Re: [Full-disclosure] [CVE-2013-6986] Insecure Data Storage in Subway Ordering for California (ZippyYum) 3.4 iOS mobile application

2013-12-17 Thread Fyodor
On Fri, Dec 6, 2013 at 8:07 PM, Daniel Wood daniel.w...@owasp.org wrote: Title: [CVE-2013-6986] Insecure Data Storage in Subway Ordering for California (ZippyYum) 3.4 iOS mobile application Reported to Vendor: May 2013 CVE Reference: CVE-2013-6986 Apparently you touched a nerve! If the

Re: [Full-disclosure] [Dailydave] Hack Cup 2013

2013-06-11 Thread Fyodor
my spelling corrector prompts me that the link should be https://sites.google.com/site/securitytournament/add-your-team ;) On Mon, Jun 10, 2013 at 9:41 PM, Nicolas Waisman nico...@immunityinc.com wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Immunity is excited to announce our fourth

Re: [Full-disclosure] www.LEORAT.com is scam

2012-06-19 Thread Fyodor
On Fri, Mar 30, 2012 at 07:23:38PM +0530, smith joseph wrote: LEORAT.COM is SCAM | LEOIMPACT.COM is SCAM | LEORAT.COM is SCAM I won't comment on the irony of people getting scammed while trying to buy malware, but your post touched a nerve at Leo. Here is their CONFIDENTIAL legal threat, which

Re: [Full-disclosure] SSL Capable NetCat and more

2011-03-28 Thread Fyodor
the mistaken timeline. Cheers, Fyodor ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Nmap NOT VULNERABLE to Windows DLL Hijacking Vulnerability

2010-09-11 Thread Fyodor
would have the same vulnerabilities if they did something dumb like add CWD to their LD_LIBRARY_PATH, but at least their vendors don't ship it that way! And while anyone is bugging MS about the DLL search path, please ask MS to re-enable raw sockets too :). Cheers, Fyodor

Re: [Full-disclosure] Nmap NOT VULNERABLE to Windows DLL Hijacking Vulnerability

2010-09-08 Thread Fyodor
, Fyodor ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Should nmap cause a DoS on cisco routers?

2010-07-07 Thread Fyodor
completely that network device makers such as HP need to start showing some resiliency. If Nmap can crash them by accident, how can they be expected to hold up to real attacks? Cheers, Fyodor ___ Full-Disclosure - We believe in it. Charter: http

[Full-disclosure] NSA tracking open source security tools

2006-02-04 Thread Fyodor
, Metasploit, Snort, Ethereal, Cain Abel, and Kismet. Nifty. For those without the magazine, I have posted a pic at: http://www.insecure.org/nmap/nmap_inthenews.html#bush Maybe open source software really will take over the world :). Cheers, Fyodor PS: For those who missed the announcement, Nmap 4.0