Dailydave mailing list archives

Fun with things not said


From: Dave Aitel <dave () immunityinc com>
Date: Wed, 19 Jul 2006 09:37:46 -0400

-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

First a Minor Interlude:
http://www.girlsarepretty.com/blog/stop_falling_in_love_with_the_international_spies_who_sleep_with_you_in_order_to_steal_state_secrets_day.html

Second:
Why doesn't Google buy PGP then and use it as a way to get Google
Desktop on more people's computers. Bundle it with an easy to use
encryption plugin for Gmail and you have a winner!

Third:
Lots of the recent Linux advisories are wrong (Ubuntu is quoted here)
"

For reference, these are the details of the original USN:

  A race condition has been discovered in the file permission handling
  of the /proc file system. A local attacker could exploit this to
  execute arbitrary code with full root privileges.

"

I'm not sure if the distributions need to go hire a kernel guy or
what, but that's not the correct explanation for the bug. We had Bas
Alberts look at it, and his exploit has no such race condition.

- -dave
-----BEGIN PGP SIGNATURE-----
Version: GnuPG v1.4.4 (GNU/Linux)
Comment: Using GnuPG with Fedora - http://enigmail.mozdev.org

iD8DBQFEvjWpB8JNm+PA+iURAo/sAJ9SIeM4hUIvY2+1ALKsEUzom7r8gACgpDzO
S7ALoNnSyeZjzTDQ4rMSWzI=
=md3k
-----END PGP SIGNATURE-----

_______________________________________________
Dailydave mailing list
Dailydave () lists immunitysec com
http://lists.immunitysec.com/mailman/listinfo/dailydave


Current thread: