Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Rick Moen
Quoting Joachim Fahrner (j...@fahrner.name): > Another nice bug in Gnome: > http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html I feel almost dirty making excuses for GNOME ;-> , but this bug in /usr/bin/gnome-exe-thumbnailer appears to be exploitable only if WINE is inst

Re: [DNG] Sexual politics and society: [was: Forums: was I have a question about libsystemd0 in devuan ascii, ]

2017-07-18 Thread Fungi4All
> From: jaro...@dyne.org >> 1. What does this have to do with Devuan? > perhaps just one thing, that the first image this project ever > released was a Valentine present, with attached a love declaration, > between two men. it may be defined a platonic dev relationship, but > definitely makes Devua

[DNG] GVFS and dependants

2017-07-18 Thread Fungi4All
In my initial installation with a live-xfce iso, there seem to have been some left overs. I am trying to find out what this group of running process does and how essential they may be. While trying to attempt to remove the 6 of the 7 installed pkgs (gvfs -- bin, is not installed) I would think t

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Joachim Fahrner
Am 2017-07-18 09:39, schrieb Rick Moen: OTOH, clearly the parser code in /usr/bin/gnome-exe-thumbnailer is rubbish, as it shouldn't be possible to fool it into processing embedded VBSCript in a filename. That's the point. All these things made by Poettering, Gnome Team, Read Hat ... are rubb

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Rick Moen
Quoting Joachim Fahrner (j...@fahrner.name): > That's the point. All these things made by Poettering, Gnome Team, > Read Hat ... are rubbish monsters, too complex to make them safe. > They put all things in they can think of. A thumbnailer that depends > on wine! Unbelievable! That's no good and c

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Fungi4All
schrieblings From: j...@fahrner.name > That"s the point. All these things made by Poettering, Gnome Team, Read > Hat ... are rubbish monsters, too complex to make them safe. They put > all things in they can think of. A thumbnailer that depends on wine! > Unbelievable! That"s no good and clean sof

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Adam Borowski
On Tue, Jul 18, 2017 at 12:39:45AM -0700, Rick Moen wrote: > Quoting Joachim Fahrner (j...@fahrner.name): > > > Another nice bug in Gnome: > > http://news.dieweltistgarnichtso.net/posts/gnome-thumbnailer-msi-fail.html > > I feel almost dirty making excuses for GNOME ;-> , but this bug in > /usr/

Re: [DNG] Sexual politics and society: [was: Forums: was I have a question about libsystemd0 in devuan ascii, ]

2017-07-18 Thread Enrico Weigelt, metux IT consult
On 18.07.2017 07:48, Fungi4All wrote: Jus'b'cause lots of you want to go to bed with Poetering does not make this a gay distribution Is Lennart a man at all ? :o --mtx ___ Dng mailing list Dng@lists.dyne.org https://mailinglists.dyne.org/cgi-b

Re: [DNG] Sexual politics and society: [was: Forums: was I have a question about libsystemd0 in devuan ascii, ]

2017-07-18 Thread Rowland Penny
On Tue, 18 Jul 2017 10:32:58 + "Enrico Weigelt, metux IT consult" wrote: > On 18.07.2017 07:48, Fungi4All wrote: > > > Jus'b'cause lots of you want to go to bed with Poetering does not > > make this a gay distribution > > Is Lennart a man at all ? :o > Look, you have been asked polit

Re: [DNG] udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "Arnt Karlsen" To: Sent: Monday, July 17, 2017 5:35 PM Subject: Re: [DNG] udev replacement On Mon, 17 Jul 2017 10:08:02 -0400, Ismael wrote in message : - Original Message - From: "Arnt Karlsen" To: "Yevgeny Kosarzhevsky" Cc: Sent: Monday, Jul

Re: [DNG] udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "Arnt Karlsen" To: Sent: Monday, July 17, 2017 5:35 PM Subject: Re: [DNG] udev replacement On Mon, 17 Jul 2017 10:08:02 -0400, Ismael wrote in message : - Original Message - From: "Arnt Karlsen" To: "Yevgeny Kosarzhevsky" Cc: Sent: Monday, Jul

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 08:43:11AM -0400, Ismael L. Donis Garcia wrote: > - Original Message - From: "Arnt Karlsen" [a-276-lines-long-cut-of-mostly-irrelevant-stuff] Could I just encourage all of us to please have a fresh look at one of the links below: - http://www.kassj.com/netiquette

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 08:56:11AM -0400, Ismael L. Donis Garcia wrote: [cutting-off-a-whole-bunch-of-irrelevant-lines] > > The problem is that try to download > http://auto.mirror.devuan.org/devuan//dists/None/main/binary-i386/Packages.gz > > And should download: > http://auto.mirror.devuan.or

[DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Arnt Karlsen
On Tue, 18 Jul 2017 08:43:11 -0400, Ismael wrote in message <137df52c5546401899313d3793aa3...@natio.co.cu>: > - Original Message - > From: "Arnt Karlsen" > To: > Sent: Monday, July 17, 2017 5:35 PM > Subject: Re: [DNG] udev replacement ... > > ..weird, I got a mine ok right now, so I

Re: [DNG] udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "KatolaZ" To: Sent: Tuesday, July 18, 2017 8:56 AM Subject: Re: [DNG] udev replacement ___ Dng mailing list Dng@lists.dyne.org https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng I'm trying to download i

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 09:22:11AM -0400, Ismael L. Donis Garcia wrote: [cut] > > I'm trying to download it locally because I use it without internet access. > > Where I live very few people have access to the internet and in their homes > practically nobody, that is why usually the one who has

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "Arnt Karlsen" To: Sent: Tuesday, July 18, 2017 9:04 AM Subject: [DNG] ..experimental mirror is fixed now?, was: udev replacement On Tue, 18 Jul 2017 08:43:11 -0400, Ismael wrote in message <137df52c5546401899313d3793aa3...@natio.co.cu>: - Original Mes

Re: [DNG] udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "KatolaZ" To: Sent: Tuesday, July 18, 2017 9:29 AM Subject: Re: [DNG] udev replacement ___ Dng mailing list Dng@lists.dyne.org https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng English is not my native

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 09:46:40AM -0400, Ismael L. Donis Garcia wrote: > > English is not my native language, so I may not explain it well. > Try the following script and you will notice the error that is giving me > when trying to download the repository for my pc. > That does not happen to me e

Re: [DNG] udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "KatolaZ" To: Sent: Tuesday, July 18, 2017 10:32 AM Subject: Re: [DNG] udev replacement And also, could you please file a bug report on bugs.devuan.org? I have never used it and I do not know how to do it. I do not know if it's too much for you to do for m

Re: [DNG] udev replacement

2017-07-18 Thread Antony Stone
On Tuesday 18 July 2017 at 15:59:01, Ismael L. Donis Garcia wrote: > >- Original Message - > >From: "KatolaZ" > >To: > >Sent: Tuesday, July 18, 2017 10:32 AM > >Subject: Re: [DNG] udev replacement > > > >And also, could you please file a bug report on bugs.devuan.org? > > I have never u

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 10:59:01AM -0400, Ismael L. Donis Garcia wrote: > >- Original Message - From: "KatolaZ" > >To: > >Sent: Tuesday, July 18, 2017 10:32 AM > >Subject: Re: [DNG] udev replacement > > > >And also, could you please file a bug report on bugs.devuan.org? > > I have never

Re: [DNG] udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "Antony Stone" To: Sent: Tuesday, July 18, 2017 11:01 AM Subject: Re: [DNG] udev replacement > On Tuesday 18 July 2017 at 15:59:01, Ismael L. Donis Garcia wrote: > >> >- Original Message - >> >From: "KatolaZ" >> >To: >> >Sent: Tuesday, July 18, 201

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 11:26:42AM -0400, Ismael L. Donis Garcia wrote: [cut] > > If I understand it very well to you. > > The problem is that I do not know how to proceed since it is not a package. > The problem is the release file, which must have the name of the codename and > not have none

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Enrico Weigelt, metux IT consult
On 18.07.2017 08:45, Rick Moen wrote: Strictly speaking, I am reasonably sure it doesn't _depend_ on WINE, but merely use it if it's present. The fact that it silently starts proprietary executables (eg. the windows scripting host), just because they're there, indeed is a huge bug, more precis

[DNG] Hello says 'idonis'

2017-07-18 Thread Ismael L. Donis Garcia
Package: amprolla Create the Release file of the experimental branch with the line: Codename: none And should have the name of the branch Codename: experimental This prevents me from downloading the repositories to my PC. Which prevents me from using devuan in places where there is no Internet

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Arnt Karlsen
On Tue, 18 Jul 2017 09:36:10 -0400, Ismael wrote in message : > - Original Message - > From: "Arnt Karlsen" > To: > Sent: Tuesday, July 18, 2017 9:04 AM > Subject: [DNG] ..experimental mirror is fixed now?, was: udev > replacement > > > > On Tue, 18 Jul 2017 08:43:11 -0400, Ismael wr

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 07:06:46PM +0200, Arnt Karlsen wrote: [cut] > > error al abrir fichero > > gpgv: Firmado el mar 18 jul 2017 06:02:23 CDT usando clave RSA ID > > 541922FB gpgv: Imposible comprobar la firma: clave pública no > > encontrada Release gpg signature does not verify. > > [ 23%] G

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Rick Moen
Quoting Enrico Weigelt, metux IT consult (enrico.weig...@gr13.net): > On 18.07.2017 08:45, Rick Moen wrote: > > >Strictly speaking, I am reasonably sure it doesn't _depend_ on WINE, but > >merely use it if it's present. > > The fact that it silently starts proprietary executables (eg. the > wind

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Rick Moen
Quoting Adam Borowski (kilob...@angband.pl): > But _why_ would you say this is an excuse? Wine is an unrelated piece of > software, and it's not a bug in Wine. I agree with your well-stated take on this. I'm merely pointing out that the original statement that GNOME's thumbnailer displays the i

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Daniel Abrecht
Since thumbnails have to be generated somehow, they need some kind of generator. To use plugins, which are resembled by executables in this case, is a perfectly fine approach for this. The real problem is that despite it's well known that thumbnail generators have a really big attack surface, noth

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "Arnt Karlsen" To: Sent: Tuesday, July 18, 2017 1:06 PM Subject: Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement On Tue, 18 Jul 2017 09:36:10 -0400, Ismael wrote in message : - Original Message - From: "Arnt Karlsen" To:

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Arnt Karlsen
On Tue, 18 Jul 2017 18:13:09 +0100, KatolaZ wrote in message <20170718171309.gk15...@katolaz.homeunix.net>: > On Tue, Jul 18, 2017 at 07:06:46PM +0200, Arnt Karlsen wrote: > > [cut] > > > > error al abrir fichero > > > gpgv: Firmado el mar 18 jul 2017 06:02:23 CDT usando clave RSA ID > > > 5419

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Ismael L. Donis Garcia
- Original Message - From: "Arnt Karlsen" To: Sent: Tuesday, July 18, 2017 2:48 PM Subject: Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement On Tue, 18 Jul 2017 18:13:09 +0100, KatolaZ wrote in message <20170718171309.gk15...@katolaz.homeunix.net>: On Tue, Jul

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Fungi4All
> From: sli...@natio.co.cu > To: dng@lists.dyne.org > - Original Message - > From: "Arnt Karlsen" >> >> ..ok, we have found a debmirror bug. :o) > I do not think so, I think it"s an insect that generates the Release file. >> ..med vennlig hilsen = with Kind Regards from Arnt Karlsen >> ...

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Arnt Karlsen
On Tue, 18 Jul 2017 15:14:41 -0400, Fungi4All wrote in message : > > From: sli...@natio.co.cu > > To: dng@lists.dyne.org > > - Original Message - > > From: "Arnt Karlsen" > >> > >> ..ok, we have found a debmirror bug. :o) > > I do not think so, I think it"s an insect that generates the >

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Adam Borowski
On Tue, Jul 18, 2017 at 10:47:07AM -0700, Rick Moen wrote: > WINE is a fine and useful package (and this bug isn't its fault). My > point is merely that in the _general_ case, it would not be expected to > accompany GNOME. (I'm very much not a GNOME fan.) It's not software that would in any way

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Adam Borowski
On Tue, Jul 18, 2017 at 06:15:20PM +, Daniel Abrecht wrote: > Since thumbnails have to be generated somehow, they need some kind of > generator. To use plugins, which are resembled by executables in this > case, is a perfectly fine approach for this. Uhm, but why? I can understand a thumbnail

Re: [DNG] udev replacement

2017-07-18 Thread Fungi4All
Are all the bug reports going to bugs.debian.whoreg?___ Dng mailing list Dng@lists.dyne.org https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread Fungi4All
> On Tue, 18 Jul 2017 15:14:41 -0400, fungi4...@protonmail.com>: >> > From: sli...@natio.co.cu >> > To: dng@lists.dyne.org >> > - Original Message - >> > From: "Arnt Karlsen" >> >> >> >> ..ok, we have found a debmirror bug. :o) >> > I do not think so, I think it"s an insect that generates

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Daniel Abrecht
On 2017-07-18 20:07, Adam Borowski wrote: > On Tue, Jul 18, 2017 at 06:15:20PM +, Daniel Abrecht wrote: >> Since thumbnails have to be generated somehow, they need some kind of >> generator. To use plugins, which are resembled by executables in this >> case, is a perfectly fine approach for thi

Re: [DNG] VBScript Injection via GNOME Thumbnailer

2017-07-18 Thread Adam Borowski
On Tue, Jul 18, 2017 at 10:07:35PM +0200, Adam Borowski wrote: > Actually, imagemagick is one of worst offenders here. The version in Jessie > is at deb8u9, and every security update tends to mention ~20 CVEs. ... nd, just hours later, here comes deb8u10: # Package: imagemagick # CVE

[DNG] I apologize, but I lost my email somehow with the, packages needed for openrc

2017-07-18 Thread zap
I want to install it on another laptop with ascii... util-linux sysvinit-util and one other package needed? i forget which though... svante, can you send those three packages directly to me one more time? I thought I had them saved somewhere... alas. _

[DNG] svante, do you still have those three packages,

2017-07-18 Thread zap
i forgot to save them, i need them for a different laptop... ___ Dng mailing list Dng@lists.dyne.org https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng

Re: [DNG] udev replacement

2017-07-18 Thread Fungi4All
https://dev1galaxy.org/viewtopic.php?pid=3224#p3224 by nixer: I have a couple of "nasty" hacks. They are done on all my devuan installs. So, I will share. Before I start, one thing you may want to know. I have a home network server operational 24/7. It is only off during power outages, which is s

[DNG] nevermind, my messages,

2017-07-18 Thread zap
I found my openrc packages and it is on again! hehe ___ Dng mailing list Dng@lists.dyne.org https://mailinglists.dyne.org/cgi-bin/mailman/listinfo/dng

Re: [DNG] I apologize, but I lost my email somehow with the, packages needed for openrc

2017-07-18 Thread Miroslav Rovis
On 170718-18:00-0400, zap wrote: > I want to install it on another laptop with ascii... > > util-linux > > sysvinit-util > > and one other package needed? i forget which though... (You've already found your own packages, as you say in your other messages, all three of different subject --that'

Re: [DNG] ..experimental mirror is fixed now?, was: udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 03:10:13PM -0400, Ismael L. Donis Garcia wrote: [cut] > >>No Arnt, there is actually an error in the Release file generated by > >>dak for experimental, and apparently this mistake bothers debmirror > >>(but not apt & Co., otherwise we would have noticed this before). It >

Re: [DNG] udev replacement

2017-07-18 Thread KatolaZ
On Tue, Jul 18, 2017 at 04:27:44PM -0400, Fungi4All wrote: > Are all the bug reports going to bugs.debian.whoreg? No, they shouldn't, as you can see here: http://bugs.devuan.org Which version of reportbug are you using? On which release? HND KatolaZ -- [ ~.,_ Enzo Nicosia aka KatolaZ - G

Re: [DNG] nevermind, my messages,

2017-07-18 Thread Jaromil
dear zap, On Tue, 18 Jul 2017, zap wrote: > I found my openrc packages and it is on again! hehe rather than opening three new thread subjects dng is a mailinglist with >500 participants, some with lower vision, and with online archives. your behaviour here affects us all and the people readi