Re: Your Opinion

2007-03-20 Thread Jack Lloyd
On Fri, Mar 16, 2007 at 02:44:07PM -0600, Neil Dickey wrote: > Even an absolutely secure operating environment ( OS +security programs ) > can be compromised by a user who is ignorant or malicious, or by third- > party software which is poorly made. Perhaps I'm misinterpreting your words, but I r

Vulnerability in man < 1.5l

2003-03-11 Thread Jack Lloyd
man 1.5l was released today, fixing a bug which results in arbitrary code execution upon reading a specially formatted man file. The basic problem is, upon finding a string with a quoting problem, the function my_xsprintf in util.c will return "unsafe" (rather than returning a string which could b

Re: VNC authentication weakness

2002-07-25 Thread Jack Lloyd
On Wed, 24 Jul 2002 [EMAIL PROTECTED] wrote: > If your server will give the same challenge repeatedly, and you can > sniff somebody else's challenge and response, it appears that you could > authenticate without knowing the password simply by connecting within > the 1-second window to get the sam

Re: Nortel CES (3DES version) offers false sense of securitywhen usi ng IPSEC

2001-02-28 Thread Jack Lloyd
> Similarly: 3DES isn't stronger than 112 bits. I'm not claiming that > 3DES is weaker than 112 bits. I claim that some smart people found > that cracking 3DES requires only on the order of 2^112 operations, 2^112 operations, given 2^56 blocks of memory. Since DES has an 8 byte block, that's 512