Re: non-root loopback crypto

2000-11-06 Thread Zak Kipling
On Mon, 6 Nov 2000, Mike Furr wrote: > I've been using the loopback crypto stuff for a while and I'm looking > for a secure way of doing this from my user account instead of having to > su to call losetup. > Does anyone have suggestions / experience with doing this? Add an entry such as: /home/u

Re: non-root loopback crypto

2000-11-06 Thread Zak Kipling
On Mon, 6 Nov 2000, Mike Furr wrote: > I've been using the loopback crypto stuff for a while and I'm looking > for a secure way of doing this from my user account instead of having to > su to call losetup. > Does anyone have suggestions / experience with doing this? Add an entry such as: /home/

non-root loopback crypto

2000-11-06 Thread Mike Furr
hi all, I've been using the loopback crypto stuff for a while and I'm looking for a secure way of doing this from my user account instead of having to su to call losetup. Does anyone have suggestions / experience with doing this? I see that you can't just run /sbin/losetup from non-root: $ losetu

Re: Problem with inetd and exim.

2000-11-06 Thread Nick Phillips
Petr Cech wrote: > > Is this really a good idea? Since the exim install does a fair bit of > > what is a not a good idea? Leaving it as it always was? Leaving tcpwrapper support out... As for default config, probably just "exim: ALL: severity mail.info: allow" or some such. There seem to be far

Re: Problem with inetd and exim.

2000-11-06 Thread Petr Cech
On Mon, Nov 06, 2000 at 09:11:45PM + , Nick Phillips wrote: > Petr Cech wrote: > > > > On Mon, Nov 06, 2000 at 09:29:01AM +0100 , Rolf Kutz wrote: > > > Hi, > > > > > > I have a Problem with inetd and exim. Exim is > > > triggert, although it is not listed in hosts.allow > > > and hosts.deny i

Re: Problem with inetd and exim.

2000-11-06 Thread Nick Phillips
Petr Cech wrote: > > On Mon, Nov 06, 2000 at 09:29:01AM +0100 , Rolf Kutz wrote: > > Hi, > > > > I have a Problem with inetd and exim. Exim is > > triggert, although it is not listed in hosts.allow > > and hosts.deny is All: All or All: All EXCEPT > > LOCAL. > > do you run exim via tcpd? Exim its

non-root loopback crypto

2000-11-06 Thread Mike Furr
hi all, I've been using the loopback crypto stuff for a while and I'm looking for a secure way of doing this from my user account instead of having to su to call losetup. Does anyone have suggestions / experience with doing this? I see that you can't just run /sbin/losetup from non-root: $ loset

Re: Problem with inetd and exim.

2000-11-06 Thread Nick Phillips
Petr Cech wrote: > > Is this really a good idea? Since the exim install does a fair bit of > > what is a not a good idea? Leaving it as it always was? Leaving tcpwrapper support out... As for default config, probably just "exim: ALL: severity mail.info: allow" or some such. There seem to be far

Re: Problem with inetd and exim.

2000-11-06 Thread Petr Cech
On Mon, Nov 06, 2000 at 09:11:45PM + , Nick Phillips wrote: > Petr Cech wrote: > > > > On Mon, Nov 06, 2000 at 09:29:01AM +0100 , Rolf Kutz wrote: > > > Hi, > > > > > > I have a Problem with inetd and exim. Exim is > > > triggert, although it is not listed in hosts.allow > > > and hosts.deny

Re: Problem with inetd and exim.

2000-11-06 Thread Nick Phillips
Petr Cech wrote: > > On Mon, Nov 06, 2000 at 09:29:01AM +0100 , Rolf Kutz wrote: > > Hi, > > > > I have a Problem with inetd and exim. Exim is > > triggert, although it is not listed in hosts.allow > > and hosts.deny is All: All or All: All EXCEPT > > LOCAL. > > do you run exim via tcpd? Exim it

Re: buffer overflow in pine <= 4.21

2000-11-06 Thread Ethan Benson
On Mon, Nov 06, 2000 at 09:54:03AM +0100, Thomas Gebhardt wrote: > > it should segfault. good indication of a buffer overflow there. > > While this kind of buffer overflow is nasty, (as far as I can see) > from a security point of view it is rather harmless. not if the program is question is se

Re: Configuring ssh

2000-11-06 Thread Ethan Benson
On Mon, Nov 06, 2000 at 12:08:17PM +0300, Alan KF LAU wrote: > My major concern is that if you enabled password authentication you'd > leave your system vulnerable to brute force password attacked as in > TELNET. > > Beside, if one could use password authentication, why would one bother > to take

Re: 'Generic' Firewall Rulesets?

2000-11-06 Thread Christopher Gahlon
He has a website with a firewall building tool that works pretty well. http://www.linux-firewall-tools.com/linux/firewall/index.html Chris Gahlon mikehaarman wrote: > There is an excellent book on just this topic by a fellow named Robert > L. Ziegler, published by New Riders and called Linux >

Re: buffer overflow in pine <= 4.21

2000-11-06 Thread Ethan Benson
On Mon, Nov 06, 2000 at 09:54:03AM +0100, Thomas Gebhardt wrote: > > it should segfault. good indication of a buffer overflow there. > > While this kind of buffer overflow is nasty, (as far as I can see) > from a security point of view it is rather harmless. not if the program is question is s

Re: Configuring ssh

2000-11-06 Thread Ethan Benson
On Mon, Nov 06, 2000 at 12:08:17PM +0300, Alan KF LAU wrote: > My major concern is that if you enabled password authentication you'd > leave your system vulnerable to brute force password attacked as in > TELNET. > > Beside, if one could use password authentication, why would one bother > to take

Re: Configuring ssh

2000-11-06 Thread Mark Janssen
On Mon, 6 Nov 2000, Karsten Mueller wrote: > > The latest version of CygWin toolkit contains OpenSSH 2.0pl1... > > along with all the other unix tools for win32... so you can just > > run ssh (including tunnels and other advanced features most term-emulators > > with ssh don't have) from your bash

Re: 'Generic' Firewall Rulesets?

2000-11-06 Thread Christopher Gahlon
He has a website with a firewall building tool that works pretty well. http://www.linux-firewall-tools.com/linux/firewall/index.html Chris Gahlon mikehaarman wrote: > There is an excellent book on just this topic by a fellow named Robert > L. Ziegler, published by New Riders and called Linux >

Re: Problem with inetd and exim.

2000-11-06 Thread Petr Cech
On Mon, Nov 06, 2000 at 11:13:40AM +0100 , Rolf Kutz wrote: > :( I use the slink defaults. It's triggert with > inetd: /usr/sbin/exim exim -bs, so I thought it > should do the job. > > So I have to recompile or call it via tcpd both will work, but the tcpd approach is easier :) > instead? > > -

Re: Configuring ssh

2000-11-06 Thread Tollef Fog Heen
* Alan KF LAU | Beside, if one could use password authentication, why would one bother | to take all the trouble setting up RSA connection? :) Using ssh-askpass and then having passwordless connections? I am probably not the only one on this list getting my mail by POP-over-SSH. -- Tollef Fo

Re: Configuring ssh

2000-11-06 Thread Mark Janssen
On Mon, 6 Nov 2000, Karsten Mueller wrote: > > The latest version of CygWin toolkit contains OpenSSH 2.0pl1... > > along with all the other unix tools for win32... so you can just > > run ssh (including tunnels and other advanced features most term-emulators > > with ssh don't have) from your bas

Re: Problem with inetd and exim.

2000-11-06 Thread Petr Cech
On Mon, Nov 06, 2000 at 09:29:01AM +0100 , Rolf Kutz wrote: > Hi, > > I have a Problem with inetd and exim. Exim is > triggert, although it is not listed in hosts.allow > and hosts.deny is All: All or All: All EXCEPT > LOCAL. do you run exim via tcpd? Exim itself is not compiled with tcpwrapers s

Re: Problem with inetd and exim.

2000-11-06 Thread Petr Cech
On Mon, Nov 06, 2000 at 11:13:40AM +0100 , Rolf Kutz wrote: > :( I use the slink defaults. It's triggert with > inetd: /usr/sbin/exim exim -bs, so I thought it > should do the job. > > So I have to recompile or call it via tcpd both will work, but the tcpd approach is easier :) > instead? > >

Problem with inetd and exim.

2000-11-06 Thread Rolf Kutz
Hi, I have a Problem with inetd and exim. Exim is triggert, although it is not listed in hosts.allow and hosts.deny is All: All or All: All EXCEPT LOCAL. Daemonmode is off, System is Slink. Tested is with telnet IP smtp. - Rolf

Re: Configuring ssh

2000-11-06 Thread Tollef Fog Heen
* Alan KF LAU | Beside, if one could use password authentication, why would one bother | to take all the trouble setting up RSA connection? :) Using ssh-askpass and then having passwordless connections? I am probably not the only one on this list getting my mail by POP-over-SSH. -- Tollef F

Re: Configuring ssh

2000-11-06 Thread Karsten Mueller
Hello Mark! > The latest version of CygWin toolkit contains OpenSSH 2.0pl1... > along with all the other unix tools for win32... so you can just > run ssh (including tunnels and other advanced features most term-emulators > with ssh don't have) from your bash shell. Nice to hear. I found nothing

Re: buffer overflow in pine <= 4.21

2000-11-06 Thread Thomas Gebhardt
Hi, > pine is riddled with buffer overflows, its considered unfixable > without totally throwing away 100% of the code and starting over. why > would anyone do that when we have mutt which is a far superior and > Free replacement. > > try this: > > (iirc) > > $ export HOME=3D`perl -e 'print "a

Re: Problem with inetd and exim.

2000-11-06 Thread Petr Cech
On Mon, Nov 06, 2000 at 09:29:01AM +0100 , Rolf Kutz wrote: > Hi, > > I have a Problem with inetd and exim. Exim is > triggert, although it is not listed in hosts.allow > and hosts.deny is All: All or All: All EXCEPT > LOCAL. do you run exim via tcpd? Exim itself is not compiled with tcpwrapers

Problem with inetd and exim.

2000-11-06 Thread Rolf Kutz
Hi, I have a Problem with inetd and exim. Exim is triggert, although it is not listed in hosts.allow and hosts.deny is All: All or All: All EXCEPT LOCAL. Daemonmode is off, System is Slink. Tested is with telnet IP smtp. - Rolf -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject o

Re: Configuring ssh

2000-11-06 Thread Karsten Mueller
Hello Mark! > The latest version of CygWin toolkit contains OpenSSH 2.0pl1... > along with all the other unix tools for win32... so you can just > run ssh (including tunnels and other advanced features most term-emulators > with ssh don't have) from your bash shell. Nice to hear. I found nothing

Re: buffer overflow in pine <= 4.21

2000-11-06 Thread Thomas Gebhardt
Hi, > pine is riddled with buffer overflows, its considered unfixable > without totally throwing away 100% of the code and starting over. why > would anyone do that when we have mutt which is a far superior and > Free replacement. > > try this: > > (iirc) > > $ export HOME=3D`perl -e 'print "