[Full-disclosure] The Anti-Sec Movement - Clarrifying what it means. Our Targets Remain HackForums.net and Milw0rm.com

2009-07-17 Thread Ant-Sec Movement
Dear Reader, In light of recent events, we have decided to clarify exactly what the Anti-Sec Movement is, and who we really are. Firstly, Anti-Sec is NOT an individual clan or group; as the name implies, we are a movement - a protest against White Hat Hackers and Full-Disclosure, if you will. Much

[Full-disclosure] [ GLSA 200907-14 ] Rasterbar libtorrent: Directory traversal

2009-07-17 Thread Robert Buchholz
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200907-14 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

Re: [Full-disclosure] The Anti-Sec Movement - Clarrifying what it means. Our Targets Remain HackForums.net and Milw0rm.com

2009-07-17 Thread Valdis' Mustache
To whom it may concern: I am frankly at a loss as to why Mr. Wallace has decided to hitch his pasty and pockmarked Scottish girth to the recent resurgence of the AntiSec movement. One can only conclude that it is an attempt to regain a presence on this esteemed list, which as all longtime

Re: [Full-disclosure] Linux 2.6.30+/SELinux/RHEL5 test kernel 0day, exploiting the unexploitable

2009-07-17 Thread yersinia
On Fri, Jul 17, 2009 at 4:26 AM, Brad Spenglerspen...@grsecurity.net wrote: Title says it all, exploit is at: http://grsecurity.net/~spender/cheddar_bay.tgz Everything is described and explained in the exploit.c file. I exploit a bug that by looking at the source is unexploitable; I defeat

[Full-disclosure] SAPGUI password sniffing paper announcement

2009-07-17 Thread Rene Ledosquet
Hi, A paper describing SAP GUI password sniffing can be found at: http://www.secaron.de/Content/presse/fachartikel/sniffing_diag.pdf regards, Rene -- The From: and Reply-To: addresses are internal news2mail gateway addresses. Reply to the list or to Rene Ledosquet r...@secaron.de

[Full-disclosure] PulseAudio local race condition privilege escalation vulnerability

2009-07-17 Thread Akita Software Security
PulseAudio local race condition privilege escalation vulnerability Yorick Koster, June 2009

[Full-disclosure] Blog post about anti-sec postings on Full Disclosure

2009-07-17 Thread Scott Mortimer
From: Scott Mortimer sc...@scott.mortimer.name To: full-disclosure@lists.grok.org.uk Date: Fri, 17 Jul 2009 14:26:20 +0200 Subject: Blog post about anti-sec postings on Full Disclosure I have written a blog post about the recent spat of anti-sec postings on Full Disclosure. Shortly thereafter,

[Full-disclosure] Blog post about anti-sec postings on Full Disclosure

2009-07-17 Thread Scott Mortimer
I have written a blog post about the recent spat of anti-sec postings on Full Disclosure. Shortly thereafter, some one from an IP address in Italy starting trying directory traversal attacks on my blog. Read more about it here: http://www.cybersec.eu/?p=181 I will forward the information to his

Re: [Full-disclosure] The Anti-Sec Movement - Clarrifying what it means. Our Targets Remain HackForums.net and Milw0rm.com

2009-07-17 Thread T Biehn
Is there any nudity in this film? -Travis On Fri, Jul 17, 2009 at 3:24 AM, Valdis' Mustachesecuritas.must...@gmail.com wrote: To whom it may concern: I am frankly at a loss as to why Mr. Wallace has decided to hitch his pasty and pockmarked Scottish girth to the recent resurgence of the

[Full-disclosure] [ MDVSA-2009:152 ] pulseaudio

2009-07-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:152 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:152 ] pulseaudio

2009-07-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:152 http://www.mandriva.com/security/

[Full-disclosure] [ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking

2009-07-17 Thread ISecAuditors Security Advisories
= INTERNET SECURITY AUDITORS ALERT 2009-NNN - Original release date: July 7th, 2009 - Last revised: July 17th, 2009 - Discovered by: Vicente Aguilera Diaz - Severity: 4.5/10 (CVSS Base Score) = I.

[Full-disclosure] Go away Anti-Sec/Security Justice

2009-07-17 Thread anti-antisec
LMH, can you and your Security Justice friends please get laid and leave the rest of us alone? This Anti-Sec rebranding is more boredom. Oh- we know where you work, and who some of you really are. I wonder how they'd feel about this stupidity? ___

Re: [Full-disclosure] Go away Anti-Sec/Security Justice

2009-07-17 Thread T Biehn
dox pull got doxed? ironic. On Fri, Jul 17, 2009 at 1:16 PM, anti-anti...@hushmail.com wrote: LMH, can you and your Security Justice friends please get laid and leave the rest of us alone? This Anti-Sec rebranding is more boredom. Oh- we know where you work, and who some of you really are. I

Re: [Full-disclosure] [ISecAuditors Security Advisories] Gmail vulnerable to automated password cracking

2009-07-17 Thread cevans
Hi Vicente, As was explained by my colleague Neel Mehta in his reply, this is not a vulnerability. Gmail has all sorts of additional limits on password brute forcing. The confusion here is the difference between login incorrect (due to bad password) and login incorrect (due to excessive login

[Full-disclosure] [ MDVSA-2009:153 ] dhcp

2009-07-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:153 http://www.mandriva.com/security/

[Full-disclosure] [ MDVSA-2009:153 ] dhcp

2009-07-17 Thread security
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 ___ Mandriva Linux Security Advisory MDVSA-2009:153 http://www.mandriva.com/security/

[Full-disclosure] n3td3v making ass of himself on twitter

2009-07-17 Thread Ureleet
lol. u r such an idiot. i call u a kid because u r much younger than i. thats y ur a kid. o, and cause u live @ home w/ ur mom and make false accusations all day on the twitter. why did i say what i said? cause u do it all day on twitter, make false accusations, and lie. i gave u a dose of

Re: [Full-disclosure] n3td3v making ass of himself on twitter

2009-07-17 Thread Ureleet
o, an i am one of ur followers on twitter. start panicing now! On Fri, Jul 17, 2009 at 5:30 PM, Ureleeturel...@gmail.com wrote: lol.  u r such an idiot. i call u a kid because u r much younger than i.  thats y ur a kid.  o, and cause u live @ home w/ ur mom and make false accusations all day

[Full-disclosure] CORE-2009-0227: Real Helix DNA RTSP and SETUP request handler vulnerabilities

2009-07-17 Thread CORE Security Technologies Advisories
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Core Security Technologies - CoreLabs Advisory http://www.coresecurity.com/corelabs/ Real Helix DNA RTSP and SETUP request handler vulnerabilities 1. *Advisory Information* Title: Real Helix DNA RTSP and SETUP request handler

Re: [Full-disclosure] n3td3v making ass of himself on twitter

2009-07-17 Thread ghost
GO KILL YOURSELF. On Fri, Jul 17, 2009 at 2:31 PM, Ureleeturel...@gmail.com wrote: o, an i am one of ur followers on twitter.  start panicing now! On Fri, Jul 17, 2009 at 5:30 PM, Ureleeturel...@gmail.com wrote: lol.  u r such an idiot. i call u a kid because u r much younger than i.  thats

Re: [Full-disclosure] n3td3v making ass of himself on twitter

2009-07-17 Thread ghost
Feel free to shut the fuck up, because no one cares about YOU or NETDEV. You're current posts polluting this list is just as bad as anything he has ever posted. MATCHING WITS WITH A RETARD IS NOT NEWS WORTHY. On Fri, Jul 17, 2009 at 2:30 PM, Ureleeturel...@gmail.com wrote: lol.  u r such an