Welcome! Log In Create A New Profile Recent Messages

Advanced

[Full-disclosure] "Please remove my e-mail and IP from internet"

Posted by Tonu Samuel 
Really funny thread is going on in Postfix-Users list. Scroll down about half of content here:

[comments.gmane.org]

Just good example how NOT to do.

Tonu
_______________________________________________
Full-Disclosure - We believe in it.
Charter: [lists.grok.org.uk]
Hosted and sponsored by Secunia - [secunia.com]
On 29/06/2012 06:47, Tonu Samuel wrote:
> Really funny thread is going on in Postfix-Users list. Scroll down about half of content here:
>
> [comments.gmane.org]
>
> Just good example how NOT to do.

I fwd'd details to lester haines of vulture central fame but doubt he will
see it a a story.

This outsourced orange sysadmin really needs the striesand effect to hit him
and orange - hard!

Has anyone contacted any of the email addresses in the logs pointing out the
disclosure. I suspect kia as a company may not be too happy that a SAP reports
email address has been disclosed. Far easier to soclially engineer something
when you have even this minor sort of info.

Jacqui

_______________________________________________
Full-Disclosure - We believe in it.
Charter: [lists.grok.org.uk]
Hosted and sponsored by Secunia - [secunia.com]
Not to mention as others pointed out it is implied that the guy might've
let out information he didn't have permission to let out, which could get
him into some serious trouble. Also I could be wrong since I don't remember
the full thing but did the guy said they were doing a pentest soon? No need
to report the guy when any remotely competent pentest team is gunna find
this and probably start laughing smiling smiley
On Jul 3, 2012 8:18 AM, "Jacqui Caren" <jacqui.caren@ntlworld.com> wrote:

> On 29/06/2012 06:47, Tonu Samuel wrote:
> > Really funny thread is going on in Postfix-Users list. Scroll down about
> half of content here:
> >
> > [comments.gmane.org]
> >
> > Just good example how NOT to do.
>
> I fwd'd details to lester haines of vulture central fame but doubt he will
> see it a a story.
>
> This outsourced orange sysadmin really needs the striesand effect to hit
> him
> and orange - hard!
>
> Has anyone contacted any of the email addresses in the logs pointing out
> the
> disclosure. I suspect kia as a company may not be too happy that a SAP
> reports
> email address has been disclosed. Far easier to soclially engineer
> something
> when you have even this minor sort of info.
>
> Jacqui
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: [lists.grok.org.uk]
> Hosted and sponsored by Secunia - [secunia.com]
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: [lists.grok.org.uk]
Hosted and sponsored by Secunia - [secunia.com]
Well that guys an idiot.. Orange has data network coverage, spanning 220
countries and territories, 967 cities 1,468 PoPs worldwide.. nice way to
draw attention to themselves..
Best comment "you should consider a job outside of the IT"

/pd
On Tue, Jul 3, 2012 at 11:28 AM, Gage Bystrom <themadichib0d@gmail.com>wrote:

> Not to mention as others pointed out it is implied that the guy might've
> let out information he didn't have permission to let out, which could get
> him into some serious trouble. Also I could be wrong since I don't remember
> the full thing but did the guy said they were doing a pentest soon? No need
> to report the guy when any remotely competent pentest team is gunna find
> this and probably start laughing smiling smiley
> On Jul 3, 2012 8:18 AM, "Jacqui Caren" <jacqui.caren@ntlworld.com> wrote:
>
>> On 29/06/2012 06:47, Tonu Samuel wrote:
>> > Really funny thread is going on in Postfix-Users list. Scroll down
>> about half of content here:
>> >
>> > [comments.gmane.org]
>> >
>> > Just good example how NOT to do.
>>
>> I fwd'd details to lester haines of vulture central fame but doubt he will
>> see it a a story.
>>
>> This outsourced orange sysadmin really needs the striesand effect to hit
>> him
>> and orange - hard!
>>
>> Has anyone contacted any of the email addresses in the logs pointing out
>> the
>> disclosure. I suspect kia as a company may not be too happy that a SAP
>> reports
>> email address has been disclosed. Far easier to soclially engineer
>> something
>> when you have even this minor sort of info.
>>
>> Jacqui
>>
>> _______________________________________________
>> Full-Disclosure - We believe in it.
>> Charter: [lists.grok.org.uk]
>> Hosted and sponsored by Secunia - [secunia.com]
>>
>
> _______________________________________________
> Full-Disclosure - We believe in it.
> Charter: [lists.grok.org.uk]
> Hosted and sponsored by Secunia - [secunia.com]
>
_______________________________________________
Full-Disclosure - We believe in it.
Charter: [lists.grok.org.uk]
Hosted and sponsored by Secunia - [secunia.com]
On 03/07/2012 17:16, Jacqui Caren wrote :
> This outsourced orange sysadmin really needs the striesand effect to hit him
> and orange - hard!
>
That's what I told him in another thread:

[permalink.gmane.org]

Now he gets what he deserves.

_______________________________________________
Full-Disclosure - We believe in it.
Charter: [lists.grok.org.uk]
Hosted and sponsored by Secunia - [secunia.com]
Sorry, you do not have permission to post/reply in this forum.