![]() |
|
OpenBSD Installation and Upgrading Installing and upgrading OpenBSD. |
![]() |
|
Thread Tools | Display Modes |
|
||||
![]()
Syspatch 1-2 are available for all architectures for OpenBSD 6.6.
http://www.openbsd.org/errata66.html
__________________
hitest |
|
|||
![]()
The third patch released: now for bgpd(8)!
|
|
|||
![]()
syspatch for OpenSMTPD : 2 patches, the 2d is very important about security system.
Gilles Chehade wrote: https://marc.info/?l=openbsd-tech&m=158025543830138&w=2 |
|
|||
![]()
An interesting review by Openwall team about OpenSMTPD "breaches":
https://www.openwall.com/lists/oss-s...y/2020/01/28/3 |
|
|||
![]() Quote:
|
|
|||
![]()
smtpd does not listen on an external interface in the default installation.
|
|
|||
![]()
Anatomy of OpenBSD's OpenSMTPD hijack hole: How a malicious sender address can lead to remote pwnage
Quote:
Last edited by gpatrick; 31st January 2020 at 03:46 AM. |
|
|||
![]() Quote:
|
|
||||
![]()
FWIW, gilles@ has published a post mortem on his blog:
https://poolp.org/posts/2020-01-30/o...ory-dissected/ |
|
|||
![]()
Didn't read all of it, but I'm still moving my mail server back to Plan 9 Upas - A Simpler Approach to Network Mail.
Erik Quanstrom also has a paper Scaling Upas about his work on nupas while at Coraid. Last edited by gpatrick; 1st February 2020 at 12:38 AM. |
|
|||
![]()
From https://poolp.org/posts/2020-01-30/o...ory-dissected/
Quote:
In my 'install.site" script I always use the following patch script snippet to configure non-root mail delivery: Code:
echo --- patch script for: aliases \( generated: Sun 2011-02-20 18:26 CET\) --- BEGIN # --- edit the following line if needed FILE=/etc/mail/aliases EXT="$(date "+%Y%m%d_%H%M%S")" patch -b -z ${EXT} -p0 ${FILE} <<END_OF_PATCH --- ORIG/aliases Sun Feb 20 03:20:19 2011 +++ NEW/aliases Sun Feb 20 17:13:19 2011 @@ -69,9 +69,9 @@ sshd: /dev/null # Well-known aliases -- these should be filled in! -# root: -# manager: -# dumper: +root: j65nko +manager: root +dumper: root # RFC 2142: NETWORK OPERATIONS MAILBOX NAMES abuse: root END_OF_PATCH echo --- patch script for: aliases --- END # -----------------
__________________
You don't need to be a genius to debug a pf.conf firewall ruleset, you just need the guts to run tcpdump |
|
|||
![]()
We continue with a new patch for OpenSMTPD, on 6.5, 6.6 and all archs.
Quote:
__________________
GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF 9EA2 B85E 9ADA C377 5E8E GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D 5B62 D0FF 7361 59BF 1733 Last edited by CiotBSD; 10th March 2020 at 11:34 PM. |
|
|||
![]()
A new patch for sysctl on 6.5, 6.6 and all archs:
Quote:
__________________
GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF 9EA2 B85E 9ADA C377 5E8E GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D 5B62 D0FF 7361 59BF 1733 |
|
|||
![]()
A new patch for 6.5, and 6.6, for UDP broadcast and multicast socket.
__________________
GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF 9EA2 B85E 9ADA C377 5E8E GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D 5B62 D0FF 7361 59BF 1733 |
|
|||
![]()
A new patch for the server dhcpd on 6.5, 6.6, into all supported architectures.
![]()
__________________
GPG:Fingerprint ed25519 : 072A 4DA2 8AFD 868D 74CF 9EA2 B85E 9ADA C377 5E8E GPG:Fingerprint rsa4096 : 4E0D 4AF7 77F5 0FAE A35D 5B62 D0FF 7361 59BF 1733 |
![]() |
Thread Tools | |
Display Modes | |
|
|
![]() |
||||
Thread | Thread Starter | Forum | Replies | Last Post |
Restrict doas.conf to syspatch only | bsd007 | OpenBSD Security | 19 | 19th October 2018 01:05 AM |
syspatch cron job | bsdsource | OpenBSD General | 4 | 29th June 2018 04:05 PM |
syspatch on only two architectures? | pawkolor | OpenBSD General | 9 | 22nd October 2017 05:39 PM |
syspatch appears to get stuck | Prevet | OpenBSD Installation and Upgrading | 1 | 9th October 2017 07:37 PM |