Just zis Guy said:
Nope. That's why we have all the worm outbreaks - they all
exploit the same fundamental weaknesses in Outhouse.
You mean the weakness of the users who opens attachements
from people they don't know?
Tony
A community for cyclists, gear, training and racing.
UK and Europe · Public discussion
This thread is locked and is currently read-only.
Thread navigation
Go to the original post, the replies on this page, or the latest preserved contribution.
Thread details
The navigation and discussion metadata provide context. Posts remain in their original chronological order.
Just zis Guy said:
Nope. That's why we have all the worm outbreaks - they all
exploit the same fundamental weaknesses in Outhouse.
You mean the weakness of the users who opens attachements
from people they don't know?
Tony
On Sat, 6 Mar 2004 20:17:15 -0000, "Tony Raven"
<[email hidden]> wrote in message
<[email hidden]>:
Quoted message said:You mean the weakness of the users who opens attachements
from people they don't know?
No, the lack of execution controls and the insecure
directory.
You can make Outhouse more secure by forcing it to do all
mail as text-only, but most people don't do that.
--
Guy
===
May contain traces of irony. Contents liable to settle after posting.
chapmancentral.demon.co.ukchapmancentral.demon.co.ukOpen ↗
88% of helmet statistics are made up, 65% of them at Washington University
"Just zis Guy, you know?" <[email hidden]> wrote in message
"]news:[email hidden]...
Quoted message said:On Sat, 6 Mar 2004 20:17:15 -0000, "Tony Raven" <junk@raven-
family.com> wrote in message <[email hidden]-
berlin.de>:Quoted message said:You mean the weakness of the users who opens attachements
from people
they
Quoted message said:Quoted message said:don't know?
No, the lack of execution controls and the insecure
directory.You can make Outhouse more secure by forcing it to do all
mail as text-only, but most people don't do that.
This doesn't qualify as a security hole - I'm talking about
a situation where you are exposed and there is nothing you
can do about it.
Sky Fly said:
This doesn't qualify as a security hole - I'm talking
about a situation where you are exposed and there is
nothing you can do about it.
Eh? It's only a security hole if it's unfixable?
So, if you were in charge of bank security, you would have
cash in open boxes and people would help themselves to what
was theirs. This would obviously not be a security hole,
because although someone might take it all, you could do
something about it, if you wanted.
A security hole is a hole in the security, whether it's one
that you could have treated or not, surely. (No, that's not
a hole in that fence, because I could put a patch on it).
regards, Ian SMith
--
|\ /| no .sig
|o o|
|/ \|
On Sun, 7 Mar 2004 00:21:47 -0000, "Sky Fly" <[email hidden]>
wrote in message : said:This doesn't qualify as a security hole - I'm talking about
a situation where you are exposed and there is nothing you
can do about it.
That's a strange notion. You can completely disable all
scripting in outhouse, and that makes it more secure - it
also makes it worthless as a groupware platform (one of its
claimed functions). You can make it much more secure by
disconnecting your computer from the Internet completely.
Each successive worm exploits the same fundamental flaws in
Outlook. Microsoft are now adding digital rights management
to make it impossible for any non-Windows user to read your
email, but they have not announced the introduction of
execution controls or directory security.
For a few choice Outlook problems see:ol=certadv&col=incnotes&col=vulnotes&qt=Outlook&charset=iso-
8859-1>
--
Guy
===
May contain traces of irony. Contents liable to settle after posting.
chapmancentral.demon.co.ukchapmancentral.demon.co.ukOpen ↗
88% of helmet statistics are made up, 65% of them at Washington University
you know? said:You can completely disable all scripting in outhouse, and
that makes it more secure - it also makes it worthless as
a groupware platform (one of its claimed functions).
Outlook doesn't do news groups, and Outlook Express is not
groupware. Also, afaik, Outlook does not rely on client-side
scripting for its groupware functions.
To make OE as safe as possible:
- Tools
- Options
- Read
- uncheck "Automatically download in preview"
- check "Read all as plain text"
- Receipts
- select "Never send receipt"
- Send
- uncheck "Reply using same format"
- select "Mail format: plain text"
- select "News format: plain text"
- Security
- select "Restricted sites zone"
- check "Warn when sending mail as me"
- check "Don't save or open unsafe attachments"
- Connection
- check "Ask before switching" Then open Internet
Options from Control Panel, tab Security, select
Restricted sites, click Custom level, and select
Disable for all settings.
On Sun, 07 Mar 2004 14:50:58 +0100, Ewoud Dronkert <[email hidden]>
wrote in message : said:Outlook doesn't do news groups, and Outlook Express is not
groupware. Also, afaik, Outlook does not rely on client-
side scripting for its groupware functions.
Unless you believe Microsoft (which is, I agree, unwise).
But what do I care? I use a groupware platform which has
execution controls, and email and news software which don't
have Outlook's vulnerabilities. When I use OE I set it to
text-only (which doesn't necessarily prevent all scripts
running, MS for some reason included plain-text scripting in
OE6) and of course I run virus checkers. Which is the point:
I reckon Gates has shares in Symantec and Network
Associates, just as he does in Intel.
--
Guy
===
May contain traces of irony. Contents liable to settle after posting.
chapmancentral.demon.co.ukchapmancentral.demon.co.ukOpen ↗
88% of helmet statistics are made up, 65% of them at Washington University
you know? said:Quoted message said:afaik, Outlook does not rely on client-side scripting for
its groupware functions.Unless you believe Microsoft
Oh OK. Can you say where they say? Tnx.
On Sun, 07 Mar 2004 15:29:08 +0100, Ewoud Dronkert <[email hidden]>
wrote in message : said:Quoted message said:Quoted message said:afaik, Outlook does not rely on client-side scripting
for its groupware functions.
Unless you believe Microsoft
Oh OK. Can you say where they say? Tnx.
That was from MSDN back in the days when I was trying to
make Outhouse do groupware. Maybe it's changed. Or maybe
not. Maybe you can sign VBScript now and MS applications
include execution controls to validate the script
signatures. Or maybe not.
Me, I use an envronment with four choices of scripting
language all protected by signatures and ECLs.
--
Guy
===
May contain traces of irony. Contents liable to settle after posting.
chapmancentral.co.ukchapmancentral.co.ukOpen ↗
88% of helmet statistics are made up, 65% of them at Washington University
On Sun, 7 Mar 2004 20:48:49 -0000, "Sky Fly" <[email hidden]>
wrote in message : said:I looked at the first few issues in the link you posted,
and it seems that MS have released patches for these
But they haven't fixed the core vulnerabilities: lack of
execution controls and directory weaknesses.
Quoted message said:Anyway, I can see that you hate OE so much you've renamed
it 'Outhouse'
That is a normal replacement. It is responsible for so much
[censored], what else could one call it? ;-)
--
Guy
===
May contain traces of irony. Contents liable to settle after posting.
chapmancentral.co.ukchapmancentral.co.ukOpen ↗
88% of helmet statistics are made up, 65% of them at Washington University
"Just zis Guy, you know?" <[email hidden]> wrote in message
"]news:[email hidden]...
Quoted message said:On Sun, 7 Mar 2004 00:21:47 -0000, "Sky Fly"
<[email hidden]> wrote in message <[email hidden]-
berlin.de>:Quoted message said:This doesn't qualify as a security hole - I'm talking
about a situation where you are exposed and there is
nothing you can do about it.That's a strange notion. You can completely disable all
scripting in outhouse, and that makes it more secure - it
also makes it worthless as a groupware platform (one of
its claimed functions). You can make it much more secure
by disconnecting your computer from the Internet
completely.Each successive worm exploits the same fundamental flaws
in Outlook. Microsoft are now adding digital rights
management to make it impossible for any non-Windows user
to read your email, but they have not announced the
introduction of execution controls or directory security.For a few choice Outlook problems see:
<url:http://search.cert.org/query.html?col=certadv&col=incn-
otes&col=vulnotes &qt=Outlook&charset=iso-8859-1>
Guy,
I looked at the first few issues in the link you posted, and
it seems that MS have released patches for these, which is
what I was saying before. I don't know about using OE for
groupware, but I believe if you apply the released patches
and do the stuff posted by Ewoud, it should be OK for a
single user. So even though I agree that the default
settings in OE predispose the user to getting all sorts of
nasty stuff on their machine, I don't see that OE qualifies
as a security hole.
Anyway, I can see that you hate OE so much you've renamed it
'Outhouse', so I suspect you'll just come back right at me
with 101 reasons to be lined up against the wall and shot
for using it. I would suggest that rather than debate this
topic (which you're not likely to give ground on), let's
choose something more on-topic (like the demerits and
demertis of recumbents bicycles).
Cheers,
--
Akin
aknak at aksoto dot idps dot co dot uk
sdorrity said:I started using cycling forums when my local usenet feed
started getting flakey. At first I just thought I was very
unpopular, then I found out that although I was getting an
up to date feed my own posts were not getting out at all.
I use some of the "in house" cyclingforums forums as well.
news.individual.net
Free, generally reliable, news server - you have to register
on the website, but that's all.
--
Carol Hague "If tin whistles are made of tin, what do they
make fog horns out of?"
- Lonnie Donegan
MartinM said:errr, does anyone else just do google, then groups, then
cycling? or am I missing something?
About 3-4 hours time delay using Google, but it *works* so
that's not the world's biggest caveat. To have a fast usenet
feed someone has to have one accessible to you. I have that
for u.r.c but not for, say, rec.ski.backcountry, so I use
Google Groups for that.
Pete.
--
Peter Clinch University of Dundee Tel 44 1382 660111 ext.
33637 Medical Physics, Ninewells Hospital Fax 44 1382 640177
Dundee DD1 9SY Scotland UK net [email hidden]
dundee.ac.uk~pjclinchOpen ↗
(MartinM) said:So is it like the private email list I am in, every single
reply to a thread will appear in my inbox unless I KF? if
so I would much prefer to use google. ;-)
Only if people send you an e-mail reply. Most messages will
just get sent to the news server that you can connect to at
your leisure and read them.
The advantage of a real news server/reader combination is
flexibility if you ask me. I can get the messages in the
form I want rather than the way the web server presents them
to me. Especially if you are doing offline reading.
Ian
Active in the last 60 minutes
0 users · 0 guests ·0 bots ·0 total
No signed-in users are active right now.
No known search crawlers active right now.