Re: [Full-disclosure] pause for reflection

2008-10-07 Thread Tonnerre Lombard
Salut, Gadi Evron, On Sun, 5 Oct 2008 03:32:03 -0500 (CDT), Gadi Evron wrote: I have dual citizenship. Along with my homeland citizenship, I am of the Internet, and see it as my personal duty to try and make the Internet safe. Poor Germans who are not allowed to have dual citizenship. ;-)

Re: [Full-disclosure] Fwd: cnn.com - Homeland Security seeks cyber counterattack system(Einstein 3.0)

2008-10-07 Thread James Matthews
The us government can't ever get their act together. It's just a waste of time On Mon, Oct 6, 2008 at 1:09 PM, Buhrmaster, Gary [EMAIL PROTECTED]wrote: Which is easier to shut down, an attack coming from a relatively small number of /16s that belong to the government, or one coming from the

[Full-disclosure] [SECURITY] [DSA 1647-1] New php5 packages fix several vulnerabilities

2008-10-07 Thread Thijs Kinkhorst
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-1647-1 [EMAIL PROTECTED] http://www.debian.org/security/ Thijs Kinkhorst October 07, 2008

[Full-disclosure] Comments on: D-Day for RFID-based transit card systems

2008-10-07 Thread n3td3v
by Elinor Mills October 6, 2008 5:35 PM PDT Want to ride the subway for free without having to jump the turnstiles? Well, as of Monday, you'll be able to do that by making a fake transit card. http://news.cnet.com/8301-1009_3-10059605-83.html by n3td3v October 6, 2008 6:44 PM PDT Can Cnet News

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread .
On Tue, Oct 7, 2008 at 1:21 PM, Anders Klixbull [EMAIL PROTECTED] wrote: You're obviously retarded Seconded. -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of imipak Sent: 7. oktober 2008 10:46 To: [EMAIL PROTECTED]; [EMAIL PROTECTED];

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread Gadi Evron
On Tue, 7 Oct 2008, Tonnerre Lombard wrote: Salut, Gadi Evron, On Sun, 5 Oct 2008 03:32:03 -0500 (CDT), Gadi Evron wrote: I have dual citizenship. Along with my homeland citizenship, I am of the Internet, and see it as my personal duty to try and make the Internet safe. Poor Germans who

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread Anders Klixbull
You're obviously retarded -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of imipak Sent: 7. oktober 2008 10:46 To: [EMAIL PROTECTED]; [EMAIL PROTECTED]; full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] pause for reflection Keep your

[Full-disclosure] Nameless but interesting podcast

2008-10-07 Thread wishi
Hi fellows! Found an interesting podcast, which is quite new: %% Adam Shostack, a well-respected voice on privacy and security issues, joins Dennis Fisher in this episode of the Nameless Security Podcast to discuss the data breach epidemic, the untimely demise of Zero Knowledge Systems and his

Re: [Full-disclosure] Comments on: D-Day for RFID-based transit card systems

2008-10-07 Thread Valdis . Kletnieks
On Tue, 07 Oct 2008 14:00:01 BST, n3td3v said: Can Cnet News please do a Youtube video showing one of their journalists getting a free ride, to prove it works? You aren't seriously suggesting that CNet actually create video evidence of one of their employees breaking the law, are you?

[Full-disclosure] Report: PC Tools Spyware Doctor v6.0 flaw

2008-10-07 Thread jose achada
Report: PC Tools Spyware Doctor v6.0 flaw Set 7, 2008 -- Affected Vendors: PC Tools -- Affected Products: Spyware Doctor v6.0 -- Download at: http://www.pctools.com/mirror/sdasetup.exe http://rapidshare.com/files/151742881/bd.rar.html

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread Anders Klixbull
Keep your talentless tripe to yourself -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of Gadi Evron Sent: 6. oktober 2008 23:58 To: rholgstad Cc: [EMAIL PROTECTED]; [EMAIL PROTECTED]; full-disclosure@lists.grok.org.uk Subject: Re: [Full-disclosure] pause

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread imipak
Keep your talentless tripe to yourself I liked it. Some of the metaphysical imagery was particularly effective... =i -- make way for history flickering like a long-lost memory ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Comments on: D-Day for RFID-based transit card systems

2008-10-07 Thread n3td3v
On Tue, Oct 7, 2008 at 3:40 PM, [EMAIL PROTECTED] wrote: On Tue, 07 Oct 2008 14:00:01 BST, n3td3v said: Can Cnet News please do a Youtube video showing one of their journalists getting a free ride, to prove it works? You aren't seriously suggesting that CNet actually create video evidence

[Full-disclosure] [OPENX-SA-2008-002] OpenX 2.4.9 and 2.6.2 fix SQL injection vulnerability

2008-10-07 Thread Matteo Beccati
OpenX security advisoryOPENX-SA-2008-002 Advisory ID: OPENX-SA-2008-002 Date: 2008-Oct-06

Re: [Full-disclosure] Comments on: D-Day for RFID-based transit card systems

2008-10-07 Thread James Matthews
That must go great. I wonder what they will do and how screwed they feel after they bought a system that sucks On Tue, Oct 7, 2008 at 9:03 AM, n3td3v [EMAIL PROTECTED] wrote: On Tue, Oct 7, 2008 at 3:40 PM, [EMAIL PROTECTED] wrote: On Tue, 07 Oct 2008 14:00:01 BST, n3td3v said: Can Cnet

[Full-disclosure] What Lexical Analysis Became in The Web-Slave New World

2008-10-07 Thread M . B . Jr .
What Lexical Analysis Became in The Web-Slave New World The point here is XSS, but rather than talking about the Internet weaknesses it exposes, this text goes against the poor algorithms being used to detect and/or avoid it. Hazardous XSS. Hazardous low-quality-XSS-filtering. These are critical

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread n3td3v
On Mon, Oct 6, 2008 at 7:37 PM, rholgstad [EMAIL PROTECTED] wrote: you are more delusional than n3td3v and Dan combined I've found something to stop me and gadi sending shit emails to F-D... http://gmailblog.blogspot.com/2008/10/new-in-labs-stop-sending-mail-you-later.html?foo

Re: [Full-disclosure] Fwd: cnn.com - Homeland Security seeks cyber counterattack system (Einstein 3.0)

2008-10-07 Thread Bruce Ediger
On Mon, 6 Oct 2008, [EMAIL PROTECTED] wrote: Hint 2: If botnets in home computers were so easy to shut down, why are there so many miscreants still using them for nefarious purposes? Easy. For the same reason that the NSA used to have (circa 1985) big, 3-ring binders full of 0-days for VMS,

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread Peter Besenbruch
On Monday 06 October 2008 23:21:22 Anders Klixbull wrote: You're obviously retarded Hey everybody! A proper use of you're! -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED] On Behalf Of imipak Sent: 7. oktober 2008 10:46 To: [EMAIL PROTECTED]; [EMAIL PROTECTED];

Re: [Full-disclosure] Fwd: cnn.com - Homeland Security seeks cyber counterattack system (Einstein 3.0)

2008-10-07 Thread Miller Grey
What? I think I missed something here. On Tue, Oct 7, 2008 at 1:53 PM, Bruce Ediger [EMAIL PROTECTED] wrote: On Mon, 6 Oct 2008, [EMAIL PROTECTED] wrote: Hint 2: If botnets in home computers were so easy to shut down, why are there so many miscreants still using them for nefarious

[Full-disclosure] [ GLSA 200810-01 ] WordNet: Execution of arbitrary code

2008-10-07 Thread Tobias Heinlein
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200810-01 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] Paul Asadoorian of PaulDotCom Enterprises / Podcast is ridiculous

2008-10-07 Thread n3td3v
On Wed, Oct 1, 2008 at 4:59 PM, Trevow Andrews [EMAIL PROTECTED] wrote: I'm sorry, I just saw his talk at NS2008 on Embedded Device Security and it is wholely outdated. I can't believe people listen to this man talk. He's been going on this embedded device security thing for years now and it's

Re: [Full-disclosure] Fwd: cnn.com - Homeland Security seeks cyber counterattack system (Einstein 3.0)

2008-10-07 Thread Bruce Ediger
On Tue, 7 Oct 2008, Miller Grey wrote: What? I think I missed something here. On Tue, Oct 7, 2008 at 1:53 PM, Bruce Ediger [EMAIL PROTECTED] wrote: On Mon, 6 Oct 2008, [EMAIL PROTECTED] wrote: Hint 2: If botnets in home computers were so easy to shut down, why are there so many miscreants

Re: [Full-disclosure] Paul Asadoorian of PaulDotCom Enterprises / Podcast is ridiculous

2008-10-07 Thread n3td3v
On Tue, Oct 7, 2008 at 10:02 PM, mark seiden [EMAIL PROTECTED] wrote: On Oct 7, 2008, at 11:48 AM, n3td3v wrote: I don't want to read/listen to anything by people who threaten people with violence on mailing lists or on irc channels. if only you stopped talking to them also on mailing

[Full-disclosure] n3td3v group members important notice

2008-10-07 Thread n3td3v
Those of you who are members of the n3td3v group take heed of this notice: -- You cannot view the group's content or participate in the group because you are not currently a member. Anyone can join. Description: a discussion group for security researchers and ethical hackers. You must be

Re: [Full-disclosure] n3td3v group members important notice

2008-10-07 Thread Ed Carp
On Tue, Oct 7, 2008 at 8:24 PM, n3td3v [EMAIL PROTECTED] wrote: I'm sorry to those reading the archive on the web and those who were reading the group via RSS / Atom news readers, but in light of recent events, n3td3v is in lockdown and will not be reopening to non-registered users for the

Re: [Full-disclosure] pause for reflection

2008-10-07 Thread Nick FitzGerald
n3td3v wrote: I've found something to stop me and gadi sending shit emails to F-D... http://gmailblog.blogspot.com/2008/10/new-in-labs-stop-sending-mail-you-later.html?foo So, for the greater good you've enabled it 24x7, yes? Now all we have to do is get Google to make the list of problems