NODE 4f624f9bMixed Messages / Re: F00FC7C8 Kills P5 AND Re: Major security flaw in Cybercash 2.1.2 (fwd)
nobody@REPLAY.COM (Anonymous)Sun, 9 Nov 1997 06:47:55 +0800
Eric Cordian wrote:
> In comp.sys.intel, the keeper of the Intel Secrets Website,
> rcollins@slip.net (Robert Collins) writes this absolutely amazing
> paragraph:
> > If nobody knew about this problem, nobody would be affected
> > by it.
> > No, I had no desire to publicize the bug.
> Egads. Talk about "Security by Obscurity"!
Robert Hettinga wrote:
> Subject: Major security flaw in Cybercash 2.1.2 (fwd)
> CyberCash v. 2.1.2 has a major security flaw that causes all credit
> card information processed by the server to be logged in a file with
> world-readable permissions. This security flaw exists in the default
> CyberCash installation and configuration.
We at the Electronic Fraud Foundation also have no desire for these
bugs to be publicized. We're making a goddamn fortune off of them.
(Damn near as much as we're making off of our remailer-donation scam.)
Ura Fishpal,
Flounder,
Electronic Fraud Foundation
[Note: You are required by Federal Law to pay me one dollar for reading
this post. Send $1 to EFF, Box 281, Bienfait, Sask. Canada S0C
0M0]
[Note From Your System Administrator: Failure to comply with the above
will result in loss of your access privileges and a hernia.]
NODE 940c1f34Re: Mixed Messages / Re: F00FC7C8 Kills P5 AND Re: Major securityflaw in Cybercash 2.1.2 (fwd)
Jamie Lawrence <jal@acm.org>Sun, 9 Nov 1997 09:08:06 +0800
At 11:33 PM +0100 on 11/8/97, Anonymous wrote:
> Eric Cordian wrote:
> > In comp.sys.intel, the keeper of the Intel Secrets Website,
> > rcollins@slip.net (Robert Collins) writes this absolutely amazing
> > paragraph:
> > > If nobody knew about this problem, nobody would be affected
> > > by it.
> > > No, I had no desire to publicize the bug.
> We at the Electronic Fraud Foundation also have no desire for these
> bugs to be publicized. We're making a goddamn fortune off of them.
> (Damn near as much as we're making off of our remailer-donation scam.)
Hope you're making a kill(1)ing.
Too bad any semi-intelligent entity with access to Alta-Vista can find
enough info to exploit this bug, right now...
Here's to hoping the remailer scam works out better -
-j
--
"This analogy is like lifting yourself by your own bootstraps."
-Douglas R. Hofstadter
_______________________________________________________________
Jamie Lawrence jal@acm.org