Re: common dns misconfiguration can lead to "same site" scripting

2008-01-22 Thread David Malone
On Mon, Jan 21, 2008 at 09:25:08AM +0100, Florian Weimer wrote: > | Note that all domains that contain hosts should have a "localhost" A > | record in them. > That RFC was obsoleted by RFC 1912 in 1996, so there's no RFC > conformance issue if you omit the domain names. But it explains why > the

Re: VNC authentication weakness

2002-07-30 Thread David Malone
On Mon, Jul 29, 2002 at 06:13:08PM +, [EMAIL PROTECTED] wrote: > On the other hand, the idea of combining many entropy sources using > a cryptographic hash is a good one. If this is used for cryptographic > purposes, I'd just like to see some more reliably-unpredictable sources in > there, if

Re: inetd DoS exploit

2001-02-28 Thread David Malone
On Mon, Feb 26, 2001 at 04:39:58PM -0500, Jose Nazario wrote: > 3] move to xinetd or other similar programs which have rate limiting. > solar designer has a neat-o patch for xinetd that can do max-per-IP > limits. very nice ... :) FreeBSD's inetd has a selection of features like like this (maximu

Re: Flaw in 3c59x.c or in Kernel?

2000-01-05 Thread David Malone
On Tue, Jan 04, 2000 at 09:21:36AM -0500, Sonny Parlin wrote: > eth1: Too much work in interrupt, status e481. Temporarily disabling > functions(7b7e). We saw this with some Linux machines in college that were connected to busy 100Mb/s ethernet. Bill Paul is right when he says ifconfiging down a

Re: ftp conversions exploit

1999-12-23 Thread David Malone
On Wed, Dec 22, 1999 at 04:47:25AM +, Desi Hacker wrote: > during the exploiting process.. the final step as instructed by the auther > doesn't work > > ftp> get "--use-compress-program=sh blah".tar > or > ftp> get "--use-compress-program=sh blah".tar > > instead is gives a warning of permiss

Problems with redhat 6 Xsession and pam.d/rlogin.

1999-10-08 Thread David Malone
I've found two problems which seem to be present in RedHat 6.0 and RedHat 6.1. They're not earthshatteringly bad, but... 1) Xsession on RedHat will start kde, gnome or anotherlevel rather than running a user's .xsession file, if you choose one of these from kdm. This is ba