/srv/irclogs.ubuntu.com/2014/10/27/#ubuntu-za.txt

Kilosmorning peeps05:09
Kiloshi tumbleweed havent you gone to bed yet?05:09
tumbleweedKilos: might do so soon05:10
Kiloswhew05:10
Kiloshave a good sleep and a good day05:10
tumbleweedthanks :) enjoy your day, too05:11
Kilosty05:12
Squirmmorning05:42
Kiloshi Squirm 05:42
bdukMore almal06:06
Kiloshi bduk 06:07
bdukGenoeg gereen Kilos 06:11
Kilosnee man net 10mm06:11
bdukDarem 150 by ons maar die meter wys net 5006:11
Kilossjoe06:11
Kilosmore inetpro 06:53
Kiloshi bushtech 06:53
bushtechHi Kilos06:54
Kiloshi Xethron 07:17
Kilosmorning superfly hows the family?07:17
superflyhi Kilos, all good.07:20
Kilosnice07:20
superflyhi ThatGraemeGuy, finally got to work?07:25
Kiloshi ThatGraemeGuy 07:25
ThatGraemeGuymorning, yes07:26
ThatGraemeGuyhour and a half to travel 7km, happy monday :)07:26
Kilosouch07:30
Kiloswhat broke07:30
ThatGraemeGuyhttp://www.tygerburger.co.za/200182/news-details/n1-into-cape-town-closed-due-to-accident07:34
Kiloseish07:35
ThatGraemeGuyeish indeed07:52
TinuvaMacwould be awesome to have a freenode server in africa08:29
Kilosspeak to the hetzner peeps, their servers are lekker fast08:36
magespawngood morning all09:40
Kiloshi magespawn 09:43
magespawnhello Kilos 09:44
Kilosimportant meet tomorrow night hey09:44
Kiloswb ThatGraemeGuy 09:44
magespawnyes i saw the mails. was it added to the agenda?09:55
Kilosthanks man i couldnt get to do that09:55
Kilosoh no if you can will you please. i keep getting lost there09:56
Kiloswhen i login i go to me not the agenda page09:56
magespawni will if i get a chance, i am trying to sort a hacked website09:59
magespawnanybody have any idea how they are redirecting canefields.co.za to http://ansainmobiliaria.com/wp/wp-content/plugins/Paypal-Account/ ?10:00
Kilossjoe10:02
Kilosill go have another go with the agenda, but things changed from last time. and when i go to G+ i dont see circles anymore10:03
Kilossort your site lad. lemme see10:03
Squirmmagespawn: I think it's in the index.html of canefields10:04
magespawncool thanks Squirm, will check there10:05
Squirmor their index.php10:05
Squirmbecause when I ping canefields.co.za, I get a reply from the company they use as their nameservers(must be their hosting providers too), found that on co.za10:05
Squirmso you're getting to the correct site, then being directed after that10:06
magespawni thought as much Squirm, just could not see how it was happeningn10:06
Squirma redirect is as simple as: header("Location: " . http://blah.blah);10:07
Squirmin php10:07
SquirmI even tried to download that file, but even wget gets redirected10:13
Squirmso I can't see the infected file either10:14
TinuvaMaccould also be .htaccess if the hacker somehow got access to write that file10:15
Squirmmagespawn: what is the IP address of the server it's hosted on?10:17
magespawnlet me check10:17
magespawn198.38.82.16110:18
Squirmthe one it's meant to be hosted on10:18
Squirmmaybe look in cpanel?10:18
magespawnSquirm, i can't find anything there10:27
SquirmConnecting to canefields.co.za (canefields.co.za)|198.38.82.161|:80... connected.10:33
SquirmHTTP request sent, awaiting response... 302 Moved Temporarily10:33
Squirmok10:33
Squirmso it looks like that's how they're doing it10:33
Squirmmagespawn: it could very well be in the .htaccess ?10:35
magespawnokay10:36
magespawn.htaccess in the public_html folder?10:36
Squirmit'll be in the root of the website10:36
Squirmso probably that one10:36
Squirmunless something has happend on the hosts side10:37
Squirmlook for the code 30210:38
magespawnhttp://pastebin.com/E8CP0Anb this is the .htaccess file10:38
Squirm:/10:39
SquirmI have a feeling you're going to have to create a ticket with your host. Tell them is seems your website is being redirected through the status code 30210:43
Squirmmaybe they can have a look10:43
magespawnthanks Squirm10:44
Squirmyeah... I'm not sure where they're hiding that10:44
Squirmor what else could be wrong10:44
KilosSquirm, you got some time?10:45
Kilosi go to agenda then login and end up in ubuntu wiki10:46
Kiloshttp://bit.ly/1sKcgnI 10:46
Squirmhttps://wiki.ubuntu.com/ZATeam/Meetings/2014102810:46
Kiloslemme look10:47
Squirmwhy do you have to login?10:47
Kilosto add an item to the agenda10:47
Squirmone logged in, try go to that link again?10:47
Kilosthere used to be an add button on the thing to add10:48
Kilosi dont see it anymore10:48
Squirmjust creating an account quick10:49
Kilosok ty10:49
Kilosweenie broke it10:50
Squirmit's hanging on the login screen :/10:50
Kilosit takes long to login10:50
Kilos5 mins last time10:51
Kilosi thought ubuntuone was given up but i see its there when you login and thats what takes the time10:51
SquirmI think nuvolari_ has made it unchangable10:52
Squirmtop left, it says Immutable Page10:52
Kilosoh ya nuvolari_  hmm...10:52
SquirmImmutable being unchangable10:52
Kilosnuvolari_, ping10:52
SquirmI'll drop him a message10:52
Kilosplease do and remind him he is chairing tomorrow night10:53
Squirmyep10:54
TinuvaMacmagespawn: you should look at your index.php again, i think it is in there, because: http://pastebin.com/HGixejRf10:54
Squirmlunch time10:54
TinuvaMacor any of the files included by index.php10:54
SquirmTinuvaMac: I checked. but look at the status code, 302 Temporarily Moved. that's usually something you put in a .htaccess or maybe even in the httpd config10:55
Squirmlunch time :)10:55
TinuvaMacsquirm, even php header('Location: http://somesite') will cause a code 302 redirect10:57
Squirmah10:57
Squirmok10:57
TinuvaMacfor example: header('Location: http://somesite.com/',true,302); 10:58
TinuvaMachttp://uk3.php.net/manual/en/function.header.php10:59
Squirmok10:59
SquirmI see10:59
TinuvaMacso I am 100% sure, there is a line like that either in index.php or any of the files included by index.php10:59
SquirmKilos: once logged in, go back to the meeting page10:59
Squirmtop left is the edit button10:59
Squirmyou have to be logged in though11:00
TinuvaMacok so check this http://pastebin.com/RWyEWGA511:02
TinuvaMacwhen i query another url on that same domain, the 302 code doesnt pop up11:02
TinuvaMacgood idea to also go on lunch now11:04
Kilosai! i dunno what to add in the edit page, used to be a add item button11:10
Kilosok its added. hope it didnt need anything in from of it11:15
magespawnStill searching no luck so far11:44
TinuvaMacdownload a copy of the website, and do a grep through the files for files with the "header" word in it12:02
magespawngood idea12:02
SquirmI think they use Redirect in javascript too12:03
TinuvaMacyeah manually searching is going to be a hit and miss scenario you want to avoid12:03
TinuvaMacits all about doing it as fast as possible12:03
magespawni have used this site http://aw-snap.info/ which helped a bit but did not list the file just the line12:12
magespawni got this back http://is.gd/ZUqDxY12:15
KilosSquirm, ty for the help earlier12:58
inetprogood afternoon12:59
inetpromagespawn: have you checked your nginx configs?12:59
magespawnno do not know how13:00
magespawnsorry got a bit lost there13:04
magespawninetpro, no, how do i do that/13:04
inetprouh13:05
inetprohow do you manage your server?13:05
magespawnthrough cPanel13:06
inetproeish! Don't you have a nginx option?13:07
inetproor web server configs13:08
inetprosorry, I don't do cpanel stuffs13:08
magespawnnot that i can see let me look under the whm login, it is shared hosting13:10
magespawnokay found nginx admin under the whm13:11
magespawnand get the error message that i do not have the proper permissions to edit 13:15
Kiloshi inetpro 13:16
inetprohi Kilos13:16
inetpromagespawn: make the call to the guy with permissions13:17
magespawngood call inetpro 13:30
Kilosfixed magespawn ?13:30
inetpromagespawn: who owns the server?13:31
magespawni have started with the support dept13:31
magespawnmochahost13:32
magespawnback again13:55
Kiloswb13:55
magespawngotta go again, need to get myself down to Empangeni14:00
Kilosgo safe14:01
magespawnchat later14:03
Squirmhome time14:37
Squirmwhat a day...14:37
Squirmevening16:32
Kiloshi Squirm 16:34
Kiloswhew i get lotsa stuff in my circles16:52
Kilosand it eats data grrr16:53
charlgood evening16:59
charlMaaz: coffee on16:59
* Maaz puts the kettle on16:59
MaazCoffee's ready for charl!17:03
charlMaaz: thanks17:05
Maazcharl: Okay :-)17:05
Kiloshi charl 17:18
charlhi Kilos 17:29
charlhow are you doing17:29
Kilosim ok ty and you?17:29
Kilostell me17:29
Kilosi spose this is a stupid question17:29
charli'm better17:30
Kilosis there a different bell.ogg file for 64bit 17:30
charlno it's a .ogg so it's a sound file17:30
Kiloswhat you mean you better?17:30
charlit isn't a binary executable so it doesn't need 54bit17:30
charl*64bit17:30
charli had a cold for a couple of days17:31
charlstill recovering17:31
Kilosno man what i mean is , i had to bring my old bell.ogg here from old 10.10 files17:31
Kilosso it doesnt change, maybe its hexchat that dont like using it17:32
Kilosim sure it was crystal clear on konversation17:32
charlah17:32
charlyeah sounds like it's related to hexchat17:32
Kiloskinda muffled on hexchat17:32
Kilosill try konversation again to check17:33
charlok17:33
Kiloslemme close here or im gonna hear it twice17:34
Kilosyeah its clearer on konversation17:35
Kilosgrrr17:36
Kiloswe got better speed since our local repo was pointed to kenya17:41
kbmonkeyhello18:15
kbmonkeyhi Kilos 18:25
Kilosohi kbmonkey  wb18:25
kbmonkeyhow gaan it Kilos 18:27
Kilosgoed dankie en self kbmonkey  18:27
kbmonkeylekker soos n cracker18:28
Kiloshehe18:28
kbmonkeykeke18:29
kbmonkeyvoel lekker moeg vanaand18:30
superflyhi Kilos\18:30
Kiloswe gotta have a serious chat about this re evalution thing tomorrow18:31
Kiloshi my fly18:31
kbmonkeyhi the fly!18:31
Kilosi hope maia kan get online tomorrow night, she couldnt connect last time18:32
kbmonkey:)18:36
Kiloswb magespawn  18:37
magespawnhi Kilos ty18:38
Kilosdid you fix that server magespawn  ?18:46
magespawnnot yet i had some other things to do, going to be working on it now18:47
Kiloswhew18:47
Kiloshave you got permissions at least18:47
Kiloshi inetpro  meeting tomorrow night hey18:51
Kilosyou have to chair18:52
inetprouh, may unfortunately not be here18:53
magespawnnot the nginx permissions18:53
kbmonkeyI have my reminder set, I should be here in time too18:53
Kilosinetpro  ok ill get nuvolari_  to chair if you can just attend18:53
Kiloshgehe18:54
Kiloshehe too18:54
magespawnlol18:54
Kilosmagespawn  how are you supposed to fix it without admin permissions18:55
magespawnthat is just for the configuration of the server itself, if that is the problem the hosting company has to sort it out18:57
Kilosah18:57
magespawni need to make sure that it is not something in my files18:57
Kilosok good luck then18:57
magespawnjust busy downloading the site now so that i can use local search to find the offending line18:58
Kilosok18:58
magespawnsomething like this header('Location: http://ansainmobiliaria.com/wp/wp-content/plugins/Paypal-Account/');18:59
Kiloswhy does it want me to login with paqypal account18:59
inetpromagespawn: go rename your index.php and create a new one with just hello world19:20
inetprothen we test and see whether it still gets redirected19:21
inetpromagespawn: hello!!19:26
inetproai!19:26
Kiloshehe19:28
Kiloshy dink man19:28
Kilosen konsentreer19:28
inetprohe probably went sleepy19:40
inetprotime for me to say good night19:43
Kilosor for late supper or a shower while that site is downloading19:43
Kilosme too. night all. sleep tight19:43
magespawnhi inetpro 19:47
magespawnwas just catching a quick snooze19:47
inetpromagespawn: ok, did you see what I said above? 19:54
charlgood evening inetpro, magespawn 19:58

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!