Re: [Full-Disclosure] client - server

2005-02-28 Thread Matteo Giannone
I have made all tests on that website : none revealing informations that can
recognize me. I mean: if mozilla would send its SERIAL NUMBER (if it exsts) that
is a way to identify my own copy of mozilla.



 which informations can a server get about a client running M$ windows XP ?
 I cannot access a website because i have been banned and I'd like to
 understand how they recognize me for sure.

All sorts of stuff. Visit browserspy (http://gemal.dk/browserspy/) for a 
bunch of tests. Java is one excellent way to steal the goods (and many 
browserspy tests use that).

The 'short' answer is, however, probably a simple IP check.
 
 I mean:
 - a simple ip check doesn't work with dynamic addresses...
 - cookies can be deleted
 - computer name can be changed
 - mac address can be changed (even I wasn't able to, because I have a usb dsl
 modem and I cannot change its MAC working with regedit or using tools like 
 smac )

MAC address? That's not visible past the DSLAM. As for dynamic 
addresses, have you kept track? I have (supposed) dynamic addresses at 
home and it's not changed in over a year.

You should dump the DSL modem and get a conventional ethernet one. Then 
change the MAC on your ethernet card at will (this will get you new 
addresses). There probably is a way to access the innerds of the USB one 
but you'd probably have to take it apart and locate the serial port.

~Mike.
 
 Anything else ?
 How the hell do they recognize me ?
 
 Matteo Giannone
 
 
 
 
 
 6X velocizzare la tua navigazione a 56k? 6X Web Accelerator di Libero!
 Scaricalo su INTERNET GRATIS 6X http://www.libero.it
 
 
 
 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.netsys.com/full-disclosure-charter.html
 





Navighi a 2 MEGA e i primi 3 mesi sono GRATIS. 
Scegli Libero Adsl Flat senza limiti su http://www.libero.it



___
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Re: [Full-Disclosure] client - server

2005-02-28 Thread Matteo Giannone
It is impossible that they banned a block of addresses of my ISP, because that
is a webserver where you play games: most of the people playing games there
use my same ISP and also live near me.

I am sure that my IP address changes in couple of hours after disconnections.

I deleted cookies, changed computer name, used different browsers
ActiveX controls are disabled by default on Internet explorer.

I really don't understand how they can ban me.

Are you all sure they cannot know my MAC address? I think they know it when I
connect to the server (i remember something of TCP/IP stack and
encapsulation/decapsulation)



Most likely they might have blocked the entire pool of IP belonging to
your ISP try to visit the website with a proxy server


On Sun, 27 Feb 2005 21:29:18 -0500, Eric Windisch [EMAIL PROTECTED] wrote:
 On Mon, 2005-02-28 at 02:43 +0100, Matteo Giannone wrote:
  - a simple ip check doesn't work with dynamic addresses...
 
 It will work for as long as your IP is valid.  They can also ban the
 entire IP block (aka, your ISP)
 
  - computer name can be changed
  - mac address can be changed (even I wasn't able to, because I have a usb
 dsl
  modem and I cannot change its MAC working with regedit or using tools like
 smac )
 
 Your browser will not (or should not, anyway) reveal your computer
 name or mac address.
 
  Anything else ?
 
 User-agents and referers.  Some browsers can send quite a bit of
 information in the user-agent string.
 
 It could also be a content filter between you and the web site in
 question.  Schools and parents setup these to censor the surfing of
 children.  Many companies filter their content too, due to the
 distraction (and legal ramifications) brought about by warez and
 pornography.
 
  How the hell do they recognize me ?
 
 By the tin-foil hat ;)
 
 -- 
 Eric Windisch [EMAIL PROTECTED]
 
 ___
 Full-Disclosure - We believe in it.
 Charter: http://lists.netsys.com/full-disclosure-charter.html
 

-- 
Gautam R. Singh
http://www.google.com/search?q=gautam.singh%40gmail.com
[mcp,ccna,cspfa,] t: +91 9885576081 | pgp:
http://gautam.techwhack.com/key/ | ymsgr: er-333 | msn: [EMAIL PROTECTED]





Navighi a 2 MEGA e i primi 3 mesi sono GRATIS. 
Scegli Libero Adsl Flat senza limiti su http://www.libero.it



___
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


[Full-Disclosure] client - server

2005-02-27 Thread Matteo Giannone
Hi list,
which informations can a server get about a client running M$ windows XP ?
I cannot access a website because i have been banned and I'd like to
understand how they recognize me for sure.

I mean:
- a simple ip check doesn't work with dynamic addresses...
- cookies can be deleted
- computer name can be changed
- mac address can be changed (even I wasn't able to, because I have a usb dsl
modem and I cannot change its MAC working with regedit or using tools like smac 
)

Anything else ?
How the hell do they recognize me ?

Matteo Giannone





6X velocizzare la tua navigazione a 56k? 6X Web Accelerator di Libero!
Scaricalo su INTERNET GRATIS 6X http://www.libero.it



___
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


[Full-Disclosure] Re: Slackware security updates

2005-01-27 Thread Matteo Giannone
On the home page www.slackware.com read the news:


/*
2004-11-27

Pat made a new entry in the ChangeLog giving us all some fresh news about his
health conditions.

He also stated (Pat's gpg signed message) that the security packages (patches)
from the GUS-BR group (GUS GPG KEY) are trusted.

EDITED on 2004-12-07
A mirror of the GUS-BR tree can be found on osuosl (ftp and http).
*/


There are no official patches in the website since november 2004, you should
manually update your system...
Or trust someone else's packages..
Or track the slackware-current...

Matteo Giannone





Navighi a 2 MEGA e i primi 3 mesi sono GRATIS. 
Scegli Libero Adsl Flat senza limiti su http://www.libero.it



___
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


[Full-Disclosure] Delay of netsys ?

2004-12-22 Thread Matteo Giannone
Is netsys.com delaying in delivering mails or is it a problem with my ISP?
I see even 3 days of lag between the post date and the arival date...
Matteo Giannone




Regala e regalati Libero ADSL: 3 mesi gratis e navighi veloce. 1.2 Mega di 
musica, film, video e sport. 
Abbonati subito senza costi di attivazione su http://www.libero.it




___
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


[Full-Disclosure] Re: controversial shadowcrew site hacked by secret service?

2004-11-17 Thread Matteo Giannone
Hello list,
Mission Impossible theme sounded weird (too weird) and so on...

Tell me: 
why should these link be active after the UNITED STATES SECRET SERVICE 
Operation ?

http://www.shadowcrew.com/phpBB2/login.php
http://archive.shadowcrew.com/Archive/

Matteo Giannone




Libero ADSL: navighi gratis a 1.2 Mega, senza canone e costi di attivazione. 
Abbonati subito su http://www.libero.it 


___
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html