Re: Linux security

2003-08-08 Thread Devdas Bhagat
your local network only, and allow connect() only to known safe ports. Devdas Bhagat ---

Re: HTTPS - How hard to decrypt?

2003-07-10 Thread Devdas Bhagat
riously recommend using client side certificates as well for authentication and authorization. Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris i

Re: Oh Dear, Where to start?!

2003-07-04 Thread Devdas Bhagat
ce to spend it. Clamav via cygwin is supposed to run on Windows. clam is GPLed. Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of it

Re: log monitoring tool against router?

2003-07-04 Thread Devdas Bhagat
r logs too? These programs are basically matching text strings. So just add your regular expressions to their dictionary files. Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The

Re: Question for you all

2003-07-03 Thread Devdas Bhagat
sibly one of pop3 (tcp/110), imap (tcp/143), pop3s(tcp/995), imaps (tcp/995). Also allow incoming tcp/53 and udp/53 for DNS. Avoid using FTP, use SCP instead. Windows clients can use Winscp. Devdas Bhagat --- Evaluating SSL VP

Re: OMail exploits..?

2003-07-03 Thread Devdas Bhagat
t say the same about OMail until I have seen the audit results. http://omail.omins.ch/ OMail has been written in PHP4, so I guess that so long as you stay patched and follow BCP w/ PHP, you should be safe. Devdas Bhagat -

Re: Anti-Virus for RedHat Linux

2003-07-03 Thread Devdas Bhagat
On 30/06/03 18:23 -0400, Paul Kurczaba wrote: > Does anyone know of a good, free Anti-Virus product for RedHat Linux. http://clamav.elektrapo.com/ http://www.bitdefender.com/ The first is GPLed, the second is not. Devdas Bha

Re: Getting an IP address from a MAC address

2003-07-03 Thread Devdas Bhagat
ork, a Linux/Unix box with arp should do the trick. Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InS

Re: Port scanning question

2003-07-03 Thread Devdas Bhagat
snort.org/ is a good place to start. Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, while InStat has confirm

Re: Ten least secure programs

2003-07-02 Thread Devdas Bhagat
> 3) Sendmail > 4) IIS Server > 5) Wireless networking Wireless networks without IPSec. > 6) PHP > 7) ? Unaudited code, in any language. r* (rsh, rcp, etc) 0) Unpatched anything* Devdas Bhagat --- Evalua

Re: Netcat (NC) Secure Remote Connections via authenication

2003-07-02 Thread Devdas Bhagat
gt; *can* be run on a Win32 machine, which would solve your problem nicely > once you find a consultant able to build it for you using Cygwin. Of Prebuilt packages are available online. You can just download and install those. Devdas Bhagat

Re: Antivirus on SQUID

2003-06-30 Thread Devdas Bhagat
nd spam checking into a single scan, and it is high performance, with a lot of flexibility. http://www.ijs.si/software/amavisd/ Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts!

Re: Locking down a user

2003-06-26 Thread Devdas Bhagat
direction, maybe a tutorial that they have found useful? http://www.google.com/search?q=scp+invalid+shell Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group jus

Re: perl scrambling

2003-06-23 Thread Devdas Bhagat
to the customer. Everything except one initial file will be encrypted, the initial file decrypts the application into memory and runs it from there. Not entirely foolproof, but it should keep out the people who would just copy the software. Devdas Bhagat

Re: redhat audit

2003-06-17 Thread Devdas Bhagat
ast x number of days. Use find for that find / -mtime x Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neoteris in the top of its Magic Quadrant, whi

Re: Firewall configuration statistics

2003-06-10 Thread Devdas Bhagat
d applications (unless they have been throughly audited for known bugs, and maybe even then). Devdas Bhagat --- Evaluating SSL VPNs' Consider NEOTERIS, chosen as leader by top analysts! The Gartner Group just put Neote

Re: open proxy

2003-04-01 Thread Devdas Bhagat
http://www.google.com/search?q=smtp+auth+domino HTH Devdas Bhagat --- SurfControl E-mail Filter puts the brakes on spam, viruses and malicious code. Safeguard your business critical communications. Download a free 30-day trial: ht

Re: smtp relay tester?

2003-03-18 Thread Devdas Bhagat
On 14/03/03 12:01 -0600, Nuzman wrote: > I'm looking for a SMTP relay tester. Any suggestions? ordb.org maps.org Devdas Bhagat

Re: SSH Passphrase

2003-03-06 Thread Devdas Bhagat
sion which it then remembers, this > isnt possible as it is non-interactive in my case. Does anyone have any > ideas or comments? You need to give the passphrase once at boot. Devdas Bhagat

Re: Is QMail also affected by the Send Mail Bug

2003-03-05 Thread Devdas Bhagat
On 04/03/03 08:24 -0500, Andrew D. Bartels wrote: > I was wondering if the Sendmail vulnerability also affects QMail. No. Nor does it affect postfix or exim. Devdas Bhagat

Re: Odd log messages

2003-03-04 Thread Devdas Bhagat
name - - [26/Feb/2003:23:00:11 -0500] "\x05\x01" 501 - > the.guys.hostname - - [26/Feb/2003:23:00:13 -0500] "CONNECT 207.46.181.13:25 > HTTP/1.1" 405 321 This is someone trying to use your Apache installation as a proxy to relay spam. The 405 error means that it has not gone through. Devdas Bhagat

Re: Outlook web access

2003-03-03 Thread Devdas Bhagat
n IMAP based webmail client? www.squirrelmail.org www.horde.org Devdas Bhagat

Re: NAT and webcashing

2003-01-13 Thread Devdas Bhagat
. Oh, and use a good pair of Intel NICs, I have seen RTL chipsets failing under load. Devdas Bhagat

Re: remote desktop question

2003-01-02 Thread Devdas Bhagat
best way to set it up? vnc + (ssh|stunnel|zeebeedee) Linux => www.freeswan.org OpenBSD has crypto support built in by default. Devdas Bhagat

Re: copying a disk image to restore on linux

2002-12-24 Thread Devdas Bhagat
king for backup tools. Devdas Bhagat

Re: Iptables and multiple ip ranges

2002-12-18 Thread Devdas Bhagat
one, and how. Use multiple rules. 192.168.0.27-192.168.0.63 = 192.168.0.32/27 + 192.168.0.28/30 + 192.168.0.27/24 HTH Devdas Bhagat

Re: syslog server- how to on Linux

2002-12-16 Thread Devdas Bhagat
tening as a service when I type > netstat -an. Any help is appreciated... a direction for information if you netstat -anu would be more specific. You need to start syslogd with the -r option (it doesn't listen to a UDP socket by default, but only a local socket). See the /etc/init.d/syslog startup script, or use yast2. Devdas Bhagat

Re: Question on Blocking an ISP.

2002-12-03 Thread Devdas Bhagat
4 different netblocks. Devdas Bhagat

Re: ridiculous situation

2002-12-02 Thread Devdas Bhagat
t add much security unless you are running a DMZ and an internal network which should not have any access to/from the Internet. Devdas Bhagat

Re: Need Help Building Linux Based Firewall

2002-11-29 Thread Devdas Bhagat
with level 8 security in place. Firewalls as a bandage for bad code are a bad idea. Properly used to segment networks with varying security requirements, they can be useful. Devdas Bhagat

Re: *nix firewall setup

2002-11-28 Thread Devdas Bhagat
On 27/11/02 11:55 +0530, Devdas Bhagat wrote: > On 26/11/02 09:20 -0800, jh wrote: > > Having never set one up before and only having a little knowledge of linux > > where can I go to get a basic tutorial that just covers firewalls and linux. > http://www.linuxguruz.org/iptab

Re: *nix firewall setup

2002-11-27 Thread Devdas Bhagat
On 26/11/02 09:20 -0800, jh wrote: > Having never set one up before and only having a little knowledge of linux > where can I go to get a basic tutorial that just covers firewalls and linux. http://www.linuxguruz.org/iptables/howto/iptables-HOWTO.html http://www.google.com/search?q=iptables+howto S

Re: Survey: Chat and IM

2002-11-26 Thread Devdas Bhagat
On 25/11/02 13:53 -0800, Fred Hoot wrote: > We have outlawed all instant messaging products and purchased a private > messaging software (Active Messenger). It is internal and can be accessed > via our VPN connections between offices. Any reason not to use Jabber? Devdas Bhagat

Re: IP to MAC mapping

2002-11-26 Thread Devdas Bhagat
on of the rule. The default rule in this case was a redirect, but could easily become a DROP. I hope this helps. Devdas Bhagat

Re: IP to MAC mapping

2002-11-25 Thread Devdas Bhagat
tomatically from a database. Devdas Bhagat

Re: Ftp Login

2002-11-04 Thread Devdas Bhagat
On 01/11/02 15:51 -0300, Pablo Gietz wrote: > DO you know if FTP (standard) login process is maked in clear text? Yes. As is telnet. And the r* services Devdas Bhagat

Re: Webmin Security Questions

2002-10-23 Thread Devdas Bhagat
> glanced over the website, and didn't see anything about SSH, SSL, or Webmin will use SSL if Net::SSLeay is installed. Pick it up from cpan. Devdas Bhagat

Re: incident response - management approach

2002-10-22 Thread Devdas Bhagat
ident Response-Investigating Computer Crime" which tells you what is expected, and how to deal with incidents (policies, pre-incident preparation, incident response). My only complaint with this book is that it is rather US centric, but is fairly broad Devdas Bhagat

Re: Listener on ports 137, 138, 139

2002-10-17 Thread Devdas Bhagat
h I trace to something called=20 169.254/16 is the block to be used by a network interface when it cannot contact its dhcp server. > Anybody has an idea about what this can be. You have File and Print sharing enabled. Devdas Bhagat

Re: Web Mail Vulnerabilities

2002-10-17 Thread Devdas Bhagat
t the coders). You could probably develop an inhouse client in a week or two. Email may contain spam, HTML, viruses... I would suggest something like demime to strip everything except plain text from the email. This is the safest way to deal with MIME (get rid of it). Hope this helps a bit. Devdas Bhagat

Re: Is SSH worth it??

2002-10-17 Thread Devdas Bhagat
$sudo vim :!sh # is an easy way to get a root shell without ever using the root password. Devdas Bhagat

Re: Ipchains Question / Seeking Information.

2002-10-16 Thread Devdas Bhagat
002 You aren't looking for connections being initiated from your box, but all connections to port 2002/tcp. I suggest that the tcp rules be modified to look for the initial SYN bit set too, or you upgrade to iptables. You are probably looking at a webserver response to a perfectly normal query. Devdas Bhagat

Re: Is SSH worth it??

2002-10-10 Thread Devdas Bhagat
hat your protection has gone from key based to password based. See man 1 ssh-agent for a way of handling your pass phrases relatively safely. Devdas Bhagat

Re: Is SSH worth it??

2002-10-09 Thread Devdas Bhagat
ne and user level. So there really will be no major change in the scripts, except for the first time key exchange. Once the keys are set up properly, you can just ssh user@remotehost or scp user@remote:/path/to/file /path/to/local or the other way round. There should be no major script change, excep

Re: Is SSH worth it??

2002-10-08 Thread Devdas Bhagat
s is this; > > On an internal network that is switched (making sniffing harder) is it > worth going to SSH and SCP?? http://ettercap.sourceforge.net/ Devdas Bhagat

Re: Log Watcher For a PIX

2002-10-07 Thread Devdas Bhagat
d but its filtering capabilities are rather useful) Devdas Bhagat

Re: ATTN Corporate Security Officers - E-Mail Usage Policies

2002-10-04 Thread Devdas Bhagat
versations). If you are worried about TLS, put in your own proxies and install your own certificates on the clients. This should allow you to perform a MITM and see plain text traffic on the proxy. Devdas Bhagat

Re: Help With firewall ports

2002-03-19 Thread Devdas Bhagat
m. This has been covered earlier. There is a firewalls list: [EMAIL PROTECTED] http://lists.gnac.net/firewalls Devdas Bhagat

Re: Fin Stealth Scanning

2002-01-21 Thread Devdas Bhagat
portscanner around. Read the source. Devdas Bhagat

Re: Hardening VS firewalling ?

2002-01-08 Thread Devdas Bhagat
centrate on one) , which one would it be and why? A firewall with good antispoofing rules, and blocks for common attacks with a default DENY policy, backed up with fully patched systems and local firewalls with very strict policies. Devdas Bhagat

Re: Network based intrusion detection

2002-01-08 Thread Devdas Bhagat
On 07/01/02 19:45 -, Greg wrote: > > > I was wondering what everyone is doing for network > based intrusion detection? I am looking for http://www.snort.org should help a lot. Devdas Bhagat

Re: Security Update Software

2002-01-08 Thread Devdas Bhagat
dows NT/2K, http://windowsupdate.microsoft.com for the rest. I suggest monitoring bugtraq and using a few good scripts to do this for you (I suggest wget+sh). More details on what you are looking for would of course help a lot more. Devdas Bhagat

Re: basic DMZ scheme

2002-01-02 Thread Devdas Bhagat
ervers should be in the internal network. Hope this helps Devdas Bhagat

Re: Which Proxy Server...

2001-12-27 Thread Devdas Bhagat
On 18/12/01 23:41 -, Securitynews wrote: > Is there such thing as POP3 proxying. Does anyone know of an application > for this? http://perdition.sourceforge.net cyrus imapd ships with its own proxy servers. Devdas Bhagat

Re: Ip Spoofing I Think

2001-12-02 Thread Devdas Bhagat
ssible to spoof the SMTP headers. but you would still want to check first that you don't have a spam source somewhere. Devdas Bhagat

Re: Single sign-on

2001-11-24 Thread Devdas Bhagat
e this even worse. If you are considering something like hailstorm, this multiplies the security problems by quite a few orders of magnitude. Hope this helps, Devdas Bhagat

Re: Remote Admin of DMZ

2001-11-20 Thread Devdas Bhagat
On 20/11/01 09:17 +1100, Matt LYNCH wrote: > risk. Does anyone else remote admin inside a DMZ and if so how?? VNC over ssh works. Am in the process of implementing it. Both are free. Devdas Bhagat

Re: SMTP alternative

2001-10-22 Thread Devdas Bhagat
olution for this problem,i know the question > may sound utopic but i really need to make this box "deamonless".anyone ? Put up a different machine as a mail server? More details about your setup and requirements would help. Devdas Bhagat -- No cat has eight tails A cat has one tail

Re: How can I catch IP packet content ?

2001-10-22 Thread Devdas Bhagat
me to catch (and display)all the content of an IP packet. Sniffers !? > Thank you in advance ! I would say that you need a sniffer. tcpdump/tethereal from the CLI, and ethereal if you want a GUI. Devdas Bhagat

Re: Small office Firewall.

2001-10-21 Thread Devdas Bhagat
eah, I don't have verisign certificates in my browsers any longer, because I don't trust them. In Applied Cryptography terms, Trent is no longer a trusted third party. Devdas Bhagat

Re: Recommendation for a "secure" mail server

2001-10-19 Thread Devdas Bhagat
On 05/10/01 13:05 -0700, Jay D. Dyson wrote: > The best suggestion I can give you is to abandon Win2K and load > either Solaris x86 or Linux and use Qmail. Or postfix on either OS, or on FreeBSD. Easier to drop in place than qmail too. Devdas Bhagat

Re: cannot clean my machine..

2001-10-18 Thread Devdas Bhagat
;. Hybris? Update your antivirus/download a new version of Norton/Trendmicro from the net and use that to clean your system. Devdas Bhagat -- God is an atheist

Re: DoS attack ...

2001-09-23 Thread Devdas Bhagat
f you can do port mirroring to the monitoring machine, try ntop, with both pcap and ntop from CVS. Devdas Bhagat -- Hello... IRON CURTAIN? Send over a SAUSAGE PIZZA! World War III? No thanks!

Re: Compartmentalizing user priviledges, Was: Re: Running more than one service on one box

2001-09-23 Thread Devdas Bhagat
le of the core OS design. Agreed Devdas Bhagat

Re: Running more than one service on one box

2001-09-21 Thread Devdas Bhagat
sible to make anything foolproof because fools are so ingenious. Keep that in mind as well. Devdas Bhagat -- Force has no place where there is need of skill. -- Herodotus

Re: Running more than one service on one box

2001-09-19 Thread Devdas Bhagat
permissions also make it pretty much a nightmare in an untrusted network. On the other hand, most *nix systems give the administrator far more control over what the system does. They don't try to do the right thing irrespective of what the admin says. So that line shoule be read as *nix machin

Re: Hardware Firewall vs Software Firewall

2001-09-17 Thread Devdas Bhagat
r, and easier to upgrade and maintain than a hardware firewall. My recommendation would be to go with what you can secure properly and fits in your budget. Devdas Bhagat -- Power corrupts. And atomic power corrupts atomically.

Re: IPX question

2001-09-14 Thread Devdas Bhagat
he IP packet. There were some benefits earlier, but no longer. Hope this helps. Devdas Bhagat -- Don't compare floating point numbers solely for equality.