Re: sshd configure howto

2007-03-17 Thread Brian A. Seklecki
>From an architecture standpoint, It wouldn't be within the mandate of sshd(8) anyway. You'd accomplish this using some userland resource quota enforcement policy (max number of processes, max instances of a shell). Hell you could do it in /etc/profile or ~/.cshrc I don't know of one OTTMH, bu

Re: Mbufs tunning

2007-03-17 Thread Brian A. Seklecki
On Fri, 2007-03-16 at 18:30 -0300, Gustavo Rios wrote: > Dear gentleman, > > when i execute some command on my server box, i got a complain about > not enough buffer available. For instance. > > $ rusers > rusers: can't send broadcast packet: No buffer space available > $ netstat(8) -m gives som

Re: Important OpenBSD errata

2007-03-17 Thread Shawn K. Quinn
On Sat, 2007-03-17 at 19:08 +0100, Karel Kulhavy wrote: > I also suggest that the list include the cumulative amount > for each donor, sorted so that the biggest donors are at the > top. To me, this makes about as much sense as publishing a similar list for penis size (and whatever its female equi

Re: sshd configure howto

2007-03-17 Thread Jay Jesus Amorin
im using this set-up for pf/authpf authentication gateway, all i'm concern of is i dont want my user use other users account. hope this helps you help me. thanks --jay-- On 3/17/07, Joachim Schipper <[EMAIL PROTECTED]> wrote: On Sat, Mar 17, 2007 at 12:46:29PM +0800, Jay Jesus Amorin wrote: >

Re: forcing WD0/WD1 designation (soekris)

2007-03-17 Thread jared r r spiegel
On Sat, Mar 17, 2007 at 03:33:30PM -0700, Marco S Hyman wrote: > > i don't think you can modify attachments with config(8), but > > You can. Or you can build a custom kernel. My box finds my SATA > drive before my ATA drive though I use the ATA drive as wd0. My > kernel config has: > > wd

Re: Important OpenBSD errata

2007-03-17 Thread Jack J. Woehr
Travers Buda wrote: * Karel Kulhavy <[EMAIL PROTECTED]> [2007-03-17 19:47:00]: It would be better if OpenBSD could be maintained secure even without a skilled security professional. Today's trend is that things are accomodated to ordinary people. You don't need a driver anymore to professio

Re: Links+

2007-03-17 Thread Nick Holland
Karel Kulhavy wrote: > http://openbsd.org/faq/faq8.html > > The name of the browser that is at http://links.twibright.com is not > Links+, but Links (or Twibright Links). It's not a different browser than the > textmode Links. If you run recent Links without -g, you get the textmode > links. > Th

Re: Important OpenBSD errata

2007-03-17 Thread Travers Buda
* Karel Kulhavy <[EMAIL PROTECTED]> [2007-03-17 19:47:00]: > It would be better if OpenBSD could be maintained secure even without a > skilled > security professional. > > Today's trend is that things are accomodated to ordinary people. You don't > need > a driver anymore to professionally driv

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Jeff Rollin
On 17/03/07, STeve Andre' <[EMAIL PROTECTED]> wrote: On Saturday 17 March 2007 19:04:45 Bob Beck wrote: > * Bryan Allen <[EMAIL PROTECTED]> [2007-03-17 16:22]: > > On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: > > > Hate to tell you this, but Canada is not the United States. > > > > Give us a co

routing configuration for a soekris + wifi ath0

2007-03-17 Thread scorch
I've just received a miniPCI ath0 card for my soekris, & plan to eliminate the current draytek wireless router from my home LAN. however this is a little further out of my currrent skill set than before, esp. in the subnet/routing arena & before i dig in too deep i could do with some feedback

Re: OpenBSD SECURITY FIX: Incorrect mbuf handling for ICMP6 packets, 2nd revision

2007-03-17 Thread Jason Dixon
On Mar 17, 2007, at 7:35 PM, Tobias Weisserth wrote: Hi everybody, I just noticed Henning's addition to the latest patch. Can I apply it if I already applied the first revision to 4.0 release + errata up to 010 first revision? Or do I have to edit the latest patch to only add the "if" test

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread STeve Andre'
On Saturday 17 March 2007 19:04:45 Bob Beck wrote: > * Bryan Allen <[EMAIL PROTECTED]> [2007-03-17 16:22]: > > On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: > > > Hate to tell you this, but Canada is not the United States. > > > > Give us a couple years. Pax Americana, yo. > > Nah, at the ra

Re: Important OpenBSD errata

2007-03-17 Thread Darrin Chandler
On Sat, Mar 17, 2007 at 08:43:57PM +, Deanna Phillips wrote: > Ray Percival writes: > > > No. Everybody with a clue knows that there is two sources for > > good data. The errata page and source-changes. > > I'd like to add undeadly's RSS here, since I don't think anyone > has mentioned it yet

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Han Boetes
Bob Beck wrote: > Hate to tell you this, but Canada is not the United States. Not that long anymore. http://www.eagleforum.org/column/2005/july05/05-07-13.html # Han

OpenBSD SECURITY FIX: Incorrect mbuf handling for ICMP6 packets, 2nd revision

2007-03-17 Thread Tobias Weisserth
Hi everybody, I just noticed Henning's addition to the latest patch. Can I apply it if I already applied the first revision to 4.0 release + errata up to 010 first revision? Or do I have to edit the latest patch to only add the "if" test? I also noticed the index is different in the two revisi

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Ray Percival
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mar 17, 2007, at 3:07 PM, Bryan Allen wrote: On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: Hate to tell you this, but Canada is not the United States. Give us a couple years. Pax Americana, yo. Actually I'm hoping to get BC to invade

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread mcb, inc.
On Sat, 17 Mar 2007, Bryan Allen wrote: On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: Hate to tell you this, but Canada is not the United States. Give us a couple years. Pax Americana, yo. Nah, we tried it in the 1840's. Wasn't worth the bother. -- Monty Brandenberg, Software Cons

Re: forcing WD0/WD1 designation (soekris)

2007-03-17 Thread Brad Brad
Hi, sounds like the soekris is saying the sil3114 is more important. Does the hardware decide precedence other than choosing the drive to boot off? Because it chose the CF for that which is correct. > perhaps the maxtor drive also has a valid bootable partition at > the front and th

Re: Important OpenBSD errata

2007-03-17 Thread Ray Percival
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On Mar 17, 2007, at 1:00 PM, Karel Kulhavy wrote: On Sat, Mar 17, 2007 at 11:43:47AM +1100, fonkprop wrote: Yet again, we see that although Theo is willing to beg, wheedle and threaten his user community into sending him money when he needs it, h

Re: PF weirdness with snapshot

2007-03-17 Thread Wade, Daniel
What am I missing here? The rules look right, why am I getting blocked? # pfctl -sr block drop in log all pass out from (fxp0) to any flags S/SA keep state pass in inet from 10.10.77.0/24 to any flags S/SA keep state # pfctl -sn nat on fxp0 inet from 10.10.77.0/24 to any -> (fxp0:0) rdr pass log o

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Bob Beck
* Bryan Allen <[EMAIL PROTECTED]> [2007-03-17 16:22]: > On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: > > > > Hate to tell you this, but Canada is not the United States. > > Give us a couple years. Pax Americana, yo. > Nah, at the rate it's going in a couple years your deficit and doll

Re: forcing WD0/WD1 designation (soekris)

2007-03-17 Thread Marco S Hyman
> i don't think you can modify attachments with config(8), but You can. Or you can build a custom kernel. My box finds my SATA drive before my ATA drive though I use the ATA drive as wd0. My kernel config has: wd1 at pciide? flags 0x wd0 at pciide? flags 0x wd* at pcii

Re: Is OpenBSD VuXML broken?

2007-03-17 Thread Reyk Floeter
On Sat, Mar 17, 2007 at 09:24:39PM +0100, Matthias Kilian wrote: > On Sun, Mar 18, 2007 at 12:56:50AM +0530, Siju George wrote: > > is there any other place to get updated RSS feed for the same thing? > > http://www.undeadly.org/cgi?action=errata > > It's also metalinked from http://www.openbsd.o

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Bryan Allen
On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: Hate to tell you this, but Canada is not the United States. Give us a couple years. Pax Americana, yo. -- bda

Re: warning "Yet Another Inane Post" or every six month wierdness on misc@ list

2007-03-17 Thread Ray Percival
On Mar 17, 2007, at 1:25 PM, Bob Beck wrote: * Diana Eichert <[EMAIL PROTECTED]> [2007-03-17 08:39]: I don't know what's worse, the junky posts from people who come out of the woodwork around release dates or the "Two chick f/cking in wild orgy" \ "Normalize your Cholesterol" \ "mature blond

Re: Important OpenBSD errata

2007-03-17 Thread Deanna Phillips
Ray Percival writes: > No. Everybody with a clue knows that there is two sources for > good data. The errata page and source-changes. I'd like to add undeadly's RSS here, since I don't think anyone has mentioned it yet. There are two RSS feeds that would have alerted people to this: one for stor

Re: Important OpenBSD errata

2007-03-17 Thread Theo de Raadt
> I get a kick out of people who are too slack to spend the two hours > of reading and twenty minutes of unattended execution time it takes > to CVS or patch a kernel and compile it. Some of these people clearly think they are entitled. But they are not entitled. Nothing entitles them to anythin

Re: Is OpenBSD VuXML broken?

2007-03-17 Thread Matthias Kilian
On Sun, Mar 18, 2007 at 12:56:50AM +0530, Siju George wrote: > is there any other place to get updated RSS feed for the same thing? http://www.undeadly.org/cgi?action=errata It's also metalinked from http://www.openbsd.org/security.html now. Ciao, Kili -- Es gibt kein Leben vor'm Login

Re: Important OpenBSD errata

2007-03-17 Thread Ben Calvert
christ. buddha. the thread that would not die. i invoke godwins law in a (probably ) unsuccessful attempt to end the insanity: nazi nazi holocaust, nazi. On Mar 17, 2007, at 12:09 PM, Karel Kulhavy wrote: [demime 1.01d removed an attachment of type application/pkcs7-signature which had a

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Bob Beck
* Sunnz <[EMAIL PROTECTED]> [2007-03-16 20:50]: > I don't live in US Canada nor Europe... but I am worried if I ordered > "From North America to anywhere worldwide", would the CD have the lack > of built-in cryptography due to the US Export laws? Hate to tell you this, but Canada is not t

Re: warning "Yet Another Inane Post" or every six month wierdness on misc@ list

2007-03-17 Thread Bob Beck
* Diana Eichert <[EMAIL PROTECTED]> [2007-03-17 08:39]: > I don't know what's worse, the junky posts from people who come out of the > woodwork around release dates or the > "Two chick f/cking in wild orgy" \ > "Normalize your Cholesterol" \ > "mature blonde milf f/cking hardcore & s/cking" \ > "

Re: Is OpenBSD VuXML broken?

2007-03-17 Thread Bob Beck
* Siju George <[EMAIL PROTECTED]> [2007-03-17 13:45]: > Hi, > > The latest entry in > > http://www.vuxml.org/openbsd/ > > is > > 2006-01-10clamav -- heap overflow in the UPX code > > more than a year now? > Certainly looks that way. > is there any other place to get updated RSS

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Sat, Mar 17, 2007 at 11:43:47AM +1100, fonkprop wrote: > Yet again, we see that although Theo is willing to beg, wheedle and threaten > his user community into sending him money when he needs it, he holds them in > too much contempt to respond to simple, uncontroversial and valid criticism. > >

Re: Important OpenBSD errata

2007-03-17 Thread Woodchuck
On Fri, 16 Mar 2007, Darren Spruell wrote: > On 3/16/07, Martin Schrvder <[EMAIL PROTECTED]> wrote: > [snip blah blah blah...] > > I want > everyone trying to make that point to think of all the software > vendors they deal with, inclu

Re: Exploit mitigation techniques and kernel code

2007-03-17 Thread Jeroen Massar
Theo de Raadt wrote: [..] >> privilege revocation/separation, > > split the kernel? huh? Well, one could do it, but then you end up with a micro-kernel or at least something that passes, and verifies, messages between the components which run in separate subsystems. Having it compartmentali

Re: Slightly OT: i386 Sound Card Recommendation

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 04:26:27PM -0400, JT Croteau wrote: > This may seem like a simple question but it has been a long time since > I've done any multimedia work on a *nix platform and never on OpenBSD. > I need to add a sound card to my OpenBSD desktop box for basic audio > playback from .mp3's

Re: Important OpenBSD errata

2007-03-17 Thread Jason George
>> > Free Software: "You don't pay back, you pay forward." >> > -- Robert A. Heinlein >> >> I was trying to decide if I should reply, and if so, how. >> >> I looked for your name on the donations list. I don't see it. > >Out of curiosity, when I bought several t-shirts at the

Re: Important OpenBSD errata

2007-03-17 Thread Ray Percival
On Mar 17, 2007, at 11:50 AM, Karel Kulhavy wrote: On Fri, Mar 16, 2007 at 05:53:10AM +, Karl O. Pinc wrote: On 03/15/2007 11:55:44 PM, Kian Mohageri wrote: Security isn't about receiving notifications to your Inbox in a timely fashion. It is about being proactive yourself. You should

Quickly fix the latest IPv6 vulnerability

2007-03-17 Thread Karel Kulhavy
For the people who don't have time to learn about compiling at the moment... Not tested though, sorry. On Fri, Mar 16, 2007 at 01:38:19PM +0100, Paul de Weerd wrote: > > sudo -s > cd /usr > export [EMAIL PROTECTED]:/cvs > export VERS=OPENBSD_`uname -r | tr '.' '_'` >

Is OpenBSD VuXML broken?

2007-03-17 Thread Siju George
Hi, The latest entry in http://www.vuxml.org/openbsd/ is 2006-01-10 clamav -- heap overflow in the UPX code more than a year now? is there any other place to get updated RSS feed for the same thing? Thankyou so much Kind Reagrds Siju

Re: OpenBSD-Entwickler wollten kritische Lu:cke kleinreden

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 05:56:03PM +0800, Lars Hansson wrote: > On Fri, 16 Mar 2007 10:08:02 +0100 > Karel Kulhavy <[EMAIL PROTECTED]> wrote: > > > http://www.heise.de/security/news/meldung/86730 > > And for the majority of the worlds population that doesn't speak German > this says exactly what?

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 01:49:52AM -0500, Travers Buda wrote: > * tony sarendal <[EMAIL PROTECTED]> [2007-03-16 06:03:49]: > > > http://www.openbsd.org/mail.html > > --- > > *security-announce* Security announcements. This low volume list receives > > OpenBSD security advisories and pointers to se

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 05:53:10AM +, Karl O. Pinc wrote: > On 03/15/2007 11:55:44 PM, Kian Mohageri wrote: > > >Security isn't about receiving notifications to your Inbox in a timely > >fashion. It is about being proactive yourself. You should be the one > >taking measures to secure your sy

Re: Important OpenBSD errata

2007-03-17 Thread Nico Meijer
Hi Karel, > Out of curiosity, when I bought several t-shirts at the kd85 shop in > Belgium, does actually a part of it go to the donations list and do I > pop there up with few dollars? No. You make it on the donations list when you make a donation. As to your suggestions: don't expect them to b

Re: Important OpenBSD errata

2007-03-17 Thread Theo de Raadt
> I also suggest that the list include the cumulative amount for each donor, > sorted so that the biggest donors are at the top. A few of us could get started with maintaining such data, but we'd get less othe done. Besides all the development discussions and such I am still falling behind by abo

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Thu, Mar 15, 2007 at 11:49:19PM -0600, Jacob Yocom-Piatt wrote: > Karl O. Pinc wrote: > > On 03/15/2007 11:29:22 PM, Theo de Raadt wrote: > > > >> I looked for your name on the donations list. I don't see it. > > > > I only buy CDs and stuff occasionally, and generally > > invest time in what I

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
--> Bram, your gtodo is mentioned. On Fri, Mar 16, 2007 at 01:40:57AM -0400, Daniel Ouellet wrote: > Karl O. Pinc wrote: > >On 03/15/2007 11:29:22 PM, Theo de Raadt wrote: > > > >>I looked for your name on the donations list. I don't see it. > > > >I only buy CDs and stuff occasionally, and gener

Re: Is the PERL in base stock?

2007-03-17 Thread Marc Espie
The perl in 4.1 is not 100% stock, and the one in 4.2 will be slightly farther from that. We have a few minor fixes and adaptations that are not in 5.8.8: - handling of E in various pod converters - path lookup to handle /usr/local along /usr and possibly a few others I'm not too familiar with...

Re: Is the PERL in base stock?

2007-03-17 Thread Randal L. Schwartz
> "Marc" == Marc Espie <[EMAIL PROTECTED]> writes: Marc> The perl in 4.1 is not 100% stock, and the one in 4.2 will be slightly Marc> farther from that. Marc> We have a few minor fixes and adaptations that are not in 5.8.8: Marc> - handling of E in various pod converters Marc> - path lookup t

verification of downloads - signature, checksums, fingerprints

2007-03-17 Thread Lars D . Noodén
What's the best practice for ensuring that the correct files are downloaded and that they are unmodified either at the mirror, in transit, or by someone masquerading as a mirror? The CD images seem to come with some checksums, but is there some certificate or key that can be acquired to ensure tha

Re: Exploit mitigation techniques and kernel code

2007-03-17 Thread Theo de Raadt
> after reading the recent CORE advisory about the mbuf handling bug, I > was wondering if some of OpenBSD's exploit mitigation strategies could > also be applied to the kernel in order to prevent exploitation of kernel > bugs. Theo's presentation about exploit mitigation ( > http://openbsd.org

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 04:31:32AM +, Karl O. Pinc wrote: > On 03/15/2007 10:48:49 PM, Ray Percival wrote: > >On Mar 15, 2007, at 7:31 PM, Karl O. Pinc wrote: > > >>I rely on having a clear channel for security related > >>problems. > > >The only communication problem here is that you don't l

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 04:23:00AM +, Karl O. Pinc wrote: > No, but if security errata announcements arn't delivered > in a fashion that delivers them to a human then they > do no good. I should not be expected to peruse the > misc@openbsd.org list to find errata announcements. > OpenBSD says

Re: Important OpenBSD errata

2007-03-17 Thread Karel Kulhavy
On Thu, Mar 15, 2007 at 10:29:22PM -0600, Theo de Raadt wrote: > > Free Software: "You don't pay back, you pay forward." > > -- Robert A. Heinlein > > I was trying to decide if I should reply, and if so, how. > > I looked for your name on the donations list. I don't see it. O

Re: pkg_add -ui auto update choses lower version of package by default if there is only one option

2007-03-17 Thread Siju George
On 3/17/07, Marc Espie <[EMAIL PROTECTED]> wrote: Maybe you built it locally and you are `in advance' compared to the official snapshot ? That is highly improbable because I don't know how to do it as of now :-) I checked my ports tree too it has curl-7.15.4 not curl-7.15.5 ==

Re: ospfctl reload problem

2007-03-17 Thread Jon Morby
On 17 Mar 2007, at 16:41, Stuart Henderson wrote: > On 2007/03/17 16:13, Stuart Henderson wrote: >> On 2007/03/17 15:08, Jon Morby wrote: Checking tcpdump it seems that the password is being passed but truncated as 7 characters plus a null character instead of the full 8 character p

Re: No Blob without Puffy

2007-03-17 Thread Theo de Raadt
> > But more and more of these Blob's are making it into FreeBSD all the > > time. The Nvidia driver (though now they are using our nvidia driver, > > I just wonder what happens if every commercial manufacturer starts requiring a > blob? Will OpenBSD stop existing? Or will you adapt a pro-blob p

Re: "make release" question for a non developer

2007-03-17 Thread Jason George
> 2) Do I have to modify another file? No. >>> Very much noted. I have been wondering about this too. >> >> it's the 'i want to create my own style ramdisk kernels >> with their own unique "in-the-ramdrive-userland" consisting >> of a different variety of crunch'ed binaries' scenari

Re: warning "Yet Another Inane Post" or every six month wierdness on misc@ list

2007-03-17 Thread Didier Wiroth
- Original Message - From: Diana Eichert <[EMAIL PROTECTED]> > Theo and crew do incredible stuff, give them a break. > Can't y'all go > harass someone else. > > diana WELL SAID ! ! ! Kind regards Didier

Re: Important OpenBSD errata

2007-03-17 Thread Siegbert Marschall
"Ray Percival" ... > attention had patched and been happy for nearly a week. The logic > behind the misc posting is so very obvious that to bitch about it is > just finding something to complain about. I, of course, don't know > the exact numbers but it seems pretty clear that misc has a much > lar

Re: ospfctl reload problem

2007-03-17 Thread Jon Morby
On 17 Mar 2007, at 15:42, Claudio Jeker wrote: > > Can you try this diff? > > -- > :wq Claudio Yup that did the tric Thanks! -- Jon Morby FidoNet Registration Services Ltd tel: 0845 004 3050 / fax: 0845 004 3051 web: http://www.fido.net/

Re: ospfctl reload problem

2007-03-17 Thread Stuart Henderson
On 2007/03/17 16:13, Stuart Henderson wrote: > On 2007/03/17 15:08, Jon Morby wrote: > > > Checking tcpdump it seems that the password is being passed but > > > truncated as 7 characters plus a null character instead of the full > > > 8 character password > > try this .. ok claudio's is proba

Re: Is the PERL in base stock?

2007-03-17 Thread Randal L. Schwartz
> "Michael" == Michael Dexter <[EMAIL PROTECTED]> writes: >> From what I can tell, the PERL used in OpenBSD is stock: Michael> http://www.openbsd.org/cgi-bin/cvsweb/src/gnu/usr.bin/perl/ Michael> Could someone confirm or deny this? Is it reviewed or hardened in any way? As far as I can tel

Re: ospfctl reload problem

2007-03-17 Thread Stuart Henderson
On 2007/03/17 15:08, Jon Morby wrote: > > Checking tcpdump it seems that the password is being passed but > > truncated as 7 characters plus a null character instead of the full > > 8 character password try this .. Index: ospf.h

Is the PERL in base stock?

2007-03-17 Thread Michael Dexter
Hello, >From what I can tell, the PERL used in OpenBSD is stock: http://www.openbsd.org/cgi-bin/cvsweb/src/gnu/usr.bin/perl/ Could someone confirm or deny this? Is it reviewed or hardened in any way? Thanks, Michael.

Re: ospfctl reload problem

2007-03-17 Thread Claudio Jeker
On Sat, Mar 17, 2007 at 03:08:21PM +, Jon Morby wrote: > On 17 Mar 2007, at 14:48, Jon Morby wrote: > > > Doing an ospfctl reload seems to result in problems with simple > > authentication enabled > > > > Mar 17 14:44:14 l2-c1 ospfd[7096]: recv_packet: authentication > > error, interface v

Exploit mitigation techniques and kernel code

2007-03-17 Thread Andreas Bartelt
Hi all, after reading the recent CORE advisory about the mbuf handling bug, I was wondering if some of OpenBSD's exploit mitigation strategies could also be applied to the kernel in order to prevent exploitation of kernel bugs. Theo's presentation about exploit mitigation ( http://openbsd.org

Re: No Blob without Puffy

2007-03-17 Thread Ray Percival
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Please do make an effort to find some information yourself before asking, or you will start getting on people's nerves, even if you do not intend to. Start? iD8DBQFF/AzH5B7p9jYarz8RAm2BAJ9ak/sun5B61mKN/jIF0GqMJbiy0gCfSsbx 9USyHH/QNgeX53vWKUov

Re: forcing WD0/WD1 designation (soekris)

2007-03-17 Thread Nick !
On 3/17/07, jared r r spiegel <[EMAIL PROTECTED]> wrote: On Sat, Mar 17, 2007 at 05:41:23AM +, Brad Brad wrote: > > This is when there's only one drive. > wd0 at pciide1 channel 0 drive 0: > > this is when there's two > wd0 at pciide0 channel 3 drive 0: > wd1 at pciide1 channel 0 drive 0:

Re: reverse ftp-proxy and reply-to?

2007-03-17 Thread Raja Subramanian
On 3/17/07, Sebastian Reitenbach <[EMAIL PROTECTED]> wrote: I use ftp-proxy on my firewall as a reverse proxy for a host on the dmz. Please find Bill Marquette's ftp-proxy patch from pfSense CVS: http://cvstrac.pfsense.com/dirview?d=tools/pfPorts/pftpx-routeto I'm successfully using this in

Re: reverse ftp-proxy and reply-to?

2007-03-17 Thread Camiel Dobbelaar
On Sat, 17 Mar 2007, Sebastian Reitenbach wrote: > I use ftp-proxy on my firewall as a reverse proxy for a host on the dmz. The > incoming connections come in on one of the the external interfaces, which is > not the default gateway of the firewall. Therefore I use reply-to statements > on the pass

Re: ospfctl reload problem

2007-03-17 Thread Jon Morby
On 17 Mar 2007, at 14:48, Jon Morby wrote: > Doing an ospfctl reload seems to result in problems with simple > authentication enabled > > Mar 17 14:44:14 l2-c1 ospfd[7096]: recv_packet: authentication > error, interface vlan544 > Mar 17 14:44:45 l2-c1 last message repeated 213 times > > Checki

Re: No Blob without Puffy

2007-03-17 Thread Ingo Schwarze
Hi Karel, Karel Kulhavy wrote on Sat, Mar 17, 2007 at 10:38:11AM +0100: > On Fri, Mar 16, 2007 at 12:38:05PM -0600, Theo de Raadt wrote: >> Someone asked: >>> Is it true that Puffy is not here because of Theo's concerns >>> about his copyrighted Puffy logo? >>> http://misc.allbsd.de/Kampagnen/NoB

ospfctl reload problem

2007-03-17 Thread Jon Morby
Doing an ospfctl reload seems to result in problems with simple authentication enabled Mar 17 14:44:14 l2-c1 ospfd[7096]: recv_packet: authentication error, interface vlan544 Mar 17 14:44:45 l2-c1 last message repeated 213 times Checking tcpdump it seems that the password is being passed but

warning "Yet Another Inane Post" or every six month wierdness on misc@ list

2007-03-17 Thread Diana Eichert
my very own inane post. Ya know, I could probably mark two dates on a calendar to indicate when inane posts start appearing on the misc@ list. What is it about upcoming releases that causes this? I don't know what's worse, the junky posts from people who come out of the woodwork around rele

Re: pkg_add -ui auto update choses lower version of package by default if there is only one option

2007-03-17 Thread Siju George
On 3/17/07, Siju George <[EMAIL PROTECTED]> wrote: On 3/16/07, Marc Espie <[EMAIL PROTECTED]> wrote: > Wait for 4.2. Sorry, it's not implemented yet. pkg_add doesn't really > know how to compare versions. And in case you're wondering, it's harder > than it seems... > Thankyou so much marc for th

Re: pkg_add -ui auto update choses lower version of package by default if there is only one option

2007-03-17 Thread Marc Espie
Maybe you built it locally and you are `in advance' compared to the official snapshot ?

Re: ERR R and booting a compact flash card

2007-03-17 Thread Gordon Turner
On Sat, 10 Mar 2007 22:39:53 +, Stuart Henderson <[EMAIL PROTECTED]> wrote: > How about trying to pxe-boot bsd.rd and install on the device itself? ... > Even if you ultimately want to use custom scripts to do things then it > would still be worth doing this as a test and if it works, try and w

PF weirdness with snapshot

2007-03-17 Thread Wade, Daniel
It's been 12 hours. Not sure where the first copy went to?? -Original Message- From: Wade, Daniel Sent: Fri 3/16/2007 8:52 PM To: misc@openbsd.org Cc: Subject:PF weirdness with snapshot Anyone else having issues with pf? I don't think my rdr pass rule is keeping s

Re: sshd configure howto

2007-03-17 Thread Joachim Schipper
On Sat, Mar 17, 2007 at 12:46:29PM +0800, Jay Jesus Amorin wrote: > On 3/17/07, Joachim Schipper <[EMAIL PROTECTED]> wrote: > >On Fri, Mar 16, 2007 at 07:17:10PM +0800, Jay Jesus Amorin wrote: > >> hi gurus, > >> > >> how will i configure sshd to allow only one username at a time. > >> > >> example

Cannot use ServerName with an Apache reverse proxy

2007-03-17 Thread Jeremie Le Hen
Hi list, Please Cc: me in your reply, I'm not subscribed. Thanks. I've already sent this to Apache users' ML and was redirected here because it appears OpenBSD's httpd(8) is more or less heavily patched. According to them, this problem would not occur with a classical Apache (I couldn't test it

Re: Compiling your own system as a way of upgrading it is not supported

2007-03-17 Thread Mike Piety
On Sat, 17 Mar 2007 01:31:05 +0100 "Martin Schrvder" <[EMAIL PROTECTED]> wrote: > 2007/3/16, Mike Piety <[EMAIL PROTECTED]>: > > uh, why don't you just load your release bsd.rd at the boot prompt, > > and do an upgrade to 4.0, using the ftp method? This would install > > 4.0- stable, and would be

Re: No Blob without Puffy

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 12:38:05PM -0600, Theo de Raadt wrote: > > Is it true that Puffy is not here because of Theo's concerns about > > his copyrighted Puffy logo? > > http://misc.allbsd.de/Kampagnen/NoBlob/NoBlob-en-Poster.jpg > > No. That is false. Whoever told you that lied to you. That wa

Re: OT: Asymmetric Multi-Core Debugging

2007-03-17 Thread J.C. Roberts
On Saturday 17 March 2007 01:42, Artur Grabowski wrote: > "J.C. Roberts" <[EMAIL PROTECTED]> writes: > > If you have ever wondered why the OpenBSD multi-processor kernel is > > named "GENERIC.MP" rather than "GENERIC.SMP," it's because you've > > missed out on some of Theo's ideas and plans to do a

Re: Compiling your own system as a way of upgrading it is not supported

2007-03-17 Thread Woodchuck
On Fri, 16 Mar 2007, Karel Kulhavy wrote: > "Some reasons why NOT to build from source: > [...] > Compiling your own system as a way of upgrading it is not supported." > http://openbsd.org/faq/faq5.html > > I want to upgrade my 4.0-release system to get rid of the ipv6 remote > vulnerability. I u

Re: No Blob without Puffy

2007-03-17 Thread Karel Kulhavy
On Fri, Mar 16, 2007 at 02:06:50PM -0500, K K wrote: > It'd be great if Theo could make a clear statement on Puffy, the same > as Marshall Kirk McKusick has for the daemon. I had cause to use a > variant of Marshall's beastie for a project which was marginally > within his published guidelines, a

Re: OT: Asymmetric Multi-Core Debugging

2007-03-17 Thread Artur Grabowski
"J.C. Roberts" <[EMAIL PROTECTED]> writes: > If you have ever wondered why the OpenBSD multi-processor kernel is > named "GENERIC.MP" rather than "GENERIC.SMP," it's because you've > missed out on some of Theo's ideas and plans to do asymmetric > mutli-processing processing rather than the usua

Re: "make release" question for a non developer

2007-03-17 Thread Marc Balmer
jared r r spiegel wrote: On Fri, Mar 16, 2007 at 11:51:15AM +0100, Alexander Hall wrote: Miod Vallat wrote: 2) Do I have to modify another file? No. Very much noted. I have been wondering about this too. it's the 'i want to create my own style ramdisk kernels with their own unique "in-

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Marc Balmer
Sunnz wrote: Just wondering... if I should order it from the international store: https://https.openbsd.org/cgi-bin/order?CD41=1&CD41%2b=Add I don't live in US Canada nor Europe... but I am worried if I ordered "From North America to anywhere worldwide", would the CD have the lack of built-in cr

reverse ftp-proxy and reply-to?

2007-03-17 Thread Sebastian Reitenbach
Hi list, I use ftp-proxy on my firewall as a reverse proxy for a host on the dmz. The incoming connections come in on one of the the external interfaces, which is not the default gateway of the firewall. Therefore I use reply-to statements on the pass in rules to make sure the answer packets are l