Re: [BUG][FIX] Re: NEWSCARD * Publish and fetch permanent named records via Network News
Stefan Claas <[email protected]>
| Newsgroups | alt.cypherpunks,alt.privacy.anon-server,sci.crypt |
|---|---|
| Organization | To protect and to server |
| Message-ID | <[email protected]> |
Byrl Raze Buckbriar wrote: > You might also try to post some test messages using tuff mode and reveal the keys publicly, so others can try to 'get' and 'show' them, and see if they encounter any bugs on their individual platforms or distros. The 'tuff' keygen in the script is very much overkill, too. When it generates a random key, it makes sure it is gangbusters bonzo bonkers random. Will do. > I wonder if it is possible to craft a encrypted message that will decrypt as a shell bomb, exploiting the shell or grabbing an unauthorized path in the script. I think that 'less' in standard terminals is pretty secure against such stuff, but someone might find a way to hack into a file path before it gets piped to less. That is not my area of expertise so any suggestions or breaks would be appreciated. I know shell bombs, but they have to been executet in bash directly IIRC, not sure if they would work with NEWSCARD, but I do not try it out. Regards Stefan -- Onion Courier Home Server Mon-Fri 15:00-21:00 UTC Sat-Sun 11:00-21:00 UTC ohpmsq5ypuw5nagt2jidfyq72jvgw3fdvq37txhnm5rfbhwuosftzuyd.onion:8080 inbox age1yubikey1qv5z678j0apqhd4ng7p22g4da8vxy3q5uvthg6su76yj0y8v7wp5kvhstum