Re: ProFTPD

1999-09-01 Thread Daniel Jacobowitz
uple other places in ProFTPd which strike me as, if not insecure, at least insufficiently paranoid; I'll pass along a patch for those to proftpd-l later. Dan /\ /\ | Daniel Jacobowitz|__|SCS Class of 2002 |

Re: ssh-1.2.27 remote buffer overflow - exploitable (VD#7)

1999-11-17 Thread Daniel Jacobowitz
d with --with-rsaref, and the guilty code in rsaglue.c is never reached. Dan /\ /--------\ | Daniel Jacobowitz|__|SCS Class of 2002 | | Debian GNU/Linux Developer__Carnegie Mellon University | |

Re: String vun. in m4 macro processor (same as in man)

2001-02-02 Thread Daniel Jacobowitz
isn't setuid, and anyone who allows arbitrary filenames to be passed to it has other problems. Dan /\ /\ | Daniel Jacobowitz|__|SCS Class of 2002 | | Debian GNU/Linux Developer__Carnegie Mellon

Re: smbd remote file creation vulnerability

2001-07-03 Thread Daniel Jacobowitz
aren't allowed make a dummy account first, login with that then make a toor account ontop of that and su over to toor. Remember, the log path must be within 15 characters to fit in a netbios name! You're not going to get anywhere on andrew, or most other AFS paths, with that restriction. -- Daniel