Re: [Full-Disclosure] wireless sniffing question

2004-12-04 Thread Cedric Blancher
Le samedi 04 décembre 2004 à 03:09 -0500, question question a écrit : Lets say I have a Linksys (or whichever brand you like) wireless router with a wireless host using 128 bit WEP encryption, and a wired host connected to the same device. Obviously it is possible for the wired box to do

Re: [Full-Disclosure] MacOSX -FreeBSD

2004-12-04 Thread Stephen Menard
Danny wrote: There is a security update, I just noticed it. Security Update 2004-12-02 delivers a number of security enhancements and is recommended for all Macintosh users. This update includes the following components: Apache AppKit HIToolbox Kerberos Postfix PSNormalizer Safari Terminal For

Re: [Full-Disclosure] secret message time

2004-12-04 Thread Gadi Evron
I agree, 100%. Gadi. Owned You wrote: -BEGIN PGP MESSAGE- Version: GnuPG v1.2.2 (FreeBSD) jA0ECgMC+39cEh21cmFg0ukBthgejpwkGVe/V+MhzCsx2/vhWD7YsiurLVQpH4m7 zvX4pOfp0ax8jp5LEQplnCry7ySd2l2BMnejz77YsZqHPNUe9g9yTwwLfg5jWo+q

Re: [Full-Disclosure] MacOSX -FreeBSD

2004-12-04 Thread Stephen Menard
On 2-Dec-04, at 3:32 PM, Randall Craig wrote: On Thu, 2 Dec 2004 10:58:02 -0600, Randall Craig [EMAIL PROTECTED] wrote: Ok I am super duper new to this list and also new to *nix... i will never go back to M$ ceptin for gaming purposes... I am running on OS

Re: [Full-Disclosure] I'm calling for LycosEU heads and team to resign or be sacked

2004-12-04 Thread Chris Umphress
On Fri, 3 Dec 2004 21:52:30 +, n3td3v [EMAIL PROTECTED] wrote: The argument that Lycos EU are not DDos'ing is not washable. Its DDoS plain and simple. Of course it's a form of DDoS. But who started it? Remember, Lycos provides e-mail services which the spammers have been taking advantage

Re: [Full-Disclosure] MacOSX -FreeBSD

2004-12-04 Thread Stephen Menard
from Apple's web Darwin Mac OSX Opensource Pages http://www.apple.com/opensource/ Mach 3.0 Kernel AND FreeBSD kernel (portions) 4.8 BSD FreeBSD libraries (libc) 5.0/5.1 BSD It has been mentioned OS X doesn't use procfs UNVERIFIED THIS May indicate Heavy Lifting required when bug

Re: [Full-Disclosure] I'm calling for LycosEU heads and team to resign or be sacked

2004-12-04 Thread Pavel Kankovsky
On Fri, 3 Dec 2004, n3td3v wrote: It is and never will be an acceptable and effective way to beat spam or any other misuse of the internet. [...] Spammers and hax0rs will not allow Lycos EU to build its bot network of screensavers, if and when the site comes back online again. Why would they

Re: [Full-Disclosure] secret message time

2004-12-04 Thread J.A. Terranson
On Sat, 4 Dec 2004, Gadi Evron wrote: I agree, 100%. Maybe - it was a little long winded: hard to tell if he really *meant* it or not... Gadi. Owned You wrote: -BEGIN PGP MESSAGE- Version: GnuPG v1.2.2 (FreeBSD)

Re: [Full-Disclosure] What to do with bot networks

2004-12-04 Thread Ron DuFresne
On Fri, 3 Dec 2004, Conor Sibley wrote: It all started yesterday when one of my servers got hacked. An ssh phisher got lucky and found an account with a weak password open on my server. Two shellcode attempts later they had full access via root. They ran a super scanner and started an

[Full-Disclosure] Re: Phpbb id: 10701 update and Attachmodule add-on Directory Traversal

2004-12-04 Thread ntx0f
Instead of just injecting mysql commands you can use system(); to virtually execute any command you want. here's some examples i've already tested : system(ls -l); -- %2527%252esystem(chr(108)%252echr(115)%252echr(32)%252echr(45)%252echr(108)) %252echr(59)%252e%2527 system(uname

RE: [Full-Disclosure] If Lycos can attack spammer sites, can we all start doing it?

2004-12-04 Thread Michael R. Schmidt
Have you read the Geneva Convention? Or better yet The United Nations International Covenant on Civil and Political Rights. Read it, the whole thing, and then bitch and moan. Do you really think Terrorists live by it? Article 7 No one shall be subjected to torture or to cruel, inhuman or

Re: [Full-Disclosure] I'm calling for LycosEU heads and team to resign or be sacked

2004-12-04 Thread Devdas Bhagat
On 05/12/04 01:06 +0100, Pavel Kankovsky wrote: snip (*) For instance, one of our servers was joe-jobbed in June. The poor machine was unable to handle the extra traffic (400-500 mails/hour) and per hour? Try a few thousand per minute. http://nixcartel.org/~devdas/minute.png (those are real