Does this mean OpenBSD will have to update the tagline on their website that says "Only two remote holes in the default install, in a heck of a long time!"?
Does this mean OpenBSD will have to update the tagline on their website that says "Only two remote holes in the default install, in a heck of a long time!"?
So, no. Still holds.
Worth pointing that Linux has had a rough week as well, this one is pretty bad: https://www.openwall.com/lists/oss-security/2019/12/02/2
Patch your systems.
Added: Just to be clear, this doesn't give any significant access to the system itself through smtpd even if it is configured to be remotely accessible. So not a possible remote hole. Dunno about other stuff.
pass in on egress proto tcp from any to egress port smtp
And maybe another one with submission instead of "smtp".I am not trolling, he was cheered a lot
back in the day, everyone adapted
its config somehow.
Yeah I know, although I don't remember coming across Tavis's config I did live through those heady days of customizing window managers and remember them with fondness. [Although that screenshot has emails dated 2006, which puts it well after that culture had peaked.]
I actually started using fvwm2 again recently on one of my machines, I am not sure why, maybe I had some nostalgia for that time period.
Back in the day I patched dwm and then Surf to enable WebGL among other nice stuff thanks to gobject being brain-damagedly easy.
Nowadays I am too lazy: cwm, tmux, mpg123, mpv+ytdl, vimb/iridium, UBo, Vimium, HTTPS ev, Priv badger, and I call it a day.
Last time I installed CentOS the only port open on the firewall by default with OpenSSH after all.
This OBSD bug is externally exploitable.
Why did you single out an obscure Linux bug? There are quite a few other OSs available apart from OBSD.
Still sucks for those of us who, you know, actually use smtpd on OpenBSD as a mail server. Thankfully it's just my personal one and I can afford to comment out the line(s) that actually enable outbound SMTP relaying, but still.
- Login with no SSH account
- Enable SSH
- Change PF rules
- Change the smtpd config
- Enable radiusd/ldapd without being root
- Running Xenocara's xlock when is not available on servers and I have no permissions
Can you exploit a bare OpenBSD install by default remotely, yes or not?
Everything else is bullshit.
And sshd is, by default:
- not exploitable by this bug
- PF rules are not set for incoming connections
The X issue. By default:
- PF doesn't accept any connection to X ports to
anything not coming from lo0, localhost interface
Smtpd. By default:
- it just listens on localhost
- there is no forwarding
- PF rules aren't enabled