removing gdm

2001-12-07 Thread An-Dee
Hello

  I have a little problem. I use woody. I installed gdm, but
  unfortunately, I cannot use my keyboard and my mouse with it, so I
  installed kdm and forget to remove gdm.
  Now I dont have any working grafical login.
  When I try to remove gdm I got the following:

Reading Package Lists...
Building Dependency Tree...
The following packages will be REMOVED:
  gdm 
0 packages upgraded, 0 newly installed, 1 to remove and 9  not upgraded.
2 packages not fully installed or removed.
Need to get 0B of archives. After unpacking 3445kB will be freed.
Do you want to continue? [Y/n] (Reading database ... 54029 files and 
directories currently installed.)
Removing gdm ...
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in exists at /usr/share/perl5/Debconf/Template.pm
line 49.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 49.
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 40.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 48.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 116.
dpkg: error processing gdm (--remove):
 subprocess pre-removal script returned error exit status 10
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in exists at /usr/share/perl5/Debconf/Template.pm
line 49.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 49.
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 40.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 48.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 116.
dpkg: error while cleaning up:
 subprocess post-installation script returned error exit status 10
Errors were encountered while processing:
 gdm
E: Sub-process /usr/bin/dpkg returned an error code (1)


   How can I remove gdm and make kdm working on my box?

thx
 An-Dee



+---+
 ICQ#: 86538852 The Bat! 1.53d 
 Win98-BeOSR5.0.3-Debian2.2 Kernel 2.4.9
 Opera 3.62 & 5.12  \\|//   1:13:59
 [EMAIL PROTECTED](o o)   2001. december 8.   
+---oOOo-(_)-oOOo---+



Re: Network traffic monitoring. (which IP makes big traffic?)

2001-12-07 Thread Dmitriy
On Thu, Dec 06, 2001 at 12:33:46AM -0800, Alvin Oga wrote:
[snip]
> 
> root# trafshow
>   - shows in a small table ( more readable) the ongoing traffic
>   ( keeps a ongoing total traffic
> 
Or try ntop .
It has a web insterface and shows loads of various statistics.


> for the rest of the network monitoring tools..
> 
>   http://www.Linux-Sec.net/Ethernet/
> 
> have fun
> alvin
> 
> On Thu, 6 Dec 2001, Cho Yoonbae wrote:
> 
> > Hi,
> > 
> > My network has been very slower than before.
> > Someone suspected the virus like nimda.
> > 
> > So I have to found out who makes very high traffic..
> > I am not network engineer now.
> > 
> > What things I have to know?
> > and Which softwares I can select?
> > 
> > I'm asking advice for you.
> > Have a nice day.
> > 
> > byebye
> > 
> 
> 
> -- 
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

-- 
GPG key-id: 1024D/DF04A255 Dmitriy
AA16 8FAB 74E1 3511 83D0  9F4B F087 CEC9 DF04 A255
* encrypted personal mail is very much preferred *
Free Dmitry Sklyarov!  http://www.freesklyarov.org


pgpqM4CFahyRb.pgp
Description: PGP signature


removing gdm

2001-12-07 Thread An-Dee

Hello

  I have a little problem. I use woody. I installed gdm, but
  unfortunately, I cannot use my keyboard and my mouse with it, so I
  installed kdm and forget to remove gdm.
  Now I dont have any working grafical login.
  When I try to remove gdm I got the following:

Reading Package Lists...
Building Dependency Tree...
The following packages will be REMOVED:
  gdm 
0 packages upgraded, 0 newly installed, 1 to remove and 9  not upgraded.
2 packages not fully installed or removed.
Need to get 0B of archives. After unpacking 3445kB will be freed.
Do you want to continue? [Y/n] (Reading database ... 54029 files and directories 
currently installed.)
Removing gdm ...
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in exists at /usr/share/perl5/Debconf/Template.pm
line 49.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 49.
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 40.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 48.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 116.
dpkg: error processing gdm (--remove):
 subprocess pre-removal script returned error exit status 10
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 29.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 53.
Use of uninitialized value in exists at /usr/share/perl5/Debconf/Template.pm
line 49.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/Template.pm line 49.
Use of uninitialized value in exists at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 40.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 48.
Use of uninitialized value in hash element at
/usr/share/perl5/Debconf/DbDriver/Cache.pm line 116.
dpkg: error while cleaning up:
 subprocess post-installation script returned error exit status 10
Errors were encountered while processing:
 gdm
E: Sub-process /usr/bin/dpkg returned an error code (1)


   How can I remove gdm and make kdm working on my box?

thx
 An-Dee



+---+
 ICQ#: 86538852 The Bat! 1.53d 
 Win98-BeOSR5.0.3-Debian2.2 Kernel 2.4.9
 Opera 3.62 & 5.12  \\|//   1:13:59
 [EMAIL PROTECTED](o o)   2001. december 8.   
+---oOOo-(_)-oOOo---+


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Spamming

2001-12-07 Thread Phillip Hofmeister
Dear Sir:

I am contacting you because you are listed as the ARIN
coordinator for the following IP address:
64.69.222.21 (aka getfriction.org).

I am a member of the Debian security list.  On the archive
listed below you will find several unsolicited ads spamming
the list for "getfriction.org" with the subject being "get 
some".  As a member of this list I would appreciate you
looking into this activity.

Archive URL:
http://lists.debian.org/debian-security/2001/debian-
security-200112


Thank you,

Phillip L. Hofmeister





Re: Network traffic monitoring. (which IP makes big traffic?)

2001-12-07 Thread Dmitriy

On Thu, Dec 06, 2001 at 12:33:46AM -0800, Alvin Oga wrote:
[snip]
> 
> root# trafshow
>   - shows in a small table ( more readable) the ongoing traffic
>   ( keeps a ongoing total traffic
> 
Or try ntop .
It has a web insterface and shows loads of various statistics.


> for the rest of the network monitoring tools..
> 
>   http://www.Linux-Sec.net/Ethernet/
> 
> have fun
> alvin
> 
> On Thu, 6 Dec 2001, Cho Yoonbae wrote:
> 
> > Hi,
> > 
> > My network has been very slower than before.
> > Someone suspected the virus like nimda.
> > 
> > So I have to found out who makes very high traffic..
> > I am not network engineer now.
> > 
> > What things I have to know?
> > and Which softwares I can select?
> > 
> > I'm asking advice for you.
> > Have a nice day.
> > 
> > byebye
> > 
> 
> 
> -- 
> To UNSUBSCRIBE, email to [EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

-- 
GPG key-id: 1024D/DF04A255 Dmitriy
AA16 8FAB 74E1 3511 83D0  9F4B F087 CEC9 DF04 A255
* encrypted personal mail is very much preferred *
Free Dmitry Sklyarov!  http://www.freesklyarov.org



msg04679/pgp0.pgp
Description: PGP signature


get some

2001-12-07 Thread get some



 get ahead. get noticed. get some.




A cool new
internet experience!
 getfriction.org 
A great gift idea
for the Holidays!


 





Spamming

2001-12-07 Thread Phillip Hofmeister

Dear Sir:

I am contacting you because you are listed as the ARIN
coordinator for the following IP address:
64.69.222.21 (aka getfriction.org).

I am a member of the Debian security list.  On the archive
listed below you will find several unsolicited ads spamming
the list for "getfriction.org" with the subject being "get 
some".  As a member of this list I would appreciate you
looking into this activity.

Archive URL:
http://lists.debian.org/debian-security/2001/debian-
security-200112


Thank you,

Phillip L. Hofmeister




-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: pam stuff

2001-12-07 Thread Philipe Gaspar
Em Sex 07 Dez 2001 05:52, Warren Turkal escreveu:
>   Is it possible to differentiate what Pam modules are used by the user
> logging?
>   For instance, I want root to use one time passwords to login, and I
> want normal users to use their normal password.
I think so.
>
>   Also, is there a way to make the root password work for all users in
> certain apps.
Yes, you can use sudo, apt-get install sudo
>   For instance, I would love to be able to make kscreensaver accept
> either the current user's password or the root password to unlock the
> screen.

-- 
Philipe Gaspar aka kr0n.
Unix SysAdmin
[EMAIL PROTECTED]
 



get some

2001-12-07 Thread get some



 get ahead. get noticed. get some.




A cool new
internet experience!
 getfriction.org 
A great gift idea
for the Holidays!


 





Re: pam stuff

2001-12-07 Thread Philipe Gaspar

Em Sex 07 Dez 2001 05:52, Warren Turkal escreveu:
>   Is it possible to differentiate what Pam modules are used by the user
> logging?
>   For instance, I want root to use one time passwords to login, and I
> want normal users to use their normal password.
I think so.
>
>   Also, is there a way to make the root password work for all users in
> certain apps.
Yes, you can use sudo, apt-get install sudo
>   For instance, I would love to be able to make kscreensaver accept
> either the current user's password or the root password to unlock the
> screen.

-- 
Philipe Gaspar aka kr0n.
Unix SysAdmin
[EMAIL PROTECTED]
 


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




Re: pam stuff

2001-12-07 Thread Phillip Hofmeister
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Warren,

Some screen locks accept either passwd (lockvc).  However,
whether or not it accepts root's passwd is up to the
program itself.  If you program does not have this
feature simply log in as root on a normal tty and send
the proc a term signal or even a kill sig (sig 9) if needed.

You can find out the proc # by typing 'ps axf' and finding
it in the list.  Then merely type 'kill proc#' or
'kill -9 proc#'.  If your PID was 78 you would type
'kill 78'.

Phil
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8EM0YS3Jybf3L5MQRAsPDAJ4hpSUUJNfWMqaEiElmPB4vpDH4UwCd
GTV7
kZgEiTDuYmiQcL9rwk0cd+o=
=gReY
-END PGP SIGNATURE-


> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
>   Is it possible to differentiate what Pam modules are 
used by the user 
> logging?
>   For instance, I want root to use one time passwords to 
login, and I 
> want normal users to use their normal password.
> 
>   Also, is there a way to make the root password work for 
all users in 
> certain apps.
>   For instance, I would love to be able to make 
kscreensaver accept 
> either the current user's password or the root password 
to unlock the 
> screen.
> - -- 
> Warren
> 
> GPG Fingerprint: 30C8 BDF1 B133 14CB 832F  2C5D 99A1 A19F 
559D 9E88
> GPG Public Key @ http://www.cbu.edu/~wturkal/wturkal.gpg
> 
> - -BEGIN GEEK CODE BLOCK-
> Version: 3.12
> GCS d- s: a-- C++ UL+ P+ L+++ E W++ N+ o-- K- w--- 
> O M+ V-- PS+ PE Y+ PGP++ t 5 X R tv+ b+ DI+ D+ 
> G e h-- r y? 
> - --END GEEK CODE BLOCK--
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v1.0.6 (GNU/Linux)
> Comment: For info see http://www.gnupg.org
> 
> 
iD8DBQE8EHVCmaGhn1WdnogRAmprAJ4mENnMkbxG7FxYXeD8AlaxgI2Q5wCe
OFeV
> 9i9lM7zZi/FixJdspS/EL7A=
> =AWif
> -END PGP SIGNATURE-
> 
> 
> -- 
> To UNSUBSCRIBE, email to debian-security-
[EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact 
[EMAIL PROTECTED]
> 
> 




Re: pam stuff

2001-12-07 Thread Phillip Hofmeister

-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

Warren,

Some screen locks accept either passwd (lockvc).  However,
whether or not it accepts root's passwd is up to the
program itself.  If you program does not have this
feature simply log in as root on a normal tty and send
the proc a term signal or even a kill sig (sig 9) if needed.

You can find out the proc # by typing 'ps axf' and finding
it in the list.  Then merely type 'kill proc#' or
'kill -9 proc#'.  If your PID was 78 you would type
'kill 78'.

Phil
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8EM0YS3Jybf3L5MQRAsPDAJ4hpSUUJNfWMqaEiElmPB4vpDH4UwCd
GTV7
kZgEiTDuYmiQcL9rwk0cd+o=
=gReY
-END PGP SIGNATURE-


> -BEGIN PGP SIGNED MESSAGE-
> Hash: SHA1
> 
>   Is it possible to differentiate what Pam modules are 
used by the user 
> logging?
>   For instance, I want root to use one time passwords to 
login, and I 
> want normal users to use their normal password.
> 
>   Also, is there a way to make the root password work for 
all users in 
> certain apps.
>   For instance, I would love to be able to make 
kscreensaver accept 
> either the current user's password or the root password 
to unlock the 
> screen.
> - -- 
> Warren
> 
> GPG Fingerprint: 30C8 BDF1 B133 14CB 832F  2C5D 99A1 A19F 
559D 9E88
> GPG Public Key @ http://www.cbu.edu/~wturkal/wturkal.gpg
> 
> - -BEGIN GEEK CODE BLOCK-
> Version: 3.12
> GCS d- s: a-- C++ UL+ P+ L+++ E W++ N+ o-- K- w--- 
> O M+ V-- PS+ PE Y+ PGP++ t 5 X R tv+ b+ DI+ D+ 
> G e h-- r y? 
> - --END GEEK CODE BLOCK--
> -BEGIN PGP SIGNATURE-
> Version: GnuPG v1.0.6 (GNU/Linux)
> Comment: For info see http://www.gnupg.org
> 
> 
iD8DBQE8EHVCmaGhn1WdnogRAmprAJ4mENnMkbxG7FxYXeD8AlaxgI2Q5wCe
OFeV
> 9i9lM7zZi/FixJdspS/EL7A=
> =AWif
> -END PGP SIGNATURE-
> 
> 
> -- 
> To UNSUBSCRIBE, email to debian-security-
[EMAIL PROTECTED]
> with a subject of "unsubscribe". Trouble? Contact 
[EMAIL PROTECTED]
> 
> 



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




lprng

2001-12-07 Thread Juha Jäykkä
  Nessus claims all versions of lprng prior to 3.6.24 has some unnamed
flaw which allows exploiting the daemon's priviledges.
  As a debian lprng runs as daemon, it is not as dangerous as nessus
claims (root compromise), at least directly. How ever, I cannot find
any references to any vulnerabilities in lprng, except one in January
2000 in security.debian.org! Since potato has lprng 3.6.12 it would be
nice to know if there is a vulnerability or not. Anyone and ideas?
  I know nessus gives a lot of false positives, such as claiming
my mail server is an open relay when testing it from the (firewalled)
subnet which it really _IS_ a relay for. Nessus has no way of knowing
outiside world cannot use it as a relay; or claiming an up-to-date
potato sshd as vulnerable to the CRC32 attack compensator bug since its
version number suggests it is vulnerable.
  Most false positives are easily dismissed by knowing your setup which
nessus does not. There are a couple of concering cases, though: This
case of lprng: nessus only says it detects an lprng daemon, but NOT
that it cannot tell the version number and just states what I describe
in the beginning. Another is Trin00. It has this far detected three
machines with Trin00. In one of them it most certainly is false since
it claims to have found Windows version of Trin00 on an IRIX host...
The other two cases, on the other hand give no hint of being falses.
Does anyone know how reliable nessus is in detecting Trin00? Does it
only check that port X is open, thus we have Trin00 there or does it
really send some commands to the supposed Trin00 client/daemon and
verify its existence from the reply? If nessus is not realiable, how
can I check for it?

-- 
 ---
| Juha Jäykkä, [EMAIL PROTECTED]|
| home: http://www.utu.fi/~juolja/  |
 ---



lprng

2001-12-07 Thread Juha Jäykkä

  Nessus claims all versions of lprng prior to 3.6.24 has some unnamed
flaw which allows exploiting the daemon's priviledges.
  As a debian lprng runs as daemon, it is not as dangerous as nessus
claims (root compromise), at least directly. How ever, I cannot find
any references to any vulnerabilities in lprng, except one in January
2000 in security.debian.org! Since potato has lprng 3.6.12 it would be
nice to know if there is a vulnerability or not. Anyone and ideas?
  I know nessus gives a lot of false positives, such as claiming
my mail server is an open relay when testing it from the (firewalled)
subnet which it really _IS_ a relay for. Nessus has no way of knowing
outiside world cannot use it as a relay; or claiming an up-to-date
potato sshd as vulnerable to the CRC32 attack compensator bug since its
version number suggests it is vulnerable.
  Most false positives are easily dismissed by knowing your setup which
nessus does not. There are a couple of concering cases, though: This
case of lprng: nessus only says it detects an lprng daemon, but NOT
that it cannot tell the version number and just states what I describe
in the beginning. Another is Trin00. It has this far detected three
machines with Trin00. In one of them it most certainly is false since
it claims to have found Windows version of Trin00 on an IRIX host...
The other two cases, on the other hand give no hint of being falses.
Does anyone know how reliable nessus is in detecting Trin00? Does it
only check that port X is open, thus we have Trin00 there or does it
really send some commands to the supposed Trin00 client/daemon and
verify its existence from the reply? If nessus is not realiable, how
can I check for it?

-- 
 ---
| Juha Jäykkä, [EMAIL PROTECTED]|
| home: http://www.utu.fi/~juolja/  |
 ---


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]




pam stuff

2001-12-07 Thread Warren Turkal
-BEGIN PGP SIGNED MESSAGE-
Hash: SHA1

  Is it possible to differentiate what Pam modules are used by the user 
logging?
  For instance, I want root to use one time passwords to login, and I 
want normal users to use their normal password.

  Also, is there a way to make the root password work for all users in 
certain apps.
  For instance, I would love to be able to make kscreensaver accept 
either the current user's password or the root password to unlock the 
screen.
- -- 
Warren

GPG Fingerprint: 30C8 BDF1 B133 14CB 832F  2C5D 99A1 A19F 559D 9E88
GPG Public Key @ http://www.cbu.edu/~wturkal/wturkal.gpg

- -BEGIN GEEK CODE BLOCK-
Version: 3.12
GCS d- s: a-- C++ UL+ P+ L+++ E W++ N+ o-- K- w--- 
O M+ V-- PS+ PE Y+ PGP++ t 5 X R tv+ b+ DI+ D+ 
G e h-- r y? 
- --END GEEK CODE BLOCK--
-BEGIN PGP SIGNATURE-
Version: GnuPG v1.0.6 (GNU/Linux)
Comment: For info see http://www.gnupg.org

iD8DBQE8EHVCmaGhn1WdnogRAmprAJ4mENnMkbxG7FxYXeD8AlaxgI2Q5wCeOFeV
9i9lM7zZi/FixJdspS/EL7A=
=AWif
-END PGP SIGNATURE-