Skip site navigation (1)Skip section navigation (2)
Date:      Wed,  5 Feb 97 17:24:40 Pacific Standard Time
From:      "Sean J. Schluntz"  <schluntz@pinpt.com>
To:        Karl Denninger  <karl@Mcs.Net>
Cc:        freebsd-security@freebsd.org, karl@Mcs.Net
Subject:   Re: 2.1.6+++: crt0.c CRITICAL CHANGE 
Message-ID:  <Chameleon.855192531.List@journeyman>
References:  <199702060116.TAA21953@Jupiter.Mcs.Net> 

next in thread | previous in thread | raw e-mail | index | archive | help
> > > I AM PART OF THE SOLUTION.  
> > 
> > > And yes, I WILL submit a pr on this as soon as I can find a few hours to 

> > > do the fix, verify it, and make world to test.  At the same time I post 
> > > it to the committers I'll post it publically, and 24 hours later I post 
> > > the exploit which takes advantage of the problem.
> > 
> > This is being part of the solution?  Telling the world how to hack the 
systems 
> > of people who don't watch the lists or don't have enough time to patch a 
> > network of systems?  
> > 
> > 24 hours is not enough time for people to get the patch implemented.  You 
> > would be personally sentencing people and their business to death by doing 

> > this.
> > 
> > Would you like it if you were sick for two days and came back to find your 

> > network toast because someone pulled a stunt like that?
> > 

> Uh, excuse me, but the EXPLOIT has been in ACTIVE use for *TWO MONTHS* now.
> 
> Its *NOT* new.  It is being *ACTIVELY* used by the hacker contingent.
> Therefore, hiding *ANYTHING* at this point serves no purpose.
> 
> How can I possibly "hurt" things at this point...

If the exploit is already public then what difference to the FBSD community 
make by you posting it?

By giving a large pointer saying, look here, come after us!!  Again, this will 
be of no help to those who do not monitor the lists and just rely on the CD 
that is shipped automatically (As mine is) when it is ready.

Being part of the problem is not being part of the solution.

If you want to follow up, do so in private, that way we don't waist other 
people time.

-Sean
----------------------------------------------------------------------
Sean J. Schluntz                                  <schluntz@pinpt.com>
Manager, Support Services                        ph. 408.997.6900 x222
PinPoint Software Corporation                    fx. 408.323.2300
6155 Almaden Expressway, Suite 100 
San Jose, CA.  95120                             http://www.pinpt.com/

Local Time Sent: 02/05/97 17:24:40
----------------------------------------------------------------------




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Chameleon.855192531.List>