-
ixmpp
is it possible to hotplug passthrough usb devices to and from bhyve vms?
-
rtprio
i think it'd need to be the pci address of the whole usb controller
-
rtprio
but it should
-
ixmpp
😩️
-
ixmpp
this is a problem
-
ixmpp
it's hard to have a hypervisor if you can't ...hypervise
-
ixmpp
i can passthrough the entire usb bus, but then i can't input to the host
-
cracauer
You could add a PCIe USB controller that you dedicate to the VM.
-
ixmpp
that was my first thought, but the one controller i do have is partially broken so i can't get it to power on
-
NatSocSiD
Hi, since I'm not getting the help I need in the pfsense channel, can I ask here? (I'm sorry if that's not a legit thing)
-
CrtxReavr
Does pfsense still use FreeBSD? I thought they were switching to linux.
-
NatSocSiD
It still use FreeBSD 12.3 for the latest version
-
NatSocSiD
But my issue is probably more related to pfsense than FreeBSD
-
kp
CrtxReavr: pfSense is very much FreeBSD based, and there are no plans that I'm aware of (and I contract for Netgate...) to change that.
-
kp
The upcoming 23.01 release will be based on FreeBSD main too.
-
ixmpp
alright i got it to work on one of the "good day" runs, but damn, all the graphics are corrupted
-
ixmpp
TIL wayland doesn't like the gpu being in passthrough mode, presumably
-
rtprio
ixmpp: sorry man, don't know if any hypervisor will do that
-
ixmpp
it works in theory
-
ixmpp
if only we lived in theory
-
endrift
I'm unsure how pfSense *could* switch to Linux, given, uh, pf
-
rtprio
yea.... no
-
NatSocSiD
How do I fix "DAD" issues? I'm getting this in the dmesg. em0: DAD detected duplicate IPv6 address 2001:470:1f07:26c::: NS in/out/loopback=0/1/0, NA in=1
-
NatSocSiD
em0: DAD complete for 2001:470:1f07:26c:: - duplicate found
-
NatSocSiD
I added fe80::1 as an alias to em0.... stupid me
-
NatSocSiD
then I deleted it but now I have a "duplicated" and it causes all sorts of issues.
-
rtprio
i would expect it to clear up if there truly is no duplicate address on the network
-
NatSocSiD
It's been ~5 hours, I rebooted multiple time but unbound refuse to bind on 2001:470:1f07:26c: since I did this
-
LxGHTNxNG
<reserves obvious sarcasm>
-
rtprio
and that ip is in ifconfig ?
-
rtprio
at this moment?
-
rtprio
ixmpp: in theory there is no difference between theory and practice, while in practice there is.
-
NatSocSiD
rtprio yes, but only one time. I'm not sure how it's duplicated
-
ixmpp
i do like that quote
-
dch
curl --cert-status -o /dev/null -vsS
git.sr.ht/~dch/ports give me a weird error
-
VimDiesel
Title: ~dch/ports - sourcehut git
-
dch
* SSL certificate problem: unable to get local issuer certificate
-
debdrup
dch: do you have Mozilla's bundle installed?
-
debdrup
Is your time accurate to within the margin of error for SSL/TLS?
-
dch
debdrup: yes, although this is a CURRENT laptop so maybe some sloppy upgrading on my part
-
dch
time is ok, and these sites work just fine in my browser
-
dch
*firefox
-
debdrup
Welp, then I'm out of ideas. :P
-
dch
debdrup: they were both good ideas :-)
-
dch
i will look for that script that regenerates tls certs that allan jude added a while back
-
debdrup
certctl?
-
dch
hmm probably
-
dch
thanks!
-
dch
certctl -v list is the same on both working and nonworking
-
_JusSx_
is there a channel for helping porters?
-
dch
yes
-
dch
#bsdports on EFnet
-
nimaje
there is #freebsd-ports here on libera too
-
dch
and mmm #freebsd-ports on libera too
-
_JusSx_
dch: thanks you very much
-
rtprio
dch: do other Letsencrypt certs work ?
-
dch
rtprio: its weird, browser works for everything, only commandline / curl
-
dch
I think its all LE certs
-
dch
I will do a fresh beinstall.sh soon
-
dch
and then it will probably all work again
-
daemon
when dealign with le acme.sh seems to do well with some tweaks
-
dch
this is something missing in my / I think
-
rtprio
can you pastebin the output?
-
dch
-
VimDiesel
Title: Snippet | IRCCloud
-
dch
^rtprio
-
rtprio
* CAfile: /usr/local/share/certs/ca-root-nss.crt
-
rtprio
* CApath: none
-
rtprio
dch is ca_root_nss installed ?
-
dch
rtprio: yep
-
rtprio
does curl --cacert /usr/local/share/certs/ca-root-nss.crt work ?
-
dch
-
VimDiesel
Title: Snippet | IRCCloud
-
dch
rtprio: and with the forced caroot it works
-
dch
let me delete & reinstall it
-
dch
nope, thats not sufficient
-
dch
but we're close
-
dch
curl --cacert /etc/ssl/cert.pem
freebsd.org -o /dev/null -4vsS works
-
VimDiesel
Title: The FreeBSD Project
-
dch
i.e. the softlink is fine
-
rtprio
uh
-
dch
so...
-
dch
reverting to curl-7.86.0 works
-
dch
hmmm
-
dch
and curl-7.87.0 does not
-
rtprio
i'm on 7.87
-
dch
me too on my desktop, and this only breaks on my laptop
-
dch
let me beinstall.sh and see if that fies it
-
rtprio
what is beinstall.sh
-
dch
oh boy are you in for some fun
-
dch
-
VimDiesel
Title: beinstall
-
dch
/usr/src/tools/build/beinstall.sh
-
rtprio
how is that different than make installworld installkernel distrdistribution DESTDIR=/mnt
-
dch
rtprio: it does the plumbing the upgrade and the boot environment all for you
-
rtprio
huhh
-
dch
and if something fails all is nicely rolled back
-
PredatorONormies
HI.
-
PredatorONormies
Inside a FBSD Jail - is there a way to leak public internet IP address if the only internet connection is to an localhost port?
-
rtprio
what do you mean?
-
rtprio
wall $(dig +short myip.opendns.com @resolver1.opendns.com)
-
rtprio
is that leaky enough?
-
PredatorONormies
The point is to not leak my address
-
PredatorONormies
And I said the only connection should be to localhost
-
PredatorONormies
Is there some sort of history file that stores IP addresses on FBS?
-
PredatorONormies
FBSD*
-
rtprio
a) yes there is a way
-
PredatorONormies
Really? How
-
rtprio
b) it depends on what software you run
-
PredatorONormies
How? Lol
-
rtprio
c) i'm not sure how it matters
-
PredatorONormies
c) it matters a lot
-
PredatorONormies
b) how? The whole point of me using FreeBSD jails is to strictly control networking access
-
PredatorONormies
a) how
-
rtprio
how does it depend on the software?
-
PredatorONormies
Yeah
-
PredatorONormies
Software depends on internet access in order to reveal IP address, right?
-
PredatorONormies
Think about it this way - what if I got some malware inside of an FBSD jail, and networking is strictly controlled?
-
AReal486
Has anyone worked with bhyve and Windows 98 - is it even possible?
-
llua
both ways you phased the question is vague enough to be yes or no
-
rtprio
PredatorONormies: i don't know man, what software are you running?
-
PredatorONormies
rtprio, Quark
-
PredatorONormies
How does it matter what software?
-
PredatorONormies
Like I said - imagine a fucking malicious person inside of the jail
-
PredatorONormies
how hard can that be?
-
PredatorONormies
:(
-
PredatorONormies
why you bully me
-
PredatorONormies
I need a jail for untrusted use
-
rtprio
yes, a malicious person inside a jail can figure out your public ip address.
-
dch
PredatorONormies: settle down please nobody's sassing you here
-
PredatorONormies
rtprio, how?
-
dch
PredatorONormies: a simple curl
jsonip.com will show the external NAT IP
-
rtprio
PredatorONormies: try that dig command i pasted
-
AReal486
llua I just want to know if it's even possible to get Windows 98 working on bhyve. I've cloned a disk with dd and want to see if I can make it boot.
-
dch
if you want to be hidden, then use tor or tor + vpn
-
rtprio
PredatorONormies: in my experience just answering the question is not that great in getting people to understand. which is why i ask, "what software, and why is it a problem"
-
llua
AReal486: i wasn't responding to you
-
rtprio
but quark is static files how are they going to root you that way
-
AReal486
oh, that was perfect timing then
-
llua
indeed
-
PredatorONormies
curl: (6) Could not resolve host:
-
PredatorONormies
Like I said - only networking connection should be localhost
-
rtprio
/r/homelab is full of people trying to hide their ip address and i simply cannot understand the attack surface
-
PredatorONormies
dch, see? It doesn't
-
dch
AReal486: I can't imagine anybody has ever tried,
wiki.freebsd.org/bhyve/Windows doesnt show it
-
VimDiesel
Title: bhyve/Windows - FreeBSD Wiki
-
rtprio
how are you going to serve any web files if it's only on localhost?
-
dch
PredatorONormies: ok, if you don't have *any* network access then ofc it won't work
-
PredatorONormies
rtprio, the proxy per-say is outside of jail xD
-
PredatorONormies
dch, BAKA
-
dch
PredatorONormies: but if you have network access then I will find your IP, curl is convenient, netcat is also functional
-
PredatorONormies
I am bad at explaining myself
-
rtprio
AReal486: i don't expect it to work, but let me see if i have that iso
-
dch
PredatorONormies: if you can't stop throwing insults around I have better things to do
-
PredatorONormies
I do ip4.addr="lo0|127. (some local IP)"
-
» dch nods
-
PredatorONormies
dch, what insulted you?
-
PredatorONormies
And I disabled IPv6 access
-
PredatorONormies
networking
-
dch
AReal486: maaaybe if you install sysutils/uefi-edk2-bhyve-csm as well, it might work?
-
rtprio
well you still have some local ip and with an ip there is a chance for it to... escape
-
PredatorONormies
Anything else I should know about? :/ Like I asked - I did in the past connect with a real straight (no bunny-hopping) internet connection so I might fear there is somewhere a log file with the IP address
-
PredatorONormies
rtprio, lol how?
-
dch
PredatorONormies: I think we're assuming this:
-
rtprio
PredatorONormies: we don't know enough of your layout to give you an answer
-
PredatorONormies
the IP doesn't directly connect to internet (on the outside of jail, where localhost connection mounts to next0
-
dch
internet <> router <> jail host running some proxy <> jail with loopback IP
-
PredatorONormies
;-;
-
PredatorONormies
dch, probably yes
-
dch
and you have something exploited that escapes to the jail only
-
PredatorONormies
I thought htat was obvious
-
PredatorONormies
exploited?
-
dch
welcome to the internet
-
PredatorONormies
something malicious, let's call it
-
PredatorONormies
lol?
-
PredatorONormies
can't we just use hand signals?
-
dch
so we have a compromised process in the jail
-
PredatorONormies
oky
-
dch
and what exactly are you worried about here that it does?
-
PredatorONormies
there are a few possible things it could do
-
PredatorONormies
let's focus on the easiest one to exploit
-
dch
from the jail, I can think of at least 5 ways I could identify the external IP of your router, presumably all behind NAT.
-
PredatorONormies
Like I said - in the past I connceted like this for some reasons I forgot: internet <> router <> jail, and perhaps there is public IP address LOGGED somewhere within that jail?
-
PredatorONormies
FIVE?
-
dch
I'm not even warmed up
-
PredatorONormies
let me hold your beer
-
dch
so inside the jail, running e.g. nginx or something like that?
-
PredatorONormies
something like that
-
dch
and you want to know if inside the jail itself, the public gateway (i.e. router) address would be visible?
-
PredatorONormies
but let's say even that got somehow compromised
-
PredatorONormies
what
-
PredatorONormies
yeah
-
PredatorONormies
aka public IP address that can deanonymize me
-
dch
so yes this is very easy
-
PredatorONormies
:( how
-
dch
the jail has network access, and is receiving inbound traffic, and has a compromised process inside it
-
PredatorONormies
not direct network access, remember
-
PredatorONormies
proxy aka firewall
-
PredatorONormies
You ever heard of Tor?
-
dch
*sigh*
-
BarnabasDK
Tor as in the system invented by US intelligence?
-
CrtxReavr
kp, perhaps I was confusing pfSense with OpenNAS?
-
daemon
even tor is not a perfet scape goat anyway
-
daemon
you can poison it with enough nodes offering relay
-
» CrtxReavr wonders how many TOR gateways are run by "three-letter organizations."
-
daemon
enough trusted peers within its web that is, saying a .onion is somewhere
-
daemon
CrtxReavr, I imagine far to many
-
BarnabasDK
and who controls the root keys for decrypting stuff
-
daemon
there are no root keys
-
daemon
its peer to peer for every link
-
BarnabasDK
true
-
BarnabasDK
so three points of attack, the algoritm, the key and the person
-
BarnabasDK
I do definately not trust tor in any way since I don't know all of them
-
CrtxReavr
Even if you're using (and trust) tor, you should still be using encrypted protocols over it.
-
BarnabasDK
that is a a way yes
-
daemon
in modern security as with old security the easiest is generally the person
-
daemon
spear phishing and its ilk often have the greatest chance of success
-
BarnabasDK
always
-
BarnabasDK
or just his dustbin
-
daemon
data/dumpster diving :D haha I remember that from years ago I bet it still would be true of modern organisations
-
BarnabasDK
it is
-
BarnabasDK
you may not get keys, but there is plenty of user ids to be had
-
daemon
I seen a bit of spam recently I thought was quite innovative
-
BarnabasDK
pwds
-
daemon
-
daemon
^ obviously stuffed blocked out for sanity reasons
-
daemon
and no one visit any url seen there
-
BarnabasDK
ah that is quite inventive
-
daemon
was sent to my work email address which is a tech firm
-
BarnabasDK
got one lately from "the water works"
-
daemon
oh what was they offering
-
BarnabasDK
in order to sync our new accounting system please log in and key in your current water usage
-
BarnabasDK
etc
-
BarnabasDK
log in being the part they where after
-
daemon
ooooh that is quite like the one our HR manager got, the persons resposible looked up who worked for ou company and emailed her asking up date payment/bank details to them as they changed banks
-
BarnabasDK
i DK we have a common public login system
-
daemon
weird when you start appreciating the efforts of the scammers/spammers
-
daemon
though innovation is innovation wherever it appears I suppose
-
parv
:-)
-
BarnabasDK
in fact all you have to guess in order to send a login request to someone is probably the user id today :-)
-
daemon
pretty sure they will all become awesome at marketing, development or automation shortly :D
-
BarnabasDK
"do you wish to login - swipe right"
-
BarnabasDK
there is one swipe between you and personal bankruptcy I suppose
-
BarnabasDK
ok .. that is a bit populistic
-
BarnabasDK
but - a password would be nice
-
Thoth
Hi People
-
PredatorONormies
> <BarnabasDK> Tor as in the system invented by US intelligence? < Yes
-
PredatorONormies
-
VimDiesel
Title: Tor Project | Anonymity Online
-
PredatorONormies
> <daemon> even tor is not a perfet scape goat anyway < Probably, yeah
-
PredatorONormies
> <daemon> you can poison it with enough nodes offering relay < That's why I prefer I2P :)
-
PredatorONormies
daemon, do you have some advice?
-
daemon
advice on what>
-
PredatorONormies
I'm trying to host a site from within a FBSD Jail, and have it be as secure from leaking my IP as possible
-
PredatorONormies
You seem to be familiar with Tor
-
PredatorONormies
what about Jails?
-
PredatorONormies
dch seems to have given up
-
daemon
yse I am I host several tor services but that is nothing to do with jails
-
daemon
you could simply install tor within the jail and offer a hidden service
-
daemon
run nginx or ngircd or w/e you want
-
daemon
bind it to localhost and point the tor hidden service at it
-
PredatorONormies
I run Quark xD remember it?
-
PredatorONormies
I do, daemon
-
daemon
I do not know what quark is
-
PredatorONormies
I run Tor outside of jails, on the host
-
PredatorONormies
and the site within a jail
-
PredatorONormies
we worked on Quark just recently
-
rtprio
you guys are still on about this?
-
PredatorONormies
remmber that redirect bug?
-
PredatorONormies
Of course
-
PredatorONormies
it's not a small deal to me
-
daemon
PredatorONormies, no I helped you with a buffering issue involving stdio
-
daemon
I did not even look up what quark is
-
daemon
anyhowe
-
daemon
if you run a website or ircd or something within a jail
-
PredatorONormies
daemon, that, yes
-
PredatorONormies
xD
-
daemon
all you do is create a bridge for that jail to be attached to that is not reachable via the outside internet
-
PredatorONormies
y
-
daemon
you run tor on the host and point a hidden service to the internal ip of the service of the internal bridge
-
PredatorONormies
dch> internet <> router <> jail host running some proxy <> jail with loopback IP
-
PredatorONormies
This, right?
-
daemon
the service is not connectable via the outside internet only via a tor hidden onion
-
PredatorONormies
Yeah
-
PredatorONormies
dch said there are at least 5 ways he could at the time remember, with which one can deanonymize from within the jail
-
daemon
depends how insane you want to be
-
PredatorONormies
I connected with the jail directly to the internet before, would there be any self public IP logged anywhere?
-
daemon
a generic non vnet jail
-
PredatorONormies
daemon, pretty insane?
-
daemon
yeah that sounds about right
-
PredatorONormies
right.. I think I don't have a vnet? But I have some vnet devfs rules so IDk
-
daemon
there are two types of jails
-
daemon
ones based on VIMAGE and ones that are not
-
daemon
the ones that are not share there localhost, with the host system
-
PredatorONormies
VIMAGE?
-
daemon
this is like chroot in linux
-
daemon
VIMAGE style jails have their own IP stack
-
PredatorONormies
oh
-
daemon
if you wanted even more isolation there is also bhyve which is an actual hypervisor
-
PredatorONormies
in jail.conf I did `ip4="lo0|127..."`
-
PredatorONormies
sounds like insecure bloat
-
daemon
I am not prepared to teach you the difference between those three ^ as it would take hours and I am busy trying to get drunk
-
PredatorONormies
wraping a RAGING dog in toilet paper
-
PredatorONormies
> trying to get drunk < sounds familiar xD
-
daemon
however
-
rtprio
PredatorONormies: ok, not sure where you get that info from
-
PredatorONormies
I drink wine so slow that I cannot really get drunk
-
PredatorONormies
because otherwise I'd have to go pee rly often
-
daemon
-
PredatorONormies
rtprio, what info from?
-
VimDiesel
Title: VIMAGE: Setup Guide | The FreeBSD Forums
-
daemon
this is old
-
PredatorONormies
xD
-
daemon
but I believe still accurate
-
rtprio
PredatorONormies: your info on bhyve
-
PredatorONormies
rtprio, no info
-
PredatorONormies
daemon, rejected
-
PredatorONormies
Does forums.freebsd.org ban the Tor network?
-
rtprio
connect with it and see
-
rtprio
we can't do everything for you
-
PredatorONormies
I did, rejecte
-
daemon
Many websites seemingly do not allow you to access them via tor due to protection from DDOS provided via things like cloudflare
-
PredatorONormies
That's not what I meant
-
daemon
the tor network is massive
-
PredatorONormies
someone I "knew" just did a firewall rule to block the Tor network
-
PredatorONormies
and this same error appeared
-
PredatorONormies
I know
-
daemon
certain nodes may be banned certain ones may not be
-
daemon
you can't just block the tor network
-
PredatorONormies
newer ones aren't, I know.
-
PredatorONormies
You can the majority of it
-
daemon
100's of exit nodes leave and re-appear every minute
-
PredatorONormies
all exit nodes are public, by which I mean their IP addresses
-
daemon
for the services they wish to allow you to connect to yes
-
PredatorONormies
Yeah I know, but I won't be sitting here for 2 hours just to try and load a fucking page lol
-
rtprio
PredatorONormies: based on this whole converstation i'm not sure you have a very soild grasp of ip networks
-
PredatorONormies
??
-
daemon
well then get a cell/mobile phone paid for in cash and a pay2go data plan, in conjunction with a cash laptop from facebook and use that from a field
-
daemon
problem solved
-
PredatorONormies
XD
-
PredatorONormies
what about satellites? (a joke, obviously)
-
daemon
also boot the laptop from a live usb
-
daemon
im starting to wonder what the hell you are trying to hide from
-
PredatorONormies
No need
-
PredatorONormies
I don't use ShitScripts
-
PredatorONormies
daemon, the governments, of course.
-
rtprio
what's a shitscript?
-
daemon
toilet paper? I mean maybe?
-
PredatorONormies
JavaScript, TypeScript, any kind of manipulation one can done on the user computer.. obviously I'm not talking about something like just HTML (which isn't really a programming langauge)
-
PredatorONormies
lol
-
daemon
well html is a markup language - its in th name :)
-
rtprio
i have no idea what you're on about, or what javascript has to do with... hiding your ip from the government or what
-
PredatorONormies
hyper-text-markup-language, did I guess right?
-
daemon
im going for a smoke
-
PredatorONormies
rtprio, it has all the DO about it
-
PredatorONormies
rtprio, you obviously aren't educated about the concept of browser attacks
-
PredatorONormies
daemon, have fun.. I hope we can talk some more.
-
rtprio
you have no idea what i'm educated in, but what do browser attacks have to do with hosting some shitty httpd in a jail
-
PredatorONormies
rtprio, who said they do?
-
V_PauAmma_V
Is this the right channel for this discussion?
-
rtprio
nope
-
rtprio
moving on
-
PredatorONormies
Yeah
-
PredatorONormies
> <PredatorONormies> I don't use ShitScripts < I cannot figure out why I said this '<PredatorONormies> I don't use ShitScripts'
-
PredatorONormies
whoops
-
PredatorONormies
I need a slap on the face to wake the fuck up
-
PredatorONormies
nice name
-
rtprio
maybe a slap will change your mind about fool's folly of "hiding my ip address"
-
PredatorONormies
It's not a fool's folly. The dangers I have might not seem real to you because you cannot imagine how dangerous governments are. Why would you? You seem to be a normie. Let me guess, you think you got nothing to hide, right?
-
rtprio
stay on topic
-
PredatorONormies
you continued it again
-
rtprio
ok man, then good luck figuring it out
-
rtprio
it's not paranoia if they're actually after you
-
PredatorONormies
It isn't paranoia if you know what their rules are and you're breaking them :) not to mention worse happening to other people
-
rtprio
maybe Ross Ulbricht can help you
-
PredatorONormies
Laugh all you want, before you burn for your mistakes, by the hands you trusted in.
-
PredatorONormies
That almost sounded cool
-
rtprio
almost as cool as almost running illegal services on tor and serving life in prison
-
PredatorONormies
> If you feed a dog, the dog will protect its feeder, regardless of him being
-
PredatorONormies
good or bad
-
PredatorONormies
- unknown, unknown
-
dch
well this graylog 4.3.9 -> 5.0.2 upgrade is turning into a fairly diabolical experience
-
dch
needs to upgrade mongodb 3 times to get to mongo 5.0
-
dch
and now elasticsearch isn't supported so I need to migrate all the things to opensearch 2.0
-
dch
(recall the elastic vs AWS drama and subsequent fork)
-
meena
dch: why does graylog need MongoDB?
-
dch
meena: for config
-
dch
config & data are separated
-
dch
if only theyd used something else than mongo
-
meena
dch: after three upgrades of MongoDB you'd want to fake it with PostgreSQL?
-
polyex
pkg can haz i3 4.22?
-
V_PauAmma_V
polyex, is it can be bogzila tiem nao?