[funsec] InfoSec: Food for Thought

2008-12-29 Thread Paul Ferguson
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Enjoy. http://haftofthespear.com/2008/12/food-for-thought/ - - ferg -BEGIN PGP SIGNATURE- Version: PGP Desktop 9.6.3 (Build 3017) wj8DBQFJWZnjq1pz9mNUZTMRAueOAJ9o+NQIhO0BoVyBTgg8q5CEQQWLpgCg3YSC JDciWoZihRhwJh1jvfMHczE= =fz80 -END PGP S

Re: [funsec] reliable IOS exploitation

2008-12-29 Thread Gadi Evron
On Mon, 29 Dec 2008, Charles Miller wrote: > Geez, first Sotirov and Appelbaum's mystery talk and now this. How come > nobody told me CCC "the" big conference?! Always was :) > Charlie > > > On Dec 29, 2008, at 5:12 PM, Gadi Evron wrote: > >> FX has given a comprehensive talk about IOS exploit

Re: [funsec] reliable IOS exploitation

2008-12-29 Thread Charles Miller
Geez, first Sotirov and Appelbaum's mystery talk and now this. How come nobody told me CCC "the" big conference?! Charlie On Dec 29, 2008, at 5:12 PM, Gadi Evron wrote: > FX has given a comprehensive talk about IOS exploitation (including > even TCL > scripts operators leave behind when th

[funsec] reliable IOS exploitation

2008-12-29 Thread Gadi Evron
FX has given a comprehensive talk about IOS exploitation (including even TCL scripts operators leave behind when they moved jobs to retain access). He has shown effective and ineffective ways of detecting compromise in IOS. Then, he has shown how reliable exploitation of IOS routers works. His

Re: [funsec] Windows 7 Beta review link

2008-12-29 Thread Daniel H. Renner
I don't see Corporate business being won over by Win v7 unless the intrusive 'Content Protection', as in media degradation/re-structure (http://www.cs.auckland.ac.nz/~pgut001/pubs/vista_cost.html) and the ability to collect data by any 3rd party included in Microsoft's club (see the Vista EULA

Re: [funsec] Windows 7 Beta review link

2008-12-29 Thread Larry Seltzer
>> Just Vista SP2, really... Lots of truth in this. Most of the praise for Win7 seems to me less about Win7 itself than as a swipe at Vista. In fact little that people criticize in Vista will change in Win7, it's just that Vista "took one for the team" by forcing driver developers to catch up, for

Re: [funsec] Windows 7 Beta review link

2008-12-29 Thread Alex Eckelberry
Just Vista SP2, really... -Original Message- From: funsec-boun...@linuxbox.org [mailto:funsec-boun...@linuxbox.org] On Behalf Of Juha-Matti Laurio Sent: Monday, December 29, 2008 7:09 AM To: funsec@linuxbox.org Subject: [funsec] Windows 7 Beta review link At Paul Thurrott's SuperSite for

[funsec] Windows 7 Beta review link

2008-12-29 Thread Juha-Matti Laurio
At Paul Thurrott's SuperSite for Windows: http://www.winsupersite.com/win7/win7_beta.asp Juha-Matti ___ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.

Re: [funsec] store.apple.com XSS reported

2008-12-29 Thread Martin Tomasek
Juha-Matti Laurio napsal(a): > Mirror at > http://www.xssed.com/mirror/55985/ > > Unfixed at time of writing this. > iXSS in iStore.. ___ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec

[funsec] store.apple.com XSS reported

2008-12-29 Thread Juha-Matti Laurio
Mirror at http://www.xssed.com/mirror/55985/ Unfixed at time of writing this. Juha-Matti ___ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-bin/mailman/listinfo/funsec Note: funsec is a public and open mailing list.

[funsec] E-mails reveal Cho's troubles at Virginia Tech

2008-12-29 Thread Juha-Matti Laurio
More at http://www.washingtonpost.com/wp-dyn/content/story/2008/12/19/ST2008121903422.html and http://www.collegiatetimes.com/stories/2008/12/18/e-mails_sent_to_cho Juha-Matti ___ Fun and Misc security discussion for OT posts. https://linuxbox.org/cgi-