Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Florian Weimer
Lazarus Long <[EMAIL PROTECTED]> writes: > > severity 130876 wishlist > > thanks > > > > This is not a bug. > > This is definitely a security risk. It helps auditing a large farm of Debian machines. For example, there is currently no reliable way to remotely tell if a box running OpenSSH

Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Florian Weimer
Lazarus Long <[EMAIL PROTECTED]> writes: > > severity 130876 wishlist > > thanks > > > > This is not a bug. > > This is definitely a security risk. It helps auditing a large farm of Debian machines. For example, there is currently no reliable way to remotely tell if a box running OpenSS

Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Mark Brown
On Sat, Jan 26, 2002 at 05:01:14AM +, Lazarus Long wrote: > severity 130876 grave > This is definitely a security risk. There is no reason that such > information should be exposed to attackers. Just because FreeBSD has That doesn't mean it's a severity grave bug, though. There's no actual

Re: Problem with IPTables

2002-01-26 Thread MULLER Guillaume
You need to load the ip_state module

Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Mark Brown
On Sat, Jan 26, 2002 at 05:01:14AM +, Lazarus Long wrote: > severity 130876 grave > This is definitely a security risk. There is no reason that such > information should be exposed to attackers. Just because FreeBSD has That doesn't mean it's a severity grave bug, though. There's no actua

Re: Problem with IPTables

2002-01-26 Thread MULLER Guillaume
You need to load the ip_state module -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Bug#130876: Very definitely a bug, security

2002-01-26 Thread Alex Pennace
On Sat, Jan 26, 2002 at 05:00:52AM +, Lazarus Long wrote: > Post your root password and IP address if you think obscurity is > irrelevant. (You are twisting a comment about *source* being available > for peer review in the crypto community, not about site-specifics being > open to all.) Apple