You can subscribe to this list here.
| 2001 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
(55) |
Oct
(44) |
Nov
(156) |
Dec
(123) |
|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2002 |
Jan
(130) |
Feb
(156) |
Mar
(162) |
Apr
(171) |
May
(97) |
Jun
(127) |
Jul
(58) |
Aug
(81) |
Sep
(86) |
Oct
(45) |
Nov
(41) |
Dec
(84) |
| 2003 |
Jan
(71) |
Feb
(87) |
Mar
(133) |
Apr
(152) |
May
(151) |
Jun
(232) |
Jul
(320) |
Aug
(237) |
Sep
(271) |
Oct
(536) |
Nov
(301) |
Dec
(393) |
| 2004 |
Jan
(393) |
Feb
(184) |
Mar
(314) |
Apr
(225) |
May
(139) |
Jun
(77) |
Jul
(87) |
Aug
(75) |
Sep
(139) |
Oct
(50) |
Nov
(8) |
Dec
(28) |
| 2005 |
Jan
(66) |
Feb
(63) |
Mar
(14) |
Apr
(14) |
May
(8) |
Jun
(23) |
Jul
(21) |
Aug
(6) |
Sep
(29) |
Oct
(55) |
Nov
(38) |
Dec
(8) |
| 2006 |
Jan
(5) |
Feb
(10) |
Mar
(1) |
Apr
(15) |
May
(32) |
Jun
(44) |
Jul
(11) |
Aug
(8) |
Sep
(9) |
Oct
(14) |
Nov
(4) |
Dec
(3) |
| 2007 |
Jan
(3) |
Feb
(3) |
Mar
(2) |
Apr
|
May
|
Jun
|
Jul
(35) |
Aug
(49) |
Sep
(8) |
Oct
(42) |
Nov
(44) |
Dec
(7) |
| 2008 |
Jan
(2) |
Feb
(7) |
Mar
(8) |
Apr
(80) |
May
(74) |
Jun
(29) |
Jul
(5) |
Aug
(7) |
Sep
(6) |
Oct
(1) |
Nov
|
Dec
|
| 2009 |
Jan
(8) |
Feb
(19) |
Mar
(3) |
Apr
(24) |
May
(22) |
Jun
(23) |
Jul
(8) |
Aug
(23) |
Sep
(8) |
Oct
(27) |
Nov
(52) |
Dec
(27) |
| 2010 |
Jan
(36) |
Feb
(29) |
Mar
(17) |
Apr
(28) |
May
(21) |
Jun
(4) |
Jul
|
Aug
(28) |
Sep
(18) |
Oct
(6) |
Nov
(34) |
Dec
(16) |
| 2011 |
Jan
(18) |
Feb
(12) |
Mar
|
Apr
|
May
(9) |
Jun
(1) |
Jul
(5) |
Aug
(5) |
Sep
(7) |
Oct
(16) |
Nov
(26) |
Dec
(17) |
| 2012 |
Jan
(6) |
Feb
(34) |
Mar
(52) |
Apr
(10) |
May
(3) |
Jun
|
Jul
|
Aug
(1) |
Sep
|
Oct
(4) |
Nov
(1) |
Dec
(4) |
| 2013 |
Jan
(5) |
Feb
|
Mar
|
Apr
(5) |
May
(4) |
Jun
|
Jul
|
Aug
(14) |
Sep
|
Oct
|
Nov
|
Dec
|
| 2014 |
Jan
|
Feb
(2) |
Mar
(5) |
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
(3) |
Dec
(11) |
| 2015 |
Jan
(5) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
(1) |
Sep
(1) |
Oct
(1) |
Nov
|
Dec
|
| 2016 |
Jan
|
Feb
|
Mar
|
Apr
|
May
|
Jun
(2) |
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2017 |
Jan
(1) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
| 2018 |
Jan
(2) |
Feb
|
Mar
|
Apr
|
May
|
Jun
|
Jul
|
Aug
|
Sep
|
Oct
|
Nov
|
Dec
|
|
From: <no...@so...> - 2002-08-06 23:34:41
|
Bugs item #591802, was opened at 2002-08-06 18:34 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=591802&group_id=34096 Category: Configuration / Scripts Group: v0.6 Status: Open Resolution: None Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: better firewall start script Initial Comment: Hi all, I'm not a programmer. Attached are the script that might improve the current firewall startup script, I think. Fell free to enhance it or comment on it. Jet Chan jc...@tr... ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=591802&group_id=34096 |
|
From: <no...@so...> - 2002-08-06 17:53:45
|
Feature Requests item #588077, was opened at 2002-07-29 10:04 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=588077&group_id=34096 >Category: Packages >Group: v0.6 Status: Open Priority: 5 Submitted By: Nobody/Anonymous (nobody) Assigned to: Nobody/Anonymous (nobody) >Summary: pop3vscan Initial Comment: Hi, I just found http://pop3vscan.sourceforge.net. It's a transparent virus scanning proxy for POP3 mail attachments. They are de-MIMEed and send to an external file virus scanner of your choice. I'd love to see it in Devil Linux. AFIK it's the only way to battle mail viruses if your POP3 mailbox and mail server is outside of your DL firewalled net and only POP3 clients are inside. Some features (exerpt from their web site): No client configuration necessary: Because POP3VScan is a full transparent proxy nothing but the scanning-server has to be configured. Fast scanning: POP3VScan supports the Kaspersky Anti-Virus Daemon (kavd) and the Trophie Daemon (which uses the Trend-AV Engine). Using kavd a Pentium-133 was able to scan nearly 500 mails in just one minute! deMIMEing: Since most scanners doesn't support decoding of MIME-Messages we have to do, for high-speed we have it built-in (using ripmime). Flexible scanner-configuration: Almost every scanner can be configured easily. Just set the capabilities of your scanner, the exit-code it gives when a mail is found and make a regular- expression which tells how to extract the virusname. Notification: Instead of the virus we send a notification to the client, which can be customized using a template. Written in C ...which means that it's faster than using a script-language. It's free POP3VScan is released under the General Public License (GPL), which means that it's free to use and also the source is available. Johannes Nieß j....@un... P.S: I tried to join the DL mailing list, but got bitten by Sourcforge mail envelope header verification and DL blocking port 25 from outside: ----- The following addresses had transient non-fatal errors ----- pop...@li... ----- Transcript of session follows ----- ... while talking to mail.sourceforge.net.: >>> MAIL From:<ni...@se...> SIZE=928 <<< 451-Envelope sender verification failed <<< 451 rejected: temporarily unable to verify envelope sender address (try again later) <ni...@se...> ... while talking to externalmx.valinux.com.: >>> MAIL From:<ni...@se...> SIZE=928 <<< 451-Envelope sender verification failed <<< 451 rejected: temporarily unable to verify envelope sender address (try again later) <ni...@se...> pop...@li...... Deferred: 451-Envelope sender verification failed Warning: message still undelivered after 4 hours Will keep trying until message is 5 days old (Message died in queue later) ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=588077&group_id=34096 |
|
From: <no...@so...> - 2002-08-06 17:53:19
|
Feature Requests item #588077, was opened at 2002-07-29 10:04 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=588077&group_id=34096 Category: None Group: None Status: Open Priority: 5 Submitted By: Nobody/Anonymous (nobody) Assigned to: Nobody/Anonymous (nobody) Summary: Feature Request: pop3vscan Initial Comment: Hi, I just found http://pop3vscan.sourceforge.net. It's a transparent virus scanning proxy for POP3 mail attachments. They are de-MIMEed and send to an external file virus scanner of your choice. I'd love to see it in Devil Linux. AFIK it's the only way to battle mail viruses if your POP3 mailbox and mail server is outside of your DL firewalled net and only POP3 clients are inside. Some features (exerpt from their web site): No client configuration necessary: Because POP3VScan is a full transparent proxy nothing but the scanning-server has to be configured. Fast scanning: POP3VScan supports the Kaspersky Anti-Virus Daemon (kavd) and the Trophie Daemon (which uses the Trend-AV Engine). Using kavd a Pentium-133 was able to scan nearly 500 mails in just one minute! deMIMEing: Since most scanners doesn't support decoding of MIME-Messages we have to do, for high-speed we have it built-in (using ripmime). Flexible scanner-configuration: Almost every scanner can be configured easily. Just set the capabilities of your scanner, the exit-code it gives when a mail is found and make a regular- expression which tells how to extract the virusname. Notification: Instead of the virus we send a notification to the client, which can be customized using a template. Written in C ...which means that it's faster than using a script-language. It's free POP3VScan is released under the General Public License (GPL), which means that it's free to use and also the source is available. Johannes Nieß j....@un... P.S: I tried to join the DL mailing list, but got bitten by Sourcforge mail envelope header verification and DL blocking port 25 from outside: ----- The following addresses had transient non-fatal errors ----- pop...@li... ----- Transcript of session follows ----- ... while talking to mail.sourceforge.net.: >>> MAIL From:<ni...@se...> SIZE=928 <<< 451-Envelope sender verification failed <<< 451 rejected: temporarily unable to verify envelope sender address (try again later) <ni...@se...> ... while talking to externalmx.valinux.com.: >>> MAIL From:<ni...@se...> SIZE=928 <<< 451-Envelope sender verification failed <<< 451 rejected: temporarily unable to verify envelope sender address (try again later) <ni...@se...> pop...@li...... Deferred: 451-Envelope sender verification failed Warning: message still undelivered after 4 hours Will keep trying until message is 5 days old (Message died in queue later) ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410646&aid=588077&group_id=34096 |
|
From: Heiko Z. <smi...@zu...> - 2002-08-06 17:51:41
|
I'll add it to our list. One of our biggest problems is, that we can't include a commercial virus scanner. What is a good FREE virusscanner for Linux ? Heiko The following message was sent by Johannes Niess <j....@un...> on 06 Aug 2002 12:37:47 +0200. > Heiko, > > I tried to join the DL mailing list, but got bitten by Sourcforge mail > envelope header verification and our DL firewall blocking port 25 from > outside. So I misused Sourceforge's Support Request ([ 588077 ] > Feature Request: pop3vscan). I assumed this would end up in the > DL mailing list archive, but it's not there and no other sign of beiing > noticed. So I apologize for this unsolicited personal mail. The > Sourceforge email went like this: > > > I just found http://pop3vscan.sourceforge.net. It's a transparent > virus scanning proxy for POP3 mail attachments. They are de-MIMEed and > send to an external file virus scanner of your choice. I'd love to > see it in Devil Linux. AFIK it's the only reasonable way to battle > mail viruses if your POP3 mailbox and mail server is outside of your > DL firewalled net and only POP3 clients are inside. > > Some features (exerpt from their web site): > > No client configuration necessary: Because POP3VScan is a full > transparent proxy nothing but the scanning-server has to be > configured. > Fast scanning: POP3VScan supports the Kaspersky Anti-Virus > Daemon (kavd) and the Trophie Daemon (which uses the > Trend-AV Engine). Using kavd a Pentium-133 was able to scan > nearly 500 mails in just one minute! > deMIMEing: Since most scanners doesn't support decoding of > MIME-Messages we have to do, for high-speed we have it > built-in (using ripmime). > Flexible scanner-configuration: Almost every scanner can be > configured easily. Just set the capabilities of your scanner, the > exit-code it gives when a mail is found and make a regular- > expression which tells how to extract the virusname. > Notification: Instead of the virus we send a notification to the > client, which can be customized using a template. > Written in C ...which means that it's faster than using a > script-language. > It's free POP3VScan is released under the General Public License > (GPL), which means that it's free to use and also the source is > available. > > Johannes Nieß > j....@un... > > > |
|
From: <no...@fr...> - 2002-08-05 20:13:57
|
This email is to inform you of release '2.3.6' of 'xinetd' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/xinetd/ The changes in this release are as follows: There are many improvements to the config parser, reduced memory consumption, an RPM spec file fixes for several bugs that caused the application to segfault on startup, and fixes for some minor security issues related to address matching. Project description: xinetd is a replacement for inetd, the internet services daemon. Anybody can use it to start servers that don't require privileged ports because xinetd does not require that the services in its configuration file be listed in /etc/services. It can do access control on all services based on the address of the remote host and time of access. Access control works on all services, whether multi-threaded or single-threaded and for both the TCP and UDP protocols. xinetd supports both internal access control, and the use of the libwrap library. IPv6 with access control is also supported. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: <no...@so...> - 2002-08-05 01:07:03
|
Bugs item #590395, was opened at 2002-08-02 17:49 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590395&group_id=34096 Category: Package Group: all >Status: Deleted >Resolution: Invalid Priority: 9 Submitted By: Heiko Zuerker (smiley73) >Assigned to: Heiko Zuerker (smiley73) Summary: update OpenSSH Initial Comment: -----BEGIN PGP SIGNED MESSAGE----- CERT Advisory CA-2002-24 Trojan Horse OpenSSH Distribution Original issue date: August 1, 2002 Last revised: -- Source: CERT/CC A complete revision history is at the end of this file. Overview The CERT/CC has received confirmation that some copies of the source code for the OpenSSH package were modified by an intruder and contain a Trojan horse. We strongly encourage sites which employ, redistribute, or mirror the OpenSSH package to immediately verify the integrity of their distribution. I. Description The CERT/CC has received confirmation that some copies of the source code for the OpenSSH package have been modified by an intruder and contain a Trojan horse. The following advisory has been released by the OpenSSH development team http://www.openssh.com/txt/trojan.adv The following files were modified to include the malicious code: openssh-3.4p1.tar.gz openssh-3.4.tgz openssh-3.2.2p1.tar.gz These files appear to have been placed on the FTP server which hosts ftp.openssh.com and ftp.openbsd.org on the 30th or 31st of July, 2002. The OpenSSH development team replaced the Trojan horse copies with the original, uncompromised versions at 13:00 UTC, August 1st, 2002. The Trojan horse copy of the source code was available long enough for copies to propagate to sites that mirror the OpenSSH site. The Trojan horse versions of OpenSSH contain malicious code that is run when the software is compiled. This code connects to a fixed remote server on 6667/tcp. It can then open a shell running as the user who compiled OpenSSH. II. Impact An intruder operating from (or able to impersonate) the remote address specified in the malicious code can gain unauthorized remote access to any host which compiled a version of OpenSSH from this Trojan horse version of the source code. The level of access would be that of the user who compiled the source code. III. Solution We encourage sites who downloaded a copy of the OpenSSH distribution to verify the authenticity of their distribution, regardless of where it was obtained. Furthermore, we encourage users to inspect any and all software that may have been downloaded from the compromised site. Note that it is not sufficient to rely on the timestamps or sizes of the file when trying to determine whether or not you have a copy of the Trojan horse version. Where to get OpenSSH The primary distribution site for OpenSSH is http://www.openssh.com/ Sites that mirror the OpenSSH source code are encouraged to verify the integrity of their sources. Verify MD5 checksums You can use the following MD5 checksums to verify the integrity of your OpenSSH source code distribution: Correct versions: 459c1d0262e939d6432f193c7a4ba8a8 openssh- 3.4p1.tar.gz d5a956263287e7fd261528bb1962f24c openssh- 3.4p1.tar.gz.sig 39659226ff5b0d16d0290b21f67c46f2 openssh-3.4.tgz 9d3e1e31e8d6cdbfa3036cb183aa4a01 openssh- 3.2.2p1.tar.gz be4f9ed8da1735efd770dc8fa2bb808a openssh- 3.2.2p1.tar.gz.sig At least one version of the modified Trojan horse distributions was reported to have the following checksum: Trojan horse version: 3ac9bc346d736b4a51d676faa2a08a57 openssh- 3.4p1.tar.gz Verify PGP signature Additionally, distributions of the portable release of OpenSSH are distributed with detached PGP signatures. Note that the Trojan horse versions were not signed correctly, and attempts to verify the signatures would have failed. As a matter of good security practice, the CERT/CC encourages users to verify, whenever possible, the integrity of downloaded software. For more information, see http://www.cert.org/incident_notes/IN-2001- 06.html Appendix A. - Vendor Information This appendix contains information provided by vendors for this advisory. As vendors report new information to the CERT/CC, we will update this section and note the changes in our revision history. If a particular vendor is not listed below, we have not received their comments. Connectiva Linux Conectiva Linux distributes openssh-3.4p1 as a security update. The distributed copy is the original one and is not affected by this trojan. The detached digital signature is always checked before building third party packages. MandrakeSoft MandrakeSoft has verified that the openssh-3.4p1 sources used to build it's latest updates (ref. MDKSA-2002:040-1) do not contain this trojan. _______________________________________________ __________________ _______________________________________________ __________________ Feedback can be directed to the author: Chad Dougherty. _______________________________________________ _______________________ This document is available from: http://www.cert.org/advisories/CA-2002-24.html _______________________________________________ _______________________ CERT/CC Contact Information Email: ce...@ce... Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT Coordination Center Software Engineering Institute Carnegie Mellon University Pittsburgh PA 15213-3890 U.S.A. CERT/CC personnel answer the hotline 08:00- 17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryption We strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from http://www.cert.org/CERT_PGP.key If you prefer to use DES, please call the CERT hotline for more information. Getting security information CERT publications and other security information are available from our web site http://www.cert.org/ To subscribe to the CERT mailing list for advisories and bulletins, send email to maj...@ce.... Please include in the body of your message subscribe cert-advisory * "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office. _______________________________________________ _______________________ NO WARRANTY Any material furnished by Carnegie Mellon University and the Software Engineering Institute is furnished on an "as is" basis. Carnegie Mellon University makes no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material. Carnegie Mellon University does not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement. _______________________________________________ __________________ Conditions for use, disclaimers, and sponsorship information Copyright 2002 Carnegie Mellon University. Revision History August 1, 2002: Initial release -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.8 iQCVAwUBPUmR3qCVPMXQI2HJAQFs7wP/SwypiZbfCb /FvMBgE3rFaY9Ul7vlyRKE KPncunJ+KVp2sBzTbNL01wOuASx836hTa/ByXwnX4LQ LX0XzBLrDcVsrDlu1pUga Z/CopXb3KclKckmti5diCz1BNQdKbYyu/G7uHkjZQPJKC 6UZr9lmge+00HMqSmHN AAOV7PQstAc= =FgfD -----END PGP SIGNATURE----- ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590395&group_id=34096 |
|
From: Heiko Z. <he...@zu...> - 2002-08-05 00:30:17
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 | -- should ramdisk.tar.bz2 be changed to vmfs.tar.bz2 ?? I would keep that as it is, it's just cosmetic. - -- cu ~ Heiko http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6-2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAj1NxgoACgkQzRJAyNsjWPnHGgCfSSv41mH5cGSpLv9gdNcvVsOc xv8AnjvH3iA+XuxB+laJmSkPMJHMOtz7 =laJ3 -----END PGP SIGNATURE----- |
|
From: John v. V. <joh...@ya...> - 2002-08-04 18:15:41
|
Hello, I am getting nearer and nearer to finishing a DL/eLSD variant CD boot OS that will include everything needed to build another Cd Boot OS. I am also trying to seperate the initrd and ramdisk file systems ( now called Virtual memory file system, from the latest stable kernel ) -- should ramdisk.tar.bz2 be changed to vmfs.tar.bz2 ?? While surfing on the topic of clustering I found the following projects on SourceForge: ##User Mode Linux UML means "User Mode Linux". It is a possiblity to Run Linux inside itself. The User-mode Linux Kernel Home Page: http://user-mode-linux.sourceforge.net/ User-Mode Linux is a safe, secure way of running Linux versions and Linux processes.Run buggy software, experiment with new Linux kernels or distributions, and poke around in the internals of Linux, all without risking our main Linux setup. User-Mode Linux gives you a virtual machine that may have more hardware and software virtual resources than your actual, physical computer. Disk storage for the virtual machine is entirely contained inside a single file on your physical machine. You can assign your virtual machine only the hardware access you want it to have. With properly limited access, nothing you do on the virtual machine can change or damage your real computer, or its software. ## On the Extreme side: openMosix based on Mosix, a transparant clustering linux system -- now proprietary: http://www.mosix.com/ openMosix is a Linux kernel extension for single-system image clustering. from the openMosix-website: http://openmosix.sourceforge.net/ openMosix is the GPLv2, Open Source, project to extend Prof. Barak's outstanding Mosix project. New releases of Mosix became proprietary software in late 2001 and openMosix was begun February 10, 2002 by Moshe Bar to keep this highly regarded Linux clustering solution available as open source. openMosix quickly acquired an international team of volunteers that captured prior releases of the GPL code and started to immediately improve and extend the solution. ===== John van Vlaanderen ################################################# # CXN, Inc. Contact: jo...@th... # # President, The Linux Society # # http://groups.yahoo.com/group/thelinuxsociety # ################################################# __________________________________________________ Do You Yahoo!? Yahoo! Health - Feel better, live better http://health.yahoo.com |
|
From: <no...@fr...> - 2002-08-04 08:27:21
|
This email is to inform you of release '2.11u' of 'util-linux' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/util-linux/ The changes in this release are as follows: This version adds a check for libz, includes minor fixes, adds messages for additional languages, and prevents umount -a from umounting devfs. Project description: Util-linux is a suite of essential utilities for any Linux system. Its primary audience is system integrators and DIY Linux hackers. Util-linux is attempting to be portable, but the only platform it has been tested much on is Linux i386. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: <no...@fr...> - 2002-08-04 08:27:15
|
This email is to inform you of release '2.11u' of 'util-linux' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/util-linux/ The changes in this release are as follows: This version adds a check for libz, includes minor fixes, adds messages for additional languages, and prevents umount -a from umounting devfs. Project description: Util-linux is a suite of essential utilities for any Linux system. Its primary audience is system integrators and DIY Linux hackers. Util-linux is attempting to be portable, but the only platform it has been tested much on is Linux i386. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: <no...@fr...> - 2002-08-03 19:32:54
|
This email is to inform you of release '2.4.19' of 'Linux' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/linux/ The changes in this release are as follows: A huge number of updates and bugfixes. Project description: Linux is a clone of the Unix kernel, written from scratch by Linus Torvalds with assistance from a loosely-knit team of hackers across the Net. It aims towards POSIX and Single UNIX Specification compliance. It has all the features you would expect in a modern fully-fledged Unix kernel, including true multitasking, virtual memory, shared libraries, demand loading, shared copy-on-write executables, proper memory management, and TCP/IP networking. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: <no...@fr...> - 2002-08-03 19:18:26
|
This email is to inform you of release '1.9.6' of 'grsecurity' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/grsecurity/ The changes in this release are as follows: PaX was updated to support 24-bit stack randomness and randomization of ET_EXEC binaries. The ACL system was updated to support a learning mode, and process-based resource restrictions were added. Gradm, the userspace ACL administration tool, was also updated for this release. Project description: grsecurity is a complete security system for Linux 2.4 that implements a detection/prevention/containment strategy. It prevents most forms of address space modification, confines programs with least privilege via its process-based ACL system, hardens syscalls, and provides many of the OpenBSD randomness features. It has auditing capabilities and a netfilter module designed to thwart portscans and OS fingerprinting. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: Heiko Z. <he...@zu...> - 2002-08-03 16:50:23
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 I just checked it, everything is fine. Did you look in the directory kernel/drivers/net ? I won't be able to help you more before next week, because I'm leaving now. - -- cu ~ Heiko http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6-2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAj1MCBcACgkQzRJAyNsjWPmFsgCg7Sw3U6Vf9Rfv70QR1MIBUBwE AVgAoI7DSJHLNq75iOZDWI+c2BujBDcZ =DCfO -----END PGP SIGNATURE----- |
|
From: Heiko Z. <he...@zu...> - 2002-08-03 14:50:32
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 Gunther Stammwitz wrote: | is there a bug in the current version of devil-linux ? | When building the whole thing and burning the ISO-image I can not find any | network-driver-modules in /lib. | There's only e100 and e1000. | | Is it my fault or is it a bug ? I don't really know. I will start a complete recompile. Hopefully it's finished before I have to leave (I'm out for the rest of the weekend). I post it, as soon as I have some information. | btw: I'm currently adding VLAN-support to devil-linux :-) cool - -- cu ~ Heiko http://www.devil-linux.org -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6-2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAj1L678ACgkQzRJAyNsjWPkPagCfUU4kEddySv7Idhjrmpng6CIH APMAnR+whfg5DO9p+UIYM5ZMvlQnNZmd =+dtG -----END PGP SIGNATURE----- |
|
From: Gunther S. <gs...@gm...> - 2002-08-03 14:34:06
|
Hello Developers, is there a bug in the current version of devil-linux ? When building the whole thing and burning the ISO-image I can not find an= y network-driver-modules in /lib. There's only e100 and e1000. Is it my fault or is it a bug ? Thanks, Gunther btw: I'm currently adding VLAN-support to devil-linux :-) + Connectivity & Colocation @ www.rackbase.de + ----------------------------------------------- Mainlab GmbH Sachsenh=E4user Landwehrweg 236 60598 Frankfurt am Main Tel. / Fax: 0700-2MAINLAB (0700-26246522) Email: in...@ma... Web: www.mainlab.de |
|
From: <no...@so...> - 2002-08-03 14:16:54
|
Bugs item #590514, was opened at 2002-08-03 09:16 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590514&group_id=34096 Category: Package Group: all Status: Open Resolution: None Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: update squid Initial Comment: v2.5pre10 is available and there were some security holes ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590514&group_id=34096 |
|
From: <no...@so...> - 2002-08-03 14:14:36
|
Bugs item #590512, was opened at 2002-08-03 09:14 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590512&group_id=34096 Category: Base System Group: all Status: Open Resolution: None Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: update Kernel to 2.4.19 Initial Comment: it's available ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590512&group_id=34096 |
|
From: <no...@fr...> - 2002-08-02 23:31:02
|
This email is to inform you of release '0.18' of 'VServer' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/vserver/ The changes in this release are as follows: The newvserver utility has been enhanced so you can interactively build vservers from the first Red Hat CD or either 7.2 or 7.3 kernel. The new kernel ctx-12 supports multiple IP numbers assigned to a vserver, and also allows binding to the broadcast address (A normal kernel allows this as well.) Some minor bugfixes were also made. Project description: VServer virtual servers operate like a normal Linux server, but allow many independent servers to be run simultaneously in one box. These can involve normal services such as telnet, mail, Web, and SQL servers - in most cases using a standard configuration. The services are unaware of the virtual server concept. Each virtual server has its own user account database and root password. Each vserver uses standard packages and runs at the same speed as a non-VServer installation. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: <no...@so...> - 2002-08-02 22:49:28
|
Bugs item #590395, was opened at 2002-08-02 17:49 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590395&group_id=34096 Category: Package Group: all Status: Open Resolution: None Priority: 9 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: update OpenSSH Initial Comment: -----BEGIN PGP SIGNED MESSAGE----- CERT Advisory CA-2002-24 Trojan Horse OpenSSH Distribution Original issue date: August 1, 2002 Last revised: -- Source: CERT/CC A complete revision history is at the end of this file. Overview The CERT/CC has received confirmation that some copies of the source code for the OpenSSH package were modified by an intruder and contain a Trojan horse. We strongly encourage sites which employ, redistribute, or mirror the OpenSSH package to immediately verify the integrity of their distribution. I. Description The CERT/CC has received confirmation that some copies of the source code for the OpenSSH package have been modified by an intruder and contain a Trojan horse. The following advisory has been released by the OpenSSH development team http://www.openssh.com/txt/trojan.adv The following files were modified to include the malicious code: openssh-3.4p1.tar.gz openssh-3.4.tgz openssh-3.2.2p1.tar.gz These files appear to have been placed on the FTP server which hosts ftp.openssh.com and ftp.openbsd.org on the 30th or 31st of July, 2002. The OpenSSH development team replaced the Trojan horse copies with the original, uncompromised versions at 13:00 UTC, August 1st, 2002. The Trojan horse copy of the source code was available long enough for copies to propagate to sites that mirror the OpenSSH site. The Trojan horse versions of OpenSSH contain malicious code that is run when the software is compiled. This code connects to a fixed remote server on 6667/tcp. It can then open a shell running as the user who compiled OpenSSH. II. Impact An intruder operating from (or able to impersonate) the remote address specified in the malicious code can gain unauthorized remote access to any host which compiled a version of OpenSSH from this Trojan horse version of the source code. The level of access would be that of the user who compiled the source code. III. Solution We encourage sites who downloaded a copy of the OpenSSH distribution to verify the authenticity of their distribution, regardless of where it was obtained. Furthermore, we encourage users to inspect any and all software that may have been downloaded from the compromised site. Note that it is not sufficient to rely on the timestamps or sizes of the file when trying to determine whether or not you have a copy of the Trojan horse version. Where to get OpenSSH The primary distribution site for OpenSSH is http://www.openssh.com/ Sites that mirror the OpenSSH source code are encouraged to verify the integrity of their sources. Verify MD5 checksums You can use the following MD5 checksums to verify the integrity of your OpenSSH source code distribution: Correct versions: 459c1d0262e939d6432f193c7a4ba8a8 openssh- 3.4p1.tar.gz d5a956263287e7fd261528bb1962f24c openssh- 3.4p1.tar.gz.sig 39659226ff5b0d16d0290b21f67c46f2 openssh-3.4.tgz 9d3e1e31e8d6cdbfa3036cb183aa4a01 openssh- 3.2.2p1.tar.gz be4f9ed8da1735efd770dc8fa2bb808a openssh- 3.2.2p1.tar.gz.sig At least one version of the modified Trojan horse distributions was reported to have the following checksum: Trojan horse version: 3ac9bc346d736b4a51d676faa2a08a57 openssh- 3.4p1.tar.gz Verify PGP signature Additionally, distributions of the portable release of OpenSSH are distributed with detached PGP signatures. Note that the Trojan horse versions were not signed correctly, and attempts to verify the signatures would have failed. As a matter of good security practice, the CERT/CC encourages users to verify, whenever possible, the integrity of downloaded software. For more information, see http://www.cert.org/incident_notes/IN-2001- 06.html Appendix A. - Vendor Information This appendix contains information provided by vendors for this advisory. As vendors report new information to the CERT/CC, we will update this section and note the changes in our revision history. If a particular vendor is not listed below, we have not received their comments. Connectiva Linux Conectiva Linux distributes openssh-3.4p1 as a security update. The distributed copy is the original one and is not affected by this trojan. The detached digital signature is always checked before building third party packages. MandrakeSoft MandrakeSoft has verified that the openssh-3.4p1 sources used to build it's latest updates (ref. MDKSA-2002:040-1) do not contain this trojan. _______________________________________________ __________________ _______________________________________________ __________________ Feedback can be directed to the author: Chad Dougherty. _______________________________________________ _______________________ This document is available from: http://www.cert.org/advisories/CA-2002-24.html _______________________________________________ _______________________ CERT/CC Contact Information Email: ce...@ce... Phone: +1 412-268-7090 (24-hour hotline) Fax: +1 412-268-6989 Postal address: CERT Coordination Center Software Engineering Institute Carnegie Mellon University Pittsburgh PA 15213-3890 U.S.A. CERT/CC personnel answer the hotline 08:00- 17:00 EST(GMT-5) / EDT(GMT-4) Monday through Friday; they are on call for emergencies during other hours, on U.S. holidays, and on weekends. Using encryption We strongly urge you to encrypt sensitive information sent by email. Our public PGP key is available from http://www.cert.org/CERT_PGP.key If you prefer to use DES, please call the CERT hotline for more information. Getting security information CERT publications and other security information are available from our web site http://www.cert.org/ To subscribe to the CERT mailing list for advisories and bulletins, send email to maj...@ce.... Please include in the body of your message subscribe cert-advisory * "CERT" and "CERT Coordination Center" are registered in the U.S. Patent and Trademark Office. _______________________________________________ _______________________ NO WARRANTY Any material furnished by Carnegie Mellon University and the Software Engineering Institute is furnished on an "as is" basis. Carnegie Mellon University makes no warranties of any kind, either expressed or implied as to any matter including, but not limited to, warranty of fitness for a particular purpose or merchantability, exclusivity or results obtained from use of the material. Carnegie Mellon University does not make any warranty of any kind with respect to freedom from patent, trademark, or copyright infringement. _______________________________________________ __________________ Conditions for use, disclaimers, and sponsorship information Copyright 2002 Carnegie Mellon University. Revision History August 1, 2002: Initial release -----BEGIN PGP SIGNATURE----- Version: PGP 6.5.8 iQCVAwUBPUmR3qCVPMXQI2HJAQFs7wP/SwypiZbfCb /FvMBgE3rFaY9Ul7vlyRKE KPncunJ+KVp2sBzTbNL01wOuASx836hTa/ByXwnX4LQ LX0XzBLrDcVsrDlu1pUga Z/CopXb3KclKckmti5diCz1BNQdKbYyu/G7uHkjZQPJKC 6UZr9lmge+00HMqSmHN AAOV7PQstAc= =FgfD -----END PGP SIGNATURE----- ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590395&group_id=34096 |
|
From: Heiko Z. <he...@zu...> - 2002-08-02 22:40:22
|
-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA1 John van V. wrote: | Hello, In some cases it may not be possible to modify the boot parameters such | as on a CD boot linux. | | I recall making on-the-fly changes to the SunOS kernel w/ adb. Is there anyway | to do this w/ the linux kernel ?? It is not possible with DL to change that on the fly. You have to specify it the ISOLINUX config file, but this is fixed on the CD. HZ -----BEGIN PGP SIGNATURE----- Version: GnuPG v1.0.6-2 (MingW32) Comment: Using GnuPG with Mozilla - http://enigmail.mozdev.org iEYEARECAAYFAj1LCPYACgkQzRJAyNsjWPlHqACgoV49siMSTEzYDDcMv+Kme+XB NlcAn1oEMTSqKC5wsKO3IfEvFiAVv1Oq =JVhN -----END PGP SIGNATURE----- |
|
From: <no...@so...> - 2002-08-02 15:18:00
|
Bugs item #590192, was opened at 2002-08-02 10:17 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590192&group_id=34096 Category: Base System Group: all Status: Open Resolution: None Priority: 9 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: update openssl Initial Comment: This email is to inform you of release '0.96e' of 'OpenSSL' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/openssl/ The changes in this release are as follows: Changes have been made due to a security advisory. Upgrading is highly recommended. ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590192&group_id=34096 |
|
From: <no...@so...> - 2002-08-02 15:17:26
|
Bugs item #590190, was opened at 2002-08-02 10:17 You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590190&group_id=34096 Category: Base System Group: all Status: Open Resolution: None Priority: 5 Submitted By: Heiko Zuerker (smiley73) Assigned to: Nobody/Anonymous (nobody) Summary: update modutils Initial Comment: This email is to inform you of release '2.4.19' of 'modutils' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/modutils/ ---------------------------------------------------------------------- You can respond by visiting: https://sourceforge.net/tracker/?func=detail&atid=410643&aid=590190&group_id=34096 |
|
From: <no...@fr...> - 2002-08-01 06:13:05
|
This email is to inform you of release '2.4.19' of 'modutils' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/modutils/ The changes in this release are as follows: This version corrects ia64 SEGREL relocations. fixes incorrect unwind data for ia64 modules, removes 64-bit warnings, incudes new aliases, adds R_PARISC_PCREL22F, and removes the flex warning. Project description: The modutils package contains utilities that are intended to make a Linux modular kernel manageable for all users, administrators, and distribution maintainers. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: <no...@fr...> - 2002-07-31 04:10:59
|
This email is to inform you of release '0.96e' of 'OpenSSL' through freshmeat.net. All URLs and other useful information can be found at http://freshmeat.net/projects/openssl/ The changes in this release are as follows: Changes have been made due to a security advisory. Upgrading is highly recommended. Project description: The OpenSSL Project is a collaborative effort to develop a robust, commercial-grade, fully featured, and Open Source toolkit implementing the Secure Sockets Layer (SSL v2/v3) and Transport Layer Security (TLS v1) as well as a full-strength general-purpose cryptography library. If you would like to cancel subscription to releases of this project, login to freshmeat.net and choose 'home' from the personal menubar at the top of the page. You'll be presented with a list of projects you're subscribed to in the right column, which you may cancel by highlighting the project in question and clicking the 'delete' button. Sincerely, freshmeat.net |
|
From: John v. V. <joh...@ya...> - 2002-07-30 17:26:53
|
Hello, In some cases it may not be possible to modify the boot parameters such
as on a CD boot linux.
I recall making on-the-fly changes to the SunOS kernel w/ adb. Is there anyway
to do this w/ the linux kernel ??
Tia, John
=====
John van Vlaanderen
#################################################
# CXN, Inc. Contact: jo...@th... #
# President, The Linux Society #
# http://groups.yahoo.com/group/thelinuxsociety #
#################################################
__________________________________________________
Do You Yahoo!?
Yahoo! Health - Feel better, live better
http://health.yahoo.com
|