[Full-disclosure] Unauthorized Digital Certificates Could Allow Spoofing

2012-06-04 Thread Georgi Guninski
http://technet.microsoft.com/en-us/security/advisory/2718704 Microsoft is aware of active attacks using unauthorized digital certificates derived from a Microsoft Certificate Authority. what does this mean? m$ inadvertently gave signing rights to lusers, they got rooted or something else?

Re: [Full-disclosure] [Full Disclosure] Unauthorized Digital Certificates Could Allow Spoofing

2012-06-04 Thread imipak
what does this mean? m$ inadvertently gave signing rights to lusers, they got rooted or something else? http://blogs.technet.com/b/srd/archive/2012/06/03/microsoft-certification-authority-signing-certificates-added-to-the-untrusted-certificate-store.aspx says: [..] certificates issued by

Re: [Full-disclosure] TrueCaller Vulnerability Allows Changing Users Details

2012-06-04 Thread Григорий Братислава
Paranoia. Thor I is always publicly share contacts: Adrian Lamo c/o DMH Vacavill Psychiatric Hospital Vacavill, CA (707) 449-6504 Hector Monsegur (480) 948-6377 ADDRESS IS WITHOLD John Paul (JP) 594 3rd St Beaver PA www.inspirosity.com (is Out of business moved into is Gay porn) Jesse Tuttle

Re: [Full-disclosure] Unauthorized Digital Certificates Could Allow Spoofing

2012-06-04 Thread Shreyas Zare
On Mon, Jun 4, 2012 at 7:21 PM, Georgi Guninski gunin...@guninski.com wrote: http://technet.microsoft.com/en-us/security/advisory/2718704 Microsoft is aware of active attacks using unauthorized digital certificates derived from a Microsoft Certificate Authority. what does this mean? m$

Re: [Full-disclosure] Unauthorized Digital Certificates Could Allow Spoofing

2012-06-04 Thread Juha-Matti Laurio
Certification path of the certificate that was used to sign WUSetupV.exe used by the Flame malware [pic]: https://twitter.com/#!/mikko/status/209620723973636096 Juha-Matti Shreyas Zare [shre...@secfence.com] wrote: On Mon, Jun 4, 2012 at 7:21 PM, Georgi Guninski gunin...@guninski.com wrote:

Re: [Full-disclosure] Full-Disclosure Digest, Vol 88, Issue 2 Re: NSA Cyber security program [ maybe off-topic ]

2012-06-04 Thread Mikhail A. Utin
-Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of full-disclosure-requ...@lists.grok.org.uk Sent: Saturday, June 02, 2012 7:00 AM To: full-disclosure@lists.grok.org.uk Subject: Full-Disclosure Digest, Vol

Re: [Full-disclosure] Unauthorized Digital Certificates Could Allow Spoofing

2012-06-04 Thread Joel Esler
This is related to the Flame malware. -- Joel Esler On Monday, June 4, 2012 at 9:51 AM, Georgi Guninski wrote: http://technet.microsoft.com/en-us/security/advisory/2718704 Microsoft is aware of active attacks using unauthorized digital certificates derived from a Microsoft Certificate

Re: [Full-disclosure] [Full Disclosure] Unauthorized Digital Certificates Could Allow Spoofing

2012-06-04 Thread Georgi Guninski
Thank you all for the information :) On Mon, Jun 04, 2012 at 03:06:41PM +0100, imipak wrote: what does this mean? m$ inadvertently gave signing rights to lusers, they got rooted or something else?

Re: [Full-disclosure] NSA Cyber security program [ maybe off-topic ]

2012-06-04 Thread Jack Slade
http://www.opm.gov/oca/12tables/indexgs.asp This is the site of the Federal pay scale. It generally matches what NSA pays, though NSA uses a little different schedule. If you scroll down to the Washington DC area list you'll see the adjusted scale for what is paid around Ft. Meade. The GS 9-11

[Full-disclosure] [SECURITY] [DSA 2481-1] arpwatch security update

2012-06-04 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2481-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez June 2, 2012

[Full-disclosure] [SECURITY] [DSA 2482-1] arpwatch security update

2012-06-04 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2482-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez June 2, 2012

[Full-disclosure] [SECURITY] [DSA 2482-1] libgdata security update

2012-06-04 Thread Yves-Alexis Perez
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2482-1 secur...@debian.org http://www.debian.org/security/ Yves-Alexis Perez June 2, 2012

[Full-disclosure] [SECURITY] [DSA 2484-1] nut security update

2012-06-04 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2484-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst June 02, 2012

[Full-disclosure] [SECURITY] [DSA 2485-1] imp4 security update

2012-06-04 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - - Debian Security Advisory DSA-2485-1 secur...@debian.org http://www.debian.org/security/ Thijs Kinkhorst June 3, 2012

[Full-disclosure] ISC Security Advisory: Handling of zero length rdata can cause named to terminate, unexpectedly

2012-06-04 Thread Larissa Shapiro
Original Message Subject:ISC Security Advisory: Handling of zero length rdata can cause named to terminate,unexpectedly Date: Mon, 04 Jun 2012 05:25:50 -0700 From: Larissa Shapiro laris...@isc.org To: bind-annou...@lists.isc.org ISC Security Advisory: Note:

Re: [Full-disclosure] Full-Disclosure Digest, Vol 88, Issue 2 Re: NSA Cyber security program [ maybe off-topic ]

2012-06-04 Thread Georgi Guninski
On Mon, Jun 04, 2012 at 10:45:52AM -0400, Mikhail A. Utin wrote: -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of full-disclosure-requ...@lists.grok.org.uk Sent: Saturday, June 02, 2012 7:00 AM

[Full-disclosure] Obama Order Sped Up Wave of Cyberattacks Against Iran

2012-06-04 Thread Jeffrey Walton
https://www.nytimes.com/2012/06/01/world/middleeast/obama-ordered-wave-of-cyberattacks-against-iran.html WASHINGTON — From his first months in office, President Obama secretly ordered increasingly sophisticated attacks on the computer systems that run Iran’s main nuclear enrichment facilities,

[Full-disclosure] EUSecWest 2012 - Amsterdam, Sept 19/20 featuring Mobile PWN2OWN - CFP Deadline June 15

2012-06-04 Thread Dragos Ruiu
EUSecWest 2012, Amsterdam, September 19/20, Featuring Mobile PWN2OWN CALL FOR PAPERS - Deadline June 15 2012    AMSTERDAM, Nederland -- The seventh annual EUSecWest    applied technical security conference - where the eminent    figures in the international security industry get    together share

Re: [Full-disclosure] Obama Order Sped Up Wave of Cyberattacks Against Iran

2012-06-04 Thread Joel Esler
So, a quote, from a book? Isn't that kinda circular? Also, there are no quotes from anyone in the room and no one is referenced except by association. Not saying it's not true, but there's nothing there that indicates it is. The only people who will know if this is 100% true were in the