Re: encrpyt harddrive without passphrase/userinput

2006-02-26 Thread Mario Ohnewald
tephan > Mario Ohnewald wrote: > > Hi Horst > > > > On Sun, 2006-02-26 at 22:23 +0100, Horst Pflugstaedt wrote: > > > >> On Sun, Feb 26, 2006 at 10:11:44PM +0100, Mario Ohnewald wrote: > >> > >>> Hello security list! > >

Re: encrpyt harddrive without passphrase/userinput

2006-02-26 Thread Mario Ohnewald
Hi Horst On Sun, 2006-02-26 at 22:23 +0100, Horst Pflugstaedt wrote: > On Sun, Feb 26, 2006 at 10:11:44PM +0100, Mario Ohnewald wrote: > > Hello security list! > > > > I would like to secure the harddrive/partitions of linux box. > > > > The whole setup must f

encrpyt harddrive without passphrase/userinput

2006-02-26 Thread Mario Ohnewald
Hello security list! I would like to secure the harddrive/partitions of linux box. The whole setup must fulfill the following requirements: a) it must be able to boot (remotely) without userinput/passphrase b) the importtant partitions such as /etc, /var, /usr and /home must be encrypted/protect

Re: suid

2004-04-17 Thread Mario Ohnewald
On Saturday 17 April 2004 01:33, Bernd Eckenfels wrote: > In article <[EMAIL PROTECTED]> you wrote: > > -rwsr-xr-x1 root root22460 Oct 1 2001 /usr/bin/crontab > > > > yes, because only in this condition normal user can set crontab rules. > > this deends on the cron used. The cron

Re: suid

2004-04-17 Thread Mario Ohnewald
On Saturday 17 April 2004 01:33, Bernd Eckenfels wrote: > In article <[EMAIL PROTECTED]> you wrote: > > -rwsr-xr-x1 root root22460 Oct 1 2001 /usr/bin/crontab > > > > yes, because only in this condition normal user can set crontab rules. > > this deends on the cron used. The cron

suid

2004-04-16 Thread Mario Ohnewald
Hello! Everybody knows that files with a suid bit set can be dangerous. Well, i was asking myself today why exactly linux uses the suid bit files?! Could someone please explain that to me? Example: ~$ ls -lah /var/spool/cron/crontabs/user -rw---1 root user 408 Apr 16 Ok, th

suid

2004-04-16 Thread Mario Ohnewald
Hello! Everybody knows that files with a suid bit set can be dangerous. Well, i was asking myself today why exactly linux uses the suid bit files?! Could someone please explain that to me? Example: ~$ ls -lah /var/spool/cron/crontabs/user -rw---1 root user 408 Apr 16 Ok, th

Tripwire email

2004-04-13 Thread Mario Ohnewald
Hello list! This is a part of my tripwire config file: # # Critical System Boot Files # These files are critical to a correct system boot. # ( rulename = "Critical system boot files", emailto = [EMAIL PROTECTED], severity = $(SIG_HI) ) { /boot -> $(SEC_CRIT) ;

Tripwire email

2004-04-13 Thread Mario Ohnewald
Hello list! This is a part of my tripwire config file: # # Critical System Boot Files # These files are critical to a correct system boot. # ( rulename = "Critical system boot files", emailto = [EMAIL PROTECTED], severity = $(SIG_HI) ) { /boot -> $(SEC_CRIT) ;

bsign

2004-02-17 Thread Mario Ohnewald
Hello! Is there a bsign howto out there or any more info than the manpage? The problem i am stuck with at the moment is: bsign --sign -i / -e /proc -I -s --P "--homedir keydir" Enter pass phrase: bsign: incorrect passphrase or gpg not installed I never set a passphrase i think. Anyway, a dpkg

bsign

2004-02-17 Thread Mario Ohnewald
Hello! Is there a bsign howto out there or any more info than the manpage? The problem i am stuck with at the moment is: bsign --sign -i / -e /proc -I -s --P "--homedir keydir" Enter pass phrase: bsign: incorrect passphrase or gpg not installed I never set a passphrase i think. Anyway, a dpkg

RE: execute application from webinterface

2003-09-02 Thread mario ohnewald
Hello! > -Original Message- > From: Jens Gutzeit [mailto:[EMAIL PROTECTED] > Sent: 02 September 2003 18:44 > To: debian-security@lists.debian.org > Subject: Re: execute application from webinterface > > > On Tuesday 02 September 2003 19:25, Jens Gutzeit wrote: > > > > what's wrong with mak

RE: execute application from webinterface

2003-09-02 Thread mario ohnewald
Hello! > -Original Message- > From: Jens Gutzeit [mailto:[EMAIL PROTECTED] > Sent: 02 September 2003 18:44 > To: [EMAIL PROTECTED] > Subject: Re: execute application from webinterface > > > On Tuesday 02 September 2003 19:25, Jens Gutzeit wrote: > > > > what's wrong with making the program

execute application from webinterface

2003-09-01 Thread mario ohnewald
Hello List! What is the securest way of starting a application, like ping, from a webinterface as a diffrent user. Lets say, to run ping 123.456.789.000 as user user123. If i use "system", it executes it as www-data. Any idea how i could solve this problem? With php, perl, bash, etc... ? Thank y

execute application from webinterface

2003-09-01 Thread mario ohnewald
Hello List! What is the securest way of starting a application, like ping, from a webinterface as a diffrent user. Lets say, to run ping 123.456.789.000 as user user123. If i use "system", it executes it as www-data. Any idea how i could solve this problem? With php, perl, bash, etc... ? Thank y

Re: Heute abend

2003-07-29 Thread Mario Ohnewald
> and in english? He will properly drive up with the bike. Can you bring the battery changer for the mobile with you onto the mountain. -- Wrong address i guess :D > > On Tue, 29 Jul 2003, Andreas Zeitz-Fehse wrote: > > > Hi, > > > > > > ich werd wohl heute mit dem Fahrad hochfahren. Kanns

Re: Heute abend

2003-07-29 Thread Mario Ohnewald
> and in english? He will properly drive up with the bike. Can you bring the battery changer for the mobile with you onto the mountain. -- Wrong address i guess :D > > On Tue, 29 Jul 2003, Andreas Zeitz-Fehse wrote: > > > Hi, > > > > > > ich werd wohl heute mit dem Fahrad hochfahren. Kanns

RE: configure ssh-access

2003-07-07 Thread Mario Ohnewald
Hello! >-Original Message- >From: Anne Carasik [mailto:[EMAIL PROTECTED] >Sent: Monday, July 07, 2003 5:05 PM >To: [EMAIL PROTECTED] >Cc: debian-security@lists.debian.org >Subject: Re: configure ssh-access > > >Why not just limit the access through SSH public key? >It sounds like that woul

RE: configure ssh-access

2003-07-07 Thread Mario Ohnewald
Hello! >-Original Message- >From: Anne Carasik [mailto:[EMAIL PROTECTED] >Sent: Monday, July 07, 2003 5:05 PM >To: [EMAIL PROTECTED] >Cc: [EMAIL PROTECTED] >Subject: Re: configure ssh-access > > >Why not just limit the access through SSH public key? >It sounds like that would accomplish wh

RE: chroot, su and sudo

2003-06-16 Thread Mario Ohnewald
Hi, >-Original Message- >From: Vincent Hanquez [mailto:[EMAIL PROTECTED] >Sent: Monday, June 16, 2003 10:46 AM >To: Mario Ohnewald >Cc: debian-security@lists.debian.org >Subject: Re: chroot, su and sudo > > >On Mon, Jun 16, 2003 at 10:22:49AM +0200, Mario Ohn

chroot, su and sudo

2003-06-16 Thread Mario Ohnewald
Hello! I want to chroot a application/gameserver. What is the better/securest way? 1.) "Chroot /path" and then do a "su -s /bin/sh user -c start.sh" or 2.) "su -s /bin/sh user" and then do the "chroot /path" as normal user and execute the "start.sh" in the chroot? Solution 2 does not need a root

RE: chroot, su and sudo

2003-06-16 Thread Mario Ohnewald
Hi, >-Original Message- >From: Vincent Hanquez [mailto:[EMAIL PROTECTED] >Sent: Monday, June 16, 2003 10:46 AM >To: Mario Ohnewald >Cc: [EMAIL PROTECTED] >Subject: Re: chroot, su and sudo > > >On Mon, Jun 16, 2003 at 10:22:49AM +0200, Mario Ohnewald wrote: >

chroot, su and sudo

2003-06-16 Thread Mario Ohnewald
Hello! I want to chroot a application/gameserver. What is the better/securest way? 1.) "Chroot /path" and then do a "su -s /bin/sh user -c start.sh" or 2.) "su -s /bin/sh user" and then do the "chroot /path" as normal user and execute the "start.sh" in the chroot? Solution 2 does not need a root