openbsd-misc mailing list

FromSubjectsort iconDate
Rob Wilson
Travelbully.com Cheap International Airfare & Hotels

<!DOCTYPE HTML PUBLIC "-//W3C//DTD HTML 4.0 Transitional//EN">
<HTML><HEAD>
<META http-equiv=Content-Type content="text/html; charset=unicode">
<META content="MSHTML 6.00.6000.16674" name=GENERATOR></HEAD>
<BODY>
<P>Hi,</P>
<P>Cheap International Airfare and Hotels @ <A
href="http://www.travelbully.com">http://www.travelbully.com</A></P>
<P>For better rates than what's posted, call Rob @ 314-757-4063 or email us
at...

Jul 9, 5:25 pm 2008
Unix Fan
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Why haven't the developers posted a formal annoncement clearifing
if the distributed BIND is vulnerable?

If so, where the hell is the patch?

-Nix Fan.

Jul 9, 11:48 am 2008
Giancarlo Razzolini
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Pal, i believe you won't even BE affected by this issue. If so, it will
take time. Time enough for developers to correct it. There's having all
this fuss in the security community about this today. Didn't see any
saying they were affected. So why don't you cool down and let the dev's
do what they LIKE to do, they aren't paid for it, and must of people who
uses openbsd doesn't even thank them, not to mention support in any
kind. So take easy and watch very carefully what you write on this
mailing list...

Jul 9, 1:06 pm 2008
Daniel A. Ramaley
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Just curious, how much did you pay for your support contract? Clearly if
you feel you are so entitled to a quick patch you must have paid a
substantial sum in order to be so upset.

Though i've given a few meager donations to OpenBSD, i have not paid for
a support contract of any sort. Thus i am not entitled to any level of
service and will have to wait patiently and without complaint just like
everyone else.

------------------------------------------------------------------------
Dan Rama...

Jul 9, 12:35 pm 2008
bofh
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Love your gimme gimme attitude. If you spent half a second thinking about this:

1). They didn't contact openbsd about this
2). Took them months to put the fix in
3). Takes time to figure out what the issue is, figure out how to fix
it, test, and deploy
4). Time that is not spend responding to gimme idiots, that is
5). Are you even running a caching server?

--
http://www.glumbert.com/media/shift
http://www.youtube.com/watch?v=tGvHNNOLnCk
"This officer's men seem to follow him merely o...

Jul 9, 12:22 pm 2008
Andreas Maus
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Hehehe ;)

Furthermore you can see in the US-CERT that this VULN was:

Date First Published 07/08/2008 02:46:15 PM

As you know some developers may live outside .us in a different
timezone (and developers in .us/.ca have to work at this time).
So in e.g. Europe this was yesterdays evening.

You can accelerate proceedings by a) donating to OpenBSD
and b) - if you need this patch REALLY FAST - hire a paid
conslutant to develope the patch and send it to the list.

And OpenBSD doesn't have a SLA ....

Jul 9, 1:17 pm 2008
David Wilk
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

I'm not one to condone shitty attitudes.

However, I think in this case it's unfair to claim that one can have
no expectations of OpenBSD with regards to security patches. If I
could have no such expectations, I would not use OpenBSD in the first
place. I have these expectations based on a very impressive security
history for which the OpenBSD developers deserve much in the way of
praise.

Additionally, loyal OpenBSD users may be interested in the details of
the vulnerability disclosure. There ...

Jul 9, 1:58 pm 2008
STeve Andre'
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

You know what I expect?

I expect the OpenBSD response will be excellent, and out on its own
timeframe. Rushing a fix into place can be worse than not doing
anything at all. I have no idea what they're doing, have no idea
with whom they may be talking. But I know that it is being worked
on, and will be a reasoned response to the problem.

More than "expect", I trust OpenBSD.

--STeve Andre'

Jul 9, 2:40 pm 2008
Theo de Raadt
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

And we will continue to try to stay ahead of the curve. But please,
bear with me, because I see you want to talk about expectations.
Sure, let's talk about them.

First off, in this case just like in some other cases, you can
_expect_ to wait for a proper OpenBSD patch, since we are not solving
this by using the ISC solution. There are reasons, and they are our
private reasons.

Meanwhile, I _expect_ that our developers will do a proper job, on
their own time schedule.

I also _expect_ tha...

Jul 9, 2:19 pm 2008
David Wilk
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

easy, Theo. I actually very much agree with you, and had not intended
to stir anything up here. If users wish to get involved in an attempt
(regardless of how hopeless) to encourage third parties to cooperate
with OpenBSD developers, then you can certainly abstain from enabling
that kind of help if you so choose. However, I wouldn't assign any
malice to those seeking information that might enable them to do so.

I think perhaps you have an inflated impression of my expectations of
OpenBSD and its...

Jul 9, 4:05 pm 2008
Steve Shockley
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

The Cert Advisory document (the MS Word doc file) claims that "OpenBSD"
was notified on 2008-5-5 11:24:02. Obviously I have no idea if this is
true. Since it seems almost everyone was caught without a patch on
disclosure day, the notification list seems suspect.

The notification timeline in the document is somewhat interesting.
Microsoft was notified first (okay, I understand the guy works there).
A bunch of large corporations were notified on April 21, then ISC was
notified on April 29. ...

Jul 9, 1:16 pm 2008
Theo de Raadt
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

You really should adjust your extremely pathetic attitude.

Jul 9, 12:02 pm 2008
Zamri Besar
Vulnerability Note VU#800113 - Multiple DNS implementations ...

Good morning,

Today, I'm received alert from one of my friends regarding to
Vulnerability Note VU#800113 - Multiple DNS implementations vulnerable
to cache poisoning.
http://www.kb.cert.org/vuls/id/800113

I checked the above site, and found that most of the *BSD status are
unknown. Is this bug affected OpenBSD default bind dns?

I'm don't know either the above bug is similar to this thread or not.
http://marc.info/?l=openbsd-misc&m=118539211412877&w=2

--
Thank you.

Yours truly,
...

Jul 9, 10:45 am 2008
Andreas Maus
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

I think named on OpenBSD 4.3 is affected too.
See
http://www.nabble.com/Actual-BIND-error---Patching-OpenBSD-4.3-named---t...

So long,

Andreas.

--
Windows 95: A 32-bit patch for a 16-bit GUI shell running on top of
an 8-bit operating system written for a 4-bit processor by a 2-bit
company who cannot stand 1 bit of competition.

Jul 9, 11:20 am 2008
Mathieu SEGAUD
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

OpenBSD's named is affected.
It is a flow in the DNS protocol, which means potentially *all*
implementations are affected...

--
Mathieu

Jul 9, 10:52 am 2008
David Terrell
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Credit where credit is due: djbdns isn't.

Without specifics on the issue, I can't tell if OpenBSD's bind is truly
vulnerable, but it certainly does use a fixed source port.

--
David Terrell
dbt@meat.net
((meatspace)) http://meat.net/

Jul 9, 11:29 am 2008
Mathieu SEGAUD
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

Stuart Henderson already answered this question on misc@ (12:10 UTC,
today). Named is vulnerable. The resolver is not :)

--
Mathieu

Jul 9, 12:14 pm 2008
Zamri Besar
Re: Vulnerability Note VU#800113 - Multiple DNS implementati...

On Thu, Jul 10, 2008 at 12:14 AM, Mathieu SEGAUD

I'm just finish re-read it right now. Thank you for the input and I
agree that at this moment, we will waiting for the latest official
update from OpenBSD developers.

And probably a minor update for those who are deploying it over
Debian. Looks like it is time to patch it.
http://www.debian.org/security/2008/dsa-1603

Have a nice day!

-zamri-

Jul 9, 1:02 pm 2008
Stuart Henderson
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

thanks to those who pointed out (self) includes 127.0.0.1, so you
don't want to use -> (self), rather use -> (egress).

e.g. "nat on egress proto udp from (self) to any port 53 -> (egress)",

if you have a larger address space available you can use more
of it, e.g. you can use "{192.0.192.0/24} random" on a firewall in
front of name servers.

Jul 9, 9:17 am 2008
Stuart Henderson
Re: ntpd.conf with nmea

it's not a server, it's a sensor.

Jul 9, 8:29 am 2008
riwanlky
Re: ntpd.conf with nmea

Thanks you to point it out. Minor mistake big different.

It working.

Best regards,
Riwan

Jul 9, 8:53 am 2008
Stuart Henderson
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

named is. the stub resolver isn't.

mcbride@ pointed out that you can give named some more protection
by natting outbound udp traffic destined for port 53 (even just on
the box running the resolver, it doesn't have to be on a firewall
in front). something like,

nat on egress proto udp from (self) to any port 53 -> (self)

there - if you need to tell people you're doing something
while you wait for a better solution, you have an option.
check this with tcpdump and requests from multiple NS, ...

Jul 9, 8:10 am 2008
Ted Unangst
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

I don't think this actually accomplishes much. It still lets poisoned
replies back in on the previous port number.

Jul 9, 1:19 pm 2008
Steve Tornio
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

But does it allow a poisoned reply from the spoofed address?

As I understand the threat, based on the limited information:

1. Attacker sends valid user a www.badman.com link to click on
2. Resolver queries to badman.com NS from port 55555 for
www.badman.com, which is a CNAME to www.ebay.com
3. New query for www.ebay.com to ebay.com NS originates from udp port
54321
4. A spoofed UDP packet from the badman.com NS using 55555 shouldn't
match the ebay query, and the poisoning shouldn't work....

Jul 9, 1:44 pm 2008
Ted Unangst
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

oh, right. I think I forgot even UDP packets have IP addresses. :(

Jul 9, 2:09 pm 2008
openbsd misc
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

http://cr.yp.to/djbdns/run-cache.html
http://www.ro.kde.org/djbdns/mywork/jumbo/index.html

I never understood the mix of authoritive server and resolver ... Use dnscache
as resolver and you you're (AFAIK) save.

Regards

Jul 9, 3:49 pm 2008
mark reardon
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

doxpara.com reports no issues with unbound FWIW.

Thanks to Stuart for this suggestion during the previous DJBware for ports
thread.

Jul 9, 8:26 am 2008
riwanlky
ntpd.conf with nmea

I want my OpenBSD 4.3 to get clock from my serial GPS device.

The device is working
# cu -l /dev/cua00 -s 4800
Connected
$GPRMC,113516.000,A,0608.4965,S,10651.2976,E,0.07,229.06,090708,,,A*75
$GPRMC,113517.000,A,0608.4964,S,10651.2975,E,0.04,193.07,090708,,,A*76
$GPRMC,113518.000,A,0608.4963,S,10651.2974,E,0.07,144.19,090708,,,A*79
$GPRMC,113519.000,A,0608.4962,S,10651.2974,E,0.06,159.34,090708,,,A*7B
$GPRMC,113520.000,A,0608.4962,S,10651.2974,E,0.08,246.72,090708,,,A*70
$GPRMC,113521.000,A,0608....

Jul 9, 7:52 am 2008
Otto Moerbeek
Re: ntpd.conf with nmea

server != sensor

See man ntpd.conf

-Otto

Jul 9, 8:14 am 2008
Martin Schröder
altq and interface groups

Hi,
setup: 4.2 with tun0 being a pppoe(8) int and tun1 being a ssh-vpn
over tun0. altq is running on tun0.

I know that altq doesn't support interface groups (and that support is
not planned (see
http://marc.info/?l=openbsd-misc&m=112431574118264&w=2)) but is there
a way around this? Currently altq sees all traffic on tun1 on tun0 as
default instead of ssh, which it is.

Best
Martin

Jul 9, 7:15 am 2008
O. Griener
ochi (-current)

hi @misc

any suggestions beside UKC disable?

/bsd: ohci0: 1 scheduling overruns
/bsd: ohci0: 4 scheduling overruns
/bsd: ohci0: 1 scheduling overruns
/bsd: ohci0: 1 scheduling overruns
/bsd: ohci0: 2 scheduling overruns
/bsd: ohci0: 2 scheduling overruns
/bsd: ohci0: 3 scheduling overruns
/bsd: ohci0: 1 scheduling overruns
/bsd: ohci0: 4 scheduling overruns
/bsd: ohci0: 2 scheduling overruns
/bsd: ohci0: 1 scheduling overruns
last message repeated 5 times
/bsd: ohci0: 2 scheduling overruns...

Jul 9, 6:26 am 2008
Andreas Maus
Actual BIND error - Patching OpenBSD 4.3 named ?

Hi.

I guess OpenBSDs named is affected by the actual issue:

http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2008-1447
http://www.kb.cert.org/vuls/id/800113

So I hope a patch is in progress ?
Or is OpenBSD not affected by this issue?

So long,

Andreas.
--
Windows 95: A 32-bit patch for a 16-bit GUI shell running on top of
an 8-bit operating system written for a 4-bit processor by a 2-bit
company who cannot stand 1 bit of competition.

Jul 9, 5:10 am 2008
Rod Whitworth
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

# tcpdump -nettti rl0 dst port 53
tcpdump: listening on rl0, link-type EN10MB
Jul 09 19:48:27.786683 00:01:80:0f:2b:94 00:00:24:c6:18:85 0800 70:
192.168.80.4.16284 > 192.168.80.1.53: 57120+ A? pps.com.au. (28)
Jul 09 19:48:43.690332 00:01:80:0f:2b:94 00:00:24:c6:18:85 0800 67:
192.168.80.4.1356 > 192.168.80.1.53: 32536+ A? ibm.com. (25)
Jul 09 19:49:11.013223 00:01:80:0f:2b:94 00:00:24:c6:18:85 0800 69:
192.168.80.4.14540 > 192.168.80.1.53: 29420+ A? intel.com. (27)
....

# uname -a
...

Jul 9, 5:53 am 2008
Steve Tornio
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

I get a different result using the external interface of my caching
name server, and mine looks vulnerable.

frank# tcpdump -nettti em1 dst port 53
tcpdump: listening on em1, link-type EN10MB
Jul 09 05:54:23.291421 00:0f:1f:04:8c:36 00:02:b9:38:23:f0 0800 82:
xx.xx.9.35505 > 205.177.95.83.53: 27972 A? a1397.g.akamaitech.net. (40)
Jul 09 05:54:25.814869 00:0f:1f:04:8c:36 00:02:b9:38:23:f0 0800 86:
xx.xx.95.9.35505 > 75.126.144.219.53: 58999% [1au] A? www.virg9lio.it.
(44)
Jul 09 05:...

Jul 9, 6:58 am 2008
Mike M
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

On 7/9/2008 at 5:58 AM Steve Tornio wrote:

|On Jul 9, 2008, at 4:53 AM, Rod Whitworth wrote:
|>
|>
|> # tcpdump -nettti rl0 dst port 53
|> tcpdump: listening on rl0, link-type EN10MB
|> Jul 09 19:48:27.786683 00:01:80:0f:2b:94 00:00:24:c6:18:85 0800 70:
|> 192.168.80.4.16284 > 192.168.80.1.53: 57120+ A? pps.com.au. (28)
|> Jul 09 19:48:43.690332 00:01:80:0f:2b:94 00:00:24:c6:18:85 0800 67:
|> 192.168.80.4.1356 > 192.168.80.1.53: 32536+ A? ibm.com. (25)
|> Jul 09 ...

Jul 9, 8:11 am 2008
mark reardon
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

Hi Andreas,

Aren't you dumping on the wrong interface here?
Should it not be your $ext_if where the alleged poisoning will come from?

Jul 9, 6:19 am 2008
Andreas Maus
Re: Actual BIND error - Patching OpenBSD 4.3 named ?

Hi Mark.

Excuse me? The tcpdump was provided by Rod Whitworth
<glisten@witworx.com>.

So long,

Andreas.

--
Windows 95: A 32-bit patch for a 16-bit GUI shell running on top of
an 8-bit operating system written for a 4-bit processor by a 2-bit
company who cannot stand 1 bit of competition.

Jul 9, 6:52 am 2008
Markus Wernig
isakmpd times out on rolled-over client certificate

Hi all

I have an OBSD4.3 VPN gateway that authenticates users based on their
certificate and an isakmpd.policy, which works just fine. Now a user had
to renew his certificate: same CA, same CA certificate, same Subject DN,
same EVERYTHING. I'd have expected that he'd just need to close the VPN
tunnel, install the new certificate, authenticate again and that'd be
it. But not so. isakmpd logs and sends back: isakmpd[26674]: dropped
message from aaa.bbb.ccc.ddd port 500 due to notification type ...

Jul 9, 4:13 am 2008
my mail
Can't install using pkg_add from FTP mirror and from Local M...

I have success install OpenBSD 4.3, but when i want install packages using pkg_add, why i can't install it?

first i try from local ssh server from my LAN

-------------------------------------------
# export PKG_PATH=scp://root@192.168.1.1/OpenBSD4.3/i386/
# pkg_add gdm
root@192.168.1.1's password:
Can't install glib2-2.14.5: lib not found iconv.4.0
Dependencies for glib2-2.14.5 resolve to: libiconv-1.12, pcre-7.6, gettext-0.17
Full dependency tree is libiconv-1.12,pcre-7.6,gettext-0.17
iconv.4....

Jul 9, 4:04 am 2008
Jacob Meuser
Re: Can't install using pkg_add from FTP mirror and from Loc...

you have libiconv.so.5.0 installed, but you are trying to install
something that wants libiconv.so.4.0.

libiconv.so.5.0 is from -current (since May 28, 2008), but you appear
to be pointing at a 4.3-release package repository, and you said you
installed 4.3.

looks like you are experiencing confusion with -release and snapshots.

http://www.openbsd.org/faq/faq5.html#Flavors

--
jakemsr@sdf.lonestar.org
SDF Public Access UNIX System - http://sdf.lonestar.org

Jul 9, 4:27 am 2008
Louis V. Lambrecht
Re: Can't install using pkg_add from FTP mirror and from Loc...

Definitely a libraries mixup with gettext and libiconv versions.

Just curious, what is the output of:
ls -ald /var/db/pkg/.*
guess there must be some list.

Jul 9, 10:53 am 2008
David Schulz
Identifying Bandwidth Hogs

Hello,

can someone recommend me a good way to quickly determine who on the
network is using up most the Bandwith, and preferrably, what are the
using it for?

I have a 4.3 Machine, which is the Firewall and Router for a Network
with about 100 Machines. Every once in a while, i see the Traffic
picking up consideribly when using bwm-ng to check. During normal
Operation, i know the average Kilobytes per second is around 100kbps ,
but when bwm-ng shows me the traffic is going up 750kbps, and th...

Jul 9, 1:51 am 2008
Martin Schröder
Re: Identifying Bandwidth Hogs

ntop?

Best
Martin

Jul 9, 4:47 am 2008
Theo de Raadt
PCI-e system

Brad in Toronto needs a PCI-e system (he prefers a desktop, i386 or
amd64) as soon as possible for some driver development he's doing.

If anyone can get him one soon, please drop him a note.

Thanks.

Jul 8, 11:15 pm 2008
Top Shop
Ko su favoriti i dobitnici?

Nagradni kviz
Euro 2008

Top Shop

Proveri ko je pobednik ...

Euro 2008 je zavr

Jul 8, 9:04 pm 2008
Jose Fragoso
trouble with running spamd on 4.4 BETA

Hi,

I am having some problems while trying to run spamd in greylisting
mode in a bridge.

For some reason, spamd is not greylisting, and the all the connections
(even the initial ones) seem to timeout. I see no added GREY entry with
spamdb. If I try to connect (say, using telnet ipaddr smtp) to the smtp
server from outside, I only see the first '220 hostname ESMTP spamd ...'
message. After that, everything hangs. If I type helo myhostname, I get
no answer. From what I understand, I should get som...

Jul 8, 8:00 pm 2008
Michael
Re: trouble with running spamd on 4.4 BETA

Hi,

Jose Fragoso schrieb:
> I am having some problems while trying to run spamd in greylisting
> mode in a bridge.
>
> For some reason, spamd is not greylisting, and the all the connections
> (even the initial ones) seem to timeout.

Just out of curiosity, is modulate state working for you?

Michael

Jul 9, 1:22 am 2008
Tom Le Page
Re: Digital IO - Phidgets support? alternatives?

Thanks for that, I had not come across the Barix range of devices before.
Indeed, it does appear more expensive per unit!
But it should be simpler to query (http) than the Phidgets...

Jul 9, 4:46 am 2008
previous daytodaynext day
NoneJuly 9, 2008None