Re: FreeBSD Security Advisory FreeBSD-SA-06:22.openssh

2006-10-07 Thread Avleen Vig
On Mon, Oct 02, 2006 at 02:25:05PM -0700, Colin Percival wrote: > Theo de Raadt wrote: > >> The OpenSSH project believe that the race condition can lead to a Denial > >> of Service or potentially remote code execution > >^ > > Bullshit. Where did any

Re: FreeBSD Security Survey

2006-05-28 Thread Avleen Vig
On Wed, May 24, 2006 at 11:20:08AM +0100, Craig Edwards wrote: > I agree, however, i do not like the gentoo dependency upon python for > its package management system. It has not broken on me yet, however i > can imagine if it does it would be a nightmare to fix, as python is > not a trivial progra

Re: exploiting kernel

2005-12-01 Thread Avleen Vig
On Thu, Dec 01, 2005 at 05:41:22PM +1000, Timothy Smith wrote: > for security, generally the kernel and base is not the biggest concern, it is > ports. > read this section on keeping your ports up to date > http://www.freebsd.org/doc/en_US.ISO8859-1/books/handbook/ports-using.html > > and this in

[ronvdaal@zarathustra.linux666.com: Possible security issue with FreeBSD 5.4 jailing and BPF]

2005-07-14 Thread Avleen Vig
This message was sent to bugtraq today: While playing around with FreeBSD 5.4 and jailing I discovered that it was possible to put an ethernet interface into promiscious mode from within the jailed environment, allowing a packetsniffer to gather data not meant for the jailed box. This also affect

Re: Will 5.4 be an "Extended Life" release?

2005-04-25 Thread Avleen Vig
On Mon, Apr 18, 2005 at 03:30:37AM +0200, Danny Pansters wrote: > Let me just boldly insert that IMHO, if 6.X is going to become stable this > autumn already that indeed 5.4 or maybe 5.5 at least one of those must be > long-term-supported. I'm sure one of the two will, as one of the two will > r