Re: How can I help ?

2000-06-15 Thread Nate Duehr
On Wed, Jun 14, 2000 at 02:43:07PM +0200, Wichert Akkerman wrote: > A good free reimplementation of portsentry is something I would really > like to see. Right now portsentry works reasonably, but it could really > use a bunch of extra features. Can't snort do almost everything portsentry does if

Re: [Q] intrusion

2000-06-15 Thread Petr Cech
On Thu, Jun 15, 2000 at 11:00:12AM -0500 , [EMAIL PROTECTED] wrote: > Hello, > I found on my machine the following message one morning: > > PAM_UNIX[763]: (su) session opened for user www-data by (uid=0) > su [821]: + ??? root-nobody > > PAM_UNIX[821]: (su) session opened for user nobody by (uid=

Re: How can I help ?

2000-06-15 Thread Nate Duehr
On Wed, Jun 14, 2000 at 02:43:07PM +0200, Wichert Akkerman wrote: > A good free reimplementation of portsentry is something I would really > like to see. Right now portsentry works reasonably, but it could really > use a bunch of extra features. Can't snort do almost everything portsentry does if

Re: [Q] intrusion

2000-06-15 Thread Petr Cech
On Thu, Jun 15, 2000 at 11:00:12AM -0500 , [EMAIL PROTECTED] wrote: > Hello, > I found on my machine the following message one morning: > > PAM_UNIX[763]: (su) session opened for user www-data by (uid=0) > su [821]: + ??? root-nobody > > PAM_UNIX[821]: (su) session opened for user nobody by (uid

Re: [Q] intrusion

2000-06-15 Thread Michael Wuertz
> PAM_UNIX[763]: (su) session opened for user www-data by (uid=0) > su [821]: + ??? root-nobody > > PAM_UNIX[821]: (su) session opened for user nobody by (uid=0) > anymore (I do assume that it is an intrusion attack, > unless there is a much simpler explanation for this). No intrusion. It's ju

[Q] intrusion

2000-06-15 Thread pvlad
Hello, I found on my machine the following message one morning: PAM_UNIX[763]: (su) session opened for user www-data by (uid=0) su [821]: + ??? root-nobody PAM_UNIX[821]: (su) session opened for user nobody by (uid=0) This is the first time it happened and since then I upgraded to the latest un

Re: [Q] intrusion

2000-06-15 Thread Michael Wuertz
> PAM_UNIX[763]: (su) session opened for user www-data by (uid=0) > su [821]: + ??? root-nobody > > PAM_UNIX[821]: (su) session opened for user nobody by (uid=0) > anymore (I do assume that it is an intrusion attack, > unless there is a much simpler explanation for this). No intrusion. It's j

[Q] intrusion

2000-06-15 Thread pvlad
Hello, I found on my machine the following message one morning: PAM_UNIX[763]: (su) session opened for user www-data by (uid=0) su [821]: + ??? root-nobody PAM_UNIX[821]: (su) session opened for user nobody by (uid=0) This is the first time it happened and since then I upgraded to the latest u

Re: How can I help ?

2000-06-15 Thread Wichert Akkerman
Previously Guido Guenther wrote: > According to upstream we can't hope that he will put portsentry under a > license which debian considers as free in the near future so a free > reimplementation would be great. Portsentry is a nice peace of software > but it's missing some crucial features such as

Re: How can I help ?

2000-06-15 Thread Wichert Akkerman
Previously Alexander Hvostov wrote: > Where might I find this? http://www.msu.ru/pniam/pniam.html ftp://ftp.nc.orc.ru/pub/Linux/pniam/pniam-0.02.tgz Wichert. -- / Generally uninteresting signature - ignore at

Re: How can I help ?

2000-06-15 Thread Wichert Akkerman
Previously Guido Guenther wrote: > According to upstream we can't hope that he will put portsentry under a > license which debian considers as free in the near future so a free > reimplementation would be great. Portsentry is a nice peace of software > but it's missing some crucial features such a

Re: How can I help ?

2000-06-15 Thread Wichert Akkerman
Previously Alexander Hvostov wrote: > Where might I find this? http://www.msu.ru/pniam/pniam.html ftp://ftp.nc.orc.ru/pub/Linux/pniam/pniam-0.02.tgz Wichert. -- / Generally uninteresting signature - ignore at