Include original rdomain in DIOCNATLOOK

2011-03-25 Thread Claudio Jeker
It is possible to NAT connections from one rdomain to another with pf. The problem is that this NAT is not visible in DIOCNATLOOK lookups. This causes ftp-proxy to fail handling connections that cross domains. Adding the incomming rdomain is not a big deal and will allow ftp-proxy and other

Make ftp-proxy rdomain aware

2011-03-25 Thread Claudio Jeker
This allows to do so magically twisted things like running ftp-proxy in rdomain 7 and proxy connections from rdomain 3 over it. pf setup is: anchor ftp-proxy/* pass in quick proto tcp to port ftp rtable 7 rdr-to 127.0.0.1 port 8021 and ftp-proxy is startet with route -T 7 exec ftp-proxy The

Re: sparc64, hardware timer, security/botan

2011-03-25 Thread Mark Kettenis
Date: Tue, 15 Mar 2011 14:22:16 +0100 From: Aleksander Piotrowski a...@openbsd.org hi mark i have signal 4, Illegal instruction crash on sparc64 with security/botan (required by newer devel/monotone). it looks like they are trying to get time from hardware timer using some funny asm's.

Re: sparc64, hardware timer, security/botan

2011-03-25 Thread Joachim Schipper
On Fri, Mar 25, 2011 at 01:36:13PM +0100, Mark Kettenis wrote: Date: Tue, 15 Mar 2011 14:22:16 +0100 From: Aleksander Piotrowski a...@openbsd.org i have signal 4, Illegal instruction crash on sparc64 with security/botan (required by newer devel/monotone). it looks like they are trying to

Re: sparc64, hardware timer, security/botan

2011-03-25 Thread Ted Unangst
On Fri, Mar 25, 2011 at 8:36 AM, Mark Kettenis mark.kette...@xs4all.nl wrote: On OpenBSD we disable access to %tick from userland. I think the idea is to make it harder for people to perform timing attacks, and therefore improve security. But I don't consider myself enough of a security

Re: sparc64, hardware timer, security/botan

2011-03-25 Thread Theo de Raadt
On Fri, Mar 25, 2011 at 8:36 AM, Mark Kettenis mark.kette...@xs4all.nl wrote: On OpenBSD we disable access to %tick from userland. I think the idea is to make it harder for people to perform timing attacks, and therefore improve security. But I don't consider myself enough of a

Re: MicroLinear 6692 PHY for tl(4) -- Olicom 2326

2011-03-25 Thread Loganaden Velvindron
Hi Claudio, The diff fails to apply cleanly: |Index: share/man/man4/Makefile |=== |RCS file: /cvs/src/share/man/man4/Makefile,v |retrieving revision 1.519 |diff -u -p -r1.519 Makefile |--- share/man/man4/Makefile15 Jan 2011

Re: sparc64, hardware timer, security/botan

2011-03-25 Thread Christian Weisgerber
Ted Unangst ted.unan...@gmail.com wrote: On OpenBSD we disable access to %tick from userland. I think the idea is to make it harder for people to perform timing attacks, I don't believe that for a minute. We allow rdtsc on i386. ... and rpcc on alpha. Not that there's a way to disable

Fix dhclient message intervals - i.e. make negotiation faster!

2011-03-25 Thread Kenneth R Westerback
Investigating PR#6543 I concluded we are mishandling the intervals between the DCHPDISCOVER packets and also between the DHCPREQUEST packets. Most obvious is the last chunk. - if (stop_selecting = 0) + if (stop_selecting = cur_time) stop_selecting is a time, not an interval. So this

Auto Submit To +34000 Websites

2011-03-25 Thread Marketing Tools
Blast Your Ad to +34000 Classified Websites! Plus Huge Array of Marketing Tools. Download Now : http://good-links.us/blast-your-ad-to-34000-classified-websites.html