Re: ipsec setkey and 2.4.21 kernel

2003-10-16 Thread Herbert Xu
U/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: ipsec setkey and 2.4.21 kernel

2003-10-16 Thread Herbert Xu
U/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: ipsec setkey and 2.4.21 kernel

2003-10-15 Thread Herbert Xu
o. Yes they should be loaded automatically. And they do if you have the right modutils/modprobe aliases. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: ipsec setkey and 2.4.21 kernel

2003-10-15 Thread Herbert Xu
o. Yes they should be loaded automatically. And they do if you have the right modutils/modprobe aliases. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apa

Re: ipsec setkey and 2.4.21 kernel

2003-10-15 Thread Herbert Xu
an GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: ipsec setkey and 2.4.21 kernel

2003-10-15 Thread Herbert Xu
an GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: 2.4.21 IPSEC problems

2003-09-05 Thread Herbert Xu
n the BTS. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: 2.4.21 IPSEC problems

2003-09-05 Thread Herbert Xu
n the BTS. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subje

Re: 2.4.21 IPSEC problems

2003-09-03 Thread Herbert Xu
On Wed, Sep 03, 2003 at 12:44:38PM +0100, Dale Amon wrote: > On Wed, Sep 03, 2003 at 07:32:49PM +1000, Herbert Xu wrote: > > I don't use racoon myself so I can't help you with it. But perhaps > > you can join the racoon mailing list and get help there. > > Tha

Re: 2.4.21 IPSEC problems

2003-09-03 Thread Herbert Xu
On Wed, Sep 03, 2003 at 12:44:38PM +0100, Dale Amon wrote: > On Wed, Sep 03, 2003 at 07:32:49PM +1000, Herbert Xu wrote: > > I don't use racoon myself so I can't help you with it. But perhaps > > you can join the racoon mailing list and get help there. > > Tha

Re: 2.4.21 IPSEC problems

2003-09-03 Thread Herbert Xu
so I can't help you with it. But perhaps you can join the racoon mailing list and get help there. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: 2.4.21 IPSEC problems

2003-09-03 Thread Herbert Xu
so I can't help you with it. But perhaps you can join the racoon mailing list and get help there. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.

Re: 2.4.21 IPSEC problems

2003-09-02 Thread Herbert Xu
a sid dist, it segfaults. I'd just run the copy that was built under woody... -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: 2.4.21 IPSEC problems

2003-09-02 Thread Herbert Xu
all that is going in > it and the lot of patches it has. Thanks to the upstream freeswan maintainers my patch is now part of their CVS code. So it will probably be released with 2.03 in a couple of months. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert

Re: 2.4.21 IPSEC problems

2003-09-02 Thread Herbert Xu
a sid dist, it segfaults. I'd just run the copy that was built under woody... -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pu

Re: 2.4.21 IPSEC problems

2003-09-02 Thread Herbert Xu
all that is going in > it and the lot of patches it has. Thanks to the upstream freeswan maintainers my patch is now part of their CVS code. So it will probably be released with 2.03 in a couple of months. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert

Re: 2.4.21 IPSEC problems

2003-08-31 Thread Herbert Xu
0.2.2-5 will definitely not work with 2.6.0-test4. Even setkey only works to a certain extent. See #203641. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key:

Re: 2.4.21 IPSEC problems

2003-08-31 Thread Herbert Xu
0.2.2-5 will definitely not work with 2.6.0-test4. Even setkey only works to a certain extent. See #203641. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key:

Re: 2.4.21 IPSEC problems

2003-08-31 Thread Herbert Xu
h the kernel ABI. isakmpd: As above. freeswan: 2.01 needs my patch to work with the new stack. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gond

Re: 2.4.21 IPSEC problems

2003-08-30 Thread Herbert Xu
h the kernel ABI. isakmpd: As above. freeswan: 2.01 needs my patch to work with the new stack. Cheers, -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: 2.4.21 IPSEC problems

2003-08-29 Thread Herbert Xu
ream source. If you use the Debian source then you must make sure that the header files are really coming from the kernel as opposed to the copy included in the Debian package. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: 2.4.21 IPSEC problems

2003-08-29 Thread Herbert Xu
urce. If you use the Debian source then you must make sure that the header files are really coming from the kernel as opposed to the copy included in the Debian package. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Pa

Re: new debian kernel

2003-08-14 Thread Herbert Xu
other issue introduced by the security fix, you should download the latest kernels from http://auric.debian.org/~herbert/. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: htt

Re: new debian kernel

2003-08-13 Thread Herbert Xu
other issue introduced by the security fix, you should download the latest kernels from http://auric.debian.org/~herbert/. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: Kernel 2.4.21 Forwarding table vulnerability

2003-07-28 Thread Herbert Xu
st. > > Ah, this one. I don't even know if it's about IP. > > As usual, Red Hat's advisory is a joke. *sigh* If you don't use bridging then it doesn't affect you. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[

Re: Kernel 2.4.21 Forwarding table vulnerability

2003-07-28 Thread Herbert Xu
st. > > Ah, this one. I don't even know if it's about IP. > > As usual, Red Hat's advisory is a joke. *sigh* If you don't use bridging then it doesn't affect you. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[

Re: [DSA-311-1] New kernel packages - Bug not fixed!

2003-06-09 Thread Herbert Xu
asily root privileges. > > Could it be that this has only been fixed in more recent kernel versions > or has there been some kind of error? Make sure the exploit binary you're running is not setuid root. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV

Re: [DSA-311-1] New kernel packages - Bug not fixed!

2003-06-09 Thread Herbert Xu
asily root privileges. > > Could it be that this has only been fixed in more recent kernel versions > or has there been some kind of error? Make sure the exploit binary you're running is not setuid root. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV

Updated kernels with security fixes

2003-05-23 Thread Herbert Xu
hould anything go wrong since none its files will be replaced. -- Debian GNU/Linux 3.0 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: use of /tmp by installers

2001-05-18 Thread Herbert Xu
nux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: use of /tmp by installers

2001-05-18 Thread Herbert Xu
nux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-18 Thread Herbert Xu
nobody ever fixed. :/ Ugh, but this is a security issue. Indeed, if root were using joe and editing a file in /tmp, it'd be a root exploit. Besides, it's not as if it's hard to fix or anything, just copy whatever nvi does. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.o

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-18 Thread Herbert Xu
nobody ever fixed. :/ Ugh, but this is a security issue. Indeed, if root were using joe and editing a file in /tmp, it'd be a root exploit. Besides, it's not as if it's hard to fix or anything, just copy whatever nvi does. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.o

Re: DWN pages not getting rounded look

2000-11-18 Thread Herbert Xu
E.? Elvis solves it by counting, i.e., elvis1.ses, elvis2.ses, etc. nvi solves it by using mkstemp. Incidentally, both of them actually store things under /var/tmp. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-18 Thread Herbert Xu
On Sat, Nov 18, 2000 at 11:26:13AM -0500, Jacob Kuntz wrote: > > what's wrong with the current practice of putting deadjoe in the current > directory? cwd == /tmp -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECT

Re: DWN pages not getting rounded look

2000-11-18 Thread Herbert Xu
DJOE.? Elvis solves it by counting, i.e., elvis1.ses, elvis2.ses, etc. nvi solves it by using mkstemp. Incidentally, both of them actually store things under /var/tmp. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-18 Thread Herbert Xu
On Sat, Nov 18, 2000 at 11:26:13AM -0500, Jacob Kuntz wrote: > > what's wrong with the current practice of putting deadjoe in the current > directory? cwd == /tmp -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECT

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-17 Thread Herbert Xu
ine with me. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-17 Thread Herbert Xu
ine with me. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subjec

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-17 Thread Herbert Xu
on't be deleted until the user intervenes in the event of a crash. Do the right thing and use tmpfile(3). -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: Bug#77257: FWD: Joe's Own Editor File Link Vulnerability

2000-11-17 Thread Herbert Xu
on't be deleted until the user intervenes in the event of a crash. Do the right thing and use tmpfile(3). -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondo

Re: possible security flaw in screen 3.9.5-9

2000-09-08 Thread Herbert Xu
> deal. (i have had lots of buggy programs which screw that up anyway) How will they do that if the only thing owned by screen are the directories? You can always do fstat after an open. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTEC

Re: possible security flaw in screen 3.9.5-9

2000-09-08 Thread Herbert Xu
> deal. (i have had lots of buggy programs which screw that up anyway) How will they do that if the only thing owned by screen are the directories? You can always do fstat after an open. -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL

Re: possible security flaw in screen 3.9.5-9

2000-09-08 Thread Herbert Xu
e screen the owner of those directories? -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: possible security flaw in screen 3.9.5-9

2000-09-08 Thread Herbert Xu
e screen the owner of those directories? -- Debian GNU/Linux 2.2 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAI

Re: Policy on file permissions

2000-07-22 Thread Herbert Xu
ised daemons from ptracing. -- Debian GNU/Linux 2.1 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt

Re: Policy on file permissions

2000-07-22 Thread Herbert Xu
ised daemons from ptracing. -- Debian GNU/Linux 2.1 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apana.org.au/~herbert/ PGP Key: http://gondor.apana.org.au/~herbert/pubkey.txt -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with

Re: Checksums on ftp

2000-04-28 Thread Herbert Xu
Alexander Hvostov <[EMAIL PROTECTED]> wrote: > NFS requires an RPC portmapper, so things get a bit complicated... Just run ppp over ssh. -- Debian GNU/Linux 2.1 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Home Page: http://gondor.apa

Re: Automatic password changing

2000-03-23 Thread Herbert Xu
yself!): > The encrypted password will show up in the ps listing... > Out of curiosity: Is there anyway to avoid this? Put the substitution command in a here document. -- Debian GNU/Linux 2.1 is out! ( http://www.debian.org/ ) Email: Herbert Xu ~{PmV>HI~} <[EMAIL PROTECTED]> Hom