Berkeley CSUA MOTD:Entry 52867
Berkeley CSUA MOTD
 
WIKI | FAQ | Tech FAQ
http://csua.com/feed/
2025/05/25 [General] UID:1000 Activity:popular
5/25    

2009/4/17-23 [Computer/SW/OS/FreeBSD] UID:52867 Activity:low
4/17    If you have a general access AssOS machines, this is worth
        taking this seriously. --psb
  http://c-skills.blogspot.com/2009/04/udev-trickery-cve-2009-1185-and-cve.html
        <DEAD>admin.fedoraproject.org/updates/udev-127-5.fc10<DEAD>
        \_ What does this have to do with MS Windows?
           \_ psb is a bsd lover.
              \_ BSD never had any security flaws, nosiree.
                 \_ I'm just explaining what AssOS is actually referring to.
                 \_ OpenBSD - "Only two remote holes in the default install,
                               in more than 10 years!"
                    \_ More like "Only two installs in more than 10 years!"
                       \_ http://openbsd.org/users.html
2025/05/25 [General] UID:1000 Activity:popular
5/25    

You may also be interested in these entries...
2009/5/4-6 [Computer/SW/OS/Linux, Computer/SW/OS/FreeBSD] UID:52939 Activity:moderate
5/4     I would appreciate a reliability ranking between:
        1) OpenBSD
        2) OpenSolaris
        3) FreeBSD
        4) Debian-Stable
        5) Suse Linux Enterprise Server
	...
2008/12/10-16 [Computer/HW/CPU, Computer/HW/Drives] UID:52220 Activity:moderate
12/9    Another idea for the CSUA that lets you spend money and maybe get some
    cool toys. Instead of buying a beefy server (like say, a massive server
    with 20 386DX processors), buy a few cheap machines (like the ones
    mentioned below) that have good disks and work on failover / load
    balancing. A netscaler or other piece of hardware is complete overkill,
    but maybe hacking an OpenBSD box could do the trick. The idea is that
	...
2007/7/17 [Computer/SW/Languages/C_Cplusplus] UID:47312 Activity:nil
7/13    CSUA Life Roster
1 point each for:                                               key:
                significant other (out of county rule applies)   G
                car (Chevy Novas do count)                       C
                housing (dorms DO NOT count)                     H
                own computer running reasonable multi-tasking OS U
	...
2007/7/13-16 [Computer/Networking] UID:47279 Activity:nil
7/13    I'm thinking about getting a Soekris 4501 to replace my the P2-400
        that is currently acting as my home firewall. Has anyone used a
        Soekris system for this purpose? If so, how well does it work? Also,
        if there are any alternatives (similar power/form factor), I would
        appreciate links to those as well. tia.
        \_ John got me to use a WRAP box similar to Soekris.  I use this one:
	...
2007/3/15-17 [Computer/SW/OS/FreeBSD] UID:45977 Activity:nil
3/14    http://www.csua.org/u/i8o
        Remote exploit in OpenBSD kernel.  Security is hard.  And yes, it
        would be really difficult to exploit this in practice. -dans
	...
2007/3/13-14 [Computer/SW/OS/FreeBSD] UID:45949 Activity:nil
3/13    OpenBSD 4.1 preorder is up:
        http://www.openbsd.org/items.html#41
	...
2007/3/13-14 [Computer/SW/Security] UID:45950 Activity:nil
3/13    OpenSSH 4.6 is out:
        http://undeadly.org/cgi?action=article&sid=20070308183425
        Portable Version:
        ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-4.6p1.tar.gz
        OpenBSD Version:
        ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-4.6.tar.gz
	...
2006/11/8-9 [Computer/SW/Security] UID:45263 Activity:nil
11/8    OpenSSH 4.5 is out:
        http://www.openssh.org/txt/release-4.5
        ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-4.5.tar.gz
        ftp://ftp.openbsd.org/pub/OpenBSD/OpenSSH/portable/openssh-4.5p1.tar.gz
	...
2006/9/27-28 [Computer/SW/OS/FreeBSD, Computer/SW/Security] UID:44580 Activity:nil
9/27    OpenSSH 4.4 is leftist
        http://www.openssh.org/txt/release-4.4
        OpenBSD src:
        http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-4.4.tar.gz
        OpenBSD src signature:
        http://ftp.openbsd.org/pub/OpenBSD/OpenSSH/openssh-4.4.tar.gz.asc
	...
2006/9/22-25 [Computer/SW/OS/FreeBSD] UID:44496 Activity:nil
9/22    OpenBSD 4.0 available for pre-order:
        http://www.openbsd.org/40.html
	...
2006/8/16-18 [Computer/SW/OS/FreeBSD] UID:44024 Activity:nil
8/16    Greatest piece of software ever written is 4.3 BSD:
        http://tinyurl.com/go7lv (informationweek.com)
        \_ Windows is run by more computers than all other OS combined.
           \_ that only makes it common, not great.
              \_ If it wasn't great people wouldn't use it.  They'd use 4.3
                 BSD.
	...
2006/3/25-26 [Computer/SW/OS/FreeBSD] UID:42421 Activity:very high
3/24    Wow!  FreeBSD sure is stable!  After seeing soda's amazing uptime
        record, I sure want to go replace my Linux boxes with FreeBSD!
        Please do not delete this, or burn down Linus' house because I have
        blasphemed the holy FreeBSD.  I'd love to see a genuine discussion with
        examples from both sides comparing the stability of *modern* FreeBSD
        and Linux machines running on x86 hardware. -dans
	...
Cache (1077 bytes)
c-skills.blogspot.com/2009/04/udev-trickery-cve-2009-1185-and-cve.html
udev trickery (CVE-2009-1185 and CVE-2009-1186) While the security industry is making weird statements about no-more-free-hugs and OSX vs. Windows exploitation fun, I add my two cents on UNIX exploitation. There have been two problems in all currently running udevd's which are shipped on all major Linux distributions. Even if you install selinux or other hardening mechanisms, you are at risk (please see above screenshot on a targeted selinux config). The first problem (CVE-2009-1185) appears since the origin of KOBJECT_UEVENT messages are not verified, so any user can spoof messages that udevd takes as granted from kernel. This allows some trickery to create a device named /dev/random with permission 0666 but major and minor number of your root blockdevice. Alternatively, CVE-2009-1186 could be exploited which is a standard stack buffer overflow. Depending on the configuration of the system CVE-2009-1185 can also be exploited with weird network interface-names and alike so at the end, chrooted/jailed or PrivSep'ed users have good chance to get a full rootshell.
Cache (8192 bytes)
openbsd.org/users.html
companies and organizations trust OpenBSD's rigorous code audit and security-first development model. They use the system to build firewalls, intrusion detection systems, or general purpose servers. Human Rights and Equal Opportunity Commission, Australia Established in 1986 and based in Sydney, HREOC is an independent statutory organisation which administers federal laws relating to alleged human rights breaches and discrimination. The Commission is also responsible for human rights education and the investigation and conciliation of discrimination and human rights complaints. OpenBSD is being utilised to offer various network services. Ministerio de Obras Pblicas del Gobierno de Chile The Public Construction Ministry of the Republic of Chile runs a national WAN and use OpenBSD for their firewalls and link loadbalancers, based on pf. They have been using OpenBSD since the year 2001, and selected the OS so they could sleep well at night without fear of being hacked. Instituto Distrital de Cultura y Turismo, Bogota, Colombia In this government agency, OpenBSD is essential: perimeter firewalls, network intrusion systems, bandwidth managers and a mail filter gateway that uses spamd and some other OpenBSD tools keep their network secure. Sonora State Electoral Council, Mxico This government agency uses OpenBSD to protect its network and for intrusion detection. The OpenBSD-based VPN provides online electoral results to both internal and external users. Azienda Ospedaliera, Mantova, Italy Azienda Ospedaliera "Carlo Poma" is the largest health institution in the province of Mantova (Lombardia) with six hospitals and other small ambulatories. OpenBSD was chosen for its reliability and now serves as the bridging firewall between the WAN and the main Hospital of Mantova. We use pf and altq for firewalling and QoS applications, and use fwanalog to generate WAN traffic statistics. Belper School, Belper, Derbyshire, UK The Belper School uses OpenBSD machines as Samba file servers for around 1100 students as well as for student web hosting and a firewall/NAT gateway. Capitol College Capitol College is the only independent college in Maryland dedicated to engineering, computer science, information technology and business. Capitol College is a regionally accredited institution offering associate, bachelor's and master's degrees, as well as professional development training and certificates. They use OpenBSD for a variety of functions, from serving their website, protecting their network with the PF firewall and QoS, Intrusion Detection monitoring, and hosting their internal Certificate Authority. ELM consortium, Biocomputing Unit EMBL, Heidelberg, Germany The ELM consortium runs the The Eukaryotic Linear Motif Database and uses OpenBSD for the consortium's communication servers. UNAM is Mexico's largest University, with over 250,000 students, and at ENEP Iztacala we have a bit over 10,000 students. This is mostly a health-oriented campus, so the computer area is not a big one. We run as servers currently two OpenBSD, one Solaris and two Linux boxes. With OpenBSD we handle the main web site (happily running on a 7-year old Sparcstation 5), part of our mail accounts and our firewall. There are two additional OpenBSD computers, in our development area. One of them acts as a network monitor (using Snort) and will shortly be moved to sit next to the firewall, and the other one serves as an OpenBSD CVS mirror. We do not do run very creative stuff, we just use OpenBSD for what it does best: run smoothly, even on older hardware, freeing us from most concerns and doubts we have about our other operating systems. "Forcefield" art installation Part of the audio and lighting for the Forcefield art installation at the 2002 Biennial exhibition at the Whitney Museum of American Art in New York is being controlled by a VAXstation 3100 running OpenBSD. Helsinki University Central Hospital, Finland The Hospital District of Helsinki and Uusimaa (HUS), with staff totaling approx. OpenBSD is used for DNS, mail gateway, VPN and firewall solutions both on the internal campus network and on the Internet. network appliance based on a modified version of OpenBSD that boots and runs from CD. Over 100 of these appliances are running in libraries around the world. They collect and preserve materials published on the web, including academic journals, theses and dissertations, cultural collections and government documents. Peter-Weiss-Gesamtschule, Unna, Germany This German comprehensive school educates students of ages 10 to 19 years old. The school offers Computer Science classes and provides laptops to students. Peter-Weiss-Gesamtschule has been using OpenBSD routers since 2003 and since December 2005, all servers run OpenBSD exclusively. They chose OpenBSD for its security and its powerful packet filter. Polytechnic Preparatory Country Day School Poly Prep CDS, a large private school in the south of Brooklyn, NY, has been using OpenBSD since its 29 release for its firewalls (on both campuses) and now for its student fileservers. The student fileservers, which are a part of the student computer club, run OpenBSD 32 and are administered by students under the guidance of an experienced UNIX Administrator. The goal of the program is to teach potential computer professionals the responsibility needed in running a UNIX-like system, good security practices and to show the students that there are alternatives to Linux. Royal Conservatory of Music The RCM in Toronto, Canada is a 120-year-old national cultural institution with an alumni base of around 800,000 Canadians who have either studied through its system of teachers and examinations or taken music lessons based on the RCM curriculum. Recently, they have been branching out into other areas of the arts. They operate a heterogeneous network that incorporates an IBM i520 (successor to the AS/400), multiple Sun boxen, Windows machines, and some FreeBSD systems. The first use of OpenBSD is to provide a secure router for the IT lab; School of Earth and Space Exploration, Arizona State University, USA SESE uses OpenBSD for nearly every public-facing server we manage. We also abuse OpenBSD on a number of authpf'ing firewalls, proxies, and monitoring (nagios, cacti, nut, etc). The University of Alberta uses OpenBSD on SPARC and Intel hardware for proxy servers, Kerberos servers, print servers, service monitoring, pre-emptive security scanning, and incident response. OpenBSD on Intel Hardware is used for Firewalls and Lan-to-Lan VPN for the university's secured subnets behind which all the University's new administrative systems reside. authenticating gateways in front of public labs and public ethernet jacks in approximately 40 locations across campus (about 1500 seats) to help secure public internet access. The Department of Computing Science is using two 20 seat OpenBSD labs for undergraduate instruction. The University of California, Davis OpenBSD is used extensively in Schools, Colleges, and Departments at UC Davis as part of the campus firewall solution. Additionally, OpenBSD servers provide instructional lab fileserver redundancy with CARP, serve up web content in Zope/Plone, proxy websites with Squid, and provide networking services such as dhcp and DNS (djbdns). Law Department The Department uses OpenBSD for Firewalls, NAT, squid proxies and intrusion detection. Their students use the web for applications such as internet courses and multimedia lectures, all of which pass through one or more OpenBSD boxes. smart card contents and protocols, both in isolation and in real applications. Plans are underway to issue cards containing secure tokens for user logins and kerberos ticket acquisition. Internally "The Packet Vault" is an OpenBSD machine that captures and records on cd-rom every packet on the local 10 Mbps ethernet. Packet contents are encrypted to comply with privacy requirements. In addition, a number of people within the department are using OpenBSD as their primary operating system. The University of Minnesota This university uses OpenBSD on Sun Sparc workstations for network monitoring and capacity planning. They query 53...