lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Thu, 23 Jun 2011 11:13:30 -0400
From: "Elazar Broad" <elazar@...hmail.com>
To: adam@...sy.net
Cc: full-disclosure@...ts.grok.org.uk
Subject: Re: [New Security Tool] INSECT Pro 2.6.1 release

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Most people charge for that, the least Juan could do is give you a
*free* "license" for his scamware(we know you want it ;) ).

<lament>Ah, the state of so-called "security" these days...it's
sad.</lament>

elazar

On Wed, 22 Jun 2011 23:38:06 -0400 adam <adam@...sy.net> wrote:
>*cough*
>
>*Directory indexes enabled:*
>http://www.insecurityresearch.com/wp-includes/
>http://www.insecurityresearch.com/wp-content/uploads/
>http://www.insecurityresearch.com/wp-content/plugins/wp-pagenavi/
>http://www.insecurityresearch.com/wp-content/plugins/wp-
>postratings/
>
>*Path disclosure:*
>http://www.insecurityresearch.com/wp-content/themes/eVid/
>
>*Other:*
>
>   - Using outdated version of SSL
>   - Outdated SSL Certificate (2009)
>   - Outdated version of mod_frontpage (which may be vulnerable to
>a root
>   access exploit)
>   - At *least* a dozen broken links
>   - MySQL is exposed to the internet
>
>Blah blah blah. Some of these may or may not be serious but the
>fact is: it
>took less than 60 seconds to find all of it. Imagine what someone
>who is *
>really* bored could find. I think I'll pass on your oh so special
>*hacker*
> tool.
-----BEGIN PGP SIGNATURE-----
Charset: UTF8
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 3.0

wpwEAQECAAYFAk4DWBoACgkQi04xwClgpZjqngP7BS/OSkELU/BGjpOSepaYERwBn47U
k+pRpovVjQHLQTxNpV9cVm0HEGq8DGacPvTtQ/1F9krmA3KzwpcJrX/71sNyKIlWofAI
XTVteAtIBL9ic9N0FTZq0QZpqKC5Ea2I/NXUE9+n7yz1X6jX6zMru/hJVKHqARVQ8Wvh
U4lFMoo=
=XzNo
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ