lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [day] [month] [year] [list]
Date: Mon Jul 10 22:52:42 2006
From: ninjadaito at hushmail.com (ninjadaito@...hmail.com)
Subject: Re: Google and Yahoo search engine zero-day code

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Dear N3tN00dle,

The more you post, the more convinced I become that you are
complete moron.  The one saving grace is that you provide so many
free laughs!!

Talk about delusions of grandeur.  LOL.

Given enough rope, you'll eventually hang yourself.

Ninja

[chop majority of cruft]

>
>1. insert exploit code into server
>
>2. wait for google and yahoo
>
>3. access key set once bot reaches your page, this lets n3td3v
>research branch access our exploied data via search.yahoo.com (a
>key
>is assigned, so noone else can query our data by accident, this
>acts
>as a password for the search data.
>
>4. Our bot goes to search.yahoo.com with matching access key, and
>grabs data... is served back to our database, where we then use
>this
>data to access corporate and consumer accounts, and do specialized
>harvesting of the type of data we've grabbed from the Yahoo and
>Google
>servers.
>
>5. We define the different types of consumer and corporate data
>thats
>arrived on our database server, allowing us to further filter and
>tag
>different types of data, this then allows us to 'search our'
>database
>on demand for corporate and (or) corporate data.
>
>6. We have world domination, and Google and Yahoo cannot detect
>the
>malicious with their conventional aduit methods, because we asked
>our
>inside contacts.
>
>Happy coding.
>
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
-----BEGIN PGP SIGNATURE-----
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 2.5

wkYEARECAAYFAkSyzBoACgkQtM6vtsm2y1s0IQCbBd+7GSpKbzbJW4ScfnfRgdWBpUsA
nRh/XuJNeWp51uCok5t1pYkJ4Rak
=2vfn
-----END PGP SIGNATURE-----




Concerned about your privacy? Instantly send FREE secure email, no account required
http://www.hushmail.com/send?l=480

Get the best prices on SSL certificates from Hushmail
https://www.hushssl.com?l=485

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ