TGViewer
Channel Public Channel
OpenBSD

OpenBSD

@openbsd

Сool OpenBSD stuff @openbsd
Feedback obsd@tuta.io

Community:
@openbsd_en
@openbsd_ru
@openbsdbr
@OpenBSD_es

OpenBSDjumpstart https://t.me/joinchat/EzTjLQuG8MdUSVqFS1xA4w

Unofficial channel. Get OpenBSD: https://www.openbsd.org/
Subscribers
1.23K
Photos
38
Videos
2
Links
408

Showing posts older than #102 · Back to latest

Older Posts 20 shown
Post #99 622
CarolinaCon 15: Writing Exploit-Resistant Code With OpenBSD.

OpenBSD is renowned for its security innovations and code quality. With its emphasis on code correctness, exploit mitigation techniques, and a rigorous development process, OpenBSD provides a rich platform and environment for developers to create robust software. This talk explores various OpenBSD programs, exploit mitigation techniques, tools, and development practices to show how you can use them to write code that is safe, robust, and resistant to exploits – even if your code is meant for platforms other than OpenBSD.

https://lteo.net/blog/2019/04/27/carolinacon-15-writing-exploit-resistant-code-with-openbsd/

#develop
Post #97 648
OpenBSD: Local privilege escalation via S/Key and YubiKey.

OpenBSD, in a non-default configuration where S/Key or YubiKey authentication is enabled, allows local users to become root by leveraging membership in the auth group. This occurs because root’s file can be written to /etc/skey or /var/db/yubikey, and need not be owned by root.

https://allelesecurity.com/asa-2019-00653/

#security
Post #95 845
Local Privilege Escalation in OpenBSD's dynamic loader (CVE-2019-19726)

We discovered a Local Privilege Escalation in OpenBSD's dynamic loader (ld.so): this vulnerability is exploitable in the default installation (via the set-user-ID executable chpass or passwd) and yields full root privileges.

We developed a simple proof of concept and successfully tested it against OpenBSD 6.6 (the current release), 6.5, 6.2, and 6.1, on both amd64 and i386; other releases and architectures are probably also exploitable.

https://www.openwall.com/lists/oss-security/2019/12/11/9

#security
Post #93 625
An OpenBSD desktop using WindowMaker.

Since I started using *N?X, I’ve regularly used WindowMaker. I’ve always liked the look and feel, the dock system and the dockapps. It may look a bit oldish nowadays. And that’s enough to try to change this. So here it is, a 2019 flavored WindowMaker Desktop, running on OpenBSD 6.4/amd64...

https://www.tumfatig.net/20190215/an-openbsd-desktop-using-windowmaker/

#desktop #windowmaker
Post #92 597
attention please: host's IP stack behavior got changed slightly.

commit from today [1] makes IP stack more paranoid. Up to now OpenBSD implemented so called 'weak host model' [2]. The today's commit alters that for hosts, which don't forward packets (don't act as routers)...

https://undeadly.org/cgi?action=article;sid=20191209024432

#network
Post #90 1.85K
Authentication vulnerabilities in OpenBSD.

We discovered an authentication-bypass vulnerability in OpenBSD's authentication system: this vulnerability is remotely exploitable in smtpd, ldapd, and radiusd, but its real-world impact should be studied on a case-by-case basis. For example, sshd is not exploitable thanks to its defense-in-depth mechanisms.

https://www.openwall.com/lists/oss-security/2019/12/04/5

#security
Post #86 562
syscall call-from verification

The following change only permits system calls from address-ranges in the process which system calls are expected from.

If you manage to upload exploit code containing a raw system call sequence and instruction, and mprotect -w+x that block, such a system call will not succeed but the process is killed. This obliges the attacker to use the libc system call stubs, which in some circumstances are difficult to find due to libc random-relinking at boot...

https://marc.info/?l=openbsd-tech&m=157488907117170

#syscall
Post #84 615
BSD, C, httpd, SQLite.

BCHS is an open source software stack for web applications. To prepare a BCHS environment, install OpenBSD, start your editor of choice, and get to work. https://learnbchs.org/index.html

#bchs
Older posts →
Threads Profile ViewerView any public Threads profile without an account.Open ThreadLook →Writing with AI? Make it sound human.Metric37 rewrites AI drafts so they read naturally. Free AI detector, 1,500 words free.Try Metric37 →