Re: security-warning

2011-06-06 Thread David Jardine
On Mon, Jun 06, 2011 at 01:29:11PM -0400, shawn wilson wrote:
> On Mon, Jun 6, 2011 at 13:21, Ron Johnson  wrote:
> > On 06/06/2011 11:12 AM, Klaus Wolf wrote:
> >>
> >> Dear guys,
> >>
> >> her is again a warning of the german Ministry for Security Internet:
> >>
> >
> > We do appreciate you thinking of us, but this isn't a security list.
> >
> 
> + iirc, most people get / know about bugtraq

or debian-security-annou...@lists.debian.org

> 
> 
> -- 
> To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
> with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
> Archive: 
> http://lists.debian.org/BANLkTim+yq6_7Y7SyQ5NPon_qoPRj=G=c...@mail.gmail.com
> 


-- 
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: http://lists.debian.org/20110606230313.GB2236@gennes.augarten



Re: security-warning

2011-06-06 Thread shawn wilson
On Mon, Jun 6, 2011 at 13:21, Ron Johnson  wrote:
> On 06/06/2011 11:12 AM, Klaus Wolf wrote:
>>
>> Dear guys,
>>
>> her is again a warning of the german Ministry for Security Internet:
>>
>
> We do appreciate you thinking of us, but this isn't a security list.
>

+ iirc, most people get / know about bugtraq


-- 
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/BANLkTim+yq6_7Y7SyQ5NPon_qoPRj=G=c...@mail.gmail.com



Re: security-warning

2011-06-06 Thread Ron Johnson

On 06/06/2011 11:12 AM, Klaus Wolf wrote:

Dear guys,

her is again a warning of the german Ministry for Security Internet:



We do appreciate you thinking of us, but this isn't a security list.

--
"Neither the wisest constitution nor the wisest laws will secure
the liberty and happiness of a people whose manners are universally
corrupt."
Samuel Adams, essay in The Public Advertiser, 1749


--
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org

Archive: http://lists.debian.org/4ded0cb7.7030...@cox.net



security-warning

2011-06-06 Thread Klaus Wolf
Dear guys,

her is again a warning of the german Ministry for Security Internet:

This warning is for Win, Mac, Linux and Solaris

[1] Adobe Security Bulletin APSB11-13 vom 2011-06-05 
http://www.adobe.com/support/security/bulletins/apsb11-13.html

Security-update:

http://get.adobe.com/de/flashplayer/


best regards

klaus


-- 
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/1307376735.17192.6.camel@LINUXWOLFIBMLMY3773.LINUXWOLF



[Way OT] Re: Security-Warning Mac

2011-06-04 Thread Andrei POPESCU
[replies only to -offtopic please, Reply-To: set accordingly]

On Sb, 04 iun 11, 09:32:49, Klaus Wolf wrote:
> Dear guys,
> 
> The German Ministerium for Security Internet gives the following
> warning:
> 
> http://www.buerger-cert.de/techwarnung.aspx?msg_nr=Bcert-2011-0041
> 
> this warning is as very high declared, that's why inform on this
> list. I know that it's allmost OT.

"allmost" OT? The only relation I can see would be via Debian's kFreeBSD 
port, but even that is a bit far fetched :)

Regards,
Andrei
-- 
Offtopic discussions among Debian users and developers:
http://lists.alioth.debian.org/mailman/listinfo/d-community-offtopic


signature.asc
Description: Digital signature


Re: Security-Warning Mac

2011-06-04 Thread shawn wilson
On Jun 4, 2011 3:33 AM, "Klaus Wolf"  wrote:
>
> Dear guys,
>
> The German Ministerium for Security Internet gives the following
> warning:
>
> http://www.buerger-cert.de/techwarnung.aspx?msg_nr=Bcert-2011-0041
>
> this warning is as very high declared, that's why inform on this
> list. I know that it's allmost OT.
>

Sense this is an English list, I figured I'd let Google translate it for
y'all. But its just a mac defender warning (I should hope everyone here is
aware of this and Apple dropping the ball on this).

http://translate.google.com/translate?sl=auto&tl=en&js=n&prev=_t&hl=en&ie=UTF-8&layout=2&eotf=1&u=http%3A%2F%2Fwww.buerger-cert.de%2Ftechwarnung.aspx%3Fmsg_nr%3DBcert-2011-0041


Security-Warning Mac

2011-06-04 Thread Klaus Wolf
Dear guys,

The German Ministerium for Security Internet gives the following
warning:

http://www.buerger-cert.de/techwarnung.aspx?msg_nr=Bcert-2011-0041

this warning is as very high declared, that's why inform on this
list. I know that it's allmost OT.

Nice day

klaus


-- 
To UNSUBSCRIBE, email to debian-user-requ...@lists.debian.org 
with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org
Archive: 
http://lists.debian.org/1307172769.7253.14.ca...@linuxwolf-mobil.fritz.box



Re: Security warning: Where should I look for?

2004-02-23 Thread Antonio Rodriguez
On Mon, Feb 23, 2004 at 07:55:25PM +, Pigeon wrote:
> On Mon, Feb 23, 2004 at 02:19:21AM +0100, Miroslav Maiksnar wrote:
> > Dne po 23. ?nora 2004 01:38 Antonio Rodriguez napsal(a):
> > > I just received a strong warning:
> > >
> > > [EMAIL PROTECTED]:~$ scp p173* [EMAIL PROTECTED]:/pathto/
> > > @@@
> > > @WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> > > @@@
> > > IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> > > Someone could be eavesdropping on you right now (man-in-the-middle attack)!
> > > It is also possible that the RSA host key has just been changed.
> > > The fingerprint for the RSA key sent by the remote host is
> > > 24:40:94:e0:81:b9:af:62:dd:70:84:47:10:d1:c3:c0.
> > > Please contact your system administrator.
> > > Add correct host key in /home/tony/.ssh/known_hosts to get rid of this
> > > message. Offending key in /home/tony/.ssh/known_hosts:2
> > > RSA host key for local.ip.here has changed and you have requested strict
> > > checking. Host key verification failed.
> > > lost connection
> > > [EMAIL PROTECTED]:~$
> > >
> > > Thanks to all.
> > 
> > Also if remote server gets reinstalled and lazy admin doesn't use backuped RSA 
> > keys, new ones is generated and every poor ssh user gets this message ;o(
> 
> You also get it if the remote host's local hostname has changed.

Well, none of these two was the case. The localhost in the remote
machine didn't change, not the ssh server was reinstalled. The only
change that I am aware of is a modification in the php4.ini of the web
server in the remote machine. I can trust this to be accurate since I
administer the remote machine two.
Ugly, eh?



-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED] 
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: Security warning: Where should I look for?

2004-02-23 Thread Pigeon
On Mon, Feb 23, 2004 at 02:19:21AM +0100, Miroslav Maiksnar wrote:
> Dne po 23. ?nora 2004 01:38 Antonio Rodriguez napsal(a):
> > I just received a strong warning:
> >
> > [EMAIL PROTECTED]:~$ scp p173* [EMAIL PROTECTED]:/pathto/
> > @@@
> > @WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> > @@@
> > IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> > Someone could be eavesdropping on you right now (man-in-the-middle attack)!
> > It is also possible that the RSA host key has just been changed.
> > The fingerprint for the RSA key sent by the remote host is
> > 24:40:94:e0:81:b9:af:62:dd:70:84:47:10:d1:c3:c0.
> > Please contact your system administrator.
> > Add correct host key in /home/tony/.ssh/known_hosts to get rid of this
> > message. Offending key in /home/tony/.ssh/known_hosts:2
> > RSA host key for local.ip.here has changed and you have requested strict
> > checking. Host key verification failed.
> > lost connection
> > [EMAIL PROTECTED]:~$
> >
> > Thanks to all.
> 
> Also if remote server gets reinstalled and lazy admin doesn't use backuped RSA 
> keys, new ones is generated and every poor ssh user gets this message ;o(

You also get it if the remote host's local hostname has changed.

-- 
Pigeon

Be kind to pigeons
Get my GPG key here: http://pgp.mit.edu:11371/pks/lookup?op=get&search=0x21C61F7F


pgp0.pgp
Description: PGP signature


Re: Security warning: Where should I look for?

2004-02-22 Thread Miroslav Maiksnar
Dne po 23. Ășnora 2004 01:38 Antonio Rodriguez napsal(a):
> I just received a strong warning:
>
> [EMAIL PROTECTED]:~$ scp p173* [EMAIL PROTECTED]:/pathto/
> @@@
> @WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> @@@
> IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> Someone could be eavesdropping on you right now (man-in-the-middle attack)!
> It is also possible that the RSA host key has just been changed.
> The fingerprint for the RSA key sent by the remote host is
> 24:40:94:e0:81:b9:af:62:dd:70:84:47:10:d1:c3:c0.
> Please contact your system administrator.
> Add correct host key in /home/tony/.ssh/known_hosts to get rid of this
> message. Offending key in /home/tony/.ssh/known_hosts:2
> RSA host key for local.ip.here has changed and you have requested strict
> checking. Host key verification failed.
> lost connection
> [EMAIL PROTECTED]:~$
>
> Thanks to all.

Also if remote server gets reinstalled and lazy admin doesn't use backuped RSA 
keys, new ones is generated and every poor ssh user gets this message ;o(

Mixi


--
To UNSUBSCRIBE, email to [EMAIL PROTECTED]
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Re: Security warning: Where should I look for?

2004-02-22 Thread Colin Watson
On Sun, Feb 22, 2004 at 07:38:34PM -0500, Antonio Rodriguez wrote:
> I just received a strong warning:
> 
> [EMAIL PROTECTED]:~$ scp p173* [EMAIL PROTECTED]:/pathto/
> @@@
> @WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
> @@@
> IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
> Someone could be eavesdropping on you right now (man-in-the-middle attack)!
> It is also possible that the RSA host key has just been changed.
> The fingerprint for the RSA key sent by the remote host is
> 24:40:94:e0:81:b9:af:62:dd:70:84:47:10:d1:c3:c0.
> Please contact your system administrator.

Do what it says, then: verify out-of-band that the new RSA key quoted
there is the one it should be, by contacting the remote system
administrator using some other means. The sysadmin can use 'ssh-keygen
-l -f /etc/ssh/ssh_host_rsa_key.pub' to display the fingerprint.

Cheers,

-- 
Colin Watson  [EMAIL PROTECTED]


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED] 
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]



Security warning: Where should I look for?

2004-02-22 Thread Antonio Rodriguez
I just received a strong warning:

[EMAIL PROTECTED]:~$ scp p173* [EMAIL PROTECTED]:/pathto/
@@@
@WARNING: REMOTE HOST IDENTIFICATION HAS CHANGED! @
@@@
IT IS POSSIBLE THAT SOMEONE IS DOING SOMETHING NASTY!
Someone could be eavesdropping on you right now (man-in-the-middle attack)!
It is also possible that the RSA host key has just been changed.
The fingerprint for the RSA key sent by the remote host is
24:40:94:e0:81:b9:af:62:dd:70:84:47:10:d1:c3:c0.
Please contact your system administrator.
Add correct host key in /home/tony/.ssh/known_hosts to get rid of this message.
Offending key in /home/tony/.ssh/known_hosts:2
RSA host key for local.ip.here has changed and you have requested strict checking.
Host key verification failed.
lost connection
[EMAIL PROTECTED]:~$ 

Thanks to all.


-- 
To UNSUBSCRIBE, email to [EMAIL PROTECTED] 
with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]