Re: [FD] Iron Mountain doesn't take physical security seriously

2014-07-05 Thread Sanguinarious
What is it with this company and warehouse fires / arson? Like seriously? Anyone else find that incredibly odd considering? It doesn't give me confidence whatever they provide for storage considering it might go up in flames in a year or two. On Thu, Jul 3, 2014 at 8:40 AM, Hinky Dink wrote: > >

Re: [FD] Iron Mountain doesn't take physical security seriously

2014-07-05 Thread Hinky Dink
You might want to check out this: http://en.wikipedia.org/wiki/Iron_Mountain_Incorporated#Data_losses $DAYJOB dropped Iron Mountain long ago. On 6/30/2014 3:41 PM, freddiela...@cock.li wrote: > Went down into my office's lobby today and saw a few dozen boxes of > confidential papers belonging t

Re: [FD] AV scan on read vs write debate....

2014-07-05 Thread Victor Aguilar
Reindl Harald wrote: Am 01.07.2014 20:26, schrieb Joe Brown: > A compromise might be to have scan on Write only, with a forced full system > scan of all files at a certain time. > For example at lunch time. bad idea > 1. You don't have an all the time performance hit if i scan my full sys

[FD] Finding page including parameters with google dorks

2014-07-05 Thread rai
Hi, Here's a google dork that doesn't seem to be listed anywhere but gets some good results: inurl:"index.php?page=" Inside that parameter, there can be straightforward lfi's, rfi's but also subtle things too. The search does bring in a lot of false positives, so looking for urls ending wit

[FD] Feed2JS/MagpieRSS 0day vulnerability (not really, it is actually CVE-2005-3330 / CVE-2008-4796)

2014-07-05 Thread Michail Strokin
Feed2JS is a tool for user-friendly(developer-wise) embedding the RSS feeds on the pages without messing with XML. I’ve found out today that it’s vulnerable to local file disclosure (all your /etc/passwds could be stolen). It could be used for remote file inclusion as well. tl;dr – fixed files at

[FD] new pen-test tool!

2014-07-05 Thread Pete Herzog
Hi! I have been working on a means for testing parties that we may not be able to legally directly test yet gives a clear answer for decision making. The idea was to use an interview like a pen-test to get information from the subject like a tester would where "asking them" was considered just one

[FD] Raritan IPMI vulnerability

2014-07-05 Thread Jörg Kost
  Vulnerability: Raritan PX power distribution software contains several well known IPMI vulnerabilities, e.g. - ipmi zero cipher - ipmi dump hash passwords    Details: E.g. Model DPXR20A-16:    Software release all before and including 01.05.08 (recent version from october 2013) ipmitool -I l

[FD] Conduct phonecalls on Android without the necessary permission, advisory+testapplication+exploits for testing (CVE-2013-6272 and CVE-2014-N/A)

2014-07-05 Thread Curesec Research Team
Hi List, we are pleased to announce the public disclosure of two new bugs in Android OS. 1. CVE-2013-6272 com.android.phone Introduction We conducted a deep investigation of android components and created some CVEs and reported bugs to the Android Security Team in late 2013. Today we want to pu