Re: [Full-Disclosure] Windoze almost managed to 200x repeat 9/11

2004-09-25 Thread Troy
thing about this is that the FAA and the developers of the app knew about the problem for quite some time, knew what the problem was, and, rather than fix the code, they just rebooted the system to work around it and ignored the main problem. -- Troy

Re: [Full-Disclosure] Viral infection via Serial Cable

2004-08-31 Thread Troy
drift. You have to start from finding out what's on the machines, and how they communicate. Once you know what you have, you can make a risk analysis of the situation. Troy On Mon, 30 Aug 2004 19:35:25 +0200, Jean Gruneberg [EMAIL PROTECTED] wrote: Hi all OK - here

[Full-Disclosure] Re: Anyone know IBM's security address?

2004-08-06 Thread troy
Quoting Michael Scheidell ([EMAIL PROTECTED]): sent alert to [EMAIL PROTECTED] [EMAIL PROTECTED] and [EMAIL PROTECTED], all three bounced. Can anyone tell me the official address or procedure to notify IBM? Try [EMAIL PROTECTED] -- Troy Bollinger [EMAIL PROTECTED] Network Security Analyst

Re: [Full-Disclosure] MD5 hash cracking service

2004-07-02 Thread Troy
if the timestamp is the same. If the system requires accurate time, then the acquired md5sum is only useful in the sense that you can theoretically break it by going through all possible combinations for the text. Troy Troy KorjuslommiTksoft Inc. [EMAIL PROTECTED] G

Re: [Full-Disclosure] FD should block attachments

2004-04-03 Thread Troy
days or less. On any other list, I would agree. If this were Usenet, I'd agree. However, Full Disclosure, by its very nature, needs to be unmoderated and unfiltered. That's what makes this list unique. -- Troy ___ Full-Disclosure - We believe

Re: [Full-Disclosure] E-mail virus free tags (Was: SHUT THE F**K UP)

2004-03-26 Thread Troy
to append a message to outgoing mail is for marketing purposes. It gets their product name out there. -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] viruses being sent to this list

2004-03-23 Thread Troy
would be to block all attachments, but that will, once again, take away what makes this list unique. -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] viruses being sent to this list

2004-03-23 Thread Troy
to filter out worms for you, you're lulling yourself into a false sense of security, which is worse than no security at all. -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] NEVER open attachments

2004-03-21 Thread Troy
. -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] NEVER open attachments

2004-03-21 Thread Troy
far that mishandles signatures like that. many persons find that repugnant While this is true, I was addressing somebody using OE, so mentioning Outlook is probably safe. :) -- Troy ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-Disclosure] NEVER open attachments

2004-03-20 Thread Troy
with an attached signature file, so it's no problem for me if you sign them. I usually ignore the signature but, if I need to verify a message, I can pull the attachment out for verification. -- Troy ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-Disclosure] NEVER open attachments

2004-03-20 Thread Troy
, but that's how it sounds. Nobody is forcing you to open attachments. If you are unable to switch to an email client that handles in-line signatures correctly, then don't read their messages. If you don't want to switch to Outlook, try Becky. http://www.rimarts.co.jp -- Troy

Re: [Full-Disclosure] Re: MS Security Response is a bunch of half-witted morons

2004-03-15 Thread Troy
on it, right? :) -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] Re: MS Security Response is a bunch of half-witted morons

2004-03-12 Thread Troy
JavaScript disabled for security reasons, regardless of their version of IE. I agree with Nick. It is ironic and unfortunate that MS would force users to turn on a potentially unsafe scripting language to read a security bulletin. -- Troy ___ Full-Disclosure

Re: A new look at PGP (WAS: Re: [Full-Disclosure] OpenPGP (GnuPG) vs. S/MIME)

2004-02-27 Thread Troy Solo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 In my opinion, it would be too easy to create false Webs of Trust through something like Orkut. I personally have people on my friends list that I've never actually met in person. /**/ /* Troy Solo*/ /* [EMAIL

Re: [Full-Disclosure] Re: Knocking Microsoft

2004-02-27 Thread Troy Solo
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Last time I checked, Windows Update didn't upgrade third-party software like apt does. /**/ /* Troy Solo*/ /* [EMAIL PROTECTED] */ /* Ignotum per Ignotius */ /**/ James F. Wilkus

Re: [Full-Disclosure] TinyURL

2003-10-29 Thread Troy
credit card numbers. Still, they should have a warning on their site. After all, curling irons have warnings not to insert them into any orifice. :) -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure

Re: [Full-Disclosure] TinyURL

2003-10-29 Thread Troy
, it wouldn't take much code to have it look at the URL, decide it if probably contains sensitive information, and make the user confirm that they still want to use the service. -- Troy ___ Full-Disclosure - We believe in it. Charter: http

Re: [Full-Disclosure] GUNINSKI THE SELF-PROMOTER

2003-07-20 Thread Troy Solo
? --- /**/ /* Troy Solo*/ /* [EMAIL PROTECTED] */ /* Ignotum per Ignotius */ /**/ ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html

Re: [Full-Disclosure] Re: Participation in System Administrator Survey

2003-07-16 Thread Troy
] and everyone else on another private list, I misunderstood and assumed that meant he spammed the list, which others apparently also did. Now that I've gone back and re-read your message, it's clear, but it was easy to mis-read, especially since I was just skimming through this thread. -- Troy

Re: [Full-Disclosure] The incredible intolerance of Knud

2003-07-11 Thread Troy
this one? http://www.rimarts.co.jp/becky.htm One of features of the Becky email client is the ability to take an incoming HTML message and display *only* the text from that message. The best thing is that this feature is *on* by default. -- Troy ___ Full

Re: [Full-Disclosure] Internet Explorer 6 DoS Bug

2003-07-07 Thread Troy
language version of XP and/or IE you use? A coworker reproduced it under English XP. However, it's a pretty much fresh install of XP. The IE build IE 6.0.2600..xpclient.010817-1148. Maybe it was fixed in a hotfix that hasn't been translated yet. -- Troy

Re: [Full-Disclosure] Adminstrivia: Digest Limits/Netiquette

2003-06-27 Thread Troy
the footer, you've most likely taken the time to trim anything not relevant to your response. -- Troy ___ Full-Disclosure - We believe in it. Charter: http://lists.netsys.com/full-disclosure-charter.html