Re: [Fwd: Re: Cross-Site Request Forgeries (Re: The Dangers of Allowing Users to Post Images)]

2001-06-19 Thread Lincoln Yeoh
Re: images in html email. It's not just images. There are other tags - embed, etc. And if Microsoft Word becomes very intertwined with IE (word uses IE to fetch stuff) then word documents with image/object links will also be an issue. Mix well and add a few macros to taste ;). Cheerio, Link.

Re: The Dangers of Allowing Users to Post Images (fwd)

2001-06-16 Thread Lincoln Yeoh
At 10:29 AM 6/15/01 -0400, Shafik Yaghmour wrote: Yeah this is kind'a old if you have been developing sites for a while, you also need to consider that someone can also do this off the site as well. So if they have the ability to link to a site from your site they can get people to go to

Re: Raptor 6.5 http vulnerability (fwd)

2001-03-27 Thread Lincoln Yeoh
At 10:16 PM 27-03-2001 +1000, Peter Robinson wrote: Most http Proxy solutions (including squid and fw1) do this unless you specify otherwise. If you don't know what your doing... you don't know what your doing!!. Don't blame the software. This is NOT a bug, just a feature .. Often you want

Re: Loopback and multi-homed routing flaw in TCP/IP stack.

2001-03-07 Thread Lincoln Yeoh
At 08:18 PM 06-03-2001 -, David Litchfield wrote: This affects Windows NT as well. I spoke of the exact same problem back in the December of 1998 (http://www.securityfocus.com/vdb/bottom.html?vid=1692 for the BID and http://oliver.efri.hr/~crv/security/bugs/NT/msproxy3.html for the details)

Re: Security information for dollars?

2001-02-03 Thread Lincoln Yeoh
At 07:06 AM 2/2/01 -0600, Shalon Wood wrote: Cooper [EMAIL PROTECTED] writes: Now, could someone explain to me why a select list of individuals should get an earlier warning? I think this is the crux of the matter. Before you can say that this is a good idea, you first have to show that some