In message <[EMAIL PROTECTED]>, Wes Peters wrote: } Lyndon Nerenberg wrote: } > } > >>>>> "Mark" == Mark Murray <[EMAIL PROTECTED]> writes: } > } > Mark> o A username may only be checked $number times per } > Mark> $timeperiod; after that, _all_ answers are silently } > Mark> converted to "no". } > } > Umm, massive DOS hole. } } Per username. If you publish your userlist, you're an idiot. The } daemon should also immediately go into "breakin evasion mode" for } all invalid usernames, answering the requests very slowly. You don't have to publish a userlist in order for some of that kind of information to leak out. Besides, by answering very slowly for invalid usernames you just gave the bad guys a way to deduce your user list anyway. -- Jon Hamilton [EMAIL PROTECTED] To Unsubscribe: send mail to [EMAIL PROTECTED] with "unsubscribe freebsd-current" in the body of the message
- Re: Crypto progress! (And a Biiiig TODO list) Daniel O'Connor
- Re: Crypto progress! (And a Biiiig TODO list) Mark Murray
- Re: Crypto progress! (And a Biiiig TODO list) Garrett Wollman
- Re: Crypto progress! (And a Biiiig TODO list) Lyndon Nerenberg
- Re: Crypto progress! (And a Biiiig TODO list... Garrett Wollman
- Re: Crypto progress! (And a Biiiig TODO ... Lyndon Nerenberg
- Re: Crypto progress! (And a Biiiig TODO ... Mark Murray
- Re: Crypto progress! (And a Biiiig TODO list) Mark Murray
- Re: Crypto progress! (And a Biiiig TODO list) Lyndon Nerenberg
- Re: Crypto progress! (And a Biiiig TODO list) Wes Peters
- Re: Crypto progress! (And a Biiiig TODO list... Jon Hamilton
- Re: Crypto progress! (And a Biiiig TODO ... Wes Peters
- Re: Crypto progress! (And a Biiiig TODO list) Robert Watson
- Re: Crypto progress! (And a Biiiig TODO list... Mark Murray
- Re: Crypto progress! (And a Biiiig TODO ... Garrett Wollman
- Re: Crypto progress! (And a Biiiig TODO ... Mark Murray
- Re: Crypto progress! (And a Biiiig TODO ... Alfred Perlstein
- Re: Crypto progress! (And a Biiiig TODO list) Mark Murray
- Re: Crypto progress! (And a Biiiig TODO list) Paul Richards
- Re: Crypto progress! (And a Biiiig TODO list) Kai Großjohann
- Re: Crypto progress! (And a Biiiig TODO list... Mark Murray