This is not SPAM

2011-05-08 Thread Boyd Stephen Smith Jr.
want to help a little bit, you can bounce or redirect SPAM message to report-listspam@lists.d.o. If you want to help a lot, writing spamassassin or protfix rules that match the SPAM and communicating that to the list admins could help. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b

Re: aptitude upgrade vs. apt-get upgrade

2011-04-01 Thread Boyd Stephen Smith Jr.
to revert some or all of these marked/scheduled changes, I recommend starting aptitude in interactive mode (aptitude). -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy `-'(. .)`-' http

Re: some feedback about security from the user's point of view

2011-01-23 Thread Boyd Stephen Smith Jr.
with that assertion. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy `-'(. .)`-' http://iguanasuicide.net/\_/ signature.asc Description: This is a digitally signed message part.

Re: non-executable stack (via PT_GNU_STACK) not being enforced

2010-10-11 Thread Boyd Stephen Smith Jr.
in the default kernel? Enable PAE. From what I understand, the features are not separable in the i386 kernel. You either suffer under PAE and get NX, or you suffer without NX and drop PAE. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o

Re: non-executable stack (via PT_GNU_STACK) not being enforced

2010-10-11 Thread Boyd Stephen Smith Jr.
On Monday, October 11, 2010 17:18:34 you wrote: On 10/11/2010 12:21 PM, Boyd Stephen Smith Jr. wrote: Anyone else perceive this situation as being a bit sub-optimal from the security perspective? No. Interesting. Do you happen to run any such systems in a production environment? Depends

Re: What's up with the git-core package?

2010-10-01 Thread Boyd Stephen Smith Jr.
been updated since last time I researched the issue. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy `-'(. .)`-' http://iguanasuicide.net/\_/ signature.asc Description

Re: About how to protect network resources in LDAP environment?

2010-08-29 Thread Boyd Stephen Smith Jr.
On Saturday, August 28, 2010 20:29:50 you wrote: On Sat, Aug 28, 2010 at 3:08 AM, Boyd Stephen Smith Jr. b...@iguanasuicide.net wrote: In 4c77f5ca.6030...@gmail.com, Min Wang wrote: (1) does this approach prevent user1- root ( su- ) user2? Yes. su does not grant Kerberos credentials. Can't

Re: About how to protect network resources in LDAP environment?

2010-08-28 Thread Boyd Stephen Smith Jr.
as a Kerberos user. Old-style NFS mostly trusts the local system to identify the user, which is why it is mostly only secure if root is shared between the NFS server and all its clients. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ

Re: Upcoming lenny point release

2010-08-25 Thread Boyd Stephen Smith Jr.
. Basically whining from someone that doesn't know what they are talking about. NB: Yes, patches from Ubuntu (in general) and Canonical employees (in specific) can and are accepted, but they aren't given preferential treatment. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net

Re: Upcoming lenny point release

2010-08-25 Thread Boyd Stephen Smith Jr.
. % ls -ld /etc/profile.d drwxr-xr-x 2 root root 48 2007-07-26 15:36 /etc/profile.d If someone can write to that directory, they have root. If they have root, you are already in trouble. Also: Patches Welcome. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net

Re: Debian 6.0 Squeeze frozen

2010-08-06 Thread Boyd Stephen Smith Jr.
http://www.debian.org/News/2010/20100806 I'm wondering if this means Squeeze will soon be receiving the same level of support of the security team as Lenny currently receives? -- Boyd Stephen Smith Jr

Re: Debian 4.0 Upgrade Path

2010-01-21 Thread Boyd Stephen Smith Jr.
and debian-announce and I haven't seen the security team claim full support for Squeeze, yet, but I could have missed it. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy `-'(. .)`-' http

Re: ipv6 and security.debian.org

2010-01-13 Thread Boyd Stephen Smith Jr.
. (Ping would be ok, but large TCP downloads would flake out.) IPv6 uses path MTU detection. Unless you have something seriously screwy with your setup, MTUs (above the minimum) should not be an issue with IPv6. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net

Re: Upcoming Lenny point release

2009-09-04 Thread Boyd Stephen Smith Jr.
. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy `-'(. .)`-' http://iguanasuicide.net/\_/ signature.asc Description: This is a digitally signed message part.

Re: HEAD's UP: possible 0day SSH exploit in the wild

2009-07-10 Thread Boyd Stephen Smith Jr.
computers, but sometimes you have not the choice. But yes, you don't want to get Kerberos tickets on an insecure system. I thought tickets only lasted for a small period of time, and could be expired early if need be so that you could use them on insecure machines. -- Boyd Stephen Smith Jr

Re: Screensaver in KDE 4.2

2009-06-13 Thread Boyd Stephen Smith Jr.
In 87ws7gavpe@mid.deneb.enyo.de, Florian Weimer wrote: * Boyd Stephen Smith, Jr.: In 200906101232.13509.zarl...@gmx.at, Johannes Zarl wrote: when my screen is locked (either via Ctrl-Alt-L or via time-delay in the screensaver itself), once I touch the mouse (and wait for the screen-lock

Screensaver in KDE 4.2 (was: Random questions about KDE4.2)

2009-06-10 Thread Boyd Stephen Smith Jr.
drawing. That wasn't enough to concern me. If you can see the unprotected desktop for enough time to take a digital photo, it could result in a compromise. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM

Re: Recommend good IDS? was Re: /dev/shm/r?

2009-06-03 Thread Boyd Stephen Smith Jr.
servers. I inherited a tripwire installation at some point. It was one mail message per day (and if you didn't get that message you knew something was wrong). It required a bit of tuning to not report errors regularly, but once I spent that time it was fairly hands-off. -- Boyd Stephen Smith Jr

Re: Debian suggestion on File Deletion

2009-06-01 Thread Boyd Stephen Smith Jr.
the current archive format over gmane, but I (probably) would notice much if it changed. META NAME=ROBOTS CONTENT=NOINDEX Or at least allow noindex tags inside posts. HTML isn't allowed by the Code of Conduct, so noindex tags don't make sense. -- Boyd Stephen Smith Jr

Re: How safely to stop using backports repo?

2009-05-29 Thread Boyd Stephen Smith Jr.
in their version. See http://www.backports.org:80/dokuwiki/doku.php?id=contribute Basic Rule 4. It both identifies the package and ensures that the version is testing is considered 'higher'. 1.2-3~bpo 1.2-3, according to dpkg. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b

Re: How safely to stop using backports repo?

2009-05-29 Thread Boyd Stephen Smith Jr.
, this will catch packages that are not in stable that were backported, but it wouldn't catch packages that are in stable but have a newer version in backports. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy

Re: [SECURITY] [DSA 1739-1] New mldonkey packages fix information disclosure

2009-03-13 Thread Boyd Stephen Smith Jr.
On Friday 13 March 2009 15:58:15 Florian Weimer wrote: For the stable distribution (etch), this problem has been fixed in version 2.9.5-2+lenny1. Of course, that is a typo. The current stable distribution is Lenny. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net

Re: Exploit in Upgrade Chain?

2009-02-12 Thread Boyd Stephen Smith Jr.
rebuild, if there truly is a sabateur in the ranks of the Debian maintainers? I'm forwarding to debian-security; perhaps they will have suggestions. This topic is more appropriate for that list than debian-user anyway. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b

Re: basically security of linux

2009-01-16 Thread Boyd Stephen Smith Jr.
. What about hardlinking the suid-root binaries to a hidden location, waiting for a security hole to be found/fixed, and then running the old binary to exploit the hole? Does dpkg handle suid/sgid files so that this is prevented? -- Boyd Stephen Smith Jr. ,= ,-_-. =. b

Re: basically security of linux

2009-01-16 Thread Boyd Stephen Smith Jr.
On Friday 2009 January 16 12:29:13 Johannes Wiedersich wrote: Boyd Stephen Smith Jr. wrote: What about hardlinking the suid-root binaries to a hidden location, waiting for a security hole to be found/fixed, and then running the old binary to exploit the hole? IIRC, a hard link is the same file

Re: basically security of linux

2009-01-16 Thread Boyd Stephen Smith Jr.
On Friday 2009 January 16 14:45:44 Michael Loftis wrote: --On January 16, 2009 7:29:13 PM +0100 Johannes Wiedersich johan...@physik.blm.tu-muenchen.de wrote: Boyd Stephen Smith Jr. wrote: What about hardlinking the suid-root binaries to a hidden location, waiting for a security hole

Re: basic security of linux

2009-01-16 Thread Boyd Stephen Smith Jr.
IIRC prevents this, Text File Busy/Text File In Use || error. As does Linux (openSUSE): $ sudo /bin/sh -c ' /opt/kde3/bin/kget' /bin/sh: /opt/kde3/bin/kget: Text file busy -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984

Re: basically security of linux

2009-01-16 Thread Boyd Stephen Smith Jr.
On Friday 2009 January 16 15:49:46 Repasi Tibor wrote: Boyd Stephen Smith Jr. wrote: On Friday 2009 January 16 13:03:53 you wrote: Boyd Stephen Smith Jr. wrote: What about hardlinking the suid-root binaries to a hidden location, waiting for a security hole to be found/fixed, and then running

Re: basically security of linux

2009-01-16 Thread Boyd Stephen Smith Jr.
installed suid binaries do get scrubbed after they aren't in use, so you only have to worry about suid binaries you've created yourself. -- Boyd Stephen Smith Jr. ,= ,-_-. =. b...@iguanasuicide.net ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy

Re: I need to see open connections this moment - With Iptables i can only see logs

2008-12-09 Thread Boyd Stephen Smith Jr.
, I've also seen iptraf used a bit. -- Boyd Stephen Smith Jr.                     ,= ,-_-. =. [EMAIL PROTECTED]                      ((_/)o o(\_)) ICQ: 514984 YM/AIM: DaTwinkDaddy           `-'(. .)`-' http://iguanasuicide.org/                      \_/     signature.asc Description