en
Feedback
OpenBSD

OpenBSD

Open in Telegram

Дool OpenBSD stuff @openbsd Feedback obsd@tuta.io Community: @openbsd_en @openbsd_ru @openbsdbr @OpenBSD_es OpenBSDjumpstart https://t.me/joinchat/EzTjLQuG8MdUSVqFS1xA4w Unofficial channel. Get OpenBSD: https://www.openbsd.org/

Show more
The country is not specifiedTechnologies & Applications53 232
1 129
Subscribers
+224 hours
+147 days
+3830 days
Posts Archive
OpenBSD
1 129
Using OpenBSD relayd to Add Security Headers. I am a huge fan of OpenBSD’s built-in httpd server as it is simple, secure, and quite performant. With the modern push of the large search providers pushing secure websites, it is now important to add security headers to your website or risk having the search results for your website downgraded. Fortunately, it is very easy to do this when you combine httpd with relayd. https://goblackcat.com/posts/using-openbsd-relayd-to-add-security-headers/ #relayd

OpenBSD
1 129
My machines are hosted in 3 different places. First is at Exoscale, second is Vultr and the third is... my flat. All of them run either OpenBSD on its -current branch, or the latest version of Ubuntu. At this time, that's Ubuntu 19.10. After a couple of years working on OpenBSD ports (i.e. packaging), I believe fresh software is better, security-wise. https://chown.me/blog/infrastructure-2019.html #server

OpenBSD
1 129
022: RELIABILITY FIX: March 10, 2020 All architectures Missing input validation in sysctl(2) can be used to crash the kernel. 023: RELIABILITY FIX: March 13, 2020 All architectures Local outbound UDP broadcast or multicast packets sent by a spliced socket can crash the kernel. #security

OpenBSD
1 129
OpenBSD Full Disk Encryption with CoreBoot and Tianocore Payload. https://functionallyparanoid.com/2020/03/07/openbsd-full-disk-encryption-with-coreboot-and-tianocore-payload/ #encryption #security

OpenBSD
1 129

OpenBSD
1 129
Remote root exploits are now publicly available for LPE and RCE in OpenBSD's OpenSMTPD's default install (CVE-2020-8794). https://www.openwall.com/lists/oss-security/2020/02/26/1 #security #opensmtpd

OpenBSD
1 129
LPE and RCE in OpenSMTPD's default install (CVE-2020-8794). https://www.openwall.com/lists/oss-security/2020/02/24/5 #opensmtpd #security

OpenBSD
1 129
The results are in. About 5 billion fuzz cases, a few 10 hours streams, and we found 6 unique bugs in OpenBSD ctags. All with an absolutely garbage fuzzer. Some were pretty tricky (uninit stack use, global overflows), but vecemu was able to detect em! https://twitter.com/gamozolabs/status/1229379329248784385 https://gist.github.com/gamozolabs/ac79a6d755e44d71f5bf0659a0848265 #security #ctags #fuzzing

OpenBSD
1 129
Configure login(1) and sshd(8) for YubiKey on OpenBSD. https://rgz.ee/openbsd/yubikey.html #sshd #yubikey

OpenBSD
1 129
Vulnerabilities(?) in OpenBSD's hypervisor. Three things are wrong: 1) The RO protections are not enforced, so the guest could have data be written to a GPA it can only access as RO. 2) If 'pvclock_ti' crosses a page, its second half could point to an HPA that doesn't belong to the guest. The guest can therefore, to some limited extent, overwrite host kernel memory. 3) The pmap is not locked, so if the GPA gets unmapped and its corresponding HPA recycled, there is a small window where the (new) content of the HPA can get overwritten. https://marc.info/?l=openbsd-tech&m=158176939604512&w=2 #security

OpenBSD
1 129

OpenBSD
1 129
Monitoring OpenBSD with Grafana and Prometheus. With any deployment of OpenBSD, it is always advisable to have some sort of monitoring enabled... Last week, I ended up moving over to a Grafana dashboard with prometheus as the monitoring system... https://www.findelabs.com/post/grafana-prometheus-monitoring-openbsd/ #grafana #prometheus #monitoring

OpenBSD
1 129
Running Sagan on OpenBSD 6.6. Sagan uses a 'Snort like' engine and rules to analyze logs (syslog/event log/snmptrap/netflow/etc). https://gist.github.com/litew/1e94730ed1b862aa59d4c6b065a0d4a9 #security #sagan

OpenBSD
1 129
SNMP v3 check for OpenBSD systems state monitoring This script uses SNMPv3 to check memory and swap usage, file system space usage and CPU load average on OpenBSD system. It also shows detailed information about all avaliable file systems, configured NICs, system information about OS and list of running processes. https://github.com/alexander-naumov/openbsd_snmp3_check #snmp #monitoring

OpenBSD
1 129
FOSDEM 2020 videos. Video recordings from FOSDEM 2020 are now available. The OpenBSD presentations were: • Giovanni Bechis (giovanni@) - OpenSMTPD over the clouds, the story of an HA setup. • Florian Obser (florian@) - unwind(8), A privilege-separated, validating DNS recursive nameserver for every laptop. https://undeadly.org/cgi?action=article;sid=20200211080946 #fosdem #video

OpenBSD
1 129
syspatch module is available in Ansible 2.9+. https://docs.ansible.com/ansible/latest/modules/syspatch_module.html #ansible #syspatch

OpenBSD
1 129
Sandbox X11 applications on OpenBSD. https://github.com/morgant/Xsunaba #x11 #desktop

OpenBSD
1 129
Docker on OpenBSD 6.1. All thanks to VMM/VMD, Alpine Linux, and the latest OpenBSD improvements https://medium.com/@dave_voutila/docker-on-openbsd-6-1-current-c620513b8110 #docker #vmm #vmd

OpenBSD
1 129
Monitoring OpenBSD using CollectD, InfluxDB and Grafana. In a ā€œget pretty graphsā€ mood, I’m looking at what can be done regarding OpenBSD monitoring using the CollectD collector and Grafana dashboard renderer. OpenBSD 6.2-current provides InfluxDB and Grafana packages. A great stack for pretty reportings. https://www.tumfatig.net/20180220/monitoring-openbsd-using-collectd-influxdb-grafana/ #collectd #influxdb #grafana