[00:00] but I also don't want any repercussions to fall to anyone else. [00:00] yeah, I do understand, it's the thing about dual use, everything has it's place [00:01] http://www.damnvulnerablelinux.org/ a few copies of different versions of windows, a networking switch, and backtrack linus ought to help [00:01] hack thyself [00:02] I'm not one to cross a line myself [00:05] so I get that, nice thing too is intentions are clear, what's the other side of cracking/black hat hacking, white hat hacking/hacking/computer security (that last one is the term that'll work the most) [00:05] understand tos [00:06] and you should be in the clear with any isp [00:12] techMiles: no solder walks into battle with just a shield, he usually has a sword too, so ISP's understand learning (it's doing that is more complex) [00:12] Yeah. [00:12] and I wasn't planning on anything like that [00:12] if anything, if I had a VPS, working on that. [00:13] not DDos, as that'd affect the entire host [00:13] but, you get the idea. [00:13] hmm I have access to Win7 and WinXP. [00:13] and a switch. :d enterprise switchhh [00:14] have attempted some mac address flooding to sniff the packets on the switch, but idk good tools [00:14] and am also paranoid about most of them, as idk what ELSE they do, if they have embedded malware, etc [00:14] as most of the free ones people create, aren't created with the best of intentions [00:15] have thought about taking a CEH course [00:16] well, you have heard of open soure right? free and you can inspect the code ;-) [00:17] heh. sadly I dont' know enough about the code to really know what to check for. [00:18] then something vetted by somebody else is good I take it [00:19] yeah. I like asking for recommendations. :P [00:20] what abt the hackthissite IRC? [00:20] any good? or a bunch of scriptkiddies? [00:21] http://www.backtrack-linux.org/backtrack/backtrack-used-by-the-nsa/ [00:22] I'd lvoe to get into that stuff. [00:22] I think that and a few lifehacker an Maximum PC posts shows the efforts of backtrack linux well [00:22] yeah. have seen the LH ones. love that site [00:22] and I have a MaxPC subscrip. :D [00:23] thanks to my gf. [00:23] <3 [00:23] hackthissite I have mixed feelings about, but it earns a metion [00:23] and if your on the security end, you'll see scripted attacks too [00:24] and if it didn't work, they wouldn't do it [00:25] yeah [00:25] I know about |----| this much linux [00:25] and about |-| this much security. [00:26] I know to encrypt any sensitive data/data transfers with as high as I can get. :D [00:28] the problem with measuring infinately evolving systems and knowledge, is measuring it accurately is infinately complex [00:29] yeah. [00:29] though, in general. lol. I know very little. [00:29] at least to me. [00:29] do I know this much security |-| or this much |----------------------------------------| [00:29] and what does it represent [00:29] same for linux ;-) [00:30] I know enough to know where to start with linux, and to generally manage my way around it, so far as server and desktop of ubuntu/debian. [00:30] security, idk where to start. [00:30] a lot of it is coding, which idk [00:30] there aren't any good college courses for it here. lol [00:30] as much as I'd love that [00:30] I want linux classes [00:30] even if I'd be bored, I'd learn moer and could help [00:30] it's something that one will never quit learning [00:30] and that'd be a foot in the door to moer. [00:31] CompTIA Linux+ and Security+ [00:31] I knowww [00:31] I want Security+ [00:31] that's it [00:31] the CompTIA Security+ pack is on my christmas list from amazon. :$ [00:32] as for linux, read up on iptables and ip6tables, for a firewall, dmcrypt for full disc encryption [00:32] will try and remember that [00:32] i do need to learn more on IPv6 [00:32] I'd love books [00:32] but by the time I finish reading them, they'er outdated [00:33] if they aren't outdated by the time they're written, published, and distributed. [00:33] they need an eBook that can be updated, and pushes out those updates and flags the chapters with new stuff ni them. [00:34] oh, the thing about outdated is that there isn't such things [00:35] another thing I wanna learn a LOT more about atm is IRC security [00:35] and backend stuff [00:35] like gecos....... no clue on what that is [00:35] besides an amphibious animal. :) [00:36] the so called Exploit Wednesday proves that "outdated" info can actually help an attacker [00:37] see I don't even know what you mean by Exploit Wed. [00:37] I feel so behind. lol [00:37] the day after Patch Tuesday [00:37] Ahhhh [00:37] makes sense [00:37] cyber monday [00:37] patch tuesday [00:38] exploit wednesday [00:38] the day when patches are out, and eveyone ignores them, or enough for Exploit Wednesday to work [00:38] Patch Tuesday is the second Tuesday of each month, on which Microsoft releases security patches [00:39] I knew about patch teusday [00:39] and I realize cyber mon has nothing to do with patch teus or exploit wed [00:40] the reason exploit wedensday works is an attacker can study the patch, and use that knowledge to attack an unpatched system easily [00:40] yeap. [00:40] reverse-engineering? [00:41] yep [00:41] that's why I runs the updates. :) [00:41] and white papers they write, explaining the patches [00:41] i know enough to have a decent firewall, keep my network firewalled, and to run a good antivirus which live-scans incoming data. [00:42] well, patches can have side effects, and enough patches at once can eat bandwidth like crazy [00:42] yeah. [00:42] one reason I like cacheing proxies myself [00:43] that's why Enterprises can use a striping of all even-machines, then all odd-machines, etc. and can download them to a local server [00:43] that distributes them to the rest of the network [00:43] 200 computers needing updates become 5, but still gotta test them if you expect a bad patch, better not need to unpatch 200 machines [00:44] yeah. [00:45] I like the idea of squid handling updates for windows, but I'd prefer for those numbers, that they run debian or ubuntu, and have a rsync mirror [00:45] squid? [00:45] after all, the best thing is run your own updates [00:46] https://help.ubuntu.com/community/Squid [00:46] a cacheing proxy server [00:47] what're the advantages of that? [00:47] like a DNS server? similar? but caches more of the data of a webpage? [00:48] ahhh nvm [00:48] I see it [00:48] that's cool. [00:49] gotta run. do you blog at all? :P sounds like I'd be able to read some pretty good info out of that [00:49] depends on it's config, but the basic idea is holding a copy of some files (my example above was windows updates) [00:49] yeah [00:50] same update wouldn't be re-fetched from MS servers [00:50] no, I haven't (and in hindsight I realize the flaw) [00:50] but that should be something I intend to fix [00:51] yes. :) [00:51] feel free to write up more info/references/tips like this for me... am loving it. :D [00:52] my issue with blogging is so much seems wrong, compared to IRC, more off the uff [00:52] or email or whatever if you don't put it up somewhere. [00:52] my issue with blogging is so much seems wrong, compared to IRC, more off the cuff [00:52] explain? [00:53] that's not to say I don't have a blog, I just let them die (unintended, but it happenes) [00:53] I'd ask more but I have to go down to my grandmother's, do her grocery shopping, help my girlfriend feed her horse, and possibly go down to a comicbook store tonight as well. [00:53] yeah. I let mine die, too. don't feel I have enough useful information to write about, really [00:53] unlike all these squid and unix tips from yourself. [00:53] ok, well, in short it's a simple as this is a chat, questions and answers [00:54] vs things to say, edit, never look right [00:54] ahhh. [00:54] hmm. [00:54] critic myself to death [00:54] take my questions, and just write 'em up in an email as a Q&A? [00:54] (I've got ideas around that, but you see the issue I' [00:54] no editing, it's like an offline multiplayer ntoepad. lol idk [00:54] ve had) [00:54] eyah [00:54] I can understand that. I am never satiesfied with my writing. [00:54] seems terrible wen I read others, etc [00:55] oh, others doesn't bug me (without a reason) [00:55] no I mean my writing seems terrible in comparison to others' [00:56] mine isn't a comparison even, just getting the point across, blog is one shot [00:56] yeah [00:56] I can explain here if you don't get it [00:56] here, I can ask immediate questions for clarification. [00:56] a blog I look at comments and what? [00:56] alright. well time to run! will hopefully ttyl, or another day. [00:56] maybe I can make a meetup sometime soon. [00:56] I'm usually around [00:57] well, I've gotta too, and idk where in the state you are [00:57] later, whoops ;-) [03:20] * cyberanger starts to choke on all the quiet [04:44] cyberanger: its friday night :) [04:45] * cyberanger says too late, strangled by the quiet, don't believe the sucide note [04:45] ha ha [04:46] cyberangewas.strangled.net will stay up as a tribute to poor cyberanger [04:47] :) [04:47] * cyberanger thinks he'll be hanging onto that domain as long as he can, seems to play into a fair bit of jokes lately [04:52] wrst: how was dinner? [04:53] it was good [04:53] all went well [04:53] made record time back from nashville [04:54] * cyberanger mutters something about a lead foot [04:59] my wife did the same thing [05:02] only slightly above the speed limit [05:02] slightly, huh [05:12] real really just five over [05:14] 5 over the limit or everyone else (I love this state for that) [05:18] the limit cyberanger I am using swype some I think I could get used to this [05:20] cyberanger good night just realized how late it is [05:22] ya.. getting pretty late [05:23] wow electricus you will turn into a pumpkin too good night [05:23] hehe, night wrst [05:24] friday night, quoting someone ;-_ [05:24] D'Oh, oh well, I was overusing those anyway [14:47] natty works again! [23:42] with all the quiet in here, I wonder, did I miss something? ;-) === mhall119_ is now known as mhall119 [23:48] hey cyberanger [23:51] hey wrst [23:51] cyberanger: its saturday guess that's why all the quiet? [23:51] * cyberanger starts to choke on all the quiet [23:52] citing last nights statement [23:52] I think this channels trying to kill me ;-) [23:55] :P [23:55] cyberanger: i read somewhere that the dock thing in 11.04 is not boing to be moveable... that's kinda crap [23:58] lousy [23:58] +1 for openbox and tin2 then [23:59] yeah that doesn't make me overly happy