Full Disclosure mailing list archives

Re: XSS and SQL injection via SIP (part 2) and toll fraud bonus


From: state () loria fr
Date: Sat, 20 Oct 2007 08:41:20 +0200

Selon phioust <phioust () gmail com>:

On 10/20/07, lulzlulzluzluz <hardened.php () gmail com> wrote:

security is serious business. plz do not joke like that phioust:
xss0day -> x-ssh0day, see serious.


 Only drraid has ssh 0day


On 10/19/07, Radu State < State () loria fr> wrote:

          my $hex = '';

          for (my $i = 0; $i < length($_[0]); $i++) {

    LOL 3 phds and not one knows the range operator?
    for(0..length($_[0]))


Yeap, Ph.d use Eiffel and Lisp.  Only when we want to be understood by a larger
community, we go to Perl and reach down.



$attackerUser = $ARGV[3];

$callUser = $ARGV[0];

$targetIP = $ARGV[1];

$targetPort = $ARGV[2];

$attackerIP= $ARGV[4];

$attackerPort= $ARGV[5];

 have you never heard of shift? or what about split @ARGV based on
spaces ... l0l perl retards

Thnaks for sharing experience


 Did you only write this in perl because C is too complicated for you?


Do you write your comments, only because writing real interesting things is to
complicated for you ? (BTW, the word "too" in your post  has another meaning
that what you wanted to say, which is normally written "to" )


you better hope perl underground does see this bullshit perl!!!



And what ? I am not a perl coder and never claimed to be one :)




_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: