<?xml version="1.0"?>
<rss version="2.0"><channel><title>Security Latest Topics</title><link>https://mandrivausers.org/index.php?/forum/13-security/</link><description>Security Latest Topics</description><language>en</language><item><title>Desperately need help - CBL Listing</title><link>https://mandrivausers.org/index.php?/topic/124617-desperately-need-help-cbl-listing/</link><description><![CDATA[
<p>Hello All</p>
<p> </p>
<p>I am desperately looking for some direction. I have a Mandriva box with two network cards. One for loc and one for net. Every now and then and it is adhoc we are getting listed on CBL with the following description:</p>
<p> </p>
<p>This IP is infected (or NATting for a computer that is infected) with the Conficker A or Conficker B botnet. </p>
<p> </p>
<p>It is referring to IP 216.66.15.109</p>
<p> </p>
<p>Is there in which I can block any and all traffic to this IP using shorewall?</p>
<p> </p>
<p>I have squid, postfix, shorewall in place. Apparently according to CBL it uses port 80, here we have a transparent proxy in use.</p>
<p> </p>
<p>Could anyone please help me out. Have battled for two weeks.</p>
<p> </p>
<p>Thank you</p>
<p> </p>
<p>Smitty</p>
]]></description><guid isPermaLink="false">124617</guid><pubDate>Wed, 01 Jul 2015 14:19:45 +0000</pubDate></item><item><title>login as root [solved]</title><link>https://mandrivausers.org/index.php?/topic/27483-login-as-root-solved/</link><description><![CDATA[<p>Is it possible to set up mandrake/mandriva to login as root instead of this deal where you login as a normal user then su to root? this is not that much of a problem except that I would like to log in with WinSCP via ssh and can only login as normal user then I cant get past the users home directory. is there another work around for this? I've always just loged in as root from windows on other distros.</p>]]></description><guid isPermaLink="false">27483</guid><pubDate>Sun, 14 Aug 2005 03:43:51 +0000</pubDate></item><item><title>Logging in as root graphically? [solved]</title><link>https://mandrivausers.org/index.php?/topic/61354-logging-in-as-root-graphically-solved/</link><description><![CDATA[
<p>Occasionally, in Mandriva 2008 I need to log in as root graphically from my current account that has lower permissions. Sometimes I need to do tasks that I can't do on my normal account, such as removing entries from the GRUB config file if Mandriva decides to add extra entries onto it for some reason, or placing/removing files from protected directories.</p>
<p> </p>
<p>Yes, I understand the risks with doing things under root, but some things I find would be much easier doing graphically rather than in a console with <em>su</em>.</p>
]]></description><guid isPermaLink="false">61354</guid><pubDate>Wed, 18 Jun 2008 18:57:44 +0000</pubDate></item><item><title>Recommend a good second party firewall</title><link>https://mandrivausers.org/index.php?/topic/109155-recommend-a-good-second-party-firewall/</link><description><![CDATA[
<p>Can you recommend a good functional second party firewall?</p>
<p>Also, in relation the Mandriva 2011 operating system.</p>
<p>Are there any addtional details I need to be aware of?</p>
<p> </p>
<p>Thank You,</p>
<p>Leo54</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Hardware by spinynorman]</span></p>
]]></description><guid isPermaLink="false">109155</guid><pubDate>Wed, 18 Jan 2012 05:26:37 +0000</pubDate></item><item><title>About Linux firewalls</title><link>https://mandrivausers.org/index.php?/topic/108753-about-linux-firewalls/</link><description><![CDATA[
<p>Hello everybody.</p>
<p> </p>
<p> </p>
<p>I am currently looking for a Linux firewall that behaves just like Zone Alarm for Windows. I know about firestarter and mandriva's own interactive firewall, but what I need is something that immediately warns me of a program trying to connect to the internet so I can block it, for example.</p>
<p> </p>
<p>Do you know of any way to achieve this with Linux?</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">108753</guid><pubDate>Wed, 28 Sep 2011 22:40:28 +0000</pubDate></item><item><title>How to trust a digital certificate - error 61</title><link>https://mandrivausers.org/index.php?/topic/108141-how-to-trust-a-digital-certificate-error-61/</link><description><![CDATA[
<p>I used to be able to access my work site using Firefox. I can login to my site successfully but when click to open an application in citrix I get the following error:</p>
<p>"You have chosen not to trust "Verisign Class 3 International Server CA - G3", the issuer of the server's security certificate (SSL error 61)". Where do I go so that I can trust this certificate?</p>
<p>Myles.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">108141</guid><pubDate>Tue, 05 Apr 2011 04:31:52 +0000</pubDate></item><item><title>possible intrusion into mandriva 2010.1 - trojan?</title><link>https://mandrivausers.org/index.php?/topic/106329-possible-intrusion-into-mandriva-20101-trojan/</link><description><![CDATA[
<p>hey people, </p>
<p> </p>
<p>in course of somebodies stupid joke with intrusion of mine privacy</p>
<p>i got a TROJAN (from some hackers) being therefore able to see content</p>
<p>of mine computer even through MS Windows. </p>
<p> </p>
<p>Can u assist? I send all logs as necessary, ip adress and </p>
<p>possibility to check access. I dont know mineself to find</p>
<p>or remove virus from linux, i know very well i have it.</p>
<p> </p>
<p>Which are available trojan options at all for Linux?</p>
<p>I have pressupossed impossibility of intrusion on linux</p>
<p>so with full security settings on, i thought it was nearly</p>
<p>impossible. </p>
<p> </p>
<p>Well i know i got Trojan. I give u all neccessary access if required with</p>
<p>ip numbers (and allowance for Mandriva to do anything to mine provider</p>
<p>company that made breach possible). Please assist in getting trojan out.</p>
<p> </p>
<p>I guess i should provise furhter technical details, </p>
<p>but i realy have no idea on internet security on linux,</p>
<p>not nooby, but pressuposed secure access to net on linux</p>
<p>and impossibility of brech. </p>
<p> </p>
<p> </p>
<p>Please help me get normal net access and privacy back.</p>
<p>All details will follow as requested.</p>
]]></description><guid isPermaLink="false">106329</guid><pubDate>Wed, 20 Oct 2010 20:29:14 +0000</pubDate></item><item><title>Linux file servers and clamav</title><link>https://mandrivausers.org/index.php?/topic/104283-linux-file-servers-and-clamav/</link><description><![CDATA[
<p>Hi folks ...</p>
<p> </p>
<p>Should i install clamav as antivirus app under linux file server (samba server). In another words is it necessary to use any antivirus application for samba servers. Thanks a lot.</p>
<p> </p>
<p>Fahd</p>
<p>100611</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Other Distros by spinynorman]</span></p>
]]></description><guid isPermaLink="false">104283</guid><pubDate>Fri, 11 Jun 2010 21:09:54 +0000</pubDate></item><item><title>Install Mandriva 2010 fully encypted</title><link>https://mandrivausers.org/index.php?/topic/101793-install-mandriva-2010-fully-encypted/</link><description><![CDATA[
<p>Hi all.</p>
<p> </p>
<p>How can I, from scratch, install Mandriva 2010.0 with the root and home partition encrypted?</p>
<p> </p>
<p>Either using LUKS or any other encryption method. I guess when I start up my box, it should ask me for a password before attempting to boot into Mandriva.</p>
<p> </p>
<p>Please guide me through this. Thanks</p>
]]></description><guid isPermaLink="false">101793</guid><pubDate>Thu, 01 Apr 2010 22:58:13 +0000</pubDate></item><item><title>protect root / user passwords</title><link>https://mandrivausers.org/index.php?/topic/101363-protect-root-user-passwords/</link><description><![CDATA[
<p>Running mdv2008.1   I have hired an assistant to help in the office and have already locked permissions on files/folders I don't want them to have access to but I remembered there is a way to reset root password by entering single user mode at boot and typing passwd. It will then prompt to enter new password and confirm without asking for the old / original password. The likelyhood that this person would go thru the trouble to learn how to do this is slim as they are unfamiliar with Linux but I want to cover all angles.</p>
<p> </p>
<p>1. Is this correct?</p>
<p>2. How can I prevent other/unauthorized users from doing this?</p>
<p> </p>
<p>I read up on /etc/passwd and etc/shadow but not sure I'm understanding. Looked into etc/passwd and it lists user IDs and etc/shadow contains the password in encoded or encrypted form but you need root password to view /etc/shadow which is a good thing, but this doesn't seem to address the ability of an unauthorized person from  entering single user mode at boot and changing the password using the command passwd. </p>
<p> </p>
<p>I don't think I need to protect against cracking the root password per se (or maybe I do), but more against someone changing it.</p>
<p> </p>
<p>Any other security tips appreciated. I don't think I'm ready to encrypt folders and files yet. One thing at a time for me right now.</p>
<p> </p>
<p>Thanks</p>
]]></description><guid isPermaLink="false">101363</guid><pubDate>Tue, 16 Mar 2010 04:50:18 +0000</pubDate></item><item><title>Can't change root password</title><link>https://mandrivausers.org/index.php?/topic/100883-cant-change-root-password/</link><description><![CDATA[
<p>Morning folks -</p>
<p> </p>
<p>We are running Mandrake MNF 8.2.  </p>
<p> </p>
<p>Recently, the root password expired and was changed at the console.  After changing it, it no longer worked, even the previous password.  I could not boot into single-user mode, as it asked for a "maintenance password".  I had to boot with a Linux live CD and edit /etc/passwd and /etc/shadow to blank out the root password.</p>
<p> </p>
<p>This allowed me to enter single-user mode, as it no longer asked me for a maintenance password.  At the prompt, I did passwd to reset the root password.  Rebooted.  The password still did not work when trying to log in as root at the console command line (no GUI).  However - the new password does work as the maintenance password and also works when I issue the reboot command as a user.  It does not work when I try to sudo though.</p>
<p> </p>
<p>In summary:</p>
<p>- root password works for single user maintenance mode</p>
<p>- root password works when I issue reboot command as a user</p>
<p>- root password does not work when I try to log in as root at the console</p>
<p> </p>
<p>Any thoughts on what the problem might be?</p>
<p> </p>
<p> </p>
<p>Regards -</p>
<p> </p>
<p>Robert</p>
]]></description><guid isPermaLink="false">100883</guid><pubDate>Thu, 04 Mar 2010 13:50:06 +0000</pubDate></item><item><title>msec logs</title><link>https://mandrivausers.org/index.php?/topic/100363-msec-logs/</link><description><![CDATA[
<p>Would someone mind having a look at these &amp;amp; telling me if i have anything to worry about please?&lt;br /&gt;I have altered the way msec runs as i was having trouble accessing my second hard drive without having to put root password in each time, some i understand like the files that have installed from mandriva up dates other bits just confuse me, two files attached&lt;br /&gt;&lt;br /&gt;Thank you&lt;br /&gt;&lt;br /&gt;Richard</p>
<p><a href="https://mandrivausers.org/applications/core/interface/file/attachment.php?id=7383" data-fileid="7383" rel="">msec1.txt</a></p>
<p><a href="https://mandrivausers.org/applications/core/interface/file/attachment.php?id=7393" data-fileid="7393" rel="">msec0.txt</a></p>
]]></description><guid isPermaLink="false">100363</guid><pubDate>Fri, 19 Feb 2010 20:18:29 +0000</pubDate></item><item><title>Muliple user Public PC protection</title><link>https://mandrivausers.org/index.php?/topic/100013-muliple-user-public-pc-protection/</link><description><![CDATA[
<p><span style="font-size:14px;"><span style="font-family:Arial;">Configure a Public PC for a library. Need to add protection to multiple profiles by setting up one of the profiles (making it the base profile image) for the others to use at login. This has been done in Ubuntu through /etc/gdm/PostLogin/Default file (with script), creating a base profile from a profile that is setup as needed used by the other profiles at login. Cannot figure out where to set this up in Mandriva. Please assist.</span></span></p>
<p><span style="font-size:14px;"><span style="font-family:Arial;">Thank you.</span></span></p>
]]></description><guid isPermaLink="false">100013</guid><pubDate>Sun, 14 Feb 2010 06:32:04 +0000</pubDate></item><item><title>need help with writing iptables rules</title><link>https://mandrivausers.org/index.php?/topic/98023-need-help-with-writing-iptables-rules/</link><description><![CDATA[
<p>Hi! Happy New Year!</p>
<p> </p>
<p>I have installed a server on a USB key, and there is very little space available, so I want to write my firewall rules myself instead of installing a firewall front-end software.</p>
<p> </p>
<p>I'm doing tests on my main PC, currently running Shorewall, so IMO I have to do some â€œhouse-cleaningâ€ first, hence the flush at the start of my script. Before any attempt, here was the output from nmap:</p>
<p></p>
<pre class="ipsCode">[root@sedentaire ~]# nmap -sS -sU 192.168.1.21

Starting Nmap 5.00 ( http://nmap.org ) at 2009-12-31 16:37 CET
Interesting ports on sedentaire (192.168.1.21):
Not shown: 1983 closed ports
PORT     STATE         SERVICE
22/tcp   open          ssh
139/tcp  open          netbios-ssn
143/tcp  open          imap
445/tcp  open          microsoft-ds
631/tcp  open          ipp
993/tcp  open          imaps
3128/tcp open          squid-http
6566/tcp open          unknown
8080/tcp open          http-proxy
68/udp   open|filtered dhcpc
123/udp  open|filtered ntp
137/udp  open|filtered netbios-ns
138/udp  open|filtered netbios-dgm
177/udp  open|filtered xdmcp
631/udp  open|filtered ipp
3130/udp open|filtered squid-ipc
5353/udp open|filtered zeroconf

Nmap done: 1 IP address (1 host up) scanned in 1.38 seconds</pre>
<div></div>
<p></p>
<p> </p>
<p>Following explanations from <a href="http://www.linuxhomenetworking.com/wiki/index.php/Quick_HOWTO_:_Ch14_:_Linux_Firewalls_Using_iptables" rel="external nofollow">linuxhomenetworking.com</a>, I wrote this simple basic firewall, just as a test:</p>
<p></p>
<pre class="ipsCode">iptables -t filter -F
iptables -t filter -A OUTPUT -j ACCEPT
iptables -t filter -A FORWARD -j ACCEPT
iptables -t filter -A INPUT -p tcp --dport 51413 -j ACCEPT
iptables -t filter -A INPUT -p udp --dport 51413 -j ACCEPT
iptables -t filter -A INPUT -j DROP</pre>
<div></div>
<p></p>
<p> </p>
<p>But it does not work. Instead of telling me that one port is opened (51413), nmap seems to just hangâ€¦</p>
<p>What is wrong with my rules?</p>
<p> </p>
<p>Yves.</p>
]]></description><guid isPermaLink="false">98023</guid><pubDate>Thu, 31 Dec 2009 16:30:05 +0000</pubDate></item><item><title>port scanning</title><link>https://mandrivausers.org/index.php?/topic/97793-port-scanning/</link><description><![CDATA[
<p>Happy New year there folks.</p>
<p>I like to comment something here to see if someone can tell me what is going on.</p>
<p>I use a wireless connection to my dsl modem based over wep (I know that must be changed =p!)</p>
<p>the thing is this</p>
<p>the conections its running fine, surfing, downloading, ssh...whatever..but suddenly its stops the stream of data and freezes for a minutes then mandy says there has been and attack / port scanning under 55383/udp port, the interesting thing is that it comes from the same ip that its my gateway. By the way I setup the modem to use the dns from the service but it shows the same ip as dns/gateway.</p>
<p>What is this?</p>
<p>thanks in advance!!! <img src="https://mandrivausers.org/uploads/emoticons/default_2thumbsup.gif" alt=":thumbs:" data-emoticon="" /></p>
]]></description><guid isPermaLink="false">97793</guid><pubDate>Mon, 28 Dec 2009 05:49:32 +0000</pubDate></item><item><title>Firewall Blocks Host</title><link>https://mandrivausers.org/index.php?/topic/96863-firewall-blocks-host/</link><description><![CDATA[
<p>hello, </p>
<p>I am configuring my system (2010)to act as a gateway to the internet for other window/linux boxes connected to it via a LAN. The host and the box on the LAN can access the internet with Drakfirewall turned off. With Drakfirewall on, the host system cannot access the internet via a browser; but the host can still down load updates, new programs ect. The other box on the LAN (windows7) can access the internet with the firewall turned on via it's browser. What am I missing in my firewall config? I'm new to linux, its great! - like 1986 again learning DOS.</p>
]]></description><guid isPermaLink="false">96863</guid><pubDate>Tue, 08 Dec 2009 14:17:23 +0000</pubDate></item><item><title>Linux TrueCrypt problems with NTFS vol over 3.8GB?</title><link>https://mandrivausers.org/index.php?/topic/89533-linux-truecrypt-problems-with-ntfs-vol-over-38gb/</link><description><![CDATA[
<p>Hi All!</p>
<p>I wrote this elsewhere, I hope here someone would answer me....</p>
<p> </p>
<p>Hi had to write some data in a TrueCrypt volume of a friend of mine, it was NTFS created with TrueCrypt x Windows.</p>
<p> </p>
<p>TrueCrypt mounted it correctly on Linux (MDV2009.1), but only in read mode... so I checked my config and all seemed ok (no privileges problems, etc. etc.), then I tried with one of my NTFS TC volumes and all worked perfectly in r\w, the only difference was that my volume was 2GB, my friend's volume was 12GB.</p>
<p> </p>
<p>So I did some tests with NTFS TC volumes (normal containers, no hidden volumes) and I noticed that all works perfectly on Linux TC, but only if the volume is almost under 3.8GB, if I create a 3.9GB TC volume NTFS it will be mounted only in read mode (I also tried with root privileges, but I doesn't seem to work).</p>
<p> </p>
<p>Did I missed something or there's a problem with TrueCrypt under Linux?</p>
<p> </p>
<p>Can someone answer me about that???</p>
<p> </p>
<p>Thanks in advance</p>
<p>gagliem</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">89533</guid><pubDate>Thu, 06 Aug 2009 00:47:56 +0000</pubDate></item><item><title>Viewing security.log in Log File Viewer?</title><link>https://mandrivausers.org/index.php?/topic/86483-viewing-securitylog-in-log-file-viewer/</link><description><![CDATA[
<p>Here's a nice quick query:</p>
<p> </p>
<p>Is it possible to get security.log to display in the log file viewer?</p>
<p> </p>
<p>It appears to be readable only by root, so unsurprisingly log viewer (running with 'ordinary' user permissions) won't touch it.</p>
<p> </p>
<p>I could open a terminal, then open it via sudo, but it would be nice to have a more user friendly way of taking a peek after the daily MSEC check :)</p>
]]></description><guid isPermaLink="false">86483</guid><pubDate>Tue, 09 Jun 2009 21:38:15 +0000</pubDate></item><item><title>msec message/log</title><link>https://mandrivausers.org/index.php?/topic/85923-msec-messagelog/</link><description><![CDATA[
<p>Hi</p>
<p>I usually get a pop up message from msec saying it has done a security check. Today i noticed a different pop up, to quick to catch properly but mentioned /var/log.</p>
<p> </p>
<p>I've looked at /var/log/msec.log and found these entries.</p>
<p> </p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,505 WARNING: Enforcing permissions on /var/log/security/suid_root.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,506 WARNING: Enforcing permissions on /var/log/security/writable.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,506 WARNING: Enforcing permissions on /var/log/security/sgid.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,506 WARNING: Enforcing permissions on /var/log/security/open_port.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,507 WARNING: Enforcing permissions on /var/log/security/unowned_user.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,507 WARNING: Enforcing permissions on /var/log/security/suid_md5.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,507 WARNING: Enforcing permissions on /var/log/security/unowned_group.today to 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,707 WARNING: Wrong permissions of /etc/rc.d/init.d/acpid: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,707 WARNING: Wrong permissions of /etc/rc.d/init.d/ip6tables: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,708 WARNING: Wrong permissions of /etc/rc.d/init.d/ntpd: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,708 WARNING: Wrong permissions of /dev: should be 755</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,708 WARNING: Wrong group of /var/log/btmp.1.gz: should be adm</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,709 WARNING: Wrong permissions of /var/log/btmp.1.gz: should be 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,709 WARNING: Wrong permissions of /etc/rc.d/init.d/xfs: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,709 WARNING: Wrong permissions of /etc/rc.d/init.d/iptables: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,709 WARNING: Wrong permissions of /etc/rc.d/init.d/mandi: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,710 WARNING: Wrong permissions of /var/log/ConsoleKit/history: should be 640</p>
<p>2009-06-01 12:08:42			2009-06-01 10:50:26,710 WARNING: Wrong permissions of /etc/rc.d/init.d/shorewall: should be 744</p>
<p>2009-06-01 12:08:42			2009-06-01 11:01:01,620 INFO: Forbidding the X server to listen to tcp connection</p>
<p>2009-06-01 12:08:42			2009-06-01 11:01:01,638 INFO: Setting minimum password length 4</p>
<p>2009-06-01 12:08:42			2009-06-01 11:01:01,654 INFO: No changes in system files</p>
<p>2009-06-01 12:08:42			2009-06-01 12:01:01,226 INFO: Forbidding the X server to listen to tcp connection</p>
<p>2009-06-01 12:08:42			2009-06-01 12:01:01,265 INFO: Setting minimum password length 4</p>
<p>2009-06-01 12:08:42			2009-06-01 12:01:01,278 INFO: No changes in system files</p>
<p> </p>
<p>Can't find anything similar in a search, any ideas what this means? is there a problem and if there is, what do i do?</p>
<p> </p>
<p>Thanks</p>
]]></description><guid isPermaLink="false">85923</guid><pubDate>Mon, 01 Jun 2009 11:31:36 +0000</pubDate></item><item><title>Anti virus program installed</title><link>https://mandrivausers.org/index.php?/topic/56084-anti-virus-program-installed/</link><description><![CDATA[
<p>Just for the fun of it, I decided to install clamav to see if I was mailing any viruses to my "Windows" friends.  This is the first scan I've done in a long time.  After the scan - no viruses!!   <img src="https://mandrivausers.org/uploads/emoticons/default_2thumbsup.gif" alt=":thumbs:" data-emoticon="" /> Thank you Linux!!</p>
<p> </p>
<p>Kieth</p>
]]></description><guid isPermaLink="false">56084</guid><pubDate>Sat, 19 Apr 2008 09:34:10 +0000</pubDate></item><item><title>Two security questions</title><link>https://mandrivausers.org/index.php?/topic/82914-two-security-questions/</link><description><![CDATA[
<p>First of all, why would I need a user called guest? Is it necessary, and does it give me a security hole? </p>
<p> </p>
<p>A little background. I'm running a samba server on this system, and I think the guest user is there to allow printing, without a log in by the end users. ( my family ). </p>
<p> </p>
<p>I found a sym link in /home pointing to my home directory. Just a guess, does  this give anyone connecting as 'guest' access to my home directory? </p>
<p> </p>
<p>Second question, is about the root passwd. If I open a konsole, and su, the password I use works, I get root privileges, as expected. If I use ctrl + alt + f1 to get a command prompt, type 'root' and use the password that works from a konsole and su, the password fails. </p>
<p> </p>
<p>I don't understand why it works with su and not through a tty. </p>
<p> </p>
<p>How can I fix this, I would like one password that works for both. </p>
<p> </p>
<p>I must admit, security is not my long suite...</p>
]]></description><guid isPermaLink="false">82914</guid><pubDate>Sat, 11 Apr 2009 14:54:04 +0000</pubDate></item><item><title>How secure are files if my computer gets stolen?</title><link>https://mandrivausers.org/index.php?/topic/13481-how-secure-are-files-if-my-computer-gets-stolen/</link><description><![CDATA[
<p>Hi all,</p>
<p> </p>
<p>I'm sorry if this sounds like a dumb question but I've been searching for a while on the Net now and can't find anything that directly answers my paranoia.</p>
<p> </p>
<p>A while back I learned of tools people can use to to reset the Administrator password on w2k and such.</p>
<p> </p>
<p>Then it hit me recently, can this happen to me when I'm using MDK 10 official with ext3? What will happen if someone steals my computer with its hard disk contents? I've got a lot of stuff on it I care about and I do  backups but only recently am I investigating encryption as part of the procedures.</p>
<p> </p>
<p>I heard of  something called loop, and also bestcrypt, but it seems I have to play around with them (compiling, etc.) to get them to work and quite frankly I'm way too newbie to try that stuff at the moment. Basically I tried the RPM &amp; .tar.gz for bestcrypt but it spits out errors. The volunteers do a great job of putting everything so I can do urpmi but it seesm for bestcrypt I'm out lof luck.</p>
<p> </p>
<p>It seems the only easy way to achieve my aims is to use gpg/gpa but it seems I have to specify each file explicitly which may not be the best, or write up some kind of script to recursively encrypt/decrypt whenver I'm done/beginning my work. Also, it makes me wonder if ext3 allows people to undelete stuff like windows.</p>
<p> </p>
<p>Can someone out there help me sleep at night?</p>
<p> </p>
<p>Thank you kindly,</p>
<p>Ben</p>
]]></description><guid isPermaLink="false">13481</guid><pubDate>Fri, 23 Apr 2004 08:21:28 +0000</pubDate></item><item><title>sshd [solved]</title><link>https://mandrivausers.org/index.php?/topic/78644-sshd-solved/</link><description><![CDATA[
<p>OK, I will be the first to admit that if you want advice about computer security then I am probably the last person on earth that you should ask, because I know next to nothing about it. However I was a bit surprised when just the other day I came across the following entry in the file /etc/ssh/sshd_config. I would particularly draw you attention to the line that is not commented out.</p>
<p> </p>
<p></p>
<pre class="ipsCode"># Authentication:

#LoginGraceTime 2m
PermitRootLogin without-password
#StrictModes yes
#MaxAuthTries 6
#MaxSessions 10</pre>
<div></div>
<p></p>
<p> </p>
<p>I have 5 versions of Mandriva running, 2x2008.0, 2x2009.0 and 1x2009.1. All three of the later versions have that line included by default as does Linux Mint. Open suse and 2008.0 do not have the file written in the same manner. </p>
<p> </p>
<p>Now it is perfectly possible that there is some reason that this is not insecure and that I just don't know about it, but you have to admit it doesn't exactly look secure does it?</p>
<p> </p>
<p>I never allow the ssh daemon to run, so it doesn't bother me that much, but if I did use ssh, I think it would bother me. Why is the file written like this?</p>
]]></description><guid isPermaLink="false">78644</guid><pubDate>Tue, 27 Jan 2009 18:21:45 +0000</pubDate></item><item><title>Wireless encryption</title><link>https://mandrivausers.org/index.php?/topic/77154-wireless-encryption/</link><description><![CDATA[
<p>Have always set my encryption on my router to WEP cos it works.</p>
<p> </p>
<p>But with the state of wifi connectivity on linux today should I be looking at something else?</p>
<p> </p>
<p>My router has the option of:</p>
<p> </p>
<p>None	</p>
<p>WEP</p>
<p>WPA-PSK [TKIP]</p>
<p>WPA2-PSK [AES]</p>
<p>WPA-PSK [TKIP] + WPA2-PSK [AES]</p>
<p> </p>
<p>Any I should be looking at?</p>
<p> </p>
<p>Ta</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">77154</guid><pubDate>Sat, 03 Jan 2009 14:10:32 +0000</pubDate></item><item><title>Email security [solved]</title><link>https://mandrivausers.org/index.php?/topic/75264-email-security-solved/</link><description><![CDATA[
<p>Up to date I have never had any bother with email security thanks to that wonderful program 'kshowmail'. Unfortunately it looks like all that is going to change pretty soon. </p>
<p> </p>
<p>I have said enough about KDE4, I just don't want to use it and even if I did the present version of it refuses to update unless it removes kshowmail. For me that means that KDE4 is going to be removed, not kshowmail. But there comes the next problem. I have tried XFCE, I like it, but I can't make it do what I want to do. I have tried Gnome, I don't like it, but I can make it do what I want to do (with enough effort). So it is going to be Gnome for me in future like it or not. This finally leads me on to the point of this post.</p>
<p> </p>
<p>Astonishingly Gnome does not have an equivalent to kshowmail. It has a bucketful of mail checkers, but nothing that will allow you to read and delete mail from the server as kshowmail does. Also I have failed in my attempts to get kshowmail to work on Gnome - I can get it to install and run but not to connect to a mail server. Since I do not want to change email servers (they do have a google mail applet that performs the function that I want but as I say I don't want to switch) I now will have to rely on filters in Thunderbird to sort junk mail unless somebody out there knows of a kshowmail like program that does run under Gnome?</p>
<p> </p>
<p>Assuming such a program does not exist (and I have tried hard to find one) how do you set up filters (or otherwise deal with) the kind of spam that spoofs the 'From' address so that it is your own address that appears to be sending it? Blacklisting your own email address does not seem like a good idea, and trying to blacklist on 'Subject' is a guessing game that could go on for eternity. So what do you do? </p>
<p> </p>
<p>Lastly a word to any Gnome devs out there. Please, pretty please, start working on 'gshowmail' - such a program is an absolute necessity in this day and age.</p>
]]></description><guid isPermaLink="false">75264</guid><pubDate>Mon, 01 Dec 2008 10:58:00 +0000</pubDate></item><item><title>How to paste as root?</title><link>https://mandrivausers.org/index.php?/topic/74804-how-to-paste-as-root/</link><description><![CDATA[
<p>Hi. I am new at Linux. Mandriva 2009 is my first experience.</p>
<p> </p>
<p>I try to install skins for VLC and it tells me to copy/paste them in certain folder. But I can't. It tells me that I don't have permission. I have tried a lot of things without success. Can you tell me how to do this, preferably in a graphic way?</p>
<p> </p>
<p>Besides I would oike to ask where can I find a complete and detailed USER MANUAL. I have been searching everywhere and I can't find it. The Help files in my Mandriva don't cover this subject of copy-pasting where root privileges are requiered. Where is the up-to-date and detailed and complete Manual?</p>
<p> </p>
<p>Thanks</p>
<p> </p>
<p>EDIT: One more qustion. Many times I find answers but for Ubuntu. The Ubuntu code is not the same as the one for Mandriva, right? You need to learn either one or another but they don't work for the other, correct? I think that this makes Linux even harder and more atomized for finding help.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">74804</guid><pubDate>Tue, 25 Nov 2008 04:59:25 +0000</pubDate></item><item><title>More Specific Firewall Control?</title><link>https://mandrivausers.org/index.php?/topic/72834-more-specific-firewall-control/</link><description><![CDATA[
<p>Hi all,</p>
<p> </p>
<p>Mandriva 2009. average noob here,  I'm new to Linux but we originally set it up here in our office (about 10 Windows XP users) to use as a file server.  The Samba works great.</p>
<p> </p>
<p>Since then we've started using it as an internet gateway also to share our cable modem connection.  Internet goes in Eth1 and out Eth0 to the hub.  We use the firewall to deny certain employees access to things like http and gnutella BUT still allow them to access SMTP and IM (because we use IM in the office.)  Other employees who don't abuse the internet get to keep http and gnutella. BTW I use Firestarter to control the firewall.</p>
<p> </p>
<p>What I want to know is there a way I can say a specific lan IP (Example: 192.168.2.100) is denied a connection to Myspace.com.  I don't want to block myspace.com for all employees because not ALL employees abuse the privilege of moderate internet use during breaks and lunch and such.</p>
<p> </p>
<p>I would like to be able to do this WITH firestarter because I'm not so great in the CLI, but if I have to use the CLI is there a way to make that change there but still keep firestarter, or will I have to through out firestarter all together and start editing the IPTABLES by hand all the time?</p>
<p> </p>
<p>Thanks in Advance!</p>
<p> </p>
<p>Beeson</p>
]]></description><guid isPermaLink="false">72834</guid><pubDate>Tue, 04 Nov 2008 04:19:27 +0000</pubDate></item><item><title>Mandriva changes my WPA password</title><link>https://mandrivausers.org/index.php?/topic/72564-mandriva-changes-my-wpa-password/</link><description><![CDATA[
<p>Hi</p>
<p> </p>
<p>I'm returning to Mandriva after installing 2009 One on a desktop and spare lappy; very impressed but with one problem that has me pulling my hair out. My wireless network is secured using WPA/PSK using a combination of numbers and uppercase letters. However, no matter what I do the configuration console immediately changes the letters to lowercase, so no way to connect. Just to test I setup a temporary network with a wholly lowercase password, no problems at all. I cannot change the password on the network as it affects too many people, plus it is such a silly problem I cannot be the first to experience it, surely?</p>
<p> </p>
<p>Any help appreciated, thanks.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">72564</guid><pubDate>Sat, 01 Nov 2008 14:17:10 +0000</pubDate></item><item><title>Parental control in Mandriva 2009</title><link>https://mandrivausers.org/index.php?/topic/71064-parental-control-in-mandriva-2009/</link><description><![CDATA[
<p>How do you reset the default High control level in the MCC? I want the setting to be normal, but every time I reset it, it goes back to high.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">71064</guid><pubDate>Sun, 19 Oct 2008 02:07:33 +0000</pubDate></item><item><title>Viruses in Linux</title><link>https://mandrivausers.org/index.php?/topic/68404-viruses-in-linux/</link><description><![CDATA[
<p>I'm an unexperienced user and new to Linux. But I know it as reliable and secure OS. Sometimes I can find some viruses on my computer - namely in wine and it's no wonder. But the other day I felt a bit confused -  for training reasons I was scanning my computer with Clamav and to my astonishment it found 33 infected files. And where?! In  /usr!!!  I traced the whole path - /usr/share/doc/clamav/test. There were 33 infected Windows files there:</p>
<p> </p>
<p> </p>
<p>----------- SCAN SUMMARY -----------</p>
<p>Known viruses: 428525</p>
<p>Engine version: 0.94</p>
<p>Scanned directories: 2</p>
<p>Scanned files: 103</p>
<p>Infected files: 33</p>
<p>Data scanned: 1.30 MB</p>
<p>Time: 3.655 sec (0 m 3 s)</p>
<p>[randolph@localhost ~]$         </p>
<p> </p>
<p>I don't think there's any danger to my Mandriva. Most probably these viruses are to be there for some reason, but which one I have no idea. I wish someone   would shed light on the issue.</p>
]]></description><guid isPermaLink="false">68404</guid><pubDate>Sat, 20 Sep 2008 10:21:57 +0000</pubDate></item><item><title><![CDATA[KDE Login & GPG Passphrase Prompt]]></title><link>https://mandrivausers.org/index.php?/topic/65234-kde-login-gpg-passphrase-prompt/</link><description><![CDATA[
<p>I feel embarrassed at having to ask this, as it's something I should either know or at least be able to find out by myself...</p>
<p> </p>
<p>I installed 2008.1 on my new laptop about 6 weeks ago. Last week, I realized that I hadn't copied my GPG keys over from my previous install. I retrieved the keys (I have 1 for personal use, 1 for work use) etc from my pre-upgrade backup and checked to make sure I could sign and encrypt plain text files with the keys.</p>
<p> </p>
<p>Ever since then, whenever I log in to KDE, I get prompted for the passphrase for my personal GPG key. Where does this get launched from and how can I switch it off? I've trawled around in the startup scripts that I think are relevant, but I can't find anywhere that the prompt might be getting generated.  <img src="https://mandrivausers.org/uploads/emoticons/default_embarassed.gif" alt=":embarassed:" data-emoticon="" /></p>
]]></description><guid isPermaLink="false">65234</guid><pubDate>Tue, 05 Aug 2008 13:42:37 +0000</pubDate></item><item><title>Stopping Shorewall blocks access to the computer</title><link>https://mandrivausers.org/index.php?/topic/63954-stopping-shorewall-blocks-access-to-the-computer/</link><description><![CDATA[<p>I have an ssh server running on my laptop behind the firewall (shorewall). With firewall running, everything is fine, and I can connect to the machine via ssh just fine. However, shutting down the shorewall service on the laptop prevents other computers from connecting to ssh server. This does not look logical to me.... Why is this happening? What is blocking connections? I need to be able to test certain things with shorewall down.</p>]]></description><guid isPermaLink="false">63954</guid><pubDate>Mon, 21 Jul 2008 07:53:24 +0000</pubDate></item><item><title>gpg: no ultimately trusted keys found</title><link>https://mandrivausers.org/index.php?/topic/59134-gpg-no-ultimately-trusted-keys-found/</link><description><![CDATA[
<p>Hi</p>
<p> </p>
<p>as a normal user then as root user I ran</p>
<p> </p>
<p>gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98</p>
<p>gpg: requesting key 22458A98 from hkp server pgp.mit.edu</p>
<p>gpg: key 22458A98: duplicated user ID detected - merged</p>
<p>gpg: key 22458A98: public key "Mandriva Security Team &lt;security@mandriva.com&gt;" imported</p>
<p>gpg: no ultimately trusted keys found</p>
<p>gpg: Total number processed: 1</p>
<p>gpg:               imported: 1</p>
<p> su</p>
<p>Password:</p>
<p>[root@]# gpg --recv-keys --keyserver pgp.mit.edu 0x22458A98</p>
<p>gpg: keyring `/root/.gnupg/secring.gpg' created</p>
<p>gpg: requesting key 22458A98 from hkp server pgp.mit.edu</p>
<p>gpg: key 22458A98: duplicated user ID detected - merged</p>
<p>gpg: key 22458A98: public key "Mandriva Security Team &lt;security@mandriva.com&gt;" imported</p>
<p>gpg: no ultimately trusted keys found</p>
<p>gpg: Total number processed: 1</p>
<p>gpg:               imported: 1</p>
<p> </p>
<p>My question (s) should I be concerned that gpg is responding with gpg: no ultimately trusted keys found</p>
<p> </p>
<p>thanks in advance for your time in explaining this to me.</p>
]]></description><guid isPermaLink="false">59134</guid><pubDate>Sat, 24 May 2008 14:03:00 +0000</pubDate></item><item><title>Sudo rejects correct password [solved]</title><link>https://mandrivausers.org/index.php?/topic/61444-sudo-rejects-correct-password-solved/</link><description><![CDATA[
<p>As the title says even when the correct password is entered sudo rejects it. I have been to the sudo website and had a look at the faq and sure enough the question has been asked. The answer is that the 'config.h'  maybe missing a definition. Now here is the problem, I don't have a 'config.h' for sudo. The only config.h's are for my own c programs. Anybody able to help this gray haired old fogey out please?</p>
<p>Thank You in advance.</p>
]]></description><guid isPermaLink="false">61444</guid><pubDate>Thu, 19 Jun 2008 22:42:50 +0000</pubDate></item><item><title>how to secure laptop against theft</title><link>https://mandrivausers.org/index.php?/topic/61114-how-to-secure-laptop-against-theft/</link><description><![CDATA[
<p>Well I have a new laptop again after my old other, almost brand new one, got stolen. What can I do to make it hard for thieves? Michaelcole recommended no-ip but are there any additional measures so I can trace any potential thieve, take control of my laptop remotely, take pictutes of them etc? </p>
<p> </p>
<p>What to do with bios? Add a password or let it boot into any traps set? How to prevent them from removing any installed OS etc</p>
]]></description><guid isPermaLink="false">61114</guid><pubDate>Sun, 15 Jun 2008 13:17:01 +0000</pubDate></item><item><title><![CDATA[How do I password protect & encrypt file archive?]]></title><link>https://mandrivausers.org/index.php?/topic/59454-how-do-i-password-protect-encrypt-file-archive/</link><description><![CDATA[
<p>Hello</p>
<p> </p>
<p>I am using Mandriva 2008 Spring KDE One. I want to know how to password protect and encrypt file archives, preferrably using the GUI.</p>
<p> </p>
<p>Ark doesn't seem to be able to do this.</p>
<p> </p>
<p>Please tell me how to do this.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Software by spinynorman]</span></p>
]]></description><guid isPermaLink="false">59454</guid><pubDate>Wed, 28 May 2008 07:55:14 +0000</pubDate></item><item><title>Purpose of sync, adm, uucp, operator system users</title><link>https://mandrivausers.org/index.php?/topic/58814-purpose-of-sync-adm-uucp-operator-system-users/</link><description><![CDATA[
<p>Mandriva's default /etc/passwd and /etc/group list users and groups for various system users. The reason for some is obvious from their name (squid for the suid proxy; postfix to run the postfix mail-system, etc), but I wonder about the need for the following users: adm, sync, operator, uucp, news, games. None of them own files. Anybody who can explain these users and whether they can be deleted from the system? </p>
<p> </p>
<p>The same applies to <em>groups</em> news, games. Surprisingly the group uucp owns some ttys in /dev/tty (I always thought uucp was the uold unix-to-unix-copy mail transfer system).</p>
]]></description><guid isPermaLink="false">58814</guid><pubDate>Sun, 18 May 2008 10:39:04 +0000</pubDate></item><item><title>Login Users List [solved]</title><link>https://mandrivausers.org/index.php?/topic/57044-login-users-list-solved/</link><description><![CDATA[
<p>I've been banging my  head against the wall trying to figure this out. I have three users configured, one for each of my kids and one for myself. Upon bootup, I only want to display their names in the users list, but still be able to type in my login name and password. Can this be done? I have the kids accounts setup with parental controls and want to go this extra step to hide my login name "so they can't start trying to guess my password".</p>
<p> </p>
<p>Any ideas.</p>
]]></description><guid isPermaLink="false">57044</guid><pubDate>Mon, 28 Apr 2008 01:31:09 +0000</pubDate></item><item><title>Masking I.P. address under Mandriva - Firefox</title><link>https://mandrivausers.org/index.php?/topic/56694-masking-ip-address-under-mandriva-firefox/</link><description><![CDATA[
<p>Helloo   and   greetings   to   everyone,</p>
<p> </p>
<p>                   I    would    really   appreciate     some     assistance    on    the     following    issue:</p>
<p> </p>
<p>  Can    you   give   me  a   hint   of  How  can  I   effectivelly <span style="text-decoration:underline;">  </span><span style="text-decoration:underline;"><strong>Hide  my  i.p.</strong></span><span style="text-decoration:underline;"> </span>   address  under     Mandriva/Firefox    while    browsing    and   sending    e-mail.</p>
<p> </p>
<p>                          <img src="https://mandrivausers.org/uploads/emoticons/default_help.gif" alt=":help:" data-emoticon="" /></p>
<p> </p>
<p>                                Thank  you.</p>
]]></description><guid isPermaLink="false">56694</guid><pubDate>Fri, 25 Apr 2008 12:50:45 +0000</pubDate></item><item><title>Someone is port scanning me</title><link>https://mandrivausers.org/index.php?/topic/56134-someone-is-port-scanning-me/</link><description><![CDATA[<p>pawel.t17.des.pwr.wroc.pl port scanned me 12 times over a period of 3 minutes according to "interactive firewall." Should I be worried about this? Would it alert me if he found any open ports?</p>]]></description><guid isPermaLink="false">56134</guid><pubDate>Sat, 19 Apr 2008 13:25:34 +0000</pubDate></item><item><title>symbolic link /home/guest points to my home dir?</title><link>https://mandrivausers.org/index.php?/topic/56484-symbolic-link-homeguest-points-to-my-home-dir/</link><description><![CDATA[<p>I just noticed that there's a link in the home dir called guest that points to my home dir... is that  needed in mandriva? i've tried a few other linux distros and never saw that before....</p>]]></description><guid isPermaLink="false">56484</guid><pubDate>Wed, 23 Apr 2008 10:46:13 +0000</pubDate></item><item><title>wifi security info</title><link>https://mandrivausers.org/index.php?/topic/51244-wifi-security-info/</link><description><![CDATA[
<p>I've avoided wifi until now because I'm pretty sure that I read somewhere of security problems with it; it's now probably time to bite the bullet, however :unsure: .  I've read the wifi-wiki, but would like to get hold of some more up-to-date info on security aspects before jumping in the deep end. Could anyone point me to a suitable source, please? Thanks.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Hardware by spinynorman]</span></p>
]]></description><guid isPermaLink="false">51244</guid><pubDate>Fri, 29 Feb 2008 18:16:18 +0000</pubDate></item><item><title>Strange goings-on in my 2006 box</title><link>https://mandrivausers.org/index.php?/topic/55114-strange-goings-on-in-my-2006-box/</link><description><![CDATA[
<p>I've just spent the last 10 minutes watching the CPU-history graph (Gnome System-monitor),  on my Tosh Sat Pro 4600 box running mva 2006. Interestingly  :unsure: , the CPU load is around 90% for about 45 seconds every minute. Only firefox, kwrite and system-monitor are running, the LAN is down (cable even removed) and, according to my understanding of computers/OS's, the machine should be just idling along at about 5-10%.  If this were Windoze I'd be panicking and reaching for the AV, but that, according to this post <a href="https://mandrivausers.org/index.php?showtopic=41909&amp;hl=anti-virus" rel="external nofollow">https://mandrivausers.org/index.php?showtop...p;hl=anti-virus</a>, </p>
<p>is unnecessary in a linux setup. Am I becoming paranoid, or somthing? How likely is it that I've got some 'uninvited friend'  ;)  running about in the box? </p>
<p> </p>
<p>If anyone could provide to this simple soul an explanation of what's going on (which might also reduce my state of concern), that would be greatly appreciated. Thanks.</p>
]]></description><guid isPermaLink="false">55114</guid><pubDate>Wed, 09 Apr 2008 17:11:07 +0000</pubDate></item><item><title>Why are root logins not allowed? [solved]</title><link>https://mandrivausers.org/index.php?/topic/55164-why-are-root-logins-not-allowed-solved/</link><description><![CDATA[
<p>I'm embarrased to have to ask this question, for I have been using MAndiva One 2008 for a few months now.  Why are root log ins not allowed in Mandriva??  </p>
<p> </p>
<p>I downloaded and installed Picasa, but it won't work. I uninstalled using thepackage manager, but the menu entry is still there under "graphics-[+]other"  I tried to delete both the Picasa launch entry and the "[+]other" folded it resides in, but when I go to save the file, it won't write to the menu because I don't have permission. I tried opening a terminal within the /.config folder, and entered "su", then my root password, but it still wouldn't  give me access to the folded (that has worked for me in the past).</p>
<p> </p>
<p>Again, whay are root log ins not allowed in Mandriva???... I haven't had this problem with other distros.  I prefer Mandriva over PCLOS, but things are easier to configure in PCLOS. Any help would be sincerely appreciated.</p>
<p> </p>
<p>Note: I did quicly red through the FAQ's. I wasn't sure where in the forum to post this question. I apologize if I picked the wrong place.</p>
]]></description><guid isPermaLink="false">55164</guid><pubDate>Wed, 09 Apr 2008 22:50:46 +0000</pubDate></item><item><title>Shorewall [solved]</title><link>https://mandrivausers.org/index.php?/topic/53104-shorewall-solved/</link><description><![CDATA[
<p>I have never fully understood firewalls, and I have more chance of grasping string theory than iptables, so I wanted to check if my thoughts on Shorewall are correct.</p>
<p> </p>
<p>When I lived in windowsland, I always used Sygate or Zone Alarm, when I moved to Linux I mostly used Firestarter. All three have one thing in common, they include a system tray icon. I recently ditched Firestarter on Mandriva in favour of the default Shorewall, and have found it to be very good (for me anyway) since it requires little or no configuration to make it work, it works well (according to Shields Up ), it starts automatically and it protects several interfaces (eth0,wlan0, ppp0). But boy do I miss that tray icon. For one thing it at least tells you that the firewall is running. I know I can check if the service is running with 'ps aux' or by looking in MCC, but that is a bit of a pain. Supposing the service failed to start, would I get any warning if I don't look for myself?? Then there is the possibility that the service might stop whilst in use (this happened regularly with Firestarter, usually when I changed interfaces and forgot to restart it).</p>
<p> </p>
<p>I know Shorewall is an iptables front end, and I assume/hope that I am correct in the assumption that once it has set the iptable rules on start up, then even if the service itself failed the iptable rules would still be in place and therefore the machine would still be firewalled - is this correct? Secondly is there an easier way to know that the service has started in the first place or perhaps more importantly if it hasn't started in the first place?</p>
]]></description><guid isPermaLink="false">53104</guid><pubDate>Mon, 17 Mar 2008 11:03:07 +0000</pubDate></item><item><title>Mandi daemon crashing</title><link>https://mandrivausers.org/index.php?/topic/31739-mandi-daemon-crashing/</link><description><![CDATA[
<p>Hi.</p>
<p> </p>
<p>I'm just wondering if someone has had similar problems. Ok, here's the situation:</p>
<p> </p>
<p>I already have shorewall up and running and I'm gonna install mandi and mandi-ifw now. The main thing why I'm asking this is that I want to have an Interactive Firewall (mandi-ifw). So:</p>
<p> </p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="forums" data-ipsquote-contenttype="forums" data-ipsquote-contentid="31739" data-ipsquote-contentclass="forums_Topic"><div>su root<p>&lt;my_pwd&gt;</p>
<p>urpmi mandi mandi-ifw</p>
</div></blockquote>
<p>This part goes like it should, but problems start from here:</p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="forums" data-ipsquote-contenttype="forums" data-ipsquote-contentid="31739" data-ipsquote-contentclass="forums_Topic"><div># service mandi start<p>Starting mandi daemon: mandi_daemon_add_watch(): READABLE</p>
<p>unable to open white list file</p>
<p>nl_bind_socket: No such file or directory</p>
<p>bind failed</p>
<p>unable to init netlink</p>
<p>unable to init "Interactive Firewall" plugin                                      [FAILED]</p>
</div></blockquote>
<p> </p>
<p>Whitelist? Where should it be? I created a file called "whitelist" to /etc/shorewall but it didn't make things any better.</p>
<p>I'm using ra0 to connect to the internet, but capability for eth0 usage would be great too, as I use it sometimes.</p>
]]></description><guid isPermaLink="false">31739</guid><pubDate>Wed, 05 Apr 2006 20:54:59 +0000</pubDate></item><item><title>block access to user's home folder [solved]</title><link>https://mandrivausers.org/index.php?/topic/52884-block-access-to-users-home-folder-solved/</link><description><![CDATA[
<p>Not sure if this is technically networking, but would like to block access to one user's home folder on the same PC. I have poked around with permissions, ownership, sharing, etc. Google returns file sharing between Windows and linux which is NOT what I'm doing.</p>
<p> </p>
<p>Under Konqueror's navigation bar in home folders:</p>
<p> </p>
<p>when logged in as user1, user1 has no access to user2 home directory</p>
<p>when logged in as user2, user2 has complete access to  user1 home directory and subfolders.</p>
<p> </p>
<p>I want user2 to have access to his own folders but no access to user1 home folder.</p>
<p> </p>
<p>In addition to  access to his own  (user2) home folder,  I want to block access to 3 of the subdirectories,  but no luck. I thought about encryption  but it seems excessive.</p>
<p> </p>
<p> </p>
<p>Any help appreciated.</p>
<p> </p>
<p> </p>
<p><span style="font-size:8px;">[moved from Networking by spinynorman]</span></p>
]]></description><guid isPermaLink="false">52884</guid><pubDate>Sat, 15 Mar 2008 04:13:29 +0000</pubDate></item><item><title><![CDATA[Firewall setup with free chat & voice comm server]]></title><link>https://mandrivausers.org/index.php?/topic/52334-firewall-setup-with-free-chat-voice-comm-server/</link><description><![CDATA[
<p>Dear friends,</p>
<p> </p>
<p>I am a network system administrator and I use Kernel 2.6 and iptables as a firewall and NAT.  My company decided to install a Windows application called CYF (CALL YOU FREE) in all the desktops of the customer support and sales department.   CALL YOU FREE is a communications application to answer incoming webcalls and chat contacts from our companyâ€™s website and we are using its freeware version.</p>
<p> </p>
<p>The issue is that when I tested the application with my computer connected directly to the internet (public IP) it works fine.  But when I connected my computer in a private IP behind the NAT I cannot even login to the system.</p>
<p> </p>
<p>I conclude that there must be a firewall problem, so I opened all ports in the firewall and it works fine.</p>
<p> </p>
<p>I would like to know how I can find out what port(s) does the application try to access.   It seems to be an Asterisk based application using IAX protocol so I tried opening port 4569 but nothing happened.</p>
<p> </p>
<p>I would appreciate your help because I really donâ€™t know how to find out what port should I open, unless I try one by one, or it may use yet more than one port.</p>
<p> </p>
<p>Thanks,</p>
<p>Ricardo Houssef.</p>
]]></description><guid isPermaLink="false">52334</guid><pubDate>Mon, 10 Mar 2008 19:51:10 +0000</pubDate></item><item><title>File permissions on LAN</title><link>https://mandrivausers.org/index.php?/topic/52084-file-permissions-on-lan/</link><description><![CDATA[
<p>PC1 Mandrake 10.2 @ 192.168.10.1</p>
<p>PC2 Mandriva2008 @ 192.168.10.2</p>
<p> </p>
<p>Connected on local LAN via ssh. I access files between the two PCs by invoking sftp://&lt;address&gt; from within Konqueror.</p>
<p> </p>
<p>I would like to allow office staff to use PC2/scanner combo to update  one or two specific folders inside the <strong>home</strong> folder on PC1. I do not want them to have access to other folders within my <strong>home</strong> folder. I tried setting permissions on all the folders I want protected, but when I ssh in to PC1 from PC2, I am able to access all <strong>home</strong> folders on PC1....BAD!  Any ideas on the best way to do this?</p>
<p> </p>
<p>Should I copy the one or two folders I want updated from PC1 to PC2 and then let them live on PC2 and be updated from there in which case I could then copy the folders back from PC2 to PC1, but then I would not know to what extent each file or folder within these directories had been updated. I suppose that when I copy these folders back to the original, Konq will alert me that some of the original folders and files already exist and I can choose to either overwrite all or autoskip files that are original, but this seems kind of sloppy and makes me nervous. </p>
<p> </p>
<p> Or should I leave these folders on PC1 and attempt to scan (using xsane) to to PC1 from PC2  . I don't even know if xsane will do this, but I can try. ( there are about 6-10 folders within each of these two main directories I want worked on, and they are nested about 4-6 folders deep within each of those.)</p>
<p> </p>
<p>Any suggestions on how to do this neatly without having scanned docs spread out on two PCs would be welcome. My main goal however is to limit access to only certain folders. If I copy those working folders to PC2, then my permissions issues are moot, but would still like to know how to do it.</p>
<p> </p>
<p>Thanks</p>
]]></description><guid isPermaLink="false">52084</guid><pubDate>Sat, 08 Mar 2008 02:48:48 +0000</pubDate></item><item><title>make linux a security server</title><link>https://mandrivausers.org/index.php?/topic/51114-make-linux-a-security-server/</link><description><![CDATA[
<p>hi, </p>
<p>i want to make one of my computers into a firewall / router / AV server for all my computers in the home network. </p>
<p>i found how to make mandriva a DNS server / FTP server but i couldn't find how to make it a security server.</p>
<p> </p>
<p>if it possible i would like to get some tutorials.</p>
<p> </p>
<p>thanks,</p>
<p>igotnoluck ;)</p>
]]></description><guid isPermaLink="false">51114</guid><pubDate>Wed, 27 Feb 2008 22:27:55 +0000</pubDate></item></channel></rss>
