[Full-disclosure] NNL-Labs MNIN - F5 FirePass Security Advisory

2007-01-06 Thread Greg Sinclair
Michael Ligh from MNIN (http://www.mnin.org) and Greg Sinclair from NNL-Labs (http://nnl-labs.com) have released on 5 January 2007 an advisory regarding multiple vulnerabilities in the F5 Firepass product. The F5 Firepass is vulnerable to multiple filter bypasses, information disclosure and

[Full-disclosure] Hancock: for those who requested sources...

2007-01-06 Thread J.A. Terranson
The below article carries most of the actual story, leaving out only a few details. For instance, the fact that Hancock left Savvis after being told to cease using the fake honorofic Dr. in anything associated with the company, and the underlying fact that this guy was a complete and utter

[Full-disclosure] flag as cyber terrorism

2007-01-06 Thread n3td3v
[headline dork reference] The latest scandal in infosec: [descriptive dork reference] We were never sure what defines cyber terrorism and a cyber terrorist but now n3td3v via cnet news unleashes the propaganda that points to the month of bugs trend as being the defined cyber terrorism threat.

Re: [Full-disclosure] flag as cyber terrorism

2007-01-06 Thread Byron Sonne
Sigh... I thought you said you were going to shut the fuck up and never bother us again? ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

[Full-disclosure] 0trace - traceroute on established connections

2007-01-06 Thread Michal Zalewski
I'd like to announce the availability of a free security reconnaissance / firewall bypassing tool called 0trace. This tool enables the user to perform hop enumeration (traceroute) within an established TCP connection, such as a HTTP or SMTP session. This is opposed to sending stray packets, as

Re: [Full-disclosure] 0trace - traceroute on established connections

2007-01-06 Thread Michal Zalewski
On Sun, 7 Jan 2007, Michal Zalewski wrote: [ Of course, I might be wrong, but Google seems to agree with my assessment. A related use of this idea is 'firewalk' by Schiffman and Goldsmith, a tool to probe firewall ACLs; another utility called 'tcptraceroute' by Michael C. Toren

Re: [Full-disclosure] flag as cyber terrorism

2007-01-06 Thread kefka
Why do you hate progress? The ones who remove freedoms, they are the ones who really hate freedom. List: Sorry for feeding the troll. --- n3td3v wrote: [headline dork reference] The latest scandal in infosec: [descriptive dork reference] We were never sure what defines cyber

Re: [Full-disclosure] flag as cyber terrorism

2007-01-06 Thread Valdis . Kletnieks
On Fri, 05 Jan 2007 21:17:58 GMT, n3td3v said: We were never sure what defines cyber terrorism and a cyber terrorist but now n3td3v via cnet news unleashes the propaganda that points to the month of bugs trend as being the defined cyber terrorism threat. After which we're *still* unclear