Full Disclosure mailing list archives

Re: Re: home land tracker software


From: Valdis.Kletnieks () vt edu
Date: Fri, 06 Feb 2004 16:18:15 -0500

On Fri, 06 Feb 2004 15:42:32 EST, gabriel rosenkoetter <gr () eclipsed net>  said:

I might be scared if it seemed like they had any data useful data, but
since it's not clear exactly what data they'd have anyway (knowing
that my name exists doesn't take more than Google, and you can get
way more than that with whois(1)).

Geezuz H. F**king.. 

An alledged infosec list, and nobody twigs to the fact that there are at
least 4 sets of data:

1) The data that the website is going to show to Joe Random Tourist.

2) The data that the website is going to show to Joe Random Tourist
with a Referer: pointing to slashdot.org

3) The data that the website is going to show to an authenticated user.

4) The data that the website is going to show to a hacker.

These are probably all different, and we're only seeing reports for (1)
and maybe (2).

Attachment: _bin
Description:


Current thread: