[00:40] mr bacon is missing: http://imgur.com/gallery/s7m9R [00:43] heh [01:09] InHisName was just me trying to win karma on reddit :-p === TheEvilPhoenix is now known as Resistance [06:21] woot [06:21] hello [06:36] ls [06:36] woops :( [09:28] Morning [09:56] morning JonathanD [09:59] hey rmg51 [10:20] o/ [11:17] good morning now that we are all back together a 2nd time [11:17] indeed. [11:17] InHisName: why did you break freenode. [11:21] I just was trying out a new hacker tool, I din't realize it was gonna DOooo something......... [11:33] Good bacon to all! [13:33] mr bacon came and went already and I couln't send him the bucket o' bacon [13:48] om nom bucket 'o bacon === paulproteus_ is now known as paulproteus [17:38] I'm dabbling around with iptables and NAT trying to connect outside to 192.168.101.163:80 anyone have suggestions. All that I tried haven't made a diff yet. [17:40] I'm seeing a default web page from my astlinux box I want the other to respond not this one. The astlinux box is where the iptables are used. [17:41] Where is "outside"? [17:43] wild wild internet [17:47] You can't route to a private IP range across the internet because the internet routers will block it [17:52] you would need to route it at the router [17:52] if you have access to it [17:52] think firewall [17:58] ^ [18:28] after experimenting with several iptable items, I needed one FORWARD and one PREROUTING item to get page to play from hidemyass proxy. Now I have a simple page up at that web site playing off one of my machines instead of a host web site. [18:35] jedijf: meeting tomorrow night? I have a potential "new contributor" to the team that would like to see what we're all about here on irc :-p [18:35] He saw we have meetings, but didn't know if they were a real thing [19:47] I have lotta usb logging into /var/log/messages -- how do I find where logs coming from so I can decide if I want to turn it off ? [19:51] seems this is set to 'yes' -- zcat /proc/config.gz | grep USB_STORAGE_DEBUG [19:53] zcat /proc/config.gz | grep USB_DEBUG [19:53] that one not set [20:28] http://pastebin.com/HJphhm89 [20:29] I found errors in /var/log/messages back in early morning hours. [20:29] Errors on ports that 'shields-UP!' reports as stealthed. [20:30] Can someone interpret these lines into something meaning ful ? [20:31] the logging above in in dmesg some sort of 'ring logging' Things fall off pretty quick due to all the USB logging. [20:32] s/in in/is in/ [20:32] InHisName, someone is trying a dictionary attack on your server [20:34] those ports 35739 and so on are all tested as 'stealthed' by shields up! How is someone hooking into a stealthed port ? [20:35] Or is that HIS IP and port numbers ? [20:35] InHisName, that's the remote port [20:36] Oh now makes more sense. Is there clue which of my ports they are trying to punch on ? [20:36] InHisName, my guess would be 22 [20:36] InHisName: just use shorewall and lock up your ports.. use pubkey auth for your ssh [20:36] InHisName, that's the standard ssh port [20:37] Yes, I noticed I had left it 'open' a few days ago and forgot about it. It is closed now. [20:38] switch port [20:38] You could always use 443 [20:38] 52500 [20:39] I am playing with web server on internal machine and connecting to port 80. What can these .ru folks try to do in that port. [20:39] You all saying to use 443 or 52500 in place of 80 ? [20:39] leave it open; the F opyum team needs something to do [20:39] if you change the port they'll have a harder time finding it [20:41] It might be tough on anyone who wanted to browse to that website if they did not know to postfix :52500 on end. [20:41] right [20:41] but if you're just playing with your own you can put it wherever you want [20:42] why does he need all of this? [20:42] j/w? [20:42] InHisName: mainly 22 [20:42] But for next few weeks where no one will be browsing yet, sounds like at least good enough temporailly. [20:42] let them hammer your 80 [20:42] InHisName: intruders? [20:42] just set a good password for ssh, lockout after 3 attempts. [20:42] thats all. [20:43] aparently so. I left 22 open for a few days. No one was getting in only 2 users and really goofy passwords. [20:43] InHisName: and no root login [20:43] sshd.config [20:43] yeah [20:43] vim that baby! [20:43] sshd_config :/ [20:43] vim is 20 years old? [20:43] jeez [20:43] search for permitrootlogin [20:44] that machine does have a root. Not ubuntu [20:44] for ssh you don't wnat to allow root login [20:45] root@inhisname.com would be a disaster [20:46] its all closed up now. Now I've opened up port 80, should I change it to big port #? [20:46] InHisName: just change it(ssh) [20:46] ssh is closed 2 hours ago [20:47] InHisName: fwiw, i moved my SSH traffic to 63329 [20:47] * Resistance chose a random port :P [20:47] i also use 2222 on occasion [20:47] depending on the setup [20:47] right now I don't need any ssh traffic from outside [20:48] Resistance: not very secure now that we all know your port and IP address... [20:48] MutantTurkey: i didnt say its to this system ;P [20:48] sure sure [20:48] but NO bot logging here so not too awful [20:48] MutantTurkey: you cant even be sure that's the correct port ;P [20:48] who cares, it's give you log monitor practice [20:49] then netstat and see the ircbots they install as crons [20:49] and john internally scanning itself [20:49] the compromised box [20:50] honeyd homework [21:30] Ok, now got big numbered port open and 80 closed. [21:31] InHisName: 80's not the problem, 22 was [21:33] I said a couple times that 22 got closed up and was asking about 80 and what to expect from that being open. I close it about 4 hours ago now. [23:04] how come when I do 'last', I only get one line output. The file grows larger after each login/logout. Still only the first line is shown with last command. [23:05] I am running an older linux 2.6.16.12 with busybox doing the last command. [23:12] waltman: new UPS works, holodeck is secure. [23:17] InHisName: try last -n5 [23:18] for 5 lines(if they exist) man last for more info...-Fad may interest you [23:20] JonathanD: excellent [23:21] JonathanD: pleia2 seems to think she's in "Florida" this week, so I guess it's working [23:21] I needed extra power for florida. [23:25] understandable, what with all that heat down there [23:25] Indeed. [23:26] and emulating Disney must be tough [23:27] waltman: emulating disney isn't the hard part. [23:27] oh? [23:27] Getting re-broadcast rights to do so is. [23:27] it's not technically being broadcast, is it? [23:27] it is, to lots of virtual people. [23:28] Besides, the media companies think you should pay for broadcast licenses if animals can hear your music. [23:28] oh, you mean that *you're* Disney? [23:28] When my cousins went down there last month, that was YOU? [23:28] There is no disney. ONly my basement. [23:28] impressive! [23:28] it's all a myth. [23:28] That explains a LOT [23:29] This is why it's always so crowded there. [23:29] it explains the mouse motif [23:29] I don't like mice. [23:29] exactly! [23:29] I haven't seen one (outside a pet store) in quite a while. [23:30] Last time I saw one was I think at my parents house, when in high school... [23:30] I shot it :/ [23:30] yow [23:30] ! [23:30] oh wait [23:30] last time was the mouse + snake? [23:30] outside doesn't count [23:30] that's NATURE [23:31] https://secure.flickr.com/photos/47445571@N07/5041763415/in/photostream [23:31] cute mouse + big scary snake [23:31] https://secure.flickr.com/photos/47445571@N07/5041763249/in/photostream RAWR I AM DEATH SNAKE! [23:32] at some point I figured out what kind of snake that was, but now I forget [23:33] I recall [23:33] waltman: apparently one that likes mice, though. [23:37] many snakes like mice, no? [23:39] I think I'd decided it was an Eastern Rat Snake [23:39] it must have been confused [23:39] as that isn't a rat. [23:40] bah, no. [23:40] eastern milk snake [23:40] that isn't a milk eihter. [23:42] wikipedia says they got the name because they're often found near barns [23:42] of course, it's not a barn, either [23:46] it's actually not been very hot, so I don't think it's working very well [23:46] hmmmm [23:47] pleia2: isn't it supposed to be 20F above the norm wherever you travel? [23:47] pleia2: the sizing algorithm for the parrots seems a little off, too [23:47] haha [23:48] * pleia2 lurks in conference hallways [23:49] there is a lot of yuengling here, it's weird [23:49] clearly I'm in PA [23:50] pleia2: beer is hard to simulate. [23:50] yeah [23:50] Much easier to just use local stuff. [23:52] JonathanD: Perhaps this explains why they switched to synthehol in the next gen series [23:57] I'm beat today. I probably should've skipped Central. [23:59] I should have skipped that beer