Re: Suggestions home server

2017-12-14 Thread Peter N. M. Hansteen
nstead of the default hardware raid mode. Haven't had a chance to try the newer versions, but I wouldn't expect any trouble -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil

Re: password-free SSH was Re: [ot] Security of my bit coin wallet

2017-11-15 Thread Peter N. M. Hansteen
osting would help follow the discussion a lot - a rant about that and a couple of other things can be had at[1] for those in need). [1] https://bsdly.blogspot.com/2011/02/problem-isnt-email-its-microsoft.html -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.b

Re: session security on OpenBSD vs popular options

2017-11-15 Thread Peter N. M. Hansteen
ld be possible to answer in a mailing list message. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]:

Re: the whole greylisting, spam filtering thing

2017-09-30 Thread Peter N. M. Hansteen
ntally more fun (fsvo) as more of the traffic moves to IPv6. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: the whole greylisting, spam filtering thing

2017-09-29 Thread Peter N. M. Hansteen
ml, for the fun parts of doing greytrapping see https://bsdly.blogspot.no/2013/05/keep-smiling-waste-spammers-time.html and https://bsdly.blogspot.no/2013/04/maintaining-publicly-available.html and of course https://bsdly.blogspot.no/2012/05/in-name-of-sane-email-setting-up-spamd.html might still be of

Re: fs level 0

2017-09-23 Thread Peter N. M. Hansteen
ould be to simply reinstall with as little deviation from the defaults as possible. I didn't get hold of a ThinkPad that I was allowed to install OpenBSD on until about 2006, but by then the install and use experience was straightforward. - P -- Peter N. M. Hansteen, member of the first RFC 1149 imp

Re: running spamd on firewall ord on the mailsystem

2017-09-19 Thread Peter N. M. Hansteen
be a lot less of the heavy computation tasks involved in content filtering that need to be performed. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all mal

Re: reiser4fs in openbsd

2017-08-25 Thread Peter N. M. Hansteen
t;> zfs is already there: https://marc.info/?l=openbsd- >> cvs=136482823110105= >> <https://marc.info/?l=openbsd-cvs=136482823110105=2> > > Why not implement it? There is reason to believe that a port of the hitherto linux-only CPIP (http://www.blug.linux.no/rfc11

Re: ftp.eu.openbsd.org no longer accepts anonymous ftp?

2017-08-19 Thread Peter N. M. Hansteen
On 08/19/17 11:44, Andreas Thulin wrote: > Also, yesterday's > > # pkg_add -u > > failed for me, apparently for that same reason. Yes, that would happen. Then again, changing ftp:// to https:// in /etc/installurl would make pkg_add -u work. - P -- Peter N. M. Hansteen, member o

ftp.eu.openbsd.org no longer accepts anonymous ftp?

2017-08-19 Thread Peter N. M. Hansteen
downloading bsd.rd only and then doing an http install as much of a hardship (the process takes only a few minutes total either way), but if the change was intentional it would probably be a good thing to update the relevant web pages. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149

Re: Preferred configuration for SLAAC in hostname.if

2017-07-21 Thread Peter N. M. Hansteen
' and 'inet6 autoconf' are > "equivalent" as far as /etc/netstart is concerned. > > What's the preferred setting for SLAAC in hostname.if(5)? "inet6 autoconf" is what you get if you choose the autoconf option during install. I wasn't even aware that the old style "rtsol"

Re: AMD64 modern laptop recommendation

2017-07-18 Thread Peter N. M. Hansteen
s can be had lightly used at attractive prices via ebay and similar. For UEFI and such, for my latest I simply did not change the BIOS defaults away from "Secure Boot" and things just worked. -- B< ---------- - Peter -- Peter N. M. Hansteen, member of the first RFC 1149

Re: AMD64 modern laptop recommendation

2017-07-18 Thread Peter N. M. Hansteen
t that device. [1] http://bsdly.blogspot.com/2017/07/openbsd-and-modern-laptop.html - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traff

Re: Robust ThinkPad suggestions for running OpenBSD.

2017-07-12 Thread Peter N. M. Hansteen
trackpoint, but then my typical work is not too mouse-intensive. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29

Re: Can I use OpenBSD in a virtual machine, for example, VirtualBox?

2017-06-27 Thread Peter N. M. Hansteen
oud' providers such as Amazon, Microsoft and others have tended to be usable and some are now even adding official support. So the short answer applies. (In addition we hav LDOMs on SPARC64, and possibly others I've forgotten just now) -- Peter N. M. Hansteen, member of the first RFC 1149 implementat

Re: Current FreeBSD looking to switch to OpenBSD

2017-06-10 Thread Peter N. M. Hansteen
Also, http://man.openbsd.org/ is very useful - go there, type your keyword in the search field, click apropos and you get all the man pages matching that keyword. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http:/

Re: Spamtrap doesn't work for me

2017-05-18 Thread Peter N. M. Hansteen
I can come up with suitable wording unless somebody beats me to it. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah s

Re: Spamtrap doesn't work for me

2017-05-17 Thread Peter N. M. Hansteen
in a table (spamd-whitelist) for performance, but performance in response towards grey or trapped hosts is not needed or expected, so the (possibly) slower database lookup is considered sufficient. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.

Re: Spamtrap doesn't work for me

2017-05-17 Thread Peter N. M. Hansteen
P|lorgne...@dataped.no but exactly matching or not) what's in the database could be the problem here. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Libreoffice Calc (sometimes) kills X when attempting to import a CSV file?

2017-05-13 Thread Peter N. M. Hansteen
And it happened again - On 05/07/17 23:48, Stuart Henderson wrote: > On 2017-05-06, Peter N. M. Hansteen <pe...@bsdly.net> wrote: >> And it happened again - >> https://home.nuug.no/~peter/soffice_vs_x_csv/fehfeh.csv triggered >> another kaboom, producing the log f

Re: OpenBSD and you

2017-05-10 Thread Peter N. M. Hansteen
On Wed, May 10, 2017 at 01:20:06PM +0300, Manolis Tzanidakis wrote: > On Wed (10/05/17), Peter N. M. Hansteen wrote: > > That was the first option that came to mind, and the one I may go for as > > a supplemental format *if* I can find a way to generate PDFs from this > > so

Re: OpenBSD and you

2017-05-10 Thread Peter N. M. Hansteen
upt other things I need to get done. The in-browser print preview method is simply not a practical option. And reverting to the previous powerpoint clone rubbish is right out. If I do find a workable option, I'll let you all know. -- Peter N. M. Hansteen, member of the first RFC 1149 implementa

Re: OpenBSD and you

2017-05-09 Thread Peter N. M. Hansteen
And I was just reminded off-list that the remark markdown variant (https://github.com/gnab/remark) used for this presentation requires javascript enabled in your browser. Sorry about that. I'll be looking into workarounds, hopefully some can be found. - Peter -- Peter N. M. Hansteen, member

Re: OpenBSD and you

2017-05-09 Thread Peter N. M. Hansteen
/~peter/openbsd_and_you/ Updates may happen occasionally. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah s

Re: Libreoffice Calc (sometimes) kills X when attempting to import a CSV file?

2017-05-07 Thread Peter N. M. Hansteen
On 05/07/17 23:48, Stuart Henderson wrote: > On 2017-05-06, Peter N. M. Hansteen <pe...@bsdly.net> wrote: >> And it happened again - >> https://home.nuug.no/~peter/soffice_vs_x_csv/fehfeh.csv triggered >> another kaboom, producing the log file >> https://home.nuug.

Re: Libreoffice Calc (sometimes) kills X when attempting to import a CSV file?

2017-05-06 Thread Peter N. M. Hansteen
dissecting the core file, in the meantime this is evidence preserved. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah s

Re: Libreoffice Calc (sometimes) kills X when attempting to import a CSV file?

2017-05-06 Thread Peter N. M. Hansteen
ome useful information. > - look at /var/crash and profit :D - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" del

Libreoffice Calc (sometimes) kills X when attempting to import a CSV file?

2017-05-06 Thread Peter N. M. Hansteen
tion is, of course: How do I go about usefully debugging this? -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]:

Re: Pf with secondary DNS resolution

2017-05-04 Thread Peter N. M. Hansteen
and some fairly straightforward scripting involving host and pfctl commands. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" del

Re: Pf with secondary DNS resolution

2017-05-03 Thread Peter N. M. Hansteen
uleset. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: OpenBSD 6.1, spamd strange behavior

2017-04-21 Thread Peter N. M. Hansteen
u're not showing us? (see the GREYTRAPPING section of the man page) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah

Re: spamd and outlook.com

2017-04-21 Thread Peter N. M. Hansteen
And apropos of the subject, quite on-topic: https://home.nuug.no/~peter/dmarc-reject_openbsd-misc_spadm_and_spf.txt - P (pats robot on virtual head) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: spamd and outlook.com

2017-04-21 Thread Peter N. M. Hansteen
something" 'system architect' responses. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: howto show IPv6 address lifetime?

2017-04-19 Thread Peter N. M. Hansteen
vltime 530703 That's output from my laptop just now, with autoconfigured inet6 addresses. I believe the pltime and vltime values are given in seconds. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ &

Re: ordering

2017-04-16 Thread Peter N. M. Hansteen
ated, you could do worse than head over to http://www.openbsd.org/donations.html and donate an equivalent (or larger!) amount via whatever option appears appropriate. I'm sure this will make you feel even better while downloading the release. -- Peter N. M. Hansteen, member of the first RFC 1149 imple

upgrading on vultr.com: make sure to select the bsd.mp set

2017-04-13 Thread Peter N. M. Hansteen
was actually quite simple: the installer does not select the bsd.mp kernel automatically, but do select it. Then it will get installed and the system will boot the correct mp kernel. I'm sure we can supply more detail if needed. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149

Re: Does OpenBSD's pf prevents Hole punching?

2017-04-08 Thread Peter N. M. Hansteen
s in the competing products are, but it *is* a very useful and capable tool for enforcing whatever policies you have in place. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the ev

Re: Topics for revised PF and networking tutorial

2017-04-07 Thread Peter N. M. Hansteen
ween address families, you use inet and inet6 respectively in the criteria. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic&quo

Re: Topics for revised PF and networking tutorial

2017-04-07 Thread Peter N. M. Hansteen
cluded. On the other hand there is a chance we will be able to offer a similar session at EuroBSDCon too, but no decisions have been made yet. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Reme

Topics for revised PF and networking tutorial

2017-04-01 Thread Peter N. M. Hansteen
o you have questions on PF and related matters, or are there specific topics you would like to see covered? We want to hear from you, either contact us directly at the reply-to address use the list. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot

Re: Sony Vaio VPCSA

2017-03-29 Thread Peter N. M. Hansteen
e (yes, that could be time consuming), if at all possible collecting dmesg output for each variation (saving to somewhere on the usb stick you're installing from should work fine). - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://w

Re: regarding OpenSSL License change

2017-03-24 Thread Peter N. M. Hansteen
ely to be time consuming (just ask the people who did just that on the OpenBSD source and ports trees at least once), but unless they get everyone explicitly on board with the new license they will need to go through one. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation tea

Re: bandwidth monitoring

2017-03-07 Thread Peter N. M. Hansteen
t most of Michael's books, btw) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconne

Re: hairpin nat with pf ?

2017-03-01 Thread Peter N. M. Hansteen
n even think of several tutorials and accompanying slides that deal with what you are looking for, available right there on the Internet. And even a book (*cough*). But start with the PF FAQ, go on to the pf.conf man page and then move to the other resources if you feel the need to. -- Pete

Re: make pf allow out on lo per user

2017-01-25 Thread Peter N. M. Hansteen
Also, as I keep repeating to anybody who cares to listen, just like "verbing weirds the language", "excessiv quicks weird your PF rule set". -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://ww

Re: Pf on lo0

2017-01-16 Thread Peter N. M. Hansteen
r the packet. Also as Sebastien mentioned do check for any "set skip on lo" or similar in your ruleset. If you have that, filtering simply does not happen on interfaces or interface groups in the "set skip" rule. -- Peter N. M. Hansteen, member of the first RFC 1149 im

Re: How to make spamd more annoying ?

2016-12-13 Thread Peter N. M. Hansteen
I want with log data. Also, a few links to useful resources such as http://bgp-spamd.net/. I hope you find this useful. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evi

Re: How to make spamd more annoying ?

2016-12-13 Thread Peter N. M. Hansteen
ffenberger's spf_fetch script that takes a file of domain names and extracts the SPF info for you: https://github.com/akpoff/spf_fetch - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to

Re: How to make spamd more annoying ?

2016-12-12 Thread Peter N. M. Hansteen
econds mark. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: LibC openBSD affected ?

2016-12-07 Thread Peter N. M. Hansteen
able to a classic buffer overflow. Yes. See http://www.tedunangst.com/flak/post/who-even-calls-link-ntoa -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malic

Re: HP Proliant MicroServer G8: not seeing disks [solved]

2016-12-02 Thread Peter N. M. Hansteen
: connecting to wsdisplay0 uhidev1 at uhub4 port 5 configuration 1 interface 1 "Microsoft Wired Keyboard 600" rev 2.00/3.00 addr 3 uhidev1: iclass 3/0, 2 report ids uhid0 at uhidev1 reportid 1: input=2, output=0, feature=0 uhid1 at uhidev1 reportid 2: input=1, output=0, feature=0 uhub5 at u

Re: PCI Express wireless adapter supported under OpenBSD

2016-11-30 Thread Peter N. M. Hansteen
d it's worth keeping in mind one other option: get the highest quality access point or 'wireless router' you can afford, configure it as access point only (no dhcp or routing, leave that to the OpenBSD tools) - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementati

Re: OpenBSD and you

2016-11-26 Thread Peter N. M. Hansteen
On 11/26/16 04:57, R0me0 *** wrote: > As I did see any mention around here, I was boosted to post this great > presentation by Peter N . M. Hansteen. > > https://home.nuug.no/~peter/blug2016/ It's nice to hear you like it! The meeting where I presented this was a lot less well att

Re: How to detect this kind of attacks

2016-11-26 Thread Peter N. M. Hansteen
d-command address=119.141.24.19 host=119.141.24.19 command="RCPT > TO:" result="550 Invalid recipient" > Nov 26 06:06:57 server smtpd[55880]: 3bcc430eee258cd7 smtp event=closed > address=119.141.24.19 host=119.141.24.19 reason=disconnect You could try configuring spamd(

Re: OpenBSD 5.2 AutoFSCK at boot

2016-11-24 Thread Peter N. M. Hansteen
n bit OpenBSD guests more frequently than others. But again, we don't have sufficient information to help you diagnose. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit

Re: HP Proliant MicroServer G8: not seeing disks

2016-11-22 Thread Peter N. M. Hansteen
xt few days. I'll report back if I notice any difference. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]:

Re: HP Proliant MicroServer G8: not seeing disks

2016-11-22 Thread Peter N. M. Hansteen
.10/51.27 addr 4 uhidev2: iclass 3/1 ums0 at uhidev2: 3 buttons, Z dir wsmouse0 at ums0 mux 0 uhub5 at uhub3 port 1 configuration 1 interface 0 "Intel Rate Matching Hub" rev 2.00/0.00 addr 2 uhub6 at uhub5 port 3 configuration 1 interface 0 "Standard Microsystems product 0x2660" r

HP Proliant MicroServer G8: not seeing disks

2016-11-22 Thread Peter N. M. Hansteen
e 0 "Alcor Micro USB Mouse" rev 1.10/51.27 addr 5 uhidev2: iclass 3/1 ums0 at uhidev2: 3 buttons, Z dir wsmouse0 at ums0 mux 0 uhub5 at uhub3 port 1 configuration 1 interface 0 "Intel Rate Matching Hub" rev 2.00/0.00 addr 2 uhub6 at uhub5 port 3 configuration 1 inter

Re: Gigabyte-range /dev, for whatever reason

2016-11-18 Thread Peter N. M. Hansteen
C) to create the situation. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Gigabyte-range /dev, for whatever reason

2016-11-17 Thread Peter N. M. Hansteen
On Fri, Nov 18, 2016 at 05:56:20AM +1000, Stuart Longland wrote: > On 18/11/16 05:51, Peter N. M. Hansteen wrote: > > This is probably a one-off (actually two, but more about that later) that > will only ever bite me and never be heard of againg, but I have to ask: > > > &g

Gigabyte-range /dev, for whatever reason

2016-11-17 Thread Peter N. M. Hansteen
this could have happened on two systems at roughly the same time. If any devs are interested, I'll probably let the last box run for a few days more before doing any major surgery (assuming nothing else weird happens). -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: Is 6.1 expected to happen soon?

2016-11-03 Thread Peter N. M. Hansteen
the established schedule. In the meantime, there are worse things knowledgeable OpenBSD users can do with their time than trying out snapshots to get the feel for how development is progressing. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ ht

Re: A detail about pf.conf

2016-10-30 Thread Peter N. M. Hansteen
If this is what the original poster is trying to address, blocking on an additional table sourced from a file might be useful. [1] https://home.nuug.no/~peter/pf/en/bruteforce.html -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www

Re: Allow FTP through Openbsd firewall

2016-10-28 Thread Peter N. M. Hansteen
That's what ftp-proxy is for. It inserts the rules it needs in the anchor. My hunch is that you're not actually allowing traffic initiated by the proxy to pass. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://w

Re: How to analyse excessive PF states?

2016-10-22 Thread Peter N. M. Hansteen
to mind). The packet loss could conceivable by a side effect of the number of states going into the territory where timeouts are scaled down (exceeding 60% of state table limit IIRC). - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://

Re: Flaw resides in BTB helps bypass ASLR

2016-10-20 Thread Peter N. M. Hansteen
ich claims that ASLR is indeed enabled by default in all recent Ubuntu releases. Well, something in this story doesn't quite fit. Until we see the actual code, and a credible demonstration, I remain unconvinced that the paper tells the whole truth. -- Peter N. M. Hansteen, member of the first RFC

Re: Flaw resides in BTB helps bypass ASLR

2016-10-20 Thread Peter N. M. Hansteen
ttps://gist.github.com/lattera/c785e7088118442f10addf8c6017c7d0 with a finished version due whenever he gets it done. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all

Re: Opinion about pflog

2016-09-28 Thread Peter N. M. Hansteen
somewhat similar reaction as yours when I first read about the binary PF logs, but in practical terms the way it's done actually makes sense. - P [1] One such setup is described, with some anecdotes just because, at http://bsdly.blogspot.com/2014/02/yes-you-too-can-be-evil-network.html --

Today's snapshot fixed a USB problem I wasn't aware I had

2016-09-20 Thread Peter N. M. Hansteen
1 and the USB drive was recognized and mountable. I had vaguely noticed some USB related commits recently, but hey, you fixed things! dmesg from today is up at https://home.nuug.no/~peter/dmesg_elke_20160920.txt. Thanks! - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 impl

Re: bugs

2016-09-20 Thread Peter N. M. Hansteen
_add -v wget > > > > cant find wget See previous. > > 4. > > > > cd /usr/games > > > > hangman Check your PATH. > > nothing works Start with the FAQ. It has lots of useful information and possibly some useful links to other resources. -- Peter N. M.

Re: Routing 10-40 Mpps on OpenBSD

2016-09-11 Thread Peter N. M. Hansteen
- P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: DMARC and misc@ (and likely other OpenBSD lists)

2016-08-26 Thread Peter N. M. Hansteen
problem is fixed. this sounds like I should perhaps worry a little less. Thanks! - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic&q

Re: PF Rules

2016-08-26 Thread Peter N. M. Hansteen
too weak to begin with. I suspect your problem may be overuse of the quick keyword. Remember, once you hit a quick rule that matches, processing for that packet stops right there. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://w

DMARC and misc@ (and likely other OpenBSD lists)

2016-08-26 Thread Peter N. M. Hansteen
-for-you.html [2] https://lists.freebsd.org/pipermail/freebsd-announce/2014-May/001550.htm l - -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic&quo

Re: Installer overwrites partition table

2016-08-24 Thread Peter N. M. Hansteen
d strongly recommend either getting some hardware you don't care about too much or spin up a VM in a virtualization setup you're comfortable with. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Rem

Re: Fwd: spamd question

2016-08-22 Thread Peter N. M. Hansteen
net>, helo reliefs.herpprotcol.eu If you see something similar, your're good for that part at least. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malic

Re: LibreSSL on old OpenBSD

2016-08-12 Thread Peter N. M. Hansteen
u actually need and leaving behind the stuff that just made its way in by accident. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic&

Re: Bare-metal PM953 / 850/950 PRO/EVO IO benchmark anyone? Re: Disk I/O performance of OpenBSD 5.9 on Xen

2016-07-21 Thread Peter N. M. Hansteen
ginally imagined. Then again, now that the thing is actually silent for the most part, that may not be a bad thing. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bi

Re: how would you troubleshoot your wifi?

2016-07-14 Thread Peter N. M. Hansteen
out what fail and how, of course. Some access points are just plain weird - in some cases I've had to play with of all things mtu sizes (setting them to various values lower than the 1500 byte default) in order to successfully connect. Any quirks like those will turn up as the hints tcpdump will

Re: How to turn off disk elevator

2016-07-13 Thread Peter N. M. Hansteen
to twiddle here, but if there is, will you realistically see any difference in performance (assuming this is about shaving cycles off)? -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on a

Re: making OpenBSD 5.9 live system on USB key

2016-07-09 Thread Peter N. M. Hansteen
s, ie ifconfig athn0 up nwid foo wpakey foospresharedsecret but there is a wpa-supplicant package available if you need it. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all m

Re: ipad as an USB disk

2016-07-08 Thread Peter N. M. Hansteen
les (photos etc) from the device to my OpenBSD machines is to use an SFTP or SCP client. I imagine there are several such applications available for the ipad too. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug

Re: making OpenBSD 5.9 live system on USB key

2016-07-08 Thread Peter N. M. Hansteen
the install could turn out to be very useful. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah spamd[29949]: 85.152.224.1

Re: A patch for cal

2016-06-21 Thread Peter N. M. Hansteen
l -wm jan 2016 January 2016 Mo Tu We Th Fr Sa > Su 1 2 3 [53] 4 5 6 7 8 9 10 [ 1] 11 12 13 14 15 16 17 [ 2] > 18 19 20 21 22 23 24 [ 3] 25 26 27 28 29 30 31 [ 4] Ah, excellent! cal -wm certainly covers almost all my week numbering needs :) - -- Peter N. M. Hansteen, member

Re: A patch for cal

2016-06-21 Thread Peter N. M. Hansteen
t aware of (and of course there's the Monday vs Sunday as week start day issue). - - P - -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic

Re: is 'set prio' in pf unidirectional or bidirectional?

2016-06-15 Thread Peter N. M. Hansteen
f each one. It's worth noting that tcpdump with the right options is able to display information such as the packets's ToS and which rule in the loaded PF rule set the packet matched. If you run those tests properly and report your findings, I'm sure it will be appreciated. - -- Peter N. M. Hanste

Re: Why can I ping but not curl google.com?

2016-05-29 Thread Peter N. M. Hansteen
b.com/anonymous/69e047797f696c1df8eaa0c82e39e01d As in, is that a pf.conf for the thing that tries to run curl or is it a separate system? - -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember

Re: the balance between OpenBSD and life

2016-05-28 Thread Peter N. M. Hansteen
to spend significant time studying, experimenting, making mistakes and fixing them. > thanks for any reply. I'm sure replies will be more constructive if you offer up some more information about the actual problem. - -- Peter N. M. Hansteen, member of the first RFC 1149 implementati

Re: panic: rw_enter:vmmaplk locking against myself

2016-05-02 Thread Peter N. M. Hansteen
CLUDE OUTPUT WHEN REPORTING THIS PANIC!" If you had done that and reported the contents, that would have been a lot more useful. http://www.openbsd.org/report.html is a useful starting point. If you can get the system to boot somehow, sendbug(1) is your friend. -- Peter N. M. H

Re: sendmail mx question

2016-04-05 Thread Peter N. M. Hansteen
anyway, but delivery would not happen immediatel y. The only advice I can offer is to check that your side has a reasonable retry period (IIRC default setups for all the MTAs on OpenBSD come with reasonable settings, but do check), and tell the other side that for their own sake they need to fix thei

Re: no bandwidthd src pkd in /usr/ports

2016-02-25 Thread Peter N. M. Hansteen
ion at sourceforge, it's possible you'd be well served with bandwidth monitoring via symon and friends or by setting up pflow and using one of the several netflow packages to generate graphs and suchlike. - -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspo

Re: hostname | /etc/hosts

2016-02-24 Thread Peter N. M. Hansteen
int as the domain for their internal-but-occasionally-internet-visible machines comes to mind. For a totally separate set of reasons, I was not compelled to stick around to help them sort out that particular mess. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team h

Re: Is true that the BSD developers were inspired to make their code free software by the example of the GNU Project, and explicit appeals from GNU activists helped persuade them?

2016-02-17 Thread Peter N. M. Hansteen
If no, what is the true story of BSD developers? Others have already supplied references to useful literature. I would suggest you read those things. Several other useful references are just a simple web search away. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementati

Re: dhcrelay: send_packet: No buffer space available

2016-02-12 Thread Peter N. M. Hansteen
dhcrelay: send_packet: No buffer space available I've seen that message only when a link or interface is down but for some reason the machine still thinks that it's OK to route packets over it anyway. So I'd start with checking routing vs actually available links. -- Peter N. M. Hansteen

Re: providing users with equal bandwidth

2016-02-04 Thread Peter N. M. Hansteen
or more queues approach a threshold that triggers shaping/. If you can come up with measurements that show the mechanism is defective, I'm sure a bug report would be appreciated. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

Re: providing users with equal bandwidth

2016-02-04 Thread Peter N. M. Hansteen
a peek at the relevant source files while preparing to measure anything). -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember to set the evil bit on all malicious network traffic" delilah s

Re: providing users with equal bandwidth

2016-02-04 Thread Peter N. M. Hansteen
you could come fairly close to that regime with some state tracking and overload tables trickery to match a finer-grained set of queues. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ "Remember t

puppet and cross-platform password hashes

2016-02-04 Thread Peter N. M. Hansteen
there, possibly with more sophisticated approaches than the ones I've mentioned here? Good suggestions may merit a beverage of choice (within reason) at the first possible opportunity. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

Re: xauth: (argv):1: bad display name "BadSystemDetected.my.domain:0" in "remove" command

2016-01-30 Thread Peter N. M. Hansteen
out of packages (or ports) tends to land somewhere under /usr/local, so the binaries you're looking for will likely be in /usr/local/bin. Other than that, pasting the error message (minus the hostname) into a favorite search engine produces a number of potentially useful hints. -- Peter N. M

Re: vmm(4) status?

2016-01-21 Thread Peter N. M. Hansteen
the userland side, the networking configuration will be changed to > a slightly different approach, but I kind of suspended this until the > previous issue is solved. for the terminally curious among us, do you have a ballpark figure for when it comes back in GENERIC? (as in, pre- or post-5

<    1   2   3   4   5   6   7   8   9   10   >