Login | Register For Free | Help
Search for: (Advanced)

Mailing List Archive: Full Disclosure: Full-Disclosure

(no subject)

 

 

First page Previous page 1 2 3 4 5 6 7 8 Next page Last page  View All Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded


tomb at byrneit

Jul 1, 2009, 11:28 AM

Post #151 of 180 (3906 views)
Permalink
Re: (no subject) [In reply to]

Reported to the Douglas County Sheriffs on their crime report form.


>-----Original Message-----
>From: full-disclosure-bounces [at] lists [mailto:full-disclosure-
>bounces [at] lists] On Behalf Of Kevin Wilcox
>Sent: Wednesday, July 01, 2009 6:32 AM
>To: Inbox (Main)
>Cc: full-disclosure [at] lists; michelle.nash2009 [at] yahoo;
>mitch nash
>Subject: Re: [Full-disclosure] (no subject)
>
>2009/7/1 Inbox (Main) <rokadeana [at] gmail>:
>>
>> Why not just ask michelle?
>>
>> Hope you don't mind: I forwarded your mail to
>michelle.nash2009 [at] yahoo
>
>I'm guessing this could have something to do with it:
>
>http://www.nrtoday.com/article/20090619/LOGS/906199976/1051/NONE&parentp
>rofile=1055
>
>In particular, the section that says,
>
>"Mitchell Dale Nash, 45, of Myrtle Creek, on suspicion of violation of
>a restraining order, interfering with making a report, harassment and
>unlawful entry into a motor vehicle."
>
>I only mention that because the original email came in from
>74.32.173.24...which gives us
>
>user [at] hos ~ $ nslookup 74.32.173.24
>Server: 152.10.248.1
>Address: 152.10.248.1#53
>
>Non-authoritative answer:
>24.173.32.74.in-addr.arpa name =
>74-32-173-24.dr01.myck.or.frontiernet.net.
>
>My favourite part is the "myck.or.frontiernet.net" section. Sounds
>like Myrtle Creek, Oregon, to me.
>
>Of course, I could be *completely* wrong...
>
>kmw
>
>--
>To take from one, because it is thought that his own industry and that
>of his fathers has acquired too much, in order to spare to others,
>who, or whose fathers have not exercised equal industry and skill, is
>to violate arbitrarily the first principle of association, ‘the
>guarantee to every one of a free exercise of his industry, & the
>fruits acquired by it.'
>
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


kz20fl at googlemail

Jul 1, 2009, 12:52 PM

Post #152 of 180 (3906 views)
Permalink
Re: (no subject) [In reply to]

What a goon. That made me laugh till it hurt

2009/7/1 Tomas L. Byrnes <tomb [at] byrneit>

> Reported to the Douglas County Sheriffs on their crime report form.
>
>
> >-----Original Message-----
> >From: full-disclosure-bounces [at] lists [mailto:full-disclosure-
> >bounces [at] lists] On Behalf Of Kevin Wilcox
> >Sent: Wednesday, July 01, 2009 6:32 AM
> >To: Inbox (Main)
> >Cc: full-disclosure [at] lists; michelle.nash2009 [at] yahoo;
> >mitch nash
> >Subject: Re: [Full-disclosure] (no subject)
> >
> >2009/7/1 Inbox (Main) <rokadeana [at] gmail>:
> >>
> >> Why not just ask michelle?
> >>
> >> Hope you don't mind: I forwarded your mail to
> >michelle.nash2009 [at] yahoo
> >
> >I'm guessing this could have something to do with it:
> >
> >http://www.nrtoday.com/article/20090619/LOGS/906199976/1051/NONE&parentp
> >rofile=1055
> >
> >In particular, the section that says,
> >
> >"Mitchell Dale Nash, 45, of Myrtle Creek, on suspicion of violation of
> >a restraining order, interfering with making a report, harassment and
> >unlawful entry into a motor vehicle."
> >
> >I only mention that because the original email came in from
> >74.32.173.24...which gives us
> >
> >user [at] hos ~ $ nslookup 74.32.173.24
> >Server: 152.10.248.1
> >Address: 152.10.248.1#53
> >
> >Non-authoritative answer:
> >24.173.32.74.in-addr.arpa name =
> >74-32-173-24.dr01.myck.or.frontiernet.net.
> >
> >My favourite part is the "myck.or.frontiernet.net" section. Sounds
> >like Myrtle Creek, Oregon, to me.
> >
> >Of course, I could be *completely* wrong...
> >
> >kmw
> >
> >--
> >To take from one, because it is thought that his own industry and that
> >of his fathers has acquired too much, in order to spare to others,
> >who, or whose fathers have not exercised equal industry and skill, is
> >to violate arbitrarily the first principle of association, ‘the
> >guarantee to every one of a free exercise of his industry, & the
> >fruits acquired by it.'
> >
> >_______________________________________________
> >Full-Disclosure - We believe in it.
> >Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >Hosted and sponsored by Secunia - http://secunia.com/
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>


antisex at hushmail

Jul 21, 2009, 6:56 PM

Post #153 of 180 (3823 views)
Permalink
Re: (no subject) [In reply to]

Awww, seriously? Can you leave governmentsecurity alone? I don't
want you fucking with my backdoorz. It's not my fault they run
litespeed.

On Tue, 21 Jul 2009 21:27:38 -0400 anti sec <anti-
sec4lyfe [at] email> wrote:
>We, the worldwide anti-sec movement have landed yet another coup
>that
>will strike full-disclosurizers into the very hearts and soul of
>their
>being.
>
>Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to
>take
>revenge against the full disclosure zionist hegemony in
>retaliation for
>the damage white hats  have been committing against the security
>world.
>Our heroic anti-sec warriors have carried out a blessed raid
>against
>4chanarchive.org. 4chan users are now burning with fear, terror
>and panic
>on their /b/, /gif/, /r9k/, and /a/ boards.
>
>The white hat world will soon be asunder and the enemies will flee
>from
>our holy power!
>
>We have repeatedly warned the security industry and the people in
>it. DO
>NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is
>using
>4chan or at least has heard of it. Thus we struck into the very
>core of
>their existence. We have fulfilled our promise and carried out our
>blessed hacking attack on 4chanarchive after our warriors exerted
>strenuous efforts over a long period of time to ensure the success
>of the
>attack.
>
>We continue to warn the websites of governmentsecurity and
>hackforums and
>all full disclosure public as a whole that they will be punished
>in the
>same way if they do not withdraw from their erroneous ways of
>living and
>see that white hats are the scum of the earth. Those who warn are
>excused.
>
>The list will be released at the usual places. those in the know
>do
>realize where that is.
>
>ANTI-SEC FOR LIFE!
>
>--
>How Strong is Your Score?
>Click here to see yours for $0!
>By FreeCreditReport.com

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


jd.mubix at gmail

Jul 21, 2009, 7:43 PM

Post #154 of 180 (3830 views)
Permalink
Re: (no subject) [In reply to]

I'm sorry, log time reader of FD, it's a great mashup of hilarity and vuln
disclosure. But this takes the cake. I can't sit silent for this one:

Are you OUTSIDE your mind? 4chan? and not even 4chan.org, an archive site.
This is the "very core" of the "White Hat" being? If this is truly a 'agent
of AntiSec' which I highly doubt, you must be selecting low hanging fruit
and finding any possible way to associate it with those you hate.

I hope those who are in Anti-Sec if there really is such a thing, come and
hunt you down... and that's the way it is... for July 21st, 2009

--
Rob Fuller | Mubix
Room362.com | Hak5.org | TheAcademyPro.com


On Tue, Jul 21, 2009 at 9:39 PM, Ed Carp <erc [at] pobox> wrote:

> Do not fuck with anti-suck. LOL!
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>


wishinet at googlemail

Jul 22, 2009, 5:00 AM

Post #155 of 180 (3810 views)
Permalink
Re: (no subject) [In reply to]

Hmmh,

I personally see a lack of defense and a need for more white hats, who
aren't constantly trying to gain media attention by breaking stuff. -
Because most stuff is already broken - as we see. Even trolls nowadays
can course some damage.
If you need a good example to proof that we need new security concepts,
look at what even idiots can do. And sell this as a good argument, for
sure!! ;) My 5 year old niece could have hacked this 4chan site.

I'm still waiting for this so called ssh thingy. Hack something real:
release an OpenSSH patch.


Have fun,
wishi


Ed Carp schrieb:
> Do not fuck with anti-suck. LOL!
>
>
> ------------------------------------------------------------------------
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


sirloxelroy at gmail

Jul 22, 2009, 7:19 AM

Post #156 of 180 (3810 views)
Permalink
Re: (no subject) [In reply to]

4chan, heart of the White Hat. ROFLMAO. OKay this is bloody funny. Dude,
get a life.

On Wed, Jul 22, 2009 at 6:00 AM,
<full-disclosure-request [at] lists>wrote:

> Send Full-Disclosure mailing list submissions to
> full-disclosure [at] lists
>
> To subscribe or unsubscribe via the World Wide Web, visit
> https://lists.grok.org.uk/mailman/listinfo/full-disclosure
> or, via email, send a message with subject or body 'help' to
> full-disclosure-request [at] lists
>
> You can reach the person managing the list at
> full-disclosure-owner [at] lists
>
> When replying, please edit your Subject line so it is more specific
> than "Re: Contents of Full-Disclosure digest..."
>
>
> Note to digest recipients - when replying to digest posts, please trim your
> post appropriately. Thank you.
>
>
> Today's Topics:
>
> 1. (no subject) (anti sec)
> 2. Re: (no subject) (Ed Carp)
> 3. Re: (no subject) (antisex [at] hushmail)
> 4. Re: (no subject) (Rob Fuller)
> 5. Re: Update: [GSEC-TZO-44-2009] One bug to rule them all -
> Firefox, IE, Safari, Opera, Chrome, Seamonkey, iPhone, iPod, Wii,
> PS3.... (Andrew Farmer)
>
>
> ----------------------------------------------------------------------
>
> Message: 1
> Date: Tue, 21 Jul 2009 20:27:38 -0500
> From: "anti sec" <anti-sec4lyfe [at] email>
> Subject: [Full-disclosure] (no subject)
> To: full-disclosure [at] lists
> Message-ID: <20090722012738.4A82FBE407E [at] ws1-9>
> Content-Type: text/plain; charset="iso-8859-1"
>
> We, the worldwide anti-sec movement have landed yet another coup that
> will strike full-disclosurizers into the very hearts and soul of their
> being.
>
> Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to take
> revenge against the full disclosure zionist hegemony in retaliation for
> the damage white hats? have been committing against the security world.
> Our heroic anti-sec warriors have carried out a blessed raid against
> 4chanarchive.org. 4chan users are now burning with fear, terror and panic
> on their /b/, /gif/, /r9k/, and /a/ boards.
>
> The white hat world will soon be asunder and the enemies will flee from
> our holy power!
>
> We have repeatedly warned the security industry and the people in it. DO
> NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is using
> 4chan or at least has heard of it. Thus we struck into the very core of
> their existence. We have fulfilled our promise and carried out our
> blessed hacking attack on 4chanarchive after our warriors exerted
> strenuous efforts over a long period of time to ensure the success of the
> attack.
>
> We continue to warn the websites of governmentsecurity and hackforums and
> all full disclosure public as a whole that they will be punished in the
> same way if they do not withdraw from their erroneous ways of living and
> see that white hats are the scum of the earth. Those who warn are
> excused.
>
> The list will be released at the usual places. those in the know do
> realize where that is.
>
> ANTI-SEC FOR LIFE!
>
> --
> How Strong is Your Score?
> Click here to see yours for $0!
> By FreeCreditReport.com
>
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL:
> http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20090721/e9123ac2/attachment-0001.html
>
> ------------------------------
>
> Message: 2
> Date: Tue, 21 Jul 2009 20:39:48 -0500
> From: Ed Carp <erc [at] pobox>
> Subject: Re: [Full-disclosure] (no subject)
> To: full-disclosure <full-disclosure [at] lists>
> Message-ID:
> <1b0d006c0907211839l3e605edekf8e3dd19b6aa4e6a [at] mail>
> Content-Type: text/plain; charset="iso-8859-1"
>
> Do not fuck with anti-suck. LOL!
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL:
> http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20090721/5d4e492b/attachment-0001.html
>
> ------------------------------
>
> Message: 3
> Date: Tue, 21 Jul 2009 21:56:07 -0400
> From: antisex [at] hushmail
> Subject: Re: [Full-disclosure] (no subject)
> To: full-disclosure [at] lists, anti-sec4lyfe [at] email
> Message-ID: <20090722015607.95B1D20045 [at] smtp>
> Content-Type: text/plain; charset="UTF-8"
>
> Awww, seriously? Can you leave governmentsecurity alone? I don't
> want you fucking with my backdoorz. It's not my fault they run
> litespeed.
>
> On Tue, 21 Jul 2009 21:27:38 -0400 anti sec <anti-
> sec4lyfe [at] email> wrote:
> >We, the worldwide anti-sec movement have landed yet another coup
> >that
> >will strike full-disclosurizers into the very hearts and soul of
> >their
> >being.
> >
> >Fellow anti-sec'ers and freedom-lovers: Rejoice, for it is time to
> >take
> >revenge against the full disclosure zionist hegemony in
> >retaliation for
> >the damage white hats? have been committing against the security
> >world.
> >Our heroic anti-sec warriors have carried out a blessed raid
> >against
> >4chanarchive.org. 4chan users are now burning with fear, terror
> >and panic
> >on their /b/, /gif/, /r9k/, and /a/ boards.
> >
> >The white hat world will soon be asunder and the enemies will flee
> >from
> >our holy power!
> >
> >We have repeatedly warned the security industry and the people in
> >it. DO
> >NOT FUCK WITH ANTI-SEC! Statistically speaking, every white hat is
> >using
> >4chan or at least has heard of it. Thus we struck into the very
> >core of
> >their existence. We have fulfilled our promise and carried out our
> >blessed hacking attack on 4chanarchive after our warriors exerted
> >strenuous efforts over a long period of time to ensure the success
> >of the
> >attack.
> >
> >We continue to warn the websites of governmentsecurity and
> >hackforums and
> >all full disclosure public as a whole that they will be punished
> >in the
> >same way if they do not withdraw from their erroneous ways of
> >living and
> >see that white hats are the scum of the earth. Those who warn are
> >excused.
> >
> >The list will be released at the usual places. those in the know
> >do
> >realize where that is.
> >
> >ANTI-SEC FOR LIFE!
> >
> >--
> >How Strong is Your Score?
> >Click here to see yours for $0!
> >By FreeCreditReport.com
>
>
>
> ------------------------------
>
> Message: 4
> Date: Tue, 21 Jul 2009 22:43:01 -0400
> From: Rob Fuller <jd.mubix [at] gmail>
> Subject: Re: [Full-disclosure] (no subject)
> To: full-disclosure <full-disclosure [at] lists>
> Message-ID:
> <e63164660907211943k876c3dw98a1330b4232448a [at] mail>
> Content-Type: text/plain; charset="iso-8859-1"
>
> I'm sorry, log time reader of FD, it's a great mashup of hilarity and vuln
> disclosure. But this takes the cake. I can't sit silent for this one:
>
> Are you OUTSIDE your mind? 4chan? and not even 4chan.org, an archive site.
> This is the "very core" of the "White Hat" being? If this is truly a 'agent
> of AntiSec' which I highly doubt, you must be selecting low hanging fruit
> and finding any possible way to associate it with those you hate.
>
> I hope those who are in Anti-Sec if there really is such a thing, come and
> hunt you down... and that's the way it is... for July 21st, 2009
>
> --
> Rob Fuller | Mubix
> Room362.com | Hak5.org | TheAcademyPro.com
>
>
> On Tue, Jul 21, 2009 at 9:39 PM, Ed Carp <erc [at] pobox> wrote:
>
> > Do not fuck with anti-suck. LOL!
> >
> > _______________________________________________
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
> >
> -------------- next part --------------
> An HTML attachment was scrubbed...
> URL:
> http://lists.grok.org.uk/pipermail/full-disclosure/attachments/20090721/ed5b51b0/attachment-0001.html
>
> ------------------------------
>
> Message: 5
> Date: Tue, 21 Jul 2009 22:32:29 -0700
> From: Andrew Farmer <andfarm [at] gmail>
> Subject: Re: [Full-disclosure] Update: [GSEC-TZO-44-2009] One bug to
> rule them all - Firefox, IE, Safari, Opera, Chrome, Seamonkey,
> iPhone,
> iPod, Wii, PS3....
> To: Michal Zalewski <lcamtuf [at] coredump>
> Cc: full-disclosure <full-disclosure [at] lists>, bugtraq
> <bugtraq [at] securityfocus>
> Message-ID: <0700497E-15A5-4C0C-9A7A-0A7D0604FEF5 [at] gmail>
> Content-Type: text/plain; charset=US-ASCII; format=flowed; delsp=yes
>
> On 21 Jul 2009, at 08:12, Michal Zalewski wrote:
> > There are literally thousands of HTML- and JavaScript-related denial
> > of service vectors in modern browsers...
>
> There's one significant difference in this one, though: while a bunch
> of nested <div>s (for instance) will just mess with the HTML renderer,
> a malformed or oversized <select> element may end up passing bad data
> to native menu APIs. It's one of the only elements I can think of
> offhand that often has effects which extend outside the HTML canvas.
>
>
>
> ------------------------------
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>
> End of Full-Disclosure Digest, Vol 53, Issue 35
> ***********************************************
>



--
Chris Brandstetter

-----BEGIN GEEK CODE BLOCK-----
Version: 3.1
GCS/IT d+(-) s++:++ a C++++$ UBLISXC*++++$ P++++$ L+++$ E-- W+++ N+ o K-
w-- O M++$ V PS- PE Y+ PGP++ t++ 5+++ X+ R- tv-- b+>+++ DI D+ G+ e+ h++ r
y?
------END GEEK CODE BLOCK------

To Decode: http://www.ebb.org/ungeek/


Klinzer at gmx

Jul 22, 2009, 9:52 AM

Post #157 of 180 (3806 views)
Permalink
Re: (no subject) [In reply to]

lol @white hats

Cheers


Am 22.07.2009 um 14:00 schrieb wishi:

> Hmmh,
>
> I personally see a lack of defense and a need for more white hats, who
> aren't constantly trying to gain media attention by breaking stuff. -
> Because most stuff is already broken - as we see. Even trolls nowadays
> can course some damage.
> If you need a good example to proof that we need new security
> concepts,
> look at what even idiots can do. And sell this as a good argument, for
> sure!! ;) My 5 year old niece could have hacked this 4chan site.
>
> I'm still waiting for this so called ssh thingy. Hack something real:
> release an OpenSSH patch.
>
>
> Have fun,
> wishi
>
>
> Ed Carp schrieb:
>> Do not fuck with anti-suck. LOL!
>>
>>
>> ------------------------------------------------------------------------
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


pierce403 at gmail

Jul 22, 2009, 10:51 AM

Post #158 of 180 (3813 views)
Permalink
Re: (no subject) [In reply to]

Won't somebody PLEASE think of the CHILDREN!!?!

On Wed, Jul 22, 2009 at 10:50 AM, Dean Pierce<pierce403 [at] gmail> wrote:
> Won't somebody PLEASE thing of the CHILDREN!!?!
>
> On Wed, Jul 22, 2009 at 9:52 AM, Ferdinand Klinzer<Klinzer [at] gmx> wrote:
>> lol @white hats
>>
>> Cheers
>>
>>
>> Am 22.07.2009 um 14:00 schrieb wishi:
>>
>>> Hmmh,
>>>
>>> I personally see a lack of defense and a need for more white hats, who
>>> aren't constantly trying to gain media attention by breaking stuff. -
>>> Because most stuff is already broken - as we see. Even trolls nowadays
>>> can course some damage.
>>> If you need a good example to proof that we need new security
>>> concepts,
>>> look at what even idiots can do. And sell this as a good argument, for
>>> sure!! ;) My 5 year old niece could have hacked this 4chan site.
>>>
>>> I'm still waiting for this so called ssh thingy. Hack something real:
>>> release an OpenSSH patch.
>>>
>>>
>>> Have fun,
>>> wishi
>>>
>>>
>>> Ed Carp schrieb:
>>>> Do not fuck with anti-suck.  LOL!
>>>>
>>>>
>>>> ------------------------------------------------------------------------
>>>>
>>>> _______________________________________________
>>>> Full-Disclosure - We believe in it.
>>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>> _______________________________________________
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


erc at pobox

Jul 22, 2009, 11:13 AM

Post #159 of 180 (3806 views)
Permalink
Re: (no subject) [In reply to]

Exactly!

2009/7/21 Josh Wheeler <jpavlakovich [at] gmail>

> Anti-Sec
>
> We will pwn your pr0n.
>
> This is beginning to seem more and more like an exercise in
> circle-jerking...
>
> On Tue, Jul 21, 2009 at 5:39 PM, Ed Carp <erc [at] pobox> wrote:
>
>> Do not fuck with anti-suck. LOL!
>>
>>


erc at pobox

Jul 22, 2009, 11:18 AM

Post #160 of 180 (3815 views)
Permalink
Re: (no subject) [In reply to]

That's what keeps me subscribed - when I've had a particularly bad day, I
always know I can come over here and have a great laugh!

2009/7/21 Rob Fuller <jd.mubix [at] gmail>

I'm sorry, log time reader of FD, it's a great mashup of hilarity and vuln
> disclosure.


root at hotmail

Jul 31, 2009, 12:27 AM

Post #161 of 180 (3693 views)
Permalink
Re: (no subject) [In reply to]

I prefer that crap many more:
http://www.voltairenet.org/en

¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤¤
> Sounds much like a marketing operations

> http://www.pbs.org/wgbh/nova/spyfactory/

> -naif
> http://infosecurity.ch



--------------------------------------------------------------------


This anonymous email message was sent from:
http://CyberAtlantis.com/anonymous_email.php

Sorry, as our system is 100% ANONYMOUS we cannot assist you in tracking down the
sender as we have NEITHER IP NOR email content of any of the emails sent.

If you are being harrassed by someone abusing this service then
you may add your email address to our database of blocked email addresses.
http://CyberAtlantis.com/add_banned.php


dan at doxpara

Dec 16, 2009, 11:24 PM

Post #162 of 180 (3164 views)
Permalink
Re: (no subject) [In reply to]

Easily the best environment for packet manipulation is scapy.

The most guaranteed to work approach involves putting a system with two
interfaces in as an attacker, and running two scapy processes that copy
frames received on one interface onto the other one. Of course, your copier
parses the frames, changes what needs to be changed, fixes up checksums,
etc.

There are other approaches that are preferable for all sorts of reasons, but
the above means you don't need to fight with ARP or addresses or firewall
rules or the kernel. (Proxy ARP, mangle tables, yadda yadda yadda.)

2009/12/16 ±è¹«¼º <kimms [at] infosec>

> Hello. List.
>
>
>
> I'm pentesting IPTV.
>
>
>
> Our IPTV network structure is this.
>
>
>
> Monitor - IPTV - VDSL modem - ISP
>
>
>
> So, for packet manipulation
>
> I have to ARP spoofing or change network structure
>
>
>
> Monitor - IPTV - attacker - VDSL modem - ISP
>
>
>
> But, I don't know IPTV SetupBox(STB)'s netmask and gateway address.
>
> So I wanna make this network
>
>
>
> Monitor - IPTV - attacker - VDSL modem - ISP
>
>
>
> Attacker is a computer.
>
> This computer have two NIC.
>
> Two NIC only transmit and receive packet. They have no IP address.
>
> I wanna manipulate this packet's field
>
>
>
> Do you know how make this network?
>
> Do you know tools that manipulate every packet (http, rstp, igmp, etc,.)?
>
>
>
> Thanks
>
> KIM
>
>
>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>


jblaum02 at gmail

Dec 17, 2009, 1:50 AM

Post #163 of 180 (3163 views)
Permalink
Re: (no subject) [In reply to]

Wow, is you're site still down Dan? </omfg>

"Dan Kaminsky" <dan [at] doxpara> wrote:

> Easily the best environment for packet manipulation is scapy.
>
> The most guaranteed to work approach involves putting a system with two
> interfaces in as an attacker, and running two scapy processes that copy
frames
> received on one interface onto the other one. Of course, your copier
parses
> the frames, changes what needs to be changed, fixes up checksums, etc.
>
> There are other approaches that are preferable for all sorts of reasons,
but
> the above means you don't need to fight with ARP or addresses or firewall
> rules or the kernel. (Proxy ARP, mangle tables, yadda yadda yadda.)


ragdelaed at gmail

Feb 13, 2010, 7:17 AM

Post #164 of 180 (2905 views)
Permalink
Re: (no subject) [In reply to]

incorrect.

On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail> wrote:

>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>


Eddie.McGhee at ncr

Feb 13, 2010, 7:28 AM

Post #165 of 180 (2899 views)
Permalink
Re: (no subject) [In reply to]

Correct!

________________________________
From: full-disclosure-bounces [at] lists [mailto:full-disclosure-bounces [at] lists] On Behalf Of edgar deal
Sent: 13 February 2010 15:18
To: 751 ...?
Cc: full-disclosure [at] lists
Subject: Re: [Full-disclosure] (no subject)

incorrect.

On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail<mailto:751hacking [at] gmail>> wrote:

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


akl at experian

Feb 15, 2010, 2:07 AM

Post #166 of 180 (2861 views)
Permalink
Re: (no subject) [In reply to]

yes the correct answer is 'cheese'



________________________________

From: full-disclosure-bounces [at] lists
[mailto:full-disclosure-bounces [at] lists] On Behalf Of edgar
deal
Sent: 13. februar 2010 16:18
To: 751 ...?
Cc: full-disclosure [at] lists
Subject: Re: [Full-disclosure] (no subject)


incorrect.


On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail> wrote:



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


uuf6429 at gmail

Feb 15, 2010, 2:15 AM

Post #167 of 180 (2862 views)
Permalink
Re: (no subject) [In reply to]

Actually, the correct answer is 239.
The full question to the answer (and sum) is left up to the read.

On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull <akl [at] experian> wrote:

> yes the correct answer is 'cheese'
>
>
>
> ------------------------------
> *From:* full-disclosure-bounces [at] lists [mailto:
> full-disclosure-bounces [at] lists] *On Behalf Of *edgar deal
> *Sent:* 13. februar 2010 16:18
> *To:* 751 ...?
> *Cc:* full-disclosure [at] lists
> *Subject:* Re: [Full-disclosure] (no subject)
>
> incorrect.
>
> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail> wrote:
>
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>


akl at experian

Feb 15, 2010, 2:25 AM

Post #168 of 180 (2864 views)
Permalink
Re: (no subject) [In reply to]

you obviously misunderstood since every geek on the planet knows that
the answer in numeric form is 42!



________________________________

From: Christian Sciberras [mailto:uuf6429 [at] gmail]
Sent: 15. februar 2010 11:15
To: Anders Klixbull
Cc: edgar deal; 751 ...?; full-disclosure [at] lists
Subject: Re: [Full-disclosure] (no subject)


Actually, the correct answer is 239.
The full question to the answer (and sum) is left up to the read.


On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull <akl [at] experian>
wrote:


yes the correct answer is 'cheese'




________________________________

From: full-disclosure-bounces [at] lists
[mailto:full-disclosure-bounces [at] lists] On Behalf Of edgar
deal
Sent: 13. februar 2010 16:18
To: 751 ...?
Cc: full-disclosure [at] lists
Subject: Re: [Full-disclosure] (no subject)


incorrect.


On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail>
wrote:



_______________________________________________
Full-Disclosure - We believe in it.
Charter:
http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


uuf6429 at gmail

Feb 15, 2010, 2:26 AM

Post #169 of 180 (2859 views)
Permalink
Re: (no subject) [In reply to]

That's old news!

It's been upgraded to 239!



On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull <akl [at] experian> wrote:

> you obviously misunderstood since every geek on the planet knows that the
> answer in numeric form is 42!
>
>
>
> ------------------------------
> *From:* Christian Sciberras [mailto:uuf6429 [at] gmail]
> *Sent:* 15. februar 2010 11:15
> *To:* Anders Klixbull
> *Cc:* edgar deal; 751 ...?; full-disclosure [at] lists
> *Subject:* Re: [Full-disclosure] (no subject)
>
> Actually, the correct answer is 239.
> The full question to the answer (and sum) is left up to the read.
>
> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull <akl [at] experian> wrote:
>
>> yes the correct answer is 'cheese'
>>
>>
>>
>> ------------------------------
>> *From:* full-disclosure-bounces [at] lists [mailto:
>> full-disclosure-bounces [at] lists] *On Behalf Of *edgar deal
>> *Sent:* 13. februar 2010 16:18
>> *To:* 751 ...?
>> *Cc:* full-disclosure [at] lists
>> *Subject:* Re: [Full-disclosure] (no subject)
>>
>> incorrect.
>>
>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail> wrote:
>>
>>>
>>> _______________________________________________
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>


ptinstructor at gmail

Feb 16, 2010, 9:15 PM

Post #170 of 180 (2792 views)
Permalink
Re: (no subject) [In reply to]

No it is still 42 and will always be

On Mon, Feb 15, 2010 at 3:56 PM, Christian Sciberras <uuf6429 [at] gmail> wrote:
> That's old news!
>
> It's been upgraded to 239!
>
>
>
> On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull <akl [at] experian> wrote:
>>
>> you obviously misunderstood since every geek on the planet knows that the
>> answer in numeric form is 42!
>>
>>
>> ________________________________
>> From: Christian Sciberras [mailto:uuf6429 [at] gmail]
>> Sent: 15. februar 2010 11:15
>> To: Anders Klixbull
>> Cc: edgar deal; 751 ...?; full-disclosure [at] lists
>> Subject: Re: [Full-disclosure] (no subject)
>>
>> Actually, the correct answer is 239.
>> The full question to the answer (and sum) is left up to the read.
>>
>> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull <akl [at] experian> wrote:
>>>
>>> yes the correct answer is 'cheese'
>>>
>>>
>>> ________________________________
>>> From: full-disclosure-bounces [at] lists
>>> [mailto:full-disclosure-bounces [at] lists] On Behalf Of edgar deal
>>> Sent: 13. februar 2010 16:18
>>> To: 751 ...?
>>> Cc: full-disclosure [at] lists
>>> Subject: Re: [Full-disclosure] (no subject)
>>>
>>> incorrect.
>>>
>>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail> wrote:
>>>>
>>>> _______________________________________________
>>>> Full-Disclosure - We believe in it.
>>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>>> Hosted and sponsored by Secunia - http://secunia.com/
>>>
>>>
>>> _______________________________________________
>>> Full-Disclosure - We believe in it.
>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>>> Hosted and sponsored by Secunia - http://secunia.com/
>>
>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


tomb at byrneit

Feb 16, 2010, 9:24 PM

Post #171 of 180 (2791 views)
Permalink
Re: (no subject) [In reply to]

Sorry for the Inconvenience.



> -----Original Message-----
> From: full-disclosure-bounces [at] lists [mailto:full-
> disclosure-bounces [at] lists] On Behalf Of gold flake
> Sent: Tuesday, February 16, 2010 9:16 PM
> To: Christian Sciberras
> Cc: 751 ...?; full-disclosure [at] lists
> Subject: Re: [Full-disclosure] (no subject)
>
> No it is still 42 and will always be
>
> On Mon, Feb 15, 2010 at 3:56 PM, Christian Sciberras
> <uuf6429 [at] gmail> wrote:
> > That's old news!
> >
> > It's been upgraded to 239!
> >
> >
> >
> > On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull <akl [at] experian>
> wrote:
> >>
> >> you obviously misunderstood since every geek on the planet knows
> that the
> >> answer in numeric form is 42!
> >>
> >>
> >> ________________________________
> >> From: Christian Sciberras [mailto:uuf6429 [at] gmail]
> >> Sent: 15. februar 2010 11:15
> >> To: Anders Klixbull
> >> Cc: edgar deal; 751 ...?; full-disclosure [at] lists
> >> Subject: Re: [Full-disclosure] (no subject)
> >>
> >> Actually, the correct answer is 239.
> >> The full question to the answer (and sum) is left up to the read.
> >>
> >> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull <akl [at] experian>
> wrote:
> >>>
> >>> yes the correct answer is 'cheese'
> >>>
> >>>
> >>> ________________________________
> >>> From: full-disclosure-bounces [at] lists
> >>> [mailto:full-disclosure-bounces [at] lists] On Behalf Of
> edgar deal
> >>> Sent: 13. februar 2010 16:18
> >>> To: 751 ...?
> >>> Cc: full-disclosure [at] lists
> >>> Subject: Re: [Full-disclosure] (no subject)
> >>>
> >>> incorrect.
> >>>
> >>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail>
> wrote:
> >>>>
> >>>> _______________________________________________
> >>>> Full-Disclosure - We believe in it.
> >>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >>>> Hosted and sponsored by Secunia - http://secunia.com/
> >>>
> >>>
> >>> _______________________________________________
> >>> Full-Disclosure - We believe in it.
> >>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> >>> Hosted and sponsored by Secunia - http://secunia.com/
> >>
> >
> >
> > _______________________________________________
> > Full-Disclosure - We believe in it.
> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> > Hosted and sponsored by Secunia - http://secunia.com/
> >
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
> Hosted and sponsored by Secunia - http://secunia.com/

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


uuf6429 at gmail

Feb 16, 2010, 11:49 PM

Post #172 of 180 (2788 views)
Permalink
Re: (no subject) [In reply to]

There was a slight error in accuracy, try your math again and you'll
see that 42 doesn't make sense.
>:)






On Wed, Feb 17, 2010 at 6:24 AM, Tomas L. Byrnes <tomb [at] byrneit> wrote:
> Sorry for the Inconvenience.
>
>
>
>> -----Original Message-----
>> From: full-disclosure-bounces [at] lists [mailto:full-
>> disclosure-bounces [at] lists] On Behalf Of gold flake
>> Sent: Tuesday, February 16, 2010 9:16 PM
>> To: Christian Sciberras
>> Cc: 751 ...?; full-disclosure [at] lists
>> Subject: Re: [Full-disclosure] (no subject)
>>
>> No it is still 42 and will always be
>>
>> On Mon, Feb 15, 2010 at 3:56 PM, Christian Sciberras
>> <uuf6429 [at] gmail> wrote:
>> > That's old news!
>> >
>> > It's been upgraded to 239!
>> >
>> >
>> >
>> > On Mon, Feb 15, 2010 at 11:25 AM, Anders Klixbull <akl [at] experian>
>> wrote:
>> >>
>> >> you obviously misunderstood since every geek on the planet knows
>> that the
>> >> answer in numeric form is 42!
>> >>
>> >>
>> >> ________________________________
>> >> From: Christian Sciberras [mailto:uuf6429 [at] gmail]
>> >> Sent: 15. februar 2010 11:15
>> >> To: Anders Klixbull
>> >> Cc: edgar deal; 751 ...?; full-disclosure [at] lists
>> >> Subject: Re: [Full-disclosure] (no subject)
>> >>
>> >> Actually, the correct answer is 239.
>> >> The full question to the answer (and sum) is left up to the read.
>> >>
>> >> On Mon, Feb 15, 2010 at 11:07 AM, Anders Klixbull <akl [at] experian>
>> wrote:
>> >>>
>> >>> yes the correct answer is 'cheese'
>> >>>
>> >>>
>> >>> ________________________________
>> >>> From: full-disclosure-bounces [at] lists
>> >>> [mailto:full-disclosure-bounces [at] lists] On Behalf Of
>> edgar deal
>> >>> Sent: 13. februar 2010 16:18
>> >>> To: 751 ...?
>> >>> Cc: full-disclosure [at] lists
>> >>> Subject: Re: [Full-disclosure] (no subject)
>> >>>
>> >>> incorrect.
>> >>>
>> >>> On Sat, Feb 13, 2010 at 1:09 AM, 751 ...? <751hacking [at] gmail>
>> wrote:
>> >>>>
>> >>>> _______________________________________________
>> >>>> Full-Disclosure - We believe in it.
>> >>>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> >>>> Hosted and sponsored by Secunia - http://secunia.com/
>> >>>
>> >>>
>> >>> _______________________________________________
>> >>> Full-Disclosure - We believe in it.
>> >>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> >>> Hosted and sponsored by Secunia - http://secunia.com/
>> >>
>> >
>> >
>> > _______________________________________________
>> > Full-Disclosure - We believe in it.
>> > Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> > Hosted and sponsored by Secunia - http://secunia.com/
>> >
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>> Hosted and sponsored by Secunia - http://secunia.com/
>

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


coderman at gmail

Nov 23, 2010, 6:36 PM

Post #173 of 180 (1003 views)
Permalink
Re: (no subject) [In reply to]

2009/12/16 Dan Kaminsky <dan [at] doxpara>:
> Easily the best environment for packet manipulation is scapy.
>
> The most guaranteed to work approach involves putting a system with two
> interfaces in as an attacker, ...

i love dual port gumstix and the old yoggie gatekeeper pro form factor
for this; both are now EOL and long past last fab run.

what is the new best form factor in production? i'd love a hw crypto
accelerated T3 more than AES-NI or Padlock style mobile kit. does one
yet exist, or perhaps soon to be?

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Valdis.Kletnieks at vt

Jun 9, 2011, 5:34 PM

Post #174 of 180 (537 views)
Permalink
Re: (no subject) [In reply to]

On Fri, 10 Jun 2011 02:40:16 +0300, nix [at] myproxylists said:

> Im happy to hear it works out to you. A few days ago, i received an email
> from https://www.proxpn.com/ admin that he suspended fraudulent user VPN
> account due to the abuse. A fraudster used a stolen credit card using
> their VPN to purchase a service from us. Needless to say, their CIDR's has
> been also added to this list.

You're incredibly lucky it was proxpn.com and not comcast.com. ;)


nix at myproxylists

Jun 9, 2011, 6:20 PM

Post #175 of 180 (535 views)
Permalink
Re: (no subject) [In reply to]

> On Fri, 10 Jun 2011 02:40:16 +0300, nix [at] myproxylists said:
>
>> Im happy to hear it works out to you. A few days ago, i received an
>> email
>> from https://www.proxpn.com/ admin that he suspended fraudulent user VPN
>> account due to the abuse. A fraudster used a stolen credit card using
>> their VPN to purchase a service from us. Needless to say, their CIDR's
>> has
>> been also added to this list.
>
> You're incredibly lucky it was proxpn.com and not comcast.com. ;)
>
I sense sarcasm. Im exacly aware of comcast and almost all other U.S cable
providers residental address ranges. Did you happend to know that comcast
do also provide static IP's for companies, dedicated hosting.

Im also fully aware of botnet proxies that are spreaded wide to comcast
ranges, not only to comcast, to a majority of U.S cable providers. We have
a method to detect some of those botnet proxies but I wont go in to
details for obvious reasons.

Once again, almost none of you did not bothered to read features. You have
the option to CHOOSE will you block hosting providers or not. It does not
block anything by default.

This is my last reply to this topic.

Simply, it does provide protection to those who wants it and everyone can
configure their API in the way they want. None is not enforced to block
anything. Period.

Atleast I managed to open discussion. Something else than daily boring
XSS/CRLF bugs.

Thanks to everyone for the feedback and interests, whether it was positive
or negative.


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

First page Previous page 1 2 3 4 5 6 7 8 Next page Last page  View All Full Disclosure full-disclosure RSS feed   Index | Next | Previous | View Threaded
 
 


Interested in having your list archived? Contact Gossamer Threads
 
  Web Applications & Managed Hosting Powered by Gossamer Threads Inc.