Posts by niconiconi@mk.absturztau.be
(DIR) Post #BAXW35RRc8KLObPmAC by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@letoams@defcon.social systemd-resolved is NOT installed.
(DIR) Post #BAXZ9XojKKjt084r2G by niconiconi@mk.absturztau.be
0 likes, 1 repeats
@letoams@defcon.social Stop blaming systemd for all the world's real and imagined problems in existence. This problem is clearly just a default fallback behavior of glibc, not systemd. It's reproducible with a fresh Live ISO of Devuan Excalibur 6.1.1 amd64 minimal in QEMU, it's a Debian fork with SysV init, there are NO systemd processes running at all. You boot with kernel cmdline hostname=example.club, set the hostname in the system via hostname example.club, and overwrite /etc/resolv.conf with nameserver 8.8.8.8. The problem is 100% reproducible. In fact, using systemd may have saved me in this case, because systemd has an empty UseDomain by default for security, but I bypassed it, and glibc doesn't do this hardening by default.
(DIR) Post #BAXZaYYKhTsX6KHuWe by niconiconi@mk.absturztau.be
1 likes, 0 repeats
@lanodan@queer.hacktivis.me Not on Alpine, but on Devuan. Definitely glibc's fallback behavior.
(DIR) Post #BAXeBAfCskJzXdDZ7Q by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@datenwolf@chaos.social Independent of the init system, the hostname command by Linux's net-tools does not accept a "strict FQDN" with a terminating dot, it's rejected: the specified hostname is invalid. Systemd-specific: if /etc/hostname contains a terminating dot, it's stripped by systemd.This is consistent with the man page of hostname, which says using FQDN is a tolerated abuse, but strictly speaking it's never designed to use FQDN. The "correct" usage is to specify hostnames without suffix, the FQDN should be set via /etc/hosts, DNS, or NIS.
(DIR) Post #BAXeJ8W4kWXlCMkFTE by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@frobozz@tty0.social Too busy to test it for now because I found the problem while bringing up a server that must be ready ASAP. Perhaps you can give it a try.
(DIR) Post #BAXkbiOagnHPPhUCpM by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@letoams@defcon.social Untouched default.
(DIR) Post #BAYxqnv46HCodTRazI by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@markymarrow@mstdn.social The original post showed exactly this (strictly speaking, it used domain ., not search ., but they should be equivalent).
(DIR) Post #BAZCvX7xSVB3JgBhTc by niconiconi@mk.absturztau.be
1 likes, 0 repeats
@lanodan@queer.hacktivis.me Everyone knows the manga and light novels always last for ages, even after nobody remembers them.
(DIR) Post #BAZDBFs3NymcQhFGYC by niconiconi@mk.absturztau.be
0 likes, 0 repeats
Original manga and light novels are the Solaris and BSD in the anime world. They last ages after the anime ended. Outsiders would react with "it's not dead?", while hardcore anime fans quietly follow them in the background.
(DIR) Post #BAZHHzYIr7VFf7TVWS by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@datenwolf@chaos.social I bet nobody is interested in fixing the problem, because it's only an issue if you manage /etc/resolv.conf by hand which is rarely done these days. If you use systemd with both -networkd and -resolved activated, which is the standard these days, /etc/resolv.conf is automatically generated by systemd, and DNS is also provided by systemd. The auto-generated configuration files would override the default behavior (because systemd's option UseDomains= is an empty string by default exactly because of this vulnerability), meaning that most deployments are not affected. pass the developers of the Linux networking tools a copy of the *BSD manual I won't be surprised if the "hostname" does this because it's a kernel space limitation. It probably is."not apt for an age of 'servers are cattle not pets'"I bet the glibc code was last touched in the early 2000s, and nobody really cared about it anymore because of "servers are cattle not pets", as it affects manual workflows more than automatic workflows with systemd.
(DIR) Post #BAZfSnDlRQ4pVEYEs4 by niconiconi@mk.absturztau.be
0 likes, 0 repeats
Starting from the second next version, the existence of a systemd project maintainer is deprecated, systemd project maintenance will be delegated to systemd-lennartd.
(DIR) Post #BAZidQfbvP1wbuL7JI by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@xeno@snug.moe Some very old systems in the '70s used the term "nucleus" instead of "kernel".
(DIR) Post #BAZjPqdGhWtP1yKdRQ by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@still@infosec.exchange ...and I thought libarchive was the most powerful compression library because I can use "tar -xf cdrom.iso" (BSD only, use "bsdtar" on GNU userland).
(DIR) Post #BAbNoS5vGAlnUZyumm by niconiconi@mk.absturztau.be
1 likes, 0 repeats
Found yet another OpenSSL gotcha: secp256k1 is very, very slow, running at 10% speed comparison to NIST P-256 (secp256r1) and X25519. secp256k1 is a pretty fast curve, but due to its lack of TLS applications, almost no manpower was dedicated to its optimization. There was an open Pull Request but the code involved multiple projects and people, which made CLA signing and merging impossible. Conclusion: if you don't trust NIST P-series, just use X25519. Using secp256k1 can be more susceptible to handshake DoS. https://github.com/openssl/openssl/issues/23524 #tls #openssl #crypto
(DIR) Post #BAbz0fBS7JNVrnFoCO by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@lispi314@udongein.xyz Did you read the screenshot? The problem is that conf.d is powerless to modify already-defined variables non-destructively because it's not supported by the syntax, so this hack was explicitly designed to be used with conf.d. You drop the file into conf.d, and it uses Lua internal variables to change an existing global variable non-destructively.The non-hack solution would involve re-including the same file n times for every virtual host. You can't change the global variable, but you can use per-host variables to simulate that effect.
(DIR) Post #BAdY4vZKpWzFOe9a88 by niconiconi@mk.absturztau.be
0 likes, 0 repeats
@ash@fedi.shorks.gay You can use Nginx as a dynamic addr:port proxy like ssh -D via server name matching and capturing?! Unbelievable.
(DIR) Post #BAdq1QW1cz4rOO5NbM by niconiconi@mk.absturztau.be
0 likes, 0 repeats
The Internet be like: there is only one protocol in the world, it's called TLS. There is only one port in the world, it's called 443. Just run everything on port 443.
(DIR) Post #BAdrg3o73rKSn6UAhU by niconiconi@mk.absturztau.be
1 likes, 0 repeats
@phooky@hexa.club Some protocols already do in-band Path MTU Discovery by sending progressively larger application data payload to work around ICMP blackholes. So it's arguably some ICMP over TLS at play.
(DIR) Post #BAdvV2IwhviolHuFWK by niconiconi@mk.absturztau.be
0 likes, 0 repeats
Ideal: TCP is a reliable transport.Reality: By default, your SSH freezes after 20 minutes when it's not scrolling text, because a middlebox decides to close your TCP.
(DIR) Post #BAdzhh5xH6uiYx7ZTs by niconiconi@mk.absturztau.be
0 likes, 0 repeats
You know OpenSSH is truly a OpenBSD project when you see this warning message.