Re: [FD] OpenSSH keyboard-interactive authentication brute force vulnerability (MaxAuthTries bypass)

2015-07-18 Thread Reed Loden
On Friday, July 17, 2015, wrote: > Do you know if this is still affected if you have fail2ban in place. > Fail2ban uses the auth logs to monitor failed password attempts. I > assume that the auth log is still updated even if x number of attempts > is allowed. Thanks http://www.reddit.com/r/net

[FD] Microsoft no longer sending e-mail based security notifications

2014-06-27 Thread Reed Loden
I received the following e-mail from MSFT earlier today. Any idea what these "changing governmental policies" are? This seems pretty ridiculous to not send e-mail notifications anymore. ~reed Begin forwarded message: Date: Fri, 27 Jun 2014 11:40:16 -0600 From: "Microsoft" Subject: Microsoft Se

Re: [FD] several issues in SQLite (+ catching up on several other bugs)

2015-04-20 Thread Reed Loden
See also https://www.sqlite.org/src/info/db8d9af4d04ee862 where they are actively trying to improve afl's results by helping it a bit. :-) On Sunday, April 19, 2015, jungle Boogie wrote: > On 14 April 2015 at 11:33, Michal Zalewski > wrote: > > Because of its versatility, SQLite sometimes finds

Re: [FD] CVE-2020-8152 – Elevation of Privilege in Backblaze

2020-12-25 Thread Reed Loden
Due to a process fail, this CVE ID was accidentally reused for another vulnerability. The updated CVE ID for this issue is CVE-2020-8290. We apologize to Jason and others for the inconvenience caused by this error. Happy holidays, ~reed (for HackerOne) On Fri, Sep 11, 2020 at 10:16 AM Jason Gef

Re: [FD] CVE-2020-8150 – Remote Code Execution as SYSTEM/root via Backblaze

2020-12-25 Thread Reed Loden
Due to a process fail, this CVE ID was accidentally reused for another vulnerability. The updated CVE ID for this issue is CVE-2020-8289. We apologize to Jason and others for the inconvenience caused by this error. Happy holidays, ~reed (for HackerOne) __