Verified PIX vulnerability to FTP-Pasv attack.

2000-03-20 Thread monti
are also subject to manipulation. Please see the credits in the attached message. Eric Monti Denmac Systems [EMAIL PROTECTED] [EMAIL PROTECTED] 847.291.7760 Summary: I confirmed and did some more research regarding the PIX hole mentioned by Jacek Lipkowski on bugtraq entitled: Re

Re: snmp problems still alive...

2000-03-14 Thread monti
, and have had to live with simply assigning very very long random strings for the community in many implementations. Eric Monti Denmac Systems [EMAIL PROTECTED] [EMAIL PROTECTED] On Fri, 10 Mar 2000, Damir Rajnovic wrote: Hello, Not so long ago there was discussion on this list regarding

Re: FireWall-1 FTP Server Vulnerability

2000-02-18 Thread monti
On Wed, 16 Feb 2000, Borbely Zoltan wrote: On Mon, Feb 14, 2000 at 07:32:54PM -0600, monti wrote: [...snip...] First watch for: client - ftp-server "PASV" which triggers the firewall to look for this immediately afterwards: client - ftp-server "227 Entering Passive Mo

Re: Amanda multiple vendor local root compromises

1999-11-01 Thread monti
hi, I confirmed a few exploitable buffer overflows in multiple suid's on an earlier version of amanda on BSDI as well a while back. As I recollect 'runtar' was one of them. I apologize that I cant provide anything more specific than this, but it was some time ago and I misplace my notes on it.