Re: [Full-disclosure] [FD] password recovery for iwork docs

2010-02-13 Thread Christian Sciberras
Press the Forgot your password? button. Sorry, couldn't help myself saying that ;). And for the question, I don't know. On Sat, Feb 13, 2010 at 8:49 AM, Dev Null devnul...@yahoo.com wrote: hi, all. i was wondering if you guys know of any password recovery software (free or otherwise) for

Re: [Full-disclosure] (no subject)

2010-02-13 Thread edgar deal
incorrect. On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? 751hack...@gmail.com wrote: ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Risk measurements

2010-02-13 Thread Craig S. Wright
Exactly, As Valdis has stated, we want economic optimality. Valdis has stated this in a far easier to understand manner than I. I will publish a financial model on the blog this weekend that displays the relationships graphically. Regards, ... Dr. Craig S Wright

Re: [Full-disclosure] Risk measurements

2010-02-13 Thread Craig S Wright
Sorry, French yes, but Spanish no. Craig -- “Throw a coconut”?  Craig, did you throw a coconut at me?  Or did Val throw a coconut at me?   I feel a Monty Python joke coming on.  Rosa, I don’t speak Spanish, so I don’t know what that really means.

[Full-disclosure] [ISecAuditors Security Advisories] Facebook Cross-Site Request Forgery vulnerability

2010-02-13 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2010-002 - Original release date: February 2nd, 2010 - Last revised: February 12th, 2010 - Discovered by: Juan Galiana Lara - Severity: 6.3/10 (CVSS Base Score) = I.

Re: [Full-disclosure] Risk measurements

2010-02-13 Thread Craig S Wright
Actually, you CAN *guarantee* software. There are program verification techniques that do test all possible paths. These do not stop implementation errors, but you can make secure software. The issue is the economics. Formal verification and repair costs from 10 to 100 times the initial cost of

Re: [Full-disclosure] Risk measurements

2010-02-13 Thread Craig S Wright
Tim, Most companies, even the large ones do not have good models. They have data, but data is not useful in itself. Most rely on mean value calculations and little more. Also, they fail to account for heterogeneity in the data, this is unequal variances. To put it simply as I can, the standard

[Full-disclosure] [Tool Announcement] NoMore AND 1=1 - a Web Application Testing Tool

2010-02-13 Thread Dani
Dear list, NoMore AND 1=1 is a tool that helps the Web Application Tester by containing a large categorized list of useful expressions to inject in his day to day duties . Those expressions come from guys like Ferruh Mavituna, Hack.ers, etc (all credited in the sources) and personal experience.

Re: [Full-disclosure] (no subject)

2010-02-13 Thread McGhee, Eddie
Correct! From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-disclosure-boun...@lists.grok.org.uk] On Behalf Of edgar deal Sent: 13 February 2010 15:18 To: 751 ...? Cc: full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] (no subject)

[Full-disclosure] Mozilla Firefox 3.6 (Multitudinous looping )Denial of Service Exploit

2010-02-13 Thread information security
http://www.exploit-db.com/exploits/11432 # Title: Mozilla Firefox 3.6 (Multitudinous looping )Denial of Service Exploit # EDB-ID: 11432 # CVE-ID: () # OSVDB-ID: () # Author: Asheesh kumar Mani Tripathi # Published: 2010-02-13 # Verified: yes # Download Exploit Code

[Full-disclosure] Internet Explorer 8 (Multitudinous looping )Denial of Service Exploit

2010-02-13 Thread information security
link:http://www.exploit-db.com/exploits/11438 # Title: Internet Explorer 8 (Multitudinous looping )Denial of Service Exploit # EDB-ID: 11438 # CVE-ID: () # OSVDB-ID: () # Author: Asheesh kumar Mani Tripathi # Published: 2010-02-13 # Verified: yes # Download Exploit Code

[Full-disclosure] answer

2010-02-13 Thread RandallM
answer me this riddle: Why do you chose to Hack IT? Defend IT? -- been great, thanks RandyM a.k.a System ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia -

Re: [Full-disclosure] answer

2010-02-13 Thread silky
On Sun, Feb 14, 2010 at 3:12 PM, RandallM randa...@fidmail.com wrote: answer me this riddle: Why do you chose to Hack IT? Defend IT? Shut IT -- been great, thanks RandyM a.k.a System -- silky GUERILLA TOP? Corpulent woodpecker, disorderly.

Re: [Full-disclosure] [funsec] answer

2010-02-13 Thread Benjamin Brown
How are those two not ultimately synonymous?=P -Ben On Sat, Feb 13, 2010 at 11:12 PM, RandallM randa...@fidmail.com wrote: answer me this riddle: Why do you chose to Hack IT? Defend IT? -- been great, thanks RandyM a.k.a System ___