Re: It's not possible to allow non-OPIE logins only from trusted networks

2011-03-09 Thread J. Hellenthal
ibly share what they have done in the past/present/future and offer up some real good insight on this. VPN access to the box(s) could be another solution where everyone is local and you don't need OPIE at all. \o/ -- Regards, J. Hellen

Re: It's not possible to allow non-OPIE logins only from trusted networks

2011-03-10 Thread J. Hellenthal
mix of modifications, scripting, programming and other such methods a experienced administrator would use. Good luck on your quest, -- Regards, J. Hellenthal ® (0x89D8547E) JJH48-ARIN ___ freebsd-security@freebsd.org mailing list http://lists.freebsd.

Re: bad email address

2011-04-20 Thread J. Hellenthal
he envelope sender > >Regards, > >Gary > Ive forwarded messages about these to postmaster@ before for these douchebags(tm). seems nothing has ever been done about that. @naver.com @bvgroup.ru @bvpress.ru Have been blacklisted here since you can never read their OON bs. procmail++ gm

Re: bad email address

2011-04-22 Thread J. Hellenthal
oesn't follow specifications there isn't >a lot MailMan can do > Yes and then repeated report after report mailman blah blah postmaster more blah blah user repeatedly offending blah blah moderator removes offending domain until the its fixed blah blah... Sometime in the near future... ;) -- Regards, J. Hellenthal WWJD pgpGvT0g6mxEk.pgp Description: PGP signature

Re: Add rc.conf variables to control host key length

2012-06-24 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 04:34:04PM +, Bjoern A. Zeeb wrote: > > On 24. Jun 2012, at 16:07 , Robert Simmons wrote: > > > Here is a set of patches that add functionality to rc.conf allowing > > users an easy way to control the length of the host keys used with ssh > > (specifically RSA and EC

Re: Add rc.conf variables to control host key length

2012-06-24 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 01:26:21PM -0400, Robert Simmons wrote: > On Sun, Jun 24, 2012 at 12:59 PM, J. Hellenthal > wrote: > > These are more then sufficient for any normal ssh use. > > I'm sorry if I sound rude, but I wanted to have a bit more of a > substantive d

Re: Add rc.conf variables to control host key length

2012-06-24 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 02:26:02PM -0400, Robert Simmons wrote: > On Sun, Jun 24, 2012 at 2:15 PM, J. Hellenthal wrote: > > On Sun, Jun 24, 2012 at 01:26:21PM -0400, Robert Simmons wrote: > >> On Sun, Jun 24, 2012 at 12:59 PM, J. Hellenthal > >> wrote: > >&

Re: Hardware potential to duplicate existing host keys... RSA DSA ECDSA was Add rc.conf variables...

2012-06-24 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 02:34:45PM -0400, Robert Simmons wrote: > In light of advanced in processors and GPUs, what is the potential for > duplication of RSA, DSA, and ECDSA keys at the current default key > lengths (2048, 1024, and 256 respectively)? Just missed this one... http://en.wikipedia

Re: Add rc.conf variables to control host key length

2012-06-24 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 03:14:51PM -0400, Garrett Wollman wrote: > < said: > > > 2048 is well more than efficient. Speaking soley for RSA in that matter. > > I asked R. about that a few months back, and he expressed the view > that 2,048 bits is the *minimum* RSA key size anyone should conside

Re: Hardware potential to duplicate existing host keys... RSA DSA ECDSA was Add rc.conf variables...

2012-06-24 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 03:34:15PM -0400, Robert Simmons wrote: > On Sun, Jun 24, 2012 at 2:56 PM, Mark Felder wrote: > > On Sun, 24 Jun 2012 13:34:45 -0500, Robert Simmons > > wrote: > > > >> In light of advanced in processors and GPUs, what is the potential for > >> duplication of RSA, DSA, a

Re: Hardware potential to duplicate existing host keys... RSA DSA ECDSA was Add rc.conf variables...

2012-06-25 Thread J. Hellenthal
On Mon, Jun 25, 2012 at 02:31:04AM +0100, RW wrote: > On Sun, 24 Jun 2012 17:23:47 -0400 > Robert Simmons wrote: > > > On Sun, Jun 24, 2012 at 5:18 PM, Dag-Erling Smørgrav > > wrote: > > > Robert Simmons writes: > > >> In light of advanced in processors and GPUs, what is the potential > > >> f

Re: Add rc.conf variables to control host key length

2012-06-25 Thread J. Hellenthal
On Sun, Jun 24, 2012 at 10:10:33PM -0400, Robert Simmons wrote: > On Sun, Jun 24, 2012 at 9:46 PM, Bjoern A. Zeeb > wrote: > > > > On 24. Jun 2012, at 17:14 , Robert Simmons wrote: > > > >> On Sun, Jun 24, 2012 at 12:34 PM, Bjoern A. Zeeb > >> wrote: > >>> On 24. Jun 2012, at 16:07 , Robert Simm

Re: Hardware potential to duplicate existing host keys... RSA DSA ECDSA was Add rc.conf variables...

2012-06-25 Thread J. Hellenthal
On Tue, Jun 26, 2012 at 03:56:09AM +0100, RW wrote: > On Mon, 25 Jun 2012 18:55:54 -0700 > Doug Barton wrote: > > > > >> My point is that the ssh protocol is designed specifically to > > >> prevent what you're describing. > > > > > > If you've obtained the server's private key by breaking the

Re: [PATCH] Make ssh-keyscan to fetch ECDSA keys by default

2012-06-25 Thread J. Hellenthal
Thanks Xin Li. sunpoet, I don't suppose you could port this into security/openssh-portable ? could you ? On Mon, Jun 25, 2012 at 12:07:04PM -0700, Xin Li wrote: > The proposed change have been committed as r237567 (for vendor branch) > and r237568 (merged to -HEAD with 1 week settle). Thanks!

Re: Putting OPIE to rest

2022-09-15 Thread J. Hellenthal
to OATH HOTP / TOTP instead (cf. security/pam_google_authenticator). > > https://reviews.freebsd.org/D36592 > > DES > -- > Dag-Erling Smørgrav - d...@des.no > -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume.

Re: help regarding IP address spoofing (when using nmap)

2023-02-02 Thread J. Hellenthal
On Thu, Feb 02, 2023 at 04:19:57PM +0530, Sambuddho Chakravarty wrote: >Hi All > I am a relatively newbie to FreeBSD (earlier was running >Linux). I am running FreeBSD 13.1.  >I am trying to run nmap with source IP address spoofing  >(for some academic purposes). It works fine w

Re: FreeBSD Security Advisory FreeBSD-SA-24:04.openssh

2024-07-01 Thread J. Hellenthal
I don't have access to an example rule right now but this could be handled with a pf rule with timeouts and max src conns as an interim fix possibly. Seems more feasible than libwrap. -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a

Re: Spoiler Alert

2019-03-05 Thread J. Hellenthal via freebsd-security
The need of the many outweighs the greed of the few. > ___ > freebsd-security@freebsd.org mailing list > https://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd

Re: [FreeBSD-Announce] FreeBSD Security Advisory FreeBSD-SA-19:07.mds

2019-05-15 Thread J. Hellenthal via freebsd-security
cpu_microcode_load="intel-ucode” Don’t remember that as needing to be yes but could be wrong. -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume. > On May 15, 2019, at 08:32, mike

Re: ?Minor Security Issue - DNS, /etc/hosts, freebsd-update, ?pkg

2019-07-05 Thread J. Hellenthal via freebsd-security
And in what revision besides an administrators local modifications suggest that those werre ever a part of the source trree ? For reference ... https://svnweb.freebsd.org/base/stable/11/etc/hosts?view=log Quite frankly the FreeBSD source committers are much more knowledged thann your insight s

Re: root .history

2020-03-31 Thread J. Hellenthal via freebsd-security
..@freebsd.org >> " >> > ___ > freebsd-security@freebsd.org mailing list > https://lists.freebsd.org/mailman/listinfo/freebsd-security > To unsubscribe, send any mail to "freebsd-security-unsubscr...@freebsd.org" -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume. smime.p7s Description: S/MIME cryptographic signature

pf/pfctl loading CIDR tables & IPv6

2020-11-14 Thread J. Hellenthal via freebsd-security
2.07.png?dl=0 Appreciate any feedback on this and willing to test any patches to resolve this situation. Thank you -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated t

Re: pf/pfctl loading CIDR tables & IPv6

2020-11-14 Thread J. Hellenthal via freebsd-security
I should also note here that after modifying the file and removing the offending information there was also another error where “/“ character was being tested and failed for IPv6 but I do not have that error available ATM. > On Nov 14, 2020, at 10:58, J. Hellenthal wrote: > > H

Re: pf/pfctl loading CIDR tables & IPv6

2020-11-14 Thread J. Hellenthal via freebsd-security
as well -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume. > On Nov 14, 2020, at 12:39, John-Mark Gurney wrote: > > J. Hellenthal via freebsd-security wrote this message on Sat, Nov 14, 2020 &g

Re: user account disappeared

2021-02-27 Thread J. Hellenthal via freebsd-security
Looks like your master passwd db is out of sync. Command is mkpwdb or something similar then run init q Personally it would seem someone got ahold of master.passwd and doesn’t know how it works or a port upgrade failed to complete properly updating the db -- J. Hellenthal The fact that

Re: user account disappeared

2021-02-27 Thread J. Hellenthal via freebsd-security
Also ls -l /etc/*pass* Should show you those. Appears you’ve missed them. -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume. > On Feb 27, 2021, at 15:23, Gareth de Vaux wrote: > > Hi all, o

Re: user account disappeared

2021-02-27 Thread J. Hellenthal via freebsd-security
https://www.unix.com/man-page/FreeBSD/8/pwd_mkdb/ -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic volume. > On Feb 27, 2021, at 18:12, J. Hellenthal wrote: > > Looks like your master passwd db

Re: user account disappeared

2021-02-28 Thread J. Hellenthal via freebsd-security
If it wasn’t ports then it was buildworld where it asks you ... would you like to run this now ? And you probably selected no instead of yes. Or some combination of that and mergemaster not being run. -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven

Re: sysrc bug

2021-05-30 Thread J. Hellenthal via freebsd-security
Think this would be an extra security bug considering that gets wiped out then the system isn't going to come back online after a reboot 🤪 Nice find !!! -- J. Hellenthal The fact that there's a highway to Hell but only a stairway to Heaven says a lot about anticipated traffic vol