Re: Advisory description text

2008-01-07 Thread Christoph Ulrich Scholler
Hi, On 07.01. 13:54, Adam Majer wrote: > Moritz Muehlenhoff wrote: > > CVE-2007-3382 > > > > It was discovered that single quotes (') in cookies were treated > > as a delimiter, which could lead to an information leak. > > > > CVE-2007-3385 > > > > It was discovered that the charact

Re: How to prevent daemons from ever being started?

2006-05-15 Thread Christoph Ulrich Scholler
Hi, On 15.05. 17:09, Uwe Hermann wrote: > What is "the Debian way" to prevent any daemon from ever starting, > whether upon reboot, upon upgrade, upon new install etc. If your default runlevel is 2, delete the symlink to the respective init script in /etc/rc2.d or even in /etc/rc[2345].d. Just m

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Christoph Ulrich Scholler
Hi, On 23.01. 07:46, Jose Marrero wrote: > Apache configured with mod_rewrite to deny blank or fake referers is a > good idea. How can you tell that a referrer is fake? Regards, uLI -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECT

Re: PermitRootLogin enabled by default

2002-06-26 Thread Christoph Ulrich Scholler
On Wed, Jun 26, 2002 at 02:11:00PM +0200 or thereabouts, InfoEmergencias - Luis Gómez wrote: > Messing up with sshd_config for all the privsep stuff, I've noticed that > PermitRootLogin was set to yes in my three woody boxes. I usually > consider this a problem (although it has been my fault - i s

Re: VI wrapper for SUDO?

2001-11-30 Thread Christoph Ulrich Scholler
hi, maybe i misunderstand the intention here, but isn't it pointless to restrict privileges of the editing process of /etc/aliases if you could just as well change root's alias to a program that's run whenever root receives email and, e. g., puts one's most favourite /etc/passwd in place of the or

Re: VI wrapper for SUDO?

2001-11-30 Thread Christoph Ulrich Scholler
hi, maybe i misunderstand the intention here, but isn't it pointless to restrict privileges of the editing process of /etc/aliases if you could just as well change root's alias to a program that's run whenever root receives email and, e. g., puts one's most favourite /etc/passwd in place of the o

Re: rogue Chinese crawler

2001-11-23 Thread Christoph Ulrich Scholler
On Fri, Nov 23, 2001 at 05:32:04PM + or thereabouts, Martin WHEELER wrote: > Is anyone else having problems with the robot from > > openfind.com.tw > ... > Anyone know of a sure-fire robot killer under woody? as a first recourse you could instruct your firewall to deny all access from op