Re: secure file transfer

2002-06-05 Thread Nato
Thanks for all the suggestions. This mailing list rocks Nato - Original Message - From: "José Luis Ledesma" <[EMAIL PROTECTED]> To: "'Renato Lozano'" <[EMAIL PROTECTED]>; Sent: Wednesday, June 05, 2002 3:57 AM Subject: RE: secure file transfer > You can do a chrooted enviroment (s

Re: secure file transfer

2002-06-05 Thread Will Aoki
On Tue, Jun 04, 2002 at 09:58:55AM -0400, Jon McCain wrote: > You can remove the sftp-server program to disable sftp but you can't > turn off the scp commands. They are part of ssh. So someone could > still use something like winscp and be able to browse everything. > > You can "break" scp by ma

Re: secure file transfer

2002-06-05 Thread Jon McCain
> > In proftpd.conf: > > RequireValidShell off > > ;-) > I would be careful about doing that. That might open ftp access for accounts you dont want to have access. Plus some applications create special accounts without shells like mysql,inetd,etc. mysql:x:103:102:MySQL Server:/var/li

unsubscribe

2002-06-05 Thread superflused
- Original Message - From: "Wichert Akkerman" <[EMAIL PROTECTED]> To: Sent: Wednesday, June 05, 2002 10:29 AM Subject: Re: Security Updates Sources > Previously Olaf Meeuwissen wrote: > > Right now, for binary-i386 you'll be getting packages for new upstream > > releases. Packages conc

Re: tripwire

2002-06-05 Thread Florian Bantner
On Mit, 05 Jun 2002, sma ten wrote: > hi, > i've installed tripwire with apt-get but now i don't really know how it > works... > in fact i've already used tripwire but with the source code .tar.gz and i > remember that i have to execute 'tripwire --check' to test the integrity ... > but now i d

Re: secure file transfer

2002-06-05 Thread Wichert Akkerman
Previously Michael van der Kolff wrote: > if you want to implement a huge one you'll have to find the x.509 cert > patch, but from what I hear it's quite a flexible implementation. It seems to work quite well. The X.509 and multi-crypto patches are both included in the kernel-patch-freeswan packag

Re: Security Updates Sources

2002-06-05 Thread Wichert Akkerman
Previously Olaf Meeuwissen wrote: > Right now, for binary-i386 you'll be getting packages for new upstream > releases. Packages concerned: qpopper, qpopper-drac and squirrelmail. > It looks pretty much the same for the other architectures I looked at. All architectures have the exact same package

tripwire

2002-06-05 Thread sma ten
hi, i've installed tripwire with apt-get but now i don't really know how it works... in fact i've already used tripwire but with the source code .tar.gz and i remember that i have to execute 'tripwire --check' to test the integrity ... but now i didn't find how to replace this command ... i've ju

RE: secure file transfer

2002-06-05 Thread José Luis Ledesma
You can do a chrooted enviroment (see above) And start de sshd witch chroot /sbin/sshd -f /etc/sshd_config Also you can specify the shell of the users in /etc/passwd as /sbin/sftp-server if you only want to allow this users do a sftp. Regards, .: total 36 drwxr-xr-x 9 root root 4096 Jun 5

Bind 9.2.0 vulnerability

2002-06-05 Thread VERBEEK, Francois
Hello Does anyone know when Bind 9.2.1 will be integrated in the testing branch? There is a CERT advisory about a vulnerability in bind 9.2.0. CERT Advisory CA-2002-15 Denial-of-Service Vulnerability in ISC BIND 9 http://www.kb.cert.org/vuls/id/739123. Bind version 9.2.1 is integrated in the