Re: [Full-disclosure] University of Central Florida Multiple LFI

2011-02-20 Thread Hack Talk
institutions - I have had many similar experiences. On Sat, Feb 19, 2011 at 5:54 PM, Hack Talk hacktalkb...@gmail.com hacktalkb...@gmail.com wrote: Weev, I actually know many of the techrangers who are UCF employed students which are in charge of maintaining websites and have spoken to them

Re: [Full-disclosure] University of Central Florida Multiple LFI

2011-02-19 Thread Hack Talk
...@gmail.comwrote: http://chemistry.cos.ucf.edu/belfield/index.php?page=../../../../../../../../../../../../../../../etc/passwd%00 On Sat, Feb 19, 2011 at 11:38 AM, Hack Talk hacktalkb...@gmail.comwrote: Found these and thought I'd share: -==- http://excel.ucf.edu

Re: [Full-disclosure] University of Central Florida Multiple LFI

2011-02-19 Thread Hack Talk
about removing it so people aren't so butthurt. Luis Santana On Sat, Feb 19, 2011 at 11:48 AM, Eyeballing Weev eyeballing.w...@gmail.com wrote: Madhur Ahuja and Hack Talk are obviously from third world countries and are only doing this for publicity, much like how Turks and Romanians hack

Re: [Full-disclosure] University of Central Florida Multiple LFI

2011-02-19 Thread Hack Talk
hacktalkblog is just as obvious as posting a link to your site. I hope UCF calls FDLE and you can explain to Special Agent Veazy and others about your research On 02/19/2011 12:04 PM, Hack Talk wrote: I actually live close to the University of Central Florida and after countless attempt

Re: [Full-disclosure] (a present for andrew wallace, with love from cal)‏

2011-02-19 Thread Hack Talk
I say we need moar Hello Kitty and less flamewars Luis Santana On Sat, Feb 19, 2011 at 12:20 PM, Psychobilly zpamh...@gmail.com wrote: From the distant I can feel The creeping smell Of sudden life leaks Tar is packaging The network is hungry. Le 19/02/2011 17:26, Cal Leeming

Re: [Full-disclosure] University of Central Florida Multiple LFI

2011-02-19 Thread Hack Talk
Merdinger shawn...@gmail.comwrote: Hi, On Sat, Feb 19, 2011 at 12:04, Hack Talk hacktalkb...@gmail.com wrote: countless attempt to contact both their infosec team, the tech rangers, and their personal web developers with no contact back or patching of these vulnerabilities I decided to post

Re: [Full-disclosure] University of Central Florida Multiple LFI

2011-02-19 Thread Hack Talk
...@gmail.com wrote: Shawn, Hack Talk would rather fire off 5 emails than pick up a phone, make a phone call and call someone from the WHOIS information since by his own admission he's a Florida resident who lives near UCF or maybe he's worried about law enforcement after all ;-) On 02/19

[Full-disclosure] University of Central Florida Multiple LFI

2011-02-18 Thread Hack Talk
Found these and thought I'd share: -==- http://excel.ucf.edu/index.php?p=../../../../../../../../../../../../../../../../../../../../etc/apache2/apache2.conf%00

Re: [Full-disclosure] jaillords.com hacked, login/password/email list

2011-02-08 Thread Hack Talk
Probably not but I'm pretty sure someone that knows the admin that is security inclined would notice it and alert the admins. Luis Santana - Security+ Administrator - http://hacktalk.net HackTalk Security - Security From The Underground On Tue, Feb 8, 2011 at 10:46 AM, Paul Schmehl

Re: [Full-disclosure] An enemy of the infosec community needs to bebrought to justice

2011-02-03 Thread Hack Talk
guess! Sent from my BlackBerry® wireless device -Original Message- From: Hack Talk hacktalkb...@gmail.com Sender: full-disclosure-boun...@lists.grok.org.uk Date: Wed, 2 Feb 2011 22:51:29 To: codermancoder...@gmail.com Cc: full-disclosure@lists.grok.org.uk; gregorydev...@aim.com

Re: [Full-disclosure] An enemy of the infosec community needs to be brought to justice

2011-02-03 Thread Hack Talk
Yea I'm waiting on this too. Post it up if you got it Luis Santana - Security+ Administrator - http://hacktalk.net HackTalk Security - Security From The Underground On Thu, Feb 3, 2011 at 5:38 PM, Wesley Kerfoot wja...@gmail.com wrote: where is the password for the archive? On Wed, Feb 2,

Re: [Full-disclosure] An enemy of the infosec community needs to be brought to justice

2011-02-03 Thread Hack Talk
3, 2011 at 11:58 PM, Justin Elze formula...@gmail.com wrote: The password is DoomedCharlatan Sent from my iPhone On Feb 3, 2011, at 6:48 PM, Hack Talk hacktalkb...@gmail.com wrote: Yea I'm waiting on this too. Post it up if you got it Luis Santana - Security+ Administrator - http

Re: [Full-disclosure] An enemy of the infosec community needs to be brought to justice

2011-02-02 Thread Hack Talk
I wish I could put that on _my_ resume. Tots jelly of GDE, tots jelly... Luis Santana - Security+ Administrator - http://hacktalk.net HackTalk Security - Security From The Underground On Wed, Feb 2, 2011 at 9:54 PM, coderman coder...@gmail.com wrote: On Wed, Feb 2, 2011 at 4:17 PM, bk

[Full-disclosure] Harvard.edu LFI

2011-01-31 Thread Hack Talk
Hey, I've tried reporting issues to Harvard University tons of times in the past but they rarely respond and even more rarely commend researchers for finding vulnerabilities so I decided that full-disclosure was the way to get Harvard off of their crimson asses and patch this vulnerability. PoC

Re: [Full-disclosure] Harvard.edu LFI

2011-01-31 Thread Hack Talk
Well that was fast, As some proof here's a screenshot of the /etc/passwd file: http://i.imgur.com/HKA51.png Luis Santana - Security+ Administrator - http://hacktalk.net HackTalk Security - Security From The Underground ___ Full-Disclosure - We