[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]

[cobalt-users] UPDATE / VPN



I got the answer on my quest re: when will the major qub3 update be
available:  "March 2002" -- still not there...zzz.   BUT, I didn't get any
takers on my other question from a weekago sunday, so I repeat it here.
Thanks to anyone who can help:

From: "Phil Lewis" <phil@xxxxxxxxxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Date: Sun, 24 Feb 2002 14:44:44 -0800
Subject: [cobalt-users] VPN doesn't authenticate existing users
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

Has anyone else found that their Qube will not authenticate existing users
when they attempt to access via VPN?

Phil Lewis

-----Original Message-----
From: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]On Behalf Of
cobalt-users-request@xxxxxxxxxxxxxxx
Sent: Monday, March 04, 2002 10:19 PM
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: cobalt-users digest, Vol 1 #4113 - 18 msgs


Send cobalt-users mailing list submissions to
	cobalt-users@xxxxxxxxxxxxxxx

To subscribe or unsubscribe via the World Wide Web, visit
	http://list.cobalt.com/mailman/listinfo/cobalt-users
or, via email, send a message with subject or body 'help' to
	cobalt-users-request@xxxxxxxxxxxxxxx

You can reach the person managing the list at
	cobalt-users-admin@xxxxxxxxxxxxxxx

When replying, please edit your Subject line so it is more specific
than "Re: Contents of cobalt-users digest..."


Today's Topics:

   1. Re: Migration from Exchange (Malcolm McLeary)
   2. RE: Reboot after OS2 update for RAQ4? (Jim Carey)
   3. FS: 1GHz RaQ XTR System (Ammar T. Al-Sayegh)
   4. Raq cgi-bin Security Hole (tolgaraq)
   5. RE: Reboot after OS2 update for RAQ4? (Kevin)
   6. Re : [cobalt-users] RaQ4-en-OSUpdate-2.0.pkg - maillogs etc not
updating (johnm@xxxxxxxxxxxxxxxxxxxx)
   7. Fw: Site List disappeared on RaQ4 (DenIT Internet Services [Thijs])
   8. CGI problems (Chan YS)
   9. Admin Cd v1 released (Charles Williams)
  10. Re: Raq cgi-bin Security Hole (Wayne Sagar)
  11. RE: RAQ3 backup (Simon Pierce)
  12. RE: Registrar services (Dan Kriwitsky)
  13. RE: eZpublish on RAQ3 (Dan Kriwitsky)
  14. Warning -DO NOT DOWNLOAD GETRIGHT- (Wayne Sagar)
  15. RE: CGI problems (Dan Kriwitsky)
  16. Re: Raq cgi-bin Security Hole (Gerald Waugh)
  17. Re: FIX - can't su to root, email stopped working, gui stopped
working, postgres database is down, virtual sites disappeared (Gerald Waugh)
  18. Re: Perpetual mail locks on Qube2 (Alain LAROCHE)

--__--__--

Message: 1
Date: Tue, 05 Mar 2002 17:56:02 +1100
Subject: Re: [cobalt-users] Migration from Exchange
From: Malcolm McLeary <mmcleary@xxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

Hi Fraser,

on 5/3/02 5:15 PM, Blue Raq at raqblue@xxxxxxxxxxx wrote:

> I have a guy who wants to migrate his data from Exchange to an XTR. Does
> anyone know if this is easy to do and whether it can be done in one go
> rather than one by one? He has about 500 existing email accounts

Are you asking about the creation of the 500 new accounts or migrating the
legacy mail?

IMHO migrating the legacy mail is a user problem.  Create the new accounts
(probably accessible via IMAP) on the XTR and tell the users they have a x
days to move what they want from their old Exchange accounts to their new
account before the Exchange Server is taken offline permanently.

Cheers,  Malcolm


--__--__--

Message: 2
From: "Jim Carey" <ozbcoz@xxxxxxxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Subject: RE: [cobalt-users] Reboot after OS2 update for RAQ4?
Date: Tue, 5 Mar 2002 18:12:33 +1100
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

> > Does the RAQ 4 need a reboot after OS2 patch is applied?
> >
> http://www.cobalt.com/support/pdf/RaQ4-en-OSUpdate-Install.pdf
> RaQ4-en-OSUpdate-2.0
> Note: This update will reboot your system after it has finished
> installing.
> --
> Dan Kriwitsky
> 
>


it didnt reboot mine - also didnt show up in the installed list - but if I
try to install it again it says it is already there

strange

Jim Carey


--__--__--

Message: 3
From: "Ammar T. Al-Sayegh" <ammar@xxxxxxxxx>
To: "CobaltUsers" <cobalt-users@xxxxxxxxxxxxxxx>
Date: Tue, 5 Mar 2002 02:30:52 -0500
Subject: [cobalt-users] FS: 1GHz RaQ XTR System
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

Hello All,

I am selling my RaQ XTR server which I just bought a couple
of months ago. I listed it on eBay (Item # 2007686825):

http://cgi.ebay.com/aw-cgi/eBayISAPI.dll?ViewItem&item=2007686825

Feel free to email me if interested.

Thank you.


-ammar






--__--__--

Message: 4
Date: Mon, 4 Mar 2002 23:41:04 -0800 (PST)
From: tolgaraq <tolgaraq@xxxxxxxxx>
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: [cobalt-users] Raq cgi-bin Security Hole
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

When I use getright and enter url of any file in
cgi-bin getright succesfuly downloads it. And your cgi
files is open to anyone who knows it's file name.

Anyone know how to prevent it?


__________________________________________________
Do You Yahoo!?
Try FREE Yahoo! Mail - the world's greatest free email!
http://mail.yahoo.com/


--__--__--

Message: 5
From: "Kevin" <owner@xxxxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Subject: RE: [cobalt-users] Reboot after OS2 update for RAQ4?
Date: Tue, 5 Mar 2002 03:14:36 -0500
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

I was prompted to reboot my server after the install.
I also removed PHP 4.06 and Webalizer 1.3 before installing the OS2 Update.
After rebooting everything appeared fine.
I then added the new Webalizer and PHP 4.1.1
The next day I updated to the PHP 4.1.2
Closed Telnet and FTP and added the SSH package.

So far - So Good
Is there anything I should check for specifically?

Thanks,
Kevin


-----Original Message-----
From: cobalt-users-admin@xxxxxxxxxxxxxxx
[mailto:cobalt-users-admin@xxxxxxxxxxxxxxx]On Behalf Of Jim Carey
Sent: Tuesday, March 05, 2002 2:13 AM
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: RE: [cobalt-users] Reboot after OS2 update for RAQ4?


> > Does the RAQ 4 need a reboot after OS2 patch is applied?
> >
> http://www.cobalt.com/support/pdf/RaQ4-en-OSUpdate-Install.pdf
> RaQ4-en-OSUpdate-2.0
> Note: This update will reboot your system after it has finished
> installing.
> --
> Dan Kriwitsky
> 
>


it didnt reboot mine - also didnt show up in the installed list - but if I
try to install it again it says it is already there

strange

Jim Carey



--__--__--

Message: 6
From: johnm@xxxxxxxxxxxxxxxxxxxx
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: Re : [cobalt-users] RaQ4-en-OSUpdate-2.0.pkg - maillogs etc not
updating
Date: Tue, 5 Mar 2002 08:53:16 +0000
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

<snip>
>> This I think I can sort out but looking at the server the
>> maillog , auth
>> and secure logs have not been updated since the server was restarted.
</snip>

After the 4am cron jobs all the server logs have started being built
again.  I did wonder about running the daily cron jobs but decided against
it yesterday afternoon as this is a production server and I wasn't sure
what would happen if I ran the cron job during the day.  Still at least I
can see what is happening now.

Cheers

John


--__--__--

Message: 7
From: "DenIT Internet Services [Thijs]" <thijs@xxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Date: Tue, 5 Mar 2002 10:28:11 +0100
Subject: [cobalt-users] Fw: Site List disappeared on RaQ4
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

Dear List,

I've got a RaQ4 where all of a sudden the sitelist went missing! I tried
solving this with metaverify -sa and -si but to no avail! What could be
wrong here? What is happening?

How can this problem be solved?

Regards

Thijs Boonstra,
Systeem Beheer


--__--__--

Message: 8
From: "Chan YS" <chan@xxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Date: Tue, 5 Mar 2002 17:44:03 +0800
Subject: [cobalt-users] CGI problems
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

We need to process form inputs and send those information in an email.
However, even though the CGI script manages to run, I do not receive any
mail containing the form data.  I believe a function called FORMMAIL or
otherwise might be missing on the server.  How could I do to make it work?

Just to clarify, is it alright to put all the CGI script files (PHP and
PERL) into a self-created cgi-bin folder under the /web directory?

Chan YS.



--__--__--

Message: 9
From: "Charles Williams" <hosting.mailing.list.account@xxxxxxxxxxxxxxx>
To: <oliver.jaeckel@xxxxxxxxxxxxxxxxxxxx>,
<lids-user@xxxxxxxxxxxxxxxxxxxxx>,
        <isp-services@xxxxxxxx>, <isp-equipment@xxxxxxxxxxxxxxxxx>,
        <ipcop-user@xxxxxxxxxxxxxxxxxxxxx>,
        "IPCop Development" <ipcop-devel@xxxxxxxxxxxxxxxxxxxxx>,
        <cobalt-users@xxxxxxxxxxxxxxx>, "CIPE" <cipe-l@xxxxxxx>
Date: Tue, 5 Mar 2002 12:13:59 +0100
Subject: [cobalt-users] Admin Cd v1 released
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

Hey all,

I just posted the first version of Admin CD on my site.  You can check it
out here: http://www.slydder.homelinux.com/stories/op/storiesView/sid/72/

As soon as I can get the next drive consolidated I will update the image.

I will also be adding boot capabilities and some tools at a later date.

chuck




--__--__--

Message: 10
From: "Wayne Sagar" <shortfork@xxxxxxxxxxx>
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: Re: [cobalt-users] Raq cgi-bin Security Hole
Date: Tue, 05 Mar 2002 03:19:37 -0800
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

>When I use getright and enter url of any file in
>cgi-bin getright succesfuly downloads it. And your cgi
>files is open to anyone who knows it's file name.
>
>Anyone know how to prevent it?

Well yea, don't install that POS! I just did to check your "vulnerability"
it only excuted the files, did not download them, likely because I have all
of the files set to non-readable by anyone but the owner.. and then once I
saw that there was no danger, I uninstalled the POS and guess what... No
more browsers.. I can not access the net via MSIE, which I was running at
the time, Nor can I access it via Netscape, which I was not running at the
time. All I can access the net with is my webTV emulator used for testing
sites, and AOL, also used for testing sites. Both are accessing the net via
my cable modem, so it's not my connection. Email works, ssh works, ftp works
(I think) Yup.. FTP works.. But even after reinstalling windoze, I can not
get either browser to access the net.

What a miserable piece of sofware and I use that term VERY losely!

So my advise is.. geezus, if you have installed it.. god, leave it in or
you'll ruin your browsers.. if you have not DON'T !!!

Now.. how in hell I'm going to get this fixed I'll never know!

Damn, one of these days I'll learn not to believe everything I read on this
system!

VERY PISSED
WS!

_________________________________________________________________
MSN Photos is the easiest way to share and print your photos:
http://photos.msn.com/support/worldwide.aspx


--__--__--

Message: 11
From: "Simon Pierce" <simon@xxxxxxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Subject: RE: [cobalt-users] RAQ3 backup
Date: Tue, 5 Mar 2002 11:44:53 -0000
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

I don't know what you mean by tar -cvpf?

I know I'm asking a lot, but is it possible for someone edit the
instructions below so they are correct and optimised, or could you post your
method Mike?

I'm so so sorry about my ignorance!

Si

> >
> > 1)Telnet in and su to root.
> >
> > cd /etc
> > tar cvfW /home/etc.tar .
> > cd /var
> > tar cvfW /home/var.tar .
> > cd /usr/admserv
> > tar cvfW /home/usr-admserv.tar .
> > cd /usr/local
> > tar cvfW /home/usr-local.tar  .
>
> I would add the p switch to tar to save the permissions on all files.
>
> > /home/log/httpd/ # httpd log files
> > /home/spool/ # user mail spools and crontab spools
> > /root/ # root's user directory
> > /home/sites/ # site files and user files
> >
> > 2)FTP tars to a safe place.
> > 3)Disaster hits!!!!!!!!!
> > 4)Upload tars to a new RaQ
> >
> > Telnet in and su to root
> > cd /etc
> > tar xvf /home/sites/home/users/admin/etc.tar
> > cd /var
> > tar xvf /home/sites/home/users/admin/var.tar
> > cd /usr/admserv
> > tar xvf /home/sites/home/users/admin/usr-admserv.tar
> > cd /usr/local
> > tar xvf /home/sites/home/users/admin/usr-local.tar
> >

> We've tried the above method and it has worked nicely although don't
forget
> about /home .

> The command tar -cvpf will be better suited in order to keep the file
> permissions and ownership in tact.

> Mike


--__--__--

Message: 12
From: "Dan Kriwitsky" <webhosting@xxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Subject: RE: [cobalt-users] Registrar services
Date: Tue, 5 Mar 2002 06:53:28 -0500
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

 > I would and I know a lot of us would like to have current
> Opinions of Companies to use. and what to watch for as far a
> service and rip off artist.
>
Please reply off list or start a thread at www.webhostingtalk.com for
this OT issue.


_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com


--__--__--

Message: 13
From: "Dan Kriwitsky" <webhosting@xxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Subject: RE: [cobalt-users] eZpublish on RAQ3
Date: Tue, 5 Mar 2002 07:06:43 -0500
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

 I dont think I changed anything in the file itself (httpd.conf) exept
add an include statement to go to another file (extrasites.conf). on
restarting the server, it tells me there is an error in extrafiles.conf
on the line which has the following:
   RewriteRule ^/filemanager/filedownload/([^/]+)/(.*)$
I don't know if that would have anything to do with the rest of the
server but..it might help in the diagnosis.  Please help.

__________
Reply:

What is the virtual host content of one of the sites you added to
extrafiles.conf?

I would simply remove that Rewrite line from your extrafiles.conf and
restart httpd first. If that doesn't do it, take out the include
statement from httpd.conf.

Also, please post in plain text to the users list because your HTML tags
are sent to everyone in the digest list and the archives.
http://list.cobalt.com/pipermail/cobalt-users/2002-March/062757.html
--
Dan Kriwitsky




_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com


--__--__--

Message: 14
From: "Wayne Sagar" <shortfork@xxxxxxxxxxx>
To: cobalt-users@xxxxxxxxxxxxxxx
Date: Tue, 05 Mar 2002 04:31:22 -0800
Subject: [cobalt-users] Warning -DO NOT DOWNLOAD GETRIGHT-
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

This is an addendum to the other message stating that the Getright download
"utility" creates a security breech in cgi files. Well, this concerned me so
I downloaded it and installed it. I've got all my cgi files set to non-world
readable and all it would do was excicute the scripts and show the results..
not dangerous as this is all available via view/source anyway..

BUT... DO NOT TRY THIS AT HOME!! Uninstalling this thing is misery! It
breaks browsers and leaves a trail of crap!

Whaat a miserable excuse for "Software"..

Just thought I'd try to save anyone else a 3 hour session with this thing!

WS

_________________________________________________________________
Chat with friends online, try MSN Messenger: http://messenger.msn.com


--__--__--

Message: 15
From: "Dan Kriwitsky" <webhosting@xxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Subject: RE: [cobalt-users] CGI problems
Date: Tue, 5 Mar 2002 06:56:53 -0500
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

> We need to process form inputs and send those information in
> an email. However, even though the CGI script manages to run,
> I do not receive any mail containing the form data.  I
> believe a function called FORMMAIL or otherwise might be
> missing on the server.  How could I do to make it work?
>
> Just to clarify, is it alright to put all the CGI script
> files (PHP and
> PERL) into a self-created cgi-bin folder under the /web directory?
>
Probably you have the wrong path to sendmail in your CGI script.
--
Dan Kriwitsky




_________________________________________________________
Do You Yahoo!?
Get your free @yahoo.com address at http://mail.yahoo.com


--__--__--

Message: 16
From: Gerald Waugh <gwaugh@xxxxxxxxxxxxxxxxxxxxxxx>
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: Re: [cobalt-users] Raq cgi-bin Security Hole
Date: Tue, 5 Mar 2002 07:44:50 -0500
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

On Tue, 05 Mar 2002, tolgaraq wrote:
> When I use getright and enter url of any file in
> cgi-bin getright succesfuly downloads it. And your cgi
> files is open to anyone who knows it's file name.
>
> Anyone know how to prevent it?

That's one of the reasons all my CGIs are chmod 711,
I know everyone likes to use 755, and that's what you get anyone can read
them.

--
Gerald Waugh


--__--__--

Message: 17
From: Gerald Waugh <gwaugh@xxxxxxxxxxxxxxxxxxxxxxx>
To: cobalt-users@xxxxxxxxxxxxxxx
Subject: Re: [cobalt-users] FIX - can't su to root, email stopped working,
gui stopped working, postgres database is down, virtual sites disappeared
Date: Tue, 5 Mar 2002 07:04:26 -0500
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

On Mon, 04 Mar 2002, Jay Summers wrote:
> > Gerald, you are correct.  FTP can be reconfigured to allow root logins,
but
> > that's totally independent from the SSH config file.  Incidentally, I
> > generally consider the fact that the openssh PKG allows root login by
> > default to be a feature, not a hole.  I do consider the fact that it
allows
> > SSH protocol 1 traffic by default to be a hole though and I plug that
> > immediately after an install.  My 2 cents.
>
> Correct me if I'm wrong, but I don't think the SSH1 protocol is anymore
> unsafe than SSH2 as long as it's the latest stable/secure release. I don't
> really have any links to back up my claim but I believe that I read this
> somewhere before. Maybe even this list...

I am subscribed to the ssh list and most people on the list seem to think
that
SSH1 is not secure [enough]

 --
Gerald Waugh


--__--__--

Message: 18
From: "Alain LAROCHE" <laroche@xxxxxxxxxxxxxxx>
To: <cobalt-users@xxxxxxxxxxxxxxx>
Date: Tue, 5 Mar 2002 14:27:06 +0100
Subject: [cobalt-users] Re: Perpetual mail locks on Qube2
Reply-To: cobalt-users@xxxxxxxxxxxxxxx

| In a previous message, Grant [Reset Parameters] Hutchinson typed
| vigorously:
|
| >One thing that I needed to do to get the system back up and running was
| >to delete a 0 byte /var/cobalt/status file. Many of the services on the
| >Qube couldn't start up properly (including the admin web server) until I
| >deleted that file and the system created a new one.
|
| Ok, never mind...
|
| I fixed the problem this afternoon, although I still have no idea why
| this stuff starts in the first place. I'm assuming that it's some
| weirdness with qpopper, but who knows. Somebosy clarify this issue forme
| if you can. At any rate, I solved the recurring mail .lock and .pop files
| by doing the following:
|
| - Turn off email services in Cobalt Admin
| - Telnet as root:
|      rm /home/spool/mail/.*.pop -i
|      rm /home/spool/mail/*.lock -i
|      rm /var/cobalt/status
| - Reboot server in Cobalt Admin
| - Restart email services in Cobalt Admin
|
| Everybody is happy again.
|
| Grant

Hi list
I have exactly the same problem on my Qube 2.
I've solved it by removing the .pop and .lock and reboot
But after 5 or 6 days, the problem was back.
It seems that the problem in comming from a qpopper update with OS 4.0.
I'm stuck with this problem.
Please help
Alain



--__--__--

_______________________________________________
cobalt-users mailing list
cobalt-users@xxxxxxxxxxxxxxx
http://list.cobalt.com/mailman/listinfo/cobalt-users


End of cobalt-users Digest