Re: Standing Up Against German Laws - Project HayNeedle

2007-11-14 Thread Raj Mathur
On Tuesday 13 November 2007 15:29, Florian Echtler wrote:
> [snip]
> As a native German speaker, allow me to clarify: with respect to IP
> communication, the law mandates saving the following information for
> 6 months:
>
> - which customer was assigned which IP for what timespan
> - sender mail address, receiver mail address and sender IP for each
> mail - in case of VOIP: caller and callee phone number and IP address

The mail addresses can only be stored if the server through which the 
mail is relayed (or on which it originates) falls under the law.  I'd 
presume that's not a significant percentage of all mails sent out from 
any country.

Of course, it's also possible to track (snoop) all SMTP traffic on the 
network, but that's totally different from just keeping mail and AAA 
server logs and from my understanding that's not what this law 
mandates.

Regards,

-- Raju
-- 
Raj Mathur[EMAIL PROTECTED]  http://kandalaya.org/
 Freedom in Technology & Software || February 2008 || http://freed.in/
   GPG: 78D4 FC67 367F 40E2 0DD5  0FEF C968 D0EF CC68 D17F
PsyTrance & Chill: http://schizoid.in/   ||   It is the mind that moves


Re: [Full-disclosure] Linux kernel source archive vulnerable

2006-09-07 Thread Raj Mathur
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

>>>>> "Hadmut" == Hadmut Danisch <[EMAIL PROTECTED]> writes:

Hadmut> [snip]

Hadmut> When unpacking such an archive, tar also sets the uid,
Hadmut> gid, and file permissions given in the tar
Hadmut> archive. Unfortunately, plenty of files and directories in
Hadmut> that archive are world writable. E.g. in the 2.6.17.11
Hadmut> archive, there are 1201 world writable directories and
Hadmut> 19554 world writable files.

I wouldn't know if something has changed drastically between 2.6.16
and 2.6.17.11, but:

[EMAIL PROTECTED]:~$ find /usr/src/linux-2.6.16/ -perm -666 ! -type l
[EMAIL PROTECTED]:~$

Not a single world-writable file or directory.  Perhaps pre-release
kernel tarballs are more lax?

Regards,

- -- Raju
- -- 
Raj Mathur[EMAIL PROTECTED]  http://kandalaya.org/
   GPG: 78D4 FC67 367F 40E2 0DD5  0FEF C968 D0EF CC68 D17F
  It is the mind that moves
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.4.5 (GNU/Linux)
Comment: Processed by Mailcrypt 3.5.8 <http://mailcrypt.sourceforge.net/>

iD8DBQFFAHFdyWjQ78xo0X8RAuEhAJ48uNVz51ERZQ3WKC5Zfj+VhsO6yACfU3Yr
O8H74/jbBOyfB4ftdxTvhhI=
=c3/3
-END PGP SIGNATURE-


Re: Netscape 6/7 crashes by a simple stylesheet...

2003-02-26 Thread Raj Mathur
>>>>> "Jocke" == jux  <[EMAIL PROTECTED]> writes:

Jocke> Hi, I'm new here so I don't know if I posted this in the
Jocke> correct list...

Jocke> I've found out that some simple CSS-code can crash Netscape
Jocke> 6 and 7.

Jocke> This is a simple html-page containing this code:

Jocke>   

Jocke>  
 
Jocke> 

Jocke> Was this already known?

Tested on following browsers on Red Hat Linux 8.0, i386:

galeon-1.2.6-0.8.0: Consumes 100% CPU but continues to respond to
events.

kdebase-3.0.3-14 (Konqueror): No effect

mozilla-1.0.1-26: Consumes 100% CPU, stops responding to events (or
takes overly long to respond -- I didn't wait more than a couple of
minutes).

netscape-communicator-4.79-1: No effect.

Regards,

-- Raju

Jocke> /Jocke

-- 
Raj Mathur[EMAIL PROTECTED]  http://kandalaya.org/
  It is the mind that moves