<?xml version="1.0" encoding="utf-8"?>
<feed xmlns="http://www.w3.org/2005/Atom">
	<id>tag:old.nabble.com,2006:forum-6620</id>
	<title>Nabble - freebsd-security</title>
	<updated>2009-12-01T05:14:57Z</updated>
	<link rel="self" type="application/atom+xml" href="http://old.nabble.com/freebsd-security-f6620.xml" />
	<link rel="alternate" type="text/html" href="http://old.nabble.com/freebsd-security-f6620.html" />
	<subtitle type="html">Security issues [members-only posting]</subtitle>
	
<entry>
	<id>tag:old.nabble.com,2006:post-26591546</id>
	<title>Re: rtld.patch -- effects on running system.</title>
	<published>2009-12-01T05:14:57Z</published>
	<updated>2009-12-01T05:14:57Z</updated>
	<author>
		<name>Dag-Erling Smørgrav</name>
	</author>
	<content type="html">Rudy Rucker &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591546&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rudy@...&lt;/a&gt;&amp;gt; writes:
&lt;br&gt;&amp;gt; Causes lots of things to freeze up or crash (example: apache /
&lt;br&gt;&amp;gt; mysql). 
&lt;br&gt;&lt;br&gt;That's... &amp;nbsp;strange. &amp;nbsp;I'm sure there is a good explanation, though.
&lt;br&gt;&lt;br&gt;I would just reboot the system after applying the patch.
&lt;br&gt;&lt;br&gt;&amp;gt; Now, how do I go about updating /libexec/ld-elf32.so.1 &amp;nbsp;(I am on an
&lt;br&gt;&amp;gt; amd64 box, FreeBSD 7.x)?
&lt;br&gt;&lt;br&gt;# make buildworld &amp;&amp; make installworld &amp;&amp; shutdown -r now new world
&lt;br&gt;&lt;br&gt;DES
&lt;br&gt;-- 
&lt;br&gt;Dag-Erling Smørgrav - &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591546&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;des@...&lt;/a&gt;
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591546&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591546&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/rtld.patch----effects-on-running-system.-tp26591090p26591546.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26591525</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-12-01T05:12:02Z</published>
	<updated>2009-12-01T05:12:02Z</updated>
	<author>
		<name>Dag-Erling Smørgrav</name>
	</author>
	<content type="html">Alex Huth &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591525&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;a.huth@...&lt;/a&gt;&amp;gt; writes:
&lt;br&gt;&amp;gt; I am new to patching systems, so forgive &amp;quot;stupid&amp;quot; questions. We have
&lt;br&gt;&amp;gt; some 6.1 systems. Are or will there be a patch for them or are they
&lt;br&gt;&amp;gt; not involved in this problem?
&lt;br&gt;&lt;br&gt;Support for 6.1 ended one and a half years ago (almost to the day), so
&lt;br&gt;no to the first part of your question. &amp;nbsp;As to the second: yes, 6.1 is
&lt;br&gt;most likely affected.
&lt;br&gt;&lt;br&gt;There is a good chance (but no guarantee) that the patch for 6.3 will
&lt;br&gt;apply cleanly on 6.1. &amp;nbsp;The security advisory will contain instructions
&lt;br&gt;on how to apply and deploy the patch.
&lt;br&gt;&lt;br&gt;&amp;gt; How do i apply such a patch? With freebsd-update? As far as i know is
&lt;br&gt;&amp;gt; this tool only for systems &amp;gt;= 6.3 or?
&lt;br&gt;&lt;br&gt;freebsd-update will work on 6.3 since 6.3 is still supported (until the
&lt;br&gt;end of January).
&lt;br&gt;&lt;br&gt;DES
&lt;br&gt;-- 
&lt;br&gt;Dag-Erling Smørgrav - &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591525&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;des@...&lt;/a&gt;
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591525&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591525&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26591525.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26590944</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-12-01T04:26:52Z</published>
	<updated>2009-12-01T04:26:52Z</updated>
	<author>
		<name>Dan Lukes</name>
	</author>
	<content type="html">Jan Muenther napsal/wrote, On 12/01/09 12:53:
&lt;br&gt;&amp;gt; I'd be greatly surprised if the affected code looked different in 6.x.
&lt;br&gt;&lt;br&gt;True, affected code is same. But unsetenv() &amp;quot;return&amp;quot; 'void' on 6.x, so 
&lt;br&gt;the code can't be patched the same way as in 7.x/8.x/HEAD
&lt;br&gt;&lt;br&gt;We need something like
&lt;br&gt;&lt;br&gt;if (getenv(...) != NULL ) {
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; unsetenv(...);
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; if (getenv(...) != NULL )
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; ABORT - BROKEN ENVIRONMENT
&lt;br&gt;}
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Dan
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26590944&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26590944&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26590944.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26590764</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-12-01T03:53:47Z</published>
	<updated>2009-12-01T03:53:47Z</updated>
	<author>
		<name>Jan Münther</name>
	</author>
	<content type="html">Hi,
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; I am new to patching systems, so forgive &amp;quot;stupid&amp;quot; questions. We have some 6.1
&lt;br&gt;&amp;gt; systems. Are or will there be a patch for them or are they not involved in
&lt;br&gt;&amp;gt; this problem?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I am new to patching systems, so forgive me any stupid questions. We have some
&lt;br&gt;&amp;gt; 6.1 and 6.3 systems. Are or will there be patches fro them or are they not
&lt;br&gt;&amp;gt; involved in this problem?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; How do i apply such a patch? With freebsd-update? As far as i know is this
&lt;br&gt;&amp;gt; tool only for systems &amp;gt;= 6.3 or?
&lt;br&gt;&amp;gt; &amp;nbsp; 
&lt;/div&gt;Patches are patches for the source code, so you'll have to apply them
&lt;br&gt;with the patch(1) program and then re-compile.
&lt;br&gt;I'd be greatly surprised if the affected code looked different in 6.x.
&lt;br&gt;&lt;br&gt;The bug itself is fairly interesting actually, if only for the reason
&lt;br&gt;that it displays what can happen if you don't check return values -
&lt;br&gt;other prime example of this causing security issues that I can think of
&lt;br&gt;off the top of my head are Windows impersonation bugs.
&lt;br&gt;&lt;br&gt;stealth wrote this up:
&lt;br&gt;&lt;a href=&quot;http://xorl.wordpress.com/2009/12/01/freebsd-ld_preload-security-bypass/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://xorl.wordpress.com/2009/12/01/freebsd-ld_preload-security-bypass/&lt;/a&gt;&lt;br&gt;&lt;br&gt;Maybe that sheds some light.
&lt;br&gt;&lt;br&gt;Cheers,
&lt;br&gt;Jan
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26590764&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26590764&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26590764.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26590561</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-12-01T03:16:27Z</published>
	<updated>2009-12-01T03:16:27Z</updated>
	<author>
		<name>Alex Huth-3</name>
	</author>
	<content type="html">* Eygene Ryabinkin schrieb:
&lt;br&gt;&amp;gt; Colin, *, good day.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Tue, Dec 01, 2009 at 01:20:45AM +0000, FreeBSD Security Officer wrote:
&lt;br&gt;&amp;gt; &amp;gt; A short time ago a &amp;quot;local root&amp;quot; exploit was posted to the full-disclosure
&lt;br&gt;&amp;gt; &amp;gt; mailing list; as the name suggests, this allows a local user to execute
&lt;br&gt;&amp;gt; &amp;gt; arbitrary code as root.
&lt;br&gt;&lt;br&gt;I am new to patching systems, so forgive &amp;quot;stupid&amp;quot; questions. We have some 6.1
&lt;br&gt;systems. Are or will there be a patch for them or are they not involved in
&lt;br&gt;this problem?
&lt;br&gt;&lt;br&gt;I am new to patching systems, so forgive me any stupid questions. We have some
&lt;br&gt;6.1 and 6.3 systems. Are or will there be patches fro them or are they not
&lt;br&gt;involved in this problem?
&lt;br&gt;&lt;br&gt;How do i apply such a patch? With freebsd-update? As far as i know is this
&lt;br&gt;tool only for systems &amp;gt;= 6.3 or?
&lt;br&gt;&lt;br&gt;Thx
&lt;br&gt;&lt;br&gt;Alex
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26590561&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26590561&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26590561.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26588579</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-12-01T01:01:08Z</published>
	<updated>2009-12-01T01:01:08Z</updated>
	<author>
		<name>István-3</name>
	</author>
	<content type="html">yeah noexec /tmp is nice
&lt;br&gt;&lt;br&gt;cat /tmp/shellscript | bash
&lt;br&gt;&lt;br&gt;same with executables
&lt;br&gt;&lt;br&gt;It is good against level0 kiddies and bots
&lt;br&gt;&lt;br&gt;On Tue, Dec 1, 2009 at 4:28 AM, Bryan Drewery &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588579&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bryan@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Colin,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thank you so much for alerting us and providing a temporary patch. I had
&lt;br&gt;&amp;gt; a user attempt to use the public exploit today, but due to /tmp being
&lt;br&gt;&amp;gt; noexec, it failed. Luckily I caught him before he modified the script to
&lt;br&gt;&amp;gt; work though. Now I am patched and can sleep tonight :)
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks,
&lt;br&gt;&amp;gt; Bryan
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; FreeBSD Security Officer wrote:
&lt;br&gt;&amp;gt; &amp;gt; Hi all,
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; A short time ago a &amp;quot;local root&amp;quot; exploit was posted to the full-disclosure
&lt;br&gt;&amp;gt; &amp;gt; mailing list; as the name suggests, this allows a local user to execute
&lt;br&gt;&amp;gt; &amp;gt; arbitrary code as root.
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; Normally it is the policy of the FreeBSD Security Team to not publicly
&lt;br&gt;&amp;gt; &amp;gt; discuss security issues until an advisory is ready, but in this case
&lt;br&gt;&amp;gt; &amp;gt; since exploit code is already widely available I want to make a patch
&lt;br&gt;&amp;gt; &amp;gt; available ASAP. &amp;nbsp;Due to the short timeline, it is possible that this
&lt;br&gt;&amp;gt; &amp;gt; patch will not be the final version which is provided when an advisory
&lt;br&gt;&amp;gt; &amp;gt; is sent out; it is even possible (although highly doubtful) that this
&lt;br&gt;&amp;gt; &amp;gt; patch does not fully fix the issue or introduces new issues -- in short,
&lt;br&gt;&amp;gt; &amp;gt; use at your own risk (even more than usual).
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; The patch is at
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; &lt;a href=&quot;http://people.freebsd.org/~cperciva/rtld.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://people.freebsd.org/~cperciva/rtld.patch&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; and has SHA256 hash
&lt;br&gt;&amp;gt; &amp;gt; &amp;nbsp; ffcba0c20335dd83e9ac0d0e920faf5b4aedf366ee5a41f548b95027e3b770c1
&lt;br&gt;&amp;gt; &amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; I expect a full security advisory concerning this issue will go out on
&lt;br&gt;&amp;gt; &amp;gt; Wednesday December 2nd.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588579&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&amp;gt; &lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;&amp;gt; To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588579&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;quot;
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;the sun shines for all
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;http://l1xl1x.blogspot.com&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://l1xl1x.blogspot.com&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588579&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26588579&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26588579.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26587868</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-11-30T23:52:33Z</published>
	<updated>2009-11-30T23:52:33Z</updated>
	<author>
		<name>Eygene Ryabinkin-3</name>
	</author>
	<content type="html">Colin, *, good day.
&lt;br&gt;&lt;br&gt;Tue, Dec 01, 2009 at 01:20:45AM +0000, FreeBSD Security Officer wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; A short time ago a &amp;quot;local root&amp;quot; exploit was posted to the full-disclosure
&lt;br&gt;&amp;gt; mailing list; as the name suggests, this allows a local user to execute
&lt;br&gt;&amp;gt; arbitrary code as root.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; [...]
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The patch is at
&lt;br&gt;&amp;gt; &amp;nbsp; &lt;a href=&quot;http://people.freebsd.org/~cperciva/rtld.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://people.freebsd.org/~cperciva/rtld.patch&lt;/a&gt;&lt;br&gt;&amp;gt; and has SHA256 hash
&lt;br&gt;&amp;gt; &amp;nbsp; ffcba0c20335dd83e9ac0d0e920faf5b4aedf366ee5a41f548b95027e3b770c1
&lt;/div&gt;&lt;br&gt;Just to ease other's life: for 7.1 (and 7.0, but it seems to be at EoL
&lt;br&gt;now, so there is already no support for it), one should use another patch:
&lt;br&gt;-----
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://codelabs.ru/fbsd/patches/vulns/freebsd-7.0-rtld-unsetenv.diff&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://codelabs.ru/fbsd/patches/vulns/freebsd-7.0-rtld-unsetenv.diff&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;nbsp; SHA256 (freebsd-7.0-rtld-unsetenv.diff) = e5ebbea24073bf644d3bc0c1ba37674a387af656b4c7e583a564a83598930897
&lt;br&gt;&amp;nbsp; SHA1 (freebsd-7.0-rtld-unsetenv.diff) = 24a79be52be0ea00ed0ea279f25efbf597f9c850
&lt;br&gt;-----
&lt;br&gt;Actually, every system that has rtld.c with r190323 or lower, should
&lt;br&gt;use this variant -- clearing of LD_ELF_HINTS_PATH was introduced only
&lt;br&gt;in r190324.
&lt;br&gt;&lt;br&gt;&lt;br&gt;By the way, if people are using NO_DYNAMIC_ROOT and all setuid
&lt;br&gt;executables come from the system itself (no sudo and other stuff from
&lt;br&gt;ports or manual installations), such system is obviously safe from this
&lt;br&gt;issue -- no dynamic loading takes place. &amp;nbsp;I don't mean that people with
&lt;br&gt;such systems shouldn't upgrade, but they probably can do it with a least
&lt;br&gt;urgency.
&lt;br&gt;&lt;br&gt;Thanks for posting the patch!
&lt;br&gt;-- 
&lt;br&gt;Eygene
&lt;br&gt;&amp;nbsp;_ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;___ &amp;nbsp; &amp;nbsp; &amp;nbsp; _.--. &amp;nbsp; #
&lt;br&gt;&amp;nbsp;\`.|\..----...-'` &amp;nbsp; `-._.-'_.-'` &amp;nbsp; # &amp;nbsp;Remember that it is hard
&lt;br&gt;&amp;nbsp;/ &amp;nbsp;' ` &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; , &amp;nbsp; &amp;nbsp; &amp;nbsp; __.--' &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;to read the on-line manual
&lt;br&gt;&amp;nbsp;)/' _/ &amp;nbsp; &amp;nbsp; \ &amp;nbsp; `-_, &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;while single-stepping the kernel.
&lt;br&gt;&amp;nbsp;`-'&amp;quot; `&amp;quot;\_ &amp;nbsp;,_.-;_.-\_ ', &amp;nbsp;fsc/as &amp;nbsp; #
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;_.-'_./ &amp;nbsp; {_.' &amp;nbsp; ; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp; &amp;nbsp;-- FreeBSD Developers handbook
&lt;br&gt;&amp;nbsp; &amp;nbsp; {_.-``-' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {_/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26587868&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26587868&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26587868.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26591090</id>
	<title>rtld.patch -- effects on running system.</title>
	<published>2009-11-30T22:49:17Z</published>
	<updated>2009-11-30T22:49:17Z</updated>
	<author>
		<name>Rudy Rucker</name>
	</author>
	<content type="html">Regarding patch here:
&lt;br&gt;&amp;nbsp;&lt;a href=&quot;http://lists.freebsd.org/pipermail/freebsd-security/2009-December/005369.html&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/pipermail/freebsd-security/2009-December/005369.html&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;I am trying to patch running systems and find some interesting behavior...
&lt;br&gt;&lt;br&gt;This Process:
&lt;br&gt;&amp;nbsp;
&lt;br&gt;cd /usr/src/libexec/rtld-elf/
&lt;br&gt;fetch &lt;a href=&quot;http://people.freebsd.org/~cperciva/rtld.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://people.freebsd.org/~cperciva/rtld.patch&lt;/a&gt;&lt;br&gt;patch &amp;lt; rtld.patch
&lt;br&gt;make
&lt;br&gt;make install
&lt;br&gt;ls -l /libexec/ld-elf.so.1
&lt;br&gt;&lt;br&gt;Causes lots of things to freeze up or crash (example: apache / mysql). 
&lt;br&gt;Restarting those services gets them back online. &amp;nbsp;:)
&lt;br&gt;For example: /usr/local/etc/rc.d/mysql restart
&lt;br&gt;&lt;br&gt;&lt;br&gt;Now, how do I go about updating /libexec/ld-elf32.so.1 &amp;nbsp;(I am on an
&lt;br&gt;amd64 box, FreeBSD 7.x)?
&lt;br&gt;&lt;br&gt;Rudy
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591090&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26591090&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/rtld.patch----effects-on-running-system.-tp26591090p26591090.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26587375</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-11-30T21:21:51Z</published>
	<updated>2009-11-30T21:21:51Z</updated>
	<author>
		<name>Brett Glass</name>
	</author>
	<content type="html">At 06:20 PM 11/30/2009, FreeBSD Security Officer wrote:
&lt;br&gt;&lt;br&gt;&amp;gt;A short time ago a &amp;quot;local root&amp;quot; exploit was posted to the full-disclosure
&lt;br&gt;&amp;gt;mailing list; as the name suggests, this allows a local user to execute
&lt;br&gt;&amp;gt;arbitrary code as root.
&lt;br&gt;&lt;br&gt;Yargh. Thank you for catching this.
&lt;br&gt;&lt;br&gt;--Brett
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26587375&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26587375&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26587375.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26586681</id>
	<title>Re: Upcoming FreeBSD Security Advisory</title>
	<published>2009-11-30T20:28:58Z</published>
	<updated>2009-11-30T20:28:58Z</updated>
	<author>
		<name>Bryan Drewery-2</name>
	</author>
	<content type="html">Colin,
&lt;br&gt;&lt;br&gt;Thank you so much for alerting us and providing a temporary patch. I had
&lt;br&gt;a user attempt to use the public exploit today, but due to /tmp being
&lt;br&gt;noexec, it failed. Luckily I caught him before he modified the script to
&lt;br&gt;work though. Now I am patched and can sleep tonight :)
&lt;br&gt;&lt;br&gt;Thanks,
&lt;br&gt;Bryan
&lt;br&gt;&lt;br&gt;FreeBSD Security Officer wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Hi all,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; A short time ago a &amp;quot;local root&amp;quot; exploit was posted to the full-disclosure
&lt;br&gt;&amp;gt; mailing list; as the name suggests, this allows a local user to execute
&lt;br&gt;&amp;gt; arbitrary code as root.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Normally it is the policy of the FreeBSD Security Team to not publicly
&lt;br&gt;&amp;gt; discuss security issues until an advisory is ready, but in this case
&lt;br&gt;&amp;gt; since exploit code is already widely available I want to make a patch
&lt;br&gt;&amp;gt; available ASAP. &amp;nbsp;Due to the short timeline, it is possible that this
&lt;br&gt;&amp;gt; patch will not be the final version which is provided when an advisory
&lt;br&gt;&amp;gt; is sent out; it is even possible (although highly doubtful) that this
&lt;br&gt;&amp;gt; patch does not fully fix the issue or introduces new issues -- in short,
&lt;br&gt;&amp;gt; use at your own risk (even more than usual).
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The patch is at
&lt;br&gt;&amp;gt; &amp;nbsp; &lt;a href=&quot;http://people.freebsd.org/~cperciva/rtld.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://people.freebsd.org/~cperciva/rtld.patch&lt;/a&gt;&lt;br&gt;&amp;gt; and has SHA256 hash
&lt;br&gt;&amp;gt; &amp;nbsp; ffcba0c20335dd83e9ac0d0e920faf5b4aedf366ee5a41f548b95027e3b770c1
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; I expect a full security advisory concerning this issue will go out on
&lt;br&gt;&amp;gt; Wednesday December 2nd.
&lt;/div&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26586681&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26586681&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26586681.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26585111</id>
	<title>Upcoming FreeBSD Security Advisory</title>
	<published>2009-11-30T17:20:45Z</published>
	<updated>2009-11-30T17:20:45Z</updated>
	<author>
		<name>FreeBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;Hi all,
&lt;br&gt;&lt;br&gt;A short time ago a &amp;quot;local root&amp;quot; exploit was posted to the full-disclosure
&lt;br&gt;mailing list; as the name suggests, this allows a local user to execute
&lt;br&gt;arbitrary code as root.
&lt;br&gt;&lt;br&gt;Normally it is the policy of the FreeBSD Security Team to not publicly
&lt;br&gt;discuss security issues until an advisory is ready, but in this case
&lt;br&gt;since exploit code is already widely available I want to make a patch
&lt;br&gt;available ASAP. &amp;nbsp;Due to the short timeline, it is possible that this
&lt;br&gt;patch will not be the final version which is provided when an advisory
&lt;br&gt;is sent out; it is even possible (although highly doubtful) that this
&lt;br&gt;patch does not fully fix the issue or introduces new issues -- in short,
&lt;br&gt;use at your own risk (even more than usual).
&lt;br&gt;&lt;br&gt;The patch is at
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://people.freebsd.org/~cperciva/rtld.patch&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://people.freebsd.org/~cperciva/rtld.patch&lt;/a&gt;&lt;br&gt;and has SHA256 hash
&lt;br&gt;&amp;nbsp; ffcba0c20335dd83e9ac0d0e920faf5b4aedf366ee5a41f548b95027e3b770c1
&lt;br&gt;&lt;br&gt;I expect a full security advisory concerning this issue will go out on
&lt;br&gt;Wednesday December 2nd.
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.10 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAksUbjcACgkQFdaIBMps37LP9ACgljaYCfgVuhD2gd9Natpq4H/9
&lt;br&gt;i48An1mgl+Mih+AWN7J9KZ1rsiEU31IZ
&lt;br&gt;=MPXj
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Colin Percival
&lt;br&gt;Security Officer, FreeBSD | freebsd.org | The power to serve
&lt;br&gt;Founder / author, Tarsnap | tarsnap.com | Online backups for the truly paranoid
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26585111&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26585111&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Upcoming-FreeBSD-Security-Advisory-tp26585111p26585111.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26470875</id>
	<title>HEADS UP: removal of PECOFF support in RELENG_[67]</title>
	<published>2009-11-22T14:05:48Z</published>
	<updated>2009-11-22T14:05:48Z</updated>
	<author>
		<name>Bjoern A. Zeeb-2</name>
	</author>
	<content type="html">Hi,
&lt;br&gt;&lt;br&gt;I'd like to give you a heads up that I intend to also remove PECOFF
&lt;br&gt;support from the stable/7 and stable/6 branches. &amp;nbsp;PECOFF support is
&lt;br&gt;non-working and unmaintained in those FreeBSD releases and has lately
&lt;br&gt;still seen public security problems.
&lt;br&gt;&lt;br&gt;PECOFF support is already gone in the upcoming 8.0 RELEASE or the
&lt;br&gt;9-CURRENT development branch.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Should no valid complaints come up saying that someone needs (and
&lt;br&gt;actively uses *cough* PECOFF support on FreeBSD it'll be removed
&lt;br&gt;earliest Novemeber 29th 2009 00:00 UTC (in about one week).
&lt;br&gt;&lt;br&gt;&lt;br&gt;/bz
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Bjoern A. Zeeb &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It will not break if you know what you are doing.
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26470875&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26470875&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/HEADS-UP%3A-removal-of-PECOFF-support-in-RELENG_-67--tp26470875p26470875.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26428103</id>
	<title>Re: Openssl TLS Reneg &quot;Bug&quot;</title>
	<published>2009-11-19T07:19:34Z</published>
	<updated>2009-11-19T07:19:34Z</updated>
	<author>
		<name>Eygene Ryabinkin-3</name>
	</author>
	<content type="html">Tue, Nov 17, 2009 at 12:47:14PM +0100, Daniel wrote:
&lt;br&gt;&amp;gt; new here so sorry if I am missing any important points. I was
&lt;br&gt;&amp;gt; wondering#: &amp;nbsp; Does anyone know of the status of the &amp;quot;amended&amp;quot; openssl
&lt;br&gt;&amp;gt; packages for FreeBSD. I'd like to try running our site with &amp;quot;reneg
&lt;br&gt;&amp;gt; off&amp;quot;, but I can't seem to find any notion of this on freebsd sites ?
&lt;br&gt;&amp;gt; Any ideas, pointers ?
&lt;br&gt;&lt;br&gt;OpenSSL port was updated to 0.9.8l:
&lt;br&gt;&amp;nbsp; &lt;a href=&quot;http://www.freebsd.org/cgi/cvsweb.cgi/ports/security/openssl/Makefile?rev=1.158;content-type=text%2Fx-cvsweb-markup&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freebsd.org/cgi/cvsweb.cgi/ports/security/openssl/Makefile?rev=1.158;content-type=text%2Fx-cvsweb-markup&lt;/a&gt;&lt;br&gt;&lt;br&gt;OpenSSL in the base system wasn't patched, according to the
&lt;br&gt;svn.frebsd.org.
&lt;br&gt;-- 
&lt;br&gt;Eygene
&lt;br&gt;&amp;nbsp;_ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;___ &amp;nbsp; &amp;nbsp; &amp;nbsp; _.--. &amp;nbsp; #
&lt;br&gt;&amp;nbsp;\`.|\..----...-'` &amp;nbsp; `-._.-'_.-'` &amp;nbsp; # &amp;nbsp;Remember that it is hard
&lt;br&gt;&amp;nbsp;/ &amp;nbsp;' ` &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; , &amp;nbsp; &amp;nbsp; &amp;nbsp; __.--' &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;to read the on-line manual
&lt;br&gt;&amp;nbsp;)/' _/ &amp;nbsp; &amp;nbsp; \ &amp;nbsp; `-_, &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;while single-stepping the kernel.
&lt;br&gt;&amp;nbsp;`-'&amp;quot; `&amp;quot;\_ &amp;nbsp;,_.-;_.-\_ ', &amp;nbsp;fsc/as &amp;nbsp; #
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;_.-'_./ &amp;nbsp; {_.' &amp;nbsp; ; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp; &amp;nbsp;-- FreeBSD Developers handbook
&lt;br&gt;&amp;nbsp; &amp;nbsp; {_.-``-' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {_/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26428103&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26428103&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Openssl-TLS-Reneg-%22Bug%22-tp26388934p26428103.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26403545</id>
	<title>Re: Openssl TLS Reneg &quot;Bug&quot;</title>
	<published>2009-11-17T23:18:55Z</published>
	<updated>2009-11-17T23:18:55Z</updated>
	<author>
		<name>Matthew Seaman-2</name>
	</author>
	<content type="html">Daniel wrote:
&lt;br&gt;&amp;gt; Dear List,
&lt;br&gt;&amp;gt; new here so sorry if I am missing any important points. I was
&lt;br&gt;&amp;gt; wondering#: &amp;nbsp; Does anyone know of the status of the &amp;quot;amended&amp;quot; openssl
&lt;br&gt;&amp;gt; packages for FreeBSD. I'd like to try running our site with &amp;quot;reneg
&lt;br&gt;&amp;gt; off&amp;quot;, but I can't seem to find any notion of this on freebsd sites ?
&lt;br&gt;&amp;gt; Any ideas, pointers ?
&lt;br&gt;&lt;br&gt;The only way of doing that at present is to use openssl-0.9.8l which
&lt;br&gt;has simply had the renegotiation stuff diked out of it. &amp;nbsp;That's available
&lt;br&gt;as the security/openssl port, but be aware that you will have to 
&lt;br&gt;rebuild any SSL-aware application to link against the shlibs it
&lt;br&gt;installs.
&lt;br&gt;&lt;br&gt;The fix in 0.9.8l is an interim measure which cripples certain openssl
&lt;br&gt;functionality: installing it may cause websites to malfunction, so make
&lt;br&gt;sure you have good backups and have thought about how you can back the
&lt;br&gt;change out if needed.
&lt;br&gt;&lt;br&gt;openssl-0.9.8m will provide the corrected renegotiation mechanisms as
&lt;br&gt;described in 
&lt;br&gt;&lt;br&gt;&lt;a href=&quot;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;https://svn.resiprocate.org/rep/ietf-drafts/ekr/draft-rescorla-tls-renegotiate.txt&lt;/a&gt;&lt;br&gt;&lt;br&gt;However, 0.9.8m has not yet been released. &amp;nbsp;I'd assume that this will
&lt;br&gt;probably be the subject of a FreeBSD Security Advisory once the fixes
&lt;br&gt;are available, and that supported FreeBSD branches will be updated to
&lt;br&gt;0.9.8m or otherwise patched to the same effect in the base system.
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Cheers,
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Matthew
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Dr Matthew J Seaman MA, D.Phil. &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; 7 Priory Courtyard
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Flat 3
&lt;br&gt;PGP: &lt;a href=&quot;http://www.infracaninophile.co.uk/pgpkey&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.infracaninophile.co.uk/pgpkey&lt;/a&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;Ramsgate
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; Kent, CT11 9PW
&lt;br&gt;&lt;br&gt;&lt;br /&gt; &lt;div class=&quot;small&quot;&gt;&lt;br/&gt;&lt;img src=&quot;http://old.nabble.com/images/icon_attachment.gif&quot; &gt; &lt;strong&gt;signature.asc&lt;/strong&gt; (267 bytes) &lt;a href=&quot;http://old.nabble.com/attachment/26403545/0/signature.asc&quot; target=&quot;_top&quot;&gt;Download Attachment&lt;/a&gt;&lt;/div&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Openssl-TLS-Reneg-%22Bug%22-tp26388934p26403545.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26388934</id>
	<title>Openssl TLS Reneg &quot;Bug&quot;</title>
	<published>2009-11-17T03:47:14Z</published>
	<updated>2009-11-17T03:47:14Z</updated>
	<author>
		<name>Daniel Amthor-2</name>
	</author>
	<content type="html">Dear List,
&lt;br&gt;new here so sorry if I am missing any important points. I was
&lt;br&gt;wondering#: &amp;nbsp; Does anyone know of the status of the &amp;quot;amended&amp;quot; openssl
&lt;br&gt;packages for FreeBSD. I'd like to try running our site with &amp;quot;reneg
&lt;br&gt;off&amp;quot;, but I can't seem to find any notion of this on freebsd sites ?
&lt;br&gt;Any ideas, pointers ?
&lt;br&gt;Best
&lt;br&gt;Daniel
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26388934&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26388934&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Openssl-TLS-Reneg-%22Bug%22-tp26388934p26388934.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26314690</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T23:45:16Z</published>
	<updated>2009-11-11T23:45:16Z</updated>
	<author>
		<name>Damian Weber</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;On Wed, 11 Nov 2009, Eygene Ryabinkin wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Date: Wed, 11 Nov 2009 22:37:44 +0300
&lt;br&gt;&amp;gt; From: Eygene Ryabinkin &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rea-fbsd@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: Damian Weber &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dweber@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cc: Bjoern A. Zeeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bzeeb-lists@...&lt;/a&gt;&amp;gt;,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wkoszek@...&lt;/a&gt;,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Oliver Pinter &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oliver.pntr@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Subject: Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Service &amp;nbsp;Exploit 23 R D Shaun Colley
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Wed, Nov 11, 2009 at 07:14:48PM +0100, Damian Weber wrote:
&lt;br&gt;&amp;gt; &amp;gt; FWIW, I got another result on 6.4-STABLE
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; FreeBSD mymachine.local 6.4-STABLE FreeBSD 6.4-STABLE #6: Sat Oct &amp;nbsp;3 13:06:12 CEST 2009 &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;root@...&lt;/a&gt;:/usr/obj/usr/src/sys/MYMACHINE &amp;nbsp;i386
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; $ ./pecoff
&lt;br&gt;&amp;gt; &amp;gt; MZaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa????aaaa
&lt;br&gt;&amp;gt; &amp;gt; [I'm truncating here, ~3500 a's follow]aaaaa: File name too long
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; You have no pecoff module loaded or compiled-in to the kernel,
&lt;br&gt;&amp;gt; aren't you? &amp;nbsp;Your &amp;quot;File name too long&amp;quot; is spitted by the shell,
&lt;br&gt;&amp;gt; so it was not handled by the PE loader at all.
&lt;/div&gt;&lt;br&gt;Confirmed. The code crashes the 6.4-stable machine when pecoff module 
&lt;br&gt;is loaded.
&lt;br&gt;&lt;br&gt;Wojciech A. Koszek wrote:
&lt;br&gt;&amp;gt; I think the best way would be to remove PECOFF from 6.x and 7.x.
&lt;br&gt;Now, I'm inclined to think that, too ;-)
&lt;br&gt;&lt;br&gt;-- Damian
&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26314690&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26314690.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26310929</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T15:07:27Z</published>
	<updated>2009-11-11T15:07:27Z</updated>
	<author>
		<name>Wojciech A. Koszek-4</name>
	</author>
	<content type="html">On Wed, Nov 11, 2009 at 05:37:50PM +0000, Bjoern A. Zeeb wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; On Mon, 20 Jul 2009, Oliver Pinter wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://milw0rm.com/exploits/9206&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://milw0rm.com/exploits/9206&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; has anyone actually been able to reproduce a problem scenario with
&lt;br&gt;&amp;gt; this on any supported releases (7.x or 6.x)?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The only thing I gould get from that was:
&lt;br&gt;&amp;gt; 	execve returned -1, errno=8: Exec format error
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Similar results applied to the scenario from
&lt;br&gt;&amp;gt; 	&lt;a href=&quot;http://www.freebsd.org/cgi/query-pr.cgi?pr=kern/80742&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freebsd.org/cgi/query-pr.cgi?pr=kern/80742&lt;/a&gt;&lt;br&gt;&amp;gt; which had been filed for a 5.x system by Wojciech A. Koszek long
&lt;br&gt;&amp;gt; before the above.
&lt;br&gt;&amp;gt;
&lt;/div&gt;&lt;br&gt;Hello,
&lt;br&gt;&lt;br&gt;This report has been lying in the PR database for a long time. I removed
&lt;br&gt;PECOFF from CURRENT some time ago, since absolutely noone was able to give
&lt;br&gt;any sensible argument for keeping PECOFF handler.
&lt;br&gt;&lt;br&gt;Because PECOFF has been introduced years before I became a commiter, I wasn't
&lt;br&gt;sure if MFC is a good idea back then. &amp;nbsp;The reason I didn't perform MFC to
&lt;br&gt;stable releases after &amp;quot;newer&amp;quot; report is our merge policy. I simply haven't yet
&lt;br&gt;studied it.
&lt;br&gt;&lt;br&gt;We can consider PECOFF bug as having &amp;quot;security implications&amp;quot;, but in order to
&lt;br&gt;make it &amp;quot;active&amp;quot;, someone has to study NOTES and enable this option. For the
&lt;br&gt;first glance I see that ports/ situation didn't change -- we seem to have 0
&lt;br&gt;ports requiring PECOFF to be present.
&lt;br&gt;&lt;br&gt;And I can't right now confirm whether the bug is still there -- I have no 6.x
&lt;br&gt;and 7.x systems for testing anymore.
&lt;br&gt;&lt;br&gt;If you want to try my code out (available in the PR), compile PECOFF -- I remember
&lt;br&gt;that I provided some sample case to panic the kernel.
&lt;br&gt;&lt;br&gt;I think the best way would be to remove PECOFF from 6.x and 7.x.
&lt;br&gt;&lt;br&gt;Thanks for CCing me.
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Wojciech A. Koszek
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26310929&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wkoszek@...&lt;/a&gt;
&lt;br&gt;&lt;a href=&quot;http://FreeBSD.czest.pl/~wkoszek/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://FreeBSD.czest.pl/~wkoszek/&lt;/a&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26310929&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26310929&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26310929.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26307250</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T11:37:44Z</published>
	<updated>2009-11-11T11:37:44Z</updated>
	<author>
		<name>Eygene Ryabinkin-3</name>
	</author>
	<content type="html">Wed, Nov 11, 2009 at 07:14:48PM +0100, Damian Weber wrote:
&lt;br&gt;&amp;gt; FWIW, I got another result on 6.4-STABLE
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; FreeBSD mymachine.local 6.4-STABLE FreeBSD 6.4-STABLE #6: Sat Oct &amp;nbsp;3 13:06:12 CEST 2009 &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307250&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;root@...&lt;/a&gt;:/usr/obj/usr/src/sys/MYMACHINE &amp;nbsp;i386
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; $ ./pecoff
&lt;br&gt;&amp;gt; MZaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaa????aaaa
&lt;br&gt;&amp;gt; [I'm truncating here, ~3500 a's follow]aaaaa: File name too long
&lt;br&gt;&lt;br&gt;You have no pecoff module loaded or compiled-in to the kernel,
&lt;br&gt;aren't you? &amp;nbsp;Your &amp;quot;File name too long&amp;quot; is spitted by the shell,
&lt;br&gt;so it was not handled by the PE loader at all.
&lt;br&gt;-- 
&lt;br&gt;Eygene
&lt;br&gt;&amp;nbsp;_ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;___ &amp;nbsp; &amp;nbsp; &amp;nbsp; _.--. &amp;nbsp; #
&lt;br&gt;&amp;nbsp;\`.|\..----...-'` &amp;nbsp; `-._.-'_.-'` &amp;nbsp; # &amp;nbsp;Remember that it is hard
&lt;br&gt;&amp;nbsp;/ &amp;nbsp;' ` &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; , &amp;nbsp; &amp;nbsp; &amp;nbsp; __.--' &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;to read the on-line manual
&lt;br&gt;&amp;nbsp;)/' _/ &amp;nbsp; &amp;nbsp; \ &amp;nbsp; `-_, &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;while single-stepping the kernel.
&lt;br&gt;&amp;nbsp;`-'&amp;quot; `&amp;quot;\_ &amp;nbsp;,_.-;_.-\_ ', &amp;nbsp;fsc/as &amp;nbsp; #
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;_.-'_./ &amp;nbsp; {_.' &amp;nbsp; ; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp; &amp;nbsp;-- FreeBSD Developers handbook
&lt;br&gt;&amp;nbsp; &amp;nbsp; {_.-``-' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {_/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307250&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307250&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26307250.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26307017</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T11:22:11Z</published>
	<updated>2009-11-11T11:22:11Z</updated>
	<author>
		<name>Damian Weber</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;On Wed, 11 Nov 2009, Bjoern A. Zeeb wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Date: Wed, 11 Nov 2009 18:59:24 +0000 (UTC)
&lt;br&gt;&amp;gt; From: Bjoern A. Zeeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bzeeb-lists@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: Damian Weber &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;dweber@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wkoszek@...&lt;/a&gt;,
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Oliver Pinter &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oliver.pntr@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Subject: Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Service &amp;nbsp;Exploit 23 R D Shaun Colley
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Wed, 11 Nov 2009, Damian Weber wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; On Wed, 11 Nov 2009, Bjoern A. Zeeb wrote:
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Date: Wed, 11 Nov 2009 17:37:50 +0000 (UTC)
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; From: Bjoern A. Zeeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bzeeb-lists@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; To: Oliver Pinter &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oliver.pntr@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=7&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=8&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wkoszek@...&lt;/a&gt;
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Subject: Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;nbsp; &amp;nbsp; Service &amp;nbsp;Exploit 23 R D Shaun Colley
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; On Mon, 20 Jul 2009, Oliver Pinter wrote:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; Hi,
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; &amp;gt; &lt;a href=&quot;http://milw0rm.com/exploits/9206&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://milw0rm.com/exploits/9206&lt;/a&gt;&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; has anyone actually been able to reproduce a problem scenario with
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; this on any supported releases (7.x or 6.x)?
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; The only thing I gould get from that was:
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 	execve returned -1, errno=8: Exec format error
&lt;br&gt;&amp;gt; &amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; FWIW, I got another result on 6.4-STABLE
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; FreeBSD mymachine.local 6.4-STABLE FreeBSD 6.4-STABLE #6: Sat Oct &amp;nbsp;3
&lt;br&gt;&amp;gt; &amp;gt; 13:06:12 CEST 2009 &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=9&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;root@...&lt;/a&gt;:/usr/obj/usr/src/sys/MYMACHINE
&lt;br&gt;&amp;gt; &amp;gt; i386
&lt;br&gt;&amp;gt; &amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; $ ./pecoff
&lt;br&gt;&amp;gt; &amp;gt; MZaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaîîîîaaaa
&lt;br&gt;&amp;gt; &amp;gt; [I'm truncating here, ~3500 a's follow]aaaaa: File name too long
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Not sure if you'd see it with ktrace or not; &amp;nbsp;I ran into that with my
&lt;br&gt;&amp;gt; tests as well and was told that it's a shell problem.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; try to run it from this:
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;br&gt;&amp;gt; #include &amp;lt;unistd.h&amp;gt;
&lt;br&gt;&amp;gt; #include &amp;lt;err.h&amp;gt;
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; int
&lt;br&gt;&amp;gt; main(int argc, char *argv[])
&lt;br&gt;&amp;gt; {
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 	if (execl(&amp;quot;./pecoff&amp;quot;, &amp;quot;./pecoff&amp;quot;, NULL) == -1)
&lt;br&gt;&amp;gt; 		err(1, &amp;quot;execl()&amp;quot;);
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; 	return (0);
&lt;br&gt;&amp;gt; }
&lt;br&gt;&amp;gt; ------------------------------------------------------------------------
&lt;/div&gt;&lt;/div&gt;execl() and /usr/local/bin/bash (bash-3.2.48_1) produce same result 
&lt;br&gt;&lt;br&gt;ktrace/kdump show
&lt;br&gt;&lt;br&gt;...
&lt;br&gt;&amp;nbsp;2380 pecoff &amp;nbsp; CALL &amp;nbsp;open(0x8048764,0x1,0)
&lt;br&gt;&amp;nbsp;2380 pecoff &amp;nbsp; NAMI &amp;nbsp;&amp;quot;evilprog.exe&amp;quot;
&lt;br&gt;&amp;nbsp;2380 pecoff &amp;nbsp; RET &amp;nbsp; open 3
&lt;br&gt;&amp;nbsp;2380 pecoff &amp;nbsp; CALL &amp;nbsp;write(0x3,0xbfbfce80,0xfe0)
&lt;br&gt;&amp;nbsp;2380 pecoff &amp;nbsp; GIO &amp;nbsp; fd 3 wrote 4064 bytes
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x0000 4d5a 6161 6161 6161 6161 6161 6161 6161 6161 &amp;nbsp;|MZaaaaaaaaaaaaaaaa|
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;0x0012 6161 6161 6161 6161 6161 6161 6161 6161 6161 &amp;nbsp;|aaaaaaaaaaaaaaaaaa|
&lt;br&gt;...
&lt;br&gt;&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=10&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26307017&amp;i=11&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26307017.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26306697</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T10:59:24Z</published>
	<updated>2009-11-11T10:59:24Z</updated>
	<author>
		<name>Bjoern A. Zeeb</name>
	</author>
	<content type="html">On Wed, 11 Nov 2009, Damian Weber wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; On Wed, 11 Nov 2009, Bjoern A. Zeeb wrote:
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Date: Wed, 11 Nov 2009 17:37:50 +0000 (UTC)
&lt;br&gt;&amp;gt;&amp;gt; From: Bjoern A. Zeeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bzeeb-lists@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; To: Oliver Pinter &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oliver.pntr@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wkoszek@...&lt;/a&gt;
&lt;br&gt;&amp;gt;&amp;gt; Subject: Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of
&lt;br&gt;&amp;gt;&amp;gt; &amp;nbsp; &amp;nbsp; Service &amp;nbsp;Exploit 23 R D Shaun Colley
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; On Mon, 20 Jul 2009, Oliver Pinter wrote:
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://milw0rm.com/exploits/9206&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://milw0rm.com/exploits/9206&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; has anyone actually been able to reproduce a problem scenario with
&lt;br&gt;&amp;gt;&amp;gt; this on any supported releases (7.x or 6.x)?
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; The only thing I gould get from that was:
&lt;br&gt;&amp;gt;&amp;gt; 	execve returned -1, errno=8: Exec format error
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; FWIW, I got another result on 6.4-STABLE
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; FreeBSD mymachine.local 6.4-STABLE FreeBSD 6.4-STABLE #6: Sat Oct &amp;nbsp;3 13:06:12 CEST 2009 &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;root@...&lt;/a&gt;:/usr/obj/usr/src/sys/MYMACHINE &amp;nbsp;i386
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; $ ./pecoff
&lt;br&gt;&amp;gt; MZaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaîîîîaaaa
&lt;br&gt;&amp;gt; [I'm truncating here, ~3500 a's follow]aaaaa: File name too long
&lt;/div&gt;&lt;/div&gt;&lt;br&gt;Not sure if you'd see it with ktrace or not; &amp;nbsp;I ran into that with my
&lt;br&gt;tests as well and was told that it's a shell problem.
&lt;br&gt;&lt;br&gt;try to run it from this:
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;#include &amp;lt;unistd.h&amp;gt;
&lt;br&gt;#include &amp;lt;err.h&amp;gt;
&lt;br&gt;&lt;br&gt;int
&lt;br&gt;main(int argc, char *argv[])
&lt;br&gt;{
&lt;br&gt;&lt;br&gt;&amp;nbsp;	if (execl(&amp;quot;./pecoff&amp;quot;, &amp;quot;./pecoff&amp;quot;, NULL) == -1)
&lt;br&gt;&amp;nbsp;		err(1, &amp;quot;execl()&amp;quot;);
&lt;br&gt;&lt;br&gt;&amp;nbsp;	return (0);
&lt;br&gt;}
&lt;br&gt;------------------------------------------------------------------------
&lt;br&gt;&lt;br&gt;&lt;br&gt;/bz
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Bjoern A. Zeeb &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It will not break if you know what you are doing.&lt;br /&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306697&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26306697.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26306580</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T10:14:48Z</published>
	<updated>2009-11-11T10:14:48Z</updated>
	<author>
		<name>Damian Weber</name>
	</author>
	<content type="html">&lt;br&gt;&lt;br&gt;On Wed, 11 Nov 2009, Bjoern A. Zeeb wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Date: Wed, 11 Nov 2009 17:37:50 +0000 (UTC)
&lt;br&gt;&amp;gt; From: Bjoern A. Zeeb &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;bzeeb-lists@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; To: Oliver Pinter &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;oliver.pntr@...&lt;/a&gt;&amp;gt;
&lt;br&gt;&amp;gt; Cc: &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt;, &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;wkoszek@...&lt;/a&gt;
&lt;br&gt;&amp;gt; Subject: Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; Service &amp;nbsp;Exploit 23 R D Shaun Colley
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; On Mon, 20 Jul 2009, Oliver Pinter wrote:
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Hi,
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; &amp;gt; &lt;a href=&quot;http://milw0rm.com/exploits/9206&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://milw0rm.com/exploits/9206&lt;/a&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; has anyone actually been able to reproduce a problem scenario with
&lt;br&gt;&amp;gt; this on any supported releases (7.x or 6.x)?
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The only thing I gould get from that was:
&lt;br&gt;&amp;gt; 	execve returned -1, errno=8: Exec format error
&lt;br&gt;&amp;gt; 
&lt;/div&gt;&lt;/div&gt;FWIW, I got another result on 6.4-STABLE
&lt;br&gt;&lt;br&gt;FreeBSD mymachine.local 6.4-STABLE FreeBSD 6.4-STABLE #6: Sat Oct &amp;nbsp;3 13:06:12 CEST 2009 &amp;nbsp; &amp;nbsp; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=4&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;root@...&lt;/a&gt;:/usr/obj/usr/src/sys/MYMACHINE &amp;nbsp;i386
&lt;br&gt;&lt;br&gt;$ ./pecoff
&lt;br&gt;MZaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaaîîîîaaaa
&lt;br&gt;[I'm truncating here, ~3500 a's follow]aaaaa: File name too long
&lt;br&gt;&lt;br&gt;-- Damian
&lt;br&gt;&lt;br /&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=5&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26306580&amp;i=6&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26306580.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26305401</id>
	<title>Re: 2009-07-20 FreeBSD 7.2 (pecoff executable) Local Denial of Service  Exploit 23 R D Shaun Colley</title>
	<published>2009-11-11T09:37:50Z</published>
	<updated>2009-11-11T09:37:50Z</updated>
	<author>
		<name>Bjoern A. Zeeb</name>
	</author>
	<content type="html">On Mon, 20 Jul 2009, Oliver Pinter wrote:
&lt;br&gt;&lt;br&gt;Hi,
&lt;br&gt;&lt;br&gt;&amp;gt; &lt;a href=&quot;http://milw0rm.com/exploits/9206&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://milw0rm.com/exploits/9206&lt;/a&gt;&lt;br&gt;&lt;br&gt;has anyone actually been able to reproduce a problem scenario with
&lt;br&gt;this on any supported releases (7.x or 6.x)?
&lt;br&gt;&lt;br&gt;The only thing I gould get from that was:
&lt;br&gt;&amp;nbsp;	execve returned -1, errno=8: Exec format error
&lt;br&gt;&lt;br&gt;Similar results applied to the scenario from
&lt;br&gt;&amp;nbsp;	&lt;a href=&quot;http://www.freebsd.org/cgi/query-pr.cgi?pr=kern/80742&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.freebsd.org/cgi/query-pr.cgi?pr=kern/80742&lt;/a&gt;&lt;br&gt;which had been filed for a 5.x system by Wojciech A. Koszek long
&lt;br&gt;before the above.
&lt;br&gt;&lt;br&gt;/bz
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Bjoern A. Zeeb &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It will not break if you know what you are doing.
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26305401&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26305401&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/2009-07-20-FreeBSD-7.2-%28pecoff-executable%29-Local-Denial-of-Service--Exploit-23-R-D-Shaun-Colley-tp24574296p26305401.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26244937</id>
	<title>[patch] OpenSSL in base: fix CVE-2009-3555</title>
	<published>2009-11-07T05:43:47Z</published>
	<updated>2009-11-07T05:43:47Z</updated>
	<author>
		<name>Eygene Ryabinkin-3</name>
	</author>
	<content type="html">&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt;Submitter-Id:	current-users
&lt;br&gt;&amp;gt;Originator:	Eygene Ryabinkin
&lt;br&gt;&amp;gt;Organization:	Code Labs
&lt;br&gt;&amp;gt;Confidential:	no 
&lt;br&gt;&amp;gt;Synopsis:	[patch] OpenSSL in base: fix CVE-2009-3555
&lt;br&gt;&amp;gt;Severity:	critical
&lt;br&gt;&amp;gt;Priority:	high
&lt;br&gt;&amp;gt;Category:	bin
&lt;br&gt;&amp;gt;Class:		sw-bug
&lt;br&gt;&amp;gt;Release:	FreeBSD 8.0-BETA2 amd64
&lt;br&gt;&amp;gt;Environment:
&lt;/div&gt;&lt;br&gt;System: FreeBSD 8.0-BETA2 amd64
&lt;br&gt;&lt;br&gt;&amp;gt;Description:
&lt;br&gt;&lt;br&gt;See [1] (not much information just now) and [2].
&lt;br&gt;&lt;br&gt;&amp;gt;How-To-Repeat:
&lt;br&gt;&lt;br&gt;[1] &lt;a href=&quot;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2009-3555&lt;/a&gt;&lt;br&gt;[2] &lt;a href=&quot;http://cvs.openssl.org/fileview?f=openssl-web/news/announce.txt&amp;v=1.52&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.openssl.org/fileview?f=openssl-web/news/announce.txt&amp;v=1.52&lt;/a&gt;&lt;br&gt;&lt;br&gt;&amp;gt;Fix:
&lt;br&gt;&lt;br&gt;The following patch applies to OpenSSL both from HEAD and 8-STABLE.
&lt;br&gt;&lt;br&gt;It completely disables renegotiation inside TLS/SSL sessions and I had
&lt;br&gt;verified that no renegotiations will take place with s_client and
&lt;br&gt;s_server.
&lt;br&gt;&lt;br&gt;--- fix-cve-2009-3555.diff begins here ---
&lt;br&gt;&amp;gt;From 01c641ca1a88d08fea282f79ff0f1a86d5319ba7 Mon Sep 17 00:00:00 2001
&lt;br&gt;From: Eygene Ryabinkin &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26244937&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rea-fbsd@...&lt;/a&gt;&amp;gt;
&lt;br&gt;Date: Sat, 7 Nov 2009 15:45:32 +0300
&lt;br&gt;&lt;br&gt;Obtained-From: &lt;a href=&quot;http://cvs.openssl.org/chngview?cn=18791&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.openssl.org/chngview?cn=18791&lt;/a&gt;&lt;br&gt;Obtained-From: &lt;a href=&quot;http://cvs.openssl.org/chngview?cn=18794&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://cvs.openssl.org/chngview?cn=18794&lt;/a&gt;&lt;br&gt;&lt;br&gt;Signed-off-by: Eygene Ryabinkin &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26244937&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;rea-fbsd@...&lt;/a&gt;&amp;gt;
&lt;br&gt;---
&lt;br&gt;&amp;nbsp;crypto/openssl/CHANGES &amp;nbsp; &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp;9 +++++++++
&lt;br&gt;&amp;nbsp;crypto/openssl/ssl/s3_lib.c &amp;nbsp;| &amp;nbsp; &amp;nbsp;3 +++
&lt;br&gt;&amp;nbsp;crypto/openssl/ssl/s3_pkt.c &amp;nbsp;| &amp;nbsp; &amp;nbsp;4 +++-
&lt;br&gt;&amp;nbsp;crypto/openssl/ssl/s3_srvr.c | &amp;nbsp; &amp;nbsp;8 ++++++++
&lt;br&gt;&amp;nbsp;crypto/openssl/ssl/ssl.h &amp;nbsp; &amp;nbsp; | &amp;nbsp; &amp;nbsp;1 +
&lt;br&gt;&amp;nbsp;crypto/openssl/ssl/ssl3.h &amp;nbsp; &amp;nbsp;| &amp;nbsp; &amp;nbsp;9 +++++----
&lt;br&gt;&amp;nbsp;crypto/openssl/ssl/ssl_err.c | &amp;nbsp; &amp;nbsp;1 +
&lt;br&gt;&amp;nbsp;7 files changed, 30 insertions(+), 5 deletions(-)
&lt;br&gt;&lt;br&gt;diff --git a/crypto/openssl/CHANGES b/crypto/openssl/CHANGES
&lt;br&gt;index 04d332e..cd445c9 100644
&lt;br&gt;--- a/crypto/openssl/CHANGES
&lt;br&gt;+++ b/crypto/openssl/CHANGES
&lt;br&gt;@@ -2,6 +2,15 @@
&lt;br&gt;&amp;nbsp; OpenSSL CHANGES
&lt;br&gt;&amp;nbsp; _______________
&lt;br&gt;&amp;nbsp;
&lt;br&gt;+ Changes between 0.9.8k and 0.9.8l &amp;nbsp;[5 Nov 2009]
&lt;br&gt;+
&lt;br&gt;+ &amp;nbsp;*) Disable renegotiation completely - this fixes a severe security
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; problem at the cost of breaking all renegotiation. Renegotiation
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; can be re-enabled by setting
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; OPENSSL_ENABLE_UNSAFE_LEGACY_SESSION_RENEGOTATION at
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; compile-time. This is really not recommended.
&lt;br&gt;+ &amp;nbsp; &amp;nbsp; [Ben Laurie]
&lt;br&gt;+
&lt;br&gt;&amp;nbsp; Changes between 0.9.8j and 0.9.8k &amp;nbsp;[25 Mar 2009]
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp; &amp;nbsp;*) Don't set val to NULL when freeing up structures, it is freed up by
&lt;br&gt;diff --git a/crypto/openssl/ssl/s3_lib.c b/crypto/openssl/ssl/s3_lib.c
&lt;br&gt;index 8916a0b..5aa7bb2 100644
&lt;br&gt;--- a/crypto/openssl/ssl/s3_lib.c
&lt;br&gt;+++ b/crypto/openssl/ssl/s3_lib.c
&lt;br&gt;@@ -2592,6 +2592,9 @@ int ssl3_renegotiate(SSL *s)
&lt;br&gt;&amp;nbsp;	if (s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS)
&lt;br&gt;&amp;nbsp;		return(0);
&lt;br&gt;&amp;nbsp;
&lt;br&gt;+	if (!(s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION))
&lt;br&gt;+		return(0);
&lt;br&gt;+
&lt;br&gt;&amp;nbsp;	s-&amp;gt;s3-&amp;gt;renegotiate=1;
&lt;br&gt;&amp;nbsp;	return(1);
&lt;br&gt;&amp;nbsp;	}
&lt;br&gt;diff --git a/crypto/openssl/ssl/s3_pkt.c b/crypto/openssl/ssl/s3_pkt.c
&lt;br&gt;index 9476dcd..b98b840 100644
&lt;br&gt;--- a/crypto/openssl/ssl/s3_pkt.c
&lt;br&gt;+++ b/crypto/openssl/ssl/s3_pkt.c
&lt;br&gt;@@ -985,6 +985,7 @@ start:
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;		if (SSL_is_init_finished(s) &amp;&amp;
&lt;br&gt;&amp;nbsp;			!(s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS) &amp;&amp;
&lt;br&gt;+			(s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION) &amp;&amp;
&lt;br&gt;&amp;nbsp;			!s-&amp;gt;s3-&amp;gt;renegotiate)
&lt;br&gt;&amp;nbsp;			{
&lt;br&gt;&amp;nbsp;			ssl3_renegotiate(s);
&lt;br&gt;@@ -1117,7 +1118,8 @@ start:
&lt;br&gt;&amp;nbsp;	if ((s-&amp;gt;s3-&amp;gt;handshake_fragment_len &amp;gt;= 4) &amp;&amp;	!s-&amp;gt;in_handshake)
&lt;br&gt;&amp;nbsp;		{
&lt;br&gt;&amp;nbsp;		if (((s-&amp;gt;state&amp;SSL_ST_MASK) == SSL_ST_OK) &amp;&amp;
&lt;br&gt;-			!(s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS))
&lt;br&gt;+			!(s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS) &amp;&amp;
&lt;br&gt;+			(s-&amp;gt;s3-&amp;gt;flags &amp; SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION))
&lt;br&gt;&amp;nbsp;			{
&lt;br&gt;&amp;nbsp;#if 0 /* worked only because C operator preferences are not as expected (and
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; * because this is not really needed for clients except for detecting
&lt;br&gt;diff --git a/crypto/openssl/ssl/s3_srvr.c b/crypto/openssl/ssl/s3_srvr.c
&lt;br&gt;index 80b45eb..79f3706 100644
&lt;br&gt;--- a/crypto/openssl/ssl/s3_srvr.c
&lt;br&gt;+++ b/crypto/openssl/ssl/s3_srvr.c
&lt;br&gt;@@ -718,6 +718,14 @@ int ssl3_get_client_hello(SSL *s)
&lt;br&gt;&amp;nbsp;#endif
&lt;br&gt;&amp;nbsp;	STACK_OF(SSL_CIPHER) *ciphers=NULL;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;+	if (s-&amp;gt;new_session
&lt;br&gt;+	 &amp;nbsp; &amp;nbsp;&amp;&amp; !(s-&amp;gt;s3-&amp;gt;flags&amp;SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION))
&lt;br&gt;+		{
&lt;br&gt;+		al=SSL_AD_HANDSHAKE_FAILURE;
&lt;br&gt;+		SSLerr(SSL_F_SSL3_GET_CLIENT_HELLO, ERR_R_INTERNAL_ERROR);
&lt;br&gt;+		goto f_err;
&lt;br&gt;+		}
&lt;br&gt;+
&lt;br&gt;&amp;nbsp;	/* We do this so that we will respond with our native type.
&lt;br&gt;&amp;nbsp;	 * If we are TLSv1 and we get SSLv3, we will respond with TLSv1,
&lt;br&gt;&amp;nbsp;	 * This down switching should be handled by a different method.
&lt;br&gt;diff --git a/crypto/openssl/ssl/ssl.h b/crypto/openssl/ssl/ssl.h
&lt;br&gt;index ff8a128..5ef11a3 100644
&lt;br&gt;--- a/crypto/openssl/ssl/ssl.h
&lt;br&gt;+++ b/crypto/openssl/ssl/ssl.h
&lt;br&gt;@@ -1952,6 +1952,7 @@ void ERR_load_SSL_strings(void);
&lt;br&gt;&amp;nbsp;#define SSL_R_NO_PRIVATE_KEY_ASSIGNED			 190
&lt;br&gt;&amp;nbsp;#define SSL_R_NO_PROTOCOLS_AVAILABLE			 191
&lt;br&gt;&amp;nbsp;#define SSL_R_NO_PUBLICKEY				 192
&lt;br&gt;+#define SSL_R_NO_RENEGOTIATION				 318
&lt;br&gt;&amp;nbsp;#define SSL_R_NO_SHARED_CIPHER				 193
&lt;br&gt;&amp;nbsp;#define SSL_R_NO_VERIFY_CALLBACK			 194
&lt;br&gt;&amp;nbsp;#define SSL_R_NULL_SSL_CTX				 195
&lt;br&gt;diff --git a/crypto/openssl/ssl/ssl3.h b/crypto/openssl/ssl/ssl3.h
&lt;br&gt;index 4b1e2e9..a1a19cb 100644
&lt;br&gt;--- a/crypto/openssl/ssl/ssl3.h
&lt;br&gt;+++ b/crypto/openssl/ssl/ssl3.h
&lt;br&gt;@@ -326,10 +326,11 @@ typedef struct ssl3_buffer_st
&lt;br&gt;&amp;nbsp;#define SSL3_CT_NUMBER			7
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;
&lt;br&gt;-#define SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS	0x0001
&lt;br&gt;-#define SSL3_FLAGS_DELAY_CLIENT_FINISHED	0x0002
&lt;br&gt;-#define SSL3_FLAGS_POP_BUFFER			0x0004
&lt;br&gt;-#define TLS1_FLAGS_TLS_PADDING_BUG		0x0008
&lt;br&gt;+#define SSL3_FLAGS_NO_RENEGOTIATE_CIPHERS		0x0001
&lt;br&gt;+#define SSL3_FLAGS_DELAY_CLIENT_FINISHED		0x0002
&lt;br&gt;+#define SSL3_FLAGS_POP_BUFFER				0x0004
&lt;br&gt;+#define TLS1_FLAGS_TLS_PADDING_BUG			0x0008
&lt;br&gt;+#define SSL3_FLAGS_ALLOW_UNSAFE_LEGACY_RENEGOTIATION	0x0010
&lt;br&gt;&amp;nbsp;
&lt;br&gt;&amp;nbsp;typedef struct ssl3_state_st
&lt;br&gt;&amp;nbsp;	{
&lt;br&gt;diff --git a/crypto/openssl/ssl/ssl_err.c b/crypto/openssl/ssl/ssl_err.c
&lt;br&gt;index 24a994f..ce2a555 100644
&lt;br&gt;--- a/crypto/openssl/ssl/ssl_err.c
&lt;br&gt;+++ b/crypto/openssl/ssl/ssl_err.c
&lt;br&gt;@@ -384,6 +384,7 @@ static ERR_STRING_DATA SSL_str_reasons[]=
&lt;br&gt;&amp;nbsp;{ERR_REASON(SSL_R_NO_PRIVATE_KEY_ASSIGNED),&amp;quot;no private key assigned&amp;quot;},
&lt;br&gt;&amp;nbsp;{ERR_REASON(SSL_R_NO_PROTOCOLS_AVAILABLE),&amp;quot;no protocols available&amp;quot;},
&lt;br&gt;&amp;nbsp;{ERR_REASON(SSL_R_NO_PUBLICKEY) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;,&amp;quot;no publickey&amp;quot;},
&lt;br&gt;+{ERR_REASON(SSL_R_NO_RENEGOTIATION) &amp;nbsp; &amp;nbsp; &amp;nbsp;,&amp;quot;no renegotiation&amp;quot;},
&lt;br&gt;&amp;nbsp;{ERR_REASON(SSL_R_NO_SHARED_CIPHER) &amp;nbsp; &amp;nbsp; &amp;nbsp;,&amp;quot;no shared cipher&amp;quot;},
&lt;br&gt;&amp;nbsp;{ERR_REASON(SSL_R_NO_VERIFY_CALLBACK) &amp;nbsp; &amp;nbsp;,&amp;quot;no verify callback&amp;quot;},
&lt;br&gt;&amp;nbsp;{ERR_REASON(SSL_R_NULL_SSL_CTX) &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;,&amp;quot;null ssl ctx&amp;quot;},
&lt;br&gt;-- 
&lt;br&gt;1.6.3.1
&lt;br&gt;--- fix-cve-2009-3555.diff ends here ---
&lt;br&gt;&lt;br&gt;It will be very good if __FreeBSD_version will be bumped after this
&lt;br&gt;update, because there are some fixes for the ports that use OpenSSL,
&lt;br&gt;but disable renegotiation by themselves. &amp;nbsp;These fixes shouldn't be
&lt;br&gt;applied when system OpenSSL will be updated (port was already
&lt;br&gt;updated to 0.9.8k).
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26244937&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26244937&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/-patch--OpenSSL-in-base%3A-fix-CVE-2009-3555-tp26244937p26244937.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26077885</id>
	<title>Re: issue with outbound SA selection</title>
	<published>2009-10-27T06:33:47Z</published>
	<updated>2009-10-27T06:33:47Z</updated>
	<author>
		<name>Bjoern A. Zeeb</name>
	</author>
	<content type="html">On Tue, 27 Oct 2009, Naveen BN wrote:
&lt;br&gt;&lt;br&gt;Hi,
&lt;br&gt;&lt;br&gt;let me copy &amp; paste what I rpelied on bugs@ already.
&lt;br&gt;&lt;br&gt;&amp;gt; My Linux kernel version is 2.6.23.1-42.fc8
&lt;br&gt;&lt;br&gt;Unfortunately this is not a linux but a FreeBSD mailing list. &amp;nbsp;If your
&lt;br&gt;issue is with a FreeBSD kernel we can certainly help, if you are
&lt;br&gt;running a linux kernel I'd try the linux-ipsec list, which no longer
&lt;br&gt;seems to exist? A good fallback might be linux-net or linux-netdev or a
&lt;br&gt;similar list. &amp;nbsp;Good luck there.
&lt;br&gt;&lt;br&gt;/bz
&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;Bjoern A. Zeeb &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; It will not break if you know what you are doing.
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26077885&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26077885&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/issue-with-outbound-SA-selection-tp26076152p26077885.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26076152</id>
	<title>issue with outbound SA selection</title>
	<published>2009-10-27T03:59:06Z</published>
	<updated>2009-10-27T03:59:06Z</updated>
	<author>
		<name>naveen.bn</name>
	</author>
	<content type="html">Hi All,
&lt;br&gt;&lt;br&gt;I have a problem using SA with selectors based on &amp;lt;src IP&amp;gt;, &amp;lt;dest IP&amp;gt; 
&lt;br&gt;and &amp;lt;dst port&amp;gt; &amp;nbsp;for outbound traffic.
&lt;br&gt;I have written two out bound SA's for the same destination IP with 
&lt;br&gt;different destination port, but I am seeing
&lt;br&gt;wrong SA has been selected for outbound traffic. My concern is why the 
&lt;br&gt;SA is not getting selected based on
&lt;br&gt;ports &amp;nbsp;mentioned security &amp;nbsp;policy.
&lt;br&gt;&lt;br&gt;FYI..
&lt;br&gt;content of file setkey.conf
&lt;br&gt;/************************* start setkey.conf ************************/
&lt;br&gt;flush;
&lt;br&gt;spdflush;
&lt;br&gt;&lt;br&gt;add 172.16.8.36 172.16.8.38[*800]* esp 0x201 -m tunnel -E 3des-cbc
&lt;br&gt;0x7aeaca3f87d060a12f4a4487d5a5c3355920fae69a96c831
&lt;br&gt;-A hmac-md5 0xc0291ff014dccdd03874d9e8e4cdf3e6;
&lt;br&gt;&lt;br&gt;add 172.16.8.38[500] 172.16.8.36 esp 0x301 -m tunnel -E 3des-cbc
&lt;br&gt;0xf6ddb555acfd9d77b03ea3843f2653255afe8eb5573965df
&lt;br&gt;-A hmac-md5 0x96358c90783bbfa3d7b196ceabe0536b;
&lt;br&gt;&lt;br&gt;add 172.16.8.36 172.16.8.38[*500] *esp 0x208 -m tunnel -E 3des-cbc
&lt;br&gt;0x7aeaca3f87d060a12f4a4487d5a5c3355920fae69a96c831
&lt;br&gt;-A hmac-md5 0xc0291ff014dccdd03874d9e8e4cdf3e6;
&lt;br&gt;&lt;br&gt;# Security policies
&lt;br&gt;spdadd 172.16.8.36 172.16.8.38[*800]* esp -P out ipsec
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esp/tunnel/172.16.8.36-172.16.8.38/require;
&lt;br&gt;&lt;br&gt;spdadd 172.16.8.38[*800] *172.16.8.36 esp &amp;nbsp;-P in ipsec
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;esp/tunnel/172.16.8.38-172.16.8.36/require;
&lt;br&gt;/************************* end setkey.conf ************************/
&lt;br&gt;&lt;br&gt;&lt;br&gt;*When a packet is sent to dest port 800 , SA which is getting selected 
&lt;br&gt;is &amp;nbsp;0x208[spi] 
&lt;br&gt;with dstport 500 instead of 0x201[spi] **with dstport 800 instead**.*
&lt;br&gt;&lt;br&gt;Please provide the criteria for outboud SA selection, please guide me 
&lt;br&gt;regarding this issue .
&lt;br&gt;My Linux kernel version is 2.6.23.1-42.fc8
&lt;br&gt;&lt;br&gt;Thanks and Regards
&lt;br&gt;Naveen
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26076152&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26076152&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/issue-with-outbound-SA-selection-tp26076152p26076152.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-26041742</id>
	<title>Re: ports/126853: ports-mgmt/portaudit: speed up audit of installed packages</title>
	<published>2009-10-24T11:28:45Z</published>
	<updated>2009-10-24T11:28:45Z</updated>
	<author>
		<name>Eygene Ryabinkin-3</name>
	</author>
	<content type="html">Fri, May 01, 2009 at 10:42:21PM +0400, Eygene Ryabinkin wrote:
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Gentlemen, good day.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Just a reminder about this PR -- it is already a bit old. &amp;nbsp;But it is
&lt;br&gt;&amp;gt; still viable and kicking on many machines of mine. &amp;nbsp;I am seeing speedups
&lt;br&gt;&amp;gt; from 10x to 26x comparing to the plain portaudit. &amp;nbsp;Since VuXML database
&lt;br&gt;&amp;gt; will only grow, this will be good to consider these patches and (likely)
&lt;br&gt;&amp;gt; integrate them into main trees.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Could someone, please, look at the patches? &amp;nbsp;I had uploaded slightly
&lt;br&gt;&amp;gt; modified patches to the old locations. &amp;nbsp;Most of changes were cosmetic:
&lt;br&gt;&amp;gt; whitespace and so on. &amp;nbsp;No real code was changed.
&lt;/div&gt;&lt;br&gt;Hmm, I am going to be a bit nasty this time -- the PR lies for 1.5 years
&lt;br&gt;and no one really looked at it. &amp;nbsp;Though, Simon and Martin promised to
&lt;br&gt;do so. &amp;nbsp;If you really don't want this patch to go in -- just say, I'll
&lt;br&gt;try to rework it to suit the project's needs. &amp;nbsp;But for me it is rediculous
&lt;br&gt;that no one is really interested in speeding up the stuff: number of
&lt;br&gt;installed ports and number of VuXML entries will only grow and the patch
&lt;br&gt;provides great opportunity to keep things very fast for the vast amount
&lt;br&gt;of time.
&lt;br&gt;&lt;br&gt;Sorry for a slightly harsh tone, but I am really disappointed with
&lt;br&gt;the handling of this PR.
&lt;br&gt;-- 
&lt;br&gt;Eygene
&lt;br&gt;&amp;nbsp;_ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;___ &amp;nbsp; &amp;nbsp; &amp;nbsp; _.--. &amp;nbsp; #
&lt;br&gt;&amp;nbsp;\`.|\..----...-'` &amp;nbsp; `-._.-'_.-'` &amp;nbsp; # &amp;nbsp;Remember that it is hard
&lt;br&gt;&amp;nbsp;/ &amp;nbsp;' ` &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; , &amp;nbsp; &amp;nbsp; &amp;nbsp; __.--' &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;to read the on-line manual
&lt;br&gt;&amp;nbsp;)/' _/ &amp;nbsp; &amp;nbsp; \ &amp;nbsp; `-_, &amp;nbsp; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;# &amp;nbsp;while single-stepping the kernel.
&lt;br&gt;&amp;nbsp;`-'&amp;quot; `&amp;quot;\_ &amp;nbsp;,_.-;_.-\_ ', &amp;nbsp;fsc/as &amp;nbsp; #
&lt;br&gt;&amp;nbsp; &amp;nbsp; &amp;nbsp;_.-'_./ &amp;nbsp; {_.' &amp;nbsp; ; / &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; # &amp;nbsp; &amp;nbsp;-- FreeBSD Developers handbook
&lt;br&gt;&amp;nbsp; &amp;nbsp; {_.-``-' &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; {_/ &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;#
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26041742&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=26041742&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-ports-126853%3A-ports-mgmt-portaudit%3A-speed-up-audit-of-installed-packages-tp23337936p26041742.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25946345</id>
	<title>HEADS UP: FreeBSD 6.3 EoL coming soon</title>
	<published>2009-10-18T05:36:26Z</published>
	<updated>2009-10-18T05:36:26Z</updated>
	<author>
		<name>FreeBSD Security Officer</name>
	</author>
	<content type="html">-----BEGIN PGP SIGNED MESSAGE-----
&lt;br&gt;Hash: SHA1
&lt;br&gt;&lt;br&gt;Hi all,
&lt;br&gt;&lt;br&gt;On January 31st, FreeBSD 6.3 will reach its End of Life and will no longer be
&lt;br&gt;supported by the FreeBSD Security Team. &amp;nbsp;Users of this release are strongly
&lt;br&gt;encouraged to upgrade to a newer release before that date -- more conservative
&lt;br&gt;users will probably wish to upgrade to FreeBSD 6.4 or FreeBSD 7.1 (which are
&lt;br&gt;both extended-support branches), while others will probably wish to upgrade to
&lt;br&gt;FreeBSD 7.2 or the upcoming FreeBSD 8.0.
&lt;br&gt;&lt;br&gt;The freebsd-update(8) utility can be used to upgrade i386 and amd64 systems
&lt;br&gt;from 6.3-RELEASE (or 6.3-RELEASE-pX for some X) to 6.4-RELEASE using binary
&lt;br&gt;updates (i.e., without compiling from source) as described in the 6.4-RELEASE
&lt;br&gt;announcement; given an adequate internet connection, this process usually takes
&lt;br&gt;15 minutes or less.
&lt;br&gt;&lt;br&gt;The current supported branches and expected EoL dates are:
&lt;br&gt;&lt;br&gt;&amp;nbsp; &amp;nbsp;+---------------------------------------------------------------------+
&lt;br&gt;&amp;nbsp; &amp;nbsp;| &amp;nbsp;Branch &amp;nbsp; | &amp;nbsp;Release &amp;nbsp; | &amp;nbsp;Type &amp;nbsp;| &amp;nbsp; Release date &amp;nbsp;| &amp;nbsp;Estimated EoL &amp;nbsp;|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+------------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_6 &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|November 30, 2010|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+------------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_6_3 |6.3-RELEASE |Extended|January 18, 2008 |January 31, 2010 |
&lt;br&gt;&amp;nbsp; &amp;nbsp;|---------------------------------------------------------------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_6_4 |6.4-RELEASE |Extended|November 18, 2008|November 30, 2010|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|---------------------------------------------------------------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_7 &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; |n/a &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;|last release + 2y|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+------------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_7_1 |7.1-RELEASE |Extended|January 4, 2009 &amp;nbsp;|January 31, 2011 |
&lt;br&gt;&amp;nbsp; &amp;nbsp;|-----------+------------+--------+-----------------+-----------------|
&lt;br&gt;&amp;nbsp; &amp;nbsp;|RELENG_7_2 |7.2-RELEASE |Normal &amp;nbsp;|May 4, 2009 &amp;nbsp; &amp;nbsp; &amp;nbsp;|May 31, 2010 &amp;nbsp; &amp;nbsp; |
&lt;br&gt;&amp;nbsp; &amp;nbsp;+---------------------------------------------------------------------+
&lt;br&gt;&lt;br&gt;When FreeBSD 8.0-RELEASE is released, it will receive &amp;quot;Normal&amp;quot; support, i.e., it
&lt;br&gt;will be supported for at least 12 months.
&lt;br&gt;&lt;br&gt;- --
&lt;br&gt;Colin Percival
&lt;br&gt;Security Officer, FreeBSD | freebsd.org | The power to serve
&lt;br&gt;Founder / author, Tarsnap | tarsnap.com | Online backups for the truly paranoid
&lt;br&gt;-----BEGIN PGP SIGNATURE-----
&lt;br&gt;Version: GnuPG v1.4.10 (FreeBSD)
&lt;br&gt;&lt;br&gt;iEYEARECAAYFAkrbC8oACgkQFdaIBMps37KQOQCgmnXQGtI/hKlFCT+dKAXzGX90
&lt;br&gt;gi4An0uC5y3SLNtrTxOvYD6HqpnrR99k
&lt;br&gt;=fl+f
&lt;br&gt;-----END PGP SIGNATURE-----
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25946345&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25946345&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/HEADS-UP%3A-FreeBSD-6.3-EoL-coming-soon-tp25946345p25946345.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25943741</id>
	<title>Re: openssh concerns</title>
	<published>2009-10-17T15:36:53Z</published>
	<updated>2009-10-17T15:36:53Z</updated>
	<author>
		<name>Darren Reed-9</name>
	</author>
	<content type="html">If this hasn't been mentioned already, disable password logins
&lt;br&gt;in sshd_config and require RSA authentication only.
&lt;br&gt;&lt;br&gt;I do this on all hosts I administer that are internet accessible
&lt;br&gt;and it allows me to confidently ignore all of the password
&lt;br&gt;guessing attacks, resulting in peace of mind.
&lt;br&gt;&lt;br&gt;Darren
&lt;br&gt;&lt;br&gt;RSAAuthentication yes
&lt;br&gt;PubkeyAuthentication yes
&lt;br&gt;PasswordAuthentication no
&lt;br&gt;ChallengeResponseAuthentication no
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25943741&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25943741&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Re%3A-openssh-concerns-tp25943741p25943741.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25919884</id>
	<title>RE: FreeBSD equivalent to Sun crypto framework APIs (PKCS#11) (for hardware AES-CTR)</title>
	<published>2009-10-15T19:26:41Z</published>
	<updated>2009-10-15T19:26:41Z</updated>
	<author>
		<name>John Case</name>
	</author>
	<content type="html">&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; There are a number of hardware solutions for performing AES-CTR in
&lt;br&gt;&amp;gt; hardware - for example the broadcom BCM5825, which is supported by
&lt;br&gt;&amp;gt; the ubsec driver.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; The problem is that OpenSSL does not currently support hardware
&lt;br&gt;&amp;gt; acceleration of AES-CTR. &amp;nbsp;The solution on a Sun system is to use the
&lt;br&gt;&amp;gt; Sun crypto framework APIs (PKCS#11) which does support AES-CTR in
&lt;br&gt;&amp;gt; hardware.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Is there an analagous API in FreeBSD that I could implement in my
&lt;br&gt;&amp;gt; code so as to use the hardware AES-CTR of devices supported by ubsec ?
&lt;/div&gt;&lt;br&gt;&amp;gt; Aside from &amp;nbsp;crypto(3) (OpenSSL), there's also crypto(9) (kernel) and
&lt;br&gt;&amp;gt; crypto(4) (userland), but they don't appear to support CTR - just CBC.
&lt;br&gt;&lt;br&gt;&lt;br&gt;Understood.
&lt;br&gt;&lt;br&gt;How difficult or trivial would it be to add AES-CTR to either crypto(9) or 
&lt;br&gt;crypto(4) ?
&lt;br&gt;&lt;br&gt;Are those just derived from OpenSSL in some way anyway ? &amp;nbsp;If not, who is 
&lt;br&gt;responsible for this kind of work ?
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25919884&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25919884&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-equivalent-to-Sun-crypto-framework-APIs-%28PKCS-11%29--%28for-hardware-AES-CTR%29-tp25896440p25919884.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25900517</id>
	<title>Re: FreeBSD equivalent to Sun crypto framework APIs (PKCS#11) (for hardware AES-CTR)</title>
	<published>2009-10-14T15:23:07Z</published>
	<updated>2009-10-14T15:23:07Z</updated>
	<author>
		<name>RW-15</name>
	</author>
	<content type="html">On Wed, 14 Oct 2009 18:02:36 +0000 (UTC)
&lt;br&gt;John Case &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25900517&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;case@...&lt;/a&gt;&amp;gt; wrote:
&lt;br&gt;&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; There are a number of hardware solutions for performing AES-CTR in 
&lt;br&gt;&amp;gt; hardware - for example the broadcom BCM5825, which is supported by
&lt;br&gt;&amp;gt; the ubsec driver.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; The problem is that OpenSSL does not currently support hardware 
&lt;br&gt;&amp;gt; acceleration of AES-CTR. &amp;nbsp;The solution on a Sun system is to use the
&lt;br&gt;&amp;gt; Sun crypto framework APIs (PKCS#11) which does support AES-CTR in
&lt;br&gt;&amp;gt; hardware.
&lt;br&gt;&amp;gt; 
&lt;br&gt;&amp;gt; Is there an analagous API in FreeBSD that I could implement in my
&lt;br&gt;&amp;gt; code so as to use the hardware AES-CTR of devices supported by ubsec ?
&lt;/div&gt;&lt;br&gt;Aside from &amp;nbsp;crypto(3) (OpenSSL), there's also crypto(9) (kernel) and
&lt;br&gt;crypto(4) (userland), but they don't appear to support CTR - just CBC.
&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25900517&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25900517&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-equivalent-to-Sun-crypto-framework-APIs-%28PKCS-11%29--%28for-hardware-AES-CTR%29-tp25896440p25900517.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25896440</id>
	<title>FreeBSD equivalent to Sun crypto framework APIs (PKCS#11)  (for hardware AES-CTR)</title>
	<published>2009-10-14T11:02:36Z</published>
	<updated>2009-10-14T11:02:36Z</updated>
	<author>
		<name>John Case</name>
	</author>
	<content type="html">&lt;br&gt;There are a number of hardware solutions for performing AES-CTR in 
&lt;br&gt;hardware - for example the broadcom BCM5825, which is supported by the 
&lt;br&gt;ubsec driver.
&lt;br&gt;&lt;br&gt;The problem is that OpenSSL does not currently support hardware 
&lt;br&gt;acceleration of AES-CTR. &amp;nbsp;The solution on a Sun system is to use the Sun 
&lt;br&gt;crypto framework APIs (PKCS#11) which does support AES-CTR in hardware.
&lt;br&gt;&lt;br&gt;Is there an analagous API in FreeBSD that I could implement in my code so 
&lt;br&gt;as to use the hardware AES-CTR of devices supported by ubsec ?
&lt;br&gt;&lt;br&gt;Or do I need to directly manipulate ubsec with my actual application in 
&lt;br&gt;order to do this ?
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25896440&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25896440&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/FreeBSD-equivalent-to-Sun-crypto-framework-APIs-%28PKCS-11%29--%28for-hardware-AES-CTR%29-tp25896440p25896440.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25831481</id>
	<title>Re: GPU crypto acceleration?</title>
	<published>2009-10-09T23:36:43Z</published>
	<updated>2009-10-09T23:36:43Z</updated>
	<author>
		<name>Chris Palmer-3</name>
	</author>
	<content type="html">On Oct 9, 2009, at 8:57 PM, remodeler wrote:
&lt;br&gt;&lt;br&gt;&amp;gt; I'm wondering if there's any core functionality or third-party &amp;nbsp;
&lt;br&gt;&amp;gt; utilities to
&lt;br&gt;&amp;gt; off-load cryptographic processing to the GPU or audio chip, instead &amp;nbsp;
&lt;br&gt;&amp;gt; of using a
&lt;br&gt;&amp;gt; hardware acceleration expansion card? This is on amd64 build.
&lt;br&gt;&lt;br&gt;Check out the Nvidia Tesla, although it probably will only work on &amp;nbsp;
&lt;br&gt;Windows and Linux.
&lt;br&gt;&lt;br&gt;What is your application, though?
&lt;br&gt;&lt;br&gt;&lt;br&gt;-- 
&lt;br&gt;&lt;a href=&quot;http://www.noncombatant.org/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://www.noncombatant.org/&lt;/a&gt;&lt;br&gt;&lt;a href=&quot;http://hemiolesque.blogspot.com/&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://hemiolesque.blogspot.com/&lt;/a&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25831481&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25831481&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/GPU-crypto-acceleration--tp25830909p25831481.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25830909</id>
	<title>GPU crypto acceleration?</title>
	<published>2009-10-09T20:57:23Z</published>
	<updated>2009-10-09T20:57:23Z</updated>
	<author>
		<name>remodeler-2</name>
	</author>
	<content type="html">I'm wondering if there's any core functionality or third-party utilities to
&lt;br&gt;off-load cryptographic processing to the GPU or audio chip, instead of using a
&lt;br&gt;hardware acceleration expansion card? This is on amd64 build.
&lt;br&gt;&lt;br&gt;Thank you.
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25830909&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25830909&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/GPU-crypto-acceleration--tp25830909p25830909.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25807216</id>
	<title>Re: Update on protection against slowloris</title>
	<published>2009-10-08T09:19:01Z</published>
	<updated>2009-10-08T09:19:01Z</updated>
	<author>
		<name>Martin Turgeon-3</name>
	</author>
	<content type="html">Martin Turgeon a écrit :
&lt;div class='shrinkable-quote'&gt;&lt;br&gt;&amp;gt; Thomas Rasmussen a écrit :
&lt;br&gt;&amp;gt;&amp;gt; Martin Turgeon wrote:
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Hi list!
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; We tested mod_antiloris 0.4 and found it quite efficient, but before 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; putting it in production, we would like to hear some feedback from 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; freebsd users. We are using Apache 2.2.x on Freebsd 6.2 and 7.2. Is 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; anyone using it? Do you have any other way to patch against 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Slowloris other than putting a proxy in front or using the HTTP 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; accept filter?
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Thanks for your feedback,
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; Martin
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; _______________________________________________
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25807216&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; To unsubscribe, send any mail to 
&lt;br&gt;&amp;gt;&amp;gt;&amp;gt; &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25807216&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;&amp;gt;&amp;gt; Hello,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; I am using it succesfully although not under any serious load, same
&lt;br&gt;&amp;gt;&amp;gt; Apache and FreeBSD versions. I found it easy (compared to the
&lt;br&gt;&amp;gt;&amp;gt; alternatives) and efficient, and no I don't know of any other ways of
&lt;br&gt;&amp;gt;&amp;gt; blocking the attack, short of using Varnish or similar. However,
&lt;br&gt;&amp;gt;&amp;gt; accf_http doesn't help at all, since HTTP POST requests bypass the
&lt;br&gt;&amp;gt;&amp;gt; filter. HTTP POST can be enabled by passing the -httpready switch to
&lt;br&gt;&amp;gt;&amp;gt; Slowloris.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Please report back with your findings, I've been wondering how it
&lt;br&gt;&amp;gt;&amp;gt; would perform under load.
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Best of luck with it,
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt;&amp;gt; Thomas Rasmussen
&lt;br&gt;&amp;gt;&amp;gt;
&lt;br&gt;&amp;gt; Hi everyone,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; We haven't put mod_antiloris in production yet, but I wrote this 
&lt;br&gt;&amp;gt; little shell script to protect us against distributed attack. It's 
&lt;br&gt;&amp;gt; running every minutes in crontab. It checks for any IP with more than 
&lt;br&gt;&amp;gt; 100 connections in FIN_WAIT_2 state and block those IP in PF.
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; #!/bin/sh
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; /usr/bin/netstat -nfinet | grep FIN_WAIT_2 &amp;gt; netstat.out
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; /usr/local/sbin/expiretable -t 300 slowloris
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; for ip in `awk '{print $5}' netstat.out | awk -F. '{print 
&lt;br&gt;&amp;gt; $1&amp;quot;.&amp;quot;$2&amp;quot;.&amp;quot;$3&amp;quot;.&amp;quot;$4}' | sort | uniq` ; do
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;if [ `grep -c $ip netstat.out` -gt 100 ] ; then
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;pfctl -t slowloris -Ta $ip 2&amp;gt; /dev/null
&lt;br&gt;&amp;gt; &amp;nbsp; &amp;nbsp; &amp;nbsp; &amp;nbsp;fi
&lt;br&gt;&amp;gt; done
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Did anyone have any comments on the script itself or the method used 
&lt;br&gt;&amp;gt; to detect the attackers?
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Thanks for your input,
&lt;br&gt;&amp;gt;
&lt;br&gt;&amp;gt; Martin
&lt;br&gt;&amp;gt;
&lt;/div&gt;Sorry for replying to my own post, but I have new informations to share. 
&lt;br&gt;We putted in production mod_antiloris and my script yesterday night. No 
&lt;br&gt;problem yet with the module but I got a few false positive with my 
&lt;br&gt;script. It seems that there are a few IP that got more than 100 
&lt;br&gt;simultaneous connections in FIN_WAIT_2 state. We noticed that a lot of 
&lt;br&gt;the FIN_WAIT_2 connections were related to a jail running Lighttpd 
&lt;br&gt;(immune to slowloris, which IP is 127.0.0.25) so I modified the initial 
&lt;br&gt;netstat so it looks like that:
&lt;br&gt;&lt;br&gt;/usr/bin/netstat -nfinet | grep -v 127.0.0.25 | grep FIN_WAIT_2 &amp;gt; 
&lt;br&gt;netstat.out
&lt;br&gt;&lt;br&gt;We didn't get any false positive since then but I'm wondering how a 
&lt;br&gt;client can have so many unclosed connections? To get in FIN_WAIT state, 
&lt;br&gt;it's the server that closed the connections but the client never closed 
&lt;br&gt;it's side of the connections. Does anyone have an idea how this can 
&lt;br&gt;happen? Is this because of a bad browser, a bad OS/TCP stack or 
&lt;br&gt;something else?
&lt;br&gt;&lt;br&gt;Thanks for taking the time to shed some light on this,
&lt;br&gt;&lt;br&gt;Martin
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25807216&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25807216&amp;i=3&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/Update-on-protection-against-slowloris-tp25684908p25807216.html" />
</entry>

<entry>
	<id>tag:old.nabble.com,2006:post-25777021</id>
	<title>Re: openssh concerns</title>
	<published>2009-10-06T14:08:56Z</published>
	<updated>2009-10-06T14:08:56Z</updated>
	<author>
		<name>Garrett Wollman-6</name>
	</author>
	<content type="html">&amp;lt;&amp;lt;On Tue, 6 Oct 2009 15:49:16 -0400, jhell &amp;lt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25777021&amp;i=0&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;jhell@...&lt;/a&gt;&amp;gt; said:
&lt;br&gt;&lt;br&gt;&amp;gt; Don't forget about making good use of the following configuration 
&lt;br&gt;&amp;gt; turntables. You can enforce a default policy of deny by just saying that a 
&lt;br&gt;&amp;gt; user must be in the group of AllowGroups. This does enforce a little bit 
&lt;br&gt;&amp;gt; more of a administrative overhead but that's for your staff and policy to 
&lt;br&gt;&amp;gt; decide.
&lt;br&gt;&lt;br&gt;Indeed, for a personal server that only I ever log in to, one of the
&lt;br&gt;first things that I do is add &amp;quot;AllowUsers wollman&amp;quot; to
&lt;br&gt;/usr/local/etc/ssh/sshd_config. &amp;nbsp;That's just a belt-and-suspenders
&lt;br&gt;thing, though, to make sure that I don't fat-finger the password file
&lt;br&gt;or something. &amp;nbsp;I generally ignore the ssh &amp;quot;invalid user&amp;quot; complaints --
&lt;br&gt;I have a modified version of /etc/periodic/security/800.loginfail that
&lt;br&gt;filters them out -- because they're totally irrelevant and have no
&lt;br&gt;impact on security. &amp;nbsp;That allows me to pay attention to the (very
&lt;br&gt;occasional) password failures on real user accounts.
&lt;br&gt;&lt;br&gt;-GAWollman
&lt;br&gt;_______________________________________________
&lt;br&gt;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25777021&amp;i=1&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security@...&lt;/a&gt; mailing list
&lt;br&gt;&lt;a href=&quot;http://lists.freebsd.org/mailman/listinfo/freebsd-security&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;http://lists.freebsd.org/mailman/listinfo/freebsd-security&lt;/a&gt;&lt;br&gt;To unsubscribe, send any mail to &amp;quot;&lt;a href=&quot;http://old.nabble.com/user/SendEmail.jtp?type=post&amp;post=25777021&amp;i=2&quot; target=&quot;_top&quot; rel=&quot;nofollow&quot;&gt;freebsd-security-unsubscribe@...&lt;/a&gt;&amp;quot;
&lt;br&gt;</content>
	<link rel="alternate" type="text/html" href="http://old.nabble.com/openssh-concerns-tp25708833p25777021.html" />
</entry>

</feed>
