<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <title>Full Disclosure</title>
    <link>http://seclists.org/#fulldisclosure</link>
    <atom:link href="http://seclists.org/rss/fulldisclosure.rss" rel="self" type="application/rss+xml" />
    <language>en-us</language>
    <description>An unmoderated high-traffic forum for disclosure of security information.  Fresh vulnerabilities sometimes hit this list many hours before they pass through the Bugtraq moderation queue.  The relaxed atmosphere of this quirky list provides some comic relief and certain industry gossip.  Unfortunately 80% of the posts are worthless drivel, so finding the gems takes patience.</description>
    <pubDate>Sat, 07 Nov 2009 23:30:06 GMT</pubDate>
    <lastBuildDate>Sat, 07 Nov 2009 23:30:06 GMT</lastBuildDate>
<!-- MHonArc v2.6.16 -->

 

  <item>
    <title>Re: How to receive SPAM mail</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/108</link>
    <description>&lt;p&gt;Posted by dramacrat on Nov 07&lt;/p&gt;If you want to be spammed, join full-disclosure.&lt;br&gt;
&lt;br&gt;
2009/11/7 Michael Holstein &amp;lt;michael.holstein () csuohio edu&amp;gt;&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 23:18:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/108</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/107</link>
    <description>&lt;p&gt;Posted by mikelitoris on Nov 07&lt;/p&gt;if a US citizen is involved, should not require a warrant.&lt;br&gt;
&lt;br&gt;
This is all well and good, until the definition of terrorist is &lt;br&gt;
changed and you become labeled a &amp;quot;terrorist&amp;quot; because your &amp;quot;reason&amp;quot; &lt;br&gt;
is suddenly counterproductive to someone else's &amp;quot;opinion&amp;quot;.  You &lt;br&gt;
must apply the warrant requirement consistently.  Otherwise, when &lt;br&gt;
interpretation of the word &amp;quot;terrorist&amp;quot; changes, it affects the &lt;br&gt;
meaning of the law....&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 23:09:24 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/107</guid>
  </item>
  <item>
    <title>[SECURITY] [DSA 1930-1] New drupal6 packages fix	several vulnerabilities</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/106</link>
    <description>&lt;p&gt;Posted by Steffen Joeris on Nov 07&lt;/p&gt;------------------------------------------------------------------------&lt;br&gt;
Debian Security Advisory DSA-1930-1                  security () debian org&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/&quot;&gt;http://www.debian.org/security/&lt;/a&gt;                      Steffen Joeris&lt;br&gt;
November 07, 2009                   &lt;a  rel=&quot;nofollow&quot; href=&quot;http://www.debian.org/security/faq&quot;&gt;http://www.debian.org/security/faq&lt;/a&gt;&lt;br&gt;
------------------------------------------------------------------------&lt;br&gt;
&lt;br&gt;
Package        : drupal6                           &lt;br&gt;
Vulnerability  : several...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 23:06:57 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/106</guid>
  </item>
  <item>
    <title>Linux 2.6.x fs/pipe.c local root exploit	(CVE-2009-3547)</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/105</link>
    <description>&lt;p&gt;Posted by Edward D. Teach on Nov 07&lt;/p&gt;For those who were not yet aware, there is at least 3 public exploits&lt;br&gt;
since 11/05/2009 for CVE-2009-3547 targeting *all* linux kernels from&lt;br&gt;
2.6.0 to 2.6.31 included. Since spender and fotis have already release&lt;br&gt;
their own, there is not need for us to keep this on our hd. &lt;br&gt;
ImpelDown.c is a poc trying to exploit null ptr dereference in fs/pipe.c&lt;br&gt;
for *all* linux kernel from 2.6.0 to 2.6.31 and ImpelDown-2.6.31only.c&lt;br&gt;
target only linux kernel version...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 23:05:03 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/105</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/104</link>
    <description>&lt;p&gt;Posted by Paul Schmehl on Nov 07&lt;/p&gt;--On November 7, 2009 11:24:55 AM -0600 Valdis.Kletnieks () vt edu wrote:&lt;br&gt;
&lt;br&gt;
No, actually I don't.  I just did a lousy job of wording it.&lt;br&gt;
&lt;br&gt;
That's only true if they can get the paperwork done and obtain the warrant &lt;br&gt;
within 72 hours.  Otherwise, at the 72 hour mark all monitoring must &lt;br&gt;
cease.  And guess who knows that?  We don't exactly keep our operational &lt;br&gt;
strictures secret, you know.  And to think that terrorists aren't aware of &lt;br&gt;
the rules within...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 19:51:48 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/104</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/103</link>
    <description>&lt;p&gt;Posted by Paul Schmehl on Nov 07&lt;/p&gt;--On November 7, 2009 11:20:31 AM -0600 Rohit Patnaik &lt;br&gt;
&amp;lt;quanticle () gmail com&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
Why?  If they were pursuing criminal charges against you, then, by all &lt;br&gt;
means, they should have to comply with all the strictures that protect our &lt;br&gt;
rights.  But to gather intelligence about what terrorists are up to, even &lt;br&gt;
if a US citizen is involved, should not require a warrant.&lt;br&gt;
&lt;br&gt;
Intelligence works best in a world of secrecy.  The more people that are...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 19:32:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/103</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/102</link>
    <description>&lt;p&gt;Posted by Valdis . Kletnieks on Nov 07&lt;/p&gt;On Fri, 06 Nov 2009 23:42:45 CST, Paul Schmehl said:&lt;br&gt;
&lt;br&gt;
Actually Paul, you have that bass-ackwards, and it's important.&lt;br&gt;
&lt;br&gt;
They are allowed to start wiretapping immediately, and then have 72 hours&lt;br&gt;
*after they already started listening* to find a FISA court judge and&lt;br&gt;
do the paperwork.  So yes, the terrorists don't wait for a warrant, and&lt;br&gt;
the NSA doesn't need to wait either.&lt;br&gt;
&lt;br&gt;
So let's see.. You're the NSA. You develop a person of interest.  You start...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 17:25:15 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/102</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/101</link>
    <description>&lt;p&gt;Posted by Rohit Patnaik on Nov 07&lt;/p&gt;The direction of the association doesn't matter. It doesn't matter if the&lt;br&gt;
&amp;quot;terrorist&amp;quot; is contacting me, or if I'm contacting the terrorist.  In either&lt;br&gt;
case, the US government should get a warrant before they spy on me.  Also,&lt;br&gt;
this executive opinion doesn't just apply to the CIA and the NSA.  It&lt;br&gt;
applies to the entire executive branch, including law enforcement.&lt;br&gt;
&lt;br&gt;
Secondly, we seem to have a general disagreement about the intent of the...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 17:20:50 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/101</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/100</link>
    <description>&lt;p&gt;Posted by Paul Schmehl on Nov 06&lt;/p&gt;--On November 6, 2009 10:10:56 PM -0600 Rohit Patnaik &lt;br&gt;
&amp;lt;quanticle () gmail com&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
First of all, the NSA and CIA don't pursue criminal cases against US &lt;br&gt;
persons.  That's the job of law enforcement.  The NSA is a military &lt;br&gt;
agency.  Their job is to protect the US against its enemies by providing &lt;br&gt;
the military with intelligence that helps in planning and the conduct of &lt;br&gt;
operations.  The CIA is a civilian agency tasked with the job of...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 05:43:08 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/100</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/99</link>
    <description>&lt;p&gt;Posted by Rohit Patnaik on Nov 06&lt;/p&gt;If it is so clear that a US citizen is involved in terrorism and is&lt;br&gt;
communicating with terrorists beyond our borders, then why is it so hard for&lt;br&gt;
the NSA, CIA, FBI or Homeland Security to get a warrant?  After all, its not&lt;br&gt;
like they can claim that there wasn't time to get a warrant - the&lt;br&gt;
pre-existing law allowed them to put in expedited requests for warrants&lt;br&gt;
after the actual wiretap started, in addition to allowing continued use of&lt;br&gt;
wiretaps while...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 04:11:18 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/99</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/98</link>
    <description>&lt;p&gt;Posted by Paul Schmehl on Nov 06&lt;/p&gt;--On November 6, 2009 6:07:17 PM -0600 Rohit Patnaik &amp;lt;quanticle () gmail com&amp;gt; &lt;br&gt;
wrote:&lt;br&gt;
&lt;br&gt;
Right.  The New York Times prints an article claiming that a &lt;br&gt;
&amp;quot;whistleblower&amp;quot; has revealed the content of a secret Executive Order.  The &lt;br&gt;
Washington Post then repeats that claim, without any substantiation other &lt;br&gt;
than the supposed statement of an anonymous informant and unnamed &lt;br&gt;
&amp;quot;administration officials&amp;quot; quoting &amp;quot;classified...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 02:57:01 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/98</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/97</link>
    <description>&lt;p&gt;Posted by Paul Schmehl on Nov 06&lt;/p&gt;--On November 5, 2009 10:03:31 PM -0600 Chris &amp;lt;r0ck () operamail com&amp;gt; wrote:&lt;br&gt;
&lt;br&gt;
Not being privy to the process, I couldn't even say if the approval &lt;br&gt;
process is that high.  I'm not inclined to believe it simply because some &lt;br&gt;
reporter or secret source claimed it to be true.  You, of course, live &lt;br&gt;
with the absolute certainty that you know the truth and no other possible &lt;br&gt;
explanation is plausible than the one you believe.&lt;br&gt;
&lt;br&gt;
I think this subject...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 01:13:07 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/97</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/96</link>
    <description>&lt;p&gt;Posted by Rohit Patnaik on Nov 06&lt;/p&gt;On Fri, Nov 6, 2009 at 1:25 PM, Paul Schmehl &amp;lt;pschmehl_lists () tx rr com&amp;gt;wrote:&lt;br&gt;
&lt;br&gt;
You say that claims about the NSA conducting warrantless wiretaps against US&lt;br&gt;
citizens are unsubstantiated.  That is totally and blatantly false (&lt;br&gt;
&lt;a  rel=&quot;nofollow&quot; href=&quot;http://is.gd/4PcWV&quot;&gt;http://is.gd/4PcWV&lt;/a&gt;).  The linked article clearly states, &amp;quot;Mr. Bush's&lt;br&gt;
executive order allowing some warrantless eavesdropping on those inside the&lt;br&gt;
United States - including American citizens, permanent legal...&lt;br&gt;</description>
    <pubDate>Sat, 07 Nov 2009 00:07:37 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/96</guid>
  </item>


  <item>
    <title>Re: How to receive SPAM mail</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/95</link>
    <description>&lt;p&gt;Posted by Michael Holstein on Nov 06&lt;/p&gt;I had to do a similar thing when doing a spam-appliance &amp;quot;vendor &lt;br&gt;
shakedown&amp;quot; .. what I did was setup a subdomain&lt;br&gt;
&lt;br&gt;
eg: test.mycompany.com&lt;br&gt;
&lt;br&gt;
and then create email IDs within that subdomain that had valid mailboxes&lt;br&gt;
&lt;br&gt;
eg: bob () test mycompany com, suzie () test mycompany com, etc.&lt;br&gt;
&lt;br&gt;
and then I used Google to search for &amp;quot;free offers&amp;quot; and &amp;quot;work from home&amp;quot;, &lt;br&gt;
etc. and entered those IDs on about 100 different sites. There's tons...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 21:47:24 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/95</guid>
  </item>
  <item>
    <title>Re: How Prosecutors Wiretap Wall Street</title>
    <link>http://seclists.org/fulldisclosure/2009/Nov/94</link>
    <description>&lt;p&gt;Posted by Paul Schmehl on Nov 06&lt;/p&gt;--On Friday, November 06, 2009 10:46:39 -0600 Valdis.Kletnieks () vt edu wrote:&lt;br&gt;
&lt;br&gt;
The root claim is that the NSA was/is conducting illegal, warrantless &lt;br&gt;
surveillance on American citizens.  That claim has never been substantiated, &lt;br&gt;
and that is precisely my point.  If you know anything about internet routing &lt;br&gt;
(and I know you do), then you understand that to capture the traffic of &lt;br&gt;
terrorists you would have to be at a peering location where traffic...&lt;br&gt;</description>
    <pubDate>Fri, 06 Nov 2009 19:36:00 GMT</pubDate>
    <guid isPermaLink="true">http://seclists.org/fulldisclosure/2009/Nov/94</guid>
  </item>

 

<!-- MHonArc v2.6.16 -->
  </channel>
</rss>
