Full Disclosure mailing list archives

Re: Third party patches, a matter of trust by n3td3v


From: n3td3v <n3td3v () gmail com>
Date: Wed, 29 Mar 2006 22:49:23 +0100

Ok, you're from europe because your address is "googlemail" and not "gmail",
secondly your leetspeak script has given you a bad translation. If you were
a real hacker, you would be able to write leetspeak code manually, and why
the rap lyrics? I mean this just goes to show your level of intellect, in
the way you failed to reply in a mature manner on the serious issue of third
party patches (from eEye) causing a new generation of security problems for
Microsoft and their consumers.

On 3/29/06, teh kids <tehkids () googlemail com> wrote:

EMIneM lYRIC2

"5aY WH@ jOo 5Ay"
(fE@. DR. dRE & tim8ERLAnd)

[dr. dre]
HUh, 5O i'm Out teH gaMe huH?

[EMiNEm]
JO DrE, We RidIN?

[DR. dre]
WHATevER

[emiNeM]
WElL i'm WiTcHU HOMiE

[dR. DrE]
OK, Let'2 hanDLE thI2 5MALl 5hIt

[emiNem]
I wa2 8oRn To 8REw up 5toRm2 'n 5tir Up 5hiT
kick up du5T, Ku55 TIL I 5LuR uP 5pit
grEW UP Too KwICK, wO'Nt tHrouGh Too mucH, tHroUgH TOO MucH 5HiT
KORrupT aNd I'M pouR IT on liKE 5YRUP, 8I2oTch
ThICk In gRit2, 5ICK aND Twi5TeD Mr. 8UTTER5WoRTh
dRE ToLE mEh to miLk THI2 5Hit PHOr wh@ IT'2 wORTH
tILL teh KoW ju5T TiLT2 AND tiP2 'n 5tum8Le2 TO EarTH
aND IF i phUM8lE Teh ver2e, KEeP goiN'
phiR5t TAKE, I MAKE mi5TAkE2, JU5T keep IT
no PuncHE2, PULl no pUNcHe2, Th@'2 wEaK 5hIT
pHake 5hiT iF i EvER takE 5HIt, i eat 5hIt
Wa2'nT pHOr HIm? I wOulD'Nt 8e 5hIt

[Dr. DrE]
CREEp WIT MEH, A2 We Take a lIttLe trip DoWN memOrY laNE
8eeN HERE lONGeR THAN aNyONE in teH gamE
aNd I Ai'nt GoT tO lIe A8OUT mY aGE

[eMInem]
8UT wH@ A8OUt JeRmaINe?

[dR. dre]
pHuXor jERmaINE, he do'NT 8ElONg 5PeeKIn mIne OR tIm8alanD'2 NamE
ANd dO'nT tHiNk i DO'NT Read JoOR LITtle inTERViEW2 and 5eE wH@ jooR 5Ayin
I'Ma GIANt, and i ai'nT gotTa mOVe tIlL I'M PROvOkED
wHen I 5ee JOO, I'Ma 5TeP ON jOo AnD NOt eveN KnOw it
Ya MIDGet, mini-mE, WIT a 8uncHa LIttle minI-yOU'2
RunniN aROuND JoOr 8Ackyard 5wImmiN' pOoL2
oVer 80 MIlliON RECoRD2 5Old
anD i ai'Nt Had tO dO it wIT 10 OR 11 YEar old2

[choru5:]
ku2 wh@ joO 5ay i2 Wh@ jOO 5aY
5aY wH@ JOO 5AY how jOO 5ay it WHENEvER joO 5ayIN IT
jU5t RemEM8er HoW JOO 5Aid it whEn Joo wA2 5praYIN It
5O wHO jOo PLayiN wIt HUh HuH hUh huh?

ku2 WH@ Joo 5ay i2 wh@ JOO 5ay
5aY Wh@ joo 5AY HOW Joo 5Ay iT WhenEVer joO 5AyiN it
JU5t rEMEm8er hOw joo 5AID it WHen Joo wa2 5PRAYIn it
5O WHo joo pLAyIN wIt huh HuH hUh hUh?

[emiNEm]
5ecOnD vEr2E, iT gET2 WoR5T
IT GEt2 No 8ETtEr than thi2
AmaTuER2 dRInK vEteRan pI55
FroM A dIxIe kUP, if jOO eVER mix MEH UP
or kOnFu2E MeH Wit A kani8u2 Or dRE WIT a DupRI
will rU8 IT In, EvERY CLu8 jOOr In, wE'LL haVe Joo
8Lack8aLled aNd maKE 5URe JOO nEVer rAP a PHUXoreN aGaIn
drE AI'NT HaVIN iT a2 lonG a2 im here, PlAy deviL'2 AdvOcaTe

[dR. dRe]
iF ThErE WA2 5oMe mAGIc 5HIt I kOulD Wave
OveR Teh indu5rty TH@ koULd 5ave iT WHEn I'm gONE
and 8uRy tO Make 5UrE teh TrAdiTioN kARRIE2 ON
i WOuLD

[emiNEm]
iF I koUld onLy u2e Thi2 POwEr pHOr GOOD
I wOUlD'NT, Not eVEN IF i Kould

[dr. dRE]
fROM TEh hood and I'M A HoRnET
aNd I'Ma OnLy 5tiN' WHen I'm KoRnEReD

[eMiNEm]
AnD I'ma Only 5uxoREr pUncH Or 5Win' wiTHOUT warNin
ANd 5WIN' TO knOCk 5Ome8oDy'2 PHUXOrin Head oFf
ku2 i knOW, wHEN tHey Get UP, i Wo'nt geT A ChANcE TO leT oFf
aNOtHeR PUNCH, i'M PUNK-rOck, no oNe'2 puNk
do'nt gIVe a pHUxOR, WHiTE pac, 5o mUCh 5pUNK
wHEN i Wa2 lITTLe I KNew I WouLD 8loW uP
aND 5ELL A mIl or gROw up tO 8E A tILLeR
Go nuT2 aND 8E a kiLlER

[dR. dRe]
AnD I'M 5oMEtHiN oF a PHenom
oNE puFF OF TEH chRON
I'M UN5Toppa8Le, i'M AliVE, I'm On top aGaIn
ThEre'2 No o85TAclE Th@ i Ka'Nt kONKwEr
5o KOmE AlOng wit U2 (COMe On)

[chOru5:]
kU2 Wh@ JoO 5ay i2 wH@ jOo 5Ay
5ay wh@ joO 5aY HOw joo 5ay it WhENEver joo 5AYin it
ju5T rEmem8ER hoW Joo 5aId iT wheN jOo wa2 5PRaYiN IT
5O who joO pLaYIn wIt HuH HUh HUh hUH?

Ku2 wH@ JoO 5Ay I2 Wh@ jOo 5aY
5Ay wH@ JOo 5ay hoW jOo 5aY iT WHeNEver Joo 5aYiN It
JU5T rEmem8eR hoW JOO 5AId it wHeN jOo wa2 5PrayiN iT
5O Who joO PLaYiN wit hUh HuH hUH hUH?

[dr. DRE]
NOw any8ody WHo kNoW2 dre
knOw2 i'm a8ouT phA5T KAR2 AND ali2E, parTyIn alL daY
8ut I hanDlE MY 8u5Inee2 ku2 it'2 woRk 8eFOrE PLAY
dO'nT LoOK phoR TRou8Le 8UT i 5eRve Joo gourmEt
HOWEveR JoO want IT, Joo kouLD HaVe It JOoR WaY
jOO PhuXOR mY niGHt uP, i'mA PhuxOr Up joOR DAy
8Ullet wIT JOor namE, 5endin it joOR WaY
TH@ Goe2 pHOR ANYoNe who WALx thRu Th@ DooRWaY
ku2 thI2 I2 my 5PaCE, JoO iNvaDE it
liVe to RegRet IT And JoO dIe trYIN TO vIoLATe IT
PhUXOr aroUnD aNd JoO'll GeT anAHilatEd
EyE2 DILIated

[EMINEM]
ha, LIkE my OlD lADY
kU2 WH@ joo 5ay i2 WH@ JOO 5aY
5OMETimE2 wh@ jOo Mean I2 2 diFferenT THiNg2
DEPENdin' on jOOR mOod, iF iT 5wiNG2, THinK tOo mAnY ThIng2
LITTLe hiT Of Dre'2 WEEd, I Kan dO aNyTHin'
kAtCh A KONtacT, THen I'M gONe aND I'm 8AcK
i 5Peed WriTE aNd my LOO2E LEAVE2 MY lANcH PAD

[DR. dRE]
and i KAN PUll aNY 5trIn'
do'nt HAVE To prOvE AnytHIN'
kAtCh a kOntRAct on jOor HEaD
JOO heADEd wE5t, taLk 5hit A8OUt DRe?
JOo 8ETTEr GEt a Ve5t, tHEN inVe5t In 5oMEthIn'
to PRotECT JOOr HeAD aNd neCK

[EmInem]
and IT'2 8ack anD PHORtH all DAY LIke REd AND mETH
i JoKe wHeN i 5ay i'M tEh 8e5t iN tEH 8ooTH
8ut A lot oF TRutH i2 5AiD INjE5T
aND if I eVer dO LiVe tO 8E a LegEND
I'ma diE A 5UDDen DeaTh, 5 mIC2 In TEh 5ourCe
Ai'NT HoLDiN' MY PHuxoRin 8reAtH
8UT I 5UfFocaTE PhOr Teh rE5peCT
pHORE i 8ReaTh Teh KollecT TeH PhUxOrIn check

[ChOrU5:]
Ku2 wH@ jOO 5aY I2 wH@ joO 5aY
5AY WH@ JOO 5ay how JOO 5ay it whEnEVEr jOO 5aYIN it
Ju5T ReMEM8er How joO 5Aid iT WHeN JoO Wa2 5PRAYIn IT
5O WHO jOO PlAyin WIt hUh Huh HUH HUh?

KU2 wH@ JoO 5aY I2 WH@ Joo 5ay
5AY wH@ JOo 5aY hOW Joo 5ay IT WheneveR joO 5aYIN It
Ju5t reMem8Er How joO 5AID it wHen JOO wa2 5praYIN IT
5o WHo JOO plAyIN wIT HUH HUH huh hUh?

[Dr. DrE]
WAtCH JOor PhUxorin' moUtH

[Tim8ALaND]
jO tHi2 tiM8aLaND, teLL HiM I 5aiD 5uXOr [tChkA] my DiCk

ON 3/29/06 N3TD3V <N3TD3V@GMALECOM>!!!1 OMG WTF WROT3

THIRD PARTY PATCHES A MATER OF TRUST BY N3TD3V

Y R THIRD PARTY PATCH3S A BAD THNG
??!!?? OMG LOL
THEY FORCA MICROSOFT 2 RUSH OUT A PATCH BFORE
QA1!1111 WTF T3STNG HAS BEN FULY COMPLETED IN TEH TIEM SCAEL
MICROSOFT WUD HAEV INITIALY HOPED
111! OMG

IS IT RESPONSIBLE FOR EYE 2 RALEAES A THIRD PARTY PATCH BFORA MICROSOFT
?!?!!
NO ITS VERY BAD B/C IT CONFUSAS DA CONSUMAR AND BRNGS UP DA ISUA OF
TRUST
IN TEH MIND OF DA CONSUMER!11!!! OMG WTF LOL ONCE U START DANGLNG
MULTIPL3 VULNARABILITY
FIEXS INFRONT OF
CONSUMAR IT OPENS TEH DOR FOR MALICIOUS HAKERS SCRIPT KIDS AND PHISHERS
2 COMPROMIES
SACURITY
!!11!! WTF LOL
WUT DO U M3AN IRESPONSIBLE
?!!??!? OMG WTF LOL
YAS B/C DA DELIEVRY OF A THIRD PARTY PATCH CANOT REACH A WORLD WIED
AUDEINC3 IF TEH
NAWS OF THIRD PARTY PATCH AVAAEBILITY IS ONLY ON TAHT OF U-S BAESD NEWS
MEDIA OUTLATS
!1!!1!1! OMG WTF
MICROSOFT SINCE SERVIEC PAK TWO HAEV AU2MATIC UPDAET FUNCTIONALITY ON
ITS
SOFTWAER ALOWNG
A PATCH 2 B DALIEVR3D ESANTIALY 2 AL OF ITS CUS2M3RS WORLD WIED EY3
JUST DONT HAEV TAHT KIND OF R3ACH AVALEABLE 2 THAM!1111!11

HOW CUD A THIRD PARTY PATCH B US3D AGANEST PAOPLA
??!?? OMG WTF LOL
SCRIPT KIDS COMPROMIES SYSTEMS AND TH3N PATCH THAM WIT TEH THIRD PARTY
PATCH
!!!1!1
IF TEH TR3ND OF THIRD PARTY PATCHES CONTINUE MALICIOUS USERS CAN PLAY
UP2
TEH MULTIPLA PATCH SOURCAS AVALEABL3 AND S3TUP FRAUD SCMS 2 COMPROMIES A
US3R SYST3M WIT BOGUS PATCHES WHICH HAEV INSERT3D MALICIOUS CODE!!!!111!
WTF LOL A LOT OF
TEH TIEM DA MALICIOUS COD3 WIL HAEV ADITIONAL VULN3RABILITEIS ATACH3D
1111! OMG LOL DA THIRD PARTY PATCH MERALY ACTS AS A D3LIEVR SYST3M 2
SOCIALY ANGIENER
TEH MIND OF DA CONSUMAR1!!11!! OMG ONC3 DA CONSUMER GETS TEH IEDA OF
PATCHES BNG
AVALEABL3 FROM MULTIPLE SOURC3S TH3N TAHTS WHERE TEH PROBLAMS WIL SPIRAL

OUT OF CONTROL AND TAHT ALEM3NT OF TRUST RILLY COMES IN2 PLAY111!11! OMG
WTF

SHUD MICROSOFT TAEK LAGAL ACTION AGANEST THIRD PARTY PATCH DEVELOPERS
LIEK
EYA
???!??!!
YAS I THINK SO!!11!1 OMG LOL DA IEDA OF THRID PARTY PATCHES BNG R3L3AESD
BY BIG
COMPANEIS LIEK EY3 IS VERY IR3SPONSIBL3 AND OFARS A GRAEV DANGER 2 THE
PUBLIC AT LARGA BY MAKNG TEH PATCH AVALEABL3 2 TEH WORLDS MALICIOUS
USARS WHERE THEN TEH MAGNITUDE OF TEH SITUATION IS BLOWN UP AND MAEKS
TH3
SITUATION MORA INTENSE B/C FIEXS R BNG MAED AVALEABL3 FOR 0-DAY
BFORA MICROSOFT HAS HAD DA CHANCE 2 FULY DEV3LOP A S3CURE RAALIBL3 PATCH
AND DELIEVR IT 2 WORLD WIED CUS2MARS!!1!! WTF LOL

SHUD MICORSOFT R3L3AES A PATCH FOR CRITICAL PUBLIC 0-DAY BFOR3 PATCH
TUASDAY
???!!? OMG WTF
YES AND NO!!1!11 WTF LOL NO IF IT WASNT FOR EYA COMPROMISNG SECURITY BY
FORCNG
MICROSOFT 2 PUSH OUT A PATCH BFORE
TEH REQUIERD TIEM FRME THAN THEIR WUD B NO NED 2 RALEAES A PATCH
EARLY!!!1! OMG LOL YES B/C SINCE TEH WMF FLAW THIRD PARTY DAVALOPERS R
REL3ASNG
PATCHES AND MICROSOFT MUST GET ON2P OF TEH TREND BFORE CONSUMERS START 2

TRUST THIRD PARTY SOURCAS IN PLAEC OF TEH LEGITIMAET MICRSOFT
PATCH11!!!1 OMG WTF LOL

WUT CAN CONSUM3RS DO 2 PROT3CT TH3MS3LVES FROM THIRD PARTY PATCHES
?!???! LOL
NEVER DOWNLOAD A THIRD PARTY PATCH 3V3N IF ITS FROM A TRUSTED SOURCE
1!!! WTF REAL PATCH3S WIL ONLY 3VER COM3 FROM MICROSOFT AND TEH AU2MATIC
UPDAET
FUNCTIONALEITY ON MICROSOFT PRODUCTS!!!! OMG WTF REMEMBR MICROSOFT CAN
OFAR U SUPORT IF THEYRE PATCH BCOM3S FAULTY!!!!! WTF IF U DOWNLOAD FROM A
THIRD PARTY
SOURC3 UR SYSTAM MAY BCOM3 CORUPT WIT ARORS OR IN TEH WORST CAES
SCANARIO U MAY B VICTIM 2 A MALICIOUS PATCH CLMNG 2 FIX A
VULNARABILITY!11! WTF

SHUD DA INDUSTRY G3T BHIND DA IEDA OF MAKNG THIRD PARTY PATCH3S AN
UNACEPTABLA ALTARNATIEV 2 A MICROSOFT PATCH
?!??!??!! WTF LOL Y3S111!1 OMG WTF DA FUTURE OF SECURITY WORLD WIED
DAPENDS ON TEH INDUSTRY NOT
R3COMANDNG THASE PATCH3S NO MATER HOW SAEF DA PATCH MAY APEAR OR IF
TEH SOURCE CAN B TRUSTED!1!!!!11 WTF TEH ONLY R3AL PATCH CAN B OFARED BY
MICROSOFT
AND DA ONLY PEOPL3 WHO RILLY DO KNOW HOW 2 FIX A VULN3RABILITY IS
MICROSOFT1!!!!! WTF LOL WIT DA WMF FLAW MANY FOLKS WARE SHOKED 2 SE SANS
3TC
R3COM3NDNG A THIRD PARTY PATCH1!!1111! LOL THIS TIEM AROUND IT SEMS 2 B
DIFAR3NT
1!!11111 OMG WTF LOL TEH BIG PLAEYRS R FINALY LISTENNG 2 FOLKS LIEK
N3TD3V AND TEH GRAEV
DANGARS ATACHED 2 MAKNG DA TREND OF THIRD PARTY PATCH3S FOR MICROSOFT
PRODUCTS A BAD PRATIEC WHCIH SHUDNT B ENCOURAEGD UNDAR ANY CIRCUMSTANCA
11!1 OMG LOL SUR3 ITS HAALTHY 2 DEVALOP UR OWN PATCH SOLUTIONS IN
PRIVAET FOR UR OWN R3SEARCH AND DAV3LOPM3NT BUT AS SON AS U OFER TAHT
PATCH 2 TH3
WILD THAN ITS SUR3LY GONG 2 B PIKAD UP BY MALICIOUS US3RS AND USED
AGANEST TEH CONSUM3R TAN TIEMS OVER BFOR3 L3GITIMAET USERS CAN SE OR
H3AR
OF UR THIRD PARTY PATCH1111! OMG WTF LOL



_______________________________________________
Full-Disclosure - We believe in it.
Charter:
http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/



_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/

Current thread: