[12180] in bugtraq
Re: RFP9903: AeDebug vulnerability
daemon@ATHENA.MIT.EDU (Joe Melhado)
Fri Oct 8 18:59:02 1999
Mime-Version: 1.0
Content-Type: text/plain; charset="us-ascii"; format=flowed
Message-Id: <4.2.0.58.19991006174047.00bde290@mail.lanline.com>
Date: Wed, 6 Oct 1999 17:43:16 -0400
Reply-To: subs@dynsol.com
From: Joe Melhado <subs@DYNSOL.COM>
X-To: BUGTRAQ@SECURITYFOCUS.COM
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To: <3.0.3.32.19991005112441.042e3e60@mail.mindspring.com>
At 02:24 PM 10/5/99 , David LeBlanc wrote:
>One other thing to consider is that when user processes crash, they can
>sometimes create a user.dmp file, which like UNIX-style core files can
>sometimes contain information useful to an attacker. There is a way to
>turn this off, but I don't recall what it is at the moment.
Control panel / system / startup shutdown
Clear the "Write debugging information to" checkbox
Joe