Re: [Full-disclosure] Can ISO15408 evaluated products be trusted?

2005-05-21 Thread Valdis . Kletnieks
On Sat, 21 May 2005 06:36:29 PDT, Nora Barrera said: > What's the use of security functions if they can be circumvented? Rule #1 of security: It's never perfect. Rule #2 of security: It's stupid to spend more effort on security than you need to. Rule #3 of security: Good security features raise

Re: [Full-disclosure] RE: Security issue in Microsoft Outlook

2005-05-21 Thread Valdis . Kletnieks
On Sat, 21 May 2005 23:03:01 BST, Colin said: > how come the troll threads are always the longest? It's springtime, and the trolls are looking for mates. The troll with the longest is most likely to reproduce. Check the list archives in a few months - if any of the trolls snag a mate, in a few mo

Re: [Full-disclosure] Ports used by trogens

2005-05-21 Thread Who?
Malicious code can be run on any port, and even more malicious code wont run with TCP ports anyways, it will use icmp or some other form of ip protocol to bypass filtering software. Blocking ports does increase the security of a system, but further measures are needed if you wish to have a "secure"

Re: [Full-disclosure] RE: Security issue in Microsoft Outlook

2005-05-21 Thread Colin
how come the troll threads are always the longest? :) C ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Can ISO15408 evaluated products be trusted?

2005-05-21 Thread HHikita
Nora Barrera wrote: > But those reports do not contain any valuable > information for me. What kind of tests were done? How? You should look into sections that cover test activity in the CEM. (5.8, 6.8, 7.9, 8.9) For EAL4 this would be the following. 8.9.2 Evaluation of Coverage (ATE_COV.2) 8.9.3

[Full-disclosure] Ports used by trogens

2005-05-21 Thread Brian Phillips
I read some time ago that malicious code when reporting home did not use port 80 or any of the other well known ports used for simple internet work. This means, as I understand it, that the home computer of the malicious code is constantly listening on some port other than port 80. Is it still

[Full-disclosure] CERT VU#637934

2005-05-21 Thread Daniel Hartmeier
/* * TCP does not adequately validate segments before updating timestamp value * http://www.kb.cert.org/vuls/id/637934 * * RFC-1323 (TCP Extensions for High Performance) * * 4.2.1 defines how the PAWS algorithm should drop packets with invalid * timestamp options: * * R1) If

Re: [Full-disclosure] Can ISO15408 evaluated products be trusted?

2005-05-21 Thread HHikita
Nora Barrera wrote: >I was told that "internal risk" is not taken into >account in Japan. No employee would hack his own >company. > > The traditional employment system in Japan was "Shuushin Koyou". You were basically assured your job until retirement. So before there were any Information tech

[Full-disclosure] [ GLSA 200505-16 ] ImageMagick, GraphicsMagick: Denial of Service vulnerability

2005-05-21 Thread Thierry Carrez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200505-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Re: [Full-disclosure] Can ISO15408 evaluated products be trusted?

2005-05-21 Thread Nora Barrera
--- [EMAIL PROTECTED] wrote: > Ask the vendor for a copy of the evaluation report. But those reports do not contain any valuable information for me. What kind of tests were done? How? It looks like security by obscurity. > Note that the EAL and PP interact - a CAPP > (Controlled Access) evaluat

Re: [Full-disclosure] Can ISO15408 evaluated products be trusted?

2005-05-21 Thread Nora Barrera
--- HHikita <[EMAIL PROTECTED]> wrote: > But you need a common vocabulary to describe > security specifications. This vocabulary should be understood by more than 100 people. > How else would you expect to archive common > recognition between all those countries. :-P Is this even possible, cons

Re: [Full-disclosure] COX Internet Outage

2005-05-21 Thread Ill will
i was down pretty much all day ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/