- Zardoz (computer security)
The Zardoz list, more formally known as the Security-Digest list, was a famous semi-private
full disclosure mailing list run by Neil Gorsuch from1989 through1991 . Zardoz is most notable for its status as a perennial target for computer hackers, who sought archives of the list for information on undisclosed software vulnerabilities. cite book | author=Suelette Dreyfus and Julian Assange | title= | year= 1997 | id=ISBN 1-86330-595-5 | publisher= Mandarin ]Membership restrictions
Access to Zardoz was approved on a case-by-case basis by Gorsuch, principally by reference to the user account used to send subscription requests; requests were approved for root users, valid
UUCP owners, or system administrators listed at the NIC. [http://groups.google.com/group/news.groups/msg/662733b4b544c271]The openness of the list to users other than Unix system administrators was a regular topic of conversation, with participants expressing concern that vulnerabilities or exploitation details disclosed on the list were liable to spread to hackers. On the other hand, the circulation of Zardoz postings among computer hackers was an open secret, mocked openly in a famous Phrack parody of an
IRC channel populated by notable security experts. [ [http://artofhacking.com/files/phrack/phrack43/live/aoh_p43-04.htm AOH :: Phrack, Inc. Issue #43 :: P43-04.TXT ] ]Notable participants
*
Keith Bostic discussed BSDSendmail vulnerabilities
*Chip Salzenberg discussed Peter Honeyman's posting of aUUCP worm, andshell script securityH
*Gene Spafford discussedVMS andUltrix bugs, and relayed law enforcement enquiries about theMorris Worm
*Tom Christiansen discussedSUID shell scripts
*Chris Torek discussed devising exploits from general descriptions of vulnerabilities
*Henry Spencer discussedUnix security
*Brendan Kehoe discussed systems security
* Alec Muffett announced Crack, the famous Unix password crackerThe majority of Zardoz participants were Unix systems administrators and C software developers. Neil Gorsuch and Gene Spafford were the most prolific contributors to the list.
References
External links
* [http://securitydigest.org/zardoz/ The Security-Digest archive project]
Wikimedia Foundation. 2010.