Re: passwords changed?

2004-04-11 Thread LeVA
2004. április 11. 06:21 dátummal Noah Meyerhans ezt írta: > On Sat, Apr 10, 2004 at 09:19:00PM +0200, LeVA wrote: > > Only as ftp. But there have been a number of locally exploitable > kernel vulnerabilities fairly recently, and an attacker could use one > of these to obtain root access once they

Re: passwords changed?

2004-04-11 Thread Tim Nicholas
On 04/11/04 21:15, LeVA wrote: 2004. április 11. 06:21 dátummal Noah Meyerhans ezt írta: On Sat, Apr 10, 2004 at 09:19:00PM +0200, LeVA wrote: Only as ftp. But there have been a number of locally exploitable kernel vulnerabilities fairly recently, and an attacker could use one of these to obt

Re: VPN Firewall Kernel

2004-04-11 Thread Dariush Pietrzak
> > at http://sourceforge.net/projects/wolk > It appears that WOLK is not in Debian. I would guess that given it's aim to > Neither the URL you provide nor the Freshmeat entry list what patches are > included in WOLK. Well, there used to be such list, but then WOLK turned into closed project

Terminal Emulator Security Issues

2004-04-11 Thread Torsten Werner
Hello, I have taken over the multi-gnome-terminal package recently and I have found out that it has still the bugs described in http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920&w=2 . I have contacted the upstream author. Furthermore I have found only _one_ DSA for the xterm package t

Re: Server slowdown...

2004-04-11 Thread Javier Fernández-Sanguino Peña
On Sun, Apr 11, 2004 at 12:28:31AM +0200, Jaroslaw Tabor wrote: (..) > After reboot, everything is working perfect. The question is where to > start investigation. Can someone suggest some tool, to record statistics > of CPU, Network, IO(drives) in correlation with processes ? Use sysstat, a

Re: Terminal Emulator Security Issues

2004-04-11 Thread Thomas Dickey
Torsten Werner <[EMAIL PROTECTED]> wrote: > Hello, > I have taken over the multi-gnome-terminal package recently and I have > found out that it has still the bugs described in > http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920&w=2 . I have > contacted the upstream author. Furthermore I

Re: passwords changed?

2004-04-11 Thread Noah Meyerhans
On Sun, Apr 11, 2004 at 11:15:10AM +0200, LeVA wrote: > I always compile the latest stable 2.4 kernel with loadable modules > disabled, but I don't apply any kernel patches. > Is this "safe", or I must apply some security patch? None of the recent kernel-level vulnerabilities have required module

platte

2004-04-11 Thread Cruz Hawkins
Dear Debian-security (Mon, 12 Apr 2004 01:42:00 +0300) No prescripjhjhtion required, no long lengthy forms to fill out. (Orlkjder today 85 % off all Meds) Dispcount Pharumacy Online Saplveplu Up to 85% ordplering your meds online! No Prescriptpluion required Fast Disecreet shipgping over_nig

Re: Server slowdown...

2004-04-11 Thread Joe Bouchard
On Sun, Apr 11, 2004 at 12:28:31AM +0200, Jaroslaw Tabor wrote: > Hello! > > I''ve strange problem with one of my servers. From time to time (once > per 2-3 months), something strange happends, and server starts working > very slow. What is strange, CPU load (from top) is about 5%, but > res

Re: passwords changed?

2004-04-11 Thread Daniel Pittman
On Sun, 11 Apr 2004, Noah Meyerhans wrote: > On Sun, Apr 11, 2004 at 11:15:10AM +0200, LeVA wrote: >> I always compile the latest stable 2.4 kernel with loadable modules >> disabled, but I don't apply any kernel patches. >> Is this "safe", or I must apply some security patch? > > None of the rece

Re: passwords changed?

2004-04-11 Thread LeVA
2004. április 11. 06:21 dátummal Noah Meyerhans ezt írta: > On Sat, Apr 10, 2004 at 09:19:00PM +0200, LeVA wrote: > > Only as ftp. But there have been a number of locally exploitable > kernel vulnerabilities fairly recently, and an attacker could use one > of these to obtain root access once they

Re: passwords changed?

2004-04-11 Thread Tim Nicholas
On 04/11/04 21:15, LeVA wrote: 2004. április 11. 06:21 dátummal Noah Meyerhans ezt írta: On Sat, Apr 10, 2004 at 09:19:00PM +0200, LeVA wrote: Only as ftp. But there have been a number of locally exploitable kernel vulnerabilities fairly recently, and an attacker could use one of these to obtain

Re: VPN Firewall Kernel

2004-04-11 Thread Dariush Pietrzak
> > at http://sourceforge.net/projects/wolk > It appears that WOLK is not in Debian. I would guess that given it's aim to > Neither the URL you provide nor the Freshmeat entry list what patches are > included in WOLK. Well, there used to be such list, but then WOLK turned into closed project

Terminal Emulator Security Issues

2004-04-11 Thread Torsten Werner
Hello, I have taken over the multi-gnome-terminal package recently and I have found out that it has still the bugs described in http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920&w=2 . I have contacted the upstream author. Furthermore I have found only _one_ DSA for the xterm package th

Re: Server slowdown...

2004-04-11 Thread Javier Fernández-Sanguino Peña
On Sun, Apr 11, 2004 at 12:28:31AM +0200, Jaroslaw Tabor wrote: (..) > After reboot, everything is working perfect. The question is where to > start investigation. Can someone suggest some tool, to record statistics > of CPU, Network, IO(drives) in correlation with processes ? Use sysstat, a

Re: Terminal Emulator Security Issues

2004-04-11 Thread Thomas Dickey
Torsten Werner <[EMAIL PROTECTED]> wrote: > Hello, > I have taken over the multi-gnome-terminal package recently and I have > found out that it has still the bugs described in > http://marc.theaimsgroup.com/?l=bugtraq&m=104612710031920&w=2 . I have > contacted the upstream author. Furthermore I

Re: passwords changed?

2004-04-11 Thread Noah Meyerhans
On Sun, Apr 11, 2004 at 11:15:10AM +0200, LeVA wrote: > I always compile the latest stable 2.4 kernel with loadable modules > disabled, but I don't apply any kernel patches. > Is this "safe", or I must apply some security patch? None of the recent kernel-level vulnerabilities have required module

platte

2004-04-11 Thread Cruz Hawkins
Dear Debian-security (Mon, 12 Apr 2004 01:42:00 +0300) No prescripjhjhtion required, no long lengthy forms to fill out. (Orlkjder today 85 % off all Meds) Dispcount Pharumacy Online Saplveplu Up to 85% ordplering your meds online! No Prescriptpluion required Fast Disecreet shipgping over_nig

Re: Server slowdown...

2004-04-11 Thread Joe Bouchard
On Sun, Apr 11, 2004 at 12:28:31AM +0200, Jaroslaw Tabor wrote: > Hello! > > I''ve strange problem with one of my servers. From time to time (once > per 2-3 months), something strange happends, and server starts working > very slow. What is strange, CPU load (from top) is about 5%, but > res

Re: passwords changed?

2004-04-11 Thread Daniel Pittman
On Sun, 11 Apr 2004, Noah Meyerhans wrote: > On Sun, Apr 11, 2004 at 11:15:10AM +0200, LeVA wrote: >> I always compile the latest stable 2.4 kernel with loadable modules >> disabled, but I don't apply any kernel patches. >> Is this "safe", or I must apply some security patch? > > None of the rece