RE: [Full-Disclosure] how do they do it???

From: Ken Pfeil (Ken_at_infosec101.org)
Date: 07/11/03

  • Next message: gregh: "[Full-Disclosure] Networking security problem?"
    To: "'morning_wood'" <se_cur_ity@hotmail.com>, "'Thor Larholm'" <lists.netsys.com@jscript.dk>, <full-disclosure@lists.netsys.com>
    Date: Thu, 10 Jul 2003 20:23:27 -0400
    
    

    Hehe..
    U forgot to say "No fix on 0day" or "Local exploit"..

    > -----Original Message-----
    > From: full-disclosure-admin@lists.netsys.com
    > [mailto:full-disclosure-admin@lists.netsys.com] On Behalf Of
    > morning_wood
    > Sent: Thursday, July 10, 2003 4:37 PM
    > To: Thor Larholm; full-disclosure@lists.netsys.com;
    > zorkshin@tampabay.rr.com
    > Subject: Re: [Full-Disclosure] how do they do it???
    >
    >
    > ----- Original Message -----
    > From: "Thor Larholm" <lists.netsys.com@jscript.dk>
    > To: <full-disclosure@lists.netsys.com>; <zorkshin@tampabay.rr.com>
    > Sent: Thursday, July 10, 2003 12:42 PM
    > Subject: Re: [Full-Disclosure] how do they do it???
    >
    >
    > > > From: <zorkshin@tampabay.rr.com>
    > > > http://www.albinoblacksheep.com/text/cupholder.php
    > > >
    > > > how do you think they do it in PHP?
    > >
    > > Thank you for confirming that you have NOT installed the MS03-021
    > patch [1] for
    > > Windows Media Player, which among others removes the ability to
    > eject CD drives
    > > using the WMP ActiveX control. I can now safely assume that you are
    > vulnerable
    > > to several vulnerabilities.
    > >
    > > Do you want an HTML email? ;)
    > >
    > >
    > > [1]
    > > http://www.microsoft.com/technet/security/bulletin/ms03-021.asp
    > >
    > >
    > > Regards
    > > Thor Larholm
    > > PivX Solutions, LLC - Senior Security Researcher
    >
    > Replies like this are realy not need are they??? MrSecurity
    > Reseacher? I suppose i should lament you on your deficencies, btw I
    > dont have the patch installed either... by choice. Dont ass-u-me as we
    > all know what that makes you look like.
    >
    > Donnie Werner
    > http://nothackers.org
    > _______________________________________________
    > Full-Disclosure - We believe in it.
    > Charter: http://lists.netsys.com/full-disclosure-charter.html
    >

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: gregh: "[Full-Disclosure] Networking security problem?"