Re: Creating Mobile Apps ..

2013-09-12 Thread Peter N. M. Hansteen
negative reactions. I'll give you this much better list for free, with a total of 25083 adresses: http://www.bsdly.net/~peter/sortlist Please make sure any future mailings of yours are sent to those addresses first. Yours sincerely Peter N. M. Hansteen -- Peter N. M. Hansteen, member of the first RFC

Re: OpenBSD crypto and NSA/Bruce Schneier

2013-09-11 Thread Peter N. M. Hansteen
-might-be-a-spook.html - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673

Re: pf set prio

2013-09-10 Thread Peter N. M. Hansteen
about the implementation and some work that will hopefully hit the tree soonish. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd

Re: pf set prio

2013-09-10 Thread Peter N. M. Hansteen
-- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: sshd unsupported option kerberosauthentication on current

2013-09-03 Thread Peter N. M. Hansteen
and read the various followups as well as several notes in http://www.openbsd.org/faq/current.html. My favorite here is http://marc.info/?l=openbsd-cvsm=137162163212109w=2 - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

EuroBSDCon 2013 early bird rates through August 31

2013-08-26 Thread Peter N. M. Hansteen
(Program committee member and speaker) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673

Re: remove entry from spamdb greylist

2013-08-14 Thread Peter N. M. Hansteen
reporting a bug would be in order, if you have sufficient logging going on at least. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah

Re: Two questions.

2013-08-09 Thread Peter N. M. Hansteen
This has been asked and answered numerous times, with generous helpings of shitheadery that serves to mask any real information offered. Check the archives for the obvious keywords. There's nothing to add since the last iteration. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149

Re: /etc/mail/spamd.key permissions/ownership?

2013-08-09 Thread Peter N. M. Hansteen
/spamd.key -rw-r--r-- 1 root wheel 2048 Nov 1 2009 /etc/mail/spamd.key (much on par with the rest of the files in that directory). - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember

Re: ifconfig(8) --frontend

2013-08-04 Thread Peter N. M. Hansteen
remember whether they've made it available to the general public. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: pflow all traffic in a queue

2013-07-16 Thread Peter N. M. Hansteen
;) - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: ALTQ(32bit)

2013-06-03 Thread Peter N. M. Hansteen
ready, unfortunately. http://bsdly.blogspot.ca/2011/07/anticipating-post-altq-world.html gives some background, diffs are being tested by various people now, and the commit of the new queueing system *must* be moving closer by the minute. But no definite ETA just yet. - P -- Peter N. M

Re: OT: term hackathon trademarked in Germany

2013-05-07 Thread Peter N. M. Hansteen
A bit late to the party, but here's my take on the situation - http://bsdly.blogspot.ca/2013/05/the-term-hackathon-has-been-trademarked.html - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: OpenBSD official reference book ( like FreeBSD handbook / NetBSD Guide )

2013-05-07 Thread Peter N. M. Hansteen
are generally considered useful. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after

Re: pflow collection and analysis

2013-05-01 Thread Peter N. M. Hansteen
. pkg_add nfsen and reading the package message should get you alle the way there inside a few minutes. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network

Re: OpenBSD Foundation benefit Auction / Absolute OpenBSD 2nd Ed.

2013-04-17 Thread Peter N. M. Hansteen
with the idea on twitter, but ICBW). The again, just a thought, after all these good people *were* willing to spend the cash on our good cause. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember

Re: pf queueing and nat

2013-04-17 Thread Peter N. M. Hansteen
. see systat queue; run it as root. What Stuart said. systat(8) rocks. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: pf queueing and nat

2013-04-16 Thread Peter N. M. Hansteen
decision. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Authentication completing my OpenBSD 5.2 install.

2013-04-03 Thread Peter N. M. Hansteen
(note: that endorsement comes from the book's tech editor). - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: [Question] Building whitelists so that spamd greylisting can work without users perceiving delivery delays...

2013-03-28 Thread Peter N. M. Hansteen
;)). - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Does OB support any 10GE NIC card

2013-03-25 Thread Peter N. M. Hansteen
the man pages. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: wireless ethernet (ralink) not working

2013-03-23 Thread Peter N. M. Hansteen
would change 'nwkey' to 'wpakey' and get sensible defaults. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: This is my first time to use OpenBSD

2013-03-18 Thread Peter N. M. Hansteen
there's a TRIM deficiency that would hurt SSD users, I'm sure patches that solve the problem will be welcomed by the developers. - Peter [1] http://manpages.ubuntu.com/manpages/oneiric/en/man8/fstrim.8.html -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: Using hostnames in pf rules

2013-03-15 Thread Peter N. M. Hansteen
-- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: renaming name of interfaces

2013-03-14 Thread Peter N. M. Hansteen
elsewhere) will give you what others have implemented interface renaming for. - Peter (whose current pet hate is Solaris11's 'vanity names' for interfaces) -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: renaming name of interfaces

2013-03-14 Thread Peter N. M. Hansteen
probably will be OK, and if your new card is a different make, all you need to do is some minor editing of config files and maybe a mv or two of hostname.* files. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http

Re: Changing Architecture from amd64 to i386

2013-02-25 Thread Peter N. M. Hansteen
data can be restored from a verified backup, right? -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147

Re: Safe bruteforce rule for mobile-friendly website

2013-02-06 Thread Peter N. M. Hansteen
either the max-src-conn or the max-src-conn-rate setting to see which one trips up the mobiles. Possibly relevant question: do all clients receive the same content, or is there a separate version you serve to mobile clients? - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation

Re: IP accounting

2013-01-25 Thread Peter N. M. Hansteen
automatic traffic graphs with a web interface to a reasonable subset of useful traffic analysis features. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious

Re: Athn0 DHCP problem...

2013-01-23 Thread Peter N. M. Hansteen
N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Athn0 won't link with new router!!

2013-01-23 Thread Peter N. M. Hansteen
no DHCP available. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673

Re: ordered OBSD cd set.

2013-01-22 Thread Peter N. M. Hansteen
or territories have odd postal or customs services, for example. for my own part, any delays in deliveries from .ca to .no have been just that kind, but fortunately most of the time delivery has been quite speedy. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: Athn0 DHCP problem...

2013-01-22 Thread Peter N. M. Hansteen
is required in ieee80211(9) before those features can be supported. which means you will need to stick to a, b or g modes for now. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set

Re: How to configure pppoe client on OpenBSD?

2013-01-13 Thread Peter N. M. Hansteen
pppoe pppoe (4) - PPP Over Ethernet protocol network interface pppoe (8) - PPP Over Ethernet translator Also, http://www.openbsd.org/cgi-bin/man.cgi -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: How to configure pppoe client on OpenBSD?

2013-01-13 Thread Peter N. M. Hansteen
', but then in text-only communication there is I suppose scope for interpretation. I'm a bit surprised if the apropos command is not general knowledge. I think it's been available in some form on all unixishes I can remember, but I could have suppressed memories of some. ;) - P -- Peter N. M

Re: How to configure pppoe client on OpenBSD?

2013-01-13 Thread Peter N. M. Hansteen
don't know. I assume Nick would have a word or two to say about this. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: Why does time/ident/daytime/comsat run after an OpenBSD 5.2 install?

2013-01-07 Thread Peter N. M. Hansteen
. Did you search the mailing lists? In almost all cases, 'search the mailing lists' is a friendly attempt to provide a pointer to good information. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember

Re: NMAP problem with PF

2013-01-04 Thread Peter N. M. Hansteen
. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Running OpenBSD on Raspberry Pi

2012-12-31 Thread Peter N. M. Hansteen
a number of tasks quite well. I recently made the mistake of rebuilding openssl on a Pentium3 box, cutting seriously into my beer time, but the day to day tasks it's been assigned all those years the machine performs admirably. - P -- Peter N. M. Hansteen, member of the first RFC 1149

Re: rsu works (was: rsu problem)

2012-12-30 Thread Peter N. M. Hansteen
of the cases they will recover semi-gracefully by themselves (as in, ssh sessions may very well survive, others more hit and miss). It's possible 'ifconfig rsu0 debug' will produce output that will be useful in diagnosing what happens at the time of those drops. -- Peter N. M. Hansteen, member of the first

Re: Running OpenBSD on Raspberry Pi

2012-12-30 Thread Peter N. M. Hansteen
search on the obvious keywords will show, whenever the question has been raised earlier, the response from developers has been less than enthusiastic. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: Running OpenBSD on Raspberry Pi

2012-12-30 Thread Peter N. M. Hansteen
get better hardware for free or the price of a bus ticket. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: A point about the BSD license I'm feeling edgy about

2012-12-29 Thread Peter N. M. Hansteen
are free to add a copyright notice of your own, in addition to simliar notices from previous contributors. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network

Re: PF block log all and ddos issue

2012-12-27 Thread Peter N. M. Hansteen
the offending IP address to make sure you don't make any noise yourself by sending replies (pfctl -k and adding to a table you block drop are optional extras). - P [1] http://bsdly.blogspot.ca/2012/12/ddos-bots-are-people-or-manned-by-some.html -- Peter N. M. Hansteen, member of the first RFC

Re: List of all software present on OpenBSD 5.2

2012-12-26 Thread Peter N. M. Hansteen
nothing. The packages installed via pkg_add are a separate issue, but the packages do depend on the base system (which is what you get, essentially, from the install iso). - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

Re: List of all software present on OpenBSD 5.2

2012-12-26 Thread Peter N. M. Hansteen
of tar included, you have CVS, with even a web frontend, see eg http://www.openbsd.org/cgi-bin/cvsweb/src/bin/pax/tar.c - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit

Re: List of all software present on OpenBSD 5.2

2012-12-26 Thread Peter N. M. Hansteen
prompts you, among other things, to create at least one regular user. It's very useful to take advantage of that opportunity. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil

Re: Netflow server software suggestion

2012-12-23 Thread Peter N. M. Hansteen
refined criteria, the query string you generate by point and click is displayed so you get a useful starting point. (I've been meaning to write a netflow/pflow/nfsen article for a while, but real life including a few incidents where nfsen came in handy have kept interfering). - P -- Peter N. M

Re: Groff replacement

2012-12-05 Thread Peter N. M. Hansteen
the /pub/OpenBSD/5.2/packages/i386 directory does not exist). Try another mirror or check whether that mirror either has an incomplete packages collection or an unexpected directory structure. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: scripts for keeping things in sync after upgrades?

2012-12-04 Thread Peter N. M. Hansteen
) is still reasonably fresh, datelined last July at http://bsdly.blogspot.ca/2012/07/keeping-your-openbsd-system-in-trim.html - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set

Re: spammers getting less stupid?

2012-11-05 Thread Peter N. M. Hansteen
block should really be discarded in favor of the second one, a true brainfart if there ever was one), with some further field notes to be found over at my blag. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http

The little ssh that (sometimes) couldn't

2012-10-28 Thread Peter N. M. Hansteen
cause of the problem. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673

Re: Why anyone in their right mind would like to use NAT64

2012-10-24 Thread Peter N. M. Hansteen
IPv6 while they also have significant amounts of equipment that needs to be kept running for a hard to determine number of years more even though it is old enough that the manufacturers have declined to offer upgrades that would enable the devices to support IPv6. - Peter -- Peter N. M. Hansteen

Re: PF issues help plz

2012-10-13 Thread Peter N. M. Hansteen
content. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: PF issues help plz

2012-10-13 Thread Peter N. M. Hansteen
in quick on iwn0 all flags S/SA pass out log quick on re0 all flags S/SA - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd

Re: Last i386 snapshot broken ?

2012-10-11 Thread Peter N. M. Hansteen
happen. also try downloading the file or files from a different mirror and check for differences. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious

Re: quick query.

2012-10-10 Thread Peter N. M. Hansteen
-system-in-trim.html (a works for me guide). - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147

Re: quick query.

2012-10-10 Thread Peter N. M. Hansteen
updates from your shell, but using some kind of remote administration software for example. Yes. That functionality would be relevant to the OP. I'd managed to forget all about it, probably because the old .profile trick works so well in other contexts. - P -- Peter N. M. Hansteen, member

Re: pfsense and or OpenBSD Home router.

2012-09-11 Thread Peter N. M. Hansteen
be a useful place to start. For those of us on even slimmer budgets, building infrastructure by dumpster diving works too. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit

Re: Language bindings to OpenBSD's filesystem

2012-09-06 Thread Peter N. M. Hansteen
FFS2 in OpenBSD support extended attributes? This commit message has a summary of why this was removed, along with and a few related programs: http://marc.info/?l=openbsd-cvsm=111904373614666w=2 -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com

Re: The ultimate OpenBSD email server

2012-08-15 Thread Peter N. M. Hansteen
to differ. spamd(8) in any configuration is a lot more lightweight than content filtering. You most likely will need content filtering in addition to greylisting+greytrapping, but stopping them earlier is a real plus. See eg http://undeadly.org/cgi?action=articlesid=20120604050025 -- Peter N. M

Re: Broken pfctl ..... ? I not understand my

2012-07-26 Thread Peter N. M. Hansteen
in the defaults. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Broken pfctl ..... ? I not understand my

2012-07-23 Thread Peter N. M. Hansteen
book is update is 15/05/2012, the site web update is 19/05/2012. it would be interesting to hear what book and web site you're referring to here. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: Microsoft is Propping Up BSD

2012-07-16 Thread Peter N. M. Hansteen
, but for some reason mentions Dru Lavigne. Fact checking? Some of us may have heard about it. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic

Re: pfsync/carp causing large number of network errors

2012-06-12 Thread Peter N. M. Hansteen
to a hardware problem, either the card itself, the cables involved or the switch port. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd

Re: Ways to handle DNS amplification attacks with OpenBSD

2012-06-09 Thread Peter N. M. Hansteen
to deal with this one. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: SMTP server pools at odds with the RFC?

2012-06-04 Thread Peter N. M. Hansteen
improvement over what appeared to be the status only a few years back. I still don't quite see why they left the crucial parts of RFC5321 as ambigous as they had been in the predecessor, but a greylisting RFC on the standards track is a very welcome development. - Peter -- Peter N. M. Hansteen, member

Re: SMTP server pools at odds with the RFC?

2012-06-04 Thread Peter N. M. Hansteen
. That did however not stop people from claiming otherwise, and it was a bit disappointing back in 2008 to find that the update did not provide even clearer language. All water under the bridge soonish now, it seems. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: spamd-setup fails from cron

2012-05-29 Thread Peter N. M. Hansteen
shifting to a few minutes past the hour and see if that helps. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949

Re: spamd greylisting: false positives

2012-05-28 Thread Peter N. M. Hansteen
, but just a simple misconfiguration), another thing you need to do is make sure the secondaries have the same or equivalent level of spam and malware protection. That's where things like spamd's syncronization options come in handy. - P -- Peter N. M. Hansteen, member of the first RFC 1149

Re: spamd greylisting: false positives

2012-05-28 Thread Peter N. M. Hansteen
In response to various tidbits that popped up in this thread, I put together some notes on setting up a sane email system, in a works for me article: http://bsdly.blogspot.com/2012/05/in-name-of-sane-email-setting-up-spamd.html -- Peter N. M. Hansteen, member of the first RFC 1149 implementation

Re: spamd greylisting: false positives

2012-05-27 Thread Peter N. M. Hansteen
smtp traffic from the members of the spamd-white table (and nospamd if you're using that) plus the one that passes smtp traffic from your real mail server to elsewhere. See the spamd and spamlogd man pages, it's explained there. But why are you synproxying for spamd? - P -- Peter N. M. Hansteen

Re: spamd greylisting: false positives

2012-05-27 Thread Peter N. M. Hansteen
on options just because they're available. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147

Re: chromium can't start since two snapshots

2012-05-19 Thread Peter N. M. Hansteen
to infer that from the error message, though ;) - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147

A totally meaningless statistics that may serve to cheer you up

2012-05-19 Thread Peter N. M. Hansteen
to somewhere in that tree. Here's hoping this produced at least some CD sales and perhaps the odd book sale. - Peter PS Do get your EuroBSDCon submission in, tomorrow's the deadline -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

Re: greylisting and blacklisting rules in pf.conf

2012-05-17 Thread Peter N. M. Hansteen
pass out log on egress proto tcp to port smtp it's possible you will find my tutorial and slides over at http://home.nuug.no/~peter/pf/ helpful, and you'll find some spamd-related field notes via the blogspot link in my .signature - P -- Peter N. M. Hansteen, member of the first RFC 1149

Re: Sendmail at home

2012-05-10 Thread Peter N. M. Hansteen
reach as packages. Do remember to read the supplied documentation and config file comments properly, and you'll get there. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil

Re: Kernel roughing in tool

2012-04-14 Thread Peter N. M. Hansteen
-- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after 42673 seconds.

Re: Request for a new list: trolling

2012-03-10 Thread Peter N. M. Hansteen
0xAAA 0x...@online.de writes: My suggestion: We create a new list, eg. trolling or smalltalk where other users can discuss about senseless questions. Wouldn't it be even better if we headed them off with a web forum or even a facebook group? - P -- Peter N. M. Hansteen, member

Re: Snappy Answers to Stupid Questions - WTF?

2012-03-08 Thread Peter N. M. Hansteen
On Fri, Mar 09, 2012 at 08:28:37AM +0100, Fredrik Staxeng wrote: Do you want users at all? Or was Linus right? well, we *do* prefer those who come with a sense of humor. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

Re: current releases not updated?

2012-03-07 Thread Peter N. M. Hansteen
and their packages around release-cutting time about half a year ago too. I'd expect snapshot updates to resume soonish, but I have no firm dates or actual officialish info. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http

Re: My OpenBSD 5.0 installation experience (long rant)

2012-03-07 Thread Peter N. M. Hansteen
for the various multiboot options. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic delilah spamd[29949]: 85.152.224.147: disconnected after

Re: My OpenBSD 5.0 installation experience (long rant)

2012-03-07 Thread Peter N. M. Hansteen
usable system. But then I tend to want OpenBSD as the main or only system. Multiboot setups like the one the OP wanted requires a bit of paying attention and is risky in general. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http

EuroBSDCon 2012 Call For Proposals

2012-03-02 Thread Peter N. M. Hansteen
EuroBSDcon 2012 === EuroBSDcon is the European technical conference for users and developers on BSD-based systems. The EuroBSDcon 2012 conference will be held in Warsaw, Poland from Thursday 18 October 2012 to Sunday 21 October 2012, with tutorials on Thursday and Friday and talks on

Re: Keeping installed ports up-to-date

2012-02-14 Thread Peter N. M. Hansteen
friend, in this case specifically part 15 - http://www.openbsd.org/faq/faq15.html - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network traffic

Re: Starting out

2012-01-27 Thread Peter N. M. Hansteen
(except the compNN.tgz set, which shrunk to sixtyish megs compressed by weedning out irrelevancies soon after) - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all

Re: OpenBSD 4.4

2012-01-24 Thread Peter N. M. Hansteen
of max connections and connections per seconds, that solved the problem. When dbg occurs, I cannot do a trace because it completely hangs. Others have offered as useful input as can be had on those. Good luck with the upgrade! All the best, Peter -- Peter N. M. Hansteen, member of the first RFC

Re: PF Snort tutorial

2012-01-04 Thread Peter N. M. Hansteen
://www.openbsd.org/ should be treated with caution, one of the things to look out for is some basic familiarity with OpenBSD such as the points (possibly minor) I pointed out earlier. Cheers, Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com

Re: CF Card setup

2011-12-27 Thread Peter N. M. Hansteen
and the man pages. OpenBSD documentation is both accessible and useful, and if you're still stuck some of us have written supplementary docs that are not that hard to find. Or come back here, reasonable questions usually generate somewhat useful answers. -- Peter N. M. Hansteen, member

Re: CF Card setup

2011-12-27 Thread Peter N. M. Hansteen
pe...@bsdly.net (Peter N. M. Hansteen) writes: for a simple dhcp setup, or for a fixed address and a specific link speed something like (lifted from man hostname.if) inet 10.0.0.1 255.255.255.0 10.0.0.255 description Bob's uplink actually that does not specify a line speed, but the man pages

Re: Upgrading AMD64 4.9-stable to 5.0

2011-12-19 Thread Peter N. M. Hansteen
errors. This sounds like the result of some fairly basic mistake, like trying to install -current packages on -stable. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all

Re: OpenBSD PF tables

2011-12-08 Thread Peter N. M. Hansteen
with, but you could possibly achieve what you want by putting your rules inside anchors and then do whatever manipulations you want to rules in the anchors from the command line. man pf.conf and man pfctl are your friends. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http

Re: OpenBSD PF tables

2011-12-08 Thread Peter N. M. Hansteen
. You may want to browse the PF faq, with http://home.nuug.no/~peter/pf/en/ or the book it spawned (http://www.nostarch.com/pf2.htm) as a useful supplement. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no

Re: Packet filter log tools

2011-12-01 Thread Peter N. M. Hansteen
are written to be viewed via tcpdump, and it's a fairly trivial excercise to produce text output that will be acceptable for tools designed for syslog-like formats. It's a common topic in my tutorials, variations have been mentioned various places on-line (and it's in a certain book). -- Peter N. M

Re: packet loss

2011-11-28 Thread Peter N. M. Hansteen
? This is what it looks like when your link goes down, then comes back again. I'd check with the upstream if they know of any specific incident that matches your disruption. - P -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http

Re: I want copy pf.conf from FreeBSD 8.2 to OpenBSD 5 and use it

2011-11-06 Thread Peter N. M. Hansteen
to any - $NAT1 all of these would be in the new syntax something like pass on $ext_if from $theonething nat-to $NATtheother or you could rewrite to use match rules. - Peter -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net

Re: traffic shaping in OpenBSD

2011-11-01 Thread Peter N. M. Hansteen
and netgraph are 'kernel-level', with some userland tools attached to make the admin's life easier. -- Peter N. M. Hansteen, member of the first RFC 1149 implementation team http://bsdly.blogspot.com/ http://www.bsdly.net/ http://www.nuug.no/ Remember to set the evil bit on all malicious network

Re: traffic shaping in OpenBSD

2011-11-01 Thread Peter N. M. Hansteen
that. If it's the altq syntax you object to, I'm slightly sympathetic, but a whole new queueing system is being gradually introduced (the new prio keyword is the first part), and from early access the new syntax will be a lot easier to deal with. -- Peter N. M. Hansteen, member of the first RFC

Re: Traffic through default pf queue

2011-10-17 Thread Peter N. M. Hansteen
of traffic by quees 'systat queues' may be what you're looking for. The other non-intrusive way to check (ie without editing in tagging etc) would be 'pfctl -vvsr' -- if traffic matches rules that do queue assignment, you'll see the counters. -- Peter N. M. Hansteen, member of the first RFC 1149

Re: Scanning detection, Single Packet Authorization

2011-10-11 Thread Peter N. M. Hansteen
to. For single packet authorization, I'm not aware of any tool in base with that capability, but a quick web search on OpenBSD single packet authorization turns up evidence that others have been at least considering the combination (and written some code). -- Peter N. M. Hansteen, member

<    1   2   3   4   5   6   7   8   9   10   >