<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Is Novell Ignoring Critical Security Problems?</title>
	<atom:link href="http://techrights.org/2008/06/01/novell-security-vanity/feed/" rel="self" type="application/rss+xml" />
	<link>http://techrights.org/2008/06/01/novell-security-vanity/</link>
	<description>Free Software Sentry – watching and reporting maneuvers of those threatened by software freedom</description>
	<lastBuildDate>Tue, 07 Feb 2012 14:00:35 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
	<item>
		<title>By: Roy Schestowitz</title>
		<link>http://techrights.org/2008/06/01/novell-security-vanity/comment-page-2/#comment-39152</link>
		<dc:creator>Roy Schestowitz</dc:creator>
		<pubDate>Sun, 23 Nov 2008 23:23:25 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2008/06/01/novell-security-vanity/#comment-39152</guid>
		<description>&lt;blockquote&gt;
sounds more like a WindowsXP exploit to me…
&lt;/blockquote&gt;

Ah. The blame game again.</description>
		<content:encoded><![CDATA[<blockquote><p>
sounds more like a WindowsXP exploit to me…
</p></blockquote>
<p>Ah. The blame game again.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Jose_X</title>
		<link>http://techrights.org/2008/06/01/novell-security-vanity/comment-page-1/#comment-39093</link>
		<dc:creator>Jose_X</dc:creator>
		<pubDate>Sun, 23 Nov 2008 20:48:36 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2008/06/01/novell-security-vanity/#comment-39093</guid>
		<description>&gt;&gt; sounds more like a WindowsXP exploit to me… 

If it&#039;s accurate, I don&#039;t see how that could be anything but a network auth issue. Kerberos (to take an example and assuming it&#039;s configured properly) won&#039;t allow you to use any services if you can&#039;t authenticate with each server providing the service. You can&#039;t get the initial auth tickets if you never provided the correct password in the beginning. So Kerberos, short of bugs or some other failure, would not have this problem no matter what the client did... a....

OK, I take that back partially. If the client is compromised with inside information from the server (ie, a server breach happened already, possibly due to leaked information from insiders), then that client can compromise the system as described if so programmed. Essentially, this means whoever compromised the client knows the admin passwords (or whatever info is needed) so that the client at login can work on your behalf to pull off this &quot;trick&quot;.

Of course, the method described can&#039;t happen if the auth server info is secure no matter what a rogue client does.. unless the protocol or the implementation are faulty, which is, I think, what is being suggested is the case here for Netware.</description>
		<content:encoded><![CDATA[<p>&gt;&gt; sounds more like a WindowsXP exploit to me… </p>
<p>If it&#8217;s accurate, I don&#8217;t see how that could be anything but a network auth issue. Kerberos (to take an example and assuming it&#8217;s configured properly) won&#8217;t allow you to use any services if you can&#8217;t authenticate with each server providing the service. You can&#8217;t get the initial auth tickets if you never provided the correct password in the beginning. So Kerberos, short of bugs or some other failure, would not have this problem no matter what the client did&#8230; a&#8230;.</p>
<p>OK, I take that back partially. If the client is compromised with inside information from the server (ie, a server breach happened already, possibly due to leaked information from insiders), then that client can compromise the system as described if so programmed. Essentially, this means whoever compromised the client knows the admin passwords (or whatever info is needed) so that the client at login can work on your behalf to pull off this &#8220;trick&#8221;.</p>
<p>Of course, the method described can&#8217;t happen if the auth server info is secure no matter what a rogue client does.. unless the protocol or the implementation are faulty, which is, I think, what is being suggested is the case here for Netware.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Dan O'Brian</title>
		<link>http://techrights.org/2008/06/01/novell-security-vanity/comment-page-1/#comment-11554</link>
		<dc:creator>Dan O'Brian</dc:creator>
		<pubDate>Sun, 01 Jun 2008 22:57:36 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2008/06/01/novell-security-vanity/#comment-11554</guid>
		<description>sounds more like a WindowsXP exploit to me...</description>
		<content:encoded><![CDATA[<p>sounds more like a WindowsXP exploit to me&#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Roy Schestowitz</title>
		<link>http://techrights.org/2008/06/01/novell-security-vanity/comment-page-1/#comment-11522</link>
		<dc:creator>Roy Schestowitz</dc:creator>
		<pubDate>Sun, 01 Jun 2008 16:48:37 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2008/06/01/novell-security-vanity/#comment-11522</guid>
		<description>Now talking on #boycottnovell
* heinlein.freenode.net sets mode +n #boycottnovell
* heinlein.freenode.net sets mode +s #boycottnovell
* #boycottnovell :[freenode-info] if you need to send private messages, please register: http://freenode.net/faq.shtml#privmsg</description>
		<content:encoded><![CDATA[<p>Now talking on #boycottnovell<br />
* heinlein.freenode.net sets mode +n #boycottnovell<br />
* heinlein.freenode.net sets mode +s #boycottnovell<br />
* #boycottnovell :[freenode-info] if you need to send private messages, please register: <a href="http://freenode.net/faq.shtml#privmsg" rel="nofollow">http://freenode.net/faq.shtml#privmsg</a></p>
]]></content:encoded>
	</item>
	<item>
		<title>By: patenttrollssuck.exe</title>
		<link>http://techrights.org/2008/06/01/novell-security-vanity/comment-page-1/#comment-11519</link>
		<dc:creator>patenttrollssuck.exe</dc:creator>
		<pubDate>Sun, 01 Jun 2008 16:15:46 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2008/06/01/novell-security-vanity/#comment-11519</guid>
		<description>roy, any word on #boycottnovell @ freenode IRC? =)</description>
		<content:encoded><![CDATA[<p>roy, any word on #boycottnovell @ freenode IRC? =)</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Uncle_Sam</title>
		<link>http://techrights.org/2008/06/01/novell-security-vanity/comment-page-1/#comment-11517</link>
		<dc:creator>Uncle_Sam</dc:creator>
		<pubDate>Sun, 01 Jun 2008 15:59:04 +0000</pubDate>
		<guid isPermaLink="false">http://boycottnovell.com/2008/06/01/novell-security-vanity/#comment-11517</guid>
		<description>Only thing MS has done is write software/technology/specifications that works only on their platform. Milk it all you can.</description>
		<content:encoded><![CDATA[<p>Only thing MS has done is write software/technology/specifications that works only on their platform. Milk it all you can.</p>
]]></content:encoded>
	</item>
</channel>
</rss>

