[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

Re: [cobalt-users] OT brief note on: CERT AdvisoryCA-2003-25Buffer Overflow in Sendmail



my .02

If you don't trust us Europeans, doesn't that cause you problems ?

you don't understand the concept... i have no problem with Europeans. if it helps change it to "I can't trust some guy (I think) living in the "south
pole" (I think) (in a red suit)

at least with zeffie. i know i can call at 5 am and he answers the phone :) hell, it even works in the reverse directory of the white pages.

it's an issue... it's often very easy to backdoor software... I even built a su program that sends the ip and passwd away in the mail for the next time the /bin/su dialog comes around... it took about an hour. If you give root to people you don't know your just asking to be part of a huge attack...
Thats my feeling these days...

if you're a host using a colo center, you should consider reading your TOS agreement before you install patches from anywhere. what kind of restrictions do they have on spamming and malicious use of the network. could you be liable for the actions of an un-official patch?

lets face it, not all of us are housekeepers working on these machines. there are people with bad intentions on the web. that's all this is about. fact is, i have never known anyone else who posts to the list, that has been able to repair a broken raq gui like zeffie. that alone signals, in my book anyway, the benefit of the doubt and then some.

nobody is here because they're using their raq as a charity service. i'm just telling it as i see it.

hope all is well with you list folks,
grant

--
I never did give them hell. I just told the truth, and they thought it was hell. Harry S Truman