what is this postponed publickey for user in the logs?

2006-08-15 Thread LeVA
message, but I'm curious about what does it mean. Maybe this is just a lost in translation thing, and I'm not getting the right meaning of that word. I've translated the english postponed word in this context to delayed. Is this right? Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email

su - and su - what is the real difference?

2006-07-28 Thread LeVA
in the real world) between running `su` (getting a non-login shell) and `su -` (getting a login shell). Is there a security related problem with any of the invokings above? AFAIK the real and effective uids are always set to 0 after both commands. Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email

Re: su - and su - what is the real difference?

2006-07-28 Thread LeVA
2006. July 28. 16:04, Michael Marsh: On 7/28/06, LeVA [EMAIL PROTECTED] wrote: Here comes a lame question yes I know, but I need to hear the experiences and opinions about this. I've read thru a number of documents which described the differences between the real and effective user ids

Re: su - and su - what is the real difference?

2006-07-28 Thread LeVA
2006. July 28. 16:04, Michael Marsh: On 7/28/06, LeVA [EMAIL PROTECTED] wrote: Here comes a lame question yes I know, but I need to hear the experiences and opinions about this. I've read thru a number of documents which described the differences between the real and effective user ids

Re: su - and su - what is the real difference?

2006-07-28 Thread LeVA
2006. July 28. 17:03, Florent Rougon: LeVA [EMAIL PROTECTED] wrote: And can you tell me why the $USER and the $LOGNAME variables gets resetted by su, no matter if I've invoked it with or without the '-' option? Which suite are you testing this on? Here, on sarge, using su

editing new known_hosts files

2006-07-22 Thread LeVA
Hi! I have reinstalled a server of mine, and now I need to remove it's old pubkey from my $HOME/.ssh/known_hosts, but it is in the new format, so no hostnames which may indicate which pubkey belongs to which host. How can I decrypt the known_hosts file? Thanks! Daniel -- LeVA

can not connect to sshd

2006-05-23 Thread LeVA
connect to the machine. What could be the problem? Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Request for comments: iptables script for use on laptops.

2006-05-23 Thread LeVA
. No? If I set up my firewall to accept only my local network (eg. -s 192.168.0.0/255.255.255.0) connecting to a port (eg. smtp), then anyone can spoof that too. So what's the point of creating rules? :) Daniel -- LeVA

Re: Request for comments: iptables script for use on laptops.

2006-05-23 Thread LeVA
2006. május 23. 10:06, Rolf Kutz [EMAIL PROTECTED] - debian-security@lists.debian.org,: * Quoting LeVA ([EMAIL PROTECTED]): iptables -A INPUT -i lo -j ACCEPT iptables -A OUTPUT -o lo -j ACCEPT But if one can spoof 127.0.0.1, then one can spoof anything else, so creating any rule

tuning the samba log file

2005-07-28 Thread LeVA
? Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

getting the MAC address from an ip

2005-06-24 Thread LeVA
Hi! How can I get a machines mac address, if I only know it's ip? Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: which pop3/imap secure method should I use?

2005-06-14 Thread LeVA
2005. június 14. 07:57, Radu Spineanu [EMAIL PROTECTED] - debian-security@lists.debian.org,: Ian Eure wrote: On Monday 13 June 2005 04:41 pm, LeVA wrote: I don't see why it would be helpful, unless you're trying to keep your info secret from a determined/resourceful attacker

which pop3/imap secure method should I use?

2005-06-13 Thread LeVA
for authentication. My mail user agent supports all of the above, so I would really appreciate if someone could tell me which configuration is the most secure way. Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: which pop3/imap secure method should I use?

2005-06-13 Thread LeVA
2005. jnius 14. 01:36, Ian Eure [EMAIL PROTECTED] - debian-security@lists.debian.org,: On Monday 13 June 2005 04:23 pm, LeVA wrote: Hi! I've configured a courier-imap server with pop3(-ssl) and imap(-ssl) support. Now I can not decide which combination of methods is the most secure

secure ident daemon

2005-03-19 Thread LeVA
Hi! Can someone please suggest me a secure ident daemon. I can not choose from the apt searched list. Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

upgrading sendmail package when postfix installed

2004-10-11 Thread LeVA
the sendmail installation, so apt-get would see that sendmail has been upgraded, or do I have upgrade sendmail (for security reasons) and then re-install postfix all over again? Thanks! Daniel -- LeVA pgpGRZ6W2bkkj.pgp Description: PGP signature

vsftpd virtual user

2004-08-15 Thread LeVA
not figure out how to make those passwd files. Thanks! Daniel -- LeVA pgp9qlMQgD9i3.pgp Description: PGP signature

Re: logging samba access

2004-06-06 Thread LeVA
be very interested if someone knew solution to this that does not require modifying samba source and then maintaining your own packages... I think increasing the log level is quite enough for me. Thanks! Daniel -- LeVA pgpoeScU65KgD.pgp Description: signature

logging samba access

2004-06-06 Thread LeVA
Hi! Is it possible to log the file/dir accesses to samba server? I.e. I got a share, and when someone mounts (from win or unix) it and access file, or write files I want samba to log it to the smb.log. Is this possible? Thanks! Daniel -- LeVA pgp1uiUEsQUo6.pgp Description: signature

Re: logging samba access

2004-06-06 Thread LeVA
be very interested if someone knew solution to this that does not require modifying samba source and then maintaining your own packages... I think increasing the log level is quite enough for me. Thanks! Daniel -- LeVA pgpaK13c71bwY.pgp Description: signature

what process is using a port

2004-05-03 Thread LeVA
Hi! Is there a way to figure out what program is using a port. For example I want to know which process is using port 80. How can I do this? ps.: and another tiny question: Is it possible to see if a symlink is pointing at a given file? Thanks! Daniel -- LeVA pgp0.pgp Description

Re: what process is using a port

2004-05-03 Thread LeVA
Wow, thanks for all the answers. I really appreciate it! Daniel -- LeVA pgp0.pgp Description: signature

what process is using a port

2004-05-03 Thread LeVA
Hi! Is there a way to figure out what program is using a port. For example I want to know which process is using port 80. How can I do this? ps.: and another tiny question: Is it possible to see if a symlink is pointing at a given file? Thanks! Daniel -- LeVA pgpys9DERUZ4Q.pgp

Re: what process is using a port

2004-05-03 Thread LeVA
Wow, thanks for all the answers. I really appreciate it! Daniel -- LeVA pgpFpG8NgrnLc.pgp Description: signature

restricting process limit

2004-04-26 Thread LeVA
? Thanks a lot! Daniel -- LeVA

syslog.conf question

2004-04-18 Thread LeVA
, then it will log to the syslog and the /var/log/mail/ dir too. What did I do wrong? Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

syslog.conf question

2004-04-18 Thread LeVA
, then it will log to the syslog and the /var/log/mail/ dir too. What did I do wrong? Thanks! Daniel -- LeVA

can not kill a process

2004-04-13 Thread LeVA
! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

can not kill a process

2004-04-13 Thread LeVA
! Daniel -- LeVA

Re: passwords changed?

2004-04-11 Thread LeVA
2004. prilis 11. 06:21 dtummal Noah Meyerhans ezt rta: On Sat, Apr 10, 2004 at 09:19:00PM +0200, LeVA wrote: Only as ftp. But there have been a number of locally exploitable kernel vulnerabilities fairly recently, and an attacker could use one of these to obtain root access once they had

Re: passwords changed?

2004-04-11 Thread LeVA
2004. április 11. 06:21 dátummal Noah Meyerhans ezt írta: On Sat, Apr 10, 2004 at 09:19:00PM +0200, LeVA wrote: Only as ftp. But there have been a number of locally exploitable kernel vulnerabilities fairly recently, and an attacker could use one of these to obtain root access once they had

Re: passwords changed?

2004-04-10 Thread LeVA
proftpd runs as user 'ftp', than the one who uses this vulnerability could only run arbitrary code as user ftp, or as root? Thanks! Daniel -- LeVA

Re: passwords changed?

2004-04-10 Thread LeVA
proftpd runs as user 'ftp', than the one who uses this vulnerability could only run arbitrary code as user ftp, or as root? Thanks! Daniel -- LeVA

chrooted apache-ssl

2004-04-09 Thread LeVA
! Daniel -- LeVA

get ip from samba

2004-04-08 Thread LeVA
Hi! Is there a way to get a machine's ip address, if I only know it's netbios name? With 'smbtree -S' I see a machine with the name 'LEVA': $ smbtree -S Password: CMD \\LEVA LeVA - Samba Server (3.0.2a-Debian) But I want to know it's ip address. I don't know how

get ip from samba

2004-04-08 Thread LeVA
Hi! Is there a way to get a machine's ip address, if I only know it's netbios name? With 'smbtree -S' I see a machine with the name 'LEVA': $ smbtree -S Password: CMD \\LEVA LeVA - Samba Server (3.0.2a-Debian) But I want to know it's ip address. I don't know how

can't see anything with 'w'

2004-04-07 Thread LeVA
the attributes to 664 in all files, but still can not display the logged in users. Any ideas? Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: can't see anything with 'w'

2004-04-07 Thread LeVA
] Website: http://www.competitiveness.com Hi! Thanks! I had to swith the /var/run/utmp file to o=r. Now it works. Daniel -- LeVA

can't see anything with 'w'

2004-04-07 Thread LeVA
the attributes to 664 in all files, but still can not display the logged in users. Any ideas? Thanks! Daniel -- LeVA

Re: can't see anything with 'w'

2004-04-07 Thread LeVA
] Website: http://www.competitiveness.com Hi! Thanks! I had to swith the /var/run/utmp file to o=r. Now it works. Daniel -- LeVA

Re: [ [Dri-devel] XFree86 local root exploit]

2004-02-14 Thread LeVA
2004. februr 12. 19:45 dtummal Ryan Underwood ezt rta: Thanks a lot! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: [ [Dri-devel] XFree86 local root exploit]

2004-02-14 Thread LeVA
2004. február 12. 19:45 dátummal Ryan Underwood ezt írta: Thanks a lot! Daniel -- LeVA

blocking AXFR record query

2004-01-28 Thread LeVA
Hi! Anyone could tell me how could I deny the AXFR record query on my bind server? I'm looking for some global variable, not specifiing per-address. Thanks! Daniel -- LeVA

cvs newpg compile error

2004-01-08 Thread LeVA
, libassuan and dirmngr sources before that newpg. What could be the problem with it? Thanks! Daniel -- LeVA

Re: GnuPG can not read some pgp signatures

2004-01-07 Thread LeVA
Wednesday 07 January 2004 08:34 dátummal Adrian 'Dagurashibanipal' von Bidder ezt írta: Clinging to sanity, LeVA mumbled in his beard: Reason: No appropriate crypto plug-in was found. Hi, I guess that your problem is NOT idea, but inline gpg signed msgs (like this one) versus PGP/MIME

GnuPG can not read some pgp signatures

2004-01-06 Thread LeVA
be the problem with the other signature files? If it helps, I can send you a signature, which is not working. Thanks for the help! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: GnuPG can not read some pgp signatures

2004-01-06 Thread LeVA
://www.rawip.org | eMail Style Guide: http://www.rawip.org/style.html| -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: GnuPG can not read some pgp signatures

2004-01-06 Thread LeVA
2004. január 06. 19:17 dátummal J.H.M. Dassen (Ray) ezt írta: On Tue, Jan 06, 2004 at 19:06:50 +0100, LeVA wrote: But there are not any gpg-idea packages anywhere. IDEA is patent encumbered in much of Europe, including The Netherlands where non-us.debian.org is hosted and apparently Germany

GnuPG can not read some pgp signatures

2004-01-06 Thread LeVA
be the problem with the other signature files? If it helps, I can send you a signature, which is not working. Thanks for the help! Daniel -- LeVA

Re: GnuPG can not read some pgp signatures

2004-01-06 Thread LeVA
2004. január 06. 19:17 dátummal J.H.M. Dassen (Ray) ezt írta: On Tue, Jan 06, 2004 at 19:06:50 +0100, LeVA wrote: But there are not any gpg-idea packages anywhere. IDEA is patent encumbered in much of Europe, including The Netherlands where non-us.debian.org is hosted and apparently Germany

Re: GnuPG can not read some pgp signatures

2004-01-06 Thread LeVA
://www.rawip.org | eMail Style Guide: http://www.rawip.org/style.html| -- LeVA

creating password for a shadow file

2003-12-01 Thread LeVA
with a command line tool? Is this htpasswd the right tool for this, and I just can not use it? Or if this is not possible, then how can I specify another destination shadow/passwd file for the adduser/useradd program. Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED

creating password for a shadow file

2003-12-01 Thread LeVA
file with a command line tool? Is this htpasswd the right tool for this, and I just can not use it? Or if this is not possible, then how can I specify another destination shadow/passwd file for the adduser/useradd program. Thanks! Daniel -- LeVA

kind of virtual server

2003-11-09 Thread LeVA
to read a different shadow/passwd file right after the connection (not after chrooting to /users/). Thanks! Daniel -- LeVA -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

kind of virtual server

2003-11-09 Thread LeVA
to read a different shadow/passwd file right after the connection (not after chrooting to /users/). Thanks! Daniel -- LeVA

sendmail + mailscanner

2003-04-14 Thread LeVA
Hello! I know this is not specially a security topic, but I need to do this for My security :)) I'm using sendmail, and I want to use mailscanner and spamassassin with it. I don't know how to configure sendmail to work with mailscanner. The mailscanner's howtos are very outdated, and in the

Re: [despammed] ptrace

2003-03-23 Thread LeVA
Hello! Thanks, that was the problem. The patch works fine. Ed McMan wrote: Saturday, March 22, 2003, 8:26:44 PM, [EMAIL PROTECTED] (debian-security) wrote: LeVA So it droped me a root shell. Well it is not good I think, after the LeVA patch... People have been saying that one of the exploits

Re: [despammed] ptrace

2003-03-23 Thread LeVA
Hello! Thanks, that was the problem. The patch works fine. Ed McMan wrote: Saturday, March 22, 2003, 8:26:44 PM, debian-security@lists.debian.org (debian-security) wrote: LeVA So it droped me a root shell. Well it is not good I think, after the LeVA patch... People have been saying

Re: PTRACE Fixed?

2003-03-22 Thread LeVA
Hello! Is the 2.4.20 kernel vulnerable to this exploit? Phillip Hofmeister wrote: All, I just patched my kernel with the patch available on kernel.org. I downloaded, compiled and ran the km3.c exploit for this bug. How can I tell if the exploit failed or not? When I run the exploit as

ptrace

2003-03-22 Thread LeVA
Hello! I have patched my kernel (2.4.20) with this patch: http://www.kernel.org/pub/linux/kernel/v2.4/testing/cset/cset-1.1076.txt It compile correctly. Now I have downloaded the km3.c and isec-ptrace-kmod-exploit.c The km3.c doesn't write the OK! stuff, and it could run forever starting child

Re: PTRACE Fixed?

2003-03-22 Thread LeVA
Hello! Is the 2.4.20 kernel vulnerable to this exploit? Phillip Hofmeister wrote: All, I just patched my kernel with the patch available on kernel.org. I downloaded, compiled and ran the km3.c exploit for this bug. How can I tell if the exploit failed or not? When I run the exploit as

ptrace

2003-03-22 Thread LeVA
Hello! I have patched my kernel (2.4.20) with this patch: http://www.kernel.org/pub/linux/kernel/v2.4/testing/cset/cset-1.1076.txt It compile correctly. Now I have downloaded the km3.c and isec-ptrace-kmod-exploit.c The km3.c doesn't write the OK! stuff, and it could run forever starting