Re: capturing traffic on cisco routers

2002-02-22 Thread Srecko Jovancevic
you can use mrtg - Original Message - From: Dave Stein [EMAIL PROTECTED] To: [EMAIL PROTECTED] Sent: Wednesday, February 20, 2002 5:39 AM Subject: capturing traffic on cisco routers Hi there, Im very new in this list, and a newbie in cisco administration, i would like to know ,if

RE: Backup tools

2002-02-22 Thread Bullough, Gavin
Hi, Veritas Netbackup is a well proven backup solution that works over a network to many different platforms and applications. http://www.veritas.com/products/listing/ProductListing.jhtml is a good place to start. Regards Gav -Original Message- From: Domingos Costa [mailto:[EMAIL

RE: Windows 2000 - Novell passwords synchronization

2002-02-22 Thread Lubrano di Ciccone, Christophe (DEF)
Setting up on the both side : domain policy for windows 2000 client using the Microsoft network logon authentification NDS for the other using Novell network logon authentification Christophe PS in the same time il should be reliable to set up minimun password lenght also -Original

RE: Backup tools

2002-02-22 Thread Stefan Kaysersberg
Hello, Does anybody know about a network backup tool which performs a backup on disk and tape devices? I've already searched for these kind of softwares, such as afbackup, burt, amanda, arkeia, etc. but they write only on tape devices or they don't support networking. I

RE: Auditory and risk-analysis

2002-02-22 Thread Lubrano di Ciccone, Christophe (DEF)
Hello, there a lot of tools depends on which box or network etc. these links may help you anyway : www.securityspace.com www.csnc.ch regards Christophe -Original Message- From: Thiago Mello [mailto:[EMAIL PROTECTED]] Sent: lundi 18 fevrier 2002 11:21 To: [EMAIL PROTECTED] Subject:

Just a question!!!

2002-02-22 Thread Bassam ALHUSSEIN
Hello all ... Every time I make a dial-up connection to the internet I see an unknown (for me) IP address that I am connected on port 80, in the out put of netstat -an on a win98SE box. The thing that I don't understand is that this is not the proxy server of ISP i'm connected to !! I used

Re: Backup tools

2002-02-22 Thread Rachel
On Wed, 2002-02-20 at 09:27, Domingos Costa wrote: Hello, Does anybody know about a network backup tool which performs a backup on disk and tape devices? I've already searched for these kind of softwares, such as afbackup, burt, amanda, arkeia, etc. but they write only on tape

Re: Backup tools

2002-02-22 Thread Renato Murilo Langona
Greetings, Domingos Costa wrote: Hello, Does anybody know about a network backup tool which performs a backup on disk and tape devices? I've already searched for these kind of softwares, such as afbackup, burt, amanda, arkeia, etc. but they write only on tape devices or

PlaceWare Java Client

2002-02-22 Thread jeff ewing
Is anyone familiar with or using the product, PlaceWare? Are there any concerns or issues that you are aware of with the product? If you are using it, were there certain precautions that were necessary? PlaceWare and PlaceWare security: http://www.placeware.com/

RE: Backup tools

2002-02-22 Thread Bejon Parsinia
I'd suggest you check out Veritas Backup Exec Enterprise Edition. This has the ability to backup data from network drives as well as the local box. Bejon -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Domingos Costa Sent: Wednesday, February 20, 2002

RE: Windows 2000 - Novell passwords synchronization

2002-02-22 Thread CHRIS GRABENSTEIN
When you change a Novell password via the NetWare client, it automatically synchronizes other resources including the Windows password. If you set the Novell password to expire one day before the Windows password expires, I would imagine that those using the Novell would be forced to change the

Re: Password Management

2002-02-22 Thread Tim O'Brien
I agree with this method and use a variation of it myself. I also have my passwords in 4TNox on my Palm Pilot. I would add that you should be careful of any temporary and/or backup files left by your editor. I use vim on Win98, Win2K and Linux. After editing my passwords text file, I

RE: Best means to block MSN Messenger, AIM and other chat programs?

2002-02-22 Thread Bejon Parsinia
I have worked with MSN Messenger issues in the past. The problem with MSN is that it uses the H.323 protocol for the capabilities of VOIP (netmeeting) and Video Conferencing (also netmeeting). H.323 uses dynamically assigned ports that span a great range of UDP ports. Check out this url for

Re: Cisco VPN client

2002-02-22 Thread Cflynn . Tech
Are you passing both phase 1 and Phase 2 ... ??? Can you ping anything in the local LAN?? --- Regards, On Wed, 20 Feb 2002 12:11:38 Tumarinson, Max wrote: I am trying to set up Cisco VPN client 3.5a behind a Winproxy 4.0h. I am able to authenticate, however I can reach anywhere on the LAN.

Re: Windows 2000 - Novell passwords synchronization

2002-02-22 Thread David Carter
There are a few options to synch the two directories and the user attributes in them. From Novell there is DirXML as well as Account Management From Microsoft there is Services for Netware and Metadirectory Services. The company that I work for is useing Netvision's Synchronicity and that

RE: Best means to block MSN Messenger, AIM and other chat programs?

2002-02-22 Thread Kinsey, Robert
Hello Ken, One of the things you will find with MSN is that if the primary port is disabled it will resort to either 8080, 8000 or similar (I don't remember which ones exactly). It might be tough to disable strictly from the firewall. hth, Robert

RE: disabling port 79

2002-02-22 Thread Hornat, Charles
The question is to you, do you use it? Finger used to be a good tool, today it leads to a security concern. If you don't use it, as with any service running, turn it off. mrcorp -Original Message- From: Dean Fox [mailto:[EMAIL PROTECTED]] Sent: Wednesday, February 20, 2002 10:55 AM

Websites can execute code on users machine

2002-02-22 Thread Mike Carney
Setting your browser to high disables this from happening but I figured I'd share this link to a Hungarian web site. I believe that the site has notified Microsoft of this problem. http://www.kurt.hu/iebug.htm I checked all the browsers in my office and they were set to medium (Is this the

Re: disabling port 79

2002-02-22 Thread Matt Hemingway
No impact. A very wise decision. It's one of the first things I do after setting up a new machine. -Matt On Wednesday 20 February 2002 07:55, Dean Fox wrote: I am contemplating to remove/disable finger or port 79 from some workstations and/or servers. Is there any negative impact for

RE: Unsigned Windows 2000 Patches

2002-02-22 Thread Bejon Parsinia
Have you downloaded the Root Certificates Update from MS Update? This should remove that message. MS has updated its certificates and your machine is out of date. :) Shocker for MS eh? Enjoy, Bejon -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]] Sent:

Re: Backup tools

2002-02-22 Thread Jim Boyer
Have a look at UltraBac From: Chris Harrison BEI Corporation dba UltraBac 15015 Main Street, Suite 200 Bellevue, WA 98007 Telephone # (425) 644-6000 Fax # (425) 644-8222 [EMAIL PROTECTED] http://www.ultrabac.com At 12:27 PM 2/20/2002 -0300, Domingos Costa wrote: Hello,

Re: ArcServIT 6.5 Enterprise

2002-02-22 Thread Kestas (Bidz)
Active prote is for NT only what about win2000 Kestas - Original Message - From: Mathieu Patenaude [EMAIL PROTECTED] To: 'Calhoun, Heath' [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Sent: Wednesday, February 20, 2002 1:01 PM Subject: RE: ArcServIT 6.5 Enterprise Use a program called

Help with ipchains

2002-02-22 Thread Chad
Can anyone recommend a good resource for ipchains, ( Very thorough and low level ) for someone who is just learning to use it ? Meaning an in-depth resource, all switches, arguments etc.. ?? With some good examples ? I am having a little difficulty finding one. Thanks. Chad

Re: disabling port 79

2002-02-22 Thread shawn merdinger
It's not an *important* service and IMO only provides attackers with info for brute force attacks (from gathered usernames) and social engineering attacks (from email addresses and user info). -scm On Wed, 20 Feb 2002, Dean Fox wrote: I am contemplating to remove/disable finger or port 79

Re: Group Policy

2002-02-22 Thread Raoul Armfield
If this is a Win2K machine you maybe able to use the runas feature to install software while remaining logged in as generic user ID At 07:58 AM 2/15/2002, Richard wrote: I am trying to find a work-around that will enable an administrator to install an application (Oracle) while still logged

RE: Backup tools

2002-02-22 Thread Tom Petersen
I think the product you are looking for is BRU which has recently moved to the Tolis group -- http://www.tolisgroup.com/ Tom Petersen -Original Message- From: Domingos Costa [mailto:[EMAIL PROTECTED]] Sent: Wednesday, February 20, 2002 10:28 AM To: [EMAIL PROTECTED] Cc: [EMAIL

RE: MORPHEUS

2002-02-22 Thread Zill, Greg
I locked my son out using port 1214 tcp udp as well as 3 ips over www proto(206.142.53.17, 206.142.53.19, 206.142.53.21) -Original Message- From: Jose Rayo [mailto:[EMAIL PROTECTED]] Sent: Wednesday, February 20, 2002 11:08 AM To: Security-BASICS (E-mail) Subject: MORPHEUS Hi you

Re: disabling port 79

2002-02-22 Thread Baba Bogdan
My personal opinion is that you shouldn`t run finger at all Baba Bogdan Sys Admin CDS NETWORK, Corpus Christi, TX, USA CAD Data Systems, Cluj-Napoca, Romania o0()()0o--- We can forgive a child who is afraid of the

RE: Best means to block MSN Messenger, AIM and other chat programs?

2002-02-22 Thread Hornat, Charles
Its better not to block ports as it will work on other ports, but to try and block the IP addys of the servers these programs try to connect to. mrcorp The information contained in this message is intended only for the

X and port 6000

2002-02-22 Thread sege
Hello Folks: I am running Mandrake Linux 8.1, and I am trying to stop X from listening 0n port 6000. Any hint on how to do this will be appreciated. TIA, Qv6

Re: Windows 2000 - Novell passwords synchronization

2002-02-22 Thread Radoslav Dejanovi
On Wednesday 20 February 2002 10:21, Udi Dahan wrote: My problem is that at least half of my clients are also Novell clients and there is no automatic synchronization between Windows 2000 and Novell. You're using Novell 5? If that is so, then Novell Client has the ability to automatically

RE: Cisco VPN client

2002-02-22 Thread Snow, Corey
It would help if you would provide more information- what exactly occurs and what error messages do you see? -Original Message- From: Tumarinson, Max [mailto:[EMAIL PROTECTED]] Sent: Wednesday, February 20, 2002 9:12 AM To: [EMAIL PROTECTED] Subject: Cisco VPN client I am

help:vpn b/w cisco pix cp2000

2002-02-22 Thread jack bird
Hello, establishing vpn between cisco pix to checkpoint.The same was done with invalid netwroks at both ends but its not happening b/w a invalid netwrok valid dmz network at checkpoint end.Can anyone help in this regard.Nat is not used. regards jack

RE: SSL Question

2002-02-22 Thread Raoul Armfield
I am new to this field but as I understand it the public key does no form of decryption only encryption the Private key does all the decrypting At 05:28 AM 2/15/2002, Shripal wrote: |Huh. No. You have private keys and public keys. Public keys are distributed |and can be used to encrypt data

Re: Backup tools

2002-02-22 Thread mmcgillis
You didn't mention your price range or what OS's but Veritas has backup software you might want to check out. I watched a presentation on it not too long ago and it seemed impressive. There website is: http://www.veritas.com Hope this helps! Melissa On Wed, 20 Feb 2002, Domingos Costa wrote:

RE: Backup tools

2002-02-22 Thread Ziggy
dump or tar i think should work Ziggy -Original Message- From: [EMAIL PROTECTED] [mailto:[EMAIL PROTECTED]]On Behalf Of Domingos Costa Sent: Wednesday, February 20, 2002 6:28 PM To: [EMAIL PROTECTED] Cc: [EMAIL PROTECTED] Subject: Backup tools Hello, Does anybody know

Re: DHCP Server solutions

2002-02-22 Thread Raoul Armfield
We do this sort of thing but we setup ACLs on the switch level this way the switch recognizes the MAC address configures the port for the proper VLAN and then the DHCP server serves up an IP adress this eliminates the problem that you are trying to avoid. At 03:41 PM 2/20/2002, Michael

Re: Webserver relaying mail

2002-02-22 Thread Lisa Bogar
Shawn, Yep, your right. I wasn't given the complete information about how they had neglected to update their code. Thanks for pointing this out. I'm kind of wondering if some of those log entries someone else experienced might be due to the same thing this individual incurred. I don't work

Re: Detecting Sniffers?

2002-02-22 Thread Matt Hemingway
I would suggest using Ettercap (http://ettercap.sourceforge.net) to sniff in the switched network. Sniff Host A from Host B. Have Ethereal (www.ethereal.com) capture on Host C. You might find something interesting with the ARP requests/changes. Another thing you can do (this is what I do)

RE: capturing traffic on cisco routers

2002-02-22 Thread Michael Bellears
You haven't stated what cisco router you are using...but Are you wanting to do accounting on the traffic ? You can use: flow-export on the cisco to export the traffic flows to a box running flow-tools to capture/analyse. Works very well. HTH, MB -Original Message- From: Dave Stein

RE: Apache Security Issue

2002-02-22 Thread Garbrecht, Frederick
Port 25 blocking at Verizon routers is news to me. I have a Verizon dsl connection and am able to connect to other mail servers just fine. I'm not sure how outbound blocking of smtp would cut down spam anyway, unless they're worried that you are going to be relaying off your own server. I get

Integration of network management software with security

2002-02-22 Thread Carmelo Floridia
Do you know if exist a network management software (likee HP-openview, Tivoli, TNG unicenter) that could be used to manage security (FIrewall, IDS...)? best regards Carmelo

RE: Webserver relaying mail

2002-02-22 Thread Darwin Gregory
formmail.pl is a script known to be exploited by spammers in the way you describe. We get many hits from people searching for this script every day, even though it does not exist on our servers. The script should be removed, and any attemps to exploit it reported to the exploiter's service

Re: Apache Security Issue

2002-02-22 Thread Red Wolf
Your best bet would to be run the web server on an off port, like 8080 Eric has a good idea... consult Apache documentation http://httpd.apache.org/docs-2.0/mod/mpm_common.html#listen I would suggest port 443, most firewalls allow outbound connections to 443 and this will maximize the number of

Re: Best means to block MSN Messenger, AIM and other chat programs?

2002-02-22 Thread ktabic
TBH, you don't really have that much of a chance blocking these programs by port, as three of them (I haven't used Yahoo) are perfectly capable of going though other ports, aside from the default port numbers (I have seen AIM using port 53 and port 80 to make it's connection) You would