Re: I have been attacked 3 times in 5 weeks

2005-05-16 Thread Karsten M. Self
rt-questions.html Peace. -- Karsten M. Self http://kmself.home.netcom.com/ What Part of "Gestalt" don't you understand? Go through his clothes and look for loose change. - Princess Bride signature.asc Description: Digital signature

Re: running services in their own little world

2004-07-24 Thread Karsten M. Self
model. Look at the services you (need to) run. Look at firewalling and other security measures. Chroot isn't a be-all, end-all solution. It's useful. It's a tool. No silver bullets here. Keep this in mind. Peace. -- Karsten M. Self <[EMAIL PROTECTED]>

Re: Attempts to poison bayesian systems

2003-12-31 Thread Karsten M. Self
on Mon, Dec 29, 2003 at 11:03:09AM +0100, Kjetil Kjernsmo ([EMAIL PROTECTED]) wrote: > On Monday 29 December 2003 00:12, Karsten M. Self wrote: > > _Random_ padding won't be > > effective. ?_Targeted_ padding will be, though spammers would have to > > target th

Re: Attempts to poison bayesian systems

2003-12-31 Thread Karsten M. Self
on Mon, Dec 29, 2003 at 11:03:09AM +0100, Kjetil Kjernsmo ([EMAIL PROTECTED]) wrote: > On Monday 29 December 2003 00:12, Karsten M. Self wrote: > > _Random_ padding won't be > > effective. ?_Targeted_ padding will be, though spammers would have to > > target the non-spam

Re: Attempts to poison bayesian systems

2003-12-28 Thread Karsten M. Self
m-learn' folder which is crawled by sa-learn every 30 minutes (cronjob), after a few days of which the chaffed messages aren't appearing in my "greylist" box (previously unknown senders). I also maintain a whitelist which is the only way a given user can end up in my inbox. Mai

Re: Attempts to poison bayesian systems

2003-12-28 Thread Karsten M. Self
m-learn' folder which is crawled by sa-learn every 30 minutes (cronjob), after a few days of which the chaffed messages aren't appearing in my "greylist" box (previously unknown senders). I also maintain a whitelist which is the only way a given user can end up in my inbox. Mailing lis

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-10 Thread Karsten M. Self
et install > Can these packages be mixed with "stock" debian woody? Yes. > Many thanks for your help! Peace. -- Karsten M. Self http://kmself.home.netcom.com/ What Part of "Gestalt" don't you understand? Kudos to Gateway's Digital Music Campaing

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-10 Thread Karsten M. Self
et install > Can these packages be mixed with "stock" debian woody? Yes. > Many thanks for your help! Peace. -- Karsten M. Self <[EMAIL PROTECTED]>http://kmself.home.netcom.com/ What Part of "Gestalt" don't you understand? Kudos to Gateway'

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-04 Thread Karsten M. Self
on Wed, Dec 03, 2003 at 04:40:12PM +, Dale Amon ([EMAIL PROTECTED]) wrote: > On Wed, Dec 03, 2003 at 06:46:51AM -0800, Karsten M. Self wrote: > > Having a team that shares experience and combines talents in > > patching a kernel and tuning it to secure configurations is a

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-04 Thread Karsten M. Self
on Wed, Dec 03, 2003 at 04:40:12PM +, Dale Amon ([EMAIL PROTECTED]) wrote: > On Wed, Dec 03, 2003 at 06:46:51AM -0800, Karsten M. Self wrote: > > Having a team that shares experience and combines talents in > > patching a kernel and tuning it to secure configurations is a

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-04 Thread Karsten M. Self
on Wed, Dec 03, 2003 at 04:57:29PM +0100, Adam ENDRODI ([EMAIL PROTECTED]) wrote: > On Wed, Dec 03, 2003 at 06:46:51AM -0800, Karsten M. Self wrote: > > on Wed, Dec 03, 2003 at 01:31:29PM +, Dale Amon ([EMAIL PROTECTED]) > > wrote: > > > On Wed, Dec 03, 2003 at 03:2

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-04 Thread Karsten M. Self
on Wed, Dec 03, 2003 at 04:57:29PM +0100, Adam ENDRODI ([EMAIL PROTECTED]) wrote: > On Wed, Dec 03, 2003 at 06:46:51AM -0800, Karsten M. Self wrote: > > on Wed, Dec 03, 2003 at 01:31:29PM +, Dale Amon ([EMAIL PROTECTED]) wrote: > > > On Wed, Dec 03, 2003 at 03:21:57PM +0200

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-03 Thread Karsten M. Self
ur own, but you're at least starting from a better base. Peace. -- Karsten M. Self http://kmself.home.netcom.com/ What Part of "Gestalt" don't you understand? Geek for hire: http://kmself.home.netcom.com/resume.html pgpgrdUgPQBxW.pgp Description: PGP signature

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-03 Thread Karsten M. Self
ur own, but you're at least starting from a better base. Peace. -- Karsten M. Self <[EMAIL PROTECTED]>http://kmself.home.netcom.com/ What Part of "Gestalt" don't you understand? Geek for hire: http://kmself.home.netcom.com/resume.html pgp0.pgp Description: PGP signature

Re: [SECURITY] [DSA-403-1] userland can access Linux kernel memory

2003-12-03 Thread Karsten M. Self
e are also unknown unknowns, The ones we don't know We don't know. - Donald Rumsfeld, "The Unknown", Feb 12, 2002 DoD news briefing Peace. -- Karsten M. Self http://kmself.home.netcom.com/ What Part of "Gestalt" don't you understand? In

Re: [SECURITY] [DSA-403-1] userland can access Linux kernel memory

2003-12-03 Thread Karsten M. Self
e are also unknown unknowns, The ones we don't know We don't know. - Donald Rumsfeld, "The Unknown", Feb 12, 2002 DoD news briefing Peace. -- Karsten M. Self <[EMAIL PROTECTED]>http://kmself.home.netcom.com/ What Part of "Gestalt"

Improved Debian Project Emergency Communications (was Re: communication structures crumbled)

2003-11-28 Thread Karsten M. Self
date schedule -- say, posts every 2-3 days for a prolonged outage. Enough to keep people informed, but not swamp developers or the fall back emergency list infrastructure, or at least a "expect updates within ". Including this information in a document distributed with Deb

Improved Debian Project Emergency Communications (was Re: communication structures crumbled)

2003-11-28 Thread Karsten M. Self
date schedule -- say, posts every 2-3 days for a prolonged outage. Enough to keep people informed, but not swamp developers or the fall back emergency list infrastructure, or at least a "expect updates within ". Including this information in a document distributed with De

Re: Mail server

2003-11-15 Thread Karsten M. Self
n't > think I'm paranoid, but it is so :) > > So, my question is: "Is there way to keep messages on server secure? > Encrypted or coded some how?" What's your threat model? Peace. -- Karsten M. Self http://kmself.home.netcom.com/ What Part of &qu

Re: Mail server

2003-11-15 Thread Karsten M. Self
n't > think I'm paranoid, but it is so :) > > So, my question is: "Is there way to keep messages on server secure? > Encrypted or coded some how?" What's your threat model? Peace. -- Karsten M. Self <[EMAIL PROTECTED]>http://kmself.home.ne

Re: Party with porn stars

2001-12-21 Thread Karsten M. Self
on Fri, Dec 21, 2001 at 10:15:14AM -0500, Justin R. Miller ([EMAIL PROTECTED]) wrote: > Thus spake Karsten M. Self (kmself@ix.netcom.com): > > > I've got a few systems for trapping spam. > > I've been quite happy with spamassassin. Feel free to check out my

Re: Party with porn stars

2001-12-21 Thread Karsten M. Self
on Fri, Dec 21, 2001 at 10:15:14AM -0500, Justin R. Miller ([EMAIL PROTECTED]) wrote: > Thus spake Karsten M. Self ([EMAIL PROTECTED]): > > > I've got a few systems for trapping spam. > > I've been quite happy with spamassassin. Feel free to check out my

Re: Party with porn stars

2001-12-21 Thread Karsten M. Self
@-encoded, big-number URLs, though I'm working on it). But it handles most cases well. I somewhat prefer the semi-auto nature of it as I have some control over the actual execution and triggering. The '-v' flag increases verbosity. Peace. -- Karsten M. Self

Re: Party with porn stars

2001-12-21 Thread Karsten M. Self
RL (@-encoded, big-number URLs, though I'm working on it). But it handles most cases well. I somewhat prefer the semi-auto nature of it as I have some control over the actual execution and triggering. The '-v' flag increases verbosity. Peace. -- Karsten M. Self <[EMAIL PROTE

Re: TREAT URGENT

2001-10-26 Thread Karsten M. Self
inguished indulgence (and all your cash) http://www.salon.com/people/feature/2001/08/07/419scams/print.html Nigerian 419 Scam "Game Over!" http://home.pacbell.net/jpaladin/ Book describes how the scam plays out. Thank you. -- Karsten M. Selfht

Re: TREAT URGENT

2001-10-26 Thread Karsten M. Self
e your distinguished indulgence (and all your cash) http://www.salon.com/people/feature/2001/08/07/419scams/print.html Nigerian 419 Scam "Game Over!" http://home.pacbell.net/jpaladin/ Book describes how the scam plays out. Thank you. -- Karsten M. Self <[EMAIL PROTECT

Re: Linux box vs black box

2001-08-18 Thread Karsten M. Self
t-quoted dictum, "Security is a process, not a product." (A corollary is "Security is a process, not a state.") Cheers. -- Karsten M. Self http://kmself.home.netcom.com/ What part of "Gestalt" don't you understand? There is no K5

Re: Linux box vs black box

2001-08-18 Thread Karsten M. Self
t-quoted dictum, "Security is a process, not a product." (A corollary is "Security is a process, not a state.") Cheers. -- Karsten M. Self <[EMAIL PROTECTED]> http://kmself.home.netcom.com/ What part of "Gestalt" don't you understand?