Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Michael Loftis
--On January 23, 2006 8:31:40 AM +0100 Maik Holtkamp [EMAIL PROTECTED] wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, yesterday morning I found a strange entry in my apache log files (debian sarge, apache 1.3, mambo 4.5.3, kernel 2.4.31). It's a dyndns homelan Server, just

Re: [SECURITY] [DSA 946-1] New sudo packages fix privilege escalation

2006-01-23 Thread Josselin Mouette
Le vendredi 20 janvier 2006 à 11:24 +0100, Martin Schulze a écrit : This update alters the former behaviour of sudo and limits the number of supported environment variables to LC_*, LANG, LANGUAGE and TERM. Additional variables are only passed through when set as env_check in /etc/sudoers,

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Edward Shornock
On Mon, Jan 23, 2006 at 08:31:40AM +0100, Maik Holtkamp wrote: -BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, yesterday morning I found a strange entry in my apache log files (debian sarge, apache 1.3, mambo 4.5.3, kernel 2.4.31). It's a dyndns homelan Server, just serving my Family

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Edward Shornock
Oops...didn't trim enough of the response and curiosity made me research this. According to the sophos site: --cut-- Linux/Rst-B will attempt to infect all ELF executables in the current working directory and the directory /bin If Linux/Rst-B is executed by a privileged user then it may attempt

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Maik Holtkamp
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Edward Shornock schrieb: On Mon, Jan 23, 2006 at 08:31:40AM +0100, Maik Holtkamp wrote: Hi, yesterday morning I found a strange entry in my apache log files (debian sarge, apache 1.3, mambo 4.5.3, kernel 2.4.31). It's a dyndns homelan

Re: Security implications of allowing init to re-exec from another path

2006-01-23 Thread Thomas Hood
For the record, we didn't add this feature. The person who requested it found that he could bind-mount a different executable over /sbin/init instead. -- Thomas Hood -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Simple symmetric NAT Setup using IPTABLES

2006-01-23 Thread Asif
Hello every one. I am having problem in setting up symmetric NAT using IPTABLES Actually I am working on SIP application. SIP has the problem on NATes networks. STUN is one of the solutions. I have embedded STUN client functionality inside SIP application. Now i have to test the application.

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Jose Marrero
Just a couple of things: Apache configured with mod_rewrite to deny blank or fake referers is a good idea. Do you have apache configured with mod_security? I highly recommend this last one since you run an php based CMS and can protect from exploits not yet discovered. On Mon, January 23,

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Christoph Ulrich Scholler
Hi, On 23.01. 07:46, Jose Marrero wrote: Apache configured with mod_rewrite to deny blank or fake referers is a good idea. How can you tell that a referrer is fake? Regards, uLI -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Strange Apache log and mambo security - sexy executable

2006-01-23 Thread Jose Marrero
Life is only probabilities...isn't it? A quick link for an overview: http://en.wikipedia.org/wiki/Referer_spam There are blacklists elsewhere, some updated every 15 minutes. On Mon, January 23, 2006 8:58 am, Christoph Ulrich Scholler said: Hi, On 23.01. 07:46, Jose Marrero wrote: Apache

Security scanner

2006-01-23 Thread Jaroslaw Tabor
Hi all! Has anyone know a network scanner I can run on Debian to search LAN for unprotected windows shares ? Or maybe something looking for simple passwords ? I'd like to automate discovering stupid users, leaving full access to their C:\. -- Jaroslaw Tabor [EMAIL PROTECTED] -- To

Re: Security scanner

2006-01-23 Thread Danny De Cock
On Tue, 24 Jan 2006, Jaroslaw Tabor wrote: Hi all! Has anyone know a network scanner I can run on Debian to search you can use the debian package gnomba to easily browse through all the windows shares that are available on your local network... very straightforward to use! kind

Re: Security scanner

2006-01-23 Thread Daniel Givens
On 1/23/06, Jaroslaw Tabor [EMAIL PROTECTED] wrote: Hi all! Has anyone know a network scanner I can run on Debian to search LAN for unprotected windows shares ? Look into Nessus. (http://www.nessus.org/) Or maybe something looking for simple passwords ? Look into John the Ripper