[Full-disclosure] [SECURITY] [DSA-2109-1] New samba packages fix buffer overflow

2010-09-17 Thread Stefan Fritsch
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA-2109-1 secur...@debian.org http://www.debian.org/security/ Stefan Fritsch September 16, 2010

[Full-disclosure] New tool for pentesting

2010-09-17 Thread runlvl
A new product was born, similiar to Core Impact, Metasploit and Immunity Canvas. INSECT is affordable, easy to use and it has a friendly user interface. It promises to be an excellent tool and it allows organizations of all sizes to conduct comprehensive penetration testing across their

Re: [Full-disclosure] DLL hijacking POC (failed, see for yourself)

2010-09-17 Thread huj huj huj
hey funboys! get a room! 2010/9/16 Stefan Kanthak stefan.kant...@nexgo.de Christian Sciberras wrote: Yes. Once again: get your homework done! http://www.codeproject.com/KB/DLL/dynamicdllloading.aspx That's a double DYNAMIC there! Did you even bother to read the article? The very

Re: [Full-disclosure] DLL hijacking POC (failed, see for yourself)

2010-09-17 Thread Christian Sciberras
We did, it's number is 253 ... $00FD. On Fri, Sep 17, 2010 at 11:07 AM, huj huj huj datski...@gmail.com wrote: hey funboys! get a room! 2010/9/16 Stefan Kanthak stefan.kant...@nexgo.de Christian Sciberras wrote: Yes. Once again: get your homework done!

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Omar B Villa
...without specialized training in penetration testing... Are you sure? I wouldn't let a newby to use a pentest tool in my company!! xDD 2010/9/17 runlvl run...@gmail.com A new product was born, similiar to Core Impact, Metasploit and Immunity Canvas. INSECT is affordable, easy to use and it

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Jhfjjf Hfdsjj
- Forwarded Message From: Jhfjjf Hfdsjj taser3...@yahoo.com To: runlvl run...@gmail.com Sent: Fri, September 17, 2010 3:26:44 AM Subject: Re: [Full-disclosure] New tool for pentesting Are you expecting us to believe that a windows only supported penetration tool with absolutely

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Taras
A new product was born, similiar to Core Impact, Metasploit and Immunity Canvas. INSECT is affordable, easy to use and it has a friendly user interface. It promises to be an excellent tool and it allows organizations of all sizes to conduct comprehensive penetration testing across their

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Hurgel Bumpf
ORLY? This screenshot http://www.faltaenvido.org/wp-content/uploads/2010/09/mainimage.jpg reminds me somehow of http://www.metasploit.com/modules/exploit/windows/ftp This module exploits a stack-based buffer overflow in EasyFTP Server 1.7.0.11 and earlier. EasyFTP fails to check input size

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Eyeballing Weev
Looking at that webpage is making me rage. I'm sending him an invoice for a new keyboard. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread rdsears
Seriously. The only reason CANVAS and IMPACT are still used is because of the 0-days that come packaged with them. Metasploit if far superior not only in exploitation, but post exploitation, persistance, networking pivioting, and just generally being a badass! Can ANYTHING really compare to

[Full-disclosure] [SECURITY] [DSA 2110-1] New Linux 2.6.26 packages fix several issues

2010-09-17 Thread dann frazier
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA-2110-1secur...@debian.org http://www.debian.org/security/ dann frazier September 17, 2010

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Mario Vilas
To be fair, both Canvas and Impact had the same pivoting features years before Metasploit (and yes, that includes the entire Windows API too). It's no wonder really, since Metasploit is newer too (Impact was created some ten odd years ago and Canvas came shortly later, if I'm not wrong). But IMHO

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread excore
I know the story of this guy. He was fired from Core for incompetence and swore he'd make a better product and compete with them. I bet they're still laughing their asses off... Check out his Twitter account: https://twitter.com/runlvl Apparently this guy used to do website defacements,

Re: [Full-disclosure] New tool for pentesting

2010-09-17 Thread Eyeballing Weev
I was just commenting on the Wordpress page, with the ugly theme, the weird URLs (page ID), and the lack of an image slideshow.. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored