Re: icmp attack?

2002-11-09 Thread Phillip Hofmeister
On Sat, 09 Nov 2002 at 09:09:27AM -0600, Hanasaki JiJi wrote: > Anyone have an interpretation of the below? > [65.26.127.147] = firewall > [192.168.1.1] = firewall > its a two nic system > > Nov 2 10:04:49 ICMP message type destination unreachable - bad host > from mkc-65-26-127-147.kc.r

Chrooting named by default (was: Re: chrooting apache[ssl,php,perl] and some mta)

2002-11-09 Thread Vincent Bernat
OoO En cette nuit striée d'éclairs du samedi 09 novembre 2002, vers 02:02, Michael Ablassmeier <[EMAIL PROTECTED]> disait: > i did some apache chroot environment (php,perl,ssl), and now > some users want to use the php "mail" command, so i have to > include some mta into the chroot. > As far as i

Re: spamd config problems

2002-11-09 Thread Stephen Gran
This one time, at band camp, Hanasaki JiJi said: > I have installed the woody spam package on a woody box and cannot find > the config file to fix the below output in syslog. > > Can someone help out w/ this? > > Thanks > > Nov 9 08:13:16 portal spamd[1290]: Still running as root: user not >

Re: allowing X display from su'd environment

2002-11-09 Thread Matt Zimmerman
On Sat, Nov 09, 2002 at 05:00:23PM +0100, Michael Eyrich wrote: > On Sat, Nov 09, 2002 at 10:41:05AM -0500, Matt Zimmerman wrote: > | An easier wethod: > | > | $ su > | # export XAUTHORITY=~user/.Xauthority > > This won't work, if ~user is NFS-mounted with the > 'root_squash'-option, because 'no

Re: icmp attack?

2002-11-09 Thread Phillip Hofmeister
On Sat, 09 Nov 2002 at 09:09:27AM -0600, Hanasaki JiJi wrote: > Anyone have an interpretation of the below? > [65.26.127.147] = firewall > [192.168.1.1] = firewall > its a two nic system > > Nov 2 10:04:49 ICMP message type destination unreachable - bad host > from mkc-65-26-127-147.kc.r

Chrooting named by default (was: Re: chrooting apache[ssl,php,perl]and some mta)

2002-11-09 Thread Vincent Bernat
OoO En cette nuit striée d'éclairs du samedi 09 novembre 2002, vers 02:02, Michael Ablassmeier <[EMAIL PROTECTED]> disait: > i did some apache chroot environment (php,perl,ssl), and now > some users want to use the php "mail" command, so i have to > include some mta into the chroot. > As far as i

Re: spamd config problems

2002-11-09 Thread Stephen Gran
This one time, at band camp, Hanasaki JiJi said: > I have installed the woody spam package on a woody box and cannot find > the config file to fix the below output in syslog. > > Can someone help out w/ this? > > Thanks > > Nov 9 08:13:16 portal spamd[1290]: Still running as root: user not >

Re: allowing X display from su'd environment

2002-11-09 Thread Michael Eyrich
On Sat, Nov 09, 2002 at 10:41:05AM -0500, Matt Zimmerman wrote: | On Sat, Nov 09, 2002 at 12:40:12PM +0700, Jean Christophe ANDR? wrote: | | > Matt Zimmerman ?crivait : | > > This disables access control in the X server. This is, almost always, a | > > very bad idea. | > | > A better way to allo

Re: allowing X display from su'd environment

2002-11-09 Thread Matt Zimmerman
On Sat, Nov 09, 2002 at 12:40:12PM +0700, Jean Christophe ANDR? wrote: > Matt Zimmerman ?crivait : > > This disables access control in the X server. This is, almost always, a > > very bad idea. > > A better way to allow it (when you switch from normal to root user) : > > [EMAIL PROTECTED]:~$

spamd config problems

2002-11-09 Thread Hanasaki JiJi
I have installed the woody spam package on a woody box and cannot find the config file to fix the below output in syslog. Can someone help out w/ this? Thanks Nov 9 08:13:16 portal spamd[1290]: Still running as root: user not specified, not found, or set to root. Fall back to nobody.

icmp attack?

2002-11-09 Thread Hanasaki JiJi
Anyone have an interpretation of the below? [65.26.127.147] = firewall [192.168.1.1] = firewall its a two nic system Nov 2 10:04:49 ICMP message type destination unreachable - bad host from mkc-65-26-127-147.kc.rr.com [65.26.127.147] (65.26.127.147->65.26.127.147) Nov 2 20:47:36 I

Re: allowing X display from su'd environment

2002-11-09 Thread Matt Zimmerman
On Sat, Nov 09, 2002 at 05:00:23PM +0100, Michael Eyrich wrote: > On Sat, Nov 09, 2002 at 10:41:05AM -0500, Matt Zimmerman wrote: > | An easier wethod: > | > | $ su > | # export XAUTHORITY=~user/.Xauthority > > This won't work, if ~user is NFS-mounted with the > 'root_squash'-option, because 'no

Re: chrooting apache[ssl,php,perl] and some mta

2002-11-09 Thread Michael Ablassmeier
On Sat, Nov 09, 2002 at 12:32:40AM -0200, Henrique de Moraes Holschuh wrote: > You could have a proper MTA outside the chroots (like postfix or exim). And > a bogus, stupid, cat-it-to-localhost-port-25 MTA inside the chroot, like > ssmtp :-) ok, i did it your way and in it works fine. Thanks. -- g

Re: allowing X display from su'd environment

2002-11-09 Thread Michael Eyrich
On Sat, Nov 09, 2002 at 10:41:05AM -0500, Matt Zimmerman wrote: | On Sat, Nov 09, 2002 at 12:40:12PM +0700, Jean Christophe ANDR? wrote: | | > Matt Zimmerman ?crivait : | > > This disables access control in the X server. This is, almost always, a | > > very bad idea. | > | > A better way to allo

Re: allowing X display from su'd environment

2002-11-09 Thread Matt Zimmerman
On Sat, Nov 09, 2002 at 12:40:12PM +0700, Jean Christophe ANDR? wrote: > Matt Zimmerman ?crivait : > > This disables access control in the X server. This is, almost always, a > > very bad idea. > > A better way to allow it (when you switch from normal to root user) : > > test@localhost:~$ su

Re: su and x (was Re: XFree86 4.2 bug in Debian Testing)

2002-11-09 Thread Christian Jaeger
Try http://fgouget.free.fr/sux/sux-readme.shtml chj

spamd config problems

2002-11-09 Thread Hanasaki JiJi
I have installed the woody spam package on a woody box and cannot find the config file to fix the below output in syslog. Can someone help out w/ this? Thanks Nov 9 08:13:16 portal spamd[1290]: Still running as root: user not specified, not found, or set to root. Fall back to nobody. -- To

su and x (was Re: XFree86 4.2 bug in Debian Testing)

2002-11-09 Thread Martin Fluch
On Sat, 9 Nov 2002, Jörg Schütter wrote: > On Sat, 9 Nov 2002 13:36:25 +0200 (EET) > Martin Fluch <[EMAIL PROTECTED]> wrote: > > > On Sat, 9 Nov 2002, Rick Moen wrote: > > > > > It's a little simpler to do: > > > > > > $ ssh -X [EMAIL PROTECTED] > > > > Even easier: the following lines in the

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Jörg Schütter
On Sat, 9 Nov 2002 13:36:25 +0200 (EET) Martin Fluch <[EMAIL PROTECTED]> wrote: > > > > On Sat, 9 Nov 2002, Rick Moen wrote: > > > It's a little simpler to do: > > > > $ ssh -X [EMAIL PROTECTED] > > Even easier: the following lines in the /root/.bashrc do the same trick: > > if [ ! "$LOGNAM

icmp attack?

2002-11-09 Thread Hanasaki JiJi
Anyone have an interpretation of the below? [65.26.127.147] = firewall [192.168.1.1] = firewall its a two nic system Nov 2 10:04:49 ICMP message type destination unreachable - bad host from mkc-65-26-127-147.kc.rr.com [65.26.127.147] (65.26.127.147->65.26.127.147) Nov 2 20:47:36 ICMP messa

Re: chrooting apache[ssl,php,perl] and some mta

2002-11-09 Thread Emmanuel Lacour
On Sat, Nov 09, 2002 at 03:48:39AM +0100, Michael Ablassmeier wrote: > On Sat, Nov 09, 2002 at 12:32:40AM -0200, Henrique de Moraes Holschuh wrote: > > > > You could have a proper MTA outside the chroots (like postfix or exim). And > > a bogus, stupid, cat-it-to-localhost-port-25 MTA inside the ch

Re: chrooting apache[ssl,php,perl] and some mta

2002-11-09 Thread Michael Ablassmeier
On Sat, Nov 09, 2002 at 12:32:40AM -0200, Henrique de Moraes Holschuh wrote: > You could have a proper MTA outside the chroots (like postfix or exim). And > a bogus, stupid, cat-it-to-localhost-port-25 MTA inside the chroot, like > ssmtp :-) ok, i did it your way and in it works fine. Thanks. -- g

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Martin Fluch
On Sat, 9 Nov 2002, Rick Moen wrote: > > [EMAIL PROTECTED]:~$ su > > Password: > > [EMAIL PROTECTED]:/home/mfluch> export XAUTHORITY=/home/mfluch/.Xauthority > > [EMAIL PROTECTED]:/home/mfluch> > > > > ...and then every X application works just as before as the normal user. > > It's a litt

Re: su and x (was Re: XFree86 4.2 bug in Debian Testing)

2002-11-09 Thread Christian Jaeger
Try http://fgouget.free.fr/sux/sux-readme.shtml chj -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

su and x (was Re: XFree86 4.2 bug in Debian Testing)

2002-11-09 Thread Martin Fluch
On Sat, 9 Nov 2002, Jörg Schütter wrote: > On Sat, 9 Nov 2002 13:36:25 +0200 (EET) > Martin Fluch <[EMAIL PROTECTED]> wrote: > > > On Sat, 9 Nov 2002, Rick Moen wrote: > > > > > It's a little simpler to do: > > > > > > $ ssh -X root@localhost > > > > Even easier: the following lines in the /ro

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Jörg Schütter
On Sat, 9 Nov 2002 13:36:25 +0200 (EET) Martin Fluch <[EMAIL PROTECTED]> wrote: > > > > On Sat, 9 Nov 2002, Rick Moen wrote: > > > It's a little simpler to do: > > > > $ ssh -X root@localhost > > Even easier: the following lines in the /root/.bashrc do the same trick: > > if [ ! "$LOGNAME"

Re: chrooting apache[ssl,php,perl] and some mta

2002-11-09 Thread Emmanuel Lacour
On Sat, Nov 09, 2002 at 03:48:39AM +0100, Michael Ablassmeier wrote: > On Sat, Nov 09, 2002 at 12:32:40AM -0200, Henrique de Moraes Holschuh wrote: > > > > You could have a proper MTA outside the chroots (like postfix or exim). And > > a bogus, stupid, cat-it-to-localhost-port-25 MTA inside the ch

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Rick Moen
Quoting Martin Fluch ([EMAIL PROTECTED]): > Indeed. Therefore I use > > [EMAIL PROTECTED]:~$ su > Password: > [EMAIL PROTECTED]:/home/mfluch> export XAUTHORITY=/home/mfluch/.Xauthority > [EMAIL PROTECTED]:/home/mfluch> > > ...and then every X application works just as before as the normal use

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Martin Fluch
> > I am using woody + testing + some unstable: > > > > in xterm/gnome-terminal usually I do (as normal user) > > xhost + > > This disables access control in the X server. This is, almost always, > a very bad idea. Indeed. Therefore I use [EMAIL PROTECTED]:~$ su Password: [EMAIL PROTECTED]:/h

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Martin Fluch
On Sat, 9 Nov 2002, Rick Moen wrote: > > mfluch@seneca:~$ su > > Password: > > root@seneca:/home/mfluch> export XAUTHORITY=/home/mfluch/.Xauthority > > root@seneca:/home/mfluch> > > > > ...and then every X application works just as before as the normal user. > > It's a little simpler to do

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Rick Moen
Quoting Martin Fluch ([EMAIL PROTECTED]): > Indeed. Therefore I use > > mfluch@seneca:~$ su > Password: > root@seneca:/home/mfluch> export XAUTHORITY=/home/mfluch/.Xauthority > root@seneca:/home/mfluch> > > ...and then every X application works just as before as the normal user. It's a littl

Re: XFree86 4.2 bug in Debian Testing

2002-11-09 Thread Martin Fluch
> > I am using woody + testing + some unstable: > > > > in xterm/gnome-terminal usually I do (as normal user) > > xhost + > > This disables access control in the X server. This is, almost always, > a very bad idea. Indeed. Therefore I use mfluch@seneca:~$ su Password: root@seneca:/home/mfluch