Re: WAS: HELP, my Debian Server was hacked!

2003-04-24 Thread Sebastian
> perl script for automatic updates... secpack does what you are looking for: http://therapy.endorphin.org/secpack/ Sebastian

Re: security problem in debian netfilter code?

2003-05-08 Thread Sebastian
find documentation about security bugs in the Debian kernels at: http://bugs.debian.org/cgi-bin/pkgreport.cgi?which=pkg&data=kernel&archive=yes&include=security Bugs #146349 and #168190 are Netfilter-related. Sebastian

Re: Logging User Activity

2003-05-14 Thread Sebastian
s not an option - some of your users could for example get the idea of sending fake logs of other users doing nasty things to the remote logging server...). Sebastian

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Sebastian
For example, if there is a bug in the openssl libraries, you must restart all services that use it. Just installing new libraries is not enough. Sebastian

Re: cracked? "rm uses obsolete (PF_INET,SOCK_PACKET)"

2003-06-15 Thread Sebastian
For example, if there is a bug in the openssl libraries, you must restart all services that use it. Just installing new libraries is not enough. Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: How can I help ?

2000-06-14 Thread Sebastian Rittau
> default in debian (I believe) But using this option prevents you from using the global /etc/shadow file, which is problematic in some cases. - Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: SMB passwords etc (was "How can I help ?")

2000-06-14 Thread Sebastian Rittau
rd sync" option with its dependence on the precise > prompt string produced by the "passwd" command. This loop protection is not really necessary since every program/daemon can be configured separately. - Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Brown Orifice Netscape update for slink?

2000-08-30 Thread Sebastian Ritter
y hand. > > Thanks. I believe as potato is released stable there will be no more updates for slink or hamm or even older distributions. Please correct me if I'm wrong. Just my $0.02 Sebastian primary email: [EMAIL PROTECTED] ICQ: sritter@86831140 -- To UNSUBSCRIBE, email to [

Abwesenheit

2004-08-30 Thread Sebastian Hennebrueder
Abwesenheit Sehr geehrte Damen und Herren, ich bin in der Zeit vom 21. August bis zum 9. September im Urlaub. In dieser Zeit können Sie sich an Herrn Zander wenden. Telefon 0391 544 56 70 Mit freundlichen Grüßen Sebastian Hennebrüder Leitung eCommerce - Internet --- Grass GmbH, eCommerce

Re: [SECURITY] [DSA 846-1] New cpio packages fix several vulnerabilities

2005-10-08 Thread Sebastian Feltel
FIXED Martin Schulze schrieb am 07.10.2005 17:51: > -- > Debian Security Advisory DSA 846-1 [EMAIL PROTECTED] > http://www.debian.org/security/ Martin Schulze > October 7th, 2005

unsubscribe

2006-04-03 Thread Sebastian Wehrmann
-- |Sebastian Wehrmann - [EMAIL PROTECTED]| || | Reichenhainer Str. 35/336 | | 09126Chemnitz | | home: +49 371 2407260 | | mobile: +49 179 9019256 | || |<><

Security review wanted

2008-01-30 Thread Sebastian Pipping
/MySQL my current code probably has security issues. As this code is running on a publicly accessible machine I depend on the kindness of its users and your security reviews. If you spot a vulnerability in that code please drop me a private mail about it. Thank you! Sebastian [1] http

Re: [SECURITY] [DSA 3148-1] chromium-browser end of life

2015-02-02 Thread Sebastian Rose
> Or use the the (non-free) Chrome DEBs provided by Google. Did they stop to put their servers into /etc/apt/sources.list before installing and, even worse, after de-installing? They did the last time I (un-)installed Chrome. - Sebastian -- Ich setzte einen Fuß in die Luft, und sie t

Re: How do you guys handle PNG/JPG binary files with potential payloads for all the image viewers?

2022-06-20 Thread Sebastian Rose
ClamAV already? If so, please ignore me (sorry for not following closely...). - Sebastian ¹ One can execute every file on GNU/Linux. But the attack is that execution of a file, not the file (otherwise we'd have to consider `rm', `gpg', `scp', and many more malware, too).

unsubscribe

2002-10-22 Thread Sebastian Jaksch

Re: scrollkeeper loading external (online) DTD

2003-01-09 Thread Sebastian Henschel
l/docbook/dtd/xml/4.1.2/docbookx.dtd,' {} \; the gnome-applets package does it this way. bye, sebastian -- ::: sebastian henschel ::: kodeaffe ::: lynx -source http://www.kodeaffe.de/shensche.pub | gpg --import pgpKLwbKqZ2qm.pgp Description: PGP signature

Re: idea for improving security

2003-05-07 Thread Sebastian Hoehn
en to your traffic. Just send a paket to one of the ports in the sequence, when some one starts sending his. That would make your login attempt invalid every time. Sebastian

Re: Please clarifiy: kernel-sources / ptracebug / debian security announcenments

2003-05-07 Thread Sebastian Zimmermann
for older ones that are all available within woody. How far back must patches be backported? Is there a clear policy about this issue? Sebastian

Re: Have I been hacked?

2003-05-08 Thread Sebastian Hoehn
Hi, you get this message when you use different names for a machine, for example the ip and the machine's name. One of them is saved in known_hosts, the other one causes this message! Sebastian Ian Goodall wrote: Thanks everyone for your help. It must be his computer as all the comput

unsubscribe

2004-01-13 Thread Sebastian Grigo
__Erdbeben im Iran: Zehntausende Kinder brauchen Hilfe. UNICEF hilft denKindern - helfen Sie mit! https://www.unicef.de/spe/spe_03.php

kernel 2.4.22 patch

2004-03-19 Thread Sebastian Schmitt
Hi, is there a kernel patch/update for the 'do_mremap VMA limit local privilege escalation vulnerability' described in http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt ? i have the kernel 2.4.22-2-686-smp running and do security updates on a daily basis. But im still vulnerable, as

Re: kernel 2.4.22 patch

2004-03-19 Thread Sebastian Schmitt
[...] > > is there a kernel patch/update for the 'do_mremap VMA limit local > > privilege escalation vulnerability' described in > > http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt ? > > That link provides the CVE identification CAN-2004-0077. > > http://cve.mitre.org/cgi-bin/cvename.c

unsubscribe

2002-10-22 Thread Sebastian Jaksch
-- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: scrollkeeper loading external (online) DTD

2003-01-09 Thread Sebastian Henschel
l/docbook/dtd/xml/4.1.2/docbookx.dtd,' {} \; the gnome-applets package does it this way. bye, sebastian -- ::: sebastian henschel ::: kodeaffe ::: lynx -source http://www.kodeaffe.de/shensche.pub | gpg --import msg08410/pgp0.pgp Description: PGP signature

unsubscribe

2004-01-13 Thread Sebastian Grigo
__Erdbeben im Iran: Zehntausende Kinder brauchen Hilfe. UNICEF hilft denKindern - helfen Sie mit! https://www.unicef.de/spe/spe_03.php -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Troub

kernel 2.4.22 patch

2004-03-19 Thread Sebastian Schmitt
Hi, is there a kernel patch/update for the 'do_mremap VMA limit local privilege escalation vulnerability' described in http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt ? i have the kernel 2.4.22-2-686-smp running and do security updates on a daily basis. But im still vulnerable, as

Re: kernel 2.4.22 patch

2004-03-19 Thread Sebastian Schmitt
[...] > > is there a kernel patch/update for the 'do_mremap VMA limit local > > privilege escalation vulnerability' described in > > http://isec.pl/vulnerabilities/isec-0014-mremap-unmap.txt ? > > That link provides the CVE identification CAN-2004-0077. > > http://cve.mitre.org/cgi-bin/cvename.c

Abwesenheit

2004-08-24 Thread Sebastian Hennebrueder
Abwesenheit Sehr geehrte Damen und Herren, ich bin in der Zeit vom 21. August bis zum 9. September im Urlaub. In dieser Zeit können Sie sich an Herrn Zander wenden. Telefon 0391 544 56 70 Mit freundlichen Grüßen Sebastian Hennebrüder Leitung eCommerce - Internet --- Grass GmbH, eCommerce

Abwesenheit

2004-08-31 Thread Sebastian Hennebrueder
Abwesenheit Sehr geehrte Damen und Herren, ich bin in der Zeit vom 21. August bis zum 9. September im Urlaub. In dieser Zeit können Sie sich an Herrn Zander wenden. Telefon 0391 544 56 70 Mit freundlichen Grüßen Sebastian Hennebrüder Leitung eCommerce - Internet --- Grass GmbH, eCommerce

Abwesenheit

2004-08-31 Thread Sebastian Hennebrueder
Abwesenheit Sehr geehrte Damen und Herren, ich bin in der Zeit vom 21. August bis zum 9. September im Urlaub. In dieser Zeit können Sie sich an Herrn Zander wenden. Telefon 0391 544 56 70 Mit freundlichen Grüßen Sebastian Hennebrüder Leitung eCommerce - Internet --- Grass GmbH, eCommerce

Re: [SECURITY] [DSA 644-1] New chbg packages fix arbitrary code execution

2005-01-18 Thread Sebastian Lövdahl
Martin Schulze wrote: This message was modified by F-Secure Anti-Virus E-Mail Scanning. This is what F-Secure gave me. Martin do you send viruses? ;) Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: debian security archive/updates b0rken???

2005-06-27 Thread Sebastian Ley
ow". I did not follow up on the current status of stable security, but in any case we should send them a response. I volunteer to translate an answer from English to German and send it to Heise. Regards, Sebastian -- PGP-Key: http://www.mmweg.rwth-aachen.de/~sebastian.ley/public.k

Identification Protocol (was: Re: your mail)

2000-03-16 Thread Sebastian Stark
On Thu, 16 Mar 2000, Ivan Ivanovic wrote: > On my Slink placed on Inernet often appears auth port connection attempts > from various sites... > What (common) application needs this port? irc server make ident connections to clients. squid can use ident for authorization. sendmail sometimes us

RE: Identification Protocol (was: Re: your mail)

2000-03-16 Thread Sebastian Stark
On Thu, 16 Mar 2000, Fredrik Liljegren wrote: > > i'd turn auth off for security reasons if your box has a direct > > connection to internet. > Many people misunderstand the usefulness of identd, and so disable it or > block all off site requests for it. identd is not there to help out remote > sit

Re: Automatic password changing

2000-03-23 Thread Sebastian Stark
the password periodically (good idea) BUT: to avoid telling the other sysadmins the new password, he choosed to set it to the actual date so they can look at the calendar to find it out... *sigh* sebastian

Re: Sendmail

2000-03-26 Thread Sebastian Stark
am of your choice. (apt-get install ssmtp) generally i'd say, don't use sendmail at all :) sebastian -- gravity is a myth. the earth sucks.

Re: bind running as root in Mandrake 7.0

2000-06-07 Thread Sebastian Rittau
install. I tend to disagree. bind could use debconf and ask a question with priority "low", default set to running bind without root permissions. Another approach is to fix bind by binding INADDR_ANY as was pointed out in this thread. This may have undesirable side-effects, though. - Sebastian

Re: How can I help ?

2000-06-14 Thread Sebastian Rittau
> default in debian (I believe) But using this option prevents you from using the global /etc/shadow file, which is problematic in some cases. - Sebastian

Re: SMB passwords etc (was "How can I help ?")

2000-06-14 Thread Sebastian Rittau
rd sync" option with its dependence on the precise > prompt string produced by the "passwd" command. This loop protection is not really necessary since every program/daemon can be configured separately. - Sebastian

Re: Can not login as root

2008-09-03 Thread Sebastian Rose
That's what an SuSE or knoppix CD is good for. I think Debian has a rescue mode too, that works (not shure - I use Debian, but for rescue I use an old SuSE CD). You could start from a CD and remove the 'x' from /etc/passwd. You might have to remount the volum with /etc/ read-write. Then restart

Re: Can not login as root

2008-09-03 Thread Sebastian Rose
Example for the previous Mail: In /etc/passwd Change the line root:x:0:0:root:/root:/bin/bash to root::0:0:root:/root:/bin/bash Note the missing 'x' which means this user has to provide a password. Murat Ohannes Berin wrote: Hi, I just insralled Debian on my laptop. However, I can not lo

Re: Securing a Network - What's the most secure Network/Server OS? - Is there a secure way to use Shares?

2009-03-01 Thread Sebastian Günther
hose 6 questions. I count 7... But I won't answer to any of these, because there are missing some fundamental constraints in this scenario to make any useful suggestions. Sebastian -- " Religion ist das Opium des Volkes. " Karl Marx s...@sti@N GÜNTHER mailto:sam...@guenther-roetgen.de pgpR4fEOMNVXQ.pgp Description: PGP signature

Re: Secure Remote Application and OS Deployment?

2009-03-16 Thread Sebastian Günther
hose who have a sane package manager. > NOTE: If it isn't possible for some of the OSs, please tell me which, > then please continue to answer how it will be possible for the others. > > Thanks in advance, > > Chip D. Panarchy > Sebastian -- " Religion

Re: "libsasl2": is there an announce list for "Main"

2009-06-08 Thread Sebastian Günther
ebian-security-announce.lists.debian.org > Thanks! > > > John > > HTH Sebastian -- " Religion ist das Opium des Volkes. " | _ ASCII ribbon campaign Karl Marx | ( ) against HTML e-mail s...@sti@N GÜNTHER

Re: HEAD's UP: possible 0day SSH exploit in the wild

2009-07-08 Thread Sebastian Posner
eed be interesting is a way to enforce that the PRIVATE KEY is password-protected - sadly, you can't see this from the public key, and I'm not aware of any possibility to query the client concerning this specific matter. Sebastian -- baboo -- Neu: GMX Doppel-FLAT mit Internet-Flatrate

Re: HEAD's UP: possible 0day SSH exploit in the wild

2009-07-08 Thread Sebastian Posner
ried such a thing. Sadly, I'm not their bossbut they are more or less my customers, so putting a security policy in place requiring the previously stated mechanism would be more like starting a war than a small skirmish. Sebastian -- baboo -- Neu: GMX Doppel-FLAT mit Internet-Flatrate + Tele

Re: How (un)safe would Debian be when only using the security.debian.org repository?

2013-11-10 Thread Sebastian Günther
gt; > Only using: > deb http://security.debian.org stable/updates main contrib non-free the other problem is, that you will not be able to install any software which has never received any security fix: e.g. neither vim nor nano are in the pool dir on that mirror. Sebastian -- "

Re: aargh... I am being asked to change to SuSE

2001-07-16 Thread Sebastian Rittau
t works, and what the flaws are. - Sebastian, who doesn't like YaST at all -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Is ident secure?

2001-09-01 Thread Sebastian Rittau
ibed for him at a different e-mail address and forwards all mail to his address. Maybe the listmaster (cc'ed) should have a look at which addresses had subscribed at the time he describes. - Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: buffer overflow in /bin/gzip?

2001-11-21 Thread Sebastian Rittau
fine. strncpy() is even more dangerous, since it doesn't add a final nul-byte if strlen(src) > n. Most people are not aware of this problem. So, most of the time you use strncpy() you should use a construction like this: strncpy(dst, src, len); dst[len] = '\0'; - Sebastian -- T

Re: SOME ITEMS THAT YOU MAY BE INTERESTED IN OR BE ABLE TO ADVISE ME ON

2002-01-24 Thread Sebastian Rittau
ear. I have to download this over ad 56kBit link and I pay by the minute. - Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Encrypted Ethernet ?

2002-02-21 Thread Sebastian Bruhn
LANs. It means, that such > device have to be transparent for all IP traffic (or may be for all > Ethernet traffic?). > > regards > Jarek Tabor Freeswan might be the solution. Check www.freeswan.org -- Sebastian Bruhn System Tekniker / System Technichian Email: [EMAIL PROTECTED]

Re: aargh... I am being asked to change to SuSE

2001-07-16 Thread Sebastian Rittau
t works, and what the flaws are. - Sebastian, who doesn't like YaST at all

Re: Is ident secure?

2001-09-01 Thread Sebastian Rittau
ibed for him at a different e-mail address and forwards all mail to his address. Maybe the listmaster (cc'ed) should have a look at which addresses had subscribed at the time he describes. - Sebastian

Re: buffer overflow in /bin/gzip?

2001-11-21 Thread Sebastian Rittau
fine. strncpy() is even more dangerous, since it doesn't add a final nul-byte if strlen(src) > n. Most people are not aware of this problem. So, most of the time you use strncpy() you should use a construction like this: strncpy(dst, src, len); dst[len] = '\0'; - Sebastian

Re: SOME ITEMS THAT YOU MAY BE INTERESTED IN OR BE ABLE TO ADVISE ME ON

2002-01-24 Thread Sebastian Rittau
his year. I have to download this over ad 56kBit link and I pay by the minute. - Sebastian

Re: Encrypted Ethernet ?

2002-02-21 Thread Sebastian Bruhn
LANs. It means, that such > device have to be transparent for all IP traffic (or may be for all > Ethernet traffic?). > > regards > Jarek Tabor Freeswan might be the solution. Check www.freeswan.org -- Sebastian Bruhn System Tekniker / System Technichian Email: [EMAIL PROTECTED]

Re: PermitRootLogin enabled by default

2002-06-26 Thread Sebastian Rittau
he other hand I don't see why allowing direct root logins is a problem. - Sebastian -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Apache + PHP and user permissions

2002-07-25 Thread Sebastian Schinzel
Hi Ralf! > 2. chroot everything > just chroot the users at the login after ssh (if you want to allow ssh), How can chroot a user who logs in via ssh? Do you have some links about this? -- Sebastian Schinzel -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "

embedding openssl source in sslcan

2016-12-22 Thread Sebastian Andrzej Siewior
SSL toolkit in Debian and one might need to scan a non-Debian / older machine. [0] https://github.com/rbsec/sslscan Sebastian