Re: [Full-Disclosure] SRT2003-05-08-1137 - ListProc mailing listULISTPROC_UMASK overflow

2003-05-09 Thread KF
Shawn McMahon wrote: On Thu, May 08, 2003 at 12:15:41PM -0500, KF said: not on hand to thoroughly test the fix. SecNetOps did not have the facilities to compile the new version of catmail in efforts to test the fix on our own. The problem appeared to be caused by a series of strcat() Huh

Re: [Full-Disclosure] Hotmail & Passport (.NET Accounts)

2003-05-09 Thread Ron DuFresne
May 08, Associated Press Microsoft admits Passport was vulnerable. Computer researcher Muhammad Faisal Rauf Danka of Pakistan discovered how to breach Microsoft Corp.'s security procedures for its Internet Passport service. The service is designed to protect customers visiting some retail Web site

Re: [Full-Disclosure] PGP vs. certificate from Verisign

2003-05-09 Thread Shawn McMahon
On Fri, May 09, 2003 at 02:57:44PM -0400, [EMAIL PROTECTED] said: > > (Personally, I use PGP because the whole IETF/NANOG/security community is > fairly small and closed (perhaps 10K people, tops?), and PGP is a better fit > than X.509, which is which is designed for hundreds of millions of users

Re: [Full-Disclosure] Multiple Vulnerabilities found in Microsoft .Net Passport Services

2003-05-09 Thread Valdis . Kletnieks
On Thu, 08 May 2003 18:57:04 +1000, Steven Evans said: > Please, can you wait until microsoft fixes your 'vulnerabilities' before you > post. Well.. it's interesting.. Vulnerability number 2 (password reset) was apparently closed down within an hour once it hit full-disclosure. Mind you, that'

RE: [Full-Disclosure] Hotmail & Passport (.NET Accounts) Vulnerability

2003-05-09 Thread David Vincent
what's-his-name said... "Is it me or ms never credit vulnerabilities according to http://www.microsoft.com/security/passport_issue.asp "a report was published detailing a security vulnerability(...)"? No more details or credit." ...and then asserted... "I also saw online news like http://www.vn

[Full-Disclosure] Firebird local root compromise

2003-05-09 Thread bob
-[[Dtors Security Research]]--[[ www.dtors.net ]]-   -[Package: Firebird_1.0.2 [FreeBSD]-[Versions Affected: 1.0.2 <-[Website: http://firebird.sf.net-[Exploit: Local Stack Overflow-[Date: 22/03/2003-[Author: [EMAIL PROTECTED] && [EMAIL PROTECTED]   ---[BACKGROUND   Firebird is a rela