Re: Default password hash

2012-06-09 Thread Dimitry Andric
On 2012-06-09 09:43, O. Hartmann wrote: > On 06/08/12 14:51, Dag-Erling Smørgrav wrote: >> We still have MD5 as our default password hash, even though known-hash >> attacks against MD5 are relatively easy these days. We've supported >> SHA256 and SHA512 for many years now, so how about making SHA5

Re: ntpd 4.2.4p8 - up to date?

2013-11-01 Thread Dimitry Andric
On 01 Nov 2013, at 17:31, Tom Evans wrote: > On Fri, Nov 1, 2013 at 4:05 PM, Karl Pielorz wrote: >> >> Hi, >> >> A friend who uses linux a lot happened to notice on a FreeBSD box I >> installed the other day and updated to 9.2-R that it's using ntpd 4.2.4p8. >> >> They reckon that's had a lot

Re: NTP security hole CVE-2013-5211?

2014-03-14 Thread Dimitry Andric
On 14 Mar 2014, at 16:38, Brett Glass wrote: > Two months after this vulnerability was announced, we're still seeing > attempts to use the NTP "monitor" query to execute and amplify DDoS attacks. > Unfortunately, FreeBSD, in its default configuration, will amplify the > attacks if not patched a

Re: am I NOT hacked?

2014-04-26 Thread Dimitry Andric
On 26 Apr 2014, at 11:55, Joe Parsons wrote: > I was slow to patch my multiple vms after that heartbleed disclosure. I just > managed to upgrade these systems to 9.2, and installed the patched openssl, FreeBSD 9.x was never vulnerable to Heartbleed, as you can read in the security advisory (Fre

Re: [CFT] ASLR, PIE, and segvguard on 11-current and 10-stable

2014-05-25 Thread Dimitry Andric
On 25 May 2014, at 19:42, Oliver Pinter wrote: > On 5/25/14, Dag-Erling Smørgrav wrote: >> Oliver Pinter writes: ... >>> PAX: blacklist clang and related binaries from PIE support >> >> Why? Performance, or do they actually break? > > No. If you definded WITH_CLANG_EXTRAS= in src.conf, t

Re: ossec hit: Hidden process (rootkit)

2014-09-22 Thread Dimitry Andric
On 22 Sep 2014, at 11:10, List Monkey wrote: > I'm running freebsd as an vm. I recently got a hit from the ossec agent: > > OSSEC HIDS Notification. > 2014 Aug 28 03:01:34 > > Received From: (host) xxx.xxx.xxx.xxx->rootcheck > Rule: 510 fired (level 7) -> "Host-based anomaly detection event (roo

Re: FreeBSD Security Advisory FreeBSD-SA-15:10.openssl

2015-06-13 Thread Dimitry Andric
On 13 Jun 2015, at 05:13, Zoran Kolic wrote: > > Do I read this advisory correctly: it does not affect 9.3? It *does* affect 9.3: > Category: contrib > Module: openssl > Announced: 2015-06-12 > Affects:All supported versions of FreeBSD. > Corrected: 2015-06-11 19

Re: openssl bug causes sshd crashed on FreeBSD 9.3-RELEASE

2016-03-09 Thread Dimitry Andric
On 09 Mar 2016, at 23:59, Dag-Erling Smørgrav wrote: > > Akihiro HIRANO writes: >> Frank Möller writes: >>> After updating to FreeBSD 9.3-RELEASE-p37 sshd from the base system >>> crashes by signal 11 when I connect to the server with an old ssh >>> client (e.g. OpenSSH_4.5p1). Using a newer s

Re: /tmp/ecp.* created during kernel build?

2016-12-28 Thread Dimitry Andric
On 28 Dec 2016, at 04:10, Roger Marquis wrote: > >> Found a couple of ecp binaries in /tmp, apparently created concurrent >> with an 11.0 x86_64 kernel build. Anyone else seen this? Could they >> be related to a "make buildkernel"? > > Confirmed 'make buildkernel' does create these files, appa

Re: Plan for OpenSSL in stable/10?

2017-01-12 Thread Dimitry Andric
On 12 Jan 2017, at 19:02, Eric van Gyzen wrote: > > Has anyone had time to discuss and form a plan for OpenSSL in stable/10, > now that 1.0.1 is end-of-life? I don't recall seeing any public > discussion or announcement; forgive me if I missed it. Would updating to 1.0.2 change the API and/or A

Re: openssl-1.0.2l

2017-05-26 Thread Dimitry Andric
On 26 May 2017, at 22:30, l...@lena.kiev.ua wrote: > > Under FreeBSD 8 (with GCC 4.2.1): > > cc -I.. -I../.. -I../modes -I../asn1 -I../evp -I../../include -fPIC > -DOPENSSL_P > IC -DZLIB_SHARED -DZLIB -DOPENSSL_THREADS -pthread -D_THREAD_SAFE > -D_REENTRANT - > DDSO_DLFCN -DHAVE_DLFCN_H -Wa,--

Re: Samba CVE-2017-7494 on 3.6.25

2017-05-29 Thread Dimitry Andric
On 29 May 2017, at 18:53, Darko Gavrilovic wrote: > > Hello, does anyone know or able to confirm if Samba CVE-2017-7494 > affects Samba 3.6.25 on Freebsd 9.x? > > https://lists.samba.org/archive/samba-announce/2017/000406.html The advisory very clearly says "all versions of Samba from 3.5.0 onw

Re: Samba CVE-2017-7494 and SMB implementation of FreeBSD 10 through 12

2017-05-30 Thread Dimitry Andric
On 30 May 2017, at 18:55, O. Hartmann wrote: > > Am Mon, 29 May 2017 23:47:46 +0200 > Dimitry Andric schrieb: > >> On 29 May 2017, at 18:53, Darko Gavrilovic wrote: >>> >>> Hello, does anyone know or able to confirm if Samba CVE-2017-7494 >

Re: Possible break-in attempt?

2018-07-18 Thread Dimitry Andric
On 18 Jul 2018, at 22:25, Grzegorz Junka wrote: > > Thank you Patrick. I don't receive that many of them. Maybe a dozen or so > since I've set up my server, which was a few years ago. Mostly with the same > IP but sometimes different IP as well. And all those I've received so far > were in the

Re: Possible break-in attempt?

2018-07-21 Thread Dimitry Andric
On 21 Jul 2018, at 21:29, Grzegorz Junka wrote: > > On 21/07/2018 12:05, Chad Jacob Milios wrote: >>> On Jul 21, 2018, at 7:57 AM, Grzegorz Junka wrote: >>> On 21/07/2018 11:03, Chad Jacob Milios wrote: > On Jul 20, 2018, at 3:05 PM, Jamie Landeg-Jones wrote: ... openssh-portable (in p