
DJonesHas ubottu got a slight factoid problem, its just announced about TLS protocol which I'm assuming has come from the RFC query just before, but the end of the factoid is cut short, it stops at "attackers t"09:06
DJonesThat was in #ubuntu at 9:02 uk time09:06
bazhangDJones, saw that. pretty bizarroid09:08
DJonesI was assuming its part the feature just added for bug reports that it picked up the reference & replied09:09
Tm_TDJones: the message length is IRC protocol (implementation) limited, so it got cut off09:46
DJonesTm_T: ok, that would explain it09:46
Tm_Tor I assume it is hitting the limit09:46
jussiyeah, it picks up RFC's also iirc.10:04
jussiGrabs them from an external site, much like the bug tracker - we probably want to turn off rfc's in #ubuntu.10:05
jussiDJones: if you have a sec, could you reply to the irc list and mention this?10:05
DJonesjussi: yeah will do10:06
jussiDJones: thanks10:06
DJonesDo you want it on the thread about the added feature10:07
ubottuThe TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attacke10:42
m4vnot sure what tracker it is ..10:42
m4vah well, I was looking all over the bugtracker configs, but is actually hardcoded in cveSnarfer method, it grabbed http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-355510:47
ubottuThe TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation handshakes with an existing connection, which allows man-in-the-middle attacke10:47
Tm_Thow repetitive10:47
m4vlooks like there's not config for disable the CVE snarfer, if you want it off I can comment it out (until somebody makes a nicer fix)11:00
Tm_Twould it disable it everywhere?11:01
Tm_Thmmm, I'm not sure if that desirable either11:02
m4vobliously, I could do it better and add a config option, but I'm sort of time and removing it is just a one line fix11:02
m4vwe can wait for tsimpson and take a look too.11:03
Tm_Tthanks, must be my new haircut11:10
* Tm_T hides11:10
elkyOh, that's hair? I thought it was a dustpuppy.11:10
jussim4v: I think we leave it untill the next ircc meeting - its not that often that people mention those numbers. Ill have a chat with tsimpson in the meantime11:21
m4vjussi: kk11:30
=== lubotu3` is now known as lubotu3
ubottuThe TLS protocol, and the SSL protocol 3.0 and possibly earlier, as used in Microsoft Internet Information Services (IIS) 7.0, mod_ssl in the Apache HTTP Server 2.2.14 and earlier, OpenSSL before 0.9.8l, GnuTLS 2.8.5 and earlier, Mozilla Network Security Services (NSS) 3.12.4 and earlier, multiple Cisco products, and other products, does not properly associate renegotiation han... (http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555)15:04
tsimpsonDJones: ^15:05
tsimpsonjpds: new Bugtracker stuff committed, you'll need to set supybot.plugins.Bantracker.cveSnarfer to True where you want CVE's to be shown (if anywhere). setting supybot.plugins.Bantracker.bugSnarfer to False overrides cveSnarfer too15:08
DJonestsimpson: That was a quick change15:28
tsimpsoneverything required to do it already existed in the plugin, so I just had to modify the functions that parse the CVEs15:30
m4vheads up, saymin was flooding #ubuntu-es a few mins ago19:51
m4vhe's now in #u19:52
IdleOnethanks m4v19:52

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!