Re: Advisory description text

2008-01-07 Thread Christoph Ulrich Scholler
Hi, On 07.01. 13:54, Adam Majer wrote: Moritz Muehlenhoff wrote: CVE-2007-3382 It was discovered that single quotes (') in cookies were treated as a delimiter, which could lead to an information leak. CVE-2007-3385 It was discovered that the character sequence \ in

Re: How to prevent daemons from ever being started?

2006-05-16 Thread Christoph Ulrich Scholler
Hi, On 15.05. 17:09, Uwe Hermann wrote: What is the Debian way to prevent any daemon from ever starting, whether upon reboot, upon upgrade, upon new install etc. If your default runlevel is 2, delete the symlink to the respective init script in /etc/rc2.d or even in /etc/rc[2345].d. Just make

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Christoph Ulrich Scholler
Hi, On 23.01. 07:46, Jose Marrero wrote: Apache configured with mod_rewrite to deny blank or fake referers is a good idea. How can you tell that a referrer is fake? Regards, uLI -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: PermitRootLogin enabled by default

2002-06-26 Thread Christoph Ulrich Scholler
On Wed, Jun 26, 2002 at 02:11:00PM +0200 or thereabouts, InfoEmergencias - Luis Gómez wrote: Messing up with sshd_config for all the privsep stuff, I've noticed that PermitRootLogin was set to yes in my three woody boxes. I usually consider this a problem (although it has been my fault - i

Re: VI wrapper for SUDO?

2001-11-30 Thread Christoph Ulrich Scholler
hi, maybe i misunderstand the intention here, but isn't it pointless to restrict privileges of the editing process of /etc/aliases if you could just as well change root's alias to a program that's run whenever root receives email and, e. g., puts one's most favourite /etc/passwd in place of the

Re: VI wrapper for SUDO?

2001-11-30 Thread Christoph Ulrich Scholler
hi, maybe i misunderstand the intention here, but isn't it pointless to restrict privileges of the editing process of /etc/aliases if you could just as well change root's alias to a program that's run whenever root receives email and, e. g., puts one's most favourite /etc/passwd in place of the

Re: rogue Chinese crawler

2001-11-23 Thread Christoph Ulrich Scholler
On Fri, Nov 23, 2001 at 05:32:04PM + or thereabouts, Martin WHEELER wrote: Is anyone else having problems with the robot from openfind.com.tw ... Anyone know of a sure-fire robot killer under woody? as a first recourse you could instruct your firewall to deny all access from