JULY 6th Lead Training 3 tips for working leads

2004-07-06 Thread OppMedia
Before I get into today’s training I want to let you know that for the next 24 hours only we are having an unbelievable sale on our email leads. We have a large supply of email leads and thought it would be great time for us to set the price so low that everybody would take advantage of it. We

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Michael Stone
On Tue, Jul 06, 2004 at 11:51:21PM +0200, Jeroen van Wolffelaar wrote: security issues. I'll post a list of a few of such issues here later tonight, that are exactly issues that could have been filed in the BTS. If you really have so much time I'm sure you can find better things to do than post lis

Re: Bug#257165: udev: input device permissions

2004-07-06 Thread Rick Moen
Quoting Mezig ([EMAIL PROTECTED]): > 1- Why if Itay, find a solution for the problem we had, doesn't it offer > his solution to the community ; ethen, if he is on a single user machine ? That would be good. I was only addressing Itay's assertion that "the consequences for sarge should be somewh

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Javier Fernández-Sanguino Peña
On Tue, Jul 06, 2004 at 08:06:36PM +0200, Jeroen van Wolffelaar wrote: > Hi, > > As I promised in [1], a suggestion for the Debian security team. > > Since the security team is generally very busy sorting out any kind of > vulnerability, sometimes fixes can take a little bit longer than usual, >

Re: Bug#257165: udev: input device permissions

2004-07-06 Thread Mezig
Rick Moen wrote: Quoting Itay Ben-Yaacov ([EMAIL PROTECTED]): Now, people using sid accept the potential consequences, but the consequences for sarge should be somewhat lesser... Actually, the consequences for sarge (while it's still the testing branch) will tend generally to be somewhat _g

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Jeroen van Wolffelaar
On Tue, Jul 06, 2004 at 10:39:09PM +0200, Bernd Eckenfels wrote: > In article <[EMAIL PROTECTED]> you wrote: > > mdz told me this isn't done for practical reasons: the BTS isn't very > > suitable for tracking which versions are affected, and a sid upload can > > close such a bug while it's still in

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > mdz told me this isn't done for practical reasons: the BTS isn't very > suitable for tracking which versions are affected, and a sid upload can > close such a bug while it's still in woody. While I think it'd still be > possible without too much hassle, i

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Matt Zimmerman
On Tue, Jul 06, 2004 at 09:13:18PM +0200, Jeroen van Wolffelaar wrote: > On Tue, Jul 06, 2004 at 03:08:38PM -0400, Michael Stone wrote: > > On Tue, Jul 06, 2004 at 08:06:36PM +0200, Jeroen van Wolffelaar wrote: > > >As an example, take CAN-2004-0519, CAN-2004-0520 and CAN-2004-0521, all > > >three

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Jeroen van Wolffelaar
On Tue, Jul 06, 2004 at 03:08:38PM -0400, Michael Stone wrote: > On Tue, Jul 06, 2004 at 08:06:36PM +0200, Jeroen van Wolffelaar wrote: > >As an example, take CAN-2004-0519, CAN-2004-0520 and CAN-2004-0521, all > >three not yet solved in woody, but also not filed in the BTS (hm, two of > >them dire

Re: Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Michael Stone
On Tue, Jul 06, 2004 at 08:06:36PM +0200, Jeroen van Wolffelaar wrote: As an example, take CAN-2004-0519, CAN-2004-0520 and CAN-2004-0521, all three not yet solved in woody, but also not filed in the BTS (hm, two of them directly refer to a patch[2][3] solving it...). Go ahead and file the bug. Mik

Proposal/suggestion for security team w.r.t. published vulerabilities

2004-07-06 Thread Jeroen van Wolffelaar
Hi, As I promised in [1], a suggestion for the Debian security team. Since the security team is generally very busy sorting out any kind of vulnerability, sometimes fixes can take a little bit longer than usual, especially if the impact is relatively low. Taking the Social Contracts 'We will not

Re: Bug#257165: udev: input device permissions

2004-07-06 Thread Rick Moen
Quoting Itay Ben-Yaacov ([EMAIL PROTECTED]): > Now, people using sid accept the potential consequences, but the > consequences for sarge should be somewhat lesser... Actually, the consequences for sarge (while it's still the testing branch) will tend generally to be somewhat _greater_ than for si

Re: FWD: Squirrelmail XSS + SQL security bug?

2004-07-06 Thread Jeroen van Wolffelaar
On Tue, Jul 06, 2004 at 12:47:21PM +0200, Rom?n Medina wrote: > > Hi Jeroen, > > > Sam, could you please forward you incoming mail about security issues to > > someone who has more time to look into it? > > Well, I wouldn't lose time doing so. Better to upgrade to latest 1.4.3a. > Yes, contrary

Re: FWD: Squirrelmail XSS + SQL security bug?

2004-07-06 Thread Román Medina
Hi Jeroen, > Sam, could you please forward you incoming mail about security issues to > someone who has more time to look into it? Well, I wouldn't lose time doing so. Better to upgrade to latest 1.4.3a. Yes, contrary to the Debian "backporting" policy, but in this case there are sufficient reas

Re: FWD: Squirrelmail XSS + SQL security bug?

2004-07-06 Thread Jeroen van Wolffelaar
On Tue, Jul 06, 2004 at 10:48:46AM +0200, Rom?n Medina wrote: > I must add the following comments: > - On May'04, I contacted Sam and some of the SquirrelMail developpers > regarding several security bugs in SquirrelMail (one of them being new > -present in all SM versions- and other being old *bu

Re: FWD: Squirrelmail XSS + SQL security bug?

2004-07-06 Thread Román Medina
I must add the following comments: - On May'04, I contacted Sam and some of the SquirrelMail developpers regarding several security bugs in SquirrelMail (one of them being new -present in all SM versions- and other being old *but present in Woody* package). After exchanging various mails with both,

You need to save money on PHARMACEUTICA|LS

2004-07-06 Thread Nell Campos
Everyone knows Medications are cheaper in Toronto. Wouldn't you like to find a place that is cheaper? We offer the Ten most popular PHAR!MACEUTICALS. http://esxcr76.com/tp/default.asp?id=gm03 http://esxcr76.com/er/r mv s.asp