From owner-freebsd-security Wed Jun 26 9:57:27 2002 Delivered-To: freebsd-security@freebsd.org Received: from lariat.org (lariat.org [63.229.157.2]) by hub.freebsd.org (Postfix) with ESMTP id B685837B401 for ; Wed, 26 Jun 2002 09:57:07 -0700 (PDT) Received: from mustang.lariat.org (IDENT:ppp1000.lariat.org@lariat.org [63.229.157.2]) by lariat.org (8.9.3/8.9.3) with ESMTP id KAA12004; Wed, 26 Jun 2002 10:56:57 -0600 (MDT) X-message-flag: Warning! Use of Microsoft Outlook is dangerous and makes your system susceptible to Internet worms. Message-Id: <4.3.2.7.2.20020626105413.02275240@localhost> X-Sender: brett@localhost X-Mailer: QUALCOMM Windows Eudora Version 4.3.2 Date: Wed, 26 Jun 2002 10:56:46 -0600 To: Attila Nagy From: Brett Glass Subject: Re: The "race" that Theo sought to avoid has begun (Was: OpenSSH Advisory) Cc: freebsd-security@FreeBSD.ORG In-Reply-To: References: <4.3.2.7.2.20020626103956.02291aa0@localhost> <4.3.2.7.2.20020626101626.02274c80@localhost> <200206261452.AAA26617@caligula.anu.edu.au> <5.1.0.14.0.20020626103651.048ec778@marble.sentex.ca> <5.1.0.14.0.20020626110043.0522ded8@marble.sentex.ca> <4.3.2.7.2.20020626101626.02274c80@localhost> <4.3.2.7.2.20020626103956.02291aa0@localhost> Mime-Version: 1.0 Content-Type: text/plain; charset="us-ascii" Sender: owner-freebsd-security@FreeBSD.ORG Precedence: bulk List-ID: List-Archive: (Web Archive) List-Help: (List Instructions) List-Subscribe: List-Unsubscribe: X-Loop: FreeBSD.org At 10:51 AM 6/26/2002, Attila Nagy wrote: >Correct me, if I'm wrong, but people, called "script kiddies" can't really >code. Some of them can. They share their scripts with the others. >Ppl, before you are going crazy, think a little. >Theo did you a favor when he released his letter. Why? Because now all of >you are using privsep, Alas, Theo's letter said that people had until July 1 to implement PrivSep before the details of the bug were revealed. Since many admins can't take whole farms of production machines down during the week, I know of several who were planning to implement PrivSep this coming weekend. The early announcement by ISS has put them and their organizations at risk. --Brett To Unsubscribe: send mail to majordomo@FreeBSD.org with "unsubscribe freebsd-security" in the body of the message