Re: [Full-Disclosure] Administrivia: Fool Disclosure

2004-11-15 Thread Gerry Eisenhaur
still feeling paranoid. | | http://tinypic.com/lzj1j | - -- +--+ | Gerry Eisenhaur | || | Cisco Security Agent ||| ||| | | Boxborough, Massachusetts.|. .|. | | PGP Key

Re: FW: [Full-Disclosure] JPEG AV Detection

2004-09-28 Thread Gerry Eisenhaur
After looking in to what the AV companies base their signature on, it appears that they use the \xff\xfe\x00\x00 or \xff\xfe\x00\x01 string in the vulnerable JPEG. If you change the size to a valid size, the AV is not triggered. I know there is some talk about other sections being vulnerable

Re: [Full-Disclosure] Automated ssh scanning

2004-08-26 Thread Gerry Eisenhaur
Yea I boned it, I missed the point. For some reason (read: lack of sleep and food), I miss-read/assumed that admin was an admin...stupid me... /gerry Tig wrote: On Wed, 25 Aug 2004 19:43:47 -0400 Gerry Eisenhaur [EMAIL PROTECTED] wrote: I am confused, you said you knew about some SSH scanning

Re: [Full-Disclosure] Automated ssh scanning

2004-08-25 Thread Gerry Eisenhaur
I am confused, you said you knew about some SSH scanning going on, then set up those accounts on a box. Now you are curious way that box got rooted? Maybe I am missing something, but it seems you already have a pretty good assumption of why it got rooted. The software, as you seem to know, is