Re: IPFW disconnections and resets

2005-04-30 Thread Remko Lodder
carries the commands given. In worst case i can access the machine again after three minutes, which isn't that bad ;-) Just my 0.02E(urocents) -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] Reporter DSINET ** [EMAIL PROTECTED] Founder Tienervaders ** [EMAIL PROTEC

Re: ports/84312: security/portaudit doesn't report about all security bugs

2005-07-30 Thread Remko Lodder
Synopsis: security/portaudit doesn't report about all security bugs Responsible-Changed-From-To: freebsd-security->remko Responsible-Changed-By: remko Responsible-Changed-When: Sat Jul 30 17:05:19 GMT 2005 Responsible-Changed-Why: I entered the apache vulnerability into VuXML so i should fix this

Re: Security warning with sshd

2005-08-21 Thread Remko Lodder
information: http://lists.freebsd.org/pipermail/freebsd-pf/2005-August/001337.html (and related messages) Cheers, Remko -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] FreeBSD** [EMAIL PROTECTED] Reporter DSINET** [EMAIL PROTECTED

Re: Ruby vulnerability?

2006-07-29 Thread Remko Lodder
e a shot on how different vendors resolved this issue and generate patches from that.. -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] FreeBSD** [EMAIL PROTECTED] /* Quis custodiet ipsos custodes */ ___ f

Re: Ruby vulnerability?

2006-07-30 Thread Remko Lodder
Sergey Matveychuk wrote: Sergey Matveychuk wrote: Good. There is three patches there. I'll test if they fix the vulnerabilities. FYI The fixes was committed. Thanks a lot for the work Sergey! -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] Fr

Re: ports / www/linux-seamonkey / flashplugin vulnerability

2006-09-13 Thread Remko Lodder
roper feedback when we have it. Thanks for the notice! Cheers, Remko on behalf of The FreeBSD Security Team -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] FreeBSD** [EMAIL PROTECTED] /* Quis custodiet ipsos cus

Re: Recent vulnerabilities in xorg-server

2007-01-11 Thread Remko Lodder
a bit longer to get the things incorporated. Thanks for using FreeBSD and your willingness to improve the product! It is being appriciated. Cheers, Remko -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] Free

Re: Support for 5.x (Was: Re: What about BIND 9.3.4 in FreeBSD in base system ?)

2007-02-06 Thread Remko Lodder
en we can try to be a brave schoolkid. Thanks. > > Chris > ___ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "[EMAIL PROTECTED]" -- Kin

Re: Support for 5.x (Was: Re: What about BIND 9.3.4 in FreeBSD in base system ?)

2007-02-06 Thread Remko Lodder
On Tue, Feb 06, 2007 at 04:08:11PM +0100, Julian H. Stacey wrote: > Remko Lodder wrote: > > On Tue, Feb 06, 2007 at 01:21:44PM +, Chris wrote: > > > On 03/02/07, Julian H. Stacey <[EMAIL PROTECTED]> wrote: > > > think you hit the nail bang on the head, I am o

Re: [tt #17465] [Comment] FreeBSD Security Advisory FreeBSD-SA-07:06.tcpdump

2007-08-05 Thread Remko Lodder
гах полная тишина, я подозреваю, это из-за >>> каких-то вопросов с безопасностью на этом сервере. >>> >> А че было-то? > > логическая ошибка > > > So, this is an english text, what was above? -- Kind regards, Remko Lodder ** [EMAIL

Re: OpenSSL bufffer overflow

2007-09-29 Thread Remko Lodder
s on our todo list. Thanks, Remko -- Kind regards, Remko Lodder ** [EMAIL PROTECTED] FreeBSD** [EMAIL PROTECTED] /* Quis custodiet ipsos custodes */ ___ freebsd-security@freebsd.org mailing list http://lists.f

RE: What about FreeBSD? - KAME Project "ipcomp6_input()" Denial of Service

2008-02-06 Thread Remko Lodder
We are aware and working on resolving this. Thanks Remko Hat: freebsd secteam -Original Message- From: "Mohacsi Janos" <[EMAIL PROTECTED]> To: freebsd-security@freebsd.org Sent: 6-2-08 21:54 Subject: What about FreeBSD? - KAME Project "ipcomp6_input()" Denial of Service TITLE: KAME Pro

Re: portaudit: xfce vulnerabilities

2008-02-13 Thread Remko Lodder
Hey Andriy, Thanks for the report, from what I know miwi was going to look at this to match 4.4.2 so that nothing else is affected.. Cheers remko -- /"\ Best regards, | [EMAIL PROTECTED] \ / Remko Lodder | [EMAIL PROTECTED] Xhttp:/

Re: VuXML entry for CVE-2008-0318 (libclamav)

2008-02-15 Thread Remko Lodder
On Thu, February 14, 2008 4:10 pm, Eygene Ryabinkin wrote: > Good day. > > Wed, Feb 13, 2008 at 06:38:46PM +0300, Eygene Ryabinkin wrote: >> Attached is the draft of the VuXML entry for the new ClamAV >> vulnerability. > > As pointed to me by Remko Lodder, the attachmen

Re: BIND update?

2008-07-08 Thread Remko Lodder
(hat: Secteam) -- /"\ Best regards, | [EMAIL PROTECTED] \ / Remko Lodder | [EMAIL PROTECTED] Xhttp://www.evilcoder.org/ | / \ ASCII Ribbon Campaign | Against HTML Mail and News

Re: BIND update?

2008-07-08 Thread Remko Lodder
stantly. The FreeBSD Security Team is aware of this situation and will investigate how to do plan and act upon this. Thanks, Remko -- /"\ Best regards, | [EMAIL PROTECTED] \ / Remko Lodder | [EMAIL PROTECTED] Xhttp://www.evilcoder.org/

Re: BIND update?

2008-07-09 Thread Remko Lodder
On Wed, July 9, 2008 5:19 pm, Josh Mason wrote: > Remko Lodder wrote: >> On Tue, July 8, 2008 8:34 pm, Andrew Storms wrote: >>> Are going to expect a update for BIND today? >>> >>> http://www.isc.org

Re: BIND update?

2008-07-09 Thread Remko Lodder
Josh Mason wrote: Thanks, you really showed how you are by sending these replies. I wish you goodluck with your quest, perhaps someday someone can help you. Goodbye. -- /"\ Best regards, | [EMAIL PROTECTED] \ / Remko Lodder | [EMAIL PROT

Re: BIND update?

2008-07-09 Thread Remko Lodder
Remko Lodder wrote: Josh Mason wrote: Thanks, you really showed how you are by sending these replies. I wish you goodluck with your quest, perhaps someday someone can help you. Goodbye. Hi, I am sorry for this reply, it was an expression of my frustation towards you. The frustation is

Re: BIND update?

2008-07-09 Thread Remko Lodder
Wesley Shields wrote: On Wed, Jul 09, 2008 at 01:27:06PM -0400, Josh Mason wrote: On 7/9/08, Remko Lodder <[EMAIL PROTECTED]> wrote: Remko Lodder wrote: Josh Mason wrote: Thanks, you really showed how you are by sending these replies. I wish you goodluck with your quest, perhaps s

Re: BIND update?

2008-07-09 Thread Remko Lodder
Best regards, | [EMAIL PROTECTED] \ / Remko Lodder | [EMAIL PROTECTED] Xhttp://www.evilcoder.org/ | / \ ASCII Ribbon Campaign | Against HTML Mail and News ___ freebsd-security@freebsd.org ma

[Fwd: cvs commit: ports/dns/bind9 Makefile distinfo ports/dns/bind94 Makefile distinfo ports/dns/bind95 Makefile distinfo]

2008-07-09 Thread Remko Lodder
an/listinfo/cvs-ports To unsubscribe, send any mail to "[EMAIL PROTECTED]" -- /"\ Best regards, | [EMAIL PROTECTED] \ / Remko Lodder | [EMAIL PROTECTED] Xhttp://www.evilcoder.org/ | / \ ASCII Ribbon

Re: freebsd-update not pulling in BIND update

2008-07-14 Thread Remko Lodder
le for /usr/sbin/named, it isn't reporting > the updated version: > > $ /usr/sbin/named -v > BIND 9.4.2 > > Any thoughts? > > thanks in advance, > mark > ___ >From my understand we don't bump the vers

Re: vuxml updates, cont.

2009-01-02 Thread Remko Lodder
e VuXML updates on secteam@ If you have questions about the FreeBSD Security Team / VuXML please let me/us know. Thanks, Remko -- /"\ Best regards,| re...@freebsd.org \ / Remko Lodder | re...@efnet Xhttp://www.evilcoder.org/| / \ A

Re: [Fwd: OpenSSL 1.0.0 beta5 release]

2010-01-23 Thread Remko Lodder
___ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org" -- /"\ Best regards,| re...@free

Re: online cheksum verification for FreeBSD

2010-03-19 Thread Remko Lodder
tripwire and get a baseline from a trusted CD (you can verify the ISO Files that we deliver) and use that to build your system. Thanks, Remko (Speaking for myself) -- /"\ Best regards,| re...@freebsd.org \ / Remko Lodder | re...@ef

Re: It's not possible to allow non-OPIE logins only from trusted networks

2011-03-10 Thread Remko Lodder
) network between them. I pushed it to my parents who are (sigh) using Windows, I use it from my Mac (Viscosity) and hell it even works on Linux/Gentoo.. And it's all.. free :-) Cheers Remko -- /"\ Best regards,| re...@freebsd.org \ / Remko Lodder

Re: Reasonable expectations of sysadmins (was Re: FreeBSD Security Advisory FreeBSD-SA-11:05.unix)

2011-10-10 Thread Remko Lodder
27;t do it. > Hi Mike, I do see the point you are mentioning and I will discuss this the next time we (Security Team) are preparing an advisory. Thanks Remko -- /"\ With kind regards,| re...@elvandar.org \ / Remko Lodder | re...@freebsd.org

Re: Pull in upstream before 9.1 code freeze?

2012-07-03 Thread Remko Lodder
..@des.no > +1 for unbound :-) -- /"\ With kind regards,| re...@elvandar.org \ / Remko Lodder | re...@freebsd.org XFreeBSD| http://www.evilcoder.org / \ The Power to Serve| Quis custodiet ip

Re: Portaudit build currently broken

2013-04-04 Thread Remko Lodder
he services anyway we can as well better do it the proper way right away instead of turning on unsupported services Thanks, Remko -- /"\ With kind regards,| re...@elvandar.org \ / Remko Lodder | re...@freebsd.org XFreeBSD

Re: NTP security hole CVE-2013-5211?

2014-03-21 Thread Remko Lodder
/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org" -- /"\ Best regards, | re...@freebsd.org \ / Remko Lodder | remko@EFnet Xhttp://www.evilcoder.org/ | / \ ASCII Ribbon Campaign | Against HTML Mail and News signature.asc Description: Message signed with OpenPGP using GPGMail

Re: NTP security hole CVE-2013-5211?

2014-03-21 Thread Remko Lodder
On 21 Mar 2014, at 20:20, Ronald F. Guilmette wrote: > > In message , > Remko Lodder wrote: > >> Reading the mails from this thread leads me to believe that there is no >> stateful firewall concept in place? > > I am not the poster to whom you were res

Re: FreeBSD Security Advisory FreeBSD-SA-14:19.tcp

2014-09-16 Thread Remko Lodder
ttp://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org" -- /"\ Best regards, | re...@freebsd.org \ / Remko Lodder | remko@EFnet Xhttp://www.evilcoder.

Re: FreeBSD Security Advisory FreeBSD-SA-14:31.ntp

2014-12-25 Thread Remko Lodder
that others think different and they are ofcourse entitled to do so. -- /"\ Best regards, | re...@freebsd.org \ / Remko Lodder | remko@EFnet Xhttp://www.evilcoder.org/ | / \ ASCII Ribbon Campaign | Against HTML Mail and Ne

Re: FreeBSD Security Advisory FreeBSD-SA-15:04.igmp (fwd) - ipfw fix?

2015-02-25 Thread Remko Lodder
ng list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org" -- /"\ Best regards, | re...@freebsd.org \ / Remko Lodder | remko@EFnet Xhttp://www.

Re: New pkg audit / vuln.xml failures (php55, unzoo)

2015-05-23 Thread Remko Lodder
d >> (despite email to the security team). > ___ > freebsd-security@freebsd.org mailing list > http://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.o

Re: Ports Secteam

2015-06-09 Thread Remko Lodder
Hi, > > On June 9, 2015 at 1:59 AM Robert Simmons wrote: > > > On Mon, Jun 8, 2015 at 7:31 PM, Xin Li wrote: > > On 06/08/15 14:37, Robert Simmons wrote: > >> I'm sure that the reason these questions have not been answered is > >> simply because they may have gotten lost i

Re: FreeBSD Security Advisory FreeBSD-SA-17:02.openssl

2017-02-23 Thread Remko Lodder
> On 23 Feb 2017, at 12:11, Andrea Venturoli wrote: > > On 02/23/17 08:39, FreeBSD Security Advisories wrote: >> -BEGIN PGP SIGNED MESSAGE- >> Hash: SHA512 >> >> = >> FreeBSD-SA-17:02.openssl

Re: The Stack Clash vulnerability

2017-06-22 Thread Remko Lodder
> On 22 Jun 2017, at 03:10, Michelle Sullivan wrote: > > Ed Maste wrote: >> On 20 June 2017 at 16:22, Ed Maste wrote: >>> On 20 June 2017 at 04:13, Vladimir Terziev wrote: Hi, I assume FreeBSD security team is already aware about the Stack Clash vulnerability, that is sta

Re: The Stack Clash vulnerability

2017-06-23 Thread Remko Lodder
> On 23 Jun 2017, at 01:19, Michelle Sullivan wrote: > > Peter, > > Peter Jeremy wrote: >> >> paying someone to provide whatever level of support you want. With >> respect to your 9.x servers, no-one is saying you must replace the >> hardware, just that the FreeBSD Project will not continue t

Re: pkg audit false negatives

2017-08-11 Thread Remko Lodder
Hi Roger, > On 11 Aug 2017, at 04:41, Roger Marquis wrote: > > In the past pkg-audit and even pkg-version have not been reliable tools > where installed ports or packages have been subsequently discontinued or > renamed. Today, however, I notice that dovecot2 is still showing up in > the output

Re: pkg audit false negatives

2017-08-11 Thread Remko Lodder
Hi Roger, > On 11 Aug 2017, at 17:14, Remko Lodder wrote: > > Hi Roger, > >> On 11 Aug 2017, at 04:41, Roger Marquis wrote: >> >> In the past pkg-audit and even pkg-version have not been reliable tools >> where installed ports or packages have been sub

Re: pkg audit false negatives

2017-08-11 Thread Remko Lodder
> On 11 Aug 2017, at 23:47, Roger Marquis wrote: > >> It had been resolved for dovecot (it will now match both variants, since >> people might still have >> the old variant of the port installed) and there is a new paragraph added to >> the porters handbook >> which tells that we need to have

Re: pkg audit false negatives

2017-08-12 Thread Remko Lodder
> On 12 Aug 2017, at 02:37, Roger Marquis wrote: > > On Fri, 11 Aug 2017, Remko Lodder wrote: > >> If an entry is removed from the ports/pkg tree?s and it is also removed >> from VuXML, then yes, it will no longer get marked in your local >> installation. Tha

Re: pkg audit false negatives

2017-08-14 Thread Remko Lodder
> On 14 Aug 2017, at 05:32, Roger Marquis wrote: > >> I do not think that holds: >> >> >> 17521php -- multiple vulnerabilities >> 17522 >> 17523 >> 17524php55 >> 175255.5.38 >> 17526 >> >> This is an entry fro

Re: BlueBorne

2017-09-18 Thread Remko Lodder
27;s bt stack? I > flipped through https://lists.freebsd.org/pipermail/freebsd-bluetooth/ > 's last year pretty quickly, there's not a lot there. After reading the > paper I wouldn't dare try diving into this stack, I'd never get back .. > > cheers, Ian We b

Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-18:02.ntp

2018-03-07 Thread Remko Lodder
> On 7 Mar 2018, at 12:50, David Chisnall wrote: > > Were these changes and the kernel changes tested together on Xen? After > updating to -p7, I get about 10 seconds of uptime on a Xen VM before the > kernel panics with a double fault and reboots. Disabling ntpd results in a > stable syst

Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-18:02.ntp

2018-03-07 Thread Remko Lodder
> On 7 Mar 2018, at 12:50, David Chisnall wrote: > > Were these changes and the kernel changes tested together on Xen? After > updating to -p7, I get about 10 seconds of uptime on a Xen VM before the > kernel panics with a double fault and reboots. Disabling ntpd results in a > stable syst

Re: SQLite vulnerability

2018-12-16 Thread Remko Lodder
Hi, It’s sad to see that you are still as negative as you where not that long ago. I said before that If you rely on the information being up to date, you should sponsor the FF or pay someone to do the work for you. You keep forgetting that we (security-officer@ and ports-secteam@) are volunteers

Re: PEAR packages potentially contain malicious code

2019-01-21 Thread Remko Lodder
Hi Stefan, > On 21 Jan 2019, at 21:18, Stefan Bethke wrote: > > I’ve just learned that the repository for the PHP PEAR set of extensions had > their distribution server compromised. > > https://twitter.com/pear/status/1086634503731404800 > > I don’t really work with PHP much apart from instal