Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 5 Feb 1997 22:44:59 -0800 (PST)
From:      Stranger Bone <ben@narcissus.ml.org>
To:        Karl Denninger <karl@Mcs.Net>
Cc:        "Sean J. Schluntz" <schluntz@pinpt.com>, freebsd-security@freebsd.org, karl@Mcs.Net
Subject:   Re: 2.1.6+++: crt0.c CRITICAL CHANGE
Message-ID:  <Pine.BSF.3.91.970205224216.2937A-100000@narcissus.ml.org>
In-Reply-To: <199702060116.TAA21953@Jupiter.Mcs.Net>

next in thread | previous in thread | raw e-mail | index | archive | help
On Wed, 5 Feb 1997, Karl Denninger wrote:

> > 
> > > I AM PART OF THE SOLUTION.  
> > 
> > > And yes, I WILL submit a pr on this as soon as I can find a few hours to 
> > > do the fix, verify it, and make world to test.  At the same time I post 
> > > it to the committers I'll post it publically, and 24 hours later I post 
> > > the exploit which takes advantage of the problem.
> > 
> > This is being part of the solution?  Telling the world how to hack the systems 
> > of people who don't watch the lists or don't have enough time to patch a 
> > network of systems?  
> > 
> > 24 hours is not enough time for people to get the patch implemented.  You 
> > would be personally sentencing people and their business to death by doing 
> > this.
> > 
> > Would you like it if you were sick for two days and came back to find your 
> > network toast because someone pulled a stunt like that?
> > 
> > -Sean
> > ----------------------------------------------------------------------
> > Sean J. Schluntz                                  <schluntz@pinpt.com>
> 
> Uh, excuse me, but the EXPLOIT has been in ACTIVE use for *TWO MONTHS* now.
> 
> Its *NOT* new.  It is being *ACTIVELY* used by the hacker contingent.
> Therefore, hiding *ANYTHING* at this point serves no purpose.
> 
> How can I possibly "hurt" things at this point...

Don't be ridiculous.  There's a huge difference between not hiding 
something and shouting it from the rooftops.  Just because some people 
have an exploit doesn't mean everyone does.

I resent your playing games with *my* security just to satisfy your 
self-image as the Security Avenger.  I'm not saying that's necessarily 
your motive, but it sure looks that way.

Be careful before you let any genies out of bottles.  They're hard to
stuff back in, and that applies to lost credibility as much as it does to
lost security. 
 
> --
> -- 
> Karl Denninger (karl@MCS.Net)| MCSNet - The Finest Internet Connectivity
> http://www.mcs.net/~karl     | T1's from $600 monthly to FULL DS-3 Service
> 			     | 99 Analog numbers, 77 ISDN, Web servers $75/mo
> Voice: [+1 312 803-MCS1 x219]| Email to "info@mcs.net" WWW: http://www.mcs.net/
> Fax:   [+1 773 248-9865]     | 2 FULL DS-3 Internet links; 400Mbps B/W Internal
> 



 Ben

"You have your mind on computers, it seems."




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?Pine.BSF.3.91.970205224216.2937A-100000>