Full Disclosure mailing list archives

HAL2001 GAY IN THE MIDDLE COCK SNARFING VULNERABILITY


From: Jack Ahz <anoncoder () yahoo com>
Date: Thu, 2 Jan 2003 21:51:05 -0800 (PST)

ADVISORY: 3RD PARTY SURVEILLANCE WEAKNESSES

DATE: 01/03/2003

DATE OF PROBLEM: HAL 2001

DESCRIPTION:

It has come to our attention that a particular set of videos encoded with the
"DIVX" format has been making the rounds on IRCNET for some time, and has now
just recently been added to the famed porn xdcc bots of Efnet. This set of
videos, entitled 'gaysshower_group_nl_2001-[1-15].mpg' shows participants of
the Hackers at Large (HAL) 2001 convention showering in a communal stall and
gingerly lathering themselves up with various commercial disinfectants. Since
most of the victims of this heinous act are German and Dutch, they are at an
extremely high risk of appearing FLAGRANTLY HOMOSEXUAL. This video, which was
first featured on various toilet/showercam feeds across the Internet, including
large streams offered free-of-charge to paying milfhunter patrons, shows
several well known 'hackers' in awkward and compromising positions. We have
learned that many of these hackers belong to the groups known as 'TESO,' 'THC,'
and 'hack.se'

THE ATTACK:

A large sign was posted at the front door of the showers saying, "Warning:
Surveillance cameras have been installed in the showers for your own
protection." By manipulating carefully patterned social trust relations, the
attacker whom we shall name "Mallory" was able to fool participants "Andy" and
"Bob" by a social engineering attack which allowed him to implant video cameras
into a public showering stall that generated high amounts of human traffic.
Participants were taped, and these tapes were sold to other users of the
internet relay chat, many of whom possessed considerably less technical skill.

SOLUTION:

There are 2 known solutions to the vulnerability:

1.  Avoid taking communal showers at well known hacker conventions, where
several grossly overweight fully-grown men and other emaciated prepubescent
hackers congregate to bathe in the nude and discuss the happenings of #norge
and #middle-earth.

2. Use a video wand device to locate hidden surveillance cameras if you must
take a shower, and then shower with your back to the camera so that your face
cannot be identified in globally distributed gay softcore pornography videos.
Such wands, as found at

http://www.techtv.com/products/consumerelectronics/story/0,23008,3333550,00.html

can be purchased from vendors such as CCS International Counterspy Gear.

   The   $4,800   VCD-100  claims  to  detect  and  locate  hidden  video
   surveillance devices. In vibrate mode, you could keep the VCD-100 in a
   coat pocket and have it silently alert you to the presence of a nearby
   camera.

We have contacted CCS and other vendors and are anticipating their followup
posts.

--- END TRANSMISSION ---


__________________________________________________
Do you Yahoo!?
Yahoo! Mail Plus - Powerful. Affordable. Sign up now.
http://mailplus.yahoo.com
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Current thread: