[Full-Disclosure] k-otik kiddies are really whores

2004-12-07 Thread swallow mycum
k-otik whores should stop linking their script kiddie site thx. you are just whores getting fame from other people works, so go get a driving license and drive taxis leaking exploits will never make you smarter, go code some hello world posts by k-otik, all linking their kiddie site:

Re: [Full-Disclosure] [Advisory] Mozilla Products Remote Crash Vulnerability

2004-12-07 Thread Juergen Schmidt
On Mon, 6 Dec 2004, Heikki Toivonen wrote: This crash was fixed today. Great. This does not mean crashes will be ignored and will go unfixed. It just means that they do not receive the urgency that exploitable crashes and other vulnerabilities receive. But this means, somebody (from

Re: [Full-Disclosure] I'm calling for LycosEU heads and team to resign or be sacked

2004-12-07 Thread Rob Carmichael
- Original Message - From: [EMAIL PROTECTED] To: Tatercrispies ; [EMAIL PROTECTED] ; bill machen ; bill machen Cc: bill machen ; kat ; John Draper Sent: Monday, December 06, 2004 9:17 PM Subject: Re: [Full-Disclosure] I'm calling for LycosEU heads and team to resign or be sacked two

[Full-Disclosure] help.msn.com

2004-12-07 Thread jamie fisher
This is gonna be quick'n'dirty. My dinner is almost cooked... More XSS for MSN to add to the list: 1. Cross site scripting (In _javascript_ context) http://help.msn.com/en_au/DirectedHelpControls.asp 1.1 GET /en_au/DirectedHelpControls.asp?DataMarket=%27%2Balert(%27Bills

[Full-Disclosure] [ GLSA 200412-05 ] mirrorselect: Insecure temporary file creation

2004-12-07 Thread Luke Macken
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security AdvisoryGLSA 200412-05:02 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - -

[Full-Disclosure] Bypass personal firewall application protection . Again.

2004-12-07 Thread offtopic
Bypass personal firewall application protection . Again. (c)oded by offtopic ([EMAIL PROTECTED]) 2004 Special thank to 3APA3A for links to the debuggers for Windows. quote src= http://www.security.nnov.ru/advisories/bypassing.asp?l=EN Personal firewall usually restricts access to network

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Valdis . Kletnieks
On Mon, 06 Dec 2004 19:29:26 PST, bipin gautam said: A simple yet effective solution would be, for AV vendors to (say) add the vulnerable system dll's, execudables etc... in a threat list (Refering to Microsoft's KB or something similar) And after completing the virus scan, suggest the

Re: [Full-Disclosure] Bypass personal firewall application protection . Again.

2004-12-07 Thread Andrei Zlate-Podani
offtopic wrote: Bypass personal firewall application protection . Again. (c)oded by offtopic ([EMAIL PROTECTED]) 2004 Special thank to 3APA3A for links to the debuggers for Windows. quote src= http://www.security.nnov.ru/advisories/bypassing.asp?l=EN Personal firewall usually restricts

[Full-Disclosure] Online Script Decoder

2004-12-07 Thread GreyMagic Security
Windows Script Encoder is a Microsoft tool to encode scripts so that Web hosts and Web clients cannot view or modify their source. It encodes the content of script tags using a very simple encoding algorithm and renames the scripts language attribute from JScript or Javascript to JScript.Encode

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Kenneth Ng
If you want an analogy, note that the US government says that smoking is bad for you. Yet, they won't ban smoking. Why? All the revenue they get from taxing cigerettes. On Tue, 07 Dec 2004 10:50:11 -0500, [EMAIL PROTECTED] [EMAIL PROTECTED] wrote: On Mon, 06 Dec 2004 19:29:26 PST, bipin

Re: [Full-Disclosure] [Advisory] Mozilla Products Remote Crash Vulnerability

2004-12-07 Thread Heikki Toivonen
Juergen Schmidt wrote: But this means, somebody (from mozilla) checked the urgency and decided, that it can wait. It would have been nice and a minimal effort to inform the initial reporter about that. * Reported Tuesday 2004-11-30 * 10 hours later it receives first comment, asking for testcase

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Ron
Simple, effective, and Won't Happen In Our Lifetime. There needs to be a good, opensource anti-virus solution where they aren't worried about their bottom line. The problem is the amount of maintenance it takes to keep a virus scanner up-to-date makes it hard for somebody to do it for free.

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread [EMAIL PROTECTED]
Couldn't agree more, their concern isn't security, but survival of the business model. By providing a what you proposed would be a threat to their profitable model as so eloquently pointed out by Valdis and many others time and time again. -cm [EMAIL PROTECTED] wrote: On Mon, 06 Dec 2004

Re: [Full-Disclosure] Lycos Ends AntiSpam Effort, Denies Downing Spam Sites

2004-12-07 Thread n3td3v
On Mon, 6 Dec 2004 22:53:00 -0800, Andrew Farmer [EMAIL PROTECTED] wrote: On 06 Dec 2004, at 12:54, james edwards wrote: http://news.netcraft.com/archives/2004/12/06/ lycos_ends_antispam_effort_denies_downing_spam_sites.html OK folks, its over. Ended a couple days ago, actually. Nah

Re: [Full-Disclosure] I'm calling for LycosEU heads and team to resign or be sacked

2004-12-07 Thread dk
[EMAIL PROTECTED] wrote: On Fri, 03 Dec 2004 21:52:30 GMT, n3td3v said: I think heads should roll over this. I think its the worst act a corporation has ever undertaken in the history of the internet. Hmm.. I don't know. Verisign's hijacking of *.com wildcards and several different Microsoft

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Ron
[EMAIL PROTECTED] wrote: On Tue, 07 Dec 2004 11:24:54 CST, Ron said: There needs to be a good, opensource anti-virus solution where they aren't worried about their bottom line. The problem is the amount of maintenance it takes to keep a virus scanner up-to-date makes it hard for somebody to

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Valdis . Kletnieks
On Tue, 07 Dec 2004 11:24:54 CST, Ron said: There needs to be a good, opensource anti-virus solution where they aren't worried about their bottom line. The problem is the amount of maintenance it takes to keep a virus scanner up-to-date makes it hard for somebody to do it for free. Well,

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Kenneth Ng
A few years ago when a big software vendor here to promote their cutting edge self healing software, I quiped I guess making software that doesn't break was too hard for them. I got a lot of angry stares that indicated that they were not amused. On Tue, 07 Dec 2004 12:43:50 -0500, [EMAIL

[Full-Disclosure] Re: Online Script Decoder

2004-12-07 Thread Paul Szabo
GreyMagic Security [EMAIL PROTECTED] kindly made an online decoder available at http://www.greymagic.com/security/tools/decoder/ On occasions it may be more useful to have a local decoder: I often use the following perl script. Cheers, Paul Szabo - [EMAIL PROTECTED]

Re: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Mary Landesman
Trend Micro's PC-cillin Internet Security 2005 already has a vulnerability assessment feature that lists missing patches and needed updates. It also scans for spyware via the system registry. The A/V vendors have known for several years now exactly how not to send a virus was cleaned from your

[Full-Disclosure] MaxDB WebTools = 7.5.00.18 buffer overflow and Denial of Service

2004-12-07 Thread Evgeny Demidov
Name: MaxDB WebTools = 7.5.00.18 buffer overflow and Denial of Service Date: 7 Dec 2004 Platforms: Any Author:Evgeny Demidov Description: MaxDB is a heavy-duty, SAP-certified open source database for OLTP and OLAP usage which offers high reliability,

[Full-Disclosure] GPRS/IP-session from Nokia/Symbian mobile phone stays up

2004-12-07 Thread Marco Davids (Prive)
Hi, For what it is worth: When my Nokia 6600 (Symbian V7.0s) mobile phone was connected to the Internet and an imap-server for some tests the other day, I decided to run a ping to the phone's IP-address (in fact I did an nmap -O to the phone first, but that didn't work). After the mail was

[Full-Disclosure] Contact BankOne.com ?

2004-12-07 Thread Andrew Smith
Hi, Has anyone got any idea how i can contact BankOne.com or anyone that can for me? I don't have an account with them which apparently means my e-mails to them aren't SECURE. Thanks, Andrew Smith. -- zxy_rbt2 ___ Full-Disclosure - We believe in it.

Re: [Full-Disclosure] Online Script Decoder

2004-12-07 Thread Elia Florio
http://www.greymagic.com/security/tools/decoder/ Is anyone able to decode this malware/exploit script-encoded : http://www.antiblock.biz/user256/2DimensionOfExploitsEnc.php it's a different layer of encoding/encrypting...or it's only a bad-encoded script? EF

RE: [Full-Disclosure] A suggestion to all AV vendors...

2004-12-07 Thread Todd Towles
Not exactly true..it is called freedom...drinking is bad for you when you take too much..but so are some vitamins are bad for you when you take too much...let the government tax cigs, if you don't want to buy the tax, don't buy them. Again we are way OT. Never go to excess, but let moderation be

Re: [Full-Disclosure] Contact BankOne.com ?

2004-12-07 Thread Owned You
Post your issues with BankOne on: http://finance.yahoo.com/q/mb?s=JPM That may get their attention. Or not; posting here will get the attention of the infosec journalists. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-Disclosure] Whois appears to have taken a hit

2004-12-07 Thread Gregory Gilliss
Update: sometimes the server responds. It appears to depend on which domain registrar the whois has to query. -- Greg On or about 2004.12.07 15:01:49 +, Gregory Gilliss ([EMAIL PROTECTED]) said: whois.opensrs.net - no response from ping or whois queries. -- Gregory A. Gilliss, CISSP