librsync and rsync vulnerability to maliciously crafted data. was Re: MD4 checksum_seed

2004-04-04 Thread Donovan Baarda
G'day again, Just revisiting an old thread after some more thought. Eran and I were discussing the vulerability of librsync and rsync to deliberate attempts to craft blocks with matching signatures but different content. It turns out it's disturbingly easy. Here's a bit of context; From: "Donovan

non-ASCII chars in filename

2004-04-04 Thread Alessandro Ranellucci
Hi all, I'm rsyncing from FreeBSD box to MacOS X 10.2, both sides running 2.6.0. Every time I launch rsync I get many errors like this: mkstemp "/web/Turur?/.8.jpg.2rYUAO" failed: No such file or directory followed by: unexpected tag 77 rsync error: error in rsync protocol data stream (code