Sendmail security fix for stable?

2006-07-08 Thread Andrew Pollock
Hi, The version of Sendmail in sarge is vulnerable to CVE-2006-1173 from what I can determine, and there's been a fixed version in testing for some time, but what's happened to stable? regards Andrew -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Conta

Log file IDS package?

2005-01-11 Thread Andrew Pollock
Hi, I've done some cursory apt-cache searching, and nothing's jumped out at me... Is there software in Debian that will do something along the lines of a tail -f of a given logfile, looking for supplied regexs and do custom actions on matches? I want to tarpit excessive SSH login failures. rega

Re: [bulletproof.net.au #29025] [Comment] [SECURITY] [DSA 525-1] New apache packages fix buffer overflow in mod_proxy

2004-06-28 Thread Andrew Pollock
On Mon, Jun 28, 2004 at 12:55:58PM +1000, Lorenzo Modesto via RT wrote: > If a customer is affected we have to announce. Send it through and > I'll approve. > You guys do realise your Request Tracker setup is replying all correspondence on tickets that are being gated into RT back to the debian-

Re: Why not push to stable?

2004-06-28 Thread Andrew Pollock
On Sat, Jun 26, 2004 at 02:55:28PM +0200, martin f krafft wrote: > also sprach Andreas Barth <[EMAIL PROTECTED]> [2004.06.26.1452 +0200]: > > what's the problem with: > > deb mirror > > deb security.d.o > > > > In this case, the file is taken from the mirror if it exists already > > there, and oth

Re: strange reboot on woody

2003-11-30 Thread Andrew Pollock
On Sun, Nov 30, 2003 at 12:51:45AM +0200, Haim Ashkenazi wrote: > Bernd Eckenfels wrote: > > > > > BTW: i recommend you disable CAD :) > I would but that is the only way I can let them safely reboot the machine > (If I'll need them to) without giving the root password (although I know > that it o

Re: passwd character limitations

2003-11-29 Thread Andrew Pollock
On Fri, Oct 31, 2003 at 06:08:50PM -0500, Federico Grau wrote: > Hello, > > I'm looking for a list of characters that are not allowable (or that cause > problems) for passwords if any under a standard Debian GNU/Linux install > (using md5). I've checked the packages docs and done a quick google s

Re: strange reboot on woody

2003-11-29 Thread Andrew Pollock
On Sun, Nov 30, 2003 at 12:51:45AM +0200, Haim Ashkenazi wrote: > Bernd Eckenfels wrote: > > > > > BTW: i recommend you disable CAD :) > I would but that is the only way I can let them safely reboot the machine > (If I'll need them to) without giving the root password (although I know > that it o

Re: passwd character limitations

2003-11-29 Thread Andrew Pollock
On Fri, Oct 31, 2003 at 06:08:50PM -0500, Federico Grau wrote: > Hello, > > I'm looking for a list of characters that are not allowable (or that cause > problems) for passwords if any under a standard Debian GNU/Linux install > (using md5). I've checked the packages docs and done a quick google s

Re: [work] Integrity of Debian packages

2003-03-06 Thread Andrew Pollock
On Thu, Mar 06, 2003 at 09:21:21PM -0500, Gary MacDougall wrote: [snip] > This is silly to blame the FBI. I'd be far more concerned about the > average knucklehead > trying to do this maliciously than thinking the FBI would do it... please. I wasn't that worried about the FBI, being Australian

Re: [work] Integrity of Debian packages

2003-03-06 Thread Andrew Pollock
On Thu, Mar 06, 2003 at 09:21:21PM -0500, Gary MacDougall wrote: [snip] > This is silly to blame the FBI. I'd be far more concerned about the > average knucklehead > trying to do this maliciously than thinking the FBI would do it... please. I wasn't that worried about the FBI, being Australian

Integrity of Debian packages

2003-03-06 Thread Andrew Pollock
Hi, One of my friends sent me this URL, it's an oldie, and the topic in general has been discussed before, but this article certainly does raise some concerns. http://www.astalavista.com/privacy/library/magic-lantern/fbi.shtml Andrew

Integrity of Debian packages

2003-03-06 Thread Andrew Pollock
Hi, One of my friends sent me this URL, it's an oldie, and the topic in general has been discussed before, but this article certainly does raise some concerns. http://www.astalavista.com/privacy/library/magic-lantern/fbi.shtml Andrew -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subj

=?iso-8859-1?Q?Re: Secure/hardened/minimal Debian (or "Why is the base system the way it i=

2002-05-20 Thread Andrew Pollock
eans I can't send mail to root locally does it not? The environment I'm in has a smarthost, but it's generally for getting mail out of the network, direct inbound SMTP isn't there, so the smarthost can't send it elsewhere internally. > On Sun, 2002-05-19 at 21:10, Andr

=?iso-8859-1?Q?Re: Secure/hardened/minimal Debian (or "Why is the base system the way it i=

2002-05-19 Thread Andrew Pollock
eans I can't send mail to root locally does it not? The environment I'm in has a smarthost, but it's generally for getting mail out of the network, direct inbound SMTP isn't there, so the smarthost can't send it elsewhere internally. > On Sun, 2002-05-19 at 21:10, Andr

Secure/hardened/minimal Debian (or "Why is the base system the way it is?")

2002-05-19 Thread Andrew Pollock
Hi, I'm currently working for a company that provides managed security solutions. Linux is used fairly extensively in the internal infrastructure. Currently it's Mandrake, however my immediate superior (who is the Mandrake guy) is open minded and has allowed me to run up some Debian installations

Secure/hardened/minimal Debian (or "Why is the base system the wayit is?")

2002-05-19 Thread Andrew Pollock
Hi, I'm currently working for a company that provides managed security solutions. Linux is used fairly extensively in the internal infrastructure. Currently it's Mandrake, however my immediate superior (who is the Mandrake guy) is open minded and has allowed me to run up some Debian installations

Re: Is snort-stat and 5snort really broken in sid?

2001-09-12 Thread Andrew Pollock
On 12.09.2001 at 11:30:02, Andrew Pollock <[EMAIL PROTECTED]> wrote: > Even if I run snort-stat manually on auth.log (after I've made snort start with > -s) it doesn't return anything when there are alerts in the log. > > Any suggestions appreciated, I'd like to

Re: Is snort-stat and 5snort really broken in sid?

2001-09-12 Thread Andrew Pollock
On 12.09.2001 at 11:30:02, Andrew Pollock <[EMAIL PROTECTED]> wrote: > Even if I run snort-stat manually on auth.log (after I've made snort start with > -s) it doesn't return anything when there are alerts in the log. > > Any suggestions appreciated, I'd like t

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
log format has changed, but snort-stat hasn't changed since version 1.7 > --sjk > > On 12 Sep, Andrew Pollock wrote: > > Hi, > > > > I've always had problems with 5snort killing snort daily when snort's running in > > dialup mode (I fixed that

Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode (I fixed that by commenting out the restart line) but I'm not getting anything in the daily notification emails either. /etc/ppp/ip-up.d/snort doesn't start snort with -s, so nothing goes into /var/lo

Re: Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
log format has changed, but snort-stat hasn't changed since version 1.7 > --sjk > > On 12 Sep, Andrew Pollock wrote: > > Hi, > > > > I've always had problems with 5snort killing snort daily when snort's running in > > dialup mode (I fixed that

Is snort-stat and 5snort really broken in sid?

2001-09-11 Thread Andrew Pollock
Hi, I've always had problems with 5snort killing snort daily when snort's running in dialup mode (I fixed that by commenting out the restart line) but I'm not getting anything in the daily notification emails either. /etc/ppp/ip-up.d/snort doesn't start snort with -s, so nothing goes into /var/l

Portsentry vs snort

2001-09-03 Thread Andrew Pollock
Hi, I'm currently running Portsentry on a box, and I've got it configured to add an ipchains rule firewalling off all access to an IP that touches one of the ports that Portsentry is listening on (after doing some sanity checks on where the portscan/port access came from). I find the way that Por

Portsentry vs snort

2001-09-03 Thread Andrew Pollock
Hi, I'm currently running Portsentry on a box, and I've got it configured to add an ipchains rule firewalling off all access to an IP that touches one of the ports that Portsentry is listening on (after doing some sanity checks on where the portscan/port access came from). I find the way that Po