Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Tonnerre Lombard
Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 Fredrick Diggle [EMAIL PROTECTED] wrote: The following output shows a manafestation of this vulnerability: C:\sort %x.%x.%x.%x 7c812f39.0.0.41414141The system cannot find the file specified. This is actually confirmed on Windows

[Full-disclosure] [FIXED] Remote Denial of Service for SSH service at Dell DRAC4 (maybe Mocana SSH)

2008-01-18 Thread Robert Scheck
Remote Denial of Service for SSH service at Dell DRAC4 (maybe Mocana SSH) ETES GmbH Security Advisory; August 13, 2007 - updated January 18, 2007 BACKGROUND == Dell Remote Access Card 4 (DRAC4) allows customers to effectively manage servers in remote locations where no administrative IT

Re: [Full-disclosure] Minute of Silence

2008-01-18 Thread Paul Schmehl
--On Friday, January 18, 2008 10:12:44 -0500 dxp [EMAIL PROTECTED] wrote: Not exactly Info-sec but I think many can relate. Bobby Fischer has passed away. Damn. Death gets checkmate. -- Paul Schmehl ([EMAIL PROTECTED]) Senior Information Security Analyst The University of Texas at Dallas

[Full-disclosure] Minute of Silence

2008-01-18 Thread dxp
Not exactly Info-sec but I think many can relate. Bobby Fischer has passed away. -- -=[ dxp ]=- 0xA3F3C6E3 signature.asc Description: This is a digitally signed message part ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Minute of Silence

2008-01-18 Thread Joey Mengele
LOLOL nice one Paul! This is the Jewish mentality. These are a criminal people. They torture their prisoners in the worst way. It's even illegal! They don't even deny it hardly. Jews were always bastards throughout history. They are liars, they are the worst pieces of shit in the world. They

Re: [Full-disclosure] Minute of Silence

2008-01-18 Thread Byron Sonne
Not exactly Info-sec but I think many can relate. Bobby Fischer has passed away. W00t! One less anti-semitic moron in the world. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and

Re: [Full-disclosure] [FDSA] Sort - Critical Format StringVulnerability

2008-01-18 Thread Larry Seltzer
This vulnerability allows for arbitrary command execution and is really quite severe. So the following proof of concept causes the Windows Calculator to be executed? C:\calc Larry Seltzer eWEEK.com Security Center Editor http://security.eweek.com/ http://blogs.pcmag.com/securitywatch/

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Fredrick Diggle
Fredrick Diggle apologizes, he always forgets that exploitation is IMPOSSIBLE if there is no how-to in phrack. Racing your own buffer is hard Lombard so he feels your pain :( Also how dare you accuse Diggle Sec of releasing fake vulnerabilities. Continue down that train of thought and you are

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread Joey Mengele
Dear Lombard Retard, Excellent analysis, except it is completely wrong LOLOLOLOL. Try %n. J Gratitude is a sickness suffered by dogs. - Gadi Evron On Fri, 18 Jan 2008 02:45:41 -0500 Tonnerre Lombard [EMAIL PROTECTED] wrote: Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 Fredrick Diggle

Re: [Full-disclosure] Gadi Bashing, enough already....

2008-01-18 Thread auto71278
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Who knew Gadi was actually smart... He should post some of his smartness to the list to convince us all. I *TOTALLY* AGREE WITH YOU, MY HERO!!! PLEASE GADI POST SOME OF YOUR L33T STUFF. PLEASE PLEASE. WE'RE READY TO LEARN SOMETHING FROM YOU. But

Re: [Full-disclosure] Minute of Silence

2008-01-18 Thread T Biehn
This thread has a lot of promise. - Sits back with a cold one. On Jan 18, 2008 10:56 AM, Byron Sonne [EMAIL PROTECTED] wrote: Not exactly Info-sec but I think many can relate. Bobby Fischer has passed away. W00t! One less anti-semitic moron in the world.

[Full-disclosure] [USN-572-1] apt-listchanges vulnerability

2008-01-18 Thread Kees Cook
=== Ubuntu Security Notice USN-572-1 January 18, 2008 apt-listchanges vulnerability CVE-2008-0302 === A security issue affects the following Ubuntu releases: Ubuntu 7.04

Re: [Full-disclosure] what is this?

2008-01-18 Thread worried security
On Jan 18, 2008 5:44 PM, Fredrick Diggle [EMAIL PROTECTED] wrote: Hear that H.D.? While analyzing security for UT Dallas Paul came to the conclusion that you suck... Do you really think HDMoore gives a crap what you say or Paul from Dallas says? Get a f***ing grip and stop trying to raise

Re: [Full-disclosure] [FDSA] Sort - Critical Format String Vulnerability

2008-01-18 Thread reepex
LOL you are an idiot could you please google format string 101, read the printf man page, and leave security forever On Jan 18, 2008 1:45 AM, Tonnerre Lombard [EMAIL PROTECTED] wrote: Salut, Fredrick, On Thu, 17 Jan 2008 12:05:13 -0600 Fredrick Diggle [EMAIL PROTECTED] wrote: The

Re: [Full-disclosure] what is this?

2008-01-18 Thread Fredrick Diggle
Hear that H.D.? While analyzing security for UT Dallas Paul came to the conclusion that you suck... On Jan 17, 2008 5:32 PM, Paul Schmehl [EMAIL PROTECTED] wrote: --On Thursday, January 17, 2008 15:16:30 -0600 Fredrick Diggle [EMAIL PROTECTED] wrote: Seems to Fredrick Diggle that if you are

Re: [Full-disclosure] Minute of Silence

2008-01-18 Thread Fredrick Diggle
All men have some prejudice, but few have true genius. On Jan 18, 2008 10:13 AM, T Biehn [EMAIL PROTECTED] wrote: This thread has a lot of promise. - Sits back with a cold one. On Jan 18, 2008 10:56 AM, Byron Sonne [EMAIL PROTECTED] wrote: Not exactly Info-sec but I think many can relate.

[Full-disclosure] silentbaker trojan sample

2008-01-18 Thread J B
Hi All, Does anyone have a sample of the Silentbanker trojan available, or know where I can get a copy; I would like to run a few tests. Thanks J _ ___ Full-Disclosure - We believe