[1403] in WWW Security List Archive

home help back first fref pref prev next nref lref last post

Re: A possible suggestion (wrt "Take me off the list")

daemon@ATHENA.MIT.EDU (amonk)
Tue Jan 9 00:15:32 1996

Date: Mon, 8 Jan 1996 09:48:25 -0500 (EST)
From: amonk <amonk@labyrinth.cftnet.com>
To: Massimo Cardaci - Unix System Manager SERCO <Massimo.Cardaci@mail.esrin.esa.it>
cc: www-security@ns2.rutgers.edu, Steff.Watkins@Bristol.ac.uk, welke@ida.org
In-Reply-To: <9601080720.AA22299@valhall.esrin.esa.it>
Errors-To: owner-www-security@ns2.rutgers.edu

Massimo,

Well, I'll know what I think soon (hopefully).  I bought two books on Java
today in the hopes of having the time to read them over soon!

But just a general rule:  Any program that is written to interact with 
the web (perl, shell, C, Java, whatever) introduces the possibility of
"code exploitation".  My advice is to be very carefull with writing your
applets, keeping an eye out for an exploit as you write.  Then, make them
public (post them or whatever) so that they can undergo a peer review.  
Most probably, the input of others will make them better in more apsects
than security.

Regards,

Kyle Amon

------------------------------------------------------------------------------
  Kyle Amon                                  Work: kyle_amon@jabil.com
  System Administrator                       Home: amonk@labyrinth.cftnet.com
  Jabil Circuit, Inc.                                                         
                                                                             
  Homepage: http://labyrinth.cftnet.com/kka                                   
------------------------------------------------------------------------------

On Mon, 8 Jan 1996, Massimo Cardaci - Unix System Manager SERCO wrote:

> hello!
> 
> I believe many people wan't to leave (I was near...) because of the lack
> of interesting topics...
> 
> Can someone initiate new ones ?
> 
> Maybe I'm a newbie, but I'd like to know what You Gurus think about 
> Java Security (I believe Java is WWW-security related topic...)
> 
> Happy New Year to everybody!
> 
> 
> ****************************************************************************
>     _/_/       _/_/ _/ _/ _/  | Massimo Cardaci
>    _/   _/ _/   _/            | ESRIN - V. G. Galilei I-00044 Frascati
>   _/           _/             | mcardaci@mail.esrin.esa.it
>  _/           _/              | http://www.esrin.esa.it:8080/handy/home.html
>   _/           _/             |---------------------------------------------
>  _/           _/              | #include <std/disclaimer.h>
> _/           _/ _/ _/ _/      | #include <std/nonsense.h>
> ****************************************************************************
> 

home help back first fref pref prev next nref lref last post