Re: Kryptor for Linux released
Rik Bobbaers <[email protected]>
| Newsgroups | gmane.comp.security.linux |
|---|---|
| Organization | KULueven - LUDIT |
| Message-ID | <[email protected]> |
On Wednesday 23 November 2005 23:41, [email protected] wrote: > The algorithm ARCS-256 bits is not vulnerable, in the way of feasible > attacks, to MD5 collisions. If you want try to make an analysis of the > algorithm so you can notice it. However the white paper of the algorithm > will be released soon. > Before saying something is insecure I suggest you to prove it. before calling something secure, i would suggest picking up a coding tutorial... that extremeftpd looks... well.. horrible (it is (if possible) worse than raveftpd) msg.c is the same "stupidity" all over again, it used to be: len = vsnprintf (buf, strlen(buf),"%s", bla); buf[len] = '\0'; and much more! and you suggest we should trust THAT software is secure??? get real! pretty neat tough... i informed them about a dozen bugs in their ftp daemon, and NO appreciation at all... this means, i'm not gonna disclose any bugs i find (believe me, this was just the beginning, there is absolutely no reason to use rosiello software... more holes than cheddar cheese ;)) -- harry aka Rik Bobbaers K.U.Leuven - LUDIT -=- Tel: +32 485 52 71 50 [email protected] -=- http://harry.ulyssis.org Disclaimer: By sending an email to ANY of my addresses you are agreeing that: 1. I am by definition, "the intended recipient" 2. All information in the email is mine to do with as I see fit and make such financial profit, political mileage, or good joke as it lends itself to. In particular, I may quote it on usenet. 3. I may take the contents as representing the views of your company. 4. This overrides any disclaimer or statement of confidentiality that may be included on your message. Disclaimer: http://www.kuleuven.be/cwis/email_disclaimer.htm