Qortora · Search · Indexed page

www.nycbug.orgFetched 2026-08-15T06:37:29Z

NYC*BUG

New York City BSD User Group

Open original source · Full cached text

NYC*BUG Home About Speakers Colo/Mirrors Mailing Lists Friends Streaming dmesgd NYCBSDCon Meetings and Events Upcoming Past VIDAR - Server Protection for Internet facing FreeBSD Servers, Jim Brown 2026-08-05 @ 18:45 local (22:45 UTC) - Backroom of Brass Monkey 55 Little West 12th St Vidar is a combination of programs, a PostgreSQL database, and the SEC correlator engine that reads logfiles from authentication, email (postfix), and web server (nginx), (and potentially any other logs) and takes action based on SEC rules to add e ntries to an IPFW firewall. In concept it is similar to fail2ban and has some features in common with blocklistd. SEC reads the logs in real time and based on its rules and correlations, outputs metadata that is piped to a process that inserts the events into a PostgreSQL database and further pipes the offending IP address to a script that updates a table named BAD in IPFW. This table is read by IPFW rules to block offending external systems from wreaking havoc on a FreeBSD host. A corresponding table named GOOD contains whitelisted IP addresses so you dont accidentally lock yourself out. <RANT> Are you sick and tired of seeing: 2a03:b0c0:3:d0::402:d001 - - [31/Jan/2026:17:37:17 -0500] \x16\x03\x01\x05\xDE\x01 ... in your nginx logs and sick of seeing: Feb 20 16:36:03 jimby dovecot[59472]: imap-login: Disconnected: Connection closed (no auth attempts in 5 secs): user=<>, rip=206.168.34.125, lip=174.136.97.66, TLS: Connection closed, ... in your mail logs and sick of seeing: Feb 20 12:47:58 jimby sshd-session[47730]: Invalid user zzzz from 2607:f170:44:12::5d0 port 520 in your authentication logs? With Vidar, you get to put the hammer down: If you abuse my system, I will shut you out. Permanently. </RANT> Vidar has additional tricks - a way to dump the IPFW BAD table and a way to import it later - you can keep this database of shame up to date on all those miscreants and keep them away. You can even import the BAD table on another FreeBSD system running IPFW. Also, theres a handy audit script that lets you compare the entries in the database with what is actually in the IPFW BAD table. Also, Vidar keeps the evidence of the event in question that resulted in blocked access. Finally, using SEC rules, you can make the block last for an hour (for a misconfigured remote system) or a day (for a script kiddie), or permanently (for a determined hacker), or any length of time you choose. There is also a feature to check live processes and alert if, for example, the vi editor is running at 2:00am in the morning. Jim Brown is a long time BSD aficionado who currently lives in Durham, NC. Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. July Social, Could be you! 2026-07-01 @ 18:45 local (22:45 UTC) - Front table of Brass Monkey 55 Little West 12th St We are having a social meeting to catch up after BSDCan. Will bring a few ideas for future meetings, stickers. https://brassmonkeynyc.com/ Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. Let's review some OpenBSD mitigations, Brian Callahan 2026-06-03 @ 18:45 local (22:45 UTC) - Backroom of Brass Monkey 55 Little West 12th St How do we know that security mitigations actually work? How often should we review code to ensure they are continuing to provide? Following two recent publications, lets explore some of OpenBSDs anti-ROP mitigations. We will explore what they do, how to test they work, how to port them to other operating systems, and how to understand larger questions about security mitigations. Youll leave having a deeper appreciation for OpenBSDs sustained security track record. Brian is a long-time face in the *BSD world. While he claims semi-retirement from OpenBSD development, in reality he probably spends even more time on it getting students excited about the BSDs. He is the Director of the Monmouth University Cybersecurity Research Center, where here leads quantum cybers ecurity and other security research. Flyer Meeting Slides 2026-06-03LetsReviewSomeOpenBSD_Mitigations.pdf Meeting Notables https://ieeexplore.ieee.org/document/11458911 https://www.researchgate.net/publication/405728967_A_Final_Return_for_OpenBSD_Anti-Return-Oriented_Programming_Mitigations https://github.com/ibara/rop https://www.openbsd.org/innovations.html https://www.linkedin.com/in/brian-robert-callahan-ph-d-cissp-707738137/ Event Video Peertube / Toobnix.org: https://toobnix.org/w/ervMrV47x8oYEWCmW9aMwe (recorded and processed by Pat McEvoy) Youtube: https://youtube.com/live/hTI2KstsAfY (recorded and processed by Pat McEvoy) Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. The Design of Unix Shell, Stephen R. Bourne 2026-05-13 @ 19:30 local (23:30 UTC) - Backroom of Brass Monkey 55 Little West 12th St Were looking at having a fireside chat with Stephen R. Bourne, covering everything from shell to its design decisions, and the relevance today. Some relevant reading for the meeting might be Stephens 1978 piece in The Bell System Technical Journal entitled UNIX Time-Sharing System: The UNIX Shell https://archive.org/details/bstj57-6-1971 (Bell System Technical Journal, Vol 57, No 6, 1978). Steve Bourne is internationally known for his work on the UNIX operating system. During his career he spent 20 years in senior engineering management positions at computer systems and networking companies. These included Cisco Systems, Sun Microsystems, Digital Equipment and Silicon Graphics. Since 2000 he has been Chief Technology Officer at El Dorado Ventures (now Rally Ventures) in Menlo Park, California. He is past chair of the ACM Queue board, a magazine that he started in 2003 for software practitioners. Steve spent nine years at Bell Laboratories as a member of the Seventh Edition UNIX team. He designed the UNIX Command Language sh or Bourne Shell which is used for scripting in the UNIX programming environment and he wrote the adb debugger tool. His book The UNIX System was widely read and published in 1983. Flyer Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. What's Changed Since The Last Time I Came this Way - a talk that was supposed to be about OpenZFS, Michael W Lucas 2026-04-01 @ 18:45 local (22:45 UTC) - Backroom of Brass Monkey 55 Little West 12th St Michael W Lucas and Allan Jude are busy working on a new OpenZFS book, which means not only documenting everything thats changed in the last 12 years but discovering everything that they got wrong the first time. The quest for accuracy has taken Lucas deep into mailing list archives, Usenet, VAX installation manuals, the Kremlins first Internet connection, the United Nations effort to merge the BSD projects, and the ULTRIX and S51K filesystems, and left MWL more convinced than ever that filesystems are nothing but a April Fools prank. This hurriedly conceived and hastily assembled talk will update you on new OpenZFS features, but will also try to determine if its a good prankor not. Michael W Lucas name may ring a bell for some in the BSD community. Hes written several shelves of books. But for anyone who has seen him speak in public during Ante COVID days, it was clear they are mere transcriptions of his rambling presentations. For this NYC*BUG meeting, he is unlikely to edit out any of his expected corny jokes we endure during his conference presentations. More likely, you know his name from his grotesque horror fiction. In the same way his technical books are just transcriptions of his presentations, his fictionaal horror is just a simple reflection of someone who lives in a haunted house filled with (pet) rats in Detroit. Flyer Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. Weird Code Injection Techniques on FreeBSD With libhijack.pdf remote presentation, Shawn Webb 2026-03-04 @ 18:45 local (23:45 UTC) - Backroom of Brass Monkey 55 Little West 12th St FreeBSD is a widely-used open source operating system, powering your Playstation 4 and 5, Netflix, Juniper devices, and many other devices. libhijack is a post-exploitation tool to make code injection easier. In as little as four lines of code, developers can inject a complete shared object into another process fully anonymously. libhijack makes it easy to force the target process to create new anonymous memory mappings, inject code into memory-backed file descriptors, and finally call fdlopen on the memfd. This presentation walks attendees through various methods in which to stealthily inject code into a target process - some of these methods are new variants of prior work and remain unique to libhijack. Shawn Webb is the co-founder of the HardenedBSD Project and the founding president of The HardenedBSD Foundation, a tax-exmpt not-for-profit 5013 charitable organization in the US. While Shawn has a few decades of experience in infosec, both as a profession and a hobby, he considers himself a perpetual newb. He works for IOActive, an offensive security company, spending his time finding vulnerabilities in customer products. While working in the NSAs backyard, he had the opportunity to be mentored by two interns - an experience that changed his life. He and his interns focused on the intersection of human rights and information security and cybersecurity. Shawn lattera Webb also maintains a post-exploitation tool called libhijack. It makes runtime process infection and runtime function hooking for remote processes over the ptrace boundary incredibly simple on FreeBSD. Flyer Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. February Social, Could be you! 2026-02-04 @ 18:45 local (23:45 UTC) - Backroom of Brass Monkey 55 Little West 12th St We are having a social meeting to catch up after the holidays. Will bring a few ideas for future meetings, stickers. https://brassmonkeynyc.com/ Nearest NYC Subway is the 14th Street/Eighth Avenue station L, A, C, E. To get to the backroom, you must enter the front door, follow the long bar on your left, and walk all the way to the back. At the rear of the BrassMonkey, you will see an alcove for the 3 bathrooms our room is off to your right. Video meeting - upcoming 4th edition of The Book of PF, CRA and more, Peter Hansteen 2026-01-10 @ 13:00 local (18:00 UTC) - at an internet connected computer near you Peter Hansteen on The Book of PF 4th edition, and doing proper engineering Peter Hansteen has a new edition of The Book of PF, its fourth, hitting shelves near you just about now. Peter would love to tell you all about the book and how to use the PF toolset properly. Its about proper engineering. Which will be on the horizon more than ever in the coming months and years as the EU Cyber Resilience Act (CRA) is coming int force. Peter has a teaser presentation about that too, and youll see how these themes tie together nicely. Peter N.M. H…