RE: [lists] [Full-Disclosure] Novell/Ximian Evolution multiple text attachmentsDoS

2005-02-26 Thread Roman Drahtmueller
> > I just wanted to inform users of Ximian Evolution 2.0 > > software that there exists a way to temporarily DoS the local > > application and/or machine by attaching an absurd amount of > > .ezm files to a normal email. > > > It seems to me that it would take an attacker more time to create

Re: [Full-Disclosure] Microsoft laxed security is threat to internet

2004-07-09 Thread Roman Drahtmueller
[...] > How much of a percentage of discussion and disclosure on this list is > actually counter acting script kiddie hood and how much is actually > aiding them to carry out further malicious activities across the > internet on a global scale? [...] nearly 100%, because if it is not this forum, i

[Full-Disclosure] SUSE Security Announcement: kernel (SUSE-SA:2004:020)

2004-07-02 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SUSE Security Announcement Package:kernel Announcement-ID:SUSE-SA:2004:020 Date: Tuesday, Ju

[Full-Disclosure] SUSE Security Announcement: Live CD 9.1 (SuSE-SA:2004:011)

2004-05-06 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:Live CD 9.1 Announcement-ID:SuSE-SA:2004:011 Date: Thursd

[Full-Disclosure] SUSE Security Announcement: kernel (SuSE-SA:2004:010)

2004-05-03 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SUSE Security Announcement Package:Linux Kernel Announcement-ID:SuSE-SA:2004:010 Date: Tuesd

Re: [Full-Disclosure] The new Microsoft math: 1 patch for 14 vulnerabilities, MS04-011

2004-04-14 Thread Roman Drahtmueller
> > I use Linux, OpenBSD and Windows in my enterprise. Linux and OpenBSD use > the "1 patch for 1 vulnerability" rule. Seems to me that MS is bunching > their patches together in order to make it seem on the surface that Windows > has less patches than other Oses, therefore it is more secure.

Re: [Full-Disclosure] Re: [ GLSA 200402-02 ] XFree86 Font Information File Buffer Overflow

2004-02-12 Thread Roman Drahtmueller
> i copy paste the wrong lines. if logged in on the console > i get a segfault. using ssh i get: > > [EMAIL PROTECTED] evert]$ X :0 -fp $PWD > Authentication failed - cannot start X server. > Perhaps you do not have console ownership? > [EMAIL PROTECTED] evert]$ > > so my real question was... is

[Full-Disclosure] SUSE Security Announcement: gpg (SuSE-SA:2003:048)

2003-12-03 Thread Roman Drahtmueller
YFAjseYcMACgkQnkDjEAAKq6ROVACgjhDM /3KM+iFjs5QXsnd4oFPOnbkAnjYGa1J3em+bmV2aiCdYXdOuGn4ZiQCVAwUQN7c7 whaQN/7O/JIVAQEB+QP/cYblSAmPXxSFiaHWB+MiUNw8B6ozBLK0QcMQ2YcL6+Vl D+nSZP20+Ja2nfiKjnibCv5ss83yXoHkYk2Rsa8foz6Y7tHwuPiccvqnIC/c9Cvz dbIsdxpfsi0qWPfvX/jLMpXqqnPjdIZErgxpwujas1n9016PuXA8K3MJwVjCqSKI Rg

Re: [Full-Disclosure] [SECURITY] [DSA-403-1] userland can access Linux kernel memory

2003-12-02 Thread Roman Drahtmueller
Hello Florian, > > > Recently multiple servers of the Debian project were compromised using a > > Debian developers account and an unknown root exploit. Forensics > > revealed a burneye encrypted exploit. Robert van der Meulen managed to > > decrypt the binary which revealed a kernel exploit. Stu

[Full-Disclosure] SuSE Security Announcement: sendmail, sendmail-tls (SuSE-SA:2003:040)

2003-09-20 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:sendmail, sendmail-tls Announcement-ID:SuSE-SA:2003:040 Date:

[Full-Disclosure] SuSE Security Announcement: openssh (second release) (SuSE-SA:2003:039)

2003-09-18 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:openssh (second release) Announcement-ID:SuSE-SA:2003:039 Date:

[Full-Disclosure] SuSE Security Announcement: openssh (SuSE-SA:2003:038)

2003-09-16 Thread Roman Drahtmueller
SMZLh8yv/QReG9heyGDPyaIyWmdd/YDkytNhNfZBwat+9um3h2C1J5wvy/Fy+8 Brhx2isXTacKTwW7jMc7SKFzNKpZOHq8E9kFnuxx4SnVOzMtzjvKV6H/Olt8qD/m fesjbYvBUNst7yjuG/SaNLf2rGrfDq7o8NbeVzsyiZVTuFU0MqE7qA== =/eES -END PGP SIGNATURE- Roman Drahtmueller, SuSE Security. ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

[Full-Disclosure] SuSE Security Announcement: wuftpd (SuSE-SA:2003:032)

2003-07-31 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:wuftpd Announcement-ID:SuSE-SA:2003:032 Date: Thursday, J

[Full-Disclosure] SuSE Security Announcement: sendmail (SuSE-SA:2003:023)

2003-04-01 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:sendmail, sendmail-tls Announcement-ID:SuSE-SA:2003:023 Date:

[Full-Disclosure] SuSE Security Announcement: kernel (SuSE-SA:2003:021)

2003-03-25 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:kernel Announcement-ID:SuSE-SA:2003:021 Date: Tuesday, Ma

[Full-Disclosure] SuSE Security Announcement: sendmail (SuSE-SA:2003:013)

2003-03-03 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:sendmail, sendmail-tls Announcement-ID:SuSE-SA:2003:013 Date:

[Full-Disclosure] SuSE Security Announcement: openssl (SuSE-SA:2003:011)

2003-02-26 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:openssl Announcement-ID:SuSE-SA:2003:011 Date: Wednesday,

[Full-Disclosure] SuSE Security Announcement: samba (SuSE-SA:2002:045)

2002-11-20 Thread Roman Drahtmueller
-BEGIN PGP SIGNED MESSAGE- __ SuSE Security Announcement Package:samba Announcement-ID:SuSE-SA:2002:045 Date: Wednesday, N

[Full-Disclosure] Re: FWD: Re: Off Topic

2002-09-11 Thread Roman Drahtmueller
How Warmongers Exploit 9/11 by Norm Dixon In the week before the first anniversary of the devastating September 11, 2001, terrorist attacks in New York and Washington, TV networks aired a seemingly never-ending string of ``special events'' featuring ``exclusive'' or ``never before seen'' foot

Re: [Full-Disclosure] Full disclosure?

2002-09-11 Thread Roman Drahtmueller
> > Let's see if this makes it through to the list. > > I can confirm that at least one post to the list has been deleted > (mine), so, so much for full disclosure. It was a nice thought while it > lasted ...not so fast. There are many reasons why a posting didn't make it to the list. Len R