Re: [Full-disclosure] Fwd: Google vulnerabilities with PoC

2014-03-14 Thread Mike Hale
No, you're saying something's a vulnerability without showing any indication of how it can be abused. On Fri, Mar 14, 2014 at 11:00 AM, Nicholas Lemonias. lem.niko...@googlemail.com wrote: The full-disclosure mailing list has really changed. It's full of lamers nowdays aiming high. On

Re: [Full-disclosure] when did piracy/theft become expression of freedom

2012-01-30 Thread Mike Hale
(the fuck you Byron mentioned) isn't fruitful to remedy the situation. On Mon, Jan 30, 2012 at 8:54 AM, Mike Hale eyeronic.des...@gmail.com wrote: What you said doesn't follow. Making a digital copy isn't burning down a business.  The analogy linking 'piracy' with theft is ludicrous

Re: [Full-disclosure] when did piracy/theft become expression of freedom

2012-01-29 Thread Mike Hale
What you said doesn't follow. Making a digital copy isn't burning down a business. The analogy linking 'piracy' with theft is ludicrous. On Sun, Jan 29, 2012 at 11:50 PM, Christian Sciberras uuf6...@gmail.com wrote: Byron, you don't protest to the government by burning down 100-year-old

Re: [Full-disclosure] I know its old, but what the heck does this do... (exposing a tool...)

2011-10-25 Thread Mike Hale
Exploits this, maybe? http://www.us-cert.gov/cas/bulletins/SB05-040.html#smb On Tue, Oct 25, 2011 at 6:50 PM, xD 0x41 sec...@gmail.com wrote: Hello List, Id like people to also, like this thread asks, to pls give some opinion, other than mine.. wich, i am yet to make;

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-14 Thread Mike Hale
. This was a war zone, not a country club. On Thu, Oct 13, 2011 at 11:23 PM, Jeffrey Walton noloa...@gmail.com wrote: On Fri, Oct 14, 2011 at 2:19 AM, Mike Hale eyeronic.des...@gmail.com wrote: Except that they weren't obviously unarmed. Not only where they not obviously unarmed, they appeared

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-14 Thread Mike Hale
; and it has no business trying to police others. The UN Security Council is a joke - it should have stopped the US a long time ago (an impossibility under its current structure). Jeff On Fri, Oct 14, 2011 at 7:28 AM, Mike Hale eyeronic.des...@gmail.com wrote: Obviously not. Again.  They looked

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-14 Thread Mike Hale
...and the allegation that it was just makes people look ridiculous. On Thu, Oct 13, 2011 at 11:05 PM, valdis.kletni...@vt.edu wrote: On Thu, 13 Oct 2011 22:44:44 PDT, Mike Hale said: Seriously!  Think about the injustice of having American helicopters engage armed individuals shadowing American soldiers

Re: [Full-disclosure] [OT] Obama said: American people understand that not everybody's been following the rules

2011-10-13 Thread Mike Hale
Seriously! Think about the injustice of having American helicopters engage armed individuals shadowing American soldiers. The inhumanity is heart breaking. Go troll somewhere else. On Thu, Oct 13, 2011 at 9:53 PM, Jeffrey Walton noloa...@gmail.com wrote: On Fri, Oct 14, 2011 at 12:22 AM,

Re: [Full-disclosure] Other recommended lists?

2011-02-21 Thread Mike Hale
Probably becuase you've been the biggest troll on this list for the last few weeks? On Mon, Feb 21, 2011 at 11:04 AM, Cal Leeming [Simplicity Media Ltd] cal.leem...@simplicitymedialtd.co.uk wrote: And why is that, Paul? On Mon, Feb 21, 2011 at 7:03 PM, Paul Schmehl pschmehl_li...@tx.rr.com

Re: [Full-disclosure] Other recommended lists?

2011-02-21 Thread Mike Hale
Your porn thread among others? Is this is a serious question? On Mon, Feb 21, 2011 at 11:07 AM, Cal Leeming [Simplicity Media Ltd] cal.leem...@simplicitymedialtd.co.uk wrote: How so? On Mon, Feb 21, 2011 at 7:06 PM, Mike Hale eyeronic.des...@gmail.com wrote: Probably becuase you've been

Re: [Full-disclosure] IBM DeveloperWorks Pwned and Defaced

2011-01-08 Thread Mike Hale
http://ploader.net/files/ad1da891a1cef64466a7562879291c30.jpg On Sat, Jan 8, 2011 at 11:23 PM, Cal Leeming [Simplicity Media Ltd] cal.leem...@simplicitymedialtd.co.uk wrote: Got a screenshot? I only see: Our apologies The IBM developerWorks Web site is currently under maintenance.

Re: [Full-disclosure] Andrew Auernheimer (aka weev) wants his victim's to masturbate for him

2011-01-07 Thread Mike Hale
Jesus, you are such a troll. On Fri, Jan 7, 2011 at 7:46 AM, Victor Rigo victor_r...@yahoo.com wrote: same old useless crap Victor Rigo, CISSP Independent Computer Security Consultant Buenos Aires, AR +5411-4316-1901 ___ Full-Disclosure - We

Re: [Full-disclosure] Flaw in Microsoft Domain Account Caching Allows Local Workstation Admins to Temporarily Escalate Privileges and Login as Cached Domain Admin Accounts (2010-M$-002)

2010-12-10 Thread Mike Hale
In fact, I can just make the Domain Admin a guest on my workstation if I want to and there is nothing they can do about it. With the caveat that they can readd themselves using GP anytime they want...but you know. I just wanted to throw that out there. I think the key vulnerability in this is

Re: [Full-disclosure] Congratulations Andrew

2010-06-25 Thread Mike Hale
That is too fucking funny. Sometimes schadenfreude comes back to bite you in the ass. On Thu, Jun 24, 2010 at 1:10 PM, Cody Robertson c...@hawkhost.com wrote: On 6/24/10 3:54 PM, T Biehn wrote: Ouch dude: http://www.cbc.ca/canada/toronto/story/2010/06/23/tor-g20-arrest.html Guess you ate a

Re: [Full-disclosure] A lot of people have labelled me a snitch, Mr Lamo told BBC News.

2010-06-07 Thread Mike Hale
Yeah, Lamo is a complete fucking douche. That said...Manning is a complete and total moron. *shakes head* -- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0 ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] WTF eEye Really?

2010-05-04 Thread Mike Hale
Looks like he rewrote it and clarified what he meant to say. I think this is a lesson on why you really should proofread stuff and ask someone else to go over your writings before you publish something. On Mon, May 3, 2010 at 5:44 PM, Sec News secn...@gmail.com wrote: Did anyone else see this?

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-27 Thread Mike Hale
Your comparison doesn't work. It's not A versus B, it's A versus C, with C being Company does nothing because it can't afford a thorough security program. On Mon, Apr 26, 2010 at 2:07 PM, Michel Messerschmidt li...@michel-messerschmidt.de wrote: On Mon, Apr 26, 2010 at 06:02:48AM -0700, Shaqe

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-27 Thread Mike Hale
-they are arguing for the fun of it without any real arguments (why else prove me right on my arguments and later on deny it?) So you fall into this category? On Tue, Apr 27, 2010 at 1:22 AM, Christian Sciberras uuf6...@gmail.comwrote: In short, you just said that PCI compliance _is_ a waste of

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-27 Thread Mike Hale
a few lines before that? On Tue, Apr 27, 2010 at 4:43 PM, Mike Hale eyeronic.des...@gmail.comwrote: -they are arguing for the fun of it without any real arguments (why else prove me right on my arguments and later on deny it?) So you fall into this category? On Tue, Apr 27, 2010 at 1:22

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-27 Thread Mike Hale
is quoting me in a different argument your point? On Tue, Apr 27, 2010 at 4:55 PM, Mike Hale eyeronic.des...@gmail.comwrote: Point is, you're arguing for the sake of arguing, as you have no understanding what PCI is, based on your own admission. On Tue, Apr 27, 2010 at 7:51 AM, Christian

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-27 Thread Mike Hale
at? Real security, or just a way companies can excuse their incompetence by citing full PCI compliance? Which reminds me, it wasn't I that brought anti-viruses to the discussion. Cheers. On Tue, Apr 27, 2010 at 5:16 PM, Mike Hale eyeronic.des...@gmail.comwrote: Actually, you're right

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-26 Thread Mike Hale
Then, as I said, the PCI requirements are total nonsense... You say this based on absolutely zero understanding of what the requirements are, by your own admission? On Sun, Apr 25, 2010 at 8:40 PM, Nick FitzGerald n...@virus-l.demon.co.uk wrote: Tracy Reed to me: Anyone authoritatively

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-24 Thread Mike Hale
Uhm.. No Uhm, yes? It's a 'hassle' if: You don't have a firewall. You use default passwords. You don't protect stored data. You don't encrypt that data in transit. You don't use antivirus. You don't restrict data access. You don't use unique logins. You don't log stuff. You don't test your

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-23 Thread Mike Hale
is money wasted. On Wed, Apr 21, 2010 at 5:44 PM, Mike Hale eyeronic.des...@gmail.com wrote: I find the findings completely flawed.  Am I missing something? -- 09 F9 11 02 9D 74 E3 5B D8 41 56 C5 63 56 88 C0 ___ Full-Disclosure - We believe

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-23 Thread Mike Hale
.  I still don’t really see what all the hubbub is about here. t From: Christian Sciberras [mailto:uuf6...@gmail.com] Sent: Friday, April 23, 2010 9:29 AM To: Thor (Hammer of God) Cc: Christopher Gilbert; Mike Hale; full-disclosure; security-bas...@securityfocus.com Subject: Re: [Full

Re: [Full-disclosure] Compliance Is Wasted Money, Study Finds

2010-04-22 Thread Mike Hale
I actually disagree with the conclusions presented by this paper. I'm in the process of writing up a more thorough explanation, but my main issue lies with their key finding on compliance spending. According to the paper, roughly 40% is spend on directly securing secrets, and another 40% is