[00:32] alpha3 fails for accessibility install; orca starts and quits immediately when you get to the live desktop [00:33] :( [00:33] I think there is too much crashing to make it usable by orca [00:37] hai Pendulum and charlie-tca === jono_ is now known as jono [00:38] we just discovered undifined was hacked today .and the hacker comes root straight away [00:38] he use the owner his name [00:38] to do things under the ownders name [00:39] what seams to have happen to by jacky possible [00:40] we now let all teammembers from speechcontrol and wintermute check there pc s [00:40] he was in 5 attempts true ssh [00:40] in amazingly fast way [00:40] :( [00:41] undi will give logs from it to help irc [00:41] undi said i never have this fast way hacking [00:41] he camre true ssh [00:42] and undi have worked by government and by europese license office [00:42] If a hacker got in through ssh, can he tell who it was? [00:42] so he know from security [00:42] its a a ip from a turkish server [00:43] 212.58.4.188 [00:43] yeah, but IP doesn't mean that much. Anyone can buy a server somewhere [00:43] Doruk.net [00:43] server in Istanbul - TURKEY [00:44] AlanBell, had checked it [00:44] (or if it's a really good hacker, they could be using a machine they've hacked into to then hack into more machines [00:44] ) [00:44] you're not a bank, and you're not a government. the authorities won't care that someone tried to crack your system [00:44] its means security needs to be improved [00:44] they'll care if they stole identity and start using your credit cards, but that's about it [00:45] i care when wintermute things and speechcontrol things are gone [00:45] they even have used it to come on wiki [00:46] what explaned why the links from the wiki where linking to empty pages [00:46] that happened on 18 february [00:46] i don't think linux like to be hacked [00:47] well just do with the info you all want [00:47] just don't say i have not warned for it [00:47] the hacker use the owners name [00:47] you only can see it on the ip adress [00:49] i have say jacky to warn everone from wintermute and speechcontrol that all team members need to check there pc [00:50] till later i am very busy at the moment not meant to be rude just want to inform you thats all [00:51] for info undifined have logs to proof it and to let see how the hacker works [00:52] http://paste.ubuntu.com/574729/ its all on here [00:58] charlie-tca: Hrm let me try the alpha 3 candidate and see if I can reproduce what you found with Orca. [00:59] If ssh is involved, IMO key authentication is the only way to do. [00:59] s/do/go/ [01:07] paultag is already busy with it [01:07] i think he know that things TheMuso ?or need i to tell him [01:14] hajour: He likely knows. [01:14] TheMuso: thanks. [01:14] Mine was a hardware installation here [01:14] ok thank you TheMuso :) [01:15] I will probably try it again tomorrow, and file all the crash reports, but I am too tired today to file them all [01:16] good night charlie-tca :) [01:16] good night, hajour [01:16] its 2:16 here in night [01:16] undi is still awake [01:16] get some rest, morning comes too fast [01:16] he don't want to go sleeping before this is resolved [01:17] and he have to be awake again at 6:00 [01:18] That pastebin does not show how the hack was successful... [01:18] Unless I missed something. [01:18] All I see are invalid attempts, then, stuff to do with a session close for root. [01:19] i just have said to undi what you said TheMuso [01:20] he comes later tomorrow again and will explain it then [01:21] i am not a IT person [01:21] i only have give true what undifined said [01:22] hajour: No problem, just not sure if I've missed something. [01:22] he says it have no use to do true me he better tell it himself [01:22] * TheMuso is now checking his gateway box ssh related activity, since he has an open ssh port for when he is on the road. [01:22] but now he really need to sleep he only have 4 hours left to sleep [01:22] TheMuso, hajour : I see nothing in that pastebin either, except failed attempts. [01:23] * TheMuso usuallyd oes check, but check again after the above discovery. [01:23] charlie-tca, undifined will tel tomorrow [01:23] he need to sleep [01:23] I will to. so far, my firewall has held up well. I will go look in the logs tonight though and make sure [01:24] ok charlie-tca and TheMuso :) [01:24] i also need to go to sleep [01:24] i have 5 hours left then the kids need to wake up [01:24] Goodnight [01:25] goodnight TheMuso and charlie-tca [01:25] and everyone else [01:25] * hajour yawns [01:25] charlie-tca: For me, the minimum requirements for ssh are key authenticatino only, and only allowing specific users with the AllowUser directive. [01:25] my logs are absolutely full of root ssh attempts, which is blocked. [01:26] yup, I get hits constantly on my firewall. I use key authentication, but also specific ip's allowed in only [01:27] I set iptables up to only allow my local ip addresses in [01:27] Yeah thats ok if you know where you are connecting from, but when on the road/over seas, I never know. [01:27] that's true [01:27] I can not even connect myself when not at home [01:28] Thats fair enough if you are willing to live with that. [01:28] Wow, a lot of attempts with oracle as the username. [01:30] I am not smart enough to know how to set it safely for other uses [01:31] Fair enough. [01:31] I have fail2ban set up on mine [01:31] never quite figured that out either [01:31] I just install it and leave it at default :) [01:31] locks you out after 3 failed attempts [01:31] * Cheri703 tried it successfully then had to wait for it to clear -_- [01:32] *tried to get it to block er [01:32] *her [01:32] Cheri703: How long does it take to clear? [01:32] 15 or so minutes? maybe? [01:32] I think that's one of the things you can change, but I haven't bothered [01:33] but it may be long enough to get whoever is poking at it to move on [01:33] dunno [01:33] fair enough. [01:33] 3 failed attempts and that ip isn't allowed access [01:33] just a small protection piece [01:33] I dunno, maybe I'm too lax with mine [01:33] Yeah, I think keys do a large part of securing SSH, you just have to be careful with the keys themselves. === jasono_ is now known as jasono [02:45] charlie-tca: Whilst booting into the desktop with accessibility/orca enabled works for me, I suspect I might know what caused it for you, and I think its a race. WIll upload a fix for it post alpha 3. [02:45] Thanks === API is now known as Guest80757 [17:25] hi, would anyone be interested in packaging the Qt at-spi bridge some time? [17:43] fregl: probably [17:43] fregl: where is the code? [17:45] AlanBell: it needs at-spi2 to work, other than that it is a single .so plugin. feedback welcome http://gitorious.org/qt-at-spi [17:45] maco: ^^ [17:46] will give it a look this weekend [17:47] thanks [17:58] maco: I am interested in helping, but you are the Qt guru [17:58] not a guru [17:59] just someone with a teensy bit of qt programming knowledge [17:59] everything is relative [18:48] Hey hi! [18:49] is there any team working on voice recognition? [18:50] darkdevil666: it's kinda complicated, but you probably want to talk to hajour and UndiFineD about speechcontrol [18:51] it's an upstream project that was started by them [18:51] bascially, voice recognition is something that linux and open source in general is waaay behind on [18:52] but hopefully speechcontrol will improve some of it for Ubuntu [18:52] I think it's really mainly meant for commands right now [18:52] (but they're also still a very new project) [18:52] that's wonderful [18:53] things that aren't so closely ubuntu related you might also want to look at are julius and CMUSphinx and simon listens [18:53] Thanks pen [18:53] you're welcome :) [18:54] (I'm head of the ubuntu accessibility team so it's kinda what I do to know this stuff ;-) ) [18:54] (especially since I'm not a developer) [18:54] thnks a lot pendulum [18:54] UndiFineD: sorry, I missed that you said that. but I'm happy to send people your way who are interested :) [18:55] darkdevil666: you're welcome :) === zkriesse_ is now known as zkriesse === popey_ is now known as popey