Skip site navigation (1)Skip section navigation (2)
Date:      Wed, 29 Oct 2014 16:42:03 -0400
From:      William Bulley <web@umich.edu>
To:        freebsd-security@freebsd.org
Subject:   broken portaudit !!
Message-ID:  <20141029204203.GA1265@itcom245.staff.itd.umich.edu>

next in thread | raw e-mail | index | archive | help
Thinking that I might wish to upgrade my 9.2-STABLE system (to 9.3-STABLE),
I decided to run "# /usr/local/sbin/portaudit -Fda" only to find that someone
at FreeBSD.org has borked the system:

   unix# /usr/local/sbin/portaudit -Fda
   fetch: http://portaudit.FreeBSD.org/auditfile.tbz: Not Found
   Couldn't fetch database.
   Old database restored.
   portaudit: Download failed.

I think some folks have moved on (to the new system) without having given any
thought to those folks (like me!) who are just a tad bit behind the herd...  :-(

See the security risks here:

   http://vuxml.freebsd.org/freebsd/

[[Note: portaudit.FreeBSD.org resolves to vuxml.freebsd.org/freebsd/]]

unix% dig -t A portaudit.FreeBSD.org

; <<>> DiG 9.9.3-P2 <<>> -t A portaudit.FreeBSD.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 60842
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;portaudit.FreeBSD.org.         IN      A

;; ANSWER SECTION:
portaudit.freebsd.org.  3600    IN      CNAME   wfe0.ysv.freebsd.org.
wfe0.ysv.FreeBSD.org.   2737    IN      A       8.8.178.110

;; Query time: 51 msec
;; SERVER: 68.94.156.1#53(68.94.156.1)
;; WHEN: Wed Oct 29 16:43:38 EDT 2014
;; MSG SIZE  rcvd: 116

unix% dig -t A vuxml.freebsd.org

; <<>> DiG 9.9.3-P2 <<>> -t A vuxml.freebsd.org
;; global options: +cmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 41971
;; flags: qr rd ra; QUERY: 1, ANSWER: 2, AUTHORITY: 0, ADDITIONAL: 1

;; OPT PSEUDOSECTION:
; EDNS: version: 0, flags:; udp: 4096
;; QUESTION SECTION:
;vuxml.freebsd.org.             IN      A

;; ANSWER SECTION:
vuxml.freebsd.org.      3600    IN      CNAME   wfe0.ysv.freebsd.org.
wfe0.ysv.freebsd.org.   3600    IN      A       8.8.178.110

;; Query time: 90 msec
;; SERVER: 68.94.156.1#53(68.94.156.1)
;; WHEN: Wed Oct 29 16:43:50 EDT 2014
;; MSG SIZE  rcvd: 85


I also note that not only is the database MIA, but there is at least
one bad link at the bottom of:

   http://vuxml.freebsd.org/

and that (borked) link would be:

   http://svnweb.freebsd.org/ports/head/ports-mgmt/portaudit   :-(


Regards,

web...

-- 

 /"\   ASCII RIBBON          / William Bulley
 \ /   CAMPAIGN AGAINST     / 
  X    HTML E-MAIL AND     / E-MAIL: web@umich.edu
 / \   LISTSERV POSTINGS  /

72 characters width template ----------------------------------------->|



Want to link to this message? Use this URL: <https://mail-archive.FreeBSD.org/cgi/mid.cgi?20141029204203.GA1265>