Re: [Full-Disclosure] Re: Cisco's stolen code

2004-05-26 Thread Benjamin Krueger
whistleblower legislation, such as the Sarbanes-Oxley Act? -- Benjamin Krueger Give me ambiguity, or give me something else! ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: Linux (in)security (Was: Re: [Full-Disclosure] Re: No Subject)

2003-10-24 Thread Benjamin Krueger
Community Of People Who Know What They're Doing. Thousands of little typical unix sysadmins running around without a clue... -- Benjamin Krueger Confidence is the mother of success. Cockyness is a mother of a time bomb. ___ Full-Disclosure - We believe

Re: [Full-Disclosure] No Subject (re: openssh exploit code?)

2003-10-21 Thread Benjamin Krueger
goes out. Maybe that's acceptable for whatever business you work in. Some of us cannot afford to diddle around with vague warnings and security patches we cannot even verify, much less a constant stream of downtimes which may or may not be necessary. -- Benjamin Krueger Confidence is the mother

Re: [Full-Disclosure] Foundstone Labs to Present Information on New Microsoft Vulnerabilities

2003-10-16 Thread Benjamin Krueger
on it, but it is not ok for a corporation to do the same? Since when were the people who discover a vulnerability given exclusive rights to further research that vulnerability? -- Benjamin Krueger Nothing disables a giant space monkey quicker than an atomic wedgie

Re: [Full-Disclosure] Weak response from RH

2003-10-09 Thread Benjamin Krueger
that they obviously believe has been sufficiently mitigated? -- Benjamin Krueger Nothing disables a giant space monkey quicker than an atomic wedgie ps. Condescension. How does a request for users to refrain from fooling with the web form constitute condescension

Re: [Full-Disclosure] Microsoft urging users to buy Harware Firew alls

2003-08-14 Thread Benjamin Krueger
* Richard M. Smith ([EMAIL PROTECTED]) [030814 00:27]: A Kia Sephia still comes with seatbelts and airbags even though it doesn't have a DVD player. Cable and DSL modems need to come with built-in firewalls for the same reason. However it's pretty clear that home cable modems are going to

Re: [Full-Disclosure] Re: improper scan abuse

2003-04-04 Thread Benjamin Krueger
be used to relay spam. Like it or not, spammers use open proxies for their dirty deeds and that makes these ports very relevant to email transactions. This practice is becoming more common, so I would suggest making provisions for it in your firewall logging and/or reporting. -- Benjamin Krueger