Bugtraq: by date

439 messages starting Jan 28 99 and ending Jan 31 00
Date index | Thread index | Author index


Thursday, 28 January

ZBServer 1.50-r1x exploit (WinNT) |Zan

Tuesday, 28 December

Re: strace can lie Pavel Machek

Friday, 31 December

Re: vibackup.sh Todd C. Miller
DNS spoofing/registering/etc Kurt Seifried
blat.c Loneguard

Saturday, 01 January

Happy New Year from BUGTRAQ and Security Focus Elias Levy
HP's Security Bulletins Digest (fwd) Justin Tripp
Re: strace can lie Pavel Machek
Re: majordomo local exploit John Archie

Sunday, 02 January

Re: More info on MS99-061 (IIS escape character vulnerability) Joakim Karlmark
HPUX Aserver revisited. Justin Tripp
Y2K bug in Shadow IDS Alfred Huger
Re: Y2K bug in Shadow IDS (fwd) Alfred Huger

Monday, 03 January

Hotmail security hole - injecting JavaScript using <IMG LOWSRC=&quot;javascript:....&quot;> Georgi Guninski
Re: majordomo local exploit Olaf Kirch
FW: Patch issued for AltaVista Search Engine Directory TraversalVuln erability AVsearch
Re: majordomo local exploit Dale Clark
compartment Marc Heuse
Symlinks and Cryogenic Sleep Olaf Kirch
PHP3 safe_mode and popen() Kristian Koehntopp
Re: HPUX Aserver revisited. Chuck Lawrence
Re: Symlinks and Cryogenic Sleep Mark A. Heilpern
First Telecom E-conso service totally insecure Thomas Quinot
Re: Symlinks and Cryogenic Sleep der Mouse
Subscription bomb tracing - feature request. Alan Brown
Re: Hotmail security hole - injecting JavaScript using <IMG LOWSR C=&quot;javascript:....&quot;> Microsoft Product Security Response Team
Another search.cgi vulnerability k0ad k1d
Re: Hotmail security hole - injecting JavaScript using <IMG Kevin Hecht

Tuesday, 04 January

Re: Hotmail security hole - injecting JavaScript using <IMG LOWSRC=&quot;javascript:....&quot;> Norbert Luckhardt
Re: Symlinks and Cryogenic Sleep Goetz Babin-Ebell
SHADOW and Y2K Problems Bill Ralph
Flaw in 3c59x.c or in Kernel? Sonny Parlin
Yet another Hotmail security hole - injecting JavaScript in IE using <IMG DYNRC=&quot;javascript:....&quot;> Georgi Guninski
Fw: [CERT Advisory CA-2000-01] Guy Cohen
Re: Symlinks and Cryogenic Sleep Marc Heuse
Re: Symlinks and Cryogenic Sleep Wietse Venema
Re: Symlinks and Cryogenic Sleep Casper Dik
FWD: Redhat advisory Alfred Huger
Re: Symlinks and Cryogenic Sleep John Cochran
Re: Hotmail security hole - injecting JavaScript using <IMG Edwin Gonzalez
The WebTV Email Exploit Dale E. Chulhan
Re: Symlinks and Cryogenic Sleep Pavel Machek
Re: irix-soundplayer.sh Dale Southard
Re: Symlinks and Cryogenic Sleep Olaf Kirch
Re: Symlinks and Cryogenic Sleep pedward () WEBCOM COM
[petrilli () digicool com: [Zope] SECURITY ALERT] George Lewis
Re: Hotmail security hole - injecting JavaScript using <IMGLOWSRC=&quot;javascript:....&quot;> Philip Stoev
Re: Symlinks and Cryogenic Sleep Antonomasia
Security problem with Solstice Backup/Legato Networker recover command Chris Siebenmann
Re: Symlinks and Cryogenic Sleep Christos Zoulas
Re: Symlinks and Cryogenic Sleep Henrik Nordstrom
Re: PHP3 safe_mode and popen() David TILLOY
[rootshell] Security Bulletin #27 Kit Knox
Re: irix-soundplayer.sh pda () ING PUC CL
Microsoft Security Bulletin (MS00-001) Microsoft Product Security
Re: Flaw in 3c59x.c or in Kernel? Raymond Dijkxhoorn
Re: Hotmail security hole - injecting JavaScript using <IMG Henrik Nordstrom
Re: irix-soundplayer.sh Darren Reed
L0pht Advisory: RH Linux 6.0/6.1, PAM and userhelper Dildog
New Allaire Security Zone Bulletins and KB Article Aleph One
Re: Flaw in 3c59x.c or in Kernel? danny
Re: Yet another Hotmail security hole - injecting JavaScript in Nick FitzGerald
Re: FWD: Redhat advisory (RPM --upgrade/-U vs. --freshen/-F) Peter W
Re: Flaw in 3c59x.c or in Kernel? Bill Paul
userhelper/PAM exploit Derek Callaway
Re: irix-soundplayer.sh... NOT Irix 6.4 pda () ING PUC CL

Wednesday, 05 January

Re: Flaw in 3c59x.c or in Kernel? Raymond Dijkxhoorn
Re: Symlinks and Cryogenic Sleep Mikael Olsson
Re: PHP3 safe_mode and popen() Thomas Köhler
Local / Remote D.o.S Attack in IMail IMONITOR Server for WinNT Version 5.08 Ussr Labs
CuteFTP saved password 'encryption' weakness Nick FitzGerald
Re: Symlinks and Cryogenic Sleep Marc Heuse
Re: vibackup.sh Kris Kennaway
Re: L0pht Advisory: RH Linux 6.0/6.1, PAM and userhelper cogNiTioN
Re: Hotmail security hole - injecting JavaScript using <IMG Metal Hurlant
Re: Flaw in 3c59x.c or in Kernel? David Malone
Re: Hotmail security hole - injecting JavaScript using <IMG Metal Hurlant
SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS Jarle Aase
JS problem in NS4.5 - known? Nick Phillips
Re: Flaw in 3c59x.c or in Kernel? Sonny Parlin
Re: Subscription bomb tracing - feature request. M. Dodge Mumford
FW: Flaw in 3c59x.c or in Kernel? William R. Lorenz
Re: Subscription bomb tracing - feature request. Brian Mueller
&quot;SANS Flash Alert For Solaris&quot; Chok Poh
Re: Yet another Hotmail security hole - injecting JavaScript in Justin King
Re: Symlinks and Cryogenic Sleep Antonomasia
Re: Flaw in 3c59x.c or in Kernel? Jonathan Poole
Re: Hotmail security hole - injecting JavaScript using <IMG Dustin Miller
[Hackerslab bug_paper] Solaris chkperm buffer overflow ±è¿ëÁØ KimYongJun (99Á¹¾÷)
Re: L0pht Advisory: RH Linux 6.0/6.1, PAM and userhelper gwynp () ARTWARE QC CA
Re: Flaw in 3c59x.c or in Kernel? Pug Bainter
Re: Symlinks and Cryogenic Sleep Pavel Kankovsky
Re: CuteFTP saved password 'encryption' weakness Brian Kifiak
Sun Security Bulletin #00193 (fwd) Jay D. Dyson
Handspring Visor Network HotSync Security Hole Jay C Austad
Re: JS problem in NS4.5 - known? Crispin Cowan
Re: Hotmail security hole - injecting JavaScript using <IMG Ajax
Re: SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS Sir Dystic
Re: Hotmail security hole - injecting JavaScript using <IMG Grahame Bowland

Thursday, 06 January

Re: PHP3 safe_mode and popen() Kristian Koehntopp
Re: Netscape Communicator 4.7 exploit [NT/win2k]. Thompson, Zach, CPG
Yet another Hotmail security hole - injecting JavaScript in IE using &quot;@import url(javascript:...)&quot; Georgi Guninski
Re: Announcement: Solaris loadable kernel module backdoor der Mouse
Security Bulletins Digest Aleph One
Re: Handspring Visor Network HotSync Security Hole Jim Frost
Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow Brock Tellier
Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow Darren Reed
Phorum 3.0.7 exploits and IDS signatures Max Vision
Stack Shield 0.7 beta vendicator () USA NET
Re: Handspring Visor Network HotSync Security Hole Jason Spence

Friday, 07 January

Re: Hotmail security hole - injecting JavaScript using <IMG ck () RIB DE
IE 5 security vulnerablity - circumventing Cross-frame security policy and accessing the DOM of &quot;old&quot; documents. Georgi Guninski
Re: majordomo local exploit Chan Wilson
Re: The WebTV Email Exploit Thompson, Zach, CPG
PalmCrack - The password testing tool for the Palm Computing Platform swlodin () IQUEST NET
Re: [Hackerslab bug_paper] Solaris chkperm buffer overflow Theodor Ragnar Gislason
[RHSA-2000:002] New lpr packages available Bill Nottingham
Stack Sheild 0.7 and SFP Overwrites vendicator () USA NET
Re: Handspring Visor Network HotSync Security Hole Chris Adams
Re: Hotmail security hole - injecting JavaScript using <IMG Andrew Pimlott

Saturday, 08 January

Re: SECURITY ALERT - WAR FTP DAEMON ALL VERSIONS Jarle Aase
L0pht Advisory: LPD, RH 4.x,5.x,6.x Dildog
Re: Hotmail security hole - injecting JavaScript using <IMG Eivind Eklund

Sunday, 09 January

Buffer overflow with WinAmp 2.10 Transfer Interrupted
Altavista followup rudi carell
secure-programs howto Signal 11
strace can lie ... but LTT might be handy Karim Yaghmour

Monday, 10 January

2nd attempt: AIX techlibss follows links Klaus.Kusche () OOE GV AT
Yet another Hotmail security hole - injecting JavaScript using &quot;j&#x41;vascript:&quot; Georgi Guninski
IIS still revealing paths for web directories Vanja Hrustic
Re: Altavista followup Roelandts, Guy

Tuesday, 11 January

Serious bug in MySQL password handling. Viktor Fougstedt
Re: Hotmail security hole - injecting JavaScript using <IMG Ajax
NIS2k Bacano
ICQ Buffer Overflow Exploit drew copley
Re: L0pht Advisory: LPD, RH 4.x,5.x,6.x Oliver Friedrichs
PowerScripts PlusMail Vulnerablity YT Cracker
SRS (Secure Remote Streaming): a secure Unix syslog Matt Conover
Re: Analysis of &quot;stacheldraht&quot; Dave Dittrich
Anyone can take over virtually any domain on the net... Thomas Reinke

Wednesday, 12 January

Serious Bug in Corel Linux.(Local root exploit) tascon () ENETE GUI UVA ES
Blinding BIND to a moving domain D. J. Bernstein
IE 5.0 vs. XML-files David Komanek
Multiple WebMail Vendor Vulnerabilities CDI
Re: IIS still revealing paths for web directories Jonah Kowall
CyberCash MCK 3.2.0.4: Large /tmp hole Sheldon Young
Re: IIS still revealing paths for web directories Vladimir Dubrovin
Administrivia: ORBS Elias Levy
Re: IIS still revealing paths for web directories Chris Tobkin
Re: Blinding BIND to a moving domain Ken Gourlay
Re: Multiple WebMail Vendor Vulnerabilities Peter W
SRS Addendum Matt Conover
Password issue in Axent ESM 5.0.1 Console Todd
WebSitePro/2.3.18 is revealing Webdirectories Lark Lizerman
Re: ICQ Buffer Overflow Exploit Dennis W. Mattison (Little Wolf)

Thursday, 13 January

SV: IIS still revealing paths for web directories Kristoffer Ustad
Local / Remote D.o.S Attack in Super Mail Transfer Package (SMTP) Server for WinNT Version 1.9x Ussr Labs
Re: IIS still revealing paths for web directories Georgi Guninski
Info on some security holes reported against SCO Unixware. Aaron Sigel
Re: XML in IE 5.0 Mike Brown
mSQL and not MySQL exploit Tonu Samuel
Re: NIS2k Brad Griffin
Re: IIS still revealing paths for web directories Eric.Stevens () AVENTIS COM
ssh-proxy, a new approach to firewall software Magosanyi Arpad
Re: procmail / Sendmail - five bugs Gregory Neil Shapiro
Re: Anyone can take over virtually any domain on the net... Janos Zsako
Re: Anyone can take over virtually any domain on the net... Jon Lewis
Re: Anyone can take over virtually any domain on the net... Jeffrey Paul
Re: Anyone can take over virtually any domain on the net... Chris Adams
Misleading sense of security in Netscape Craig Ruefenacht
Re: Anyone can take over virtually any domain on the net... Russ Johnson
Re: Anyone can take over virtually any domain on the net... Ryan Russell
Re: Anyone can take over virtually any domain on the net... Shafik Yaghmour
New MySQL Available Scott
Re: Anyone can take over virtually any domain on the net... Haight, Kristofer
Re: Anyone can take over virtually any domain on the net... Kurt Seifried
Re: ICQ Buffer Overflow Exploit Simon Steed
BindView Security Advisory: Local Promotion Vulnerability in Windows NT 4 BindView Security Advisory
Microsoft Security Bulletin (MS00-003) Microsoft Product Security
Re: CyberCash MCK 3.2.0.4: Large /tmp hole (fwd) Dave G.
Re: WebSitePro/2.3.18 is revealing Webdirectories Chris
Re: IIS still revealing paths for web directories Scott Buchanan
Re: XML in IE 5.0 Mikael Olsson
Re: ICQ Buffer Overflow Exploit Michael DeSimone
Re: XML in IE 5.0 Mike Brown
MS IIS 5.0 Access Violation on handling URL String Lark Lizerman
Re: WebSitePro/2.3.18 + 2.4.9 is revealing Webdirectories Lark Lizerman
Re: WebSitePro/2.3.18 is revealing Webdirectories Lark Lizerman

Friday, 14 January

Re: Anyone can take over virtually any domain on the net... BUGTRAQ () ROZZ COM
Re: Password issue in Axent ESM 5.0.1 Console Scott Blake
Re: ICQ Buffer Overflow Exploit Tom Schumm
Fwd: Crash identified in Notes, Domino, and MTA with Date Conversio ns Xander Teunissen
Re: Password issue in Axent ESM 5.0.1 Console Harold Toomey
Re: Misleading sense of security in Netscape Steven M. Bellovin
Re: Anyone can take over virtually any domain... Brian Mueller
Re: Anyone can take over virtually any domain on the net... root
Re: MS IIS 5.0 Access Violation on handling URL String Anthony Benjamin
Re: XML in IE 5.0 Ryan Russell
Re: Anyone can take over virtually any domain on the net... Bryan Fullerton
Altavista Free Internet Security Plex Inphiniti
Re: IIS still revealing paths for web directories Rob Systhine
Re: Anyone can take over virtually any domain on the net... Max Vision

Saturday, 15 January

Re: IIS still revealing paths for web directories Vanja Hrustic
Re: IIS still revealing paths for web directories Taneli Huuskonen
Re: IIS still revealing paths for web directories Henrik Nordstrom
Re: Anyone can take over virtually any domain on the net... Nick Lamb
Re: IIS still revealing paths for web directories Antonio Ropero
Re: HOTMAIL is revealing Webdirectories Gushterul
Re: Anyone can take over virtually any domain on the net... Homer Wilson Smith
Re: ICQ Buffer Overflow Exploit Thomas Maschutznig
Re: MS IIS 5.0 Access Violation on handling URL String David Litchfield
Re: IIS still revealing paths for web directories Norbert Luckhardt
Re: MS IIS 5.0 Access Violation on handling URL String Lark Lizerman
Re: IIS still revealing paths for web directories Frank Knobbe at Home
Announce: BOF on Distributed DoS, San Jose 1/18/00 David Kennedy CISSP

Sunday, 16 January

Re: Password Issue in Axent ESM 5.0.1 Console Todd Hathaway
TB2 Pro sending NT passwords cleartext David Masten
Yahoo Pager/Messanger Buffer Overflow Jaynus Jaynus

Monday, 17 January

[support_feedback () us-support external hp com: Security Bulletins Digest] Patrick Oonk
Security hole in mail2web web-based emailservice Patrick Oonk
usual iploggers miss some variable stealth scans vecna
Re: XML in IE 5.0 Brian Behlendorf
Re: XML in IE 5.0 Darren Reed
Re: Anyone can take over virtually any domain on the net... Brian Mueller
Re: Altavista Free Internet Security Bill
Nortel Contivity Vulnerability foo
Microsoft Security Bulletin (MS00-005) Microsoft Product Security
Re: TB2 Pro sending NT passwords cleartext William J Husler
Re: problem with SNMPc John Comeau
IIS still revealing paths for web directories Michael Howard
Re: MS IIS 5.0 Access Violation on handling URL String Michael Howard
Re: Altavista Free Internet Security Firstname Lastname
Updated PalmCrack 1.1 Distribution Noncon Inc
Re: tcpdump under RedHat 6.1 John Comeau
Re: usual iploggers miss some variable stealth scans Simple Nomad

Tuesday, 18 January

Re: ICQ Buffer Overflow Exploit x-x-x-x-x-x-x-x-x
Re: IIS still revealing paths for web directories Niklas Schiffler
More Interscan Viruswall stuff john lampe
AW: usual iploggers miss some variable stealth scans Tobi
Warning: VCasel security hole. bob mare
Administrivia Elias Levy
Re: IIS still revealing paths for web directories Brock Tellier
Trusted process on an untrusted machine? Mike Frantzen
Re: usual iploggers miss some variable stealth scans David LeBlanc
Re: usual iploggers miss some variable stealth scans Alec Kosky
Re: usual iploggers miss some variable stealth scans Hank Leininger
Re: XML in IE 5.0 Meilicke, Scott
Re: Misleading sense of security in Netscape Jefferson Ogata
Re: ICQ Buffer Overflow Exploit Bryce Walter
Re: MS IIS 5.0 Access Violation on handling URL String Michael Howard
Re: IIS still revealing paths for web directories Chris Tobkin
Re: MS IIS 5.0 Access Violation on handling URL String Imran Ghory
Re: Nortel Contivity Vulnerability Bill Fumerola
stream.c - new FreeBSD exploit? The Tree of Life
Re: problem with SNMPc Marc Cozzi
Re: XML in IE 5.0 David LeBlanc

Wednesday, 19 January

Re: Microsoft Security Bulletin (MS00-005) Pauli Ojanpera
Re: tcpdump under RedHat 6.1 Francois Morris
Re: ICQ Buffer Overflow Exploit Jeremy Johnson
Re: XML in IE 5.0 Jesper M. Johansson
AW: usual iploggers miss some variable stealth scans Tobi
Re: Microsoft Security Bulletin (MS00-005) bugtraq () NS DOOMSDAY COM
Some discussion in http-wg ... FW: webmail vulnerabilities: a new pragma token? Eric D. Williams
Re: Microsoft Security Bulletin (MS00-005) Brock Tellier
Re: IIS still revealing paths for web directories Kevin Matthew
FW: FreeBSD Security Advisory: FreeBSD-SA-00:01.make FreeBSD Security Officer
Re: ICQ Buffer Overflow Exploit Nick Summy
Re: usual iploggers miss some variable stealth scans Oliver Friedrichs
Re: Trusted process on an untrusted machine? Pavel Machek
Re: Trusted process on an untrusted machine? Tim Newsham
Re: Trusted process on an untrusted machine? Mike Frantzen
Re: problem with SNMPc Stefan Schneider
Re: Microsoft Security Bulletin (MS00-005) Matt Davis
Graphiciizing su for NT WAS: RE: XML in IE 5.0 SanMillan, Todd
SubSeven 2.1a (trojan) Andrew Griffiths
Re: Microsoft Security Bulletin (MS00-005) Tabor J. Wells
Re: XML in IE 5.0 Jesper M. Johansson
Unixware ppptalk what's your style?
Re: ICQ Buffer Overflow Exploit Dylan Griffiths
Re: Trusted process on an untrusted machine? Anonymous Anonymous
Security Issues with HIGHSPEEDWEB.NET leased servers Brian Mueller
connlogd update Alec Kosky
Re: Trusted process on an untrusted machine? Crispin Cowan
Crafted Packets Handling by Firewalls - FW-1 case Ofir Arkin

Thursday, 20 January

Worldsecure/Mail 4.3 vulnerability Andreas Küchler
Re: XML in IE 5.0 David LeBlanc
Re: Trusted process on an untrusted machine? Pavel Machek
Re: usual iploggers miss some variable stealth scans Andrea Gho
Re: Some discussion in http-wg ... FW: webmail vulnerabilities: a new pragma token? Ryan Russell
Microsoft Security Bulletin (MS00-002) Microsoft Product Security
Re: stream.c - new FreeBSD exploit? Bill Fumerola
Re: IIS still revealing paths for web directories Michael Howard
Re: Worldsecure/Mail 4.3 vulnerability salme () US IBM COM
FW: Security Vulnerability with SMS 2.0 Remote Control Brandon Eisenmann
Re: Security Issues with HIGHSPEEDWEB.NET leased servers Pedro Hugo
Rh 6.1 initial root password encryption Ken Barber
AusCERT Advisory AA-2000.01 Majordomo open() call Vulnerability Christopher P. Lindsey
Re: Crafted Packets Handling by Firewalls - FW-1 case Darren Reed
Re: Security Issues with HIGHSPEEDWEB.NET leased servers Brian Mueller
Quick remedy for stream.c Brett Glass
Re: Crafted Packets Handling by Firewalls - FW-1 case IAKOVLEV () FR IBM COM
Microimages X Server for Win - Vulnerability Mike Wilson

Friday, 21 January

Re: usual iploggers miss some variable stealth scans Ralf Laue
Re: Unixware ppptalk Andrew Malcolm
Re: Microimages X Server for Win - Vulnerability Nathanael Lierly
(no subject) Morris, Joseph L.
Nortel Contivity Vulnerability: typo foo
Vulnerabilities in Checkpoint FW-1 version 3.x and maybe 4.x root
Re: stream.c - new FreeBSD exploit? Darren Reed
Re: Graphiciizing su for NT WAS: RE: XML in IE 5.0 Jesper M. Johansson
explanation and code for stream.c issues Tim Yardley
Re: Info on some security holes reported against SCO Unixware. Brock Tellier
Re: explanation and code for stream.c issues Tim Yardley
Re: Info on some security holes reported against SCO Unixware. Aaron Sigel
Re: explanation and code for stream.c issues Erik Fichtner
Re: Quick remedy for stream.c Frasnelli, Dan
*BSD procfs vulnerability FEAR Advisories
Re: Quick remedy for stream.c bella
Re: explanation and code for stream.c issues Brett Glass
stream.c/raped.c tests (just for stats) Vanja Hrustic
Microsoft Security Bulletin (MS00-004) Microsoft Product Security
Re: Vulnerabilities in Checkpoint FW-1 version 3.x and maybe 4.x Scott, Richard
Re: stream.c - new FreeBSD exploit? Haight, Kristofer
Re: stream.c - new FreeBSD exploit? Adam Lynch
Re: Vulnerabilities in Checkpoint FW-1 version 3.x and maybe 4.x Jonah Kowall
Re: FW: Security Vulnerability with SMS 2.0 Remote Control Maniac .
stream.c Dino Amato
Fw: stream.c Dino Amato
RDISK registry enumeration file vulnerability in Windows NT 4.0 Terminal Server Edition Arne Vidstrom
NIS security advisory : password method downgrade Stefan Laudat
Re: Microsoft Security Bulletin (MS00-005) Microsoft Product Security Response Team
Re: explanation and code for stream.c issues Tim Yardley
Windows 2000 Run As... Feature David Terrell
Fwd: Re: Fwd: Re: explanation and code for stream.c issues Tim Yardley
S/Key & OPIE Database Vulnerability harikiri
Re: explanation and code for stream.c issues Nathan Ollerenshaw
Re: explanation and code for stream.c issues Giorgos Keramidas

Saturday, 22 January

Re: Vulnerabilities in Checkpoint FW-1 version 3.x and maybe 4.x Vanja Hrustic
Re: tcpdump under RedHat 6.1 Ken Lyon
Re: stream.c - new FreeBSD exploit? Frank (sysadmin)
Re: explanation and code for stream.c issues Vladimir Dubrovin
Re: Vulnerabilities in Checkpoint FW-1 version 3.x and maybe 4.x Markus Hofmann
Re: explanation and code for stream.c issues Don Lewis
Re: explanation and code for stream.c issues Vladimir Dubrovin
Re: Rh 6.1 initial root password encryption Fabian Kroenner
Re: explanation and code for stream.c issues Don Lewis
Re: usual iploggers miss some variable stealth scans antirez
Solaris 7 and solaris 8 file permissions Steve Dispensa
RFPoison is not a trojan, and the source will prove it .rain.forest.puppy.
remote root qmail-pop with vpopmail advisory and exploit with patch what's your style?

Sunday, 23 January

Re: stream.c - new FreeBSD exploit? Guy Cohen
The 200 trusted .com servers D. J. Bernstein
Re: Solaris 7 and solaris 8 file permissions Jonathan [no, I don't write for /.] Katz
Re: vpopmail/vchkpw remote root exploit D. J. Bernstein
Re: Windows 2000 Run As... Feature Seth R Arnold
Re: Windows 2000 Run As... Feature Steven Kastl
Re: S/Key & OPIE Database Vulnerability David Maxwell
Re: *BSD procfs vulnerability Theo de Raadt
S/Key & OPIE Database Vulnerability Steve VanDevender
Re: remote root qmail-pop with vpopmail advisory and exploit with patch (fwd) iv0
Re: usual iploggers miss some variable stealth scans Theo de Raadt
Re: NIS security advisory : password method downgrade Thorsten Kukuk

Monday, 24 January

Re: Solaris 7 and solaris 8 file permissions Casper Dik
Re: Solaris 7 and solaris 8 file permissions Darren Moffat - Solaris Sustaining Engineering
Re: NIS security advisory : password method downgrade Darren Moffat - Solaris Sustaining Engineering
Re: Windows 2000 Run As... Feature Jesper M. Johansson
Re: Windows 2000 Run As... Feature jdglaser
VMware 1.1.2 Symlink Vulnerability harikiri
Re: RDISK registry enumeration file vulnerability in Windows NT 4.0 Terminal Server Edition Andy Polyakov
Re: remote root qmail-pop with vpopmail advisory and exploit with patch (fwd) iv0
Security Bulletins Digest Aleph One
majordomo 1.94.5 does not fix all vulnerabilities Brock Sides
Re: S/Key & OPIE Database Vulnerability Evil Pete
Re: VMware 1.1.2 Symlink Vulnerability (not) Peter W
New Security Paradigms Workshop 2000: Call For Papers Crispin Cowan
Re: VMware 1.1.2 Symlink Vulnerability Oinos
Re: Windows 2000 Run As... Feature Camillo Särs

Tuesday, 25 January

Re: Windows 2000 Run As... Feature jdglaser
Lotus Notes Local Replicated Database Problem Matt Storey
Re: majordomo 1.94.5 does not fix all vulnerabilities Chan Wilson
Re: S/Key & OPIE Database Vulnerability Mudge
Re: majordomo 1.94.5 does not fix all vulnerabilities Dave Barr
Re: majordomo 1.94.5 does not fix all vulnerabilities Olaf Kirch
Stream.c needs more clarification Vanja Hrustic
Re: Nortel Contivity Vulnerability: typo John Duksta
multicasts from hell Tim Yardley
Re: Windows 2000 Run As... Feature David LeBlanc
Re: Windows 2000 Run As... Feature David LeBlanc
Re: S/Key & OPIE Database Vulnerability Steve VanDevender
Re: S/Key & OPIE Database Vulnerability Mudge
Re: S/Key & OPIE Database Vulnerability Mudge
Re: S/Key & OPIE Database Vulnerability Steve VanDevender
Re: majordomo 1.94.5 does not fix all vulnerabilities Martin Mares
Re: Windows 2000 Run As... Feature Ben Russell

Wednesday, 26 January

Re: Lotus Notes Local Replicated Database Problem bram () E-WARENESS BE
Qpopper security bug Zhodiac
Re: Nortel Contivity Vulnerability: typo Ray Beaulieu
SAS behavior in Windows NT - RE: Windows 2000 Run As... Feature jdglaser
Re: SAS behavior in Windows NT - RE: Windows 2000 Run As... Feature Jesper M. Johansson
Re: S/Key & OPIE Database Vulnerability Steve VanDevender
Re: Windows 2000 Run As... Feature Steve Wolfe
Re: SAS behavior in Windows NT - RE: Windows 2000 Run As... Feature David LeBlanc
Re: SAS behavior in Windows NT - RE: Windows 2000 Run As... Feature jdglaser
Re: S/Key & OPIE Database Vulnerability Dug Song
Microsoft Security Bulletin (MS00-006) Microsoft Product Security
Future of s/key (Re: S/Key & OPIE Database Vulnerability) Frasnelli, Dan
Alert: MS IIS 4 / IS 2 (Cerberus Security Advisory CISADV000126) Mnemonix

Thursday, 27 January

Re: S/Key & OPIE Database Vulnerability Eivind Eklund
Re: Windows 2000 Run As... Feature Kenn Humborg
Re: SAS behavior in Windows NT - RE: Windows 2000 Run As... Feature Peter Berendi
Re: S/Key & OPIE Database Vulnerability Brandon Palmer
Multicast from hell John Watkins
Re: SAS behavior in Windows NT - RE: Windows 2000 Run As... Feature Ron Parker
ANNOUNCE: CIS 5.0.0 Mnemonix
New SCO patches... Aaron Sigel
Re: S/Key & OPIE Database Vulnerability Jordan Ritter
Re: Future of s/key (Re: S/Key & OPIE Database Vulnerability) der Mouse
Cobalt RaQ2 - a user of mine changed my admin password.. Chuck Pitre - Technical Support
FW: Undocumented back door NHCTC

Friday, 28 January

[FreeBSD Security Advisory: FreeBSD-SA-00:02.procfs] Patrick Oonk
Re: S/Key & OPIE Database Vulnerability Eivind Eklund
Re: Multicast from hell Omachonu Ogali
FTPPro has weird features - Fwd: Important matter for your abuse department Cedric Amand
Re: Alert: MS IIS 4 / IS 2 (Cerberus Security Advisory CISADV000126) Mnemonix
Re: S/Key & OPIE Database Vulnerability Jordan Ritter
SyGate 3.11 Port 7323 / Remote Admin hole jalerta () nestworks com

Saturday, 29 January

&quot;Strip Script Tags&quot; in FW-1 can be circumvented Arne Vidstrom
Re: Cobalt RaQ2 - and QUBE2 Nir Simionovich (Rin Solo)
rzsz emails usage stats without user consent Kris Kennaway
[LoWNOISE] Rightfax web client 5.2 ET LoWNOISE
Re: Future of s/key (Re: S/Key & OPIE Database Vulnerability) Greg A. Woods

Sunday, 30 January

RedHat 6.1 /and others/ PAM Michal Zalewski
Re: Alert: MS IIS 4 / IS 2 (Cerberus Security Advisory CISADV000126) Fredrik Widlund
Tempfile vulnerabilities foo
Bypass Virus Checking Neil Bortnak

Monday, 31 January

Disable Parent Paths Robert Zachary
Re: Alert: MS IIS 4 / IS 2 (Cerberus Security Advisory CISADV0001 26) Cave, Glynis
[ Cobalt ] Security Advisory -- 01.31.2000 Jeff Bilicki
New Allaire Security Zone Bulletin Aleph One