Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread someone
You are perfectly correct, it was ed, not vi and sudoedit could be the solution, thanks. I will try to search the internet how to do the LD_PRELOAD trick with ed. Thanks :) On Tue, Apr 28, 2015 at 7:09 AM, Philip Guenther wrote: > On Mon, Apr 27, 2015 at 9:43 PM, someone > wrote: > > "Yeah, th

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread Philip Guenther
On Mon, Apr 27, 2015 at 9:43 PM, someone wrote: > "Yeah, that LD_PRELOAD trick NOEXEC uses doesn't work so well with > static executables." > > Thank you, so there is a way tricking noexec with vi to get a root shell. No, that's not what naddy demonstrated. He showed that NOEXEC didn't work with

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread Theo de Raadt
> "Yeah, that LD_PRELOAD trick NOEXEC uses doesn't work so well with > static executables." > > Thank you, so there is a way tricking noexec with vi to get a root shell. > But how exactly? Why isn't it fixed? :O Oh something is broken? Please show your work.

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread someone
"Yeah, that LD_PRELOAD trick NOEXEC uses doesn't work so well with static executables." Thank you, so there is a way tricking noexec with vi to get a root shell. But how exactly? Why isn't it fixed? :O On Mon, Apr 27, 2015 at 9:49 PM, Christian Weisgerber wrote: > On 2015-04-27, "whynot sudo"

Re: timer_create for openbsd. Any equivalent ?

2015-04-27 Thread Ted Unangst
syphax azmole wrote: > Hello list, > > I have a small "C" program using standard POSIX timer_create(2), > timer_delete(2) and SIGEV_SIGNAL. > It seems that OpenBSD doesn't have such API. (and doesn't have librt). > I'm curious: why are they not implemented ? For security reason ? they are > not ea

Re: Whatever happened to reop?

2015-04-27 Thread Ted Unangst
Christian Weisgerber wrote: > A year ago, tedu@ published reop, which "does everything you’d > expect a PGP program to do". > http://www.tedunangst.com/flak/post/reop > > There's GitHub site that's still active and there is ports/security/reop, > maintained by jturner@, but generally it has been a

Re: spamdb - can't delete spam db entry (Error 22)

2015-04-27 Thread Adam Wolk
On Mon, Apr 27, 2015, at 10:52 PM, Adam Wolk wrote: > On Mon, Apr 27, 2015, at 10:43 PM, Adam Wolk wrote: > > On Mon, Apr 27, 2015, at 10:22 PM, Todd C. Miller wrote: > > > On Mon, 27 Apr 2015 20:06:59 +0200, Adam Wolk wrote: > > > > > > > Apr 27 19:54:55 tintagel spamd[27724]: can't delete 66.111

OpenBSD 5.6 and 5.7 freeze on installation on macbook pro late 2013

2015-04-27 Thread syphax azmole
Hello list, I tried OpenBSD on my laptop, a macbook pro late 2013, and I have freeze while installing it. With OpenBSD 5.6, it hangs 5 minutes when printing "scsibusx at softraidx: 256 targets", and then continue until prompting command from user. (with I for installation, U for upgrade, etc...).

timer_create for openbsd. Any equivalent ?

2015-04-27 Thread syphax azmole
Hello list, I have a small "C" program using standard POSIX timer_create(2), timer_delete(2) and SIGEV_SIGNAL. It seems that OpenBSD doesn't have such API. (and doesn't have librt). I'm curious: why are they not implemented ? For security reason ? they are not easy to implement ? Maybe they are us

Re: spamdb - can't delete spam db entry (Error 22)

2015-04-27 Thread Adam Wolk
On Mon, Apr 27, 2015, at 10:43 PM, Adam Wolk wrote: > On Mon, Apr 27, 2015, at 10:22 PM, Todd C. Miller wrote: > > On Mon, 27 Apr 2015 20:06:59 +0200, Adam Wolk wrote: > > > > > Apr 27 19:54:55 tintagel spamd[27724]: can't delete 66.111.4.25 > > > out1-smtp.messagingengine.com > > > from spamd d

Re: spamdb - can't delete spam db entry (Error 22)

2015-04-27 Thread Adam Wolk
On Mon, Apr 27, 2015, at 10:22 PM, Todd C. Miller wrote: > On Mon, 27 Apr 2015 20:06:59 +0200, Adam Wolk wrote: > > > Apr 27 19:54:55 tintagel spamd[27724]: can't delete 66.111.4.25 > > out1-smtp.messagingengine.com > > from spamd db (Error 22) > > > > Does anyone know how serious that error is

Re: spamdb - can't delete spam db entry (Error 22)

2015-04-27 Thread Todd C. Miller
On Mon, 27 Apr 2015 20:06:59 +0200, Adam Wolk wrote: > Apr 27 19:54:55 tintagel spamd[27724]: can't delete 66.111.4.25 > out1-smtp.messagingengine.com > from spamd db (Error 22) > > Does anyone know how serious that error is (should I be worried) and > what might have caused it? Error 22 is EIN

Re: interesting package isue....cant find with a browser.

2015-04-27 Thread Ton Muller
On 27-4-2015 21:46, Ville Valkonen wrote: > Hi, > > On Apr 27, 2015 9:56 PM, "Ton Muller" wrote: >> >> Ok. >> perhaps a bit cryptic. >> but this is the situation, the package portal is huge, ok, no problem >> with it. >> but finding a sertain package is a pain. >> i can recall from the time i was

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread Christian Weisgerber
On 2015-04-27, "whynot sudo" wrote: > Cmnd_Alias FOO = /bin/ed, /usr/bin/ed, /usr/bin/vi > foouser LOCALHOST = NOPASSWD: NOEXEC: FOO > > Can the "foouser" escape to root prompt? Let's try! $ sudo ed !sh # id uid=0(root) gid=0(wheel) groups=0(wheel), 2(kmem), 3(sys), 4(tty), 5(operator), 20(sta

Re: interesting package isue....cant find with a browser.

2015-04-27 Thread Ville Valkonen
Hi, On Apr 27, 2015 9:56 PM, "Ton Muller" wrote: > > Ok. > perhaps a bit cryptic. > but this is the situation, the package portal is huge, ok, no problem > with it. > but finding a sertain package is a pain. > i can recall from the time i was running 4.6, i when to below link > http://www.openbsd

Re: interesting package isue....cant find with a browser.

2015-04-27 Thread sam
On Mon, 27 Apr 2015 20:56:00 +0200 Ton Muller wrote: > Ok. > perhaps a bit cryptic. > but this is the situation, the package portal is huge, ok, no problem > with it. > but finding a sertain package is a pain. > i can recall from the time i was running 4.6, i when to below link > http://www.openb

interesting package isue....cant find with a browser.

2015-04-27 Thread Ton Muller
Ok. perhaps a bit cryptic. but this is the situation, the package portal is huge, ok, no problem with it. but finding a sertain package is a pain. i can recall from the time i was running 4.6, i when to below link http://www.openbsd.org/4.6_packages/i386.html a nice web portal opened with a discri

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread Stefan Johnson
On Mon, Apr 27, 2015 at 1:44 PM, Richo Healey wrote: > On 28/04/15 05:28 +1200, Carlin Bingham wrote: > >> On Tue, 28 Apr 2015, at 04:46 AM, whynot sudo wrote: >> >>> Hello list, >>> >>> We know it's safer* to use sudoedit, but what bad things can happen if we >>> have the following in sudoers? >

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread Richo Healey
On 28/04/15 05:28 +1200, Carlin Bingham wrote: On Tue, 28 Apr 2015, at 04:46 AM, whynot sudo wrote: Hello list, We know it's safer* to use sudoedit, but what bad things can happen if we have the following in sudoers? Cmnd_Alias FOO = /bin/ed, /usr/bin/ed, /usr/bin/vi foouser LOCALHOST = NOPASS

Re: Duplicate pf rules when using groupname

2015-04-27 Thread Brian S. Vangsgaard
"Lists A list allows the specification of multiple similar criteria within a rule. For example, multiple protocols, port numbers, addresses, etc. So, instead of writing one filter rule for each IP address that needs to be blocked, one rule can be written by specifying the IP addresses in a lis

spamdb - can't delete spam db entry (Error 22)

2015-04-27 Thread Adam Wolk
Hi all, I spent part of the weekend setting up a private OpenSMTPD server using spamd. Everything seems to be working great but I'm now starting to see some weird behaviour. The server is running an amd64 snapshot from Apr 25 using a default spamd configuration. Does anyone know how serious that

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread Carlin Bingham
On Tue, 28 Apr 2015, at 04:46 AM, whynot sudo wrote: > Hello list, > > We know it's safer* to use sudoedit, but what bad things can happen if we > have the following in sudoers? > > Cmnd_Alias FOO = /bin/ed, /usr/bin/ed, /usr/bin/vi > foouser LOCALHOST = NOPASSWD: NOEXEC: FOO > > Can the "foous

Re: Whatever happened to reop?

2015-04-27 Thread Bryan Steele
On Mon, Apr 27, 2015 at 05:34:43PM +0200, Christian Weisgerber wrote: > A year ago, tedu@ published reop, which "does everything you???d > expect a PGP program to do". > http://www.tedunangst.com/flak/post/reop > > There's GitHub site that's still active and there is ports/security/reop, > maintai

Re: What bad things could happen if we don't use sudoedit?

2015-04-27 Thread whynot sudo
"In the bad thing category, you could break your sudo config." What do you mean by that? Original Message From: ludovic coues To: whynot sudo Subject: Re: What bad things could happen if we don't use sudoedit? Date: Mon, 27 Apr 2015 18:52:56 +0200 > 2015-04-27 18:46 GMT+02

What bad things could happen if we don't use sudoedit?

2015-04-27 Thread whynot sudo
Hello list, We know it's safer* to use sudoedit, but what bad things can happen if we have the following in sudoers? Cmnd_Alias FOO = /bin/ed, /usr/bin/ed, /usr/bin/vi foouser LOCALHOST = NOPASSWD: NOEXEC: FOO Can the "foouser" escape to root prompt? - of course besides that he could now edit

Whatever happened to reop?

2015-04-27 Thread Christian Weisgerber
A year ago, tedu@ published reop, which "does everything you’d expect a PGP program to do". http://www.tedunangst.com/flak/post/reop There's GitHub site that's still active and there is ports/security/reop, maintained by jturner@, but generally it has been awfully silent. If anybody uses reop, th

Re: Duplicate pf rules when using groupname

2015-04-27 Thread Joseph Crivello
http://www.openbsd.org/faq/pf/macros.html "Lists A list allows the specification of multiple similar criteria within a rule. For example, multiple protocols, port numbers, addresses, etc. So, instead of writing one filter rule for each IP address that needs to be blocked, one rule can be written

Re: i386 bsd.rd panic

2015-04-27 Thread Tim van der Molen
Theo de Raadt (2015-04-26 16:53 +0200): > > Eivind Eide (2015-04-26 13:02 +0200): > > > I've been trying to update this -current machine with the bsd.rd from the > > > last 4 snapshots, > > > the last being from "Sun Apr 26 02:22:08 MDT 2015". > > > However this kernel immediately after reporting h

Re: ksh manpage lies

2015-04-27 Thread Theo de Raadt
> > Careful with your allegations, ok? > > I apologize. I wonder if RANDOM can refer to srand_deterministic. I don't see any reason. It is documenting the standards-required behaviour, and it follows it as far as I can see.

Duplicate pf rules when using groupname

2015-04-27 Thread Brian S. Vangsgaard
Hi, I'm getting a strange output from pfctl that I cannot explain, perhaps someone lurking the list have the answer? When using interface groupnames in my pf.conf, I see the same rule 4 times when doing a pfctl -s rules. The interface group i'm using, have a vlan and carp member. Ex. pass

Re: ksh manpage lies

2015-04-27 Thread u
> Careful with your allegations, ok? I apologize. I wonder if RANDOM can refer to srand_deterministic.