[14971] in bugtraq

home help back first fref pref prev next nref lref last post

Re: RFP2K04: Mining BlackICE with RFPickAxe

daemon@ATHENA.MIT.EDU (rain forest puppy)
Fri May 19 20:54:17 2000

Mime-Version: 1.0
Content-Type: TEXT/PLAIN; charset=US-ASCII
Message-Id:  <Pine.LNX.4.10.10005191314520.11537-100000@eight.wiretrip.net>
Date:         Fri, 19 May 2000 13:16:23 -0500
Reply-To: rain forest puppy <rfp@WIRETRIP.NET>
From: rain forest puppy <rfp@WIRETRIP.NET>
X-To:         Andrew Lambeth <andrew@nfr.net>
To: BUGTRAQ@SECURITYFOCUS.COM
In-Reply-To:  <39258513.C4FB32@nfr.net>

> No version of the NFR windows client has ever been in any way vulnerable
> to any form or variation of the exploit discussed in this advisory.
>
> The NFR windows client does not store any information in a Microsoft
> .mdb file nor does it use Microsoft Access or Jet in any way.

I apologize, I have reviewed tons of IDS consoles, and I was working from
memory.  I will make a public note indicating NFR does not use .mdb.

Thanks for dropping me a note,
- rfp

home help back first fref pref prev next nref lref last post