new debian kernel

2003-08-14 Thread Martynas Domarkas
Hello, using debian kernel 2.4.18-11 on some servers, after "ps ax" command at the end of input I noticed "Segmentation fault" message. "strace ps ax" gave: open("/proc/1048/environ", O_RDONLY)= 7 read(7, +++ killed by SIGSEGV +++ Is it unsuccesfull patch for http://cve.mitre.org/cgi-bin/

Re: new debian kernel

2003-08-14 Thread Martynas Domarkas
Yes it is fixed in kernel-source 2.4.18-13. However, due to another issue introduced by the security fix, you should download the latest kernels from http://auric.debian.org/~herbert/. Thanks for your answer. 2.4.18-12 works without segfaults. Is something wrong in 2.4.18-12 more? Is that local

Re: new debian kernel

2003-08-13 Thread Martynas Domarkas
Yes it is fixed in kernel-source 2.4.18-13. However, due to another issue introduced by the security fix, you should download the latest kernels from http://auric.debian.org/~herbert/. Thanks for your answer. 2.4.18-12 works without segfaults. Is something wrong in 2.4.18-12 more? Is that local

new debian kernel

2003-08-13 Thread Martynas Domarkas
Hello, using debian kernel 2.4.18-11 on some servers, after "ps ax" command at the end of input I noticed "Segmentation fault" message. "strace ps ax" gave: open("/proc/1048/environ", O_RDONLY)= 7 read(7, +++ killed by SIGSEGV +++ Is it unsuccesfull patch for http://cve.mitre.org/cgi-bin/

Re: Passwordless Authentication (was Re: How to reduce sid security)

2003-08-01 Thread Martynas Domarkas
Pn, 2003-08-01 12:04, Kjetil Kjernsmo rašė: > On Friday 01 August 2003 04:10, Peter Cordes wrote: > > You should use ssh-keygen to create a keypair on each machine, and > > copy the public key from the machine you generated it on to the other > > machine. This allows quick passwordless authenticat

Re: Passwordless Authentication (was Re: How to reduce sid security)

2003-08-01 Thread Martynas Domarkas
Pn, 2003-08-01 12:04, Kjetil Kjernsmo rašė: > On Friday 01 August 2003 04:10, Peter Cordes wrote: > > You should use ssh-keygen to create a keypair on each machine, and > > copy the public key from the machine you generated it on to the other > > machine. This allows quick passwordless authenticat

Re: evolution

2003-06-30 Thread Martynas Domarkas
Pn, 2003-06-27 05:59, Jean Christophe ANDRÉ rašė: > Matt Zimmerman écrivait : > > > There are a LOT of connetcions: ~700 in a 5 minutes. I did not find any > > > configuration options with that hosts. What could it be? > > This is surely an evolution "feature" where it means to provide you with >

Re: evolution

2003-06-30 Thread Martynas Domarkas
Pn, 2003-06-27 05:59, Jean Christophe ANDRÉ rašė: > Matt Zimmerman écrivait : > > > There are a LOT of connetcions: ~700 in a 5 minutes. I did not find any > > > configuration options with that hosts. What could it be? > > This is surely an evolution "feature" where it means to provide you with >

evolution

2003-06-26 Thread Martynas Domarkas
ution-exec tcp 0 1 192.168.0.1:33933 63.236.73.20:80 SYN_SENT 4055/evolution-exec There are a LOT of connetcions: ~700 in a 5 minutes. I did not find any configuration options with that hosts. What could it be? -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698

evolution

2003-06-26 Thread Martynas Domarkas
ution-exec tcp 0 1 192.168.0.1:33933 63.236.73.20:80 SYN_SENT 4055/evolution-exec There are a LOT of connetcions: ~700 in a 5 minutes. I did not find any configuration options with that hosts. What could it be? -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698 44331

Re: pppoe

2003-06-23 Thread Martynas Domarkas
Sorry people, there was my stupid mistake. DSL username and password are very similar... So I mixed them :- Regards, Martynas Pr, 2003-06-23 14:05, Martynas Domarkas rašė: > Hi, > > I have little question about pppoe. Earlier I used Slackware with self > compiled rp-pppoe

Re: pppoe

2003-06-23 Thread Martynas Domarkas
Pr, 2003-06-23 15:01, Robert Ian Smit rašė: > There is a nice package called pppoeconf that will setup a PPPoE > connection. > Yes, I used exactly THAT package for pppoe configuration. I just checked configuration files manualy. Regards, Martynas > > Bob > > > -- > To UNSUBSCRIBE, email t

Re: pppoe

2003-06-23 Thread Martynas Domarkas
Sorry people, there was my stupid mistake. DSL username and password are very similar... So I mixed them :- Regards, Martynas Pr, 2003-06-23 14:05, Martynas Domarkas rašė: > Hi, > > I have little question about pppoe. Earlier I used Slackware with self > compiled rp-pppoe

pppoe

2003-06-23 Thread Martynas Domarkas
Jun 22 12:40:22 hanzanet pppoe[539]: read (asyncReadFromPPP): Input/output error Jun 22 12:40:22 hanzanet pppoe[539]: Sent PADT Can somebody give me hints? -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698 44331

Re: pppoe

2003-06-23 Thread Martynas Domarkas
Pr, 2003-06-23 15:01, Robert Ian Smit rašė: > There is a nice package called pppoeconf that will setup a PPPoE > connection. > Yes, I used exactly THAT package for pppoe configuration. I just checked configuration files manualy. Regards, Martynas > > Bob > > > -- > To UNSUBSCRIBE, email t

pppoe

2003-06-23 Thread Martynas Domarkas
Jun 22 12:40:22 hanzanet pppoe[539]: read (asyncReadFromPPP): Input/output error Jun 22 12:40:22 hanzanet pppoe[539]: Sent PADT Can somebody give me hints? -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +

Re: Re[2]: apache

2003-06-10 Thread Martynas Domarkas
An, 2003-06-10 13:46, Dominik Schulz rašė: > Perhaps I've got you wrong but wouldn't > --- snip --- > TransferLog "| /usr/sbin/rotatelogs > /var/www/domain.tld/logs/domain.tld-%Y-%m-%d_access.log 604800" > --- end --- > do it? > > Martynas Domarkas &l

Re: Re[2]: apache

2003-06-10 Thread Martynas Domarkas
An, 2003-06-10 13:46, Dominik Schulz rašė: > Perhaps I've got you wrong but wouldn't > --- snip --- > TransferLog "| /usr/sbin/rotatelogs > /var/www/domain.tld/logs/domain.tld-%Y-%m-%d_access.log 604800" > --- end --- > do it? > > Martynas Domarkas &l

Re: apache

2003-06-10 Thread Martynas Domarkas
An, 2003-06-10 12:56, Teun Vink rašė: > On Tue, 2003-06-10 at 11:07, Martynas Domarkas wrote: > [...] > > > > Thanks, but I realy do not like instalation of another packages. There > > must be a way to do this with apache configuration. > > You could add a line t

Re: apache

2003-06-10 Thread Martynas Domarkas
An, 2003-06-10 12:01, Jamie Heilman rašė: > Martynas Domarkas wrote: > > Hi. I would like to use date string in apache log file names. Is there a > > way to use some directive in httpd.conf to be parsed as shell command > > like `date +%Y%m%d` or some other way to solve th

apache

2003-06-10 Thread Martynas Domarkas
creation after apache process receives SIGUSR1. -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698 44331

Re: apache

2003-06-10 Thread Martynas Domarkas
An, 2003-06-10 12:56, Teun Vink rašė: > On Tue, 2003-06-10 at 11:07, Martynas Domarkas wrote: > [...] > > > > Thanks, but I realy do not like instalation of another packages. There > > must be a way to do this with apache configuration. > > You could add a line t

Re: apache

2003-06-10 Thread Martynas Domarkas
An, 2003-06-10 12:01, Jamie Heilman rašė: > Martynas Domarkas wrote: > > Hi. I would like to use date string in apache log file names. Is there a > > way to use some directive in httpd.conf to be parsed as shell command > > like `date +%Y%m%d` or some other way to solve th

apache

2003-06-10 Thread Martynas Domarkas
creation after apache process receives SIGUSR1. -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698 44331 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

LVS+grsecurity

2003-05-28 Thread Martynas Domarkas
, 2.4.20, patched with grsecurity. -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698 44331 -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

LVS+grsecurity

2003-05-28 Thread Martynas Domarkas
, 2.4.20, patched with grsecurity. -- Pagarbiai IT sistemų administratorius Martynas Domarkas tel.: +370 698 44331

Daylight Saving

2003-03-28 Thread Martynas Domarkas
Hi, can somebody tell me in what hour exactly computers clock is ajusted because of DST in Debian/Woody? Or maybe is this change independent from OS? -- Pagarbiai IT sistemų administratorius Martynas Domarkas

Daylight Saving

2003-03-27 Thread Martynas Domarkas
Hi, can somebody tell me in what hour exactly computers clock is ajusted because of DST in Debian/Woody? Or maybe is this change independent from OS? -- Pagarbiai IT sistemų administratorius Martynas Domarkas -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubs

Re: kernel ptrace bug

2003-03-19 Thread Martynas Domarkas
Yes, but no programmer may access production servers :-) M. Tr, 2003-03-19 18:26, Phillip Hofmeister rašė: > On Wed, 19 Mar 2003 at 05:18:05PM +0200, Martynas Domarkas wrote: > > Grsecurity patch can limit ordinary user use ptrace. Can it help avoid > > ptrace exploit? >

Re: kernel ptrace bug

2003-03-19 Thread Martynas Domarkas
Yes, but no programmer may access production servers :-) M. Tr, 2003-03-19 18:26, Phillip Hofmeister rašė: > On Wed, 19 Mar 2003 at 05:18:05PM +0200, Martynas Domarkas wrote: > > Grsecurity patch can limit ordinary user use ptrace. Can it help avoid > > ptrace exploit? >

kernel ptrace bug

2003-03-19 Thread Martynas Domarkas
Grsecurity patch can limit ordinary user use ptrace. Can it help avoid ptrace exploit? Martynas

kernel ptrace bug

2003-03-19 Thread Martynas Domarkas
Grsecurity patch can limit ordinary user use ptrace. Can it help avoid ptrace exploit? Martynas -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Re[2]: HTTP tunnel with linux server and windows client

2003-03-04 Thread Martynas Domarkas
We use following: user connects to firewall (kind of a commercial software firewall) using VPN client. And after authentication some firewall rules are applied. Session is encrypted. User can do some job on an internal network. PPTP is something like and free: http://project.terminus.sk/wmpptpd/

Re: Re[2]: HTTP tunnel with linux server and windows client

2003-03-04 Thread Martynas Domarkas
We use following: user connects to firewall (kind of a commercial software firewall) using VPN client. And after authentication some firewall rules are applied. Session is encrypted. User can do some job on an internal network. PPTP is something like and free: http://project.terminus.sk/wmpptpd/

Re: HTTP tunnel with linux server and windows client

2003-03-03 Thread Martynas Domarkas
Try this: http://www.htthost.com/ , but use it on your own risk. It is a real security hole. Better is to ask system administrator open some rules on firewall for you. Regards, Martynas Pr, 2003-03-03 17:30, Ant rašė: > Hello , > Is there is any software to bypass http proxy > > --- --{

Re: HTTP tunnel with linux server and windows client

2003-03-03 Thread Martynas Domarkas
Try this: http://www.htthost.com/ , but use it on your own risk. It is a real security hole. Better is to ask system administrator open some rules on firewall for you. Regards, Martynas Pr, 2003-03-03 17:30, Ant rašė: > Hello , > Is there is any software to bypass http proxy > > --- --{

Re: Apache Virtual Hosts Chroot ?

2003-02-25 Thread Martynas Domarkas
I think you can setup chrooted logins for uploading files: your chroot will run sshd (proftpd?) and users will have their homes in chroot to. Play with home directory permisions so they have no possibility access files they don't own. Another way is let people upload files to other location than y

Re: Apache Virtual Hosts Chroot ?

2003-02-25 Thread Martynas Domarkas
I think you can setup chrooted logins for uploading files: your chroot will run sshd (proftpd?) and users will have their homes in chroot to. Play with home directory permisions so they have no possibility access files they don't own. Another way is let people upload files to other location than y

Re: Putting Apache, PHP, Tomcat and CGI in a jail

2003-01-06 Thread Martynas Domarkas
as on normal apache... Comments and usage instructions are inside the script. Regards, Martynas Sk, 2003-01-05 05:34, George Georgalis rašė: > On Sun, Jan 05, 2003 at 01:16:31AM +0100, Javier Fern?ndez-Sanguino Pe?a > wrote: > >On Sat, Jan 04, 2003 at 09:00:45PM +0200, Martyn

Re: Putting Apache, PHP, Tomcat and CGI in a jail

2003-01-05 Thread Martynas Domarkas
as on normal apache... Comments and usage instructions are inside the script. Regards, Martynas Sk, 2003-01-05 05:34, George Georgalis raðë: > On Sun, Jan 05, 2003 at 01:16:31AM +0100, Javier Fern?ndez-Sanguino Pe?a wrote: > >On Sat, Jan 04, 2003 at 09:00:45PM +0200, Martynas Domarkas

Re: Putting Apache, PHP, Tomcat and CGI in a jail

2003-01-05 Thread Martynas Domarkas
k so. Now I try write a script for creation of chrooted environment which uses standart unix tools: bash, ldd, gawk (awk), grep, file. In case of success I send link to you ;-) Regards, Martynas Sk, 2003-01-05 02:16, Javier Fernández-Sanguino Peña rašė: > On Sat, Jan 04, 2003 at 09:00:45PM +020

Re: Putting Apache, PHP, Tomcat and CGI in a jail

2003-01-05 Thread Martynas Domarkas
k so. Now I try write a script for creation of chrooted environment which uses standart unix tools: bash, ldd, gawk (awk), grep, file. In case of success I send link to you ;-) Regards, Martynas Sk, 2003-01-05 02:16, Javier Fernández-Sanguino Peña rašė: > On Sat, Jan 04, 2003 at 09:00:45P

Re: Putting Apache, PHP, Tomcat and CGI in a jail

2003-01-04 Thread Martynas Domarkas
Hi, I'm currently trying to use makejail... it does not work very good. Simple way is copy /bin/bash with libraries (try ldd /bin/bash to find out which libs you need), so you can do chroot /your/chroot/dir. After do dpkg -L apache and copy contents of apache package to chroot, also repeat it with

Re: Putting Apache, PHP, Tomcat and CGI in a jail

2003-01-04 Thread Martynas Domarkas
Hi, I'm currently trying to use makejail... it does not work very good. Simple way is copy /bin/bash with libraries (try ldd /bin/bash to find out which libs you need), so you can do chroot /your/chroot/dir. After do dpkg -L apache and copy contents of apache package to chroot, also repeat it with