Re: GET http://someStrangeOrExternalDomain.com

2003-10-13 Thread Thomas Horsten
Hi Ricardo, On Friday 03 October 2003 22:51, Ricardo wrote: I found on my apache´s log a lot of messages like *.*.*.* - - [Date] GET http://someStrangeOrExternalDomain.com HTP1.0/ 404 206 - - I saw on many lists and FAQs some indications that the problem may be caused because of an

Re: GET http://someStrangeOrExternalDomain.com

2003-10-13 Thread Thomas Horsten
Hi Ricardo, On Friday 03 October 2003 22:51, Ricardo wrote: I found on my apache´s log a lot of messages like *.*.*.* - - [Date] GET http://someStrangeOrExternalDomain.com HTP1.0/ 404 206 - - I saw on many lists and FAQs some indications that the problem may be caused because of an

Re: MS BS

2003-09-24 Thread Thomas Horsten
On Mon, 22 Sep 2003, Ted Roby wrote: My secalert account for these lists is being drenched with 40 to 70 of these fake Microsoft Update emails per day. My filters on my client dump them to a Junk folder, but I would prefer it if my Exim filter would do the job at the server level instead. I

Re: Debian + Verisign's .com/.net hijack

2003-09-17 Thread Thomas Horsten
On Wed, 17 Sep 2003, Gaël Le Mignot wrote: What precisely have they done? I'd not heard about their latest idiocy... They decided to answer to all requests for a non-existing domain in .com or .net with the IP of some of their computers, hosting an advertising page... Please

Re: Debian + Verisign's .com/.net hijack

2003-09-17 Thread Thomas Horsten
On Wed, 17 Sep 2003, Gaël Le Mignot wrote: What precisely have they done? I'd not heard about their latest idiocy... They decided to answer to all requests for a non-existing domain in .com or .net with the IP of some of their computers, hosting an advertising page... Please

Re: ssh vulnerability in the wild

2003-09-16 Thread Thomas Horsten
On Tue, 16 Sep 2003, Alexander Neumann wrote: According to Wichert, the security team is already working on an update. Is there an emergency patch/workaround for this, if disabling ssh is not an option? Are systems with Privilege Separation affected? Thanks, Thomas -- To UNSUBSCRIBE, email

Re: ssh vulnerability in the wild

2003-09-16 Thread Thomas Horsten
On Tue, 16 Sep 2003, Steve Suehring wrote: Actually, there is a patch for buffer.c: http://www.freebsd.org/cgi/cvsweb.cgi/src/crypto/openssh/buffer.c.diff?r1=1.1.1.6r2=1.1.1.7f=h I've applied that patch to woody's ssh source, rebuilt it, and installed it on a number of servers already.

Re: ssh vulnerability in the wild

2003-09-16 Thread Thomas Horsten
On Tue, 16 Sep 2003, Alexander Neumann wrote: According to Wichert, the security team is already working on an update. Is there an emergency patch/workaround for this, if disabling ssh is not an option? Are systems with Privilege Separation affected? Thanks, Thomas

Re: Possible buffer overflows = security problem?

2003-09-05 Thread Thomas Horsten
Hi Frank, On Fri, 5 Sep 2003, Frank Lichtenheld wrote: char path[256]; sprintf( path, some string/%s, packagename); There are no further checks as I can see. I'm not very experienced in C programming and don't know much about the details of exploiting buffer overflows or the like... Is

Re: Possible buffer overflows = security problem?

2003-09-05 Thread Thomas Horsten
Hi Frank, On Fri, 5 Sep 2003, Frank Lichtenheld wrote: char path[256]; sprintf( path, some string/%s, packagename); There are no further checks as I can see. I'm not very experienced in C programming and don't know much about the details of exploiting buffer overflows or the like... Is

Re: ScanMail Message to recipient: eManager settings were matchedand action was taken.

2003-08-30 Thread Thomas Horsten
Who are mpuk and why are they censoring debian's mailing list, apparently from several different senders? On Sat, 30 Aug 2003, System Attendant wrote: eManager Notification * The following message was blocked because it contains sensitive content. Source

Re: ScanMail Message to recipient: eManager settings were matched and action was taken.

2003-08-30 Thread Thomas Horsten
Who are mpuk and why are they censoring debian's mailing list, apparently from several different senders? On Sat, 30 Aug 2003, System Attendant wrote: eManager Notification * The following message was blocked because it contains sensitive content. Source

Re: Yet anothe rhave i been hacked alert

2003-05-16 Thread Thomas Horsten
On Fri, 16 May 2003, Andreas Vitz wrote: May 15 09:37:07 kai-router pppoe[180]: Bogus PPPoE length field (111) May 15 09:47:18 kai-router pppoe[180]: Bogus PPPoE length field (172) i get them day by day, since a week or so. I use a adsl connection. so my final question have i been hacked

Re: idea for improving security

2003-05-07 Thread Thomas Horsten
On Wednesday 07 May 2003 13:54, Jay Kline wrote: This is still prety complex, if the end result is just to allow access to port 22. SSH is pretty secure, there have been very few problems with ssh that allow someone without an account to gain access to the system its on. If you take all

Re: unsubscribe

2002-11-17 Thread Thomas Horsten
You STUPID IDIOT. Can't you read. Jesus your IQ must be 80. On Sun, 17 Nov 2002, Antoine Patois wrote: -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Re: unsubscribe

2002-11-17 Thread Thomas Horsten
You STUPID IDIOT. Can't you read. Jesus your IQ must be 80. On Sun, 17 Nov 2002, Antoine Patois wrote: -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

RE: unsubscribe

2002-11-16 Thread Thomas Horsten
On 15 Nov 2002, Yogesh Sharma wrote: I think debian list has to add some filter on subject and if subject contains unsubscribe redirect that email to [EMAIL PROTECTED] or else we have add following message in multiple languages. To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

RE: unsubscribe

2002-11-16 Thread Thomas Horsten
On 15 Nov 2002, Yogesh Sharma wrote: I think debian list has to add some filter on subject and if subject contains unsubscribe redirect that email to [EMAIL PROTECTED] or else we have add following message in multiple languages. To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of

Re: unsubscribe

2002-11-15 Thread Thomas Horsten
Are you thick or what? On Fri, 15 Nov 2002, Stone wrote: Pozdrawiam Stone [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe.

Re: unsubscribe

2002-11-15 Thread Thomas Horsten
Are you thick or what? On Fri, 15 Nov 2002, Stone wrote: Pozdrawiam Stone [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: spam

2002-11-11 Thread Thomas Horsten
On Sun, 10 Nov 2002 [EMAIL PROTECTED] wrote: how can i block these bastards from korea from spaming me 10 times per day? Set your mail server up to filter all Korean mail (that is, if you don't have any friends or relatives in Korea). There is a site, http://www.blackholes.us which has a

Re: spam

2002-11-11 Thread Thomas Horsten
On Sun, 10 Nov 2002 [EMAIL PROTECTED] wrote: how can i block these bastards from korea from spaming me 10 times per day? Set your mail server up to filter all Korean mail (that is, if you don't have any friends or relatives in Korea). There is a site, http://www.blackholes.us which has a

Re: I dont understand that

2002-09-21 Thread Thomas Horsten
On Sat, 21 Sep 2002, Petar D Donchev wrote: I have linux woody box with 2.2.20 kernel. i receive some strange messages in my log like this: Sep 21 00:59:49 cs kernel: Oops: Sep 21 00:59:49 cs kernel: CPU:0 Sep 21 00:59:49 cs kernel: EIP:0010:[find_inode+32/72] Sep 21 00:59:49

Re: I dont understand that

2002-09-21 Thread Thomas Horsten
On Sat, 21 Sep 2002, Petar D Donchev wrote: I have linux woody box with 2.2.20 kernel. i receive some strange messages in my log like this: Sep 21 00:59:49 cs kernel: Oops: Sep 21 00:59:49 cs kernel: CPU:0 Sep 21 00:59:49 cs kernel: EIP:0010:[find_inode+32/72] Sep 21 00:59:49

Re: question from a newbie regarding possible trojan

2002-09-17 Thread Thomas Horsten
to check if netstat has been tampered with: $ dpkg -S /bin/netstat net-tools: /bin/netstat $ debsums net-tools Hope this was useful. Remember that auditing the integrity of the system files is only a small part of securing your system, but it is an important one. Regards, Thomas Horsten [EMAIL

Re: question from a newbie regarding possible trojan

2002-09-17 Thread Thomas Horsten
to check if netstat has been tampered with: $ dpkg -S /bin/netstat net-tools: /bin/netstat $ debsums net-tools Hope this was useful. Remember that auditing the integrity of the system files is only a small part of securing your system, but it is an important one. Regards, Thomas Horsten [EMAIL

Re: http://www.securiteam.com/unixfocus/5QP020K350.html

2002-08-08 Thread Thomas Horsten
On Thu, 8 Aug 2002, Roger Ward wrote: Which bug? this url does not work Seems he typed the URL manually or something, the last character is an O and not 0, I found the correct article: http://www.securiteam.com/unixfocus/5QP020K35O.html // Thomas