lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [thread-next>] [day] [month] [year] [list]
Date: Fri, 11 Jul 2008 13:22:31 -0700
From: "Sandy Vagina" <bigsandyvagina@...il.com>
To: full-disclosure@...ts.grok.org.uk
Subject: Re: Nominate Dan Kaminsky for Most Overhyped Bug
	Pwnie Award

n3td3v wrote:
> Please nominate Mr.DNS aka Dan Kaminsky for Most Overhyped Bug on the
> Pwnie Awards 2008.

Perhaps if you bothered to read anywhere close to as much as you
write, you would have seen that Dino, one of the judges, specifically
disqualified this bug from the Pwnies for being too awesome:

http://blog.trailofbits.com/2008/07/09/dan-kaminsky-disqualified-from-most-overhyped-bug-pwnie/

> I have heard about the vulnerability

In the future, don't stop at hearing about something and proceed
straight to working on comprehending.

> People should ignore this and post the exploit to Full-Disclosure
> before Blackhat conference to fuck up the Blackhat profits and show
> everyone how lame the exploit actually is.

Turned down your talk submission on "secret stuff I do with MI5", did they?

Given how much you can't stand it when anyone but you gets some
attention for infosec stuff, Dan's patch must have triggered a full,
rolling on the floor, kicking, crying and screaming until you can't
breathe tantrum.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ