On Sat, 6 Sep 2003, 3APA3A wrote: > Dear bugtraq@securityfocus.com, > > Well, we all blame Microsoft in insecure default configuration... Isn't > it time to clean outdated code in Unix? This has been a known problem for quite a while. In fact D. J. Bernstein already solved it with tcpserver: http://cr.yp.to/ucspi-tcp.html If you look at the bottom he points out pretty much what you pointed out. -- Thamer Al-Harbash GPG Key fingerprint: D7F3 1E3B F329 8DD5 FAE3 03B1 A663 E359 D686 AA1F "HLAGHLHALUAG (KTHANX)"