Re: [Full-disclosure] Hacking The Interwebs

2008-01-15 Thread Fredrick Diggle
The following is a interview Fred Diggle Security conducted with the great researcher pdp (architect). In it he discloses some of his elite 0day research as well as his thoughts on the future of security and XSS. This should be published in phrack for sure. fred diggle: Hello to the pdp

Re: [Full-disclosure] Hacking The Interwebs

2008-01-15 Thread Ed Carp
So ... pdp is an emotionally immature kid who hacks JS because it's easy and likes to pretend that he knows something. So what ... nothing to see here, folks, move on... The more complex the system, the more holes people will find ... why is that such a big revelation for folks? Why pat

Re: [Full-disclosure] Hacking The Interwebs

2008-01-15 Thread reepex
On 1/13/08, pdp (architect) [EMAIL PROTECTED] wrote: The most malicious of all malicious things to do when a device is compromised via the attack described in the link pointed at the top of this email, is to change the primary DNS server. That will effectively turn the router and the network

[Full-disclosure] Hacking The Interwebs

2008-01-13 Thread pdp (architect)
http://www.gnucitizen.org/blog/hacking-the-interwebs When the victim visits a malicious SWF file, a 4 step ATTACK will silently execute in the background. At that moment the attacker will have control over their router, pretty much regardless of its model. *Many of the home routers are vulnerable