Re: debian sarge, rkhunter, pd-admin

2008-03-22 Thread Dimitar Dobrev
Sorry it has nothing to do with pd admin, the output is also the same on other "plain" sarge boxes. Rkhunter does not exist in the apt repository of sarge so i install the last stable version this way on such boxes: installer.sh --layout /usr/local --install ... so the question becomes more

Re: [SECURITY] [DSA 1517-1] New ldapscripts packages fix information disclosure

2008-03-22 Thread Harrie
Harrie wrote: [snip] Sorry, I replied to the list, which wasn't appropriet, it was ment for someone else. I'm really sorry. -- Regards, Harrie -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1517-1] New ldapscripts packages fix information disclosure

2008-03-22 Thread Harrie
Thijs Kinkhorst wrote: Don Armstrong discovered that ldapscripts, a suite of tools to manipulate user accounts in LDAP, sends the password as a command line argument when calling LDAP programs, which may allow a local attacker to read this password from the process listing. "BOFH" discovered t