Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

A New Class of Vulnerability in Oracle: Lateral SQL Injection

 

 

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


davidl at ngssoftware

Apr 24, 2008, 9:49 AM

Post #1 of 21 (910 views)
Permalink
A New Class of Vulnerability in Oracle: Lateral SQL Injection

Hey all,
I've just released some research that demonstrates a new class of
vulnerability in Oracle and how it can be exploited by an attacker. You can
grab the paper from here:
http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf
Cheers,
David Litchfield
NGSSoftware Ltd
http://www.ngssoftware.com/
http://www.davidlitchfield.com/blog


--
E-MAIL DISCLAIMER

The information contained in this email and any subsequent
correspondence is private, is solely for the intended recipient(s) and
may contain confidential or privileged information. For those other than
the intended recipient(s), any disclosure, copying, distribution, or any
other action taken, or omitted to be taken, in reliance on such
information is prohibited and may be unlawful. If you are not the
intended recipient and have received this message in error, please
inform the sender and delete this mail and any attachments.

The views expressed in this email do not necessarily reflect NGS policy.
NGS accepts no liability or responsibility for any onward transmission
or use of emails and attachments having left the NGS domain.

NGS and NGSSoftware are trading names of Next Generation Security
Software Ltd. Registered office address: 52 Throwley Way, Sutton, SM1
4BF with Company Number 04225835 and VAT Number 783096402

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


xploitable at gmail

Apr 24, 2008, 1:32 PM

Post #2 of 21 (857 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, Apr 24, 2008 at 5:49 PM, David Litchfield
<davidl [at] ngssoftware> wrote:
> Hey all,
> I've just released some research that demonstrates a new class of
> vulnerability in Oracle and how it can be exploited by an attacker. You can
> grab the paper from here:
> http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf
> Cheers,
> David Litchfield
> NGSSoftware Ltd
> http://www.ngssoftware.com/
> http://www.davidlitchfield.com/blog
>

Thanks for waiting until Web Application Security Awareness Day,

All the best,

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


malix at hush

Apr 24, 2008, 1:47 PM

Post #3 of 21 (855 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

And here I thought you were canceling that piece of shit.
That you even presume to believe that David Litchfield of all
people gives the slightest fuck about what you have to say simply
blows my mind.
As always, please (and let me spell it out for you), SHUT THE FUCK
UP.

On Thu, 24 Apr 2008 13:32:43 -0700 n3td3v <xploitable [at] gmail>
wrote:
>On Thu, Apr 24, 2008 at 5:49 PM, David Litchfield
><davidl [at] ngssoftware> wrote:
>> Hey all,
>> I've just released some research that demonstrates a new class
>of
>> vulnerability in Oracle and how it can be exploited by an
>attacker. You can
>> grab the paper from here:
>> http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf
>> Cheers,
>> David Litchfield
>> NGSSoftware Ltd
>> http://www.ngssoftware.com/
>> http://www.davidlitchfield.com/blog
>>
>
>Thanks for waiting until Web Application Security Awareness Day,
>
>All the best,
>
>n3td3v
>
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/

--
Click here to compare rates and find the best deal on renting a car.
http://tagline.hushmail.com/fc/Ioyw6h4eRvD8OebJMba3jGtSFzdQpeikv8jYecE9cx4Yl239ZI8uxC/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


xploitable at gmail

Apr 24, 2008, 1:53 PM

Post #4 of 21 (858 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, Apr 24, 2008 at 9:47 PM, <malix [at] hush> wrote:
> And here I thought you were canceling that piece of shit.
> That you even presume to believe that David Litchfield of all
> people gives the slightest fuck about what you have to say simply
> blows my mind.
> As always, please (and let me spell it out for you), SHUT THE FUCK
> UP.

What have you ever contributed to the security community apart from
this bullshit?

All the best,

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Valdis.Kletnieks at vt

Apr 24, 2008, 2:24 PM

Post #5 of 21 (848 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, 24 Apr 2008 22:13:09 BST, n3td3v said:

> High up government officials are backing Web Application Application
> Security Awareness Day, so I would watch what you're saying.

Can you cite an actual press release or other similar thing from anybody
other than yourself? Pretty wimpy-ass backing if they won't even come out
and say "Yeah, sounds like a good idea", much less "We're supporting it and
have several events planned".


ureleet at gmail

Apr 24, 2008, 2:29 PM

Post #6 of 21 (866 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

did u just threaten everyone? and for furthermore, did that richard dude
just threaten everyone? nice move.
i am sure richard didnt want his personal email posted to the list, thats
why he sent it directly to you.

On Thu, Apr 24, 2008 at 5:13 PM, n3td3v <xploitable [at] gmail> wrote:

>
> On Thu, Apr 24, 2008 at 9:58 PM, Kurt Dillard <kurtdillard [at] msn> wrote:
> > I wouldn't use such harsh language as Malix, but he's correct. David has
> > done a lot of ground-breaking research over the past decade and he's had
> a
> > major impact on how Microsoft and Oracle create, test, and patch their
> > products. You are unemployed and note that you were in some Yahoo chat
> > groups on your CV. Sarcastically whining at David only reaffirms what we
> all
> > think of you.
>
> Hey,
>
> High up government officials are backing Web Application Application
> Security Awareness Day, so I would watch what you're saying.
>
>
> ---------- Forwarded message ----------
> From: Richard Golodner <rgolodner [at] infratection>
> Date: Thu, Apr 24, 2008 at 5:53 PM
> Subject:
> To: n3td3v <xploitable [at] gmail>
>
>
>
> N3td3v, so you used bad language and lost your cool, so what. Do not
> give up on 5/1. You do not know who has planned to do what. All you really
> know is that there are a bunch of assholes out there that have balls that
> grow very big when they are hiding behind an email address and computer.
> Some of these fuckers I told to introduce themselves to me at any IT-Sec
> conference and then we can see what is up. To this day not one of them has
> said hello to me.
> I am from the street with multiple gunshot wounds to my body, but
> did not die. If it was not for IT I would be dead or in jail, but after
> twenty odd years have made a career and a shitload of money.
> What I am saying is that these guys are punks. I wonder how much
> mouth they would have if they were to actually meet you in person. I am
> not
> a big man 5'11 185 pounds, but have several belts in various combative
> martial art formats. From now on at IT conferences I am going to put
> "friend
> of n3td3v" underneath my real name on my nametag and we will see who has
> the
> real balls. And if someone thinks they are tougher than me, I will give
> them
> the opportunity to prove it. It will not be the first time I have punched
> out a motherfucker at one of these events, but I let them attack me first.
> Then, I kick the shit out of them.
> DO NOT LET THESE FUCKERS BEAT YOU! ANNOUNCE THAT 5/1 IS STILL ON!
> And do not let these douche bags upset you. This is most important. Do not
> apologize for what you are doing, ever! And keep on rolling forward.
> Richard
>


ureleet at gmail

Apr 24, 2008, 2:30 PM

Post #7 of 21 (855 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

so did u or didnt u cancel it? please make up ur mind so we know whether to
post anything on may 1 or not.
i support the "take a day off from fd" day on may 1.

On Thu, Apr 24, 2008 at 4:32 PM, n3td3v <xploitable [at] gmail> wrote:

>
> On Thu, Apr 24, 2008 at 5:49 PM, David Litchfield
> <davidl [at] ngssoftware> wrote:
> > Hey all,
> > I've just released some research that demonstrates a new class of
> > vulnerability in Oracle and how it can be exploited by an attacker. You
> can
> > grab the paper from here:
> > http://www.databasesecurity.com/dbsec/lateral-sql-injection.pdf
> > Cheers,
> > David Litchfield
> > NGSSoftware Ltd
> > http://www.ngssoftware.com/
> > http://www.davidlitchfield.com/blog
> >
>
> Thanks for waiting until Web Application Security Awareness Day,
>
> All the best,
>
> n3td3v
>


xploitable at gmail

Apr 24, 2008, 2:31 PM

Post #8 of 21 (862 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, Apr 24, 2008 at 10:24 PM, <Valdis.Kletnieks [at] vt> wrote:
> On Thu, 24 Apr 2008 22:13:09 BST, n3td3v said:
>
> > High up government officials are backing Web Application Application
> > Security Awareness Day, so I would watch what you're saying.
>
> Can you cite an actual press release or other similar thing from anybody
> other than yourself? Pretty wimpy-ass backing if they won't even come out
> and say "Yeah, sounds like a good idea", much less "We're supporting it and
> have several events planned".
>

Did MI6 need a press release to kill Princess Diana?

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


ureleet at gmail

Apr 24, 2008, 2:34 PM

Post #9 of 21 (854 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

objection, speculation.


On Thu, Apr 24, 2008 at 5:31 PM, n3td3v <xploitable [at] gmail> wrote:

>
> On Thu, Apr 24, 2008 at 10:24 PM, <Valdis.Kletnieks [at] vt> wrote:
> > On Thu, 24 Apr 2008 22:13:09 BST, n3td3v said:
> >
> > > High up government officials are backing Web Application Application
> > > Security Awareness Day, so I would watch what you're saying.
> >
> > Can you cite an actual press release or other similar thing from anybody
> > other than yourself? Pretty wimpy-ass backing if they won't even come
> out
> > and say "Yeah, sounds like a good idea", much less "We're supporting it
> and
> > have several events planned".
> >
>
> Did MI6 need a press release to kill Princess Diana?
>


malix at hush

Apr 24, 2008, 2:46 PM

Post #10 of 21 (852 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

Kurt,
You're right, such language isn't constructive, my apologies.

n3td3v,
Given Richard's extraordinary credentials
(http://www.linkedin.com/pub/5/04B/758) I suggest you two team up
and start a new consultancy: The Asshat Stikeforce!
Then you can give each other a regular stroke, both literal and
figurative.

On Thu, 24 Apr 2008 14:13:09 -0700 n3td3v <xploitable [at] gmail>
wrote:
>On Thu, Apr 24, 2008 at 9:58 PM, Kurt Dillard
><kurtdillard [at] msn> wrote:
>> I wouldn't use such harsh language as Malix, but he's correct.
>David has
>> done a lot of ground-breaking research over the past decade and
>he's had a
>> major impact on how Microsoft and Oracle create, test, and
>patch their
>> products. You are unemployed and note that you were in some
>Yahoo chat
>> groups on your CV. Sarcastically whining at David only
>reaffirms what we all
>> think of you.
>
>Hey,
>
>High up government officials are backing Web Application
>Application
>Security Awareness Day, so I would watch what you're saying.
>
>
>---------- Forwarded message ----------
>From: Richard Golodner <rgolodner [at] infratection>
>Date: Thu, Apr 24, 2008 at 5:53 PM
>Subject:
>To: n3td3v <xploitable [at] gmail>
>
>
>
> N3td3v, so you used bad language and lost your cool, so
>what. Do not
> give up on 5/1. You do not know who has planned to do what. All
>you really
> know is that there are a bunch of assholes out there that have
>balls that
> grow very big when they are hiding behind an email address and
>computer.
> Some of these fuckers I told to introduce themselves to me at any
>IT-Sec
> conference and then we can see what is up. To this day not one of
>them has
> said hello to me.
> I am from the street with multiple gunshot wounds to my
>body, but
> did not die. If it was not for IT I would be dead or in jail, but
>after
> twenty odd years have made a career and a shitload of money.
> What I am saying is that these guys are punks. I wonder
>how much
> mouth they would have if they were to actually meet you in
>person. I am not
> a big man 5'11 185 pounds, but have several belts in various
>combative
> martial art formats. From now on at IT conferences I am going to
>put "friend
> of n3td3v" underneath my real name on my nametag and we will see
>who has the
> real balls. And if someone thinks they are tougher than me, I
>will give them
> the opportunity to prove it. It will not be the first time I have
>punched
> out a motherfucker at one of these events, but I let them attack
>me first.
> Then, I kick the shit out of them.
> DO NOT LET THESE FUCKERS BEAT YOU! ANNOUNCE THAT 5/1 IS
>STILL ON!
> And do not let these douche bags upset you. This is most
>important. Do not
> apologize for what you are doing, ever! And keep on rolling
>forward.
> Richard
>
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/

--
Hotel pics, info and virtual tours. Click here to book a hotel online.
http://tagline.hushmail.com/fc/Ioyw6h4eRCkcpRKxipEXSi8scccewhpFANKyjJi5tm8hdNie6Wdbbq/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


version5 at gmail

Apr 24, 2008, 2:46 PM

Post #11 of 21 (847 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <xploitable [at] gmail> wrote:
> High up government officials are backing Web Application Application
> Security Awareness Day, so I would watch what you're saying.
>
> ---------- Forwarded message ----------
> From: Richard Golodner <rgolodner [at] infratection>
> Date: Thu, Apr 24, 2008 at 5:53 PM
> Subject:
> To: n3td3v <xploitable [at] gmail>
>
> I am from the street with multiple gunshot wounds to my body, but
> did not die. If it was not for IT I would be dead or in jail, but after
> twenty odd years have made a career and a shitload of money.

Did Richard "50 Cent" Golodner just rap to you in an email? That has
to be a first.

> What I am saying is that these guys are punks. I wonder how much
> mouth they would have if they were to actually meet you in person. I am not
> a big man 5'11 185 pounds, but have several belts in various combative
> martial art formats.

As opposed to non combative?

> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



--
http://www.smashthestack.org
http://www.unprotectedhex.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


xploitable at gmail

Apr 24, 2008, 2:57 PM

Post #12 of 21 (860 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, Apr 24, 2008 at 10:46 PM, nnp <version5 [at] gmail> wrote:
> On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <xploitable [at] gmail> wrote:
> > High up government officials are backing Web Application Application
> > Security Awareness Day, so I would watch what you're saying.
> >
> > ---------- Forwarded message ----------
> > From: Richard Golodner <rgolodner [at] infratection>
> > Date: Thu, Apr 24, 2008 at 5:53 PM
> > Subject:
> > To: n3td3v <xploitable [at] gmail>
> >
>
> > I am from the street with multiple gunshot wounds to my body, but
> > did not die. If it was not for IT I would be dead or in jail, but after
> > twenty odd years have made a career and a shitload of money.
>
> Did Richard "50 Cent" Golodner just rap to you in an email? That has
> to be a first.
>
>
> > What I am saying is that these guys are punks. I wonder how much
> > mouth they would have if they were to actually meet you in person. I am not
> > a big man 5'11 185 pounds, but have several belts in various combative
> > martial art formats.
>
> As opposed to non combative?

If you want to have your communications tapped rather than rapped,
keep on going boyo.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


auto188821 at hush

Apr 24, 2008, 3:03 PM

Post #13 of 21 (849 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

>High up government officials are backing Web Application
>Application
>Security Awareness Day, so I would watch what you're saying.
>
>
>---------- Forwarded message ----------
>From: Richard Golodner <rgolodner [at] infratection>

Oh noes! The great and powerful Richard Golodner (that none of us
have ever heard of but he makes fascinating vague claims about
being shot and threats to cause your detractors bodily harm and
teach us a lesson but no one would ever approach him because by
publicly aligning himself with you would make people avoid him
simply because he wouldnt be worth the stigma of proxy association)
is going to get us!


classy - just like n0td3v.

--
Click here for great computer networking solutions!
http://tagline.hushmail.com/fc/Ioyw6h4fM6mh2ZoJ6CDyS6QDIcrzfGaFG6q6YE0yTjZ38iH0qnRRvK/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


version5 at gmail

Apr 24, 2008, 3:36 PM

Post #14 of 21 (850 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Thu, Apr 24, 2008 at 10:57 PM, n3td3v <xploitable [at] gmail> wrote:
> On Thu, Apr 24, 2008 at 10:46 PM, nnp <version5 [at] gmail> wrote:
> > On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <xploitable [at] gmail> wrote:
> > > High up government officials are backing Web Application Application
> > > Security Awareness Day, so I would watch what you're saying.
> > >
> > > ---------- Forwarded message ----------
> > > From: Richard Golodner <rgolodner [at] infratection>
> > > Date: Thu, Apr 24, 2008 at 5:53 PM
> > > Subject:
> > > To: n3td3v <xploitable [at] gmail>
> > >
> >
> > > I am from the street with multiple gunshot wounds to my body, but
> > > did not die. If it was not for IT I would be dead or in jail, but after
> > > twenty odd years have made a career and a shitload of money.
> >
> > Did Richard "50 Cent" Golodner just rap to you in an email? That has
> > to be a first.
> >
> >
> > > What I am saying is that these guys are punks. I wonder how much
> > > mouth they would have if they were to actually meet you in person. I am not
> > > a big man 5'11 185 pounds, but have several belts in various combative
> > > martial art formats.
> >
> > As opposed to non combative?
>
> If you want to have your communications tapped rather than rapped,
> keep on going boyo.

Are you implying that if I stop, the feds will rap my communications
instead of tapping them? That sounds quite entertaining to be honest.

>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>



--
http://www.smashthestack.org
http://www.unprotectedhex.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


ureleet at gmail

Apr 24, 2008, 4:09 PM

Post #15 of 21 (856 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

are you again threatening us? in america, thats enuff to call the police.
and no, i am not threatening to do so.

On Thu, Apr 24, 2008 at 5:57 PM, n3td3v <xploitable [at] gmail> wrote:

>
> On Thu, Apr 24, 2008 at 10:46 PM, nnp <version5 [at] gmail> wrote:
> > On Thu, Apr 24, 2008 at 10:13 PM, n3td3v <xploitable [at] gmail> wrote:
> > > High up government officials are backing Web Application Application
> > > Security Awareness Day, so I would watch what you're saying.
> > >
> > > ---------- Forwarded message ----------
> > > From: Richard Golodner <rgolodner [at] infratection>
> > > Date: Thu, Apr 24, 2008 at 5:53 PM
> > > Subject:
> > > To: n3td3v <xploitable [at] gmail>
> > >
> >
> > > I am from the street with multiple gunshot wounds to my body,
> but
> > > did not die. If it was not for IT I would be dead or in jail, but
> after
> > > twenty odd years have made a career and a shitload of money.
> >
> > Did Richard "50 Cent" Golodner just rap to you in an email? That has
> > to be a first.
> >
> >
> > > What I am saying is that these guys are punks. I wonder how
> much
> > > mouth they would have if they were to actually meet you in person. I
> am not
> > > a big man 5'11 185 pounds, but have several belts in various
> combative
> > > martial art formats.
> >
> > As opposed to non combative?
>
> If you want to have your communications tapped rather than rapped,
> keep on going boyo.
>


xploitable at gmail

Apr 24, 2008, 4:19 PM

Post #16 of 21 (853 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Fri, Apr 25, 2008 at 12:09 AM, Ureleet <ureleet [at] gmail> wrote:
> are you again threatening us? in america, thats enuff to call the police.
> and no, i am not threatening to do so.

I live in UK under British rule, all the best with the extradition.

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


ureleet at gmail

Apr 24, 2008, 4:22 PM

Post #17 of 21 (862 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

no, you idiot, i was telling you to quit threatening ppl. god you are
thick.

On Thu, Apr 24, 2008 at 7:19 PM, n3td3v <xploitable [at] gmail> wrote:

>
> On Fri, Apr 25, 2008 at 12:09 AM, Ureleet <ureleet [at] gmail> wrote:
> > are you again threatening us? in america, thats enuff to call the
> police.
> > and no, i am not threatening to do so.
>
> I live in UK under British rule, all the best with the extradition.
>
> n3td3v
>


xploitable at gmail

Apr 24, 2008, 4:41 PM

Post #18 of 21 (844 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Fri, Apr 25, 2008 at 12:22 AM, Ureleet <ureleet [at] gmail> wrote:
> no, you idiot, i was telling you to quit threatening ppl. god you are
> thick.

In Britian, we reject people like you. All the best at passport control.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


ifor.bigun at googlemail

Apr 25, 2008, 7:51 AM

Post #19 of 21 (793 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Friday 25 April 2008 00:41, n3td3v wrote:
> On Fri, Apr 25, 2008 at 12:22 AM, Ureleet <ureleet [at] gmail> wrote:
> > no, you idiot, i was telling you to quit threatening ppl. god you are
> > thick.
>
> In Britian, we reject people like you. All the best at passport control.
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

I hope you aren't Welsh, N3td3v - I noticed you used the word 'boyo' earlier.
In Wales, we reject people like you. If it were not beneath me to stoop to
such childish behaviour, I'd say you were a complete tit, but I'll refrain.
Please n3td3v, I'm asking you nicely. Take up carpentry or knitting,
brick-laying or something else that's nothing to do with security -
*anything* that isn't a magnet to people suffering from paranoid delusion.
Get on the homing pigeon mailing lists instead of f-d. Try taking 'Which
Caravan' magazine for a month or two - you'll enjoy it, I'm sure. And stop
taking the drugs - really. It's for your own good.

Think of the caravan - the open road. Take Richard Golodner with you - you can
go on long trips, taking it in turns to be the one who gets to ride along
behind in the caravan. The GOOD LIFE. Think n3td3v. You could go to the USA
(sorry, Uncle Sam) - plenty of open road there, and Richard will know the
places to avoid, where you're likely to get shot.

Think hard about it n3td3v. It'd be the best *real* contribution to security
you've ever made. The entire list would be grateful to you. And if you sort
yourself out in a couple of years and become a useful person who's still
interested in security, you'd be welcomed back on the list. Only then, your
name will be w1nn3b4g0.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


xploitable at gmail

Apr 25, 2008, 11:47 AM

Post #20 of 21 (819 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

On Fri, Apr 25, 2008 at 3:51 PM, Jonathan Roach
<ifor.bigun [at] googlemail> wrote:
> In Wales, we

<hatred chopped off, intelligence tip kept>

Thanks for letting me know you live in Wales.

All the best,

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


ureleet at gmail

Apr 25, 2008, 12:56 PM

Post #21 of 21 (828 views)
Permalink
Re: A New Class of Vulnerability in Oracle: Lateral SQL Injection [In reply to]

which you will do _nothing_ with. bye.

On Fri, Apr 25, 2008 at 2:47 PM, n3td3v <xploitable [at] gmail> wrote:

>
> On Fri, Apr 25, 2008 at 3:51 PM, Jonathan Roach
> <ifor.bigun [at] googlemail> wrote:
> > In Wales, we
>
> <hatred chopped off, intelligence tip kept>
>
> Thanks for letting me know you live in Wales.
>
> All the best,
>
> n3td3v
>

Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.