Hacker Leaks Unreleased CERT Reports
Call Me Black Cloud writes "A hacker calling himself "Hack4Life" swiped 3 unpublished vulnerability reports from a company working with CERT and posted them to the Full Disclosure mailing list. A couple of days later, he did it again (while promising weekly leaks). Wired also has a story, including a link to one of the postings."
Its a little too ironic if he's using the leaks in the reports he steals....
wonder if there will be an advisory over this
It shouldn't be that hard to catch him if they know what information is being leaked and when.
With the way ISS handles things I bet they're after this guy.
Otherwise... $5.00 says he works for ISS... any takers?
scott
I drink too much coffee. I leak several times per day.
How to Download YouTube Videos
hmmmmmm?
I don't think any regular readers of slashdot fit that discription.
Yeah, I'm going to be a leaker too, in the bathroom a minute or two after I hit submit. I don't think that Slashdot readers would be too interested in the details though.
"I think that when you become a Republican, you don't get to score any more." -- Butt-head
It's the sound of every sysadmin on Earth switching to BSD!
"In a 32-bit world, you're a 2-bit user. You've got your own newsgroup, alt.total.loser." -Weird Al
Store the Windows vulnerabilities on a Windows server, Linux vulnerabilities on a Linux server, etc.
That might take the edge off some companies' complaints about vulnerabilities leaking out before the clock is up.
No, they prefer continous flame wars. ;)
"There is a way that seems right to a man, but its end is the way of death." Proverbs 16:25 (NKJV)
"I'm going to release these at 7pm on Friday, so that sysadmins don't know about this and can't do anything about this til Monday morning" (paraphrased).
What I'd like to know, is what real sys admin is NOT glued to multiple consoles at 7pm on a Friday?
That's about the start of the week when real work can get done!
War crimes, torture, lies, illegal spying... Would someone give Bush a blowjob, already, so he can be impeached?
he'll be called 'Packed4Life'.
Worst. Hacker name. Ever.
</voice>
SIGFEH
Ya know, I thought it was just me, but every dos attack/hack attempt I have seen against my servers has been on friday night or on weekends. Assholes. I work my ass off all week, and I want to relax on the weekend.
Hum, look at the references section
6. http://www.kb.cert.org/vuls/id/192995
7. file://localhost/XDR.html#vendors
8. http://www.kb.cert.org/vuls/id/516825
localhost!? They're obviously already using the vulnerability to put files on my computer.
.oO Kaa Oo.
I am under the impression that these 'masses' are the same ones who give moderation points :P
"'Yrch!' said Legolas, falling into his own tongue."