Re: activating an unconfigured interface using /etc/network/interfaces...?

2003-07-24 Thread Keegan Quinn
Hello Matthew, On Wed, Jul 23, 2003 at 10:34:32PM -0700, Matthew Whitworth wrote: > I have a dual-homed host spanning two networks and I would like to leave > one of its interfaces unconfigured so that I can use libpcap > applications on that network unobserved. I can do this using the > comma

Re: activating an unconfigured interface using /etc/network/interfaces...?

2003-07-24 Thread Keegan Quinn
Hello Matthew, On Wed, Jul 23, 2003 at 10:34:32PM -0700, Matthew Whitworth wrote: > I have a dual-homed host spanning two networks and I would like to leave > one of its interfaces unconfigured so that I can use libpcap > applications on that network unobserved. I can do this using the > comma

Re: Could sudo be an security issue?

2003-05-14 Thread Keegan Quinn
On Wednesday 14 May 2003 04:17 pm, Stewart James wrote: > Hi all, Hello Stewart, > My manager just came in asking questions about sudo. We use sudo here as a > replacement for hacing to know root passwords - in general there are > around 5 of us who need root access to the machines we maintain. w

Re: Kernel 2.4.21-rc2 still vulnarable or am I doing something wrong?

2003-05-13 Thread Keegan Quinn
On Tuesday 13 May 2003 06:11 am, Peter Holm wrote: > Did I something wrong? Or is this exploit, if not for a root shell, > still good for a local DOS? Yes, any user on any system may use all of the available CPU time unless the administrator has placed limits on them doing so. Presumably the exp

Re: Apt-get only security patches

2003-05-08 Thread Keegan Quinn
On Thursday 08 May 2003 03:30 am, Rudolph van Graan wrote: > Hi, > > Rolf Kutz wrote: > > apt-listchanges. It displays the new changelog > > entries from the debs before installing them, but > > has to download them first, so no bandwidth > > saving. > > This is almost exactly what I looked for - i

Re: iptables with no module support?

2003-04-23 Thread Keegan Quinn
Sorry for the duplicate. I seem to be about 3 hours behind on email delivery. - Keegan

Re: iptables with no module support?

2003-04-23 Thread Keegan Quinn
On Wednesday 23 April 2003 07:17 am, David Ramsden wrote: > I'm building a 'secure' server. > I downloaded the 2.4.20 kernel source from kernel.org and patched with > grsecurity (latest patch). > I also disabled loadable modules or any module support in the kernel for > added security - So everythi

Re: is iptables enough?

2003-03-20 Thread Keegan Quinn
On Wednesday 19 March 2003 01:07 pm, Ian Garrison wrote: >Imo iptables is a reasonably good stateful firewall and is fine in most > cases. However, a very wise person once said that the ideal setup is to > layer more than one implementation of packet filter and firewall between > the wild and

Re: is iptables enough?

2003-03-20 Thread Keegan Quinn
On Wednesday 19 March 2003 01:07 pm, Ian Garrison wrote: >Imo iptables is a reasonably good stateful firewall and is fine in most > cases. However, a very wise person once said that the ideal setup is to > layer more than one implementation of packet filter and firewall between > the wild and

Re: is iptables enough?

2003-03-19 Thread Keegan Quinn
Hello, On Wednesday 19 March 2003 11:44 am, Jones wrote: > I am planning to replace a (dead) Windows 2000 computer that was used > as a web server and email server with a Debian Linux solution. This > machine is connected to the net via DSL and would run apache and > exim/qpopper and sshd. Every

Re: is iptables enough?

2003-03-19 Thread Keegan Quinn
Hello, On Wednesday 19 March 2003 11:44 am, Jones wrote: > I am planning to replace a (dead) Windows 2000 computer that was used > as a web server and email server with a Debian Linux solution. This > machine is connected to the net via DSL and would run apache and > exim/qpopper and sshd. Every

Re: OT: Is it so easy to break into an NIS?

2003-03-18 Thread Keegan Quinn
On Tuesday 18 March 2003 04:13 pm, Haim Ashkenazi wrote: > Hi Hello, > A friend just asked me this question and I got curious. say I'm equipped > with a linux laptop and some knowledge, I can walk into a company that uses > NIS, find out the settings (NISDOMAIN, free ip address, etc...) and join >

Re: OT: Is it so easy to break into an NIS?

2003-03-18 Thread Keegan Quinn
On Tuesday 18 March 2003 04:13 pm, Haim Ashkenazi wrote: > Hi Hello, > A friend just asked me this question and I got curious. say I'm equipped > with a linux laptop and some knowledge, I can walk into a company that uses > NIS, find out the settings (NISDOMAIN, free ip address, etc...) and join >