From owner-freebsd-security@FreeBSD.ORG Mon Jun 19 17:24:00 2006 Return-Path: X-Original-To: freebsd-security@freebsd.org Delivered-To: freebsd-security@freebsd.org Received: from mx1.FreeBSD.org (mx1.freebsd.org [216.136.204.125]) by hub.freebsd.org (Postfix) with ESMTP id EB82316A474 for ; Mon, 19 Jun 2006 17:24:00 +0000 (UTC) (envelope-from arne_woerner@yahoo.com) Received: from web30304.mail.mud.yahoo.com (web30304.mail.mud.yahoo.com [68.142.200.97]) by mx1.FreeBSD.org (Postfix) with SMTP id CFE3B43D45 for ; Mon, 19 Jun 2006 17:23:59 +0000 (GMT) (envelope-from arne_woerner@yahoo.com) Received: (qmail 53574 invoked by uid 60001); 19 Jun 2006 17:23:59 -0000 DomainKey-Signature: a=rsa-sha1; q=dns; c=nofws; s=s1024; d=yahoo.com; h=Message-ID:Received:Date:From:Subject:To:In-Reply-To:MIME-Version:Content-Type:Content-Transfer-Encoding; b=o+kmpyvCOVooYYTq9wluJxLkzK72QFJJ+n2/cfE3W3y6Gajsae0V7LeD868kJA2EbUBe3z+SgpsYVq4bd6wNs/LYHHoxFDl9qbnReWzYostv3EGqSHRpAOr3pvnc7jly5oirokTWU/HHk22k7eB5IbYj13MA0auBZf2F8tHcyOs= ; Message-ID: <20060619172359.53572.qmail@web30304.mail.mud.yahoo.com> Received: from [213.54.84.110] by web30304.mail.mud.yahoo.com via HTTP; Mon, 19 Jun 2006 10:23:59 PDT Date: Mon, 19 Jun 2006 10:23:59 -0700 (PDT) From: "R. B. Riddick" To: Nick Borisov , freebsd-security@freebsd.org In-Reply-To: <3bcb4e3f0606190951xef1495dr3c608c8da038a6f5@mail.gmail.com> MIME-Version: 1.0 Content-Type: text/plain; charset=iso-8859-1 Content-Transfer-Encoding: 8bit Cc: Subject: Re: memory pages nulling when releasing X-BeenThere: freebsd-security@freebsd.org X-Mailman-Version: 2.1.5 Precedence: list List-Id: "Security issues \[members-only posting\]" List-Unsubscribe: , List-Archive: List-Post: List-Help: List-Subscribe: , X-List-Received-Date: Mon, 19 Jun 2006 17:24:01 -0000 --- Nick Borisov wrote: > 2006/6/19, R. B. Riddick : > > It was possible to transfer about 20MB of data over about > > one hour from a single IP, that was never seen there before... > > Well, you are not goin' to say that was a great achievement of those > administrators, are you? =) > No, I will not say or write, that they did a good job (especially because it was possible to prove the "attack" after a few seconds (technically - since IPs dont lie!?) and after a few minutes (administratively - since it was about noon, so that the local administrators were present)). There is even a cinema movie and a book about them (somehow there was some loophole before...). Its is called "23", I think... Some people will never learn... http://german.imdb.com/title/tt0126765/ -Arne __________________________________________________ Do You Yahoo!? Tired of spam? Yahoo! Mail has the best spam protection around http://mail.yahoo.com