From cstef at parallel.ru Mon May 13 10:48:30 2019 From: cstef at parallel.ru (Konstantin Stefanov) Date: Mon, 13 May 2019 10:48:30 +0300 Subject: [freebsd] =?utf-8?b?amFpbGF1ZGl0INC4INGA0LXQv9C+0LfQuNGC0L7RgNC4?= =?utf-8?q?=D0=B9_pkg_FreeBSD-latest?= Message-ID: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> ???????????. ???? ? ???? ?????? ? ??????????? jail. ? ????? ?? ??????? ??? pkg ??????? ??????????? ??? ? ????? ????????????: FreeBSD-latest: { url: "pkg+http://pkg.FreeBSD.org/${ABI}/latest", mirror_type: "srv", signature_type: "fingerprints", fingerprints: "/usr/share/keys/pkg", enabled: yes, priority: 1 } ? ???? ?? ??? ??????? ????? jailaudit, ???????, ? ????????, ?????? ??? ???? ??????? ??????? pkg audit, ? ????????? ?????? ? ?????????? ?????? security. ? ??? ?? ???? ????? ???? ????? jailaudit ?????????? ???? ????????? ???? FreeBSD-latest.meta is vulnerable: openssh -- multiple vulnerabilities CVE: CVE-2006-5051 CVE: CVE-2006-4924 WWW: https://vuxml.FreeBSD.org/freebsd/32db37a5-50c3-11db-acf3-000c6ec775d9.html ? CVE ???????? ?????, ???????, ????????, ? ??????? ?????? ??? ???????. ????????? ???????? ????????, ??? ?????? ??????? (????? ???????????? pkg query -a) jailaudit ????????? ??? ?????? ls -1 /var/db/pkg/ |grep -v '.sqlite$' |grep -v 'auditfile'|grep -v 'vuln.xml' ? ???? /var/db/pkg/FreeBSD-latest.meta ???????? ? ?????? ????????????? ???????, ????? ???? ?????????? ? pkg audit FreeBSD-latest.meta ? ?????????? ???????? ??????? ????. ?????????? ???????: 1. ? ????? ?????? ???????? ?? ????? ? /var/db/pkg ? ???????? ?? ????? ? pkg audit, ??? ??? ????? ???? ?????? ???????????? 2. ????? ?????? ? ????, ???? ??????? pkg audit, ?????? ? ?????? FreeBSD-latest.meta ? ?????????? ?? ?????-????? ???? 3. ? ? ???-?? ??????, ??????? ????? .meta ?? ???????????? (??????? ??? ???? grep -v ? ??????? ?? ? ????? ?????? ? ????-?? ???? ????? ?? ??????? -- ?????????? ???????? -- ?????????? ????????, ??????????? ???????????? ?????????????? ?????????? ???? ??? ???. +7 (495) 939-23-41 From eugen at grosbein.net Mon May 13 16:09:21 2019 From: eugen at grosbein.net (Eugene Grosbein) Date: Mon, 13 May 2019 20:09:21 +0700 Subject: [freebsd] =?utf-8?b?amFpbGF1ZGl0INC4INGA0LXQv9C+0LfQuNGC0L7RgNC4?= =?utf-8?q?=D0=B9_pkg_FreeBSD-latest?= In-Reply-To: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> Message-ID: <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> 13.05.2019 14:48, Konstantin Stefanov ?????: > ???????????. > > ???? ? ???? ?????? ? ??????????? jail. ? ????? ?? ??????? ??? pkg ??????? ??????????? ??? ? ????? ????????????: > FreeBSD-latest: { > url: "pkg+http://pkg.FreeBSD.org/${ABI}/latest", > mirror_type: "srv", > signature_type: "fingerprints", > fingerprints: "/usr/share/keys/pkg", > enabled: yes, > priority: 1 > } > > ? ???? ?? ??? ??????? ????? jailaudit, ???????, ? ????????, ?????? ??? ???? ??????? ??????? pkg audit, ? ????????? ?????? ? ?????????? ?????? security. ? ??? ?? ???? ????? ???? ????? jailaudit ?????????? ???? ????????? ???? > > FreeBSD-latest.meta is vulnerable: > openssh -- multiple vulnerabilities > CVE: CVE-2006-5051 > CVE: CVE-2006-4924 > WWW: https://vuxml.FreeBSD.org/freebsd/32db37a5-50c3-11db-acf3-000c6ec775d9.html > > ? CVE ???????? ?????, ???????, ????????, ? ??????? ?????? ??? ???????. > ????????? ???????? ????????, ??? ?????? ??????? (????? ???????????? pkg query -a) jailaudit ????????? ??? ?????? > ls -1 /var/db/pkg/ |grep -v '.sqlite$' |grep -v 'auditfile'|grep -v 'vuln.xml' > ? ???? /var/db/pkg/FreeBSD-latest.meta ???????? ? ?????? ????????????? ???????, ????? ???? ?????????? ? pkg audit FreeBSD-latest.meta ? ?????????? ???????? ??????? ????. > > ?????????? ???????: > 1. ? ????? ?????? ???????? ?? ????? ? /var/db/pkg ? ???????? ?? ????? ? pkg audit, ??? ??? ????? ???? ?????? ???????????? > 2. ????? ?????? ? ????, ???? ??????? pkg audit, ?????? ? ?????? FreeBSD-latest.meta ? ?????????? ?? ?????-????? ???? > 3. ? ? ???-?? ??????, ??????? ????? .meta ?? ???????????? (??????? ??? ???? grep -v ? ??????? > > ?? ? ????? ?????? ? ????-?? ???? ????? ?? ??????? ?? ???? ??????? ?? ???????, ?? ???? ?? pkg-descr ????? jailaudit, ??? ????? ?????? ????, ??????? ????????, ????? pkgng ??? ?? ???? ? ??????? ? ?????? pkg audit ????????????? portaduit. jailaudit ?????? ?????????????? ????? ???????? ? IMHO ?? ????? ??????. ?????? ???????????? ???????????? ??????? ???? ??????: jls | awk 'NR>1 {print $3, $4}' | while read name root do printf "\nAudit for $name:\n" env PKG_DBDIR=$root/var/db/pkg pkg audit done From cstef at parallel.ru Tue May 14 09:41:09 2019 From: cstef at parallel.ru (Konstantin Stefanov) Date: Tue, 14 May 2019 09:41:09 +0300 Subject: [freebsd] =?utf-8?b?amFpbGF1ZGl0INC4INGA0LXQv9C+0LfQuNGC0L7RgNC4?= =?utf-8?q?=D0=B9_pkg_FreeBSD-latest?= In-Reply-To: <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> Message-ID: On 13.05.2019 16:09, Eugene Grosbein wrote: > 13.05.2019 14:48, Konstantin Stefanov ?????: > >> ???????????. >> >> ???? ? ???? ?????? ? ??????????? jail. ? ????? ?? ??????? ??? pkg ??????? ??????????? ??? ? ????? ????????????: >> FreeBSD-latest: { >> url: "pkg+http://pkg.FreeBSD.org/${ABI}/latest", >> mirror_type: "srv", >> signature_type: "fingerprints", >> fingerprints: "/usr/share/keys/pkg", >> enabled: yes, >> priority: 1 >> } >> >> ? ???? ?? ??? ??????? ????? jailaudit, ???????, ? ????????, ?????? ??? ???? ??????? ??????? pkg audit, ? ????????? ?????? ? ?????????? ?????? security. ? ??? ?? ???? ????? ???? ????? jailaudit ?????????? ???? ????????? ???? >> >> FreeBSD-latest.meta is vulnerable: >> openssh -- multiple vulnerabilities >> CVE: CVE-2006-5051 >> CVE: CVE-2006-4924 >> WWW: https://vuxml.FreeBSD.org/freebsd/32db37a5-50c3-11db-acf3-000c6ec775d9.html >> >> ? CVE ???????? ?????, ???????, ????????, ? ??????? ?????? ??? ???????. >> ????????? ???????? ????????, ??? ?????? ??????? (????? ???????????? pkg query -a) jailaudit ????????? ??? ?????? >> ls -1 /var/db/pkg/ |grep -v '.sqlite$' |grep -v 'auditfile'|grep -v 'vuln.xml' >> ? ???? /var/db/pkg/FreeBSD-latest.meta ???????? ? ?????? ????????????? ???????, ????? ???? ?????????? ? pkg audit FreeBSD-latest.meta ? ?????????? ???????? ??????? ????. >> >> ?????????? ???????: >> 1. ? ????? ?????? ???????? ?? ????? ? /var/db/pkg ? ???????? ?? ????? ? pkg audit, ??? ??? ????? ???? ?????? ???????????? >> 2. ????? ?????? ? ????, ???? ??????? pkg audit, ?????? ? ?????? FreeBSD-latest.meta ? ?????????? ?? ?????-????? ???? >> 3. ? ? ???-?? ??????, ??????? ????? .meta ?? ???????????? (??????? ??? ???? grep -v ? ??????? >> >> ?? ? ????? ?????? ? ????-?? ???? ????? ?? ??????? > > ?? ???? ??????? ?? ???????, ?? ???? ?? pkg-descr ????? jailaudit, ??? ????? ?????? ????, > ??????? ????????, ????? pkgng ??? ?? ???? ? ??????? ? ?????? pkg audit ????????????? > portaduit. ??? ??, ?? ????? ???? ?????? ????????? pkg audit. > jailaudit ?????? ?????????????? ????? ???????? ? IMHO ?? ????? ??????. > ?????? ???????????? ???????????? ??????? ???? ??????: > > jls | awk 'NR>1 {print $3, $4}' | while read name root > do > printf "\nAudit for $name:\n" > env PKG_DBDIR=$root/var/db/pkg pkg audit > done > ? ?????, ?? ???????? ??? ? ??????. ???? ?????? ?????? ? periodic/security, ? ????? ???????? ? ????? security output. ??? ?? ???, ??? ???? ???? ??????? ?????, ??????? ?????? ??, ??? ??? ????, ? ???????? ???, ? ?? ???? ????? ??? ???????? ??????????, ??? ??? ?? ??????? ? ?????? ???-?? ??????????. ? ?????? ??? ????? ????????? ??????? ??????, ??? ?????? ????. ???????? ?????? - ????? ?? ???-???? ??????? ? /var/db/pkg (?????, ??? ?????? ???-?? ????, ?? ???? ????? ?????????? ????? ????????????? ???????) ? ????????? ????????? ??? ??? ????????? -- ?????????? ????????, ??????????? ???????????? ?????????????? ?????????? ???? ??? ???. +7 (495) 939-23-41 From yz at yz.kiev.ua Tue May 14 11:15:18 2019 From: yz at yz.kiev.ua (George L. Yermulnik) Date: Tue, 14 May 2019 11:15:18 +0300 Subject: [freebsd] =?koi8-r?b?amFpbGF1ZGl0IMkg0sXQz9rJ1M/SycogcGtnIEZyZWVC?= =?koi8-r?b?U0QtbGF0ZXN0?= In-Reply-To: References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> Message-ID: <20190514081518.GG20712@yz.kiev.ua> Hello! On Tue, 14 May 2019 at 09:41:09 (+0300), Konstantin Stefanov wrote: > ??? ?? ???, ??? ???? ???? ??????? ?????, ??????? ?????? ??, ??? ??? > ????, ? ???????? ???, ? ?? ???? ????? ??? ???????? ??????????, ??? ??? > ?? ??????? ? ?????? ???-?? ??????????. ? ?????? ??? ????? ????????? > ??????? ??????, ??? ?????? ????. ???????? ?????? - ????? ?? ???-???? > ??????? ? /var/db/pkg (?????, ??? ?????? ???-?? ????, ?? ???? ????? > ?????????? ????? ????????????? ???????) ? ????????? ????????? ??? ??? > ????????? ?????? ? ???? ? ???? ?????? ??? ?????????????? ???????????? =) ????????? ??????????? ????? ??? ?????? - ?????, ?? ? ?????, ????? ? ????????? ?????????. -- George L. Yermulnik [YZ-RIPE] From cstef at parallel.ru Tue May 14 11:25:01 2019 From: cstef at parallel.ru (Konstantin Stefanov) Date: Tue, 14 May 2019 11:25:01 +0300 Subject: [freebsd] =?utf-8?b?amFpbGF1ZGl0INC4INGA0LXQv9C+0LfQuNGC0L7RgNC4?= =?utf-8?q?=D0=B9_pkg_FreeBSD-latest?= In-Reply-To: <20190514081518.GG20712@yz.kiev.ua> References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> <20190514081518.GG20712@yz.kiev.ua> Message-ID: On 14.05.2019 11:15, George L. Yermulnik wrote: > Hello! > > On Tue, 14 May 2019 at 09:41:09 (+0300), Konstantin Stefanov wrote: > >> ??? ?? ???, ??? ???? ???? ??????? ?????, ??????? ?????? ??, ??? ??? >> ????, ? ???????? ???, ? ?? ???? ????? ??? ???????? ??????????, ??? ??? >> ?? ??????? ? ?????? ???-?? ??????????. ? ?????? ??? ????? ????????? >> ??????? ??????, ??? ?????? ????. ???????? ?????? - ????? ?? ???-???? >> ??????? ? /var/db/pkg (?????, ??? ?????? ???-?? ????, ?? ???? ????? >> ?????????? ????? ????????????? ???????) ? ????????? ????????? ??? ??? >> ????????? > > ?????? ? ???? ? ???? ?????? ??? ?????????????? ???????????? =) ??-?????, ??? ???????????? ???. ????? ?????? ??, ??? ????, ?? ? ?????. ????? ????????? ???, ????? ???? ??????????? ??????, ?? ??????? ?? ???, ??? ?????? ??? ? ????, ??? ???? ??? ?????????? ????? ???????? ????????????. > ????????? ??????????? ????? ??? ?????? - ?????, ?? ? ?????, ????? ? > ????????? ?????????. ???, ?? ??????: ?????, ? ??????? ? ???? ?????, ?????? ?? ??????????. -- ?????????? ???????? From yz at yz.kiev.ua Tue May 14 11:34:40 2019 From: yz at yz.kiev.ua (George L. Yermulnik) Date: Tue, 14 May 2019 11:34:40 +0300 Subject: [freebsd] =?koi8-r?b?amFpbGF1ZGl0IMkg0sXQz9rJ1M/SycogcGtnIEZyZWVC?= =?koi8-r?b?U0QtbGF0ZXN0?= In-Reply-To: References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> <20190514081518.GG20712@yz.kiev.ua> Message-ID: <20190514083440.GH20712@yz.kiev.ua> Hello! On Tue, 14 May 2019 at 11:25:01 (+0300), Konstantin Stefanov wrote: > > ????????? ??????????? ????? ??? ?????? - ?????, ?? ? ?????, ????? ? > > ????????? ?????????. > ???, ?? ??????: ?????, ? ??????? ? ???? ?????, ?????? ?? ??????????. ??????????: # pwd /usr/ports/ports-mgmt/jailaudit # make -V MAINTAINER cryx-ports at h3q.com # host -t mx h3q.com h3q.com mail is handled by 10 mail.h3q.com. h3q.com mail is handled by 30 mail.h3q.de. # telnet mail.h3q.com. 25 Trying 213.73.89.199... Connected to mail.h3q.com. Escape character is '^]'. 220 mail.h3q.com ESMTP EHLO my.host 250-mail.h3q.com 250-STARTTLS 250-PIPELINING 250 8BITMIME mail from:<> 250 ok rcpt to: 250 ok quit 221 mail.h3q.com Connection closed by foreign host. -- George L. Yermulnik [YZ-RIPE] From cstef at parallel.ru Tue May 14 12:50:31 2019 From: cstef at parallel.ru (Konstantin Stefanov) Date: Tue, 14 May 2019 12:50:31 +0300 Subject: [freebsd] =?utf-8?b?amFpbGF1ZGl0INC4INGA0LXQv9C+0LfQuNGC0L7RgNC4?= =?utf-8?q?=D0=B9_pkg_FreeBSD-latest?= In-Reply-To: <20190514083440.GH20712@yz.kiev.ua> References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> <20190514081518.GG20712@yz.kiev.ua> <20190514083440.GH20712@yz.kiev.ua> Message-ID: On 14.05.2019 11:34, George L. Yermulnik wrote: > Hello! > > On Tue, 14 May 2019 at 11:25:01 (+0300), Konstantin Stefanov wrote: > >>> ????????? ??????????? ????? ??? ?????? - ?????, ?? ? ?????, ????? ? >>> ????????? ?????????. >> ???, ?? ??????: ?????, ? ??????? ? ???? ?????, ?????? ?? ??????????. > > ??????????: > # pwd > /usr/ports/ports-mgmt/jailaudit > # make -V MAINTAINER > cryx-ports at h3q.com > # host -t mx h3q.com > h3q.com mail is handled by 10 mail.h3q.com. > h3q.com mail is handled by 30 mail.h3q.de. > # telnet mail.h3q.com. 25 > Trying 213.73.89.199... > Connected to mail.h3q.com. > Escape character is '^]'. > 220 mail.h3q.com ESMTP > EHLO my.host > 250-mail.h3q.com > 250-STARTTLS > 250-PIPELINING > 250 8BITMIME > mail from:<> > 250 ok > rcpt to: > 250 ok > quit > 221 mail.h3q.com > Connection closed by foreign host. > ??, ? ??????! ?????????, ??? ?? ? ????????? ????, ??? ?? ?????????? ???-?? ? ???? ??????????, ??? ?????? ???. ???????? ????????. -- ?????????? ????????, ??????????? ???????????? ?????????????? ?????????? ???? ??? ???. +7 (495) 939-23-41 From yz at yz.kiev.ua Tue May 14 13:06:58 2019 From: yz at yz.kiev.ua (George L. Yermulnik) Date: Tue, 14 May 2019 13:06:58 +0300 Subject: [freebsd] =?koi8-r?b?amFpbGF1ZGl0IMkg0sXQz9rJ1M/SycogcGtnIEZyZWVC?= =?koi8-r?b?U0QtbGF0ZXN0?= In-Reply-To: References: <4975cebb-ae8c-3ea5-08e7-0036ff968af9@parallel.ru> <6345de0f-9b67-9863-70f4-966711326307@grosbein.net> <20190514081518.GG20712@yz.kiev.ua> <20190514083440.GH20712@yz.kiev.ua> Message-ID: <20190514100658.GI20712@yz.kiev.ua> Hello! On Tue, 14 May 2019 at 12:50:31 (+0300), Konstantin Stefanov wrote: > ??, ? ??????! ?????????, ??? ?? ? ????????? ????, ??? ?? ?????????? > ???-?? ? ???? ??????????, ??? ?????? ???. ?????. -- George L. Yermulnik [YZ-RIPE]