Re: [Full-disclosure] #warning -- DICE.COM insecure passwords

2013-02-12 Thread Valdis . Kletnieks
On Mon, 11 Feb 2013 04:30:29 -0800, warn...@type-error.net said: job / recruiter website dice.com use ancient crypt() hash function. passwords limited to seven characters. cracking user passwords quite simple. be very afraid of future hash / cracked password dump. maybe dice.com should improve

Re: [Full-disclosure] #warning -- DICE.COM insecure passwords

2013-02-12 Thread Tim
That's assuming that they didn't do the risk analysis and decide that the effort required to fix the problem (which will probably require, among other things, having every single user change their password) is worth the effort. Given that so many places have gotten hacked and pwned that the

Re: [Full-disclosure] #warning -- DICE.COM insecure passwords

2013-02-12 Thread Travis Biehn
What Tim said. I think warning was writing about the public shame from having a massive pw dump not having some neckbeard expose them over using crypt on some random industry mailing list (shudders). Here is a long article on secure password storage. It is extremely exciting:

Re: [Full-disclosure] #warning -- DICE.COM insecure passwords

2013-02-12 Thread Jeffrey Walton
On Tue, Feb 12, 2013 at 5:58 PM, Travis Biehn tbi...@gmail.com wrote: What Tim said. I think warning was writing about the public shame from having a massive pw dump not having some neckbeard expose them over using crypt on some random industry mailing list (shudders). Here is a long article

[Full-disclosure] #warning -- DICE.COM insecure passwords

2013-02-11 Thread warning
job / recruiter website dice.com use ancient crypt() hash function. passwords limited to seven characters. cracking user passwords quite simple. be very afraid of future hash / cracked password dump. maybe dice.com should improve their security to avoid public shaming? #warning

Re: [Full-disclosure] Warning is about APT

2012-06-25 Thread c-APT-ure
Hi mustntlive could you maybe try a better translation service so that it's easier to understand the meaning of your messages? (I assume this is automated translation from your native language) thanks however for this great site about APT. it's really great !! (i'm not just saying this because i

Re: [Full-disclosure] Warning is about APT

2012-06-25 Thread rancor
You know that was not for real, just someone making fun of one of the characters on the list. Don't waste your time On Jun 25, 2012 9:09 PM, c-APT-ure toms.security.st...@gmail.com wrote: Hi mustntlive could you maybe try a better translation service so that it's easier to understand the

[Full-disclosure] Warning is about APT

2012-06-22 Thread Григорий Братислава
Hello full disclosure!! !! !! Is like to warn you about APT. APT is mean Association for is Prevention of is Torture. http://www.apt.ch Is musntlive receive email from APT is say to stop using their name for mean malware from China. Is musntlive's best interest to believe is this APT overflow

Re: [Full-disclosure] Warning is about vulnerability

2011-06-07 Thread coderman
2011/6/3 Григорий Братислава musntl...@gmail.com: ... I is like to warn you is about vulnerability. Is vulnerability is what get Sony, RSA, L3, Google and is Hilary Clinton hacked. Please is watch vulnerabilities and is never forgot when is you use !! many times, is many more take your

[Full-disclosure] Warning is about vulnerability

2011-06-03 Thread Григорий Братислава
Hello is list!! I is like to warn you is about vulnerability. Is vulnerability is what get Sony, RSA, L3, Google and is Hilary Clinton hacked. Please is watch vulnerabilities and is never forgot when is you use !! many times, is many more take your advisories is serious!!

Re: [Full-disclosure] Warning is about vulnerability

2011-06-03 Thread Jubei Trippataka
You are the Borat of FD. 2011/6/4 Григорий Братислава musntl...@gmail.com Hello is list!! I is like to warn you is about vulnerability. Is vulnerability is what get Sony, RSA, L3, Google and is Hilary Clinton hacked. Please is watch vulnerabilities and is never forgot when is you use !!

Re: [Full-disclosure] Warning - t00ls.org hidden callback in shells

2011-04-26 Thread Seanybob
Just an update to the previous post on this topic. The attacker has been moving around his datafile containing the list of urls with shell scripts installed. His old one: http://xmors.byethost7.com/mynameisahmed..html has been shutdown. Did some investigating, and found some other places this

[Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Sabahattin Gucukoglu
BrailleNote Apex offers telnet and FTP access on the standard ports, with read/write privilege on the entire file system, to all comers. No authentication is required. BrailleNote is unsafe on any network whose devices you are not in full charge of, and which (by NAT or firewall) does not

Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Thor (Hammer of God)
...@list.humanware.com Cc: full-disclosure@lists.grok.org.uk; bugt...@securityfocus.com; me- ma...@sabahattin-gucukoglu.com; supp...@humanware.com Subject: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers BrailleNote Apex offers telnet and FTP access on the standard

Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Sabahattin Gucukoglu
On 1 Oct 2010, at 22:57, Thor (Hammer of God) wrote: ⠠⠊⠋ ⠃⠁⠙ ⠛⠥⠽⠎ ⠁⠗⠑ ⠕⠝ ⠽⠕⠥⠗ ⠝⠑⠞⠺⠕⠗⠅, ⠽⠕⠥ ⠼⠚⠼⠉⠼⠊;⠗⠑ ⠎⠉⠗⠑⠺⠑⠙ ⠁⠝⠽⠺⠁⠽ (If a bad guy is on your network, you're screwed anyway) With those services closed, it doesn't take a five-second run of nmap and wget to ransack the owner's device, though. And

Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers

2010-10-01 Thread Thor (Hammer of God)
@lists.grok.org.uk; bugt...@securityfocus.com Subject: Re: [Full-disclosure] Warning: BrailleNote Apex Offers Read/Write FTP And Telnet Access To All Comers On 1 Oct 2010, at 22:57, Thor (Hammer of God) wrote: ⠠⠊⠋ ⠃⠁⠙ ⠛⠥⠽⠎ ⠁⠗⠑ ⠕⠝ ⠽⠕⠥⠗ ⠝⠑⠞⠺⠕⠗⠅, ⠽⠕⠥ ⠼⠚⠼⠉⠼⠊;⠗⠑ ⠎⠉⠗⠑⠺⠑⠙ ⠁⠝⠽⠺⠁⠽ (If a bad guy is on your network

Re: [Full-disclosure] Warning

2008-07-10 Thread Valdis . Kletnieks
On Wed, 09 Jul 2008 15:56:27 PDT, Adolf Hitler said: ^ ^^ This man is a danger to the community at large. Pot. Kettle. Black. pgpw0eOVPaVzm.pgp Description: PGP signature ___ Full-Disclosure - We believe in

Re: [Full-disclosure] Warning

2008-07-10 Thread KJK::Hyperion
Adolf Hitler ha scritto: This man is a danger to the community at large. He's stated on several occasions that he accepts pedophiles and is willing to work with them. GB2HD2K, dimbulb. We don't give a shit about goon justice ___ Full-Disclosure - We

[Full-disclosure] Warning

2008-07-09 Thread Adolf Hitler
This man is a danger to the community at large. He's stated on several occasions that he accepts pedophiles and is willing to work with them. He's 34 years old and plays with toys. He has an enlarged prostate and has stated verbatim that he likes dildos in his ass. Beware! Anthony Scott Heaton

[Full-disclosure] Warning: Hackers hijacking unused IP Addresses inside Trusted domains [POC]

2007-11-21 Thread XSS Worm XSS Security Information Portal
*Domain Name System Hijacked: Hackers Abuse Domain-Name Trust* *InternetWorld's ** Andy Patriziohttp://www.internetnews.com/feedback.php/http://www.internetnews.com/security/article.php/3712071 **and Finjan's Yuval Ben-Itzahk http://finjan.com/ discuss the fundamental weaknesses in Finjan's

Re: [Full-disclosure] Warning: Hackers hijacking unused IP Addresses inside Trusted domains [POC]

2007-11-21 Thread Paul Schmehl
--On Wednesday, November 21, 2007 21:45:35 +1100 XSS Worm XSS Security Information Portal [EMAIL PROTECTED] wrote: In the case of Yahoo, security firm Finjan said hackers exploited an unused IP address within Yahoo's hierarchy and used that as the domain address behind a forged Google

Re: [Full-disclosure] Warning: Hackers hijacking unused IP Addresses inside Trusted domains [POC]

2007-11-21 Thread Gadi Evron
On Wed, 21 Nov 2007, Paul Schmehl wrote: If Yahoo was able to fix the problem quickly, then it would appear that Yahoo had a compromised domain server or servers. We all get pwned at one point or another, how we respond is what matters. -- Paul Schmehl ([EMAIL PROTECTED]) Senior