Re: Compromising Debian Repositories

2013-08-03 Thread Aníbal Monsalve Salazar
On Sat, Aug 03, 2013 at 12:17:06PM +0200, Volker Birk wrote: > Not to mention the build tool chains. It reminds me of Ken Thompson's article Reflections on Trusting Trust. In which he explains how to train the C compiler. http://cm.bell-labs.com/who/ken/trust.html "The moral is obvious. You ca

Re: OpenSSH not logging denied public keys, even with logging set to verbose.

2012-03-01 Thread Aníbal Monsalve Salazar
On Thu, Mar 01, 2012 at 06:56:07AM -0600, Jordon Bedwell wrote: >The problem is I cannot get sshd to log publickey denied errors to >/var/log/auth.log so our daemons can ban these users. I want to know >what happened to messages like "publickey denied for [user] from [ip]" >I cannot get it to log

bios infection (was: how to fix rootkit?)

2012-02-08 Thread Aníbal Monsalve Salazar
On Thu, Feb 09, 2012 at 11:07:20AM +1100, Russell Coker wrote: >On Thu, 9 Feb 2012, Stephen Hemminger wrote: >>The advice I heard is trust nothing (even reflash the BIOS). > >Do you know of any real-world exploits that involve replacing the BIOS? It's >been theoretically possible for a long time

Re: [SECURITY] [DSA 1172-1] New bind9 packages fix denial of service

2006-09-09 Thread Aníbal Monsalve Salazar
On Sat, Sep 09, 2006 at 12:36:25AM -0700, David Broome wrote: >A quick bug report for the list. Can someone second this behaviour? Déjà vu (maybe), see http://bugs.debian.org/265642 Aníbal Monsalve Salazar -- http://v7w.com/anibal signature.asc Description: Digital signature

Re: sendmail vulnerability

2006-03-23 Thread Aníbal Monsalve Salazar
or should I try to >install sendmail 8.13.6 standalone? sendmail 8.13.6-1 is in NEW. See http://ftp-master.debian.org/new.html Aníbal Monsalve Salazar -- http://v7w.com/anibal signature.asc Description: Digital signature

Re: Port 699 listening

2005-12-15 Thread Aníbal Monsalve Salazar
e. It tells you about the -i option and tcp_wrapper support. >Jeffrey Aníbal Monsalve Salazar -- .''`. Debian GNU/Linux : :' : Free Operating System `. `' http://debian.org/ `- http://v7w.com/anibal signature.asc Description: Digital signature

Re: Passwordless Authentication (was Re: How to reduce sid security)

2003-08-14 Thread Aníbal Monsalve Salazar
evries/security/ssh2_pubkey_auth_config.nl.html > > Grx HdV Aníbal Monsalve Salazar -- .''`. Debian GNU/Linux | Building 28C : :' : Free Operating System | Monash University VIC 3800 `. `' http://debian.org/| Australia `- | pgp0.pgp Description: PGP signature

Re: Passwordless Authentication (was Re: How to reduce sid security)

2003-08-11 Thread Aníbal Monsalve Salazar
> http://huizen.dto.tudelft.nl/devries/security/ssh2_pubkey_auth_config.nl.html > > Grx HdV Aníbal Monsalve Salazar -- .''`. Debian GNU/Linux | Building 28C : :' : Free Operating System | Monash University VIC 3800 `. `' http://debian.org/| Australia `- | pgp5ZeHsYfa3z.pgp Description: PGP signature

Re: how to help with security in debian

2003-06-04 Thread Aníbal Monsalve Salazar
On Sun, Jun 01, 2003 at 12:14 +1000, Aníbal Monsalve Salazar wrote: > A month ago or so, Martin Schulze sent a message about his guidelines > to help with security in debian. It was Martin Michlmayr who posted the message: http://lists.debian.org/debian-devel-announce/2003/debian-devel-an

Re: how to help with security in debian

2003-06-03 Thread Aníbal Monsalve Salazar
On Sun, Jun 01, 2003 at 12:14 +1000, Aníbal Monsalve Salazar wrote: > A month ago or so, Martin Schulze sent a message about his guidelines > to help with security in debian. It was Martin Michlmayr who posted the message: http://lists.debian.org/debian-devel-announce/2003/debian-devel-an

how to help with security in debian

2003-06-01 Thread Aníbal Monsalve Salazar
A month ago or so, Martin Schulze sent a message about his guidelines to help with security in debian. It included a URL at infodrom.org. Could someone please send me the message and the URL? pgp0.pgp Description: PGP signature

how to help with security in debian

2003-05-31 Thread Aníbal Monsalve Salazar
A month ago or so, Martin Schulze sent a message about his guidelines to help with security in debian. It included a URL at infodrom.org. Could someone please send me the message and the URL? pgphaVdBqoFc7.pgp Description: PGP signature