Re: [Full-Disclosure] Administrivia: List Compromised due to Mailman Vulnerability

From: Steve Blass (sblass_at_asu.edu)
Date: 02/09/05

  • Next message: Dominic Hargreaves: "[Full-Disclosure] [FLSA-2005:1943] Updated libpng resolves security vulnerabilities"
    Date: Wed, 09 Feb 2005 12:45:19 -0700
    To: full-disclosure@lists.netsys.com
    
    

    John Cartwright wrote:

    >...
    >
    >Subscriber addresses and passwords have been compromised.
    >
    d'0h!

    >...
    >
    >SLASH = '/'
    >
    >def true_path(path):
    > "Ensure that the path is safe by removing .."
    > parts = [x for x in path.split(SLASH) if x not in ('.', '..')]
    > return SLASH.join(parts)[1:]
    >
    >
    >
    That's an improvement, but better is to extract and validate the tail of
    the path to your repository and then anchor the root where it belongs.

    Fully disclosing that FD was compromised was a stand up thing to do
    though. Good job!

    -
    Steve

    _______________________________________________
    Full-Disclosure - We believe in it.
    Charter: http://lists.netsys.com/full-disclosure-charter.html


  • Next message: Dominic Hargreaves: "[Full-Disclosure] [FLSA-2005:1943] Updated libpng resolves security vulnerabilities"

    Relevant Pages

    • Re: VB6 & Active Directory
      ... understood him to want to validate a given username + password pair inside ... Kerberos does not pass passwords across the network, ... uses a "double-encryption technique" to verify ... Security is provided by security providers such as Kerberos. ...
      (microsoft.public.vb.general.discussion)
    • Re: Windows Password Validation
      ... Once set these passwords were correctly authenticated with ... I have a VB 6 routine to validate users' passwords before allowing them ... : Tony Spratt. ...
      (microsoft.public.vb.winapi)
    • Re: Text function MID, RIGHT, LEN
      ... Validate with Sfift+Ctrl+enterr ... I try to extract part of a text: ... SAVANNAH CHARD FLO-FAIRTRADE BIB, 200 CL ... Someone who now how I can fix this? ...
      (microsoft.public.excel.misc)
    • Re: Importing passwords
      ... Passwords can be scripted from files. ... The difficult part is to EXTRACT a password, ... which requires something like ADMTv2 or a ... third party tool if you are extracting passwords ...
      (microsoft.public.windows.server.migration)
    • Re: network passwords
      ... I'm about to re-instal XP as it is running very slowly, but I need to extract my passwords, particularly for my home network connection. ... If you have forgotten where you posted or can't find your post, use Google Groups Advanced Search and search for your name. ...
      (microsoft.public.windowsxp.network_web)