DSA-1571 and GSSAPI

2008-05-15 Thread Juha Jäykkä
Hi all! I was wondering how bad this actually is and it looks extremely horrible. In practice, all data transmitter over the wire for the last two years and be snooped upon (if someone has captured it - and the paranoid must assume someone has). Trusting on the security of ssh, we have, for ex

Re: DSA-1571 and GSSAPI

2008-05-27 Thread Juha Jäykkä
-Juha -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- signature.asc Description: This is a digitally

/usr/lib/libkssl.so.2.0.2

2002-12-20 Thread Juha Jäykkä
three machines, using ftp.fi.debian.org-mirror. How is this possible? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja

Re: /usr/lib/libkssl.so.2.0.2

2002-12-20 Thread Juha Jäykkä
so.2.0.2 It's 3-1 for 4b... then. :) -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http:/

sshd, pam and expired passwords

2003-09-12 Thread Juha Jäykkä
any other relevant configuration items? -- --- | Juha Jäykkä, [EMAIL PROTECTED], Assistant | | Laboratory of Theoretical Physics | | Department of Physics, University of

/usr/lib/libkssl.so.2.0.2

2002-12-20 Thread Juha Jäykkä
three machines, using ftp.fi.debian.org-mirror. How is this possible? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja

Re: /usr/lib/libkssl.so.2.0.2

2002-12-20 Thread Juha Jäykkä
so.2.0.2 It's 3-1 for 4b... then. :) -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http:/

sshd, pam and expired passwords

2003-09-12 Thread Juha Jäykkä
any other relevant configuration items? -- --- | Juha Jäykkä, [EMAIL PROTECTED], Assistant | | Laboratory of Theoretical Physics | | Department of Physics, University of

Re: Applications using Linux capabilities

2001-03-22 Thread Juha Jäykkä
it. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: Unidentified subject!

2001-04-17 Thread Juha Jäykkä
feasible? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

wdm & security

2001-05-24 Thread Juha Jäykkä
lsa-utils was broken last week.) -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: wdm & security

2001-05-25 Thread Juha Jäykkä
what you come up with. Thanks. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

RE: wdm & security

2001-05-28 Thread Juha Jäykkä
not non-existent. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: hi, any help ? about an evil mysterious crazy Open tcp port ?

2001-05-29 Thread Juha Jäykkä
me it is some windows stuff. This does not preclude the possibility of a backdoor/trojan, though: a wise backdoor would listen on a port which would be open anyway thus concealing (partly) its presence. -- --- | Juha J

Re: A question about Knark and modules

2001-06-17 Thread Juha Jäykkä
, is it a problem? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: Applications using Linux capabilities

2001-03-22 Thread Juha Jäykkä
it. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: Unidentified subject!

2001-04-17 Thread Juha Jäykkä
feasible? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a s

wdm & security

2001-05-24 Thread Juha Jäykkä
lsa-utils was broken last week.) -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCR

Re: wdm & security

2001-05-25 Thread Juha Jäykkä
what you come up with. Thanks. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subj

RE: wdm & security

2001-05-28 Thread Juha Jäykkä
not non-existent. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSU

Re: hi, any help ? about an evil mysterious crazy Open tcp port ?

2001-05-28 Thread Juha Jäykkä
me it is some windows stuff. This does not preclude the possibility of a backdoor/trojan, though: a wise backdoor would listen on a port which would be open anyway thus concealing (partly) its presence. -- --- | Juha J

Re: A question about Knark and modules

2001-06-17 Thread Juha Jäykkä
, is it a problem? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE

shared root account

2001-07-06 Thread Juha Jäykkä
... -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a

Re: shared root account

2001-07-06 Thread Juha Jäykkä
ogins over the wire until perhaps now. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ |

Re: shared root account

2001-07-09 Thread Juha Jäykkä
lies did not answer my question at all, some of them had good points, thanks to those. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --

aargh... I am being asked to change to SuSE

2001-07-16 Thread Juha Jäykkä
. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Cont

non-US security fixes URL

2001-07-19 Thread Juha Jäykkä
What might be the URL/apt-get sources.list line for security fixes of the non-US packages? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja

Re: non-US security fixes URL

2001-07-19 Thread Juha Jäykkä
an.org security pages might want to add that non-US security fix URL to the pages. Currently it is not mentioned there. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www

strange AIDE reports

2001-09-24 Thread Juha Jäykkä
? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL

Re: strange AIDE reports

2001-09-24 Thread Juha Jäykkä
pdate, too, and move the aide.db.new to aide.db. Besides this started right after installation - before installing anything new. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http:

Re: strange AIDE reports

2001-09-26 Thread Juha Jäykkä
arded sensitive) as changed, but these files seem totally random! After this, I reran 'aide --check' and got a segfault. Repeat as many times as I would, all get segfaulted... Aide broken? Aide version is sid's: 0.7-10. -- ---

the slrn-0.9.6.2 -hole

2001-09-26 Thread Juha Jäykkä
Does anyone happen to know which versions are vulnerable besides the one DSA mentioned? I have a woody which would need slrn removed if woody's newest version (that is, 0.9.7.2-4) is vulnerable. -- --- | Juha J

central administration techniques

2001-10-19 Thread Juha Jäykkä
all machines, since I doubt my little scheme would be the weakest link in security. The only problem I can see is in 1. and 2. - could the DSA key be abused to automatically root all the machines? Ideas? -- --- |

Re: central administration techniques

2001-10-19 Thread Juha Jäykkä
there, though: I basically would have TWO suided programs now though crashing a program which only runs another should be impossible (unless the init routines can be crashed). -- ------- | Juha Jäykkä, [EMAIL PROTECTED]

Re: central administration techniques

2001-10-19 Thread Juha Jäykkä
. (10Base-2) -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTEC

Re: question about something, but don't know if it exists...

2001-11-05 Thread Juha Jäykkä
ng inside your network over IPSec. No more stealing, I would think. There may be other options as well, but that would end all kinds of network sniffing inside your network. -- --- | Juha Jä

Re: question about something, but don't know if it exists...

2001-11-07 Thread Juha Jäykkä
Of course, there is a problem if your computers are not very fast - IPSec encrypts absolutely everything so it really takes some CPU. -- ------- | Juha Jäykkä, [EMAIL PROTECTED]|

Re: MTAs

2001-11-18 Thread Juha Jäykkä
, does it still need to be suid root? Since inetd runs root anyway, there should be no need for exim to: the port is already bound when exim starts and exim will not be able to bind to it anyway. Just wondering if I should do some dpkg-statoverrides. -- ----

Re: MTAs

2001-11-21 Thread Juha Jäykkä
es with the permissions of /var/spool/mail/. Now another question: are there? -- --- | Juha Jäykkä, [EMAIL PROTECTED]|

openssh version numbers...

2001-11-26 Thread Juha Jäykkä
hange the whole _format_ of their version numbers??? 2.9 is lacking one minor version specifier as compared to 2.9.9, which has two. TIA. -- --- | Juha Jäykkä, [EMAIL PROTECTED]|

lprng

2001-12-07 Thread Juha Jäykkä
or it? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Secure 2.4.x kernel

2001-12-27 Thread Juha Jäykkä
done with their computer which is sitting 24/7 on a DSL line - that is most unfortunate. Ever heard the phrase: "There is nothing valuable on my computer - why would anyone break into it?" Who would educate them..? -- -----

shared root account

2001-07-06 Thread Juha Jäykkä
... -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: shared root account

2001-07-06 Thread Juha Jäykkä
ogins over the wire until perhaps now. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: shared root account

2001-07-09 Thread Juha Jäykkä
lies did not answer my question at all, some of them had good points, thanks to those. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

aargh... I am being asked to change to SuSE

2001-07-16 Thread Juha Jäykkä
. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

non-US security fixes URL

2001-07-19 Thread Juha Jäykkä
What might be the URL/apt-get sources.list line for security fixes of the non-US packages? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: non-US security fixes URL

2001-07-20 Thread Juha Jäykkä
ng the www.debian.org security pages might want to add that non-US security fix URL to the pages. Currently it is not mentioned there. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | ho

strange AIDE reports

2001-09-24 Thread Juha Jäykkä
? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: strange AIDE reports

2001-09-24 Thread Juha Jäykkä
e, too, and move the aide.db.new to aide.db. Besides this started right after installation - before installing anything new. -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: strange AIDE reports

2001-09-26 Thread Juha Jäykkä
arded sensitive) as changed, but these files seem totally random! After this, I reran 'aide --check' and got a segfault. Repeat as many times as I would, all get segfaulted... Aide broken? Aide version is sid's: 0.7-10. -- ---

the slrn-0.9.6.2 -hole

2001-09-26 Thread Juha Jäykkä
Does anyone happen to know which versions are vulnerable besides the one DSA mentioned? I have a woody which would need slrn removed if woody's newest version (that is, 0.9.7.2-4) is vulnerable. -- --- | Juha J

central administration techniques

2001-10-19 Thread Juha Jäykkä
all machines, since I doubt my little scheme would be the weakest link in security. The only problem I can see is in 1. and 2. - could the DSA key be abused to automatically root all the machines? Ideas? -- --- |

Re: central administration techniques

2001-10-19 Thread Juha Jäykkä
there, though: I basically would have TWO suided programs now though crashing a program which only runs another should be impossible (unless the init routines can be crashed). -- ------- | Juha Jäykkä, [EMAIL PROTECTED]

Re: central administration techniques

2001-10-19 Thread Juha Jäykkä
. (10Base-2) -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: question about something, but don't know if it exists...

2001-11-06 Thread Juha Jäykkä
ng inside your network over IPSec. No more stealing, I would think. There may be other options as well, but that would end all kinds of network sniffing inside your network. -- --- | Juha Jä

Re: question about something, but don't know if it exists...

2001-11-07 Thread Juha Jäykkä
Of course, there is a problem if your computers are not very fast - IPSec encrypts absolutely everything so it really takes some CPU. -- ------- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: MTAs

2001-11-19 Thread Juha Jäykkä
, does it still need to be suid root? Since inetd runs root anyway, there should be no need for exim to: the port is already bound when exim starts and exim will not be able to bind to it anyway. Just wondering if I should do some dpkg-statoverrides. -- ----

Re: MTAs

2001-11-21 Thread Juha Jäykkä
es with the permissions of /var/spool/mail/. Now another question: are there? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

openssh version numbers...

2001-11-26 Thread Juha Jäykkä
hange the whole _format_ of their version numbers??? 2.9 is lacking one minor version specifier as compared to 2.9.9, which has two. TIA. -- --- | Juha Jäykkä, [EMAIL PROTECTED]|

lprng

2001-12-07 Thread Juha Jäykkä
or it? -- --- | Juha Jäykkä, [EMAIL PROTECTED]| | home: http://www.utu.fi/~juolja/ | ---

Re: Secure 2.4.x kernel

2001-12-27 Thread Juha Jäykkä
done with their computer which is sitting 24/7 on a DSL line - that is most unfortunate. Ever heard the phrase: "There is nothing valuable on my computer - why would anyone break into it?" Who would educate them..? -- -----