[SECURITY] [DSA 519-1] New CVS packages fix several potential security problems

2004-06-15 Thread Martin Schulze
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 - -- Debian Security Advisory DSA 519-1 [EMAIL PROTECTED] http://www.debian.org/security/ Martin Schulze June 15th, 2004

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread Jan Meijer
On Tue, 15 Jun 2004, Ross Tsolakidis wrote: I'd appreciate some help on how to stop this from happening. Run something like aide so you can detect when it goes wrong (though there are some caveats it does not sound like they will hit you) and run a netflow-collector next to it, if you can.

Re: Kernel Crash Bug????

2004-06-15 Thread Rudy Gevaert
Would it be possible to run that program trough e.g. perl/php/... ? A use could ftp the executable and write a php script that execute it. Thanks in advance, Rudy -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Kernel Crash Bug????

2004-06-15 Thread Russell Coker
On Tue, 15 Jun 2004 17:24, Rudy Gevaert [EMAIL PROTECTED] wrote: Would it be possible to run that program trough e.g. perl/php/... ? A use could ftp the executable and write a php script that execute it. Does PHP allow executing arbitary binaries? If the user can install CGI-BIN scripts then

Re: Kernel Crash Bug????

2004-06-15 Thread Rudy Gevaert
Ignore my message. I didn't read the url give aboven carefully enough. It mentions what I asked. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Kernel Crash Bug????

2004-06-15 Thread David Ramsden
On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: On Tue, 15 Jun 2004 17:24, Rudy Gevaert [EMAIL PROTECTED] wrote: Would it be possible to run that program trough e.g. perl/php/... ? A use could ftp the executable and write a php script that execute it. Does PHP allow

Re: password managers

2004-06-15 Thread Alberto Gonzalez Iniesta
On Tue, Jun 15, 2004 at 12:46:13AM +0200, Stephan Dietl wrote: Hello! andrew lattis [EMAIL PROTECTED] schrieb: what does everyone else use to keep track of all there passwords? Following an article of Martin Joey Schulze in a german magazine i send a mail with the password encryted for

Re: may CAN-2004-041[678] affect on woody?

2004-06-15 Thread Hideki Yamane
Hi, Fri, 11 Jun 2004 20:50:12 +0900, [EMAIL PROTECTED] may CAN-2004-041[678] affect on woody? May CAN-2004-0416, CAN-2004-0417 and CAN-2004-0418 not affect on Debian woody? Or, may anyone works for merging this fix? The answer is It affects woody and now DSA 519-1 was shipped. --

securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread Rudy Gevaert
On Tue, Jun 15, 2004 at 09:23:33AM +0100, David Ramsden wrote: On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: Does PHP allow executing arbitary binaries? [snip] Yes, unless in your php.ini you have something along the lines of: disable_functions =

Re: securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread Jeroen van Wolffelaar
On Tue, Jun 15, 2004 at 10:35:33AM +0200, Rudy Gevaert wrote: On Tue, Jun 15, 2004 at 09:23:33AM +0100, David Ramsden wrote: On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: Does PHP allow executing arbitary binaries? [snip] Yes, unless in your php.ini you have

Re: securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread David Ramsden
On Tue, Jun 15, 2004 at 11:20:35AM +0200, Jeroen van Wolffelaar wrote: On Tue, Jun 15, 2004 at 10:35:33AM +0200, Rudy Gevaert wrote: On Tue, Jun 15, 2004 at 09:23:33AM +0100, David Ramsden wrote: On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: Does PHP allow executing

Re: securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread Hideki Yamane
Hi, Tue, 15 Jun 2004 10:35:33 +0200, Rudy Gevaert securing PHP (was: Kernel Crash Bug) Can somebody point me to some documentation about securing PHP? Not documentation but patch for php, Hardened-PHP. http://www.hardened-php.net/ -- Regards, Hideki Yamanemailto:henrich @

Re: password managers

2004-06-15 Thread Kenneth Jacker
al what does everyone else use to keep track of all there passwords? I've used 'tkpasman' for years ... nice! http://www.xs4all.nl/~wbsoft/linux/tkpasman.html -- Prof Kenneth H Jacker [EMAIL PROTECTED] Computer Science Dept www.cs.appstate.edu/~khj Appalachian State Univ

Re: password managers

2004-06-15 Thread Micah Anderson
Try kedpm, its a debian package, and has console as well as GUI support and uses the FPM data, really nice. micah On Tue, 15 Jun 2004, Kenneth Jacker wrote: al what does everyone else use to keep track of all there passwords? I've used 'tkpasman' for years ... nice!

Re: password managers

2004-06-15 Thread Kenneth Jacker
micah Try kedpm, its a debian package, and has console as well as micah GUI support and uses the FPM data, really nice. Thanks for the suggestion! Though I found a web site for 'kedpm': http://kedpm.sourceforge.net/ the following return no Debian packages:

Re: [OT] Spam fights

2004-06-15 Thread Alain Tesio
Here is a list of junk subject patterns in case someone is interested. Alain junkMailPatterns.gz Description: Binary data

Re: Spam fights

2004-06-15 Thread Alain Tesio
Can the mailing list software add a X-Subscribed : yes/no in the mail headers ? Then people decide to filter it out or not. Alain -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

RE: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread Ross Tsolakidis
Wipe, install, set up chkrootkit and run it often. I've already done that. There was no rootkit. How does phpnuke compromise apache if apache is set up correctly? I believe it's some of the modules available and running php with 'safe mode off'. I need to find the vulnerable code on this box.

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread David Ramsden
On Tue, Jun 15, 2004 at 02:32:21PM +1000, Ross Tsolakidis wrote: Wipe, install, set up chkrootkit and run it often. I've already done that. There was no rootkit. An alternative to chkrootkit is rkhunter - it's a set of scripts. You can find the web address on something like freshmeat.net or

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread TiM
Look at installing mod_security, http://modsecurity.org Install some rules for it to harden your webserver, see if anything is flagged in the security log. Ross Tsolakidis wrote: Wipe, install, set up chkrootkit and run it often. I've already done that. There was no rootkit. How does phpnuke

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread Alvin Oga
hi ya On Wed, 16 Jun 2004, TiM wrote: Look at installing mod_security, http://modsecurity.org Install some rules for it to harden your webserver, see if anything is flagged in the security log. other web server testing tools http://www.linux-sec.net/Web/#Testing c ya alvin

Re: password managers

2004-06-15 Thread Russell Coker
On Tue, 15 Jun 2004 18:46, Alberto Gonzalez Iniesta [EMAIL PROTECTED] wrote: Some of the applications I run use kwallet, that seems similar to what Russell Cooker described for OS X. No. kwallet can be ptraced, this allows a hostile program to get access to all it's data with ease. Of course

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread s. keeling
Incoming from Ross Tsolakidis: One of our webservers seems to get compromised on a daily basis. When I do a ps ax I see these processes all the time. 18687 ?S 0:00 shell 18701 ?Z 0:00 [sh defunct] 18704 ?T 0:00 ./3 200.177.162.185 1524 I vaguely

Re: Kernel Crash Bug????

2004-06-15 Thread Rudy Gevaert
Would it be possible to run that program trough e.g. perl/php/... ? A use could ftp the executable and write a php script that execute it. Thanks in advance, Rudy

Re: Kernel Crash Bug????

2004-06-15 Thread Russell Coker
On Tue, 15 Jun 2004 17:24, Rudy Gevaert [EMAIL PROTECTED] wrote: Would it be possible to run that program trough e.g. perl/php/... ? A use could ftp the executable and write a php script that execute it. Does PHP allow executing arbitary binaries? If the user can install CGI-BIN scripts then

Re: Kernel Crash Bug????

2004-06-15 Thread Rudy Gevaert
Ignore my message. I didn't read the url give aboven carefully enough. It mentions what I asked.

Re: Kernel Crash Bug????

2004-06-15 Thread David Ramsden
On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: On Tue, 15 Jun 2004 17:24, Rudy Gevaert [EMAIL PROTECTED] wrote: Would it be possible to run that program trough e.g. perl/php/... ? A use could ftp the executable and write a php script that execute it. Does PHP allow

Re: password managers

2004-06-15 Thread Alberto Gonzalez Iniesta
On Tue, Jun 15, 2004 at 12:46:13AM +0200, Stephan Dietl wrote: Hello! andrew lattis [EMAIL PROTECTED] schrieb: what does everyone else use to keep track of all there passwords? Following an article of Martin Joey Schulze in a german magazine i send a mail with the password encryted for

Re: may CAN-2004-041[678] affect on woody?

2004-06-15 Thread Hideki Yamane
Hi, Fri, 11 Jun 2004 20:50:12 +0900, [EMAIL PROTECTED] may CAN-2004-041[678] affect on woody? May CAN-2004-0416, CAN-2004-0417 and CAN-2004-0418 not affect on Debian woody? Or, may anyone works for merging this fix? The answer is It affects woody and now DSA 519-1 was shipped. --

securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread Rudy Gevaert
On Tue, Jun 15, 2004 at 09:23:33AM +0100, David Ramsden wrote: On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: Does PHP allow executing arbitary binaries? [snip] Yes, unless in your php.ini you have something along the lines of: disable_functions =

Re: securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread Jeroen van Wolffelaar
On Tue, Jun 15, 2004 at 10:35:33AM +0200, Rudy Gevaert wrote: On Tue, Jun 15, 2004 at 09:23:33AM +0100, David Ramsden wrote: On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: Does PHP allow executing arbitary binaries? [snip] Yes, unless in your php.ini you have

Re: securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread David Ramsden
On Tue, Jun 15, 2004 at 11:20:35AM +0200, Jeroen van Wolffelaar wrote: On Tue, Jun 15, 2004 at 10:35:33AM +0200, Rudy Gevaert wrote: On Tue, Jun 15, 2004 at 09:23:33AM +0100, David Ramsden wrote: On Tue, Jun 15, 2004 at 05:52:18PM +1000, Russell Coker wrote: Does PHP allow executing

Re: securing PHP (was: Kernel Crash Bug????)

2004-06-15 Thread Hideki Yamane
Hi, Tue, 15 Jun 2004 10:35:33 +0200, Rudy Gevaert securing PHP (was: Kernel Crash Bug) Can somebody point me to some documentation about securing PHP? Not documentation but patch for php, Hardened-PHP. http://www.hardened-php.net/ -- Regards, Hideki Yamanemailto:henrich @

Re: password managers

2004-06-15 Thread Kenneth Jacker
al what does everyone else use to keep track of all there passwords? I've used 'tkpasman' for years ... nice! http://www.xs4all.nl/~wbsoft/linux/tkpasman.html -- Prof Kenneth H Jacker [EMAIL PROTECTED] Computer Science Dept www.cs.appstate.edu/~khj Appalachian State Univ

Re: password managers

2004-06-15 Thread Micah Anderson
Try kedpm, its a debian package, and has console as well as GUI support and uses the FPM data, really nice. micah On Tue, 15 Jun 2004, Kenneth Jacker wrote: al what does everyone else use to keep track of all there passwords? I've used 'tkpasman' for years ... nice!

Re: password managers

2004-06-15 Thread Kenneth Jacker
micah Try kedpm, its a debian package, and has console as well as micah GUI support and uses the FPM data, really nice. Thanks for the suggestion! Though I found a web site for 'kedpm': http://kedpm.sourceforge.net/ the following return no Debian packages:

Re: [OT] Spam fights

2004-06-15 Thread Alain Tesio
Here is a list of junk subject patterns in case someone is interested. Alain junkMailPatterns.gz Description: Binary data

Re: Spam fights

2004-06-15 Thread Alain Tesio
Can the mailing list software add a X-Subscribed : yes/no in the mail headers ? Then people decide to filter it out or not. Alain

RE: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread Ross Tsolakidis
Wipe, install, set up chkrootkit and run it often. I've already done that. There was no rootkit. How does phpnuke compromise apache if apache is set up correctly? I believe it's some of the modules available and running php with 'safe mode off'. I need to find the vulnerable code on this box.

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread David Ramsden
On Tue, Jun 15, 2004 at 02:32:21PM +1000, Ross Tsolakidis wrote: Wipe, install, set up chkrootkit and run it often. I've already done that. There was no rootkit. An alternative to chkrootkit is rkhunter - it's a set of scripts. You can find the web address on something like freshmeat.net or

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread TiM
Look at installing mod_security, http://modsecurity.org Install some rules for it to harden your webserver, see if anything is flagged in the security log. Ross Tsolakidis wrote: Wipe, install, set up chkrootkit and run it often. I've already done that. There was no rootkit. How does

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-15 Thread Alvin Oga
hi ya On Wed, 16 Jun 2004, TiM wrote: Look at installing mod_security, http://modsecurity.org Install some rules for it to harden your webserver, see if anything is flagged in the security log. other web server testing tools http://www.linux-sec.net/Web/#Testing c ya alvin