Re: [BUG][FIX] Re: NEWSCARD * Publish and fetch permanent named records via Network News

Stefan Claas <[email protected]>
Newsgroups alt.cypherpunks,alt.privacy.anon-server,sci.crypt
Organization To protect and to server
Message-ID <[email protected]>
Byrl Raze Buckbriar wrote:
 
> You might also try to post some test messages using tuff mode and reveal the keys publicly, so others can try to 'get' and 'show' them, and see if they encounter any bugs on their individual platforms or distros. The 'tuff' keygen in the script is very much overkill, too. When it generates a random key, it makes sure it is gangbusters bonzo bonkers random.

Will do.

> I wonder if it is possible to craft a encrypted message that will decrypt as a shell bomb, exploiting the shell or grabbing an unauthorized path in the script. I think that 'less' in standard terminals is pretty secure against such stuff, but someone might find a way to hack into a file path before it gets piped to less. That is not my area of expertise so any suggestions or breaks would be appreciated.

I know shell bombs, but they have to been executet in bash directly IIRC,
not sure if they would work with NEWSCARD, but I do not try it out.

Regards
Stefan

-- 
Onion Courier Home Server Mon-Fri 15:00-21:00 UTC Sat-Sun 11:00-21:00 UTC
ohpmsq5ypuw5nagt2jidfyq72jvgw3fdvq37txhnm5rfbhwuosftzuyd.onion:8080 inbox
 age1yubikey1qv5z678j0apqhd4ng7p22g4da8vxy3q5uvthg6su76yj0y8v7wp5kvhstum
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.