BugTraq
0day: PDF pwns Windows Sep 20 2007 01:21PM
pdp (architect) (pdp gnucitizen googlemail com) (3 replies)
Re: [Full-disclosure] 0day: PDF pwns Windows Sep 21 2007 07:53PM
Thierry Zoller (Thierry Zoller lu) (2 replies)
Re: [Full-disclosure] 0day: PDF pwns Windows Sep 21 2007 09:21PM
Aaron Collins (collinsa ehawaii gov)
Re: [Full-disclosure] 0day: PDF pwns Windows Sep 21 2007 09:21PM
Kevin Finisterre (lists) (kf_lists digitalmunition com)
Re: 0day: PDF pwns Windows Sep 20 2007 04:55PM
Aditya K Sood (zeroknock secniche org)
Re: 0day: PDF pwns Windows Sep 20 2007 03:29PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: 0day: PDF pwns Windows Sep 20 2007 11:16PM
Crispin Cowan (crispin novell com) (2 replies)
Re: 0day: PDF pwns Windows Sep 23 2007 05:34AM
Crispin Cowan (crispin novell com) (2 replies)
Re: 0day: PDF pwns Windows Sep 25 2007 04:15PM
Iggy E (iggy_e yahoo com)
Re: 0day: PDF pwns Windows Sep 23 2007 11:52PM
Chad Perrin (perrin apotheon com) (2 replies)
Re: 0day: PDF pwns Windows Sep 24 2007 10:57PM
Lamont Granquist (lamont scriptkiddie org) (1 replies)
Re: 0day: PDF pwns Windows Sep 25 2007 05:57PM
Roland Kuhn (rkuhn e18 physik tu-muenchen de) (1 replies)
RE: 0day: PDF pwns Windows Sep 25 2007 06:39PM
Thor (Hammer of God) (thor hammerofgod com) (2 replies)
Re: 0day: PDF pwns Windows Sep 25 2007 09:03PM
Steve Shockley (steve shockley shockley net)
defining 0day Sep 25 2007 07:02PM
Gadi Evron (ge linuxbox org) (3 replies)
RE: defining 0day Sep 25 2007 09:20PM
David Gillett (gillettdavid fhda edu)
Re: defining 0day Sep 25 2007 08:40PM
Charles Miller (cmiller pastiche org) (2 replies)
Re: defining 0day Sep 26 2007 11:25PM
Zow Terry Brugger (zow llnl gov) (1 replies)
Re: defining 0day Sep 26 2007 11:10PM
Chad Perrin (perrin apotheon com) (1 replies)
RE: defining 0day Sep 28 2007 12:20AM
Marvin Simkin (Marvin Simkin asu edu) (1 replies)
Re: defining 0day Sep 27 2007 06:34PM
Chad Perrin (perrin apotheon com)
Re: defining 0day Sep 25 2007 08:57PM
Gadi Evron (ge linuxbox org)
Re: defining 0day Sep 25 2007 07:51PM
Brian Loe (knobdy gmail com) (1 replies)
Re: defining 0day Sep 25 2007 07:59PM
Gadi Evron (ge linuxbox org) (1 replies)
Re: defining 0day Sep 25 2007 08:15PM
Brian Loe (knobdy gmail com) (1 replies)
Re: defining 0day Sep 25 2007 08:37PM
Adrian Griffis (adriang63 gmail com) (2 replies)
Re: defining 0day Sep 25 2007 09:05PM
Andrew Weaver (aweaver ee net)
Re: defining 0day Sep 25 2007 08:54PM
Brian Loe (knobdy gmail com)
Re: 0day: PDF pwns Windows Sep 24 2007 09:59PM
Crispin Cowan (crispin novell com) (1 replies)
Re: [Full-disclosure] 0day: PDF pwns Windows Sep 25 2007 01:39PM
J. Oquendo (sil infiltrated net)
Crispin Cowan wrote:

>
> This is a perfectly viable way to produce what amounts to Internet
> munitions. The recent incident of Estonia Under *Russian Cyber Attack*?
> <http://www.internetnews.com/security/article.php/3678606> is an example
> of such a network brush war in which possession of such an arsenal would
> be very useful.
>
> Crispin

One would presume that governments across the world would have their
shares of unpublished exploits but with all the incidences of government
networks being compromised, I don't believe this to be the case. What
happened in Estonia though was nothing more than a botnet attack on
their infrastructure
(http://www.informationweek.com/showArticle.jhtml?articleID=199602023)
not an 0day attack.

0day's defined as "unpublished exploit" wouldn't do much in a
cyberwarfare theater as country against country as the purpose of such
warfare would LIKELY be to disconnect/disrupt communications. In the
cases of industrial/country vs. country espionage it might (likely) will
be more effective for the long haul but in the short term, 0days will
be useless in this type of "cyberfight". Think about it logically, you
want to "disrupt" country X's communications, not tap them. You'd want
to make sure their physical army had no mechanism to communicate. You'd
want to make sure financially you would cripple them. Not worry about
injecting some crapware onto a machine for the sake of seeing what their
doing.

Reconnaissance is usually something done beforehand to mitigate your
strategy. Not mitigate what's happening after you possibly sent 1Gb of
traffic down a 100Mb pipe.

--
====================================================
J. Oquendo
"Excusatio non petita, accusatio manifesta"

http://pgp.mit.edu:11371/pks/lookup?op=get&search=0xF684C42E
sil . infiltrated @ net http://www.infiltrated.net

0? *?H?÷
 ?0?1 0 +0? *?H?÷
 ?0??0?r 'ôêôz?Än»n©0
 *?H?÷
0o1 0 USE10U
 AddTrust AB1&0$U AddTrust External TTP Network1"0 UAddTrust External CA Root0
050607080910Z
200530104838Z0®1 0 UUS1 0 UUT10USalt Lake City10U
The USERTRUST Network1!0U http://www.usertrust.com1604U-UTN-USERFirst-Clien
t Authentication and Email0?"0
 *?H?÷
?0?
?²9?¤ò}«A;bF7®ÍÁ`u¼9eùJG¢¹ÌHÌj?ÕM5¹¤BåÎIâ?/|Ò1ÇN´?d.)Õ¢dÄ?½?Q5y¤
Nh{z¤?¨ò?ò?Ìɤ2?» O0½?  ?ån¢Fúx¼¢o«Y^¥/ÏÊÚmª/묡³jª·.g5?yái?âæFÍ ¥ê¾ Îv:z?êüÚ'[=s"æHaÆ
Lói±¨.¶Ô1 ,¼???¤¥×?CüZ¯q×YÚº?
¯úóáÂð¤Åg?ÖÖT:Þ
¤ºw³eÈýÓtbªÊh?¡?~õGeËøMW(tÒ4ÿ0¶îöb0?,룁á0Þ0U#0?­½?z4´
&÷úÄ&Tï½à$ËT0U??g}ĝ&pK´PH|Þ=®n}0Uÿ0Uÿ
0ÿ0{Ut0r08 6 4?2http://crl.comodoca.com/AddTrustExternalCARoot.c
rl06 4 2?0http://crl.comodo.net/AddTrustExternalCARoot.crl0
 *?H?÷
?Ø?o(¬¦¢ç?Á?Û~¡ýóâð©?TBk? Ä mא?fyCqüøo¯ÛvEâ7=ÝäYx¬ô?FózÏ[?r-åFÁº)óËIy?<ºm¤mhO­r6¨¹±ý¿Ï
ð¤j?5PÏmU±ÝY0Jßm ?dI|ï6»ôãiôø9Z­K?:·íÓÏ
D¢û¿ä/p?%ûZT³Ðļmûs2,é??$-Ö?zhP?MéÌõ»gèÜ.;üNÍþ?ã¨
¥&DeéòMR§®Ü>Êk2\Alþõ] êÿÑú??Xm=?Gåþ.?ÂÌ?¡ò»0?Á0?© 
Ñ¡øsß?-?HK?«'0
 *?H?÷
0®1 0 UUS1 0 UUT10USalt Lake City10U
The USERTRUST Network1!0U http://www.usertrust.com1604U-UTN-USERFirst-Clien
t Authentication and Email0
061005000000Z
071005235959Z0Ù1503U ,Comodo Trust Network - PERSONA NOT VALIDATED1F0DU =Terms and Conditions of use: http://www.comodo.net/repository10U (c)2003 Comodo Limited10U
J. Oquendo1"0  *?H?÷
 sil (at) infiltrated (dot) net0 [email concealed]?0
 *?H?÷
0?½Ç?(ä$:²µDT,¢Ò;º»lpjÅ©rºSê:Ò#&Çây*?îE¥Ð)»ÜMHü~¨a¥Õ~
¹ÃX gÈÇgIçV¶§:'7ÕI´óÛ¥ªAcU|2Å^?ç¾ï¼bèïæ æ¾ÊÂ%Nï?eäùm?1×3¡+< DKu£?00?,0U#0???g}ĝ&pK´PH|Þ=®n}0
Un@.zÙ¶p_"µ?xx?rѬ$0Uÿ 0 Uÿ00 U%0+ +²10 `?H?øB 0FU ?0=0; +²10+0)+https://secure.comodo.net/CPS0¥U0?0
L J H?Fhttp://crl.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmai
l.crl0J H F?Dhttp://crl.comodo.net/UTN-USERFirst-ClientAuthenticationand
Email.crl0?+z0x0;+0?/http://crt.comodoca.com/UTNAddTr
ustClientCA.crt09+0?-http://crt.comodo.net/UTNAddTrustClientCA.c
rt0U0sil (at) infiltrated (dot) net0 [email concealed]
 *?H?÷
?>|(aµ]ºGìC¡yÂó(ãü?tïë¤F<¡&S?»ê6î¢w¥ë}úæâp¾lê#è«ú]¢t^¦Ð(l??
uv?ç7¿ÒþÄÉë?#? ?PGsbT??ïÓî]>¤.¤I{?rE5K³ã?³øø?tWÏËÛXÜÊCo´ù²Öò
à´²qÃõD??þã rw¨g?+k+(`9qò!ÝÒÿ×g?Ü?¬?·¾MUõ·hóB±ò¸Äîz {?¼?|¨?6àS?&?çüJ÷??õJ?Éæ?[ýõT*?ÒéÒ'oEjÓÖ #B\Ã8ô
ö£?Ù?¯ñ¦7¶0?Á0?© 
Ñ¡øsß?-?HK?«'0
 *?H?÷
0®1 0 UUS1 0 UUT10USalt Lake City10U
The USERTRUST Network1!0U http://www.usertrust.com1604U-UTN-USERFirst-Clien
t Authentication and Email0
061005000000Z
071005235959Z0Ù1503U ,Comodo Trust Network - PERSONA NOT VALIDATED1F0DU =Terms and Conditions of use: http://www.comodo.net/repository10U (c)2003 Comodo Limited10U
J. Oquendo1"0  *?H?÷
 sil (at) infiltrated (dot) net0 [email concealed]?0
 *?H?÷
0?½Ç?(ä$:²µDT,¢Ò;º»lpjÅ©rºSê:Ò#&Çây*?îE¥Ð)»ÜMHü~¨a¥Õ~
¹ÃX gÈÇgIçV¶§:'7ÕI´óÛ¥ªAcU|2Å^?ç¾ï¼bèïæ æ¾ÊÂ%Nï?eäùm?1×3¡+< DKu£?00?,0U#0???g}ĝ&pK´PH|Þ=®n}0
Un@.zÙ¶p_"µ?xx?rѬ$0Uÿ 0 Uÿ00 U%0+ +²10 `?H?øB 0FU ?0=0; +²10+0)+https://secure.comodo.net/CPS0¥U0?0
L J H?Fhttp://crl.comodoca.com/UTN-USERFirst-ClientAuthenticationandEmai
l.crl0J H F?Dhttp://crl.comodo.net/UTN-USERFirst-ClientAuthenticationand
Email.crl0?+z0x0;+0?/http://crt.comodoca.com/UTNAddTr
ustClientCA.crt09+0?-http://crt.comodo.net/UTNAddTrustClientCA.c
rt0U0sil (at) infiltrated (dot) net0 [email concealed]
 *?H?÷
?>|(aµ]ºGìC¡yÂó(ãü?tïë¤F<¡&S?»ê6î¢w¥ë}úæâp¾lê#è«ú]¢t^¦Ð(l??
uv?ç7¿ÒþÄÉë?#? ?PGsbT??ïÓî]>¤.¤I{?rE5K³ã?³øø?tWÏËÛXÜÊCo´ù²Öò
à´²qÃõD??þã rw¨g?+k+(`9qò!ÝÒÿ×g?Ü?¬?·¾MUõ·hóB±ò¸Äîz {?¼?|¨?6àS?&?çüJ÷??õJ?Éæ?[ýõT*?ÒéÒ'oEjÓÖ #B\Ã8ô
ö£?Ù?¯ñ¦7¶1?Ï0?Ë0Ã0®1 0 UUS1 0 UUT10USalt Lake City10U
The USERTRUST Network1!0U http://www.usertrust.com1604U-UTN-USERFirst-Clien
t Authentication and Email
Ñ¡øsß?-?HK?«'0 + ?a0 *?H?÷
 1  *?H?÷
0 *?H?÷
 1
070925133929Z0# *?H?÷
 1¹?¡OóÂnìW¾âµÆ_(`ýî0R *?H?÷
 1E0C0
*?H?÷
0*?H?÷
?0
*?H?÷
@0+0
*?H?÷
(0Ô +?71Æ0Ã0®1 0 UUS1 0 UUT10USalt Lake City10U
The USERTRUST Network1!0U http://www.usertrust.com1604U-UTN-USERFirst-Clien
t Authentication and Email
Ñ¡øsß?-?HK?«'0Ö *?H?÷
  1Æ Ã0®1 0 UUS1 0 UUT10USalt Lake City10U
The USERTRUST Network1!0U http://www.usertrust.com1604U-UTN-USERFirst-Clien
t Authentication and Email
Ñ¡øsß?-?HK?«'0
 *?H?÷
?c?ò5³ÞkUrß#AnîãïÀ°[??8øÏ§ù"Nê?ÛÆ|Te
õî@u5ëY·Mw´ÈÕÿw@brdQÇkHËÑü?EÓ/fñ~¸P )ß8½0ÐNØ?ã?±?´g$å?ÞâwsG'ó#ûB®Ý?Ä?3?¶¤l

[ reply ]
Re: 0day: PDF pwns Windows Sep 21 2007 06:34PM
Casper Dik Sun COM (1 replies)
Re: 0day: PDF pwns Windows Sep 21 2007 07:24PM
J. Oquendo (sil infiltrated net)


 

Privacy Statement
Copyright 2010, SecurityFocus