OSEC

Neohapsis is currently accepting applications for employment. For more information, please visit our website www.neohapsis.com or email hr@neohapsis.com
 
Re: [discuss] Replying to mail on exploits

From: John C. Danielson (jdii1215johndanielsonii.com)
Date: Tue Nov 25 2003 - 20:11:29 CST


Vincent Danen wrote:

>
> On Nov 25, 2003, at 15:04, Vox wrote:
>
>>> Folks, do me a favour. If someone posts something to exploits (like
>>> Jordan did), please make your replies on discuss... exploits is
>>> somewhat of a read-only "announce" type list.
>>
>>
>> Uhm...why don't you just setup the reply-to on exploits to point to
>> discuss and save yourself the headaches? :)
>
>
> It should be doing that already... IIRC, I set it up to do that when I
> set the list up initially.
>
> Some people's email clients work differently, however, so setting that
> is never fool-proof.
>
> ---
> MandrakeSoft Security; http://www.mandrakesecure.net/
> Online Security Resource Book; http://linsec.ca/
> "lynx -source http://linsec.ca/vdanen.asc | gpg --import"
> {FE6F2AFD : 88D8 0D23 8D4B 3407 5BD7 66F9 2043 D0E5 FE6F 2AFD}

Vincent:

Thanks for the excellent job you and others are doing with Mandrake 9.2
security stuff and the way Mandrake behaves. It is more and more the
best distro out there, IMHO.

John-- who runs Thunderbird .3 as mail client, KDE 3.1.3, Opera as
browser as my memory amoutn degredation issues were traced to Mozilla of
1.5 and down (browser part) having a closeout routine that left KDe
reserving space for it in hung\sleeping kdeinit sessions and did not
reuse the kdeinit as kde just spawned a new session per page accessed in
Mozilla and when exiting cleared only the WINDOW resources and not the
underlying stuff. This is not a pure Mandrake issue, but could be
addressed with handling of a bundling issue-- I think Mozilla ahould be
dropped, Thunderbird included, and Opera 7.22 non-reg, which feeds TEXT
ads for less intrusion than the banner in non-reg (and I registered it
for both O\S environments I use) used to have should be in the bundle at
least as an alternative.

This might be the wrong place, but BugTraq is absolutely not the place
for this input strategy so I stick it here as it is something that might
well be passed along to be looked at. The newer stock kernels (I use
Enterprise 2.4.22-10-latest)are better on my P4 also, and networking is
much better over here in US. Curiously, with this combo and the latest
folding 4.00 Pre1 client, I get 1.5X to 2X the folding pointage
throughput as I used to get also-- this means twice as much work goes to
Stanford, and that is my priority.

Excellent security hole stomping and filling job, I like the fact also
that Mandrake devs are on TOP of that BIG TIME.

John.