Re: MD5 collisions found - alternative?

2004-08-24 Thread Sam Vilain
Bartosz Fenski aka fEnIo wrote: Collisions have been found? Collisions were always. Every hashing algorithm makes collisions... that's just natural. They found way to generate two input values that makes the same hash. That's still long way before they can generate input having hash of another inpu

Re: MD5 collisions found - alternative?

2004-08-24 Thread Sam Vilain
Robert Trebula wrote: Maybe you have already noticed - collisions have been found in MD5 hashing algorithm: http://eprint.iacr.org/2004/199.pdf http://www.freedom-to-tinker.com/archives/000664.html http://www.unixwiz.net/techtips/iguide-crypto-hashes.html My question is: Is there an easy way to ma

Re: running services in their own little world

2004-07-31 Thread Sam Vilain
ary, using vserver + fwbuilder, you can configure multi-tier, firewalled collections of Debian GNU/Linux hosts on a single system. -- Sam Vilain, sam /\T vilain |><>T net, PGP key ID: 0x05B52F13 (include my PGP key ID in personal replies to avoid spam filtering) -- To UNSUBSCRIBE, email

Re: linux random capabilities ...

2002-07-31 Thread Sam Vilain
of things, there's the Math::TrulyRandom Perl module, which uses fluctuations in the system timer to get some of that much-loved entropy. This takes some time but also produces pretty good random numbers. -- Sam Vilain, [EMAIL PROTECTED] WWW: http://sam.vilain.net/ 7D74 2A09 B2D3 C30

Re: utilisateur backup

2002-07-22 Thread Sam Vilain
often they contain things like secret keys to encryption, etc that will allow a malicious user to pretend to be the machine that they have access to the backups of. Protect your backups carefully! -- Sam Vilain, [EMAIL PROTECTED] WWW: http://sam.vilain.net/ 7D74 2A09 B2D3 C30F F78E

Re: More SSH Fun (X11 forwarding)

2002-07-08 Thread Sam Vilain
ent and server in both > verbose and debugging modes provides me with nothing useful :( > > -Anne > -- > .-"".__."``". Anne Carasik, System Administrator > .-.--. _...' (/) (/) ``' gator at cacr dot caltech dot edu > (O/ O) \-'

Re: CERT Advisory CA-2002-19 Buffer Overflow in Multiple DNS Resolver Libraries

2002-07-01 Thread Sam Vilain
ebian.org/151247) If you are running any of the the following packages: bind bind-dev Then you need version 8.3.3-1 or higher, which were uploaded to unstable approximately 12 hours ago (Sun, 30 Jun 2002 21:48:10 -0600). The fixed packages do not appear to be available yet on security.debi

CERT Advisory CA-2002-19 Buffer Overflow in Multiple DNS Resolver Libraries

2002-07-01 Thread Sam Vilain
e Mellon University. Revision History June 28, 2002: Initial release -BEGIN PGP SIGNATURE- Version: PGP 6.5.8 iQCVAwUBPRzRIKCVPMXQI2HJAQFUUAP+JrIx1x3vF0BL7zFcURQSOOIsmEoGzqAP B+xs5kf4Oy5uYRRLASvYFh/XjnyGXIA5v8ECWx00B52PBKi7aPQS5o4Kiz1rxkFf +c5oziLDXNwy4Vj2ArUjdzM47Ghrq8QXHBOoHaK5OWAF6tyw