Re: Getting envolved

2007-12-13 Thread Bob Beck
> > If you like the current way it works, you should be able to continue > > with this system. But what if my mum, who has low computer skill, would > > like to install a free, functional and secure system? I think the > > software should help her to make the most accurate choices. Because I > > th

Re: Getting envolved

2007-12-13 Thread Bob Beck
> > Users who can no invest the effort learn enough to use a simple > > interface do not deserve a reliable operating system. They deserve windows, > > and they deserve pop up buttong in their browsers that they click ok blindly > > for everything. > > > > -Bob > > Do you apply this rea

Re: Getting envolved

2007-12-14 Thread Bob Beck
* Douglas A. Tutty <[EMAIL PROTECTED]> [2007-12-13 21:46]: > On Thu, Dec 13, 2007 at 08:22:07PM -0700, Theo de Raadt wrote: > > > When I read that, it sounded a lot to me like saying "if you're not a > > > skilled medical practitioner, you don't deserve decent health care." > > > Seems to me o

Re: Developers: First Reply Gets My Copy Of /On Bullshit/

2007-12-14 Thread Bob Beck
Me! Me! Ship it to my address: 51 Franklin Street, Fifth Floor Boston, MA 02110-1301 USA -Bob * Breen Ouellette <[EMAIL PROTECTED]> [2007-12-14 13:02]: > OpenBSD developers, > > In recognition of all the bullshit flying around recently on misc@, I > would like to offer to mail

Re: Developers: First Reply Gets My Copy Of /On Bullshit/

2007-12-14 Thread Bob Beck
ROTECTED]> [2007-12-14 13:41]: > It's yours Bob. Given the address you've posted, I imagine that you > might want me to send it in care of someone with the initials RMS? > > Breeno > > > Bob Beck wrote: > > Me! Me! Ship it to my address: > > >

Re: Real men don't attack straw men

2007-12-14 Thread Bob Beck
> Having recipes for non-free programs in the ports system is more like > including present-day neofascist web sites in the list of "interesting > links" in your web site. I am against censorship, so I do not believe > in closing down those neofascist web sites. But I won't refer people > to them

Re: spam story

2006-12-14 Thread Bob Beck
* Jacob Yocom-Piatt <[EMAIL PROTECTED]> [2006-12-14 09:15]: > spamd in greylisting mode without any blacklists has been working pretty > well here at work and at home for the past couple weeks. however, at > work i noticed that a considerable amount of spam was getting through > and was confuse

Re: spam story

2006-12-14 Thread Bob Beck
> is there any way to work around users like this besides not whitelisting > outbound mail? a spamlogd "blacklist" of users that do not have the > outbound mail IPs whitelisted is a thought, but maybe not the right idea. > Actually, come to think of it, if I could get away with it, I'd

Re: greylisting

2007-01-09 Thread Bob Beck
Sounds to me like your pf rules and/or bridge setup are not set up correctly to allow the connections to be redirected. -Bob * Stephen Schaff <[EMAIL PROTECTED]> [2007-01-08 18:52]: > tail -f /var/log/daemon shows: > > Jan 8 02:23:38 spamd spamd[4966]: listening for incoming co

Re: ODBC repost...

2007-01-09 Thread Bob Beck
> > Sorry, made a few mistakes in my original post... > > > > We're going to be using an OpenBSD 4.0 machine to collect employee > > Punch-in data and store that data in a form similar to that of a Microsoft > > Access Database file. We would then like to access that data from our > > mainframe via

Re: Greyscaner question

2007-01-17 Thread Bob Beck
1) I don't have enough information to tell what you are asking. show the real logs. 2) "greyscanner" is not part of openbsd - it is a proof of concept piece written by me, so you should probably ask me directly (with full logs) rather than asking the list. -Bob * Ramdas <[EMAIL PROTE

Re: Is Theo still hiking ????

2007-01-27 Thread Bob Beck
Yes, theo is still hiking, although I'm quite surprised that the usual pack of idiots on misc@ can't contribut adequatly to comic relief - in my experience they are usually much funnier than theo. -Bob * Allie Daneman <[EMAIL PROTECTED]> [2007-01-26 22:59]: > Is Theo still hiking

Re: Idea for additionnal funding

2007-01-29 Thread Bob Beck
And the other thing people forget who try to "helpfully" set us up a 501(c) in the US is that most of our expenses are *NOT* in the united states. and a 501(c) has to spend most of it's money in the united states. This is not helpful to us. A Canadian solution is in the works.

Re: http load balancing with pf (apache access log)

2007-01-29 Thread Bob Beck
* Marian Hettwer <[EMAIL PROTECTED]> [2007-01-29 09:49]: > Hi OpenBSD'lers, > > I'm about to use OpenBSD's pf(4) for load balancing some webservers. So > far, everything is looking just perfect. > Compared to pound, pf(4) is incredibly fast with few CPU and memory usage. > So I'd say: Thats great

Re: Idea for additionnal funding

2007-01-29 Thread Bob Beck
* Jack J. Woehr <[EMAIL PROTECTED]> [2007-01-29 11:49]: > > On Jan 29, 2007, at 9:00 AM, Bob Beck wrote: > > > a 501(c) has to spend most of it's money in the > >united states. This is not helpful to us. > > > > A Canadian solution is i

Re: spamd - SPEWS status

2007-02-01 Thread Bob Beck
Yeah, probably time to retire spews, they aren't going to fix it. Aside from my traplist (which I'll add) anyone have any suggestions for useful addtions when I commit this? I seldom use exernally maintained blacklists anymore :) -Bob * Josh Grosse <[EMAIL PROTECTED]>

Re: spamd - SPEWS status

2007-02-05 Thread Bob Beck
* smith <[EMAIL PROTECTED]> [2007-02-01 17:15]: > On Thu, 01 Feb 2007 15:38:37 -0500, Daniel Ouellet wrote > > May be if there was a way to distribute one own addition only may be > > a good idea as then we could merge traplist from multiple locations > > if one wants to do this. I wouldn't have

Re: How to create /var/db/spamd

2007-02-05 Thread Bob Beck
it is created automatically by spamd when you run it in greylisting mode -Bob * Vijay Sankar <[EMAIL PROTECTED]> [2007-02-02 10:34]: > How can /var/db/spamd be created? I went through spamd.conf(5), pfctl(8), > spamd-setup(8), spamdb(8), spamlogd(8) etc. and did not see it men

Re: spamd issue

2007-02-20 Thread Bob Beck
No, I'm not seeing this, can you mail me any details? your setup, how big, Got a core file? etc? you mention you have debug logging on, can you capture a debug level syslog? if so can you pinpoint where it stops and show me? thanks -Bob * [EMAIL PROTECTED] <[EMA

Re: spamd unnecessarily abrasive?

2007-02-20 Thread Bob Beck
> I was thinking the exact same thing. > > A number of our customers use the ability to customize their SMTP > banner via our products in order to avoid some very basic system > identification by spammers (Cisco PIX does this too for instance, but > in a very broken and disruptive way). It

Re: spamd unnecessarily abrasive?

2007-02-20 Thread Bob Beck
> i have seen a number of spammer outfits doing this: following the RFC > and retrying until the spam gets though and they're whitelisted, then > they're free to push crap through. any thoughts on how to best combat > this behavior besides spamassassin + amavisd (i.e. wasting cpu cycles > and b

Re: CUPS

2007-02-24 Thread Bob Beck
* Tang Tse <[EMAIL PROTECTED]> [2007-02-24 04:38]: > Hi, > > Thanks for your answear. So best i use linux for a printer server? > No, I've used the CUPS/ghostscript mashups to attempt to make hundred dollar inkjets work on linux. similarly handbuilt them on openbsd. neither with any rel

Re: filesystem hackathon: still seeking donations

2007-02-26 Thread Bob Beck
* Nikolay Sturm <[EMAIL PROTECTED]> [2007-02-26 16:20]: > * Nikolay Sturm [2007-02-26]: > > unfortunately the first call for hardware donations wasn't really that > > successful, we got a few interesting pieces of hardware, but we are > > still lacking major parts. So here's the second call for don

Re: kadmin problem

2007-02-27 Thread Bob Beck
* RJ45 <[EMAIL PROTECTED]> [2007-02-27 02:40]: > actually i just need ssh kerberos authentication > but the problem is that using ssh kerberos authentication I got an error > upon autghentication > Feb 26 21:42:54 bastionbox1 krb5: verify: Server not found in Kerberos > database > Feb 26 21:42:54

Re: Concerning Filesystem Mini-Hackathon and faster kernel building (distcc)

2007-02-27 Thread Bob Beck
> It was just targeted at THIS particular issue and the future ideas to > continue making OpenBSD (development) better/more fun. > And by detracting from the important issue which is: * We need gear in europe for f2k7 * You manage to sidetrack something important with your hack. So in do

Re: spamd-white

2007-02-27 Thread Bob Beck
* Tom Bombadil <[EMAIL PROTECTED]> [2007-02-27 15:09]: > Greetings... > > By any chance, will spamd delete any IPs that I add manually to spamd-white? > Yes. > spamd(8) says: > "spamd regularly scans the /var/db/spamd database and configures all > whitelist addresses as the spamd-white

Re: amusing greylisting HELO/EHLO identification side-effect

2007-02-28 Thread Bob Beck
* Marco S Hyman <[EMAIL PROTECTED]> [2007-02-27 19:27]: > I found it highly amusing that as a result of runnig the latest spamd > in greylisting mode with this change > > Make spamd include the HELO/EHLO identification string sent by > the connecting hosts in the tuple key when greylisting. ca

Re: a few questions on spamdb

2007-02-28 Thread Bob Beck
* Tom Bombadil <[EMAIL PROTECTED]> [2007-02-28 12:59]: > I wonder how people are coping with master downtime when using spamd? > > Is it a good idea to regularly dump into a file, rsync it > to the backup carp server, and load these IPs in a separate table? > I was thinking of lowering "whiteexp"

Re: yelp...bit screwed, cyrus-imap not starting after switch to 64bit

2007-03-05 Thread Bob Beck
* Paul Pruett <[EMAIL PROTECTED]> [2007-03-05 07:04]: > Okay, sorry to pester list, > but I jumped and fell short on an active mail machine, about 6 hours ago. > I knew doing this on a cyrus-imapd server was insane > I "Upgraded" from i386 openbsd 4.0 to amd64 openbsd 4.0 > > So if someone e

Re: Stanford SRP auth.

2007-03-08 Thread Bob Beck
* Johan P. Lindstrvm <[EMAIL PROTECTED]> [2007-03-08 05:25]: > The Stanford SRP Authentication Project > > The Secure Remote Password protocol is the core technology behind the > Stanford SRP Authentication Project. The Project is an Open Source > initiative that integrates secure password authent

Re: authpf - update user rules without kicking them out

2007-03-08 Thread Bob Beck
> # cat /etc/authpf/users/cyoub/authpf.rules > external_if = "bge0" > internal_if = "bge1" > pass in quick on $external_if from $user_ip to 172.16.0.0/22 > pass in quick on $external_if from $user_ip to 172.16.4.0/22 > pass in quick on $external_if from $user_ip to 172.16.8.0/22 <-- I add this > af

Re: a few questions on spamdb

2007-03-08 Thread Bob Beck
* Tom Bombadil <[EMAIL PROTECTED]> [2007-03-08 19:39]: > > I'm currently going in to test some new stuff that > > will fix this problem. so as theo said. wait a few days.. > > damn... you guys rock! > Will it be something in the lines of pfsync? > Yes. go read undeadly. -Bob

Re: spamd and MailEnable mta problems

2007-03-11 Thread Bob Beck
> Guess this is a MailEnable bug, but maybe anyone has the possibility to test > if this patch helps to workaround the problem. This is completely a mailenable bug and should be reported to them. They are assuming that the sending mta can always send the numeric code as one byte. in fact,

Re: Greytrapper and invalid source addresses (rfc822)

2007-03-14 Thread Bob Beck
Your problem is that you are running the greytrapper script for 4.0 on 4.1 - the spamdb database has changed - there is a new field in the spamdb output. you should not run that old greytrapper script on 4.1 spamd. -Bob * Jeff Ross <[EMAIL PROTECTED]> [2007-03-14 09:55]:

Re: No Blob without Puffy

2007-03-16 Thread Bob Beck
* Karel Kulhavy <[EMAIL PROTECTED]> [2007-03-16 12:20]: > Is it true that Puffy is not here because of Theo's concerns about > his copyrighted Puffy logo? > http://misc.allbsd.de/Kampagnen/NoBlob/NoBlob-en-Poster.jpg Hunh? a "No Blob" poster with FreeBSD on it? that's a fucking joke. they'

Re: Is OpenBSD VuXML broken?

2007-03-17 Thread Bob Beck
* Siju George <[EMAIL PROTECTED]> [2007-03-17 13:45]: > Hi, > > The latest entry in > > http://www.vuxml.org/openbsd/ > > is > > 2006-01-10clamav -- heap overflow in the UPX code > > more than a year now? > Certainly looks that way. > is there any other place to get updated RSS

Re: warning "Yet Another Inane Post" or every six month wierdness on misc@ list

2007-03-17 Thread Bob Beck
* Diana Eichert <[EMAIL PROTECTED]> [2007-03-17 08:39]: > I don't know what's worse, the junky posts from people who come out of the > woodwork around release dates or the > "Two chick f/cking in wild orgy" \ > "Normalize your Cholesterol" \ > "mature blonde milf f/cking hardcore & s/cking" \ > "

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Bob Beck
* Sunnz <[EMAIL PROTECTED]> [2007-03-16 20:50]: > I don't live in US Canada nor Europe... but I am worried if I ordered > "From North America to anywhere worldwide", would the CD have the lack > of built-in cryptography due to the US Export laws? Hate to tell you this, but Canada is not t

Re: OpenBSD 4.1 Pre-Orders...

2007-03-17 Thread Bob Beck
* Bryan Allen <[EMAIL PROTECTED]> [2007-03-17 16:22]: > On Mar 17, 2007, at 4:12 PM, Bob Beck wrote: > > > > Hate to tell you this, but Canada is not the United States. > > Give us a couple years. Pax Americana, yo. > Nah, at the rate it's going

Re: spamlogd (how to specify port?)

2007-03-18 Thread Bob Beck
Sorry, Absolutely not. I am not putting in a knob for this If you're crazy enough to run an MTA on a non-standard port you know enough to recompile. -Bob * Joachim Schipper <[EMAIL PROTECTED]> [2007-03-18 16:16]: > On Sun, Mar 18, 2007 at 08:57:32PM +, Stuart Henderso

Re: NOOP and Spamd

2007-03-19 Thread Bob Beck
* Sid Carter <[EMAIL PROTECTED]> [2007-03-19 03:25]: > > Regardless, if NOOP is in the SMTP standard, and spamd does not handle > > it correctly, that is a bug that needs to be fixed. Bullshit. that's not a good enough reason - spamd does not implement all of smtp, and never will. saying

Re: is the Thinkpad T30 supported?

2007-03-20 Thread Bob Beck
I have a T30. pretty much everything works on it and very well, it suspends and resumes again. It would be a good choice for a used laptop. -Bob * Igor Sobrado <[EMAIL PROTECTED]> [2007-03-20 03:19]: > Hello. > > I am looking for a laptop to replace my old, but excell

Re: Daylight savings fix with OpenNTPD

2007-03-20 Thread Bob Beck
* Bray Mailloux <[EMAIL PROTECTED]> [2007-03-20 13:33]: > Have a patch been issued? Yes. see the errata page > It might just be the time servers, but date is > reporting 11:04:31 when it is 12:05. It aint the time servers they report in UCT. Your timezone is wrong

Re: USB Printer Recommendation

2007-03-21 Thread Bob Beck
* James Turner <[EMAIL PROTECTED]> [2007-03-21 00:11]: > I'm looking to finally cut the last strand that keeps windows on my hard > drive. I currently have a brother mfc-210c printer. I'm looking to replace > it with a cheap openbsd/lpr friendly solution. Although the mfc is a > multifunction

Re: USB Printer Recommendation

2007-03-21 Thread Bob Beck
> Although this seems like a great printer, my biggest limitation is price. We > have a university property disposition near me, which I'm going to go check > out > later today. My friend has gotten a couple sun sparc stations from them for > under $20 bucks. I'm hoping they will have some chea

Re: USB Printer Recommendation

2007-03-21 Thread Bob Beck
* Darrin Chandler <[EMAIL PROTECTED]> [2007-03-21 11:30]: > On Wed, Mar 21, 2007 at 10:27:40AM -0600, Bob Beck wrote: > > LexMark C510 laser. Color, ethernet, postscript. $325 CDN 6 months ago > > just works. > > > > I've had nothing but pain

Re: Microsoft gets the Most Secure Operating Systems award

2007-03-22 Thread Bob Beck
> Siju George wrote: > >Hi, > > > >http://www.internetnews.com/security/article.php/3667201 > > > >Just for some entertainment, no troll :-) > > > >--Siju > > > > IMHO it's not a fair comparison, most linux distributions ship with alot > more software than microsoft windows does, and most bugrepo

Re: Saving memory on small machines

2007-03-22 Thread Bob Beck
* Artur Grabowski <[EMAIL PROTECTED]> [2007-03-22 10:32]: > Kamil Monticolo <[EMAIL PROTECTED]> writes: > > > # ls -lhS /usr/lib/libcrypto*a > > -r--r--r-- 1 root bin 11.7M Mar 22 13:53 /usr/lib/libcrypto_pic.a > > -r--r--r-- 1 root bin 11.6M Mar 22 13:53 /usr/lib/libcrypto_p.a > > -r--r--r-

Re: Text about openbsd's security technology

2007-03-23 Thread Bob Beck
* Rafael Almeida <[EMAIL PROTECTED]> [2007-03-23 14:52]: > I'm aware that OpenBSD's developers create new technology for making > the exploiter's life harder. On the OpenBSD site I could find a list > of some of those kinda features (following this paragraph). Yet, I > could not find any article de

Re: An introduction of sorts

2007-03-26 Thread Bob Beck
> That is where I post questions I feel is too dumb :-) > Now Bob Beck might comment some thing like > " Oh my! you can ask dumber questions?" > > LOL! Oh, I'm aware there are dumber questions. Don't forget I work at a university :) -Bob

Re: using spamd to block outbound spam

2007-04-12 Thread Bob Beck
* Paolo Supino <[EMAIL PROTECTED]> [2007-04-12 22:12]: > Hi > > I have the following problem: I host a group of windows servers that > run a webapp using IIS6 ASP technology. The webapp was written and is > maintained by a small private company that develops custom webapps for > companies. On

Re: Mail Server (seeking recommendations)

2007-04-14 Thread Bob Beck
> >We have settled on > >what software to use for everything but the mail server. > > I'm reasonably happy using the Courier-MTA suite on OpenBSD. It's had > four reported vulnerabilities > (http://secunia.com/product/2557/?task=advisories), three DOS and one > remote-code-execution in a corne

Re: using spamd to block outbound spam

2007-04-14 Thread Bob Beck
> You are going about this all wrong. First step is finding a suitable > blunt instrument and getting the developers to fix it. The second step > is configuring rate limiting, along the lines of '1000 mails/hour'; > this will allow a large batch of e-mail to get through immediately, but > stop spam

Re: using spamd to block outbound spam

2007-04-14 Thread Bob Beck
* Paolo Supino <[EMAIL PROTECTED]> [2007-04-14 08:43]: > Hi Kyle > > 1. Fixing the code is impossible :-( I already tried it, the developers > keep saying that they're code is sound and safe. I've shown logs and > statistics to the bosses of the company that owns the webapp, but the > only resp

Re: spamd - good job!

2007-04-20 Thread Bob Beck
Thanks. 4.1 has some major changes too, so bear in mind spamd wise it's a big change from 4.0 -Bob * Frank Bax <[EMAIL PROTECTED]> [2007-04-20 08:29]: > I'm finally upgrading from 3.5 to 4.0! I use the whitelist from puremagic > and in the past 2.5 years I have also added anoth

Re: Webservers with Terrabytes of Data in - recomended setups

2007-04-20 Thread Bob Beck
Bullshit. just use NFS :) -Bob * Steven Harms <[EMAIL PROTECTED]> [2007-04-19 17:01]: > This isn't an OpenBSD specific solution, but you should be able to use an > EMC san to accomplish this (we use a fiber channel setup) > > On 4/19/07, Stuart Henderson <[EMAIL PROTECTED]> wro

Re: spamd - good job!

2007-04-20 Thread Bob Beck
sting functionality to be forewarned > about; or just new features? > > I'm actually running a February snapshot (early 4.1 beta) if that makes a > difference; this is considered "living on the edge" for me. > > > > At 12:59 PM 4/20/07, Bob Beck wrote: >

OpenBSD 4.1 Released

2007-05-01 Thread Bob Beck
ko, Alexandre Anriot, Andreas Gunnarsson, Angelos D. Keromytis, Anil Madhavapeddy, Antoine Jacoutot, Artur Grabowski, Ben Lindstrom, Bernd Ahlers, Bjorn Sandell, Bob Beck, Brad Smith, Brandon Creighton, Brian Caswell, Brian Somers, Bruno Rohee, Camiel Dobbelaar, Can Erkin Acar, Cedric Ber

Re: authpf: real world uses of $user_id ?

2007-05-02 Thread Bob Beck
still wonder why such a feature exists... Oh for god's sake. It matters when you play with tagging. You can tag in the authpf rule based on $user_id and then have rules which reference the tagged packet. I.e. packets tagged with "beck" get different treatmen

Re: Spamd Q

2007-05-10 Thread Bob Beck
The example in the man page assumes your mail server requires no redirection. If you actually redirect connections to your real mail server, then you will need to modify the example appropriately. -Bob * Steve Shockley <[EMAIL PROTECTED]> [2007-05-03 19:02]: > I've jus

Re: OpenBSD serial terminal binary programs

2007-05-11 Thread Bob Beck
> >Makes me think some sort of OS has to be present before using cu. I have a > >couple of sparc machines with no monitor/OS that I would love to throw an > >OS > >on.. > > > >Zach > > sure you can, but the hardware boot ROM has to support it. I ran most of > my non-intel systems headless for

Re: Spamd default behaviour of accepting everything

2007-05-22 Thread Bob Beck
> I just used dnsstuff to test one of my domain names and it showed me > (the first time only) that my server is an openrelay, which is obviously > not true. This is due to the default behaviour of spamd of accepting > everything, even when a spamd.alloweddomains file is present. I think > this cou

Re: smtp auth + greylisting

2007-05-22 Thread Bob Beck
Trust me - bit the bullet and change to 587/465 anyway. we had to for road warriors because 25 is blocked in so many places anyway from walkups. You're better just getting your users to switch. * Chad M Stewart <[EMAIL PROTECTED]> [2007-05-22 12:46]: > Since having users change th

Re: Spamd default behaviour of accepting everything

2007-05-22 Thread Bob Beck
> just deduced from trial and error. Also greylisting should happen at > RCPT TO, and probably not at DATA as there are some widely used MTAs > that are buggy and choke when a 4xx error is sent in the DATA phase. I've been running this at DATA for months, and not seen any issues with it.

Re: smtp auth + greylisting

2007-05-22 Thread Bob Beck
... We walked in, sat down, Obie brought up the the help desk page with the twenty seven 800 x 600 colour glossy screenshots with circles and arrows and a paragraph below each one explaining what each one was to be used to show Windows users what to do. Luser came in and said "My mail's

Re: Spamd default behaviour of accepting everything

2007-05-22 Thread Bob Beck
> I manage about 30 mail servers, all using greylisting for years (not > OpenBSD spamd, but a version running in the MTA). But as I greylist at > RCPT TO, I only noticed the problem it when clamav did go down and the > server was producing a 4xx error at DATA when it should have scanned the > mail.

Re: Dell PERC 3/Di - No Disks Found

2007-05-23 Thread Bob Beck
> Things are better with an ebay'd ami(4) (PERC3/SC, PERC3/DC, etc) which > shouldn't be too expensive or hard to find, are supported by GENERIC, > and work with bioctl/sensorsd. Yes, if you can get an ami based perc, they rock. -Bob

Re: Spamd default behaviour of accepting everything

2007-05-23 Thread Bob Beck
> rfc 2821 specifically forbids this behaviour. > > > The DATA command can fail at only two points in the protocol exchange: > >- If there was no MAIL, or no RCPT, command, or all such commands > were rejected, the server MAY return a "command out of sequence" > (503) or "no val

Re: Spamd default behaviour of accepting everything

2007-05-24 Thread Bob Beck
> yes, but not in response to the DATA command (what I was talking about) > but after. > no, you're wrong. right from rfc 2821: 8< DATA I: 354 -> data -> S: 250 E: 552, 554, 451, 452 E: 451, 554, 503 8< explicitly - if I decide something is wro

Re: OpenBSD sucks

2007-06-01 Thread Bob Beck
* Miod Vallat <[EMAIL PROTECTED]> [2007-05-31 23:05]: > Good! You only have to buy a boat then, since you've already got the > boat anchor! > > Miod This from the man with an mcd(4) hooked up to an isa bus on his hp300 That's kinda like a guy with a pierced nipple being called a fr

Re: spamd

2007-06-04 Thread Bob Beck
Many things. according to the logs you have there it didn't even talk smtp to you, so it shouldn't pass. * Edgars Mak??a <[EMAIL PROTECTED]> [2007-06-04 12:07]: > Hi! > > I have some problems with spamd. A lot of smtp servers stops at this > point of cycle: > Jun 4 20:40:17 firewall spa

Re: hoststated/spamd

2007-06-08 Thread Bob Beck
> rdr-anchor "hoststated/smtp" from > rdr proto tcp from ! to $MX port smtp -> 127.0.0.1 port spamd The fact that those two table names are different looks suspiciously wrong to me. -Bob

Re: simple spamd questions

2007-06-10 Thread Bob Beck
* Juan Miscaro <[EMAIL PROTECTED]> [2007-06-10 10:24]: > --- Jeff Santos <[EMAIL PROTECTED]> wrote: > > > Hi, > > > > Thank you. > > > > Can I assume that all connected/disconnected messages I see in > > /var/log/daemon > > are > > from blacklisted hosts or some are still greylisted (undefined)?

Re: beck's greyscanner for spamd 4.1

2007-06-11 Thread Bob Beck
read the archives for the answer to this and other fascinating questions. or look very carefully at the contents of that directory. * Anton Karpov <[EMAIL PROTECTED]> [2007-06-09 04:53]: > I've noticed that original greyscanner by beck@ doesn't work with latest > s

Re: Spamd variation

2007-06-12 Thread Bob Beck
* Praveen <[EMAIL PROTECTED]> [2007-06-12 05:14]: > Hi, >From the man page it appears that spamd relies on > static information about spam originators. > Why not a more dynamic scheme ?. No, it doesn't. please read the man page instead of trolling. > > Why not run the content of the

Re: hoststated/spamd

2007-06-12 Thread Bob Beck
I still don't see how hosts in spamd-white are not sent to spamd. what if a host is in spamd-white, but not in spamd-exempt.. -Bob * Stuart Henderson <[EMAIL PROTECTED]> [2007-06-11 17:21]: > On 2007/06/08 16:02, Bob Beck wrote: > > > rdr-anchor "host

Re: hardware needed for network stack performance work

2007-06-13 Thread Bob Beck
>3) Use info garnered through survey to > a) craft appeals on website Don't need a survey for this. we have a pretty good idea what biggies are using it. > b) create email appeals to self-identified users in correct > classes. Oh, a directed spam ca

Re: hardware needed for network stack performance work

2007-06-13 Thread Bob Beck
> Or maybe we need 20 more people like Jason Dixon, to make an appeal to a > company where they have contacts, where the message will at least be > read. That's directly targetted, and therefore more meaningful, and I > think has a higher chance of success. > > Anyone out there know companies usin

Re: greylisting and mailer pools redux

2007-06-13 Thread Bob Beck
* Satadru Pramanik <[EMAIL PROTECTED]> [2007-06-13 16:00]: > I have OpenBSD 4.0 setup with spamd doing greylisting for a mail > server, and I am having a problem with more and more companies sending > mail that is getting stuck in spamd from having a pool of mail servers > sending mail from several

Re: Security of the keyboard

2007-06-20 Thread Bob Beck
> > And guess what. Keyboards use a serial protocol. Which means that > > there will be slightly different voltage drops in the system varying > > with the keys you press. ZOMG! OpenBSD provides a side channel for > > attackers through the sensors framework! > > And don't forget the aps(4) sensor

Re: authpf allows only one user from the same source ip; kicks off previous user

2007-06-25 Thread Bob Beck
Nope. That's how it is supposed to work. The point of authpf is for the user to say "this IP is me" - if that IP could perhaps not be him, well, this is not an application for authpf. I.E. if your users are coming in from a NAT, you should rethink what you are doing. -Bo

Re: authpf allows only one user from the same source ip; kicks off previous user

2007-06-25 Thread Bob Beck
> I fully understand your reasoning. Under normal circumstances users > authenticate from their desktop machines (which is a unique IP) and > therefore not a problem. However, sometimes they are VNC'd into servers > (more CPU power) and want to access resources behind the internal > 'firewall'.

Re: Publishing your spamtraps list, is that a wise move?

2007-07-05 Thread Bob Beck
> The only downside to this that I can see is that occasionally somebody > naive and innocent sending backscatter (bounces of undeliverable spam) > would be tarpitted for a while. I do not view such people as "innocent" - having your mail server configured to do this is acting as a DOS mul

Re: mysql problem

2007-07-13 Thread Bob Beck
You are setting the user, not the login class. You have made a login class _mysql in /etc/login.conf, but it looks like you may not have that as user _mysql's default login class. You need to either change user _mysql to be in the _mysql login class by default, (hint, chfn _mysql

Re: fsck Segmentation fault on 4.1

2007-07-13 Thread Bob Beck
> I want to report a problem i experienced while testing OpenBSD 4.1 . > I've installed it, increased VM_PHYSSEG_MAX to 16 > in /usr/src/sys/arch/i386/include/vmparam.h to make > it work with this particular motherboard and made a > stable release. Fluffy!!! There be dragons..

Re: print filter?

2007-07-17 Thread Bob Beck
I used to fight with such insanity constantly. However since printers are frequently sold and shipped with a basically undocumented interface, and more than half the time these filter utilites are barely reverse engineered POS's I decided long ago that fighting with them was count

Announcing: The OpenBSD Foundation

2007-07-25 Thread Bob Beck
The OpenBSD Foundation is pleased to announce today it has completed its organization as a Canadian federal non-profit corporation and is ready for public interaction. The OpenBSD Foundation has been formed for the purpose of supporting the OpenBSD project, and related projects such as OpenSSH

Re: spamd DB_SCAN_INTERVAL

2007-08-30 Thread Bob Beck
* Tom Bombadil <[EMAIL PROTECTED]> [2007-08-30 13:56]: > Hi all... > > What happens if we change "#define DB_SCAN_INTERVAL 60" to 600 in > /usr/src/libexec/spamd/grey.h? > Probably Bad things. > Sorry, I'm no C coder... > > Basically we just want to spread out table scans for now until

I respect the GPL immensely, really I do - but I believe this type of action weakens us all.

2007-09-01 Thread Bob Beck
[ A copy of this is going to the linux kernel mailing list, regarding the recent license modifications to reyk's files] >Oh, and if you look at the OpenBSD CVS you see versions 4 months old >with dozens of contributions by Reyk and with: > >/* $OpenBSD: ath.c,v 1.63 2007/05/09 16:41:14 reyk

Re: Fwd: That whole "Linux stealing our code" thing

2007-09-01 Thread Bob Beck
>As a free software user and developer, the question I have is how come >the Linux community feels that they can take the BSD code that was >reverse-engineered at OpenBSD, and put a more restrictive licence onto >it, such that there will be no possibility of the changes going back >to OpenBSD, give

Re: scanner??

2007-09-11 Thread Bob Beck
Interesting, because I'm seeking the same. Based on sane's site and what was at the local staples, I bought a Canon Lide 25 - however the sane support on openbsd didn't work, better yet, if I boot to windows to see if the thing is boned or not, trying to install the windows driver crashes (

Re: scanner??

2007-09-11 Thread Bob Beck
amount of pain that was my vasectomy... If I get something that works I'll let the list know. -Bob > On Tue, 11 Sep 2007, Bob Beck wrote: > > > Interesting, because I'm seeking the same. Based on sane's site and > >what was at the local staples, I b

Re: using spamd to grey-TRAP *only*, with *no* grey-LIST delays, stutters, etc ?

2007-09-11 Thread Bob Beck
> My question is about using spamd to GREYTRAP, but not GREYLIST. > spamd doesn't do that. because it needs to look at the address in order to trap. it does this offline after one delay. It is not written to do instantaneous type trapping, because your MTA can do that. -Bob

Re: using spamd to grey-TRAP *only*, with *no* grey-LIST delays, stutters, etc ?

2007-09-11 Thread Bob Beck
* snowcrash+openbsd <[EMAIL PROTECTED]> [2007-09-11 11:41]: > hi, > > > it does this offline after one delay > > well, fair enough, then. > > what, then, is the MINIMUM value of that delay? > > "1 minute" is obviouly OK. Nope, because it's up to the client (the other end) how fast he r

Re: lost whitelisted hosts with spamd

2007-09-13 Thread Bob Beck
spamlogd not only needs to be running, but it needs to see the connections - your pf rules need to log them correctly. The best way to see if this is happening is to fire off some debug level syslogging, and see if spamlogd is logging lines for the hosts that connect in. You should

Re: OpenBSD Install Goal

2007-09-13 Thread Bob Beck
> I hope one day soon OpenBSD will adopt a nice ncurses setup similar to > something like FreeBSD with ease to it. I don't think it's worth putting my efforts into. The current installer is about the easiest thing I have to deal with from AIX, 4 linux distributions, and FreeBSD. > As Op

Re: The Atheros story in much fewer words

2007-09-14 Thread Bob Beck
* Craig Skinner <[EMAIL PROTECTED]> [2007-09-14 02:58]: > Daniel Ouellet wrote: > > > >Look to me if a corporation wanted to kill the open source, they > >couldn't pick a better way to do it and here the GPL is walking right > >into it! Or may be some guys are well paid to create the problem and

Re: The Atheros story in much fewer words

2007-09-14 Thread Bob Beck
* Bob Beck [2007-09-14 08:14]: > * Craig Skinner <[EMAIL PROTECTED]> [2007-09-14 02:58]: > > Daniel Ouellet wrote: > Doesn't this simply sound like making free software developers > and users lose their freedoms and work they've authored? Who wins? > pr

Re: Sun Systems

2007-09-19 Thread Christopher Beck
-BEGIN PGP SIGNED MESSAGE- Hash: SHA1 Hi, i'm interested in that monitor. From where are you (country) and how much money would you want? Jonathan Lindsey wrote: > I have several old sun workstations that I'm going to get rid of. These > include many sparc classics, a sparc 4, 5, 10, and

Re: another spamd-setup question

2007-09-19 Thread Bob Beck
hat is, to the degree that it was ever useful. If you look at the > data, it contains entire /16s. Your choice, of course, but I would > personally not recommend any blacklists other than beck@'s freshly > trapped and agressively maintained list (uatraps in recent spamd.conf &

<    1   2   3   4   5   >