Bypassing allowed_users with PAM in sshd?

2006-11-08 Thread Marcus Williams
Hi - I noticed in logwatch reports today that someone had tried logging in as root to one of my servers recently. No surprise there as this happens every day. However I have explicitly set up a set of users in allowed_users and root isnt one of them (I also have AllowRootLogin set to false).

Grsecurity patches on Debian

2005-02-07 Thread Marcus Williams
Hi - Has anyone any advice on using grsecurity on a server running Debian (testing) - I'm thinking about patching my new kernel with the grsecurity stuff and starting to use it but I'm unsure of what I can expect. Are the defaults going to break (or stop from functioning) anything obvious (name

Re: doing an ssh into a compromised host

2004-11-03 Thread Marcus Williams
ts ssh or not - its really for gpg and such. Looks like you could write a wrapper script so that it supported ssh though. Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*] -- To UNSUBSCRIBE, email to [EMAIL

Re: Recommended firewall package?

2004-11-02 Thread Marcus Williams
give it a once over. Never gone back to the iptables mess I had (it still generates an iptables script but I dont have to look at/maintain it, which can only be good thing IMNSHO). Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This mes

Re: Providing secure file access on a colo-server

2004-10-08 Thread Marcus Williams
pport sftp and the users that use Frontpage might not be willing to have that extra step involved (publish to local drive -> drag to winscp). Not that they'll have the choice in the end :) Thanks Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge

Providing secure file access on a colo-server

2004-10-08 Thread Marcus Williams
pport sftp (dav server might be possible?) Cheers Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
happens with media errors on the tape when you read it back? Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*]

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
happens with media errors on the tape when you read it back? Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe".

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
On 13/01/2004, Alexander Neumann wrote: > * Marcus Williams <[EMAIL PROTECTED]> wrote: >> [I meant to send this to the list] > Thanks. I was just writing a mail about honoring the > Mail-Followup-To:-Header... ;) [snip] Sigh.. one of my wish list items for TheBat! is proper

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
[I meant to send this to the list] On 13/01/2004, Alexander Neumann wrote: > You are able to store the backup-files on a local disk... Yes, but then we lose the ability to take them offsite. Well, unless I then move them to a tape. Worth thinking about though. Thanks Marcus -- Mar

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
On 13/01/2004, Alexander Neumann wrote: > * Marcus Williams <[EMAIL PROTECTED]> wrote: >> [I meant to send this to the list] > Thanks. I was just writing a mail about honoring the > Mail-Followup-To:-Header... ;) [snip] Sigh.. one of my wish list items for TheBat! is proper

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
[I meant to send this to the list] On 13/01/2004, Alexander Neumann wrote: > You are able to store the backup-files on a local disk... Yes, but then we lose the ability to take them offsite. Well, unless I then move them to a tape. Worth thinking about though. Thanks Marcus -- Mar

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*]

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
a further security measure (in case of fire etc). This rules out backups to encrypted filesystems on a harddrive as hard drives are easily breakable (if dropped for instance)] Thanks, Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*]

Encrypted backups

2004-01-13 Thread Marcus Williams
rypted backup sets (which I was expecting). Does anyone know of ways to speed the process up? Are there any other ways of getting an encrypted backup set that might be faster? Thanks Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is p

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is private [ ] public [*] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of "unsubscribe". Trouble? Contact [EMAIL PROTECTED]

Re: Encrypted backups

2004-01-13 Thread Marcus Williams
a further security measure (in case of fire etc). This rules out backups to encrypted filesystems on a harddrive as hard drives are easily breakable (if dropped for instance)] Thanks, Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This messa

Encrypted backups

2004-01-13 Thread Marcus Williams
rypted backup sets (which I was expecting). Does anyone know of ways to speed the process up? Are there any other ways of getting an encrypted backup set that might be faster? Thanks Marcus -- Marcus Williams -- http://www.quintic.co.uk Quintic Ltd, 39 Newnham Road, Cambridge, UK This message is p