Re: Strange Large ICMP packets IDS246

2002-11-18 Thread enyc
> Today I had a whole bunch of large ICMP packages on the company's LAN (about > 20). > Interesting is, that they came mostly from the Windows 2000 Servers. I > discovered the first of these packages 2 or 3 weeks ago. > These packets are long (2090 Bytes) and not filled with nulls, but with > more

Re: NetFilter connection tracking

2002-11-25 Thread enyc
' matches returned ident connections and/or can forward ident connection to machine that actually originated outgoing connection instead of only recieving ident connection on iptables/netfilter machine itself. -enyc

Re: HTTP tunnel with linux server and windows client

2003-03-12 Thread enyc
rections using OpenSSH'es port forwarding, but this means logging in each time etc... Just thoughts, anyway... Btw -- ?maybe you should be using a different mailing list, not debian-security?. -enyc

Re: Can anyone help me ID who is trying to hack my system?

2003-10-07 Thread enyc
filesharing (netbios-over-tcp/ip) 'nonsense traffic' all the time.. It seems to be normal really, to be honest! Ignore it! You are likely to see lots of DENY's aimed at 'port 135' TCP (to do with windoze RPC (remote procedure call) to do with viruses (like m$blast) that infect 3vil windoze comptuers! P.s. -- ?what program or debian-package are you getting these firewall log messages from -- they don't look like linux 'dmesg' errors?! -enyc <[EMAIL PROTECTED]>

Squid package containing buffer overrun ??

2003-10-23 Thread enyc
rmally allow things to be updated unless a vulnerability has been proved to really exist?? I'm confused and would like to know what others think! -enyc <[EMAIL PROTECTED]>

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-03 Thread enyc
> ... but on a second thought: how do I find this information out ion my > own and what does "SMP" stand for? Not sure about your first question -- but SMP = Symettric Multi-Processor (e.g. more than 1 CPU in 1 motherboard/mothercard)... > Joh [EMAIL PROTECTED]

Re: Strange Large ICMP packets IDS246

2002-11-18 Thread enyc
> Today I had a whole bunch of large ICMP packages on the company's LAN (about 20). > Interesting is, that they came mostly from the Windows 2000 Servers. I > discovered the first of these packages 2 or 3 weeks ago. > These packets are long (2090 Bytes) and not filled with nulls, but with > more or

Re: NetFilter connection tracking

2002-11-25 Thread enyc
' matches returned ident connections and/or can forward ident connection to machine that actually originated outgoing connection instead of only recieving ident connection on iptables/netfilter machine itself. -enyc -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: HTTP tunnel with linux server and windows client

2003-03-12 Thread enyc
rections using OpenSSH'es port forwarding, but this means logging in each time etc... Just thoughts, anyway... Btw -- ?maybe you should be using a different mailing list, not debian-security?. -enyc -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Can anyone help me ID who is trying to hack my system?

2003-10-07 Thread enyc
filesharing (netbios-over-tcp/ip) 'nonsense traffic' all the time.. It seems to be normal really, to be honest! Ignore it! You are likely to see lots of DENY's aimed at 'port 135' TCP (to do with windoze RPC (remote procedure call) to do with viruses (like m$blast) that infe

Squid package containing buffer overrun ??

2003-10-23 Thread enyc
rmally allow things to be updated unless a vulnerability has been proved to really exist?? I'm confused and would like to know what others think! -enyc <[EMAIL PROTECTED]> -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Will 2.4.20 Source be patched for the latest kernel vulnerability?

2003-12-03 Thread enyc
> ... but on a second thought: how do I find this information out ion my > own and what does "SMP" stand for? Not sure about your first question -- but SMP = Symettric Multi-Processor (e.g. more than 1 CPU in 1 motherboard/mothercard)... > Joh [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMA