Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
On Wed, 2002-12-18 at 15:11, Blars Blarson wrote: > In article <[EMAIL PROTECTED]> [EMAIL PROTECTED] writes: > >create a second DMZ, but that would cost me the lost of three ip's, so > >I'm trying to figure out ways to isolate him without putting it in > >another subnet. > > There's no need to use

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
Thanx, everybody. As always you've been a great help :) Bye -- Haim

syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Samuel Lucas Vaz de Mello
Hi all! I'm getting this messages in the syslog: Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:17:56 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:27:57 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:37:57 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:47:57

Solo para tí

2002-12-19 Thread Centro Relax
Regálate una terapia antiestrés y disfruta nuestro cálido ambiente Relax y si no te gusta nuestro servicio NO PAGAS. Contamos también con masaje reductivo, Anticelulitis y 4 manos. Ven con nosotros y disfruta de una experiencia inolvidable con nuestro Masaje en Pareja. Más información en h

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Vincent Hanquez
On Thu, Dec 19, 2002 at 08:42:38AM -0200, Samuel Lucas Vaz de Mello wrote: > Hi all! > > I'm getting this messages in the syslog: > > Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 > Some idea about what this mean? > Regards, Hi, this message is syslog-ng notice mess

Re: [d-security] Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Christian Hammers
On Thu, Dec 19, 2002 at 12:40:51PM +0100, Vincent Hanquez wrote: > > Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 > You can rid of this message with something like that: ... Why not simply let syslog-ng log (it could be interesting somewhen) and install logcheck to filter out everythin

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Tommi Virtanen
On Thu, Dec 19, 2002 at 08:42:38AM -0200, Samuel Lucas Vaz de Mello wrote: > I'm getting this messages in the syslog: > > Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 > Dec 18 10:17:56 debian syslog-ng[164]: STATS: dropped 0 > Dec 18 10:27:57 debian syslog-ng[164]: STATS: dropped

suse's openldap2 audit relevant?

2002-12-19 Thread Bernhard Reiter
Just read http://lwn.net/Alerts/17457/ Excerpt: To: <[EMAIL PROTECTED]> Subject: [suse-security-announce] SuSE Security Announcement: OpenLDAP2 (SuSE-SA:2002:047) Date: Fri, 6 Dec 2002 12:16:32 +0100 (MET) 1) security vulnerability resolved: Buffer over

Re: OpenLDAP ssl support / SASL support

2002-12-19 Thread Hanasaki JiJi
Thank you Martin, I am CCing the package maintainer for confirmation. Wichert, if this is indeed the case, please could you add Secure connection support to the package? Thank you. == from the Debian site == Wichert Akkerman is responsible for this Debian package. [EMAIL PROTECTED] Martin

Re: OpenLDAP ssl support / SASL support

2002-12-19 Thread Wichert Akkerman
Previously Hanasaki JiJi wrote: > I am CCing the package maintainer for confirmation. Wichert, if this is > indeed the case, please could you add Secure connection support to the > package? Thank you. I haven't maintained the openldap packages for some time now. There are ssl-enabled packags i

Re: OpenLDAP ssl support / SASL support

2002-12-19 Thread Hanasaki JiJi
Sorry about that Wichert. I pulled the info from: http://packages.debian.org/stable/net/slapd.html Wichert Akkerman wrote: Previously Hanasaki JiJi wrote: I am CCing the package maintainer for confirmation. Wichert, if this is indeed the case, please could you add Secure connection support t

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread David B Harris
On Thu, 19 Dec 2002 12:40:51 +0100 Vincent Hanquez <[EMAIL PROTECTED]> wrote: > Hi, > this message is syslog-ng notice message, which tell you it hasn't > drop any /dev/log packets. > (this feature seem not connected as far as I can see) > > You can rid of this message with something like th

Re: Bug #173254 Submitted: Snort In Stable "Unusable"

2002-12-19 Thread Marcus Frings
Luis Bustamante wrote: > I've been building latest snort on woody without problems. If > someone is interested I usually upload updated versions for woody on: Thanks Luis for offering this service! Since you are not the official maintainer of snort I might ask before I add your URL to my apt.

Re: SSH

2002-12-19 Thread Dale Amon
Did the mainstream ssh ever address the hidden Markov chain attack on the password based on interpacket timings of the login?

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Vincent Hanquez
On Thu, Dec 19, 2002 at 08:42:05AM -0500, David B Harris wrote: > But remove stating messages is not what I've done.. The patch drops ONLY "0 droppet packet" message. others are logged. > options { stats(3600); }; I've check the source and effectively there is an option like that. > # stats(

Re: SSH

2002-12-19 Thread Hubert Chan
> "Dale" == Dale Amon <[EMAIL PROTECTED]> writes: Dale> Did the mainstream ssh ever address the hidden Markov chain attack Dale> on the password based on interpacket timings of the login? IIRC, it is an issue with the SSH1 *protocol* (i.e. all implementations will have the problem), that is n

Re: FTP-SSL

2002-12-19 Thread Daniel Lysfjord
It seems like FileZilla[1] supports ftp-ssl.. [1]: http://sourceforge.net/projects/filezilla

Re: FTP-SSL

2002-12-19 Thread Cristian Ionescu-Idbohrn
On Thu, 19 Dec 2002, Daniel Lysfjord wrote: > It seems like FileZilla[1] supports ftp-ssl.. > > [1]: http://sourceforge.net/projects/filezilla What about lftp? Depends: ..., libssl0.9.6, ...

Re: FTP-SSL

2002-12-19 Thread Daniel Lysfjord
Quoting Cristian Ionescu-Idbohrn <[EMAIL PROTECTED]>: > On Thu, 19 Dec 2002, Daniel Lysfjord wrote: > > > It seems like FileZilla[1] supports ftp-ssl.. > > > > [1]: http://sourceforge.net/projects/filezilla > > What about lftp? > > Depends: ..., libssl0.9.6, ... >From man lftp(1) : lf

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
On Wed, 2002-12-18 at 15:11, Blars Blarson wrote: > In article <1040204536.12811.100.camel@parker> [EMAIL PROTECTED] writes: > >create a second DMZ, but that would cost me the lost of three ip's, so > >I'm trying to figure out ways to isolate him without putting it in > >another subnet. > > There'

Re: Need an advise about isolating a host in the DMZ

2002-12-19 Thread Haim Ashkenazi
Thanx, everybody. As always you've been a great help :) Bye -- Haim -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Samuel Lucas Vaz de Mello
Hi all! I'm getting this messages in the syslog: Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:17:56 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:27:57 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:37:57 debian syslog-ng[164]: STATS: dropped 0 Dec 18 10:47:57

Solo para tí

2002-12-19 Thread Centro Relax
Regálate una terapia antiestrés y disfruta nuestro cálido ambiente Relax y si no te gusta nuestro servicio NO PAGAS. Contamos también con masaje reductivo, Anticelulitis y 4 manos. Ven con nosotros y disfruta de una experiencia inolvidable con nuestro Masaje en Pareja. Más información en http://

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Vincent Hanquez
On Thu, Dec 19, 2002 at 08:42:38AM -0200, Samuel Lucas Vaz de Mello wrote: > Hi all! > > I'm getting this messages in the syslog: > > Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 > Some idea about what this mean? > Regards, Hi, this message is syslog-ng notice mess

Re: [d-security] Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Christian Hammers
On Thu, Dec 19, 2002 at 12:40:51PM +0100, Vincent Hanquez wrote: > > Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 > You can rid of this message with something like that: ... Why not simply let syslog-ng log (it could be interesting somewhen) and install logcheck to filter out everythin

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Tommi Virtanen
On Thu, Dec 19, 2002 at 08:42:38AM -0200, Samuel Lucas Vaz de Mello wrote: > I'm getting this messages in the syslog: > > Dec 18 10:07:55 debian syslog-ng[164]: STATS: dropped 0 > Dec 18 10:17:56 debian syslog-ng[164]: STATS: dropped 0 > Dec 18 10:27:57 debian syslog-ng[164]: STATS: dropped

suse's openldap2 audit relevant?

2002-12-19 Thread Bernhard Reiter
Just read http://lwn.net/Alerts/17457/ Excerpt: To: <[EMAIL PROTECTED]> Subject: [suse-security-announce] SuSE Security Announcement: OpenLDAP2 (SuSE-SA:2002:047) Date: Fri, 6 Dec 2002 12:16:32 +0100 (MET) 1) security vulnerability resolved: Buffer over

Re: OpenLDAP ssl support / SASL support

2002-12-19 Thread Hanasaki JiJi
Thank you Martin, I am CCing the package maintainer for confirmation. Wichert, if this is indeed the case, please could you add Secure connection support to the package? Thank you. == from the Debian site == Wichert Akkerman is responsible for this Debian package. [EMAIL PROTECTED] Martin Ru

Re: OpenLDAP ssl support / SASL support

2002-12-19 Thread Wichert Akkerman
Previously Hanasaki JiJi wrote: > I am CCing the package maintainer for confirmation. Wichert, if this is > indeed the case, please could you add Secure connection support to the > package? Thank you. I haven't maintained the openldap packages for some time now. There are ssl-enabled packags i

Re: OpenLDAP ssl support / SASL support

2002-12-19 Thread Hanasaki JiJi
Sorry about that Wichert. I pulled the info from: http://packages.debian.org/stable/net/slapd.html Wichert Akkerman wrote: Previously Hanasaki JiJi wrote: I am CCing the package maintainer for confirmation. Wichert, if this is indeed the case, please could you add Secure connection support t

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread David B Harris
On Thu, 19 Dec 2002 12:40:51 +0100 Vincent Hanquez <[EMAIL PROTECTED]> wrote: > Hi, > this message is syslog-ng notice message, which tell you it hasn't > drop any /dev/log packets. > (this feature seem not connected as far as I can see) > > You can rid of this message with something like th

Re: Bug #173254 Submitted: Snort In Stable "Unusable"

2002-12-19 Thread Marcus Frings
Luis Bustamante wrote: > I've been building latest snort on woody without problems. If > someone is interested I usually upload updated versions for woody on: Thanks Luis for offering this service! Since you are not the official maintainer of snort I might ask before I add your URL to my apt.

Re: SSH

2002-12-19 Thread Dale Amon
Did the mainstream ssh ever address the hidden Markov chain attack on the password based on interpacket timings of the login? -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: syslog-ng[164]: STATS: dropped 0

2002-12-19 Thread Vincent Hanquez
On Thu, Dec 19, 2002 at 08:42:05AM -0500, David B Harris wrote: > But remove stating messages is not what I've done.. The patch drops ONLY "0 droppet packet" message. others are logged. > options { stats(3600); }; I've check the source and effectively there is an option like that. > # stats(

Re: SSH

2002-12-19 Thread Hubert Chan
> "Dale" == Dale Amon <[EMAIL PROTECTED]> writes: Dale> Did the mainstream ssh ever address the hidden Markov chain attack Dale> on the password based on interpacket timings of the login? IIRC, it is an issue with the SSH1 *protocol* (i.e. all implementations will have the problem), that is n

Re: FTP-SSL

2002-12-19 Thread Daniel Lysfjord
It seems like FileZilla[1] supports ftp-ssl.. [1]: http://sourceforge.net/projects/filezilla -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: FTP-SSL

2002-12-19 Thread Cristian Ionescu-Idbohrn
On Thu, 19 Dec 2002, Daniel Lysfjord wrote: > It seems like FileZilla[1] supports ftp-ssl.. > > [1]: http://sourceforge.net/projects/filezilla What about lftp? Depends: ..., libssl0.9.6, ... -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL

Re: FTP-SSL

2002-12-19 Thread Daniel Lysfjord
Quoting Cristian Ionescu-Idbohrn <[EMAIL PROTECTED]>: > On Thu, 19 Dec 2002, Daniel Lysfjord wrote: > > > It seems like FileZilla[1] supports ftp-ssl.. > > > > [1]: http://sourceforge.net/projects/filezilla > > What about lftp? > > Depends: ..., libssl0.9.6, ... >From man lftp(1) : lf

CUPS vulnerabilities (remote root compromise)

2002-12-19 Thread David Ehle
Hello all, Is the Debian package of cups Vulnerable to the security issues detailed here?: http://www.idefense.com/advisory/12.19.02.txt It doesn't mentions version 1.1.15-4 explicitly, but the vulnerablites havn't been tested on many different Distros yet. If the Debian package is affec