[Full-disclosure] Re: SendGate: Sendmail Multiple Vulnerabilities (Race Condition DoS, Memory Jumps, Integer Overflow)

2006-03-25 Thread Todd Burroughs

On Fri, 24 Mar 2006, Gadi Evron wrote:

On Thu, 23 Mar 2006, Claus Assmann wrote:

It took Sendmail a mounth to fix this. A mounth.


No. It took sendmail a week to fix this.  The rest of the time was
used to coordinate the release with all the involved vendors etc.


There are a few choices, full disclosure and "responsible disclosure" are
some. You can't do both. Releasing it out of nowhere, obfuscated in very
ineffective way, isn't it.

Not when it's critical infrastructure. With critical internet
infrastructure you need to be a tad bit smarter than that.


How would you suggest that they release this?

I think that they did it in a pretty responsible way.  They where
notified of the problem, they fixed it and gave vendors who use/ship
the product some time to create and test patches, then it became public.
This was done in a month, any longer and I would think that they would be
putting us at risk, but I think that this is a very reasonable response.
0Day full-disclosure eith a 'sploit would have been more trouble for me
;-)  (I'm probably not alone with that).

Todd

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/


[Full-disclosure] cpanel exploit

2006-09-29 Thread Todd Burroughs
Anyone have any info on this cpanel exploit.   I have a friend who found it
pretty open to full user level acess, but not root.

I'm curious to know what the hole is/was.

http://www.thewhir.com/marketwatch/092706_Web_Hosts_Hit_by_Hackers.cfm

http://news.netcraft.com/archives/2006/09/23/hostgator_cpanel_security_hole_exploited_in_mass_hack.html

Todd

---
The Internet has given us unprecedented opportunity to communicate and
share on a global scale without borders; fight to keep it that way.

Jesus died for your sins, make it worth his time.

___
Full-Disclosure - We believe in it.
Charter: http://lists.grok.org.uk/full-disclosure-charter.html
Hosted and sponsored by Secunia - http://secunia.com/