Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-28 Thread nDiScReEt
On Saturday 25 May 2002 11:25 pm, Femme wrote: On Sat, 25 May 2002 20:50:16 -0700 James [EMAIL PROTECTED] wrote: Check your commonhttpd.conf file, (/etc/httpd/conf/ ) but usually the default allows you to follow symlinks (in the past) if not look for # Each directory to which Apache

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-28 Thread FemmeFatale
nDiScReEt wrote: Thx for all you guys' help! I hope to get this working soon...lord knows I've learned alot since I asked what I thought was a simple question. Heh, never underestimate the power of linux to make it complex fast :) Femme As far as the apache maintenance, that would

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread Bill Kenworthy
Mount your win32/ntfs(ro) partitions (where the files reside) and either serve from them or symlink into the path if required. BillK On Sun, 2002-05-26 at 08:11, Femme wrote: On Sat, 25 May 2002 19:43:23 -0300 WOOkY [EMAIL PROTECTED] wrote: I'm trying to make a ftp-like thing for ppl on

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread Jeferson Lopes Zacco
Femme wrote: *giggles* Hacks are cool. Thx mucho James. I'll try your idea /or ndiscreets. Not sure which yet will yield better results. As an aside, any chance someone can point me to a newbie-fied apache install/maintenance URL? I'm pretty useless with HTML/web stuff...having

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread FemmeFatale
Bill Kenworthy wrote: Mount your win32/ntfs(ro) partitions (where the files reside) and either serve from them or symlink into the path if required. BillK On Sun, 2002-05-26 at 08:11, Femme wrote: On Sat, 25 May 2002 19:43:23 -0300 WOOkY [EMAIL PROTECTED] wrote: I'm trying to

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread James
On Sat, 25 May 2002 22:25:10 -0600 Femme [EMAIL PROTECTED] wrote: On Sat, 25 May 2002 20:50:16 -0700 James [EMAIL PROTECTED] wrote: Check your commonhttpd.conf file, (/etc/httpd/conf/ ) but usually the default allows you to follow symlinks (in the past) if not look for # Each

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread FemmeFatale
Jeferson Lopes Zacco wrote: Femme wrote: *giggles* Hacks are cool. Thx mucho James. I'll try your idea /or ndiscreets. Not sure which yet will yield better results. As an aside, any chance someone can point me to a newbie-fied apache install/maintenance URL? I'm pretty

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread FemmeFatale
James wrote: On Sat, 25 May 2002 22:25:10 -0600 *giggles* Hacks are cool. Thx mucho James. I'll try your idea /or ndiscreets. Not sure which yet will yield better results. As an aside, any chance someone can point me to a newbie-fied apache install/maintenance URL? I'm pretty

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-26 Thread nDiScReEt
Guess you really didn't notice they both suggested the same thing (ops, include me and Civ also)? James gave you a nice tip that apache should be configured to actually follow symlinks, but if I remember it well that's the default behaviour. Wooky Almost, the other guys suggestion was

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread David Relson
At 10:04 PM 5/24/02, Femme wrote: Yes I'm seeing 1433 turn up alot along with some suspicious ports :( Don't know what to do about it I reconfigured Bastille intoa more paranoid mode, and since I've done that 20 mins ago, it seems to be holding up much more like the BrickWall its supposed

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread Femme
On Fri, 24 May 2002 22:59:13 -0700 James [EMAIL PROTECTED] wrote: Actually pretty easy. cd to /var/www/html move any index.xxx files to index.xxx.old then put the files you want to share in this directory. voila when people go to http://your.ip.number they get a list of files and can then

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread Hicham A.
Hi Femme! On Sat, 25 May 2002, Femme wrote: OK James you piqued my intellectual stupidity switch. Im going to try this idea (however hare-brained I think it is :), and let the list know I guess. Caveat: if i come screaming back here to the list with no hair left its all YOUR fault ;p

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread civileme
Femme wrote: On Fri, 24 May 2002 22:59:13 -0700 James [EMAIL PROTECTED] wrote: Actually pretty easy. cd to /var/www/html move any index.xxx files to index.xxx.old then put the files you want to share in this directory. voila when people go to http://your.ip.number they get a list of files and

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread WOOkY
-Mensagem Original- De: Hicham A. [EMAIL PROTECTED] Para: [EMAIL PROTECTED] Enviada em: sábado, 25 de maio de 2002 19:08 Assunto: Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site] I'm sorry I didn't quite follow what are you trying to do... you just want to access files from

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread Femme
On Sat, 25 May 2002 19:43:23 -0300 WOOkY [EMAIL PROTECTED] wrote: -Mensagem Original- De: Hicham A. [EMAIL PROTECTED] Para: [EMAIL PROTECTED] Enviada em: sábado, 25 de maio de 2002 19:08 Assunto: Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site] I'm sorry I didn't

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread WOOkY
Actually it was the same suggestion I gave... since he is a nicer guy than I am, he just told you how to do it as well. :^) Of course, I'd rather do it at the console, but that's the beauty of linux: freedom of choice. Good Luck. Wooky/Jeferson L. Zacco I'm sorry I didn't quite follow what are

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread James
Check your commonhttpd.conf file, (/etc/httpd/conf/ ) but usually the default allows you to follow symlinks (in the past) if not look for # Each directory to which Apache has access, can be configured with respect# to which services and features are allowed and/or disabled in that# directory

(fwd) Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread Hicham A.
I think that nDiScReEt wanted to send this mail here, so I forwarded it. - Forwarded message from nDiScReEt [EMAIL PROTECTED] - From: nDiScReEt [EMAIL PROTECTED] Subject: Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site] To: [EMAIL PROTECTED] Organization: Maximum Time

Re: (fwd) Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread Femme
On Sun, 26 May 2002 00:13:14 -0400 Hicham A. [EMAIL PROTECTED] wrote: I think that nDiScReEt wanted to send this mail here, so I forwarded it. Or you can symlink the directory. Let us say that the other partition that contains the mp3 is mounted on windows. You would link the mp3

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-25 Thread Femme
On Sat, 25 May 2002 20:50:16 -0700 James [EMAIL PROTECTED] wrote: Check your commonhttpd.conf file, (/etc/httpd/conf/ ) but usually the default allows you to follow symlinks (in the past) if not look for # Each directory to which Apache has access, can be configured with respect# to which

honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Pierre Fortin
On Thu, 23 May 2002 23:15:52 -0800 civileme [EMAIL PROTECTED] wrote: Load up the honeyport for Nimda and the shutdown script for codered and see what happens Civileme, Where can I find the tools you're referring to...? I have my own (http://pfortin.com/Linux/HoneyPort -- needs updating

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread FemmeFatale
Pierre Fortin wrote: On Thu, 23 May 2002 23:15:52 -0800 civileme [EMAIL PROTECTED] wrote: Load up the honeyport for Nimda and the shutdown script for codered and see what happens Civileme, Where can I find the tools you're referring to...? I have my own

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread J. Craig Woods
FemmeFatale wrote: BTW, fwiw I found most of these kids are trying to get to my NETBios * i do share a HDD with my g/f* and ssh/unix ports. Makes me wonder if it isn't someone on one of the lists..cause this started not long after i posted the info on the ftp. :\ *hopes i'm

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Brian
On Fri, 24 May 2002 18:48:41 -0600 Femme [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 19:19:47 -0500 J. Craig Woods [EMAIL PROTECTED] wrote: Femme, you need to talk to us. Am I the only one that feels your postings are somewhat cryptic. Are you being hit with an ddos type of

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread civileme
FemmeFatale wrote: Pierre Fortin wrote: On Thu, 23 May 2002 23:15:52 -0800 civileme [EMAIL PROTECTED] wrote: Load up the honeyport for Nimda and the shutdown script for codered and see what happens Civileme, Where can I find the tools you're referring to...? I have my own

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Femme
On Fri, 24 May 2002 18:51:02 -0700 Brian [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 18:48:41 -0600 Femme [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 19:19:47 -0500 J. Craig Woods [EMAIL PROTECTED] wrote: Femme, you need to talk to us. Am I the only one that feels your

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Femme
On Fri, 24 May 2002 17:53:02 -0800 civileme [EMAIL PROTECTED] wrote: FemmeFatale wrote: Pierre Fortin wrote: On Thu, 23 May 2002 23:15:52 -0800 civileme [EMAIL PROTECTED] wrote: Load up the honeyport for Nimda and the shutdown script for codered and see what happens Civileme,

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Brian
On Fri, 24 May 2002 20:04:45 -0600 Femme [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 18:51:02 -0700 Brian [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 18:48:41 -0600 Femme [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 19:19:47 -0500 J. Craig Woods [EMAIL PROTECTED] wrote:

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread James
On Fri, 24 May 2002 20:06:23 -0600 Femme [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 17:53:02 -0800 civileme [EMAIL PROTECTED] wrote: FemmeFatale wrote: Pierre Fortin wrote: On Thu, 23 May 2002 23:15:52 -0800 civileme [EMAIL PROTECTED] wrote: Load up the honeyport for

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread James
If anyone is intrested I've got a script I put together when CodeRed was hammmering away. It sets up iptables or ipchains rules that block the offending site. James On Fri, 24 May 2002 17:55:45 -0800 civileme [EMAIL PROTECTED] wrote: Pierre Fortin wrote: On Thu, 23 May 2002 23:15:52

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Pierre Fortin
On Fri, 24 May 2002 20:50:52 -0700 James [EMAIL PROTECTED] wrote: If anyone is intrested I've got a script I put together when CodeRed was hammmering away. It sets up iptables or ipchains rules that block the offending site. Where's the *fun* in that...? I prefer 'self-defense' tactics...

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread danrembolt
Got a script to attack the attacker? I've been looking for one. On Fri, 24 May 2002 20:50:52 -0700 James [EMAIL PROTECTED] wrote: If anyone is intrested I've got a script I put together when CodeRed was hammmering away. It sets up iptables or ipchains rules that block the

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread Femme
On Fri, 24 May 2002 20:49:21 -0700 *nods* Got those ports being attacked too, as well as looking for SSH ports Some other obscure ports Unix/linux uses. I don't know why though... whats 139 Sorry i'm sorta half-aware/educated on security(hangs my head sheepishly). NetBios-ssn

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread nDiScReEt
On Friday 24 May 2002 10:50 pm, you wrote: If anyone is intrested I've got a script I put together when CodeRed was hammmering away. It sets up iptables or ipchains rules that block the offending site. James I'm interested. On Fri, 24 May 2002 17:55:45 -0800 civileme [EMAIL PROTECTED]

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread James
On Fri, 24 May 2002 23:22:29 -0600 Femme [EMAIL PROTECTED] wrote: On Fri, 24 May 2002 20:49:21 -0700 *nods* Got those ports being attacked too, as well as looking for SSH ports Some other obscure ports Unix/linux uses. I don't know why though... whats 139 Sorry i'm sorta

Re: honeyport/shutdown [was: Re: [expert] OT, my ftp site]

2002-05-24 Thread James
On Fri, 24 May 2002 21:43:37 -0700 [EMAIL PROTECTED] wrote: Got a script to attack the attacker? I've been looking for one. Nah I'm being a good little boy. Actually once my box is covered I don't care. Someone did write something that when his/her box was attacked by codered it used