Re: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3....

2009-07-22 Thread Steven M. Christey
On Tue, 21 Jul 2009, Michal Zalewski wrote: The code created an oversized list, which does not seem to be that far from creating an overly nested DOM tree, or drawing an oversized CANVAS shape, or any other creating-too-many-things-for-the-renderer-to-handle attacks... but really, I'm not

Re: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii, PS3....

2009-07-22 Thread Thierry Zoller
Hi Steven, [Removing a few addresses in CC that surely do not care too much about this discussion] SMC I strongly suspect that as we collectively try to figure out how to solve SMC resource-consumption issues for all kinds of software, we will quickly run SMC into lots of complexity that

Re: [Full-disclosure] (no subject)

2009-07-22 Thread wishi
Hmmh, I personally see a lack of defense and a need for more white hats, who aren't constantly trying to gain media attention by breaking stuff. - Because most stuff is already broken - as we see. Even trolls nowadays can course some damage. If you need a good example to proof that we need new

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Valdis . Kletnieks
On Tue, 21 Jul 2009 20:27:38 CDT, anti sec said: Our heroic anti-sec warriors have carried out a blessed raid against 4chanarchive.org. 4chan users are now burning with fear, terror and panic on their /b/, /gif/, /r9k/, and /a/ boards. Great. Now you pissed off anon. Why didn't you pick on

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Christophe Delondre
because those poor guys don't know what NSA or crime syndicates are ... because those poor guys don't know what's outside of their room ... my dear 'anti-sec', open the door of your home and take a look outside ... do you really think we need skiddies like you in these (economic) crisis times ?

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Christophe Delondre
because those poor guys don't know what NSA or crime syndicates are ... because those poor guys don't know what's outside of their room ... my dear 'anti-sec', open the door of your home and take a look outside ... do you really think we need skiddies like you in these (economic) crisis times ?

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Chris Brandstetter
4chan, heart of the White Hat. ROFLMAO. OKay this is bloody funny. Dude, get a life. On Wed, Jul 22, 2009 at 6:00 AM, full-disclosure-requ...@lists.grok.org.ukwrote: Send Full-Disclosure mailing list submissions to full-disclosure@lists.grok.org.uk To subscribe or unsubscribe via

[Full-disclosure] [Mailing list Vulnerability] Troll exploit of mailing lists and newsgroups

2009-07-22 Thread mrx
I am new to this list, I am new to IT security, I have so far contributed very little if anything of actual value to this list. I have gained much insight from the vast majority of posts here, I will hopefully continue to do so. There are some intelligent and wise persons contributing to this

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Turgut Baumann
I think that some kind of nazi party would be a better deal, maybe someone of these guys understand this revenge against the full disclosure zionist hegemony-shit, because I don't - I'm just to stupid for demogagy. valdis.kletni...@vt.edu schrieb: On Tue, 21 Jul 2009 20:27:38 CDT, anti sec

[Full-disclosure] [USN-798-1] Firefox and Xulrunner vulnerabilities

2009-07-22 Thread Jamie Strandboge
=== Ubuntu Security Notice USN-798-1 July 22, 2009 firefox-3.0, xulrunner-1.9 vulnerabilities CVE-2009-2462, CVE-2009-2463, CVE-2009-2464, CVE-2009-2465, CVE-2009-2466, CVE-2009-2467, CVE-2009-2469, CVE-2009-2472

[Full-disclosure] hackforums is back online

2009-07-22 Thread Leandro Malaquias
www.hackforums.net --LM ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Ferdinand Klinzer
lol @white hats Cheers Am 22.07.2009 um 14:00 schrieb wishi: Hmmh, I personally see a lack of defense and a need for more white hats, who aren't constantly trying to gain media attention by breaking stuff. - Because most stuff is already broken - as we see. Even trolls nowadays can

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Dean Pierce
Won't somebody PLEASE think of the CHILDREN!!?! On Wed, Jul 22, 2009 at 10:50 AM, Dean Piercepierce...@gmail.com wrote: Won't somebody PLEASE thing of the CHILDREN!!?! On Wed, Jul 22, 2009 at 9:52 AM, Ferdinand Klinzerklin...@gmx.de wrote: lol @white hats Cheers Am 22.07.2009 um 14:00

Re: [Full-disclosure] [Mailing list Vulnerability] Troll exploit of mailing lists and newsgroups

2009-07-22 Thread Dean Pierce
I'm not sure you understand the purpose. Full disclosure is a toll feed bag. A hacker soap opera of magic, mystery, and intrigue. Seriously, when you subscribed were you expecting an 0day factory? Serious security research discussions? Some retard help forum? Those all exist in other places.

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Ed Carp
Exactly! 2009/7/21 Josh Wheeler jpavlakov...@gmail.com Anti-Sec We will pwn your pr0n. This is beginning to seem more and more like an exercise in circle-jerking... On Tue, Jul 21, 2009 at 5:39 PM, Ed Carp e...@pobox.com wrote: Do not fuck with anti-suck. LOL!

Re: [Full-disclosure] (no subject)

2009-07-22 Thread Ed Carp
That's what keeps me subscribed - when I've had a particularly bad day, I always know I can come over here and have a great laugh! 2009/7/21 Rob Fuller jd.mu...@gmail.com I'm sorry, log time reader of FD, it's a great mashup of hilarity and vuln disclosure.

Re: [Full-disclosure] [Mailing list Vulnerability] Troll exploit of mailing lists and newsgroups

2009-07-22 Thread Stephen Menard
Your Clock's off DOH! time for a beer Received: from lists.grok.org.uk (localhost [127.0.0.1]) by lists.grok.org.uk (Postfix) with ESMTP id CB44E1CB; Wed, 22 Jul 2009 15:45:17 +0100 (BST) X-Original-To: full-disclosure@lists.grok.org.uk Delivered-To: