Re: [Fwd: Re: AIM Password theft]

From: Thor Larholm (thor_at_PIVX.COM)
Date: 09/24/03

  • Next message: Larry Seltzer: "Re: Perpetual restarts after installing MS03-039 patch"
    Date:         Wed, 24 Sep 2003 12:57:30 -0700
    To: NTBUGTRAQ@LISTSERV.NTBUGTRAQ.COM
    
    

    Don't you just hate it when your bad predictions turn out true? At least 200
    people that subscribe to the list did not see that post, and that is just the
    people whose malfunctioning antivirus actively bounce the message and whose
    bounces were not caught by my mailserver filters.

    "Antigen found VIRUS= Exploit-ObjectData (NAI) virus", "ALERT - GroupShield",
    "TFS Virus Alert" - the list goes on and on.

    Seriously, if you are going to subscribe to a SECURITY mailinglist you will have
    to expect that exploit code, proof-of-concepts and code snippets thereof are
    posted to the list from time to time. I honestly believe that this should be a
    very valid reason for a forced unsubscribe by the list administrator, just as
    OutOfOffice bounces are, and would recommend to include a tiny POC in any troll
    bounce-trigger message the administrator sends out.

    Add to the fact that there was actually NO exploit code, or even functional
    HTML, in the post and you only intensify the problem by continuing to use
    antivirus which simply do NOT work, adding to your sense of false security.

    Regards
    Thor Larholm
    PivX Solutions, LLC - Senior Security Researcher
    http://www.pivx.com/larholm/unpatched - Unpatched IE vulnerabilities

    -----Original Message-----
    From: Thor Larholm
    Sent: Tue 9/23/2003 2:05 PM
    To: Mark Coleman; bugtraq@securityfocus.org
    Subject: RE: [Fwd: Re: AIM Password theft]
    <snip>

    Now, if any mind-boggling lame antivirus system shouts back at me for
    repeating GM#001 or the Object Data HTTP header, I reserve the right to
    mail your system administrator and notify him of his malfunctioning
    software.

    ----
    Are You "Certifiable"? Summer's Hottest Certification Just Got HOTTER!
    With a growth rate exceeding 110%, the TICSA security practitioner
    certification is one of the hottest IT credentials available.  And now, for
    a limited time, you can save 33% off of the TICSA certification exam! To
    learn more about the TICSA certification, and to register as a TICSA
    candidate online, just go to
    http://www.trusecure.com/offer/s0100/
    ----
    

  • Next message: Larry Seltzer: "Re: Perpetual restarts after installing MS03-039 patch"

    Relevant Pages

    • Re: Drivial Pursuit: Internet Explorer Browser & Your Files and Folders !
      ... The default Enhanced Security Configuration of IE ... access to files and folders on the local machine from the internet. ... With a growth rate exceeding 110%, the TICSA security practitioner certification is one of the hottest IT credentials available. ... And now, for a limited time, you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Re: Workaround for stopping MS2003-030 exploitation via HTML? [VU#561284]
      ... >Internet Explorer 'Run ActiveX Controls' security setting to disable in ... >appropriate IE security zones would prevent exploitation of this in web ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (Cert)
    • MSTDC Security Configuration Resources
      ... After some digging into the MSDTC Event issue for people, ... DTC Security Considerations - Overview of Managing Features ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Re: Norton Internet Security 2003 blacklist fault?
      ... "a.com" can be both a portion of a domain and a host name. ... it's security companies that make ... Summer's Hottest Certification Just Got HOTTER! ... you can save 33% off of the TICSA certification exam! ...
      (NT-Bugtraq)
    • Risks Digest 24.59
      ... ACM FORUM ON RISKS TO THE PUBLIC IN COMPUTERS AND RELATED SYSTEMS ... Workshop on Web Security, ... FDA - MedWatch - Medical Device Safety - Change in Daylight ... Subject: REVIEW: "FISMA Certification and Accreditation Handbook", ...
      (comp.risks)