Skip site navigation (1)Skip section navigation (2)
Date:      Fri, 28 Jan 2000 02:36:54 -0700
From:      Warner Losh <imp@village.org>
To:        Kris Kennaway <kris@hub.freebsd.org>
Cc:        Masafumi NAKANE <max@wide.ad.jp>, serg@dor.zaural.ru, freebsd-security@FreeBSD.ORG, freebsd-bugs@FreeBSD.ORG
Subject:   Re: delegate buffer overflow (ports) 
Message-ID:  <200001280936.CAA60674@harmony.village.org>
In-Reply-To: Your message of "Fri, 28 Jan 2000 00:55:54 PST." <Pine.BSF.4.21.0001280053120.27989-100000@hub.freebsd.org> 
References:  <Pine.BSF.4.21.0001280053120.27989-100000@hub.freebsd.org>  

next in thread | previous in thread | raw e-mail | index | archive | help
In message <Pine.BSF.4.21.0001280053120.27989-100000@hub.freebsd.org> Kris Kennaway writes:
: **************************************
: ** WARNING!!! WARNING!!! WARNING!!! **
: **************************************
: 
: THIS PORT CONTAINS KNOWN SECURITY HOLES WHICH ALLOW A REMOTE ATTACKER TO
: EASILY TAKE CONTROL OF YOUR MACHINE. YOU INSTALL THIS PORT AT YOUR OWN
: RISK!! DON'T COME CRYING TO US IF YOU GET ROOTED BECAUSE OF INSTALLING
: THIS PORT.
: 
: Do you want hackers to be able to take remote control of your
: machine? (y/N):
: 
: then I guess I have no problem with it :-)

I think that your questions are too mildly worded.  :-)

Something more like the following might be acceptible to me :-)


**************************************
** WARNING!!! WARNING!!! WARNING!!! **
**************************************

THIS PORT CONTAINS KNOWN SECURITY HOLES WHICH ALLOW A REMOTE ATTACKER
TO EASILY TAKE CONTROL OF YOUR MACHINE. YOU INSTALL THIS PORT AT YOUR
OWN RISK!! DON'T COME CRYING TO US IF YOU GET ROOTED BECAUSE OF
INSTALLING THIS PORT.  DO NOT INSTALL THIS MACHINE THAT YOU CARE
ABOUT.  YOU ARE STRONGLY ENCOURAGED NOT TO INSTALL THIS PORT.  BAD
THINGS WILL HAPPEN TO YOU AND YOUR CHILDREN UNTO THE SEVENTH
GENERATION IF YOU INSTALL THIS PORT.  PLAGUES OF LOCUS WILL DESEND
FROM THE SKY.  YOUR LIVE MOPPING UP FROM THE HACKER PENETRAIONS WILL
BE A NIGHTMARE.

**************************************
** WARNING!!! WARNING!!! WARNING!!! **
**************************************

To proceed, type "I want hackers to be able to remotely control my
system."
-->I want hackers to be able to remotely control my system

OK.  We're not sure about this.  Please reconsider.  If you are still
insistant about it, type "I'm stupid and I really want this package
installed" now.
-->I'm stupid and I really wnat this package installed

Can't we talk you out of it?  IF not, say proceed:
--> Proceed

**************************************
** WARNING!!! WARNING!!! WARNING!!! **
**************************************

YOU HAVE BEEN WARNED.  YOUR SYSTEM WILL NEVER BE SECURE AGAIN UNTIL
YOU REMOVE THIS PACKAGE.

**************************************
** WARNING!!! WARNING!!! WARNING!!! **
**************************************


To Unsubscribe: send mail to majordomo@FreeBSD.org
with "unsubscribe freebsd-security" in the body of the message




Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?200001280936.CAA60674>