<rss version="2.0"><channel><title>Security Basics (basics) Mailing List</title>
<link>http://seclists.org/#basics</link>
<description>A high-volume list which permits people to ask &quot;stupid questions&quot; without being derided as &quot;n00bs&quot;.  I recommend this list to network security newbies, but be sure to read Bugtraq and other lists as well.</description>
<language>en-us</language><ttl>60</ttl>
<item><title>RE: DNS flaw for home users...</title><description>Posted by Murda Mcloud on Jul 24&lt;p&gt;


&lt;p&gt;
Bit of searching netted me this on Kaminsky&#39;s site:
&lt;br /&gt;
&lt;p&gt;http://www.doxpara.com/ 
&lt;br /&gt;
Click on the DNS checker. 
&lt;br /&gt;
Also here:
&lt;br /&gt;
https://www.dns-oarc.net/
&lt;br /&gt;
&lt;p&gt;the second one gives pretty graphs.
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;&lt;p&gt;&lt;p&gt;&amp;gt; &amp;gt;-----Original Message-----
&lt;br /&gt;
&amp;gt; &amp;gt;From: Murda Mcloud [mailto:murdamcloud_at_bigpond&amp;#46;com]
&lt;br /&gt;
&amp;gt;...</description>
<link>http://seclists.org/basics/2008/Jul/0280.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0280.html</guid>
<pubDate>Thu, 24 Jul 2008 13:42:44 +1000</pubDate></item>
<item><title>DNS flaw for home users...</title><description>Posted by Murda Mcloud on Jul 24&lt;p&gt;


&lt;p&gt;
With all the brouhaha surrounding the DNS flaw that Dan Kaminsky has hinted
&lt;br /&gt;
at and others have &#39;accidentally&#39; disclosed or stumbled upon, what kind of
&lt;br /&gt;
advice would you be giving to home users?
&lt;br /&gt;
&lt;p&gt;Obviously the whole push is towards patching and trying to do that before
&lt;br /&gt;
the evil ones work out how...</description>
<link>http://seclists.org/basics/2008/Jul/0279.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0279.html</guid>
<pubDate>Thu, 24 Jul 2008 11:16:20 +1000</pubDate></item>
<item><title>Firefox GPO Restrictions</title><description>Posted by Lafosse Ricardo on Jul 23&lt;p&gt;


&lt;p&gt;
Hello all,
&lt;br /&gt;
&lt;p&gt;I am working on restricting user options in Firefox via GPO; however all
&lt;br /&gt;
the Firefox ADM templates that I have utilized have not worked. These
&lt;br /&gt;
templates include: wetdog, firefoxadm (from sourceforge), and firefoxadm
&lt;br /&gt;
(from frontmotion). The users are using Firefox 2.0.0.16. Any
&lt;br /&gt;...</description>
<link>http://seclists.org/basics/2008/Jul/0278.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0278.html</guid>
<pubDate>Wed, 23 Jul 2008 15:45:54 -0400</pubDate></item>
<item><title>RE: College Courses for Info Sec or Certificates or Both?</title><description>Posted by William Mohney on Jul 23&lt;p&gt;


&lt;p&gt;
Here is the bottom line information related to experience for the
&lt;br /&gt;
various certs from ISC2
&lt;br /&gt;
&lt;p&gt;https://www.isc2.org/cgi-bin/content.cgi?category=1187
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;Bill  
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;-----Original Message-----
&lt;br /&gt;
From: listbounce_at_securityfocus&amp;#46;com [mailto:listbounce_at_securityfocus&amp;#46;com]
&lt;br /&gt;
On Behalf Of Krzyston,...</description>
<link>http://seclists.org/basics/2008/Jul/0277.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0277.html</guid>
<pubDate>Wed, 23 Jul 2008 10:54:00 -0500</pubDate></item>
<item><title>netqmail-1.06 CNAME_lookup_failed_temporarily._(4.4.3)</title><description>Posted by razi garbie on Jul 24&lt;p&gt;


&lt;p&gt;
Hi list,
&lt;br /&gt;
&lt;p&gt;In my send log i keep getting CNAME_lookup_failed_temporarily for a
&lt;br /&gt;
particular domain.
&lt;br /&gt;
&lt;p&gt;2008-07-24 08:56:20.409984500 info msg 3670583: bytes 1022 from
&lt;br /&gt;
&amp;lt;me_at_mydomain&amp;#46;com&amp;gt; qp 5699 uid 64011
&lt;br /&gt;
2008-07-24 08:56:20.522038500 starting delivery 92112: msg 3670583 to
&lt;br /&gt;
remote...</description>
<link>http://seclists.org/basics/2008/Jul/0276.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0276.html</guid>
<pubDate>Thu, 24 Jul 2008 11:03:54 +0200</pubDate></item>
<item><title>RE: How to run a non proxy enabled application through a proxy?</title><description>Posted by Troy Robinson on Jul 24&lt;p&gt;


&lt;p&gt;
Depending on the application, you may find proxychains another useful tool.
&lt;br /&gt;
&lt;p&gt;http://proxychains.sourceforge.net/
&lt;br /&gt;
&lt;p&gt;You configure proxychains.conf with the proxy server details as needed, then
&lt;br /&gt;
you can execute the application through proxychains:
&lt;br /&gt;
&lt;p&gt;To run an nmap scan
&lt;br /&gt;
proxychains nmap -P0 host -p...</description>
<link>http://seclists.org/basics/2008/Jul/0275.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0275.html</guid>
<pubDate>Thu, 24 Jul 2008 13:09:51 +1000</pubDate></item>
<item><title>Re: Nmap questions for the experts</title><description>Posted by Javier Reyna Padilla on Jul 23&lt;p&gt;


&lt;p&gt;
Just  few comments:
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;Javier Reyna
&lt;br /&gt;
&lt;p&gt;mark mark wrote:
&lt;br /&gt;
&amp;gt; Hi,
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; I have some questions regarding nmap. I&#39;m not sure if this is the
&lt;br /&gt;
&amp;gt; proper list, i just searched google and found some people asking
&lt;br /&gt;
&amp;gt; nmap-related questions here. Anyway, here are my questions:
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; 1....</description>
<link>http://seclists.org/basics/2008/Jul/0274.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0274.html</guid>
<pubDate>Wed, 23 Jul 2008 11:40:53 -0500</pubDate></item>
<item><title>Re: College Courses for Info Sec or Certificates or Both?</title><description>Posted by Patrick J Kobly on Jul 23&lt;p&gt;


&lt;p&gt;
Not quite...  Certification requirements have changed a bit in the last 
&lt;br /&gt;
year...  Check out 
&lt;br /&gt;
https://www.isc2.org/cgi-bin/content.cgi?category=1187.  The requirement 
&lt;br /&gt;
for the endorser also changed to require an (ISC)^2 member (any of their 
&lt;br /&gt;
certs) to endorse your application.  (You used to be...</description>
<link>http://seclists.org/basics/2008/Jul/0273.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0273.html</guid>
<pubDate>Wed, 23 Jul 2008 10:14:09 -0600</pubDate></item>
<item><title>Re: Checkpoint or other Solution required</title><description>Posted by Javier Reyna Padilla on Jul 23&lt;p&gt;


&lt;p&gt;
You can check e-mail content using smtp-resources, but this is not a 
&lt;br /&gt;
solution for inspecting a large volume of messages, your FW will be 
&lt;br /&gt;
overloaded for sure.You can check email content usin an IPS such as ISS 
&lt;br /&gt;
Provent&iacute;a, snort_inline, tipping point,  an antispam sucha as barracuda 
&lt;br /&gt;
spam...</description>
<link>http://seclists.org/basics/2008/Jul/0272.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0272.html</guid>
<pubDate>Wed, 23 Jul 2008 11:32:55 -0500</pubDate></item>
<item><title>Re: Call cabins with VoIP</title><description>Posted by Shawn Merdinger on Jul 22&lt;p&gt;


&lt;p&gt;
Hola Diego,
&lt;br /&gt;
&lt;p&gt;If the cabins are within wifi reach of each other, you might look into
&lt;br /&gt;
doing a mesh network with Linksys WRT-54G routers running Sveasoft in
&lt;br /&gt;
WDS mode.  Then you can place a router in each cabin with a VoIP phone
&lt;br /&gt;
or an ATA adapter and regular phone.  Off the main router you have a
&lt;br /&gt;...</description>
<link>http://seclists.org/basics/2008/Jul/0271.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0271.html</guid>
<pubDate>Tue, 22 Jul 2008 20:38:07 -0600</pubDate></item>
<item><title>RE: College Courses for Info Sec or Certificates or Both?</title><description>Posted by Brandon Louder on Jul 23&lt;p&gt;


&lt;p&gt;
That is correct. 5 years experience in 1 of the 10 domains or 4 years
&lt;br /&gt;
and the Security+. 
&lt;br /&gt;
&lt;p&gt;-----Original Message-----
&lt;br /&gt;
From: listbounce_at_securityfocus&amp;#46;com [mailto:listbounce_at_securityfocus&amp;#46;com]
&lt;br /&gt;
On Behalf Of Krzyston, Randy
&lt;br /&gt;
Sent: Tuesday, July 22, 2008 10:38 AM
&lt;br /&gt;
To:...</description>
<link>http://seclists.org/basics/2008/Jul/0270.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0270.html</guid>
<pubDate>Wed, 23 Jul 2008 09:52:07 -0500</pubDate></item>
<item><title>Nmap questions for the experts</title><description>Posted by mark mark on Jul 23&lt;p&gt;


&lt;p&gt;
Hi,
&lt;br /&gt;
&lt;p&gt;I have some questions regarding nmap. I&#39;m not sure if this is the
&lt;br /&gt;
proper list, i just searched google and found some people asking
&lt;br /&gt;
nmap-related questions here. Anyway, here are my questions:
&lt;br /&gt;
&lt;p&gt;&lt;p&gt;1. Is there any way I can specify two different source port for nmap&#39;s
&lt;br /&gt;
-g when doing a TCP and...</description>
<link>http://seclists.org/basics/2008/Jul/0269.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0269.html</guid>
<pubDate>Wed, 23 Jul 2008 11:56:43 +0400</pubDate></item>
<item><title>Re: Online Incident Response Management</title><description>Posted by Deepak Parashar on Jul 22&lt;p&gt;


&lt;p&gt;
would recommend to go with ISS.
&lt;br /&gt;
&lt;p&gt;-Deepak
&lt;br /&gt;
&lt;p&gt;On Tue, Jul 22, 2008 at 9:21 AM, Ramki B Ramakrishnan &amp;lt;bramkie_at_gmail&amp;#46;com&amp;gt; wrote:
&lt;br /&gt;
&amp;gt; You can also look at Cisco Systems MARS, it has case management.
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; http://www.cisco.com/go/mars
&lt;br /&gt;
&amp;gt;
&lt;br /&gt;
&amp;gt; Ramki
&lt;br /&gt;
&amp;gt; -----
&lt;br /&gt;
&amp;gt; Ramki B....</description>
<link>http://seclists.org/basics/2008/Jul/0268.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0268.html</guid>
<pubDate>Tue, 22 Jul 2008 22:02:53 -0400</pubDate></item>
<item><title>Re: College Courses for Info Sec or Certificates or Both?</title><description>Posted by Chuck Taylor on Jul 22&lt;p&gt;


&lt;p&gt;
Phil,
&lt;br /&gt;
&lt;p&gt;I think you should definitely go for your 4 year degree.  The 4 year
&lt;br /&gt;
degree is starting to become the minimum standard.  I am not saying that
&lt;br /&gt;
you cannot be successful without it, just saying that it is definitely
&lt;br /&gt;
something employers look for.  Not to mention that getting a 4 year
&lt;br /&gt;...</description>
<link>http://seclists.org/basics/2008/Jul/0267.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0267.html</guid>
<pubDate>Tue, 22 Jul 2008 16:22:56 -0400</pubDate></item>
<item><title>basic question about authentification</title><description>Posted by Yvon Thoraval on Jul 22&lt;p&gt;


&lt;p&gt;
Hey all,
&lt;br /&gt;
&lt;p&gt;new to ssh and scp I&#39;m doing files upload|download from a personal
&lt;br /&gt;
computer to an handheld mobile phone.
&lt;br /&gt;
on the computer side i&#39;m using OpenSSH as installed by Apple Mac OS X 10.4.11.
&lt;br /&gt;
on the other, an e2831 phone named &amp;quot;Twin-Tact&amp;quot; running QTopia, I&#39;ve
&lt;br /&gt;
installed by myself...</description>
<link>http://seclists.org/basics/2008/Jul/0266.html</link><guid isPermaLink="true">http://seclists.org/basics/2008/Jul/0266.html</guid>
<pubDate>Tue, 22 Jul 2008 19:03:50 +0200</pubDate></item>
</channel></rss>