user flags in public temp space (was Re: chflags() [heads up])

1999-08-04 Thread Strange
Adam Morrison wrote: > From the OpenBSD change logs: > revision 1.59 > date: 1999/07/30 18:27:47; author: deraadt; state: Exp; lines: +20 -1 > do not permit regular users to chflags/fchflags on chr or blk devices -- > even if they happen to own them at the moment. Mike Frantzen ([EMAIL PROTEC

NSW Dragon Fire gets drowned

1999-08-04 Thread Stefan Laudat
Application: Dragon Fire 3.1 IDS for Unices Developer: Network Security Wizards Urgency: VERY HIGH Symptoms: Web users can run arbitrary commands *remotely*. Storyline: -- In the middle of developement of a Linux IDS , I wanted to take a short glimpse at some similar products on

Re: DPEC Online Courseware

1999-08-04 Thread Dallas Cooper
In reference to the report submitted on 1/15/99, DPEC has resolved this security issue as of our 3/99 CD release. To obtain this update, contact DPEC at [EMAIL PROTECTED]

Re: Cisco 675 password nonsense

1999-08-04 Thread Brian Elfert
On Sat, 31 Jul 1999, DeMoNx wrote: > switching all non-business/special adsl accounts over to using PPP rather > than bridging mode for 'security reasons', I got a little suspicious. With With good reason. In bridging mode with a Windows 9x/NT box, your network neighborhood will show everyone e

Followup: Remotely Lock up Gauntlet 5.0

1999-08-04 Thread Mike Frantzen
> * Description: > * If you know an IP that will be routed through a Gauntlet 5.0 Firewall, > * you can remotely lock up the firewall (tested against Solaris 2.6 and > * BSDI). It locks up to the point that one packet will disable STOP-A > * (L1-A) on Sparcs and ~3-5 packets will disable

Re: Alert : MS Office 97 Vulnerability (Explanation and Fix)

1999-08-04 Thread Wanderley J. Abreu Jr.
Hi, Based on the recent messages post on NTBugtraq list about MS Office Vunerability, I developed a fix program following the instructons given by Russ Cooper. The Program set the 3rd byte of EditFlag Key value to 00 and plus give other options for set EditFlags entries. Here

[LoWNOISE] Password hunting with webramp

1999-08-04 Thread ET LoWNOISE
Hi, Just to go deeper. Definition: (taken from www.webramp.com) What is a WebRamp? A WebRamp is a communications device that allows your whole office to share Internet access. You can choose from a va

Re: SGID man

1999-08-04 Thread Isaac To
> "Solar" == Solar Designer <[EMAIL PROTECTED]> writes: Solar> I wouldn't normally post this, but while we're on the topic... Solar> There's an ancient problem with SGID man that I keep seeing on Solar> various systems. For example, on Red Hat 5.2: This seems to be a very genera

bo2k plugins

1999-08-04 Thread Alfred Huger
-- Forwarded message -- Date: Sun, 01 Aug 1999 21:29:40 -0500 From: Irwan Amir Widjaja <[EMAIL PROTECTED]> To: [EMAIL PROTECTED] Subject: bo2k plugins Hi, I recently (July 31st) discovered that the CAST-256 plugin v2.2 which allows any user to connect to any CAST256 server with a

Vulnerabilities in BO2k encryption plugins

1999-08-04 Thread Ben Greenbaum
Discovered by Irwan Amir Widjaja <[EMAIL PROTECTED]> and Daniel Roethlisberger <[EMAIL PROTECTED]>. Two popular encryption plugins for Back Orifice 2000 have been found to have serious security flaws: BO_CAST and BO2K IDEA. Both have been fixed. The flaw is that due to a small error in one line o

Nifty DoS in Foundry networks gear.

1999-08-04 Thread Jan B. Koum
Running tcp nmap scan against Foundry network gear make it go boom. What makes it more sad is that Foundry is in the networking business -- they route packets. They don't make toasters which get it's tcp/ip stack written by a recent CS grad. Anyway, the version I have which reboots after s

Administrivia: BUGTRAQ-JP, BUGTRAQ-ES and SF-NEWS

1999-08-04 Thread Elias Levy
Well it took longer that I thought it would, but that is always the case. Right? This message is to announce the availability of three new mailing lists. The first two are BUGTRAQ-JP (Japanese) and BUGTRAQ-ES (Spanish). The first one will be moderated by Nobuo Miwa <[EMAIL PROTECTED]> and the sec

Follow up to .hta HTML Application in IE5

1999-08-04 Thread Bryan Batchelder
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Aleph -- This is just a brief follow up for anyone interested, I have had several people ask me about this: To remove the association between .hta and HTML applications, you can do the following: 1. Open up Windows Explorer (i.e. double cli