[Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread gyrniff
After acquiring and installing a copy of 'Windows Server 2003 Standard Edition 180-Day Evaluation' I walked through the 'role wizard', used the 'custom role config' and selected everything ;-) After reboot the server made two POST request to microsoft controlled webserveres without any

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread martin scherer
might get caught using an illegal copy of a win2003 server? yup. - Original Message - From: gyrniff [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, August 04, 2003 11:57 AM Subject: [Full-Disclosure] Microsoft win2003server phone home After acquiring and installing a copy

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Gaurav Kumar
ot; [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, August 04, 2003 3:27 PM Subject: [Full-Disclosure] Microsoft win2003server phone home After acquiring and installing a copy of 'Windows Server 2003 Standard Edition 180-Day Evaluation' I walked through the 'role wizard', used the 'custom r

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread manohar singh
] Microsoft win2003server phone home After acquiring and installing a copy of 'Windows Server 2003 Standard Edition 180-Day Evaluation' I walked through the 'role wizard',  used the 'custom role config' and selected everything ;-) After reboot the server made two POST request to microsoft

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Gaurav Kumar
) =-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-=-= - Original Message - From: manohar singh [EMAIL PROTECTED] To: Gaurav Kumar [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Sent: Monday, August 04, 2003 5:52 PM Subject: Re: [Full-Disclosure] Microsoft win2003server phone home jeeesus, where's the manager? someone throw these kiddies

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Orochford
oliver rochford - Original Message From: Gaurav Kumar [EMAIL PROTECTED] To: manohar singh [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Re: [Full-Disclosure] Microsoft win2003server phone home Date: 04/08/03 09:44 jeeesus, where's the manager? someone throw these kiddies out

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Mike Garegnani
- From: gyrniff [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Monday, August 04, 2003 3:27 PM Subject: [Full-Disclosure] Microsoft win2003server phone home After acquiring and installing a copy of 'Windows Server 2003 Standard Edition 180-Day Evaluation' I walked through the 'role wizard', used

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Matthew Murphy
Mike Garegnani writes: [snip] all that was posted was a guid, and not to mention it was a 404 so aside from your post showing up somewhere in a log it won't be used or even seen for that matter. but it certainly can be a security issue. [snip] Um, since when did 404's guarantee that data

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Valdis . Kletnieks
On Mon, 04 Aug 2003 13:15:26 +0200, martin scherer [EMAIL PROTECTED] said: 3. Could it be considered as a security risk to let a newly installed server, request information from an arbitrary server that I have no control over ? security in the way that your server might end up getting

RE: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Jason Coombs
[EMAIL PROTECTED] -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] Behalf Of [EMAIL PROTECTED] Sent: Monday, August 04, 2003 8:43 AM To: martin scherer Cc: [EMAIL PROTECTED] Subject: Re: [Full-Disclosure] Microsoft win2003server phone home On Mon, 04 Aug 2003 13:15:26

Re: [Full-Disclosure] Microsoft win2003server phone home

2003-08-04 Thread Valdis . Kletnieks
On Mon, 04 Aug 2003 10:37:20 -1000, Jason Coombs said: Closing down *most* of these exposures is why the 'rpm' package manager supports using PGP to sign the packages... You *do* realize that digital signatures can be forged with theft of private keys, right? Yep, fully aware of that. On