home.social

#pf — Public Fediverse posts

Live and recent posts from across the Fediverse tagged #pf, aggregated by home.social.

fetched live
  1. 🚨 EUVD-2024-24238

    📊 Score: 7.8/10 (CVSS v3.1)
    📦 Product: Linux, Linux, Linux (+17 more)
    🏢 Vendor: Linux
    📅 Published: 2024-05-01 | Updated: 2026-08-05

    📝 In the Linux kernel, the following vulnerability has been resolved:

    KVM: Always flush async #PF workqueue when vCPU is being destroyed

    Always flush the per-vCPU async #PF workqueue when a vCPU is clearing its
    co...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  2. 🚨 EUVD-2024-24238

    📊 Score: 7.8/10 (CVSS v3.1)
    📦 Product: Linux, Linux, Linux (+17 more)
    🏢 Vendor: Linux
    📅 Published: 2024-05-01 | Updated: 2026-08-05

    📝 In the Linux kernel, the following vulnerability has been resolved:

    KVM: Always flush async #PF workqueue when vCPU is being destroyed

    Always flush the per-vCPU async #PF workqueue when a vCPU is clearing its
    co...

    🔗 euvd.enisa.europa.eu/vulnerabi

    #cybersecurity #infosec #euvd #cve #vulnerability

  3. Every time I have anything to do with #nftables I'm reminded just how much I dislike it (and #iptables before it) and how great #OpenBSD #pf is.

  4. Game seeks players! #PF-1e Ahkean Adventures
    Flavour: "Semi-free form low to mid level Pathfinder game where youths touched by the divine come into their own."
    Read more: rpgcrossing.com/showthread.php
    cdn.bsky.app/img/avatar_thumbn

    Missing content? Check our main feed at bsky.app/profile/rpgcrossing.b

    #pf
  5. Game seeks players! #PF-1e Ahkean Adventures
    Flavour: "Semi-free form low to mid level Pathfinder game where youths touched by the divine come into their own."
    Read more: rpgcrossing.com/showthread.php
    cdn.bsky.app/img/avatar_thumbn

    Missing content? Check our main feed at bsky.app/profile/rpgcrossing.b

    #pf
  6. Sobre Vald3mar da #Costa Net0 , presidente do #PL, partido de Flávi0 Rachadinha Chocolate B0Is0nar0 ( #PL RJ) , é alvo de investigação da #PF por desvio de R$ 119 milhões em #Emendas -

    instagram.com/p/Dany-qcJqc_/ -

    RI @helder.rsilva13 - #Emendas #Corrupção -

  7. Enquanto a #PF investiga o #B0Is0Master sobre indícios de #Fraude, #ManipulaçãoContábil e bloqueio de centenas de milhões de reais, a gestão de Tarcísio de Freitas aparentemente abriu as portas do consignado da Polícia Militar para o #DigiMais -

    instagram.com/p/DZ8AboVo9t_/ -

    RI @reisptsp -

  8. @bpl I'd recommend moving domain blocklist expectations to a higher level outside the browser, whether your /etc/hosts to prevent domain-name resolution or a local firewall (I'm a fan of #pf) preventing outbound access to a list of hosts to prevent communications with them even if connected by IP address alone rather than name.

    #pf
  9. @bpl I'd recommend moving domain blocklist expectations to a higher level outside the browser, whether your /etc/hosts to prevent domain-name resolution or a local firewall (I'm a fan of #pf) preventing outbound access to a list of hosts to prevent communications with them even if connected by IP address alone rather than name.

    #pf
  10. Finally it's here! Unfortunately I have only the previous 2 editions of @pitrh book of PF and never got the first edition.

    P.S.: screw that Bezos guy, I bought them directly from Nostarch Press.

    #RunBSD #PF #OpenBSD

  11. Finally it's here! Unfortunately I have only the previous 2 editions of @pitrh book of PF and never got the first edition.

    P.S.: screw that Bezos guy, I bought them directly from Nostarch Press.

    #RunBSD #PF #OpenBSD

  12. Jaques Wagner criou “ambiente propício” ao Master segundo a PF | BandNews TV

    Saiba mais em: 📱 Redes sociais: 📸 Instagram: 🐦Twitter: ➡️ TikTok: 🔵 Facebook: #bandnewstv #PT #Governo #Master #Fraude #PF #operação

    fllics.com/en/video/jaques-wag

  13. Jaques Wagner criou “ambiente propício” ao Master segundo a PF | BandNews TV

    Saiba mais em: 📱 Redes sociais: 📸 Instagram: 🐦Twitter: ➡️ TikTok: 🔵 Facebook: #bandnewstv #PT #Governo #Master #Fraude #PF #operação

    fllics.com/en/video/jaques-wag

  14. ❤️ #FreeBSD jails

    I'm turning a cheap-ass VPS into a gotosocial instance. I created 3 jails for nginx, postgres and gotosocial service. This works really cleanly, each jail has an internal IP address, the only ports open on the VPS are port 22 (for ssh, password login disabled), and 80 and 443 which route directly to the nginx jail. So simple to set up and extremely secure. #ZFS means the storage overhead for each jail is small. #PF (packet filter) is the firewall. Everything is quite tractable.

  15. ❤️ #FreeBSD jails

    I'm turning a cheap-ass VPS into a gotosocial instance. I created 3 jails for nginx, postgres and gotosocial service. This works really cleanly, each jail has an internal IP address, the only ports open on the VPS are port 22 (for ssh, password login disabled), and 80 and 443 which route directly to the nginx jail. So simple to set up and extremely secure. #ZFS means the storage overhead for each jail is small. #PF (packet filter) is the firewall. Everything is quite tractable.

  16. I upgraded my box to #FreeBSD 15.1-RELEASE. Everything ran smoothly as always.

    After that I upgraded my 3 #Bastille #jails to FreeBSD 15.1-RELEASE too.
    I just found anything strange:

    {HOST} # bastille service <JailName> pf restart

    [JailName]:
    Enabling pfpfctl: DIOCADDRULE: Operation not permitted
    /etc/rc.d/pf: WARNING: Unable to load /etc/pf.conf.
    pfctl: DIOCSTART: Operation not permitted.

    To solve this issue with PF startup, I had to change jails securelevel to 1 instead of 2 (default value).

    Is it normal now, or should I missed something?

    #FreeBSD #BastilleBSD #PF

  17. I upgraded my box to #FreeBSD 15.1-RELEASE. Everything ran smoothly as always.

    After that I upgraded my 3 #Bastille #jails to FreeBSD 15.1-RELEASE too.
    I just found anything strange:

    {HOST} # bastille service <JailName> pf restart

    [JailName]:
    Enabling pfpfctl: DIOCADDRULE: Operation not permitted
    /etc/rc.d/pf: WARNING: Unable to load /etc/pf.conf.
    pfctl: DIOCSTART: Operation not permitted.

    To solve this issue with PF startup, I had to change jails securelevel to 1 instead of 2 (default value).

    Is it normal now, or should I missed something?

    #FreeBSD #BastilleBSD #PF

  18. While doing some device testing, my understanding of how DummyNet is setup on PF was lacking. The Manpage gave no examples. So here are some for #FreeBSD #PF Routers.

    Up Only
    pass quick on $if_int from <slowDevices> to <fb> dnpipe 1

    Up/Down (Responses)
    pass quick on $if_int from <slowDevices> to <fb> dnpipe (1, 2)

    Manpage:"The first pipe or queue number will be used to
    shape the traffic in the rule direction, the second will be used to shape
    the traffic in the reverse direction."

  19. While doing some device testing, my understanding of how DummyNet is setup on PF was lacking. The Manpage gave no examples. So here are some for #FreeBSD #PF Routers.

    Up Only
    pass quick on $if_int from <slowDevices> to <fb> dnpipe 1

    Up/Down (Responses)
    pass quick on $if_int from <slowDevices> to <fb> dnpipe (1, 2)

    Manpage:"The first pipe or queue number will be used to
    shape the traffic in the rule direction, the second will be used to shape
    the traffic in the reverse direction."

  20. I'm trying to setup wireguard, but as a first step, I can't seem to get a simple ping to work, not even to the normal ip address. I'm guessing it's a firewall thing, I've already set `pass inet proto icmp all icmp-type $icmp_types keep state` but no luck.. (pf on FreeBSD)

    Giving up for today 😅

    #pf #firewall #icmp #FreeBSD

  21. PF investiga empresa de Virginia por R$ 22,4 mi recebidos: Relatórios do Coaf citam repasses à Talismã Digital; defesa da influenciadora nega irregularidades. Leia no Poder360. poder360.com.br/poder-justica/ #PF #TalismãDigital

  22. Daniel Vorcaro tenta enviar delação mas as informações não agradam a PF | BandNews TV

    Saiba mais em: 📱 Redes sociais: 📸 Instagram: 🐦Twitter: ➡️ TikTok: 🔵 Facebook: #bandnewstv #Master #Vorcaro #PF #delação

    fllics.com/en/video/daniel-vor

  23. Daniel Vorcaro tenta enviar delação mas as informações não agradam a PF | BandNews TV

    Saiba mais em: 📱 Redes sociais: 📸 Instagram: 🐦Twitter: ➡️ TikTok: 🔵 Facebook: #bandnewstv #Master #Vorcaro #PF #delação

    fllics.com/en/video/daniel-vor

  24. TIL that #OpenBSD's #pf doesn't whinge about using variables in CIDR notation:

    wan_if="ixv0"
    dmz_if="ixv1"
    dmz_cidr="24"
    pass in on $wan_if to ($dmz_if:network)/$dmz_cidr

    I haven't tested to see if it does what I *intended*, but at least

    $ pfctl -nvf test.pf

    doesn't spew errors… 😆

    (even if it feels kinda dirty)

  25. TIL that #OpenBSD's #pf doesn't whinge about using variables in CIDR notation:

    wan_if="ixv0"
    dmz_if="ixv1"
    dmz_cidr="24"
    pass in on $wan_if to ($dmz_if:network)/$dmz_cidr

    I haven't tested to see if it does what I *intended*, but at least

    $ pfctl -nvf test.pf

    doesn't spew errors… 😆

    (even if it feels kinda dirty)

  26. I have a #firewall question that perhaps #AskFedi can help with please: Is it worth pre-calculating a whitelist by removing black listed items from it first, and if so, what tool do you use to do that?

    More specifically: I have a geoIP based whitelist for some countries. I also have a global blacklist. I was thinking it might be easier to create one allow list, that removes the IPs (v4, v6, and ranges in CIDR notation) that appear in the blacklist from the geoIP list. I'm running #pf on #FreeBSD if that makes a difference. Or should I just load both into the firewall as pass and block respectively, and let it calculate if the IP is allowed to connect?

    I tried using grepcidr to do this calculation, but it doesn't seem to do the set maths I was hoping it would do. But I'm not even sure it's worth bothering.

    #Networking #HomeLab #webserver #OpenBSD

  27. I have a #firewall question that perhaps #AskFedi can help with please: Is it worth pre-calculating a whitelist by removing black listed items from it first, and if so, what tool do you use to do that?

    More specifically: I have a geoIP based whitelist for some countries. I also have a global blacklist. I was thinking it might be easier to create one allow list, that removes the IPs (v4, v6, and ranges in CIDR notation) that appear in the blacklist from the geoIP list. I'm running #pf on #FreeBSD if that makes a difference. Or should I just load both into the firewall as pass and block respectively, and let it calculate if the IP is allowed to connect?

    I tried using grepcidr to do this calculation, but it doesn't seem to do the set maths I was hoping it would do. But I'm not even sure it's worth bothering.

    #Networking #HomeLab #webserver #OpenBSD

  28. Use #IPv6 they said! It's the future!

    Can I please have the 3 hours back that I wasted trying to resolve a #pf firewall issue caused by transposing two digits in an IPv6 IP address?