[Full-disclosure] Insecure Use of RC4 in LSrunasE and Supercrypt (CVE-2007-6340)

2008-01-29 Thread Daniel Roethlisberger
# # # COMPASS SECURITY ADVISORY http://www.csnc.ch/ # # # # Product: LSrunasE, Supercrypt # Vendor: Geert Moernaut # Type: Flawed Encryption # Ris

[Full-disclosure] [ GLSA 200801-17 ] Netkit FTP Server: Denial of Service

2008-01-29 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200801-17 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

[Full-disclosure] [ GLSA 200801-16 ] MaraDNS: CNAME Denial of Service

2008-01-29 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200801-16 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -

Re: [Full-disclosure] Save XP

2008-01-29 Thread James Matthews
Ok signed up! I hope it works! On Jan 28, 2008 9:43 PM, scott <[EMAIL PROTECTED]> wrote: > For all those who believe Vista is still not up to par,you can help stop > MS from forcing us to go to Vista. > > For those who don't know,MS is planning on stopping XP sales after June > 30,2008.There are

Re: [Full-disclosure] Save XP

2008-01-29 Thread blah
While I see more *nix folks, I also see more computer savvy folks in general, so I'm not sure the proportions have necessarily changed. I also can count the number of "normal" (non-IT) home users using linux on 1 hand, still. I don't see evidence of *nix making serious inroads into the average co

Re: [Full-disclosure] Save XP

2008-01-29 Thread Peter Besenbruch
On Tuesday 29 January 2008 02:52:12 Tremaine Lea wrote: > I run into a heck of a lot more people running linux (usually Ubuntu) these > days than I did even 5 years ago. Especially since Ubuntu didn't exist five years ago. ;) On a more serious note, it was almost five years ago to the day that I

[Full-disclosure] Advisory: Tripwire Enterprise/Server XSS Vulnerability

2008-01-29 Thread Liquidmatrix Security Digest
Name: Tripwire Enterprise/Server XSS Vulnerability Release Date: 29 January 2008 Reference: LSD001-2008 Discover: Dave Lewis Vendor: Tripwire Product: Tripwire Enterprise/Server Management Web Interface Systems Affected: version 7.0 (as tested) NB. Earlier versions are affected as well. Please upgr

Re: [Full-disclosure] Save XP

2008-01-29 Thread Tremaine Lea
On Tue, 2008-01-29 at 10:28 +0100, Vincent Archer wrote: > Windows survives on the strength of its application ecosystem, not > because of any strength in the OS itself. That's true of any system; > except for a few fanatics, you care about what applications you run, > not what the system under

Re: [Full-disclosure] Save XP

2008-01-29 Thread Steward Smith
My Amiga is way better than your Atari!!! On Tue, 2008-01-29 at 10:28 +0100, Vincent Archer wrote: > On Tue, 2008-01-29 at 01:00 +0100, [EMAIL PROTECTED] wrote: > > On Mon, 28 Jan 2008 18:52:37 EST, T Biehn said: > > > Do you guys really think that any of those options are viable > > > alternati

Re: [Full-disclosure] Save XP

2008-01-29 Thread Vincent Archer
On Tue, 2008-01-29 at 01:00 +0100, [EMAIL PROTECTED] wrote: > On Mon, 28 Jan 2008 18:52:37 EST, T Biehn said: > > Do you guys really think that any of those options are viable > > alternatives to windows? > > Actually, they *are* viable alternatives to Windows for a very large > percentage > of

[Full-disclosure] [ GLSA 200801-15 ] PostgreSQL: Multiple vulnerabilities

2008-01-29 Thread Raphael Marichez
- - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - Gentoo Linux Security Advisory GLSA 200801-15 - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - - http://security.gentoo.org/ - - - - - -