Re: Debian audititing tool?

2000-12-21 Thread Lupe Christoph
y is at http://www.freeveracity.org/ Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | The equal opportunity democracy - every vote has an equal chance | | of being counted. Though a bad one if you live in Florida. | | Those peopl

Re: Logging practices (and why does it suck in Debian?)

2001-04-20 Thread Lupe Christoph
of libc? Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys/joke

Re: Is ident secure?

2001-09-01 Thread Lupe Christoph
On Saturday, 2001-09-01 at 11:02:41 +0200, Martin F Krafft wrote: also sprach Layne (on Fri, 31 Aug 2001 11:04:30PM -0400): MARTIN FONDLES YOUNG BOYS. which one? Which Martin or which boy? *-O Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have

Re: Asking for documentation help (Re: IPSec questions...)

2002-01-14 Thread Lupe Christoph
sincerely hope this can happen soon. Until then, SuSE is ways easier to set up for PPTP. (Dunno what they deliver in the US, but here in Germany, they have those patches integrated.) Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged

Re: Debian security being trashed in Linux Today comments

2002-01-14 Thread Lupe Christoph
? I don't keep debian-security mails around, so I can't see what MIME-type the attachments had. The binary crap must be the spreadsheet which has been inlined. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality

Re: Debian security being trashed in Linux Today comments

2002-01-15 Thread Lupe Christoph
, and Windowses. My gut feeling is that Debian would shine in such a comparison. Initially, I came to Debian because I had the feeling that it was the Linux dustribution with the fastest reaction to the discovery of vulnerabilities. Judging from BUGTRAQ. Lupe Christoph -- | [EMAIL PROTECTED

Re: Debian security being trashed in Linux Today comments

2002-01-15 Thread Lupe Christoph
On Tuesday, 2002-01-15 at 13:07:12 +0100, Javier Fernández-Sanguino Peña wrote: On Tue, Jan 15, 2002 at 09:23:20AM +0100, Lupe Christoph wrote: I still think a table and graph would be a god addition to the security FAQ, as an answer to the question How long does Debian take to fix known

Re: dpkg-buildpackage (-rfakeroot) leaves setuid binaries

2002-01-22 Thread Lupe Christoph
to catch somebody unawares from a Makefile.PL. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http

Re: CERT Advisory CA-2002-05 Multiple Vulnerabilities in PHP fileupload

2002-02-28 Thread Lupe Christoph
. Or wait if somebody provides an updated php4 package (4.0.5-3?). HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again

Re: Debian mail server.

2002-04-01 Thread Lupe Christoph
. Not much better, though. Maybe worse... Putting the IMAP server in a chroot jail would also give you an increase in security. HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Lupe Christoph
. HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys/joke/klingon.htm

Re: fswcert

2002-04-08 Thread Lupe Christoph
-in certificate.pem -noout -text | sed -n -e 's/.*Subject: //p' Mail me directly if you need help setting this up. HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest

Re: fswcert

2002-04-09 Thread Lupe Christoph
On Tuesday, 2002-04-09 at 08:50:18 -0400, Andrew Pimlott wrote: On Tue, Apr 09, 2002 at 08:01:14AM +0200, Lupe Christoph wrote: Here is an example: conn %default authby=rsasig leftrsasigkey=%cert rightrsasigkey=%cert left=%defaultroute

Re: world readable log files and /etc/ files

2002-04-29 Thread Lupe Christoph
about the permissions, so I have to go check them. Be paranoid within reason. If you tighten security so much that you can only work as root, you're easier to screw by trojans. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO

Re: Why is there a prompt for a root shell when the default linux kernel boots?

2002-05-01 Thread Lupe Christoph
and could change DELAY. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys

Re: SSL update.. still giving me a Vulnerable status

2002-09-17 Thread Lupe Christoph
library. On my Woody machine, after I restarted httpd, I get 1.2.3.4 443 PATCHED: detects small overflow, but crashes (0.9.6e) HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed

Re: SSL update.. still giving me a Vulnerable status

2002-09-18 Thread Lupe Christoph
libssl0.9.6 Sarge: ii libssl0.9.6 0.9.6e-1 SSL shared libraries Woody: ii libssl0.9.6 0.9.6c-2.woody.1 SSL shared libraries HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398

Re: SSL problems in woody (slapper)

2002-09-21 Thread Lupe Christoph
-ssl's Description in sarge says: Description: Pseudopackage for migration from Debian 2.2 (potato). I checked woody, same situation. So unless you are running potato, you can remove both packages. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big

Why does rpc.statd need a privileged port?

2002-09-28 Thread Lupe Christoph
would break locking between a Solaris and a Linux box, I doubt this would be a good idea. Opinions? Comments? Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed to be| | unsinkable

Re: Why does rpc.statd need a privileged port?

2002-09-28 Thread Lupe Christoph
On Saturday, 2002-09-28 at 18:33:43 +0200, Wichert Akkerman wrote: Previously Lupe Christoph wrote: Opinions? Comments? Does it really matter? Well it may collide with a service started after it that wants this particular privileged port. I also believe that services that do not require

Re: Probem with openssh and pam modules

2002-10-02 Thread Lupe Christoph
Correct me if I'm wrong, but don't we expect people who run unstable to diagnoseproblems themselves? If they can't they should be running stable or at least testing? Unstable is not just a name... Lupe Christoph On Wednesday, 2002-10-02 at 09:44:38 -0700, Anne Carasik wrote: This one time

Re: Encrypting/emailing logs and configs

2002-11-02 Thread Lupe Christoph
$KEYFILE backup@cabernet:$REMOTEFILE $LOCALFILE HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed to be| | unsinkable. The designer had a speech impediment. He said: I have | | thith great

Re: Multiple SSL Virtualhosts on Apache 1.3

2002-11-05 Thread Lupe Christoph
you use address-based virtual hosts, the certificates are associated with individual addresses, and are available at the right time. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed

Latest libpcap tcpdump sources from tcpdump.org contain a trojan

2002-11-13 Thread Lupe Christoph
Hi! Please read http://www.hlug.org/modules.php?op=modloadname=Newsfile=articlesid=6mode=threadorder=0thold=0 Is Debian affected? Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed

Re: Apologies re: VPN + Roadwarrior

2002-12-12 Thread Lupe Christoph
/ Host does not resolve http://www.vpnc.org/conformance.html404 Access denied, or file does not exist Can you please correct again? Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic

Unusable Update for Stable

2003-02-12 Thread Lupe Christoph
/updates/main Packages 100 /var/lib/dpkg/status Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed to be| | unsinkable. The designer had a speech impediment. He said: I have | | thith

Re: secure topologies - smtp/dns/whois/....

2003-03-23 Thread Lupe Christoph
for the firewall, use port redirection to the DMZ for incoming connections. HTH, Lupe Christoph PS: If you have never used iptables, and you sound like it, give fwbuilder a try. Even if you have, it might be useful because it makes management of the rules easier. -- | [EMAIL PROTECTED

Re: odd process running /usr/sbin/sendmail -i -CronDaemon -odi -oem root

2003-06-19 Thread Lupe Christoph
this then: lsof | grep 2637562 And I find I started a sleep command that (never) feeds the sendmail process: sleep 27412 lupe1w FIFO0,5 2637562 pipe HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort

Heads up: [lcamtuf@ghettot.org: [Full-Disclosure] Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce scanning]

2003-08-03 Thread Lupe Christoph
- Forwarded message from Michal Zalewski [EMAIL PROTECTED] - From: Michal Zalewski [EMAIL PROTECTED] To: [EMAIL PROTECTED], [EMAIL PROTECTED], [EMAIL PROTECTED] Date: Sun, 3 Aug 2003 21:12:34 +0200 (CEST) Subject: [Full-Disclosure] Postfix 1.1.12 remote DoS / Postfix 1.1.11 bounce

Re: Postfix Security Documentation

2003-08-20 Thread Lupe Christoph
to be secure out of the box (except for programming errors, as we recently saw :-( ). So improving Postfix security should be done inside of Postfix. You may want to you the Postfix mailing list (warning: lots of traffic!) and ask there. Lupe Christoph -- | [EMAIL PROTECTED] | http

Re: apache security issue (with upstream new release)

2003-10-31 Thread Lupe Christoph
, the potential for an ordinary user to exploit this is there. This allows access to the user the Apache work processes run as. Not much, but depending on local setup, this can be harmful. So I believe it should be fixed. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe

Re: passwd character limitations

2003-11-01 Thread Lupe Christoph
/perl5/Crypt/PasswdMD5.pm which claims to be based on the implementation found on FreeBSD 2.2.[56]-RELEASE, MD5 passwords consist of the invariant string '$1$' and the encrypted password encoded with the alphabet [./a-zA-Z]. This is similar to Base64 encoding, but uses a different alphabet. HTH, Lupe

3.0r2 or hacked packages?

2003-11-25 Thread Lupe Christoph
. ;-) Thanks! Lupe Christoph PS: I'd like to compare these packages to the installed versions. How can I do that with the least amount of hassle? -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze

Re: When will kernel-image-2.4.23 be available ?

2003-12-05 Thread Lupe Christoph
, so a Life CD Debian is very handy. I carry a Knoppix with me at almost any time... And a Debian Stable CD 1. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry

Re: When will kernel-image-2.4.23 be available ?

2003-12-05 Thread Lupe Christoph
as they are currently in the archives? I would like to build a new kernel with the vuln patched ASAP, rather than wait for the upload to reopen. Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze

Re: When will kernel-image-2.4.23 be available ?

2003-12-05 Thread Lupe Christoph
Quoting Thomas Sjögren [EMAIL PROTECTED]: On Fri, Dec 05, 2003 at 08:08:46AM +0100, Lupe Christoph wrote: BUT! Does anybody have a patch for the do_brk vuln on any kernel-source package = 2.4.20 as they are currently in the archives? I would like to build a new kernel with the vuln patched

Re: extrange passwd behaviour

2003-12-05 Thread Lupe Christoph
and DES uses 56 bit keys. Eight 7 bit chars give you exactly 56 bits... I've always wondered if the high bit does indeed make no difference. Right now, I have only Solaris to try. ... Nope, the high bit is ignored on Solaris. I'll have to try this at home tonight with Debian and FreeBSD. Lupe

Re: extrange passwd behaviour

2003-12-06 Thread Lupe Christoph
about X/Open and their Unix standards? I'd bet they specify this in exceeding detail. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry Pratchett

Re: extrange passwd behaviour

2003-12-06 Thread Lupe Christoph
password to the yppasswordd. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry Pratchett | -- To UNSUBSCRIBE, email to [EMAIL

Re: extrange passwd behaviour

2003-12-07 Thread Lupe Christoph
support for MD5. FreeBSD supports MD5 passwords. So it's not non-Linux. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry Pratchett

Re: secure file permissions

2003-12-07 Thread Lupe Christoph
to change them, so I guess you should know why. BTW, try running ls as a user when /etc/group and /etc/passwd are 600. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time

Re: aide, apt-get and remote management...

2003-12-14 Thread Lupe Christoph
On Friday, 2003-12-12 at 12:39:49 +0100, Adam ENDRODI wrote: On Fri, Dec 12, 2003 at 07:46:38AM +0100, Lupe Christoph wrote: We don't use AIDE exclusively at a client site, but in combination with Tripwire. We think tripwire is a little more secure becuse it uses signed databases

Content-Type in DSAs

2004-01-06 Thread Lupe Christoph
. And I will set it up now. But for the sake of people like me before I started to investigate this, I still wanted to ask this question. Thank you for your patience, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze

tripwire .deb for Woody

2004-01-13 Thread Lupe Christoph
to Sarge, configure does not contain this test. The backport to Sarge fails in a different way, BTW. I could not find a tripwire*.deb with Google. Please help! Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze

Re: tripwire .deb for Woody

2004-01-13 Thread Lupe Christoph
On Tuesday, 2004-01-13 at 13:34:18 +0100, Lupe Christoph wrote: Has anybody on this list managed to backport the tripwire package to Woody? I'm running into a strange problem where configure tries to locate an include file named locale. Yes, without an suffix. I don't know much C

Re: aide, apt-get and remote management...

2004-01-19 Thread Lupe Christoph
plans: ... Encrypted and signed database. They are in the Debian source package. I haven't gotten around to investigating how they work, though. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze

Re: LKM

2004-01-27 Thread Lupe Christoph
1 0 Jan19 ?00:00:06 [kupdated] So ps does not give chkrootkit a PID, but /proc has those processes. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry

Re: chrootkit and false LKM positive

2004-01-27 Thread Lupe Christoph
running 2.4.23. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry Pratchett | -- To UNSUBSCRIBE, email to [EMAIL PROTECTED

Re: security.debian.org

2004-02-10 Thread Lupe Christoph
. the packets are taking a quite different path. Maybe U Twente switched providers? Also see http://www.debian.org/News/2004/20040202 That's old news. The machine has been reactivated. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort

Re: Help! File permissions keep changing...

2004-02-18 Thread Lupe Christoph
directory. That's why GNU find and xargs have the options -print0 and -0, respectively. Names in Unixish filesystems can't have NULs in them. Stoopid(tm) example: find foo bar -print0 | xargs -0 ls -ld There, I made the thread even more offtopic! :-O HTH, Lupe Christoph -- | [EMAIL PROTECTED

Re: Tripwire (clone) which would you prefer?

2004-02-23 Thread Lupe Christoph
and versatile as AIDE and Tripwire. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief of Time, Terry Pratchett | -- To UNSUBSCRIBE, email

Re: Slightly OT: Setting the primary NIC

2004-03-21 Thread Lupe Christoph
, the source IP address is set to that of the interface the packet is sent on. So you have a weird configuration for sure. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Violence is the resort of the violent Lu Tze | | Thief

Re: Slightly OT: Setting the primary NIC

2004-03-21 Thread Lupe Christoph
On Sunday, 2004-03-21 at 03:17:45 -0800, Brandon High wrote: On Sun, Mar 21, 2004 at 11:58:00AM +0100, Lupe Christoph wrote: Can anyone tell me how I can tell the machine which NIC is the primary? There is no such thing as a primary NIC. Unless a daemon explicitly binds a socket

Re: Woody Backport of tripwire

2004-04-23 Thread Lupe Christoph
do that, you will need to use CXX=g++-3.0 GCC=gcc-3.0 dpkg-buildpackage -rfakeroot -us -uc (Or similar) g++ 2.95 will not do. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering is like

Re: apt-get update

2004-05-14 Thread Lupe Christoph
mail to [EMAIL PROTECTED] to inquire. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering is like | | covering yourself with barbecue sauce and breaking into the Charity| | Home for Badgers

Re: Q: server monitoring

2004-04-30 Thread Lupe Christoph
) for performance monitoring. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering is like | | covering yourself with barbecue sauce and breaking into the Charity| | Home for Badgers with Rabies

Re: [bulletproof.net.au #29025] [Comment] [SECURITY] [DSA 525-1] New apache packages fix buffer overflow in mod_proxy

2004-06-28 Thread Lupe Christoph
as for any error or incompleteness in the contents of this e-mail. Especially given this Stoopid(tm) footer, you should keep your RT mails off debian-security and any other lists you feed into RT. Thank you, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de

Re: Ihre Anfrage: Support-JOB 14077 -- WG: [EMAIL PROTECTED]: [SECURITY] [DSA 531-1] New php4 packages fix multiple vulnerabilities]

2004-07-22 Thread Lupe Christoph
um! Danke, Lupe Christoph On Thursday, 2004-07-22 at 12:28:59 +0200, ET Support wrote: Guten Tag, wir haben Ihre Anfrage erhalten und bearbeiten diese schnellstmoeglich. Folgende Informationen wurden erfasst: Bearbeitungs-Nr:14077 Subject:WG

Re: Machine-readable form for debian security advisories

2004-08-11 Thread Lupe Christoph
avoid it. You don't mention VuXML (http://www.vuxml.org/), so I suppose you did not know it. Please have a look there. Thank you, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering is like

Re: Machine-readable form for debian security advisories

2004-08-12 Thread Lupe Christoph
for pointing it out! That's something I *can* comment on: Glad you found it useful. So I hope to see VuXML being used for Debian as well in the future. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering

Re: OT, spam tips.

2004-10-22 Thread Lupe Christoph
in SBL/XBL this is a good indication that the mail is Spam. But there are lots of other better criteria. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering is like | | covering yourself

Re: [SECURITY] [DSA 594-1] New Apache packages fix arbitrary code execution

2004-11-17 Thread Lupe Christoph
Quoting [EMAIL PROTECTED]: Nur zu Info - und um anzumerken dass uns das nicht betrifft. Ich moechte noch anmerken, dass uns die Mail auch nicht betrifft :-P Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet

Re: [SECURITY] [DSA-594-1] New Apache packages fix arbitrary code execution

2004-11-18 Thread Lupe Christoph
if I am. :) You are correct. The files are /usr/bin/htpasswd and /usr/lib/apache/1.3/mod_include.so. Both are indeed in apache-common. Otherwise, the apache-perl package might be affected too. Not only apache-ssl. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe

Re: murphy in sbl.spamhaus.org

2004-11-25 Thread Lupe Christoph
SFBs are too Stoopid(tm) to whitelist important mail servers./rant Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | ... putting a mail server on the Internet without filtering is like | | covering yourself with barbecue sauce and breaking into the Charity

Re: File System Integrity Checker for Sarge

2005-01-03 Thread Lupe Christoph
is the tool supported/packaged? HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Ask not what your computer can do for you | | ask what you can do for your computer. | -- To UNSUBSCRIBE

Re: Log file IDS package?

2005-01-11 Thread Lupe Christoph
performed on a match, not perform an action if a count is exceeded. That would need to be done in the script called when a match is found. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Ask not what your computer can do for you

Re: Debian audititing tool?

2000-12-21 Thread Lupe Christoph
://www.freeveracity.org/ Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | The equal opportunity democracy - every vote has an equal chance | | of being counted. Though a bad one if you live in Florida. | | Those people told us how to run a democracy ?!?|

Re: More detailed auditing design proposal

2000-12-23 Thread Lupe Christoph
probably require massive CPU power, alas.) HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | The equal opportunity democracy - every vote has an equal chance | | of being counted. Though a bad one if you live in Florida. | | Those

Re: Logging practices (and why does it suck in Debian?)

2001-04-20 Thread Lupe Christoph
of libc? Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys/joke/klingon.htm|

Re: Linux LDAP problem

2001-08-28 Thread Lupe Christoph
by other applications, so it's not clear. But there's a way: RTFS! :-) HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us

Re: Is ident secure?

2001-09-01 Thread Lupe Christoph
On Saturday, 2001-09-01 at 11:02:41 +0200, Martin F Krafft wrote: also sprach Layne (on Fri, 31 Aug 2001 11:04:30PM -0400): MARTIN FONDLES YOUNG BOYS. which one? Which Martin or which boy? *-O Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have

Re: Asking for documentation help (Re: IPSec questions...)

2002-01-14 Thread Lupe Christoph
sincerely hope this can happen soon. Until then, SuSE is ways easier to set up for PPTP. (Dunno what they deliver in the US, but here in Germany, they have those patches integrated.) Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged

Re: Debian security being trashed in Linux Today comments

2002-01-14 Thread Lupe Christoph
? I don't keep debian-security mails around, so I can't see what MIME-type the attachments had. The binary crap must be the spreadsheet which has been inlined. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality

Re: Debian security being trashed in Linux Today comments

2002-01-15 Thread Lupe Christoph
, and Windowses. My gut feeling is that Debian would shine in such a comparison. Initially, I came to Debian because I had the feeling that it was the Linux dustribution with the fastest reaction to the discovery of vulnerabilities. Judging from BUGTRAQ. Lupe Christoph -- | [EMAIL PROTECTED

Re: Debian security being trashed in Linux Today comments

2002-01-16 Thread Lupe Christoph
On Tuesday, 2002-01-15 at 13:07:12 +0100, Javier Fernández-Sanguino Peña wrote: On Tue, Jan 15, 2002 at 09:23:20AM +0100, Lupe Christoph wrote: I still think a table and graph would be a god addition to the security FAQ, as an answer to the question How long does Debian take to fix known

Re: dpkg-buildpackage (-rfakeroot) leaves setuid binaries

2002-01-22 Thread Lupe Christoph
to catch somebody unawares from a Makefile.PL. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http

Re: CERT Advisory CA-2002-05 Multiple Vulnerabilities in PHP fileupload

2002-02-28 Thread Lupe Christoph
if somebody provides an updated php4 package (4.0.5-3?). HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again

Re: Debian mail server.

2002-04-01 Thread Lupe Christoph
. Not much better, though. Maybe worse... Putting the IMAP server in a chroot jail would also give you an increase in security. HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team

Re: iptables not logging or dhcp-client lying?

2002-04-03 Thread Lupe Christoph
. HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys/joke/klingon.htm

Re: fswcert

2002-04-09 Thread Lupe Christoph
: openssl x509 -in certificate.pem -noout -text | sed -n -e 's/.*Subject: //p' Mail me directly if you need help setting this up. HTH, Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team

Re: fswcert

2002-04-09 Thread Lupe Christoph
On Tuesday, 2002-04-09 at 08:50:18 -0400, Andrew Pimlott wrote: On Tue, Apr 09, 2002 at 08:01:14AM +0200, Lupe Christoph wrote: Here is an example: conn %default authby=rsasig leftrsasigkey=%cert rightrsasigkey=%cert left=%defaultroute

Re: world readable log files and /etc/ files

2002-04-29 Thread Lupe Christoph
about the permissions, so I have to go check them. Be paranoid within reason. If you tighten security so much that you can only work as root, you're easier to screw by trojans. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO

Re: Why is there a prompt for a root shell when the default linux kernel boots?

2002-05-01 Thread Lupe Christoph
and could change DELAY. Lupe Christoph -- | [EMAIL PROTECTED] |http://free.prohosting.com/~lupe | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys

Re: NIS et propagation de groupes

2002-06-20 Thread Lupe Christoph
| --- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] --- Also sprach Sebastien Picard --- And a shorter signature would also be appreciated. Thank you, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de

Re: [Fwd: ISS Advisory: OpenSSH Remote Challenge Vulnerability]

2002-06-26 Thread Lupe Christoph
charge for falling for Theo. Seems I took a firm stand and bent over for him. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern

Re: Good Day

2002-07-02 Thread Lupe Christoph
. I know. I received about 20,000 bounces for invalid addresses. apt-get install spamassassin It trapped that one for me as well as 99% of the spam I receive. I still find a Spam in my norfmal inbox now and then. Not enough to warrant tweaking Spamassasin's rules. Lupe Christoph -- | [EMAIL

Re: Question on the safety sharing NFS with untrusted machines.

2002-07-25 Thread Lupe Christoph
the two machines. HTH, Lupe CHristoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | I have challenged the entire ISO-9000 quality assurance team to a | | Bat-Leth contest on the holodeck. They will not concern us again. | | http://public.logica.com/~stepneys/joke

Re: LDAP Help requested...please :)

2002-08-14 Thread Lupe Christoph
'ldapsearch -x' I get the database dif as I should. Wee, do you want SASL, or not? Your '-x' makes the ldap utilities use basic authentication, i.e. they authenticate against the LDAP database. If you leave '-x' out, SASL is used, so you must set it up. (sasldb) HTH, Lupe Christoph -- | [EMAIL

Re: debian-security-announce-$lang@lists?

2002-08-14 Thread Lupe Christoph
the people who volunteer to do it in such a short timeframe.) Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | || | After a while you give up trying to escape who you

Re: Good Day - spamassin

2002-09-12 Thread Lupe Christoph
On Thursday, 2002-09-12 at 10:20:39 +0200, Marcel Hicking wrote: --On Mittwoch, 3. Juli 2002 14:04 +0300 Samuli Suonpaa [EMAIL PROTECTED] wrote: i would rather see that the spam senders see a bounce email that fills up their boxes with returned undeliverables.. So if some spammes forged

Re: SSL update.. still giving me a Vulnerable status

2002-09-18 Thread Lupe Christoph
library. On my Woody machine, after I restarted httpd, I get 1.2.3.4 443 PATCHED: detects small overflow, but crashes (0.9.6e) HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed

Re: SSL update.. still giving me a Vulnerable status

2002-09-18 Thread Lupe Christoph
libssl0.9.6 Sarge: ii libssl0.9.6 0.9.6e-1 SSL shared libraries Woody: ii libssl0.9.6 0.9.6c-2.woody.1 SSL shared libraries HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398

Re: SSL problems in woody (slapper)

2002-09-21 Thread Lupe Christoph
-ssl's Description in sarge says: Description: Pseudopackage for migration from Debian 2.2 (potato). I checked woody, same situation. So unless you are running potato, you can remove both packages. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big

Why does rpc.statd need a privileged port?

2002-09-28 Thread Lupe Christoph
would break locking between a Solaris and a Linux box, I doubt this would be a good idea. Opinions? Comments? Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed to be| | unsinkable

Re: Why does rpc.statd need a privileged port?

2002-09-28 Thread Lupe Christoph
On Saturday, 2002-09-28 at 18:33:43 +0200, Wichert Akkerman wrote: Previously Lupe Christoph wrote: Opinions? Comments? Does it really matter? Well it may collide with a service started after it that wants this particular privileged port. I also believe that services that do not require

Re: Probem with openssh and pam modules

2002-10-02 Thread Lupe Christoph
Correct me if I'm wrong, but don't we expect people who run unstable to diagnoseproblems themselves? If they can't they should be running stable or at least testing? Unstable is not just a name... Lupe Christoph On Wednesday, 2002-10-02 at 09:44:38 -0700, Anne Carasik wrote: This one time

Re: questions about chrooting bind 8.3.3

2002-10-30 Thread Lupe Christoph
control, or how could it use a library function otherwise? You may need the libraries in the jail if named runs external programs. AFAIR, named versions 4 and 8 do that, version 9 doesn't. HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big

Re: Encrypting/emailing logs and configs

2002-11-02 Thread Lupe Christoph
$KEYFILE [EMAIL PROTECTED]:$REMOTEFILE $LOCALFILE HTH, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed to be| | unsinkable. The designer had a speech impediment. He said: I have | | thith

Re: Multiple SSL Virtualhosts on Apache 1.3

2002-11-05 Thread Lupe Christoph
you use address-based virtual hosts, the certificates are associated with individual addresses, and are available at the right time. Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed

Latest libpcap tcpdump sources from tcpdump.org contain a trojan

2002-11-13 Thread Lupe Christoph
Hi! Please read http://www.hlug.org/modules.php?op=modloadname=Newsfile=articlesid=6mode=threadorder=0thold=0 Is Debian affected? Thanks, Lupe Christoph -- | [EMAIL PROTECTED] | http://www.lupe-christoph.de/ | | Big Misunderstandings #6398: The Titanic was not supposed

  1   2   >