[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Message-Id: <20070719141603.C4BA0C381F@mailserver10.hushmail.com>
Date: Thu, 19 Jul 2007 10:15:57 -0400
From: "Joey Mengele" <joey.mengele@...hmail.com>
To: <andre@...rations.net>,<lmh@...o-pull.com>,<dave@...atasec.com>
Cc: full-disclosure@...ts.grok.org.uk, fuzzing@...testar.linuxbox.org,
dailydave@...ts.immunitysec.com
Subject: Re: [fuzzing] The truth
But what does Dr. Neal Krawetz have to say? I will not draw any
conclusions until he has the time to analyze the writing samples.
As Neal has taught us, the students of Full Disclosure, there is no
validation required for online impersonation [1]. How do we know
you are not impersonating this David Maynor character?
More importantly, and of equal relevance to this list (these
lists?), how can we be sure you aren't n3td3v? Or GOBBLES? Or both?
J
[1] http://www.securityfocus.com/columnists/441
On Thu, 19 Jul 2007 09:36:49 -0400 David Maynor
<dave@...atasec.com> wrote:
>http://erratasec.blogspot.com/2007/07/i-am-not-lmh.html
>
>-----Original Message-----
>From: full-disclosure-bounces@...ts.grok.org.uk [mailto:full-
>disclosure-bounces@...ts.grok.org.uk] On Behalf Of
>andre@...rations.net
>Sent: Thursday, July 19, 2007 9:15 AM
>To: Lance M. Havok
>Cc: full-disclosure@...ts.grok.org.uk;
>fuzzing@...testar.linuxbox.org; dailydave@...ts.immunitysec.com
>Subject: Re: [Full-disclosure] [fuzzing] The truth
>
>Dave / LMH / whatever,
>
>Give up.
>
>You really don't get it, do you?
>
>Rouland, Ptacek, hdm, myself - we're all out to get you.
>Infosecsellout is a collaborative effort to drive you insane.
>
>Aitel even wrote that script just to make you more paranoid.
>
>If anyone actually cares that you used two identities online I'll
>really be surprised. So did my grandma.
>
>Is this some kind of story? A confession? A bug report? Your
>whole
>paragraph about SILC leads nowhere - it doesn't make any sense.
>
>Ptacek, hdm, myself, et al - we all know who Infosecsellout is.
>Not
>because we wrote clever scripts that do user fingerprinting via
>behavorial statistical analysis. Think of it more like hearing the
>voice of an old friend call you on the phone. Someone you haven't
>heard from in awhile. Easy to identify, correct?
>
>Wait, why am I asking you? - that's probably never going to happen
>to you.
>
>dre
>
>_______________________________________________
>Full-Disclosure - We believe in it.
>Charter: http://lists.grok.org.uk/full-disclosure-charter.html
>Hosted and sponsored by Secunia - http://secunia.com/
--
Click for free info on getting an MBA and make $200K/ year
http://tagline.hushmail.com/fc/Ioyw6h4dDMuaA9DlFrXR40LjjGs7d8fkCvBa3ypawS7AlnYdsQkaT2/
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/
Powered by blists - more mailing lists