tripwire config

2001-12-30 Thread John Christopher
Hi - A few questions about configuring Tripwire (BTW, I am using the "academic release" version on various Linux, FreeBSD and OpenBSD boxes, which are configured as single-function servers [i.e. www servers, firewalls, database servers, etc.]): 1. When creating the policy file that instructs Tr

RE: windows XP and firewalls

2001-12-30 Thread Chris Chandler
If you are using NPF there is a setting in there to add a range of IP addresses for your home network and even settings that allow it to "learn" from outbound connections from the client computers. These can be found under the advanced settings -Original Message- From: Cami Boyd [mailto:[

Re: Has 3des been broken

2001-12-30 Thread Andrew Chong
AES will replace DES and 3DES. On Oct 2, 2000, NIST announced the selection of the Rijindael block cipher as the proposed AES algorithm. Andrew Chong, CISSP Senior System Architect - Original Message - From: "Dante Mercurio" <[EMAIL PROTECTED]> To: <[EMAIL PROTECTED]>; <[EMAIL PROTECTED]

basic DMZ scheme

2001-12-30 Thread Roman Serbski
Hi list Probably this is OT (I'm sorry), but could someone point me to URLs where I could find information about DMZ organizing? I have main firewall with three NICs, one goes to private LAN, second one to DMZ, third one to ISP. Is there any basic document about where to place service servers

Re: Encrypted chat for business use

2001-12-30 Thread Richard Cotterell
Ref: Rhett Hensley <[EMAIL PROTECTED]>'s message dated 26 Dec 2001, 13:46 hours. >Greets, > I have recently became in need for encrypted chat in my place of work. I >have seen a few options such as using pgp plugins to encrypt messages when >using icq or jabber but I was wondering wh

Re: which ftp-server?

2001-12-30 Thread Devon Ryan
Michael Rice wrote: >>If it's at all feasable, i urge you to implement SSH (and >>SCP for file transfers). >> > > I've heard this recommendation all too often. Implementing SSH/SCP gives > the user far more than file transfer ability. (though my experience is on > unix, I don't know about SS

ipchains & iptables together???

2001-12-30 Thread Shinta H Leagazpi
can I use both ipchains and iptables at the same time??? __ www.edsamail.com

Re: firewall

2001-12-30 Thread Inferi Dii
Try www.ciscoshop.com LOL Hardware costs may vary from location to location, but unless you have an in house CCIE you may be spending thousands of USD on consultants. Ok, maybe you don't need a CCIE, but it wouldn't hurt! ID >From: "Rajamohan Nalappan" <[EMAIL PROTECTED]> >To: <[EMAIL PROTECTED

RE: Has 3des been broken

2001-12-30 Thread Kevin Brown
3DES does not use a true single 168 bit key. This is a common mistake. 168 bits comes from the fact that 3DES (which can be applied a few different ways) usually uses 3 56 bit keys (sometimes using 3 different keys and sometimes using 2 keys with one used twice). 56+56+56=168. The reason the "

RE: Has 3des been broken

2001-12-30 Thread M Lister
> Still purely theoretical. IBM just got a quantum computer to factor the > number 9. Gonna take a few more years before they can tackle 3des. Then If I remember correctly, just recently they [IBM] factored the number 15 into factors 3 and 5 using a Quantum Computer. Maybe the development will be

bastille on r.h. 7.2

2001-12-30 Thread Michael Desrosiers
Hey, Has anyone else had this problem with Bastille 1.3.0-0.6 trying to run the InteractiveBastille script [root@neo /]# InteractiveBastille Using Tk user interface module. Only displaying questions relevant to the current configuration. Something weird discovered between question records:

NAT, Internet access and security

2001-12-30 Thread Gilles Poiret
Hello, I plan to give my company access to Internet. My ISP propose me partial-time access (20h) on a RNIS solution, with a router, a single IP address (dynamic), so using private addresses for computers on my LAN. This offer doesn't include security stuff (excepted for e-mails). So I'm wonder

Port Walking

2001-12-30 Thread Rich Richenberg
Hello All, We're having a debate here about whether a computer will "walk" ports if it tries to connect to another system on one port and is unsuccessful. The port in question is 1214. There is a rule in place that essentially sends a reset to both systems if any IP tries to connect to any IP via

mailing lists for conferences?

2001-12-30 Thread leon
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi everyone, Does anyone know of any mailing lists that have information on upcoming security conferences or seminars and where they are being held? Thanks in advance and happy new year to everyone, Leon -BEGIN PGP SIGNATURE- Version: PGPf

Re: Description "Hacking server"

2001-12-30 Thread H Carvey
In-Reply-To: <[EMAIL PROTECTED]> I'm not sure what you mean when you say you found "hacking server" in a description "at" usermanager. I have to assume that you're saying that a user or machine account in UserManager on your NT4.0 system had the words "hacking server" (and the 'numericals'