Re: how to fix rootkit?

2012-02-09 Thread Répási Tibor
But you can't trust ld.so and all those shared libraries ... sure you may link all your tools fully static, even then they rely on syscalls and devices, which may also not trustworthy due to the possibly compromised kernel. On 02/08/2012 06:46 PM, Fernando Mercês wrote: Reading memory after t

Re: /usr/bin/ssh-copy-id & trojan or variant UNIX/Exploit-SSHIDEN

2004-01-15 Thread Répási Tibor
Hy, I have the same file on my woody box. Don't worry about it: 1. f-prot /usr/bin/ssh-copy-id Virus scanning report - 15. January 2004 21:26 F-PROT 3.12d SIGN.DEF created 9. January 2004 SIGN2.DEF created 9. January 2004 MACRO.DEF created 12. January 2004 Search: /usr/

Re: /usr/bin/ssh-copy-id & trojan or variant UNIX/Exploit-SSHIDEN

2004-01-15 Thread Répási Tibor
Hy, I have the same file on my woody box. Don't worry about it: 1. f-prot /usr/bin/ssh-copy-id Virus scanning report - 15. January 2004 21:26 F-PROT 3.12d SIGN.DEF created 9. January 2004 SIGN2.DEF created 9. January 2004 MACRO.DEF created 12. January 2004 Search: /usr/bin

Re: bridge firewall with kernel 2.4.22

2003-12-01 Thread Répási Tibor
Hy, bridging is not routing! A bridge forwards frames at leyer 2, a router forwards ip packets at leyer 3. However iptables is a 3rd leyer firewall, therefore bridged traffic is not affected by any iptables rule! Francisco Oliveira wrote: hi I have compiled kernel 2.4.22 for bridge and ipt

Re: bridge firewall with kernel 2.4.22

2003-12-01 Thread Répási Tibor
Hy, bridging is not routing! A bridge forwards frames at leyer 2, a router forwards ip packets at leyer 3. However iptables is a 3rd leyer firewall, therefore bridged traffic is not affected by any iptables rule! Francisco Oliveira wrote: hi I have compiled kernel 2.4.22 for bridge and iptabl

Re: Verisign does hijack 'country' domains !!!

2003-09-28 Thread Répási Tibor
Hy Michelle, Your problem seems to be offtopic here. All the same we have noticed that some e-mail sent from tudelf.nl to iit.uni-miskolc.hu was lost. According to our MTA logs the messages was never tried to deliver to us, so it seems the flaw is at tudelft.nl. Two professors at Delft was ver

Re: Verisign does hijack 'country' domains !!!

2003-09-28 Thread Répási Tibor
Hy Michelle, Your problem seems to be offtopic here. All the same we have noticed that some e-mail sent from tudelf.nl to iit.uni-miskolc.hu was lost. According to our MTA logs the messages was never tried to deliver to us, so it seems the flaw is at tudelft.nl. Two professors at Delft was very

Re: sendmail + mailscanner

2003-04-14 Thread Répási Tibor
Hy, just follow the steps described in /usr/share/sendmail/examples/amavis download the lates sources and it works. I've installed it a few weeks ago and it is running well. I'm using it with f-prot, but You can config it for any antivir software You want. Regards, Tibor Repa

ping6

2002-01-17 Thread Répási Tibor
Hy! What is /bin/ping6 ??? Is it normal that /bin/ping and /bin/ping6 has setuid to root? regards, Tibor Repasi

ping6

2002-01-17 Thread Répási Tibor
Hy! What is /bin/ping6 ??? Is it normal that /bin/ping and /bin/ping6 has setuid to root? regards, Tibor Repasi -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

RE: strange auth log

2002-01-07 Thread Répási Tibor
This box is hosted in a hosting center, I thing there aren't any cats or other animals. It is a possibility that somebody droped his coat or something else to the keyboard, but a more important question is, why crashes the system so that it needed a hw reset to restart? I don't find any other

RE: strange auth log

2002-01-07 Thread Répási Tibor
This box is hosted in a hosting center, I thing there aren't any cats or other animals. It is a possibility that somebody droped his coat or something else to the keyboard, but a more important question is, why crashes the system so that it needed a hw reset to restart? I don't find any other

strange auth log

2002-01-07 Thread Répási Tibor
Hi there, I've some strange lines in my auth.log : Jan 5 19:45:57 panda PAM_unix[500]: bad username [ ] Jan 5 19:46:00 panda login[500]: FAILED LOGIN (1) on `tty1' FOR `UNKNOWN', User not known to the underlying authentication module Jan 5 19:46:05 panda PAM_unix[500]: bad username [ ] Jan

strange auth log

2002-01-06 Thread Répási Tibor
Hi there, I've some strange lines in my auth.log : Jan 5 19:45:57 panda PAM_unix[500]: bad username [ ] Jan 5 19:46:00 panda login[500]: FAILED LOGIN (1) on `tty1' FOR `UNKNOWN', User not known to the underlying authentication module Jan 5 19:46:05 panda PAM_unix[500]: bad username [ ] Ja