Re: wget: Arbitrary file overwriting/appending/creating and other vulnerabilities

2004-12-10 Thread Ulf Härnhammar
Quoting Jan Minar <[EMAIL PROTECTED]>: > (2) Use alternative retrieval programs, such as pavuk, axel, or > ncftpget. FWIW pavuk is much worse securitywise than wget. I've been working on patching pavuk for a few months, and it has lots of strcpy() and sprintf() calls that lead to buffer overflows

Re: keep-session-cookies

2004-12-10 Thread Nicolas Schodet
* Deryck Thake <[EMAIL PROTECTED]> [041125 20:01]: > Is the keep-session-cookies feature working for any wget 1.9.* on > Windows? I can see that the session cookie is saved in the cookies.txt > file but it does not appear to be used when I rerun wget with the the > load-cookies option. You muste u

Re: wget: Arbitrary file overwriting/appending/creating and other vulnerabilities

2004-12-10 Thread Greg Hurrell
El 09/12/2004, a las 10:14, Jan Minar escribió: (0) Wget authors are/were incompetent. Everything else is a corollary. That's a very aggressive stance to take, and not likely to be productive. Patches, for example, would be more productive. -- Mauro Tortonesi in a private mail exchange with me

Re: cookies protected site problem

2004-12-10 Thread Jean Francois Ortolo
On Thu, 9 Dec 2004, Jean Francois Ortolo wrote: Hi Sir <...> Best regards. Jean Francois Ortolo Hi Sir I present my apologies, the problem is solved now. In fact, there was only one session cookie, the only remaining problem being to properly choose the succession of urls to visit. I've

wget bug with large files

2004-12-10 Thread Roberto Sebastiano
I got a crash in wget downloading a large iso file (2,4 GB) newdeal:/pub/isos# wget -c ftp://ftp.belnet.be/linux/fedora/linux/core/3/i386/iso/FC3-i386-DVD.iso --09:22:17-- ftp://ftp.belnet.be/linux/fedora/linux/core/3/i386/iso/FC3-i386-DVD.iso => `FC3-i386-DVD.iso' Resolving ftp.belnet