Re: Upcoming changes in advisory format

2011-01-06 Thread Lionel Elie Mamane
On Sat, Dec 18, 2010 at 01:08:07PM +0100, Moritz Muehlenhoff wrote: > Traditionally Debian security advisories have included MD5 check sums > of the updated packages. > Since apt cryptographically enforces the integrity of the archive > for quite some time now, we've decided to finally drop the h

Re: How safely to stop using backports repo?

2009-05-28 Thread Lionel Elie Mamane
On Thu, May 28, 2009 at 01:20:25AM +0700, sthu.d...@gmail.com wrote: > Thank You for Your reply: >> Otherwise, you can `apt-get remove` them (plus --purge if you want >> to reset your configuration files) and re-install them : that way >> you'll use the main-repo version and you won't want have se

Re: Debian bind DNS

2006-05-09 Thread Lionel Elie Mamane
On Tue, May 09, 2006 at 06:09:54AM +0200, Florian Weimer wrote: > * martin: >> I have built a local DNS server bind (Debian Sarge).The DNS should >> accelerate DNS look ups by LAN clients. But Now, in contrary the >> local dns is slower than a custom DNS by my webhoster :-( > You should use BIND

Re: [SECURITY] [DSA 1027-1] New mailman packages fix denial of service

2006-04-06 Thread Lionel Elie Mamane
On Thu, Apr 06, 2006 at 10:22:22AM +0200, Martin Schulze wrote: > -- > Debian Security Advisory DSA 1027-1[EMAIL PROTECTED] > http://www.debian.org/security/ Steve Kemp > Apri

Re: [Pkg-mailman-hackers] Bug#339095: Re: Mailman DoS CVE-2005-3573, debbug #339095

2006-01-20 Thread Lionel Elie Mamane
On Thu, Jan 19, 2006 at 03:33:21PM -0300, Luciano Bello wrote: > I just want to know what happened with the CVE-2005-3573[1], > particularly in stable/sarge. We (mailman Debian package maintainers) haven't heard back from the security team. -- Lionel -- To UNSUBSCRIBE, email to [EMAIL P

Re: Mailman DoS CVE-2005-3573, debbug #339095

2005-12-14 Thread Lionel Elie Mamane
On Wed, Dec 14, 2005 at 03:29:48PM +0100, Lionel Elie Mamane wrote: > On Wed, Dec 14, 2005 at 12:25:50PM +0100, Lionel Elie Mamane wrote: > > > I've noticed that an issue I have fixed in Mailman in sid has been > > issued a CVE and that Mandrake has issued a securi

Re: Mailman DoS CVE-2005-3573, debbug #339095

2005-12-14 Thread Lionel Elie Mamane
On Wed, Dec 14, 2005 at 12:25:50PM +0100, Lionel Elie Mamane wrote: > I've noticed that an issue I have fixed in Mailman in sid has been > issued a CVE and that Mandrake has issued a security advisory over > it. The Mandrake security advisory also covers another DoS that'

Mailman DoS CVE-2005-3573, debbug #339095

2005-12-14 Thread Lionel Elie Mamane
ow + + * Don't fall apart if the filename of an attachment is an invalid UTF-8 +string, which leads to a DoS attack (closes: #339095) +This is CVE-2005-3573 + + -- Lionel Elie Mamane <[EMAIL PROTECTED]> Wed, 14 Dec 2005 12:13:45 +0100 + mailman (2.1.5-8) unstable; urgency=low

Re: [PATCH] 2.4.28 and 2.6.10 PATCH FOR uselib() exploit

2005-01-09 Thread Lionel Elie Mamane
On Sat, Jan 08, 2005 at 02:40:52PM -0500, Simon Raven / Eric S. Côté wrote: > 2.4.28 > http://www.grsecurity.net/linux-2.4.28-secfix-200501071141.patch Is huge, touches many areas. Didn't apply cleanly to a pristine 2.4.28. The LKML gives http://linux.bkbits.net:8080/linux-2.4/[EMAIL PROTECTED]

Re: pgp in Debian: obsolete?

2004-09-02 Thread Lionel Elie Mamane
On Thu, Aug 12, 2004 at 11:20:28PM +0200, Florian Weimer wrote: >> Quoting Florian Weimer ([EMAIL PROTECTED]): >> Just out of curiosity, are there now, or have there been in the >> past, any _other_ implementations of the OpenPGP spec, besides >> GnuPG? > GnuPG is not a complete implementation of

Re: VPN question

2002-11-28 Thread Lionel Elie Mamane
On Thu, Nov 28, 2002 at 12:37:03AM +0100, David J. M. Karlsen wrote: > I want to include crypto-patches from kerneli.org as well and these > patches seem to clash with the freeswan ones. The latest freeswan patches include the CryptoAPI stuff. -- Lionel

Re: VPN question

2002-11-28 Thread Lionel Elie Mamane
On Thu, Nov 28, 2002 at 12:37:03AM +0100, David J. M. Karlsen wrote: > I want to include crypto-patches from kerneli.org as well and these > patches seem to clash with the freeswan ones. The latest freeswan patches include the CryptoAPI stuff. -- Lionel -- To UNSUBSCRIBE, email to [EMAIL PRO

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 12:47:24PM +0100, Lionel Elie Mamane wrote: > On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: >> security.debian.org >> Is it possible to set up a mirror somewhere for the time being? > ftp://download.xs4all.nl/pub/debian-securi

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: > security.debian.org > Is it possible to set up a mirror somewhere for the time being? ftp://download.xs4all.nl/pub/debian-security/ is a mirror, too. The question still remains on what will happen for *future* security rele

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 12:47:24PM +0100, Lionel Elie Mamane wrote: > On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: >> security.debian.org >> Is it possible to set up a mirror somewhere for the time being? > ftp://download.xs4all.nl/pub/debian-securi

Re: security.debian.org down, mirror needed

2002-11-20 Thread Lionel Elie Mamane
On Wed, Nov 20, 2002 at 11:04:46AM +0100, Richard van den Berg wrote: > security.debian.org > Is it possible to set up a mirror somewhere for the time being? ftp://download.xs4all.nl/pub/debian-security/ is a mirror, too. The question still remains on what will happen for *future* security rele

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:32:56PM +0100, Andrea Frigido wrote: > OK, now I install kernel-patch-freeswan-ext package, thanks :) > It is compatible with kernel 2.4.18 or I need to use the kernel 2.4.19? I don't know, but I guess it is. If you find out, let us know. -- Lionel pgp9Z6KhYHk10.pgp

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:17:31PM +0100, Andrea Frigido wrote: > Alle 19:07, lunedì 18 novembre 2002, Lionel Elie Mamane ha scritto: >> On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: >>> kernel-patch-freeswan-ext UNSTABLE package or kernel-patch-freeswan

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: > Alle 13:02, giovedì 14 novembre 2002, Lionel Elie Mamane ha scritto: >> On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: >> While using a free OS is always better, you can use any other IPSEC >>

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:32:56PM +0100, Andrea Frigido wrote: > OK, now I install kernel-patch-freeswan-ext package, thanks :) > It is compatible with kernel 2.4.18 or I need to use the kernel 2.4.19? I don't know, but I guess it is. If you find out, let us know. -- Lionel msg07813/pgp0

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:17:31PM +0100, Andrea Frigido wrote: > Alle 19:07, lunedì 18 novembre 2002, Lionel Elie Mamane ha scritto: >> On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: >>> kernel-patch-freeswan-ext UNSTABLE package or kernel-patch-freeswan

Re: VPN question

2002-11-18 Thread Lionel Elie Mamane
On Mon, Nov 18, 2002 at 07:02:59PM +0100, Andrea Frigido wrote: > Alle 13:02, giovedì 14 novembre 2002, Lionel Elie Mamane ha scritto: >> On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: >> While using a free OS is always better, you can use any other IPSEC >>

Re: VPN question

2002-11-14 Thread Lionel Elie Mamane
On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: > I must create a VPN between an external company and a server behind my > firewall. > Company--->its_routermy_firewall<-server > * How to implement this VPN??? I would use IPSEC, but there are other solutio

Re: VPN question

2002-11-14 Thread Lionel Elie Mamane
On Thu, Nov 14, 2002 at 12:43:48PM +0100, Iñaki Martínez wrote: > I must create a VPN between an external company and a server behind my > firewall. > Company--->its_routermy_firewall<-server > * How to implement this VPN??? I would use IPSEC, but there are other solutio

Re: "Latest libpcap & tcpdump sources from tcpdump.org contain a trojan"

2002-11-13 Thread Lionel Elie Mamane
On Wed, Nov 13, 2002 at 08:15:58PM +0100, Lupe Christoph wrote: > Is Debian affected? I checked a few hours ago, and it was not, at least the mirror I'm using. -- Lionel pgpRBCwvNmdOx.pgp Description: PGP signature

Re: "Latest libpcap & tcpdump sources from tcpdump.org contain a trojan"

2002-11-13 Thread Lionel Elie Mamane
On Wed, Nov 13, 2002 at 08:15:58PM +0100, Lupe Christoph wrote: > Is Debian affected? I checked a few hours ago, and it was not, at least the mirror I'm using. -- Lionel msg07715/pgp0.pgp Description: PGP signature

Re: Multiple SSL Virtualhosts on Apache 1.3

2002-11-05 Thread Lionel Elie Mamane
On Tue, Nov 05, 2002 at 11:00:46AM +0100, DEFFONTAINES Vincent wrote: > I managed to create several Virtualhosts on a apache-ssl (1.3) server (same > IP, same port, several names). > The "trick" is to use the same Certificate for every Virtualhost, which will > of course generate a warning on bro

Re: Multiple SSL Virtualhosts on Apache 1.3

2002-11-05 Thread Lionel Elie Mamane
On Tue, Nov 05, 2002 at 11:00:46AM +0100, DEFFONTAINES Vincent wrote: > I managed to create several Virtualhosts on a apache-ssl (1.3) server (same > IP, same port, several names). > The "trick" is to use the same Certificate for every Virtualhost, which will > of course generate a warning on bro

Re: export problems on security updates?

2002-10-09 Thread Lionel Elie Mamane
On Wed, Oct 09, 2002 at 10:21:31PM +0200, Alberto Cortés wrote: >> deb http://security.debian.org/ woody/updates main contrib non-free > Since I am not living in the US, and some security updates deals with > cryptographic software, I understand that it will be illegal for me > downloading thes

Re: export problems on security updates?

2002-10-09 Thread Lionel Elie Mamane
On Wed, Oct 09, 2002 at 10:21:31PM +0200, Alberto Cortés wrote: >> deb http://security.debian.org/ woody/updates main contrib non-free > Since I am not living in the US, and some security updates deals with > cryptographic software, I understand that it will be illegal for me > downloading the

Re: encrypting/decrypting partitions on the fly?

2002-08-08 Thread Lionel Elie Mamane
On Thu, Aug 08, 2002 at 08:47:27AM +0200, [EMAIL PROTECTED] wrote: > Hello! > Anybody know of a tool like PGPDisk for Linux? Google for "Linux encrypted loopback", should give results. -- Lionel pgpg8CvXAWNIt.pgp Description: PGP signature

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 12:21:20PM +0200, eim wrote: > On Wed, 2002-05-01 at 12:10, Lionel Elie Mamane wrote: >> On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: >>> * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown >>> command: "capa&qu

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: > * May 1 11:48:10 foobox in.qpopper[11047]: connect from foo.bar.org > * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown > command: "capa". > > Well, (-ERR Unknown command: "capa") sounds quite strange, > anyone has idea

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 12:21:20PM +0200, eim wrote: > On Wed, 2002-05-01 at 12:10, Lionel Elie Mamane wrote: >> On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: >>> * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown >>> command: "capa&qu

Re: qpopper related question

2002-05-01 Thread Lionel Elie Mamane
On Wed, May 01, 2002 at 11:47:25AM +0200, eim wrote: > * May 1 11:48:10 foobox in.qpopper[11047]: connect from foo.bar.org > * May 1 11:48:10 foobox in.qpopper[11047]: @foo.bar.org: -ERR Unknown > command: "capa". > > Well, (-ERR Unknown command: "capa") sounds quite strange, > anyone has idea

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Lionel Elie Mamane
On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: > What's the best way to figure out the admin for a subnet from a > machine's IP? whois the_ip_adress -- Lionel Mamane pgpMU0pdcNCQO.pgp Description: PGP signature

Re: failed ssh breakins on my exposed www box ..

2002-03-24 Thread Lionel Elie Mamane
On Sun, Mar 24, 2002 at 08:01:04AM -0800, Stephen Hassard wrote: > What's the best way to figure out the admin for a subnet from a > machine's IP? whois the_ip_adress -- Lionel Mamane msg06057/pgp0.pgp Description: PGP signature