Re: [Full-disclosure] Filezilla's silent caching of user's credentials

2010-10-14 Thread silky
*is* a direct complaint to them, after bugs have been closed for years. I didn't start this thread. Do you even understand what is going on here? Your emails suggest you do not. Cheers, Chris. -- silky http://dnoondt.wordpress.com/ Every morning when I wake up, I experience an exquisite joy

Re: [Full-disclosure] Filezilla's silent caching of user's credentials

2010-10-14 Thread silky
the developer on the issue of the nature of stored passwords on a local machine is meaningless. If their position is *influenced* by yours, then I will comment, otherwise, I don't see the point. -- silky http://dnoondt.wordpress.com/ Every morning when I wake up, I experience an exquisite joy — the joy

Re: [Full-disclosure] Filezilla's silent caching of user's credentials

2010-10-14 Thread silky
adding to the uselessness. I will leave you with one thought. Shouldn't the default be encrypt? -- silky http://dnoondt.wordpress.com/ Every morning when I wake up, I experience an exquisite joy — the joy of being this signature. ___ Full-Disclosure - We

Re: [Full-disclosure] Filezilla's silent caching of user's credentials

2010-10-13 Thread silky
into your FTP server from a public terminal with Filezilla. Rubbish. The passwords should be encoded so-as to avoid trivial searching. End of story. It takes 10 minutes to do from a development point of view, and there is no excuse. -- silky http://dnoondt.wordpress.com/ Every morning when I wake up

Re: [Full-disclosure] Filezilla's silent caching of user's credentials

2010-10-13 Thread silky
and appropriate policy). Chris. -- silky http://dnoondt.wordpress.com/ Every morning when I wake up, I experience an exquisite joy — the joy of being this signature. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

Re: [Full-disclosure] answer

2010-02-13 Thread silky
On Sun, Feb 14, 2010 at 3:12 PM, RandallM randa...@fidmail.com wrote: answer me this riddle: Why do you chose to Hack IT? Defend IT? Shut IT -- been great, thanks RandyM a.k.a System -- silky GUERILLA TOP? Corpulent woodpecker, disorderly

Re: [Full-disclosure] [Code-Crunchers] a simple race condition and how you'd solve it

2009-07-02 Thread silky
, and, at the end of computation, if your data is still wanted.        Gadi. -- Gadi Evron, g...@linuxbox.org. Blog: http://gevron.livejournal.com/ -- noon silky http://lets.coozi.com.au/ ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-disclosure] Major Greek bank sites with SSL vulnerable to XSS and open redirects

2009-05-11 Thread silky
replying -- silky ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Major Greek bank sites with SSL vulnerable to XSS and open redirects

2009-05-11 Thread silky
On Mon, May 11, 2009 at 5:59 PM, valdis.kletni...@vt.edu wrote: On Mon, 11 May 2009 16:19:49 +1000, silky said: On Mon, May 11, 2009 at 10:33 AM, Paul Schmehl pschmehl_li...@tx.rr.com wrote: Everything is insecure by default. There is no such thing as secure by default. Those

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-03 Thread silky
Architecture for the Internet fergdawg(at)netzero.net ferg's tech blog: http://fergdawg.blogspot.com/ -- noon silky http://www.themonkeynet.com/armada/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure

Re: [Full-disclosure] Google Chrome Browser Vulnerability

2008-09-02 Thread silky
silky http://www.themonkeynet.com/armada/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Linus summarizes state of the security industry with precision and accuracy.

2008-08-15 Thread silky
Interview with Network World , 08/14/2008 http://www.networkworld.com/news/2008/081408-torvalds-security-circus.html [ ED: Dr. Diggle the Zoologist grunt / proctologist has lots of company, lol ] -- noon silky http://www.themonkeynet.com/armada/ http://www.themonkeynet.com

Re: [Full-disclosure] (:

2008-06-12 Thread silky
yet. like in the see i told you so fashion. maybe i've missed it. -- I)ruid, C²ISSP [EMAIL PROTECTED] http://druid.caughq.org -- silky http://www.boxofgoodfeelings.com/ http://www.themonkeynet.com/ http://lets.coozi.com.au/ ___ Full-Disclosure - We

Re: [Full-disclosure] n3td3v says don't let EUSecWest Cisco IOS presentation go ahead

2008-05-20 Thread silky
, or...) , and the company gets pwned by somebody with a rootkit. -- silky http://www.boxofgoodfeelings.com/ http://lets.coozi.com.au/ ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia

Re: [Full-disclosure] Ureleet

2008-05-01 Thread silky
On Fri, May 2, 2008 at 10:31 AM, Pat [EMAIL PROTECTED] wrote: Was there any reason for the both of you to include the mailing lists on your petty personal rants heretofore? dude, they're the same person. 2008/5/2 Ureleet [EMAIL PROTECTED]: -- http://lets.coozi.com.au/

Re: [Full-disclosure] Gmail 0day

2007-11-08 Thread silky
On 11/9/07, pdp (architect) [EMAIL PROTECTED] wrote: well this XSS can lead to so much data being stolen that it is not even funny! orly? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted

Re: [Full-disclosure] Gmail 0day

2007-11-08 Thread silky
worked for me minutes after it was posted. seems fixed now. On 11/9/07, crazy frog crazy frog [EMAIL PROTECTED] wrote: i tested it on gmail latest version,itsnot working for me? On Nov 8, 2007 7:04 AM, Scripter Hack [EMAIL PROTECTED] wrote: There is a html injection vulnerability in

Re: [Full-disclosure] Gmail 0day

2007-11-08 Thread silky
, 2007 10:00 PM, silky [EMAIL PROTECTED] wrote: On 11/9/07, pdp (architect) [EMAIL PROTECTED] wrote: well this XSS can lead to so much data being stolen that it is not even funny! orly? -- pdp (architect) | petko d. petkov http://www.gnucitizen.org -- mike http

[Full-disclosure] an open letter to kevin bacon: hello, how's it going?

2007-11-01 Thread silky
please, if you know kevin bacon, can you forward this mail to him, and have him reply to me? or at least if you know someone who you think might then know him, please send it on. i'm testing something. thanks. == hi kevin! it's mike!

Re: [Full-disclosure] !!! W4RN1NG N1GS und P1GZ !!!

2007-10-14 Thread silky
next week on animal planet: the mating habits of security noobs ... On 10/15/07, Dude VanVinkle [EMAIL PROTECTED] wrote: MISS DUDE VAN WINKLE, VALDIS KINIETIKZ AND GAY EVRON OFF OF THIS LIST NOW. GTFO PLZ U R RUINING THE INTERNET. -- mike http://lets.coozi.com.au/

Re: [Full-disclosure] extension for Firefox to force HTTPS always?

2007-10-13 Thread silky
on the google sites; customisegoogle lets you force them into ssl. but obviously that's not all sites. On 10/13/07, Kristian Erik Hermansen [EMAIL PROTECTED] wrote: So one example is that you are in a wifi cafe and you want to browse sites which may be available on both http and https. One

Re: [Full-disclosure] List of security conferences

2007-10-10 Thread silky
maybe this is of some use; i don't know https://www.google.com/calendar/embed?src=pe2ikdbe6b841od6e26ato0asc%40group.calendar.google.comgsessionid=BinzC1HQmHc On 10/10/07, Bernd Marienfeldt [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 [EMAIL PROTECTED] wrote:

Re: [Full-disclosure] In ur server-status

2007-07-21 Thread silky
wow. coolest thing ever. can't blame people. apache don't even disable it. http://www.apache.org/server-status nice find! On 7/22/07, Todd Troxell [EMAIL PROTECTED] wrote: Noticing lots of admins tend to forget about /server-status, I typed at random: http://www.cnn.com/server-status