lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20050218154734.GA21909@jschipper.dynalias.net>
From: j.schipper at math.uu.nl (Joachim Schipper)
Subject: Re: iDEFENSE Labs Website Launch (iDEFENSE Labs)

On Fri, Feb 18, 2005 at 07:53:29AM -0500, Edge, Ronald D wrote:
> > Date: Thu, 17 Feb 2005 12:20:30 -0500
> > From: "iDEFENSE Labs" <labs-no-reply@...fense.com>
> > Subject: [Full-Disclosure] iDEFENSE Labs Website Launch
> > To: <full-disclosure@...ts.netsys.com>,
> > 	<dailydave@...ts.immunitysec.com>,	
> > <bugtraq@...urityfocus.com>
> > Message-ID:
> > 	<FB24803D1DF2A34FA59FC157B77C970503E244C3@...erv04.idef.com>
> > Content-Type: text/plain;	charset="us-ascii"
> > 
> > iDEFENSE Labs is pleased to announce the launch of our community site:
> > 
> >     http://labs.idefense.com
> 
> Funny. All I get is a blank white page. Could it be you are expecting me
> to trust your site, turn off all my defenses, turn on scripting, to view
> the page? You're kidding right, this is just a joke to test participants
> gullibility, right?
> 
> Ron.

To be fair, it can be circumvented by just reading the source. However,
while Wetware/1.0 is a rather secure Javascript interpreter, it suffers
from lack of speed.

In short, I gave up when I got another blank page after finding their
front page. Looks like the guys at iDEFENSE are not prepared for this
kind of paranoia...
 
Other than the fact it's not really accessible without enabling
Javascript, it might be a fine site, though.

		Joachim

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ