Re: the su - user thread [Potential Debian Security Issue]

2002-01-22 Thread Kevin van Haaren
At 5:11 PM +1300 1/22/02, Adam Warner wrote: 1. Log in as root 2. su - user 3. startx (running KDE, not GNOME) 4. Click on the Control Center 5. There in the Control Center info box it will state that the user is root! Why does the KDE Control Center think the user is currently root? In contrast

Re: the su - user thread [Potential Debian Security Issue]

2002-01-22 Thread Kevin van Haaren
At 5:11 PM +1300 1/22/02, Adam Warner wrote: >1. Log in as root >2. su - user >3. startx (running KDE, not GNOME) >4. Click on the Control Center >5. There in the Control Center info box it will state that the user is >root! > >Why does the KDE Control Center think the user is currently root? In >

Re: Mailserver HDD organization

2002-01-19 Thread Kevin van Haaren
At 12:37 PM + 1/19/02, Pete Ryland wrote: I wouldn't always believe the version reported by a large mail server. It's quite common practice (I'm sure a lot on this list may do so) to display a version string that is not at all accurate in an attempt to put off crackers or create a honeypot.

Re: Mailserver HDD organization

2002-01-19 Thread Kevin van Haaren
At 12:37 PM + 1/19/02, Pete Ryland wrote: >I wouldn't always believe the version reported by a large mail server. It's >quite common practice (I'm sure a lot on this list may do so) to display a >version string that is not at all accurate in an attempt to put off crackers >or create a honeypo

Re: ProFtpd question

2001-06-30 Thread Kevin van Haaren
At 7:39 PM +0200 6/27/01, Jean-Marc Boursot wrote: Moreover, I think it's a good idea to disable ftp for people with a "real" valid shell (ie only include pseudo shells in /etc/shells) as it isn't a secure protocol. You should disable shell for any account that can access the machine via any i

Re: ProFtpd question

2001-06-30 Thread Kevin van Haaren
At 7:39 PM +0200 6/27/01, Jean-Marc Boursot wrote: >Moreover, I think it's a good idea to disable ftp for people with a >"real" valid shell (ie only include pseudo shells in /etc/shells) as it >isn't a secure protocol. You should disable shell for any account that can access the machine via any

Re: Followup: Syslog

2001-04-13 Thread Kevin van Haaren
--On Friday, April 13, 2001 3:40 PM -0700 Micah Anderson <[EMAIL PROTECTED]> hath wrote: | One additional tweak which falls into line with the security setups, that | I think is a good idea is to made the log files in /var/log to be chattr | +a (append only) so logfiles cannot be modified or

Re: Followup: Syslog

2001-04-13 Thread Kevin van Haaren
--On Friday, April 13, 2001 3:40 PM -0700 Micah Anderson <[EMAIL PROTECTED]> hath wrote: | One additional tweak which falls into line with the security setups, that | I think is a good idea is to made the log files in /var/log to be chattr | +a (append only) so logfiles cannot be modified or r

Re: NTP security

2001-03-12 Thread Kevin van Haaren
At 10:32 -0600 3/10/2001, Piotr Tarnowski wrote: Hi, I've installed NTP daemon on my firewall (with sync to external machine) and on all internal machines (with sync to my firewall). I found that this had opend port 123/udp on my firewall, so now everybody from the net can use my machine as a

Re: NTP security

2001-03-12 Thread Kevin van Haaren
At 10:32 -0600 3/10/2001, Piotr Tarnowski wrote: >Hi, > >I've installed NTP daemon on my firewall (with sync to >external machine) and >on all internal machines (with sync to my firewall). > >I found that this had opend port 123/udp on my firewall, >so now everybody >from the net can use my machi

Re: SSH with potato, not very secure?

2001-03-02 Thread Kevin van Haaren
At 06:08 + 3/2/2001, Jacob Meuser wrote: I believe it becomes uncommented if one installs over the network? (That would make sense to ME anyway.) <[EMAIL PROTECTED]> It didn't on my network install. I did an FTP install of PowerPC Debian (Potato). I had to uncomment the security line a

Re: SSH with potato, not very secure?

2001-03-02 Thread Kevin van Haaren
At 06:08 + 3/2/2001, Jacob Meuser wrote: >I believe it becomes uncommented if one installs over the network? (That >would make sense to ME anyway.) > ><[EMAIL PROTECTED]> It didn't on my network install. I did an FTP install of PowerPC Debian (Potato). I had to uncomment the security line

questions on ident, postfix & proftp

2000-12-17 Thread Kevin van Haaren
op authentication == smtp authentication, as it seems more secure). Reading through the sample configs it looks like postfix provides this through sasl but it isn't recommended using it yet. Is there another way to securely provide authenticated smtp? Thanks, Kevin van Haaren

questions on ident, postfix & proftp

2000-12-17 Thread Kevin van Haaren
op authentication == smtp authentication, as it seems more secure). Reading through the sample configs it looks like postfix provides this through sasl but it isn't recommended using it yet. Is there another way to securely provide authenticated smtp? Thanks, Kevin van Haaren -- To UNSUBSCR