Re: spam from chrooted CMSes

2009-04-12 Thread Vadim Zhukov
On 10 April 2009 c. 05:42:21 Uwe Dippel wrote: I'm running postfix as MTA on a machine with several CMS, on a chrooted Apache. Recently, there is a huge number of spam being sent from there, alas. When I scan the postfix-logs, all those come from 'root', meaning they don't come through port

Re: spam from chrooted CMSes

2009-04-12 Thread Uwe Dippel
Matthew Weigel unique at idempot.net writes: Huh? I'm talking about the CMS itself authenticating to the SMTP server, and giving each application a single set of credentials. chroot is the name, and isolation is the game. This should be set in the CMS's config files, much like database

Re: spam from chrooted CMSes

2009-04-12 Thread Uwe Dippel
Vadim Zhukov wrote: Do your clients have ability to connect to external hosts? If yes then you should not even bother logging PHP mail() calls or such. If outgoing connections are closed then you should have different system users (i.e., different UIDs) for each client; otherwise it'll be

Re: ssh tunnel tun device forwarding without root

2009-04-12 Thread Alexander Hall
Lars Noodin wrote: Lars NoodC)n wrote: What way is there to use sudo on both the local and the remote machine instead? ... Ok. (so that this goes in the archives) One work-around is to change the group for the relevant tun device on the remote machine. Then give the group rw privileges

Re: ssh tunnel tun device forwarding without root

2009-04-12 Thread Lars Noodén
Alexander Hall wrote: Lars NoodC)n wrote: $ ls -l /dev/tun? crw--- 1 root wheel40, 0 Apr 11 14:50 /dev/tun0 crw-rw 1 root dialer 40, 1 Apr 11 20:23 /dev/tun1 I've been wondering about this too. Although I have not tested this yet... It works to

Re: How to find my USB?

2009-04-12 Thread Juan Jimenez Galdos
The USB DISK PRO is working but i have another USB (is sd5 FAT32), an i have this problem: when i write mount -t msdos /dev/sd5i /mnt/usb2 or mount /dev/sd5i /mnt/usb2 it says mount_ffs: /dev/sd5h on /mnt/usb2: No such file or directory (i haven't mounted anything). Is sd5 too. Somebody could

Re: How to find my USB?

2009-04-12 Thread Juan Jimenez Galdos
disklabel sd5 disklabel: /dev/rsd5: No such file or directory ls -aF /mnt ./../ cd0/ usb2/ # sysctl hw.disknames hw.disknames=wd0,cd0,sd0,sd1,sd2,sd3,sd4,sd5,sd6 dmesg: sd5 at scsibus2 targ 1 lun 0: , TDK Trans-it, PMAP SCSI0 0/direct removable sd5: 4006MB, 15 cyl, 255 head, 63 sec, 512

Re: ssh tunnel tun device forwarding without root

2009-04-12 Thread J.C. Roberts
On Sun, 12 Apr 2009 15:29:57 +0300 Lars Noodin larsnoo...@openoffice.org wrote: Alexander Hall wrote: Lars NoodC)n wrote: $ ls -l /dev/tun? crw--- 1 root wheel40, 0 Apr 11 14:50 /dev/tun0 crw-rw 1 root dialer 40, 1 Apr 11 20:23 /dev/tun1 I've been

Re: European orders - Thank you Theo and your team, some of us appreciate you!

2009-04-12 Thread Steve Fairhead
Slightly late in responding to this, but hey: Michael Grigoni wrote: William Chivers wrote: Thank you Theo and your team of developers for OpenBSD. Some people responding to the European Orders thread seem to have lost sight of what OpenBSD is and who develops it. I am a bit of a newbie

Re: How to find my USB?

2009-04-12 Thread Stijn
Juan Jimenez Galdos wrote: The USB DISK PRO is working but i have another USB (is sd5 FAT32), an i have this problem: when i write mount -t msdos /dev/sd5i /mnt/usb2 or mount /dev/sd5i /mnt/usb2 it says mount_ffs: /dev/sd5h on /mnt/usb2: No such file or directory (i haven't mounted anything). Is

I can't use gnome with a normal user

2009-04-12 Thread Juan Jimenez Galdos
I have created a normal user and when i log on with gdm (gnome), instead of starting gnome, i only have a terminal and all the screen gray. I can't maximize or minimize, and i can't open another tab in the terminal. Somebody could help me? What can i do? Thank you very much.

Re: I can't use gnome with a normal user

2009-04-12 Thread Juan Jimenez Galdos
Ok, i have found the problem, i had to start gnome-session.

matching ipv6 esp traffic

2009-04-12 Thread Florian Obser
Hi, I'm trying to secure my wlan access point with ipsec. Apparently I cannot match ipv6 esp traffic. This is on 4.4 I build a simplified setup with qemu, ipsec-gw and ipsec-client: - ipsec-gw [r...@ipsec-gw:~]# cat /etc/ipsec.conf ike passive esp from 10.12.32.235 to 10.12.32.236

I can't download torrents with ktorrent with a normal user

2009-04-12 Thread Juan Jimenez Galdos
The thing is: When I am using root i haven't any problems, but if i use a normal user the torrents don't start, and the torrents can't connect with the tracker or the peers. if the configuration of pf is the same in root and with a normal user, why this is happening? I don't understand. Somebody

Re: I can't download torrents with ktorrent with a normal user

2009-04-12 Thread Vadim Zhukov
On 12 April 2009 c. 19:54:18 Juan Jimenez Galdos wrote: The thing is: When I am using root i haven't any problems, but if i use a normal user the torrents don't start, and the torrents can't connect with the tracker or the peers. if the configuration of pf is the same in root and with a normal

Re: How to find my USB?

2009-04-12 Thread Brynet
Hi Juan, OpenBSD does not have a dynamic /dev filesystem, thus only 5 sd(4) device nodes are created by default. To create additonal device nodes yourself, it's very simple: # cd /dev # ./MAKEDEV sd{5,6} Hope that helps.. -Brynet

Re: How to find my USB?

2009-04-12 Thread Juan Jimenez Galdos
Thank you very much! It works.

Serial connection settings on Sun Ultra 1

2009-04-12 Thread Aapo Lehtinen
Hello I'm trying to get Sun Fire V100 working using old ultra 1 machine (obsd4.4/sparc64) as terminal. I'm using tip(1). The problem is connection dies easily with Lost Carrier. [EOT]. Now, I'm bit new to using serial connections so I've only tried tweaking /etc/ttys by changing type from sun

Re: I can't download torrents with ktorrent with a normal user

2009-04-12 Thread Juan Jimenez Galdos
Don't worry, it was the configuration of pf, not the account :). Now it works, thank you very much.

I need to mount in a normal account

2009-04-12 Thread Juan Jimenez Galdos
Hi. I need two things: I need to use the command mkdir, the command mount and umount, but ONLY THOSE. Somebody could say me what could i write in sudoers? I have searched and i have tried several things but it's a little difficult configure two comands. Thank you very much.

Graphics card, buying advice.

2009-04-12 Thread Torbjørn Hårstad Orskaug
Hello! I'm currently in the process of building a system (i386/amd64) for a research project where we'll primarily use OpenBSD for development. I'd like to run Xorg on this machine, preferably with accelerated 2D and 3D graphics. I've been reading around a bit and noticed that OpenBSD just

more information about PF BUG

2009-04-12 Thread Fernando Quintero
Hi list, it's about: http://www.openbsd.org/errata45.html#002_pf I'm trying to reproduce this bug, but i would like to get more information about how the kernel panic is produced. so, anyone has more information? http://www.securitytracker.com/alerts/2009/Apr/1022032.html I review the patchs,

Re: more information about PF BUG

2009-04-12 Thread Maxim Bourmistrov
It is a one line-addition to ping.c. Then you use newly compiled ping like this: ping -D public IP This scenario works for NAT and attacker sitting on the local network. Tested on OpenBSD 4.3 acting as a NAT-box. //maxim On 12 apr 2009, at 22.05, Fernando Quintero wrote: Hi list, it's

correction to gre(4) man page

2009-04-12 Thread Pete Vickers
SEE ALSO section, entry for Web Cache Coordination Protocol V1.0, link is broken. A suitable replacement is: http://www.ietf.org/proceedings/99jul/I-D/draft-ietf-wrec-web-pro-00.txt /Pete

Request for DVI monitors in the UK

2009-04-12 Thread Theo de Raadt
Around two weeks ago Owain (oga@) mailed out a request for some monitors in the UK, so that he could hack better on X. A pair of monitors capable of 1600x1200 resolution with vga and dvi inputs needed for debugging multi-head X11 setups in London, England. Monitors would preferably

Re: I need to mount in a normal account

2009-04-12 Thread Fred Crowson
On 4/12/09, Juan Jimenez Galdos juangmgald...@gmail.com wrote: Hi. I need two things: I need to use the command mkdir, the command mount and umount, but ONLY THOSE. Somebody could say me what could i write in sudoers? I have searched and i have tried several things but it's a little difficult

Re: correction to gre(4) man page

2009-04-12 Thread Jason McIntyre
On Sun, Apr 12, 2009 at 10:40:08PM +0200, Pete Vickers wrote: SEE ALSO section, entry for Web Cache Coordination Protocol V1.0, link is broken. A suitable replacement is: http://www.ietf.org/proceedings/99jul/I-D/draft-ietf-wrec-web-pro-00.txt /Pete that link works fine here. jmc

Re: Serial connection settings on Sun Ultra 1

2009-04-12 Thread Fred Crowson
On 4/12/09, Aapo Lehtinen a...@pokat.org wrote: Hello I'm trying to get Sun Fire V100 working using old ultra 1 machine (obsd4.4/sparc64) as terminal. I'm using tip(1). The problem is connection dies easily with Lost Carrier. [EOT]. Now, I'm bit new to using serial connections so I've only

Re: spam from chrooted CMSes

2009-04-12 Thread Stuart Henderson
On 2009-04-12, Uwe Dippel udip...@uniten.edu.my wrote: chroot is the name, and isolation is the game. it's not all that unusual for PHP hosts to disable mail(); most of the main CMS have some way to send mail without it, and these usually do allow smtp-auth. so you could install pear-Mail and

Re: I need to mount in a normal account

2009-04-12 Thread Juan Jimenez Galdos
I repeat: I have searched and i have tried several things but it's a little difficult configure two comands. Please lend me some help. Thank you very much.

Re: I need to mount in a normal account

2009-04-12 Thread Abel Camarillo
Nobody will help you if you don't describe thoroughly what was the problem. I have seen a lot of messages from you recently, are you doing your homework? (lurking through the docs) On Mon, Apr 13, 2009 at 01:07:49AM +0200, Juan Jimenez Galdos wrote: I repeat: I have searched and i have tried

Re: I need to mount in a normal account

2009-04-12 Thread Stuart Henderson
On 2009-04-12, Abel Camarillo acam...@the00z.org wrote: Nobody will help you if you don't describe thoroughly what was the problem. I have seen a lot of messages from you recently, are you doing your homework? (lurking through the docs) probably not, looking at the examples in the default

Re: Serial connection settings on Sun Ultra 1

2009-04-12 Thread Nick Holland
Aapo Lehtinen wrote: Hello I'm trying to get Sun Fire V100 working using old ultra 1 machine (obsd4.4/sparc64) as terminal. I'm using tip(1). The problem is connection dies easily with Lost Carrier. [EOT]. Now, I'm bit new to using serial connections so I've only tried tweaking /etc/ttys