Re: blocking AXFR record query

2004-01-28 Thread David Barroso
* James Miller ([EMAIL PROTECTED]) wrote: > > > If memory serves.. AXFR is a zone transfer... So, at your firewall, would > want to only allowing TCP queries from your backup (secondary, > trinary..etc.) dns servers (on the outside of your firewall) and limit > everyone else to UDP queries. And

Re: blocking AXFR record query

2004-01-28 Thread David Barroso
* James Miller ([EMAIL PROTECTED]) wrote: > > > If memory serves.. AXFR is a zone transfer... So, at your firewall, would > want to only allowing TCP queries from your backup (secondary, > trinary..etc.) dns servers (on the outside of your firewall) and limit > everyone else to UDP queries. And

Re: [Fwd: Re: LWN: Ptrace vulnerability in 2.2 and 2.4 kernels]

2003-04-01 Thread David Barroso
* Dariush Pietrzak ([EMAIL PROTECTED]) wrote: > > One reason is security: > > it's relatively easy for an intruder to install a kernel module based > > rootkit, and then hide her processes, files or connections. > isn't it security-by-obscurity? > Determined hacker can still relatively easily inser

Re: [Fwd: Re: LWN: Ptrace vulnerability in 2.2 and 2.4 kernels]

2003-04-01 Thread David Barroso
* Dariush Pietrzak ([EMAIL PROTECTED]) wrote: > > One reason is security: > > it's relatively easy for an intruder to install a kernel module based > > rootkit, and then hide her processes, files or connections. > isn't it security-by-obscurity? > Determined hacker can still relatively easily inser

Re: [Fwd: Re: LWN: Ptrace vulnerability in 2.2 and 2.4 kernels]

2003-04-01 Thread David Barroso
* Marcin Owsiany ([EMAIL PROTECTED]) wrote: > On Tue, Apr 01, 2003 at 02:30:17PM +0100, Dale Amon wrote: > > On Tue, Apr 01, 2003 at 03:36:15PM +0200, Maurizio Lemmo - Tannoiser wrote: > > > In a server enviroment, where there no need to load modules at run-time, > > > could be a "usable workaorund

Re: [Fwd: Re: LWN: Ptrace vulnerability in 2.2 and 2.4 kernels]

2003-04-01 Thread David Barroso
* Marcin Owsiany ([EMAIL PROTECTED]) wrote: > On Tue, Apr 01, 2003 at 02:30:17PM +0100, Dale Amon wrote: > > On Tue, Apr 01, 2003 at 03:36:15PM +0200, Maurizio Lemmo - Tannoiser wrote: > > > In a server enviroment, where there no need to load modules at run-time, > > > could be a "usable workaorund

Re: Key servers

2002-04-14 Thread David Barroso
ail to [EMAIL PROTECTED] > with a subject of "unsubscribe". Trouble? Contact > [EMAIL PROTECTED] > -- David Barroso aka tomac-- How do I type "for i in *.dvi do xdvi i [EMAIL PROTECTED] -- done" in a GUI? -- (Discussion in comp.os.li

Re: Key servers

2002-04-14 Thread David Barroso
ail to [EMAIL PROTECTED] > with a subject of "unsubscribe". Trouble? Contact > [EMAIL PROTECTED] > -- David Barroso aka tomac-- How do I type "for i in *.dvi do xdvi i [EMAIL PROTECTED] -- done" in a GUI? -- (Discussion i

Port 10 connections

2001-01-27 Thread David Barroso
Hi, I've just installed my new iptables rules in my debian box, and I've got plenty of connections from different hosts to port 10...What can it be? I'v searched about port 10 connections, but the only thing I know is that it's unassigned...Any ideas? Regards -- http://www.somoslopeor.com

Port 10 connections

2001-01-27 Thread David Barroso
Hi, I've just installed my new iptables rules in my debian box, and I've got plenty of connections from different hosts to port 10...What can it be? I'v searched about port 10 connections, but the only thing I know is that it's unassigned...Any ideas? Regards -- http://www.somoslopeor.com