Re: [Full-Disclosure] Global HIGH Security Risk

From: Benjamin Keller (benjamin@conceptis.com)
Date: 02/03/03

  • Next message: yossarian: "Re: [Full-Disclosure] Global HIGH Security Risk"
    From: Benjamin Keller <benjamin@conceptis.com>
    To: full-disclosure@lists.netsys.com
    Date: Mon, 03 Feb 2003 15:06:54 -0500 (EST)
    

    I say you go to your local library/Internet cafe, create a hotmail/hushmail
    account,

    And mail it all to the list and lets see what happens....

    Benjamin Keller
    Systems Administrator
    Conceptis Technologies

    On Mon, 3 Feb 2003, Jonathan Rickman wrote:

    > -----pgpenvelope processed message
    >
    > gpg: decrypt_message failed: eof
    >
    > pgpenvelope_decrypt: GnuPG produced no output (possibly a failed decryption, or invalid data)
    > skipping a block
    >
    > -----end pgpenvelope information
    >
    > -----BEGIN PGP SIGNED MESSAGE-----
    >
    > On Mon, 3 Feb 2003, ^Shadown^ wrote:
    >
    > > Dear Folks,
    > >
    > > I'm sorry if anybody didn't like the subject, but is *that* important.
    > > While a research I've developed a technique to literaly bypass *every* security network software and device (*every* firewall, ids, etc), which become an unstopable security risk for the hole security community, but I don't know the legal term on how to post something like this.
    > > And I need help on this, need people who may advice me on how to share this information.
    > > I'm really scared, because i.e "The arrest that happends after the DEFCON X conference because of the *PDF security*", and I swear that this is a large *mayor* security risk.
    > > I will *NOT* answer any question about the new technique (the one I've developed and applied) until I get adviced on how to post it *without* getting in trouble, so please don't write to me because I'll delete them all.
    > > I hope for your help.
    > > Best Regards.
    > >
    > > ^Shadown^
    > >
    > > PD: As this mail was sent to SecurityFocus, Vuln-Watch and Cert lists (last Friday) and It wasn't posted, this msg and the information I'm gonna release will *not* be allow to post or referenced on other lists but Full-Disclosure. (except by myself).
    > > Thnx.
    >
    >
    > Well, it's pretty obvious why they didn't post it. Honestly, and I'm not
    > trying to insult you, this is probably something you should keep to
    > yourself. The odds of you making an ass out of yourself seem pretty good
    > at this point. Anything's possible, but what you're describing sounds far
    > fetched to me. But hey, who knows? I've been wrong at least three times
    > this year, and we're barely a month into it. :)
    >
    > - --
    > Jonathan Rickman
    > X Corps Security
    > http://www.xcorps.net
    >
    > -----BEGIN PGP SIGNATURE-----
    > Version: PGP 6.5.8
    >
    > iQEVAwUBPj7DXzTwrX0N9QH/AQEIGwf/Uawkm5UiP01HTVIZxf6xD+TlaUxCnoPt
    > 977Zsr1pYQTt7qF64XpUX0FDOJCAIyiSU9JOjUwnbNJBRqv+0RG8SBWdgCFDoFq+
    > ukfC/cqlFI4J+iiHR6L9RM3d66JSvqqoIl3gAfwCbq3kQcBkWKG5WJJ4tHXwvcnr
    > Dg8XEZs/JtdyTO+quvtMTlITvgnZ9lQZ3dADdN/EkfB+5HGoC3s98uMEe+EE1tme
    > dlmC4Ve6ls/4ZNApf5DLlphMZR5cQf3D+4kPj8pJZD/2IRTEgPilnvCIRwE2yoOK
    > 1uL2kSh2kc4L4+mOsZ3wH0EmsC4NEt593a3reix5N5I5zy99mRPlqA==
    > =jmZK
    > -----END PGP SIGNATURE-----
    >
    >
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



    Relevant Pages

    • Re: [Full-disclosure] PC/Laptop microphones
      ... HAVE BANK ACCOUNT ... Need I cite the list charter? ... Full-Disclosure - We believe in it. ... Hosted and sponsored by Secunia - http://secunia.com/ ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Out of Office AutoReply: Snort Signature to det ect credit ca rds
      ... There had been a milter rule to block these from my account to ... Full-Disclosure - We believe in it. ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • Re: [Full-disclosure] Re: RSA HAVE CRACKED PHISHING, NO SERIOUSLY
      ... I don't think the claim to have thought of some groundbreaking perfect solution to stop phishers. ... If not then it would be only take seconds to sort through hundreds of fake and real account numbers. ... Subject: [Full-disclosure] Re: RSA HAVE CRACKED PHISHING, ... Charter: http://lists.grok.org.uk/full-disclosure-charter.html ...
      (Full-Disclosure)
    • [Full-Disclosure] This sums up Yahoo!s securitypolicyto a -T-
      ... Subject: Re: [Full-Disclosure] This sums up Yahoo!s ... they probably already have their son's account information anyway... ... Because we all know Yahoo! ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • [Full-disclosure] List Charter
      ... This document serves as a charter for the [Full-Disclosure] mailing ... Typically posting will be ... members may be removed from the list by the management. ...
      (Full-Disclosure)