/srv/irclogs.ubuntu.com/2012/03/11/#ubuntu-mythtv.txt

NashaKHello all, could anyone tell me why, after editing ~/mythtv/.lircrc and rebooting, my changes arent recognised by myth?02:03
NashaKAll has been well previously, remote working fine, but now after making some modifications, newly assigned buttons dont work, and modified buttons dont work02:06
NashaKIronically, all the buttons im having issues with are irexec related02:08
Naranekok, so... do you know any reason why mythbuntu would create ssh keys and a root account to mysql for them?10:33
NaranekI think my mythbuntu box was hacked some time ago, because I found this strange account in mysql, and there were some ecdsa-keys I definitely hadn't done myself10:36
Naranekso I wiped the system and did a fresh install10:36
Naranekbut now the keys and the account have appeared again10:37
Naranekon the ubuntu forums there is another mythbuntu user with the same problem, so I wouldn't rule out that there's an unpatched vulnerability in mythbuntu10:39
Naranekany ideas what to do?10:40
Naranekok, I also have root login enabled in the sshd_config10:50
Naranekso I'm definitely hacked10:50
Naranekcould you have a look if you have strange logins in mysql.11:03
franksteraudio stopped working with mythtv this morning - was wondering if it is because of the recent mythtv updates this weekend11:49
franksteram running oneiric11:49
frankster2012-03-11 11:30:20.445 ALSA, Error: no playback control PCM found on mixer device default12:21
frankster2012-03-11 11:30:20.445 ALSA, Error: Unable to open audio mixer. Volume control disabled12:21
franksterI wonder if these log statements are related to the problem12:21
mrandfrankster: doesn't make sense that an update would cause that.  Google turns up some hints: http://code.mythtv.org/trac/ticket/9416 and http://ubuntuforums.org/showthread.php?t=1647938   Probably more hits if you search the mythtv-users mailing list13:22
frankstermrand; yeah you're right - I downgraded the frontend to some version from last year and the sound still doesn't work. I can play sound outside of mythtv15:12
Seeker`Naranek: how long between wiping the system and the keys reappearing?15:23
NaranekI'm not sure. I just noticed them, but I haven't used the box much15:45
Naranekrkhunter found a suspicious /etc/.java directory that was made 15 days after installation, but I'm not sure if it's related to this15:46
NaranekI installed the system about three months ago15:46
tmktfrankster: did you give the audio auto detecting a shot/15:56
frankstertmkt: I haven't had great results from that! in fact I can't tell what it does. Its the option in the frontend general settings page right? is it meant to populate the list beneath it/choose the best one out of the list?16:08
franksterI've tried the default option in the list and an ugly alsa path I won't repeat here. I assume that the default option is what was working up until this morning16:11
Seeker`Naranek: http://www.velocityreviews.com/forums/t754763-re-unexplained-files-why.html16:39
Zinn[www.velocityreviews.com] Re: Unexplained files - why?16:39
NaranekSeeker`: thanks. those were the files I was looking for16:49
Naranekhttp://ubuntuforums.org/showthread.php?p=11642766 here is another user having the same issue. In the post there is a link to my post after the first breach.16:54
Zinn[ubuntuforums.org] Unexpected user/host in mySQL - Ubuntu Forums16:54
likwid-naranek, i have the .pub key as well as the mysql user, though its from the host kapok17:08
likwid-my BE isn't available from the outside.17:08
likwid-id guess some package installed it.17:08
likwid-which unfortunately doesnt seem to be the case17:09
likwid-root@mythtv:/etc/ssh# dpkg -S /etc/ssh/ssh_host_ecdsa_key.pub17:09
likwid-dpkg-query: no path found matching pattern /etc/ssh/ssh_host_ecdsa_key.pub.17:09
Naranekok17:11
Naranekstrange17:11
Naranekdo you mean isn't available from outside as in no services available to the net or airgapped?17:12
likwid-correct17:12
likwid-its not available from outside17:13
likwid-i do not forward any ports on my router to it17:14
Naranekok, but it's still connected to the internet17:14
Naranek?17:14
NaranekI had only ssh and web server visible on the outside, and there wasn't anything complex on the web server17:16
Naranekso I think it's possible that it's some vulnerability on the basic packages of the mythtv17:17
likwid-its connected but the only connections it makes to the outside is updates/schedules direct17:20
Naranekdo you know of a way to search references to cardamom or kapok in the mythtv sources?17:22
likwid-need to find the build bot logs for ubuntu/myth.. couuld search those18:13
NaranekI think I'll contact security@ubuntu.com to see if they can help18:14
likwid-yea i dont think they are malicious18:50
tgm4883Naranek, what are you seeing as the mysql user?18:50
tgm4883the one that you believe is suspicious18:50
tgm4883Also, when you reinstalled, did you use the same password?18:51
Naranektgm4883: different password and username19:14
Naranekuser: root19:14
tgm4883Naranek, the mysql user you see added is root?19:14
tgm4883and you think that is suspicious?19:15
Naranekhost: cardamom19:15
tgm4883what is cardamom?19:15
Naranekyes. I haven't created that user and I don't know the host19:15
Naraneksome spice I think :D19:15
Naranekin the earlier installation I found a reference to cardamom in my known_hosts19:16
Naranekand some ssh-keys which I haven't made myself19:16
Naranekand root login turned on in sshd_config19:17
tgm4883well the mysql root user is created on install19:19
tgm4883it's the master user for mysql19:19
tgm4883The root login for sshd is odd19:20
Naranekyes, but it has the host localhost or 127.0.0.119:20
NaranekI don't remember which19:20
tgm4883should have both19:20
tgm4883I have a third in mine which seems odd, but it isn't cardamom19:20
tgm4883researching19:21
Naraneklikwid- had kapok instead of cardamom19:21
tgm4883do you have anything else installed using mysql?19:22
emacsenHi. I installed mythbuntu and it's all working, except I don't think upnp is working. I can't see it with my boxee or vlc on my laptop. Is there something I need to do to enable it, or a way to check it?19:23
emacsen!help upnp19:24
Zinn!help upnp For a  complete list of my knowledge visit: http://www.baablogic.net/Zinn.cgi  Other available commands: !status, !about, !bug [bug_number].19:24
Naranektgm4883: nothing else installed using mysql19:25
Naranekmight I ask what was your extra hostname?19:26
tgm4883king19:27
tgm4883Naranek, stick around, I might have a better answer for you in a bit.19:28
NaranekI will... I'll need to get some sleep soon, but I'll leave the screen on. Thanks!19:29
emacsenokay, so enna is the third client not to see a upnp server. so I think it's not on19:35

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!