Re: [Full-disclosure] Open Letter to Lee Vartan, Assistant United States Attorney in regards to the Goatse SecurityiPad case.

2010-11-22 Thread huj huj huj
lol point scoring arguments? thats highly debatable but yes i mean the weev version of n3td3v you couldn't troll your way out of a wet paperbag 2010/11/19 Joe Average yahooinsi...@gmail.com On Thu, Nov 18, 2010 at 2:55 PM, huj huj huj datski...@gmail.com wrote: no i will not same as

[Full-disclosure] Bypassing Export address table Address Filter (EAF)

2010-11-22 Thread Berend-Jan Wever
Hey list, If you're interested in a short analysis of Microsoft's new EAF pseudo-mitigation and how to bypass it, have a look here: http://skypher.com/index.php/2010/11/17/bypassing-eaf/ Cheers, SkyLined Berend-Jan Wever berendjanwe...@gmail.com Delft, The Netherlands

Re: [Full-disclosure] SSH scans, i caught one

2010-11-22 Thread Valdis . Kletnieks
On Mon, 22 Nov 2010 10:36:09 +1030, Graham Gower said: strace indicates that you'll want a uClibc based system. open(/lib/ld-uClibc.so.0, O_RDONLY) = -1 ENOENT (No such file or directory) Wait.. Didn't 'file' say this binary was statically linked? What's going on here?

Re: [Full-disclosure] NIPS/NIDS prodcuts: HTML evasions

2010-11-22 Thread John Jacobs
Hi Mahesh, I generally try to find the one which offers the most HTML-evasions. There's a few people who require say, 10 evasions, but those are often individuals who settle for less in life. When speaking with our vendors we always require, at a minimum, at least 11 evasions to be

[Full-disclosure] [SECURITY] CVE-2010-4172: Apache Tomcat Manager application XSS vulnerability

2010-11-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2010-4172: Apache Tomcat Manager application XSS vulnerability Severity: Tomcat 7.0.x - Low, Tomcat 6.0.x - Moderate Vendor: The Apache Software Foundation Versions Affected: - - Tomcat 7.0.0 to 7.0.4 - Not affected in default configuration.

[Full-disclosure] [SECURITY] CVE-2010-4172: Apache Tomcat Manager application XSS vulnerability

2010-11-22 Thread Mark Thomas
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2010-4172: Apache Tomcat Manager application XSS vulnerability Severity: Tomcat 7.0.x - Low, Tomcat 6.0.x - Moderate Vendor: The Apache Software Foundation Versions Affected: - - Tomcat 7.0.0 to 7.0.4 - Not affected in default configuration.

[Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Mikhail A. Utin
Hello, Opening looking OK email message in my MS OE I've very likely got new kind of virus, which exploits MS Office flaw recently announced. Immediately after, my OE started consuming huge memory when I switched between folders or messages. I've not seen any process in Task Manager taking up

[Full-disclosure] Agnitio Security Code Review Tool v1.0.0 released

2010-11-22 Thread David Rook
Hi, I've released a tool called Agnitio which I hope will help people carryout security focused code reviews and find vulnerabilities in the source code they are reviewing. The tool is basically a checklist with some process enforcement, audit trail creation and reporting built in. You can

Re: [Full-disclosure] SSH scans, i caught one

2010-11-22 Thread Lukasz Jaroszewski
On Mon, Nov 22, 2010 at 1:06 AM, Graham Gower graham.go...@gmail.com wrote: strace indicates that you'll want a uClibc based system. execve(./syslgd, [./syslgd], [/* 12 vars */]) = 0 svr4_syscall()                          = -1 ERRNO_4090 (Unknown error 4090) cacheflush(0x11a000, 0x990, 0x3)  

Re: [Full-disclosure] SSH scans, i caught one

2010-11-22 Thread Lukasz Jaroszewski
On Mon, Nov 22, 2010 at 1:06 AM, Graham Gower graham.go...@gmail.com wrote: strace indicates that you'll want a uClibc based system. execve(./syslgd, [./syslgd], [/* 12 vars */]) = 0 svr4_syscall()                          = -1 ERRNO_4090 (Unknown error 4090) cacheflush(0x11a000, 0x990, 0x3)  

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Thor (Hammer of God)
You know, every time I start to get a bit of hope for what looks like an upward trend of businesses and organizations taking security seriously, I see crap like this. Your organization is a Medicare prescription contractor with a national network of 61,022 contracted pharmacies, and not only

Re: [Full-disclosure] SSH scans, i caught one

2010-11-22 Thread Marco van Berkum
A friend pointed me to a botnet called Chuck Norris. http://www.muni.cz/ics/research/cyber/files/chuck_norris.pdf This botnet looks exactly similar, tho this one uses telnet to bruteforce. At least, according to the pdf. Exact same commands, but this time via SSH. Chuck Norris 2? :) Grtz, Marco

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Gary Baribault
Oh, man, now you've made him cry! Gary B On 11/22/2010 03:16 PM, Thor (Hammer of God) wrote: You know, every time I start to get a bit of hope for what looks like an upward trend of businesses and organizations taking security seriously, I see crap like this. Your organization is a

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Thor (Hammer of God)
Keep it on the list. No need for private emails if you need assistance - give everyone a chance! My response was far more useful than your post - I got pwned by an Office virus by opening an attachment in OE - What could it be?? Jeeze dude. And I didn't give any adice about Noton. I said

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Jeffrey Walton
On Mon, Nov 22, 2010 at 4:52 PM, Thor (Hammer of God) t...@hammerofgod.com wrote: Keep it on the list.  No need for private emails if you need assistance - give everyone a chance! [SNIP]  And I didn't give any adice about Noton. ... I'm going to go out on a limb and guess Mikhail's command

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Gary Baribault
On 11/22/2010 05:09 PM, Jeffrey Walton wrote: And I didn't give any adice about Noton. ... I'm going to go out on a limb and guess Mikhail's command of English is better than your ability to speak Russian (or whatever European language/dialect it might be). If I am wrong, please accept my

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-22 Thread Ryan Sears
Yeah I've got to go with Thor on this one. You endangered your entire infrastructure by exposing internal defects in your (or your staffs) knowledge. That's a big no-no. Every company presumably has people in it who aren't the 'sharpest tools in the shed' so to speak, but in one email you've

[Full-disclosure] Deadline extension: CTRQ 2011 | The Fourth International Conference on Communication Theory, Reliability, and Quality of Service

2010-11-22 Thread Alejandro Canovas
INVITATION: = Please consider to contribute to and/or forward to the appropriate groups the following opportunity to submit and publish original scientific results. = == CTRQ 2011 | Call for Papers === CALL FOR PAPERS, TUTORIALS, PANELS