Re: Unable to gain access to secure sites.

2001-05-16 Thread Alexander Hvostov
On Wed, 16 May 2001 12:53:50 +0600 Igor Goldenberg <[EMAIL PROTECTED]> wrote: > On Tue, May 15, 2001 at 10:04:07PM -0700, Alexander Hvostov wrote: > > > Note that my MUA, Sylpheed, was moved from main to non-US in the last > > upgrade, > > since the maintainer dec

Re: Unable to gain access to secure sites.

2001-05-16 Thread Alexander Hvostov
On Wed, 16 May 2001 12:53:50 +0600 Igor Goldenberg <[EMAIL PROTECTED]> wrote: > On Tue, May 15, 2001 at 10:04:07PM -0700, Alexander Hvostov wrote: > > > Note that my MUA, Sylpheed, was moved from main to non-US in the last upgrade, > > since the maintainer decided t

Re: Unable to gain access to secure sites.

2001-05-16 Thread Alexander Hvostov
On 15 May 2001 21:58:40 -0700 [EMAIL PROTECTED] (Thomas Bushnell, BSG) wrote: > Peter Cordes <[EMAIL PROTECTED]> writes: > > > It should be possible with netscape. Mozilla in Debian is not making much > > progress, because the maintainer doesn't want to do anything until someone > > decides whe

Re: Unable to gain access to secure sites.

2001-05-15 Thread Alexander Hvostov
On 15 May 2001 21:58:40 -0700 [EMAIL PROTECTED] (Thomas Bushnell, BSG) wrote: > Peter Cordes <[EMAIL PROTECTED]> writes: > > > It should be possible with netscape. Mozilla in Debian is not making much > > progress, because the maintainer doesn't want to do anything until someone > > decides wh

Re: rpc.statd

2001-04-08 Thread Alexander Hvostov
On Sun, 8 Apr 2001 18:04:54 -0400 "Robert Bartels" <[EMAIL PROTECTED]> wrote: > I saw this in my logs today. > > Apr 8 15:08:43 mikado rpc.statd[179]: gethostbyname error for > ^X÷ÿ¿^X÷ÿ¿^Y÷ÿ¿^Y÷ÿ¿^Z÷ÿ¿^Z÷ÿ¿^[÷ÿ¿^[÷ÿ¿%8x%8x%8x%8x%8x%8x%8x%8x%8x%236x%n%1 > 37x%n%10x%n%192x%n\220\220\220\220\220\2

Re: rpc.statd

2001-04-08 Thread Alexander Hvostov
On Sun, 8 Apr 2001 18:04:54 -0400 "Robert Bartels" <[EMAIL PROTECTED]> wrote: > I saw this in my logs today. > > Apr 8 15:08:43 mikado rpc.statd[179]: gethostbyname error for > ^X÷ÿ¿^X÷ÿ¿^Y÷ÿ¿^Y÷ÿ¿^Z÷ÿ¿^Z÷ÿ¿^[÷ÿ¿^[÷ÿ¿%8x%8x%8x%8x%8x%8x%8x%8x%8x%236x%n%1 > 37x%n%10x%n%192x%n\220\220\220\220\220\

Re: UDP Port 1035

2001-04-07 Thread Alexander Hvostov
On 07 Apr 2001 09:34:44 +0200 Berend De Schouwer <[EMAIL PROTECTED]> wrote: > On 07 Apr 2001 01:27:54 -0700, Tim Uckun wrote: > > What service runs on UDP port 1035? I did not see it in /etc/services and > > netstat says that it's active along with tcp 1 and 6 (and others but I know > > those).

Re: UDP Port 1035

2001-04-07 Thread Alexander Hvostov
On 07 Apr 2001 09:34:44 +0200 Berend De Schouwer <[EMAIL PROTECTED]> wrote: > On 07 Apr 2001 01:27:54 -0700, Tim Uckun wrote: > > What service runs on UDP port 1035? I did not see it in /etc/services and > > netstat says that it's active along with tcp 1 and 6 (and others but I know > > those).

Re: Applications using Linux capabilities

2001-03-24 Thread Alexander Hvostov
On Sat, 24 Mar 2001 01:14:31 -0900 Ethan Benson <[EMAIL PROTECTED]> wrote: > On Sat, Mar 24, 2001 at 12:39:03AM -0500, Daniel Jacobowitz wrote: > > > > Vsftpd does, too. > > i have read GnuPG has code to use a capability to allocate secure > memory instead of using suid, but its only really usefu

Re: Applications using Linux capabilities

2001-03-24 Thread Alexander Hvostov
On Sat, 24 Mar 2001 01:14:31 -0900 Ethan Benson <[EMAIL PROTECTED]> wrote: > On Sat, Mar 24, 2001 at 12:39:03AM -0500, Daniel Jacobowitz wrote: > > > > Vsftpd does, too. > > i have read GnuPG has code to use a capability to allocate secure > memory instead of using suid, but its only really usef

Re: Something Wicked happened! 001a.

2001-03-24 Thread Alexander Hvostov
On Fri, 23 Mar 2001 22:23:59 -0800 Wade Richards <[EMAIL PROTECTED]> wrote: > Hi all, > > I've received the following log message > kernel: eth0: Something Wicked happened! 001a. > a few times. I've read through the source for the driver, and it doesn't > appear to denote an extremely Wic

Re: Something Wicked happened! 001a.

2001-03-23 Thread Alexander Hvostov
On Fri, 23 Mar 2001 22:23:59 -0800 Wade Richards <[EMAIL PROTECTED]> wrote: > Hi all, > > I've received the following log message > kernel: eth0: Something Wicked happened! 001a. > a few times. I've read through the source for the driver, and it doesn't > appear to denote an extremely Wi

Re: Is it possible to chroot scp?

2001-03-12 Thread Alexander Hvostov
[EMAIL PROTECTED] wrote: Hello. I have been setting up a webserver that users need to acess remotely. The problem is that I don't like the way that ftp sends passwords plaintext. I am currently useing proftpd, as I also require the ability to chroot users into thier own directories. Now, esse

Re: Is it possible to chroot scp?

2001-03-11 Thread Alexander Hvostov
[EMAIL PROTECTED] wrote: > Hello. > > I have been setting up a webserver that users need to acess remotely. > The problem is that I don't like the way that ftp sends passwords > plaintext. I am currently useing proftpd, as I also require the > ability to chroot users into thier own directories.

Re: saft port

2001-03-08 Thread Alexander Hvostov
Kozman, SAFT is a nifty little protocol that lets you send a file to some other user on the internet without them having to explicitly accept it. Instead, the SAFT server will receive the file and place it in a queue for access later on. The protocol itself is quite new; an implementation is in th

Re: i've been port scanned. now what

2001-03-08 Thread Alexander Hvostov
Daniel, Wouldn't surprise me. Often these kinds of things are done from compromised hosts, so that they don't reveal the true identity of the attacker (who, obviously, doesn't want to go to jail ;). Regards, Alex. On Mon, 5 Mar 2001, [iso-8859-2] Szabó Dániel wrote: > Hello. > My packet filter

Re: saft port

2001-03-08 Thread Alexander Hvostov
Kozman, SAFT is a nifty little protocol that lets you send a file to some other user on the internet without them having to explicitly accept it. Instead, the SAFT server will receive the file and place it in a queue for access later on. The protocol itself is quite new; an implementation is in t

Re: i've been port scanned. now what

2001-03-08 Thread Alexander Hvostov
Daniel, Wouldn't surprise me. Often these kinds of things are done from compromised hosts, so that they don't reveal the true identity of the attacker (who, obviously, doesn't want to go to jail ;). Regards, Alex. On Mon, 5 Mar 2001, [iso-8859-2] Szabó Dániel wrote: > Hello. > My packet filte

Re: promiscuous eth0

2001-03-07 Thread Alexander Hvostov
On Mon, 5 Mar 2001, Jaan Sarv wrote: > > Also, paranoid network administrators might be a little upset by it, since > > Linux sends out a frame indicating it is switching into (or out > > of) promiscuous mode. This is possible evidence that you're running a > > sniffer of some kind (such as snort)

Re: promiscuous eth0

2001-03-07 Thread Alexander Hvostov
On Mon, 5 Mar 2001, Jaan Sarv wrote: > > Also, paranoid network administrators might be a little upset by it, since > > Linux sends out a frame indicating it is switching into (or out > > of) promiscuous mode. This is possible evidence that you're running a > > sniffer of some kind (such as snort

Re: promiscuous eth0

2001-03-02 Thread Alexander Hvostov
Jeff, It can potentially slow your machine down somewhat, as now the kernel has to handle each and every frame transmitted on the network eth0 is attached to, rather than only the ones addressed to your machine and broadcasts. Quite a lot of load if your system isn't addressed much on a high-traff

Re: promiscuous eth0

2001-03-02 Thread Alexander Hvostov
Jeff, It can potentially slow your machine down somewhat, as now the kernel has to handle each and every frame transmitted on the network eth0 is attached to, rather than only the ones addressed to your machine and broadcasts. Quite a lot of load if your system isn't addressed much on a high-traf

Re: Quitting debian-java

2001-03-02 Thread Alexander Hvostov
t flame me. I'm thin-skinned. ] On Thu, 1 Mar 2001, Seth Arnold wrote: > * Alexander Hvostov <[EMAIL PROTECTED]> [010301 22:35]: > > That's why you create classes under packages other than `java' or > > `javax'. The Java API proper is in the `java' and `jav

Re: Quitting debian-java

2001-03-01 Thread Alexander Hvostov
t flame me. I'm thin-skinned. ] On Thu, 1 Mar 2001, Seth Arnold wrote: > * Alexander Hvostov <[EMAIL PROTECTED]> [010301 22:35]: > > That's why you create classes under packages other than `java' or > > `javax'. The Java API proper is in the `java' and `jav

Re: who owns the ports?

2001-02-07 Thread Alexander Hvostov
Matthias, netstat -atp | less Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P--- L++>++$ E+ W+(-) N+ o? K? w---() !O !M !V PS+(++)>+ PE-(--) Y+>+ PGP t+>+

Re: who owns the ports?

2001-02-07 Thread Alexander Hvostov
Matthias, netstat -atp | less Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P--- L++>++$ E+ W+(-) N+ o? K? w---() !O !M !V PS+(++)>+ PE-(--) Y+>+ PGP t+>+

Re: Disappointment in security handling in Debian

2001-02-01 Thread Alexander Hvostov
Lucien, I've proposed a secure by default configuration for new Debian installations on this list before. It drew harsh criticism from at least one person whose belief it was that those who lack the knowledge to secure their systems deserve to be rooted. Because of this attitude, and the fact that

Re: Disappointment in security handling in Debian

2001-02-01 Thread Alexander Hvostov
Lucien, I've proposed a secure by default configuration for new Debian installations on this list before. It drew harsh criticism from at least one person whose belief it was that those who lack the knowledge to secure their systems deserve to be rooted. Because of this attitude, and the fact tha

Re: connecting to my box

2001-01-26 Thread Alexander Hvostov
Mohammed, Check /etc/hosts.deny and /etc/hosts.allow. It looks like tcpd is refusing the connection. The problem may also be caused by improper DNS entries for the machine you're trying to connect from. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9

Re: connecting to my box

2001-01-26 Thread Alexander Hvostov
Mohammed, Check /etc/hosts.deny and /etc/hosts.allow. It looks like tcpd is refusing the connection. The problem may also be caused by improper DNS entries for the machine you're trying to connect from. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED

[OT?] inverted `limit' match support in iptables/netfilter

2001-01-15 Thread Alexander Hvostov
Hello, I'm trying to get the `limit' match support in iptables/netfilter to be inverted in the sense that it only matches when the limit has been exceeded. For instance, to log a flood: iptables -I INPUT -m limit ! --limit 1/s -j LOG However, for some reason, the `!' flag does not seem to change

[OT?] inverted `limit' match support in iptables/netfilter

2001-01-15 Thread Alexander Hvostov
Hello, I'm trying to get the `limit' match support in iptables/netfilter to be inverted in the sense that it only matches when the limit has been exceeded. For instance, to log a flood: iptables -I INPUT -m limit ! --limit 1/s -j LOG However, for some reason, the `!' flag does not seem to chang

Re: Processes

2000-12-02 Thread Alexander Hvostov
Rando, I suggest using a signal other than SIGKILL in that instance. :P Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P--- L++>++$ E+ W+(-) N+ o? K? w---()

Re: Processes

2000-12-02 Thread Alexander Hvostov
Rando, I suggest using a signal other than SIGKILL in that instance. :P Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P--- L++>++$ E+ W+(-) N+ o? K? w---()

Re: Workstation question...

2000-11-15 Thread Alexander Hvostov
Henning, While the `unstable' version of Debian, named `woody', now comes with XFree86 4.0 (which supports your GeForce), I don't imagine a newbie would be too comfortable running the unstable distribution... By the way, can I have your equipment? A Descent monitor? Cool!! I have _got_ to see tha

Re: restricted bash (rbash)

2000-11-15 Thread Alexander Hvostov
Jochen, mkdir /usr/local/bin/restricted;ln -s /usr/local/bin/restricted/;... export PATH=/usr/local/bin/restricted;exec rbash ...boom. Now only the commands you want the user to be able to run will be available. Shell scripts, however, continue to work fine, since their `hash bang' doesn't pay

Re: Workstation question...

2000-11-14 Thread Alexander Hvostov
Henning, While the `unstable' version of Debian, named `woody', now comes with XFree86 4.0 (which supports your GeForce), I don't imagine a newbie would be too comfortable running the unstable distribution... By the way, can I have your equipment? A Descent monitor? Cool!! I have _got_ to see th

Re: restricted bash (rbash)

2000-11-14 Thread Alexander Hvostov
Jochen, mkdir /usr/local/bin/restricted;ln -s /usr/local/bin/restricted/;... export PATH=/usr/local/bin/restricted;exec rbash ...boom. Now only the commands you want the user to be able to run will be available. Shell scripts, however, continue to work fine, since their `hash bang' doesn't pay

Re: SCSI Tape backup

2000-11-07 Thread Alexander Hvostov
Jason, What exactly does this have to do with security? Ask this on debian-user or something. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P--- L++>++$ E+

Re: SCSI Tape backup

2000-11-07 Thread Alexander Hvostov
Jason, What exactly does this have to do with security? Ask this on debian-user or something. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P--- L++>++$ E+

Re: Configuring ssh

2000-11-05 Thread Alexander Hvostov
Use PuTTY. Go to http://www.openssh.com/, click on "Alternatives -> For Windows & Mac", and at the top is PuTTY. SSH2 support was only added quite recently, though, and hasn't made it into the stable distribution as of yet. Still, I use it whenever SSHing from Windows boxes. It's a small download,

Re: Configuring ssh

2000-11-05 Thread Alexander Hvostov
Use PuTTY. Go to http://www.openssh.com/, click on "Alternatives -> For Windows & Mac", and at the top is PuTTY. SSH2 support was only added quite recently, though, and hasn't made it into the stable distribution as of yet. Still, I use it whenever SSHing from Windows boxes. It's a small download

Re: I want to try something for freedom.

2000-11-02 Thread Alexander Hvostov
e--> h! !r y>+++ --END GEEK CODE BLOCK-- On Thu, 2 Nov 2000, Robert Varga wrote: > > > On Wed, 1 Nov 2000, Patrick Maheral wrote: > > > On Wed, 1 Nov 2000, Alexander Hvostov wrote: > > > Penguin, > > > > > > Because the patents and IP o

Re: I want to try something for freedom.

2000-11-01 Thread Alexander Hvostov
e--> h! !r y>+++ --END GEEK CODE BLOCK-- On Thu, 2 Nov 2000, Robert Varga wrote: > > > On Wed, 1 Nov 2000, Patrick Maheral wrote: > > > On Wed, 1 Nov 2000, Alexander Hvostov wrote: > > > Penguin, > > > > > > Because the patents and IP o

Re: I want to try something for freedom.

2000-11-01 Thread Alexander Hvostov
Penguin, Because the patents and IP on your radio expired a long time ago. The ones on the algorithms haven't. :) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL+++

Re: I want to try something for freedom.

2000-11-01 Thread Alexander Hvostov
Penguin, I hope you know assembly and don't mind being sued... In other words, it's impossible, for legal reasons. The owners of those proprietary algorithms are highly unlikely to think twice about putting you on the street. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367

Re: I want to try something for freedom.

2000-11-01 Thread Alexander Hvostov
Penguin, Because the patents and IP on your radio expired a long time ago. The ones on the algorithms haven't. :) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL++

Re: I want to try something for freedom.

2000-10-31 Thread Alexander Hvostov
Penguin, I hope you know assembly and don't mind being sued... In other words, it's impossible, for legal reasons. The owners of those proprietary algorithms are highly unlikely to think twice about putting you on the street. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367

Re: Conflicts make APT useless

2000-10-10 Thread Alexander Hvostov
Thomas, Make sure you have the latest version of libdb2 as well. For that matter, make sure you have the latest version of everything. I have ldconfig, and it's owned by libc6, so I'm not sure how you got that... By the way, what's this got to do with debian-security? Regards, Alex. --- PGP/GP

Re: Conflicts make APT useless

2000-10-10 Thread Alexander Hvostov
Thomas, Make sure you have the latest version of libdb2 as well. For that matter, make sure you have the latest version of everything. I have ldconfig, and it's owned by libc6, so I'm not sure how you got that... By the way, what's this got to do with debian-security? Regards, Alex. --- PGP/G

Re: atd - can I remove it if I don't use at?

2000-09-25 Thread Alexander Hvostov
Mo, Red Hat security is always lousy ;) Unlike Red Hat, Debian gets security bugs and such fixed in a timely manner, especially if you are using the current `unstable' distribution (which is presently `woody'); `at' should be fine. Be sure to get security updates from security.debian.org if you d

Re: atd - can I remove it if I don't use at?

2000-09-25 Thread Alexander Hvostov
Mo, Red Hat security is always lousy ;) Unlike Red Hat, Debian gets security bugs and such fixed in a timely manner, especially if you are using the current `unstable' distribution (which is presently `woody'); `at' should be fine. Be sure to get security updates from security.debian.org if you

Re: extra .. folder in /dev

2000-09-01 Thread Alexander Hvostov
Wesley, e2fsck -f should find and clean that up, but I _strongly_ advise you to reinstall completely. Rooted boxes are like some forms of cancer -- no matter how hard you try, you just can't get the "disease" (or the script kiddie, in your case) to go away. Reinstallation is your only real option.

Re: extra .. folder in /dev

2000-09-01 Thread Alexander Hvostov
Wesley, e2fsck -f should find and clean that up, but I _strongly_ advise you to reinstall completely. Rooted boxes are like some forms of cancer -- no matter how hard you try, you just can't get the "disease" (or the script kiddie, in your case) to go away. Reinstallation is your only real option

Re: SecurityPortal Review of Potato

2000-08-30 Thread Alexander Hvostov
Peter, dpkg-divert --local --rename # enable daemon again dpkg-divert --local --rename --remove Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L++

Re: Logging atempts

2000-07-16 Thread Alexander Hvostov
Florian and all, ippl is a generally better program than iplogger. (this is by ippl's design ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+

Re: Logging atempts

2000-07-16 Thread Alexander Hvostov
Florian and all, ippl is a generally better program than iplogger. (this is by ippl's design ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+

Re: strange upd traffic (ipchains newbie)

2000-07-14 Thread Alexander Hvostov
Thomas, Create a rule for each possible source address, i.e.: for i in 127.0.0.1 192.168.1.1 192.168.1.2 192.168.1.3; do ipchains -A input -s $i done That will set up counters for traffic coming from 127.0.0.1, 192.168.1.1, 192.168.1.2, and 192.168.1.3, all with their own counters. Alternative

Re: strange upd traffic (ipchains newbie)

2000-07-14 Thread Alexander Hvostov
Thomas, Create a rule for each possible source address, i.e.: for i in 127.0.0.1 192.168.1.1 192.168.1.2 192.168.1.3; do ipchains -A input -s $i done That will set up counters for traffic coming from 127.0.0.1, 192.168.1.1, 192.168.1.2, and 192.168.1.3, all with their own counters. Alternativ

Re: strange upd traffic (ipchains newbie)

2000-07-13 Thread Alexander Hvostov
Thomas, Shave off the `-j ACCEPT' from the end of that ipchains rule! Read the man page for more. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>

Re: strange upd traffic (ipchains newbie)

2000-07-13 Thread Alexander Hvostov
Thomas, Shave off the `-j ACCEPT' from the end of that ipchains rule! Read the man page for more. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++

Re: [lamagra@DIGIBEL.ORG: proftp advisory]

2000-07-07 Thread Alexander Hvostov
>+ PE- Y+ PGP t+ !5 X-- !R tv b DI D++ G>+++ e-- h! !r y --END GEEK CODE BLOCK-- On Fri, 7 Jul 2000, Wichert Akkerman wrote: > Previously Alexander Hvostov wrote: > > It still needs to be fixed, and I'm glad someone decided to audit proftpd. > > W

Re: A query on ipchains

2000-07-07 Thread Alexander Hvostov
Marco, No. What I gather here is that Koala has his own LAN, as well as a corporate intranet, which is then connected to the Internet by masquerading. He wants a router between his own LAN and the corporate intranet. That router must forward Internet-bound datagrams from his LAN to the corporate r

Re: [lamagra@DIGIBEL.ORG: proftp advisory]

2000-07-07 Thread Alexander Hvostov
>+ PE- Y+ PGP t+ !5 X-- !R tv b DI D++ G>+++ e-- h! !r y --END GEEK CODE BLOCK-- On Fri, 7 Jul 2000, Wichert Akkerman wrote: > Previously Alexander Hvostov wrote: > > It still needs to be fixed, and I'm glad someone decided to audit proftpd. > > W

Re: A query on ipchains

2000-07-07 Thread Alexander Hvostov
Marco, No. What I gather here is that Koala has his own LAN, as well as a corporate intranet, which is then connected to the Internet by masquerading. He wants a router between his own LAN and the corporate intranet. That router must forward Internet-bound datagrams from his LAN to the corporate

re: [lamagra@DIGIBEL.ORG: proftp advisory]

2000-07-05 Thread Alexander Hvostov
Johan, It still needs to be fixed, and I'm glad someone decided to audit proftpd. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o

re: [lamagra@DIGIBEL.ORG: proftp advisory]

2000-07-05 Thread Alexander Hvostov
Johan, It still needs to be fixed, and I'm glad someone decided to audit proftpd. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N

Re: using password aging with ssh

2000-07-04 Thread Alexander Hvostov
EEK CODE BLOCK-- On Tue, 4 Jul 2000, thomas lakofski wrote: > Alex, > > not from what I've seen -- users just get the standard 'access denied' as > if they had entered the wrong password. telnet works as expected. > > regards, > > -thomas > >

Re: using password aging with ssh

2000-07-04 Thread Alexander Hvostov
EEK CODE BLOCK-- On Tue, 4 Jul 2000, thomas lakofski wrote: > Alex, > > not from what I've seen -- users just get the standard 'access denied' as > if they had entered the wrong password. telnet works as expected. > > regards, > > -thomas > >

Re: HHHEEEEEEEEELLLLLLLLPPPPPPPP!!!!!!!!!!

2000-07-04 Thread Alexander Hvostov
Dennis, We don't want you to leave debian-security. ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o? K? w--() !O M- !V PS+>+

Re: using password aging with ssh

2000-07-04 Thread Alexander Hvostov
Thomas, The old password is requested first.. ;P Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o? K? w--() !O M- !V PS+>+ PE- Y

Re: HHHEEEEEEEEELLLLLLLLPPPPPPPP!!!!!!!!!!

2000-07-04 Thread Alexander Hvostov
Dennis, We don't want you to leave debian-security. ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o? K? w--() !O M- !V PS+>+

Re: using password aging with ssh

2000-07-04 Thread Alexander Hvostov
Thomas, The old password is requested first.. ;P Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o? K? w--() !O M- !V PS+>+ PE- Y

Re: Sheesh .. talk about beating a dead horse (autofs)

2000-07-03 Thread Alexander Hvostov
Christopher, If you have access to WinNT source, you must be of some importance to Micro$oft (or perhaps they are to you), so why are you on this mailing list? Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version:

Re: Sheesh .. talk about beating a dead horse (autofs)

2000-07-03 Thread Alexander Hvostov
Christopher, If you have access to WinNT source, you must be of some importance to Micro$oft (or perhaps they are to you), so why are you on this mailing list? Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version:

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-03 Thread Alexander Hvostov
Wichert, So is root's password. ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o? K? w--() !O M- !V PS+>+ PE- Y+ PGP t+ !5 X-

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-03 Thread Alexander Hvostov
Wichert, So is root's password. ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCS/CM>CC/IT d- s:+ a16 C++()>$ UL>$ P---() L+++>+ E+>+ W+(-) N o? K? w--() !O M- !V PS+>+ PE- Y+ PGP t+ !5 X-

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Alexander Hvostov
Thor, Disable booting from floppy in BIOS, password protect LILO, install chassis intrusion detection system wired to gun turrets with 50mm heavy machine guns... ...okay, I think I'm going a little overboard here... ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B4

Re: SECURITY PROBLEM: autofs [all versions]

2000-07-01 Thread Alexander Hvostov
Thor, Disable booting from floppy in BIOS, password protect LILO, install chassis intrusion detection system wired to gun turrets with 50mm heavy machine guns... ...okay, I think I'm going a little overboard here... ;) Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B

Re: Kernel capability bug for kernels < 2.2.16

2000-06-16 Thread Alexander Hvostov
Tollef, There are other security bugs that 2.2.16 fixes, y'know. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCM d- s:+ a--- C UL P L+++ E W++ N o-- K- w O--- M- V- PS+ PE- Y PGP t+ 5 X- R tv

Re: Kernel capability bug for kernels < 2.2.16

2000-06-16 Thread Alexander Hvostov
Tollef, There are other security bugs that 2.2.16 fixes, y'know. Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCM d- s:+ a--- C UL P L+++ E W++ N o-- K- w O--- M- V- PS+ PE- Y PGP t+ 5 X- R t

Re: How can I help ?

2000-06-14 Thread Alexander Hvostov
--END GEEK CODE BLOCK-- On Wed, 14 Jun 2000, Wichert Akkerman wrote: > Previously Alexander Hvostov wrote: > > I have a better idea: an integrated 'user' command, which uses plugins to > > access the actual database server (like PAM, but for writing to the > &g

Re: How can I help ?

2000-06-14 Thread Alexander Hvostov
--END GEEK CODE BLOCK-- On Wed, 14 Jun 2000, Wichert Akkerman wrote: > Previously Alexander Hvostov wrote: > > I have a better idea: an integrated 'user' command, which uses plugins to > > access the actual database server (like PAM, but for writing to the > &g

Re: How can I help ?

2000-06-14 Thread Alexander Hvostov
s:+ a--- C UL P L+++ E W++ N o-- K- w O--- M- V- PS+ PE- Y PGP t+ 5 X- R tv+ b DI--- D+ G e-- h++ r--- y --END GEEK CODE BLOCK-- On Wed, 14 Jun 2000, L. Besselink wrote: > On Wed, 14 Jun 2000, Alexander Hvostov wrote: > > > Lennie, > > > > Can you give

Re: How can I help ?

2000-06-14 Thread Alexander Hvostov
Lennie, Can you give me any more details than just that Linux I/O performance is inferior to *BSD? Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCM d- s:+ a--- C UL P L+++ E W++ N o-- K- w O--

Re: How can I help ?

2000-06-14 Thread Alexander Hvostov
s:+ a--- C UL P L+++ E W++ N o-- K- w O--- M- V- PS+ PE- Y PGP t+ 5 X- R tv+ b DI--- D+ G e-- h++ r--- y --END GEEK CODE BLOCK-- On Wed, 14 Jun 2000, L. Besselink wrote: > On Wed, 14 Jun 2000, Alexander Hvostov wrote: > > > Lennie, > > > > Can you give

Re: How can I help ?

2000-06-14 Thread Alexander Hvostov
Lennie, Can you give me any more details than just that Linux I/O performance is inferior to *BSD? Regards, Alex. --- PGP/GPG Fingerprint: EFD1 AC6C 7ED5 E453 C367 AC7A B474 16E0 758D 7ED9 -BEGIN GEEK CODE BLOCK- Version: 3.12 GCM d- s:+ a--- C UL P L+++ E W++ N o-- K- w O-

Re: How can I help ?

2000-06-13 Thread Alexander Hvostov
Michael, I have a better idea: an integrated 'user' command, which uses plugins to access the actual database server (like PAM, but for writing to the database rather than reading from it), and performs any of several functions. Some examples: # user add joe Enter password: Repeat password: User

RE: How can I help ?

2000-06-13 Thread Alexander Hvostov
> As I recall after windows 95 the passwords are sent over the line > encrypted. The encryption might be weak but they are not clear text > anymore. > > There is a switch in SMB to allow encrypted passwords. This is ON by > default in debian (I believe) > > -Ryan > > O

Re: How can I help ?

2000-06-13 Thread Alexander Hvostov
Michael, I have a better idea: an integrated 'user' command, which uses plugins to access the actual database server (like PAM, but for writing to the database rather than reading from it), and performs any of several functions. Some examples: # user add joe Enter password: Repeat password: User

RE: How can I help ?

2000-06-13 Thread Alexander Hvostov
> As I recall after windows 95 the passwords are sent over the line > encrypted. The encryption might be weak but they are not clear text > anymore. > > There is a switch in SMB to allow encrypted passwords. This is ON by > default in debian (I believe) > > -Ryan > > O

RE: How can I help ?

2000-06-13 Thread Alexander Hvostov
Ronny and all, If you want to use LDAP, I suggest you do LDAP over SSL/TLS. The current OpenLDAP doesn't support it natively, but I believe there's a patch, and of course there's always wrappers like stunnel. Of course, if you want to use user authentication from Windows, using PAM is more or les

RE: How can I help ?

2000-06-13 Thread Alexander Hvostov
Ronny and all, If you want to use LDAP, I suggest you do LDAP over SSL/TLS. The current OpenLDAP doesn't support it natively, but I believe there's a patch, and of course there's always wrappers like stunnel. Of course, if you want to use user authentication from Windows, using PAM is more or le

Re: suid shell scripts

2000-06-05 Thread Alexander Hvostov
Jim, The Linux kernel does not permit any executable file beginning with #! (a file which requires an interpreter) to have setuid privileges. For this you will have to have to write a small compiled binary (e.g. C) program, which simply performs an execl(), perhaps after doing setuid() to change t

Re: On the security of e-mails

2000-05-26 Thread Alexander Hvostov
y 2000, Ethan Benson wrote: > On Fri, May 26, 2000 at 02:37:59AM -0700, Alexander Hvostov wrote: > > Ethan, > > > > Only one problem. Charlie Brown doesn't have hordes of lawyers. > > and the Free software movement does? > > MS has hoards of lawyers and b

Re: On the security of e-mails

2000-05-26 Thread Alexander Hvostov
t+ 5 X- R tv+ b DI--- D+ G e-- h++ r--- y --END GEEK CODE BLOCK-- On Fri, 26 May 2000, Ethan Benson wrote: > On Fri, May 26, 2000 at 02:19:06AM -0700, Alexander Hvostov wrote: > > Ethan, and everyone, > > > > I seem to keep having to repeat myself: the USA recen

Re: On the security of e-mails

2000-05-26 Thread Alexander Hvostov
GCM d- s:+ a--- C UL P L+++ E W++ N o-- K- w O--- M- V- PS+ PE- Y PGP t+ 5 X- R tv+ b DI--- D+ G e-- h++ r--- y --END GEEK CODE BLOCK-- On Fri, 26 May 2000, Sergio Brandano wrote: > > Alexander Hvostov wrote > > > ...Unless you encrypt to a public key belonging

Re: On the security of e-mails

2000-05-26 Thread Alexander Hvostov
:19:33AM -0700, Alexander Hvostov wrote: > > Sergio, > > > > That's what GPG and a good MUA like Pine is for. Let's see "Big > > Brother" crack 1024-bit public key crypto anytime this decade... > > > > I know you can't legally do this in

Re: On the security of e-mails

2000-05-26 Thread Alexander Hvostov
BLOCK- Version: 3.12 GCM d- s:+ a--- C UL P L+++ E W++ N o-- K- w O--- M- V- PS+ PE- Y PGP t+ 5 X- R tv+ b DI--- D+ G e-- h++ r--- y --END GEEK CODE BLOCK-- On Fri, 26 May 2000, Julien Stern wrote: > On Fri, May 26, 2000 at 12:19:33AM -0700, Alexander Hvostov wrote: &g

Re: On the security of e-mails

2000-05-26 Thread Alexander Hvostov
Bradley, Uhm, isn't Sendmail's SMTP-over-SSL thing supposed to conform to some standard..? I seriously doubt the other endpoint has to be Sendmail; rather, I think it probably only needs to be running a proper SMTP-over-SSL implementation. If this is the case, then this can be done with stunnel an

  1   2   >