Re: Upcoming changes in advisory format

2011-01-06 Thread Lionel Elie Mamane
On Sat, Dec 18, 2010 at 01:08:07PM +0100, Moritz Muehlenhoff wrote: Traditionally Debian security advisories have included MD5 check sums of the updated packages. Since apt cryptographically enforces the integrity of the archive for quite some time now, we've decided to finally drop the hash

Re: How safely to stop using backports repo?

2009-05-28 Thread Lionel Elie Mamane
On Thu, May 28, 2009 at 01:20:25AM +0700, sthu.d...@gmail.com wrote: Thank You for Your reply: Otherwise, you can `apt-get remove` them (plus --purge if you want to reset your configuration files) and re-install them : that way you'll use the main-repo version and you won't want have security

Re: Debian bind DNS

2006-05-09 Thread Lionel Elie Mamane
On Tue, May 09, 2006 at 06:09:54AM +0200, Florian Weimer wrote: * martin: I have built a local DNS server bind (Debian Sarge).The DNS should accelerate DNS look ups by LAN clients. But Now, in contrary the local dns is slower than a custom DNS by my webhoster :-( You should use BIND 9,

Re: [SECURITY] [DSA 1027-1] New mailman packages fix denial of service

2006-04-06 Thread Lionel Elie Mamane
On Thu, Apr 06, 2006 at 10:22:22AM +0200, Martin Schulze wrote: -- Debian Security Advisory DSA 1027-1[EMAIL PROTECTED] http://www.debian.org/security/ Steve Kemp April

Mailman DoS CVE-2005-3573, debbug #339095

2005-12-14 Thread Lionel Elie Mamane
fall apart if the filename of an attachment is an invalid UTF-8 +string, which leads to a DoS attack (closes: #339095) +This is CVE-2005-3573 + + -- Lionel Elie Mamane [EMAIL PROTECTED] Wed, 14 Dec 2005 12:13:45 +0100 + mailman (2.1.5-8) unstable; urgency=low * Add Italian debconf

Re: Mailman DoS CVE-2005-3573, debbug #339095

2005-12-14 Thread Lionel Elie Mamane
On Wed, Dec 14, 2005 at 12:25:50PM +0100, Lionel Elie Mamane wrote: I've noticed that an issue I have fixed in Mailman in sid has been issued a CVE and that Mandrake has issued a security advisory over it. The Mandrake security advisory also covers another DoS that's - again - already fixed

Re: Mailman DoS CVE-2005-3573, debbug #339095

2005-12-14 Thread Lionel Elie Mamane
On Wed, Dec 14, 2005 at 03:29:48PM +0100, Lionel Elie Mamane wrote: On Wed, Dec 14, 2005 at 12:25:50PM +0100, Lionel Elie Mamane wrote: I've noticed that an issue I have fixed in Mailman in sid has been issued a CVE and that Mandrake has issued a security advisory over it. The Mandrake

Re: [PATCH] 2.4.28 and 2.6.10 PATCH FOR uselib() exploit

2005-01-09 Thread Lionel Elie Mamane
On Sat, Jan 08, 2005 at 02:40:52PM -0500, Simon Raven / Eric S. Côté wrote: 2.4.28 http://www.grsecurity.net/linux-2.4.28-secfix-200501071141.patch Is huge, touches many areas. Didn't apply cleanly to a pristine 2.4.28. The LKML gives http://linux.bkbits.net:8080/linux-2.4/[EMAIL

Re: pgp in Debian: obsolete?

2004-09-02 Thread Lionel Elie Mamane
On Thu, Aug 12, 2004 at 11:20:28PM +0200, Florian Weimer wrote: Quoting Florian Weimer ([EMAIL PROTECTED]): Just out of curiosity, are there now, or have there been in the past, any _other_ implementations of the OpenPGP spec, besides GnuPG? GnuPG is not a complete implementation of

Re: VPN question

2002-11-28 Thread Lionel Elie Mamane
On Thu, Nov 28, 2002 at 12:37:03AM +0100, David J. M. Karlsen wrote: I want to include crypto-patches from kerneli.org as well and these patches seem to clash with the freeswan ones. The latest freeswan patches include the CryptoAPI stuff. -- Lionel

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: security.debian.org Is it possible to set up a mirror somewhere for the time being? ftp://download.xs4all.nl/pub/debian-security/ is a mirror, too. The question still remains on what will happen for *future* security

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 12:47:24PM +0100, Lionel Elie Mamane wrote: On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: security.debian.org Is it possible to set up a mirror somewhere for the time being? ftp://download.xs4all.nl/pub/debian-security/ is a mirror, too. Err

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: security.debian.org Is it possible to set up a mirror somewhere for the time being? ftp://download.xs4all.nl/pub/debian-security/ is a mirror, too. The question still remains on what will happen for *future* security

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 12:47:24PM +0100, Lionel Elie Mamane wrote: On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: security.debian.org Is it possible to set up a mirror somewhere for the time being? ftp://download.xs4all.nl/pub/debian-security/ is a mirror, too. Err

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:17:31PM +0100, Andrea Frigido wrote: Alle 19:07, lunedì 18 novembre 2002, Lionel Elie Mamane ha scritto: On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: kernel-patch-freeswan-ext UNSTABLE package or kernel-patch-freeswan STABLE package? This package

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:32:56PM +0100, Andrea Frigido wrote: OK, now I install kernel-patch-freeswan-ext package, thanks :) It is compatible with kernel 2.4.18 or I need to use the kernel 2.4.19? I don't know, but I guess it is. If you find out, let us know. -- Lionel

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: Alle 13:02, giovedì 14 novembre 2002, Lionel Elie Mamane ha scritto: On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: While using a free OS is always better, you can use any other IPSEC implementation, they should

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:17:31PM +0100, Andrea Frigido wrote: Alle 19:07, lunedì 18 novembre 2002, Lionel Elie Mamane ha scritto: On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: kernel-patch-freeswan-ext UNSTABLE package or kernel-patch-freeswan STABLE package? This package

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:32:56PM +0100, Andrea Frigido wrote: OK, now I install kernel-patch-freeswan-ext package, thanks :) It is compatible with kernel 2.4.18 or I need to use the kernel 2.4.19? I don't know, but I guess it is. If you find out, let us know. -- Lionel pgp9Z6KhYHk10.pgp

Re: VPN question

2002-11-14 Thread Lionel Elie Mamane
On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: I must create a VPN between an external company and a server behind my firewall. Company---its_routerInternet---my_firewall-server * How to implement this VPN??? I would use IPSEC, but there are other solutions:

Re: VPN question

2002-11-14 Thread Lionel Elie Mamane
On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: I must create a VPN between an external company and a server behind my firewall. Company---its_routerInternet---my_firewall-server * How to implement this VPN??? I would use IPSEC, but there are other solutions:

Re: Latest libpcap tcpdump sources from tcpdump.org contain a trojan

2002-11-13 Thread Lionel Elie Mamane
On Wed, Nov 13, 2002 at 08:15:58PM +0100, Lupe Christoph wrote: Is Debian affected? I checked a few hours ago, and it was not, at least the mirror I'm using. -- Lionel msg07715/pgp0.pgp Description: PGP signature

Re: Latest libpcap tcpdump sources from tcpdump.org contain a trojan

2002-11-13 Thread Lionel Elie Mamane
On Wed, Nov 13, 2002 at 08:15:58PM +0100, Lupe Christoph wrote: Is Debian affected? I checked a few hours ago, and it was not, at least the mirror I'm using. -- Lionel pgpRBCwvNmdOx.pgp Description: PGP signature

Re: Multiple SSL Virtualhosts on Apache 1.3

2002-11-05 Thread Lionel Elie Mamane
On Tue, Nov 05, 2002 at 11:00:46AM +0100, DEFFONTAINES Vincent wrote: I managed to create several Virtualhosts on a apache-ssl (1.3) server (same IP, same port, several names). The trick is to use the same Certificate for every Virtualhost, which will of course generate a warning on

Re: Multiple SSL Virtualhosts on Apache 1.3

2002-11-05 Thread Lionel Elie Mamane
On Tue, Nov 05, 2002 at 11:00:46AM +0100, DEFFONTAINES Vincent wrote: I managed to create several Virtualhosts on a apache-ssl (1.3) server (same IP, same port, several names). The trick is to use the same Certificate for every Virtualhost, which will of course generate a warning on

Re: export problems on security updates?

2002-10-09 Thread Lionel Elie Mamane
On Wed, Oct 09, 2002 at 10:21:31PM +0200, Alberto Cortés wrote: deb http://security.debian.org/ woody/updates main contrib non-free Since I am not living in the US, and some security updates deals with cryptographic software, I understand that it will be illegal for me downloading these

Re: export problems on security updates?

2002-10-09 Thread Lionel Elie Mamane
On Wed, Oct 09, 2002 at 10:21:31PM +0200, Alberto Cortés wrote: deb http://security.debian.org/ woody/updates main contrib non-free Since I am not living in the US, and some security updates deals with cryptographic software, I understand that it will be illegal for me downloading these

Re: encrypting/decrypting partitions on the fly?

2002-08-08 Thread Lionel Elie Mamane
On Thu, Aug 08, 2002 at 08:47:27AM +0200, [EMAIL PROTECTED] wrote: Hello! Anybody know of a tool like PGPDisk for Linux? Google for Linux encrypted loopback, should give results. -- Lionel pgpg8CvXAWNIt.pgp Description: PGP signature

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: * May 1 11:48:10 foobox in.qpopper[11047]: connect from foo.bar.org * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown command: capa. Well, (-ERR Unknown command: capa) sounds quite strange, anyone has idea what

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: * May 1 11:48:10 foobox in.qpopper[11047]: connect from foo.bar.org * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown command: capa. Well, (-ERR Unknown command: capa) sounds quite strange, anyone has idea what this

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 12:21:20PM +0200, eim wrote: On Wed, 2002-05-01 at 12:10, Lionel Elie Mamane wrote: On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown command: capa. Well, (-ERR Unknown command: capa) sounds

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Lionel Elie Mamane
On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: What's the best way to figure out the admin for a subnet from a machine's IP? whois the_ip_adress -- Lionel Mamane msg06057/pgp0.pgp Description: PGP signature