Re: about bash and Debian Lenny

2014-10-06 Thread Simon Valiquette
3.2-4+deb5u1.dsc is fine AFAIK. Simon Valiquette -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: https://lists.debian.org/5432e22d.1040...@ieee.org

Re: RSA/DSA

2011-11-29 Thread Simon Valiquette
ues anyway) I don't think you will have any problem. If you want to be sure, you can increase the verbosity of OpenSSH and check in the logs if any connection ever used something else than RSA. If after few months no host ever used DSA, you'll know you probably can disable it c

Re: Recent libssl update.

2011-11-13 Thread Simon Valiquette
o restart it if you want to be sure it use the new version of the library. I hope that makes thing clearer. Simon Valiquette -- To UNSUBSCRIBE, email to debian-security-requ...@lists.debian.org with a subject of "unsubscribe". Trouble? Contact listmas...@lists.debian.org Archive: http://

Re: how to send IP packets by myself

2009-09-22 Thread Simon Valiquette
tantan un jour écrivit: Hello, to know someone from using a packet generator? tcpreplay allow you to send specific packets from a file, including invalid ones AFAIK. Since you can alter the packets, it can be useful for testing the application when receiving bad data like a string that is

Re: PGP key to use to contact the Security Team

2009-01-07 Thread Simon Valiquette
Joey Schulze un jour écrivit: Simon Valiquette wrote: In the Securing Debian Manual, the key id to use to send an encrypted email to the security team is 363CCD95, but on the following link, it is F2E861A3 that is listed instead. http://www.debian.org/security/faq.en.html#contact Maybe

PGP key to use to contact the Security Team

2008-12-29 Thread Simon Valiquette
could someone clarify what will happens after it expire in six weeks? Will it be replaced by a new key, or will the expiration date simply be changed? 3. If the old key 363CCD95 is not used anymore, is there any reasons for not revoking it? Thank you in advance for the clarifications, Simon Valiquett

Re: Root login

2008-09-14 Thread Simon Valiquette
I only made some quick tests by disabling one tty in securetty, so you should check It before trusting that It works as intended. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: apt-get not upgrading kernel

2008-09-12 Thread Simon Valiquette
security problem (or hiding/fixing the bug by pure luck). Checking for that bug is not very difficult, but checking for this bug and all the other one can be very time consumming and boring, which can explain some delay. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with

Re: apt-get not upgrading kernel

2008-09-12 Thread Simon Valiquette
fect 2.6.18? More specifically, can someone confirm that CVE-2008-3915 doesn't affect the 2.6.18 kernel series in Debian? If I believe this link, this bug is not limited to 2.6.24 in Etch-and-a-half. http://web.nvd.nist.gov/view/vuln/detail?vulnId=CVE-2008-3915 Simon Valiquette -

Re: apt-get not upgrading kernel

2008-09-12 Thread Simon Valiquette
ge at your place. Hopefully, the security team will eventually release an update for the other kernel. If you can't wait, you can try to manualy patch your kernel for the security issues that concern you the most and recompile. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PR

Re: Password leaks are security holes

2008-08-29 Thread Simon Valiquette
Eduardo M KALINOWSKI un jour écrivit: Simon Valiquette wrote: Personally, I would prefer never to see password stored in clear text anywhere, whatever the file permissions are. And If I really want to still see them, I certainly won't complain if all I have to do is make a small chan

Re: DNS and cats: Password leaks are security holes

2008-08-28 Thread Simon Valiquette
W. Martin Borgert un jour écrivit: On 2008-08-28 20:40, Simon Valiquette wrote: That's obviously true, but that doesn't cover the case when logs are copied to a second system with sysadmins that doesn't have access to the first server. And if someone use the standard 514 sysl

Re: Password leaks are security holes

2008-08-28 Thread Simon Valiquette
rd too often (possibly because they sometime put their password in the user field) then they start writting down the password somewhere they think nobody will find It, even if It is forbiden by policy. Policy won't change human nature, sorry. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Fwd: Password leaks are security holes

2008-08-28 Thread Simon Valiquette
most likely a very bad password that someone could guess anyway, so that is a non-issue (except for the fact that the password should obviously be changed for a better one). Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Microsoft-IIS/6.0 serves up Debian... WTF!

2008-06-08 Thread Simon Valiquette
t you don't like to see them lying about the server application and version they use, which is something done by a lot of people on production systems that directly face the Internet. Simon Valiquette -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.6 (Linux PPC) iD8DBQFITE9qJPE+P+aMAJI

Re: Accepted openssh-blacklist 0.3 (source all)

2008-05-21 Thread Simon Valiquette
roper format for SSH. In any case, It can generate 2048 DSA keys or even longer ones if needed. Look at those man pages and on Google. man openssl man dsaparam man gendsa Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1571-1] vulnerability of past SSH/SSL sessions

2008-05-14 Thread Simon Valiquette
Micah Anderson un jour écrivit: * Simon Valiquette <[EMAIL PROTECTED]> [2008-05-14 16:36-0400]: In other words, if a vulnerable key have been involved, and if someone was able to intercept and save the encrypted data, he/she can now decipher It, whether It is passwords, ssh se

Re: [SECURITY] [DSA 1571-1] vulnerability of past SSH/SSL sessions

2008-05-14 Thread Simon Valiquette
probably easily answer this one. I still need to change the passwords and host key of every possibly affected system (mostly done), but I would feel better by knowing exactly what to expect. Thank you, Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: securing server

2008-05-07 Thread Simon Valiquette
en care of). Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Kernel upgrade for 3Ware Driver issues?

2008-04-23 Thread Simon Valiquette
ude both fix at the same time. But there should be an official way to get major problems fixed when the risk of breaking somethings is low enough. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1494-1] New linux-2.6 packages fix privilege escalation

2008-02-11 Thread Simon Valiquette
And maybe make a statement about It if an architecture is not affected (though It is obviously not the case here). Simon Valiquette http://gulus.USherbrooke.ca -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.6 (Linux PPC) iD8DBQFHsNVRJPE+P+aMAJIRA9XjAKDBFjM1qF7Uoz69bWAqmShNgHr2vQCeJ

Re: Firewall with woody

2007-10-17 Thread Simon Valiquette
uch better than Sarge in my opinion and would go directly there. If you are paranoid, you will also want to activate SELinux. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

missing security updates for powerpc

2007-08-29 Thread Simon Valiquette
t-get -Vu build-dep rsync sudo apt-get -Vu source --compile rsync dpkg -i rsync_2.6.9-2etch1_powerpc.deb At least, I was not forced to wait for support and could recompile or patch It myself, which would not have been possible with most closed source software :o) Simon Valiquette -BEGI

Re: [DSA 1359-1] New dovecot packages fix directory traversal

2007-08-28 Thread Simon Valiquette
-BEGIN PGP SIGNED MESSAGE- Hash: RIPEMD160 Simon Valiquette un jour écrivit: > > There is no updated packages for Debian Etch PowerPC, contrarily > to what is stated on the previous line. > > > In case sec.deb.org/dists/etch/updates/main/binary-powerpc/Packages.g

Re: [DSA 1360-1] New rsync packages fix arbitrary code execution

2007-08-28 Thread Simon Valiquette
c.deb file, but realized the whole section was also missing in the advisory. Actually, the file have not been uploaded at all on security.debian.org Is there again a problem with the build host or something? Simon Valiquette -BEGIN PGP SIGNATURE- Version: G

Re: secure installation

2007-08-16 Thread Simon Valiquette
an It will solve, and not makes the computer significantly more secure (many trojan will use port 80 or 21 anyway). But adding the option to install a firewall in the expert mode makes sense to me. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: ftpd - security thread ?

2007-05-05 Thread Simon Valiquette
il only when I was about to answer. How to reproduce It? apt-get -Vu remove --purge ftpd Then your next installation will again download ftpd from this mirror. Unless me missed something, problem solved. Simon Valiquette -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of &qu

Re: GPG errors from apt update

2006-08-31 Thread Simon Valiquette
ght be worth to verify. Simon Valiquette http://gulus.USherbrooke.ca -BEGIN PGP SIGNATURE- Version: GnuPG v1.4.5 (Linux PPC) iD8DBQFE96xfJPE+P+aMAJIRA448AJ423Wn32g6MgB6fM+yDCytZ2wiXtgCeNMkp RkaffrOc1zYvs1gWLCQKuJQ= =xJSd -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to [EMAIL PROTEC