/srv/irclogs.ubuntu.com/2009/12/30/#ubuntu-server.txt

PC_Nerd1011Hi - I had a server installation setup to my laptop (crossover), and my laptop wirelessly to the internet, then bridged the connections....  such that I statically set the sever to 192.168.0.7...   I've since placed it in a seperate subnet, and while the /etc/resolv.conf file states its statically 192.168.1.2, pinging and dns/dhcp works to it... but a nslookup <hostname> of that server resolves to its old IP address...   how c02:03
PC_Nerd101Is there any way to test that apt connections are definately connecting to the proxy as specified in /etc/apt/apt.conf.d/01proxy ?...  I have abox running apt-cacher, but I want to make sure that if that box is for whatever reason unavailable, that the updates will fail instead of defaulting to the direct updates....03:42
pmatulisPC_Nerd101: sniff the wire while an apt operation is in progress03:47
PC_Nerd101hmm ok -   what program would you recomend for packet sniffing?03:54
JanCPC_Nerd101: tcpdump, wireshark, ...04:00
PC_Nerd101JanC: Thanks :)04:32
PC_Nerd1011Should apt-cacher include the headers, eg if I disconnect fromteh internet after running a proxied/cached "aptitude update" - should the next machine be able to get the package information from teh cache without having to send any packets at all to teh internet?05:04
PC_Nerd1011Hi - is there a specific tool recomended for execution of commands over multiple ssh connections, similar to tentakel as written about at  http://tinyurl.com/tentakel-tutorial ?07:05
erichammondPC_Nerd1011: I'm not sure what's recommended, but I occasionally use clusterssh for interactive control of multiple hosts.  You might also check out dsh.07:29
uvirtbotNew bug: #501568 in mysql-dfsg-5.0 (universe) "package mysql-server-core-5.0 (not installed) failed to install/upgrade: nicht vollständig gelesen in buffer_copy (Backend dpkg-deb während »./usr/sbin/mysqld«)" [Undecided,New] https://launchpad.net/bugs/50156807:36
PC_Nerd1011erichammond: Thanks, I'll look into it :)07:44
=== Thugal_ is now known as Thugal
jericoWhat do you guys think. ext3 or ext4 for a home server?08:27
Jeeves_ext408:29
Jeeves_faster08:29
Jeeves_and less clueless progs that don't use the fs correct08:29
jericoIf I was going to setup a partition for only 700MB files should I use standard, largefile, or largefile408:34
Jeeves_I don't think that it matters much08:34
jericoalright, thanks Jeeves08:35
Jeeves_np!08:38
=== johe|work_ is now known as johe|work
uvirtbotNew bug: #362067 in mysql-dfsg-5.0 (universe) "package libdbi-perl 1.607-1 failed to install/upgrade: el paquete libdbi-perl ya est? instalado y configurado" [Undecided,New] https://launchpad.net/bugs/36206709:01
PC_Nerd1011What is the best method to image a server installation ( almost duplicate hardware), but to be able to change things like the hostname upon writing the image for each copy ?10:33
_rubeni tend to go for unintended (preseeded) installs instead10:35
_rubendoing a systemwide find/replace on the hostname is quite doable as well .. it kinda boils down to how much customization you want/need10:36
PC_Nerd1011not much - all it requires is to copy the /etc/apt/apt.conf.d/01proxy, authorised ssh keys for a specific user ( which will be the one user on each machine), and the /etc/resolv.conf /etc/hosts and /etc/network/interfaces files - thats it10:39
PC_Nerd1011ultimately - I'd like to look at doing a diskless boot from an image, and simply have each physical machine have their static hostname... is that possible?10:42
_rubennot if there's more customization needed than just the hostname (like diff ssh keys) .. perhaps ltsp is more suited for this ?10:44
_ruben!ltsp10:44
ubottuLTSP is the Linux Terminal Server Project, which adds thin-client support to Linux servers. See chapter 3 of the !edubuntuhandbook, http://www.ltsp.org and/or http://en.wikipedia.org/wiki/Linux_Terminal_Server_Project10:44
PC_Nerd1011hmm, I'm farely sure I want the seperate machines, copied images with static hostnames...  its for a custom server app...   think "blade servers with dynamic resource allocation" - but through software not hardware, and therefore based on hostname10:48
_rubenah10:50
PC_Nerd1011The main thing is that when its installing packages ( eg openssh-server) upon installation, I want it to be using the apt-cacher's proxy setting ....   is there a way to interupt the server's live cd installation in order to add this proxy setting ?11:26
_rubenif apt-cacher acts as a "normal" proxy, you should be able to specify that during install time just fine11:32
_rubencould even preseed it11:32
_rubeni never used apt-cacher or similar, i have a full local mirror (using debmirror, planning to move to plain rsync)11:32
PC_Nerd1011Hmm ok - well I"ll have a good read through all the documentation on preseeding etc and decide on teh best method11:48
PC_Nerd1011thanks :)11:48
_rubenpreseeding + local mirror = install "simple" machines in just a few minutes11:48
_rubensimple meaning not a lot of (big) packages11:49
PC_Nerd1011hmm - I just dont want to have a massive repository mirror that I will rarely/never use. ( ++ the storage required_11:54
PC_Nerd1011btw - I've just managed to have only one account, root password not setup and then I've made a mistake in /etc/sudoers - meaning I cant sudo nano /etc/sudoers to fix it...   is there a factory restore for sudoers ?11:55
_rubenboot into single user recovery mode, you'll be root, fix /etc/sudoers11:58
PC_Nerd1011thats a grub boot menu option isnt it ?12:00
_rubenyeah12:02
=== ogra_ is now known as ogra
uvirtbotNew bug: #501628 in samba (main) "package samba-common 2:3.4.0-3ubuntu5.3 failed to install/upgrade: Unterprozess installiertes post-installation-Skript gab den Fehlerwert 1 zur?ck" [Undecided,New] https://launchpad.net/bugs/50162813:16
erichammondIs there a PPA with the latest ec2-api-tools package version available?  The one on Karmic does not support registering EBS boot AMIs.14:19
uvirtbotNew bug: #501648 in krb5 (main) "Strange dependencies in "libkrb5-3" (kerberos) package " [Undecided,New] https://launchpad.net/bugs/50164814:47
erichammondLooks like smoser's will do: https://launchpad.net/~smoser/+archive/ppa14:48
uvirtbotNew bug: #498987 in vlan (main) "vlan" [Undecided,New] https://launchpad.net/bugs/49898715:15
_rubennice bug title :p15:16
uvirtbotNew bug: #501655 in mysql-dfsg-5.1 (main) "package mysql-server-5.1 5.1.37-1ubuntu5 failed to install/upgrade: subprocess installed pre-removal script returned error exit status 1" [Undecided,New] https://launchpad.net/bugs/50165515:31
sarmaHi, my ubuntu server was comprimised via apache phpmyadmin. I am trying use  netstat -npcuve but I got a lot of empty but tcpdump shows a lot of connection.18:55
sarmaAny ideas ?18:55
sarmaWhat i am trying to find out which process is doing DDOS.18:56
Ninjixsarma: try htop18:56
sarmaok18:57
Ninjixsarma: investigate what is using cpu18:57
Ninjixshould be a good tipoff18:57
sarmaNinjix, cpu is free18:58
sarmaJust a sec18:58
sarmaI have 4 cpus indicators but process i do not see ????18:59
Ninjixsort by usage or by mem18:59
sarmaCpu 4 says 84.1 usage18:59
Ninjixhave you restarted your apache2?18:59
sarmaI unistalated it19:00
sarmaapt-get remove purge19:00
sarmaand stop first19:00
Ninjixok.19:00
sarmaonly sshd is active19:00
Ninjixis your mysql still running?19:01
sarmaNop19:01
sarmaI have 3 sshd19:01
Ninjixwhat does `netstat -an | grep tcp` look like?19:02
sarmanormal19:02
sarmaonly my ssh sessions19:03
sarma319:03
sarmasessions and listening tcp6       0      0 :::22                   :::*                    LISTEN19:03
sarmaOne more thing my provider blocked all internet traffic from my server.19:04
sarmaSo maybe this is the reason why nothing shows in netstat19:04
Ninjixare those connection attempts in the tcpdump or outbound from your host?19:04
PJiPhoneBest bet might be to backup data and reinstall from scratch19:06
PJiPhoneVerify config files ok before migrating19:07
sarmahttp://pastebin.com/m7cb4fe919:08
sarmaHere is the tcpdump19:08
PJiPhoneBbl19:09
Ninjixsarma: what does `netstat -nlp` return currently?19:10
sarmahttp://pastebin.com/m61af2fdc19:11
sarmaHere it is19:11
sarmaNothing19:11
Ninjixsarma: looks like your apache was running a worm19:11
sarmaLooks like19:11
sarmaVirus19:11
sarmaBuy ubuntu-servers uses www-data user only19:12
sarmaHow can this spread as root user19:12
Ninjixhave you looked for new files, yet?19:14
sarmaYes i have19:14
Ninjixturn up anything?19:15
sarmaAnd i found out all of them in tmp and so on.19:15
sarmaThem19:15
sarmabloody thing19:15
sarmait i have bash in that folder19:16
sarmasmall bash size19:17
Ninjixwell, if you are feeling confident enough, you can run `sudo watch -n 1 netstat -nltup` in a separate console19:19
Ninjixthen re-install apache and look for odd behavior19:20
Ninjixthe previous malware may have siblings trying to communicate with it on the same IP19:20
sarmaNext time i will choroot bloody apache19:22
Ninjixbut best bet is to backup your data after checking it for contamination then reinstall19:22
sarmaYes i will do so19:23
sarmaTnx man for you help.19:23
Ninjixnp19:23
Ninjixand good luck19:23
sarmaAny other recomendation how to protect my web server more on ubuntu19:24
sarmaI regulry do update19:24
sarmaBut look like thats not enough19:24
Ninjixset a policy that all admin type web apps get moved to different port than general pub (http 80/443)19:24
Ninjixor setup some .htaccess rules that only allow access to admin web apps from localhost19:25
Ninjixuse ssh port redirection to access your admin apps19:25
NinjixApache binaries are pretty solid and Debian community does a good job keeping it patched up19:27
sarmaThis was a exploit in Phpmyadmin, the problem is i can not prevent from students from instaling such aplications?19:27
Ninjixthe PHP, Rails and other code we install in our Apache is an entirely different story.19:27
Ninjixahh... I see19:28
Ninjixmight want to ask around in one the PHP or LAMP channels19:29
Ninjixbet you are not the first sysadmin to face this particular problem19:29
sarmaOh tnx very much. I will try my luck with chroot19:30
DrManhattanGood afternoon MenZa , good to see you again20:14
tarskihow easy is it, if i want to download and install the server edition, but I want to use lighttpd instead of apache. is this easy to do? or are things woven together in the distro for apache20:45
Ninjixtarski: just install the base system then added the lighttpd packages as needed20:49
tarskiNinjix: so when I download && install the cd, I'm given the choice if I want to install apache or not?20:50
tarskiNinjix: I mean the server-edition ISO20:51
Ninjixtarski: yes20:52
Ninjixyou will get several configuration options20:52
tarskiNinjix: thanks20:52
Ninjixyou can select all, some or none20:52
NinjixI think you will want to select only the SSH Server option then add what you want by hand post-install20:53
tarskiNinjix: ok. sounds good.20:54
ptingis there a sshfs fstab options such that it'll do a sudo su immediately after mounting? ie... sshfs#myserver: /mnt/blah fuse user,noauto,initcmd='sudo su' 0 021:13
ScottKpting: I don't know the answer to your question, but generally sudo -i would be preferred to sudo su.21:15
ptingScottK, thanks for the pointer. i'll remember to use that next time21:18
uvirtbotNew bug: #501718 in samba (main) "Samba dosn't work if I change the name of computer from intslation to another" [Undecided,New] https://launchpad.net/bugs/50171821:21
TXXHey21:31
TXXI got ubuntu server installed with no Desktop envoirment21:32
TXXbut i want gnome installed but not booted into when i start the system21:32
TXXi just want it as an instance to vnc into21:32
TXXi started with a simple sudo apt-get install x-window-system-core xserver-xorg gnome-desktop-environment21:32
TXXbut Package x-window-system-core is a virtual package provided by:21:32
TXX  xorg 1:7.4+3ubuntu1021:32
TXXYou should explicitly select one to install.21:32
TXXi get this output21:32
NinjixTXX: maybe you should install desktop and set it to boot into console run level21:34
TXXNinjix, how do i set it to boot into console?21:34
TXXcause i just install the ubuntu-desktop package and then set boot to only use console21:35
TXXi can just insatll the *21:35
TXXevt get logged into the login screen when vncing in to get a option of choosing what DE21:42
NinjixTXX: edit your /etc/default/grub file and set GRUB_CMDLINE_LINUX_DEFAULT=”quiet splash text”21:46
TXX: o21:47
TXXNinjix, you are so lovly i could donate some money to you, but i am broke21:47
Ninjixthen you are using the correct OS at the right price. :)21:47
TXXXD heh yeah i guess so21:48
Ninjixmake sure you run `sudo update-grub` after editing21:48
TXX: o21:48
TXXoh shit yeah thanks21:49
Aisonwtf is going on here23:04
Aisoni'm running a ubuntu server with samba23:04
Aisonnow I copied 1gb zip file to this samba share23:05
Aisonafter comparing the md5sums they are different23:05
Aisonso I copied again23:05
Aisonbut then, they are again different23:05
Aisonwell, now after 5 times copy, the md5 sums are equal23:07
Aisoncrazy!23:07
MTecknologyAison: samba sucks..23:07

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!