Re: Debian Security Support in Place

2005-07-08 Thread Phillip Hofmeister
It is my favorite distro, and I hope this isn't seen as a flame. But, two Debian releases in one year? That's kind of funny . -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: safety of encrypted filesystems

2005-06-23 Thread Phillip Hofmeister
HICH* file changed. > > he has only one file and this was unaltered, the question is why. Perhaps the block that was changed was a free block? -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: safety of encrypted filesystems

2005-06-22 Thread Phillip Hofmeister
nt it, change your block, remount it, and run a tripwire check. This should identify *WHICH* file changed. -- Phillip Hofmeister pgpFA0uNAsSYs.pgp Description: PGP signature

Re: Crypto File System-Problems Creating One

2005-06-08 Thread Phillip Hofmeister
ssword: > ioctl: LOOP_SET_STATUS: Invalid argument You're trying to mount a block device over a loopback? This may present a problemI'm not sure. -- Phillip Hofmeister pgpDHAZsI8iop.pgp Description: PGP signature

Re: [sec] Re: failed root login attempts

2004-09-29 Thread Phillip Hofmeister
with weak root passwords. Best practices suggest: PermitRootLogin no Then again, the people who have weak root passwords are not ones to follow best practices. -- Phillip Hofmeister pgped9HHVcQPF.pgp Description: PGP signature

Re: telnetd vulnerability from BUGTRAQ

2004-09-28 Thread Phillip Hofmeister
host is not known (public/server key) then SSH is every bit as easy to eaves drop as FTP. There are many tools that will easily attempt a man-in-the-middle SSH attack. -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: telnetd vulnerability from BUGTRAQ

2004-09-28 Thread Phillip Hofmeister
e from an IBM MVS Environment). -- Phillip Hofmeister pgp22WChho3mU.pgp Description: PGP signature

Re: Rebuilding packages on *all* architectures

2004-09-07 Thread Phillip Hofmeister
he hands of the intruder even after he has delivered the bomb. -- Phillip Hofmeister pgpvqSkqSutVT.pgp Description: PGP signature

Re: MD5 collisions found - alternative?

2004-08-25 Thread Phillip Hofmeister
ch space in half right there. I agree. There is value in maintaining two completely different data points by hashing the item with two functions though (but not XORing the result together). For example: EVEN IF hash1(x) == hash1(y), it is HIGHLY unlikely hash2(x) == hash2(y). Keeping a r

Re: MD5 collisions found - alternative?

2004-08-24 Thread Phillip Hofmeister
postulate correctly: If I, the user, encrypt a message with algorithm X and the cipher text is intercepted by the attacker. The attacker can make his chances of brute forcing the text BETTER by encrypting my cipher text with algorithm Y. This simply does not hold up. -- Phillip Hofmeister -- To

Re: newbie iptables question

2004-08-13 Thread Phillip Hofmeister
ter because you (or your IPTABLES Interface program) did not log this. It is for this reason I run my own IPTABLES script and edit it by hand (pretty masochistichuh?). My guess is this packet was related to an automated attack (worm). Hope this helps, -- Phillip Hofmeister -- To UNSUBS

Re: pgp in Debian: obsolete?

2004-08-12 Thread Phillip Hofmeister
On Thu, 12 Aug 2004 at 03:35:29AM -0400, Matthias Urlichs wrote: > Hi, Phillip Hofmeister wrote: > > > If you wanted to > > make a second version of GPG and place it in non-free, that would likely > > be an acceptable option. > > > You don't need to make a

Re: pgp in Debian: obsolete?

2004-08-11 Thread Phillip Hofmeister
llowed and > any further redistribution of the source code in any modified form is > expressly prohibited. Which is a clear violation of the social contract. If you wanted to make a second version of GPG and place it in non-free, that would likely be an acceptable option. -- Ph

Re: mod_ssl 2.8.19 for Apache 1.3.31

2004-07-19 Thread Phillip Hofmeister
stable/updates main non-free contrib HTH -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: A question about : [Fwd: JULY 6th Lead Training 3 tips for working leads]

2004-07-08 Thread Phillip Hofmeister
here is a French version as well... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: A question about : [Fwd: JULY 6th Lead Training 3 tips for working leads]

2004-07-07 Thread Phillip Hofmeister
, try not to do the spammers a favor by posting their original message back to the list. HTH, -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subjec

Re: Why not push to stable?

2004-06-26 Thread Phillip Hofmeister
or on them. People use Debian (partially) because they like the wide range of control it offers them. If you take away some of that control then it diminishes the reason why some ppl prefer Debian. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~p

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
anging my head on it and > see what I can come up with. You can visit http://www.spamarchive.org/ and download other people's spam to train your filters . Warning: Just throwing a bunch of spam at your filters w/o giving it any ham will likely result in falsely high bogosity scores (false-rejects) since there

Re: Unusual spam recently - hummm - postprocess

2004-06-03 Thread Phillip Hofmeister
> > > I get the concept of vaporware. Seen a lot of it over the years. > > Sorry to hear about your sysadmin shortage, then. > > -- > Cheers, > Rick Moen Bu^so^stopu min per kulero. > [EMAIL PROTECTED] > > > -- Phil

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
anging my head on it and > see what I can come up with. You can visit http://www.spamarchive.org/ and download other people's spam to train your filters . Warning: Just throwing a bunch of spam at your filters w/o giving it any ham will likely result in falsely high bogosity scores (false-rejects) since there

Re: Unusual spam recently - hummm - postprocess

2004-06-03 Thread Phillip Hofmeister
> > > I get the concept of vaporware. Seen a lot of it over the years. > > Sorry to hear about your sysadmin shortage, then. > > -- > Cheers, > Rick Moen Bu^so^stopu min per kulero. > [EMAIL PROTECTED] > > > -- Phil

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
s. I have found it very reliable (for me). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
s. I have found it very reliable (for me). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
, just bogofilter. Here is my relevant procmailrc snippet... :0 f | bogofilter -p -u -l :0 c * ^X-Bogosity: Yes Mail/Junk :0: * ^X-Bogosity: Unsure Mail/Unsure Hope this helps! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhof

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
ect to the normal SMTP Server for the zionlth.org domain. Implementing your suggestion wide spread would cause my emails (and all emails from people in my situation) to be rejected just because their ISP has their head on backwards and thinks blocking port 25 outbound will reduce spam abuse. -- P

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
, just bogofilter. Here is my relevant procmailrc snippet... :0 f | bogofilter -p -u -l :0 c * ^X-Bogosity: Yes Mail/Junk :0: * ^X-Bogosity: Unsure Mail/Unsure Hope this helps! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhof

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
ect to the normal SMTP Server for the zionlth.org domain. Implementing your suggestion wide spread would cause my emails (and all emails from people in my situation) to be rejected just because their ISP has their head on backwards and thinks blocking port 25 outbound will reduce spam abuse. -- P

Re: grsecurity2 and per-user tmp dirs

2004-05-22 Thread Phillip Hofmeister
als with FIFOs. This is done so someone does not create a FIFO with the name of a tmp file they are predicting you will open and then you write all your information to THEIR FIFO. I hope this helps. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: grsecurity2 and per-user tmp dirs

2004-05-22 Thread Phillip Hofmeister
als with FIFOs. This is done so someone does not create a FIFO with the name of a tmp file they are predicting you will open and then you write all your information to THEIR FIFO. I hope this helps. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: debian and viruses ...

2004-05-19 Thread Phillip Hofmeister
) of > wirus signatures, rules, etc ? A few tools: Spam: bogofilter spamassassin Virus: amavisd-new and clamav (or your favorite supported antivirus software, clam just happens to be O/S and free...) HTH, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wge

Re: debian and viruses ...

2004-05-19 Thread Phillip Hofmeister
) of > wirus signatures, rules, etc ? A few tools: Spam: bogofilter spamassassin Virus: amavisd-new and clamav (or your favorite supported antivirus software, clam just happens to be O/S and free...) HTH, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wge

Re: Woody Backport of tripwire

2004-04-23 Thread Phillip Hofmeister
On Fri, 23 Apr 2004 at 01:19:13PM -0400, Giacomo Mulas wrote: > On Fri, 23 Apr 2004, Phillip Hofmeister wrote: > > > I did not realize 3.0+ was needed. The build dependencies did not > > specify that. I might file a bug against tripwire for that build > > dependency.

Re: Woody Backport of tripwire

2004-04-23 Thread Phillip Hofmeister
On Fri, 23 Apr 2004 at 01:19:13PM -0400, Giacomo Mulas wrote: > On Fri, 23 Apr 2004, Phillip Hofmeister wrote: > > > I did not realize 3.0+ was needed. The build dependencies did not > > specify that. I might file a bug against tripwire for that build > > dependency.

Re: Woody Backport of tripwire

2004-04-23 Thread Phillip Hofmeister
3.0+ was needed. The build dependencies did not specify that. I might file a bug against tripwire for that build dependency. Thanks. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Woody Backport of tripwire

2004-04-23 Thread Phillip Hofmeister
3.0+ was needed. The build dependencies did not specify that. I might file a bug against tripwire for that build dependency. Thanks. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email

Woody Backport of tripwire

2004-04-22 Thread Phillip Hofmeister
Can anyone refer me to a woody backport of tripwire (or a version such as 2.3.1.2+)? I know it is non-free, I like it anyhow. Any help would be appreciated. Thanks, -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg

Re: Major TCP Vulnerability

2004-04-22 Thread Phillip Hofmeister
rograms from startup scripts? Probably not. Yet another great reason to apply the GRSecurity Kernel patch, randomized source ports. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE-

Woody Backport of tripwire

2004-04-22 Thread Phillip Hofmeister
Can anyone refer me to a woody backport of tripwire (or a version such as 2.3.1.2+)? I know it is non-free, I like it anyhow. Any help would be appreciated. Thanks, -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg

Re: Major TCP Vulnerability

2004-04-22 Thread Phillip Hofmeister
rograms from startup scripts? Probably not. Yet another great reason to apply the GRSecurity Kernel patch, randomized source ports. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE-

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
again vulnerable to intruders on the LAN. IPSec will get you across the "untrusted" Internet though (unless someone pulls the plug at OSI layer 1 or 2...) Hope this answers your question. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
again vulnerable to intruders on the LAN. IPSec will get you across the "untrusted" Internet though (unless someone pulls the plug at OSI layer 1 or 2...) Hope this answers your question. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zio

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
them the information. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import - End forwarded message - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
them the information. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import - End forwarded message - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/k

Re: makedev: /dev/tty([0-9])* should not have 666 permissions

2004-04-19 Thread Phillip Hofmeister
d packages, asking them to > > check the permissions on these devices on upgrade, and correct if > > necessary. Seems trivial enough to do. A patch would probably not > > hurt. > > -- System Information > Debian Release: 3.0 > Architecture: i386 > Kernel: Linux

Re: Eterm & others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Phillip Hofmeister
> | ,''`. Stephen Gran | > | : :' : [EMAIL PROTECTED] | > | `. `' Debian user, admin, and developer | > |`-

Re: makedev: /dev/tty([0-9])* should not have 666 permissions

2004-04-19 Thread Phillip Hofmeister
> > check the permissions on these devices on upgrade, and correct if > > necessary. Seems trivial enough to do. A patch would probably not > > hurt. > > -- System Information > Debian Release: 3.0 > Architecture: i386 > Kernel: Linux kontryhel 2.4.26-jan #3 SMP M

Re: Eterm & others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Phillip Hofmeister
--- > | ,''`. Stephen Gran | > | : :' : [EMAIL PROTECTED] | > | `. `' Debian user, admin, and developer | > |`-

Re: suid

2004-04-17 Thread Phillip Hofmeister
opies the file into the crontab directory and notifies the daemon of the new crontab. I think the current system works well... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: suid

2004-04-17 Thread Phillip Hofmeister
opies the file into the crontab directory and notifies the daemon of the new crontab. I think the current system works well... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
another notification mechanism is used. However, DoS is still possible (and really happens - in form of daemon crashes), because when it is not possible to allocatre a "struct sigqueue" object, kernel behaviour in signal-passing changes, causing random hangs and segfaults in different progr

Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
suggestions. If you contribute please be sure to CC the Bug report. At question here is where should this bug be directed? The kernel pseudo package or glibc (linuxthreads). Credits: Thanks to Matt Zimmerman and Herbert Xu for contributing already. Thanks, - -- Phillip Hofmeister PGP/GPG Key: http

Re: Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
notification mechanism is used. However, DoS is still possible (and really happens - in form of daemon crashes), because when it is not possible to allocatre a "struct sigqueue" object, kernel behaviour in signal-passing changes, causing random hangs and segfaults in different programs.

Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
suggestions. If you contribute please be sure to CC the Bug report. At question here is where should this bug be directed? The kernel pseudo package or glibc (linuxthreads). Credits: Thanks to Matt Zimmerman and Herbert Xu for contributing already. Thanks, - -- Phillip Hofmeister PGP/GPG Key: http

Re: [SECURITY] [DSA 479-1] New Linux 2.4.18 packages fix local root exploit (source+alpha+i386+powerpc)

2004-04-14 Thread Phillip Hofmeister
are a little bit scary, as > far as there are no patch- days for debian ;). So I'd like to know, which of > them might have been fixed earlier. > It's just my interest to track the linux-sec-efforts from my point of view. > > Keep smiling > yanosz > -- Phillip Hofme

Re: [SECURITY] [DSA 479-1] New Linux 2.4.18 packages fix local root exploit (source+alpha+i386+powerpc)

2004-04-14 Thread Phillip Hofmeister
are a little bit scary, as > far as there are no patch- days for debian ;). So I'd like to know, which of > them might have been fixed earlier. > It's just my interest to track the linux-sec-efforts from my point of view. > > Keep smiling > yanosz > -- Phillip Hofme

Re: Does apt check gpg signatures before install

2004-03-29 Thread Phillip Hofmeister
On Mon, 29 Mar 2004 at 01:39:00PM -0500, Florian Weimer wrote: > apt 0.6 (available in experimental) checks the signatures on the Release > files. Is there a backport of this apt to stable? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionl

Re: Does apt check gpg signatures before install

2004-03-29 Thread Phillip Hofmeister
On Mon, 29 Mar 2004 at 01:39:00PM -0500, Florian Weimer wrote: > apt 0.6 (available in experimental) checks the signatures on the Release > files. Is there a backport of this apt to stable? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionl

Re: kernel 2.4.22 patch

2004-03-19 Thread Phillip Hofmeister
pgpXhKEcgiYVU.pgp Description: PGP message

Re: kernel 2.4.22 patch

2004-03-19 Thread Phillip Hofmeister
pgp0.pgp Description: PGP message

Re: mozilla - the forgotten package?

2004-03-11 Thread Phillip Hofmeister
e, leaving the current on in place for compatibility sakes. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: mozilla - the forgotten package?

2004-03-11 Thread Phillip Hofmeister
e, leaving the current on in place for compatibility sakes. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
the SYSLOG Kern Facility syslog(3). - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFALoIAS3Jybf3L5MQRAqHEAJ9ZmPEGrMPU9OWSKIi2LDJ/qjnzHQCgg

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
s a week rotation period. In a week the log usually becomes around 90 MB (This is just a log saying what run, not what files were opened). Good luck! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
the SYSLOG Kern Facility syslog(3). - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFALoIAS3Jybf3L5MQRAqHEAJ9ZmPEGrMPU9OWSKIi2LDJ/qjnzHQCgg

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
s a week rotation period. In a week the log usually becomes around 90 MB (This is just a log saying what run, not what files were opened). Good luck! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key

Re: Which Distro?

2004-02-06 Thread Phillip Hofmeister
opment environment. I need > the entire nuts & bolts usefuls of Debian. nybody here to help me? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Which Distro?

2004-02-06 Thread Phillip Hofmeister
opment environment. I need the entire nuts & bolts usefuls > of Debian. nybody here to help me? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
r maintained by an ISP. No, I am not on the same subnet as 63.165.219.29. Take care, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PG

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
r maintained by an ISP. No, I am not on the same subnet as 63.165.219.29. Take care, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PG

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
1. Unless they are on your subnet and they can send an ARP request for the IP and your machine responds. The statement above assumes the attacker/researcher is not on your subnet. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
ABLES -A ETH0-IN -p tcp --dport 113 -j REJECT --reject-with tcp-reset -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
1. Unless they are on your subnet and they can send an ARP request for the IP and your machine responds. The statement above assumes the attacker/researcher is not on your subnet. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
ABLES -A ETH0-IN -p tcp --dport 113 -j REJECT --reject-with tcp-reset -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe&q

Re: Web based password changer

2004-01-23 Thread Phillip Hofmeister
RSecurity patch. It hides processes not belonging to you (unless you are root). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- Excuse #194: Too much radiation coming from the soil. pgpIGx3K0Bgik.pgp De

Re: Web based password changer

2004-01-23 Thread Phillip Hofmeister
RSecurity patch. It hides processes not belonging to you (unless you are root). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- Excuse #194: Too much radiation coming from the soil. pgp0.pgp Descrip

Re: suspicious smbd connections

2003-12-23 Thread Phillip Hofmeister
t; with new IP-address. What are these connections? Is somebody trying to > scan me or what is the reason for these messages? > Thank you in advance! > > > -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc

Re: suspicious smbd connections

2003-12-23 Thread Phillip Hofmeister
t; with new IP-address. What are these connections? Is somebody trying to > scan me or what is the reason for these messages? > Thank you in advance! > > > -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc

Re: exim virus scanning and spam scanning

2003-12-21 Thread Phillip Hofmeister
not related to amavis. Amavis is responsible for parsing the MIME and saving them to files in /tmp. Clamscan is then used to scan the files placed in /tmp by amavis. Clamscan has come a long way. They now have over 10,000 definitions. However, you can use commercial av's (like Sophis) w

Re: exim virus scanning and spam scanning

2003-12-21 Thread Phillip Hofmeister
not related to amavis. Amavis is responsible for parsing the MIME and saving them to files in /tmp. Clamscan is then used to scan the files placed in /tmp by amavis. Clamscan has come a long way. They now have over 10,000 definitions. However, you can use commercial av's (like Sophis) w

Re: secure file permissions

2003-12-08 Thread Phillip Hofmeister
m. I fail to see how this would make things any better on your system. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #148: endothermal recalibration -BEGIN PGP SIGNATURE- Version: GnuPG

Re: secure file permissions

2003-12-08 Thread Phillip Hofmeister
m. I fail to see how this would make things any better on your system. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #148: endothermal recalibration -BEGIN PGP SIGNATURE- Version: GnuPG

Re: When will kernel-image-2.4.23 be available ?

2003-12-03 Thread Phillip Hofmeister
o testing (sarge). > > Except for (1), this has been, almost always, the path for security > upgrades to enter testing. > > > -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #198: Interference from lunar radiation

Re: When will kernel-image-2.4.23 be available ?

2003-12-03 Thread Phillip Hofmeister
o testing (sarge). > > Except for (1), this has been, almost always, the path for security > upgrades to enter testing. > > > -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #198:

Re: apache+ssl+tomcat+jk+php

2003-11-12 Thread Phillip Hofmeister
ble to do it. Why ??? > > (it works without tomcat , anyway) ! > Can anybody help ? > regards > > > - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #194: Too mu

Re: apache+ssl+tomcat+jk+php

2003-11-12 Thread Phillip Hofmeister
ble to do it. Why ??? > > (it works without tomcat , anyway) ! > Can anybody help ? > regards > > > - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #194: Too mu

Re: passwd character limitations

2003-11-01 Thread Phillip Hofmeister
..and all you will get out is hexadecimal digits. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #21: Improperly oriented keyboard -BEGIN PGP SIGNATURE- V

Re: apache security issue (with upstream new release)

2003-11-01 Thread Phillip Hofmeister
then what kind of assurance do you really have? - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #247: Your process is not ISO 9000 compliant -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.2 (

Re: passwd character limitations

2003-11-01 Thread Phillip Hofmeister
..and all you will get out is hexadecimal digits. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #21: Improperly oriented keyboard -BEGIN PGP SIGNATURE- V

Re: apache security issue (with upstream new release)

2003-11-01 Thread Phillip Hofmeister
then what kind of assurance do you really have? - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #247: Your process is not ISO 9000 compliant -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.2 (

Re: apache security issue (with upstream new release)

2003-10-30 Thread Phillip Hofmeister
agree fully with it...but I do understand it... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #227: You must've hit the wrong anykey. -BEGIN PGP SIGNATURE- Version

Re: apache security issue (with upstream new release)

2003-10-30 Thread Phillip Hofmeister
agree fully with it...but I do understand it... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #227: You must've hit the wrong anykey. -BEGIN PGP SIGNATURE- Version

Re: chkrootkit reporting processes hidden

2003-10-29 Thread Phillip Hofmeister
essage. Now, I am not saying there is *NOT* a security problem with your machine. AFA the PROMISC mode one the NICs...are you running snort or something to the like? If so, these NIDs (Network Intrusion Detectors) place cards in PROMISC mode to watch traffic. Just a few things to be aware of...

Re: chkrootkit reporting processes hidden

2003-10-29 Thread Phillip Hofmeister
essage. Now, I am not saying there is *NOT* a security problem with your machine. AFA the PROMISC mode one the NICs...are you running snort or something to the like? If so, these NIDs (Network Intrusion Detectors) place cards in PROMISC mode to watch traffic. Just a few things to be aware of...

Apache: Apears to be vulnerable to CAN-2003-0542 (WAS: apache security issue (with upstream new release))

2003-10-29 Thread Phillip Hofmeister
>issue to BTS, maintainer said "Kindly don't submit "new version" >bugs with in about 10 minutes of the release. It's childish and >unhelpful." >http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=200593&archive=yes > >so I don't wa

Apache: Apears to be vulnerable to CAN-2003-0542 (WAS: apache security issue (with upstream new release))

2003-10-29 Thread Phillip Hofmeister
>issue to BTS, maintainer said "Kindly don't submit "new version" >bugs with in about 10 minutes of the release. It's childish and >unhelpful." >http://bugs.debian.org/cgi-bin/bugreport.cgi?bug=200593&archive=yes > >so I don't want to post it to BTS... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #113: Daemons loose in system.

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
On Thu, 09 Oct 2003 at 01:58:40PM -0400, Brandon High wrote: > On Thu, Oct 09, 2003 at 08:06:46AM -0400, Phillip Hofmeister wrote: > > If I r00t your system I'll have access to remount it rw anyhow. Any > > "hacker" who doesn't know how to remount a file syst

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
On Thu, 09 Oct 2003 at 01:58:40PM -0400, Brandon High wrote: > On Thu, Oct 09, 2003 at 08:06:46AM -0400, Phillip Hofmeister wrote: > > If I r00t your system I'll have access to remount it rw anyhow. Any > > "hacker" who doesn't know how to remount a file syst

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
ne down for 3 seconds until they type: cat /proc/mounts (Oh, it's ro!) and then types mount -o remount/rw /usr Just my $.02... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #34: Heavy gr

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
ne down for 3 seconds until they type: cat /proc/mounts (Oh, it's ro!) and then types mount -o remount/rw /usr Just my $.02... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #34: Heavy gr

Re: services installed and running "out of the box"

2003-09-28 Thread Phillip Hofmeister
every system you install. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #139: NOTICE: alloc: /dev/null: filesystem full -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.2

  1   2   3   4   5   >