wu-ftpd security

2002-10-21 Thread Steve Johnson
Hi, I'm using wu-ftpd and set up /etc/wu-ftpd/ftpaccess to allow only one user(using the deny-uid and allow-uid directives). I also added a 'restricted-uid myuser' flag. Everything is worknig fine, but I'm confused. It's chrooting (or appears to) that user to it's home directory just as I would

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > killall -9 sshd > > done Isn't that a bit extreme? /etc/init.d/sshd restart would do just fine without any of that forcing. -- Regards, Time 13 \ 9 . 3 clockbot.net / 6 msg07477/pgp0.pgp Desc

Re: wu-ftpd security

2002-10-21 Thread Bob Nielsen
I don't know if wu-ftpd is configurable to do otherwise, but on my installation only anonymous users are chrooted (to /home/ftp, which has bin, etc and lib dirs.) On Mon, Oct 21, 2002 at 09:48:54AM -0500, Steve Johnson wrote: > Hi, > I'm using wu-ftpd and set up /etc/wu-ftpd/ftpaccess to allow onl

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:51:49PM +0200, vdongen wrote: > afaik /etc/issue.net is intended for telnet and not for ssh. Are you saying using /etc/issue.net is a security risk or that it will not work? I use /etc/issue.net on all my sshd's without problems(fwiw) -- Regards, Time 13

Re: Apache SIGUSR1 bug

2002-10-21 Thread Matt Zimmerman
On Sun, Oct 20, 2002 at 04:32:53PM -0400, Phillip Hofmeister wrote: > I have not seen a Security release for the Apache SIGUSR1 bug reported > on bugtrack some weeks ago. Is woody vulnerable? Yes, a DSA is in progress. -- - mdz

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:23:42PM +0200, Aleksander Iwanski wrote: > killall -9 sshd > > done Isn't that a bit extreme? /etc/init.d/sshd restart would do just fine without any of that forcing. -- Regards, Time 13 \ 9 . 3 clockbot.net / 6 pgpOB7u3DBaoN.pgp Descripti

Re: Dear friends, never miss the chance to travel in China, the beautiful and mysterious place to be!

2002-10-21 Thread martin f krafft
also sprach Arne Schwabe <[EMAIL PROTECTED]> [2002.10.19.2009 +0200]: > err, can you at least fix your broken spam program before posting to > the list? err, you can at least *not* respond and confirm the list address, and further spam the list. think before you act! sorry for this post to every

Re: wu-ftpd security

2002-10-21 Thread Bob Nielsen
I don't know if wu-ftpd is configurable to do otherwise, but on my installation only anonymous users are chrooted (to /home/ftp, which has bin, etc and lib dirs.) On Mon, Oct 21, 2002 at 09:48:54AM -0500, Steve Johnson wrote: > Hi, > I'm using wu-ftpd and set up /etc/wu-ftpd/ftpaccess to allow onl

Re: Apache SIGUSR1 bug

2002-10-21 Thread Matt Zimmerman
On Sun, Oct 20, 2002 at 04:32:53PM -0400, Phillip Hofmeister wrote: > I have not seen a Security release for the Apache SIGUSR1 bug reported > on bugtrack some weeks ago. Is woody vulnerable? Yes, a DSA is in progress. -- - mdz -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject o

Re: Dear friends, never miss the chance to travel in China, the beautiful and mysterious place to be!

2002-10-21 Thread martin f krafft
also sprach Arne Schwabe <[EMAIL PROTECTED]> [2002.10.19.2009 +0200]: > err, can you at least fix your broken spam program before posting to > the list? err, you can at least *not* respond and confirm the list address, and further spam the list. think before you act! sorry for this post to every

Re: [OT] secure, minimal Debian installation for linux-based thin clients?

2002-10-21 Thread Matt Zimmerman
On Fri, Oct 18, 2002 at 01:01:09PM -0700, Chris Majewski wrote: > OK, thanks. BTW, how does that differ from running tasksel and not > selecting any tasks? Or is that even possible? If you run tasksel and do not select any tasks, you get packages of priority 'standard' and higher. -- - md

Re: ssh "banner"

2002-10-21 Thread Time
On Fri, Oct 18, 2002 at 03:51:49PM +0200, vdongen wrote: > afaik /etc/issue.net is intended for telnet and not for ssh. Are you saying using /etc/issue.net is a security risk or that it will not work? I use /etc/issue.net on all my sshd's without problems(fwiw) -- Regards, Time 13

Re: [OT] secure, minimal Debian installation for linux-based thin clients?

2002-10-21 Thread Matt Zimmerman
On Fri, Oct 18, 2002 at 01:01:09PM -0700, Chris Majewski wrote: > OK, thanks. BTW, how does that differ from running tasksel and not > selecting any tasks? Or is that even possible? If you run tasksel and do not select any tasks, you get packages of priority 'standard' and higher. -- - md

wu-ftpd security

2002-10-21 Thread Steve Johnson
Hi, I'm using wu-ftpd and set up /etc/wu-ftpd/ftpaccess to allow only one user(using the deny-uid and allow-uid directives). I also added a 'restricted-uid myuser' flag. Everything is worknig fine, but I'm confused. It's chrooting (or appears to) that user to it's home directory just as I would

Re: [OT] secure, minimal Debian installation for linux-based thin clients?

2002-10-21 Thread R. Bradley Tilley
On Friday 18 October 2002 03:46 pm, Noah L. Meyerhans wrote: > On Fri, Oct 18, 2002 at 12:41:37PM -0700, Chris Majewski wrote: > > Now, we're looking to upgrade the Linux on these thin clients. I like > > Debian, so that's one obvious choice. However, a standard Debian > > install (e.g. wh

Re: ssh "banner"

2002-10-21 Thread przemolicc
On Fri, Oct 18, 2002 at 04:13:22PM +0200, Johannes Berth wrote: > * [EMAIL PROTECTED] <[EMAIL PROTECTED]>: > > SSH-2.0-OpenSSH_3.4p1 Debian 1:3.4p1-1 > > > > How can I disable the message ? > > You don't want to disable it. Oh, really ?! Are you refering to "SSH-2.0" or to "OpenSSH_3.4p1 Debian