Re: a compromised machine

2005-07-24 Thread Christoph Haas
On Sun, Jul 24, 2005 at 09:54:28AM +0200, Nejc Novak wrote: > I think one of my servers has been compromised. Since i don't have a lot > of experiencei with these things, i beg you for your help. > > Information i have gathered together till now are the following. Server > is runnin latest debia

Critical bug in pdns - security team not responding

2005-07-09 Thread Christoph Haas
Dear list... our package 'pdns' in Sarge has a serious bug which can be abused to run a DoS attack against a name server. My co-maintainer already mailed the security team but did not get a response yet. Currently we are preparing a new package to upload into 'unstable'. How else can we get the f

Re: Recommended firewall package?

2004-11-01 Thread Christoph Haas
x "drop-in: " $IPT -A logdrop -j DROP # log+drop incoming port 445 traffic $IPT -A INPUT -i eth1 --dport 445 -j logdrop Cheers Christoph -- Dipl.-Inform Christoph Haas OTTO GmbH & Co. KG / Wandsbeker Straße 3-7 / 22172 Hamburg Department IT-KS-SN (Server & Networks) Phone

Re: Spyware / Adware

2004-09-03 Thread Christoph Haas
On Tue, Aug 31, 2004 at 06:33:07AM -0400, Snyder, Dave (D.F.) wrote: > Is Linux vulnerable to these unwanted downloads and if so, how do I protect > Linux so I don't have a similar issue? In theory, yes. Surfing security depends mainly on your web browser. However generally security standards on L

Re: Forcing users to use sasl on postfix

2003-09-03 Thread Christoph Haas
On Tue, Sep 02, 2003 at 06:43:28PM -0300, Leandro Rodrigo Saad Cruz wrote: > I want all users that send email on my smtp gateway to use sasl > authentication. You are invited to verify your configuration with my tutorial at workaround.org/ispmail.shtml - perhaps that'll help you. > smtpd_recipien

Re: Forcing users to use sasl on postfix

2003-09-03 Thread Christoph Haas
On Tue, Sep 02, 2003 at 06:43:28PM -0300, Leandro Rodrigo Saad Cruz wrote: > I want all users that send email on my smtp gateway to use sasl > authentication. You are invited to verify your configuration with my tutorial at workaround.org/ispmail.shtml - perhaps that'll help you. > smtpd_recipien

Re: OT: An Idea for an IDS

2003-07-01 Thread Christoph Haas
On Tue, Jul 01, 2003 at 10:22:33AM +0200, Volker Tanger wrote: > ...which is the official license to shoot yourself into the foot. What > happens if I send you a forged, suspicious packet with source-IP equal > to the IP address of your gateway router, your DNS server, your internal > system(s), ..

Re: OT: An Idea for an IDS

2003-07-01 Thread Christoph Haas
On Tue, Jul 01, 2003 at 10:22:33AM +0200, Volker Tanger wrote: > ...which is the official license to shoot yourself into the foot. What > happens if I send you a forged, suspicious packet with source-IP equal > to the IP address of your gateway router, your DNS server, your internal > system(s), ..

Re: request to german speaking users

2003-06-30 Thread Christoph Haas
On Sun, Jun 29, 2003 at 10:32:54PM +0200, Christian Kujau wrote: > hm, patches. i'm not good at creating patches. would it help too if i/we > send you "this word, sentence, page XX.." and the like? That's a terrible burden for Alexander to create text from it. Please get the docbook formatted cod

Re: request to german speaking users

2003-06-30 Thread Christoph Haas
On Sun, Jun 29, 2003 at 10:32:54PM +0200, Christian Kujau wrote: > hm, patches. i'm not good at creating patches. would it help too if i/we > send you "this word, sentence, page XX.." and the like? That's a terrible burden for Alexander to create text from it. Please get the docbook formatted cod

Re: request to german speaking users

2003-06-29 Thread Christoph Haas
Hi, Alexander... On Thu, Jun 26, 2003 at 11:32:56PM +0200, Alexander Schmehl wrote: > I just finished the translation of the security howto to german, but > some parts are very ugly hacked. > > It would be very nice, if some of you would review my translation (or > at least small parts of it), an

Re: request to german speaking users

2003-06-29 Thread Christoph Haas
Hi, Alexander... On Thu, Jun 26, 2003 at 11:32:56PM +0200, Alexander Schmehl wrote: > I just finished the translation of the security howto to german, but > some parts are very ugly hacked. > > It would be very nice, if some of you would review my translation (or > at least small parts of it), an

Re: MAC address change

2003-06-22 Thread Christoph Haas
On Sun, Jun 22, 2003 at 01:54:33PM +0200, Adam ENDRODI wrote: > How widely do you think changing the MAC address of a NIC via > ``ifconfig hw'' is supported by the various network cards > and drivers out there nowadays? > > My collegue and me have debated several times whether watching > the LAN

Re: MAC address change

2003-06-22 Thread Christoph Haas
On Sun, Jun 22, 2003 at 01:54:33PM +0200, Adam ENDRODI wrote: > How widely do you think changing the MAC address of a NIC via > ``ifconfig hw'' is supported by the various network cards > and drivers out there nowadays? > > My collegue and me have debated several times whether watching > the LAN

Re: Scanning with reverse connections?

2003-06-06 Thread Christoph Haas
On Thu, Jun 05, 2003 at 08:29:10PM +0100, Hamish Marson wrote: > I've noticed some strange traffic on our firewalls recently. Someone (Or > multiple someones) are attempting to send tcp packets inbound to our > network FROM well known ports (e.g. port 80) to multiple port numbers, > and usually

Re: Scanning with reverse connections?

2003-06-05 Thread Christoph Haas
On Thu, Jun 05, 2003 at 08:29:10PM +0100, Hamish Marson wrote: > I've noticed some strange traffic on our firewalls recently. Someone (Or > multiple someones) are attempting to send tcp packets inbound to our > network FROM well known ports (e.g. port 80) to multiple port numbers, > and usually

Re: /etc/hosts on a router

2003-05-16 Thread Christoph Haas
Hi, Daniel... > I have found a nice "HOSTS" list for windows (similar to the /etc/hosts file > in linux) which matches some bad sites to localhost, so your pc won't access > them! With windows this works very nice, but how can I do this with Debian? This works only when resolving names from the l