Re: chkrootkit sniffers

2006-08-13 Thread Christian Schuerer
On Sunday 13 August 2006 23:38, Nicolas Haller wrote: > It remains strange because normally, lo is a non-broadcast interface. With version 0.46 it get this result: Checking `sniffer'... lo: not promisc and no packet sniffer sockets lan: PACKET SNIFFER(/sbin/dhclient3[6515]) Maybe it's just becau

Re: chkrootkit sniffers

2006-08-11 Thread Christian Schuerer
On Thursday 10 August 2006 23:23, Sven Hartge wrote: > Um 22:48 Uhr am 10.08.06 schrieb Henri Salo: > > I am running Debian stable (kernel 2.6.8-2) chkrootkit version 0.44 with > > command chkrootkit and it gives me: > > > > Checking `sniffer'... lo: PACKET SNIFFER(/sbin/dhclient[29148]) > > eth0:

Strange 'su' error messages

2004-01-13 Thread Christian Schuerer
Hello! Since updating my debian server yesterday I get the following error messages every hour (generated by logcheck): Jan 13 00:05:01 asterix su[2102]: + ??? root:bin Today there is even an additional line: Jan 13 06:05:01 asterix su[5684]: + ??? root:bin Jan 13 06:25:01 asterix su[57

Strange 'su' error messages

2004-01-13 Thread Christian Schuerer
Hello! Since updating my debian server yesterday I get the following error messages every hour (generated by logcheck): Jan 13 00:05:01 asterix su[2102]: + ??? root:bin Today there is even an additional line: Jan 13 06:05:01 asterix su[5684]: + ??? root:bin Jan 13 06:25:01 asterix su[57

Re: Named daemon and port 32770? (and port 32985 on restart)

2002-10-15 Thread Christian Schuerer-Waldheim
Hi! > Any ideas on why there is a single UDP port open? My configuration is > pretty simple, no controls configured for the name server and a 'listen-on > port 53' statement in the config file As I can remember, bind is controlled (start, stop, etc) via an extra daemon. For this it would ne

Re: Named daemon and port 32770? (and port 32985 on restart)

2002-10-15 Thread Christian Schuerer-Waldheim
Hi! > Any ideas on why there is a single UDP port open? My configuration is > pretty simple, no controls configured for the name server and a 'listen-on > port 53' statement in the config file As I can remember, bind is controlled (start, stop, etc) via an extra daemon. For this it would n

Access on Port 0

2002-10-11 Thread Christian Schuerer-Waldheim
Hello! In my firewall-log I can find several entries like this: 8<--- Oct 11 19:25:48 asterix kernel: Dropwall: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:**:**:**:**:**:**:**:** SRC=***.***.***.*** DST=***.***.***.*** LEN=1456 TOS=0x00 PREC=0x00 TTL=110 ID=21266 PROTO=UDP SPT=17060 DPT=0 LEN

Access on Port 0

2002-10-11 Thread Christian Schuerer-Waldheim
Hello! In my firewall-log I can find several entries like this: 8<--- Oct 11 19:25:48 asterix kernel: Dropwall: IN=eth0 OUT= MAC=ff:ff:ff:ff:ff:ff:**:**:**:**:**:**:**:** SRC=***.***.***.*** DST=***.***.***.*** LEN=1456 TOS=0x00 PREC=0x00 TTL=110 ID=21266 PROTO=UDP SPT=17060 DPT=0 LEN

Re: SMTP and POP3 with ssl + login/password

2002-10-10 Thread Christian Schuerer-Waldheim
Hi! > I need to setup a Debian Woody server with th following: > > * SMTP (i like sendmail) with: >+ incomming authentication SECURE > to send an email with this server it MUST be necessary authentication > with SSL > > * POP3 (i like qpopper) >+ outgoing authentication SE

Re: SMTP and POP3 with ssl + login/password

2002-10-10 Thread Christian Schuerer-Waldheim
Hi! > I need to setup a Debian Woody server with th following: > > * SMTP (i like sendmail) with: >+ incomming authentication SECURE > to send an email with this server it MUST be necessary authentication > with SSL > > * POP3 (i like qpopper) >+ outgoing authentication S