BeroList 2.5.9 Code Quality Is A Disaster

2001-03-25 Thread Matthias Andree
-BEGIN PGP SIGNED MESSAGE- I wrote to the leafnode mailing list: > [EMAIL PROTECTED] (Cornelius Krasel) writes: > > > My guess would be that BeroList eats a multiline Content-Type header. > > The test mail I sent to the list, with the Subject "IGNORE > THIStest mail for...", supports thi

MDKSA-2001:033-1 - openssh update

2001-03-25 Thread Linux Mandrake Security Team
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Linux-Mandrake Security Update Advisory Package name: openssh Date:

Re: Verisign certificates problem

2001-03-25 Thread Peter Gutmann
"Sinclair, Roy" <[EMAIL PROTECTED]> writes: >Some information regarding Verisign Certificates that has come out of this >fiasco is quite disturbing but has been under reported and may have been >missed by many in the security business. > >Pay close attention to this paragraph from the Frequently

CRLs (was Re: Verisign certificates problem

2001-03-25 Thread j eric townsend
someone wrote: >The first question I have after seeing that is how many of the rest of the >500,000 certificates that Verisign says they have issued also do not have >this CRL Distribution Point field properly filled in. For that matter, how many certificates out there are attached to any sort of

ILMI community in olicom/crosscomm routers

2001-03-25 Thread Jacek Lipkowski
Crosscomm/Olicom routers have a undocumented community string ILMI (yes, the same as in cisco :) that has read and write permissions (i didn't check the whole tree, but you can set system.sysContact.0 for example). This was checked on a XLT-F router with software 'XL 80 IM Version 5.5 Build Level

Re: Yes, they have found a serious PGP vulnerability...sort of

2001-03-25 Thread Pavel Kankovsky
On Fri, 23 Mar 2001, Casper Dik wrote: > How is any proposed defense going to work? They're modifying your > secret key stored on your system; if they can do that they can also > remove any checks from your PGP program. Yes and no. Yes because in most cases, the ability to modify a file contai

Re: Verisign certificates problem

2001-03-25 Thread Peter Gutmann
Elias Levy <[EMAIL PROTECTED]> writes: >Actually checking most of the CA certificates shipped with IE less than half >have a CPD field. Of the big CA only Entrust seems to use the field. That's not surprising, they invented and, I believe, patented the thing. Peter.

Re: Microsoft KB# to Advisory name mapping

2001-03-25 Thread Michael C. Bazarewsky
All, The Microsoft Hot-Fix Checker: http://www.microsoft.com/Downloads/Release.asp?ReleaseID=24168 uses the file: http://www.microsoft.com/technet/security/search/bulletins.xml to tell it the mappings between Knowledge Base numbers, names, and advisory numbers. I suspect that making a modifi

Re: SurfControl Bypass Vulnerability

2001-03-25 Thread Dan Harkless
Paul Cardon <[EMAIL PROTECTED]> writes: > > Whatever software is doing that should be converting the "hostname" > > into something it can match. A small amount of translation never > > goes astray. When that is done, evrything is either a hostname or > > a dotted-quad string and life is much eas

Re: Windows Sharing Allows Internet Tracking

2001-03-25 Thread Marc Maiffret
I could be wrong about the following so let me know if you know for a _fact_ that I am. |-Original Message- |From: Bugtraq List [mailto:[EMAIL PROTECTED]]On Behalf Of |Preston W Chang |Sent: Wednesday, March 21, 2001 3:13 PM |To: [EMAIL PROTECTED] |Subject: Windows Sharing Allows Internet