Vulnerability Development mailing list archives

In response to Mr. Testa's statment (was PERL's -e check)


From: Joseph Nicholas Yarbrough <nyarbrough () LURHQ COM>
Date: Wed, 27 Dec 2000 02:29:52 -0500

In response to Joe Testa's post:
<post>
         - Joe Testa

P.S.  I'd like to personally thank Joseph Nicholas Yarbrough
<nyarbrough () lurhq com>
for privately replying to my first post to insult my "P.S." greets.  Thanks
for your immaturity, Joe!
</post>

I would like to personally announce that it was humor. I have included my
(non public) response to his' original VULN-DEV post.

----------  Forwarded Message  ----------
P.S.  Greets to @stake and the cDc.
I just wanted you to know that I there are hundreds of people all over the
world that laughed at this... I laughed very hard.

But in response to your question...
I assume you are trying to create a file that doesn't exist.
I think -e is vulnerable to symlink attacks, so if you could create(or
modify) a symlink... you could overwrite/create a file.

-Nick
-------------------------------------------------------

I find "Greets" sigs funny. Especially if they "$greet =~ s/s/z/". But I find
"Greets" to a Win32 based trojan maker extreemly funny, as do many others. I
did not insult you. I just said that we found it humorous. Had I said
"laughed at you" instead of "laughed at this", it would have been an insult.
Furthermore, this message did not go to a public forum, as you mentioned. I
did not want _anyone_ else to see the joke so Mr. Testa would not go on the
defensive(and the offensive). He responded in a private message insulting my
company. Then he publically posted a message to VULN-DEV with further
insults.

When you get on a list such as this, sometimes your ego gets ruffled far too
easily. Lets get back on topic, and leave flame sigs off the list.

That said, I apologize for the misunderstanding. I never meant to upset or
insult anyone.

Sincerely,

Joseph Nicholas Yarbrough
Information Security Analyst
LURHQ Corporation
==========================>
nyarbrough () lurhq com


Current thread: