[SECURITY] [DSA 079-1] New UUCP packages fix local exploit

2001-09-24 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - Debian Security Advisory DSA 079-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze September 24, 2001

Re: Need Help with the Debian Securing Manual (contributions accepted)

2001-09-24 Thread Nicole Zimmerman
At 00:26 on Sep 24, Will Aoki combined all the right letters to say: Mozilla's default language setting is only US English (en-us). My guess is that people getting 403s are running their browsers with out of the box language settings or have changed language settings but haven't listed

Subject!

2001-09-24 Thread Dietmar Braun
Hello all, please, PLEASE use a subject when you are mailing to this list! It is quite annoying getting mails without any subject, and usually many people are filtering mails without a subject. Thanks. Regards, Dietmar -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

RE: New IIS worm

2001-09-24 Thread Anders Gjære
LaBrea could maby be interesting for someone http://hts.dshield.org/LaBrea/ its for decreasing the spread of worms witch tryes random ip's mvh anders # -Original Message- # From: Karl E. Jorgensen [mailto:[EMAIL PROTECTED]] # Sent: 23. september 2001 18:19 # To: [EMAIL PROTECTED]

strange AIDE reports

2001-09-24 Thread Juha Jäykkä
I keep receiving strange reports from AIDE. The number of changed files increases monotonically daily and the affair started immediately after installation, so I doubt there has been a break-in - unless someone managed to spoof my DNS queries or hijack my connections to ftp.fi.debian.org. Aside

Re: strange AIDE reports

2001-09-24 Thread Vegard Engen
On Mon, Sep 24, 2001 at 02:02:49PM +0300, Juha Jäykkä wrote: I keep receiving strange reports from AIDE. The number of changed files increases monotonically daily and the affair started immediately after installation, so I doubt there has been a break-in - unless someone managed to spoof my

Re: strange AIDE reports

2001-09-24 Thread Juha Jäykkä
Any ideas except a break-in? Well - you say you're using unstable. Are you updating your system? There are a lot of changes in unstable. After a package replacement, binary files will of course have changed. Of course, but every time I run apt, I run aide --update, too, and move the

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread Haris Sehic
On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: Do you know if it can infect my debian box? Thanks, Enrique only if you have VB installed ---snip--- script language='VBScript' ---snip---

Re: Need Help with the Debian Securing Manual (contributionsaccepted)

2001-09-24 Thread James Hamilton
Works fine for me. Thank you, James Hamilton Systems/Software Engineer Davis Tool, Inc. http://www.davistl.com Nicole Zimmerman [EMAIL PROTECTED] 09/23/01 06:40PM Yup, I'm not using a proxy. http://www.debian.org/doc/manuals/securing-debian-howto/ I can access the following URL (which I

Re: [Fwd: Virus found in sent message ?????????????????????3????]

2001-09-24 Thread Emmanuel Valliet
(2001-09-24) Haris Sehic sed : | On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: |Do you know if it can infect my debian box? | | Thanks, | Enrique | | only if you have VB installed | |

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread Haris Sehic
On Mon, Sep 24, 2001 at 02:17:07PM -0400, Emmanuel Valliet wrote: Or perhaps if you have wine (did you read /. today :D ? ) hui 10x i was not on /. for 2 days now :) its funny .. worm emulation if you want smile god i love linux even becose of this fackt /smile bye Haris -- First They

Re: [Fwd: Virus found in sent message?????????????????????3????]

2001-09-24 Thread James Hamilton
That is some funny stuff. :) Emmanuel Valliet [EMAIL PROTECTED] 09/24/01 11:17AM (2001-09-24) Haris Sehic sed : | On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: |Do you know if it can infect my debian box? | | Thanks, |

Questions regarding the Security Secretary Position

2001-09-24 Thread Martin Schulze
I'm awfully sorry for the delay, but I wasn't able to work on this earlier again. Here's a list of questions and answers that came up with the posting I made last week. Q: Is a requirement being a Debian developer? No. It is my understanding that it would be good to have fresh blood in

St. Jude model?

2001-09-24 Thread Brian P. Flaherty
Hello, Is anyone here familiar with something called the St. Jude model of root exploit detection (see http://sourceforge.net/projects/stjude)? There is a paper explaining the idea on the website, as well as a linux kernel module. It sounds like a good idea, but has anyone here used it? Brian

Re: Need Help with the Debian Securing Manual (contributions accepted)

2001-09-24 Thread Andrew Sione Taumoefolau
Yup, I'm not using a proxy. http://www.debian.org/doc/manuals/securing-debian-howto/ I can access the following URL (which I found by going through the www.debian.org/doc tree): http://www.debian.org/doc/manuals/securing-debian-howto/index.en.html People may be getting the security

Re: Need Help with the Debian Securing Manual (contributions accepted)

2001-09-24 Thread Nicole Zimmerman
Actually it works in Netscape 4.77 but not Mozilla. So it doesn't look like it's a server-side problem. That was my first guess, too. The Forbidden error also does not have any mention of apache or any web server for that matter. The plot thickens :o) -nicole At 15:54 on Sep 24, Andrew Sione

crc32 compensation attack

2001-09-24 Thread Micah Anderson
Got what appears to be a crc32 compensation attack in my logs today, about 10 minutes worth of these types of messages should I be worried? Should I laugh at this feable attempt to break in? Should I gnaw my fingernails with my shotgun on my lap? Active System Attack Alerts

Re: Need Help with the Debian Securing Manual (contributions accepted)

2001-09-24 Thread Will Aoki
On Sun, Sep 23, 2001 at 06:40:46PM -0700, Nicole Zimmerman wrote: Yup, I'm not using a proxy. http://www.debian.org/doc/manuals/securing-debian-howto/ I can access the following URL (which I found by going through the www.debian.org/doc tree):

Re: Need Help with the Debian Securing Manual (contributions accepted)

2001-09-24 Thread Nicole Zimmerman
At 00:26 on Sep 24, Will Aoki combined all the right letters to say: Mozilla's default language setting is only US English (en-us). My guess is that people getting 403s are running their browsers with out of the box language settings or have changed language settings but haven't listed 'en'

Re: crc32 compensation attack

2001-09-24 Thread Jamie Heilman
Micah Anderson wrote: Got what appears to be a crc32 compensation attack in my logs today, about 10 minutes worth of these types of messages should I be worried? Should I laugh at this feable attempt to break in? Should I gnaw my fingernails with my shotgun on my lap? heh,

Questions regarding the Security Secretary Position

2001-09-24 Thread Martin Schulze
I'm awfully sorry for the delay, but I wasn't able to work on this earlier again. Here's a list of questions and answers that came up with the posting I made last week. Q: Is a requirement being a Debian developer? No. It is my understanding that it would be good to have fresh blood in

Subject!

2001-09-24 Thread Dietmar Braun
Hello all, please, PLEASE use a subject when you are mailing to this list! It is quite annoying getting mails without any subject, and usually many people are filtering mails without a subject. Thanks. Regards, Dietmar

RE: New IIS worm

2001-09-24 Thread Anders Gjære
LaBrea could maby be interesting for someone http://hts.dshield.org/LaBrea/ its for decreasing the spread of worms witch tryes random ip's mvh anders # -Original Message- # From: Karl E. Jorgensen [mailto:[EMAIL PROTECTED] # Sent: 23. september 2001 18:19 # To:

strange AIDE reports

2001-09-24 Thread Juha Jäykkä
I keep receiving strange reports from AIDE. The number of changed files increases monotonically daily and the affair started immediately after installation, so I doubt there has been a break-in - unless someone managed to spoof my DNS queries or hijack my connections to ftp.fi.debian.org. Aside

Re: strange AIDE reports

2001-09-24 Thread Vegard Engen
On Mon, Sep 24, 2001 at 02:02:49PM +0300, Juha Jäykkä wrote: I keep receiving strange reports from AIDE. The number of changed files increases monotonically daily and the affair started immediately after installation, so I doubt there has been a break-in - unless someone managed to spoof my

Re: strange AIDE reports

2001-09-24 Thread Juha Jäykkä
Any ideas except a break-in? Well - you say you're using unstable. Are you updating your system? There are a lot of changes in unstable. After a package replacement, binary files will of course have changed. Of course, but every time I run apt, I run aide --update, too, and move the

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread Haris Sehic
On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: Do you know if it can infect my debian box? Thanks, Enrique only if you have VB installed ---snip--- script language='VBScript' ---snip---

Re: Need Help with the Debian Securing Manual (contributions accepted)

2001-09-24 Thread James Hamilton
Works fine for me. Thank you, James Hamilton Systems/Software Engineer Davis Tool, Inc. http://www.davistl.com Nicole Zimmerman [EMAIL PROTECTED] 09/23/01 06:40PM Yup, I'm not using a proxy. http://www.debian.org/doc/manuals/securing-debian-howto/ I can access the following URL (which I

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread Emmanuel Valliet
(2001-09-24) Haris Sehic sed : | On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: |Do you know if it can infect my debian box? | | Thanks, | Enrique | | only if you have VB installed | | ---snip---

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread Haris Sehic
On Mon, Sep 24, 2001 at 02:17:07PM -0400, Emmanuel Valliet wrote: Or perhaps if you have wine (did you read /. today :D ? ) hui 10x i was not on /. for 2 days now :) its funny .. worm emulation if you want smile god i love linux even becose of this fackt /smile bye Haris -- First They

Re: [Fwd: Virus found in sent message ?????????????????????3????]

2001-09-24 Thread James Hamilton
That is some funny stuff. :) Emmanuel Valliet [EMAIL PROTECTED] 09/24/01 11:17AM (2001-09-24) Haris Sehic sed : | On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: |Do you know if it can infect my debian box? | | Thanks, |

Re: [Fwd: Virus found in sent message ?????????????????????3???? ]

2001-09-24 Thread John Galt
They DID use Wine to execute SirCam once... :) On Mon, 24 Sep 2001, Haris Sehic wrote: On Mon, Sep 24, 2001 at 07:39:13PM +0200, Enrique de la Torre wrote: Do you know if it can infect my debian box? Thanks, Enrique