Re: Long Exim break-in analysis

2010-12-22 Thread Maximilian Wilhelm
Anno domini 2010 Izak Burger scripsit: Hi! Nice reports :) But there is one bit that gets me. It does this: mkdir -p /usr/include/mysql echo dropbear /usr/include/mysql/mysql.hh1 It never does anything with that file, and that file does not exist on a real system, so its almost like its

Re: [SECURITY] [DSA 1714-1] New rt2570 packages fix arbitrary code execution

2009-01-28 Thread Maximilian Wilhelm
Anno domini 2009 Chris Lamb scripsit: Moritz Muehlenhoff wrote: - Debian Security Advisory DSA-1714-1 secur...@debian.org http://www.debian.org/security/ Moritz Muehlenhoff

Re: Root login

2008-09-04 Thread Maximilian Wilhelm
Anno domini 2008 François Cerbelle scripsit: Le Jeu 4 septembre 2008 14:25, Paweł Krzywicki a écrit : On czwartek, 4 września 2008, [EMAIL PROTECTED] wrote: i too noticed a similar thing when i installed on my new laptop etch. the solution was as Cerbelle said. Login as a normal user and

Re: Mass-updating cached hosts keys afrer ssh security upgrade?

2008-07-22 Thread Maximilian Wilhelm
Anno domini 2008 JW scripsit: Hi! In the past several weeks I have applied the openssh/openssl updates to my systems - the updates the fix the random-number-generator weakness. This has turned into an unexpected nightmare: my users have, between them all, dozens of cached host keys, and

Re: Why not have firewall rules by default?

2008-01-23 Thread Maximilian Wilhelm
Am Wednesday, den 23 January hub Florian Weimer folgendes in die Tasten: * Ondrej Zajicek: You could also have an 'ENABLED' variable like some files in /etc/default have (so that ports wouldn't be opened by default; the user would have to manually enable them for the port to be opened).

Re: nmap Xmas scans and unrecognized outcoming connections

2007-12-07 Thread Maximilian Wilhelm
Am Friday, den 7 December hub Martín Peluso folgendes in die Tasten: Hi! Two days ago one of my machines started to receive several nmap Xmas scans from 73.23.32.79. Later, in another machine which is running under Debian etch, Firestarter showed me four outcoming connections to the same

/var/lib/dpkg/info/$package.md5sums

2007-08-19 Thread Maximilian Wilhelm
Hi! While tracking down an incident in our network, I used 'debsums' to check what files have been modified on our still Sarge boxes and on our Etch boxes, too. I noticed that for some essential packages there are no md5sums information in /var/lib/dpkg/info/: debsums: no md5sums for bzip2