Re: About user monitoring

2002-04-17 Thread martin f krafft
also sprach Halil Demirezen [EMAIL PROTECTED] [2002.04.16.1911 +0200]: I am planning to write code that will load the users terminal screens to my screen. And root will surely manage that. Is there anyone to tell me any link which contains information about this subject.

Re: Apache htaccess

2002-04-22 Thread martin f krafft
also sprach Nik Engel [EMAIL PROTECTED] [2002.04.22.1204 +0200]: Meaning to say, htaccess ist only working from outside. But when i want to reache the apache sever from the inside network i don need to authenticate ? Order Allow,Deny Allow from 10.0.0.0/8 AuthName realm name AuthType Basic

Re: Apache htaccess

2002-04-22 Thread martin f krafft
also sprach Nik Engel [EMAIL PROTECTED] [2002.04.22.1236 +0200]: That is clear, but i want to have an .htpasswd auth from outside anf from inside noauth for the same host: meaning : .htpassws for any/0 ! 192.168.0.0/8 is this suitable ? did you try my suggestion? it does what you want...

Re: A more secure form of .htaccess?

2002-04-26 Thread martin f krafft
also sprach eim [EMAIL PROTECTED] [2002.04.26.1757 +0200]: With https data will be encripted and it's impossible to find out login and password because they're not sent over the net in a clear way. never say impossible. -- martin; (greetings from the heart of the sun.) \

Re: A more secure form of .htaccess?

2002-04-26 Thread martin f krafft
also sprach Dan Faerch [EMAIL PROTECTED] [2002.04.26.1955 +0200]: Second more, if your users are allowed to have pages on the same address as the login system, the browser can, without much effort, be tricked into giving away your systems username and password to a personal user page... how?

Re: IPtables and Connection Tracking

2002-04-27 Thread martin f krafft
also sprach vdongen [EMAIL PROTECTED] [2002.04.27.1812 +0200]: Does the connection tracking hold the connections even if the firewall was flushed? If it is so, is it a bug or a feature? did you by chance forget to flush all tables and just flushed by doing iptables -F ??? i have

Re: A more secure form of .htaccess?

2002-04-27 Thread martin f krafft
also sprach Dan Faerch [EMAIL PROTECTED] [2002.04.27.2120 +0200]: you know their algorithm against MAC table overflow? No i dont.. I would be very interrested in reading about it, if you know of a link.. Im sure that it would be possible to enforce some level of security.. it's quite simple.

Re: Fixing file system privileges

2002-05-10 Thread martin f krafft
also sprach Peter Cordes [EMAIL PROTECTED] [2002.05.10.2333 +0200]: Err, I guess you would need get-selections|grep 'install$'|cut -f1 why not dpkg --get-selections|grep -v 'deinstall$'|cut -f1 you want to save status, and since 'install$' matches lines ending in 'deinstall' as well ;^ --

Re: Fixing file system privileges

2002-05-11 Thread martin f krafft
also sprach Peter Cordes [EMAIL PROTECTED] [2002.05.11.0155 +0200]: nope, purge is a possible status too. since when? fishbowl:~ dpkg --get-selections | grep purge fishbowl:~ -- martin; (greetings from the heart of the sun.) \ echo mailto: !#^.*|tr * mailto:; [EMAIL

Re: Fixing file system privileges

2002-05-11 Thread martin f krafft
also sprach David Stanaway [EMAIL PROTECTED] [2002.05.11.0904 +0200]: Since the last time you hit _ in dselect maybe. [EMAIL PROTECTED]:~$ dpkg --get-selections |grep purge aptitude purge [EMAIL PROTECTED]:~$ sudo dpkg --purge aptitude (Reading database

shellutils: uuencode bug (still!!!)

2002-06-09 Thread martin f krafft
Package: shellutils Version: 2.0.11-11 Severity: grave Justification: user security hole Tags: security http://www.aerasec.de/security/index.html?lang=enid=ae-200205-037 this is still not patched and over a month old... redhat is the only distro that patched this. let debian be the second. --

Re: poppassd

2002-06-23 Thread martin f krafft
word? thanks, Martin F. Krafft mailto:[EMAIL PROTECTED] AERAsec Network Services and Security GmbH -- mailto:[EMAIL PROTECTED] | Wagenberger Strasse 1 http://www.aerasec.de/ | 85662 Hohenbrunn (DE) t: +49.(0)8102.89519-0 | f: +49.(0)8102.89519-9 pgp3dvXnjcOpw.pgp Description: PGP signature

Re: DSA-134-1

2002-06-25 Thread martin f krafft
also sprach Ralf Dreibrodt [EMAIL PROTECTED] [2002.06.25.1510 +0200]: i unterstand it as remote chrooted nobody exploit, this is much more better than a remote root-exploit. better in what way? -- martin; (greetings from the heart of the sun.) \ echo mailto: !#^.*|tr *

Re: Your Confirmation Required

2002-07-18 Thread martin f krafft
could you ***PLEASE STOP*** replying to the originating address of such messages or spam??? -- martin; (greetings from the heart of the sun.) \ echo mailto: !#^.*|tr * mailto:; [EMAIL PROTECTED] seminars, n.: from semi and arse, hence, any half-assed discussion.

Re: Spam handling (Re: Your Confirmation Required)

2002-07-18 Thread martin f krafft
also sprach Tim Haynes [EMAIL PROTECTED] [2002.07.18.1241 +0200]: 3. I've added a procmail rule here locally so that all mails From: .*italy.*minute get automatically reported to Razor2. Could you please stop that, this is ridiculous. -- martin; (greetings from the heart of

Re: You've Been Added!

2002-07-18 Thread martin f krafft
also sprach Alexander Thoma [EMAIL PROTECTED] [2002.07.18.1240 +0200]: italyminutes.it - *plonk* Who the f**k is readding the list to this sh*t ?!?!?!? Who the f**k is replying and confirming our email address??? Yes, I know that italyminutes.it long has our confirmed email, but it's a NEVER

Re: Spam handling (Re: Your Confirmation Required)

2002-07-18 Thread martin f krafft
also sprach Tim Haynes [EMAIL PROTECTED] [2002.07.18.1301 +0200]: 3. I've added a procmail rule here locally so that all mails From: .*italy.*minute get automatically reported to Razor2. Could you please stop that, this is ridiculous. No. The rule in question matches exactly every

Re: Support for Potato

2002-07-24 Thread martin f krafft
also sprach Wichert Akkerman [EMAIL PROTECTED] [2002.07.25.0057 +0200]: Currently we're thinking of at least 3 months full support and somewhat longer for remote exploits. We haven't made any decisions yet though. How much work (in man hours per day) do you reckon Potato's maintenance to be,

Re: port 6051: hacked?

2002-09-07 Thread martin f krafft
also sprach Phillip Hofmeister [EMAIL PROTECTED] [2002.09.07.2008 +0200]: If they create a file in a directory watched by tripwire (fools) they will change the inode (date) on that directory and tripwire will flag it. Granted they could make a file in /tmp (which most sane people with tripwire

Re: port 6051: hacked?

2002-09-08 Thread martin f krafft
also sprach Giacomo Mulas [EMAIL PROTECTED] [2002.09.08.0746 +0200]: try putting any binary, as a test, in /tmp, e.g. copy /bin/ls to /tmp/testexe. Then issue the command /lib/ld-linux.so.2 /tmp/testexe to see how (little) useful the noexe option is... i feel dizzy. thanks for letting me

Re: icmp: type-#69 (catched that bastard)

2002-09-15 Thread martin f krafft
also sprach Tim Haynes [EMAIL PROTECTED] [2002.09.15.1812 +0200]: I can't name one, but that doesn't say an awful lot. Googling for `ICMP type 69' doesn't lead to any obvious results, either. :( sorry to spurt into the thread randomly. using any packet generation tool, i don't think it's quite

Re: port 6051: hacked?

2002-09-17 Thread martin f krafft
also sprach Michelle Konzack [EMAIL PROTECTED] [2002.09.14.1334 +0200]: It may be a very big security problem... at least i can't reproduce that on a grsecurity 1.9.6 enabled kernel. -- martin; (greetings from the heart of the sun.) \ echo mailto: !#^.*|tr * mailto:; [EMAIL

Re: Business Proposal (Urgent)

2002-09-24 Thread martin f krafft
also sprach Mark Janssen [EMAIL PROTECTED] [2002.09.24.0914 +0200]: I suggest you first read: http://home.rica.net/alphae/419coal/ Which clearly describes the working of this scam... Just ignore it, or send it on to the relevant government agency... I don't think that Brad was very serious.

IBM and wrong DSA

2002-10-04 Thread martin f krafft
[joey, CCing you to make sure you see this immediately. you probably read debian-security too, i'd assume...] Check out http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2002.765.1 DSA 169 is htcheck, not tomcat, right? At least that's the case on www.debian.org. What's

Re: IBM and wrong DSA

2002-10-04 Thread martin f krafft
also sprach martin f krafft [EMAIL PROTECTED] [2002.10.04.1810 +0200]: Check out http://www-1.ibm.com/services/continuity/recover1.nsf/MSS/MSS-OAR-E01-2002.765.1 DSA 169 is htcheck, not tomcat, right? At least that's the case on www.debian.org. Sorry, this has already been addressed

Re: harden-clients idea

2002-10-08 Thread martin f krafft
also sprach Kjetil Kjernsmo [EMAIL PROTECTED] [2002.10.08.1247 +0200]: The problem with e.g. telnet isn't really that it shouldn't be used for anything, but that it shouldn't be used by somebody. It is quite OK to use to check what the webserver responds to a particular request, for

Re: harden-clients idea

2002-10-08 Thread martin f krafft
also sprach Peter Cordes [EMAIL PROTECTED] [2002.10.08.2008 +0200]: It uses the telnet protocol, not just a raw TCP connection, so netcat is inadequate. netcat can negotiate telnet connections with the -t option. unless you are using very ancient terminal types, netcat is a complete substitute

Re: Dear friends, never miss the chance to travel in China, the beautiful and mysterious place to be!

2002-10-21 Thread martin f krafft
else. -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than to fix a system pgp4P88nb59YP.pgp Description: PGP signature

security updates for testing?

2002-11-21 Thread martin f krafft
? -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system pgpPf4OjKN9x1.pgp Description: PGP signature

Re: security updates for testing?

2002-11-22 Thread martin f krafft
count on it for security. give me an estimate (someone) on how much manpower is required to provide this service for testing? -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing

Re: port 113

2002-12-03 Thread martin f krafft
to certain FTP or IRC servers. -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system NOTE: The public PGP keyservers are broken! Get my key here: http://people.debian.org

Re: VPN + Roadwarrior

2002-12-12 Thread martin f krafft
.''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system NOTE: The public PGP keyservers are broken! Get my key here: http://people.debian.org/~madduck/gpg/330c4a75.asc pgpM0P1CQqIOc.pgp

Re: VPN + Roadwarrior

2002-12-12 Thread martin f krafft
.''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system NOTE: The public PGP keyservers are broken! Get my key here: http://people.debian.org/~madduck/gpg/330c4a75.asc pgptCGIO76yZq.pgp

Re: securing pop3

2003-02-10 Thread martin f krafft
! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system NOTE: The pgp.net keyservers and their mirrors are broken! Get my key here: http://people.debian.org/~madduck/gpg/330c4a75.asc

Re: securing pop3

2003-02-10 Thread martin f krafft
also sprach Mike Dresser [EMAIL PROTECTED] [2003.02.10.2226 +0100]: That lets you in just fine unfortunately. so put /bin/true for the shell. -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin

Re: securing pop3

2003-02-10 Thread martin f krafft
-ssl and postfix-tls for the SSL functionality. -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system NOTE

Re: Peace is not off topic

2003-03-10 Thread martin f krafft
-security is not the place. -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system NOTE: The pgp.net keyservers

STOP THE FUXXING PEACE TALKS!

2003-03-11 Thread martin f krafft
BLOODY HELL, TAKE THIS SHIT OFF HERE. I AM GETTING ANNOYED BY USELESS DISCUSSION OF THIS SORT ON *DEBIAN*-SECURITY. GO ELSEWHERE! -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user

expiring passwords

2003-03-15 Thread martin f krafft
notification script that parses /ec/shadow? Thanks, -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system Keyserver

Re: Traffic monitoring

2003-03-16 Thread martin f krafft
accounting device. -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system Keyserver problems? http

Re: Security patches

2003-12-18 Thread martin f krafft
precautions take care to prevent that. -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, and user `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP

Re: Security patches

2004-01-03 Thread martin f krafft
with SE Linux? I always wondered about LSM... they are stacking modules, right? So this would have to come before or after SELinux, at which point one can take control from the other, no? -- Please do not CC me when replying to lists; I read them! .''`. martin f. krafft [EMAIL PROTECTED

Where is the security announcement?

2005-07-06 Thread martin f krafft
more. We've already given the professional world enough of a reason to abandon ship and laugh at us. PS: the random quote generator seems to be able to establish semantic context at last! -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :not-so-proud Debian developer and author: http

Re: Where is the security announcement?

2005-07-07 Thread martin f krafft
also sprach Robin Schroeder [EMAIL PROTECTED] [2005.07.07.1133 +0200]: I got at least security announcements from debian-security-announce@lists.debian.org Not between 3 June and 30 June. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL

Re: Sudo question

2005-07-08 Thread martin f krafft
the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP subkeys? Use subkeys.pgp.net as keyserver! how do you feel about women's

Re: Debian Security Support in Place

2005-07-09 Thread martin f krafft
to pay 1-2 people taking care of sarge after May 2006. And if that is unacceptable to you: Ubuntu has announced a 5 year support plan for server systems: http://www.ubuntulinux.org/UbuntuFoundation -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft

Re: Debian Security Support in Place

2005-07-10 Thread martin f krafft
for testing afterwards. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer, admin, user, and author `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP subkeys? Use

Please announce current lack of security support

2005-07-26 Thread martin f krafft
announcement ASAP to alert our users of the current lack of security support? -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP subkeys

Re: Please announce current lack of security support

2005-07-27 Thread martin f krafft
mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net as keyserver

Re: Bad press again...

2005-08-26 Thread martin f krafft
and communicative security team. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system

Re: Bad press again...

2005-08-26 Thread martin f krafft
! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net as keyserver! der beruf ist eine schutzwehr, hinter welche man sich

Re: Bad press again...

2005-08-26 Thread martin f krafft
a DNS A record. It's a whole lot easier to point that elsewhere in case of problems than expecting users to make sense of the errors they get when some servers can't be reached. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED

Re: Bad press again...

2005-08-26 Thread martin f krafft
also sprach martin f krafft [EMAIL PROTECTED] [2005.08.26.1907 +0200]: security.debian.org is not a server, it's a DNS A record. It's a whole lot easier to point that elsewhere in case of problems than expecting users to make sense of the errors they get when some servers can't be reached. Ah

Re: Bad press again...

2005-08-27 Thread martin f krafft
have any new stuff. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid

Re: Bad press again...

2005-08-27 Thread martin f krafft
! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net as keyserver! we all know linux is great... it does

Re: Bad press again...

2005-08-27 Thread martin f krafft
, it's essentially more of a clog than a bottleneck. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than

Re: Bad press again...

2005-08-27 Thread martin f krafft
. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys

Re: Bad press again...

2005-08-27 Thread martin f krafft
. He's never replied to mails or pings from me about this stuff. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things

Re: Bad press again...

2005-08-27 Thread martin f krafft
that don't know better? -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid

Re: Bad press again...

2005-08-27 Thread martin f krafft
security infrastructure went down for a while and we found out about it from a German news magazine. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info

Re: Bad press again...

2005-08-27 Thread martin f krafft
asset and a keystone in the future of Debian security. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than

Re: Bad press again...

2005-08-28 Thread martin f krafft
the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net as keyserver! he gave me his card he

Re: Bad press again...

2005-08-28 Thread martin f krafft
files and expects others to do the same. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing

Re: Bad press again...

2005-08-29 Thread martin f krafft
is a delegation. Looks more like tbm actually wanted to write a different message and forgot to change the subject afterwards. :) -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http

anonftpsync (was: security archive defective!?)

2005-09-01 Thread martin f krafft
also sprach Andreas Barth [EMAIL PROTECTED] [2005.09.01.0858 +0200]: I strongly recommend to use anonftpsync for mirroring any of the debian archives What's the advantage over debmirror? -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL

Re: Security implications of allowing init to re-exec from another path

2006-01-04 Thread martin f krafft
to kernel modules and other Linux maladities. That is, if the attacker gets root... -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you

Re: Security implications of allowing init to re-exec from another path

2006-01-04 Thread martin f krafft
copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net

Re: getting to www servers from inside where they have an Internal IP

2006-01-29 Thread martin f krafft
that I know. I suggest using a second nameserver to resolve the A record to the internal IP. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian

tartini (one of the security mirrors) unreliable

2006-02-16 Thread martin f krafft
no other problems. Maybe the administrators would be so kind as to investigate the issue and send an update when it's resolved? -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http

Re: first A record of security.debian.org extremely slow

2006-02-21 Thread martin f krafft
. Cheers, -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub

Re: first A record of security.debian.org extremely slow

2006-02-21 Thread martin f krafft
A record available instead? (I can't think of a simple way of doing that off the top of my head, though) It also bears the risk of hardcoding and forgetting, or missing an update. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED

Re: first A record of security.debian.org extremely slow

2006-02-27 Thread martin f krafft
domain where sometimes it's very important to have updates without any delays. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have

Re: db.debian.org certificate

2006-02-28 Thread martin f krafft
also sprach Noèl Köthe [EMAIL PROTECTED] [2006.02.28.2224 +0100]: the https db.debian.org certificate is expired on 2006-01-30. #354747 -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author

Re: first A record of security.debian.org extremely slow

2006-03-01 Thread martin f krafft
really matter. So far, Debian security updates predated widespread (semi-)automated exploits by weeks. Why then do you think security.d.o is not mirrored by Debian? -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud

Re: first A record of security.debian.org extremely slow

2006-03-02 Thread martin f krafft
! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net as keyserver! doesn't he know who i think i am

Re: first A record of security.debian.org extremely slow

2006-03-02 Thread martin f krafft
the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use subkeys.pgp.net as keyserver! if one cannot enjoy reading

Re: first A record of security.debian.org extremely slow

2006-03-08 Thread martin f krafft
not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use

Re: howto block ssh brute-force

2006-03-12 Thread martin f krafft
not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use

Re: howto block ssh brute-force

2006-03-12 Thread martin f krafft
with the iptables module. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid

Re: howto block ssh brute-force

2006-03-12 Thread martin f krafft
not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use

umn.edu security.d.o host unreachable

2006-03-13 Thread martin f krafft
, -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys? Use

Re: umn.edu security.d.o host unreachable

2006-03-13 Thread martin f krafft
is not reachable. Good to see you're on top of the issue. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do

fail2ban [was: howto block ssh brute-force]

2006-03-13 Thread martin f krafft
? -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system Invalid/expired PGP (sub)keys

masking out invalid root logins with logcheck?

2006-05-07 Thread martin f krafft
, which is what fail2ban takes care of anyway... Cheers, -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do

Re: masking out invalid root logins with logcheck?

2006-05-07 Thread martin f krafft
, since password logins are not possible anyway. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing

Re: masking out invalid root logins with logcheck?

2006-05-07 Thread martin f krafft
feedback. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system obviously i was either onto

Re: masking out invalid root logins with logcheck?

2006-05-07 Thread martin f krafft
. Sure, those get logged anyway, as cracking attempts, because our policy is never to log in as root. However, we leave without-password in there and keep a separate root DSA key, just in case. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL

Re: masking out invalid root logins with logcheck?

2006-05-07 Thread martin f krafft
not want to go down this path; instead, I prefer to enforce a strong password policy. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when

Re: masking out invalid root logins with logcheck?

2006-05-08 Thread martin f krafft
are right. To be on the safe side, I added a comment to sshd_config. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better

Re: How to prevent daemons from ever being started?

2006-05-15 Thread martin f krafft
are already in place. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system wer

Re: Command history log for audit trail

2006-06-15 Thread martin f krafft
to create a log for all commands run on a system? apt-cache show acct? Though it really lacks a lot of information. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http

BADSIG verifying s.d.o Release file

2006-06-30 Thread martin f krafft
(2006) [EMAIL PROTECTED] Cheers, -- .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system if a man treats life artistically, his brain is his heart

Re: BADSIG verifying s.d.o Release file

2006-06-30 Thread martin f krafft
? -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http://debiansystem.info `. `'` `- Debian - when you have better things to do than fixing a system lessing was a heretics' heretic

Re: BADSIG verifying s.d.o Release file

2006-06-30 Thread martin f krafft
that hadn't been spotted since we've only just started releasing advisories with it.) Ok. Thanks for your time and the explanation, Steve. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' :proud Debian developer and author: http

Re: BADSIG verifying s.d.o Release file

2006-06-30 Thread martin f krafft
be that the Release.gpg file has a size of zero? If so, I've already informed ftpmasters. If not, what's the other cause? I don't know. My file was *not* zero, it was really a BADSIG. Now it seems fixed though. -- Please do not send copies of list mail to me; I read the list! .''`. martin f

Re: su - and su - what is the real difference?

2006-07-28 Thread martin f krafft
also sprach LeVA [EMAIL PROTECTED] [2006.07.28.1533 +0100]: So running su with the '-' option is safer then running without it? In that it bears less surprises, yes. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED

Re: help: duplicate MAC address

2006-10-18 Thread martin f krafft
de:ad:be:ef:ba:be -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' : proud Debian developer, author, administrator, and user `. `'` http://people.debian.org/~madduck - http://debiansystem.info `- Debian - when you have better things

Re: help: duplicate MAC address

2006-10-18 Thread martin f krafft
mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' : proud Debian developer, author, administrator, and user `. `'` http://people.debian.org/~madduck - http://debiansystem.info `- Debian - when you have better things to do than fixing systems NP: Porcupine Tree

Re: DD machine mysterious reboot

2006-10-29 Thread martin f krafft
incredibly crap it is. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL PROTECTED] : :' : proud Debian developer, author, administrator, and user `. `'` http://people.debian.org/~madduck - http://debiansystem.info `- Debian - when you have better

Re: kernel.panic (was: Re: DD machine mysterious reboot)

2006-10-29 Thread martin f krafft
will loop on a panic; if non-zero it indicates that the kernel should autoreboot after this number of seconds. When you use the software watchdog device driver, the recommended setting is 60. -- Please do not send copies of list mail to me; I read the list! .''`. martin f. krafft [EMAIL

<    1   2   3   4   5   >