Re: PS Information Leak on HP True64 Alpha OSF1 v5.1 1885

2007-02-09 Thread Ivan Jager
On Tue, 6 Feb 2007, Andrea "bunker" Purificato wrote: [After months of silence from the "HP Software Security Response Team"] -Type: Information leak -Risk: low -Author: Andrea "bunker" Purificato - http://rawlab.mindcreations.com -Description: the "ps" command (also /usr/ucb/ps) on HP OSF1 v5

Re: STP mitm attack idea

2010-04-29 Thread Ivan Jager
On Wed, Apr 28, 2010 at 05:26:09PM -0400, Jason T. Masker scribbled thusly: > Best practice is to implement layer 2 security mechanisms which would > identify these ports as "access" ports and shut them down if any STP > traffic was received through these interfaces. On Cisco equipment, > this is k

Re: /proc filesystem allows bypassing directory permissions on Linux

2009-10-28 Thread Ivan Jager
On Sat, Oct 24, 2009 at 10:36:11PM +0400, Dan Yefimov scribbled thusly: > Thus Debian kernel team should be blamed for that misbehaviour. Don't > worry, hardlinks behave just the same way, as you describe. Use authentic > Linux kernels, if you dislike that. Shall we blame Red Hat too? Just teste