Re: One more 3Com SNMP vulnerability

1999-09-03 Thread Peter Hicks
Hi there I'm running version 3.17 firmware on the SSII Hub 10's here, and the securityUserTable is only visible if you use a read-write community string. Peter. - Original Message - From: Nerijus Krukauskas [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: 30 August 1999 14:43 Subject:

Re: ProFTPD

1999-09-03 Thread pb
Hi, Note that user takes the value "user@host" given at password prompt for anonymous access (forgetting any potential dns attacks into remhost) This allows anyone to smash the stack just with an anonymous access and a file to download. (see last published exploits.) Regards, Pascal On Mon, Aug

Re: [Fwd: ISS Security Advisory: Buffer Overflow in Netscape Enterprise and FastTrack Web Servers]

1999-09-03 Thread Jason Axley
Just to keep y'all updated, and to summarize what's known so far: 1) The ISS advisory sucks (no details, didn't mention that it was NT-only or that Solaris wasn't vulnerable, they supposedly worked with Netscape on this, but don't have more specific info about which platforms/versions are

Re: Vixie Cron version 3.0pl1 vulnerable to root exploit

1999-09-03 Thread Valentin Nechayev
Martin Schulze [EMAIL PROTECTED] wrote: Red Hat has recently released a Security Advisory (RHSA-1999:030-01) covering a reverse denial of service bug in the vixie cron package. As user you could restart sendmail even if the host should not receive mail through the SMTP port. Further

Re: Cisco and Nmap Dos

1999-09-03 Thread Lancashire, Andrew
Travis, Thanks for the response, we are running 11.2. I would also agree with the allocation of memory issues that you mention. One other note, it was told to me yesterday a 2500 series in the same time frame over 5 hops away had the same problem. Although this router has much less mem (4Meg)