Slashdot Mirror


User: taviso

taviso's activity in the archive.

Stories
0
Comments
46
First seen
Last seen
Profile
(view on slashdot.org)

Comments · 46

  1. Re:Change controlled environments? on Google Advocates 7-Day Deadline For Vulnerability Disclosure · · Score: 1

    Hackers don't give a shit about your change control, they're not going to give you a head start because you're slow to respond to threats.

    How does not telling anyone that people are actively exploiting this change that?

  2. Re:Ok... on Serious Security Bugs Found In Android Kernel · · Score: 4, Interesting

    Odd question.

    I don't know about three days, but certainly under a week, which is completely normal in free software. Proprietary vendors generally want between six months and two years, but free software vendors and projects very rarely ask for more than a week or two delay before publication.

    In fact, Linus famously tells people not to tell him about any security issue you want kept secret for more than a week, as he will just go ahead and fix it.

  3. Re:Ok... on Serious Security Bugs Found In Android Kernel · · Score: 5, Interesting

    Odd, I don't know why you're picking on me, but I assume "Android Kernel" is marketing-speak for "Linux", in which I've reported found and fixes dozens of flaws over the years.

    As you're so interested, here are some from the last month or two that you can take a look at.

    CVE-2010-3080, A use-after-free in snd_seq_oss_open
    CVE-2010-2960, A to-userspace dereference in keyctl_session_to_parent.
    CVE-2010-2954, Kernel panic and to-userspace dereference in AF_IRDA sockets.
    CVE-2010-3067, Various problems with aio (things like aio_submit())

    The coverity results I've seen in the past are generally very low quality with a high density of chaff. I haven't seen the report they're talking about, but would be surprised if there were any noteworthy findings with any significant security impact. The only report I've seen them publish that had any convincing vulnerabilities was in 2006, where they found a verifiable privilege escalation in XFree86 (due to a pretty horrendous typo).

    I'm a little saddened that you so readily associate me with Windows security, where as I consider myself primarily a Linux security developer, but I guess I'm flattered that where I spend my time is so important to you.

    (perhaps a little creepy, though).

  4. Re:Elite on Google Up Ante For Disclosure Rules, Increases Bug Bounty · · Score: 1

    You didn't elect me your doctor either, but I'm sure you would like me to tell you if you water supply was poisoned.

  5. Re:Elite on Google Up Ante For Disclosure Rules, Increases Bug Bounty · · Score: 3, Insightful

    Actually, his comment was entirely accurate.

    I've reported dozens of critical vulnerabilities in Microsoft software over the years, and I still have multiple open cases with Microsoft security, this particular case wasn't as simple as you have assumed. I would not be so presumptuous to explain the ethics of your work to you, but evidently you believe you're qualified to lecture me in mine.

    If I were to read the sensationalised lay-press coverage of your latest publication or project, would it prepare me to write a critique of your
    work?

  6. Re:Free time. on Newly-Found Windows Bug Affects All Versions Since NT · · Score: 5, Funny

    Applications Welcome ;-)

  7. Re:OK, just a second now... on Microsoft Plugs "Drive-By" and 14 Other Holes · · Score: 4, Informative

    I discovered this bug (check the credit section in the advisory), so can explain. The bug is in parsing a component of TTF files, which are handled by the GDI kernel subsystem in Windows. Anything that tries to load fonts can be used to exploit this vulnerability, as they will eventually reach this code, Internet Explorer just happens to be the easiest way to reach it remotely.

    Other browsers _are_ affected, the difference is that there's only one level of indirection before the vulnerable code in Internet Explorer, and at least two in other browsers. This is because IE supports EOT files directly, which via TTLoadEmbeddedFont() are decoded and passed straight to GDI, where as other browsers take a TTF input, convert it into an EOT and then pass that to TTLoadEmbeddedFont, so you have to convince three different chunks of code your input is valid (the browser, t2embed, then gdi), instead of just two in IE.

    If you use any browser that support @font-face on Windows (Safari, Firefox 3.5+), you should still patch and reboot.

  8. Re:Security through Obscurity? on Local Privilege Escalation On All Linux Kernels · · Score: 3, Interesting

    Actually, it is possible to map at NULL in Windows, which is just as plagued by NULL pointer dereferences as Linux is.

    Try this:

    BaseAddress = (PVOID) 0x00000001; // (1 & ~PAGE_SIZE) == NULL
    RegionSize = 0x1000;
    NtAllocateVirtualMemory(GetCurrentProcess(), &BaseAddress, 0, &RegionSize, MEM_COMMIT | MEM_RESERVE, PAGE_EXECUTE_READWRITE);

  9. Re:Block Flash wherever possible on Flash Vulnerabilities Affect Thousands of Sites · · Score: 1

    Interesting that you consider flashblock a security tool (I use flashblock as well, but simply to suppress the onslaught of distracting ads).

    If there was a vulnerability discovered in flash player, flashblock would provide little protection, to demonstrate my point, install flashblock and click here (harmless testcase). Did flashblock prevent flash player from crashing, or taking down firefox?

    (to pre-empt replies, yes i do know about noscript)

  10. Re:If you can get high before you watch this on Hitachi Goes Perpendicular · · Score: 5, Informative

    $ sudo emerge media-gfx/swftools
    # non gentoo users: http://www.quiss.org/swftools/
    $ wget http://www.hitachigst.com/hdd/research/images/pr%2 0images/Get_Perpendicular.swf
    $ swfextract --mp3 Get_Perpendicular.swf
    $ xmms output.mp3

  11. Re:Yea right. on Considering Watercooling Your PC? · · Score: 1

    Oh please, next you'll be telling us water and electricity doesn't mix. [english translation]

  12. Re:Jesus Christ. on Biggest Console System Collection on eBay · · Score: 5, Funny

    What the heck, though, is someone going to do with 78 NES decks?

    Beowulf cluster.

  13. Re:Metisse on Metisse - New Looking Glass Alternative · · Score: 4, Funny

    First Upside-Down Post!

  14. Re:Sorry if redundant... Where can i get classic s on PHP Contest: Revenge of the Apple Eating Robots · · Score: 4, Informative

    it's usually distributed as part of a collection called "bsd games", if you use Linux try here.

  15. Re:The Martian Rovers' engineers' desktops on Whose Desktop Would You Most Like To See? · · Score: 1

    Some people have reported seeing engineers using Xv in the background of tv reports.

    http://www.trilon.com/xv/xvtv.html

  16. Re:sorry.... on Mozilla Thunderbird 0.4 Released · · Score: 2, Funny

    I agree, all software should be named after an animal/celebrity/pokemon that can beat the mascot of competing applications in a fight, that way we can all play top trumps wihle browsing freshmeat.

  17. Re:Linux Lottery? on Red Hat Cornering SCO in Delaware · · Score: 4, Informative

    Ahh, Found the answer in a court transcript, here.

    In sum, SCO's campaign is designed both to slow the growth of
    LINUX, and to reverse its failing fortunes by convincing LINUX users
    that they need to pay SCO a license fee to use the lower-cost LINUX
    operating system. As SCO's own representatives have proclaimed, if SCO
    is successful at this effort, it can add "billions" of dollars in
    undeserved revenues to its declining bottom line. Additionally, SCO's
    campaign is designed to further what, upon information and belief, has
    been referred to as the "LINUX Lottery" -- the ability to reap personal
    profit by carefully timed purchases of SCO stock.

  18. Linux Lottery? on Red Hat Cornering SCO in Delaware · · Score: 4, Interesting

    45. All documents concerning a Linux Lottery or the phrase the "Linux Lottery'.

    Thats a new one on me, anyone have any clue where this phrase comes from or what it means..why are RH interested in it?

  19. Re:RFID is inevitable on And They Shall Know You By Your Books · · Score: 1

    There was a fascinating program about RFID this evening on Radio 4, available on the web here.

    works fine with mplayer, as well..

    $ mplayer rtsp://rmv8.bbc.net.uk/radio4/news/inbusiness/inbu siness.ra

  20. Re:Slashdot County Fair! on Word Processors: One Writer's Retreat · · Score: 1

    > Real men just concatenate their files line by line, don't they?

    You've obviously never heard of TECO.

  21. Thread on Getting Hacked Through Your Terminal · · Score: 4, Informative

    The author went on to have an interesting converstaion with Micahel Jennings, author of Eterm on Bugtraq here.

  22. Re:Slashdotted! on The Next Level of X-Box Modding · · Score: 5, Informative

    Mirror here.

    wget --page-requisites --convert-links 'http://www.sweclockers.com/html/artikel/art_03022 5_xbox_mod.php?page=15

  23. Re:apt-get install from Debian on Gestures For The Linux Desktop · · Score: 3, Informative

    fvwm has had this functionality using libstroke since version 2.3.4 (2.5.5 is the latest release)

  24. Re:nice screen shots on Falcon's Eye: a Make-over for Nethack · · Score: 1

    obviously not many brainf*ck coders on slashdot then :)

  25. Re:Windows Clients/hosts? on Has the RIAA Wormed 95% of P2P Networks? · · Score: 5, Informative

    oh please, this comes from the same guy that bought you Hewlett Packard 48 Series Calculators advisory.

    its funny, laugh.