Re: [Full-disclosure] How to access your favorite sites in the event of a DNS takedown ?

2012-06-25 Thread alan buxey
Hi,

 But after reading this article you will know how easily you can access your 
 websites. You can access them by typing their IP address in your web-browser.
 
 Copy the IP addresses given below:
 
 tumblr.com 174.121.194.34
 wikipedia.org 208.80.152.201

partially true and not always the case. the servers may be co-hosted and if 
reached via IP address you wouldnt
be handled by the virtual hosting redirection and therefore drop onto some 
other site/service/catch-all... same is true if
you use alternatives to the old IPv4 - for example, I prefer to access 
www.wikipedia.org via 2620:0:862:ed1a::1


alan

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] SSH scans, i caught one

2010-11-19 Thread Alan Buxey
Hi,

So I downloaded all his files from the /pwn/ directory. The funny part is,
most of them are MIPS files(?).

interesting...going for a particular target/platform I'd suggest - like some 
small
home routers...OpenWRT box type deviceswhy target the PC to get interesting
information like passwords when you can exploit their little home router and 
listen in on everything with no AV software on the PC ever picking you up...

alan

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Nipper licensing

2009-09-02 Thread Alan Buxey
Hi,

 NipperUnlimited devices   1 Year  £7000

snip

ouch. a couple of years ago we had some home-brew code doing the job. Nipper
came along...was free..and did everything we did + a little more.

but now it looks like we'll be picking up our old Perl code and fixing it up
to do everything that Nipper does - and a little more.

:-(


alan

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] Nipper licensing

2009-09-02 Thread Alan Buxey
Hi,
 You going to share that perl code so that we can help you make it even  
 better?

I believe in Open Source - GPL or BSD - and the best way to make
a better place is to release code and allow as many skilled people
to work on it as possible. the internet would be dead without
such philosophy.

I can understand the authors private reasons for the change in Nipper
but the pros/cons of GPL were surely known from the early days?

not sure how making it 100% commercial will help - the old version 
is out there and is useful (with some niggles)..i expect some
person will fork it.. call it 'slipper' or somesuch. A better route
would be the 'make a commercial version' with more features,
support, etc. 

regarding OS - unlss i work on it privately and start from scratch
then my paymasters need to agree on IP/copyright :-|

alan

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Re: [Full-disclosure] ByPass a BlueCoat Proxy 8100 Serie authentification

2009-08-14 Thread Alan Buxey
Hi,

  **
  Test two : i just add a spoofed http header REFERER to a whitelisted 
  (localdatabase) site
  Result   : W00t !!
  **
 
 Can you elaborate on, to a whitelisted (localdatabase) site?

i think it basically means 'to a site thats been configured as allowed in the 
configuration of the BC' -   allowed = whitelisted, int he configuration = 
localdatabase

alan

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/