Re: sftp server empty password login

2024-03-26 Thread Darren Tucker
On Tue, 26 Mar 2024 at 23:49, Sylvain Saboua wrote: [...] > /bin/true is not in the /etc/shells file on my system. > Did you suggest I should add it ? I did suggest that as a possible resolution to your problem. Since your problem is now resolved, I wouldn't change it. -- Darren

Re: sftp server empty password login

2024-03-26 Thread Darren Tucker
've edited the passwd file with vipw and removed the hashed password value leaving nothing in the password field, ie someuser::1001:1001: [etc ...] -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA Good judgement comes with exper

Re: Booting OpenBSD 7.3's i386 bsd.rd

2023-05-01 Thread Darren Tucker
t> set tty com0 (Replace 19200 with whatever the console speed is). If that works, put it in /etc/boot.conf -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA Good judgement comes with experience. Unfortunately, the experience usua

Re: LAN slow speed transfer

2023-02-03 Thread Darren Tucker
On Fri, 3 Feb 2023 at 22:40, Crystal Kolipe wrote: > On Fri, Feb 03, 2023 at 10:33:16PM +1100, Darren Tucker wrote: > > Fast ethernet (100base-T) uses pins 1, 2, 3 & 6 [...] > But the output from ifconfig does suggest that the link was running with > 1000baseT modulation: &g

Re: LAN slow speed transfer

2023-02-03 Thread Darren Tucker
, which is about the speed that you saw. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: gl.inet Brume (GL-MV1000): sdcard works with 6.8 but not -current

2022-05-24 Thread Darren Tucker
On Fri, 13 May 2022 at 11:07, Darren Tucker wrote: > I've had two people ask me about this device in the last few days > so I thought I'd post a followup describing what I did and found. > As a reminder, this is an gl.inet GL-MV1000[0] (aka Brume) device. Current status: > Using t

Re: gl.inet Brume (GL-MV1000): sdcard works with 6.8 but not -current

2022-05-12 Thread Darren Tucker
d0 at scsibus0 targ 1 lun 0: removable sd0: 7456MB, 512 bytes/sector, 15269888 sectors scsibus1 at sdmmc0: 2 targets, initiator 0 sd1 at scsibus1 targ 1 lun 0: removable sd1: 60906MB, 512 bytes/sector, 124735488 sectors vscsi0 at root scsibus2 at vscsi0: 256 targets softraid0 at root scsibus3 at softraid0

Re: ssh authlog: Failed none for invalid user

2021-08-10 Thread Darren Tucker
hat to do next. This is what you're seeing. When I last looked, the bulk of the password guessing bots just sent a single "password" auth method and if it doesn't work, disconnect. Apparently the bots you're seeing behave a bit more like other clients. [0] https://datatracker.ietf.org/doc/

Re: poor ethernet network performance

2021-05-16 Thread Darren Tucker
lar in the past and it was a duplex mismatch. If you have a managed switch, check that it and ifconfig agree on the duplex setting that was auto-negotiated. Failing that, try forcing either full-duplex or half-duplex with ifconfig and/or hostname.re0. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA

Re: gl.inet Brume (GL-MV1000): sdcard works with 6.8 but not -current

2021-04-05 Thread Darren Tucker
lf, which is still running 6.8 stable due to the aforementioned problem finding the sdcard. Any thanks to you and Patrick for the analysis and fix. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes

Re: gl.inet Brume (GL-MV1000): sdcard works with 6.8 but not -current

2021-04-03 Thread Darren Tucker
switch seems to > > be pretty common in this class of device. > > And if someone wants to program it, feel free to, mvsw(4) exists for a > reason, might just need some code. :) > and maybe docs :-) # man 4 mvsw man: No entry for mvsw in section 4 of the manual. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: The simplest full cray data core with 3 cpu's and a physics hack that makes it work

2021-04-02 Thread Darren Tucker
. > To drag this a tiny bit toward the approximate direction of being on-topic: if you do find one and want to run OpenSSH on it, you'll need to use 7.6p1 or earlier since I removed UNICOS support in 7.7p1 ( https://github.com/openssh/openssh-portable/commit/ddc0f3814881ea279a6b6d4d98e03afc60ae1ed7

Re: gl.inet Brume (GL-MV1000): sdcard works with 6.8 but not -current

2021-04-01 Thread Darren Tucker
initiator 0 sd1 at scsibus1 targ 1 lun 0: removable sd1: 30436MB, 512 bytes/sector, 62333952 sectors vscsi0 at root scsibus2 at vscsi0: 256 targets softraid0 at root scsibus3 at softraid0: 256 targets root on sd1a (9e51f250b602291d.a) swap on sd1b dump on sd1b WARNING: CHECK AND RESET THE D

gl.inet Brume (GL-MV1000): sdcard works with 6.8 but not -current

2021-03-31 Thread Darren Tucker
1a (9e51f250b602291d.a) swap on sd1b dump on sd1b WARNING: CHECK AND RESET THE DATE! Automatic boot in progress: starting file system checks. /dev/sd1a (9e51f250b602291d.a): file system is clean; not checking 9e51f250b602291d.i: 6 files, 16034 free (8017 clusters) pf enabled starting network r

Re: sshd: no IP address in error msg?

2021-03-16 Thread Darren Tucker
ort 21285: invalid format -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: Problem with SSH Internet traffic outgoing endpoint with dynamic port forwarding

2019-07-11 Thread Darren Tucker
socks client to an IP address as well as domain name. The test to an IP address will remove the DNS variable. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the exper

Re: RS-232 serial to ethernet

2019-04-09 Thread Darren Tucker
parts (microsd card, case) so it'd probably cost more (and the onboard wifi isn't supported so if you wanted wifi you'd have to add a USB one). -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes

Re: Broken links on https://www.openssh.com/goals.html

2019-04-04 Thread Darren Tucker
or the existing functions pending a better solution. The change should be live shortly. Thanks. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually

Re: ssh -Y behaviour change

2018-09-12 Thread Darren Tucker
break; -- config_test = 1; break; case 'Y': options.forward_x11 = 1; options.forward_x11_trusted = 1; -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880

Re: Two Factor Authentication Prompt

2018-08-13 Thread Darren Tucker
conf side, but sshd's ChallengeResponseAuthentication/keyboard-interactive does support that. You can ensure you are using that on the client side by adding "-o PreferredAuthentication=keyboard-interactive" on the client side or disabling PasswordAuthentication in sshd_config. -- Dar

Re: IPQoS values in sshd

2018-08-07 Thread Darren Tucker
ged in -current but that change has not yet made it to a release. From https://man.openbsd.org/ssh_config.5: "The default is af21 (Low-Latency Data) for interactive sessions and cs1 (Lower Effort) for non-interactive sessions." -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA /

Re: SSH segfault when SendEnv is used in .ssh/config

2018-06-13 Thread Darren Tucker
made 2 days ago? This may have been fixed: http://cvsweb.openbsd.org/cgi-bin/cvsweb/src/usr.bin/ssh/readconf.c?rev=1.291=text/x-cvsweb-markup If not, could you please share the fragment of your config that triggers it? -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B

Re: Best testcases for SSHD when fuzzing with afl?

2018-05-06 Thread Darren Tucker
On 5 May 2018 at 21:50, Hess THR <hessnovth...@mail.com> wrote: [...] > But the question: does anybody have more? Or better? Any idea how to have > more and better quality testcases? https://anongit.mindrot.org/openssh-fuzz-cases.git/ -- Darren Tucker (dtucker at dtucker.net) GPG

Re: Disabling message CRCs in SSHD

2018-04-28 Thread Darren Tucker
a weak integrity guarantee compared to a proper MAC). [0] https://github.com/openssh/openssh-portable/commit/3d6d09f2 [1] https://www.openssh.com/releasenotes.html#7.6 -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judg

Re: kernel relink segfaults on ALIX

2018-04-19 Thread Darren Tucker
t have a lot. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: What's the inc. SSH conn. launch seq., rel. to login.conf rlimit enforcement?

2018-03-21 Thread Darren Tucker
openbsd.org/login.conf.5 > > Also I'd guess it should be a similar process for SFTP sftp works approximately the same as a shell except sftp-server is exec'ed instead of the shell. >, telnet telnetd is no longer supported but I think it always exec'ed login(1). > other authenticated

Re: ssh from cisco to OpenBSD 6.2 error status 0

2017-12-28 Thread Darren Tucker
der a Host for that device to save you having to remember it. I don't know if your Cisco has any equivalent. -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: NTP issue on Lanner FW-7526B

2017-12-08 Thread Darren Tucker
On 9 December 2017 at 09:40, Christian Weisgerber <na...@mips.inka.de> wrote: > On 2017-12-08, Darren Tucker <dtuc...@dtucker.net> wrote: > > > If your hardware doesn't have a clock (or the clock is bad) then it can > > take ntpd a long time to adjust it bac

Re: NTP issue on Lanner FW-7526B

2017-12-08 Thread Darren Tucker
id this long convergence by telling ntpd to step to the correct time on startup (although this won't step after startup, so it requires that your NTP servers be reachable at boot time). $ grep ntp /etc/rc.conf.local ntpd_flags="-s" -- Darren Tucker (dtucker at dtucker.net) GPG key 11EAA6F

Re: relayd TLS load balancer for multiple websites

2017-09-28 Thread Darren Tucker
ith multiple SANs. Letsencrypt at least supports this as long as all of the domains map (or can be made to map) to the place requesting the certificate. -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes wit

Re: Portable OpenSSH 7.5p1 with LibreSSL 2.6.1 fails

2017-09-07 Thread Darren Tucker
utput. The exact reason will be in config.log (although you may have to scroll back a way to find it). A common cause of this is not having added the new lib directory to the runtime linker config via ldconfig(8). -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860

Re: OpenSSH logging and MaxAuthTries

2017-03-19 Thread Darren Tucker
get the full number of MaxAuthTries log in attempts? Assuming my guess above is correct, PreferredAuthentications=password -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

panic: rw_enter: netlock locking against myself (NFS related?)

2017-02-08 Thread Darren Tucker
0x14200 bored systq 25519 499550 0 0 3 0x40014200 bored softclock 67706 213188 0 0 3 0x40014200idle0 1 179173 0 0 30x82 wait init 0 0 -1 0 3 0x10200 scheduler swapper ddb> -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: pledging a portable program

2017-01-16 Thread Darren Tucker
implementation mechanisms although there are no drop-in replacements at the moment. -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: Hardware recommendations for compact 1U firewall

2016-12-18 Thread Darren Tucker
d be interested in hearing the result. [1] http://undeadly.org/cgi?action=article=20130201054156 -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: unknown hostname on ssh tunnel end causes 'administratively prohibited: open failed'

2016-11-23 Thread Darren Tucker
annel_open: failure %s", ctype); packet_start(SSH2_MSG_CHANNEL_OPEN_FAILURE); packet_put_int(rchan); - packet_put_int(SSH2_OPEN_ADMINISTRATIVELY_PROHIBITED); + packet_put_int(reason); if (!(datafellows & SSH_BUG_OPENFAILURE)) { -

Re: Serverkeybits, protocol 2

2016-11-02 Thread Darren Tucker
ee KexAlgorithms in sshd_config(8)), and exactly which one gets used will depend on what the client and server support and/or have enabled. They all have the same security properties, though. -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6

Re: serial input line not working

2016-09-21 Thread Darren Tucker
engines.ch/alix3d3.htm has "fix serial port" against the most recent firmware version... -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new) Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: usb disk dirty after every reboot

2016-09-19 Thread Darren Tucker
what could be causing this? I suspect your addition to the shutdown script makes the unmount early enough that it has time to complete whatever operation it's trying to complete. -- Darren Tucker (dtucker at zip.com.au) GPG key 11EAA6FA / A86E 3E07 5B19 5880 E860 37F4 9357 ECEF 11EA A6FA (new)

Re: PC Engines APU NIC (RTL8111E) performance

2016-08-09 Thread Darren Tucker
USB revision 1.0 uhub6 at usb6 "ATI OHCI root hub" rev 1.00/1.00 addr 1 umass0 at uhub2 port 1 configuration 1 interface 0 "Generic Flash Card Reader/Writer" rev 2.01/1.00 addr 2 umass0: using SCSI over Bulk-Only scsibus2 at umass0: 2 targets, initiator 0 sd1 at sc

Re: PC Engines APU NIC (RTL8111E) performance

2016-08-04 Thread Darren Tucker
((t) & 0xf) +#define RL_IM_RXPKTS(t)(((t) & 0xf) << 4) #define RL_IM_TXTIME(t) (((t) & 0xf) << 8) +#define RL_IM_TXPKTS(t)(((t) & 0xf) << 12) struct rl_chain_data { u_int16_t cur_r

Re: PC Engines APU NIC (RTL8111E) performance

2016-08-04 Thread Darren Tucker
ke a difference (which is probably an indication that I did something wrong). I could dig up the patch if you'd like to try it. The other thing to be aware of is that if you're following current, POOL_DEBUG is usually set in your config, which will be quite expensive when pushing packets. --

Re: sshfs key exchange fails

2016-06-18 Thread Darren Tucker
run it on port 222) and if the reason isn't obvious from the log please post it to the list. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: sshfs key exchange fails

2016-06-17 Thread Darren Tucker
first "+" means "append this to the list of accepted algorithms". The second "+" doesn't mean anything so sshd is trying to parse that as an algorithm name and failing (this should be obvious from the log message). Try: KexAlgorithms +diffie-hellman-group1-sha1,diffie-he

Re: sshd Connection Failures - 2 June Snapshot (amd64)

2016-06-07 Thread Darren Tucker
min group size >- DH_GRP_MIN (2048 since OpenBSD 5.9) thus didn't cause the min value to be modified, and any client that preferred another key exchange method (most recent versions of OpenSSH) never triggered the problem. Sorry for the inconvenience. -- Darren Tucker (dtucker at zip.com.au

Re: document the actual meaning of ssh's "command" argument

2016-06-01 Thread Darren Tucker
On Thu, Jun 2, 2016 at 2:06 PM, <pizdel...@gmail.com> wrote: > On Thu, Jun 02, 2016 at 08:53:49AM +1000, Darren Tucker wrote: > > > i'm inclined to disagree with this diff, for the following reasons: > > > > - other than the concatenation with spaces, i

Re: document the actual meaning of ssh's "command" argument

2016-06-01 Thread Darren Tucker
connection, which might use sh -c or might do something completely different depending on the server. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: how to submit bug report regarding pf queueing?

2016-03-09 Thread Darren Tucker
quot;) since that's how the rest of my rules are written but while the ruleset loads fine it doesn't actually do anything because queues must be assigned to real interface names (quoth pf.conf(5): "The root queue must specifically reference an interface") -- Darren Tucker (dtucker at zip.co

Re: APU.1D RealtekRTL8111E

2015-11-02 Thread Darren Tucker
On Mon, Nov 2, 2015 at 12:56 PM, Darren Tucker <dtuc...@zip.com.au> wrote: > Not that I have seen, but I don't know what the limiting factor is. > iperf will push ~500Mbit/s from userspace (mtu 1500) [...] > I also notice dlg just made the following change to sys/dev/ic/re.c > w

Re: APU.1D RealtekRTL8111E

2015-11-01 Thread Darren Tucker
onfiguration 1 interface 0 "Generic Flash Card Reader/Writer" rev 2.01/1.00 addr 2 umass0: using SCSI over Bulk-Only scsibus2 at umass0: 2 targets, initiator 0 sd0 at scsibus2 targ 1 lun 0: <Multiple, Card Reader, 1.00> SCSI2 0/direct removable serial.058f6366058F63666485 sd0: 3886MB,

Re: Sep 13 snapshot doesn't cleanly unmount / on reboot?

2015-09-16 Thread Darren Tucker
scripts or the kernel? > Have you tried stuff like sync;sync;reboot or sync;sync;sleep 2;reboot ? > For a sample size of 1 trial each, neither helps. Also, shouldn't the last-mounted location have been updated to "/" when the root filesystem got remounted read-write? -- Darren T

Sep 13 snapshot doesn't cleanly unmount / on reboot?

2015-09-15 Thread Darren Tucker
774a32b.a) swap on sd0b dump on sd0b WARNING: /mnt was not properly unmounted Automatic boot in progress: starting file system checks. /dev/sd0a (0b606ebc9774a32b.a): FREE BLK COUNT(S) WRONG IN SUPERBLK (SALVAGED) /dev/sd0a (0b606ebc9774a32b.a): 148615 files, 1630100 used, 308347 free (47619 fra

sparc64 panic: IOMMU overwrite with vr(4) under load

2015-05-28 Thread Darren Tucker
: extent_free: region not found kdb breakpoint at 155ef04 Stopped at Debugger+0x8: nop RUN AT LEAST 'trace' AND 'ps' AND INCLUDE OUTPUT WHEN REPORTING THIS PANIC! DO NOT EVEN BOTHER REPORTING THIS WITHOUT INCLUDING THAT INFORMATION! ddb rebooting -- Darren Tucker (dtucker at zip.com.au

Re: OpenSSH and Android

2015-05-07 Thread Darren Tucker
constant # define mblen(x, y) 1 The obvious thing to try would be to change that to: # define mblen(x, y) (1) (BTW openssh-unix-...@mindrot.org is the best place to get help with portable OpenSSH. See http://www.openssh.com/report.html for details.) -- Darren Tucker (dtucker at zip.com.au) GPG

Re: WinSCP clients unable to connect to recent amd64 -current

2015-05-05 Thread Darren Tucker
On Tue, May 5, 2015 at 3:02 PM, lawgi...@nym.hush.com wrote: On 5/4/2015 at 9:39 PM, Darren Tucker dtuc...@zip.com.au wrote: Please try this patch on your server. [...] We upgrade from snapshots, and don't have the source installed, so we can't easily check this patch. I have committed

Re: WinSCP clients unable to connect to recent amd64 -current

2015-05-04 Thread Darren Tucker
) TTSSH/2.70*, TTSSH/2.71*, TTSSH/2.72*,SSH_BUG_HOSTKEYS }, + { WinSCP*,SSH_OLD_DHGEX }, { NULL, 0 } }; -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE

Re: Alix, pppoe(VDSL), extremely low upload speed

2015-03-09 Thread Darren Tucker
resulted in the speed going back up to what I expected (about 85 mbit/s). If you are still having problems you might want to check that out. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience

panic on beaglebone black with sdcard with no partitions

2015-01-05 Thread Darren Tucker
'?' for help at any prompt) p OpenBSD area: 0-3451136; size: 3451136; free: 3451136 #size offset fstype [fsize bsize cpg] c: 34511360 unused -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7

Re: panic on beaglebone black with sdcard with no partitions

2015-01-05 Thread Darren Tucker
On Mon, Jan 5, 2015 at 9:14 PM, Darren Tucker dtuc...@zip.com.au wrote: [..] sd0 at scsibus0 targ 1 lun 0: SD/MMC, Drive #01, SCSI2 0/direct fixed sd0: 7580MB, 512 bytes/sector, 15523840 sectors scsibus1 at sdmmc1: 2 targets, initiator 0 sd1 at scsibus1 targ 1 lun 0: SD/MMC, Drive #01

Re: Packet Filter router i368 vs 64bit

2014-12-10 Thread Darren Tucker
. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: Packet Filter router i368 vs 64bit

2014-12-02 Thread Darren Tucker
, in which case doing those in software would be faster at the cost of using more CPU, but I never tested this theory. [1] http://undeadly.org/cgi?action=articlesid=20130201054156 -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good

panic on qemu Sep 10 kernel

2014-09-20 Thread Darren Tucker
idle0 25159 0 0 0 3 0x14200 kmalloc kmthread 1 0 1 0 20x82init 0 -1 0 0 3 0x10200 scheduler swapper ddb -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE

Re: panic on qemu Sep 10 kernel

2014-09-20 Thread Darren Tucker
On Sat, Sep 20, 2014 at 11:41:38PM +1000, Darren Tucker wrote: This is qemu/kvm on a linux host. It has previously worked fine. There's a similar panic in the mp kernel which I can also capture if it'll help. I was able to bring it up in single-user enough to ifconfig the network up, cvs up

Re: panic on qemu Sep 10 kernel

2014-09-20 Thread Darren Tucker
On Sun, Sep 21, 2014 at 12:10:06AM +1000, Darren Tucker wrote: On Sat, Sep 20, 2014 at 11:41:38PM +1000, Darren Tucker wrote: This is qemu/kvm on a linux host. It has previously worked fine. There's a similar panic in the mp kernel which I can also capture if it'll help. I was able

Re: sshd segfaults with incomplete /etc/hosts

2014-05-12 Thread Darren Tucker
) at /usr/src/lib/libc/asr/asr.c:224 #7 0x0154178b in getnameinfo (sa=0xcfbcc854, salen=16, host=0xcfbccdb0 , hostlen=256, serv=0x0, servlen=0, flags=8) at /usr/src/lib/libc/asr/getnameinfo.c:47 -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982

Re: sshd segfaults with incomplete /etc/hosts

2014-05-12 Thread Darren Tucker
On Mon, May 12, 2014 at 04:39:57PM -0400, Darren Tucker wrote: Indeed. It looks like a bug in the libc resolver rather than sshd, though. I've been kinda busy recently so I haven't kept up with recent changes so I'm not sure exactly what's changed in there. Looks like it should be readily

Re: sftp -R as ssh_config option

2014-03-08 Thread Darren Tucker
is concerned, the underlying ssh is just an 8-bit clean bidirectional pipe. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: pf redirect through socks tunnel?

2014-02-02 Thread Darren Tucker
) to retrieve the original address which does not require privileges. That does look like a better way of doing it and would likely also simplify things. If I'm reading commit logs correctly, divert-to was added about 6 months after I originally wrote that code. -- Darren Tucker (dtucker

Re: pf redirect through socks tunnel?

2014-01-30 Thread Darren Tucker
then. The other gotcha is that it needed to be run as root to open the PF device to look up the NAT states. That could potentially be mitigated by a setuid helper program, but from memory it needed write access for the DIOCNATLOOK ioctl, so it'd still be potentially dangerous. -- Darren Tucker

Re: Is Soekris OpenBSD friendly?

2013-11-16 Thread Darren Tucker
at the cost of more CPU usage although I never tested that. [1] http://undeadly.org/cgi?action=articlesid=20130201054156 -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately

Re: matching single-part label in ssh_config ?

2013-11-03 Thread Darren Tucker
the first for any hostname containing a dot, and the second for anything without. Also: it's not in 5.4 but it is in current: check out the Match keyword for a more flexible method. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good

Re: matching single-part label in ssh_config ?

2013-11-03 Thread Darren Tucker
On Sun, Nov 03, 2013 at 01:00:28PM +0200, Lars Nooden wrote: On Sun, 3 Nov 2013, Darren Tucker wrote: [snip] Also: it's not in 5.4 but it is in current: check out the Match keyword for a more flexible method. Cool. Were there any particular use cases in mind with 'exec' ? ProxyCommand

Re: My VPS is acting slow (KVM)

2013-10-06 Thread Darren Tucker
. # config -o /bsd -e /bsd ukc disable mpbios ukc disable uhci ukc quit then reboot. anyway, this is just a guess. you might get some better advice if you provide more info, like the output of dmesg. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982

Re: OpenBSD not forwarding to specific sites

2013-09-30 Thread Darren Tucker
) on? It's in sysctl.conf (not in that list) and it's off by default. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: ssh/sftp performance

2013-08-21 Thread Darren Tucker
one of the faster MACs (umac...@openssh.com is probably going to be the fastest one but you might want to try the others too). -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately

Re: Canceled SSH forwarding

2013-05-23 Thread Darren Tucker
. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: Forcing choice of keys for ssh

2013-05-16 Thread Darren Tucker
offers many different identities. The default is ``no''. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: OpenSSH sshd -E

2013-04-29 Thread Darren Tucker
of the system log. [...] Is this something from upcoming 6.3 or was it missed in the release notes for 6.2? It was added after the 5.2 release and will be in 5.3. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes

Re: snapshot ssh: ChrootDirectory sftp Connection closed

2013-04-17 Thread Darren Tucker
+ strcasecmp(options.chroot_directory, none) != 0) + fatal(server lacks privileges to chroot to ChrootDirectory); + if (getuid() != pw-pw_uid || geteuid() != pw-pw_uid) fatal(Failed to set uids to %u., (u_int) pw-pw_uid); } -- Darren Tucker (dtucker

Re: snapshot ssh: ChrootDirectory sftp Connection closed

2013-04-17 Thread Darren Tucker
. I would expect the compiled in default for UsePrivilegeSeparation to change at some point down the track, at which point it will be commented out in sshd_config again. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement

Re: Fallthrough in ssh_config

2013-03-21 Thread Darren Tucker
. There is an open enhancement request to let it match subnets, which may or may not be sufficient for what you want (https://bugzilla.mindrot.org/show_bug.cgi?id=1169). -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes

Re: Can I change ssh port forwardings on a active connection *non-interactively* ?

2012-11-17 Thread Darren Tucker
this? If you start ssh with ControlMaster mode enabled you can use ssh -O forward to add forwardings to an established connection, eg: $ ssh -o ControlMaster=yes -o ControlPath=/tmp/ctl localhost $ ssh -o ControlMaster=no -o ControlPath=/tmp/ctl -O forward \ -L 1234:127.0.0.1:22 localhost -- Darren

Re: SSI

2012-09-27 Thread Darren Tucker
(or, at least, it's taking much longer than they expected). -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: hello I have question for openssh !

2012-06-26 Thread Darren Tucker
key, which an MITM can't do since it doesn't have access to the corresponding private key. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4  37C9 C982 80C7 8FF4 FA69     Good judgement comes with experience. Unfortunately, the experience usually comes from bad

Re: after upgrade to current(25-06-2012), can not login ssh

2012-06-26 Thread Darren Tucker
mquery() to sandbox-systrace.c work on my system. thank you. Slight variant (SYSTR_POLICY_PERMIT) committed, thanks. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately

Re: hello I have question for openssh !

2012-06-21 Thread Darren Tucker
topic: I added an openssh specs page recently (http://www.openssh.com/specs.html) which should be the authoritative reference for what is supported. Corrections are welcome (but before someone says RFC6594, note that I'm trying to keep it accurate for the most recent release). -- Darren Tucker

Re: SSH connection failure: broken pipe

2010-12-04 Thread Darren Tucker
connection and check if the send-q is non zero (indicating un-acked data). -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: umask for remote host in sftp / sftp-server

2009-10-31 Thread Darren Tucker
Lars Nooden wrote: How can umask be set on the remote host for chrooted sftp users? You can set it on the server side with sftp-server's -u option but that's very new (post 4.6). You would have something like this in sshd_config: Subsystem sftp sftp-server -u 0022 -- Darren Tucker

Re: How to determine my ip address (logged in via ssh)

2009-01-09 Thread Darren Tucker
Falk Brockerhoff wrote: is there any gentle way how to determine my ip address if I connected via ssh to an openbsd system? echo $SSH_CLIENT | cut -f1 -d' ' -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes

Re: Latest Portable OpenNTPD?

2008-11-21 Thread Darren Tucker
things and slacking in this department. [1] http://www.zip.com.au/~dtucker/openntpd/snapshot/ -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad

Re: IP over Simulated Radio/Satellite Channels

2007-11-25 Thread Darren Tucker
to the same tun device. http://www.iijlab.net/~kjc/software/dist/tunbridge-0.1.tar.gz -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: GSSAPI logins into OpenSSH combined with auto-obtaining AFS tokens

2007-07-10 Thread Darren Tucker
token before accessing the user's home directory. The default is ``no''. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: classify scp and ssh

2007-07-08 Thread Darren Tucker
somehost-xfer Hostname somehost ProxyCommand nc -T throughput %h %p -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: ssh and sudo, password not hidden

2007-07-01 Thread Darren Tucker
-- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: Load balancing with DSR

2007-06-13 Thread Darren Tucker
Pierre-Yves Ritschard wrote: On Wed, 13 Jun 2007 15:40:36 +1000 Darren Tucker [EMAIL PROTECTED] wrote: [...] 1. add a static published arp entry for the cluster address on the balancer with its own mac address so packets aimed at the cluster address will go to the balancer. 2. configure all

Re: skey with scp

2007-05-15 Thread Darren Tucker
@host.example.com:/home/username/foo.bar . Any other suggestions? I don't use skey so I can't test it but this will probably work: scp -o User=username:skey host.example.com:/home/username/foo.bar . -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4

Re: SFTP no autocompletion?

2007-05-15 Thread Darren Tucker
into this would probably want to look at what Ben Lindstrom has already done with this: http://www.eviladmin.org/patches/sftp-tab.patch -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience

Re: SCP/SFTP: Couldn't open /dev/null

2007-03-27 Thread Darren Tucker
I'm not sure as I don't transfer files that often. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: /bsd: proc: table is full (OpenBSD server 4.0 GENERIC#1107 i386)

2007-03-05 Thread Darren Tucker
. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

Re: ssh/sshd challenge-response seems to have stopped working in -current

2007-02-27 Thread Darren Tucker
on ChallengeResponseAuthentication. I'll do a patch later today. -- Darren Tucker (dtucker at zip.com.au) GPG key 8FF4FA69 / D9A3 86E9 7EEE AF4B B2D4 37C9 C982 80C7 8FF4 FA69 Good judgement comes with experience. Unfortunately, the experience usually comes from bad judgement.

  1   2   >