Re: new bind security bug?

2011-07-08 Thread Michael Scheidell
Also bad form to top post. Should i amso mispell some words so you can amuae yourself? -- Michael Scheidell, CTO SECNAP Network Security -Original message- From: Mark Andrews To: Michael Scheidell Cc: "freebsd-security@freebsd.org" Sent: Fri, Jul 8, 2011 02:20:48 GMT+00:

new bind security bug? Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-11:02.bind

2011-07-07 Thread Michael Scheidell
reebsd-security To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org" -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 >*| *SECNAP Network Security Corporation * Best Mobile Solutions Product of 2011 * Best Intrusion Prevention Product * Ho

Fwd: Не удается доставить: Re: 193.138.118.3 ? lagoon.freebsd.lublin.pl /cache, freebsd, lublin, pl on TOR end point list?

2011-04-16 Thread Michael Scheidell
) with Microsoft SMTP Server (TLS) id 14.0.722.0; Sat, 16 Apr 2011 05:31:22 -0400 Message-ID:<4da961f1.1040...@secnap.com> Date: Sat, 16 Apr 2011 05:31:29 -0400 From: Michael Scheidell User-Agent: Mozilla/5.0 (Macintosh; U; Intel Mac OS X 10.6; en-US;rv:1.9.2.15) Gecko/20110303 Thunderbir

Re: 193.138.118.3 ? lagoon.freebsd.lublin.pl /cache, freebsd, lublin, pl on TOR end point list?

2011-04-16 Thread Michael Scheidell
it's not used for any kind of illegal activities. so, option C: being too paranoid and I should get more rest :-) I will try to track down what server is lookup up cache.freebsd.lublin.pl and see why its doing that. thanks. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN:

193.138.118.3 ? lagoon.freebsd.lublin.pl /cache, freebsd, lublin, pl on TOR end point list?

2011-04-16 Thread Michael Scheidell
ce that they are involved in this prohibit them from being on any RR link for ports source code lookups? C) am I too paranoid? its 5am localtime, go back to bed? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Best I

Re: packet capture and if_bridge ignore bpf rules

2010-12-21 Thread Michael Scheidell
On 12/11/10 11:05 AM, Michael Scheidell wrote: I am just not working on tracking this down, and sometimes like to use tcpdump/tshark to watch specific packets on a host to look for 'interesting' things. I think I have seen this since 6.x I don't remember it on 5.x, but 5.x used

packet capture and if_bridge ignore bpf rules

2010-12-11 Thread Michael Scheidell
member: em1 flags=1e7 ifmaxaddr 0 port 2 priority 128 path cost 200 proto rstp role designated state forwarding so, what magic to make bpf filters work? -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 *| *SECNAP Network Security Corporation

Re: any interest in tripwire commercial?

2010-12-11 Thread Michael Scheidell
r, It looks like only you and me are interested. with that huge response, I guess its never going to happen. -- Michael Scheidell, CTO o: 561-999-5000 d: 561-948-2259 ISN: 1259*1300 >*| *SECNAP Network Security Corporation * Certified SNORT Integrator * 2008-9 Hot Company Award Winner,

any interest in tripwire commercial?

2010-11-30 Thread Michael Scheidell
Any interest in Tripwire Commercial version? I have a client who wants to allow their enterprise tripwire console to be able to monitor the servers that do the real work (the freebsd servers) as well as the token windows servers which are being monitored now. What version would you like to see

Re: ports/128749: [vuxml] VBA parser vulnerability in ClamAV

2008-11-12 Thread Michael Scheidell
yname/; /^PTHREAD_LIBS/s/lthr/lpthread/" Makefile (replace lthr with lpthread which has proven unstable in clamav anyway) I have several legacy 5.5 systems running this way. Note: unofficial, not supported by me, SECNAP, Freebsd, the RNC, the DNC, or the free masons. YMMV -- Michael Sc

Re: FreeBSD Security Advisory FreeBSD-SA-08:06.bind

2008-07-13 Thread Michael Scheidell
NOTE WELL: If a port number is specified via the query-source or query-source-v6 options to BIND, randomized port selection will not be used. Consequently it is strongly recommended that these options not be used to specify fixed port numbers -- Michael Scheidell, CTO >|SECNAP Network Secur

RE: FreeBSD Security Advisory FreeBSD-SA-07:07.bind

2007-08-01 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Chris Byrnes > Sent: Wednesday, August 01, 2007 6:13 PM > To: freebsd-security@freebsd.org > Subject: Re: FreeBSD Security Advisory FreeBSD-SA-07:07.bind > > Stop in /usr/src/usr.sbin/named. > > > An

RE: MOAB advisories

2007-01-14 Thread Michael Scheidell
Never mind, advisory states it affects freebsd 6.1. - This email has been scanned and certified safe by SpammerTrap(tm) For Information please see http://www.spammertrap.com ___ freebsd-secu

RE: MOAB advisories

2007-01-14 Thread Michael Scheidell
Why would you think any of these had anything to do with Freebsd? They all clearly state 'Apple DMG'. (a compressed disk image only for Apple Max OSX) -- Michael Scheidell, CTO SECNAP Network Security Corporation Web based Security and privacy Training: http://www.secnap.co

RE: SSH scans vs connection ratelimiting

2006-08-22 Thread Michael Scheidell
sts, ssh will complain about it if it even gets that far) -- Michael Scheidell, CTO 561-999-5000, ext 1131 SECNAP Network Security Corporation Keep up to date with latest information on IT security: Real time security alerts: http://www.secnap.com/news __

RE: seeding dev/random in 5.5

2006-08-08 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Kevin Day > Sent: Tuesday, August 08, 2006 4:59 PM > To: Doug Barton > Cc: freebsd-security@freebsd.org > Subject: Re: seeding dev/random in 5.5 > Yes, the install I had to do in amsterdam, translatin

Re: seeding dev/random in 5.5

2006-08-08 Thread Michael Scheidell
R. B. Riddick wrote: > --- Michael Scheidell <[EMAIL PROTECTED]> wrote: > >> R. B. Riddick wrote: >> >>> Why do u believe, that /dev/random isnt seeded by networking? >>> >>> >>> >> because it isn't

Re: seeding dev/random in 5.5

2006-08-08 Thread Michael Scheidell
garbage on console. #2, put in more than 5 packets of garbage from ethernet (which, acknowledged: if hacker is trying to seed known data to this box, he could feed it known data) -- Michael Scheidell, CTO SECNAP Network Security / www.secnap.com [EMAIL PROTECTED] / 1+561-999-5000, x 1131 __

Re: seeding dev/random in 5.5

2006-08-08 Thread Michael Scheidell
R. B. Riddick wrote: > --- Michael Scheidell <[EMAIL PROTECTED]> wrote: > >>> I think that during the first reboot after a fresh install >>> the kern.random.sys sysctl settings are already orderly >>> before rc.d/sshd is called... >>> >>

RE: seeding dev/random in 5.5

2006-08-08 Thread Michael Scheidell
> -Original Message- > From: R. B. Riddick [mailto:[EMAIL PROTECTED] > Sent: Tuesday, August 08, 2006 4:12 AM > To: Michael Scheidell; freebsd-security@freebsd.org > Subject: Re: seeding dev/random in 5.5 > > I think that during the first reboot after a

seeding dev/random in 5.5

2006-08-07 Thread Michael Scheidell
ying to figure out just WHY 'system won't boot'. (it booted, but sshd didn't start!) There is enough random[pun intended] things that can happen when you install a new system, that I would like to try to eliminate one of them. -- Michael Scheidell, CTO SECNAP Network Securi

RE: Port scan from Apache?

2006-07-21 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of [EMAIL PROTECTED] > Sent: Friday, July 21, 2006 12:43 AM > To: Clemens Renner > Cc: freebsd-security@freebsd.org > Subject: Re: Port scan from Apache? > > > Clemens Renner wrote: > > Hi everyone, > >

RE: Anyone running ntop on FBSD5.4

2006-06-12 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of talonz > Sent: Sunday, June 11, 2006 7:28 PM > To: Remco Bressers > Cc: freebsd-security@freebsd.org > Subject: Re: Anyone running ntop on FBSD5.4 > > > Remco Bressers wrote: > I had this same problem

Anyone running ntop on FBSD5.4

2006-06-11 Thread Michael Scheidell
If you are running ntop on 5.4, what compile options? Use ports version? Or surgefile tarball? It makes a great security forensics tools, but I can't get it to stop segfaulting.Was wondering if anyone found a fix for it. -- Michael Scheidell, CTO 561-999-5000, ext 1131 SECNAP Network Sec

Domtools.com hyjacked?

2005-12-30 Thread Michael Scheidell
Attempted to install dlint port. Only distribution site is www.domtools.com Email to '[EMAIL PROTECTED]' and [EMAIL PROTECTED] bounces (can't relay) Phone number missing on whois record. Fetch of tarball fails checksum (it delivers a generic 'web hosted search engine that just hijacked someone's

RE: Useful addition to ipfw

2005-12-13 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of Borja Marcos > Sent: Tuesday, December 13, 2005 11:00 AM > To: freebsd-security@freebsd.org > Subject: Useful addition to ipfw > > > Hello, > > I've found myself in a situation where a simple data

Freebsd port issue: ZDI-05-002: Clam Antivirus Remote Code Execution

2005-11-05 Thread Michael Scheidell
This was in bugtraq, and hasn't shown up in portaudit yet so I thought I would send it and the fix to you. I submitted a pr for a patch as well. (but for some reason, ir bounced) Problem #1: Clamav 87 has been found to have a security vulnerability that could lead to remot

RE: Problem with portaudit's database

2005-09-07 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Simon L. Nielsen > Sent: Wednesday, September 07, 2005 7:35 AM > To: Dmitry Pryanishnikov > Cc: freebsd-security@freebsd.org > Subject: Re: Problem with portaudit's database > On 2005.09.07 10:35:21

RE: Perl master site changed to tobez.org?

2005-06-29 Thread Michael Scheidell
Ok, yes, there is that... Thanks. > -Original Message- > From: Colin Percival [mailto:[EMAIL PROTECTED] > Sent: Wednesday, June 29, 2005 5:41 PM > To: Michael Scheidell > Cc: freebsd-security@freebsd.org > Subject: Re: Perl master site changed to tobez.org? >

Perl master site changed to tobez.org?

2005-06-29 Thread Michael Scheidell
Tobez: no disrespect intended, obviously you saw a problem with the master sites for perl 5.8.7 and did what you could to help, and with your position as a maintainer, I know that the trust we have in you and your patches is well earned, so don't take this question as anything but my well-earned pa

RE: IPFW disconnections and resets

2005-04-30 Thread Michael Scheidell
> -Original Message- > From: [EMAIL PROTECTED] > [mailto:[EMAIL PROTECTED] On Behalf Of > Siddhartha Jain > Sent: Friday, April 29, 2005 8:21 AM > To: freebsd-security@freebsd.org > Subject: Re: IPFW disconnections and resets > > Just out of curiosity, why is that IPFW behaves this way

RE: IPFW disconnections and resets

2005-04-29 Thread Michael Scheidell
> > I use that all the time, maybe 1 out of 100 times it will kill > a ssh session (only one that has irssi open cause of the time > updating it kills it, i have it set to update every second > though, so normally it'd be like 1 out of 500 or so) and even > if it does, it still finishes loadin