Re: [Full-Disclosure] Re: HTML Help API - Privilege Escalation

Valdis.Kletnieks_at_vt.edu
Date: 10/24/03

  • Next message: Joshua Levitsky: "[Full-Disclosure] Symantec AntiVirus and AOL"
    To: killedbythoughts@mindcrime.net
    Date: Fri, 24 Oct 2003 16:41:45 -0400
    
    
    

    On Fri, 24 Oct 2003 20:08:24 +0200, Sebastian Niehaus <killedbythoughts@mindcrime.net> said:

    > Well, if you have a programm to be run in suid mode, every Unix admin
    > should be alerted. They are used to review the source code of this
    > kind of stuff.

    When was the last time you audited the source for 'ping' or 'traceroute'?

    Is there *anybody* qualified to do an audit of /usr/X11R6/bin/XFree86?

    
    

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html



  • Next message: Joshua Levitsky: "[Full-Disclosure] Symantec AntiVirus and AOL"

    Relevant Pages

    • Re: New version of Truecrypt released (6.1a)
      ... ..thus failing nemo_outis's requirement of "source code that is known ... to have had a thorough review by competent people." ... Truecrypt's source code not having had thorough competent ... independent review. ...
      (alt.privacy)
    • Re: Rules for constructors
      ... Normally I review code made by a group of developers ... of TeX and we have a Pascal compiler that does not recognize ... the Gosling-Emacs editor as our normal environment. ... to review/analize/change source code programs made by other people... ...
      (comp.lang.java.programmer)
    • RE: [Full-Disclosure] Exclusive: Windows 2000 & Windows NT 4 Source Code Leaks
      ... Subject: [Full-Disclosure] Exclusive: Windows 2000 & Windows NT 4 Source Code Leaks ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • RE: [Full-Disclosure] Re: W2K source "leaked"?
      ... Subject: [Full-Disclosure] Re: W2K source "leaked"? ... Again, I don't know/care if this is true of MS' source code being posted, ... Charter: http://lists.netsys.com/full-disclosure-charter.html ...
      (Full-Disclosure)
    • VS.NET Add-In AppDomain Problem
      ... to review the source code currently loaded into the IDE for coding standards ... into an in-memory assembly at review time. ... reviews source code in a secondary AppDomain so that the whole AppDomain can ... the review had finished and although VS.NET did not unload, ...
      (microsoft.public.dotnet.framework.remoting)

  • Quantcast