[funsec] xkcd: Exploits of a Mom

2007-10-09 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 We love xkcd: http://xkcd.com/327/ Enjoy. :-) - - ferg p.s. Bonus: How xkcd inspired a major mapping of the Internet: http://www.networkworld.com/community/node/20390 Pretty freekin' cool. -BEGIN PGP SIGNATURE- Version: PGP Desktop 9.6

Re: [funsec] Image of the Day: 'Hello My Name Is Inigo Montoya'

2007-10-09 Thread Gadi Evron
inconceivable! On Tue, 9 Oct 2007, Paul Ferguson wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I know Gadi will love this. :-) http://laughingsquid.com/hello-my-name-is-inigo-montoya/ Enjoy. :-) - - ferg -BEGIN PGP SIGNATURE- Version: PGP Desktop 9.6.3 (Build 3017) wj8DBQFH

RE: [funsec] The false positive in McAfee GroupShield

2007-10-09 Thread Craig Schmugar
One man's false positive is another man's proactive protection. Looking at the driver, "Exploit-CVE2007-3845" is a bit too specific of a name for such a heuristic detection. But, I'm not overly concerned about it catching other exploit code. OK, the context may not be exactly right in this speci

[funsec] Odd-ball press release about CEO's inbox being "hacked"

2007-10-09 Thread rms
http://www.marketwire.com/mw/release.do?id=778715 Oct 09, 2007 09:08 ET PSPP Holdings, Inc. Warns Shareholders of Disinformation Campaign Conducted by Previous Management -- Company Also Clarifies Talking Points and Relationships LOS ANGELES, CA--(Marketwire - October 9, 2007) - PSPP Holdings, In

Re: [funsec] UK encryption key law

2007-10-09 Thread Dude VanWinkle
On 10/8/07, Rob, grandpa of Ryan, Trevor, Devon & Hannah <[EMAIL PROTECTED]> wrote: > http://ars.userfriendly.org/cartoons/?id=20071006&mode=classic Here is how: http://upload.wikimedia.org/wikipedia/en/thumb/1/15/Aurora_2.jpg/300px-Aurora_2.jpg ___ Fun

Re: cc: [funsec] "too beautiful not to share"

2007-10-09 Thread Dude VanWinkle
On 10/9/07, Brian Loe <[EMAIL PROTECTED]> wrote: > More non-news - New York is full of liberals. Woo-hoo! Only a country > bashing fool could take PRIDE in seeing a leader booed. > So you never boo'ed clinton? -JP ___ Fun and Misc security discussion f

Re: cc: [funsec] "too beautiful not to share"

2007-10-09 Thread Brian Loe
On 10/9/07, [EMAIL PROTECTED] <[EMAIL PROTECTED]> wrote: > Now this is the classical moronic views, attitudes, and conceptual capacity > of your current "Republican" government! > So you take offense to a Republic with a Republican form of government? Good. > Leak severs link to al-Qaeda's secre

cc: [funsec] "too beautiful not to share"

2007-10-09 Thread SDALAN04
Now this is the classical moronic views, attitudes, and conceptual capacity of your current "Republican" government! Leak severs link to al-Qaeda's secrets http://www.msnbc.msn.com/id/21186181/ Couldn't find the story on Rudy Giuliani getting booed at the Yankee Stadium yesterday. But found th

[funsec] 'What's the point of the .asia top-level domain?'

2007-10-09 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I love this quote: "In what must have domain registrars around the world rubbing their hands with glee and ordering new yachts, we now have another TLD that nobody can quite remember asking for (is it like the gherkin in a fastburger?) which will coin

[funsec] How Russia Became a Malware Hornet's Nest

2007-10-09 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Via SearchSecurity news. [snip] That Russia is a hornet's nest of malicious cyber activity is nothing new. The question for some in the information security community is why people from that part of the world are so determined to earn a living writin

[funsec] Australia: XSS Flaw Makes PM Say: 'I want to suck your blood'

2007-10-09 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Via ZDNet Australia. [snip] The Web sites of Australia's two major political parties contain cross-site scripting (XSS) flaws, which could be exploited to fraudulently acquire political donations, say security experts. A short line of script develop

Re: [funsec] The false positive in McAfee GroupShield

2007-10-09 Thread rms
I assumed that McAfee didn't like my Python code. What's wrong with Python? ;-) Richard > Yeah, it was posted to the whole list pointing to this Firefox exploit: > http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3845 > > Let's hope McAfee guys are reading. > > - Juha-Matti > > > [EMAIL PRO

Re: [funsec] The false positive in McAfee GroupShield

2007-10-09 Thread Juha-Matti Laurio
Yeah, it was posted to the whole list pointing to this Firefox exploit: http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2007-3845 Let's hope McAfee guys are reading. - Juha-Matti [EMAIL PROTECTED] wrote: This warning is kind of funny. I wonder what triggered the false positive in my origi

[funsec] Image of the Day: 'Hello My Name Is Inigo Montoya'

2007-10-09 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 I know Gadi will love this. :-) http://laughingsquid.com/hello-my-name-is-inigo-montoya/ Enjoy. :-) - - ferg -BEGIN PGP SIGNATURE- Version: PGP Desktop 9.6.3 (Build 3017) wj8DBQFHC9t1q1pz9mNUZTMRAhcaAKCSI8z64zrAvKLX93CvxiWnA8nbZwCfeQSa 65o

Re: [funsec] The false positive in McAfee GroupShield

2007-10-09 Thread John Payne
On Oct 9, 2007, at 3:02 PM, [EMAIL PROTECTED] wrote: This warning is kind of funny. I wonder what triggered the false positive in my original message. Funny in that everybody should now instantly point and laugh at [EMAIL PROTECTED] Whether or not there was a false positive is not the

Re: [funsec] The false positive in McAfee GroupShield

2007-10-09 Thread rms
This warning is kind of funny. I wonder what triggered the false positive in my original message. Richard > McAfee GroupShield™ Alert > > McAfee GroupShield discovered a problem with this email. If you do not > know the sender, it is probably a virus. If you do know the sender but > were not e

[funsec] McAfee GroupShield Alert

2007-10-09 Thread rand
McAfee GroupShield™ Alert McAfee GroupShield discovered a problem with this email. If you do not know the sender, it is probably a virus. If you do know the sender but were not expecting an attachment from them or the subject or message text "doesn't sound like something they would say," it is pr

[funsec] McAfee GroupShield Alert

2007-10-09 Thread rand
McAfee GroupShield™ Alert McAfee GroupShield discovered a problem with this email. If you do not know the sender, it is probably a virus. If you do know the sender but were not expecting an attachment from them or the subject or message text "doesn't sound like something they would say," it is pr

[funsec] Adobe confirms critical vulnerability after a remarkable delay

2007-10-09 Thread Juha-Matti Laurio
Adobe has provided information with a workaround related to critical code execution vulnerability reported by Mr. Petko D. Petkov (aka pdp) on 20 th Sep. http://www.gnucitizen.org/blog/0day-pdf-pwns-windows That was almost three weeks ago... The following advisory title states affected Acrobat

[funsec] Turkish hackers target Swedish sites

2007-10-09 Thread Juha-Matti Laurio
This was not covered on the list yet: CBC News: Turkish hackers target Swedish sites http://www.cbc.ca/technology/story/2007/10/08/turkey-hackers.html And the point is here: "Turkish hackers have targeted more than 5,000 Swedish websites since a Swedish newspaper published caricature of the Pro