lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <4b6ee9310607261620t2c277058rde4b2b000eb60af4@mail.gmail.com>
Date: Wed, 26 Jul 2006 23:20:16 +0000
From: n3td3v <xploitable@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: F-Secure to release XSS "potential dangers"

On 7/26/06, c0ntex <c0ntexb@...il.com> wrote:
> On 26/07/06, n3td3v <xploitable@...il.com> wrote:
>
> > F-Secure know the enemy of the Netscape web site are reading their blog:
>
> I see you notice that f-secure, a security company, have released
> information about a security bug - well spotted - next, you
> thoughtlessly share your opinion and disgust about said site
> advertising said information, then work a form of magic that surpasses
> even Harry Potters book of wizardry by sending /to a public mailing
> list/  a link to the same information. You then execute ./mounth -vv,
> apposed to the earlier ./mouth -v, providing a nice write-up about the
> bug, netscape and security for search bots to index.
>
> Netscape is d00med!! and it is all n3td3v's fault lol
>
> --
>
> regards
> c0ntex

You missed the point of my post.

I have nothing against F-Secure reporting the bug, I only have
something against F-Secure supplying information on how to use an XSS
vulnerability properly in which to cause the most damage to the
Netscape web site.

If you read my post and the F-Secure blog properly, you'll see they
reported that the vulnerability wasn't exploited fully, and F-Secure
promised to publish information to show attackers how to do the job
properly.

Thanks for your attempt to wind me up, you almost succeeded.

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ