Re: How to reduce sid security

2003-08-07 Thread Boyd Moore
[EMAIL PROTECTED] (Boyd Moore) wrote in message news:<[EMAIL PROTECTED]>... > Peter Cordes <[EMAIL PROTECTED]> wrote in message news:<[EMAIL PROTECTED]>... > > On Thu, Jul 31, 2003 at 02:17:46PM -0700, Boyd Moore wrote: > > > I have two Debian systems behind a Linksys router, with the router > > >

Re: How to reduce sid security

2003-08-07 Thread Thomas Ritter
[...] > but apparently they have reversed the priority. Now rsh, rlogin, etc. > works, but still not remote X windows. What about configuring X for network access? Wasn't X configured not to use network and sockets instead by default? -- Thomas Ritter "Those who would give up essential libert

Re: Debian Stable server hacked

2003-08-07 Thread Matt Zimmerman
On Wed, Aug 06, 2003 at 04:01:39PM +0200, Thijs Welman wrote: > All packages are unmodified releases from Debian stable and, yes, i do > update packes from security.debian.org as soon as there are any updates. :) If you don't also subscribe to debian-security-announce, then you are missing import

Re: How to reduce sid security

2003-08-07 Thread David Wright
Quoting Boyd Moore ([EMAIL PROTECTED]): > Well I did have rlogin, that is it points to netkit-rlogin. I finally > got rsh to work by commenting out the ALL: PARANOID line in > hosts.deny. I thought that the hosts.allow overrode the hosts.deny, > but apparently they have reversed the priority.

Re: Debian Stable server hacked

2003-08-07 Thread Thijs Welman
Hi, Matt Zimmerman wrote: If you don't also subscribe to debian-security-announce, then you are missing important things like kernel updates. There are several local root exploits in the stock woody kernel which have been fixed by security updates that would not be installed automatically. Yo

Re: Debian Stable server hacked

2003-08-07 Thread Eric LeBlanc
On Thu, 7 Aug 2003, Thijs Welman wrote: > > Thanks. I forgot to mantion that i am subscribed to > debian-security-announce as well (ofcourse ;)). As far as the kernel > updates are concerned: i use my own kernel. At this moment that's 2.4.21 > with Alan Cox' patches (ac4). Could be there's an exp

Re: Debian Stable server hacked

2003-08-07 Thread Matt Zimmerman
On Thu, Aug 07, 2003 at 07:03:13PM +0200, Thijs Welman wrote: > Matt Zimmerman wrote: > > >If you don't also subscribe to debian-security-announce, then you are > >missing important things like kernel updates. There are several local root > >exploits in the stock woody kernel which have been fix

Re: Debian Stable server hacked

2003-08-07 Thread Matt Zimmerman
On Thu, Aug 07, 2003 at 01:27:20PM -0400, Eric LeBlanc wrote: > Since 7 years, I always use custom kernels, and I never had problems (bugs > nor exploits). In 7 years, you've never encountered a bug in the kernel? You are fortunate indeed. -- - mdz

Re: Debian Stable server hacked

2003-08-07 Thread Wolfgang Fischer
On Thu, 07 Aug 2003 03:00:12 +0200, Peter Cordes wrote: > sshd logs IP addresses of connections. Was the IP address for those did > not receive id connections inside your site, or does it belong to an ISP > somewhere, or what? If it's a local address, and not a computer lab, that > might give y

Re: Debian Stable server hacked

2003-08-07 Thread Wolfgang Fischer
On Wed, 06 Aug 2003 17:50:06 +0200, Alan James wrote: > > You say that you have apache and php4 installed. Are you running any php > applications that may have been compromised ? Although I'd expect those > to leave the attacker with access to www-data rather than root. Maybe this has been combin

Re: Debian Stable server hacked

2003-08-07 Thread Wolfgang Fischer
Hi, maybe a legitimate user account combined with a local root exploit have been used to crack the server. Does this server has any legitimate user accounts? Are you sure you trust this users? Are you sure they (or you) don't write their passwords on a piece of paper? Who has local access to the s

Curriculum

2003-08-07 Thread Hugo Kavamura
Hugo Kazumi Kavamura 20 Anos / Solteiro / Brasileiro Objetivo Atuar na área de informática / web / suporte / comunicação Contatos: E-mail : [EMAIL PROTECTED] Telefone : (11) 6331-0765 (11) 9898-1262 Formação: - UniFAI - Faculdade Ipiranga Cursando 2 º semestre de Engenharia da computação Conhe

Re: Debian Stable server hacked

2003-08-07 Thread Thijs Welman
Hi, Matt Zimmerman wrote: If you don't also subscribe to debian-security-announce, then you are missing important things like kernel updates. There are several local root exploits in the stock woody kernel which have been fixed by security updates that would not be installed automatically. You

Re: Debian Stable server hacked

2003-08-07 Thread Matt Zimmerman
On Thu, Aug 07, 2003 at 07:03:13PM +0200, Thijs Welman wrote: > Matt Zimmerman wrote: > > >If you don't also subscribe to debian-security-announce, then you are > >missing important things like kernel updates. There are several local root > >exploits in the stock woody kernel which have been fix