Re: Cyrus21/ Vulnerability

2004-12-05 Thread Andreas John
Hello Christoph! Do not use testing or unstable on machines exposed to the public. There is no security support for them: http://www.debian.org/security/faq#testing Hmmm .. is this information accurate? apt-setup gives me: deb http://security.debian.org/ testing/updates main contrib non-free Is

Cyrus21/ Vulnerability

2004-12-05 Thread Andreas John
, or? Any better ideas to solve the problem? rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Help with pureftpd config

2004-09-29 Thread Andreas John
Mancey Sys Admin, Network/info specialist Phone (592) 227-5989,227-6198 Sustainable Development Networking Programme (Guyana) http://www.sdnp.org.gy -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL

Re: status of VLAN support in Debian/Linux in general

2004-09-12 Thread Andreas John
) Both Servers have one NIC per network X. If you change to the new setup you will lose redundancy! (if this is not the question you setup will be fine) Rgds, j. Leonardo Boselli wrote: Il 11 Sep 2004 alle 21:30 Andreas John immise in rete 1.) VLAN is an IEEE Standard. (802.1q

Postfix/X-Envelope-To

2004-09-12 Thread Andreas John
Hello All! I wondering is someone knows how to add an X-Envelope-To header to all incoming e-mails which reveal the real username even when working with virtuals. I tried several apoaches like: --- # cat /etc/procmailrc ENV_TO=$1 :0f * ENV_TO ?? . | formail -i X-Envelope-To: $ENV_TO :0fE |

Re: status of VLAN support in Debian/Linux in general

2004-09-11 Thread Andreas John
bug in the cisco asic. Don't wonder why the error LEDs blink. Mr. Sascha Pollok wrote a patch that add a padding to the frames so the cisco gets more happy. 6.) To our experience the usage of VLAN does not cause siginifcant CPU load on linux. HTH, Andreas -- Andreas John net-lab GmbH

Re: status of VLAN support in Debian/Linux in general

2004-09-11 Thread Andreas John
Replying to myself: 1.) tulip driver in 2.6 does work with VLAN (test was: ping -s 1472 ip vs. ping -s 1468) 2.) I wrote about a framesize of a tagged frame with 1504 byte I correct myself by quoting candelatech: --- 2 - 802.1q tagging adds an additional header field (4 Bytes) to the ethernet

Re: ssh and root logins

2004-08-10 Thread Andreas John
find this most secure--no more worries about password cracks (I just have to worry about the physical security of the USB key on my keychain). Regards, Mark -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email

Re: ssh and root logins

2004-08-10 Thread Andreas John
Russell Coker wrote: On Tue, 10 Aug 2004 20:52, Dale E Martin [EMAIL PROTECTED] wrote: I've noticed a fair number of attempted root logins on my various boxes Same here. Also attempted logins to test, admin, and some other accounts. ^ ^ ^ ^ ^ ^ ^ ^^ Uh man,

Re: Streaming Video Server

2004-07-09 Thread Andreas John
! Andreas -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net On Fri, Jul 09, 2004 at 11:02:46AM +0200, Stefan Neufeind wrote: Or you might want to try out the Helix Server (from Real Networks) - which is afaik not really free either. Have a look

Re: Streaming Video Server

2004-07-09 Thread Andreas John
! Andreas -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net On Fri, Jul 09, 2004 at 11:02:46AM +0200, Stefan Neufeind wrote: Or you might want to try out the Helix Server (from Real Networks) - which is afaik not really free either. Have a look

Re: email server - how to

2004-06-29 Thread Andreas John
Best to use 2U machines with the maximum number of disks IMHO. A 2U machine should be able to have 5 disks. I say: 9 Disks without problems. e.g. pcicase http://www.pcicase.de/catalog/produktweb/IPC-C2-X/IPC-C2D.htm -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe.

Re: email server - how to

2004-06-29 Thread Andreas John
Best to use 2U machines with the maximum number of disks IMHO. A 2U machine should be able to have 5 disks. I say: 9 Disks without problems. e.g. pcicase http://www.pcicase.de/catalog/produktweb/IPC-C2-X/IPC-C2D.htm

Re: restricting sftp/ssh login access

2004-06-28 Thread Andreas John
Hi! 1.) Set users shell to /bin/false and add it to /etc/shells. This will prevent ssh access for users, but allows ftp etc. But what you are asking for is that (I think) 2.) http://chrootssh.sourceforge.net/index.php Chroot your ssh for non-admin users by - patching ssh - replacing Users

Re: restricting sftp/ssh login access

2004-06-28 Thread Andreas John
Hi! 1.) Set users shell to /bin/false and add it to /etc/shells. This will prevent ssh access for users, but allows ftp etc. But what you are asking for is that (I think) 2.) http://chrootssh.sourceforge.net/index.php Chroot your ssh for non-admin users by - patching ssh - replacing Users

Re: recommendation for gbit sx card?

2004-06-25 Thread Andreas John
in today's kernels? -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: recommendation for gbit sx card?

2004-06-25 Thread Andreas John
in today's kernels? -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: Configuring Wireless ISP

2004-06-23 Thread Andreas John
Hola! (2) http://jodies.de/ipcalc My answer to (2) in intl. language :-) apt-get install sipcalc -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Configuring Wireless ISP

2004-06-23 Thread Andreas John
Hola! (2) http://jodies.de/ipcalc My answer to (2) in intl. language :-) apt-get install sipcalc

Re: DF bit - Dont Fragment

2004-06-21 Thread Andreas John
between myself and the server via a CIPE tunnel stopped working when the packets got tooo large) - Or is there a bug in packet fragmentation in the linux kernel? Regards -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email

Re: DF bit - Dont Fragment

2004-06-21 Thread Andreas John
between myself and the server via a CIPE tunnel stopped working when the packets got tooo large) - Or is there a bug in packet fragmentation in the linux kernel? Regards -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

DROA and FTC

2004-06-17 Thread Andreas John
This may be interesting to all kind of ISPs. Not really Debian realted, but IMO it's worth mentioning here. FTC's opinion to DROA practices and refund decision! http://www.ftc.gov/opa/2003/12/domainreg.htm Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331

DROA and FTC

2004-06-17 Thread Andreas John
This may be interesting to all kind of ISPs. Not really Debian realted, but IMO it's worth mentioning here. FTC's opinion to DROA practices and refund decision! http://www.ftc.gov/opa/2003/12/domainreg.htm Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331

Re: how to relocate servers transparently

2004-06-14 Thread Andreas John
forwarder in some way? Can that be done between two different class A networks? As above, as long as both new and old servers are serving the same (new) zone details, there shouldnt be a problem. Brad -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net

Re: how to relocate servers transparently

2004-06-14 Thread Andreas John
DNAT? cheers -- vbi -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: how to relocate servers transparently

2004-06-14 Thread Andreas John
forwarder in some way? Can that be done between two different class A networks? As above, as long as both new and old servers are serving the same (new) zone details, there shouldnt be a problem. Brad -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net

Re: how to relocate servers transparently

2004-06-14 Thread Andreas John
DNAT? cheers -- vbi -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: [PHP] safe mode bug ?

2004-06-06 Thread Andreas John
is not really safe. You might want to restrict access with open_basedir . The most secure solution is still to install php's cgi executable in an suexec environment. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: [PHP] safe mode bug ?

2004-06-06 Thread Andreas John
is not really safe. You might want to restrict access with open_basedir . The most secure solution is still to install php's cgi executable in an suexec environment. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: LDAP for Services

2004-05-31 Thread Andreas John
in it. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: Postfix SMTP AUTH with TLS Problems

2004-05-30 Thread Andreas John
.2 (0x4000) Any ideas about where I should go from here? thanks, Adam -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Postfix SMTP AUTH with TLS Problems

2004-05-30 Thread Andreas John
.2 (0x4000) Any ideas about where I should go from here? thanks, Adam -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: Chkrootkit - true/false ?

2004-05-22 Thread Andreas John
positives, but this is no reason not look for a trojan. read the perl code to see what it checks. it's quite simple, it checks the existence of certain hidden directories, files or processes. try to invstigate, why they exist on your machine. rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b

Re: Chkrootkit - true/false ?

2004-05-22 Thread Andreas John
positives, but this is no reason not look for a trojan. read the perl code to see what it checks. it's quite simple, it checks the existence of certain hidden directories, files or processes. try to invstigate, why they exist on your machine. rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b

Re: multiple IP addresses cause ZONE TRANSFER to fail.

2004-05-21 Thread Andreas John
by a series of short-term targets is as pointless as a dieter stepping on a scale every half-hour, Larry Page, one of Google's co-founders -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED

Re: multiple IP addresses cause ZONE TRANSFER to fail.

2004-05-21 Thread Andreas John
by a series of short-term targets is as pointless as a dieter stepping on a scale every half-hour, Larry Page, one of Google's co-founders -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: [mailinglists] Ulimit and max processes

2004-05-18 Thread Andreas John
an for some weired reason there is d #define in the kernel source of 2.2.series that made it into Andrew's special 2.4.x. Andrew: Did you upgrade the 256er-boxen from 2.2? Did you use make oldconfig or took you parts (patches) from the kernel before? rgds, Andreas -- Andreas John net-lab GmbH

Re: [mailinglists] Ulimit and max processes

2004-05-18 Thread Andreas John
:) -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: [mailinglists] Ulimit and max processes

2004-05-18 Thread Andreas John
an for some weired reason there is d #define in the kernel source of 2.2.series that made it into Andrew's special 2.4.x. Andrew: Did you upgrade the 256er-boxen from 2.2? Did you use make oldconfig or took you parts (patches) from the kernel before? rgds, Andreas -- Andreas John net-lab GmbH

Re: Monitoring software

2004-04-26 Thread Andreas John
but in the end the config was just too much and too complex. Any suggestions are welcome. Thanks Craig -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact

Re: Monitoring software

2004-04-26 Thread Andreas John
the config was just too much and too complex. Any suggestions are welcome. Thanks Craig -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: RaiserFS via NFS

2004-04-18 Thread Andreas John
? RaiserFs is a realy fast filesystem for very much smal files Greetings Michelle -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Re: RaiserFS via NFS

2004-04-18 Thread Andreas John
is a realy fast filesystem for very much smal files Greetings Michelle -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: RaiserFS via NFS

2004-04-17 Thread Andreas John
with a database structure, for extX there are most recue utils out, for laptops a journaling FS can cause power consumption, so ext2 may be cool for them. Large file access may be better with FS A, databases may like FS B more etc Rgds, J. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067

Re: RaiserFS via NFS

2004-04-17 Thread Andreas John
to mail. With Maildir you will have less problems than with mbox, but you still do NOT have atomic transactions, and as such you will at some stage statistically have a problem. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: RaiserFS via NFS

2004-04-17 Thread Andreas John
with a database structure, for extX there are most recue utils out, for laptops a journaling FS can cause power consumption, so ext2 may be cool for them. Large file access may be better with FS A, databases may like FS B more etc Rgds, J. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067

Re: debian on HP proliant

2004-04-17 Thread Andreas John
as installer: http://d-i.pascal.at/ You may mount this an put modules to it's initrd easily. I could send you an dump vom my about 4 weeks old d-i on stick. Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: RaiserFS via NFS

2004-04-17 Thread Andreas John
to mail. With Maildir you will have less problems than with mbox, but you still do NOT have atomic transactions, and as such you will at some stage statistically have a problem. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: bandwidth

2004-04-12 Thread Andreas John
of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: Little BIG problem with Backbone

2004-04-09 Thread Andreas John
Hello! Before all this begins to get silly: You are playing with amount of money which I would not concern as pennyware. As from you mails before, it's clearly to recognize that you haven an idea, but no concept nor the skills you need. You will need probably consultants who help you to find a

Re: OSF for an ISP (was Re: ..idea; ddos spam hosts off Internet?)

2004-04-09 Thread Andreas John
from an dialup ip, so I think it would be an accepted way to try what Pulu wants to do. Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact

Re: Little BIG problem with Backbone

2004-04-09 Thread Andreas John
Hello! Before all this begins to get silly: You are playing with amount of money which I would not concern as pennyware. As from you mails before, it's clearly to recognize that you haven an idea, but no concept nor the skills you need. You will need probably consultants who help you to find a

Re: OSF for an ISP (was Re: ..idea; ddos spam hosts off Internet?)

2004-04-09 Thread Andreas John
an dialup ip, so I think it would be an accepted way to try what Pulu wants to do. Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: Attempt on smtpd / faking remote ip

2004-04-04 Thread Andreas John
.) Boot superrescue, knoppix or so 2.) Run chkrootkit (deb package is mostly a little old) 3.) If you run chkrotokit on Debian, chkrootkit reports one false positive! (AFAIR it was lkm rootkit, debian reports some ps processes to much, bug/incompatibility in ps command) Rgds, j. -- Andreas John net

Re: Postfix MTA and amavisd-new (Debian) calls clamd and spamassassin on a mailgateway (success)

2004-04-02 Thread Andreas John
/procmailrc # Spamassassin :0fw | /usr/bin/spamc I weant spam only to be filtered when delivered locally, i.e. I don't want outgoing mail to be tagghed as spam, this sometimes happened. Amavis alterntively has a local domains variable. HTH. rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067

Re: How to set up a Debian mirror..

2004-03-29 Thread Andreas John
? OR Are there utilities in Debian that will make it easy to maintain a mirror of i386 Debian ? Thanks! -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble

Re: How to set up a Debian mirror..

2004-03-29 Thread Andreas John
only? OR Are there utilities in Debian that will make it easy to maintain a mirror of i386 Debian ? Thanks! -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49 69 85700331 http://www.net-lab.net

Re: Which SATA RAID controller?

2004-03-23 Thread Andreas John
based solutions, i.e. RocketRAID (1520 two channel ... 1820 8 channel). My experience with Highpoint is gerenally better than with Promise, but I ordered my first RR 1520 Controller 2 Days ago. It's not here yet ;-) Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel

Re: Which SATA RAID controller?

2004-03-23 Thread Andreas John
based solutions, i.e. RocketRAID (1520 two channel ... 1820 8 channel). My experience with Highpoint is gerenally better than with Promise, but I ordered my first RR 1520 Controller 2 Days ago. It's not here yet ;-) Rgds, j. -- Andreas John net-lab GmbH Luisenstrasse 30b 63067 Offenbach Tel: +49