Idea about "skeleton jail"

2005-01-31 Thread Xin LI
Dear folks, The recent discussion about whether we should have the perl port to touch/install /usr/bin/perl. While I'm not interested in joining the discussion, it inspired me that we can make use of the fact that ports should not install things to "system" area and take advantage from it. Finall

GVRP announces under FreeBSD

2005-01-31 Thread Dmitry Morozovsky
Dear colleagues, is there any existing solution for announcing dot1Q vlans from FreeBSD router via GVRP? Quick googling does not reveal anything informative. Thanks in advance. Sincerely, D.Marck [DM5020, MCK-RIPE, DM3-RIPN] -

Simple question about CPUs and processes

2005-01-31 Thread security
Hi list, I'd like some insight on the following; Me and a friend were discussing tech stuff and he said that, when using dual (or more) CPU systems, it is the hardware itself (and alone) choosing which CPU will execute this or that process. But I think it is the OS kernel (FreeBSD in this case) a

Re: Simple question about CPUs and processes

2005-01-31 Thread Robert Watson
On Mon, 31 Jan 2005 [EMAIL PROTECTED] wrote: > I'd like some insight on the following; Me and a friend were discussing > tech stuff and he said that, when using dual (or more) CPU systems, it > is the hardware itself (and alone) choosing which CPU will execute this > or that process. > > But I

Re: Simple question about CPUs and processes

2005-01-31 Thread Ryan Sommers
[EMAIL PROTECTED] wrote: Hi list, I'd like some insight on the following; Me and a friend were discussing tech stuff and he said that, when using dual (or more) CPU systems, it is the hardware itself (and alone) choosing which CPU will execute this or that process. The OS and the OS alone chooses w

Re: Simple question about CPUs and processes

2005-01-31 Thread security
Hey, Thanks for the replies Robert and Ryan! That was insigthful. I didn't know about the BP and the shutdown thingy, always learning :-) >> On Mon, 31 Jan 2005 [EMAIL PROTECTED] wrote: >> >>> I'd like some insight on the following; Me and a friend were discussing >>> tech stuff and he said tha

Re: Idea about "skeleton jail"

2005-01-31 Thread Jeremie Le Hen
On Mon, Jan 31, 2005 at 09:39:52PM +0800, Xin LI wrote: > Dear folks, > > The recent discussion about whether we should have the perl port to > touch/install /usr/bin/perl. While I'm not interested in joining the > discussion, it inspired me that we can make use of the fact that ports > should no

Intel motherboard S875WP1-E with SATA un Promise raid problem...

2005-01-31 Thread Casper
Hi, I read that there is already discusion about it: http://lists.freebsd.org/pipermail/freebsd-hackers/2005-January/009814.html But it not helped me. I have googled etc working little bit every day, and turn then the bigest discusion about it is here, so I decidadet to post q. here. I have alrea

Re: Simple question about CPUs and processes

2005-01-31 Thread Kamal R. Prasad
--- Ryan Sommers <[EMAIL PROTECTED]> wrote: > [EMAIL PROTECTED] wrote: > [snip] > CPU cares about is > endlessly executing instructions fed to it and > delivering > interrupts/exceptions. What your friend might be Im not sure to how many types of hw FreeBSD has been ported, but the POWER4 pro

TCP stack errors

2005-01-31 Thread Jose Hidalgo Herrera
I have a 4.10p5 (cvsuped with RELENG_4_10 last friday) that shows things like this with a netstat -sf inet: tcp: 3630 discarded for bad checksums 85 discarded for bad header offset fields 1220093 bad connection attempts 137097 embryonic conn

Re: Idea about "skeleton jail"

2005-01-31 Thread Xin LI
å 2005-01-31äç 17:10 +0100ïJeremie Le Henåéï > On Mon, Jan 31, 2005 at 09:39:52PM +0800, Xin LI wrote [snip] > Why don't you simply call the target "installjail" instead of > "installskel" ? I'd admit that I have chosen the name just by chance. I prefer installskel over installjail since I think

Re: Idea about 'skeleton jail

2005-01-31 Thread security
Very nice idea!! This greatly improves jail management on FreeBSD. There is a possibility for a minor drawback -- if one can change a system binary in the host system, them all jails are compromised -- but assuming one would need root access on the host to change the binary, he would have power to

Re: Idea about 'skeleton jail

2005-01-31 Thread Pawel Malachowski
On Mon, Jan 31, 2005 at 01:29:24PM -0600, [EMAIL PROTECTED] wrote: > Very nice idea!! This greatly improves jail management on FreeBSD. There > is a possibility for a minor drawback -- if one can change a system binary > in the host system, them all jails are compromised -- but assuming one > woul

syscall list

2005-01-31 Thread H. S.
Hi, I don't remember how to extract the syscall list from the kernel. There was an article some time ago about this, and checking the syscall address to make sure it was not changed in the kernel. Could anyone point me to this article? I've tried to google around but didn't find it. Best Regards

RE: syscall list

2005-01-31 Thread Steven Alexander
Syscalls are talked about in section 2.7 Forensic Analysis of a Live Linux System, Part Two http://www.securityfocus.com/infocus/1773 This article is more in depth on this point; it's by the same author. Detecting Kernel-level Compromises With gdb http://www.securityfocus.com/infocus/

RE: syscall list

2005-01-31 Thread gerarra
>Hi, > >I don't remember how to extract the syscall list from the kernel. There >was an article some time ago about this, and checking the syscall address >to make sure it was not changed in the kernel. Could anyone point me to >this article? I've tried to google around but didn't find it. > >Best

Re: bug in calcru()

2005-01-31 Thread Don Lewis
On 26 Jan, Chris Landauer wrote: > > hihi, doug - > >> Doug Ambrisko <[EMAIL PROTECTED]> wrote >> ... >> The assumption with this calculation is that st & it tend to be >> small compared to tt so the 1024 X shouldn't overflow much. >> ... >> [EMAIL PROTECTED] wrote: >> |..

Re: Idea about "skeleton jail"

2005-01-31 Thread Justin Hopper
On Mon, 2005-01-31 at 21:39 +0800, Xin LI wrote: > Dear folks, > > The recent discussion about whether we should have the perl port to > touch/install /usr/bin/perl. While I'm not interested in joining the > discussion, it inspired me that we can make use of the fact that ports > should not insta