Re: A list of known security holes?

2000-10-06 Thread Peter Theobald
I thought +htr was an ASP security bug only? At 11:30 AM 10/6/00 -0400, Nadir Ait-Laoussine wrote: >This message is in MIME format. Since your mail reader does not understand >this format, some or all of this message may not be legible. > >--_=_NextPart_001_01C02FAA.59D650C2 >Content-Type: te

RE: A list of known security holes?

2000-10-06 Thread Mark W. Breneman
http://www.securityfocus.com/ http://www.beyondsecurity.com/ (*just found) http://www.w3.org/Security/Faq/www-security-faq.html (old info?) Also I have heard of a site something like bugtrack.com that is said to be very good. I have not found it yet. Anyone know the correct name? And read and m

RE: A list of known security holes?

2000-10-06 Thread Chris Montgomery
A good place to start is: http://www.allaire.com/developer/securityzone/ Chris Montgomery [EMAIL PROTECTED] Web Development & Consulting http://www.astutia.com Allaire Consulting Partner & NetObjects Reseller 210-490-3249/888-745-7603Fax 210-490-4692 Find a Job in San Anton

RE: A list of known security holes?

2000-10-06 Thread Shawnea Carter
House of Fusion (www.houseoffusion.com) has an excellent security section. Shawnea -Original Message- From: Nadir Ait-Laoussine [mailto:[EMAIL PROTECTED]] Sent: Friday, October 06, 2000 11:30 AM To: CF-Talk Cc: James Dunham Subject: A list of known security holes? This message is

RE: A list of known security holes?

2000-10-06 Thread Dave Watts
> I thought +htr was an ASP security bug only? It's an IIS problem, so if you're running CF on IIS, and haven't followed IIS security best practices, you may be vulnerable. Dave Watts, CTO, Fig Leaf Software http://www.figleaf.com/ voice: (202) 797-5496 fax: (202) 797-5444 --

Re: A list of known security holes?

2000-10-06 Thread Howie Hamlin
al Message - From: "Peter Theobald" <[EMAIL PROTECTED]> To: "CF-Talk" <[EMAIL PROTECTED]> Cc: "James Dunham" <[EMAIL PROTECTED]> Sent: Friday, October 06, 2000 12:39 PM Subject: Re: A list of known secur

Re: A list of known security holes?

2000-10-06 Thread myshka
Nadir, Try securityfocus.com, the maintainers of the Bugtraq list. They have a database of vulnerabilities by vendor, including Allaire. Best, Seva you wrote: > Hello all; > > Does anyone know of a good web site that lists the security holes with all > the major web servers / CF serv

RE: A list of known security holes?

2000-10-06 Thread Warrick, Mark
CQ: 346566 -- > -Original Message- > From: Peter Theobald [mailto:[EMAIL PROTECTED]] > Sent: Friday, October 06, 2000 9:40 AM > To: CF-Talk > Cc: James Dunham > Subject: Re: A list of known security holes? > > > I thought +htr was an ASP security bug only?

RE: A list of known security holes?

2000-10-06 Thread Peter Theobald
- > > >> -Original Message- >> From: Peter Theobald [mailto:[EMAIL PROTECTED]] >> Sent: Friday, October 06, 2000 9:40 AM >> To: CF-Talk >> Cc: James Dunham >> Subject: Re: A list of known security holes? >> >> >> I thought +h

RE: A list of known security holes?

2000-10-08 Thread Scott, Andrew
* Ph 9273 0693 * [EMAIL PROTECTED] -Original Message- From: Peter Theobald [mailto:[EMAIL PROTECTED]] Sent: 07 October 2000 03:40 To: CF-Talk Cc: James Dunham Subject: Re: A list of known security holes? I thought +htr was an ASP security bug only? At 11:30 AM 10/6/00 -0400, Nadir Ait