Re: DSA-311-1 New kernel packages - Bug is not fixed!

2003-06-09 Thread Mike Dresser
On Mon, 9 Jun 2003, Helmar wrote: > I just upgraded my kernel image from 2.4.18-k6 to 2.4.18-1-k6 and i > cannot confirm that the above bug has been fixed. The simple exploit (i > think it has been from bugtraq) is still working fine, giving every > local user easily root privileges. > take the s

Re: DSA-311-1 New kernel packages - Bug is not fixed!

2003-06-09 Thread Mike Dresser
On Mon, 9 Jun 2003, Helmar wrote: > I just upgraded my kernel image from 2.4.18-k6 to 2.4.18-1-k6 and i > cannot confirm that the above bug has been fixed. The simple exploit (i > think it has been from bugtraq) is still working fine, giving every > local user easily root privileges. > take the s

Re: promiscuous mode

2003-05-23 Thread Mike Dresser
On Fri, 23 May 2003, Ian Goodall wrote: > I have premoved promiscuous mode from my card. When checking ifconfig (eth0) > I am still getting all the network traffic flowing through my computer or at > least a lot of it. The system is sitting idle and I can see the traffic > going up a few meg a min

Re: Apt-get only security patches

2003-05-07 Thread Mike Dresser
On Wed, 7 May 2003, Rudolph van Graan wrote: > The following packages will be upgraded > kdewallpapers mime-support > 2 packages upgraded, 0 newly installed, 0 to remove and 0 not upgraded. > Need to get 0B/1030kB of archives. After unpacking 105kB will be freed. > Do you want to continue? [Y/n

Re: Can't fmirror security.debian.org

2003-05-05 Thread Mike Dresser
On Mon, 5 May 2003 [EMAIL PROTECTED] wrote: > $ rsync -avz security.debian.org::debian-security . > rsync: read error: Connection reset by peer > rsync error: error in rsync protocol data stream (code 12) at io.c(162) Works fine here, you might want to check your firewall logs to see if you're be

Re: securing pop3

2003-02-10 Thread Mike Dresser
On Mon, 10 Feb 2003, vincenzo wrote: > You can simply add them in the /etc/passwd file without giving any shell > at all, like that: > leon:x:1050:100::/home/leon: > That lets you in just fine unfortunately. mdresser:x:1000:1000:Mike Dresser,,,:/home/mdresser: x:~# login x log

Re: securing pop3

2003-02-10 Thread Mike Dresser
On Mon, 10 Feb 2003, vincenzo wrote: > You can simply add them in the /etc/passwd file without giving any shell > at all, like that: > leon:x:1050:100::/home/leon: > That lets you in just fine unfortunately. mdresser:x:1000:1000:Mike Dresser,,,:/home/mdresser: x:~# login x log

Re: [security-unixtech] Re: question about SSH / IPTABLES

2003-01-23 Thread Mike Dresser
On 23 Jan 2003, Stanislas Rusinsky wrote: > in sshd_conf : > > AllowTcpForwarding no : > Specifies whether TCP forwarding is permitted. The default > is > ``yes''. Note that disabling TCP forwarding does not improve security > unless users are also denied shell access, as they

Re: [security-unixtech] Re: question about SSH / IPTABLES

2003-01-23 Thread Mike Dresser
On 23 Jan 2003, Stanislas Rusinsky wrote: > in sshd_conf : > > AllowTcpForwarding no : > Specifies whether TCP forwarding is permitted. The default is > ``yes''. Note that disabling TCP forwarding does not improve security > unless users are also denied shell access, as they ca

Re: SSH

2002-12-17 Thread Mike Dresser
On Mon, 16 Dec 2002, Phillip Hofmeister wrote: > Hi all, > > I am sure you have seen the SSH CERT. Are we vulnerable? If so is > there a time line for an update? > > Thanks, The vendor response in the CERT advisory said OpenSSH was not vulnerable.

Re: SSH

2002-12-17 Thread Mike Dresser
On Mon, 16 Dec 2002, Phillip Hofmeister wrote: > Hi all, > > I am sure you have seen the SSH CERT. Are we vulnerable? If so is > there a time line for an update? > > Thanks, The vendor response in the CERT advisory said OpenSSH was not vulnerable. -- To UNSUBSCRIBE, email to [EMAIL PROTECTE

Bind issues

2002-11-13 Thread Mike Dresser
Any word from the security team on what's going on with potato's bind? Mike

Bind issues

2002-11-13 Thread Mike Dresser
Any word from the security team on what's going on with potato's bind? Mike -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: http://www.securiteam.com/unixfocus/5QP020K350.html

2002-08-08 Thread Mike Dresser
On Thu, 8 Aug 2002, Roger Ward wrote: > Which bug? this url does not work oops. http://www.securiteam.com/unixfocus/5QP020K35O.html It's the DNS parsing code bug.

http://www.securiteam.com/unixfocus/5QP020K350.html

2002-08-08 Thread Mike Dresser
Did the above mentioned hole ever get fixed in potato bitchx? Seems that it should have been, but the exploit is well over a year old, and I see nothing in the changelog. Mike

Re: sources.list for potato

2002-06-20 Thread Mike Dresser
> For a truly stable Debian system, drop > > deb http://http.us.debian.org/debian dists/potato-proposed-updates/ > > (wait for official release updates) and then just s/potato/stable/g. > Note that non-US is being phased out. I've seen way too many packages that take too long to get into stable

sources.list for potato

2002-06-20 Thread Mike Dresser
Hate to beat a dead horse, but deb http://http.us.debian.org/debian potato main contrib non-free deb http://http.us.debian.org/debian dists/potato-proposed-updates/ deb http://non-us.debian.org/debian-non-US potato/non-US main contrib non-free deb http://non-us.debian.org/debian-security potato/

Re: Questions on Sysloging with a DMZ

2002-06-14 Thread Mike Dresser
> logging console > > should get what you need on a cisco. Might have to set that serial port > to no password, which brings up an additional home if physical security > is a concern. > > --Rich What about the cisco that's 35 miles away? I'm thinking with what these cisco's do, and actually log,

Questions on Sysloging with a DMZ

2002-06-14 Thread Mike Dresser
I've done some looking around on the web, and haven't really found an answer to the following question. How do you securely handle syslogging when you have servers in the DMZ, and then the servers that are inside on the internal network? Seems that the fundamental rule is never allow internal lan

Re: passwords and crypt?

2001-11-29 Thread Mike Dresser
> Interesting. I'm running Debian 2.2r2 (dist-upgraded to testing). I > selected MD5 for my passwords during installation. However, it seems > that it has defaulted my passwords to 8 characters too: > > >From /etc/pam.d/passwd (login is the same) > > password required pam_unix.so nullok obs

Re: passwords and crypt?

2001-11-29 Thread Mike Dresser
> Interesting. I'm running Debian 2.2r2 (dist-upgraded to testing). I > selected MD5 for my passwords during installation. However, it seems > that it has defaulted my passwords to 8 characters too: > > >From /etc/pam.d/passwd (login is the same) > > password required pam_unix.so nullok ob

Re: passwords and crypt?

2001-11-29 Thread Mike Dresser
On Fri, 30 Nov 2001, Roger Keays wrote: > > Hi all, > > I'm not sure if this is common knowledge or not, but I have just noticed > the effects of having the first two letters of your password the same as > the first two in your login name... You can use any extension of your > password!! > > e.g

Re: passwords and crypt?

2001-11-29 Thread Mike Dresser
On Fri, 30 Nov 2001, Roger Keays wrote: > > Hi all, > > I'm not sure if this is common knowledge or not, but I have just noticed > the effects of having the first two letters of your password the same as > the first two in your login name... You can use any extension of your > password!! > > e.

Re: Yeh

2001-08-03 Thread Mike Dresser
Robert Davidson Security wrote: > On Fri, Aug 03, 2001 at 03:50:23AM +1000, Ian Miller wrote: > > I know this may not be the place for it... but its a real laugh. > > > > http://www.linuks.mine.nu/debian/ > > Yep, it's not the place but it's a great site! > > I love the porn.conf file... links act

Re: apt and other sources.

2001-07-17 Thread Mike Dresser
es/ Over the years, this is what I seem to have accumulated. Any comments/suggestions? The proposed-updates, was because of a package not making it into security.d.o due to whatever reason it was at the time. Mike Dresser

Re: apt and other sources.

2001-07-17 Thread Mike Dresser
Over the years, this is what I seem to have accumulated. Any comments/suggestions? The proposed-updates, was because of a package not making it into security.d.o due to whatever reason it was at the time. Mike Dresser -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "un

Re: [SECURITY] [DSA 045-1] ntp remote root exploit fixed

2001-04-05 Thread Mike Dresser
Peter Cordes wrote: > yeti:~$ grep 2064 /usr/share/nmap/nmap-services > distrib-net-losers 2064/tcp # A group of lamers working on a silly > closed-source client for solving the RSA cryptographic challenge. This is > the keyblock proxy port. > > It used to be s/losers/assholes/ and s/silly/stup

Re: [SECURITY] [DSA 045-1] ntp remote root exploit fixed

2001-04-05 Thread Mike Dresser
Peter Cordes wrote: > yeti:~$ grep 2064 /usr/share/nmap/nmap-services > distrib-net-losers 2064/tcp # A group of lamers working on a silly > closed-source client for solving the RSA cryptographic challenge. This is > the keyblock proxy port. > > It used to be s/losers/assholes/ and s/silly/stu

Re: Strange output from "last" command

2001-03-21 Thread Mike Dresser
"William R. Ward" wrote: > I've replaced the legit usernames and IP's with "xxx" but left them in > for context. I'm worried that the "date" entries are a consequence of > some hacker activity, but I have been unable to find any other > symptoms. I did a web search and did not find any mention o

Re: Strange output from "last" command

2001-03-21 Thread Mike Dresser
"William R. Ward" wrote: > I've replaced the legit usernames and IP's with "xxx" but left them in > for context. I'm worried that the "date" entries are a consequence of > some hacker activity, but I have been unable to find any other > symptoms. I did a web search and did not find any mention

Re: Allow FTP in, but not shell login

2001-03-13 Thread Mike Dresser
Mike Fedyk wrote: > If you try to su to a user with a shell set to /dev/null, what happens? > /bin/false just exits the su, even from root. su - username -s /bin/sh mike

Re: Allow FTP in, but not shell login

2001-03-13 Thread Mike Dresser
Mike Fedyk wrote: > If you try to su to a user with a shell set to /dev/null, what happens? > /bin/false just exits the su, even from root. su - username -s /bin/sh mike -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: how secure is mail and ftp and netscape/IE???

2001-02-22 Thread Mike Dresser
Somehow, I'm getting the impression you haven't taken this system offline, and properly either reinstall or definately fix what's wrong. That should be your first priority, if so. Steve Rudd wrote: > Hello! Steve here, > > Well I am one of the family now! My server is Debian 2.2r2. A benign hac

Re: how secure is mail and ftp and netscape/IE???

2001-02-21 Thread Mike Dresser
Somehow, I'm getting the impression you haven't taken this system offline, and properly either reinstall or definately fix what's wrong. That should be your first priority, if so. Steve Rudd wrote: > Hello! Steve here, > > Well I am one of the family now! My server is Debian 2.2r2. A benign hack

Re: SSH and RSA

2001-02-19 Thread Mike Dresser
You don't mention whether the previous admin is still with you, but if not, you'll want to remove his RSA keys from the server, or else you can change your root password all you want, and he'll still be able to connect, assuming he can get to the machine via your network/internet. Duane Powers wro

Re: SSH and RSA

2001-02-19 Thread Mike Dresser
You don't mention whether the previous admin is still with you, but if not, you'll want to remove his RSA keys from the server, or else you can change your root password all you want, and he'll still be able to connect, assuming he can get to the machine via your network/internet. Duane Powers wr

Re: The Next Yahoo

2001-02-06 Thread Mike Dresser
please." I don't think SPI would complain about multiple donations per advertisement. =) Mike Dresser

Re: The Next Yahoo

2001-02-06 Thread Mike Dresser
please." I don't think SPI would complain about multiple donations per advertisement. =) Mike Dresser -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]