Re: [Full-Disclosure] overburning edit of molded cdroms feasible?

2004-11-30 Thread Phillip R. Paradis
Saber Taylor wrote: Scenario: chinese agent buys molded cdroms from stores in Washington D.C. and overburns new data along the same spiral with a specialized cdrom drive. Returns the cdroms to the story which then re-shrinkwraps and puts back on the shelf. 1.) Is this possible? 2.) Could firmware

RE: [Full-Disclosure] IE is just as safe as FireFox

2004-11-25 Thread Phillip R. Paradis
Nice ...fresh from the oven too. This, if it works, should be a 'extremely critical' update from Ms. Wouldn't such a tool be of limited utility, given that the unpriviliged application's windows are on the same desktop as, and can therefore send messages to, windows belonging to

RE: [in] Re: [Full-Disclosure] IE is just as safe as FireFox

2004-11-23 Thread Phillip R. Paradis
either use sudo or su to do work as root, but Windows doesn't make users the admin by default *either*, unless you setup Fast User Switching *during* the install. Windows XP doesn't allow that to be selected during installation. It is activated or not based on available system memory

RE: [Full-Disclosure] Windows user privileges

2004-11-23 Thread Phillip R. Paradis
1. XP would be more suitable to run as a user if the runas service and windows installers were developed to add more complete and easy to use privilege elevation techniques outside of active directory and the default group policy that gets applied. ... 4. The windows install creates the first

RE: [Full-Disclosure] Windows user privileges

2004-11-23 Thread Phillip R. Paradis
is that windowed applications do not get polled for refresh, so for example using an explorer instance in a runas will not update the file listing until you press F5 I have witnessed bad things come of this Are we able to run Explorer.exe using runas utility... Yes, but it won't do much

RE: [Full-Disclosure] Slightly off-topic: www.georgewbush.com

2004-11-05 Thread Phillip R. Paradis
NOTHING is more fucked up than the US election. Not even Microsoft? Sad, but true. ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

RE: [Full-Disclosure] RE: Vulnerability in IBM Windows XP: default hidden Administrator account allows local Administrator access

2004-09-17 Thread Phillip R. Paradis
2) if you knew about it, and wanted to change it, they told you that you would lose data if you did! Amazingly enough, they are telling the truth. Security-related information for that account, such as personal certificates, saved passwords, etc., are deleted if the password is reset. Because

RE: [Full-Disclosure] RE: Vulnerability in IBM Windows XP: default hidden Administrator account allows local Administrator access

2004-09-17 Thread Phillip R. Paradis
I guess that means If you call IBM support and you have changed your local administrator password to anything other than blank, then we may not be able to help you out of the bind you have gotten yourself into (data loss). See my prior post. To change the password without losing the

RE: [Full-Disclosure] SP2 is killing me. Help?

2004-08-12 Thread Phillip R. Paradis
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of xtrecate Ultimately what difference to an end user does it make if the applications are broken by a service pack install or a virus? None at all. But the user has control over installing service

RE: [Full-Disclosure] Imaging Operating Systems

2004-05-28 Thread Phillip R. Paradis
Ghost won't work (IIRC) on unknown OS types as it ony copies used data blocks. Netcat does a binary copy and does not care what OS or data... Not sure about newer versions of Ghost, but I know some older versions will copy unknown partition types just fine; it merely does a bitwise copy of

RE: [Full-Disclosure] C# Web application security scanner

2004-05-20 Thread Phillip R. Paradis
Do you have any reason to believe Our tools are written in C# will be of any help in making a sale? With the right brochures, a few buzzwords and some pretty screen shots, of course it would. Too many holders of corporate checkbooks are insufferably clueless about technology, and would easily

RE: [Full-Disclosure] Microsoft plans tighter security measures in Windows XP SP2

2003-11-02 Thread Phillip R. Paradis
My Windows XP Professional EULA (which I never assented to because it was installed on machine when I got it and only my cat ever hit the OK button. Sue him). It seems to indicate there is no problem with VNC as long as only one user at a time is accessing the machine remotely. For a

RE: [Full-Disclosure] Re: Do you really think CDs will be protected in future?

2003-10-09 Thread Phillip R. Paradis
And since you asked for my opinion, (although I know I will get flamed for this) I think the recording industry does have a case. I have seen many a music lover who never bought any CDs. But they are going about it in a wrong way. What they need to do is this: I agree that they do have a

RE: [Full-Disclosure] Re: Do you really think CDs will be protected in future?

2003-10-09 Thread Phillip R. Paradis
-Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Sent: Thursday, October 09, 2003 3:04 PM To: Phillip R. Paradis Cc: [EMAIL PROTECTED] Subject: Re: [Full-Disclosure] Re: Do you really think CDs will be protected in future? On Thu, 09 Oct 2003 13:41:40 EDT