Re: [Full-disclosure] DoS via tables corruption in WordPress (Timothy Goddard)

2014-02-12 Thread Mikhail A. Utin
Hello, I would add my question. I'm installing WP and MySQL for it. I installed accounts and MySQL hashed passwords. So, it's secure. However WP config file uses clear text password to communicate with MySQL. Config file more likely will stay as 755 on my Linux

[Full-disclosure] : EE BrightBox router hacked - bares all if you ask nicely

2014-01-16 Thread Mikhail A. Utin
and being a bit off the list topic. However, we sometimes should discuss things leading to insecurity. Mikhail Utin, CISSP, PhD -- Message: 1 Date: Thu, 16 Jan 2014 12:00:18 +0100 From: ?micier Januszkiewicz ga...@tut.by To: gold

Re: [Full-disclosure] [CVE-2013-6986] Insecure Data Storage in Subway Ordering

2013-12-19 Thread Mikhail A. Utin
Hello, I'm on your side. You are right in both how you are handling the case and you conclusion. They failed in a few business aspects, thus responsible for outcome. After all, legal side of our work is not less important than IT and InfoSec technologies we use. Good luck Mikhail Utin, CISSP

Re: [Full-disclosure] Where are you guys standing re: the (full) disclosure

2013-12-13 Thread Mikhail A. Utin
Answers: 1. Whether you are right and there is a bug, lrt the vendor (M$) know; that is ethical. They will decide if to consider your finding as a bug. Your following steps depend on their opinion on the finding. 2. If you keep it for yourself - no problems. If you disclose on Internet before

Re: [Full-disclosure] Full-Disclosure Digest, Vol 95, Issue 15- Aaron Swartz death

2013-01-15 Thread Mikhail A. Utin
Message: 2 Date: Mon, 14 Jan 2013 11:02:26 -0500 From: Jeffrey Walton noloa...@gmail.com Subject: Re: [Full-disclosure] petition to remove Aaron Swartz prosecutor To: richa...@fastmail.fm Cc: full-disclosure@lists.grok.org.uk Message-ID:

Re: [Full-disclosure] how to sell and get a fair price

2013-01-15 Thread Mikhail A. Utin
, will be glad to support and devout some time. Regards Mikhail From: Christian Sciberras [mailto:uuf6...@gmail.com] Sent: Monday, January 14, 2013 4:17 PM To: Valdis Kletnieks Cc: Mikhail A. Utin; full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] how to sell and get a fair price Valdis

[Full-disclosure] how to sell and get a fair price

2013-01-10 Thread Mikhail A. Utin
List, Here is the link to Information Security Magazine issue with Market for vulnerability information grows - Cashing on Zero-day exploits for your information. I once shared my idea that ZDI is not right way to go. It should be a market place (web portal) for selling vulnerabilities based

Re: [Full-disclosure] :Re: [OT] How much a million facebook

2012-11-01 Thread Mikhail A. Utin
It looks like an initial research before writing a business plan and looking for venture capital investment. I'll think about reserving some funds for :-) Mikhail Utin, CISSP -- Message: 10 Date: Thu, 1 Nov 2012 00:37:13 +0530 From: Memory Vandal memvan...@gmail.com

Re: [Full-disclosure] Full-Disclosure Digest, Vol 92, Issue 34 - 1. Microsoft Windows Help program (WinHlp32.exe) memory

2012-10-30 Thread Mikhail A. Utin
. Mikhail utin, CISSP -Original Message- Today's Topics: 1. Microsoft Windows Help program (WinHlp32.exe) memory corruption (kaveh ghaemmaghami) 2. Microsoft Paint 5.1 memory corruption (kaveh ghaemmaghami) ** Hello list! I want to warn

Re: [Full-disclosure] Full-Disclosure Digest, Vol 89, Issue 15 suspicion of rootkit (Alexandru Balan)

2012-07-12 Thread Mikhail A. Utin
-Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of full-disclosure-requ...@lists.grok.org.uk Sent: Thursday, July 12, 2012 4:40 AM To: full-disclosure@lists.grok.org.uk Subject: Full-Disclosure Digest, Vol

Re: [Full-disclosure] Full-Disclosure Digest, Vol 89, Issue 11: ] How much time is appropriate for fixing

2012-07-11 Thread Mikhail A. Utin
Mikhail utin, CISSP, PhD -Original Message- From: paul.sz...@sydney.edu.au [mailto:paul.sz...@sydney.edu.au] Sent: Tuesday, July 10, 2012 6:41 PM To: full-disclosure@lists.grok.org.uk; Mikhail A. Utin Subject: Re: [Full-disclosure] Full-Disclosure Digest, Vol 89, Issue 11: ] How much time

Re: [Full-disclosure] Full-Disclosure Digest, Vol 89, Issue 11: ] How much time is appropriate for fixing

2012-07-10 Thread Mikhail A. Utin
flavor you prefer. The most of it is free time contribution. Somebody pays for that, but we use. It is nice to be paid for something, but consider the alternative. Otherwise our communications will die and we do not have an OS for a fun or profit. Mikhail Utin -Original Message- From: full

Re: [Full-disclosure] Full-Disclosure Digest, Vol 88, Issue 34 Re: www.LEORAT.com is scam (Thor (Hammer of God))

2012-06-20 Thread Mikhail A. Utin
Whoever from so named leoimpact.com: WHOIS brings fake mailing address of PO in the US, and the phone does not belong to leorat either. Just shut up and stop sending fake messages. You are nothing and not having a name rats. Not a legal entity. Mikhail -Original Message- From:

Re: [Full-disclosure] Full-Disclosure Digest, Vol 88, Issue 11:

2012-06-08 Thread Mikhail A. Utin
My 10 cents: I'm glad that such discussions happen on this list. I would not consider that as out of topic, because Information Security, and security in general, did/do include significant political component, and we cannot avoid or ignore it. Plus, and it is important as well, it gives as a

Re: [Full-disclosure] Full-Disclosure Digest, Vol 88, Issue 2 Re: NSA Cyber security program [ maybe off-topic ]

2012-06-04 Thread Mikhail A. Utin
-Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of full-disclosure-requ...@lists.grok.org.uk Sent: Saturday, June 02, 2012 7:00 AM To: full-disclosure@lists.grok.org.uk Subject: Full-Disclosure Digest, Vol

[Full-disclosure] LulzSec $ Sabu - lessons learned

2012-03-09 Thread Mikhail A. Utin
Hello, My two cents to lessons learned: - If FBI is hacked, CIA will LOL - if CIA is hacked, FBI will LOL - if DoD is hacked both FBI and CIA will LOL But if Stratfor is hacked, all three guys get very serious, guess why? If you do serious hacking, do not brag and do not do stupid hacks. Mikhail

Re: [Full-disclosure] Full-Disclosure Digest, Vol 83, Issue 21

2012-01-17 Thread Mikhail A. Utin
as You are right, and You are right as well. Anybody's going to the Source? Any experience with? It may bring us to the common ground and would be very helpful in future real life cases. Mikhail Utin, CISSP From: full-disclosure-boun...@lists.grok.org.uk

Re: [Full-disclosure] Facebook Attach EXE Vulnerability

2011-11-01 Thread Mikhail A. Utin
is not enabled, thus was not accepting new connections. Mikhail A. Utin, CISSP Information Security Analyst -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of full-disclosure-requ...@lists.grok.org.uk Sent

Re: [Full-disclosure] Full-Disclosure Digest, Vol 80, Issue 54

2011-10-13 Thread Mikhail A. Utin
of such discussions. This list is a part of our life though. Suggestion: assign one day of a week to release steam and talk whatever we want to. Purists can just ignore discussions on that day. And as usually: you are right, and you are right too. Cheers and be patient. Mikhail A. Utin, CISSP -Original

Re: [Full-disclosure] Microsoft's Binary Planting Clean-Up Mission

2011-09-16 Thread Mikhail A. Utin
. Mikhail A. Utin, CISSP Information Security Analyst -Original Message- From: ACROS Security Lists [mailto:li...@acros.si] Sent: Thursday, September 15, 2011 3:54 PM To: 'Thor (Hammer of God)' Cc: bugt...@securityfocus.com; full-disclosure@lists.grok.org.uk Subject: RE: [Full-disclosure

Re: [Full-disclosure] Full-Disclosure Digest, Vol 79, Issue 21

2011-09-14 Thread Mikhail A. Utin
See MS advisory for full list of affected products. It is NOT just 2007. It includes 2010 products as well. Mikhail A. Utin, CISSP Information Security Analyst -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk

Re: [Full-disclosure] ZDI-11-208: Adobe Shockwave rcsL Parsing Remote Code Execution Vulnerability

2011-06-20 Thread Mikhail A. Utin
I see numerous announcements from ZDI pointing to June 14th updates. Is that what big guys MS and Adobe missed in last week updates? If NO, then we need to stop ZDI from polluting our list with last year news. Anyway, I see repetitive announcements pretty often. Thank you Mikhail A. Utin

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-23 Thread Mikhail A. Utin
Mikhail A. Utin, CISSP Information Security Analyst Commonwealth Care Alliance 30 Winter St. Boston, MA TEL: (617) 426-0600 x.288 FAX: (617) 249-2114 http://www.commonwealthcare.org mu...@commonwealthcare.org -Original Message- From: Ryan Sears [mailto:rdse...@mtu.edu] Sent: Monday

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-23 Thread Mikhail A. Utin
basics, and our experience as they are kiddies. Eventually they will grow ... may be. List, thank you very much Mikhail A. Utin, CISSP Information Security Analyst Commonwealth Care Alliance 30 Winter St. Boston, MA TEL: (617) 426-0600 x.288 FAX: (617) 249-2114 http://www.commonwealthcare.org mu

[Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Mikhail A. Utin
Hello, Opening looking OK email message in my MS OE I've very likely got new kind of virus, which exploits MS Office flaw recently announced. Immediately after, my OE started consuming huge memory when I switched between folders or messages. I've not seen any process in Task Manager taking up

[Full-disclosure] looking for enterprise AV solution

2010-10-26 Thread Mikhail A. Utin
Folks, We are looking an enterprise level AV-software to replace our current AVG having in our eyes poor detection and removal capability. Reviews bring really mixed results as nothin's perfect. Access to logs and relible management control features are important as well. Any advising? Thank

Re: [Full-disclosure] Full-Disclosure Digest, Vol 68, Issue 5

2010-10-04 Thread Mikhail A. Utin
Their policy of publishing whatever they think is buzzing cannot be respected by people who understand possible problems of innocent people involved. Leaking of military secrets is stupid as it gets. If they get closed, it is what they deserve. Mikhail A. Utin, CISSP -Original Message