<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD><TITLE>RE: [Full-Disclosure] And you're proud of this Mike Evanchick?</TITLE>
<META http-equiv=Content-Type content="text/html; charset=iso-8859-1">
<META content="MSHTML 6.00.3790.1289" name=GENERATOR>
<STYLE></STYLE>
</HEAD>
<BODY bgColor=#ffffff>
<DIV><FONT face=Arial size=2>wasnt meant as attack. sorry about that. The
statment was totally wrong, by no means is any AVP going to save you from true
attackers.</FONT></DIV>
<DIV><FONT face=Arial size=2></FONT> </DIV>
<DIV><FONT face=Arial size=2>Mike</FONT></DIV>
<DIV><FONT face=Arial size=2><A
href="http://www.michaelevanchik.com">www.michaelevanchik.com</A><BR></FONT></DIV>
<DIV><FONT face=Arial size=2> </DIV></FONT>
<BLOCKQUOTE dir=ltr
style="PADDING-RIGHT: 0px; PADDING-LEFT: 5px; MARGIN-LEFT: 5px; BORDER-LEFT: #000000 2px solid; MARGIN-RIGHT: 0px">
<DIV style="FONT: 10pt arial">----- Original Message ----- </DIV>
<DIV
style="BACKGROUND: #e4e4e4; FONT: 10pt arial; font-color: black"><B>From:</B>
<A title=xyberpix@xyberpix.com
href="mailto:xyberpix@xyberpix.com">xyberpix</A> </DIV>
<DIV style="FONT: 10pt arial"><B>To:</B> <A title=toddtowles@brookshires.com
href="mailto:toddtowles@brookshires.com">Todd Towles</A> </DIV>
<DIV style="FONT: 10pt arial"><B>Cc:</B> <A title=Mike@MichaelEvanchik.com
href="mailto:Mike@MichaelEvanchik.com">Michael Evanchik</A> ; <A
title=full-disclosure@lists.netsys.com
href="mailto:full-disclosure@lists.netsys.com">full-disclosure@lists.netsys.com</A>
</DIV>
<DIV style="FONT: 10pt arial"><B>Sent:</B> Thursday, December 30, 2004 12:55
PM</DIV>
<DIV style="FONT: 10pt arial"><B>Subject:</B> RE: [Full-Disclosure] And you're
proud of this Mike Evanchick?</DIV>
<DIV><BR></DIV><!-- Converted from text/plain format -->
<P><TT><FONT size=2>I have to aggree with Todd on this one, the attack was
extremely<BR>unprofessional, and things like this should be left out of
mailing<BR>lists. I could carry on, but am forcing myself not to
here.<BR><BR>xyberpix<BR><BR>On Thu, 2004-12-30 at 08:38 -0600, Todd Towles
wrote:<BR>> Umm..and you were the one giving cheers to Norton. Of course AV
can be<BR>> fooled..and of course a patch from microsoft is the only true
way to<BR>> fix the problem.<BR>> <BR>> She was attacking you
for giving Cheers to Norton. I didn't release<BR>> the POC, you did. I am
happy Norton is detecting it. If you want to<BR>> change your words right
in the middle of the sentence, I really don't<BR>>
care.<BR>> <BR>> By attacking me on a personal level, you have
proven to me..to be<BR>> unprofessional at
best.<BR>><BR>> <BR>>
______________________________________________________________<BR>>
From: Michael Evanchik [<A
href="mailto:Mike@MichaelEvanchik.com">mailto:Mike@MichaelEvanchik.com</A>]<BR>>
Sent: Wednesday, December 29, 2004 5:03
PM<BR>> To: Todd Towles;
Elle Chicka;
full-disclosure@lists.netsys.com<BR>>
Subject: Re: [Full-Disclosure] And you're proud of this
Mike<BR>>
Evanchick?<BR>> <BR>> <BR>>
Todd,<BR>> <BR>>
Listen, you are so wrong i cant belive you even have the
guts<BR>> to post
this. How stupid can you be? Norton or any AVP
can<BR>> easily be
fooled. The active x object "ca"+n b"+ +e
crea"<BR>> +ted" like this.
code changed around , or even different
local<BR>> code can be used
and tada AVP is fooled. Only a true
patch<BR>> from microsoft
or disable the help control in the registry
is<BR>> going to stop
this. Her concern is
wise. <BR>> <BR>>
Mike<BR>>
www.michaelevanchik.com<BR>> <BR>>
----- Original Message
-----<BR>>
From: Todd
Towles<BR>>
To: Elle Chicka ;
full-disclosure@lists.netsys.com<BR>>
Sent: Wednesday, December 29, 2004 9:36
AM<BR>>
Subject: RE: [Full-Disclosure] And you're proud
of<BR>>
this Mike
Evanchick?<BR>> <BR>> <BR>>
Well, if you have Norton, it couldn't
wreak<BR>>
havoc...now could it? Most of the AV compaines are
now<BR>>
detecting the exploit. This detection response is
much<BR>>
faster than most of the other exploits which
are<BR>>
wreaking havoc on your network, so it would
sound.<BR>> <BR>>
Nice work to
Norton.<BR>> <BR>> <BR>>
______________________________________________<BR>>
From:
full-disclosure-bounces@lists.netsys.com<BR>>
[<A
href="mailto:full-disclosure-bounces@lists.netsys.com">mailto:full-disclosure-bounces@lists.netsys.com</A>]
On Behalf Of Elle
Chicka<BR>>
Sent: Monday, December 27, 2004 11:16
PM<BR>>
To:
full-disclosure@lists.netsys.com<BR>>
Subject: [Full-Disclosure] And you're proud
of<BR>>
this Mike
Evanchick?<BR>> <BR>> <BR>>
You so proudly posted
this:<BR>>
------------------------<BR>>
<A
href="http://securityresponse.symantec.com/avcenter/venc/data/trojan.phel.a.html">http://securityresponse.symantec.com/avcenter/venc/data/trojanphel.a.html</A><BR>> <BR>>
mike<BR>> <BR>>
www.michaelevanchik.com<BR>> <BR>>
------------------------<BR>>
Obviously you are just tickled to see that
the<BR>>
kiddies were able to so quickly turn
your<BR>>
point/click sploit code into a virus to
wreak<BR>>
havoc on my
network.<BR>> <BR>>
Thanks a lot for helping to make all of us
a<BR>>
little less secure over the
holiday's.<BR>> <BR>> <BR>>
__________________________________________________<BR>>
Do You
Yahoo!?<BR>>
Tired of spam? Yahoo! Mail has the best
spam<BR>>
protection
around<BR>>
<A
href="http://mail.yahoo.com">http://mail.yahoo.com</A><BR>> <BR>>
_______________________________________________<BR>> Full-Disclosure - We
believe in it.<BR>> Charter: <A
href="http://lists.netsys.com/full-disclosure-charter.html">http://lists.netsys.com/full-disclosure-charter.html</A><BR>--<BR>For
Security and Open Source news and tips visit:<BR><BR><A
href="http://www.xyberpix.com">http://www.xyberpix.com</A><BR></FONT></TT></P></BLOCKQUOTE></BODY></HTML>