Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-27 Thread Jonathan Roach
On Friday 25 April 2008 00:41, n3td3v wrote: > On Fri, Apr 25, 2008 at 12:22 AM, Ureleet <[EMAIL PROTECTED]> wrote: > > no, you idiot, i was telling you to quit threatening ppl. god you are > > thick. > > In Britian, we reject people like you. All the best at passport control. > >

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-25 Thread Ureleet
which you will do _nothing_ with. bye. On Fri, Apr 25, 2008 at 2:47 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Fri, Apr 25, 2008 at 3:51 PM, Jonathan Roach > <[EMAIL PROTECTED]> wrote: > > In Wales, we > > > > Thanks for letting me know you live in Wales. > > All the best, > > n3td3v > _

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-25 Thread n3td3v
On Fri, Apr 25, 2008 at 3:51 PM, Jonathan Roach <[EMAIL PROTECTED]> wrote: > In Wales, we Thanks for letting me know you live in Wales. All the best, n3td3v ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-c

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Fri, Apr 25, 2008 at 12:22 AM, Ureleet <[EMAIL PROTECTED]> wrote: > no, you idiot, i was telling you to quit threatening ppl. god you are > thick. In Britian, we reject people like you. All the best at passport control. ___ Full-Disclosure - We beli

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Ureleet
no, you idiot, i was telling you to quit threatening ppl. god you are thick. On Thu, Apr 24, 2008 at 7:19 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Fri, Apr 25, 2008 at 12:09 AM, Ureleet <[EMAIL PROTECTED]> wrote: > > are you again threatening us? in america, thats enuff to call the > police

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Fri, Apr 25, 2008 at 12:09 AM, Ureleet <[EMAIL PROTECTED]> wrote: > are you again threatening us? in america, thats enuff to call the police. > and no, i am not threatening to do so. I live in UK under British rule, all the best with the extradition. n3td3v __

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Ureleet
are you again threatening us? in america, thats enuff to call the police. and no, i am not threatening to do so. On Thu, Apr 24, 2008 at 5:57 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Thu, Apr 24, 2008 at 10:46 PM, nnp <[EMAIL PROTECTED]> wrote: > > On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread nnp
On Thu, Apr 24, 2008 at 10:57 PM, n3td3v <[EMAIL PROTECTED]> wrote: > On Thu, Apr 24, 2008 at 10:46 PM, nnp <[EMAIL PROTECTED]> wrote: > > On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > > High up government officials are backing Web Application Application > > > Secu

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread auto188821
>High up government officials are backing Web Application >Application >Security Awareness Day, so I would watch what you're saying. > > >-- Forwarded message -- >From: Richard Golodner <[EMAIL PROTECTED]> Oh noes! The great and powerful Richard Golodner (that none of us have ev

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Thu, Apr 24, 2008 at 10:46 PM, nnp <[EMAIL PROTECTED]> wrote: > On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > High up government officials are backing Web Application Application > > Security Awareness Day, so I would watch what you're saying. > > > > --

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread nnp
On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <[EMAIL PROTECTED]> wrote: > High up government officials are backing Web Application Application > Security Awareness Day, so I would watch what you're saying. > > -- Forwarded message -- > From: Richard Golodner <[EMAIL PROTECTED]> > D

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread malix
Kurt, You're right, such language isn't constructive, my apologies. n3td3v, Given Richard's extraordinary credentials (http://www.linkedin.com/pub/5/04B/758) I suggest you two team up and start a new consultancy: The Asshat Stikeforce! Then you can give each other a regular stroke, both literal

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Thu, Apr 24, 2008 at 10:24 PM, <[EMAIL PROTECTED]> wrote: > On Thu, 24 Apr 2008 22:13:09 BST, n3td3v said: > > > High up government officials are backing Web Application Application > > Security Awareness Day, so I would watch what you're saying. > > Can you cite an actual press release or o

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Ureleet
objection, speculation. On Thu, Apr 24, 2008 at 5:31 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Thu, Apr 24, 2008 at 10:24 PM, <[EMAIL PROTECTED]> wrote: > > On Thu, 24 Apr 2008 22:13:09 BST, n3td3v said: > > > > > High up government officials are backing Web Application Application > > > S

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Ureleet
so did u or didnt u cancel it? please make up ur mind so we know whether to post anything on may 1 or not. i support the "take a day off from fd" day on may 1. On Thu, Apr 24, 2008 at 4:32 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Thu, Apr 24, 2008 at 5:49 PM, David Litchfield > <[EMAIL PROTE

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Ureleet
did u just threaten everyone? and for furthermore, did that richard dude just threaten everyone? nice move. i am sure richard didnt want his personal email posted to the list, thats why he sent it directly to you. On Thu, Apr 24, 2008 at 5:13 PM, n3td3v <[EMAIL PROTECTED]> wrote: > > On Thu, Ap

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Valdis . Kletnieks
On Thu, 24 Apr 2008 22:13:09 BST, n3td3v said: > High up government officials are backing Web Application Application > Security Awareness Day, so I would watch what you're saying. Can you cite an actual press release or other similar thing from anybody other than yourself? Pretty wimpy-ass back

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Thu, Apr 24, 2008 at 9:58 PM, Kurt Dillard <[EMAIL PROTECTED]> wrote: > I wouldn't use such harsh language as Malix, but he's correct. David has > done a lot of ground-breaking research over the past decade and he's had a > major impact on how Microsoft and Oracle create, test, and patch their

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread Kurt Dillard
l-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection On Thu, Apr 24, 2008 at 9:47 PM, <[EMAIL PROTECTED]> wrote: > And here I thought you were canceling that piece of shit. > That you even presume to believe that David Litchfield of all > people gives the slig

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Thu, Apr 24, 2008 at 9:47 PM, <[EMAIL PROTECTED]> wrote: > And here I thought you were canceling that piece of shit. > That you even presume to believe that David Litchfield of all > people gives the slightest fuck about what you have to say simply > blows my mind. > As always, please (and

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread malix
And here I thought you were canceling that piece of shit. That you even presume to believe that David Litchfield of all people gives the slightest fuck about what you have to say simply blows my mind. As always, please (and let me spell it out for you), SHUT THE FUCK UP. On Thu, 24 Apr 2008 13:

Re: [Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread n3td3v
On Thu, Apr 24, 2008 at 5:49 PM, David Litchfield <[EMAIL PROTECTED]> wrote: > Hey all, > I've just released some research that demonstrates a new class of > vulnerability in Oracle and how it can be exploited by an attacker. You can > grab the paper from here: > http://www.databasesecurity.com

[Full-disclosure] A New Class of Vulnerability in Oracle: Lateral SQL Injection

2008-04-24 Thread David Litchfield
Hey all, I've just released some research that demonstrates a new class of vulnerability in Oracle and how it can be exploited by an attacker. You can grab the paper from here: http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf Cheers, David Litchfield NGSSoftware Ltd http://www.ngssof