Re: Debian Security Support in Place

2005-07-08 Thread Phillip Hofmeister
favorite distro, and I hope this isn't seen as a flame. But, two Debian releases in one year? That's kind of funny grins. -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: safety of encrypted filesystems

2005-06-23 Thread Phillip Hofmeister
one file and this was unaltered, the question is why. Perhaps the block that was changed was a free block? -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: safety of encrypted filesystems

2005-06-22 Thread Phillip Hofmeister
. This should identify *WHICH* file changed. -- Phillip Hofmeister pgpFA0uNAsSYs.pgp Description: PGP signature

Re: Crypto File System-Problems Creating One

2005-06-08 Thread Phillip Hofmeister
: Invalid argument You're trying to mount a block device over a loopback? This may present a problemI'm not sure. -- Phillip Hofmeister pgpDHAZsI8iop.pgp Description: PGP signature

Re: [sec] Re: failed root login attempts

2004-09-29 Thread Phillip Hofmeister
have weak root passwords are not ones to follow best practices. -- Phillip Hofmeister pgped9HHVcQPF.pgp Description: PGP signature

Re: telnetd vulnerability from BUGTRAQ

2004-09-28 Thread Phillip Hofmeister
with a machine that uses EBCDIC. If you specify ASCII file mode, the EBCDIC machine is responsible for doing the EBCDIC to ASCII conversation. If you just ask for Binary you'll get garbage when you open the file because it is in EBCDIC! (I have this experience from an IBM MVS Environment). -- Phillip

Re: telnetd vulnerability from BUGTRAQ

2004-09-28 Thread Phillip Hofmeister
is every bit as easy to eaves drop as FTP. There are many tools that will easily attempt a man-in-the-middle SSH attack. -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Rebuilding packages on *all* architectures

2004-09-07 Thread Phillip Hofmeister
even after he has delivered the bomb. -- Phillip Hofmeister pgpvqSkqSutVT.pgp Description: PGP signature

Re: MD5 collisions found - alternative?

2004-08-25 Thread Phillip Hofmeister
the result together). For example: EVEN IF hash1(x) == hash1(y), it is HIGHLY unlikely hash2(x) == hash2(y). Keeping a record of both hashes on hand provides value and strengthens your certainty of integrity on very large orders of magnitude. -- Phillip Hofmeister pgpLWjIwGrvEX.pgp Description: PGP

Re: MD5 collisions found - alternative?

2004-08-24 Thread Phillip Hofmeister
with algorithm X and the cipher text is intercepted by the attacker. The attacker can make his chances of brute forcing the text BETTER by encrypting my cipher text with algorithm Y. This simply does not hold up. -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: newbie iptables question

2004-08-13 Thread Phillip Hofmeister
this. It is for this reason I run my own IPTABLES script and edit it by hand (pretty masochistichuh?). My guess is this packet was related to an automated attack (worm). Hope this helps, -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact

Re: pgp in Debian: obsolete?

2004-08-12 Thread Phillip Hofmeister
On Thu, 12 Aug 2004 at 03:35:29AM -0400, Matthias Urlichs wrote: Hi, Phillip Hofmeister wrote: If you wanted to make a second version of GPG and place it in non-free, that would likely be an acceptable option. You don't need to make a second version of GPG; the IDEA module can

Re: pgp in Debian: obsolete?

2004-08-11 Thread Phillip Hofmeister
in any modified form is expressly prohibited. Which is a clear violation of the social contract. If you wanted to make a second version of GPG and place it in non-free, that would likely be an acceptable option. -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: mod_ssl 2.8.19 for Apache 1.3.31

2004-07-19 Thread Phillip Hofmeister
contrib HTH -- Phillip Hofmeister -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: A question about : [Fwd: JULY 6th Lead Training 3 tips for working leads]

2004-07-08 Thread Phillip Hofmeister
... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: A question about : [Fwd: JULY 6th Lead Training 3 tips for working leads]

2004-07-07 Thread Phillip Hofmeister
by posting their original message back to the list. HTH, -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Re: Why not push to stable?

2004-06-26 Thread Phillip Hofmeister
) because they like the wide range of control it offers them. If you take away some of that control then it diminishes the reason why some ppl prefer Debian. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
to the normal SMTP Server for the zionlth.org domain. Implementing your suggestion wide spread would cause my emails (and all emails from people in my situation) to be rejected just because their ISP has their head on backwards and thinks blocking port 25 outbound will reduce spam abuse. -- Phillip

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Unusual spam recently - hummm - postprocess

2004-06-03 Thread Phillip Hofmeister
of it over the years. Sorry to hear about your sysadmin shortage, then. -- Cheers, Rick MoenBu^so^stopu min per kulero. [EMAIL PROTECTED] -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
people's spam to train your filters G. Warning: Just throwing a bunch of spam at your filters w/o giving it any ham will likely result in falsely high bogosity scores (false-rejects) since there is no ham tokens to reduce the score. HTH, - -- Phillip Hofmeister PGP/GPG Key: http

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
to the normal SMTP Server for the zionlth.org domain. Implementing your suggestion wide spread would cause my emails (and all emails from people in my situation) to be rejected just because their ISP has their head on backwards and thinks blocking port 25 outbound will reduce spam abuse. -- Phillip

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
-Bogosity: Yes Mail/Junk :0: * ^X-Bogosity: Unsure Mail/Unsure Hope this helps! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) Comment: Key

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Unusual spam recently - hummm - postprocess

2004-06-03 Thread Phillip Hofmeister
of it over the years. Sorry to hear about your sysadmin shortage, then. -- Cheers, Rick MoenBu^so^stopu min per kulero. [EMAIL PROTECTED] -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei

Re: Unusual spam recently - hummm

2004-06-03 Thread Phillip Hofmeister
people's spam to train your filters G. Warning: Just throwing a bunch of spam at your filters w/o giving it any ham will likely result in falsely high bogosity scores (false-rejects) since there is no ham tokens to reduce the score. HTH, - -- Phillip Hofmeister PGP/GPG Key: http

Re: grsecurity2 and per-user tmp dirs

2004-05-22 Thread Phillip Hofmeister
with the name of a tmp file they are predicting you will open and then you write all your information to THEIR FIFO. I hope this helps. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: grsecurity2 and per-user tmp dirs

2004-05-22 Thread Phillip Hofmeister
with the name of a tmp file they are predicting you will open and then you write all your information to THEIR FIFO. I hope this helps. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: debian and viruses ...

2004-05-19 Thread Phillip Hofmeister
: bogofilter spamassassin Virus: amavisd-new and clamav (or your favorite supported antivirus software, clam just happens to be O/S and free...) HTH, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN

Re: debian and viruses ...

2004-05-19 Thread Phillip Hofmeister
: bogofilter spamassassin Virus: amavisd-new and clamav (or your favorite supported antivirus software, clam just happens to be O/S and free...) HTH, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN

Re: Woody Backport of tripwire

2004-04-23 Thread Phillip Hofmeister
dependencies did not specify that. I might file a bug against tripwire for that build dependency. Thanks. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Woody Backport of tripwire

2004-04-23 Thread Phillip Hofmeister
On Fri, 23 Apr 2004 at 01:19:13PM -0400, Giacomo Mulas wrote: On Fri, 23 Apr 2004, Phillip Hofmeister wrote: I did not realize 3.0+ was needed. The build dependencies did not specify that. I might file a bug against tripwire for that build dependency. it is meant for sid, the default

Re: Major TCP Vulnerability

2004-04-22 Thread Phillip Hofmeister
scripts? Probably not. Yet another great reason to apply the GRSecurity Kernel patch, randomized source ports. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG

Woody Backport of tripwire

2004-04-22 Thread Phillip Hofmeister
Can anyone refer me to a woody backport of tripwire (or a version such as 2.3.1.2+)? I know it is non-free, I like it anyhow. Any help would be appreciated. Thanks, -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg

Re: Major TCP Vulnerability

2004-04-22 Thread Phillip Hofmeister
scripts? Probably not. Yet another great reason to apply the GRSecurity Kernel patch, randomized source ports. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG

Woody Backport of tripwire

2004-04-22 Thread Phillip Hofmeister
Can anyone refer me to a woody backport of tripwire (or a version such as 2.3.1.2+)? I know it is non-free, I like it anyhow. Any help would be appreciated. Thanks, -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import - End forwarded message - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
will get you across the untrusted Internet though (unless someone pulls the plug at OSI layer 1 or 2...) Hope this answers your question. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import - End forwarded message - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Major TCP Vulnerability

2004-04-20 Thread Phillip Hofmeister
will get you across the untrusted Internet though (unless someone pulls the plug at OSI layer 1 or 2...) Hope this answers your question. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Phillip Hofmeister
, and developer | |`- http://www.debian.org | - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: makedev: /dev/tty([0-9])* should not have 666 permissions

2004-04-19 Thread Phillip Hofmeister
- -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFAhEP5S3Jybf3L5MQRAtfuAJ40TFzSQFCNN0UmbyQtM2QM0mSrUACgjmY2 ssBFqnnpuHMCHOf3qbaKiU4

Re: Eterm others allow arbitrary commands execution via escape sequencies [Was: CAN-2003-0020?]

2004-04-19 Thread Phillip Hofmeister
, and developer | |`- http://www.debian.org | - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: makedev: /dev/tty([0-9])* should not have 666 permissions

2004-04-19 Thread Phillip Hofmeister
/Group - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFAhEP5S3Jybf3L5MQRAtfuAJ40TFzSQFCNN0UmbyQtM2QM0mSrUACgjmY2

Re: suid

2004-04-17 Thread Phillip Hofmeister
works well... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
suggestions. If you contribute please be sure to CC the Bug report. At question here is where should this bug be directed? The kernel pseudo package or glibc (linuxthreads). Credits: Thanks to Matt Zimmerman and Herbert Xu for contributing already. Thanks, - -- Phillip Hofmeister PGP/GPG Key: http

Re: Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
of daemon crashes), because when it is not possible to allocatre a struct sigqueue object, kernel behaviour in signal-passing changes, causing random hangs and segfaults in different programs. /Bugtraq Post -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http

Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
suggestions. If you contribute please be sure to CC the Bug report. At question here is where should this bug be directed? The kernel pseudo package or glibc (linuxthreads). Credits: Thanks to Matt Zimmerman and Herbert Xu for contributing already. Thanks, - -- Phillip Hofmeister PGP/GPG Key: http

Re: Bug #243954: DoS on Linux kernel 2.4 and 2.6 using sigqueue overflow

2004-04-16 Thread Phillip Hofmeister
- in form of daemon crashes), because when it is not possible to allocatre a struct sigqueue object, kernel behaviour in signal-passing changes, causing random hangs and segfaults in different programs. /Bugtraq Post -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http

Re: [SECURITY] [DSA 479-1] New Linux 2.4.18 packages fix local root exploit (source+alpha+i386+powerpc)

2004-04-14 Thread Phillip Hofmeister
to know, which of them might have been fixed earlier. It's just my interest to track the linux-sec-efforts from my point of view. Keep smiling yanosz -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Does apt check gpg signatures before install

2004-03-29 Thread Phillip Hofmeister
On Mon, 29 Mar 2004 at 01:39:00PM -0500, Florian Weimer wrote: apt 0.6 (available in experimental) checks the signatures on the Release files. Is there a backport of this apt to stable? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org

Re: Does apt check gpg signatures before install

2004-03-29 Thread Phillip Hofmeister
On Mon, 29 Mar 2004 at 01:39:00PM -0500, Florian Weimer wrote: apt 0.6 (available in experimental) checks the signatures on the Release files. Is there a backport of this apt to stable? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org

Re: kernel 2.4.22 patch

2004-03-19 Thread Phillip Hofmeister
pgp0.pgp Description: PGP message

Re: kernel 2.4.22 patch

2004-03-19 Thread Phillip Hofmeister
pgpXhKEcgiYVU.pgp Description: PGP message

Re: mozilla - the forgotten package?

2004-03-11 Thread Phillip Hofmeister
the current on in place for compatibility sakes. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: mozilla - the forgotten package?

2004-03-11 Thread Phillip Hofmeister
the current on in place for compatibility sakes. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
saying what run, not what files were opened). Good luck! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
to the SYSLOG Kern Facility syslog(3). - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFALoIAS3Jybf3L5MQRAqHEAJ9ZmPEGrMPU9OWSKIi2LDJ/qjnzHQCgg2D8

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
saying what run, not what files were opened). Good luck! - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux

Re: How to tell what process accessed a file

2004-02-14 Thread Phillip Hofmeister
to the SYSLOG Kern Facility syslog(3). - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.4 (GNU/Linux) iD8DBQFALoIAS3Jybf3L5MQRAqHEAJ9ZmPEGrMPU9OWSKIi2LDJ/qjnzHQCgg2D8

Re: Which Distro?

2004-02-06 Thread Phillip Hofmeister
the entire nuts bolts usefuls of Debian. nybody here to help me? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL

Re: Which Distro?

2004-02-06 Thread Phillip Hofmeister
the entire nuts bolts usefuls of Debian. nybody here to help me? -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
tcp --dport 113 -j REJECT --reject-with tcp-reset -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
subnet and they can send an ARP request for the IP and your machine responds. The statement above assumes the attacker/researcher is not on your subnet. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
as 63.165.219.29. Take care, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQFAIDPyS3Jybf3L5MQRAns7AJ9sAkTwrpyUyXpVq80KaBE4jNK21QCgktRB

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
tcp --dport 113 -j REJECT --reject-with tcp-reset -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
subnet and they can send an ARP request for the IP and your machine responds. The statement above assumes the attacker/researcher is not on your subnet. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Phillip Hofmeister
as 63.165.219.29. Take care, - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux) iD8DBQFAIDPyS3Jybf3L5MQRAns7AJ9sAkTwrpyUyXpVq80KaBE4jNK21QCgktRB

Re: Web based password changer

2004-01-23 Thread Phillip Hofmeister
. It hides processes not belonging to you (unless you are root). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- Excuse #194: Too much radiation coming from the soil. pgp0.pgp Description: PGP

Re: Web based password changer

2004-01-23 Thread Phillip Hofmeister
. It hides processes not belonging to you (unless you are root). -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- Excuse #194: Too much radiation coming from the soil. pgpIGx3K0Bgik.pgp Description: PGP

Re: suspicious smbd connections

2003-12-23 Thread Phillip Hofmeister
are these connections? Is somebody trying to scan me or what is the reason for these messages? Thank you in advance! -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- Excuse #138: Popper unable

Re: suspicious smbd connections

2003-12-23 Thread Phillip Hofmeister
are these connections? Is somebody trying to scan me or what is the reason for these messages? Thank you in advance! -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.asc | gpg --import -- Excuse #138: Popper unable

Re: exim virus scanning and spam scanning

2003-12-21 Thread Phillip Hofmeister
10,000 definitions. However, you can use commercial av's (like Sophis) with amavis if you wish. Last I checked several months ago Sophis has over 80,000 definitions. Hope this helps. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei

Re: secure file permissions

2003-12-08 Thread Phillip Hofmeister
this would make things any better on your system. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #148: endothermal recalibration -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux

Re: secure file permissions

2003-12-08 Thread Phillip Hofmeister
this would make things any better on your system. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #148: endothermal recalibration -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.3 (GNU/Linux

Re: When will kernel-image-2.4.23 be available ?

2003-12-03 Thread Phillip Hofmeister
always, the path for security upgrades to enter testing. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #198: Interference from lunar radiation -- To UNSUBSCRIBE, email to [EMAIL PROTECTED

Re: When will kernel-image-2.4.23 be available ?

2003-12-03 Thread Phillip Hofmeister
always, the path for security upgrades to enter testing. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #198: Interference from lunar radiation

Re: apache+ssl+tomcat+jk+php

2003-11-12 Thread Phillip Hofmeister
??? (it works without tomcat , anyway) ! Can anybody help ? regards - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #194: Too much radiation coming from the soil. -BEGIN PGP

Re: apache+ssl+tomcat+jk+php

2003-11-12 Thread Phillip Hofmeister
??? (it works without tomcat , anyway) ! Can anybody help ? regards - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #194: Too much radiation coming from the soil. -BEGIN PGP

Re: apache security issue (with upstream new release)

2003-11-01 Thread Phillip Hofmeister
of technicality...but... If you are really looking for assurance than 'rm -rf /' would not affect your day because weekly full backups and nightly incremental should be made. If you don't have valid off system, perhaps off-site backups, then what kind of assurance do you really have? - -- Phillip

Re: passwd character limitations

2003-11-01 Thread Phillip Hofmeister
. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #21: Improperly oriented keyboard -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE/pFWlS3Jybf3L5MQRAoWXAJ4k74yGA22dvG5EOnF

Re: apache security issue (with upstream new release)

2003-11-01 Thread Phillip Hofmeister
of technicality...but... If you are really looking for assurance than 'rm -rf /' would not affect your day because weekly full backups and nightly incremental should be made. If you don't have valid off system, perhaps off-site backups, then what kind of assurance do you really have? - -- Phillip

Re: passwd character limitations

2003-11-01 Thread Phillip Hofmeister
. - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #21: Improperly oriented keyboard -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE/pFWlS3Jybf3L5MQRAoWXAJ4k74yGA22dvG5EOnF

Re: apache security issue (with upstream new release)

2003-10-30 Thread Phillip Hofmeister
it... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #227: You must've hit the wrong anykey. -BEGIN PGP SIGNATURE- Version: GnuPG v1.2.2 (GNU/Linux) iD8DBQE

Apache: Apears to be vulnerable to CAN-2003-0542 (WAS: apache security issue (with upstream new release))

2003-10-29 Thread Phillip Hofmeister
don't want to post it to BTS... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #113: Daemons loose in system. -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble

Re: chkrootkit reporting processes hidden

2003-10-29 Thread Phillip Hofmeister
problem with your machine. AFA the PROMISC mode one the NICs...are you running snort or something to the like? If so, these NIDs (Network Intrusion Detectors) place cards in PROMISC mode to watch traffic. Just a few things to be aware of... -- Phillip Hofmeister PGP/GPG Key: http

Apache: Apears to be vulnerable to CAN-2003-0542 (WAS: apache security issue (with upstream new release))

2003-10-29 Thread Phillip Hofmeister
don't want to post it to BTS... -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #113: Daemons loose in system.

Re: chkrootkit reporting processes hidden

2003-10-29 Thread Phillip Hofmeister
problem with your machine. AFA the PROMISC mode one the NICs...are you running snort or something to the like? If so, these NIDs (Network Intrusion Detectors) place cards in PROMISC mode to watch traffic. Just a few things to be aware of... -- Phillip Hofmeister PGP/GPG Key: http

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
/mounts (Oh, it's ro!) and then types mount -o remount/rw /usr Just my $.02... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #34: Heavy gravity fluctuation move computer to floor rapidly

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
On Thu, 09 Oct 2003 at 01:58:40PM -0400, Brandon High wrote: On Thu, Oct 09, 2003 at 08:06:46AM -0400, Phillip Hofmeister wrote: If I r00t your system I'll have access to remount it rw anyhow. Any hacker who doesn't know how to remount a file system is really lame. You may slow someone

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
/mounts (Oh, it's ro!) and then types mount -o remount/rw /usr Just my $.02... - -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import - -- Excuse #34: Heavy gravity fluctuation move computer to floor rapidly

Re: How efficient is mounting /usr ro?

2003-10-09 Thread Phillip Hofmeister
On Thu, 09 Oct 2003 at 01:58:40PM -0400, Brandon High wrote: On Thu, Oct 09, 2003 at 08:06:46AM -0400, Phillip Hofmeister wrote: If I r00t your system I'll have access to remount it rw anyhow. Any hacker who doesn't know how to remount a file system is really lame. You may slow someone

Re: services installed and running out of the box

2003-09-29 Thread Phillip Hofmeister
are doing)) to be a bare minimum for best-practices. Unfortunately (unlike RedHat and Mandrake) Debian offers no firewall as part of the default installation. My advise, have a good generic firewall shell script and use it and place it in /etc/rc(S|2).d/ of every system you install. - -- Phillip

Re: services installed and running out of the box

2003-09-28 Thread Phillip Hofmeister
are doing)) to be a bare minimum for best-practices. Unfortunately (unlike RedHat and Mandrake) Debian offers no firewall as part of the default installation. My advise, have a good generic firewall shell script and use it and place it in /etc/rc(S|2).d/ of every system you install. - -- Phillip

Re: Will Bind9 in stable get patched?

2003-09-22 Thread Phillip Hofmeister
is available for woody from http://people.debian.org/~lamont/ . Is the unstable version patched? If so one could 'apt-get source --compile -t unstable bind9' Thanks -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import

Re: Watch out! vsftpd anonymous access always enabled!

2003-09-22 Thread Phillip Hofmeister
did they come to conclusion that creating shell accounts is the best way of giving access to few files? Rsync doesn't require a shell account. You can run an rsyncd. WebDAV is also a great tool. You can use the htpasswd to create a passwd file for apache. -- Phillip Hofmeister PGP/GPG Key

Re: Will Bind9 in stable get patched?

2003-09-22 Thread Phillip Hofmeister
is available for woody from http://people.debian.org/~lamont/ . Is the unstable version patched? If so one could 'apt-get source --compile -t unstable bind9' Thanks -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import

Re: Watch out! vsftpd anonymous access always enabled!

2003-09-22 Thread Phillip Hofmeister
did they come to conclusion that creating shell accounts is the best way of giving access to few files? Rsync doesn't require a shell account. You can run an rsyncd. WebDAV is also a great tool. You can use the htpasswd to create a passwd file for apache. -- Phillip Hofmeister PGP/GPG Key

Re: Strange segmentation faults and Zombies

2003-09-18 Thread Phillip Hofmeister
. This way he won't get access to the clean systems because the passwd for the clean system will not be given to the dirty one. -- Phillip Hofmeister PGP/GPG Key: http://www.zionlth.org/~plhofmei/ wget -O - http://www.zionlth.org/~plhofmei/key.txt | gpg --import -- Excuse #145: Short leg on process table

Re: Debian Stable server hacked

2003-08-22 Thread Phillip Hofmeister
. But there is no reason why a PaX-enabled kernel could not be provided as an option. All it needs is someone willing to do the work (hint, hint). I would be willing to maintain a grsec kernel image with PaX and temp. file symlink blocking if someone would be willing to sponsor it (hint, hint) - -- Phillip

  1   2   3   4   >