/srv/irclogs.ubuntu.com/2014/06/12/#ubuntu-server.txt

=== Lcawte is now known as Lcawte|Away
=== paralle21_ is now known as parallel21
z1hazehow can i remove a symlink without deleting the whole directory it points to?01:20
MontyHI have what will be a simple question for you, but my google fu has failed to find an answer01:21
MontyHhow do you deny all to cron01:21
MontyHoh, yeah, ubuntu 12.04 server 32bit01:21
MontyHthe google fu says I should edit /etc/cron.deny which does not exist01:22
MontyHany help?01:22
sarnoldz1haze: rm will only delete the symlink; I couldn't even find any way in the manpage to get it to follow a link :) -- and bonus, deleting a directory requires the -r command line option :)01:22
z1hazeoh ok lol01:23
z1hazewas just nervous01:23
sarnoldMontyH: check the cron(1) manpage, it describes the interations between /etc/cron.allow and /etc/cron.deny01:24
sarnoldz1haze: it's good to be nervous :)01:24
MontyHsarnold: ok read the whole man page twice, no mention on how to shut everyone out of cron01:29
sarnoldMontyH: oh! nuts, maybe it was an addition between precise and trusty..01:31
MontyHit WAS there in 10.04 I used it01:31
sarnoldMontyH: oh man. I'm sorry. it's in crontab(1). :( http://manpages.ubuntu.com/manpages/precise/en/man1/crontab.1.html01:32
MontyHok long story short, monday night some guys, 1 geolocated to China, the other to Viet Nam somehow slipped a cron job in that repeatedly attacked the password on the root user. no biggie it can't log on, but how did they get it in there?01:33
sarnoldMontyH: things to check: (a) do you still allow password logins via sshd? require keys (b) do you use any cpanel or webmin or plesk or other "control panels"? those are normally crap01:35
MontyHyeah I know control panels are a no go. working on sshd as we speak01:38
MontyHI need some words of wisdom, how would someone from china or viet nam slip a cron job into my server that repeatedly bangs the root door?01:54
MontyHI know they arent that good because theyre trying root on ubuntu01:54
MontyHand I mean 46 pages of logs bangin the door01:55
sarnoldMontyH: can you share some log entries?01:56
MontyHunfortunately the server that contained the log has been removed and quarantined. my desktop at work has the log01:58
MontyHand naturally I got no way to get there01:59
MontyHand naturally I didnt email it to myself. I'll be back tomorrow with it, thx02:02
sarnoldMontyH: heh, sounds like a good way to enjoy the rest of the night :)02:03
PryMar56MontyH, if its an ssh login attempt, move the service off port 22 on the WAN02:05
stonedIdleOne, here too I hope?03:32
IdleOnekeep it up with your attitude and yes you will get banned her also03:32
stonedThere was no attitude.03:33
stonedYou're just an asshole.03:33
stonedPlease get your dick hard.03:33
IdleOneif you would like to discuss how to resolve your bans you can join #ubuntu-ops03:33
stonedban me.03:33
stonedNOW.03:33
stonedNo thanks.03:33
IdleOnefine03:33
MontyHfriends and neighbors I have a problem you guys can unite around. Monday 00:00:00 to  Wednesday 12:32:00 I was the recipient of a hack. I geolocated the 2 ip's to china and viet nam. they did not penetrate ssh, but they DID somehow penetrate cron. leaving behind a coocoo's egg that kept beating on root's door and trying to log in. now we all know root cannot log in so I brought up just03:49
MontyHssh on a different machine03:49
MontyHI need help shutting off cron03:50
MontyHpls, thx and all the niceties I can present03:50
cfhowlettMontyH *I* can't help, but if no response here, ask the ##linux channel.03:51
MontyHwell therein lies the rub, other distros have cron.deny, ubuntu does not03:51
cfhowlettMontyH sadly such technical discourse far exceeds my paygrade03:52
MontyH46 pages of logged attempts in 3 days all after root, wonder why they dint find out it was ubuntu first03:52
cfhowlettMontyH kiddiescripters will do that03:53
MontyHsomehow they slipped my cron a crontab without breaking ssh03:53
hilarieI'm on Lubuntu 14.04 server, and have it running openVPN and DHCP it NATS everything on my LAN over the openvpn tunnel, I'd like to exempt things from SSL from going over the tunnel, is there any way to use IPtables to make it so some traffic that is being natted doesn't go through the tunnel?05:01
=== karl_marx is now known as karl
=== karl is now known as Guest65021
=== Guest65021 is now known as orwe
=== orwe is now known as orwell
=== orwell is now known as skizo
=== skizo is now known as phrenia
=== phrenia is now known as phren
=== phren is now known as skizo
=== skizo is now known as khaitanya
sarnoldhilarie: you may get more traction in an openvpn channel -- I don't know how to do it, but I'd first guess that you need to modify routing table to have some IPs that have traffic routed through openvpn, some IPs that don't, and then use iptables rules to re-write port 443 traffic to an IP that's not routed via openvpn..05:58
=== Trey is now known as Guest21536
hilariesarnold, I'll try over there in the morning, thank you07:03
sarnoldhilarie: good luck :)07:04
ws2k3hello i'm trying to install ubuntu 12.04 but it hangs after selecter the mirror it shows an emty purple window07:54
ws2k3i restarted the installation twice so this is the 3th time it happens07:54
=== Asandari- is now known as Asandari
=== medberry is now known as Guest96733
=== dhkl is now known as fruitloop
=== fruitloop is now known as dhkl
pmatulismorning10:53
=== EzeQL____ is now known as EzeQL
=== med_ is now known as Guest81993
=== Trey is now known as Guest73727
tarvidIn a rash move I upgraded apache2 to 2.4.9 and now all the virtualhosts are broken13:23
tarvidis there a way to run the upgrade again and answer the configuration questions more carefully? I answered "keep"13:24
pmatulistarvid: man dpkg-reconfigure13:26
tarvidpmatulis, I can't invoke the configuration prompts,13:33
pmatulistarvid: have backups of your original configurations?13:34
tarvidyes pre upgrade13:35
tarvidthey don't work with 2.4.913:35
pmatulisthat's odd13:35
tarvidI never had a working 2.4.913:35
pmatuliswhat release of ubuntu is this?13:35
tarvid12.0413:36
tarvidbut I munged things by trying to get to php 5.513:36
tarvidwhich prompted an upgrade to apache 2.4.913:37
pmatulishow did you get 2.4.9?13:37
tarvidfrom a PPA I am looking it up13:38
tarvidondrej-php513:38
pmatuliswell, you are installing PHP and Apache outside the Precise archives.  problems should be expected13:39
tarvidI've got them13:40
pmatulisthere you go13:40
pmatulisapache 2.4.9 will only available in 14.10 , and you're installing it on 12.0413:41
pmatulis*be available13:41
tarvidI trusted the PPA13:42
pmatulisi bet that PPA installed a lot of other stuff right?13:42
tarvidyes13:42
pmatulisyeah, tons of libraries prolly13:42
tarvidand that makes restoring old files problematic13:42
tarvidI do have a recent backup of most things13:43
tarvidwill etc and bin catch most of that13:44
=== Ursinha is now known as Ursinha-afk
pmatulisif you need php 5.5 then why not install 14.04 LTS?  i'm not sure why you were forced to install apache 2.4.9 b/c trusty ships with 2.4.713:44
pmatulis(14.04 = trusty)13:45
OpenTokixpmatulis: I am guessing some idiot developer gagging for the 0.0.2 difference13:46
tarvidI can run the rsync backwards,  I don't want to push homes13:46
pmatulisheh heh, gagging13:47
OpenTokix=)13:47
=== Ursinha-afk is now known as Ursinha
=== TDog_ is now known as TDog
=== medberry is now known as Guest15740
=== med_ is now known as Guest429
=== Lcawte|Away is now known as Lcawte
aboSamoorHi all, I upgraded my ubuntu server on my gateway, and the connectivity with the internet stopped working, I am not sure how to debug what happened, is there any default values changed in the new ubuntu, everything used to work16:18
markthomasaboSamoor, the first thing I would check is your network interfaces and the routing table to make sure they're intact.  Have you done this?16:23
aboSamoormarkthomas: my /etc file is kept under etckeeper, I could not see anything that should the networking changed, I am kind of lost, do not know which tool I should use to debug the situation. The gateway runs DHCP, DNS, NIS and the local network services running really fine, it is just the gateway can not connect to the internet. One more thing, the gateway is able to ping the router it is behind.16:35
=== n2deep is now known as N2Deep
markthomasaboSamoor okay, so that's a partial answer to my question.16:36
markthomasIf you can ping out, then it's likely that the external interface and at least a portion of the routing table are correct.  You may want to run netstat -rn (or route) and verify that the default route is set up correctly.  Then, check that IP forwarding is enabled, and check your iptables rules16:37
markthomasaboSamoor, cat /proc/sys/net/ipv4/ip_forward16:40
aboSamoormarkthomas: after two days of work16:43
aboSamoormarkthomas: and nothing worked, I just restarted it and it works16:43
aboSamoormarkthomas: :-D, man you are a miracle, I do not know what happened, but it works16:44
=== psivaa is now known as psivaa-afk
tarvidManaged to revert but the process was ugly17:25
s0x_hey guys ... im trying to setup an ubuntu server atm but am struggling with setting the domain for it. It gets its ip from an existing DNS but the domain should be set manually. I tried to add a domain entry into /etc/resolvconf/resolv.conf.d/head so it does add it to resolv.conf. Even though hostname -d or -f does not recognize the domain17:25
s0x_there is hardly any documentation online how to properly set the domain name ... could anyone give me a bit of support?17:25
markthomass0x_ have you tried adding the FQDN to /etc/hosts?17:26
markthomasor adding the FQDN to /etc/hostname?  I'm not clear what the problem is, but one of those might help.17:27
s0x_markthomas: thats not the proper way to do that, is it?17:27
s0x_if you do so hostname acts kind of weired17:27
s0x_hostname gives you the fqdn while hostname -f does not17:28
markthomass0x_ the question is, what problem are you trying to solve?17:28
s0x_i tried that earlier17:28
markthomasFQDN is a function of DNS.  I'm not sure what behavior on the local system you're trying to modify.17:28
s0x_we are setting up a private cloud over hear ... and there is no way to influence the dns that it could give us the domainname17:28
markthomasOkay, working in a cloud environment is 1000x more complex than setting up "a server"17:29
s0x_it is actually just a couple of vm's inside a dmz which act as kind of a mini cloud17:29
markthomasYou mentioned "it gets its IP from an existing DNS" and I'm not sure from that what your setup is.17:29
markthomasSince IPs are not assigned by a DNS server.17:30
ryan_turner|MTWso all you're really trying to do is set the fqdn17:30
markthomasOkay, so you have two VMs.  And these have statically-assigned IPs?17:30
s0x_aehhh sry DHCP17:30
s0x_just a typo :D17:30
s0x_no DNS at all :p17:31
markthomasOkay.  What are you trying to solve by assigning server IPs by DHCP?17:31
markthomasBecause if you want to use DHCP to assign IPs and you want the hostnames to resolve, you have to have dynamic DNS set up.17:31
markthomasFor such a tiny setup, would you not be better off using static IPs?17:31
s0x_these are public ips so there is no way to set them statically17:31
ryan_turner|MTW^^ which most of the time is unnecessary17:31
markthomasThat statement in itself is not accurate.  Who is issuing the IPs?17:32
s0x_well ... we are deployin machines on demand17:32
ryan_turner|MTWcoulsnt be dhcp17:32
s0x_an existing DHCP we cant influence17:32
lordievaderGood evening.17:33
ryan_turner|MTWset your fqdn and then have your dns folks give you a dyndns script.17:33
markthomasOkay.  So back to my initial question: if this is external DNS resolution, you will need a properly-configured dynamic DNS.  If not...then what are you trying to solve?17:33
s0x_well ... we have to setup the FQDN manually ... .there is no point in discussin if that makes sense ...17:35
ryan_turner|MTWReading your original question, all you're asking is how do you ignore the domain-name given during dhcp negotiation?17:36
s0x_i dont get one!17:36
ryan_turner|MTWThen that's your DHCP server configuration's issue.17:37
ryan_turner|MTWBut in all honesty that's not really... normal17:38
ryan_turner|MTWit's usually a search domain that it gives out17:38
lockIs there any way to check if a NIC is supportted on ubuntu?17:42
markthomass0x_ when you don't have a FQDN assigned by DHCP, what affect is it having?17:45
sarnoldlock: easiest is to just try; next easiest is to look through e.g. http://www.ubuntu.com/certification/catalog/search/?query=nic17:46
sarnoldlock: you could also look for model number or chipset numbers in /lib/modules/`uname -r`/kernel/drivers/net17:47
lockthank you sarnold17:48
=== Guest429 is now known as med_
med_jamespage, have you ever had kernel panics using neutron with VXLAN?17:52
* med_ is stuck in kernel panics on a neutron node17:52
=== Jare_ is now known as Jare
geniijahayes91: If you just state ( as briefly as possible) the actual type of help you need into the channel, someone may know how to assist you.17:55
geniiLike, if you're having a specific question about setting up your dhcp server, etc17:56
jahayes91I'm looking for some help with isc-dhcp server17:56
jahayes91Ah apologies, I'm having issues with starting the service. I have it all installed and configured as far as I can see.17:57
geniijahayes91: If you put what's in your /etc/dhcp/dhcpd.conf into a pastebin for us to see please :)17:59
jahayes91Sure18:00
=== Trey is now known as Guest89489
jahayes91http://pastebin.com/WNi5Q9XE Thanks guys :)18:08
jahayes91http://pastebin.com/WNi5Q9XE Thanks guys :)18:17
sarnoldhey jahayes91, you didn't miss anything while you were gone18:18
jahayes91New to this irc business... I think i managed to disconnect myself...18:18
sarnoldyou did :) but just for twenty seconds18:19
=== unreal_ is now known as unreal
=== jahayes91 is now known as JamieHayes
=== medberry is now known as Guest81830
forrestHi guys, is anyone familiar enough with febootstrap to know why this error:febootstrap: aptitude: error: no file was downloaded corresponding to package dpkg would be generated when running  update-guestfs-appliance? I've already reviewed the relevant search via google and confirmed I am running febootstrap 3.14-2. This is on a 12.04 machine.19:17
=== med_ is now known as Guest68322
znfHello.20:18
znfCan someone give me a hint of how to configure the network interface with dhcp on a server? I did edit /etc/networking/interfaces but it doesn't do anything after reboot, just like I haven't touched it20:19
sarnoldznf: can you pastebin your /etc/network/interfaces? someone might be able to give it a look (lunchtime for me ;)20:31
znfnevermind, I somehow typed "auth eth0" instead of "auto eth0"20:31
=== EzeQL__ is now known as EzeQL
cloudmanHi is mod_expires.c installed as default on 12.04?21:03
zartooshHI I am using ubuntu 12.04. The top command indicates one of the applications are running %172  how is that possible?21:05
cloudmanHi is mod_expires.c installed as default on Buntu12.04?21:07
cloudmanand mod_headers.c21:07
cloudmanI cannot locate them on a system21:08
sarnoldzartoosh: one core = 100% -- so your application is using 1.72 cpu cores.22:01
zartooshsarnold, thanks22:28
=== Trey is now known as Guest94523
tarvidI have a remote machine with 13.10 desktop. I want to load 14.04 server. I can access the 13.10 desktop with ssh22:54
sarnoldtarvid: do-release-upgrade ought to get you there22:58
tarvidI suppose the remnants of the desktop installation will not be all that significant22:59
sarnold?22:59
tarvidIt has 13.10 desktop installed23:00
tarvidbut do-release-upgrade is running23:00
sarnolddo-release-upgrade can upgrade desktops :)23:00
tarvidI am going to make it a server and I have this lingering attachment to the rubric that real servers don't run desktop23:01
sarnoldah :) feel free to apt-get purge whatver you don't want to keep, either before or after the upgrade.23:02
tarvidbut frankly, I don't give a damn as long as it works reasonably well23:02
tarvidshbouldn23:03
tarvidt be too hard to make a recovery partition23:03
=== Lcawte is now known as Lcawte|Away
=== danfinch1 is now known as danfinch
genitrust_hey everyone! i have a server that is giving the internet to all other computers on the network through eth1  192.168.0.123:56
genitrust_...but for the machines (there are many) that grab the DNS automatically from my gateway, how do I tell these machines to use 8.8.8.8 as the default DNS?23:56
sarnoldgenitrust_: why not run a caching recursor yourself?23:57
genitrust_sure why not? i mean if that helps us solve this , great :D23:58
sarnoldgenitrust_: I've used powerdns recursor and enjoyed it :)23:58
genitrust_is that somethign i can apt-get install ? :D23:58
sarnoldgenitrust_: package pdns-recursor -- some online documentation (of newer version, of course) is at http://doc.powerdns.com/html/built-in-recursor.html23:59
genitrust_instead of us logging into every machine and saying, "ok use 8.8.8.8 every time you boot up!" ... we want to have our gateway tell the machines, "hey dumbass, use 8.8.8.8 for your DNS, not 127.0.0.1"23:59

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!