/* HINT: Search archives @ http://www.indyramp.com/masq/ before posting! */


Hey Everyone,

Lots of changes and some SERIOUS security issues covered. 

399 users on the Updates list and counting!!!


Ok, first, here are the changes posted to my site from the 
main page's "Top 10" since the last update sent out on 
2/21/00:

--
03/19/00
        Updated TrinityOS and the TrinityOS archive

03/18/00
        Updated TrinityOS and the TrinityOS archive

03/18/00
        Updated the Internet retailers URL on the CD-R page

02/21/00
        Updated TrinityOS, including new firewall rulesets, 
        archive, etc

        Updated the IP Masq HOWTO to v1.82

01/24/00
        Updated TrinityOS, posted a 01/03/00 TrinityOS port 
        to .doc and .pdf, and updated function.s 

01/17/00
        Updated TrinityOS and the TrinityOS-security archive 
        as well 

        Updated the CD Writer page to add clarifications of 
        CD writer formats and issues with different colored 
        blank CD media.

01/02/00
        Updated TrinityOS and the archive as well

01/02/00
        Added PS, PDF, and a TGZ archive of the IP-Masq HOWTO v1.80 


Here are all the changes to TrinityOS...


--
I       3/27/00 Updated the IPCHAINS firewall to v3.55
        *Sent
        Update* Deleted the text from the IPCHAINS firewall 
                        ruleset and the DHCPcd section:
                        --
                        #******************************************
                        # ABSOLUTELY CRITICAL:  If you run the 
                        # /etc/dhcpcd/dhcpcd-ethX.exe file (needed 
                        # for DHCP'ed DSL and cablemodem users), 
                        # you CANNOT also enable the 
                        # /etc/rc.d/init.d/firewall script below.
                      #******************************************
                        --

                        The reason for this is that the firewall 
                        script file WON'T be executed if the old IP 
                        address for the machine was the same after 
                        reboot.  So, you need to have:

                                Redhat:    the /etc/rc.d/init.d/firewall 
                                                script activated

                                Slackware: have the /etc/rc.d/rc.local 
                                        script load the /etc/rc.d/rc.firewall
                                        ruleset.


                        Please NOTE:
                        ------------

                                I think there still might be some 
                                issues with this setup.  The problem
                                stems around the fact that the 
                                rc.firewall might get loaded from both
                                dhcpcd's /etc/dhcpcd/dhcpcd-ethX.exe AND               
                 /etc/rc.d/init.d/firewall.
I'm still 
                                looking into this and if you have any 
                                comments on this, I'd love to hear 
                                from you.

                        [Section 10 and 35]


*C*                     There are -6- new security vunerabilities 
                        for Linux that depends on the distro you 
                        are running.  Check out this section ASAP!!
                        [Section 60]

G                       Updated the TrinityOS archive script to 
                        reflect the DHCPcd issues.

------------------

N       3/25/00 Updated the SSH Url
                        [Section 3]

N                       Fixed a typo where I was calling the 
                        "Dial-In Server HOWTO" the "Dial-UP" 
                        server HOWTO.
                        [Section 5]

G                       Updated the IPCHAINS firewall to 3.54
                                - Added filters for the new 
                                "Shaft" DDos tools
                        [Section 10]

------------------

I       03/20/00        Found a typo in the /usr/lib/sendmail-cf/cf/trinityos.mc 
                        file.  Changed "confSTMP" to "confSMTP".  
                        Thanks to [EMAIL PROTECTED] for this one.
                        [Section 25]

------------------

*C*     03/19/00        I -thought- I solved all the DHCPcd 
                        issues but it sounds like DHCP users 
                        cannot run both the /etc/rc.d/init.d/firewall 
                        and the /etc/dhcpcd/dhcpcd-eth0.exe file.  
                        This yeilds BAD results.  I have added comments 
                        to make DHCP users aware of this in both the
                        IPCHAINS firewall and the DHCP sections.
                        [Section 10, 35]

                        I have changed the enabling the 
                        /etc/rc.d/init.d/firewall script
                        from AutoFix to Userfix in the TrinityOS 
                        archive script.

------------------

I       03/18/00        Added a top section to clarify why TrinityOS 
                        is both Trademarked and Copyrighted:

                        --
                      Sorry for all the legal stuff...

                      Yet I've already had one company try 
                        to have the name TrinityOS taken from 
                        me and one HOWTO author has already 
                        ripped off MUCH of TrinityOS's content 
                        though it was re-written to avoid and 
                        direct copyright issue.  I'm just 
                        covering my butt here from the many 
                        lowlifes in the world.
                        --
                        [Intro]

N                       Updated the URL for Diald
                        Thanks to [EMAIL PROTECTED] for this one.
                        [Section 5]

N                       Tripwire has gone OpenSource for Linux!  
                        Woohoo!  They have also released a version 
                        that runs on Glibc.  I've updated the 
                        Tripwire section with all the new URLs.
                        Thanks to [EMAIL PROTECTED] for this one.
                        [Section 5]

N                       Added a few URLs for PPPoE
                        [Section 5]

N                       Added a few URLs for PPTP and Encrypted 
                        PPTP VPNs
                        [Section 5]

G                       Added a URL to Robert Gram's FAQ on how 
                        to understand what Firewall logs mean.
                        [Section 5]

N                       Added a URL for Linux Real Time Messangers 
                        (ICQ, AIM, etc)
                        [Section 5]

N                       Deleted the reference to /etc/localhosts.  
                        This is OLD stuff. Thanks to [EMAIL PROTECTED] 
                        for this one.
                        [Section 7]

G                       Fixed the permission setting locations of 
                        klogd and syslogd.
                        Thanks to [EMAIL PROTECTED] for this one.
                        [Section 8]

G                       Updated the IPCHAINS rc.firewall ruleset to v3.52

                # v3.52 - 03/18/00
                #     - Finally found a 100% solution for 
                #       DHCPcd users out there that get DHCP'ed 
                #       IP addresses on their external INTERFACE.  
                #       Changes in the firewall ruleset is only 
                #       the DELETION of comments in the top 
                #       section to then refer users to the DHCPcd 
                #       section in TrinityOS for full details 
                #       (as it should be to minimize confusion).
                #
                #           The syntax "dhcpcd -D -H $EXTINT                    
                #             etc/rc.d/rc.firewall" was WRONG.
                #
                #     - Moved the PORTFW variabled to be below 
                #       the SECUREHOST section for clarity.
                #
                #     - Added some comments for PORTFW users 
                #       on how to allow portfw access to explict 
                #       hosts and/or networks.
                #
                #     - Added two more PORFWIP variabless to 
                #       the IPCHAINS ruleset
                #
                #     - Moved the PORFW section from the INPUT 
                #       section to the FORWARDing section for 
                #       better clarity
                #
                #     - Added a section in the general INPUT 
                #       section for Squid w/ JunkBuster.
                #
                #     - Expanded on the DoubleClick filtering 
                #       example with network numbers from 
                #       [EMAIL PROTECTED]
                #
                #       Thanks to [EMAIL PROTECTED] for helping 
                #     troubleshoot this for me.
                #       [Section 10]
                #

G                       Deleted an extra "#" from the 
                        /etc/rc.d/init.d/firewall script that 
                        kept it running with Linuxconf.
                        Thanks to [EMAIL PROTECTED] for catching 
                        this one.
                        [Section 10]

G                       Updated the IPFWADM rc.firewall ruleset 
                        to v2.97

                        # v2.97 - Deleted the DHCPcd commands as 
                        #         the syntax was old an misleading.  
                        #         Update to IPCHAINS for a far 
                        #         superior firewall ruleset.
                        [Section 10]

G                       Added a recommendation for users to 
                        check out Robert Gram's Firewall hit
                        FAQ to understand what their firewall 
                        logs really mean.
                        [Section 10]

I                       Finally found the proper solution to get 
                        users that use DHCPcd on their external 
                        interfaces to re-run the rc.firewall 
                        ruleset upon a lease renew.
                        [Section 35]

I                       Updates to the TrinityOS archives:

                        - Fixed the permission setting locations 
                        of klogd and syslogd
                        Thankd to [EMAIL PROTECTED] for catching 
                        this.

                        - Fixed an error in the TrinityOS archive 
                          where chkconfig was enabling "network" 
                          instead of "firewall" in the various 
                          /etc/rc.d/rc.Xd dirs.
                          Thanks to [EMAIL PROTECTED] for catching 
                          this one.

                        - Updated the firewall to v3.52

-----------------

N       03/13/00        Added the URL for the DHCPcd homepage
                        [Section 5]

-----------------

N       03/05/00        [EMAIL PROTECTED] informed me that the 
                        Trinity site, the first nuclear test 
                        site, wasn't in Nevada but White Planes, 
                        New Mexico.  Thanks James!

N                       Updated the rc.firewall ruleset to v3.51 
                        - Removed a duplicate input filter for spoofed 
                          packets, etc. Interestingly enough, 
                          trinityos.wri didn't have the duped line.
                        Thanks to [EMAIL PROTECTED] for the sharp eye.
                        [Section 10]

N                       Updated the TrinityOS archive

------------------

N       02/29/00        Updated the proceedures for installing 
                         Sendmail manually.  Before I did:

                        cp /usr/src/archive/sendmail/sendmail-x.x.x/                   
 /usr/lib/sendmail-cf

                        now it is:

                        mkdir /usr/lib/sendmail-cf
                        tar cpf - /usr/src/archive/sendmail/sendmail-x.x.x/* | (cd
/usr/lib/sendmail-cf; tar xvpf -)

                        This fixes an issue where the 
                        /usr/lib/sendmail-cf dir isn't already 
                        present or when its on the same file 
                        system.  Thanks to [EMAIL PROTECTED] for 
                        bringing this to my attention.
                        [Section 25]

------------------

N       02/26/99        Updated the IPCHAINS rc.firewall to v3.50

                        - Fixed a minor error in the commented 
                        Diald line were the $INTLAN variable needed 
                        to have the extra "/24" deleted.  Thanks to 
                        [EMAIL PROTECTED] for reporting this.
                        [Section 10]

G                       Fixed a missing "fi" statement in the 
                        TrinityOS-security.sh script that
                        would kill it after the PPP section.

------------------

.----------------------------------------------------------------------------.
|  David A. Ranch - Linux/Networking/PC hardware         [EMAIL PROTECTED]  |
!----                                                                    ----!
`----- For more detailed info, see http://www.ecst.csuchico.edu/~dranch -----'


_______________________________________________
Masq maillist  -  [EMAIL PROTECTED]
Admin requests can be handled at http://www.indyramp.com/masq-list/ -- THIS INCLUDES 
UNSUBSCRIBING!
or email to [EMAIL PROTECTED]

PLEASE read the HOWTO and search the archives before posting.
You can start your search at http://www.indyramp.com/masq/
Please keep general linux/unix/pc/internet questions off the list.

Reply via email to