/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */
Hey Everyone,
Happy New Year! Anyway, lots of updates.
PS. There are now 336 people on the list.
Keep um' coming.
PPS. TrinityOS is starting to get some decent
press. Check it out:
Sharing a Six Pack:
http://www.linuxcare.com/news_columns/tales/index.epl
--David
G 01/02/00 Added the URL for downloading all
*Sent the various port-numbers, protocol-numbers,
etc from the IANA. To be, ALL of these
files belong in a globally readible
directory in /etc/iana.
[Section 5]
G Added a pointer to this IANA archive when
describing how to read a firewall
IPCHAINS hit.
[Section 10]
G Fixed two typos in the TrinityOS-security.sh
archive. A missing ending " and a missing
"rc.d". Thanks to [EMAIL PROTECTED] for
the heads up.
N Moved all TrinityOS updates older than
11/25/99 to the TrinityOS-updates
list. URL is above.
------------------
N 01/01/00 Hehehe.. gotta love that date eh?
Anyway, just added a link to the Linux
Application page. Lots of these good links
are on my main Linux page but some need to be
in TrinityOS.
[Section 5]
N Added a URL for Ethereal. An EXCELLENT
GUI network sniffer.
[Section 5]
N Fixed a missing ">" on line 139 of the
Sendlogs scripts. Thanks to [EMAIL PROTECTED]
for this one.
[Section 9]
Updated the TrinityOS-security.sh archive
too.
------------------
N 12/29/99 Updated the info in the Partition recovery
tools to denote which ones were Linux and
DOS utils. As it stands, I lost the
partition table on my laptop due to Dell's
new "Resume-from-Disk" feature that actually
OVER-WROTE my partition table. Grrrr..
[Section 51]
------------------
G 12/26/99 Updated the TrinityOS filewall to v3.45
- Added an explict filter for
unauthorized IPSEC VPNs
- reordered some input and output
filters for better enduser
customization.
G Updated the TrinityOS-security archive
G Its HIGH on my list to make the TrinityOS
ruleset modular. What this means is
when I update the ruleset, you won't have
to re-edit the ruleset itself. All
enduser configs that are specific to your
environment will be in a different config
file, something like
/etc/rc.d/rc.firewall.config
------------------
G 12/23/99 Updated the TrinityOS-security.tgz archive
- Updated the firewall to 3.43
- Fix the init.d directory to be in
the right place
- Updated the DHCPcd syntax
N Added a new "Completed" section on
"LILO / File System Recovery"
which is Section 51.
[Section 2]
N Cleaned up and expanded on the "Feature
section" of TrinityOS
[Section 3]
G Added a Feature section for "Recovery"
noting that TrinityOS covers recovery from
when your box was hacked into and the
recovery of LILO / File system problems.
[Section 3]
G Updated the rc.firewall to v3.43
- Updated the DHCPcd syntax in the
firewall ruleset
[Section 10]
G Updated the DHCPcd section to reflect the
newer DHCPcd syntax.
[Section 35]
I Added a whole new section on MBR, partition
table, and file system recovery and tools.
[Section 51]
------------------
N 12/22/99 Updated the URL for Robert Zeigler's
firewall site
[Section 5]
------------------
N 12/20/99 Updated the SSH alias in /etc/bashrc to
use a full path
[Section 30]
------------------
G 12/19/99 Added a URL to RPMLevel from the author
of RPMWatch. This tool might turn out
to be easier than AutoRPM.
[Section 5]
G Updated the IPCHAINS ruleset to v3.42
- Fixed a HUGE error of the text above
the /bin/sh line
- Cleaned up and added a few more ECHO
lines
[Section 10]
G Changed the method of loading of the
rc.firewall script to be more Redhat-ish.
To be specific, I created a
/etc/rc.d/init.d/firewall script instead
of the manual editing of
/etc/rc.d/init.d/network to load the
rc.firewall script.
[Section 10]
G Updated the TrinityOS-security archive to
TrinityOS-security-121999.tgz
- Added the new v3.42 ruleset
- Change the firewall to load after the
network comes up via the Redhat method
of /etc/rc.d/init.d/firewall
------------------
G 12/18/99 Added the URL for the ICQ kernel modules
and their versions. As it stands, there
is a new version for the 2.2.x kernels
that is greatly improved.
[Section 5]
N Updated the IPCHAINS ruleset to v3.41
- Added a commented section on setting
the TOS bits
- Added a recommendation for ICQ
users to change the UDP timeout
[Section 10]
------------------
N 12/16/99 Added URLs for WU-FTP
[Section 5]
N I've started adding Application and Game
URLs. Namely I've added the URL for
Xshipwars that looks VERY cool.
[Section 5]
I Added a new security warning about a root
exploit with HTDIG v3.1.x. Please note
this is NOT a standard install on Redhat.
This is for initially focused at Debian
users *if* it is installed.
[Section 10]
------------------
G 12/14/99 Updated the TrinityOS-security.tgz archive.
URL is above.
G Added the LogSurfer URL. This tool is
like Swatch but it understands states to
better detect attacks! Very cool!
[Section 5]
I Updated the rc.firewall ruleset to v3.40
- Added filters for the Trinoo
flooder
- fixed typos with commented
"echo" statements that were
missing the front "
[Section 10]
-------------------
N 12/11/99 Updated the PCMCIA URL]
[Section 5]
-------------------
N 11/30/99 - Fixed a typo that had "window 8192"
instead of "window 16384".
[Section 16]
---------------
.----------------------------------------------------------------------------.
| David A. Ranch - Linux/Networking/PC hardware [EMAIL PROTECTED] |
!---- ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'
_______________________________________________
Masq maillist - [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]
PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.