Re: clamav and magic byte

2005-11-02 Thread Florian Weimer
* Geoff Crompton: > Anyone know if clamav is vulnerable to the magic byte detection evasion > issue discussed at http://www.securityfocus.com/bid/15189? > > Or alternatively, can anyone work out if it is vulnerable? It is vulnerable only in the sense that it doesn't detect viruses for which there

clamav and magic byte

2005-11-02 Thread Geoff Crompton
Anyone know if clamav is vulnerable to the magic byte detection evasion issue discussed at http://www.securityfocus.com/bid/15189? Or alternatively, can anyone work out if it is vulnerable? -- Geoff Crompton Debian System Administrator Strategic Data +61 3 9340 9000 -- To UNSUBSCRIBE, email to

Re: whitehat

2005-11-02 Thread alex black
Perhaps I should rephrase: Is there any company or individual on this list that provides penetration testing services, can provide a sample report and sample engagement contract with specific terms, has performed penetration testing on debian servers running public-facing applications in the

Re: whitehat

2005-11-02 Thread Alvin Oga
hi ya alex - lots of options .. too too too many ... but bottom line ... you have to do the work .. not the outside white-hat you're looking for On Wed, 2 Nov 2005, alex black wrote: > Not much, frankly. The idea here is to have someone that is not > malicious, but is skilled, to attempt

Re: whitehat to test a security config

2005-11-02 Thread Bernd Eckenfels
In article <[EMAIL PROTECTED]> you wrote: > I'm looking for (preferably) a company, or individual, to attempt to > breach a standard config I have created to deploy client applications > in production. It is intentionally a minimal config which is tightly > locked down and audited daily. I thin

Patrina Graham?

2005-11-02 Thread keith
Hello, My name is Keith Smith. I seek info on debt transfer and debt termination. Can you assist me? Thanks Keith Smith 240 353-7893 BlackBerry service provided by Nextel -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: whitehat

2005-11-02 Thread alex black
--- Alvin Oga <[EMAIL PROTECTED]> wrote: > questions for you > - what else is in the goals for the security test, > where i'm not > using audit, pen-test, assessments and other > "security words" Just to see if you can get in, that's all. > - what is the consequence if some > whitehat/grayhat/

Re: [SECURITY] [DSA 879-1] New gallery packages fix privilege escalation

2005-11-02 Thread Michael Schultheiss
Norbert Tretkowski wrote: > * Martin Schulze wrote: > > A bug in gallery has been discoverd that grants all registrated > > postnuke users full access to the gallery. > > Huh? This bugs is with regards to the integration of Gallery into a Postnuke site. --

Re: whitehat to test a security config

2005-11-02 Thread Rob Burgers
- Original Message - From: "Harry" <[EMAIL PROTECTED]> To: <> Sent: Tuesday, November 01, 2005 10:48 AM Subject: Re: whitehat to test a security config --- Alvin Oga <[EMAIL PROTECTED]> wrote: questions for you - what else is in the goals for the security test, where i'm not usin

Re: [SECURITY] [DSA 879-1] New gallery packages fix privilege escalation

2005-11-02 Thread Jose Marrero
Why every gallery update breaks the customizations one has done to it? I am referring to skins, headers, etc. On Wed, November 2, 2005 6:01 am, Norbert Tretkowski said: > * Martin Schulze wrote: >> A bug in gallery has been discoverd that grants all registrated >> postnuke users full access to th

Re: [SECURITY] [DSA 879-1] New gallery packages fix privilege escalation

2005-11-02 Thread Emmanuel Lacour
On Wed, Nov 02, 2005 at 03:01:54PM +0100, Norbert Tretkowski wrote: > * Martin Schulze wrote: > > A bug in gallery has been discoverd that grants all registrated > > postnuke users full access to the gallery. > > Huh? > Gallery can be easily embedded in postnuke, phpnike, mambo, ... --

Re: [SECURITY] [DSA 879-1] New gallery packages fix privilege escalation

2005-11-02 Thread Norbert Tretkowski
* Martin Schulze wrote: > A bug in gallery has been discoverd that grants all registrated > postnuke users full access to the gallery. Huh? Norbert -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Unknown sevice runing on debian machin

2005-11-02 Thread TOPMANN (Torben Pollmann)
[EMAIL PROTECTED] wrote: [EMAIL PROTECTED] wrote: plese help me stop this scrvice PID USER PR NI VIRT RES SHR S %CPU %MEMTIME+ COMMAND 2284 debuser 16 0 51144 10m 48m S 41.0 4.2 110:14.86 amor kill -9 2284 ? but apt-cache search amor says : amor - a KDE creature