Re: Bind 8 bug experience

2002-11-15 Thread Chris Adams
in switching, running something other than BIND is looking good). -- Chris Adams [EMAIL PROTECTED] Systems and Network Administrator - HiWAAY Internet Services I don't speak for anybody but myself - that's enough trouble.

Re: A Study In Scarlet - Exploiting Common Vulnerabilities in PHPApplications

2001-07-03 Thread Chris Adams
on 2001-07-02 07:37, Shaun Clowes at [EMAIL PROTECTED] wrote: SecureReality is pleased to announce the release of our new paper entitled 'A Study In Scarlet - Exploiting Common Vulnerabilities in PHP You listed many common mistakes, which is good, but I think your conclusion (I contend that

Re: Network Solutions Crypt-PW Authentication-Scheme vulnerability

2001-06-10 Thread Chris Adams
characters of that. This also means that anyone with your encrypted password can probably call up and have changes made (since they know what NetSol believes is the first two characters). -- Chris Adams [EMAIL PROTECTED] Systems and Network Administrator - HiWAAY Internet Services I don't speak

Re: The out-of-domain NS registration attack

2000-03-20 Thread Chris Adams
still be okay. -- Chris Adams [EMAIL PROTECTED] Systems and Network Administrator - HiWAAY Information Services I don't speak for anybody but myself - that's enough trouble.

Re: Anyone can take over virtually any domain on the net...

2000-01-14 Thread Chris Adams
it expire and risking losing it), they still have en effective monopoly on all existing domain names that are registered with them. -- Chris Adams [EMAIL PROTECTED] Systems and Network Administrator - HiWAAY Information Services I don't speak for anybody but myself - that's enough trouble.

Re: Handspring Visor Network HotSync Security Hole

2000-01-10 Thread Chris Adams
On Thu, 6 Jan 2000 14:19:24 -0500, Jim Frost wrote: If you have Network HotSync (provided on the CD that comes with your Visor) enabled on your machine, and a malicious user knows your name (ex. John Smith), and the ip of your machine (ex. 192.168.22.22, or jsmith.company.com), he can change

Security flaw in Cobalt RaQ2 cgiwrap

1999-11-08 Thread Chris Adams
submitted to site1 being submitted to site2 instead. This is the biggest security problem. I notified Cobalt about this several weeks ago now, and they've said they are working on it, but that is it. They haven't released any kind of notice or update as of yet either. -- Chris Adams [EMAIL P