New dsniff revision

Marcos Fouces mfouces at yahoo.es
Wed Feb 22 23:16:12 UTC 2017


Hello

I uploaded to repo a first attempt of libnids1.24 package wich aims to 
close its two critical bugs:

#855602: fixed upstream in 1.24 release.

#851060: i tried using -fno-strict-aliasing flag as reporter indicates. 
I didn't noticed any change on my amd64, but he talked about armhf arch.

I built dsniff (1) against this new version of libnids-dev (2) and here 
is the result:

* Run dsniff

* Run the same test as bug reporter: curl -v --basic --user foo:bar 
http://neverssl.com/

dsniff says this:

dsniff: listening on eth0
-----------------
02/22/17 23:56:32 tcp 192.168.1.3.47942 -> 
s3-website-us-west-2.amazonaws.com.80 (http)
GET / HTTP/1.1
Host: neverssl.com
Authorization: Basic Zm9vOmJhcg== [foo:bar]

(1) https://anonscm.debian.org/cgit/pkg-security/dsniff.git

(2) https://anonscm.debian.org/cgit/pkg-security/libnids.git

Cheers,

Marcos


El 17/02/17 a las 08:29, Gianfranco Costamagna escribió:
> Hi,
>
>> Can someone review and upload it or point out any change needed?
>
>
> I would appreciate a coordination on bug
> https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=851060
>
> before sponsoring.
> (also, we are on freeze, but changes should be acceptable for an unblock)
>
> G.
>
>
>




More information about the Pkg-security-team mailing list