Re: Trendmicro - Interscan - List of BCC: is revealed when stripping attachments and notifying destination addresses

2002-04-25 Thread Rich Lafferty
7;t trust and saying "Here, do with this what you will". Of course, the reliable fix for this is for your local MTA or MUA to implement Bcc: as a separate message transaction, because they are the only trustworthy links in the message path. -Rich -- Rich Lafferty --+--

MUAs that delete spoolfiles (was Solaris /usr/bin/mailx exploit (SPARC))

2001-05-16 Thread Rich Lafferty
malicious user should be > able to steal other users' mail. I think. If they can, then *that's* a flaw in the MTA, which should never deliver into something that isn't owned by the recipient. -Rich -- -- Rich Lafferty ---

Re: SECURITY.NNOV: The Bat! bug

2001-04-25 Thread Rich Lafferty
on't use The Bat, and I haven't been following this thread closely, so I don't know if the updated RFCs actually clarify the issue at hand, but they do clarify a lot of stuff that 821 and 822 were a little liberal on.) -Rich -- -- Ric

Re: MicroImages MIX X Server

1999-10-09 Thread Rich Lafferty
ly crash the X > applications running on them. Just my .02 -- That must have been a while ago. Both the Windows and MacOS versions of MI/X from 1997 have host-based authentication. -Rich -- ------ Rich Lafferty --- Sysadmin/Programmer, Information

Re: MicroImages MIX X Server

1999-10-06 Thread Rich Lafferty
above but the server keeps running fine. -Rich -- -- Rich Lafferty --- Sysadmin/Programmer, Information and Instructional Technology Services Concordia University, Montreal, QC (514) 848-7625 - [EMAIL PROTECTED] -- PGP signature