Mozilla + GStreamer1 = Problem

2015-07-23 Thread Stefan Wollny
Hi there! (Again) I'd like to bring an issue to the attention of those who are skilled enough to handle this... To begin with: The following relates to current-i386 (current-amd64 was effected too but I didn't test lately). With /usr/local/libexec/gstreamer-1.0/gst-plugin-scanner enabled

Re: Alleged OpenSSH bug

2015-07-23 Thread Garance A Drosehn
On 23 Jul 2015, at 17:38, Marc Espie wrote: Not surprisingly, as the patch clearly shows, the problem is right smack in the middle of USE_PAM code. I wouldn't call that an OpenSSH bug. I would call it a systemic design flaw in PAM. As usual. LOTS of security holes in authentication systems

Re: Alleged OpenSSH bug

2015-07-23 Thread bofh
On Thu, Jul 23, 2015 at 5:10 PM, Ted Unangst t...@tedunangst.com wrote: Come on. Calling it an oversight is not condescending. I think it's perfectly reasonable to say it was an oversight. He did't say it was the hole of the century. There's no need to be so defensive. Given that the last

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Tuyosi Takesima
Gilles's advices is essential ! i read http://yama-ga.seesaa.net/article/394367473.html too. so i rewrite smtpd.conf listen on lo0 listen on em0 port 25 listen on em0 port 465 listen on em0 port 587 table aliases db:/etc/mail/aliases.db accept from any

Re: Alleged OpenSSH bug

2015-07-23 Thread Giancarlo Razzolini
Em 23-07-2015 16:43, Garance A Drosehn escreveu: As noted in my message, I did actually test it on a variety of systems. You mentioned FreeBSD boxes and a Mac. That ain't a variety of systems. I happened to avoid it on my systems, but that was more by luck than any cleverness on my part.

Re: Alleged OpenSSH bug

2015-07-23 Thread bofh
On Thu, Jul 23, 2015 at 5:10 PM, Ted Unangst t...@tedunangst.com wrote: Giancarlo Razzolini wrote: The original post wondered if this was some mis-timed April Fool's joke. My reply was just to say that it's a real issue, although many people won't see this issue due to the way sshd is

Re: Alleged OpenSSH bug

2015-07-23 Thread Marc Espie
On Thu, Jul 23, 2015 at 12:29:37PM -0400, Garance A Drosehn wrote: On 23 Jul 2015, at 10:06, Emilio Perea wrote: To me it looks like a mistimed April Fools' joke, but hope somebody more knowledgeable will respond:

rdomain with BGP dynamic route

2015-07-23 Thread XU, YANG (YANG)
Hi all, I am configuring OpenBSD bgpd so that it can relay the routes learned from customer BGP servers to a route reflector (RR). Customer BGP servers only speak IPv4 BGP, so my OpenBSD bgpd needs to add different route-distinguisher and route-target to the dynamic routes learned from each

Re: Audio Boost for Sndio

2015-07-23 Thread Geoff Steckel
Some sound cards have two volume controls: one is for the specific source and the other is for the whole card. Both must be at 100% for maximum output. On 07/23/2015 06:55 AM, ropers wrote: I'm talking out my arse here, but: To me, your submission vaguely reminds me of the CD Loudness War

Re: OpenBSD projects

2015-07-23 Thread jungle Boogie
On 28 December 2014 at 15:14, Ingo Schwarze schwa...@usta.de wrote: Hi, as this request met quite a bit of interest, i have drafted a list at this *temporary* URI: http://mdocml.bsd.lv/openbsd_projects.html If developers want it, moving it to the OpenBSD web site would be fine with me.

Re: Alleged OpenSSH bug

2015-07-23 Thread Garance A Drosehn
On 23 Jul 2015, at 13:33, Theo de Raadt wrote: My freebsd boxes do *not* have the problem, but that's because I have set 'ChallengeResponseAuthentication no'. I don't even remember why I set that on my freebsd boxes. I change very few settings, but for some reason I decided to change that

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Gilles Chehade
On Fri, Jul 24, 2015 at 02:09:53AM +0900, Tuyosi Takesima wrote: thanks for Denis |Tell me if I'm wrong but you don't listen on port 25 or 465. your advise is great ! /etc/mail/smtpd.conf is rewriten . listen on lo0 listen on em0 port 25-to recieve mail from gmx

Re: Alleged OpenSSH bug

2015-07-23 Thread Ted Unangst
Giancarlo Razzolini wrote: The original post wondered if this was some mis-timed April Fool's joke. My reply was just to say that it's a real issue, although many people won't see this issue due to the way sshd is configured on their systems. You were condescending, admit it. Quoting

Re: Alleged OpenSSH bug

2015-07-23 Thread Peter N. M. Hansteen
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 On 07/23/15 16:06, Emilio Perea wrote: To me it looks like a mistimed April Fools' joke, but hope somebody more knowledgeable will respond:

Alleged OpenSSH bug

2015-07-23 Thread Emilio Perea
To me it looks like a mistimed April Fools' joke, but hope somebody more knowledgeable will respond: https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-interactive-authentication-brute-force-vulnerability-maxauthtries-bypass/

Re: Bluetooth Support

2015-07-23 Thread Peter Hessler
All bluetooth support was removed some releases ago. The code rotted. If someone wants to work on this again, they are welcome to. On 2015 Jul 23 (Thu) at 10:02:55 -0400 (-0400), Richard E. Thornton wrote: :I am just curious - is Bluetooth supported on any bluetooth enabled :computers? Or is

Bluetooth Support

2015-07-23 Thread Richard E. Thornton
I am just curious - is Bluetooth supported on any bluetooth enabled computers? Or is this a dead topic? Richard

Re: smplayer and mpv freeze my computer

2015-07-23 Thread L.R. D.S.
I had similar situations this week in #1024, in two different ways: - The ffmpeg can't input mpeg (this include ffplay), but lib-vpx is normal. The Xenocara does not freeze, it just can't play; Reproduced in i386 #1024, almost all mp4 files this happen, but may be just a upgrade bug. - The

Re: USB CD/DVD burner

2015-07-23 Thread Matthew Martin
LG/Hitachi GP08NU6B has done the job for a few years although usb2 and discontinued now. On 7/23/15, L.R. D.S. arrowscr...@mail.com wrote: I don't know about this Samsung, but I have one TSSTcorp TS-H653G and this one work fine with cdio.

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Denis Fondras
so , accordingly i rewrite /etc/mail/smtpd.conf listen on lo0 listen on em0 port 587 Tell me if I'm wrong but you don't listen on port 25 or 465.

Building Tor with libevent 2.x (from ports)

2015-07-23 Thread nusenu
Hi Pascal, as we have learned from Nicholas, OpenBSD will stay with libevent 1.4.x for the time being. Do you have any plans to make the Tor port use libevent 2.x from ports? Background: Tor on OpenBSD using libevent 1.4.15 is significantly slower (less throughput) compared to other OSes with

Re: OpenBSD release with libevent 2.x?

2015-07-23 Thread nusenu
-BEGIN PGP SIGNED MESSAGE- Hash: SHA512 No we have pretty much settled on a (mildly forked) 1.4 now and there are no plans to update the base system. Thanks for your answer. -BEGIN PGP SIGNATURE- iQIcBAEBCgAGBQJVsQq6AAoJEFv7XvVCELh0fNkP/17w6ZopeuWUvqLqPzNzoakd

Re: Alleged OpenSSH bug

2015-07-23 Thread Giancarlo Razzolini
Em 23-07-2015 11:16, Peter N. M. Hansteen escreveu: In my *very* limited testing, using variations of the first ssh command in that blog post, none of my OpenBSD boxes with fairly pristine out of the box /etc/ssh/sshd_config permitted more than three tries before closing the connection. I also

Re: Alleged OpenSSH bug

2015-07-23 Thread Theo de Raadt
It seems to affect only FreeBSD. But it's bad, and affect a lot of versions, dating back to 2007. And also, as I guessed, interaction with PAM is the culprit. That's why Dr. House doesn't allow exotic things to be ported to OpenBSD. You Can't Always Get What You Want. Seriously, dlopen

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Tuyosi Takesima
thanks for Denis |Tell me if I'm wrong but you don't listen on port 25 or 465. your advise is great ! /etc/mail/smtpd.conf is rewriten . listen on lo0 listen on em0 port 25-to recieve mail from gmx listen on em0 port 465 -to recieve mail from gmail

Re: Alleged OpenSSH bug

2015-07-23 Thread Garance A Drosehn
On 23 Jul 2015, at 10:06, Emilio Perea wrote: To me it looks like a mistimed April Fools' joke, but hope somebody more knowledgeable will respond: https://kingcope.wordpress.com/2015/07/16/openssh-keyboard-interactive-authentication-brute-force-vulnerability-maxauthtries-bypass/ It is a

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Tuyosi Takesima
i have done my homework buti cannot send mails to x...@gmail.com x...@gmx.com . Do you have any error code or message ? thunderbird says --- An error occurred while sending mail. The mail server responded: Invalid recipient. --- Please check the message

MPLS configuration problem

2015-07-23 Thread reza kakhki
Hi misc I want to implement simple MPLS network according to this page http://lteo.net/blog/2013/09/03/a-small-mpls-test-network-built-with-openbsd/ but when configuring PE1 , after run this command ifconfig mpe0 mplslabel 666 i got this log ifconfig: SIOCSETLABEL: Network is unreachable , why

Re: MPLS configuration problem

2015-07-23 Thread XU, YANG (YANG)
Reza, I am doing something similar, and I followed https://2011.eurobsdcon.org/papers/jeker/MPLS.pdf. I don't see a problem when running ifconfig mpe2 rdomain 2;ifconfig mpe2 mplslabel 999;ifconfig mpe2 192.168.238.2/32. I run on OpenBSD 5.5. -Yang

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Denis Fondras
buti cannot send mails to x...@gmail.com x...@gmx.com . Do you have any error code or message ?

Re: Alleged OpenSSH bug

2015-07-23 Thread Giancarlo Razzolini
Em 23-07-2015 13:29, Garance A Drosehn escreveu: It is a real issue. Your servers might not see the issue depending on what options have been set for sshd_config. My freebsd boxes do *not* have the problem, but that's because I have set 'ChallengeResponseAuthentication no'. I don't even

Re: Alleged OpenSSH bug

2015-07-23 Thread Theo de Raadt
It is a real issue. Your servers might not see the issue depending on what options have been set for sshd_config. Some operating systems have extremely fast passwd checks, others have slow ones. FreeBSD seems to be the worst affected because their PAM integration does not terminate the loop

Re: Alleged OpenSSH bug

2015-07-23 Thread Theo de Raadt
But it depends on the right (wrong) combination of factors which, unfortunately, FreeBSD has. Exactly.

Re: Alleged OpenSSH bug

2015-07-23 Thread Mike
On 7/23/2015 12:29 PM, Garance A Drosehn wrote: On 23 Jul 2015, at 10:06, Emilio Perea wrote: [snip] It is a real issue. Your servers might not see the issue depending on what options have been set for sshd_config. My freebsd boxes do *not* have the problem, but that's because I have

Re: Alleged OpenSSH bug

2015-07-23 Thread jungle Boogie
On 23 July 2015 at 09:15, Giancarlo Razzolini grazzol...@gmail.com wrote: Em 23-07-2015 11:16, Peter N. M. Hansteen escreveu: However, running that command pinting at a FreeBSD 10.1 box in my care gave more than three tries. I aborted well before reaching 1 for obvious reasons. Digging

Re: Building Tor with libevent 2.x (from ports)

2015-07-23 Thread Michael McConville
On Thu, Jul 23, 2015 at 05:40:54PM +0200, nusenu wrote: as we have learned from Nicholas, OpenBSD will stay with libevent 1.4.x for the time being. Do you have any plans to make the Tor port use libevent 2.x from ports? Background: Tor on OpenBSD using libevent 1.4.15 is significantly

Re: Alleged OpenSSH bug

2015-07-23 Thread Giancarlo Razzolini
Em 23-07-2015 11:16, Peter N. M. Hansteen escreveu: However, running that command pinting at a FreeBSD 10.1 box in my care gave more than three tries. I aborted well before reaching 1 for obvious reasons. Digging some more, I've found this: http://seclists.org/oss-sec/2015/q3/156 It seems

Re: LibreSSL and easy-rsa

2015-07-23 Thread Stuart Henderson
On 2015-07-22, Predrag Punosevac punoseva...@gmail.com wrote: Hi Misc, I apologize if this was asked earlier. I am using easy-rsa to generate certificates for my new OpenVPN gateway. Could somebody confirm if easy-rsa is now using LibreSSL? Quick inspection of It uses the openssl command

Re: Alleged OpenSSH bug

2015-07-23 Thread Mihai Popescu
It seems to affect only FreeBSD. But it's bad, and affect a lot of versions, dating back to 2007. And also, as I guessed, interaction with PAM is the culprit. That's why Dr. House doesn't allow exotic things to be ported to OpenBSD. You Can't Always Get What You Want.

Re: elementary opensmtpd setting on rental server

2015-07-23 Thread Craig Skinner
On 2015-07-23 Thu 11:27 AM |, Tuyosi Takesima wrote: Gmail server reject mail from PC2 because Gmail server thinks that it is relayed by aoi. Post logs. and aoi server reject mail from PC1 because aoi server thinks that it is relayed by Gmail. Post logs. ssh -l user aoi.jp and

Re: Audio Boost for Sndio

2015-07-23 Thread ropers
I'm talking out my arse here, but: To me, your submission vaguely reminds me of the CD Loudness War https://en.wikipedia.org/wiki/Loudness_war. It sounds to me as if your hardware may be inherently a bit too quiet, but to an extent it's possible to compensate for that by pre-processing the signal