Vulnerability Development mailing list archives

Re: Denial of Service in Xitami webserver all versions...


From: simon () TRAGOIDIA FORCE9 CO UK (Simon)
Date: Wed, 5 Apr 2000 02:17:26 +0100


-----BEGIN PGP SIGNED MESSAGE-----
Hash: SHA1

GraffiX, how-do-you-do!

      On 05/04/2000 it is highly likely that you wrote this:

G> Ummm....actually, they released the fix for BOTH platforms (2.4d7 and
G> 2.5b3) yesterday, March 3rd, based on the lengthy discussions in the Xitami
G> mailing list we've been having for days now regarding these DoS
G> bugs.  Below is the release info:

Whatever! Yes, I mailed the info from this list to IMatix the other day (1st
April) . If Pieter Hintjens posted the fixes for both platforms on the 3rd
April (i think that's when you meant), then the info did the job ;) I take
zero credit, and am not attempting to either. Just thought that it might be
Ok to post this info as I got a reply from Pieter Hintjens the other day and
forgot to post info here in a timely fashion. Hope this has not upset anyone.

(I've been following _all_ of the discussion by the way and wasn't trying to
steal anyone's glory)

Mail from IMatix:

We're releasing a fix this minute...  We'll also take your suggestion
about not allowing anonymous connections by default.

- -
Pieter Hintjens
iMatix Corporation

-----BEGIN PGP SIGNATURE-----
Version: PGP 6.5i
Comment: Privacy is freedom. Protect your freedom with PGP.

iQA/AwUBOOqUJstub/5cfolmEQLItwCgtINAUmY55fymIQBEuNzhQR58Xn0An0q7
Z8/hlJCT4ZmbMFc4B1wGJIIY
=zRgQ
-----END PGP SIGNATURE-----


Current thread: