Re: [Full-disclosure] Re: Linux kernel source archive vulnerable

2006-09-08 Thread Jurjen Oskam
a leading / from the archive? Much fun can be had when you carelessly extract as root, then. -- Jurjen Oskam Savage's Law of Expediency: You want it bad, you'll get it bad. ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full

Re: [Full-disclosure] Microsoft DNS resolver: deliberately sabotaged hosts-file lookup

2006-04-14 Thread Jurjen Oskam
? My guess is that it uses a default dns server from microsoft at a stable IP. Why guess when it takes all of 30 seconds to *see* what happens? I tried (using go.microsoft.com), and saw that it uses the same DNS server as the one being used for all other queries. -- Jurjen Oskam Savage's Law

Re: [Full-disclosure] Interesting idea for a covert channel or I justdidn't research enough?

2005-10-08 Thread Jurjen Oskam
configured, up-to-date SSH daemon. -- Jurjen Oskam ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/

Re: [Full-disclosure] Interesting idea for a covert channel or I just didn't research enough?

2005-10-06 Thread Jurjen Oskam
for a particular IP address. When you try to open a particular URL on my website, you get a 404 because that document doesn't exist. The webserver logs this. A script in the background sees in the log that this happened, and opens up port 22 to the IP address which requested the non-existant URL. -- Jurjen