Re: [Full-Disclosure] Spyware installs with no interaction in IE on fully patched XP SP2 box

2004-10-03 Thread Joel R. Helgeson
What was the site? Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." - Original Message - From: "Geraldo Rivera&quo

Re: [Full-Disclosure] XP Remote Desktop Remote Activation

2004-10-02 Thread Joel R. Helgeson
If someone installs a backdoor, that can be detected by AV scanner. If you gain temporary shell, open up the management interface, you'll have full control of the box without anyone becoming the wiser. Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation &q

[Full-Disclosure] 6 gmail invites - contact off list

2004-09-13 Thread Joel R. Helgeson
Email me off list at [EMAIL PROTECTED] for your free invite.   Joel R. HelgesonDirector of Networking & Security ServicesSymetriQ Corporation   "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life."

Re: [Full-Disclosure] Erasing a hard disk easily

2004-07-14 Thread Joel R. Helgeson
someone is going to go through those pains to recover the data then there are much easier ways to hack into/gain access to your secrets. FWIW... Regards, Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set

[Full-Disclosure] Top 15 Reasons Why Admins Use Security Scanners

2004-04-28 Thread Joel R. Helgeson
computers on my network, that are not within compliance? -How do I report to Management that we have done all we could to lock down? -How do I detect unknown and/or rogue devices/connections? Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire,

[Full-Disclosure] Cisco LEAP exploit tool...

2004-04-10 Thread Joel R. Helgeson
"Just a day after Cisco released a security warning about its WLSE access point management tool, a tool to crack wi-fi networks using LEAP authentication has been released, reports Wi-Fi Networking News. The tool, called Asleap and developed by Beyond-Security, actively de-authenticates user

Re: [Full-Disclosure] MCSE training question

2004-04-05 Thread Joel R. Helgeson
that he can put into his resume' to spice it up... I always thought the default MCSE logo was a bit booring so I spiced it up. Give it to your friend, or do whatever you wish with it. I'll attach it to this message (mcse.gif). Enjoy... 8o) Joel R. Helgeson Director of Networ

[Full-Disclosure] Windows 2000 Source code .torrent

2004-02-13 Thread Joel R. Helgeson
Click here, then OPEN the file: http://torrent.spyderlake.com/download.php?info_hash=f03fc1e04869294d5644d3c8c5d0fb8f2d26aa59 If you aren't familiar with Bit Torrent, Shame on you. Download it here: http://bitconjurer.org/BitTorrent/ Joel R. Helgeson Director of Networking & Security

Re: [Full-Disclosure] MyDoom virus sent is an earlier message with subject "Error"

2004-02-08 Thread Joel R. Helgeson
Hell yeah, I just got BOMBARDED with a couple hundred bounce messages from the MyDoom Virus, and I can say without question that I am not, nor have I ever been infected with th e MyDoom Virus. Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man

Re: [Full-Disclosure] Doom virus: (Upon posting)

2004-01-27 Thread Joel R. Helgeson
1) It spoofs the from: field - therefore it could show as coming from anyone. 2) If someone opens the virus, it will propegate to all addresses in the victims address book. If FD is in your address book, it'll send a copy to the list - which has happened several times. Joel R. Helgeson Dir

[Full-Disclosure] IE Unpatched Vuln Site?

2003-12-10 Thread Joel R. Helgeson
I remember there being a website that was dedicated to publishing information about unpatched IE vulnerabilities.  I also seem to recall that the site was voluntarily shut down at the request of Microsoft for a period of time?   Can anyone offer any detail about this issue?  What is/was the

Re: [Full-Disclosure] Wireless Security

2003-11-28 Thread Joel R. Helgeson
se. I am not a paid endorser of any product, nor do I have any financial interest in any wireless gateway company. I'm pretty sure they can now export the product overseas. Regards, Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire

Re: [Full-Disclosure] The Birth Of A Gay Slut

2003-11-23 Thread Joel R. Helgeson
There once was a sailor from Brighton, who said to his girl "yer a tight one!"; She said, " 'pon my soul, but yer in the wrong hole, there's plenty of room in the right one!" Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "

Re: [Full-Disclosure] TinyURL

2003-10-29 Thread Joel R. Helgeson
name and password to the entire web!! Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." - Original Message - From: "T

Re: [Full-Disclosure] TinyURL

2003-10-29 Thread Joel R. Helgeson
ecode Looks like they wanted to get someone into their site, but didn't want to actually 'give' the username and password out, so they tinyurl'ed it. Someone wanna perl script it and find a goldmine it all out? Joel R. Helgeson Director of Networking & Security Services Syme

Re: [Full-Disclosure] TinyURL

2003-10-29 Thread Joel R. Helgeson
That reminds me of a joke: What do you call a prostitute with a runny nose? ... Full! > Another from Tinyurl... > > From News.COM.AU: > "War stress wears out prostitutes" > http://tinyurl.com/49b > > And we thought we had it hard... ___ Full-Disc

[Full-Disclosure] TinyURL

2003-10-29 Thread Joel R. Helgeson
e string. Thoughts? Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." ___ Full-D

Re: [Full-Disclosure] OT: An odd question that has arrisen within my household

2003-10-12 Thread Joel R. Helgeson
tools with precision Tier III - "Script Kiddies" - Inexpert - Ability to download exploit code and tools - Very little understanding of the actual vulnerability (launching Linux attacks against MS boxes) - Randomly fire off scripts until something works Joel R. Helgeson Director of

Re: [Full-Disclosure] Internet Explorer (BAN IT !!!)

2003-10-08 Thread Joel R. Helgeson
e? LOL, Just kidding... Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." - Original Message - From: "Stephen" <[

Re: [Full-Disclosure] IE Changes / Software Patents

2003-10-08 Thread Joel R. Helgeson
Does anyone care to wager how many security vulnerabilities Microsoft will create by making this change? Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for t

[Full-Disclosure] Email Harvesting virus?

2003-10-06 Thread Joel R. Helgeson
I came across an intersting event today. I haven't been able to research it as much as I'd like, but I'd like to toss it out to the community just the same.   A customers machine appears to be infected with some type of malware that apparently harvests email addresses and puts them into a fi

Re: [Full-Disclosure] Electronic Crimes Act 2003 of Pakistan

2003-10-04 Thread Joel R. Helgeson
Its not any worse than the DMCA... Joel R. Helgeson Director of Networking & Security Services SymetriQ Corporation "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." - Original Message - From: "mo

Re: [Full-Disclosure] NINCOMPOOPERY OF MICROSOFT

2003-10-01 Thread Joel R. Helgeson
Well, it goes like this: If you kill 1 man, you're a murderer Kill 20, and you're a mass-murderering maniac. Kill 6 million, and you're a revolutionary. - Original Message - From: "Georgi Guninski" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wednesday, October 01, 2003 2:06 PM Subje

[Full-Disclosure] explorer.exe on port 1024 tcp

2003-09-12 Thread Joel R. Helgeson
sPort Proto Path 432 Explorer -> 1024 TCP C:\WINDOWS\Explorer.EXE 432 Explorer -> 123 UDP C:\WINDOWS\Explorer.EXE 4 System -> 123 UDP Any insight into this would be appreciated. Joel R. Helgeson "Give a man fire, and he'll be w

Re: [Full-Disclosure] Tracking a virus by logging infected machines

2003-09-02 Thread Joel R. Helgeson
Why would any virus writer do this? This leads a clear audit trail that would lead the authorities directly back to the creator. I suppose it wouldn't be a bad thing if the virus author was looking for some free room & board for the next 5-10 years. Joel R. Helgeson Director of N

Re: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1052 - 29 msgs

2003-08-21 Thread Joel R. Helgeson
#2 - Original Message - From: "Arthur Corliss" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 21, 2003 3:11 PM Subject: [Full-Disclosure] Re: Full-Disclosure digest, Vol 1 #1052 - 29 msgs > > Date: Thu, 21 Aug 2003 10:43:02 -0700 > > From: Chris Cappuccio <[EMAIL PROT

Re: [Full-Disclosure] TCP port 25 traffic?

2003-08-16 Thread Joel R. Helgeson
Title: TCP port 25 traffic? Yeah, I think its called SPAM, not new though Try connecting to your server via telnet on port 25 and see if you can get an interactive connection.   type in the following commands: expn vrfy   and see if they are accepted.  If so, your server is open to possib

Re: [Full-Disclosure] Execution Flow Control (EFC)

2003-08-16 Thread Joel R. Helgeson
How exactly does this differ from any other Host based IDS system? - Original Message - From: "Shanphen Dawa" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, August 16, 2003 7:13 AM Subject: [Full-Disclosure] Execution Flow Control (EFC) > This was posted to bugtraq. > > http

Re: [Full-Disclosure] Red Bull Worm

2003-08-14 Thread Joel R. Helgeson
<[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, August 07, 2003 11:47 AM Subject: Re: [Full-Disclosure] Red Bull Worm > Joel R. Helgeson wrote: > > Lets see, the last big worm to exploit windows was named Code Red after the > > Mountain Dew Code Red was brought to m

[Full-Disclosure] Red Bull Worm

2003-08-14 Thread Joel R. Helgeson
Lets see, the last big worm to exploit windows was named Code Red after the Mountain Dew Code Red was brought to market. Being that this worm is much more effective than Code Red ever was, I say worm should be named Red Bull as it is sure to exhibit much more energy than the Code Red worm. O

Re: [Full-Disclosure] Vulnerability Disclosure Debate

2003-08-14 Thread Joel R. Helgeson
> > Also, full disclosure, including exploit code, frees you from the > > obligation to believe in software vendor advisories and patches - > > another critical issue, demonstrated again by the RPC/DCOM flaw: > > Exploit code *does not* solve the problem. I can do just as well by > providing no c

Re: [Full-Disclosure] Vulnerability Disclosure Debate

2003-08-09 Thread Joel R. Helgeson
If they did that, how could we write NESSUS plugins that would accurately scan for vulnerabilities? I say it'll never happen. Full Disclosure is the way to go. Managing security by applying patches is fundamentally flawed. The programmers need to write secure code. The onus is on them, not us.

Re: [Full-Disclosure] Win-Trap captured DCOM-RPC exploit code, on the spot!

2003-07-27 Thread Joel R. Helgeson
Advertise your products in a magazine. Don't come here for free advertising. Go fuck yourselves and your stupid product, we don't care! "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." - Original Message - From: "Executable Se

Re: [Full-Disclosure] Win32 Cisco Exploit

2003-07-24 Thread Joel R. Helgeson
I just tested it against one of my test cisco routers. nuthin happened. "Give a man fire, and he'll be warm for a day; set a man on fire, and he'll be warm for the rest of his life." - Original Message - From: "amilabs" <[EMAIL PROTECTED]> To: "'amilabs'" <[EMAIL PROTECTED]>; <[EMAIL PROT