lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [day] [month] [year] [list]
Message-ID: <20041227085504.GA5027@elf.ucw.cz>
Date: Mon, 27 Dec 2004 09:55:04 +0100
From: Pavel Machek <pavel@....cz>
To: "Thomas C. Greene" <thomas.greene@...register.co.uk>
Cc: NTBugtraq@...tserv.ntbugtraq.com, focus-linux@...urityfocus.com,
        bugtraq@...urityfocus.com, vulnwatch@...nwatch.org,
        full-disclosure@...ts.netsys.com
Subject: Re: *nix data wipe tools


Hi!

> I've posted the final versions of a few simple, free shell scripts that i've 
> been working on to make data hygiene more convenient on *nix systems. Thanks 
> to list members who helped test them and contributed improvements.

Too simple, I'd say. Imagine sensitive file (/etc/shadow?). It is
subsequently freed and now is reused by one-byte /var/something/lock.

No programs I know will wipe this properly, not even on ext2 :-(.

								Pavel
-- 
People were complaining that M$ turns users into beta-testers...
...jr ghea gurz vagb qrirybcref, naq gurl frrz gb yvxr vg gung jnl!
_______________________________________________
Full-Disclosure - We believe in it.
Charter: http://lists.netsys.com/full-disclosure-charter.html


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ