Re: Y2K bug in Shadow IDS (fwd)

From: Alfred Huger (ahat_private)
Date: Sun Jan 02 2000 - 14:13:38 PST

  • Next message: Georgi Guninski: "Hotmail security hole - injecting JavaScript using <IMG"

    Alfred Huger
    VP of Engineering
    SecurityFocus.com
    
    ---------- Forwarded message ----------
    Date: Sun, 2 Jan 2000 17:12:14 -0500 (EST)
    From: Peter W <peterwat_private>
    To: Alfred Huger <ahat_private>
    Subject: Re: Y2K bug in Shadow IDS
    
    At 1:00pm Jan 2, 2000, Alfred Huger wrote:
    
    > I changed the top of 'sensor/variables.ph' into
    >
    >         # We need various timestamps all over the place
    >         @T = localtime;
    >         if ($T[5] > 99) {
    >         $T[5] -= 100;
    >         }
    
    Or
    	@T = localtime;
    	$T[5] %= 100;
    
    > By the way, the Shadow perl scripts also use /tmp a lot with
    > predictable file names, so local exploits are possible,
    > but this is more of a Bugtraq issue I guess.
    
    Fun.
    



    This archive was generated by hypermail 2b30 : Fri Apr 13 2001 - 15:25:38 PDT