Re: md5 hashes used in security announcements

2008-10-24 Thread paddy
but i didn't get any reply at > > all > > from this. has it been overlooked? > > I guess not, it's just strange that you think this is not > known to us. Is there a bug number ? Regards, Paddy -- Segmentation fault (core dumped): .sig too big -- To UNSUBSCRI

Re: [SECURITY] [DSA 1571-1] New openssl packages fix predictable random number generator

2008-05-13 Thread paddy
ein. I never tire of reading that file ... Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Install process certification

2008-01-04 Thread paddy
you be satisfied by checking a signature of a checksum of the CD against a public key that you trust ? http://www.debian.org/CD/faq/#verify Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Bug#439335: CVE-2007-4131: GNU tar Directory Traversal

2007-12-19 Thread paddy
etc/passwd, I'd say this is > > grave bug. > > This bug is monitored via the security tracker: > http://security-tracker.debian.net/tracker/CVE-2007-4131 > So they should be aware of it. just noticed this going past in an osx update and had a "what ever happenned to that?&quo

Re: perl regex vulnerability - debian - pcre only?

2007-11-06 Thread paddy
according to proportions of debian, security, perl, beer, buffy and a pony. Thank you.) Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Firewall with woody

2007-10-17 Thread paddy
y-tracker.debian.net/tracker/ are handy. Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Firewall with woody

2007-10-17 Thread paddy
l, is no longer supported. I did hope the original poster would find them useful resources in the context of your observation about checking for vulnerabilities. Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Firewall with woody

2007-10-17 Thread paddy
he release of stable, something like a year. 2. Upgrading your system is documented, tested and supported. Kudos to all who make it possible. Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-22 Thread paddy
ther there isn't a sufficiently different needs for users of differing experience that it might make sense to have an option at install time. It is a commonly used idiom. Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-21 Thread paddy
t; - Are you a novice user running KDE: use guarddog or knetfilter is one of those installed by default ? Regards, Paddy Smith -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-21 Thread paddy
interface controlled systems ? Is the whole idea of such mandatory features really compatible with Debian, or more generally, software freedom ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-20 Thread paddy
cases life threatening, and everyday non-safety-critical systems can easily be a very serious nuisiance to other users. Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-20 Thread paddy
base here; I'm just expressing my (limited) understanding > of the issue. no, you are bang on the mark! absolutely spot on! I can't help wondering if the problem is more one of the distro being able to solve the problem of how to supply an implementation, and I'm not sure how

Re: security.debian.org: MD5Sum mismatch

2007-08-17 Thread paddy
an be caused by an update. (I *wish* those updates > were atomic, but they probably arent'.) why not though ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-17 Thread paddy
proaching networks and come up with something practical. networks are what people have computers for these days. air gaps are the exception. Do ordinary folk really *need* to grok rp_filter ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-16 Thread paddy
think I need to be protected from > myself. I think that is what most people are trying to say. All I'm saying is, would it be possible to have a single simple option that users could *elect* to take, that wasn't the default, that wasn't bending anyones life out of shape, mar

Re: secure installation

2007-08-16 Thread paddy
om there, so enabling > rp_filter would do absolutely nothing. does it not cover the case of packets arriving at eth0 spoofed as from 127.0.0.1 ? what would be a easy way to test that ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: secure installation

2007-08-16 Thread paddy
it help to have a task style package that could set a range of such options ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 1342-2] New bind9 packages fix DNS cache poisoning

2007-07-30 Thread paddy
Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: BIND 9 security update

2007-07-25 Thread paddy
On Wed, Jul 25, 2007 at 10:35:14AM +0200, Florian Weimer wrote: > Will there be a timely security update for BIND 9, or does it make > sene to roll your own? this would be CVE-2007-2926 ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscrib

Re: security idea - bootable CD to check your system

2007-06-25 Thread paddy
oubt applies with kernels. and then it is all to easy to assume that the underlying hardware is not a problem. but in practice being able to boot from known-clean (eg: read-only media) is a gold-standard weapon in the armoury, and anything that can help join the dots from there to "this

Re: Package management and security

2007-06-07 Thread paddy
ebian stable version and needs to upgrade the package to the > >latest author available version, and you are cron-ing this how ? Regards, Paddy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Remote Root In Nvidia xserver Driver

2006-10-18 Thread paddy
On Wed, Oct 18, 2006 at 03:30:18AM +0100, paddy wrote: > On Tue, Oct 17, 2006 at 09:53:49PM -0400, Noah Meyerhans wrote: > > On Wed, Oct 18, 2006 at 02:11:24AM +0100, paddy wrote: > > > > NB: although some are saying this is a local root exploit only, the > > > &

Re: Remote Root In Nvidia xserver Driver

2006-10-17 Thread paddy
On Tue, Oct 17, 2006 at 09:53:49PM -0400, Noah Meyerhans wrote: > On Wed, Oct 18, 2006 at 02:11:24AM +0100, paddy wrote: > > > NB: although some are saying this is a local root exploit only, the > > > bulletin points out it can be exploited by visiting a malicious > > &

Re: Remote Root In Nvidia xserver Driver

2006-10-17 Thread paddy
nd thanks for doing this ... > NB: although some are saying this is a local root exploit only, the bulletin > points out it can be exploited by visiting a malicious webpage. I've not scrutinised the claims closely, but it looks like a remote vulnerability to me :-( Regards, Paddy

Re: When are security updates effective?

2006-09-04 Thread paddy
and so it's output for the use you suggest cannot be completely trusted. Seems to me that there are plenty of other problems getting to a compartment you can sanitise effectively, like the possibility of an exploit to persist via filesystem and hooks like cron or .profile, no ? but I

Re: How to prevent daemons from ever being started?

2006-05-15 Thread paddy
> I don't have an answer for the "don't start upon new install" problem, > though. while it doesn't cover "at system installation time" couldn't you get this out of policy-rc.d ?? To impact at system install time I suppose you're talking something like a CDD ? Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Debian bind DNS

2006-05-07 Thread paddy
lookup cached then you should have a win. If you are are forwarding the rest to your webhoster's DNS (??? ISP) then you shouldn't lose much there. perhaps you could dump the packets with tcpdump or ethereal and get an idea what's going on that way? Regards, Paddy -- Perl 6 will give yo

Re: masking out invalid root logins with logcheck?

2006-05-07 Thread paddy
about ? Is there any worthwhile analysis of such traffic beyond "there are these attacks and we don't care about them" ? do you need it ? do you already have it ? Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: first A record of security.debian.org extremely slow

2006-03-06 Thread paddy
n time to make the check. Perhaps freshclam's dns based mechanism may also be of interest as a point of comparison ? (I'm sorry I'm not able to describe it in detail off the top of my head, but the paralell seems obvious) Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Clamav CVE-2006-0162

2006-01-18 Thread paddy
n't be too far away. also http://lists.debian.org/debian-volatile-announce/debian-volatile-announce-2006/msg1.html Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: hardening checkpoints

2005-12-22 Thread paddy
ce that I have agreed to this calling. I love democracy. I love the Republic. Once this crisis has abated, I will lay down the powers you have given me! Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: hardening checkpoints

2005-12-21 Thread paddy
ith my prefered Desktop. In all Internet Cafes i get an IP via DHCP. > > So, there is no problem with infected Windows Machines... :-) > > I suggest you, to create your own striped down Live-System + USB-Key But you still have the possibility of hardware keyloggers to consider. Reg

Re: package name case in DSAs ?

2005-11-08 Thread paddy
On Tue, Nov 08, 2005 at 06:50:40PM -0200, Goedson Teixeira Paixao wrote: > * paddy ([EMAIL PROTECTED]) wrote: > > Hi, > > > > I just noticed that the use of case for package names in the subject > > line of DSA mails has been inconsistent or has changed. > > &

package name case in DSAs ?

2005-11-08 Thread paddy
Hi, I just noticed that the use of case for package names in the subject line of DSA mails has been inconsistent or has changed. For example, clamav and ClamAV. Apologies, I'm sure you have more important things to consider. Regards, Paddy -- Perl 6 will give you the big knob. -- Larry

Re: Abwesenheit

2005-09-19 Thread paddy
are should not use it. 8-/ I'm surprised. Do you mean it conflicts with a standard ? or just that its a commonly used extension that isn't explicitly standardized ? Is there a standard way to recognize mailing list traffic ? Regards, Paddy -- Perl 6 will give you the big knob.

Re: Abwesenheit

2005-09-19 Thread paddy
list back to > > them and generating a new reply... and so on ;-( > > Normally a reasonnably configured utoresponder will only send this > message once. So actually most of these ppl _are_ subscribed to d-s. Is there a reason not to simply read the "Precedence: list" h

Re: Timeliness of Debian Security Announceness? (DSA 756-1 Squirrelmail)

2005-07-14 Thread paddy
> are not used by normal unix-centered developers? > > Kind regards, > Herwig Wittmann Herwig, I hope this link will help http://newraff.debian.org/~joeyh/stable-security.html Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Can (non-embargoed) uploads be downloaded from somewhere ?

2005-06-30 Thread paddy
Mike, thanks for your quick response on this one. On Thu, Jun 30, 2005 at 03:45:27PM -0400, Michael Stone wrote: > On Thu, Jun 30, 2005 at 07:49:50PM +0100, paddy wrote: > >Is there a standard way to download such a package ? > > No. > > Mike Stone Is this a bug or a

Can (non-embargoed) uploads be downloaded from somewhere ?

2005-06-30 Thread paddy
such a package ? Regards, Paddy -- Perl 6 will give you the big knob. -- Larry Wall -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]