Re: [work] Integrity of Debian packages

2003-03-07 Thread Blars Blarson
In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: >If the FBI has the power, time and energy to install a proxy between my >router >and my ISP to spoof a package host (i.e. security.debian.org) just to >root my servers, then they >are clearly a heck of lot more "geeky" than I thought. Hel

Re: Integrity of Debian packages

2003-03-07 Thread Javier Fernández-Sanguino Peña
On Fri, Mar 07, 2003 at 11:33:15AM +1000, Andrew Pollock wrote: > Hi, > > One of my friends sent me this URL, it's an oldie, and the topic in > general has been discussed before, but this article certainly does raise > some concerns. > Send them this url: http://www.debian.org/doc/manu

Re: Bug#182886: libc6: local hostnames containing a dot get forwarded outside when doing host-lookups.

2003-03-07 Thread GOTO Masanori
At Sun, 2 Mar 2003 19:18:02 +0100, Bernhard R. Link <[EMAIL PROTECTED]> wrote: > * Vassilii Khachaturov <[EMAIL PROTECTED]> [030228 21:58]: > > > Thanks, I missed that. Being placed unter "internal variables" and > > > "debug" seems to have tricked me in ignoring this part. > > > > > > There shoul

unsubscribe

2003-03-07 Thread Tomas Willebrand
unsubscribe

unsubscribe

2003-03-07 Thread Karlheinz Theiler

chkrootkit and LKM

2003-03-07 Thread Jacques Lav!gnotte
Bonjour... When running from a shell logged on the machine I get : Checking `lkm'... You have 1 process hidden for readdir command You have 1 process hidden for ps command Warning: Possible LKM Trojan installed Sometimes I get 2 or 3 processes, sometimes NONE. Are there knownes 'fals

/var/log/wtmp

2003-03-07 Thread Albert Cervera Areny
I received a mail with this subject from localhost, and with what I suppose it is the diff between wtmp and its previous version. What I'd like to know is how I can rebuild the file to see what's been the change and the logins deleted? Also.. what is the daemon that sends this messages? Thanks

Re: chkrootkit and LKM

2003-03-07 Thread Jens Schuessler
* Jacques Lav!gnotte <[EMAIL PROTECTED]> [07-03-03 14:05]: > > Bonjour... > > When running from a shell logged on the machine I get : > > Checking `lkm'... You have 1 process hidden for readdir command > You have 1 process hidden for ps command > Warning: Possible LKM Trojan installed >

Re: [work] Integrity of Debian packages

2003-03-07 Thread Ted Parvu
On Thu, Mar 06, 2003 at 11:53:42PM -0800, Blars Blarson wrote: > >on me, then they certianly can put a line sniffer between me and my > >ISP... isn't that > >easier?!?! > > No need to put it between, their packet sniffer is already in place at > your ISP. Please read about CARNIVORE, which made

Re: [work] Integrity of Debian packages

2003-03-07 Thread Gary MacDougall
Yes, the American Empire is certainly on the move... and the World is their oyster. Be afraid, be very afraid. Ted Maybe you should talk to the family of the 3300 people in the WTC that died because the FBI, CIA or Special Services didn't have or couldn't intercept the many mail, fax

Re: [work] Integrity of Debian packages

2003-03-07 Thread Ted Parvu
On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: > > Maybe you should talk to the family of the 3300 people in the WTC that > died because the FBI, CIA > or Special Services didn't have or couldn't intercept the many mail, fax > and cell phone communications > that went between t

Re: [work] Integrity of Debian packages

2003-03-07 Thread Gary MacDougall
You can quote Ben Franklin all you want,  but Ben Franklin's world was a far simpler, easy to undersand and clearly not as geographical world as ours is today.  I'm sure if Ben was alive today, he'd have a much more "updated" and relative quote than a quote that was intended for the times he

Re: [work] Integrity of Debian packages

2003-03-07 Thread Nathan R. Valentine
You're all offtopic. Take it to debian-jingoism or debian-too-much-fox-news. Thank you. Please drive thru. ;) -- --- Nathan Valentine - <[EMAIL PROTECTED]> http://www.nathanvalentine.org AIM: NRVesKY signature.asc Description: This is a digitally signed message part

Re: [work] Integrity of Debian packages

2003-03-07 Thread Alastair McKinstry
This is off-topic, but you should probably know: the FBI, CIA and others were monitoring the hijackers _specifically_ prior to 9/11. As a matter of tradecraft, Al Qaeda often mention specific times and operations during calls, to flush out whether their calls are being intercepted: they mention p

Re: Way off topic: Hijacked airplanes and the no-good US govt

2003-03-07 Thread Peter Cordes
On Fri, Mar 07, 2003 at 10:39:54AM -0800, Ted Parvu wrote: > On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: > > > > Maybe you should talk to the family of the 3300 people in the WTC that > > died because the FBI, CIA > > or Special Services didn't have or couldn't intercept the

Re: [OT] [work] Integrity of Debian packages

2003-03-07 Thread Johannes Werner
well this really starts to become interesting I personally do not think that 9/11 (or something like that) could be prevented by any of those organizations (wasn't there a discussion that they knew about it beforeh

Re: [work] Integrity of Debian packages

2003-03-07 Thread Peter Cordes
On Fri, Mar 07, 2003 at 02:09:02PM -0500, Gary MacDougall wrote: > > You can quote Ben Franklin all you want, but Ben Franklin's world was a > far simpler, easy to > undersand and clearly not as geographical world as ours is today. > > I'm sure if Ben was alive today, he'd have a much more "up

Re: [work] Integrity of Debian packages

2003-03-07 Thread Christian Storch
> Maybe you should talk to the family of the 3300 people in the WTC that > died because the FBI, CIA > or Special Services didn't have or couldn't intercept the many mail, fax > and cell phone communications > that went between the cowards that flew planes into the buildings. > > You know, I fee

Re: [work] Integrity of Debian packages

2003-03-07 Thread Ted Parvu
On Fri, Mar 07, 2003 at 02:09:02PM -0500, Gary MacDougall wrote: > > hometown (Boston). They were carrying people, just like you and I and > up until 30 seconds before the disaster, we had no reason to believe > that the flight was hostile (other than the sporadic communication of > the poor folks

Re: [work] Integrity of Debian packages

2003-03-07 Thread Rich Puhek
Gary MacDougall wrote: Yes, the American Empire is certainly on the move... and the World is their oyster. Be afraid, be very afraid. Ted Maybe you should talk to the family of the 3300 people in the WTC that died because the FBI, CIA or Special Services didn't have or couldn't interc

Re: [work] Integrity of Debian packages

2003-03-07 Thread Rich Puhek
Ted Parvu wrote: On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: Maybe you should talk to the family of the 3300 people in the WTC that died because the FBI, CIA or Special Services didn't have or couldn't intercept the many mail, fax and cell phone communications that went

Re: [work] Integrity of Debian packages

2003-03-07 Thread Dale Amon
The people who fought the hijackers to the death in Pennsylvania are now part of our national lore on a par with the Boston Tea Party and Paul Revere's ride. I salute their bravery and only hope that should I as an individual ever be in a similar situation, I would have the guts to remember and fo

Re: [work] Integrity of Debian packages

2003-03-07 Thread Hubert Chan
> "Christian" == Christian Storch <[EMAIL PROTECTED]> writes: Christian> So I'm thinking about establishing an own small debian Christian> archive out of self recompiled packages as ong as there is no Christian> secure solution of authenticating packages! Just make sure that the sources are s

Re: [work] Integrity of Debian packages

2003-03-07 Thread Andrew Sayers
On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: > > The price of freedom is costly. > There is an important on-topic security issue here, albeit one as old as civilisation itself: should the state rule the citizen, or the citizen rule the state? If you believe the rulers should

SMTP logs : what do these mean?

2003-03-07 Thread Hanasaki JiJi
2003-03-03 05:19:37 H=(cyberproxy.com) [218.22.143.178] F=<[EMAIL PROTECTED]> rejected RCPT <[EMAIL PROTECTED]>: Please go away. 2003-03-03 05:19:43 H=(cyberproxy.com) [195.112.112.198] F=<[EMAIL PROTECTED]> rejected RCPT <[EMAIL PROTECTED]>: Please

Re: SMTP logs : what do these mean?

2003-03-07 Thread Ted Parvu
On Fri, Mar 07, 2003 at 06:08:40PM -0600, Hanasaki JiJi wrote: > 2003-03-03 05:19:37 > H=(cyberproxy.com) [218.22.143.178] > F=<[EMAIL PROTECTED]> rejected RCPT > <[EMAIL PROTECTED]>: Please go away. > SPAM, SPAM, SPAM... Somebody is trying to relay... At least that is what it

Re: SMTP logs : what do these mean?

2003-03-07 Thread Glen Mehn
your logs say: before-reporting-as-abuse-please-see-www.njabl.org looks like your IP or netblock is listed as a spam netblock. If your server is secure, you can go sort it out at each site, by requesting that your site be rechecked. Unless you're in the unfortunate position of being on a netb

Re: [work] Integrity (of Debian packages)

2003-03-07 Thread Pav
On Fri, Mar 07, 2003 at 02:09:02PM -0500, Gary MacDougall wrote: > > You can quote Ben Franklin all you want, but Ben Franklin's world was a > far simpler, easy to > undersand and clearly not as geographical world as ours is today. > > I'm sure if Ben was alive today, he'd have a much more "up

Re: [work] Integrity of Debian packages

2003-03-07 Thread Joost Beintema
... > Your comment seems to lay blame for 9/11 on the intelligence community. > It's fair to say that they had major flaws at that time (and possibly > now as well). You could argue that this specific incident could have > been prevented if certain measures were in place. Keep in mind, the > pe

Re: [work] Integrity of Debian packages

2003-03-07 Thread Blars Blarson
In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: >If the FBI has the power, time and energy to install a proxy between my >router >and my ISP to spoof a package host (i.e. security.debian.org) just to >root my servers, then they >are clearly a heck of lot more "geeky" than I thought. Hel

Re: Integrity of Debian packages

2003-03-07 Thread Javier Fernández-Sanguino Peña
On Fri, Mar 07, 2003 at 11:33:15AM +1000, Andrew Pollock wrote: > Hi, > > One of my friends sent me this URL, it's an oldie, and the topic in > general has been discussed before, but this article certainly does raise > some concerns. > Send them this url: http://www.debian.org/doc/manu

Re: Bug#182886: libc6: local hostnames containing a dot get forwarded outside when doing host-lookups.

2003-03-07 Thread GOTO Masanori
At Sun, 2 Mar 2003 19:18:02 +0100, Bernhard R. Link <[EMAIL PROTECTED]> wrote: > * Vassilii Khachaturov <[EMAIL PROTECTED]> [030228 21:58]: > > > Thanks, I missed that. Being placed unter "internal variables" and > > > "debug" seems to have tricked me in ignoring this part. > > > > > > There shoul

unsubscribe

2003-03-07 Thread Tomas Willebrand
unsubscribe -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

unsubscribe

2003-03-07 Thread Karlheinz Theiler
-- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

chkrootkit and LKM

2003-03-07 Thread Jacques Lav!gnotte
Bonjour... When running from a shell logged on the machine I get : Checking `lkm'... You have 1 process hidden for readdir command You have 1 process hidden for ps command Warning: Possible LKM Trojan installed Sometimes I get 2 or 3 processes, sometimes NONE. Are there knownes 'fals

/var/log/wtmp

2003-03-07 Thread Albert Cervera Areny
I received a mail with this subject from localhost, and with what I suppose it is the diff between wtmp and its previous version. What I'd like to know is how I can rebuild the file to see what's been the change and the logins deleted? Also.. what is the daemon that sends this messages? Thanks

Re: chkrootkit and LKM

2003-03-07 Thread Jens Schuessler
* Jacques Lav!gnotte <[EMAIL PROTECTED]> [07-03-03 14:05]: > > Bonjour... > > When running from a shell logged on the machine I get : > > Checking `lkm'... You have 1 process hidden for readdir command > You have 1 process hidden for ps command > Warning: Possible LKM Trojan installed >

Re: [work] Integrity of Debian packages

2003-03-07 Thread Ted Parvu
On Thu, Mar 06, 2003 at 11:53:42PM -0800, Blars Blarson wrote: > >on me, then they certianly can put a line sniffer between me and my > >ISP... isn't that > >easier?!?! > > No need to put it between, their packet sniffer is already in place at > your ISP. Please read about CARNIVORE, which made

Re: [work] Integrity of Debian packages

2003-03-07 Thread Gary MacDougall
Yes, the American Empire is certainly on the move... and the World is their oyster. Be afraid, be very afraid. Ted Maybe you should talk to the family of the 3300 people in the WTC that died because the FBI, CIA or Special Services didn't have or couldn't intercept the many mail, fax and

Re: [work] Integrity of Debian packages

2003-03-07 Thread Ted Parvu
On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: > > Maybe you should talk to the family of the 3300 people in the WTC that > died because the FBI, CIA > or Special Services didn't have or couldn't intercept the many mail, fax > and cell phone communications > that went between t

Re: [work] Integrity of Debian packages

2003-03-07 Thread Gary MacDougall
You can quote Ben Franklin all you want,  but Ben Franklin's world was a far simpler, easy to undersand and clearly not as geographical world as ours is today.  I'm sure if Ben was alive today, he'd have a much more "updated" and relative quote than a quote that was intended for the times he

Re: [work] Integrity of Debian packages

2003-03-07 Thread Nathan R. Valentine
You're all offtopic. Take it to debian-jingoism or debian-too-much-fox-news. Thank you. Please drive thru. ;) -- --- Nathan Valentine - <[EMAIL PROTECTED]> http://www.nathanvalentine.org AIM: NRVesKY signature.asc Description: This is a digitally signed message part

Re: [work] Integrity of Debian packages

2003-03-07 Thread Alastair McKinstry
This is off-topic, but you should probably know: the FBI, CIA and others were monitoring the hijackers _specifically_ prior to 9/11. As a matter of tradecraft, Al Qaeda often mention specific times and operations during calls, to flush out whether their calls are being intercepted: they mention p

Re: Way off topic: Hijacked airplanes and the no-good US govt

2003-03-07 Thread Peter Cordes
On Fri, Mar 07, 2003 at 10:39:54AM -0800, Ted Parvu wrote: > On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: > > > > Maybe you should talk to the family of the 3300 people in the WTC that > > died because the FBI, CIA > > or Special Services didn't have or couldn't intercept the

Re: [OT] [work] Integrity of Debian packages

2003-03-07 Thread Johannes Werner
well this really starts to become interesting I personally do not think that 9/11 (or something like that) could be prevented by any of those organizations (wasn't there a discussion that they knew about it beforeh

Re: [work] Integrity of Debian packages

2003-03-07 Thread Peter Cordes
On Fri, Mar 07, 2003 at 02:09:02PM -0500, Gary MacDougall wrote: > > You can quote Ben Franklin all you want, but Ben Franklin's world was a > far simpler, easy to > undersand and clearly not as geographical world as ours is today. > > I'm sure if Ben was alive today, he'd have a much more "up

Re: [work] Integrity of Debian packages

2003-03-07 Thread Christian Storch
> Maybe you should talk to the family of the 3300 people in the WTC that > died because the FBI, CIA > or Special Services didn't have or couldn't intercept the many mail, fax > and cell phone communications > that went between the cowards that flew planes into the buildings. > > You know, I fee

Re: [work] Integrity of Debian packages

2003-03-07 Thread Ted Parvu
On Fri, Mar 07, 2003 at 02:09:02PM -0500, Gary MacDougall wrote: > > hometown (Boston). They were carrying people, just like you and I and > up until 30 seconds before the disaster, we had no reason to believe > that the flight was hostile (other than the sporadic communication of > the poor folks

Re: [work] Integrity of Debian packages

2003-03-07 Thread Rich Puhek
Gary MacDougall wrote: Yes, the American Empire is certainly on the move... and the World is their oyster. Be afraid, be very afraid. Ted Maybe you should talk to the family of the 3300 people in the WTC that died because the FBI, CIA or Special Services didn't have or couldn't intercept t

Re: [work] Integrity of Debian packages

2003-03-07 Thread Rich Puhek
Ted Parvu wrote: On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: Maybe you should talk to the family of the 3300 people in the WTC that died because the FBI, CIA or Special Services didn't have or couldn't intercept the many mail, fax and cell phone communications that went be

Re: [work] Integrity of Debian packages

2003-03-07 Thread Dale Amon
The people who fought the hijackers to the death in Pennsylvania are now part of our national lore on a par with the Boston Tea Party and Paul Revere's ride. I salute their bravery and only hope that should I as an individual ever be in a similar situation, I would have the guts to remember and fo

Re: [work] Integrity of Debian packages

2003-03-07 Thread Hubert Chan
> "Christian" == Christian Storch <[EMAIL PROTECTED]> writes: Christian> So I'm thinking about establishing an own small debian Christian> archive out of self recompiled packages as ong as there is no Christian> secure solution of authenticating packages! Just make sure that the sources are s

Re: [work] Integrity of Debian packages

2003-03-07 Thread Andrew Sayers
On Fri, Mar 07, 2003 at 01:10:29PM -0500, Gary MacDougall wrote: > > The price of freedom is costly. > There is an important on-topic security issue here, albeit one as old as civilisation itself: should the state rule the citizen, or the citizen rule the state? If you believe the rulers should

SMTP logs : what do these mean?

2003-03-07 Thread Hanasaki JiJi
2003-03-03 05:19:37 H=(cyberproxy.com) [218.22.143.178] F=<[EMAIL PROTECTED]> rejected RCPT <[EMAIL PROTECTED]>: Please go away. 2003-03-03 05:19:43 H=(cyberproxy.com) [195.112.112.198] F=<[EMAIL PROTECTED]> rejected RCPT <[EMAIL PROTECTED]>: Please g

Re: SMTP logs : what do these mean?

2003-03-07 Thread Ted Parvu
On Fri, Mar 07, 2003 at 06:08:40PM -0600, Hanasaki JiJi wrote: > 2003-03-03 05:19:37 > H=(cyberproxy.com) [218.22.143.178] > F=<[EMAIL PROTECTED]> rejected RCPT > <[EMAIL PROTECTED]>: Please go away. > SPAM, SPAM, SPAM... Somebody is trying to relay... At least that is what it

Re: SMTP logs : what do these mean?

2003-03-07 Thread Glen Mehn
your logs say: before-reporting-as-abuse-please-see-www.njabl.org looks like your IP or netblock is listed as a spam netblock. If your server is secure, you can go sort it out at each site, by requesting that your site be rechecked. Unless you're in the unfortunate position of being on a netbl

Re: [work] Integrity (of Debian packages)

2003-03-07 Thread Pav
On Fri, Mar 07, 2003 at 02:09:02PM -0500, Gary MacDougall wrote: > > You can quote Ben Franklin all you want, but Ben Franklin's world was a > far simpler, easy to > undersand and clearly not as geographical world as ours is today. > > I'm sure if Ben was alive today, he'd have a much more "up

Re: [work] Integrity of Debian packages

2003-03-07 Thread Joost Beintema
... > Your comment seems to lay blame for 9/11 on the intelligence community. > It's fair to say that they had major flaws at that time (and possibly > now as well). You could argue that this specific incident could have > been prevented if certain measures were in place. Keep in mind, the > pe