Re: [Full-disclosure] Samba Remote Zero-Day Exploit

2010-02-09 Thread Krzysztof Halasa
Thierry Zoller writes: > Facts : > - Several distributions run with vulnerable settings per default > if there is a "misconfiguration" it is part of the vendor. > - Your not supposed to be able to traverse dirs. What's wrong with creating $HOME/tmp -> /tmp/$USER (not necessarily with Samba, ma

Re: Sudo tricks

2006-03-29 Thread Krzysztof Halasa
to [EMAIL PROTECTED] but the reverse is forbidden. Switching to higher level is never safe. Switching to lower level _can_ be safe - under conditions. One can consider root and non-root admin account to have the same security level, though (with non-root account used instead of root to limit accidental damage only). -- Krzysztof Halasa

Re: FW: Vulnerability in Novell Netware

2001-03-19 Thread Krzysztof Halasa
disable "change to client rights" feature. Another thing which comes to mind is using regular account for printing, not root^H^H^H^Hadmin account. -- Krzysztof Halasa Network Administrator