Re: apache segmentation fault

2004-04-16 Thread Vincent Deffontaines
Robert Velter a dit : > Hello all, > > there seems to be a new apache vulnerability. Following error messages > occure many times in my error.log: > [...] > System is woody with all security updates applied. > Any hints or tips how to track down the attack? > A good start might be : LogLevel debu

Re: Squid proxy help

2004-04-23 Thread Vincent Deffontaines
Craig Schneider a dit : > Hi Guys > > I was just wondering if you know how I could possibly setup squid so > that it will accept connections from the internet and filter before they > hit a IIS6 hosted intranet. > > Any ideas at this point would be welcome. > > Thanks > Craig > > > Squid has quite

[OT] Trojan/[spy/ad]ware and thawte.com

2004-06-01 Thread Vincent Deffontaines
This is the 2nd occurence of strange entries on my proxy logs, within a few days (comments below): *** 10* - - [28/May/2004:14:09:17 +0200] "GET http://delivery.inet-traffic.com/inetdl.exe HTTP/1.0" 200 247544 TCP_REFRESH_HIT:DIRECT 10* - - [28/May/2004

Re: INFECTED (PORTS: 600)

2006-05-19 Thread Vincent Deffontaines
o hide, if root is, and lsof indicates it's not /sbin/rpc.statd then > you're owned. It's kind of unusual for statd to show up on such a low > port but not totally unheard of. Indeed, root has to be running it. It looks like a privileged port to me. Vincent Deffontaines -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Why not have firewall rules by default?

2008-01-23 Thread Vincent Deffontaines
Michael Loftis wrote: [snip] It's better to leave the service disabled, or even better, completely uninstalled from a security standpoint, and from a DoS standpoint as well. The Linux kernel isn't very efficient at processing firewall rules. Newer kernels might be though (I honestly haven't lo

Re: Sarge, Bind9 (9.2.4-1sarge3) and DNS cache poisoning

2008-07-18 Thread Vincent Deffontaines
Linux vanilla kernel since 2.6.21.1 See http://software.inl.fr//trac/wiki/contribs/RandomSkype Vincent Deffontaines -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: [DSA 1605-1] DNS vulnerability impact on the libc stub resolver

2008-08-13 Thread Vincent Deffontaines
Moritz Muehlenhoff a écrit : > Hideki Yamane wrote: >>> The 2.6.24 >>> kernel available since the last etch point release offers some >>> protection as well. >> >> Umm? This is NEW information for me. Could you give me any references? >> (certainly if you can disclosure. It is a sensitive issue

Re: [DSA 1605-1] DNS vulnerability impact on the libc stub resolver

2008-08-13 Thread Vincent Deffontaines
Rick Moen a écrit : > Quoting Vincent Deffontaines ([EMAIL PROTECTED]): > >> And the Linux kernel (Netfilter) implements NAT source port >> randomization >> since 2.6.21, which can make it a conveninent way to protect your natted >> hosts without any patching. &g

Re: libapache2-mod-security2 error message

2017-01-23 Thread Vincent Deffontaines
Le 2017-01-23 03:26, Tea Wrex a écrit : I'm getting this error message and I don't know what to do to remedy it. Note: It was working fine the other day and I have not modified anything since it was working This is from the Apache error log. [Sun Jan 22 17:46:49.561357 2017] [mpm_prefork:notice

Huge Intel CPU Bug Allegedly Causes Kernel Memory Vulnerability With Up To 30% Performance Hit

2018-01-03 Thread Vincent Deffontaines
l.org/pub/scm/linux/kernel/git/torvalds/linux.git/commit/?id=5aa90a84589282b87666f92b6c3c917c8080a9bf Vincent Deffontaines

Re: apache segmentation fault

2004-04-16 Thread Vincent Deffontaines
Robert Velter a dit : > Hello all, > > there seems to be a new apache vulnerability. Following error messages > occure many times in my error.log: > [...] > System is woody with all security updates applied. > Any hints or tips how to track down the attack? > A good start might be : LogLevel debu

Re: Squid proxy help

2004-04-23 Thread Vincent Deffontaines
Craig Schneider a dit : > Hi Guys > > I was just wondering if you know how I could possibly setup squid so > that it will accept connections from the internet and filter before they > hit a IIS6 hosted intranet. > > Any ideas at this point would be welcome. > > Thanks > Craig > > > Squid has quite

[OT] Trojan/[spy/ad]ware and thawte.com

2004-06-01 Thread Vincent Deffontaines
This is the 2nd occurence of strange entries on my proxy logs, within a few days (comments below): *** 10* - - [28/May/2004:14:09:17 +0200] "GET http://delivery.inet-traffic.com/inetdl.exe HTTP/1.0" 200 247544 TCP_REFRESH_HIT:DIRECT 10* - - [28/May/2004

Re: Root login

2008-09-08 Thread Vincent Deffontaines
Marek Kubica a écrit : On Thu, 4 Sep 2008 13:25:13 +0100 Paweł Krzywicki <[EMAIL PROTECTED]> wrote: the solution was as Cerbelle said. Login as a normal user and do sudo ( or you can activate root login from the login menu; but i personally consider it really dangerous!) I am wondering why this

Re: Is this a hacking attempt?

2015-01-20 Thread Vincent Deffontaines
Le 2015-01-20 12:40, Marko Randjelovic a écrit : I was running Wheezy Iceweasel with vanilla 3.14 kernel with grsec. I tried to play video on YouTube with gnash plugin but Iceweasel crashed with alike messages execution attempt in ... Terminating task /usr/lib/iceweasel/iceweasel Full log can