5 msgDSA/DSS keys and DSA 1576-1/CVE-2008-0166.
2 msgopenssl/openssh fixes for lenny (testing)
2 msgopenssl / x509 certs
2 msgleakage of keys?

dowkd.pl - how the blacklist data is generated ?
\ Alexandre Dulaunoy (14 May 2008)
. \ nicolas vigier (14 May 2008)

9 msgRe: [SECURITY] [DSA 1576-1] New openssh package...
4 msgdowkd.pl via Package
1 msgCHAO BAN
48 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
4 msgBroken link on Debian CVE Web page (Was: [SECUR...
11 msgRe: [SECURITY] [DSA 1571-1] New openssl package...
3 msgRe: [SECURITY] [DSA 1575-1] New Linux 2.6.18 pa...
1 msgMystery of Lyle & Louise is Making Headlines
1 msgHerr Bühler Arbeite nicht mehr bei der V-ZUG AG
5 msgRe: [SECURITY] [DSA 1573-1] New php5 packages f...
4 msgRe: [SECURITY] [DSA 1572-1] New php5 packages f...
3 msgQuestion about Security
37 msgsecuring server
1 msgRe: [SECURITY] [DSA 1570-1] New kazehakase pack...
2 msgRe: [SECURITY] [DSA 1569-1] New cacti packages ...
Subject:dowkd.pl - how the blacklist data is generated ?
Group:Debian-security
From:Alexandre Dulaunoy
Date:14 May 2008


 
Hi,

For my understanding, the black list in the dowkd.pl is generated
from the potential remaining entropy source which seems to be
only the PID value added in the pool.

Could we have some false negative[1] when running the dowkd script ?
and would it possible to have the source code of the "black list
generator" application
(especially to see the endianness effect on some arch) ?

Thanks a lot for any info,

adulau

[1] false positive is not an issue but an advantage. As regenerating keys
in this case is a good idea ;-)

--
-- Alexandre Dulaunoy (adulau) -- http://www.foo.be/
-- http://www.foo.be/cgi-bin/wiki.pl/Diary
-- "Knowledge can create problems, it is not through ignorance
-- that we can solve them" Isaac Asimov


--
To UNSUBSCRIBE, email to debian-security-REQUEST
with a subject of "unsubscribe". Trouble? Contact listmaster



© 2004-2008 readlist.com