Re: [Full-disclosure] DNS and NAT (was: DNS and CheckPoint)

2008-07-11 Thread Riad S. Wahby
[EMAIL PROTECTED] wrote: > With 64K source ports, you'll have collisions over 1% of the time at only 1024 > in use. With 8K in use, you're hitting collisions 12% of the time. Good point. When collisions occur, as Thomas and I have pointed out, the behavior of the NAT implementation is going to be

Re: [Full-disclosure] DNS and NAT (was: DNS and CheckPoint)

2008-07-10 Thread Riad S. Wahby
Thomas Cross <[EMAIL PROTECTED]> wrote: >We've also been wondering whether NAT devices ought to randomly assign >UDP source ports, although no NAT vendor that wea**re aware of has done >this to date. Some quick testing implies that ipchains MASQUERADE-based NAT doesn't suffer this prob

Re: [Full-disclosure] Linux + bash and a silver fork

2007-08-27 Thread Riad S. Wahby
Niko Lilja <[EMAIL PROTECTED]> wrote: >:() { :&:; } ;: I've had that on a t-shirt and hat for years. (Actually, I think I gave the hat to my now-ex-girlfriend.) This isn't new, nor is its solution, viz., a sane ulimit policy. -=rsw ___ Full-Discl

Re: [Full-disclosure] 18th anniversary of Internet worm a.k.a. Morris worm

2006-11-02 Thread Riad S. Wahby
"morrisworm.com" <[EMAIL PROTECTED]> wrote: > Exactly 18 years ago the concept of buffer overflows and worms were > brought to the public and the internet saw its first great panic. ...and one week ago, Robert Morris got tenure at MIT. Congrats, RTM. -- Riad S.

[Full-disclosure] Re: A Move to Remove

2006-03-31 Thread Riad S. Wahby
r the security industry is in such a sad state. Please, go ahead and vote in broadcast to the list. At least then those interested in free discourse will know which ones of you to blacklist. -- Riad S. Wahby [EMAIL PROTECTED] ___ Full-Disclosure - We

[Full-disclosure] Re: Fwd: FAQ: How to subscribe and or contribute to cypherpunks

2006-02-27 Thread Riad S. Wahby
s basically the same setup that LNE did. -- Riad S. Wahby [EMAIL PROTECTED] ___ Full-Disclosure - We believe in it. Charter: http://lists.grok.org.uk/full-disclosure-charter.html Hosted and sponsored by Secunia - http://secunia.com/