Re: Several security issues seeking help

2004-07-08 Thread Jean-Francois Dive
] http://bugs.debian.org/257973 -- Jeroen van Wolffelaar [EMAIL PROTECTED] (also for Jabber MSN; ICQ: 33944357) http://Jeroen.A-Eskwadraat.nl -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- -- - Jean-Francois Dive

Re: IPSec tunnels with isakmpd

2004-06-16 Thread Jean-Francois Dive
. __ Yahoo! lanza su nueva tecnolog?a de b?squedas ?te atreves a comparar? http://busquedas.yahoo.es -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] I think

Re: IPSec tunnels with isakmpd

2004-06-16 Thread Jean-Francois Dive
. __ Yahoo! lanza su nueva tecnolog?a de b?squedas ?te atreves a comparar? http://busquedas.yahoo.es -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] I think

Re: IPSec WinXP interop

2004-01-05 Thread Jean-Francois Dive
/ FAQ - http://www.debian.org/doc/FAQ/ Install manual (i386) - http://www.debian.org/releases/stable/i386/install -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] I think

Re: Is there a FAM(file alteration monitor) exploit in the wild?

2003-12-08 Thread Jean-Francois Dive
file. The local-only security options do not work when called from inetd. How are you supposed to protect this program? Firewall? I turned it off for now:( joe -- -- - Jean-Francois Dive -- [EMAIL PROTECTED] I think that God in creating Man somewhat overestimated his ability

Re: Is there a FAM(file alteration monitor) exploit in the wild?

2003-12-08 Thread Jean-Francois Dive
file. The local-only security options do not work when called from inetd. How are you supposed to protect this program? Firewall? I turned it off for now:( joe -- -- - Jean-Francois Dive -- [EMAIL PROTECTED] I think that God in creating Man somewhat overestimated his ability

Re: H323 Gateways

2003-04-02 Thread Jean-Francois Dive
/ ideas? -- Daniel -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - Marquis de LaPlace - deterministic Principles -

Re: [Q] How to keep Debian system secure: automation?

2003-03-06 Thread Jean-Francois Dive
if you build your own packages *from debian sources*, just get the appropriate source tree. This apply for the kernel as well. JeF On Tue, 2003-03-04 at 14:10, Kynn Jones wrote: apt-get update/upgrade is good enough for me as a way to keep up with security updates at the binary

Re: Firewall Informer

2003-02-23 Thread Jean-Francois Dive
Hi, I'm glad to see this is not a standard form of spamming as your answered comments on the list. However, this list is not the proper place to post commercial advertisement about security product not supported under linux and particulary Debian GNU Linux. Thanks, JeF On Mon, 2003-02-24 at

Re: Firewall Informer

2003-02-23 Thread Jean-Francois Dive
Hi, I'm glad to see this is not a standard form of spamming as your answered comments on the list. However, this list is not the proper place to post commercial advertisement about security product not supported under linux and particulary Debian GNU Linux. Thanks, JeF On Mon, 2003-02-24 at

Re: raw disk access

2003-01-16 Thread Jean-Francois Dive
On Mon, 2003-01-13 at 03:19, Jean-Francois Dive wrote: already answered but dd | nc (to send it to another box) is a classical. Otherwise, some other tools can give you as well memory dumps which may sometimes be very usefull. JeF On Tue, Jan 07, 2003 at 10:08:22PM -0500, viv

Re: raw disk access

2003-01-16 Thread Jean-Francois Dive
On Mon, 2003-01-13 at 03:19, Jean-Francois Dive wrote: already answered but dd | nc (to send it to another box) is a classical. Otherwise, some other tools can give you as well memory dumps which may sometimes be very usefull. JeF On Tue, Jan 07, 2003 at 10:08:22PM -0500, viv

Re: raw disk access

2003-01-12 Thread Jean-Francois Dive
reference material (raw drive access and how to work with the images created). If it helps, i am running with the latest 'unstable' packages. Many thanks. -- viv [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness

Re: raw disk access

2003-01-12 Thread Jean-Francois Dive
reference material (raw drive access and how to work with the images created). If it helps, i am running with the latest 'unstable' packages. Many thanks. -- viv [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness

Re: Dedicated Firewall + snmpd smux 199/tcp

2002-12-15 Thread Jean-Francois Dive
. -- Gerard -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic Universe_, Michael Talbot

Re: a nessus developpers joke?

2002-10-15 Thread Jean-Francois Dive
FranceOnLine -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic

Re: a nessus developpers joke?

2002-10-15 Thread Jean-Francois Dive
FranceOnLine -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic

Re: harden-clients idea

2002-10-08 Thread Jean-Francois Dive
-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic Universe_, Michael Talbot -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: harden-clients idea

2002-10-08 Thread Jean-Francois Dive
-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic Universe_, Michael Talbot

Re: FreeS/WAN and kernel 2.4.20-pre7

2002-09-23 Thread Jean-Francois Dive
). Anyone else having this problem, or should I report this as a bug? -- rob e [EMAIL PROTECTED] pgp 0x8bb5c71e -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive

Re: FreeS/WAN and kernel 2.4.20-pre7

2002-09-23 Thread Jean-Francois Dive
). Anyone else having this problem, or should I report this as a bug? -- rob e [EMAIL PROTECTED] pgp 0x8bb5c71e -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive

Postgres buffer overflow in stable .

2002-09-10 Thread Jean-Francois Dive
-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic Universe_, Michael Talbot

Re: port 6051: hacked?

2002-09-08 Thread Jean-Francois Dive
ramps in terms of centimeters of rise per foot of run. a compromise, i imagine... -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic Universe_, Michael Talbot pgpeUtprmGHOV.pgp Description: PGP

Re: port 6051: hacked?

2002-09-06 Thread Jean-Francois Dive
, Ramin Nikolay Hristov -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] There is no such thing as randomness. Only order of infinite complexity. - _The Holographic

Re: port 6051: hacked?

2002-09-06 Thread Jean-Francois Dive
quite shure that there was no breakin, but will follow the suggestion by Jean-Francois Dive an let a sniffer run... you really almost *never* can be 100% sure. The latest root kit are running in the kernel, dont need to change any command as they hide information at the system call level. Some

linux random capabilities ...

2002-07-31 Thread Jean-Francois Dive
mechanims are. Finally, i read here and there some work on hardware random generation devices (based on radio activity readings, or diods based devices or whatever), is there anyone with some experience with those ? thanks, cheers, JeF -- - Jean-Francois Dive -- [EMAIL PROTECTED]

Re: PPTP with Encryption

2002-05-01 Thread Jean-Francois Dive
[EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: PPTP with Encryption

2002-05-01 Thread Jean-Francois Dive
[EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: logging iptables

2002-04-21 Thread Jean-Francois Dive
are forever - Albert Einstein -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED

SPSL implementation ..

2002-04-02 Thread Jean-Francois Dive
that have been defined by SSH people to define security policies in IPSec / IKE context, and is defined now in a (expired) draft. thanks, Cheers, JeF -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

SPSL implementation ..

2002-04-02 Thread Jean-Francois Dive
that have been defined by SSH people to define security policies in IPSec / IKE context, and is defined now in a (expired) draft. thanks, Cheers, JeF -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Re: [SECURITY] [DSA 122-1] New zlib other packages fix buffer overflow

2002-03-12 Thread Jean-Francois Dive
] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [SECURITY] [DSA 122-1] New zlib other packages fix buffer overflow

2002-03-12 Thread Jean-Francois Dive
] -- - Jean-Francois Dive -- [EMAIL PROTECTED]

PPTP and encryption / RC4 weaknesses

2002-03-04 Thread Jean-Francois Dive
that the problem in WEP is the key extrapolation which is the problem, but i'd like to know if RC4 in PPTP can be considered as secure, purely on encryption side. Thanks for any pointer on this.( except the 'read the applied cryptography book ;) JeF -- - Jean-Francois Dive -- [EMAIL PROTECTED

Re: PPTP and encryption / RC4 weaknesses

2002-03-04 Thread Jean-Francois Dive
On Mon, Mar 04, 2002 at 03:20:44PM +0100, Christoph Moench-Tegeder wrote: thanks, this confirm me that i really have to avoid it ;) cheers, JeF ## Jean-Francois Dive ([EMAIL PROTECTED]): I was wondering: PPTP use RC4 up to 128 bit keys as an encryption mechanism. I'd like to have

Re: hosts.{allow,deny} vs iptables.

2002-03-04 Thread Jean-Francois Dive
/ iD8DBQE8grxhFsfyfWvjfZARAlNpAJ9R9limzM711W+n0HU+r91/QGtToACgxi0X JSPo/zUMHGqKp4Vdk/zp8Go= =doh1 -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED]

PPTP and encryption / RC4 weaknesses

2002-03-04 Thread Jean-Francois Dive
that the problem in WEP is the key extrapolation which is the problem, but i'd like to know if RC4 in PPTP can be considered as secure, purely on encryption side. Thanks for any pointer on this.( except the 'read the applied cryptography book ;) JeF -- - Jean-Francois Dive -- [EMAIL PROTECTED]

Re: PPTP and encryption / RC4 weaknesses

2002-03-04 Thread Jean-Francois Dive
On Mon, Mar 04, 2002 at 03:20:44PM +0100, Christoph Moench-Tegeder wrote: thanks, this confirm me that i really have to avoid it ;) cheers, JeF ## Jean-Francois Dive ([EMAIL PROTECTED]): I was wondering: PPTP use RC4 up to 128 bit keys as an encryption mechanism. I'd like to have

Re: hosts.{allow,deny} vs iptables.

2002-03-03 Thread Jean-Francois Dive
/ iD8DBQE8grxhFsfyfWvjfZARAlNpAJ9R9limzM711W+n0HU+r91/QGtToACgxi0X JSPo/zUMHGqKp4Vdk/zp8Go= =doh1 -END PGP SIGNATURE- -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL

Re: Security implications of chpasswd.

2002-02-28 Thread Jean-Francois Dive
? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED]

Re: PPPoverEthernet vs. PPPoverATM

2002-02-25 Thread Jean-Francois Dive
be considered as quite secure (if you don't define a default internal server in the NAT parameters). http://www.sateh.com (if I remember well) -Original Message- From: Jean-Francois Dive [SMTP:[EMAIL PROTECTED]] Sent: Thursday, February 21, 2002 2:17 PM

Re: port-forward ssh

2002-02-25 Thread Jean-Francois Dive
-- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: PPPoverEthernet vs. PPPoverATM

2002-02-25 Thread Jean-Francois Dive
be considered as quite secure (if you don't define a default internal server in the NAT parameters). http://www.sateh.com (if I remember well) -Original Message- From: Jean-Francois Dive [SMTP:[EMAIL PROTECTED] Sent: Thursday, February 21, 2002 2:17 PM

Re: port-forward ssh

2002-02-25 Thread Jean-Francois Dive
-- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED]

Re: PPPoverEthernet vs. PPPoverATM

2002-02-21 Thread Jean-Francois Dive
] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED] -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: PPPoverEthernet vs. PPPoverATM

2002-02-21 Thread Jean-Francois Dive
PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED] -- - Jean-Francois Dive -- [EMAIL PROTECTED]