Security Basics mailing list archives

Re: powerbook with nmap superpowers


From: Geoffrey J Gowey <gjgowey () gmail com>
Date: Thu, 16 Jul 2009 23:37:11 -0700

Well I'll explain my hatred of ubuntu and why I advise developers to steer clear of it. 3 years ago I tried developing a java application on a clients ubuntu based desktop and that is when I opened the can of worms.

The short of it is that ubuntu heavilly and stringently embraces Unicode end to end through out its entire system. The problem with this is that they have to patch and modify everything including libraries to get this to work, but it doesn't completely work as these modifications bring about other problems. However, these problems are typically ones that will only be encountered by developers or specialized apps (like nmap).

Sent from my iPhone

On Jul 16, 2009, at 10:08 PM, Jonathan Gallant <blackdog.tasha () gmail com> wrote:

Not to knock ubuntu (I'm really not trying to start a distro flame war), but
Not to worry :) I'm not particularly attached to any distro.

Following on your suggestion I popped in a Knoppix livecd, but I
couldn't compile nmap, so I used the original binary from my ubuntu
system with the same results. However I really hadn't tested anything
new - just the same binary compiled with the same gcc compiler running
on knoppix.

Nmap on windows worked great, and I thought perhaps ubuntu is
compiling nmap funny so I converted the nmap-5.0 rpm to deb and
installed that. This gave me the "lots of info" I was looking for and
without the "Access Denied" error.

I'm quite interested in why nmap compiled on ubuntu would give me less
access than nmap compiled/packaged somewhere else. My next test I
suppose is to compile nmap on a completely different system as you
suggested. Would you know what weird things ubuntu does to their
binaries? We are talking about gcc now, and not nmap since I had
compiled nmap myself. Why would an ubuntu gcc compiled nmap give me
less access than some other gcc compiled nmap? Or is it some
dependency library that ubuntu doesn't pull in but the rpm did?

cheers,

J

------------------------------------------------------------------------
Securing Apache Web Server with thawte Digital Certificate
In this guide we examine the importance of Apache-SSL and who needs an SSL certificate.  We look at how SSL works, how 
it benefits your company and how your customers can tell if a site is secure. You will find out how to test, purchase, 
install and use a thawte Digital Certificate on your Apache web server. Throughout, best practices for set-up are 
highlighted to help you ensure efficient ongoing management of your encryption keys and digital certificates.

http://www.dinclinx.com/Redirect.aspx?36;4175;25;1371;0;5;946;e13b6be442f727d1
------------------------------------------------------------------------


Current thread: