Re: [Full-disclosure] ** FreeBSD local r00t zeroday

2009-11-30 Thread Benji
7.0 not vuln. On Mon, Nov 30, 2009 at 10:49 PM, Ed Carp e...@pobox.com wrote: On 11/30/09, Kingcope kco...@googlemail.com wrote: Systems tested/affected ** FreeBSD 8.0-RELEASE *** VULNERABLE FreeBSD 7.1-RELEASE *** VULNERABLE FreeBSD 6.3-RELEASE ***

Re: [Full-disclosure] ** FreeBSD local r00t zeroday

2009-12-01 Thread Benji
Not to disappoint, but it doesn't look like it even compiled, might be the reason it didn't work. Sent from my iPhone On 1 Dec 2009, at 11:59, r00f r00f r00f...@gmail.com wrote: I have a box with release 7.1 uname -a gives back this : FreeBSD 7.1-RELEASE #0: Thu Jan 1 14:37:25 UTC 2009

Re: [Full-disclosure] ** FreeBSD local r00t zeroday

2009-12-01 Thread Benji
I think we're missing the point here. The exploit didnt compile due to his/her copy of gcc which apparently doesnt understand -fPIC c1: error: unrecognized command line option -fPIC. Thus, obviously, there's no chance it was ever going to work. On Tue, Dec 1, 2009 at 7:47 PM, bk cho...@gmail.com

Re: [Full-disclosure] ** FreeBSD local r00t zeroday

2009-12-02 Thread Benji
Just FYI, what you posted isn't code, but actually an error message. Just FYI. On Wednesday, December 2, 2009, Chris r...@operamail.com wrote: r00f, you moron.  Read the fucking code.  Everything you need to know is in the fucking exploit.  If you can't grasp it, you have no business running

Re: [Full-disclosure] IE 0day for sale

2009-12-11 Thread Benji
Free dorrar? Sent from my iPhone On 11 Dec 2009, at 16:23, Freddie Vicious fred.vici...@gmail.com wrote: Hello list, I offer a 0day exploit on Microsoft Internet Explorer, versions 8, 7, 6. Tested on Windows 2000/XP/2003/Vista/2008/7. Serious offers only, no bullshit please :) -- Best

Re: [Full-disclosure] Extremely important posting on my blog on the latest in XSS!!!11

2009-12-22 Thread Benji
Where is the upvote button? Sent from my iPhone On 21 Dec 2009, at 10:18, hackyourid...@googlemail.com wrote: Hello participants of Full-Distortion. I know you have nothing better to do than to read my emails, so let me tell you about these extremely important postings on my blog on the

Re: [Full-disclosure] Antisec for lulz - exposed (anti-sec.com)

2010-01-01 Thread Benji
did you just come out as ProSec then, and not the reciever of information like you previously claimed? We had good lulz watching u for months.. trust me.. Even yr post reply shows how much we broke your heart and how pissed off you are.. take it easy bro.. don't take it to the heart.. What you

Re: [Full-disclosure] iiscan

2010-01-07 Thread Benji
You didn't know that the Feds own hushmail?€$#!! Sent from my iPhone On 7 Jan 2010, at 16:52, Jeffrey Walton noloa...@gmail.com wrote: Hi Robin, Suppose that acquiring the code requires you to agree to unfavorable terms of service hidden somewhere on the site, including agreeing to future

Re: [Full-disclosure] Surge in Skype Spam activity

2010-01-11 Thread Benji
Hah, I see what you did there. Sent from my iPhone On 11 Jan 2010, at 13:43, Larry Seltzer la...@larryseltzer.com wrote: It’s harmless, he’s just blowing his own company’s horn. Speaking of spam… h, shall I click a tinyurl coming from a f-d poster? n/n, pick one this is email,

Re: [Full-disclosure] Nginx, Varnish, Cherokee, thttpd, mini-httpd, WEBrick, Orion, AOLserver, Yaws and Boa log escape sequence injection

2010-01-11 Thread Benji
*spelt On Sun, Jan 10, 2010 at 9:21 PM, Jef Poskanzer j...@mail.acme.com wrote: It's spelled synergy. --- Jef Jef Poskanzer j...@mail.acme.com http://acme.com/jef/ ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Cross Site Identification (CSID) attack. Description and demonstration.

2010-01-13 Thread Benji
yes, but scarier BECAUSE IT INVOLVES FACEBOOK ARGH! On Wed, Jan 13, 2010 at 4:45 PM, Christian Sciberras uuf6...@gmail.comwrote: I'm confused, isn't this just like XSRF (cross-site request forgery)? Regards, Chris. On Wed, Jan 13, 2010 at 4:33 PM, Ronen Z ro...@quaji.com wrote: Hi,

Re: [Full-disclosure] All China, All The Time

2010-01-15 Thread Benji
Actually you were boasting, it was irrelevant to have what you have as a security precausion. Infact, one could argue that you were making your setup insecure by telling people how you're secured from the get go. On Fri, Jan 15, 2010 at 6:38 PM, Christian Sciberras uuf6...@gmail.comwrote: My

Re: [Full-disclosure] All China, All The Time

2010-01-15 Thread Benji
pointing me towards what to look for? On Fri, Jan 15, 2010 at 6:44 PM, Christian Sciberras uuf6...@gmail.comwrote: No, that was actually configuration description; best of luck finding our facility. On Fri, Jan 15, 2010 at 7:42 PM, Benji m...@b3nji.com wrote: Actually you were boasting

Re: [Full-disclosure] FREE STEPHEN WATT !!!

2010-01-21 Thread Benji
and my mum. On Thu, Jan 21, 2010 at 6:11 PM, Jeff Williams jeffwilli...@gmail.comwrote: You just forgot kaminsky, 2010/1/21 p...@hushmail.com -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Fuck Gadi Evron, Fuck #phr...@efnet, Fuck anti-sec.com kiddiotz, Fuck romeo, Fuck Fedz, Fuck Ratz

Re: [Full-disclosure] Cross Site Scripting (XSS) Vulnerability in ibibo

2010-02-02 Thread Benji
Xssed.com. That is all. Sent from my iPhone On 2 Feb 2010, at 20:10, rockey killer skg...@gmail.com wrote: network. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by

Re: [Full-disclosure] SMS Banking

2010-02-10 Thread Benji
Sorry to butt in, but may I also have a contract to be the agent for the tickets for this comedy show? Thanks BenjiManagementCo - Sending Your (Security) Theatre GLOBAL On Wed, Feb 10, 2010 at 7:27 PM, Craig S. Wright craig.wri...@information-defense.com wrote: Please do not misquote. The

Re: [Full-disclosure] Rising Online Virus Scanner ActiveX Control DoS (Stack overflow)

2010-02-17 Thread Benji
Dude you are such a rebel. # Because Bullshit like this is unsaleable and i don't want to waste time # coordinating patches with this vendor this is a fulldisc publishing. Sent from my iPhone On 17 Feb 2010, at 15:46, wirebonder 42 wirebonde...@googlemail.com wrote: # Exploit Title:

Re: [Full-disclosure] Why

2010-02-19 Thread Benji
Where should I send the cheque so that the funds may be released? On Fri, Feb 19, 2010 at 10:24 PM, Jonathan Barningham n3t...@hush.aiwrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 man someone please help me On Fri, 19 Feb 2010 22:08:43 + Jonathan Barningham n3t...@hush.ai

Re: [Full-disclosure] ACM.ORG data leak still there 4 days after announcing to CEO John White

2010-02-22 Thread Benji
I have a question.. I get the idea you've extracted the whole database, or as much as you can, and you have approached the company? Im confused as to why you'd attract the attention to yourself when you've broken quite a few laws. Sure, you can say you havent given them any information, but your

Re: [Full-disclosure] ACM.ORG data leak still there 4 days after announcing to CEO John White

2010-02-22 Thread Benji
you've displayed that a hole is there, someone could go and dump the database saving them the time of even looking for a vulnerable site. I'm just wondering what makes you so sure they wont do anything like that? On Mon, Feb 22, 2010 at 7:46 PM, the hacker i...@the-hacker.info wrote: Hello Benji

Re: [Full-disclosure] ACM.ORG data leak still there 4 days after announcing to CEO John White

2010-02-22 Thread Benji
I'm not a lawyer, and I assume Benji isn't either, but it's worth noting that Title 18 Section 1030, the Computer Fraud and Abuse Act of 1986, pretty much limits crimes to those intent on committing fraud or disclosing national secrets. Exposing personal information doesn't seem to fit under any

Re: [Full-disclosure] Ubuntu Lucid Lynx is Big brother Ubuntu

2010-02-25 Thread Benji
Im curious as to how you chose the wording for this sentence, mainly the 'autistic' part? I never asked for my OS to become this big chatroom filled with a bunch of autistic, idiotic facebook kids. I can't stand that. On Thu, Feb 25, 2010 at 10:37 PM, John Q Public johndoet...@hush.ai wrote:

Re: [Full-disclosure] Wordpress plugin 'Analytics360'- authenticated user sql injection

2010-03-01 Thread Benji
http://crowdfavorite.com/ loads fine here. On Mon, Mar 1, 2010 at 4:03 PM, Jan G.B. ro0ot.w...@googlemail.com wrote: Hi there, I just noticed that authenticated users for the admin area of a wordpress blog may inject code into database queries, when the plugin Analytics360 is activated.

Re: [Full-disclosure] I have been threatened.

2010-03-02 Thread Benji
If Yahoo has ninjas, what does Google have ?! @#! Sent from my iPhone On 2 Mar 2010, at 16:08, James Rankin kz2...@googlemail.com wrote: Mini Ninjas! On 2 March 2010 16:06, valdis.kletni...@vt.edu wrote: On Tue, 02 Mar 2010 09:01:59 EST, Kain, Becki (B.) said: Yahoo.com has assassins?

Re: [Full-disclosure] credit union phishing scam

2010-03-11 Thread Benji
Maybe we can get a definition of the Internet so I can fully grasp what this fishing game is? On 11 Mar 2010, at 08:58, Anders Klixbull a...@experian.dk wrote: Thank you shawarma! From: full-disclosure-boun...@lists.grok.org.uk [mailto:full- disclosure-boun...@lists.grok.org.uk] On

Re: [Full-disclosure] SQL DB Structure Extraction vulnerabilities

2010-03-20 Thread Benji
oh dude, I've missed you. On Wed, Mar 17, 2010 at 9:36 PM, MustLive mustl...@websecurity.com.uawrote: Hello Full-Disclosure! Yesterday I wrote English version of my article SQL DB Structure Extraction vulnerabilities (http://websecurity.com.ua/4038/). There is such variety of Information

Re: [Full-disclosure] SQL DB Structure Extraction vulnerabilities

2010-03-21 Thread Benji
I would love to, can you do an article about it please? Ive just about grasped email but I think I definitely have potential. Much love, Benji On Sun, Mar 21, 2010 at 7:56 PM, MustLive mustl...@websecurity.com.uawrote: *Hello Benji!* oh dude, I've missed you. Really? :-) To not miss me

Re: [Full-disclosure] WINDOWS KERNEL SOURCE LEAK GET IT NOW B4 INEVITABLE TAKEDOWN

2010-03-22 Thread Benji
This seems absurd. Why would any organisation holding 18-27~ year olds need staff?! On Mon, Mar 22, 2010 at 6:59 PM, valdis.kletni...@vt.edu wrote: On Mon, 22 Mar 2010 18:20:04 -, james o' hare said: On Mon, Mar 22, 2010 at 6:06 PM, valdis.kletni...@vt.edu wrote: On Mon, 22 Mar 2010

Re: [Full-disclosure] WINDOWS KERNEL SOURCE LEAK GET IT NOW B4 INEVITABLE TAKEDOWN

2010-03-22 Thread Benji
, 2010 at 8:26 PM, valdis.kletni...@vt.edu wrote: On Mon, 22 Mar 2010 19:27:35 -, Benji said: This seems absurd. Why would any organisation holding 18-27~ year olds need staff?! If you have to ask, the answer won't make any sense to you. But what the heck... Think back a year or two

Re: [Full-disclosure] WINDOWS KERNEL SOURCE LEAK GET IT NOW B4 INEVITABLE TAKEDOWN

2010-03-22 Thread Benji
to bear that in mind. On Mon, Mar 22, 2010 at 9:55 PM, valdis.kletni...@vt.edu wrote: On Mon, 22 Mar 2010 20:30:34 -, Benji said: to smoke. I was like the bounty hunter of the halls. Do you have hall monitors at 'college' (is that the correct spelling?)? If you do, email me, I'm currently

Re: [Full-disclosure] Possible RDP vulnerability

2010-03-27 Thread Benji
However, it was a trick question. ZZINGG On Sat, Mar 27, 2010 at 6:48 PM, Mr. Hinky Dink d...@mrhinkydink.comwrote: In your case, had you answered the question correctly I would have promised to never (again) blog about you arguing with Craig S. Wright.

Re: [Full-disclosure] StreamArmor v1.0 has Released!!!

2010-03-30 Thread Benji
WHY WOULD YOU TRUST SOMEONE CALLED EVIL FINGERS?!?!!!?!!!1ONEONEOMFGONE!!!ONETWO On Tue, Mar 30, 2010 at 3:53 PM, T Biehn tbi...@gmail.com wrote: HELLO AND THANK YOU FOR YOUR NOTICE I WILL QUICKLY DOWNLOAD THESE APPLICATIONS AND ERADICATE MY EVIL STREAMS. On Sun, Mar 28, 2010 at

Re: [Full-disclosure] Security system

2010-03-30 Thread Benji
You take someone who can't spell and has a website like that. seriously? On Tue, Mar 30, 2010 at 7:15 PM, Michael Holstein michael.holst...@csuohio.edu wrote: Any one got any ides how I would program a system to call me from a voip network to alert me of a home security breach.

Re: [Full-disclosure] Security system

2010-03-30 Thread Benji
Nevermind, people take Kaminsky seriously and he doesn't even *have* a website... On Tue, Mar 30, 2010 at 7:52 PM, Benji m...@b3nji.com wrote: You take someone who can't spell and has a website like that. seriously? On Tue, Mar 30, 2010 at 7:15 PM, Michael Holstein michael.holst

Re: [Full-disclosure] Security system

2010-04-02 Thread Benji
Good, they have minds of their own. On Fri, Apr 2, 2010 at 3:03 PM, T Biehn tbi...@gmail.com wrote: Can't hurt. I don't trust machines in DCs much less VPSs. An adversary with the resources and motivation to kill power, net, and jam GSM when they're pwning your house would probably be able

Re: [Full-disclosure] Weev's Mugshot

2010-04-06 Thread Benji
Try squinting and turning your head at a 780o angle parallel with the moon. On Tue, Apr 6, 2010 at 8:37 AM, BMF badmotherfs...@gmail.com wrote: On Mon, Apr 5, 2010 at 8:36 PM, Scarf Pride Worldwide terdlinkmob...@gmail.com wrote: Allegedly he obstructed justice by giving a false name.. most

Re: [Full-disclosure] Vulnerabilities in TAK cms

2010-04-08 Thread Benji
nah, he'd be telling us how that was an easy way to find valid accounts. -Benji On Thu, Apr 8, 2010 at 6:30 PM, T Biehn tbi...@gmail.com wrote: If there were an account lockout after 5 tries would you be telling us about how there was a DOS vector on the same software? -Travis On Mon, Apr

Re: [Full-disclosure] Vulnerability in CB Captcha for Joomla and Mambo

2010-04-15 Thread Benji
By this point, if these advisories arent automated, you're doing it wrong. On Thu, Apr 15, 2010 at 12:24 PM, MustLive mustl...@websecurity.com.uawrote: Hello Full-Disclosure! I want to warn you about security vulnerability in plugin CB Captcha (plug_cbcaptcha) for component Community Builder

Re: [Full-disclosure] Vulnerabilities in phpCOIN

2010-04-15 Thread Benji
tl;dr you're all supposedly wrong On Thu, Apr 15, 2010 at 9:55 PM, MustLive mustl...@websecurity.com.uawrote: Hello Jan, Valdis, Christian and Jeff! I'll answer at all your letters in one message. Even if I already banned Jan and he put my email to his blacklist, it's possible that he will

Re: [Full-disclosure] [CORELAN-10-032] - Easyzip 2000 .zip Stack BOF

2010-04-26 Thread Benji
Please forward information about this certification. Benji CE, CCNA, CCDA, CCNP, CCSP, CCVP, CCIP, CCDP, CCIE, CEH, GIAC, ECSA, LPT (Unemployed) On Sun, Apr 25, 2010 at 8:21 PM, jeff smith smith.jeff...@gmail.com wrote: Wow, once again, scary shit... Are you going to exploit EVERY FUCKING

Re: [Full-disclosure] 0days for sale

2010-05-04 Thread Benji
tree trousand dorrar? On Tue, May 4, 2010 at 3:16 PM, adida...@hushmail.com wrote: Hello, 0days for sale in both DNS-SEC and IPv6. Bug is in specs. Only serious buyers, thanks. ___ Full-Disclosure - We believe in it. Charter:

Re: [Full-disclosure] Vulnerabilities in DS-Syndicate for Joomla

2010-05-23 Thread Benji
oh cool, so you've moved from discovering leet xss vulnerabilities to publishing old exploits? I would offer you a sec. job, but unfortunately I think you're too qualified. On Sat, May 22, 2010 at 4:09 PM, MustLive mustl...@websecurity.com.uawrote: Hello Full-Disclosure! I want to warn you

Re: [Full-disclosure] Vulnerabilities in DS-Syndicate for Joomla

2010-05-26 Thread Benji
aww shucks, I love you too On Wed, May 26, 2010 at 9:31 PM, MustLive mustl...@websecurity.com.uawrote: Hello Benji! It's good that you are drawing attention to my advisories, but very often your letters are unequal and not serious. So I've put you in my blacklist. I already wrote

Re: [Full-disclosure] PuTTY private key passphrase stealing attack

2010-06-01 Thread Benji
You should make a show about it. On Tue, Jun 1, 2010 at 6:07 AM, Rob Fuller jd.mu...@gmail.com wrote: Couldn't this also be thwarted by having a MOTD? It generally displays before the bashrc if I'm not mistaken. -- Rob Fuller | Mubix Room362.com | Hak5.org On Mon, May 31, 2010 at 8:47

Re: [Full-disclosure] Hacxx Anti Malware for Windows XP

2010-06-07 Thread Benji
on an unrelated note, would anyone know how to uninstall this? thx intentrnets. On Mon, Jun 7, 2010 at 4:27 PM, T Biehn tbi...@gmail.com wrote: Actually, The code is clean (Yes I looked), other than him setting his website as the search provider for IE. -Travis On Mon, Jun 7, 2010 at

Re: [Full-disclosure] Hacxx Anti Malware for Windows XP

2010-06-07 Thread Benji
, 2010 at 10:23 PM, Benji m...@b3nji.com wrote: on an unrelated note, would anyone know how to uninstall this? thx intentrnets. On Mon, Jun 7, 2010 at 4:27 PM, T Biehn tbi...@gmail.com wrote: Actually, The code is clean (Yes I looked), other than him setting his website as the search

Re: [Full-disclosure] Hacxx Anti Malware for Windows XP

2010-06-07 Thread Benji
so what are you saying? norton internet security 2010 is malware? that protects against malware? stop being such a troll. On Mon, Jun 7, 2010 at 10:38 PM, Peter Besenbruch p...@lava.net wrote: On Mon, 7 Jun 2010 21:31:03 +0100 Benji m...@b3nji.com wrote: Im new to computers, what is wrong

Re: [Full-disclosure] RDP, can it be done safely?

2010-06-09 Thread Benji
That wouldve been me. Can I have the royalties as some sort of discount? chrz. On Wed, Jun 9, 2010 at 11:53 PM, Larry Seltzer la...@larryseltzer.comwrote: digression 10 years ago I wrote a book on Terminal Services for Windows 2000. Believe it or not, I still get trivial royalties on it,

Re: [Full-disclosure] RDP, can it be done safely?

2010-06-09 Thread Benji
I like this idea. On Wed, Jun 9, 2010 at 11:58 PM, Larry Seltzer la...@larryseltzer.comwrote: I might be able to buy you one beer with the money, but it won’t be anything good. *From:* Thor (Hammer of God) [mailto:t...@hammerofgod.com] *Sent:* Wednesday, June 09, 2010 6:56 PM *To:*

Re: [Full-disclosure] RDP, can it be done safely?

2010-06-09 Thread Benji
thats the best you could come up with? you sir, need to browse the internet some moar. On Thu, Jun 10, 2010 at 12:15 AM, Larry Seltzer la...@larryseltzer.comwrote: Click here to retrieve your free beer. http://bit.ly/4a8VOA *From:* Benji [mailto:m...@b3nji.com] *Sent:* Wednesday, June

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Benji
because when she gets 0wn3d she can be all like 'ruh roh, well, 0day can happen to anyone' On Fri, Jun 11, 2010 at 4:01 PM, Benjamin Franz jfr...@freerun.com wrote: On 06/11/2010 02:40 AM, Christian Sciberras wrote: In my humble opinion, he could have waited a couple more days just in case

Re: [Full-disclosure] Microsoft Windows Help Centre Handles Malformed Escape Sequences Incorrectly

2010-06-11 Thread Benji
You're just jealous I had the intuition to protect myself. Sent from my iPhone On 11 Jun 2010, at 17:03, T Biehn tbi...@gmail.com wrote: It's a good thing I ran that anti-hacker script!!! On Fri, Jun 11, 2010 at 11:28 AM, Benji m...@b3nji.com wrote: because when she gets 0wn3d she can be all

Re: [Full-disclosure] My private key

2010-06-12 Thread Benji
And then gets his identity stolen? Sent from my iPhone On 12 Jun 2010, at 12:12, Larry Seltzer la...@larryseltzer.com wrote: Oh cool, this is like those TV ads where the guy parades his social security # around, right? From: full-disclosure-boun...@lists.grok.org.uk [mailto:full-

Re: [Full-disclosure] Reg: Gmail Account Deleted

2010-06-13 Thread Benji
It sounds like you've been the victim of a hacker, probably chinese. Sounds like 0day, talk to mubix. On Sun, Jun 13, 2010 at 2:34 PM, Srinivas Naik naik.sr...@gmail.com wrote: Hi, My friends Gmail got deleted very recently; I dono if there is some problem with Google or any other

Re: [Full-disclosure] Vulnerability in Huge MS Server

2010-06-14 Thread Benji
or zimbabwe $? On Mon, Jun 14, 2010 at 6:47 PM, valdis.kletni...@vt.edu wrote: On Mon, 14 Jun 2010 13:39:16 EDT, musnt live said: Since this no is free bugs. Opening bid for multipurpose remote server PoC affecting: I no SHARE right now -- only to serious bidder who no blink at 5 digits

Re: [Full-disclosure] yahoomail dom based xss vulnerability

2010-06-15 Thread Benji
Sup bro I waz checkin owt ur javascriptz skriptz and waz wonderin if u cud explain how diz shiz werks. Peaze. Sent from my iPhone On 15 Jun 2010, at 09:18, pratul agrawal pratu...@yahoo.com wrote: Its working Bro. I think u had done some mistakes so u try it again with check that

Re: [Full-disclosure] THQ website has multiple SQL injection bugs, and a reflected XSS

2010-06-17 Thread Benji
rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble rabble On Wed, Jun 16, 2010 at 9:05 PM, Harry Balls thqaredumbas...@yahoo.com wrote: This is pretty

Re: [Full-disclosure] targetted SSH bruteforce attacks

2010-06-17 Thread Benji
What? Think about what you said. Anyone. else. seeing. a. targetted. attack. Why would anyone else see a TARGETTED attack? anyway, no, you're not special, distributed SSH bruteforce is normal. On Thu, Jun 17, 2010 at 1:44 PM, Gary Baribault g...@baribault.net wrote: I just knew that people

Re: [Full-disclosure] PacketStorm

2010-06-22 Thread Benji
packetstorm goes down and leading internet research gets owned? coincidence? i think not On Tue, Jun 22, 2010 at 4:53 PM, Stack Smasher stacksmas...@gmail.com wrote: Dude you just got P0wn3D!!! For the low low price of just $19.95 I can scan your site with a free version of

Re: [Full-disclosure] Congratulations Andrew

2010-06-25 Thread Benji
Same thing? Sent from my iPhone On 25 Jun 2010, at 08:34, Ed Carp edc...@gmail.com wrote: Auernheimer was also arrested in March for giving a false name to law enforcement officers responding to a parking complaint. Idiot. Sent from my iPad, probably mobile On Jun 25, 2010, at 12:06

Re: [Full-disclosure] Many sites hacked at Bluehost (including their CEO blog)

2010-06-27 Thread Benji
You've got to be fucking kidding me You spam reddit with your retarded, provoking OMFG THE INTERNET IS GOING TO IMPLODE posts, and now full disclosure? You've deleted my comments off of your blog posts before, and you seriously need to stop posting about the same crap over and over again...

Re: [Full-disclosure] [funsec] The Economist, cyber war issue

2010-07-01 Thread Benji
OMG IT'S THE INTERNET AGAIN On Thu, Jul 1, 2010 at 3:37 PM, Joel Esler joel.es...@me.com wrote: Yeah!  Moar buzzwords! On Jul 1, 2010, at 9:23 AM, Gadi Evron wrote: The upcoming issue will be about cyber war. Check out the front page image:

Re: [Full-disclosure] Should nmap cause a DoS on cisco routers?

2010-07-01 Thread Benji
That was certainly a useful email. On Thu, Jul 1, 2010 at 9:42 PM, Dan Kaminsky d...@doxpara.com wrote: I would not object to posts on Full-Disclosure along the lines of nmap -sV crashes x device.  Unauthenticated remote permanent DoS's from standard network scanning tools are certainly

Re: [Full-disclosure] Should nmap cause a DoS on cisco routers?

2010-07-08 Thread Benji
to improve HP run nmap -A --allports printsvr IP on your network daily! nmap -A -p9100-9107 printsvr IP FTFY. On Wed, Jul 7, 2010 at 9:52 AM, coderman coder...@gmail.com wrote: On Thu, Jul 01, 2010 at 08:01:26PM -0400, Dan Kaminsky wrote: ...  If we can't get pissed, how is that QA guy

Re: [Full-disclosure] Using of the sites for attacks on other sites

2010-07-11 Thread Benji
One say, I hope I can troll FD as well as you do. Sent from my iPhone On 11 Jul 2010, at 21:53, MustLive mustl...@websecurity.com.ua wrote: Hello Chris and Sebastien! I do not see your name anywhere in the top ten? Chris, I'll answer at your question, even Sebastien already have answered

Re: [Full-disclosure] Two biggest Indian University Websites are vulnerable

2010-07-17 Thread Benji
yesterday. They are aware of the problem. Now upto them how much time they will take to rectify it. We hope they atleast have the wisdom to bring the site down till it is debugged. They have the wisest men working for them, after all. 2. In reply to other email from Benji, discovery consists

Re: [Full-disclosure] Sending spam via sites and creating spam-botnets

2010-07-21 Thread Benji
P.S. If your site will be DDoSed from Google's servers or you will receive spam from IBM's servers, than you will be knowing what type of botnets it is. Pjear bitches. Sent from my iPhone On 20 Jul 2010, at 19:50, MustLive mustl...@websecurity.com.ua wrote: Hello participants of

Re: [Full-disclosure] On the iPhone PDF and kernel exploit

2010-08-05 Thread Benji
.. surely if this was the index of webroot we'd see faq.html etc? are we sure that this isnt infact a purpose made folder? On Thu, Aug 5, 2010 at 11:59 AM, Mario Vilas mvi...@gmail.com wrote: http://jailbreakme.com/_/ gives me a 404 Not Found error. There were a few vulnerabilities in

Re: [Full-disclosure] so like i hrd python devz like mudkipz?

2010-08-27 Thread Benji
All publicity is good publicity - Michael Scott On Fri, Aug 27, 2010 at 7:05 PM, Tim tim-secur...@sentinelchicken.org wrote: so like i hrd python devz like mudkipz?  http://bugs.python.org/issue9702 I presume you are Dave B? So this is a great example of why introductory programming

Re: [Full-disclosure] so like i hrd python devz like mudkipz?

2010-08-27 Thread Benji
cool, send my regards. On Fri, Aug 27, 2010 at 7:57 PM, spamtester spamtester spamtesterspamtes...@gmail.com wrote: On 28 August 2010 04:56, Benji m...@b3nji.com wrote: maybe it's correct, you should send a letter to it and find out. please note: turn around time: 2 years. My relatives

Re: [Full-disclosure] so like i hrd python devz like mudkipz?

2010-08-27 Thread Benji
, Benji m...@b3nji.com wrote: k just dont tell my dad please :/ you are funny you know. You do realise you cannot expect to hold this email account  / domain with incorrect whois information / information like that. What are you clueless or just not caring? You have held this domain since

Re: [Full-disclosure] so like i hrd python devz like mudkipz?

2010-08-27 Thread Benji
k just dont tell my dad please :/ On Fri, Aug 27, 2010 at 7:25 PM, spamtester spamtester spamtesterspamtes...@gmail.com wrote: On 28 August 2010 04:14, Benji m...@b3nji.com wrote: All publicity is good publicity  - Michael Scott YOU DUN GOOFED! whois for b3nji.com Registrant Contact

Re: [Full-disclosure] monitoring the media monitors for fun and profit!

2010-09-22 Thread Benji
what On Tue, Sep 21, 2010 at 7:25 PM, omfgo...@hushmail.com wrote: monitoring the media monitors for fun and profit! http://www.robtex.com/ip/64.38.235.186.html http://www.robtex.com/ip/64.38.235.189.html http://www.robtex.com/ip/173.201.177.83.html

Re: [Full-disclosure] XSS in a lot of products

2010-09-30 Thread Benji
Thou shalt not read anymore emails for fear of ownage. Sent from my BlackBerry® wireless device -Original Message- From: rancor theran...@gmail.com Sender: full-disclosure-boun...@lists.grok.org.uk Date: Wed, 29 Sep 2010 21:02:59 To: pepelotas...@gmail.com Cc:

Re: [Full-disclosure] full disclosure my dear (Microsoft IIS 6.0 Denial of Service)

2010-10-01 Thread Benji
geeks - the only ones that could ever possibly care about a DOS. On Fri, Oct 1, 2010 at 10:23 AM, Jacky Jack jacksonsmth...@gmail.com wrote: Are you trying to Pwn$ G33ks here? On Fri, Oct 1, 2010 at 8:41 AM, HI-TECH . isowarez.isowarez.isowa...@googlemail.com wrote: vulnerability

Re: [Full-disclosure] Ebay and HTML/JS/PDF/FLash includes

2010-10-07 Thread Benji
This is because the average Iq of your typical eBay user is 100 and thus rely on 'ooohh shiny' --Original Message-- From: bugme not Sender: full-disclosure-boun...@lists.grok.org.uk To: full-disclosure@lists.grok.org.uk Subject: [Full-disclosure] Ebay and HTML/JS/PDF/FLash includes

Re: [Full-disclosure] WikiLeaks

2010-10-07 Thread Benji
Quit whining Sent from my BlackBerry® wireless device -Original Message- From: Cal Leeming [Simplicity Media Ltd] cal.leem...@simplicitymedialtd.co.uk Sender: full-disclosure-boun...@lists.grok.org.uk Date: Thu, 07 Oct 2010 15:05:18 To: full-disclosure@lists.grok.org.uk

Re: [Full-disclosure] OT: Hacking Pink Floyd

2010-10-14 Thread Benji
Do you have to take a breath every couple of seconds? It's painful to listen to On Thu, Oct 14, 2010 at 11:26 PM, Thor (Hammer of God) t...@hammerofgod.com wrote: I’ve had several communications with some of you guys about music and such, so I thought this would be a fun way to kick off yet

Re: [Full-disclosure] Fwd: ipv6 flaw (is bullshit)

2010-10-18 Thread Benji
Oh Andrew, I do love it when you declare yourself 'one of the worlds most skilled web application and browser exploit hackers in the world'. Got your macs back yet or still rockin' an aspire one? Sent from my BlackBerry® wireless device -Original Message- From: Andrew Auernheimer

Re: [Full-disclosure] Fwd: ipv6 flaw (is bullshit)

2010-10-19 Thread Benji
Dramatisation? I don't remember dramatising anything? Sent from my BlackBerry® wireless device -Original Message- From: batch stack batc...@gmail.com Sender: full-disclosure-boun...@lists.grok.org.uk Date: Tue, 19 Oct 2010 05:51:56 To: full-disclosure@lists.grok.org.uk Subject: Re:

Re: [Full-disclosure] Fwd: ipv6 flaw (is bullshit)

2010-10-26 Thread Benji
What did you say? Sent from my BlackBerry® wireless device -Original Message- From: Christian Sciberras uuf6...@gmail.com Sender: full-disclosure-boun...@lists.grok.org.uk Date: Tue, 26 Oct 2010 19:56:32 To: PsychoBillyzpamh...@gmail.com Cc: full-disclosure@lists.grok.org.uk Subject:

Re: [Full-disclosure] African ISP SekuritY

2010-10-27 Thread Benji
Isn't it still a hack depending on how the u/p were obtained? Could someone please explain the definition based difference between a breach and a hack? Sent from my BlackBerry® wireless device -Original Message- From: Bill Hicks 420b1llh1...@gmail.com Sender:

Re: [Full-disclosure] 0-day vulnerability

2010-10-28 Thread Benji
clearly sir, you are uneducated. http://www.youtube.com/watch?v=L74o9RQbkUA On Fri, Oct 29, 2010 at 2:18 AM, Josey Yelsef hg_expo...@yahoo.com wrote: Are you threatening the internet? --- On *Fri, 10/29/10, Jubei Trippataka vpn.1.fana...@gmail.com* wrote: From: Jubei Trippataka

Re: [Full-disclosure] Evilgrade 2.0 - the update explotation framework is back

2010-10-29 Thread Benji
Actually, that time probably would've been a v1, but I'm fine with it being left as it is. On Fri, Oct 29, 2010 at 9:43 PM, Jacky Jack jacksonsmth...@gmail.comwrote: It's now a time for vendors to re-consider their updating scheme. On Fri, Oct 29, 2010 at 6:25 PM, [ISR] - Infobyte Security

Re: [Full-disclosure] [0dayz] Acrobat Reader Memory Corruption RemoteArbitrary Code Execution

2010-11-04 Thread Benji
Are we sure this is the correct use of the term 0day? Sent from my BlackBerry® wireless device -Original Message- From: s...@hushmail.com Sender: full-disclosure-boun...@lists.grok.org.uk Date: Wed, 03 Nov 2010 14:00:24 To: bugt...@securityfocus.com Cc: full-disclosure@lists.grok.org.uk

Re: [Full-disclosure] [0dayz] Acrobat Reader Memory Corruption RemoteArbitrary Code Execution

2010-11-04 Thread Benji
with user permissions. Please stop posting to this list. Your like mustlive without the crappy vulns. -Original Message- From: full-disclosure-boun...@lists.grok.org.uk [mailto: full-disclosure-boun...@lists.grok.org.uk] On Behalf Of Benji Sent: 04 November 2010 10:25 To: s

Re: [Full-disclosure] Open Letter to Lee Vartan, Assistant United States Attorney in regards to the Goatse SecurityiPad case.

2010-11-18 Thread Benji
I can't even troll F-D this bad, and its no longer remotely on topic. Its become; Who-can-make-the-other-look-like-a-whiney-little-bitch-first Why not talk on IRC? Hint; weev hangs in #phrack Sent from my BlackBerry® wireless device -Original Message- From: huj huj huj

Re: [Full-disclosure] Open Letter to Lee Vartan, Assistant United States Attorney in regards to the Goatse SecurityiPad case.

2010-11-18 Thread Benji
Although I very much agree with what you've said, Andrew has said previously that the charges have been dropped, or atleast, they have been 'forgotten about'. Sent from my BlackBerry® wireless device -Original Message- From: Andrew Kirch trel...@trelane.net Sender:

Re: [Full-disclosure] virus in email RTF message MS OE almost disabled

2010-11-23 Thread Benji
*throws his The CISSP Prep Guide: Gold Edition away, picks up Security for Dummies* On Tue, Nov 23, 2010 at 3:03 PM, Mikhail A. Utin mu...@commonwealthcare.org wrote: This my final reply. For still interested: - it happened on my home PC - immediately disconnected (for a few interested

Re: [Full-disclosure] new facebook SQL injection vulnerability

2010-11-30 Thread Benji
so if I upload a 'hacked by benji' html file to my google sites account, by your logic this would count as hacking Google. Cant wait to see The Register report about this. 2010/11/30 Maciej Gojny v...@ariko-security.com Hello Full Disclosure ! Today i have found next SQL injection

Re: [Full-disclosure] new facebook SQL injection vulnerability

2010-11-30 Thread Benji
No, you've found a vuln in a Facebook App. Aka a 3rd party script included via iframe to a directory at apps.facebook.com. So no access to real Facebook.com databases/servers, probably just a dreamhost account. 2010/11/30 Maciej Gojny v...@ariko-security.com Benji@ I dont understand You, I

Re: [Full-disclosure] new facebook SQL injection vulnerability

2010-11-30 Thread Benji
http://apps.facebook.com/buysalepals/viewuser.php?u=10423643201' 2010/11/30 Reed Loden r...@reedloden.com What I believe Benji is saying is that it looks (from the little information you posted) like you just found a SQL injection in a facebook app, which is not the same thing

Re: [Full-disclosure] New Source Code Vulnerability Scanner (Free30 Day Trial)

2010-12-03 Thread Benji
I NEED AN ADULT --Original Message-- From: Cal Leeming [Simplicity Media Ltd] Sender: full-disclosure-boun...@lists.grok.org.uk To: dave b Cc: full-disclosure@lists.grok.org.uk Cc: vulns...@hushmail.com ReplyTo: cal.leem...@simplicitymedialtd.co.uk Subject: Re: [Full-disclosure] New

Re: [Full-disclosure] Linux kernel exploit

2010-12-08 Thread Benji
working here aswell ownst...@local[~]$ uname -a FreeBSD local 8.1-RELEASE-p1 FreeBSD 8.1-RELEASE-p1 #4: Thu Sep 23 08:30:18 UTC 2010 r...@benjir0x:/*usr*/*obj*/*usr*/*src*/*sys*/GENERIC amd64 ownst...@local[~]$ ./w00tw00t [*] Resolving kernel addresses... [+] Resolved econet_ioctl to

Re: [Full-disclosure] Linux kernel exploit

2010-12-13 Thread Benji
I heard rumors it's backdoored and sends your /etc/passwd and uname to Dan Rosenberg. Just sayin' On Mon, Dec 13, 2010 at 3:27 PM, fireb...@backtrack.com.br wrote: I tested it on a VM with CentOS 5.5 i386 updated and did not work. Last login: Tue Dec 13 12:48:54 2010 [r...@localhost~]#nano

Re: [Full-disclosure] Linux kernel exploit

2010-12-13 Thread Benji
in there, it still would have posed no risk, because the sandbox is re-generated every time (see comment 1) No more troll feed for you! On Mon, Dec 13, 2010 at 9:16 PM, Benji m...@b3nji.com wrote: wait wait wait. you dont have time to read header notes, but do have time to run code you dont really

Re: [Full-disclosure] Linux kernel exploit

2010-12-13 Thread Benji
wait wait wait. you dont have time to read header notes, but do have time to run code you dont really know what it does on your system? can I send you some code? it's a linux 2.6.* 0day, remote root. On Mon, Dec 13, 2010 at 9:14 PM, Cal Leeming [Simplicity Media Ltd]

Re: [Full-disclosure] Linux kernel exploit

2010-12-13 Thread Benji
it doesnt contribute to testing, i can assure you there's been enough 'tests' of this exploit. On Mon, Dec 13, 2010 at 9:32 PM, Cal Leeming [Simplicity Media Ltd] cal.leem...@simplicitymedialtd.co.uk wrote: Actually Ryan, I'll think you'll find a lot of people just wanted to contribute

Re: [Full-disclosure] OpenBSD IPSEC has backdoor

2010-12-15 Thread Benji
Dont encourage that weasel. On Wed, Dec 15, 2010 at 2:33 PM, Nahuel Grisolia nah...@bonsai-sec.comwrote: Kingcope, Where is the exploit for this? :P regards, -- Nahuel Grisolia - C|EH Information Security Consultant Bonsai Information Security Project Leader http://www.bonsai-sec.com/

Re: [Full-disclosure] RHEL Linux Kernel Exploit

2010-12-15 Thread Benji
wooosshhh, right over Vlads head On Wed, Dec 15, 2010 at 5:35 PM, valdis.kletni...@vt.edu wrote: On Wed, 15 Dec 2010 12:25:26 EST, musnt live said: [musntl...@pizda ~]# gcc -o hakaruski fullnullson.c ./hakaruski [*] Failed to open file descriptors. '#'. Exploit testing fail.

  1   2   3   >