Bruce Steers said,
> i just read this url http://www.abraxis.co.uk/SA-2001-11-08.html
> some of you might want to know
If you insist on using YAM and AWNPIPE, there is a sort of fix. Rename
AWNPIPE in DEVS:DOSDrivers and change the name in any AWNPipe scripts you
run (stringer is handy for this).
It's not a real fix, the insecurity is still there, but no one knows the
name of the pipe to send it too.
This is a serious risk, it is possible to erase a hard drive partition
with this exploit.
Cheers
Neil
--
"Bother," said Pooh, as the Death Star exploded around him.