<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: More on msec</title>
	<atom:link href="http://dodonov.net/blog/2010/02/18/more-on-msec/feed/" rel="self" type="application/rss+xml" />
	<link>http://dodonov.net/blog/2010/02/18/more-on-msec/</link>
	<description>My view on technology, open-source, Linux and other cool things.</description>
	<lastBuildDate>Sat, 04 Feb 2012 13:20:41 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=</generator>
	<item>
		<title>By: eugeni</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17281</link>
		<dc:creator>eugeni</dc:creator>
		<pubDate>Wed, 26 May 2010 13:19:20 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17281</guid>
		<description>&lt;p&gt;Hi,&lt;/p&gt;

&lt;p&gt;this message says that some application on your system has put your network card in &#039;promiscuous&#039; mode - a mode in which it intercepts all network packets, even if they are not intended for it. This is suspicious, because under normal circumstances the network card shouldn&#039;t be running in this mode. However, many applications do this on purpose (for example, traffic analyzers).&lt;/p&gt;

&lt;p&gt;To confirm what network card is running in this mode, try running (as root) &#039;promisc_check&#039; in console. This will display you the information about what network card is currently running in this mode.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Hi,</p>

<p>this message says that some application on your system has put your network card in &#8216;promiscuous&#8217; mode &#8211; a mode in which it intercepts all network packets, even if they are not intended for it. This is suspicious, because under normal circumstances the network card shouldn&#8217;t be running in this mode. However, many applications do this on purpose (for example, traffic analyzers).</p>

<p>To confirm what network card is running in this mode, try running (as root) &#8216;promisc_check&#8217; in console. This will display you the information about what network card is currently running in this mode.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Julien</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17279</link>
		<dc:creator>Julien</dc:creator>
		<pubDate>Wed, 26 May 2010 06:39:48 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17279</guid>
		<description>&lt;p&gt;I am looking for help about msec. I my log (mandriva 2010.0), I got &quot;localhost msec: A sniffer is probably running on your system&quot;. I wonder if someone is sniffing my network? Or maybe it is from a program on my computer. I am a newbie so I don&#039;t what to check. I am connected on the internet through an apple airport express and an intel wireless card with WPA key.
Could you let me know how to investigate this security breach?
Thanks,
Julien&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>I am looking for help about msec. I my log (mandriva 2010.0), I got &#8220;localhost msec: A sniffer is probably running on your system&#8221;. I wonder if someone is sniffing my network? Or maybe it is from a program on my computer. I am a newbie so I don&#8217;t what to check. I am connected on the internet through an apple airport express and an intel wireless card with WPA key.
Could you let me know how to investigate this security breach?
Thanks,
Julien</p>]]></content:encoded>
	</item>
	<item>
		<title>By: vfmBOFH</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17233</link>
		<dc:creator>vfmBOFH</dc:creator>
		<pubDate>Thu, 25 Feb 2010 11:03:51 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17233</guid>
		<description>&lt;p&gt;Yargh!&lt;/p&gt;

&lt;p&gt;Next time i will try the --help trick before open my big mouth :D&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Yargh!</p>

<p>Next time i will try the &#8211;help trick before open my big mouth <img src='http://dodonov.net/blog/wp-includes/images/smilies/icon_biggrin.gif' alt=':D' class='wp-smiley' /> </p>]]></content:encoded>
	</item>
	<item>
		<title>By: eugeni</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17231</link>
		<dc:creator>eugeni</dc:creator>
		<pubDate>Tue, 23 Feb 2010 14:23:31 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17231</guid>
		<description>&lt;p&gt;@vfmBOFH this functionality is already in the console version (e.g., just run &#039;msec -s &lt;new profile name&gt;&#039; to save current settings as a new profile). The gui for it is missing indeed however.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@vfmBOFH this functionality is already in the console version (e.g., just run &#8216;msec -s <new profile name>&#8216; to save current settings as a new profile). The gui for it is missing indeed however.</new></p>]]></content:encoded>
	</item>
	<item>
		<title>By: vfmBOFH</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17230</link>
		<dc:creator>vfmBOFH</dc:creator>
		<pubDate>Tue, 23 Feb 2010 12:32:08 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17230</guid>
		<description>&lt;p&gt;First of all, congratulations for a a job well done.&lt;/p&gt;

&lt;p&gt;Now, focusing on the &quot;profiles&quot;. Maybe can be useful grant to the sysadmin create his own profile. I explain: If a sysadmin selects the &quot;desktop&quot; profile, but needs some fine tunning, after apply changes will be a great option save these changes to re-use (i.e. deploying a large amount of machines) in another installation. So, the idea is implement a &quot;Load/Save&quot; advanced settings or something else..&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>First of all, congratulations for a a job well done.</p>

<p>Now, focusing on the &#8220;profiles&#8221;. Maybe can be useful grant to the sysadmin create his own profile. I explain: If a sysadmin selects the &#8220;desktop&#8221; profile, but needs some fine tunning, after apply changes will be a great option save these changes to re-use (i.e. deploying a large amount of machines) in another installation. So, the idea is implement a &#8220;Load/Save&#8221; advanced settings or something else..</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Davy Defaud</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17226</link>
		<dc:creator>Davy Defaud</dc:creator>
		<pubDate>Sun, 21 Feb 2010 12:18:43 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17226</guid>
		<description>&lt;p&gt;Ola Dr Eugeni,&lt;/p&gt;

&lt;p&gt;Thanks for all these msec improvements.&lt;/p&gt;

&lt;p&gt;There&#039;s a particular point that I&#039;d like to see improved. It&#039;s the way msec is dealing with the /net special autofs mount point.
This special directory is used when configured in /etc/autofs/auto.master as a special mount point that is able to mount every NFS servers&#039; exported file systems. For example, /net/an-nfs-server/export1 is mounting the /export1 FS of the NFS server named an-nfs-server.
The problem is that, even if the NFS mount is auto-unmounted after a given time, the /net/an-nfs-server/export1 mount point stays on the client until the next restart of the autofs service. And, when msec is performing its checks, every remote FS that has been mounted since the last restart of autofs (e.g. since the system is up), are automatically re-mounted, and the checks go across the remote FS...&lt;/p&gt;

&lt;p&gt;IMHO, msec should consider /net as an exception, at least if we ensure that autofs is using it for that particular purpose.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>Ola Dr Eugeni,</p>

<p>Thanks for all these msec improvements.</p>

<p>There&#8217;s a particular point that I&#8217;d like to see improved. It&#8217;s the way msec is dealing with the /net special autofs mount point.
This special directory is used when configured in /etc/autofs/auto.master as a special mount point that is able to mount every NFS servers&#8217; exported file systems. For example, /net/an-nfs-server/export1 is mounting the /export1 FS of the NFS server named an-nfs-server.
The problem is that, even if the NFS mount is auto-unmounted after a given time, the /net/an-nfs-server/export1 mount point stays on the client until the next restart of the autofs service. And, when msec is performing its checks, every remote FS that has been mounted since the last restart of autofs (e.g. since the system is up), are automatically re-mounted, and the checks go across the remote FS&#8230;</p>

<p>IMHO, msec should consider /net as an exception, at least if we ensure that autofs is using it for that particular purpose.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: eugeni</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17222</link>
		<dc:creator>eugeni</dc:creator>
		<pubDate>Sat, 20 Feb 2010 11:11:40 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17222</guid>
		<description>&lt;p&gt;@motitos, I think that the &quot;fileserver&quot; should be adequate for you. The difference between it and the &quot;webserver&quot; is that it runs the I/O-intensive periodic check weekly instead of daily.&lt;/p&gt;

&lt;p&gt;As your server does not receives user-generated content, nor has php scripts, it is less likely to be compromised by a php exploit or something like that.&lt;/p&gt;

&lt;p&gt;But on the other hand, if you don&#039;t have that much files, you could use the &quot;webserver&quot; level and just run most periodic checks daily.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@motitos, I think that the &#8220;fileserver&#8221; should be adequate for you. The difference between it and the &#8220;webserver&#8221; is that it runs the I/O-intensive periodic check weekly instead of daily.</p>

<p>As your server does not receives user-generated content, nor has php scripts, it is less likely to be compromised by a php exploit or something like that.</p>

<p>But on the other hand, if you don&#8217;t have that much files, you could use the &#8220;webserver&#8221; level and just run most periodic checks daily.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: motitos</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17221</link>
		<dc:creator>motitos</dc:creator>
		<pubDate>Sat, 20 Feb 2010 08:36:28 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17221</guid>
		<description>&lt;p&gt;First of all, thanx so much for this great tool!&lt;/p&gt;

&lt;p&gt;I run a server (with Mandriva, of course!) with Apache, proftpd, ssh and nx. I don&#039;t use php nor cgi&#039;s, so Apache simply sends totally static webpages. Now, the question: which level do you recommend me? I&#039;m unsure if &quot;webserver&quot; level is the one for me, or I&#039;d rather make a personal one.&lt;/p&gt;

&lt;p&gt;Thank you in advance!
motitos&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>First of all, thanx so much for this great tool!</p>

<p>I run a server (with Mandriva, of course!) with Apache, proftpd, ssh and nx. I don&#8217;t use php nor cgi&#8217;s, so Apache simply sends totally static webpages. Now, the question: which level do you recommend me? I&#8217;m unsure if &#8220;webserver&#8221; level is the one for me, or I&#8217;d rather make a personal one.</p>

<p>Thank you in advance!
motitos</p>]]></content:encoded>
	</item>
	<item>
		<title>By: eugeni</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17220</link>
		<dc:creator>eugeni</dc:creator>
		<pubDate>Fri, 19 Feb 2010 15:59:37 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17220</guid>
		<description>&lt;p&gt;@promneneur, &quot;home desktop connected to internet&quot; is what the &quot;Standard&quot; profile represents now. I still don&#039;t know if the &quot;Standard&quot; should be renamed to &quot;Desktop&quot;, or just its description should be improved.&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>@promneneur, &#8220;home desktop connected to internet&#8221; is what the &#8220;Standard&#8221; profile represents now. I still don&#8217;t know if the &#8220;Standard&#8221; should be renamed to &#8220;Desktop&#8221;, or just its description should be improved.</p>]]></content:encoded>
	</item>
	<item>
		<title>By: promneneur</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17219</link>
		<dc:creator>promneneur</dc:creator>
		<pubDate>Fri, 19 Feb 2010 15:56:15 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17219</guid>
		<description>&lt;p&gt;a profile &quot;home desktop connected to internet&quot; is missing&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>a profile &#8220;home desktop connected to internet&#8221; is missing</p>]]></content:encoded>
	</item>
	<item>
		<title>By: Eugeni: More on msec - 3 News</title>
		<link>http://dodonov.net/blog/2010/02/18/more-on-msec/comment-page-1/#comment-17218</link>
		<dc:creator>Eugeni: More on msec - 3 News</dc:creator>
		<pubDate>Thu, 18 Feb 2010 22:21:44 +0000</pubDate>
		<guid isPermaLink="false">http://dodonov.net/blog/?p=730#comment-17218</guid>
		<description>&lt;p&gt;[...] the original here: Eugeni: More on msec               Tags: [...]&lt;/p&gt;
</description>
		<content:encoded><![CDATA[<p>[...] the original here: Eugeni: More on msec               Tags: [...]</p>]]></content:encoded>
	</item>
</channel>
</rss>

<!-- Performance optimized by W3 Total Cache. Learn more: http://www.w3-edge.com/wordpress-plugins/

Served from: dodonov.net @ 2012-02-07 13:58:31 -->
