Re: [Full-disclosure] Defense in depth -- the Microsoft way (part 8): execute everywhere!

2013-08-24 Thread Stefan Kanthak
Jeffrey Walton wrote: > Hi Stefan, > >> ... administrative rights for every user account This WAS the default for user accounts back then, and still IS the default for user accounts created during setup. > Hmmm... XP/x64 appears to have a bug such that the second user also > needs to be admin (

Re: [Full-disclosure] Defense in depth -- the Microsoft way (part 8): execute everywhere!

2013-08-24 Thread Jeffrey Walton
Hi Stefan, > ... administrative rights for every user account Hmmm... XP/x64 appears to have a bug such that the second user also needs to be admin (perhaps XP/x86, too). XP does not recognize the first account as admin, so the second account cannot be limited (at least on my test box). Vista and

[Full-disclosure] Defense in depth -- the Microsoft way (part 8): execute everywhere!

2013-08-24 Thread Stefan Kanthak
Hi, since it's start about 20 years ago Windows NT supports (fine grained) ACLs, including the permission "execute file". In their very finite wisdom Microsoft but decided back then to have this permission set on EVERY file a user creates (and assumes it is set on local and remote file systems wh

Re: [Full-disclosure] [DAHAX-2013-001] Cloudflare XSS Vulnerability

2013-08-24 Thread jonathan schatz
On Aug 23, 2013, at 1:48 AM, Bart van Tuil wrote: > Is it just me, or does it seem that **any** way to change the browser > headers requires a degree of control that is same as, or higher than, > the one we're trying to get? > > I am sure there are a lot of ways (flash, javascript, objects) to

[Full-disclosure] CVE-2013-2192: Apache Hadoop Man in the Middle Vulnerability

2013-08-24 Thread Aaron T. Myers
Hello, Please see below for the official announcement of a serious security vulnerability which has been discovered and subsequently fixed in Apache Hadoop releases. Best, Aaron -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-2192: Apache Hadoop Man in the Middle Vulnerability Severity:

[Full-disclosure] CVE-2013-2193: Apache HBase Man in the Middle Vulnerability

2013-08-24 Thread Aaron T. Myers
Hello, Please see below for the official announcement of a serious security vulnerability which has been discovered and subsequently fixed in Apache HBase releases. Best, Aaron -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 CVE-2013-2193: Apache HBase Man in the Middle Vulnerability Severity: S