Re: Why so cool OS doesn't have vuln database?

2009-05-18 Thread Joachim Schipper
On Mon, May 18, 2009 at 11:51:02AM +0500, Yuriy Grishin wrote: > Hi, Joachim > > I've got that you wanted to say. > There are some tools for that are available. > The main problem is that they detect an intrusion *after* the server is > compromised. > Intrusion detection systems are good but intr

Re: Why so cool OS doesn't have vuln database?

2009-05-18 Thread Yuriy Grishin
As I said it's unreal for a guy from a Russian village. You may hit me for that but it's done in FreeBSD therefore it's possible. Janne Johansson wrote: Yuriy Grishin wrote: Indeed you're right. I've got the same experience with php5-gd library. The audit program told that this library is

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Yuriy Grishin
Hi, Joachim I've got that you wanted to say. There are some tools for that are available. The main problem is that they detect an intrusion *after* the server is compromised. Intrusion detection systems are good but intrusion prevention systems are better. Joachim Schipper wrote: On Sun, May

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Janne Johansson
Yuriy Grishin wrote: Indeed you're right. I've got the same experience with php5-gd library. The audit program told that this library is vulnerable but there was no patch available. So this message was about useless. On the other hand in most cases this sort of applications could save admin's

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Yuriy Grishin
Indeed you're right. I've got the same experience with php5-gd library. The audit program told that this library is vulnerable but there was no patch available. So this message was about useless. On the other hand in most cases this sort of applications could save admin's time. TomC!E! BodE>C

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Yuriy Grishin
Thanks a lot! TomC!E! BodE>C!r wrote: Read the FAQ please http://www.openbsd.org/stable.html 1) Get and update source code trough CVS 2) Rebuild kernel and boot with it 3) Rebuild binaries 4) Done There was thread about it last month I think.You haven't packages updated in -stable.You must use

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Joachim Schipper
On Sun, May 17, 2009 at 03:04:18AM +0200, Ingo Schwarze wrote: > Hi Joachim, hi Yurij, > > Joachim Schipper wrote on Sat, May 16, 2009 at 01:23:20PM +0200: > > On Fri, May 15, 2009 at 10:39:06PM +0500, Yuriy Grishin wrote: > > >> I've installed OpenBSD 4.5 on my home gateway. > >> Random pids and

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Tomáš Bodžár
Read the FAQ please http://www.openbsd.org/stable.html 1) Get and update source code trough CVS 2) Rebuild kernel and boot with it 3) Rebuild binaries 4) Done There was thread about it last month I think.You haven't packages updated in -stable.You must use -current if you want updated packages.Of

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Yuriy Grishin
Martin Schrvder wrote: 2009/5/17, Yuriy Grishin : OpenBSD just uses different approach, got it. It's not a technological problem. Search the archives for discussions of security upgrades to ports. In short: The devs all run current and such don't need it; not enough users have steppe

Re: Why so cool OS doesn't have vuln database?

2009-05-17 Thread Martin Schröder
2009/5/17, Yuriy Grishin : > OpenBSD just uses different approach, got it. It's not a technological problem. Search the archives for discussions of security upgrades to ports. In short: The devs all run current and such don't need it; not enough users have stepped forward and started working on

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Tomáš Bodžár
I tried this db app on DragonFly,but guess what.You installed sudo,then you install this vulnerability-check and it say that you installed sudo which has local security bug.So what was help for me then?But if you are admin of some servers then you are reading about security problems in similar impo

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
Jacob Meuser wrote: On Sun, May 17, 2009 at 09:16:17AM +0500, Yuriy Grishin wrote: Jacob Meuser wrote: On Sat, May 16, 2009 at 11:14:34PM +0500, Yuriy Grishin wrote: On the other hand maintaining the database is extremely huge work. Did it face some pro

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Jacob Meuser
On Sun, May 17, 2009 at 09:16:17AM +0500, Yuriy Grishin wrote: > Jacob Meuser wrote: > >On Sat, May 16, 2009 at 11:14:34PM +0500, Yuriy Grishin wrote: > > > > > >>On the other hand maintaining the database is extremely huge work. > >> > > > > > >>Did it face some problems? > >> > > > >m

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
TomC!E! BodE>C!r wrote: I think that this sorta Not Found The requested URL /openbsd/ was not found on this server. ;-) Ooops! It has just been removed. -- Code cheap ($3 per an application)

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
Jacob Meuser wrote: On Sat, May 16, 2009 at 11:14:34PM +0500, Yuriy Grishin wrote: On the other hand maintaining the database is extremely huge work. Did it face some problems? maintaining the database is extremely huge work. It is for one guy. It is not for the commun

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Ingo Schwarze
Hi Joachim, hi Yurij, Joachim Schipper wrote on Sat, May 16, 2009 at 01:23:20PM +0200: > On Fri, May 15, 2009 at 10:39:06PM +0500, Yuriy Grishin wrote: >> I've installed OpenBSD 4.5 on my home gateway. >> Random pids and critical files permission are really cool. >> I just confused a little bit b

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Jacob Meuser
On Sat, May 16, 2009 at 11:14:34PM +0500, Yuriy Grishin wrote: > On the other hand maintaining the database is extremely huge work. > Did it face some problems? maintaining the database is extremely huge work. -- jake...@sdf.lonestar.org SDF Public Access UNIX System - http://sdf.lonestar.org

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Tomáš Bodžár
I think that this sorta Not Found The requested URL /openbsd/ was not found on this server. ;-) 2009/5/16 Yuriy Grishin : > Porting portaudit won't be too difficult I suppose. > On the other hand maintaining the database is extremely huge work. > It's impossible for me to do it alone in any cas

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
Porting portaudit won't be too difficult I suppose. On the other hand maintaining the database is extremely huge work. It's impossible for me to do it alone in any case but I'm ready to contribute in some way.. (will I be given a mailbox at openbsd.org? :) I've seen this http://www.vuxml.org/ope

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Martin Schröder
2009/5/16, Yuriy Grishin : > Iqigo Ortiz de Urbina wrote: > > > I wonder if he is after something similar to portaudit[1] on OpenBSD? > > > Exactly! We don't have that, but we are eagerly awaiting you port and your work on the database. Not to mention the updated ports. Best Martin

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
Yep. TomC!E! BodE>C!r wrote: I think that you are looking for tool which isn't available under OpenBSD.Here you must know what you are doing.Do you read FAQ part of pages? 2009/5/16 Yuriy Grishin : J Sisson wrote: Sorry, I meant your_last_post.[your configuration]. In other words, it

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
Iqigo Ortiz de Urbina wrote: I wonder if he is after something similar to portaudit[1] on OpenBSD? Exactly! -- Code cheap ($3 per an application)

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Iñigo Ortiz de Urbina
I wonder if he is after something similar to portaudit[1] on OpenBSD? [1]: http://www.freebsd.org/doc/en/books/handbook/security-portaudit.html 2009/5/16 Toma( Bod8ar > > I think that you are looking for tool which isn't available under > OpenBSD.Here you must know what you are doing.Do you re

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Tomáš Bodžár
I think that you are looking for tool which isn't available under OpenBSD.Here you must know what you are doing.Do you read FAQ part of pages? 2009/5/16 Yuriy Grishin : > J Sisson wrote: >> >> Sorry, I meant your_last_post.[your configuration]. >> >> In other words, it'd help people make recommend

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
My packages are : # pkg_info apr-1.2.11p2Apache Portable Runtime apr-util-1.2.10p2 companion library to APR autoconf-2.59p3 automatically configure source code on many Un*x platforms autoconf-2.61p3 automatically configure source code on many Un*x platforms autoconf-2.62 a

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
Joachim Schipper wrote: On Fri, May 15, 2009 at 10:39:06PM +0500, Yuriy Grishin wrote: Hello! I've installed OpenBSD 4.5 on my home gateway. Random pids and critical files permission are really cool. I just confused a little bit because I haven't found any way to check the vulnerabilities o

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Yuriy Grishin
J Sisson wrote: Sorry, I meant your_last_post.[your configuration]. In other words, it'd help people make recommendations if we knew the hardware you were running and what changes you'd made to the base system. Here you are the output of dmesg -

Re: Why so cool OS doesn't have vuln database?

2009-05-16 Thread Joachim Schipper
On Fri, May 15, 2009 at 10:39:06PM +0500, Yuriy Grishin wrote: > Hello! > > I've installed OpenBSD 4.5 on my home gateway. > Random pids and critical files permission are really cool. > I just confused a little bit because I haven't found any way to check the > vulnerabilities of my configuration.

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread Tomáš Bodžár
And vulnerabities in ports are mentioned on Undeadly in New Ports of The Week or you can watch cvs or find informations about apps in ports yourself. 2009/5/15 andrew fresh : > On Fri, May 15, 2009 at 10:39:06PM +0500, Yuriy Grishin wrote: >> I've installed OpenBSD 4.5 on my home gateway. >> Rando

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread Giancarlo Razzolini
Yuriy Grishin escreveu: Hello! I've installed OpenBSD 4.5 on my home gateway. Random pids and critical files permission are really cool. I just confused a little bit because I haven't found any way to check the vulnerabilities of my configuration. Are there any? http://www.openbsd.org/errat

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread andrew fresh
On Fri, May 15, 2009 at 10:39:06PM +0500, Yuriy Grishin wrote: > I've installed OpenBSD 4.5 on my home gateway. > Random pids and critical files permission are really cool. > I just confused a little bit because I haven't found any way to check the > vulnerabilities of my configuration. http://ww

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread J Sisson
Sorry, I meant your_last_post.[your configuration]. In other words, it'd help people make recommendations if we knew the hardware you were running and what changes you'd made to the base system. On Fri, May 15, 2009 at 12:55 PM, Yuriy Grishin < grishin-mailing-li...@minselhoz.samara.ru> wrote: >

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread Tomáš Bodžár
Yes,you can.Just use http://marc.info/ or similar search engine for mailing lists. 2009/5/15 Yuriy Grishin : > J Sisson wrote: >> >> select dmesg, custom_options from last_post.[my configuration]. > > sorry, I've just subscribed. > Can't see your previous post. > > -- http://www.openbsd.org/ly

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread Yuriy Grishin
J Sisson wrote: select dmesg, custom_options from last_post.[my configuration]. sorry, I've just subscribed. Can't see your previous post.

Re: Why so cool OS doesn't have vuln database?

2009-05-15 Thread J Sisson
select dmesg, custom_options from last_post.[my configuration]. 2009/5/15 Yuriy Grishin > Hello! > > I've installed OpenBSD 4.5 on my home gateway. > Random pids and critical files permission are really cool. > I just confused a little bit because I haven't found any way to check the > vulnerabi

Why so cool OS doesn't have vuln database?

2009-05-15 Thread Yuriy Grishin
Hello! I've installed OpenBSD 4.5 on my home gateway. Random pids and critical files permission are really cool. I just confused a little bit because I haven't found any way to check the vulnerabilities of my configuration. Are there any?