/srv/irclogs.ubuntu.com/2012/11/06/#ubuntu-us-or.txt

youpankeysHi to everybody04:47
=== philballew_ is now known as philballew
bkerensakees: do you know by chance if Google's Account System takes a while to propagate password changes globally? I am having trouble doing svn check in with google code08:08
bkerensaoh08:16
bkerensa:s you create a svn password08:16
bkerensaI see08:16
keesbkerensa: did you find out how the bad people got into your stuff?16:26
bkerensakees: so I have not and I am leaning towards thinking it was neither an app or account compromise16:27
bkerensaI think something different happened16:27
bkerensa:s16:27
bkerensakees:  http://pastebin.com/baRxUH4y16:31
bkerensaI have been getting e-mails like that are forged and allegedly come from my facebook friends16:32
bkerensayour name has been in them too :)16:32
bkerensabut in following up with each person they said I never sent them any message16:32
bkerensanor them to me16:32
bkerensaso I did some searching and found out that for some period of time Facebook had a leak of friend data16:32
bkerensaI think someone found a way to forge @facebook.com e-mails which deliver messages like a chat on FB16:33
bkerensabut FB notably sees that these are forgeries and puts a little icon when it displays the message on FB (why it doesnt completely block them idk)16:33
keesbkerensa: oh, maybe I misunderstood? I thought you were cleaning up iframes from an intrusion?16:39
bkerensakees: lol oh16:40
bkerensakees: that was a consulting thing but yeah on that I did find out how :)16:40
bkerensalooks like I was confused16:40
keesah-ha, okay16:40
bkerensakees: the client had outdated themes that were using the timthumb image library which had a vulnerability that allowed xss16:41
bkerensahttp://code.google.com/p/timthumb/issues/detail?id=4916:42
bkerensa:s16:42
bkerensasadly wordpress has had native image resizing support for some time now16:42
* kees nods16:44
keeswhat OS is under that wordpress?16:44
kees(not that it would help XSS)16:44
bkerensakees: I believe either CentOS or RHEL since it was a cpanel server16:45
bkerensacpanel = :s16:45
keeshehe16:46
bkerensakees: http://www.youtube.com/watch?v=QdpGd74DrBM16:50
bkerensayou see this?16:50
keesgotta love touch screen calibration *SIGH*16:53
bkerensakees:  :s I hope that gets sorted and is just one machine16:55
bkerensa:(16:55
bkerensakees: look look :) they left a backdoor http://pastebin.com/SJuSvJVx17:59
bkerensathese guys are fun bad guys :s kind of? :)17:59
keesheh, is that a php shell?18:02
bkerensakees: yes18:03
bkerensalol funny their ip re-directs to google18:03
bkerensahah18:03
bkerensaslangasek: do you know how I can mark a Debian bug as Invalid?22:30
bkerensahttp://bugs.debian.org/cgi-bin/bugreport.cgi?bug=69230322:30
lubotu1Debian bug 692303 in searchmonkey "Upgrade Searchmonkey from 0.8.1-8 to 2.0.0" [Wishlist,Open]22:30
bkerensaupstream is EOL development of this app so we wont be able to grant the wishlist bug22:31
slangasekbkerensa: invalid == closed in Debian22:32
slangasekhowever, I don't see how upstream EOLing prevents the Debian maintainer from upgrading to the last available version?22:32
bkerensaslangasek: the latest available source package is windows source not linux22:32
bkerensahe has no plans to release for linux or continue development at all22:33
slangasekit's still for the Debian maintainer to decide whether to put effort into making the software work on Debian22:35
bkerensaslangasek: I'm the co-maintainer22:57
bkerensathe maintainer is to busy to maintain22:57
bkerensa:s22:57
slangasekoh, well22:57
slangasekthen yeah, close the bug ;)22:57
slangasekan optionally set the 'wontfix' tag22:57
bkerensakk23:00

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!