Re: SAD DNS cache poisoning attack

2020-11-14 Thread Baptiste Jonglez
On 15-11-20, Baptiste Jonglez wrote: > There are two solutions to fix/workaround the problem: > > 1) randomize ICMP rate limiting (done in upstream kernel, there are >already OpenWrt patches to update it) I just checked, here are stable kernel versions containing the fix: - 4.9.241 - 4.14.20

SAD DNS cache poisoning attack

2020-11-14 Thread Baptiste Jonglez
Hi, There is a new generic cache poisoning attack for DNS: https://www.saddns.net/ It's a bit tricky, but the general idea is that an attacker can guess the ephemeral port used by a DNS resolver make a DNS query (that's dnsmasq in our case). The attacker then "just" has to guess the transaction

[no subject]

2020-11-14 Thread Filip Moc via openwrt-devel
The sender domain has a DMARC Reject/Quarantine policy which disallows sending mailing list messages using the original "From" header. To mitigate this problem, the original message has been wrapped automatically by the mailing list software.--- Begin Message --- You can flash via tftp recovery:

[no subject]

2020-11-14 Thread Filip Moc via openwrt-devel
The sender domain has a DMARC Reject/Quarantine policy which disallows sending mailing list messages using the original "From" header. To mitigate this problem, the original message has been wrapped automatically by the mailing list software.--- Begin Message --- This is required for LTE module MR

[no subject]

2020-11-14 Thread Filip Moc via openwrt-devel
The sender domain has a DMARC Reject/Quarantine policy which disallows sending mailing list messages using the original "From" header. To mitigate this problem, the original message has been wrapped automatically by the mailing list software.--- Begin Message --- This is required for LTE module MR

[no subject]

2020-11-14 Thread Filip Moc via openwrt-devel
The sender domain has a DMARC Reject/Quarantine policy which disallows sending mailing list messages using the original "From" header. To mitigate this problem, the original message has been wrapped automatically by the mailing list software.--- Begin Message --- There already was an option for au

[PATCH] valgrind: Update to version 3.16.1

2020-11-14 Thread Hauke Mehrtens
No special changes, just get in sync with recent code. See here for the changelog: https://valgrind.org/docs/manual/dist.news.html Signed-off-by: Hauke Mehrtens --- package/devel/valgrind/Makefile | 6 +++--- .../devel/valgrind/patches/100-fix_configure_check.patch

[PATCH] strace: Update to version 5.9

2020-11-14 Thread Hauke Mehrtens
No special changes, just get in sync with recent code. See here for the changelog: https://github.com/strace/strace/releases/tag/v5.9 Signed-off-by: Hauke Mehrtens --- package/devel/strace/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/devel/strace/Makef

[PATCH] iperf3: Update to version 3.9

2020-11-14 Thread Hauke Mehrtens
No special changes, just get in sync with recent code. See here for the changelog: http://software.es.net/iperf/news.html#iperf-3-9-released Signed-off-by: Hauke Mehrtens --- package/network/utils/iperf3/Makefile | 4 ++-- 1 file changed, 2 insertions(+), 2 deletions(-) diff --git a/package/net

Re: Wireless Battle of the Mesh with OpenWrt talks this weekend

2020-11-14 Thread Hauke Mehrtens
On 11/11/20 12:38 AM, Hauke Mehrtens wrote: OpenWrt supports this year's "Wireless Battle of the Mesh - Virtual Global Edition". The event aims to virtually bring together people from across the globe who are interested in community networks, including wireless mesh network technologies, fibe

[PATCH] dropbear: update to 2.81

2020-11-14 Thread Hans Dedecker
Update dropbear to latest stable 2.81; for the changes see https://matt.ucc.asn.au/dropbear/CHANGES Refresh patches Signed-off-by: Hans Dedecker --- package/network/services/dropbear/Makefile | 6 +++--- .../network/services/dropbear/patches/110-change_user.patch | 2 +- .../s

Re: Upcoming 19.07.4 and 18.07.9 stable releases

2020-11-14 Thread Jo-Philipp Wich
Hi, > Are there any real blockers left? LuCI support for bridge-vlan config is unmerged/unpolished yet. I'd rather not ship 20.x without functioning switch config support in the ui. ~ Jo signature.asc Description: OpenPGP digital signature ___ open

Re: Download server is down?

2020-11-14 Thread Torbjorn Jansson
On 2020-11-14 09:58, Hannu Nyman wrote: Looks like the download server is down, or at least has major trouble (with the backend?). There are several forum discussions about errors like 504 Gateway Time-out 502 Bad Gateway https://downloads.openwrt.org/releases/ Had the same issue but it

RE: RE: Upcoming 19.07.4 and 18.07.9 stable releases

2020-11-14 Thread Adrian Schmutzler
> -Original Message- > From: openwrt-devel [mailto:openwrt-devel-boun...@lists.openwrt.org] > On Behalf Of Hannu Nyman > Sent: Samstag, 14. November 2020 10:08 > To: openwrt-devel@lists.openwrt.org > Subject: Re: RE: Upcoming 19.07.4 and 18.07.9 stable releases > > I wonder why there seems

Re: Upcoming 19.07.4 and 18.07.9 stable releases

2020-11-14 Thread Bjørn Mork
Hannu Nyman writes: > I wonder why there seems to be practically no discussion about > preparations for the 20.0x release (or actually 20.1x now...). > > I think that last time it was mentioned in August: > > http://lists.openwrt.org/pipermail/openwrt-adm/2020-August/001639.html > > > Is there an

Re: RE: Upcoming 19.07.4 and 18.07.9 stable releases

2020-11-14 Thread Hannu Nyman
I wonder why there seems to be practically no discussion about preparations for the 20.0x release (or actually 20.1x now...). I think that last time it was mentioned in August: http://lists.openwrt.org/pipermail/openwrt-adm/2020-August/001639.html Is there any hope for a release, or will 2020

Download server is down?

2020-11-14 Thread Hannu Nyman
Looks like the download server is down, or at least has major trouble (with the backend?). There are several forum discussions about errors like 504 Gateway Time-out 502 Bad Gateway https://downloads.openwrt.org/releases/ ___ openwrt-devel maili