Re: Things to watch on my server

2002-06-07 Thread Emmanuel Valliet
On Fri, Jun 07, 2002 at 03:14:23PM +0200, Wouter van Gils wrote: Well, you could stop looking at log files, and let logcheck do it for you :) apt-get install logcheck You might also want a Network Intrusion Detection System -- snort apt-get install snort And you can too install AIDE.

Re: stat=I/O error: Input/output error in Sendmail on Debian

2002-05-06 Thread Emmanuel Valliet
(2002-05-06) Informasjon sed : | Hello! | | | Can anyone help me find a solution to this message I get in my logfile in Sendmail. | | stat=I/O error: Input/output error | | It happens only when I send to one special host/recipient. | | Please! | | Stian Kristoffersen I had this

RE: Hacked too?

2002-01-11 Thread Emmanuel Valliet
(2002-01-12) Igor Balusov sed : | What is mean: | If you're running PortSentry/klaxon or another program that binds itself to | unused ports probably chkrootkit will give you a false positive on the | bindshell test (ports .. 31336/tcp, 31337/tcp ...).? | It is from

RE: Hacked too?

2002-01-11 Thread Emmanuel Valliet
(2002-01-12) Igor Balusov sed : | What is mean: | If you're running PortSentry/klaxon or another program that binds itself to | unused ports probably chkrootkit will give you a false positive on the | bindshell test (ports .. 31336/tcp, 31337/tcp ...).? | It is from

Re: How do I disable (close) ports?

2001-12-04 Thread Emmanuel Valliet
(2001-12-04) J. Paul Bruns-Bielkowicz sed : | Hi, | I disabled all but a few ports in /etc/services, but I have | tcp0 0 pa237.olsztyn.sdi.t:111 80.116.215.37:1064 | ESTABLISHED | when I netstat my machine. What exactly does this mean? I just want | 25/tcp opensmtp

Re: FTP and security

2001-11-08 Thread Emmanuel Valliet
(2001-11-09) Jari Eskelinen sed : | While were on the subject, is there an OpenSSH port of SFTP? | openssh has a sftp subsystem, yes. | | How about sftp-client with decent (G)UI, is there one (for Linux, | preferable for Debian)? OpenSSH's sftp-client is pathetic. How you even | can

Re: [Fwd: Virus found in sent message ?????????????????????3????]

2001-09-24 Thread Emmanuel Valliet
(2001-09-24) Haris Sehic sed : | On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: |Do you know if it can infect my debian box? | | Thanks, | Enrique | | only if you have VB installed | |

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread Emmanuel Valliet
(2001-09-24) Haris Sehic sed : | On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: |Do you know if it can infect my debian box? | | Thanks, | Enrique | | only if you have VB installed | | ---snip---

Re: i am experincing intrusion attempts

2001-09-18 Thread Emmanuel Valliet
(2001-09-18) [EMAIL PROTECTED] sed : | I need to trace the person who is hitting on my pc 40 times a day. | Any ideas? | Drew Watching the logs, using snort, traceroute, whois, and hosts, you should be able to locate him, or at least his ISP. And after

Re: New IIS worm

2001-09-18 Thread Emmanuel Valliet
(2001-09-18) Emmanuel Valliet sed : | | I know we don't care on linux, but I have reallly a lot of hits from | machine querying for the ..%%35c../winnt/system32/cmd.exe and Cie. | And it starts to make a lot of apache childs, and the global charge | grows consequently. | Is there a way

Re: i am experincing intrusion attempts

2001-09-18 Thread Emmanuel Valliet
(2001-09-18) [EMAIL PROTECTED] sed : | I need to trace the person who is hitting on my pc 40 times a day. | Any ideas? | Drew Watching the logs, using snort, traceroute, whois, and hosts, you should be able to locate him, or at least his ISP. And after

New IIS worm

2001-09-18 Thread Emmanuel Valliet
I know we don't care on linux, but I have reallly a lot of hits from machine querying for the ..%%35c../winnt/system32/cmd.exe and Cie. And it starts to make a lot of apache childs, and the global charge grows consequently. Is there a way to protect from that ? Using an apache configuration trick

Re: New IIS worm

2001-09-18 Thread Emmanuel Valliet
(2001-09-18) Emmanuel Valliet sed : | | I know we don't care on linux, but I have reallly a lot of hits from | machine querying for the ..%%35c../winnt/system32/cmd.exe and Cie. | And it starts to make a lot of apache childs, and the global charge | grows consequently. | Is there a way

Re: Secure Network Filesystem

2001-08-28 Thread Emmanuel Valliet
(2001-08-28) Alisson Sellaro sed : | Hi there folks | | I'm planning a modification in the network of my departament | here. We have a pretty standard lay-out with a DMZ and a | screened subnet firewalling schema (two firewalls, one from | outside to our DMZ and other from the DMZ to our

Re: Secure Network Filesystem

2001-08-28 Thread Emmanuel Valliet
(2001-08-28) Alisson Sellaro sed : | Hi there folks | | I'm planning a modification in the network of my departament | here. We have a pretty standard lay-out with a DMZ and a | screened subnet firewalling schema (two firewalls, one from | outside to our DMZ and other from the DMZ to our

Re: apt-get do not douwnload new packages announced in debian-security-announce

2001-08-09 Thread Emmanuel Valliet
-. Alberto Cortés (2001-08-09) : | I have a little problem with apt-get, i think i am not doing it the | proper way. | |When there is a announce that certain package has a bug, (like | gnupg v1.0.5) you can read in www.debian.org that there is a new | package to download