/srv/irclogs.ubuntu.com/2015/10/04/#ubuntu-us-tn.txt

=== aeden__d is now known as aedend
aedendI think I have znc setup correctly now01:53
cyberangeraedend: ssl?02:29
aedendcyberanger, I think so...02:29
aedendare you talking about the settings for znc?02:32
* Unit193 shrugs.02:39
cyberangeraedend: Both how you connect to znc, and how znc connects to irc02:41
aedendcyberanger, It says I'm using a secure connection02:42
Unit193cyberanger: Guessing not first.02:43
aedendI use ssl to connect to znc and znc connects to chat.freenode.net 669702:44
* Unit193 is wrong. \o/02:45
aedendcyberanger, are you seeing something that would suggest I have it configured wrong?02:46
cyberangerNo, Just bringing it up02:49
cyberangerYou mentioned having it setup, thought it was something you'd want02:49
aedendI've got all this setup but I don't understand the benefit02:54
Unit193IRC addicts.02:55
aedendIf I close this client, since I have znc setup I'll still be connected?02:55
Unit193And you'll see backlog, right.02:55
aedendok.02:56
aedendto test this I just joined ##linux (its pretty busy). If I close this client and come back in 10 minutes02:57
aedendI should see everything that took place while I was gone02:57
aedendyeah... I've got something setup wrong. That didn't work03:06
aedenddecided to destroy my droplet and start over...03:34
Unit1930_o03:37
aedendjust easier than trying to backtrack hours of configs03:39
cyberangerHrm04:17
* cyberanger just fixed his tts issue on android04:18
cyberangerRead it to me pro seems to no longer work, SpeakMe does04:18
cyberangerNo to set pushbullet back up fully04:19
cyberangeraedend: do you know which version your running?04:21
aedendcyberanger, version of what?04:32
cyberangerznc04:32
aedendI deleted the droplet... configuring it again atm04:32
cyberangerOh right04:32
=== aeden__d is now known as aedend
average_guyafter playing with squid config a bit realized I really don't want all my web traffic flowing through my server seems dangerous14:06
aedendas opposed to flowing through what?14:11
average_guyresidential gateway (comcast router)14:12
average_guythe proxy sends traffic thru sever to get cached and on to the client, I dont wanna rek my server14:13
aedendI'm new to networking but can yo not set up ufw policies14:15
average_guyIf I firewall out the traffic, the proxy would do nothing and if I let the traffic in to be cached there would be who-knows-what on my server14:21
average_guythink imma call it good and leave it alone a bit, It does transmission, quassel, owncloud, cups, samba, mumble and a couple other things well atm14:23
average_guyi should quit while i'm ahead14:23
aedendI guess I was thinking you could set up what traffic you wanted to allow and block everything else.14:25
aedendcan fail2ban jail cached stuff ?14:26
average_guyI knew what a proxy was, I just didn't think real hard before I started tryin to put it on14:26
aedendwhich proxy did you intall14:26
average_guysquid14:27
average_guywell squid3, but yeah, I just really don't need it14:28
average_guyI don't worry about security much but I try not to make my, server expecially, an easy target14:29
aedendyou could monitor your squid proxy access log, if you see a lot of unwanted attempts you could filter those ip's with fail2ban?14:31
aedendor are we just not on the same page here :/14:32
average_guybut what if the desired web content IS the malicious code14:32
average_guyit would go in there and I wouldn't know till it was too late14:33
average_guyI don't care if the windows pc's get rekt, the server backs them up, I cant lose the server14:34
average_guyso just seems dangerous to have anything I didnt specifically order going to it14:35
aedendI agree. And I'm learning all this as I setup my own vps. I was under the impression that fail2ban can be configured with application specific policies to jail unwanted stuff14:46
aedendwithout first allowing unwanted traffic in to determine what to ban14:49
average_guyI'm not an expert either but my problem is with it allowing port 80 traffic in for cache there would be know way to tell good from bad14:50
aedendsample fail2ban apache policy  https://paste.debian.net/314368/14:52
average_guyhmm, that does look nice14:53
aedendhere is another one, maybe give you some ideas.  https://paste.debian.net/314370/14:54
average_guyI broke something :(15:01
average_guytransmission is running but the client can't connect to it15:02
average_guyugh15:02
average_guyfixed, still dunno why it suddenly broke tho15:10
average_guyso, the fail2ban policy looks like it can monitior what I have cached and make sure it dosent do anything funny?15:11
aedendaverage_guy, I'm not sure. I'm learning as I go setting up this droplet.15:12
average_guylol, thats cool I figuring it all out too, linux is a toy to me15:13
average_guyI have cloud backups of everything important in case I DO rek stuff up15:14
average_guywife calls linux my 'nerd game"15:15
aedendI know the feeling, It's more of a toy for me as well. I really don't have a need for anything I'm doing. I just like learning about it15:22
aedendplus, I get sucked in when something doesn't work. It becomes personal almost lol, like I have to figure it out15:23
average_guyit IS facinating. I have been obsessed with computers since they became commercially available15:24
average_guyI have server hardware and fibre and all kinds of stuff, I like making big complicated SAN configs n stuff just to do it15:24
average_guyto know how things work15:25
aedendlol, ok, well, I'm not there yet. Once I start doing something I get caught up in knowing everything about it15:25
aedendWhich is why it takes me so long to get stuff working.15:26
average_guyI have the plug on unlimited free hardware so I feel almost obligated to do something with it15:27
aedendI'll start of configuring a firewall, but then I'll start reading about how ufw works, which leads to iptables, which leads to..15:27
aedendaverage_guy, you _should_ feel obligated. It is your duty :)15:27
aedendI get sidetracked. To access my droplet I use ssh (of course). But instead of just connecting I started reading on how ssh-agent works15:31
cyberangeraedend: you may want to look at mosh too19:21
cyberangeraverage_guy: foxyproxy22:18
cyberangeror PAC files22:18
average_guyoh woiw, I never seen foxyproxy before cyberanger. Reading now22:20
cyberangerIt's what I use, I want a few specific URI's to go to the UK, to pass a geoip check there22:24
cyberangerthe rest stays in the US, or over tor22:24
aedendsooo, I got this vps. What now?? If I could owncloud configured so I could not rely on icloud, that would be great23:42
aedend*get23:42

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!