Re: Delegate creates directories writable for anyone

1999-07-22 Thread KOJIMA Hajime
In <[EMAIL PROTECTED]>, Olaf Seibert wrote: | On 30 june, I wrote (approximately) the following email to the author of | Delegate, a multi-protocol proxy deamon (ftp, http, telnet, etc). So far | I have received no reply, so now I'm posting here. This is an un-official fix for delegate 5.9.1 th

Re: linuxconf doesn't seem to deal correctly with /etc/pam.d/reboot

1999-07-22 Thread Marcelo Roccasalva
On Wed, Jun 30, 1999 at 11:32:14PM +0100, Domingos Bruges wrote: > Greetings you all, > > I'm not sure that what I'm about the say does really work, but i've > tested it successfully in 3 RedHat 6.0 boxes with (1.14 - subrev 4). > > If you use linuxconf in order to create / edit any user > system

old gnu finger bugs

1999-07-22 Thread Andrew Jones (CS/Physics student)
This is an old issue that has not be resolved. Gnu finger version 1.37 which is downloadable from metalab has two old security problems that date back to 1995. Here are some of the original posts. http://www.securityfocus.com/templates/archive.pike?list=1&date=1995-03-15&[EMAIL PROTECTED] Both

First reflections on security of MSN Messenger

1999-07-22 Thread Dmitri Alperovitch
Hi. Having just downloaded and briefly examined the newly released Microsoft's MSN Messenger, (Microsoft's alternative to ICQ, AIM and other instant messaging clients) I must say that Microsoft has not learn a single thing from serious security design mistakes made by other instant messengers. H

Re: Root Perms Gained with Patrol SNMP Agent 3.2 (all others?)

1999-07-22 Thread Aleph One
Please note that this vulnerability was fixed by BMC at the same time as they fixed the temporary file creation vulnerabilities reported by ISS last November. You can download the upgrade from the Patrol support web site at http://www.bmc.com/support.html Versions 3.2.05 and higher are known not

Administrivia

1999-07-22 Thread Aleph One
Every so often I get requests to post job openings on the list. As that is not within the charter of the list I reject them. With this in mind we've created a few mailing list: SecurityJobs. SecurityJobs is a mailing list and Forum on SecurityFocus developed to help IT Security Professionals find