Re: SuSe / Debian man package format string vulnerability

2001-02-05 Thread Seth Arnold
* Darren Moffat [EMAIL PROTECTED] [010205 19:24]: Exactly what is it that man MUST do to perform the job of turning nroff man pages into viewable text ? It is setuid some user in order to store pre-formatted manpages around, so that future invocations do not have to format the manpage. It is

Re: URGENT SECURITY ADVISORY FOR SSH SECURE SHELL 3.0.0

2001-07-24 Thread Seth Arnold
On Mon, Jul 23, 2001 at 03:17:26PM -0400, Sports wrote: What about 2.9? A quick glance at the source code suggests that SSH 2.3.0 and 2.4.0 have the same problem. Is this true? You've fallen pray to the 'product problem'. 2.9 is OpenSSH. 2.3.0, 2.4.0, and 3.0 are ssh.com. This problem is

Re: A technique to mitigate cookie-stealing XSS attacks

2002-11-14 Thread Seth Arnold
On Sun, Nov 10, 2002 at 04:21:41AM +0100, Ulf Harnhammar wrote: On Thu, 7 Nov 2002, Justin King wrote: I would be very interested in major browsers supporting a dead tag with an optional parameter to be a hash of the data between the opening and closing dead tag. This tag would indicate