Bugtraq: by author

194 messages starting Apr 10 98 and ending Apr 13 98
Date index | Thread index | Author index


Aaron Bornstein

Re: Sun rpcbind Aaron Bornstein (Apr 10)

Adam Shostack

Re: Article on writing secure software Adam Shostack (Apr 06)

Alan Cox

Linux 2.0.33 vulnerability: fragment patterns Alan Cox (Apr 16)
Re: New possible exploit for 2.0.33 (kfree_skb error) Alan Cox (Apr 15)
Qcam : Actually seems to be generic libqcam bug Alan Cox (Apr 20)
Linux 2.0.34pre10: Summary of fixed vulnerabilities Alan Cox (Apr 20)

Aleph One

[UPDATE] Security Contact Aleph One (Apr 03)
Re: scoterm exploit Aleph One (Apr 17)
IE EMBED Fix Aleph One (Apr 06)
HPSBUX9804-078 Security Vulnerability in Openmail on HP-UX Aleph One (Apr 29)
Sun Security Bulletin #00167 Aleph One (Apr 08)
Re: DOS: Teardrop mixed with a SYN - syndrop.c Aleph One (Apr 03)
RFC-1644 (fwd) Aleph One (Apr 06)
Sun Security Bulletin #00168 Aleph One (Apr 29)
CERT Vendor-Initiated Bulletin VB-98.04 - xterm.Xaw Aleph One (Apr 27)
CA-98.05 Multiple Vulnerabilities in BIND Aleph One (Apr 08)
SECURITY: procps 1.2.7 fixes security hole Aleph One (Apr 20)
Re: How to exploit mudge by AlephOne by JP AntiOnline Aleph One (Apr 24)
MacOS based buffer overflows... Aleph One (Apr 14)
Vendor Contacts Aleph One (Apr 01)

Andrew Lun

[Fwd: BSDI inetd crash] Andrew Lun (Apr 07)

Ariel Biener

Re: BSD coredumps follow symlinks Ariel Biener (Apr 06)

Avi Rubin

IEEE newsletter on Security & Privacy Avi Rubin (Apr 27)

BarKode

Flaw in HTTP-Authentication in O'Reilly Website Pro BarKode (Apr 23)

Bernd Johannes Wuebben

Re: Security hole in kppp Bernd Johannes Wuebben (Apr 29)

bluefish () SWIPNET SE

DOS: Teardrop mixed with a SYN - syndrop.c bluefish () SWIPNET SE (Apr 02)

Brian Krahmer

New IE4 bug w/Active Desktop installed Brian Krahmer (Apr 21)

Cacaio Torquato

hole in Inet Explorer Cacaio Torquato (Nov 04)

Carl Dunham

Re: APC UPS PowerChute PLUS exploit... Carl Dunham (Apr 21)

Casper Dik

Re: (Q) Sun Rpcbind problem. Casper Dik (Apr 10)
Re: wtmpx utility for solaris Casper Dik (Apr 01)

chameleon

Some Past Frontpage Exploits chameleon (Apr 26)

Chiaki Ishikawa

(Q) Sun Rpcbind problem. Chiaki Ishikawa (Apr 10)
(follow-up) Wietse's RPCBIND Chiaki Ishikawa (Apr 13)

Chris Evans

QuakeI client: serious holes. Chris Evans (Apr 07)
Re: QW server hole Chris Evans (Apr 07)
smbmount problem? Chris Evans (Apr 21)
Re: smbmount problem? Chris Evans (Apr 25)
QuakeI server serious hole (yawn) Chris Evans (Apr 06)

Chris Kline

Serv-U FTP Exploit? Chris Kline (Apr 29)

Chris Liljenstolpe - Network Engineer

Re: APC UPS PowerChute PLUS exploit... Chris Liljenstolpe - Network Engineer (Apr 12)

Chris Wedgwood

AppleShare IP Mail Server Chris Wedgwood (Apr 07)

Codex

nmap -U <host> undetectable by netranger v2.0 Codex (Apr 01)

Crispin Cowan

Re: [Fwd: CERT Advisory CA-98.05 - bind_problems] Crispin Cowan (Apr 09)

Czako Krisztian

Re: smbmount problem? Czako Krisztian (Apr 21)

Damian Kelly

Re: Geac ADVANCE library system security HOLE Damian Kelly (Apr 03)

Daniel Harris

FreeBSD + ircII + purepak.irc = reboot Daniel Harris (Apr 08)

Daragh Malone

Security Hole in Netscape Enterprise Server 3.0 Daragh Malone (Apr 24)

Darren Reed

HP printers revisted. Darren Reed (Apr 27)

David Jones

Vulnerability in HP OpenMail David Jones (Apr 21)

David LeBlanc

Re: Leveraging search engines against FrontPage enabled websites David LeBlanc (Apr 28)
Re: name of built-in administrator David LeBlanc (Apr 28)
Re: NT configuration caution David LeBlanc (Apr 21)
Re: name of built-in administrator David LeBlanc (Apr 28)
Re: NT configuration caution David LeBlanc (Apr 22)
Re: Some Past Frontpage Exploits David LeBlanc (Apr 27)
Re: NT configuration caution David LeBlanc (Apr 21)
Re: name of built-in administrator David LeBlanc (Apr 28)

David Luyer

Re: AppleShare IP Mail Server David Luyer (Apr 07)

Denis Papp

BSD coredumps follow symlinks Denis Papp (Mar 28)

der Mouse

Re: pine/pico vt control characters bug der Mouse (Apr 25)

DilDog

Update on Windows Buffer Overflow DilDog (Apr 17)
The Tao of Windows Buffer Overflow DilDog (Apr 16)

Dr. Mudge

How to exploit mudge by AlephOne by JP AntiOnline Dr. Mudge (Apr 24)

Erik Troan

SECURITY: lpr-0.31 now available Erik Troan (Apr 23)

Eugene Bradley

Re: Buffer overflows in Solaris 2.6 ufsdump and ufsrestore Eugene Bradley (Apr 23)

Evil Erik

Re: obsd boot hack (boot-modified-kernel-attack) Evil Erik (Apr 16)

F0RMiCA

How to exploit AlephOne by JP of AntiOnline F0RMiCA (Apr 24)

Fabrice Planchon

SGI O2 ipx security issue Fabrice Planchon (Apr 08)

Fernand Portela

Communicator exploits Fernand Portela (Apr 10)

frank darden

Leveraging search engines against Frontpage enabled servers frank darden (Apr 26)

FrontLine Assembly

Re: BSDI inetd crash FrontLine Assembly (Apr 08)

GAVRILIS DIMITR

Geac ADVANCE library system security HOLE GAVRILIS DIMITR (Apr 02)

George

NT configuration caution George (Apr 20)

Glenn F. Maynard

QW vulnerability Glenn F. Maynard (Apr 07)

Greg Alexander

Linux libc5.4.33 dumbness w/ mk[s]temp() Greg Alexander (Apr 11)

GvS One

feature Re: pine/pico vt control characters bug GvS One (Apr 25)

Hamdi Tounsi

code to crash radiusd Hamdi Tounsi (Apr 15)
code to crash cistron's radius Hamdi Tounsi (Apr 21)

Hank Leininger

Re: xdm problems Hank Leininger (Apr 19)

Harold Gutch

nestea.c, BSD-Port Harold Gutch (Apr 26)

Iain P.C. Moffat

Re: APC UPS PowerChute PLUS exploit... Iain P.C. Moffat (Apr 13)

J.A. Gutierrez

HP-UX glance bug (#4?) J.A. Gutierrez (Apr 27)
perfomer_tools again J.A. Gutierrez (Apr 06)

James E. Robinson, III

Re: More Microsoft debri James E. Robinson, III (Apr 23)

James W. Abendschan

Re: AppleShare IP Mail Server James W. Abendschan (Apr 07)

Jamie Lawrence

SUMMARY/WARNING: AnswerBook2 DoS bug Jamie Lawrence (Apr 30)

Jared Mauch

BIND 8.1.2-T3B and BIND 4.9.7-T1B (fwd) Jared Mauch (Apr 08)

jdrodriguez () FANDAGO READ TASC COM

Credit for Novell Post jdrodriguez () FANDAGO READ TASC COM (Apr 16)
Novell Netware 4.X Hidden user accounts jdrodriguez () FANDAGO READ TASC COM (Apr 16)

Jeff Polk

Re: obsd boot hack (boot-modified-kernel-attack) Jeff Polk (Apr 14)

Jim Dennis

Re: Article on writing secure software Jim Dennis (Apr 07)

Joe

BIND 4.9.7 named follows symlinks, clobbers anything. Joe (Apr 10)

Joey Hess

Re: [Debian 2.0] /usr/bin/suidexec gives root access Joey Hess (Apr 28)

John McDonald

Re: Novell Netware 4.X Hidden user accounts John McDonald (Apr 17)
Re: Symlink problem (Tested only on a Digital Unix 4.0) John McDonald (Apr 07)

John Vranesevich

Special Report On Buffer Overfolws John Vranesevich (Apr 25)

Jonathan A. Zdziarski

Re: Symlink problem (Tested only on a Digital Unix 4.0) Jonathan A. Zdziarski (Apr 06)
Re: Buffer overflows in Solaris 2.6 ufsdump and ufsrestore Jonathan A. Zdziarski (Apr 23)

Jon Beaton

smtp overflows Jon Beaton (Apr 08)

Jon Lewis

Re: Linux 2.0.33 vulnerability: oversized packets Jon Lewis (Apr 20)
Re: Linux 2.0.33 vulnerability: oversized packets Jon Lewis (Apr 21)

Josh Richards

Re: code to crash radiusd Josh Richards (Apr 17)

Joshua J. Drake

BIND vulnerability test program.. Joshua J. Drake (Apr 09)

Juergen Schmidt

Re: obsd boot hack (boot-modified-kernel-attack) Juergen Schmidt (Apr 14)

Ken Williams

announce: weaken for netscape !! (fwd) Ken Williams (Apr 10)

kevingeo () CRUZIO COM

Temporary fix for remote exploit in qwsv kevingeo () CRUZIO COM (Apr 09)
Temporary fix for remote exploit in qwsv [fix] kevingeo () CRUZIO COM (Apr 09)

Krzysztof G. Baranowski

Re: Linux 2.0.33 vulnerability: oversized packets Krzysztof G. Baranowski (Apr 21)

Kyle McLerren

Linux possible problem? Kyle McLerren (Apr 22)

Lloyd Vancil

More Microsoft debri Lloyd Vancil (Apr 23)

Marc Slemko

Re: Another Frontpage Bug, with promiscuous ScriptAliases Marc Slemko (Apr 23)

Mark

Re: Have Crackers Found Military's Achilles Heel? Mark (Apr 23)

Mark.Andrews () CMIS CSIRO AU

Re: BIND 4.9.7 named follows symlinks, clobbers anything. Mark.Andrews () CMIS CSIRO AU (Apr 11)

Mark Schaefer

BSDI inetd crash Mark Schaefer (Apr 07)

Matt Barrie

Re: feature Re: pine/pico vt control characters bug Matt Barrie (Apr 25)

Matthew Frederick

Re: Security Hole in Netscape Enterprise Server 3.0 Matthew Frederick (Apr 24)

Matthieu Herrb

Re: xdm problems Matthieu Herrb (Apr 20)

Max Vision

Re: New IE4 bug w/Active Desktop installed Max Vision (Apr 21)

Michael Howard

Re: More Microsoft debri Michael Howard (Apr 23)

Michael Nelson

Re: Leveraging search engines against FrontPage enabled websites Michael Nelson (Apr 28)

Michal Zalewski

pine/pico vt control characters bug Michal Zalewski (Apr 25)
mailrc and pine security holes Michal Zalewski (Apr 05)
portmap 4.0-8 DoS Michal Zalewski (Apr 01)
pine/pico vt control characters bug [2] Michal Zalewski (Apr 25)
Re: feature Re: pine/pico vt control characters bug Michal Zalewski (Apr 25)
Linux 2.0.33 vulnerability: oversized packets Michal Zalewski (Apr 17)

Mike Hardy

Re: QW server hole Mike Hardy (Apr 08)

MrJeKKyL

Re: Leveraging search engines against FrontPage enabled websites MrJeKKyL (Apr 26)

neonhaze

insecure tmp file creation (slack) neonhaze (Apr 06)

Niall Smart

Vulnerability in OpenBSD, FreeBSD-stable lprm. Niall Smart (Apr 22)

Nicolas Dubee

Sun rpcbind Nicolas Dubee (Apr 10)

Niek Jongerius

Re: Webramp M3 login info Niek Jongerius (Apr 21)

Nir Soffer

Re: BSD coredumps follow symlinks Nir Soffer (Apr 02)

Oskar Pearson

DNS Tunnel - through bastion hosts Oskar Pearson (Apr 13)

Pascal Gienger

Re: APC UPS PowerChute PLUS exploit... Pascal Gienger (Apr 14)
Re: APC UPS PowerChute PLUS exploit... Pascal Gienger (Apr 13)

Patrick J. Volkerding

Re: [Fwd: CERT Advisory CA-98.05 - bind_problems] Patrick J. Volkerding (Apr 09)

Paul

New possible exploit for 2.0.33 (kfree_skb error) Paul (Apr 15)

Paul A Vixie

Re: BIND 4.9.7 named follows symlinks, clobbers anything. Paul A Vixie (Apr 11)

Paul Szabo

Re: Symlink problem (Tested only on a Digital Unix 4.0) Paul Szabo (Apr 06)

pedward () WEBCOM COM

Another Frontpage Bug, with promiscuous ScriptAliases pedward () WEBCOM COM (Apr 23)
Re: More Microsoft debri pedward () WEBCOM COM (Apr 23)

Peter Bierman

Re: MacOS based buffer overflows... Peter Bierman (Apr 14)

Peter Shipley

obsd boot hack (boot-modified-kernel-attack) Peter Shipley (Apr 14)

Peter van Dijk

Re: portmap 4.0-8 DoS Peter van Dijk (Apr 07)

phayden

Re: Novell Netware 4.X Hidden user accounts phayden (Apr 17)

Pihl Fredrik

Re: Security Hole in Netscape Enterprise Server 3.0 Pihl Fredrik (Apr 24)

Renaud Deraison

Announce : Nessus Alpha 1 Renaud Deraison (Apr 04)

ReverendTW

Bug in M$ Solitare ReverendTW (Apr 03)

Richard Hearn

hole in IE4 Richard Hearn (Apr 23)

Richard Peters

Re: APC UPS PowerChute PLUS exploit... Richard Peters (Apr 13)

Richi Jennings

Re: Vulnerability in HP OpenMail Richi Jennings (Apr 23)

Rick Perry

Re: APC UPS PowerChute PLUS exploit... Rick Perry (Apr 13)

Robert MACDONALD

Re: Novell Netware 4.X Hidden user accounts Robert MACDONALD (Apr 17)

Ronny Cook

BSD coredumps follow symlinks Ronny Cook (Apr 02)
Re: BSD coredumps follow symlinks Ronny Cook (Apr 05)

root

Symlink problem (Tested only on a Digital Unix 4.0) root (Apr 06)

Rop Gonggrijp

GSM SIMs cloned ! Rop Gonggrijp (Apr 13)

Russell Coker - mailing lists account

Re: [Debian 2.0] /usr/bin/suidexec gives root access Russell Coker - mailing lists account (Apr 28)

Ryan

lastx.c v2.0 Ryan (Apr 19)

Ryan Murray

MGE UPS Systems Ryan Murray (Apr 12)
Re: MGE UPS Systems Ryan Murray (Apr 13)

Scott Stone

Re: APC UPS PowerChute PLUS exploit... Scott Stone (Apr 14)

seifried () SEIFRIED ORG

Re: NT configuration caution seifried () SEIFRIED ORG (Apr 20)

Seth McGann

The ICQ exploitation Center - www.wpi.edu/~smm/icq Seth McGann (Apr 06)
ICQ Spoofer Seth McGann (Apr 05)
Buffer overflows in Solaris 2.6 ufsdump and ufsrestore Seth McGann (Apr 23)

SGI Security Coordinator

IRIX LicenseManager(1M) Vulnerabilities SGI Security Coordinator (Apr 13)
Buffer Overflow Vulnerability in suidperl/sperl program SGI Security Coordinator (Apr 06)
IRIX 6.3 & 6.4 mailcap vulnerability SGI Security Coordinator (Apr 02)
Performer API Search Tool 2.2 pfdispaly.cgi Vulnerability SGI Security Coordinator (Apr 02)
suid_exec Buffer Overflow SGI Security Coordinator (Apr 06)

SnowCrash

Re: MacOS based buffer overflows... SnowCrash (Apr 14)

standby

Security hole in TMS/SMS standby (Apr 03)

|[TDP]|

Security hole in kppp |[TDP]| (Apr 29)

Ted Hickman [Network Admin]

syndrop / modified version Ted Hickman [Network Admin] (Apr 15)

the_coyote () GEOCITIES COM

Webramp M3 login info the_coyote () GEOCITIES COM (Apr 18)

Theo de Raadt

Re: MGE UPS Systems Theo de Raadt (Apr 13)
Re: CERT Vendor-Initiated Bulletin VB-98.04 - xterm.Xaw Theo de Raadt (Apr 30)
Re: obsd boot hack (boot-modified-kernel-attack) Theo de Raadt (Apr 14)

Theo Schlossnagle

APC UPS PowerChute PLUS exploit... Theo Schlossnagle (Apr 10)

The Tree of Life

nestea v2. The program that DoS's 2.0.33s The Tree of Life (Apr 18)

Thomas Roessler

xdm problems Thomas Roessler (Apr 16)
[Debian 2.0] /usr/bin/suidexec gives root access Thomas Roessler (Apr 28)

Tim Newsham

Re: NT configuration caution Tim Newsham (Apr 21)

tony () BAGEL NEOSOFT COM

SunSec ## 169 tony () BAGEL NEOSOFT COM (Apr 29)

Trane Francks

Article on writing secure software Trane Francks (Apr 05)

Vasim Valejev

Example of RFC-1644 attack Vasim Valejev (Apr 07)

Vic Anderson

Re: name of built-in administrator Vic Anderson (Apr 28)

Wietse Venema

Wietse's RPCBIND Wietse Venema (Apr 10)

X

Official SummerCon Announcement X (Apr 08)

Zacharopoulos Dimitris

Re: NT configuration caution Zacharopoulos Dimitris (Apr 21)

Zack Weinberg

Re: Linux libc5.4.33 dumbness w/ mk[s]temp() Zack Weinberg (Apr 13)