Re: secure topologies - smtp/dns/whois/....

2003-03-23 Thread Lupe Christoph
On Saturday, 2003-03-22 at 12:01:13 -0600, Hanasaki JiJi wrote: Would you share your opinions on the following setup for daemons? firewall runs whois server - gwhois or jwhois? No services on the firewall. Put that on a machine in the DMZ. iptables - firewall ... because it

Re: Patch fot ptrace is good but ....

2003-03-23 Thread Couraud Régis
Le Sunday 23 March 2003 05:01, Guille -bisho- a écrit : Thus no problem, the patch functions ,-) But so now I launch the same exploit but to compile and use before levelling of the kernel : [EMAIL PROTECTED]:~/ptrace$ ./ptrace-before-compiling [EMAIL PROTECTED]:~/ptrace# id uid=0(root)

Re: PTRACE Fixed?

2003-03-23 Thread Lars Ellenberg
On Sat, Mar 22, 2003 at 10:58:24AM -0800, Jon wrote: On Sat, 2003-03-22 at 04:43, Markus Kolb wrote: Jon wrote: [...] Linux kmod + ptrace local root exploit by [EMAIL PROTECTED] = Simple mode, executing /usr/bin/id /dev/tty sizeof(shellcode)=95 = Child process

Re: [despammed] ptrace

2003-03-23 Thread LeVA
Hello! Thanks, that was the problem. The patch works fine. Ed McMan wrote: Saturday, March 22, 2003, 8:26:44 PM, [EMAIL PROTECTED] (debian-security) wrote: LeVA So it droped me a root shell. Well it is not good I think, after the LeVA patch... People have been saying that one of the exploits

Re: iptables route

2003-03-23 Thread Mauricio Alejandro Araya Lopez
On Sat, 22 Mar 2003, Eduardo Rocha Costa wrote: Thanks for the advice, shorewall is very good... only 4 hours and I make the configuration !! Hi, if you want to improve your firewall and security, just see http://www.netfilter.org -- Mauricio Alejandro Araya Lopez* User #249395

Re: Is this an obsolete tiger file?

2003-03-23 Thread Javier Fernández-Sanguino Peña
On Fri, Mar 21, 2003 at 02:41:44AM +, Dale Amon wrote: chkrootkit finds this file: Searching for suspicious files and dirs, it may take a while... /usr/lib/tiger/bin/.bintype which appears to be quite old. Is this just a leftover from a long ago tiger? It only contains Linux 2.2.17

Re: ptrace

2003-03-23 Thread Josh Carroll
If you compiled and ran the resulting binary before upgrading your kernel, the isec-ptrace-kmod-exploit binary may already be set[ug]id, which is a side effect of running it. Make sure it's not +s and/or g+s, or better yet just remove it and recompile it. --- LeVA [EMAIL PROTECTED] wrote: Hello!

unsubscribe

2003-03-23 Thread Tomas Willebrand
unsubscribe -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: secure topologies - smtp/dns/whois/....

2003-03-23 Thread Lupe Christoph
On Saturday, 2003-03-22 at 12:01:13 -0600, Hanasaki JiJi wrote: Would you share your opinions on the following setup for daemons? firewall runs whois server - gwhois or jwhois? No services on the firewall. Put that on a machine in the DMZ. iptables - firewall ... because it

Re: Patch fot ptrace is good but ....

2003-03-23 Thread Couraud Régis
Le Sunday 23 March 2003 05:01, Guille -bisho- a écrit : Thus no problem, the patch functions ,-) But so now I launch the same exploit but to compile and use before levelling of the kernel : [EMAIL PROTECTED]:~/ptrace$ ./ptrace-before-compiling [EMAIL PROTECTED]:~/ptrace# id uid=0(root)

Re: PTRACE Fixed?

2003-03-23 Thread Lars Ellenberg
On Sat, Mar 22, 2003 at 10:58:24AM -0800, Jon wrote: On Sat, 2003-03-22 at 04:43, Markus Kolb wrote: Jon wrote: [...] Linux kmod + ptrace local root exploit by [EMAIL PROTECTED] = Simple mode, executing /usr/bin/id /dev/tty sizeof(shellcode)=95 = Child process

Re: [SECURITY] [DSA 265-1] -- BAD SIGNATURE !?

2003-03-23 Thread Nick Boyce
On Saturday 22 Mar 2003 6:36 am, Martin Schulze wrote: Nick Boyce wrote : I get a bad signature reported by Kmail on this announcement. Saving the message out to a text file and verifying manually also fails : Ditch KMail, it is a permanent source of problems when it comes to digital

Re: [despammed] ptrace

2003-03-23 Thread LeVA
Hello! Thanks, that was the problem. The patch works fine. Ed McMan wrote: Saturday, March 22, 2003, 8:26:44 PM, debian-security@lists.debian.org (debian-security) wrote: LeVA So it droped me a root shell. Well it is not good I think, after the LeVA patch... People have been saying that

Re: iptables route

2003-03-23 Thread Mauricio Alejandro Araya Lopez
On Sat, 22 Mar 2003, Eduardo Rocha Costa wrote: Thanks for the advice, shorewall is very good... only 4 hours and I make the configuration !! Hi, if you want to improve your firewall and security, just see http://www.netfilter.org -- Mauricio Alejandro Araya Lopez* User #249395

Re: Is this an obsolete tiger file?

2003-03-23 Thread Javier Fernández-Sanguino Peña
On Fri, Mar 21, 2003 at 02:41:44AM +, Dale Amon wrote: chkrootkit finds this file: Searching for suspicious files and dirs, it may take a while... /usr/lib/tiger/bin/.bintype which appears to be quite old. Is this just a leftover from a long ago tiger? It only contains Linux 2.2.17

Re: ptrace

2003-03-23 Thread Josh Carroll
If you compiled and ran the resulting binary before upgrading your kernel, the isec-ptrace-kmod-exploit binary may already be set[ug]id, which is a side effect of running it. Make sure it's not +s and/or g+s, or better yet just remove it and recompile it. --- LeVA [EMAIL PROTECTED] wrote: Hello!