----------------------------------------------------------------------------------
@MSGID: 2:203/910 6ab6d15a
@PID: GED+W64 2.0.0-b20260923
@CHRS: CP866 2
@TZUTC: 0200
@TID: hpt/lnx 1.9 2024-03-02
* Originally in enet.sysop
* Crossposted in fidonews
* Crossposted in fido_sysop
Hello All,
qico 0.60.1 is out.
A security release.
It hardens BinkP session and password handling:
- handshake and file commands are now accepted only in the right phase,
sessions offering conflicting passwords in one M_ADR are refused.
- plaintext password compares are case-sensitive.
- failed passwords are no longer logged.
- short reads and writes are treated as errors.
- busy password-protected aka no longer opens an unprotected session.
Alongside those, the release fixes outbound busy-file handling, UTC
timestamps on BinkP transfers, the "if date" condition, longrescan,
showpkt logging and inbound modem log names.
New in this version are the kill-old-bsy keyword and systemd socket
activation for inbound ifcico.
Binaries for Debian 12 and NetBSD 11 are attached.
See `Changes` for the full notes.
Code and changelog:
https://github.com/glasslike/qico
Mvh,
Alex.
---
* Origin: Rabarber > Skelleftea > Sweden (2:203/910)
SEEN-BY: 30/0 203/0 2 124 412 910 221/1 230/0
250/1 263/1 275/100 280/464 5003
SEEN-BY: 280/5555 292/789 854 8125 301/1 320/219
331/51 335/364 410/9 421/790
SEEN-BY: 455/19 463/68 467/70 469/122 712/848
5001/100 5015/46 5020/290 715
SEEN-BY: 5020/921 1146 2992 5452 8912 9696 5022/2
5023/24 5030/1081 1997
SEEN-BY: 5034/13 5051/44 5055/73 5057/19 5061/15
5075/35 128 6035/3 6090/1
@PATH: 203/910 0 292/854 5020/715