Re: [gull] Twint/DebiX+ et Android 8

2024-06-17 Thread Marc SCHAEFER via gull
Hello, On Mon, Jun 17, 2024 at 08:12:51AM +0200, Claude Paroz via gull wrote: > Résultat des courses: un week-end passé à découvrir comment flasher une ROM > Android libre (+ ajout des outils Google non libres pour pouvoir installer > les apps sus-mentionnées) sur ce téléphone. Opération quasi

[epfl-usa] Cette liste de distribution est-elle encore utile?

2024-06-07 Thread Marc SCHAEFER via epfl-usa
Bonjour, Cette liste: https://secure.alphanet.ch/cgi-bin/mailman/listinfo/epfl-usa est-elle encore utile? Merci de me répondre directement (et pas à la liste). ___ epfl-usa mailing list epfl-usa@lists.alphanet.ch

[ftn-nostalgie] Cette liste est-elle encore utile?

2024-06-06 Thread Marc SCHAEFER via ftn-nostalgie
Bonjour, Cette liste: https://secure.alphanet.ch/cgi-bin/mailman/listinfo/ftn-nostalgie est-elle encore utile? Merci de me répondre sans passer par la liste. ___ ftn-nostalgie mailing list ftn-nostalgie@lists.alphanet.ch

[cafe-du-coin] Cette liste de distribution est-elle encore utile?

2024-06-06 Thread Marc SCHAEFER via cafe-du-coin
Bonjour, Cette liste est-elle encore utile? https://secure.alphanet.ch/cgi-bin/mailman/listinfo/cafe-du-coin Avec mes meilleures salutations. ___ cafe-du-coin mailing list cafe-du-coin@lists.alphanet.ch

Re: Debian bookwork / grub2 / LVM / RAID / dm-integrity fails to boot

2024-05-23 Thread Marc SCHAEFER
Hello, On Wed, May 22, 2024 at 05:03:34PM -0400, Stefan Monnier wrote: > Hmm... I've been using a "plain old partition" for /boot (with > everything else in LVM) for "ever", originally because the boot loader > was not able to read LVM, and later out of habit. I was thinking of > finally moving

Re: Debian bookwork / grub2 / LVM / RAID / dm-integrity fails to boot

2024-05-22 Thread Marc SCHAEFER
Hello, On Wed, May 22, 2024 at 10:13:06AM +, Andy Smith wrote: > metadata tags to some PVs prevented grub from assembling them, grub is indeed very fragile if you use dm-integrity anywhere on any of your LVs on the same VG where /boot is (or at least if in the list of LVs, the dm-integrity

Re: Debian bookwork / grub2 / LVM / RAID / dm-integrity fails to boot

2024-05-22 Thread Marc SCHAEFER
Hello, On Wed, May 22, 2024 at 08:57:38AM +0200, Marc SCHAEFER wrote: > I will try this work-around and report back here. As I said, I can > live with /boot on RAID without dm-integrity, as long as the rest can be > dm-integrity+raid protected. So, enable dm-integrity on all LVs,

Re: Debian bookwork / grub2 / LVM / RAID / dm-integrity fails to boot

2024-05-22 Thread Marc SCHAEFER
Additional info: On Wed, May 22, 2024 at 08:49:56AM +0200, Marc SCHAEFER wrote: > Having /boot on a LVM non enabled dm-integrity logical volume does not > work either, as soon as there is ANY LVM dm-integrity enabled logical > volume anywhere (even not linked to booting), grub2 complains

Re: Debian bookwork / grub2 / LVM / RAID / dm-integrity fails to boot

2024-05-22 Thread Marc SCHAEFER
Hello, On Tue, May 21, 2024 at 08:41:58PM +0200, Franco Martelli wrote: > I can only recommend you to read carefully the Wiki: > https://raid.wiki.kernel.org/index.php/Dm-integrity I did, and it looks it does not seem to document anything pertaining to my issue: 1) I don't use integritysetup

Debian bookwork / grub2 / LVM / RAID / dm-integrity fails to boot

2024-05-20 Thread Marc SCHAEFER
Hello, 1. INITIAL SITUATION: WORKS (no dm-integrity at all) I have a Debian bookwork uptodate system that boots correctly with kernel 6.1.0-21-amd64. It is setup like this: - /dev/nvme1n1p1 is /boot/efi - /dev/nvme0n1p2 and /dev/nvme1n1p2 are the two LVM physical volumes - a volume

Re: [gull] Je surf pour vous - 2024-05-13

2024-05-15 Thread Marc SCHAEFER via gull
Hello, On Mon, May 13, 2024 at 05:06:55PM +0200, Philippe Strauss via gull wrote: > Critical OpenVPN Zero-Day Flaws Affecting Millions of Endpoints > https://cybersecuritynews.com/openvpn-zero-day-flaws/ Comme je suis abonné à la liste openvpn, voici quelques infos: Il y a récemment eu 2

Re: HDD long-term data storage with ensured integrity

2024-05-04 Thread Marc SCHAEFER
On Fri, May 03, 2024 at 01:50:52PM -0700, David Christensen wrote: > Thank you for devising a benchmark and posting some data. :-) I did not do the comparison hosted on github. I just wrote the script which tests the dm-integrity on dm-raid error detection and error correction. > FreeBSD also

Re: HDD long-term data storage with ensured integrity

2024-05-03 Thread Marc SCHAEFER
On Mon, Apr 08, 2024 at 10:04:01PM +0200, Marc SCHAEFER wrote: > For off-site long-term offline archiving, no, I am not using RAID. Now, as I had to think a bit about ONLINE integrity, I found this comparison: https://github.com/t13a/dm-integrity-benchmarks Contenders are btrfs,

Re: [gull] Requêtes SQL en LIKE ...% avec psycopg3

2024-04-23 Thread Marc SCHAEFER via gull
Hello, On Mon, Apr 22, 2024 at 04:47:55PM +0200, Philippe Strauss via gull wrote: > Le code (pour le framework Flask) d'un de ces support d'autocomplete est: Je ne connais pas :) Le risque principal avec LIKE c'est que des % peuvent être injectés. C'est surtout dangereux dans du code comme:

[swinog] Re: Swisscom DNS issue: spectrum-conference.org wrongfully resolves to a bluewin address in swisscom mobile networks

2024-04-23 Thread Marc SCHAEFER via swinog
Hello, On Tue, Apr 23, 2024 at 10:04:14AM +0200, Stefan via swinog wrote: > But you know that it is already daily business that Swiss ISP's are blocking > websites? One of the example you give was voted by the Swiss people (Casino blocking). ISP have no say in that matter. Some countries go way

Re: [gull] [resolu] exfat - inconsistence du catalogue sous Linux et macOS - utf8 nfc nfd

2024-04-20 Thread Marc SCHAEFER via gull
On Sat, Apr 20, 2024 at 05:08:54PM +0200, Marc SCHAEFER via gull wrote: > Ca me rappelle des beaux souvenirs Amiga, qui avait développé (avec > Electronic Arts?) le fameux format IFF, qui évitait justement les > Forks (et la perte de performance des fichiers .info, de mémoire). La lectur

Re: [gull] [resolu] exfat - inconsistence du catalogue sous Linux et macOS - utf8 nfc nfd

2024-04-20 Thread Marc SCHAEFER via gull
Salut, On Sat, Apr 20, 2024 at 10:56:53AM +0200, Frederic Dumas via gull wrote: > Dommage que le gestionnaire de la mailing-list bloque les pièces-jointes, Il suffit de mettre le fichier sur un site comme grosfichiers.com puis de mettre l'URL ici. Cela évitera à tout le monde de devoir

Re: [gull] exfat - inconsistence du catalogue sous Linux et macOS

2024-04-18 Thread Marc SCHAEFER via gull
Salut, On Thu, Apr 18, 2024 at 07:55:41AM +0200, felix via gull wrote: > Attention! L'UTF8 de Apple n'est pas forcement le même que celui de Linux... > > voire: > General Batiment > Gnral Btiment C'est juste. En fait, il s'agit ici de la normalisation Unicode: >

Re: SOLVED (was: Re: using mbuffer: what am i doing wrong?)

2024-04-14 Thread Marc SCHAEFER
On Thu, Apr 11, 2024 at 04:14:33PM +0200, DdB wrote: > - the resulting transfer is way faster than say ... ssh. AFAIK ssh is mono-threaded (like OpenVPN, unless you use the kernel module). wireguard is multi-threaded. The symptom will be one CPU ("core") at 100% and the rest mostly idle.

Re: using mbuffer: what am i doing wrong?

2024-04-11 Thread Marc SCHAEFER
Hello, On Tue, Apr 09, 2024 at 03:13:01PM +0200, DdB wrote: > from my research, the abbreviated takeaway is: I never used mbuffer, I use buffer combined with netcat-traditional: # receiver (TCP server on port 8000) nc -l -p 8000 | buffer -S 1048576 -s 32768 -o /dev/null # sender (TCP

Re: HDD long-term data storage with ensured integrity

2024-04-08 Thread Marc SCHAEFER
Hello, On Mon, Apr 08, 2024 at 11:28:04AM -0700, David Christensen wrote: > So, an ext4 file system on an LVM logical volume? > > Why LVM? Are you implementing redundancy (RAID)? Is your data larger than > a single disk (concatenation/ JBOD)? Something else? For off-site long-term offline

Re: HDD long-term data storage with ensured integrity

2024-04-08 Thread Marc SCHAEFER
For offline storage: On Tue, Apr 02, 2024 at 05:53:15AM -0700, David Christensen wrote: > Does anyone have any comments or suggestions regarding how to use magnetic > hard disk drives, commodity x86 computers, and Debian for long-term data > storage with ensured integrity? I use LVM on ext4, and

Re: [gull] Docker premier pas

2024-04-03 Thread Marc SCHAEFER via gull
Salut, On Wed, Apr 03, 2024 at 07:51:03AM +0200, felix via gull wrote: > Mais bon, j'ai installé un buster. (oldoldstable). J'ai alors essayé de > changer quelque trucs pour passer en bookworm Dans mon experience, si le host est buster, alors des conteneurs lxc ou Docker de types buster ou

Re: [gull] Grosse tentative de backdoorer les ssh de debian et redhat

2024-03-31 Thread Marc SCHAEFER via gull
On Sun, Mar 31, 2024 at 04:03:53PM +0200, Marc SCHAEFER via gull wrote: > > https://www.nongnu.org/lzip/xz_inadequate.html > > Cette URL est considérée comme "FUD" (Fear, Uncertainty, Doubt) par des > contributeurs de l'URL précédente. Et surtout, ce qu'il faudrait c'

Re: [gull] Grosse tentative de backdoorer les ssh de debian et redhat

2024-03-31 Thread Marc SCHAEFER via gull
Hello, merci pour ces URLs: On Sun, Mar 31, 2024 at 12:05:33AM +0100, Philippe Strauss via gull wrote: > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1068024 Il dit que d'autres commits suspects existent avant la version à laquelle Debian unstable vient de retourner (toutefois, toujours OK

sshd dependancy to systemd and attack surface

2024-03-30 Thread Marc SCHAEFER
Hello, sshd has a dependancy to systemd, and thus includes a lot of libraries, which augments its attack surface. The recent xz-utils issue [1] has lead to this post by someone suggesting (with a patch, apparently) to confine the sshd -> systemd dependancy in a subprocess [2]. Maybe you want to

Re: making Debian secure by default

2024-03-30 Thread Marc SCHAEFER
Hello, On Fri, Mar 29, 2024 at 07:02:54PM +0100, Kamil Jo?ca wrote: > O-o, is there any simple test to check if I have infected version or > not? For example, under root: path="$(ldd $(which sshd) | grep liblzma | grep -o '/[^ ]*')" if hexdump -ve '1/1 "%.2x"' "$path" | grep -q

Re: [gull] Grosse tentative de backdoorer les ssh de debian et redhat

2024-03-30 Thread Marc SCHAEFER via gull
Hello, On Fri, Mar 29, 2024 at 07:01:49PM +0100, Philippe Strauss via gull wrote: > https://www.openwall.com/lists/oss-security/2024/03/29/4 Et quelqu'un a analysé temporellement ce qui s'est passé. Y compris des faux comptes qui poussent pour qu'une personne ait un accès développeur, en

Re: making Debian secure by default

2024-03-28 Thread Marc SCHAEFER
Hello, On Wed, Mar 27, 2024 at 05:30:50PM -0400, Lee wrote: > Apparently the root of the security issue is that wall is a setguid program? a) wall must be able to write to your tty, which is not possible if wall is not installed setguid OR if people have sane permissions on their terminals

Re: Debugging an USB array issue

2024-03-15 Thread Marc SCHAEFER
Hello, On Fri, Mar 15, 2024 at 06:54:38PM +0100, to...@tuxteam.de wrote: > I may be stating the obvious, but have you made sure the USB hub > is providing enough power to keep your disks happy? It's a 60W external power supply, for 4 disks.

Re: Debugging an USB array issue

2024-03-15 Thread Marc SCHAEFER
Hello, On Fri, Mar 15, 2024 at 01:30:08PM -0400, Dan Ritter wrote: > I have never had long-term happiness with multiple disks > connected via USB. I strongly recommend that you find a 4 or 8 > disk SATA/SAS PCIe card -- an LSI 2008, for example -- and connect > through that, instead. US prices

Debugging an USB array issue

2024-03-15 Thread Marc SCHAEFER
Hello, on a Debian bullseye uptodate system [1], I experiment frequent (every 3-4 hours on heavy load) disk disconnections from a md RAID10 array with 4 drives connected to an USB 1M adapter [2]. Errors do not look like a timeout, but like a DMA error [3]. Immediately after, the disk

Re: [Openvpn-users] Client history

2024-02-28 Thread Marc SCHAEFER
On Wed, Feb 28, 2024 at 12:52:17PM +, Peter Davis via Openvpn-users wrote: > # #!/bin/bash > # export script_type="client-connect" > # export common_name="CommonName" > # export trusted_ip="192.168.129.253" > # ./server-events.sh I did not follow the whole discussion, but why on earth are you

[Openvpn-users] OpenVPN and MTU

2024-02-22 Thread Marc SCHAEFER
Hello, First: I don't have any problem with OpenVPN and MTU, this is out of curiosity. This is a simplified network map: 185.250.56.2 OpenVPN --- A.B.C.D (PPPoE) OpenVPN -- 193.72.186.160 (BGP router for 193.72.186.0/24) Look: (reliant is somewhere else on the internet, X.Y.88.46)

Re: [Openvpn-users] How to hide the number of connections to the server?

2024-02-08 Thread Marc SCHAEFER
Hello, On Thu, Feb 08, 2024 at 11:59:16AM +0100, Gert Doering wrote: > On Thu, Feb 08, 2024 at 10:36:31AM +, Peter Davis via Openvpn-users wrote: > > Is there a way to hide the number of connections to a server? Can an > > intermediate server do this? Instead of connecting directly to the

Re: [Openvpn-users] Can a configuration item be cleared in the server.conf file

2024-02-05 Thread Marc SCHAEFER
On Mon, Feb 05, 2024 at 09:55:58AM +0100, Bo Berglund wrote: > I tried the service restart and it worked inasfar as the logs now look like > this > example: > > Mon Feb 5 09:42:42 2024 us=734354 succeeded -> ifconfig_pool_set() Do you mean rsyslog logs? Again, systemd changes everything: you

Re: [Openvpn-users] Can a configuration item be cleared in the server.conf file

2024-02-05 Thread Marc SCHAEFER
Hello, On Mon, Feb 05, 2024 at 12:06:13AM +0100, Bo Berglund wrote: > restart the specific services or do I have to restart the server computer > itself? I am no systemd specialist, however, most of the times you change a systemd config file you should do: systemctl daemon-reload

Re: [Openvpn-users] Can a configuration item be cleared in the server.conf file

2024-01-27 Thread Marc SCHAEFER
Hello, On Sat, Jan 27, 2024 at 01:06:15PM +0100, Jochen Bern wrote: > (Note that, back when I had to try to get rid of the parameterless > "--daemon" in the unit file, I found that the unit file would get > overwritten with every update - unlike "normal" config files, where a new > packaged

Re: [Openvpn-users] OpenVPN on port 443

2024-01-24 Thread Marc SCHAEFER
Hello, On Wed, Jan 24, 2024 at 11:49:43AM +, Peter Davis wrote: > I am testing this scenario in a virtual environment before moving it to the > real world. So, use subnets within private address ranges (10.0.0.0/8, 172.16.0.0/12, 192.168.0.0/16), or possibly some other reserved addresses

[swinog] Re: Microsoft massive spam outbreak

2024-01-24 Thread Marc SCHAEFER via swinog
Hello, On Mon, Jan 22, 2024 at 04:07:26PM +0100, Benoit Panizzon via swinog wrote: > I am aware, Microsoft Office365 customer service blames this on us > 'falsely and for no reason' blocking email from those ip addresses, and > when presented with Evidence of what happened, they close the case

Re: [Openvpn-users] OpenVPN on port 443

2024-01-23 Thread Marc SCHAEFER
Hello, On Wed, Jan 24, 2024 at 06:14:22AM +, Peter Davis via Openvpn-users wrote: > 1- I don't understand what you mean about "server 20.20.0.0 255.255.255.0". > What is the difference between IP range 10.X and 20.X? 10.0.0.0/8 is a private range, that you can use as you please for private

Re: [Openvpn-users] Reaching connected client machine from the server through the tunnel?

2024-01-17 Thread Marc SCHAEFER
Hello, On Wed, Jan 17, 2024 at 09:57:41PM +0100, Bo Berglund wrote: > Is there some way when that RPi has connected to my OpenVPN server to reach it > "backwards" via the connected tunnel? I mean to establish a command line SSH > interface through the tunnel or similar. Well, it has a

Re: [Openvpn-users] OpenVpn client connect on system start in Linux?

2023-11-22 Thread Marc SCHAEFER
On Wed, Nov 22, 2023 at 03:03:45PM +0100, Marc SCHAEFER wrote: > that particular config, for example, if your file is /etc/openvpn/toto.conf I meant /etc/openvpn/client/toto.conf > systemctl status openvpn-client@toto.service ___ Openvpn

Re: [Openvpn-users] OpenVpn client connect on system start in Linux?

2023-11-22 Thread Marc SCHAEFER
Hello, On Wed, Nov 22, 2023 at 02:44:57PM +0100, Bo Berglund wrote: > Is it enough to put the OVPN file (renamed to extension conf) into the > /etc/openvpn/client dir? I think it is not enough with recent Debian releases using systemd. AFAIK raspi is somewhat Debian. Here you need to test the

Re: [Openvpn-users] --user specified but lacking CAP_SETPCAP

2023-10-26 Thread Marc SCHAEFER
> used to allow the OpenVPN process to keep setup certain capabilities as it > transitions to the user provided via the --user option. The CAP_NET_ADMIN > is, not surprisingly, used to setup the virtual network adapter (both tun > and ovpn-dco) and get network routes set up properly. And, if you

Re: Regarding debian10 with latest linux kernel version.

2023-08-29 Thread Marc SCHAEFER
Hello, On Tue, Aug 29, 2023 at 05:25:01AM +, Nitin Singh wrote: > I am using debian10 base distribution along with linux-kernel 4.19.x. > I wanted to test my application along with linux kernel version-6.1.x > . > I know that it is not supported officially not work>, but is it possible to

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Marc SCHAEFER
Hello, On Fri, Aug 25, 2023 at 01:41:36PM +0200, Christopher Huhn wrote: > Given that will give you an updated package in Bullseye you'd still have to > change your code to change the GDBM_PREREAD behaviour. Do you mean that something changed in bookworm that will create a problem for my

Re: bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Marc SCHAEFER
Hello, Thank you for your answers. In short: the work-around that I mentionned in the bug report is in place, and it works for me. The problem is "solved" for me and it does not look that any further effort to fix it in bullseye will work. Long version: Although it seems that ALL users of that

bullseye / libgdbm6:amd64 is a catastrophgy

2023-08-25 Thread Marc SCHAEFER
Hello, AFAIK is bullseye not yet LTS-handled. Will LTS fixes important bugs, or only security fixes? I reported this: https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1043023 I have a local work-around (keep the buster version), and the maintainer also proposed another local work-around.

Bug#1043023: libgdbm6:amd64: /usr/lib/x86_64-linux-gnu/libgdbm.so.6 in Debian bullseye uses huge amount of memory

2023-08-04 Thread Marc Schaefer
Package: libgdbm6 Version: 1.19-2 Severity: important Dear Maintainer, I run a few DBM-intensive applications. They manipulate huge DBMs, but they work usually like a charm: 15168 mojolic+ 20 0 90.8g 156260 5460 S 0.0 3.0 0:00.30 known_passwords 15159 mojolic+ 20 0 16.6g

Re: Bullseye debian security support?

2023-05-31 Thread Marc SCHAEFER
Hello, On Wed, May 31, 2023 at 11:37:34AM -0700, John Conover wrote: > How long will Debian Bullseye have debian security team support after > Bookworm is announced? LTS planning is here: https://wiki.debian.org/LTS bullseye will be LTS-supported til june 2026 (not yet clearly defined), but

buster docker has issue with bookworm container

2023-05-30 Thread Marc SCHAEFER
Hello, I had a few issues with building a bookworm container using the debian:bookworm image (problems with repository signatures and lzma decompression errors) on a buster docker host. The buster and bullseye containers seem to work like a charm though. So I went the bullseye -> upgrade to

Re: [gull] OpenSIL

2023-05-07 Thread Marc SCHAEFER via gull
On Sun, May 07, 2023 at 02:01:53PM +0200, Daniel Cordey via gull wrote: > https://www.phoronix.com/news/AMD-openSIL-Presentation Intéressant; sur mes systèmes embarqués apu2, j'utilise par exemple Coreboot qui est mentionné dans l'article, et qui est déjà open source. Dans l'article que tu

Re: Debian 10 and LTS version

2023-03-30 Thread Marc SCHAEFER
Hello, On Thu, Mar 30, 2023 at 09:16:41AM +0200, Badr BENZERKANE wrote: > For a task to do it, I need to install a light operating system for our > industrial computer and as I searched on the Internet I based it on Debian > 10.13 netinst because I want a version without desktop environment and I

Re: [gull] [SPAM] Re: [SPAM] Re: Truc et astuces: nice et ionice (rappel)]

2023-03-07 Thread Marc SCHAEFER via gull
On Tue, Mar 07, 2023 at 02:30:22PM +0100, felix via gull wrote: > Supporte, ... presque! C'est vrai que c'était un peu exagéré de dire "supporte". Malgré toutes ces années, cela reste un projet de pouvoir tourner une Debian avec un kernel non Linux, semble-t-il.

Re: [gull] [SPAM] Re: [SPAM] Re: Truc et astuces: nice et ionice (rappel)]

2023-03-07 Thread Marc SCHAEFER via gull
Hello, On Sun, Mar 05, 2023 at 11:34:55AM +0100, Daniel Cordey via gull wrote: > peut-être ce patch qui est proposé par Debian, mais qui n'est disponible que > pour les architectures x86. Ubuntu ayant rajouté le support des ARM. Debian propose des patches mais aussi des kernels directement

Re: [gull] [SPAM] Re: Truc et astuces: nice et ionice (rappel)]

2023-03-05 Thread Marc SCHAEFER via gull
> Le 04.03.23 à 13:38, Marc SCHAEFER via gull a écrit : > structures du kernel. C'est tombé à l'eau à l'époque. Je ne sais pas quelle > base est utilisée par Ubuntu pour son kernel temps réel, mais il y a > toujours eu une base de développement temps réel pour les kernel *X, mais &g

Re: [gull] Truc et astuces: nice et ionice (rappel)]

2023-03-04 Thread Marc SCHAEFER via gull
On Sat, Mar 04, 2023 at 01:17:00PM +0100, Daniel Cordey via gull wrote: > Le 04.03.23 à 12:46, Marc SCHAEFER via gull a écrit : > > > Soit c'est psychologique, soit ça rend effectivement les I/O plus > > souples dans mon workload et refait marcher l'ionice. > >

Re: [gull] Truc et astuces: nice et ionice (rappel)

2023-03-04 Thread Marc SCHAEFER via gull
On Fri, Mar 03, 2023 at 09:54:31AM +0100, felix via gull wrote: > $ exec nice -19 ionice -c 3 bash Attention, de mémoire les priorités de queue d'I/O ont été désactivées par défaut dans pas mal de distributions, ce qui fait qu'ionice -c3 n'a aujourd'hui pas d'effet. Work-around: activer le I/O

Re: [gull] [SPAM] Re: gap: journalctl vs ps

2023-02-25 Thread Marc SCHAEFER via gull
On Fri, Feb 24, 2023 at 06:56:57PM +0100, felix via gull wrote: > J'ai un gap immédiatement après avoir booté! Si j'étais un système qui doit maintenir un temps précis, je noterais durant l'exploitation à quel point je dois faire des corrections d'horloge locale, et peut-être qu'au moment du

Re: [Openvpn-users] openVPN vs openSSH for single user access

2023-02-15 Thread Marc SCHAEFER
On Wed, Feb 15, 2023 at 05:43:12PM +0100, Jan Just Keijser wrote: > Having port 22 open on the internet is asking for bots & script kiddies to > try and break in, but usually fail2ban takes care of it quite nicely. Yes, and I you can report to abuseipdb.com -- that's why my main server has port

Re: [Openvpn-users] openVPN vs openSSH for single user access

2023-02-15 Thread Marc SCHAEFER
On Wed, Feb 15, 2023 at 05:19:07PM +0100, Gert Doering wrote: > SPF itself is not the problem (that only checks envelope-from, which > the list does change), but DMARC with p=reject is. Correct! > Not sure if the list actually can do the "do the From: rewrite for > DMARC p=reject enabled

Re: [Openvpn-users] openVPN vs openSSH for single user access

2023-02-15 Thread Marc SCHAEFER
On Wed, Feb 15, 2023 at 04:43:07PM +0100, Gert Doering wrote: > On Wed, Feb 15, 2023 at 04:06:44PM +0100, Marc SCHAEFER wrote: > > I run OpenSSH with UDP and on a random port, it's is presumably much > > more difficult to find on scanners. > > I guess this was inte

Re: [Openvpn-users] openVPN vs openSSH for single user access

2023-02-15 Thread Marc SCHAEFER
On Wed, Feb 15, 2023 at 02:12:58PM +0100, Stefanie Leisestreichler wrote: > Which leads to the question: Do you focus with same caution to an exposed > openvpn service or is this more specific for those sshd? No. I run OpenSSH with UDP and on a random port, it's is presumably much more difficult

Three Apache2 vulnerabilities

2023-02-02 Thread Marc SCHAEFER
Hello, CERT-FR considers three new Apache2 vulnerabilities to be of concern [1]. These are: CVE-2022-37436 [2] CVE-2022-36760 [3] CVE-2006-20001 [4] The first one will modify how clients may apply some security headers if a malicious backend triggers this bug (some headers will be in the

Bug#1011413: inn2: nnrpd as distributed does not support $modify_headers, recompiled does

2023-01-29 Thread Marc Schaefer
You can close this bug indeed! Forgot to tell you that it works ok on bullseye. 28 janv. 2023 23:15:24 Marco d'Itri : > On May 24, Marco d'Itri wrote: > >>> Package: inn2 >>> Version: 2.6.3-1+deb10u2 >> Sorry, I have no plans to spend time debugging oldstable but please let >> me know if this

[asterisk-users] sip trunk, parsing DID

2023-01-23 Thread Marc SCHAEFER
Hello, I am using a Swiss VoIP provider called sipcall. They have what they call a SIP trunk, and it is less expensive than individual accounts. From Asterisk's point of view, this is just a regular SIP account, which can however receive and send calls from multiple numbers. I just migrated from

Re: [gull] SBC

2022-12-18 Thread Marc SCHAEFER via gull
On Sat, Dec 17, 2022 at 05:40:47PM +0100, Philippe Strauss via gull wrote: > Bon à savoir, mon prochain serveur perso ce sera ce genre de dissipation, > pas plus. Un serveur sur apu2 c'est pas mal aussi. J'en ai un avec 1 TB en RAID1 (1x SSD 7mm, 1x mSATA, interne), et la consommation est entre 8

Re: [gull] SBC

2022-12-14 Thread Marc SCHAEFER via gull
Hello, On Wed, Dec 14, 2022 at 05:45:17PM +0100, felix via gull wrote: > Pour de l'embarqué, j'utilise des APU2: http://pcengines.ch/ > Mais pas de GPU! Moi aussi, plein d'apu2s (routeurs, switches, firewalls, IDS, cluster lxc ou docker, serveur de fichiers, web, etc). Si l'accélérateur de

Re: [gull] Commentaires avisés

2022-12-08 Thread Marc SCHAEFER via gull
Tiens, salut Dominik, > Ma meilleure anecdote sur les langages de programmation vient de > Charles Rapin, professeur d'informatique de l'EPFL décédé en 1998. Il Ah, un excellent prof: les autres profs que j'avais eus à l'époque en informatique n'étaient pas des informaticiens (normal à l'époque)

Re: [gull] Commentaires avisés au sujet de Rust

2022-12-03 Thread Marc SCHAEFER via gull
Bonjour, On Sat, Dec 03, 2022 at 03:57:00PM +0100, Philippe Strauss via gull wrote: > elle est morte cette liste... Un peu en sommeil. [ 14 lignes de citations inutiles et mal placées, supprimées ] Sur le thème des langages "memory-safe" et l'amélioration de sécurité, au moins pour les

[swinog] Re: How to destroy data effectively?

2022-12-03 Thread Marc SCHAEFER via swinog
Hello, On Fri, Dec 02, 2022 at 03:55:23PM +0100, Patrick Studer via swinog wrote: > We recommend remove them from computers and bring them to a company named XXX > (to professional shred them). As a joke, we now know where to look for your data :) ___

Re: Asterisk: request for testing

2022-10-26 Thread Marc SCHAEFER
On Tue, Oct 25, 2022 at 05:11:58PM +0200, Markus Koschany wrote: > I can wait a few days more but wanted to release at the end of the month at > the > latest. So, I won't be able to test in that time frame, release :) signature.asc Description: PGP signature

Re: Asterisk: request for testing

2022-10-25 Thread Marc SCHAEFER
Hello, I would like to test (mainly on buster), but so far I have not found the time to do so. When do you intend to release this: > I have prepared two security updates of Asterisk, a Private Branch Exchange, > one for Bullseye and one for Buster. The update will address 27 CVE in Buster > and

Re: [gull] [SECURITY] [DSA 5257-1] linux security update

2022-10-19 Thread Marc SCHAEFER via gull
Hello, > je me suis un peu fait troué par le bug wifi. Pour recadrer la discussion, sur le fond, j'ai simplement fait un travail de classification qui permet à chacun de déterminer s'il doit paniquer ou non. Je ne souhaitais en fait pas me prononcer sur l'utilité ou non de ce forward. Mais je

Re: [gull] Fwd: [SECURITY] [DSA 5257-1] linux security update

2022-10-19 Thread Marc SCHAEFER via gull
On Wed, Oct 19, 2022 at 08:23:51AM +0200, Concombre Masqué via gull wrote: > Suffisamment importante pour justifier un fwd. à la liste du GULL. Vraiment? La dangerosité d'une vulnérabilité dépend fortement de l'usage que l'on fait de son système. Evidemment, il faut faire toutes les mises à

[swinog] Re: switch started blocking whois queries?

2022-10-17 Thread Marc SCHAEFER
Hello, whois alphanet.ch works from UPC/Sunrise, SWITCH and init7 for me. The disclaimer and some of the data are still there. ___ swinog mailing list -- swinog@lists.swinog.ch To unsubscribe send an email to swinog-le...@lists.swinog.ch

Re: [gull] liste du GULL test 20

2022-07-11 Thread Marc SCHAEFER via gull
On Thu, Jul 07, 2022 at 02:46:55PM +0200, felix via gull wrote: > J'en suis à 20... J'ajoute un élément important pour TOUS les abonnés de la liste gull: vérifiez si vous avez configuré un .forward et faites autrement. Du style: u...@toto.ch est l'abonné à la liste GULL mais

Re: [gull] The End of the Privacy of Digital Correspondence

2022-07-06 Thread Marc SCHAEFER via gull
Hello, On Wed, Jul 06, 2022 at 12:25:05PM +0200, Philippe Strauss via gull wrote: > > du vrai end-to-end encryption -- plutôt positif, non? > > je ne comprends pas ton troisième paragraphe, élabore qque peu STP! Il y a deux scénarii possibles: - soit l'EU obligerait l'IA côté serveur -

Re: [gull] The End of the Privacy of Digital Correspondence

2022-07-06 Thread Marc SCHAEFER via gull
Hello, On Tue, Jul 05, 2022 at 05:08:18PM +0200, Philippe Strauss via gull wrote: > En trois mots: une A.I. scannant _TOUS_ les messages de chat et > messageries, ce afin de transmettre les contenus pédocriminels aux > autorités. Dans un premier temps tout du moins. Et donc rendre illégal le

Re: [gull] liste du GULL

2022-07-03 Thread Marc SCHAEFER via gull
On Sat, Jul 02, 2022 at 05:19:27PM +0200, felix via gull wrote: > Il semble bien, en effet que gmail rejette de plus en plus systématiquement > nos mails... Il faudrait ajouter un champ SPF et un champ DKIM au serveur de mail, et un champ DMARC. C'est assez facile à faire, il n'y a même pas

Re: ntp warnings with tzdata leap-seconds file

2022-06-28 Thread Marc SCHAEFER
Hello, On Tue, Jun 28, 2022 at 01:24:38PM +0200, Emilio Pozuelo Monfort wrote: > On 27/06/2022 16:33, Marc SCHAEFER wrote: > > On another subject, I still get the ntp warnings even after updating tzdata, > > and restarting ntpd manually, also with buster: > > > > J

Re: What to do with sox

2022-06-27 Thread Marc SCHAEFER
Hello, On Mon, Jun 27, 2022 at 04:01:46PM +0200, Enrico Zini wrote: > Alternatively, is it worth reaching out to those who have sox installed > to figure out what they are using it for, and reassess those > vulnerabilities based on the kind of exposure that sox is actually > having? I am for

Re: buster & ntpd leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): will expire in less than 19 days

2022-06-09 Thread Marc SCHAEFER
On Thu, Jun 09, 2022 at 09:49:31AM +, Schmidt, Bernhard wrote: > /usr/share/zoneinfo/leap-seconds.list is provided by the tzdata > package. That one would need to be updated in Buster. Thank you, forgot to verify that. > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=1012191 And there is

buster & ntpd leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): will expire in less than 19 days

2022-06-09 Thread Marc SCHAEFER
Hello, buster is not yet handled by LTS, but it will be soon AFAIK. Jun 9 09:10:02 virtual ntpd[20743]: leapsecond file ('/usr/share/zoneinfo/leap-seconds.list'): will expire in less than 19 days Could you look into it, or should I still report a bug against buster's ntpd? Thank you.

Re: [gull] Duckduckgo

2022-05-25 Thread Marc SCHAEFER via gull
On Wed, May 25, 2022 at 09:37:18AM +0200, Daniel Cordey via gull wrote: > niveau de recherche, mais ça utilise Bing qui n'est clairement pas > comparable à Google et qui est bien plus biaisé que Google; entre autre :-( Il se peut aussi que Google, grâce à ton profil anonyme, voire ta connexion,

Bug#1011413: inn2: nnrpd as distributed does not support $modify_headers, recompiled does

2022-05-22 Thread Marc SCHAEFER
Package: inn2 Version: 2.6.3-1+deb10u2 Severity: normal Dear Maintainer, I do this in my /etc/news/filter/filter_nnrpd.pl's filter_post: $modify_headers = 1; $hdr{'X-test'} = "42"; return ""; However, - with stock INN2 package, the X-test header does not get added - doing

Bug#1009751: onak's keyd uses 100% CPU

2022-04-16 Thread Marc SCHAEFER
Package: onak Version: 0.5.0-1 Severity: important Dear Maintainer, on a buster system, keyd uses 100% CPU: onak 30318 98.6 0.0 8864 4884 ?Rs 08:04 5:39 /usr/sbin/keyd -f vz15:~# strace -p 30318 2>&1 | head -20 strace: Process 30318 attached _newselect(4, [3], NULL, NULL,

Re: [Openvpn-users] Getting: 2 updates could not be installed automatically

2022-03-08 Thread Marc SCHAEFER
On Tue, Mar 08, 2022 at 10:02:19PM +0100, Bo Berglund wrote: > It says that I have held broken packages but I have no idea on what that even > means or how one can "hold" something in a computer A held package is a package that is marked as DO NOT TOUCH (no upgrade). To list held packages,

Re: [gull] VaudTax 2021

2022-03-02 Thread Marc SCHAEFER via gull
Salut Daniel, On Wed, Mar 02, 2022 at 10:35:27PM +0100, Daniel Cordey via gull wrote: > Il me dit avoir besoin de la libwebkit2gtt, disant qu'il ne la trouve pas et > que je dois l'installer. Sauf, que j'ai déjà la nouvelle version. Pour la 1ère fois de ma vie, j'ai utilisé ClicknTax [1], je

Re: [Openvpn-users] Expected transfer speed LAN-LAN using OpenVPN?

2022-02-13 Thread Marc SCHAEFER
Hello, On Sat, Feb 12, 2022 at 06:22:41PM +0100, Bo Berglund wrote: > So this is about 10 Mbit/s speed... > I had really hoped for something better than 1/25th of the connection speed. > Is this normal or is there some way to improve the speed? Depending on the hardware, I can measure upto 7-8

Re: [users@httpd] Dynamic authentication rules

2022-02-12 Thread Marc SCHAEFER
On Fri, Feb 11, 2022 at 06:21:50PM -0500, stormy wrote: > Maybe I'm missing something that you refer to as "tricks" and "presumably"? > Proof of concept? Context? If the dynamic way does not work, I will simply generate about 100 different configurations and merge them in Apache, it's not

[users@httpd] Dynamic authentication rules

2022-02-11 Thread Marc SCHAEFER
Hello, In general, I would handle that kind of authentification tricks in a perl script, however in this case I would need to protect a script directly in Apache. What presumably would work: AuthType Basic AuthName "Login Required for testing" AuthUserFile

Re: [swinog] SPF checking on upcmail.net failing

2022-01-25 Thread Marc SCHAEFER
Hello, On Tue, Jan 25, 2022 at 02:38:58PM +0100, Marc SCHAEFER wrote: > On Tue, Jan 25, 2022 at 01:03:23PM +, Beat Eichenberger wrote: > > Is there a UPC mailadmin following this list? > > Also, the return address for billing bounces: > > : host mx2.tripolis.com[87.

Re: [swinog] SPF checking on upcmail.net failing

2022-01-25 Thread Marc SCHAEFER
On Tue, Jan 25, 2022 at 01:03:23PM +, Beat Eichenberger wrote: > Is there a UPC mailadmin following this list? Also, the return address for billing bounces: : host mx2.tripolis.com[87.253.151.86] said: 450 4.1.1 : Recipient address rejected: unverified address: User unknown in

Re: [swinog] UPC Cablecom IPv6 verschwunden?

2022-01-06 Thread Marc SCHAEFER
On Thu, Jan 06, 2022 at 01:06:33PM +0100, Lukas Knauer wrote: > Was that ever available? iirc Cablecom/UPC offers either IPv4-only or > IPv6+CGNAT (aka "Dualstack lite"). But no real dual stack. BTW, I made a video about how to create IPv6 servers on an *end-user* connection, and I mention the

Re: [gull] Fwd: OIN

2021-11-23 Thread Marc SCHAEFER
On Mon, Nov 22, 2021 at 10:58:35AM +0100, Daniel Cordey wrote: > En effet, la liste ne publie pas lorsqu'elle est en "cc". Apparemment si, j'ai reçu ces 3 mails via la liste: 1 Nov 22 Daniel Cordey ( 832) [gull] Fwd: OIN 2 Nov 22 Daniel Cordey ( 119) [gull] Fwd: OIN 3

Re: sysrq over *USB*

2021-11-21 Thread Marc SCHAEFER
On Fri, Oct 15, 2021 at 09:02:50PM +0200, Marc SCHAEFER wrote: > Should I abandon all hope to make it work with USB, or should it work? Yes, sysrq can work with USB, but not with stock Debian kernels, because of [1]. Here is the work-around: 1) recompile kernel (see [2]) with the follow

Re: Does sysrq work over USB?

2021-11-21 Thread Marc SCHAEFER
Hello, On Sun, Nov 21, 2021 at 07:07:33PM +0100, Valentin Vidi?? wrote: > I tried and it doesn't work for me either, but the problem is most > likely missing CONFIG_USB_SERIAL_CONSOLE=y option in the kernel build: > > https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=868352 Yes, with a

Re: Does sysrq work over USB?

2021-11-21 Thread Marc SCHAEFER
On Tue, Nov 16, 2021 at 10:29:00PM +0100, Valentin Vidi?? wrote: > Do you have console=ttyUSB0,... set? What does /proc/consoles say? No, I did not. Now, I have added on a test machine: console=ttyUSB0,9600 console=tty0 to /etc/default/grub and started upgrade-grub and rebooted. I had and

  1   2   3   4   5   6   7   8   9   10   >