Full Disclosure mailing list archives

Re: [New Security Tool] INSECT Pro 2.6.1 release


From: "Elazar Broad" <elazar () hushmail com>
Date: Thu, 23 Jun 2011 11:13:30 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

Most people charge for that, the least Juan could do is give you a
*free* "license" for his scamware(we know you want it ;) ).

<lament>Ah, the state of so-called "security" these days...it's
sad.</lament>

elazar

On Wed, 22 Jun 2011 23:38:06 -0400 adam <adam () papsy net> wrote:
*cough*

*Directory indexes enabled:*
http://www.insecurityresearch.com/wp-includes/
http://www.insecurityresearch.com/wp-content/uploads/
http://www.insecurityresearch.com/wp-content/plugins/wp-pagenavi/
http://www.insecurityresearch.com/wp-content/plugins/wp-
postratings/

*Path disclosure:*
http://www.insecurityresearch.com/wp-content/themes/eVid/

*Other:*

  - Using outdated version of SSL
  - Outdated SSL Certificate (2009)
  - Outdated version of mod_frontpage (which may be vulnerable to
a root
  access exploit)
  - At *least* a dozen broken links
  - MySQL is exposed to the internet

Blah blah blah. Some of these may or may not be serious but the
fact is: it
took less than 60 seconds to find all of it. Imagine what someone
who is *
really* bored could find. I think I'll pass on your oh so special
*hacker*
tool.
-----BEGIN PGP SIGNATURE-----
Charset: UTF8
Note: This signature can be verified at https://www.hushtools.com/verify
Version: Hush 3.0

wpwEAQECAAYFAk4DWBoACgkQi04xwClgpZjqngP7BS/OSkELU/BGjpOSepaYERwBn47U
k+pRpovVjQHLQTxNpV9cVm0HEGq8DGacPvTtQ/1F9krmA3KzwpcJrX/71sNyKIlWofAI
XTVteAtIBL9ic9N0FTZq0QZpqKC5Ea2I/NXUE9+n7yz1X6jX6zMru/hJVKHqARVQ8Wvh
U4lFMoo=
=XzNo
-----END PGP SIGNATURE-----

_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


Current thread: