Re: rm files owned by root?

2004-12-29 Thread Richard Atterer
or a process possessing the CAP_LINUX_IMMUTABLE capability can set or clear this attribute. Is something similar also available for other filing systems? Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7

Re: [OT] Is calculating an MD5 hash of a Rjindael encrypted block and it's key insecure?

2004-08-12 Thread Richard Atterer
-paranoia hat on, the solution is not ideal. This is important because $s and $c get stored in the cookie. Why $s? Surely you'll only store $c in the cookie, otherwise there's no point in encrypting the data. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key

Re: [OT] Is calculating an MD5 hash of a Rjindael encrypted block and it's key insecure?

2004-08-12 Thread Richard Atterer
On Thu, Aug 12, 2004 at 01:56:53PM +0200, Marcel Weber wrote: Richard Atterer wrote: This strikes me as a weird solution. What's wrong with setting the cookie lifetime higher, so that people only need to log in e.g. once a day? Hmm, presumably the web application is closed-source or un

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-16 Thread Richard Atterer
You could also try installing snoopy, which logs all commands executed by users to auth.log. Then look for unusual commands executed by user www-data if you suspect insecure PHP scripts etc. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http

Re: Advice needed, trying to find the vulnerable code on Debian webserver.

2004-06-16 Thread Richard Atterer
You could also try installing snoopy, which logs all commands executed by users to auth.log. Then look for unusual commands executed by user www-data if you suspect insecure PHP scripts etc. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http

Re: Spam fights

2004-06-10 Thread Richard Atterer
in the From field. If I confirm, the person sending me the confirmation message will be delivered the spam. If more people did this, confirmation senders would notice that the system doesn't work. Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net

Re: Spam fights

2004-06-10 Thread Richard Atterer
in the From field. If I confirm, the person sending me the confirmation message will be delivered the spam. If more people did this, confirmation senders would notice that the system doesn't work. Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net

Re: Non-existent user able to log in??? hacked????

2004-05-18 Thread Richard Atterer
, and compare the md5sums. It doesn't look like the attacker did anything once he was logged in (maybe he was just scanning the net for open FTP servers), but if any doubt remains, reinstall from scratch. Maybe also consider using a different ftpd... Cheers, Richard -- __ _ |_) /| Richard

Re: Secure temporary fifo creation

2004-05-18 Thread Richard Atterer
the GNOME guidelines mentioned there, and just create your fifo instead of doing the open(). Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Non-existent user able to log in??? hacked????

2004-05-18 Thread Richard Atterer
, and compare the md5sums. It doesn't look like the attacker did anything once he was logged in (maybe he was just scanning the net for open FTP servers), but if any doubt remains, reinstall from scratch. Maybe also consider using a different ftpd... Cheers, Richard -- __ _ |_) /| Richard

Re: i want to hide return path...

2004-05-04 Thread Richard Atterer
can specify any sender address you like. HTH, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: i want to hide return path...

2004-05-04 Thread Richard Atterer
can specify any sender address you like. HTH, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: name based virtual host and apache-ssl

2004-03-24 Thread Richard Atterer
... but do today's browsers support it? Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: name based virtual host and apache-ssl

2004-03-24 Thread Richard Atterer
... but do today's browsers support it? Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: mozilla - the forgotten package?

2004-03-10 Thread Richard Atterer
-- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: mozilla - the forgotten package?

2004-03-10 Thread Richard Atterer
-- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Big VPN

2004-03-03 Thread Richard Atterer
, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Big VPN

2004-03-03 Thread Richard Atterer
of the 100 LANs would just route all 10.0.0.0/16 addresses to the central node, and only the central node would be trusted, so you don't have to mess with CAs etc... Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7

Re: Big VPN

2004-03-03 Thread Richard Atterer
, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Big VPN

2004-03-03 Thread Richard Atterer
of the 100 LANs would just route all 10.0.0.0/16 addresses to the central node, and only the central node would be trusted, so you don't have to mess with CAs etc... Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Big VPN

2004-03-02 Thread Richard Atterer
-- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Big VPN

2004-03-02 Thread Richard Atterer
-- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Tripwire (clone) which would you prefer?

2004-02-23 Thread Richard Atterer
Also see this page for a useful comparison between AIDE and tripwire: http://www.fbunet.de/aide.shtml Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject

Re: Tripwire (clone) which would you prefer?

2004-02-23 Thread Richard Atterer
Also see this page for a useful comparison between AIDE and tripwire: http://www.fbunet.de/aide.shtml Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Help! File permissions keep changing...

2004-02-18 Thread Richard Atterer
dir). Set up a default umask which allows global read access and *let* users defeat it! If they know how to change their umask to something more restrictive, they're bound to know what they're doing! Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http

Re: arpwatch and arp packets ...urgent

2004-02-18 Thread Richard Atterer
LAN is configured to the address 1.2.3.4. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯ -- To UNSUBSCRIBE, email to [EMAIL PROTECTED] with a subject of unsubscribe. Trouble? Contact [EMAIL PROTECTED]

Re: Help! File permissions keep changing...

2004-02-18 Thread Richard Atterer
dir). Set up a default umask which allows global read access and *let* users defeat it! If they know how to change their umask to something more restrictive, they're bound to know what they're doing! Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http

Re: arpwatch and arp packets ...urgent

2004-02-18 Thread Richard Atterer
LAN is configured to the address 1.2.3.4. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net | 0x888354F7 ¯ '` ¯

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Richard Atterer
On Tue, Feb 03, 2004 at 05:38:40AM +0100, Philipp Schulte wrote: No, with REJECT they would show up as closed. DROP produces filtered. FWIW, you also need --reject-with tcp-reset to fool nmap. Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net

Re: Hacked - is it my turn? - interesting

2004-02-03 Thread Richard Atterer
On Tue, Feb 03, 2004 at 05:38:40AM +0100, Philipp Schulte wrote: No, with REJECT they would show up as closed. DROP produces filtered. FWIW, you also need --reject-with tcp-reset to fool nmap. Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http://atterer.net

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Richard Atterer
solution. Maybe have a look at sslwrap+redir, or stunnel, which can run on any machine in your DMZ and forward incoming connections to the internal machine, adding SSL encryption to make it more secure. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http

Re: Need recomendations for https proxy that serves as a firewall proxy

2003-12-31 Thread Richard Atterer
solution. Maybe have a look at sslwrap+redir, or stunnel, which can run on any machine in your DMZ and forward incoming connections to the internal machine, adding SSL encryption to make it more secure. Cheers, Richard -- __ _ |_) /| Richard Atterer | GnuPG key: | \/¯| http