Re: [FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-07 Thread Andrew Case
its 64KB per request so you can read much more than that through multiple requests Thanks, Andrew (@attrc) On 4/7/2014 7:10 PM, Kirils Solovjovs wrote: > We are doomed. > > Description: http://www.openssl.org/news/vulnerabilities.html > Article dedicated to the bug: http://heartbleed.com/ > Tool

[FD] heartbleed OpenSSL bug CVE-2014-0160

2014-04-07 Thread Kirils Solovjovs
We are doomed. Description: http://www.openssl.org/news/vulnerabilities.html Article dedicated to the bug: http://heartbleed.com/ Tool to check if TLS heartbeat extension is supported: http://possible.lv/tools/hb/ A missing bounds check in the handling of the TLS heartbeat extension can be used t

[FD] NoSuchCon 2014 CFP is now open

2014-04-07 Thread NoSuchCon
TL;DR = Conference: NoSuchCon 2014 Date: 19-21 November Venue: Paris, France Motto: "the bullshit-free conference" CFP deadline: September 31st 2014 Web: www.nosuchcon.org Contact: cfp{at}nosuchcon.org Twitter: @NoSuchCon Details === The USA are sucking oil from this planet up to the las

Re: [FD] Legality of Open Source Tools

2014-04-07 Thread Daniel Wood
Toni, The English version has this information in Chapter 38, I didn't find it in a Chapter 34. The key to all this is the language of intent, using verbiage such as "aggravated", "unlawful", and "to cause detriment". This is the same as the United States and many other countries; if you don'

[FD] Advisory: Security Industry Scams and Lies

2014-04-07 Thread Nico Le Moin
Hello List, I want to warn you about entities that exploit public internet infrastructure for self promotion. I will do so by example, entity Pete Herzog (PH): - PH abuses the ability to post to public mailing lists ( for example seclists.org/fulldisclosure/2014/Apr/55 ). - PH creates wikipedi