006-08-09 Thread mikeiscool
On 8/10/06, NTR <[EMAIL PROTECTED]> wrote: Hi All, I am trying analyze NNTP traffic and i have created a profile for NNTP protocol. It's a kind of NNTP protocol anomaly detection. I have also observed some time Yahoo Instant Messenger uses NNTP port. Though it is using NNTP port the format is

Re: [Full-disclosure] HackingRFID group

2006-08-03 Thread mikeiscool
On 8/3/06, Josh L. Perrymon <[EMAIL PROTECTED]> wrote: http://groups.google.com/group/hackingRFID I have started a private google group for discussing hacking RFID if anyone is interested. why is it private? kind of ironic that you'd send a request for members in a private list via fd. -- mi

Re: OT (joke) Re: [Full-disclosure] Hushmail addresses are being used to impersonate n3td3v

2006-08-01 Thread mikeiscool
On 8/1/06, Charlie Harvey <[EMAIL PROTECTED]> wrote: Gxi estis 2006-07-31 08:47 kaj tiele skribis n3td3v v3dt3n --8< > I am the real n3td3v as i own n3td3v.com So there you little twerp. --8< No, I'm n3td3v. No, I'm n3d

Re: [Full-disclosure] Symantec 3300 E-mail Gateway dropping spoofed mails

2006-07-18 Thread mikeiscool
On 7/19/06, Josh L. Perrymon <[EMAIL PROTECTED]> wrote: This email gateway is blocking email messages spoofed from my RH3 box... The error message: X-NAI-Spam-Level: ** X-NAI-Spam-Score: 2.3 X-NAI-Spam-Report: 2 Rules triggered * 1.8 -- MIME_MISSING_BOUNDARY -- RAW: MIME section missing bo

Re: [Full-disclosure] Looking for any vulnerabilities in GreenBorder Pro - Download please, and let me know

2006-07-13 Thread mikeiscool
On 7/14/06, Bill Stout <[EMAIL PROTECTED]> spammed: Hi guys, I'm looking for vulnerabilities or other weaknesses in our GreenBorder Pro (application virtualization and isolation) product. I invite you to download and hammer it. Please tell me of any vulnerability you may find. how about

Re: [Full-disclosure] Cookies marked as secure

2006-07-11 Thread mikeiscool
On 7/12/06, Josh L. Perrymon <[EMAIL PROTECTED]> wrote: Ok, I'm having a discussion with a buddy about secure cookies. I'm looking at a Java application that used several cookies after logging in; SessionID CookieIDtype FailMSGID so on... Obviously the application is using some code tha

Re: [Full-disclosure] Newest Phishing Technique:

2006-07-10 Thread mikeiscool
On 7/11/06, Joel R. Helgeson <[EMAIL PROTECTED]> wrote:   Joel Helgesoncool; someone followed my advice then. http://archives.neohapsis.com/archives/fulldisclosure/2006-07/0030.html -- mic ___ Full-Disclosure - We believe in it. Charter: http:/

Re: [Full-disclosure] Vhoning

2006-07-10 Thread mikeiscool
On 7/11/06, n3td3v <[EMAIL PROTECTED]> wrote: What (I and) the underground call it: "Vhoning" vhoning looks alot like whoring ... to me anyway. .. my proposal for the name is "mikeiscool'ing". it will help my brand (of me). thanks. i'd also like to propose another term. "netdev'ing". you

[Full-disclosure] Re: Two-Factor Authentication on the Web

2006-07-06 Thread mikeiscool
On 7/6/06, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: http://www.theregister.co.uk/2005/04/04/fingerprint_merc_chop/ Carjackers swipe biometric Merc, plus owner's finger honestly, this guy should sue mercedes. this absoutely had to forsee this possibility and they did not care. something lik

[Full-disclosure] Re: [WEB SECURITY] Cross Site Scripting in Google

2006-07-05 Thread mikeiscool
On 7/5/06, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: Did you even bother to email them and let them know? Being that they're still vulnerable probably not the irony of your whinge being posted to fd is too much for me to handle. -- mic ___ Fu

Re: [Full-disclosure] Undisclosed breach at major US facility

2006-07-04 Thread mikeiscool
On 7/5/06, Q-Ball <[EMAIL PROTECTED]> wrote: Security is simply a cost/benefit excercise at the end of the day. No one implements security just to feel better about themselves. i do it makes me feel cool -- mic ___ Full-Disclosure - We believe in i

Re: [Full-disclosure] Undisclosed breach at major US facility

2006-07-03 Thread mikeiscool
On 7/4/06, r r <[EMAIL PROTECTED]> wrote: Need some advise here. I would like to know what to do if I --hypothetically speaking-- I were to retrieve _complete_ databases of a MAJOR us hospital. My hypothetical model is not brute force, but rather an 'accidental' discovery by trying to retrieve u

[Full-disclosure] google; make a feature called "use google services anonymously"

2006-07-02 Thread mikeiscool
because that would be good. the way it would operate is like so: 1. stop reading my email. even with a robot. 2. stop linking my google accounts 3. stop remembering which google groups i visit 4. stop linking the google services i use 5. don't share subdomain specific information with your other

Re: [Full-disclosure] Are consumers being misled by "phishing"?

2006-06-28 Thread mikeiscool
On 6/29/06, n3td3v <[EMAIL PROTECTED]> wrote: I believe the industry coined up "phishing" to make more money out of social engineering. Its obvious now that both are over lapping. Only the other day Gadi Evron was trying to coin up a phrase for "voice phishing". Why can't we cut to the chase and

Re: [Full-disclosure] Pen-Testing / App Scanner Patents

2006-06-27 Thread mikeiscool
On 6/27/06, Josh L. Perrymon <[EMAIL PROTECTED]> wrote: http://lists.grok.org.uk/pipermail/full-disclosure/2004-January/015690.html Anyone heard anything else on the Sanctum INC patent for pentesting??? WTF? A friend told me about this one and Watchfire patents on application scanners.. wtf

Re: [Full-disclosure] Sniffing RFID ID's ( Physical Security )

2006-06-26 Thread mikeiscool
On 6/27/06, Josh L. Perrymon <[EMAIL PROTECTED]> wrote: My post was based more on *existing* RFID implementations used for physical security access cards. I know that non-contact cards such as RFID Credit Cards use encryption so on... But are still vulnerable to non-authorized transactions.. I'

Re: [Full-disclosure] Sniffing RFID ID's ( Physical Security )

2006-06-26 Thread mikeiscool
On 6/27/06, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: On Tue, 27 Jun 2006 14:24:35 +1000, mikeiscool said: > eh? > > surely a RFID would only communicate it's private token with a trusted > (i.e. keyed) source. > > like a smartcard ... Well.. Yeah. That *woul

Re: [Full-disclosure] Sniffing RFID ID's ( Physical Security )

2006-06-26 Thread mikeiscool
On 6/27/06, Josh L. Perrymon <[EMAIL PROTECTED]> wrote: I was contacted by Eweek recently about previous posts about RFID and how it is being used at the World Cup and Olympics. This got me thinking a little more about some previous ideas I have had. I think the real risk is in RFID access cards.

Re: [Full-disclosure] notepad oddatiy

2006-06-15 Thread mikeiscool
On 6/16/06, John Bond <[EMAIL PROTECTED]> wrote: could some one tell me why/how this happens. unicode -- mic (fd tech support) ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsore

Re: [Full-disclosure] Phishing and Spammers

2006-06-14 Thread mikeiscool
On 6/15/06, Geo. <[EMAIL PROTECTED]> wrote: I would appreciate hearing a little feedback on this idea. It strikes me that phishers and spammers have a vulnerability that we have not yet exploited. They collect information, granted the returns are small but since email is cheap they send out tons