[SECURITY] [DSA 276-1] New Linux kernel packages (s390) fix local root exploit

2003-04-03 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 276-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze April 3rd, 2003

[SECURITY] [DSA 277-1] New apcupsd packages fix remote root exploit

2003-04-03 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 277-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze April 3rd, 2003

Re: RES: removing portsentry routes

2003-04-03 Thread Thomas Ritter
Yes, iptables -F (and/or calling your firewall script if you have one). But don't forget to clean up /etc/hosts.deny from time to time, it can get very big if you switched TCP wrappers denial in portsentry. Thomas Ritter -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Why PHP is parsing not only .php

2003-04-03 Thread Yoss
Hello. Please, take a look at this: http://www.milc.com.pl/aa.php.txt Why PHP is parsing file with .php.txt extension? I think that is a security hole, because in easy way we can imagine that thereis php script that should allow to upload only .txt files. 99% of coders will check this with

Re: Why PHP is parsing not only .php

2003-04-03 Thread Bart-Jan Vrielink
On Thu, 2003-04-03 at 12:43, Yoss wrote: Why PHP is parsing file with .php.txt extension? I think that is a security hole, because in easy way we can imagine that thereis php script that should allow to upload only .txt files. 99% of coders will check this with /.+?\.txt$/ because this is

Re: Why PHP is parsing not only .php

2003-04-03 Thread Chris Francy
This is expected behaviour... Please see the secion about files with multiple extensions on the page http://httpd.apache.org/docs/mod/mod_mime.html#addencoding --- If more than one extension is given which maps onto the same type of meta-information, then the one to the right will be used. For

Re: [despammed] Re: Why PHP is parsing not only .php

2003-04-03 Thread Ed McMan
Thursday, April 3, 2003, 1:44:09 PM, Chris Francy (Chris) wrote: Chris This is expected behaviour... Please see the secion about files with Chris multiple extensions on the page Chris http://httpd.apache.org/docs/mod/mod_mime.html#addencoding Chris --- Chris If more than one extension is given

Re: H323 Gateways

2003-04-03 Thread funky soul
hi Daniel, On Wed, 2 Apr 2003 10:46:09 +0200 Jean-Francois Dive [EMAIL PROTECTED] wrote: a vpn between the 2 lans / clients yeah. try vpnd, it's easy. don't forget to allow and forward traffic from/to the vpn device (usually sl0). -- , , / \GNU's not Unix

Re: RES: removing portsentry routes

2003-04-03 Thread Thomas Ritter
Yes, iptables -F (and/or calling your firewall script if you have one). But don't forget to clean up /etc/hosts.deny from time to time, it can get very big if you switched TCP wrappers denial in portsentry. Thomas Ritter

Why PHP is parsing not only .php

2003-04-03 Thread Yoss
Hello. Please, take a look at this: http://www.milc.com.pl/aa.php.txt Why PHP is parsing file with .php.txt extension? I think that is a security hole, because in easy way we can imagine that thereis php script that should allow to upload only .txt files. 99% of coders will check this with

Re: Why PHP is parsing not only .php

2003-04-03 Thread Bart-Jan Vrielink
On Thu, 2003-04-03 at 12:43, Yoss wrote: Why PHP is parsing file with .php.txt extension? I think that is a security hole, because in easy way we can imagine that thereis php script that should allow to upload only .txt files. 99% of coders will check this with /.+?\.txt$/ because this is

Re: Why PHP is parsing not only .php

2003-04-03 Thread Chris Francy
This is expected behaviour... Please see the secion about files with multiple extensions on the page http://httpd.apache.org/docs/mod/mod_mime.html#addencoding --- If more than one extension is given which maps onto the same type of meta-information, then the one to the right will be used. For

Re: [despammed] Re: Why PHP is parsing not only .php

2003-04-03 Thread Ed McMan
Thursday, April 3, 2003, 1:44:09 PM, Chris Francy (Chris) wrote: Chris This is expected behaviour... Please see the secion about files with Chris multiple extensions on the page Chris http://httpd.apache.org/docs/mod/mod_mime.html#addencoding Chris --- Chris If more than one extension is given

Re: H323 Gateways

2003-04-03 Thread funky soul
hi Daniel, On Wed, 2 Apr 2003 10:46:09 +0200 Jean-Francois Dive [EMAIL PROTECTED] wrote: a vpn between the 2 lans / clients yeah. try vpnd, it's easy. don't forget to allow and forward traffic from/to the vpn device (usually sl0). -- , , / \GNU's not Unix