lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Date: Sun, 11 May 2008 02:59:17 +0100
From: n3td3v <xploitable@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: Fwd: NOTICE: Site compromised

On Sun, May 11, 2008 at 2:22 AM, Dr. J Swift <fdiscsplat@...il.com> wrote:
> On Sat, May 10, 2008 at 8:11 PM, n3td3v <xploitable@...il.com> wrote:
>> ---------- Forwarded message ----------
>> From: Robert Lemos <mail@...ertlemos.com>
>> Date: Sat, May 10, 2008 at 4:21 PM
>> Subject: NOTICE: Site compromised
>> To: feedback@...ertlemos.com
>>
>>
>> You are being sent this notice, because you had a user account on my
>> site, robertlemos.com.
>> Hackers gained access to the password account to the site. This does
>> not mean they have your password, but a scrambled version of your
>> password, known as a hash. Unfortunately, malicious hackers could use
>> try to brute force the hash or use other techniques to find your
>> password, especially if is an easy to guess combination of letters and
>> numbers.
>> For that reason, I recommend that, if you use the password on other
>> accounts, you change those accounts to use a new password.
>> If you have any questions, feel free to contact me. I apologize for
>> the inconvenience.
>> -R
>> | robert lemos | mail@...ertlemos.com |
>> | science & technology journalist |
>> | http://www.robertlemos.com |
>>
>
> Mr. Wallace,
>
> Apparently, even a high-ranking security officer such as yourself
> posts exploits to Full Disclosure.
>
> After your exploit, Mr Lemos' website only says that his site formerly
> contained "the musings of a technology and science journalist..."
>
> Is this an action of the n3td3v group in furtherance of the n3td3v agenda?
>
> This seems to be another confirmation of your illicit hacking that
> chills me and forces me to hide behind a pseudonym.  I am stunned into
> disbelief that you have said intelligence services tacitly work with
> you.  I now fully believe your claim of being involved in the
> "political scene" of security.
>
> How else could you be allowed to make copious international threats of
> violence, intimidation, slander, and engender frivolous and harassing
> lawsuits while simultaneously hacking and destroying your enemies'
> internet presence?
>
> I am now even more uncertain of being able to life without harm to my
> person or career, Mr. Wallace.
>

---------- Forwarded message ----------
From: n3td3v <xploitable@...il.com>
Date: Sun, May 11, 2008 at 2:30 AM
Subject: Re: [Full-disclosure] ZF04 has been released!
To: full-disclosure@...ts.grok.org.uk


On Sat, May 10, 2008 at 12:36 AM,  <robert.lemos@....hush.com> wrote:
> -----BEGIN PGP SIGNED MESSAGE-----
> Hash: SHA1
>
> I, Robert Lemos (see robertlemos.com, I need hits!) have
> collaborated with the ZF0 team to bring you this piece. Check out
> my blog or milw0rm or http://cypher0.h18.ru//zf04.txt for more
> information! I am talking to SecurityFocus about making it a
> featured item, so don't forget to check securityfocus.com and
> robertlemos.com for further details in the upcoming weeks!
>
> Thank you dearies,
>
> Bobby "Bologna" Lemos

This is dreadful news,

I hope Robert Lemos's site recovers as quickly as possible, and I
condemn any law breaking by ZF0.

All the best,

n3td3v

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ