9.1 on FTP

2012-12-07 Thread sib
Hi freebsd-questions.

While looking for a 9.1-rc3 ISO to test on my old PPC Mac, I saw a
9.1-RELEASE(!) ISO under releases/powerpc. I didn't think 9.1 was out or
announced yet, even though it was supposed to be announced some days ago.
I can't find it under any other directories for amd64,i386,etc. It's also
not on freebsd-update. Why was there an ISO for PPC? As I check now, it's
either been removed or I can't find it. Something fishy is going on?

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Somewhat OT: Is Full Command Logging Possible?

2012-12-07 Thread Devin Teske

On Dec 7, 2012, at 5:22 PM, Paul Schmehl wrote:

> --On December 7, 2012 10:23:56 AM +0100 Fleuriot Damien  wrote:
> 
>> 
>> On Dec 6, 2012, at 9:20 PM, Paul Schmehl  wrote:
>> 
>>> --On December 6, 2012 1:19:00 PM -0600 Tim Daneliuk
>>>  wrote:
 
 I understand this.  Even the organization in question understands
 this.  They are not trying to *prevent* any kind of access.  All
 they're trying to do *log* it.  Why?  To meet some obscure
 compliance requirement they have to adhere to in order to
 remain in business.
 
 
 I know all of this is silly but that's our future when you
 let Our Fine Government regulate pretty much anything.
 
 
>>> 
>>> I sent this last night, but for some reason it never showed up.
>>> 
>>> /usr/ports/security/sudoscript
>>> 
>>> I believe this will meet your requirements.
>> 
>> 
>> I'm sorry to say it won't.
>> Nothing will prevent a user from removing sudoscript's FIFO once he gets
>> root privileges.
>> 
> 
> Well, sure, but, if someone logs in and sudos to root, that will be logged by 
> sudoscript.  If the logging then ceases, that would be cause for disciplinary 
> action up to and including dismissal.
> 

What about the case of:

sudo vim

or

sudo vim file

Surely that wouldn't raise an eyebrow, but…

Then execute within vim:

:sh

or

^_^
-- 
Devin

… and another gem …

sr env HOME=$HOME vim

then

:E

_
The information contained in this message is proprietary and/or confidential. 
If you are not the intended recipient, please: (i) delete the message and all 
copies; (ii) do not disclose, distribute or use the message in any manner; and 
(iii) notify the sender immediately. In addition, please be aware that any 
message addressed to our domain is subject to archiving and review by persons 
other than the intended recipient. Thank you.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: VPS FreeBSD Hosting

2012-12-07 Thread David Brodbeck
On Sun, Nov 25, 2012 at 1:18 PM, Daniel Feenberg  wrote:

> We have had good experience with pair.com and rootbsd.com. Both were used
> for websites. We never had any problems with either, so I can't report on
> their problem solving skills, but customer service from both was good for
> the handful of routine questions we had.
>

I'm using rootbsd.com as well.  I run a few low-traffic websites and a
couple MUDs off one of their Lambda instances.  I've found their customer
service to be prompt and helpful on the few occasions when I've had
problems.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


FreeBSD 802.11 Testbed

2012-12-07 Thread Hooman Oroojeni
Dear All,
I would like to implement a physical 802.11 wireless testbed that all
systems run Freebsd 9. Including a server enabling me to define traffic for
the network as a file. And evaluate performance of network such as delay,
throughput, bandwidth,... and analyse them.

Any idea appreciated in this respect.

Regards,
Hooman

--
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Somewhat OT: Is Full Command Logging Possible?

2012-12-07 Thread Paul Schmehl

--On December 7, 2012 10:23:56 AM +0100 Fleuriot Damien  wrote:



On Dec 6, 2012, at 9:20 PM, Paul Schmehl  wrote:


--On December 6, 2012 1:19:00 PM -0600 Tim Daneliuk
 wrote:


I understand this.  Even the organization in question understands
this.  They are not trying to *prevent* any kind of access.  All
they're trying to do *log* it.  Why?  To meet some obscure
compliance requirement they have to adhere to in order to
remain in business.


I know all of this is silly but that's our future when you
let Our Fine Government regulate pretty much anything.




I sent this last night, but for some reason it never showed up.

/usr/ports/security/sudoscript

I believe this will meet your requirements.



I'm sorry to say it won't.
Nothing will prevent a user from removing sudoscript's FIFO once he gets
root privileges.



Well, sure, but, if someone logs in and sudos to root, that will be logged 
by sudoscript.  If the logging then ceases, that would be cause for 
disciplinary action up to and including dismissal.


Not all problems can be solved with technology.
Paul Schmehl, Senior Infosec Analyst
As if it wasn't already obvious, my opinions
are my own and not those of my employer.
***
"It is as useless to argue with those who have
renounced the use of reason as to administer
medication to the dead." Thomas Jefferson
"There are some ideas so wrong that only a very
intelligent person could believe in them." George Orwell

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Stickers

2012-12-07 Thread CONNOR KELLY (RIT Student)
I am a student at Rochester Institute of Technology.  I was wondering if
you could send any stickers or swag with the freebsd logo or something
similar to me.  I would probably keep some for myself and pass the rest out
to my friends at my university.  This is in no way an official
communication from my school.  If need be I'll be able to pay for postage.
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Questions not working again?

2012-12-07 Thread Bas Smeelen

On 12/08/12 01:04, Bas Smeelen wrote:

On 12/08/12 01:00, Erich Dollansky wrote:



Hi,

On Fri, 07 Dec 2012 13:32:40 -1000
Al Plant  wrote:


Aloha FreeBSD mail list.

This is the second month that it questions have stopped working to my
mail box. All the other lists are fine that I subscribe to. My
firewall spam wall has not been changed.


what Do you mean? You could not post to it?

You did not get any messages from it anymore?

Erich


Any way to fix this?


There is no difference between the mails I get from questions and what 
I got in my mail


The mail in archives on http-list I meant

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Questions not working again?

2012-12-07 Thread Bas Smeelen

On 12/08/12 01:00, Erich Dollansky wrote:

Hi,

On Fri, 07 Dec 2012 13:32:40 -1000
Al Plant  wrote:


Aloha FreeBSD mail list.

This is the second month that it questions have stopped working to my
mail box. All the other lists are fine that I subscribe to. My
firewall spam wall has not been changed.


what Do you mean? You could not post to it?

You did not get any messages from it anymore?

Erich


Any way to fix this?


There is no difference between the mails I get from questions and what I 
got in my mail




~Al Plant - Honolulu, Hawaii -  Phone:  808-284-2740
+ http://hawaiidakine.com + http://freebsdinfo.org +
+ http://aloha50.net   - Supporting - FreeBSD  7.2 - 8.0 - 9* +
< email: n...@hdk5.net >
"All that's really worth doing is what we do for others."- Lewis
Carrol

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to
"freebsd-questions-unsubscr...@freebsd.org"

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"



___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Questions not working again?

2012-12-07 Thread Erich Dollansky
Hi,

On Fri, 07 Dec 2012 13:32:40 -1000
Al Plant  wrote:

> Aloha FreeBSD mail list.
> 
> This is the second month that it questions have stopped working to my 
> mail box. All the other lists are fine that I subscribe to. My
> firewall spam wall has not been changed.
> 
what Do you mean? You could not post to it?

You did not get any messages from it anymore?

Erich

> Any way to fix this?
> 
> ~Al Plant - Honolulu, Hawaii -  Phone:  808-284-2740
>+ http://hawaiidakine.com + http://freebsdinfo.org +
>+ http://aloha50.net   - Supporting - FreeBSD  7.2 - 8.0 - 9* +
>< email: n...@hdk5.net >
> "All that's really worth doing is what we do for others."- Lewis
> Carrol
> 
> ___
> freebsd-questions@freebsd.org mailing list
> http://lists.freebsd.org/mailman/listinfo/freebsd-questions
> To unsubscribe, send any mail to
> "freebsd-questions-unsubscr...@freebsd.org"

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Questions not working again?

2012-12-07 Thread Al Plant

Aloha FreeBSD mail list.

This is the second month that it questions have stopped working to my 
mail box. All the other lists are fine that I subscribe to. My firewall 
spam wall has not been changed.


Any way to fix this?

~Al Plant - Honolulu, Hawaii -  Phone:  808-284-2740
  + http://hawaiidakine.com + http://freebsdinfo.org +
  + http://aloha50.net   - Supporting - FreeBSD  7.2 - 8.0 - 9* +
  < email: n...@hdk5.net >
"All that's really worth doing is what we do for others."- Lewis Carrol

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: 9.1-RC3 LiveCD missing features

2012-12-07 Thread Bas Smeelen

On 12/08/12 00:05, Tomek CEDRO wrote:
On 12/07/12 23:11, Chuck Burns wrote:

On 12/7/2012 3:50 PM, CeDeROM wrote:

Hello

I have tried to chceck for badblocks on my / but I did not find 
badblocks
program on LiveCD and there is no option to install it. This is very 
useful

utility, please add it as part of LiveCD

Also there is a problem with DHCP based workstations using LiveCD -
although interface gets configured it is impossible to update
/etc/resolv.conf (by dhclient and by hand) and so this workstation 
pretty

useless for IPv4 (is it more usable on IPv6?). Please update

Thank you
Tomek




dd if=/dev/zer of=/dev/ada0

^^^ There's your "badblocks" program.  Any hard drive made in the last 
decade have been self-remapping..  Attempting to write to a bad block 
will cause the hard drive to remap an unused sector into it's place, 
until the drive runs out of said "unused" backup sectors, and at that 
time, will begin simply begin just "losing" storage space... IE the 
number of total sectors on the drive will begin to shrink.





/dev/zero

Badblocks is outdated for more than 17 years I guess
The dd mentioned above will let the firmware remap all bad sectors until 
there are no spare sectors left (and wipe anything on disk as a bonus 
;then you can begin to think about replacing your harddrive.


As for DHCP, it works for me when booting from a netinstall for instance 
or going to fixit.
Tomek, please try to describe more accurately what you are doing and try 
to accomplish



As I get ffs_valloc kernel panic on my / I want to check for badblocks but
cannot do that from the system itself so I need another FreeBSD instance to
run badblocks on unmounted /. There are no badblocks on LiveCD and I cannot
simply download it with pkg_add -r. Installing another system just to test
existing one seems silly. It would be nice to finally have swiss army knife
on generic LiveCD FreeBSD install, not using linux windows hirens etc :-)

I have just started dd if=root of=root from LiveCD, Ill let you know if
that worked :-)


I will be surprised what that will do for you

I have lloked at the picture and all I can come up wih is either bad 
hardware or a very strange software/system configuration.


Good luck
Please reply to this list if any

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: openjdk port build failures

2012-12-07 Thread dweimer

On 2012-12-07 16:01, dweimer wrote:

I am working on a 9.1-Release system built from source (Original
Install from 9.1RC1), and am having trouble getting openjdk to build.
I tried 7 first, and after that failed tried 6, has anyone else ran
into this, Is it possibly because I have the system and ports where
possible built with clang?  Below is the output from the end of the
openjdk6 build attempt.

uname -v: FreeBSD 9.1-RELEASE #1 r243900: Wed Dec  5 14:05:38 CST 
2012


Recursively making corbalogcompile build @ Fri Dec  7 15:48:25 CST 
2012 ...

gmake[5]: Entering directory

`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun/rmi/corbalogcompile'
# Java sources to be compiled: (listed in file

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/tmp/sun/com.sun.corba.se.impl.logging/.classes.list)

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/ActivationSystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/IORSystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/InterceptorsSystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/NamingSystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/OMGSystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/ORBUtilSystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/POASystemException.java

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/UtilSystemException.java
# Running javac:
/usr/local/bootstrap-openjdk/bin/java -Xmx874m -Xms128m

-Xbootclasspath/p:/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/langtools/dist/bootstrap/lib/javac.jar
-jar

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/langtools/dist/bootstrap/lib/javac.jar
-XDignore.symbol.file=true -source 1.5 -target 5 -encoding ascii
-classpath /usr/local/bootstrap-openjdk/lib/tools.jar -Xprefer:source
-sourcepath

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc:../../../../src/solaris/classes:../../../../src/share/classes
-d
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/classes

@/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/tmp/sun/com.sun.corba.se.impl.logging/.classes.list
gmake[5]: *** [.compile.classlist] Killed: 9
gmake[5]: Leaving directory

`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun/rmi/corbalogcompile'
gmake[4]: *** [build] Error 1
gmake[4]: Leaving directory
`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun/rmi'
gmake[3]: *** [build] Error 1
gmake[3]: Leaving directory
`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun'
gmake[2]: *** [build] Error 1
gmake[2]: Leaving directory 
`/var/ports/usr/ports/java/openjdk6/work/corba/make'

gmake[1]: *** [corba-build] Error 2
gmake[1]: Leaving directory `/var/ports/usr/ports/java/openjdk6/work'
gmake: *** [build_product_image] Error 2
*** [do-build] Error code 1

Stop in /usr/ports/java/openjdk6.
*** [install] Error code 1

Stop in /usr/ports/java/openjdk6.


Well, think I just noticed the cause, this test Virtual machine only 
has 1G of ram setup on it, I did create and additional 1G of swap space, 
but forgot to setup the fstab file so it wasn't turned on.  Just 
happened to look at the console while closing windows on my laptop to 
head home from the office, and saw several processes were killed reason 
given: out of swap space.


Will give this another go around with the swap active and see if it 
works..


--
Thanks,
   Dean E. Weimer
   http://www.dweimer.net/
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


openjdk port build failures

2012-12-07 Thread dweimer
I am working on a 9.1-Release system built from source (Original 
Install from 9.1RC1), and am having trouble getting openjdk to build.  I 
tried 7 first, and after that failed tried 6, has anyone else ran into 
this, Is it possibly because I have the system and ports where possible 
built with clang?  Below is the output from the end of the openjdk6 
build attempt.


uname -v: FreeBSD 9.1-RELEASE #1 r243900: Wed Dec  5 14:05:38 CST 2012

Recursively making corbalogcompile build @ Fri Dec  7 15:48:25 CST 
2012 ...
gmake[5]: Entering directory 
`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun/rmi/corbalogcompile'
# Java sources to be compiled: (listed in file 
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/tmp/sun/com.sun.corba.se.impl.logging/.classes.list)

/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/ActivationSystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/IORSystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/InterceptorsSystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/NamingSystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/OMGSystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/ORBUtilSystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/POASystemException.java
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc/com/sun/corba/se/impl/logging/UtilSystemException.java
# Running javac:
/usr/local/bootstrap-openjdk/bin/java -Xmx874m -Xms128m 
-Xbootclasspath/p:/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/langtools/dist/bootstrap/lib/javac.jar 
-jar 
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/langtools/dist/bootstrap/lib/javac.jar 
-XDignore.symbol.file=true -source 1.5 -target 5 -encoding ascii 
-classpath /usr/local/bootstrap-openjdk/lib/tools.jar -Xprefer:source 
-sourcepath 
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/gensrc:../../../../src/solaris/classes:../../../../src/share/classes 
-d 
/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/classes 
@/var/ports/usr/ports/java/openjdk6/work/build/bsd-amd64/corba/tmp/sun/com.sun.corba.se.impl.logging/.classes.list

gmake[5]: *** [.compile.classlist] Killed: 9
gmake[5]: Leaving directory 
`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun/rmi/corbalogcompile'

gmake[4]: *** [build] Error 1
gmake[4]: Leaving directory 
`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun/rmi'

gmake[3]: *** [build] Error 1
gmake[3]: Leaving directory 
`/var/ports/usr/ports/java/openjdk6/work/corba/make/sun'

gmake[2]: *** [build] Error 1
gmake[2]: Leaving directory 
`/var/ports/usr/ports/java/openjdk6/work/corba/make'

gmake[1]: *** [corba-build] Error 2
gmake[1]: Leaving directory `/var/ports/usr/ports/java/openjdk6/work'
gmake: *** [build_product_image] Error 2
*** [do-build] Error code 1

Stop in /usr/ports/java/openjdk6.
*** [install] Error code 1

Stop in /usr/ports/java/openjdk6.

--
Thanks,
   Dean E. Weimer
   http://www.dweimer.net/
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: pkg version?

2012-12-07 Thread Matthew Seaman
On 07/12/2012 15:52, Walter Hurry wrote:
> $ pkg query %v pkg
> 1.0.3
> $ pkg -v
> 1.0.2

This is due to a mistake in the release process: we forgot to update the
version number in the source code.  Ooops.

Will be rectified in version 1.0.4, if not sooner.

Cheers,

Matthew
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


pkg version?

2012-12-07 Thread Walter Hurry
$ pkg query %v pkg
1.0.3
$ pkg -v
1.0.2
$ 

Why the discrepancy?

By the way:

## SVN ## - update to 1.0.3
## SVN ## - changes:
## SVN ##   * Accept to query _https._tcp srv records
## SVN ##   * Fix diskspace change calculation in pkg upgrade
## SVN ##   * Fix pkg info -s -F apackage

Excellent. Thanks, Matthew.

$ pkg info -s -F gcc-4.6.4.20121123.txz
gcc-4.6.4.20121123 size is: 567 MB
$

Yep, that bit works.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: SMS application

2012-12-07 Thread dweimer

On 2012-12-06 13:59, Carmel wrote:

Can anyone recommend a good SMS application that works on FreeBSD? I
have used several different ones on MS Windows; however, I cannot 
find

one that works on FreeBSD. There doesn't appear to be a fully
functional one in the ports system either, although I might have 
missed

it.


Why not just check here: 
http://www.freebsd.org/cgi/ports.cgi?query=sms&stype=all


--
Thanks,
   Dean E. Weimer
   http://www.dweimer.net/
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Brian Blencoe

2012-12-07 Thread Fleuriot Damien

On Dec 7, 2012, at 3:09 PM, Brian Blencoe  wrote:

> Hello
> 
> I am a student, doing a presentation project on FreeBSD. I have been surfing 
> your web site, getting some reading done. If you have any good ideas that I 
> could include into my presentation, please email me.
> 
> Thank You 
> 
> Brian Blencoe
> 910-470-7001
> blenc...@gmail.com


What exactly is your presentation about ?


Open source software ?
Web servers ?
root privileges and the 101 funniest ways to abuse them ?


There are tons of things to be said about FreeBSD, or any OS for that matter ;)

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: what replaces javaws? using icedtea-web and openjdk6.

2012-12-07 Thread Antonio Olivares
On Thu, Dec 6, 2012 at 3:46 PM, Dan Nelson  wrote:
> In the last episode (Dec 06), Antonio Olivares said:
>> >> http://www.freebsd.org/cgi/query-pr.cgi?pr=ports/173603
>> >
>> > I apply the suggested fix:
>> >
>> > $ sh -x `which itweb-javaws` jviewer.jnlp
>> > + JAVA=/usr/local/openjdk6/jre/bin/java
>> > + 
>> > LAUNCHER_BOOTCLASSPATH=-Xbootclasspath/a:/usr/local/share/icedtea-web/netx.jar
>> > + LAUNCHER_FLAGS=-Xms8m
>> > + CLASSNAME=net.sourceforge.jnlp.runtime.Boot
>> > + BINARY_LOCATION=/usr/local/bin/itweb-javaws
>> > + PROGRAM_NAME=itweb-javaws
>> > + CP=/usr/local/openjdk6/jre/lib/rt.jar
>> > /usr/local/bin/itweb-javaws: 11: Syntax error: Bad function name
>> >
>> I try once more on another machine not 64 bit, it returns the same
>> error and java web start does not work :(
>>
>> $ sh -x `which itweb-javaws` jviewer.jnlp
>> + JAVA=/usr/local/openjdk6/jre/bin/java
>> + 
>> LAUNCHER_BOOTCLASSPATH=-Xbootclasspath/a:/usr/local/share/icedtea-web/netx.jar
>> + LAUNCHER_FLAGS=-Xms8m
>> + CLASSNAME=net.sourceforge.jnlp.runtime.Boot
>> + BINARY_LOCATION=/usr/local/bin/itweb-javaws
>> + PROGRAM_NAME=itweb-javaws
>> + CP=/usr/local/openjdk6/jre/lib/rt.jar
>> /usr/local/bin/itweb-javaws: 11: Syntax error: Bad function name
>>
>> Any other ideas as to how to fix this?
>
> Don't try and run it through /bin/sh .  The script uses bash-isms (array
> syntax specifically).  Just run "itweb-javaws jviewer.jnlp".
>
> --
> Dan Nelson
> dnel...@allantgroup.com

This is what I get when I run it:

$ itweb-javaws jviewer.jnlp
Error: could not find libjava.so
Error: could not find Java 2 Runtime Environment.
$

E-213-3W# pkg_version "<" | grep 'openjdk'
bootstrap-openjdk   =
openjdk6=
E-213-3W# pkg_version "<" | grep 'icedtea-web'
icedtea-web =
E-213-3W#

Thanks for helping.

Regards,


Antonio
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Brian Blencoe

2012-12-07 Thread Brian Blencoe
Hello

I am a student, doing a presentation project on FreeBSD. I have been surfing 
your web site, getting some reading done. If you have any good ideas that I 
could include into my presentation, please email me.

Thank You 

Brian Blencoe
910-470-7001
blenc...@gmail.com
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Somewhat OT: Is Full Command Logging Possible?

2012-12-07 Thread Tim Daneliuk

On 12/07/2012 03:23 AM, Fleuriot Damien wrote:

- audit trails cannot be tampered (chflags sappend)


Another way to achieve this is to send the logging output
to a another log collection machine or appliance (think
"Arcsite") to which even the root users under consideration
do not have access.  That is, implement a separation of powers
scheme where no one organization has complete control of
the entire monitoring workflow.


--

Tim Daneliuk tun...@tundraware.com
PGP Key: http://www.tundraware.com/PGP/

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: root filesystem and soft-update

2012-12-07 Thread Rick Miller
On Tue, Dec 4, 2012 at 4:50 PM, Rick Miller  wrote:
> Hi all,
>
> I remember one time seeing a site that explained why soft-updates was
> not enabled for the root filesystem.  I tried looking for it earlier,
> but failed to locate it.  Is there someone who knows where it is?

Thanks Steve and Bas.  Both answers were helpful.


-- 
Take care
Rick Miller
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: gPXE booting FreeBSD?

2012-12-07 Thread Rick Miller
On Tue, Dec 4, 2012 at 10:55 AM, Rick Miller  wrote:
> Hi All,
>
> Does anyone have any experience booting FreeBSD via gPXE and have
> pointers to relevant documentation and/or blog posts?

Thanks for all your replies.  Our current direction appears to be one
of modifying the FreeBSD bootonly ISO to perform installs and load it
from gPXE as follows...

The menu will appear something like (from memory, syntax may be wrong):

kernel memdisk
imgargs memdisk raw iso
initrd http path to the ISO

Once we have it tested and implemented, I'll likely blog the subject
at http://blog.hostileadmin.com/

-- 
Take care
Rick Miller
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: SMS application

2012-12-07 Thread Andrea Venturoli

On 12/07/12 09:08, Boris Samorodov wrote:


As for me I use comms/gammu as an sms-tool.


There's also smstools, which should be similar.

(Assuming SMS=Short Message Service and what the OP wants is simply 
send/receive).


 bye
av.

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Login class and limit

2012-12-07 Thread Vagner
On 17:47 Thu 06 Dec , Lowell Gilbert wrote:
> Vagner  writes:
> 
> > On 06:53 Thu 06 Dec , Charles Swiger wrote:
> 
> >> "su -", "su -l", and "sudo -i" provide a login shell, which gets the
> >> limits setup by login.conf.  Normally daemons are started at boot
> >> via rc mechanism (or perhaps get spawned from inetd) and do not
> >> have a login shell associated with them to setup the limits.
> >> 
> >> Either use one of the su/sudo flavors I mention above, or "/bin/sh -l"
> >> to provide a login env to the process?
> >
> > ie means to implement restrictions limits(1) and login.conf(5) for daemons 
> > is not possible?
> 
> It's possible, but you would have to use a login shell, which is usually
> inconvenient for a daemon (not having an attached terminal for I/O).
> 
> The usual way to do this is to start the daemon in a script that
> explicitly sets the limits with /usr/bin/limits (or maybe ulimit, but
> limits(1) seems more common). Several ports do this, for example.
> 

Thx for all! I try starting daemon with explicitly sets from rc script.
Thanks again!

-- 
Respectfully,
Stanislav Putrya
System administrator
FotoStrana.Ru Ltd.
ICQ IM: 328585847
Jabber-GoogleTalk: root.vagner
mob.phone SPB: +79215788755
mob.phone RND: +79525600664
email: vag...@bsdway.ru
email: put...@playform.ru
email: root.vag...@gmail.com
site: bsdway.ru
site: fotostrana.ru


 ( ) ASCII ribbon campaign
  X  - against HTML, vCards and
 / \ - proprietary attachments in e-mail
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Somewhat OT: Is Full Command Logging Possible?

2012-12-07 Thread Fleuriot Damien

On Dec 6, 2012, at 9:20 PM, Paul Schmehl  wrote:

> --On December 6, 2012 1:19:00 PM -0600 Tim Daneliuk  
> wrote:
>> 
>> I understand this.  Even the organization in question understands
>> this.  They are not trying to *prevent* any kind of access.  All
>> they're trying to do *log* it.  Why?  To meet some obscure
>> compliance requirement they have to adhere to in order to
>> remain in business.
>> 
>> 
>> I know all of this is silly but that's our future when you
>> let Our Fine Government regulate pretty much anything.
>> 
>> 
> 
> I sent this last night, but for some reason it never showed up.
> 
> /usr/ports/security/sudoscript
> 
> I believe this will meet your requirements.


I'm sorry to say it won't.
Nothing will prevent a user from removing sudoscript's FIFO once he gets root 
privileges.


Basically, what Tim wants to do sounds very akin to the PCI DSS requirements 
that every user's action be logged.
The bad news is _this is not achievable on MS/nux/bsd_ systems.
The kind of logging and security required can only be attained on mainframes 
(read: i/Series , z/Series) using RACF and other absolutely awesome features.


The only thing Tim can do is try to approach the level of security that's 
required.

Devin's suggestion of a kernel module is what comes closest to achieving the 
goal, provided that:
- the functionnality is compiled in-kernel to prevent kldunload'ing the module
- the system runs at a secure level high enough to prevent kldunloads , if it 
can't be compiled in-kernel
- the functions used by the module cannot be overriden by another module (for 
example redeclare this module's sendlog() function with another dummy module, 
making sendlog() basically do a NOOP)

Another contestant that comes a close second is the use of the AUDIT framework, 
however one would need to ensure:
- audit trails cannot be tampered (chflags sappend)
- the audit daemon cannot be killed

___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: Somewhat OT: Is Full Command Logging Possible?

2012-12-07 Thread Damien Fleuriot

On 6 Dec 2012, at 20:19, Tim Daneliuk  wrote:

> On 12/06/2012 12:55 PM, n j wrote:
>> On Thu, Dec 6, 2012 at 12:47 AM, Tim Daneliuk  wrote:
>>> ...
>>> Well ... does auditd provide a record of every command issued within a
>>> script?
>>> I was under the impression (and I may well be wrong) that it  noted only
>>> the name of the script being executed.
>> 
>> Even if you configured auditd to record every command issued within a
>> script, you'd still have a problem if a malicious user put the same
>> commands inside a binary.
>> 
>> As some people already pointed out, there is practically no way to
>> control users once you give them root privileges.
> 
> I understand this.  Even the organization in question understands
> this.  They are not trying to *prevent* any kind of access.  All
> they're trying to do *log* it.  Why?  To meet some obscure
> compliance requirement they have to adhere to in order to
> remain in business.
> 
> 
> I know all of this is silly but that's our future when you
> let Our Fine Government regulate pretty much anything.
> 
> 

This sounds awfully similar to PCI DSS requirements to me.

Nothing to do with .gov then ;)
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"


Re: SMS application

2012-12-07 Thread Boris Samorodov
06.12.2012 23:59, Carmel пишет:
> Can anyone recommend a good SMS application that works on FreeBSD? I
> have used several different ones on MS Windows; however, I cannot find
> one that works on FreeBSD. There doesn't appear to be a fully
> functional one in the ports system either, although I might have missed
> it.
> 

This command may be a good start to investigate:
-
% make -C /usr/ports search key=sms display=path
-

As for me I use comms/gammu as an sms-tool.

-- 
WBR, Boris Samorodov (bsam)
FreeBSD Committer, http://www.FreeBSD.org The Power To Serve
___
freebsd-questions@freebsd.org mailing list
http://lists.freebsd.org/mailman/listinfo/freebsd-questions
To unsubscribe, send any mail to "freebsd-questions-unsubscr...@freebsd.org"