/srv/irclogs.ubuntu.com/2016/08/05/#ubuntu-za.txt

magespawngood morning05:02
superflygood morning magespawn05:34
superflywow, chesedo, your IRC client is having fun05:34
paddatrapperMorning magespawn, superfly06:00
superflyhey paddatrapper06:00
paddatrapperHow goes it superfly? 06:01
superflypaddatrapper: full of hate right now, to be honest. too many things that don't work and cost me money that I don't have.06:02
superflyand I can rant and rage, but it's not going to change anything.06:02
superflyDepartment of Home Affairs. Need I say more?06:02
paddatrapperSay no more. I perfectly understand your rage... 06:05
andrewlsdsuperfly: "despite all my rage, Home Affairs is still taking and age"  [rat in a cage]06:21
superflyandrewlsd: no, they're nopt taking an age, they're outsourcing their visa stuff to a company that has no clue on the requirements for visas, so that I get a rejection 2 years later because of said company's incompetence06:22
andrewlsdyip. ... and at your expense.06:56
ra1v3nGood morning07:14
andrewlsdhi ra1v3n07:16
ra1v3nHello andrewlsd 07:17
Sicelosuperfly: you need visa to be in SA?07:30
ra1v3nDepends on your country of origin07:31
Siceloof course .. that's why i'm asking07:32
* Sicelo thought superfly was SA citizen07:32
superflySicelo: I am, but my wife isn't07:32
Siceloah .. i'm also non-South African, and  completely agree that the VFS system is just a mess :(07:34
Siceloand the hectic fees they have, omg!07:35
superflySicelo: exactly. and because my wife is married to a South African, we don't have to pay Home Affairs' fees. Now we're getting slapped with VFS's fees when we would not normally pay, and we never asked for VFS in the first palce07:42
superfly*place07:42
=== MaNL is now known as MaNI
Kiloshi superfly inetpro paddatrapper magespawn Langjan MaNI and all others08:16
Kiloswhat happened Langjan 08:16
superflyevening Kilos08:16
Kilosyou broke it08:17
paddatrapperHey Kilos08:18
LangjanHi Kilos het jy lekker gerus?08:46
Kilosai!08:57
LangjanChasing sheep Kilos? 09:11
Kilosi was09:15
Kiloshehe09:15
Kilosactually moving hay / lucerne mix where they can get to it09:16
KilosLangjan so tell what you broke man09:16
LangjanHi Kilos vertel my eers of je lekker geslaap het en uitgerus is vir die nuwe uitdagings wat my brekasies bied?09:19
Langjanjy09:19
Kilosman ek het geslaap09:20
LangjanUitgerus?09:20
Kiloslekker warm in die bed , wou nie opstaan nie09:20
LangjanEk het so gesien...lmga!09:20
Kiloshaha09:20
Kiloswas 7 uur wakker maar was te koud om op te sit of staan09:21
Langjanai, was net onder 7° hier, nie te sleg nie09:21
Kilosnow tell me what i need to start thinking about09:21
Kilosryp hier weer09:22
LangjanOk, I decided to use the other HDD with Zorin installed because its IDE and I want to get it to a stgae where I can get my onconverted friend to sit down and do everything that he does on windopz 09:23
Langjanstage09:23
Kilosok09:23
LangjanIts running nicely, just had to sort the jumpers out first09:24
Langjanso have a spare 160 GB HDD09:24
LangjanI upgraded his ram from 1,5 to 2 GB in trade for the HDD09:25
Kilosok09:25
LangjanAnother Q09:25
Kilos?09:26
LangjanI have a 5,7 GB folder named Systemback, dunno where it came from, want to delete it09:26
Kilossystemback is that tool for making an iso of your running system09:26
LangjanIts not a tool, its a folder09:27
Kilosyes man but the tool makes folders when you run it so it knows what you have going there09:27
LangjanContents look the same as /home except my documents and pics are not there09:28
Kilosyou ran system back before right?09:28
ra1v3nmake it into an Iso burn to dvd ... then clear the backup09:28
ra1v3nsimples09:28
ra1v3n^^09:28
LangjanCant remember if I did09:29
Kilostoo big for dvd09:29
Langjanthks ra1v3n 09:29
Kilosyou cant have a systemback folder unless you ran it09:29
Langjanok then I ran it, do I need it?09:30
Kiloswell09:30
Kilosdebatable09:30
Langjanwell 09:30
Langjanlets debate09:30
Kilosdid you make a stick with the iso on09:30
ra1v3nLangjan, you can clear the system back folder from within system back09:30
ra1v3nI never include playonlinux etc. you can exclude certain folders09:31
LangjanKilos, you mean an iso of the systemback? No09:31
ra1v3nback those up separately 09:32
Kilosthat was the whole idea of running it Langjan 09:32
LangjanI always back up my file and pic and email folders separately 09:32
Kilosif you feel you dont need it you can aptitude purge systemback09:32
ra1v3nif your system is running perfectly and you want a backup .... clear the systemback and create a new one 09:32
LangjanOK that makes sense thks ra1v3n 09:33
Kiloslisten to ra1v3n 09:33
ra1v3nwhat I do Is I create a new user with full priveledges (so that I get a clean homefolder)09:33
ra1v3nthen run systemback from inside that user 09:33
ra1v3nthen once done I write to dvd09:33
ra1v3ndestroy the temporary user09:34
ra1v3nclear the systemback folder09:34
ra1v3nback up all your aps with aptoncd09:34
Langjansounds complicated but worth doing 09:35
Langjanwhat about vbox?09:35
ra1v3nthen write that to a dvd aswell (make sure you select dvd image NOT cd)09:35
ra1v3nthen back up the excluded folder like your WINE and Playonlinux and all your doccies and pics09:36
ra1v3nthen if the shite does hit the fan you can recover quickly09:36
Langjanwill vbox also run after backup09:36
ra1v3nyes its complicated but it makes life easier after a crash09:36
ra1v3nvirtualbox?09:36
Langjandont use wine and playonlinux09:36
ra1v3nIn what way?09:37
Langjanyes09:37
ra1v3nthe virtualbox app itself will be backed up09:37
ra1v3nbut I suggest you backup your vbox appliances seperately09:37
ra1v3nthis is why I create a dummy user .... clean homefolder no fluff like masive vbox appliances09:38
LangjanBy appliances do you mean the Win xp os running there?09:38
ra1v3nyes09:38
Kilosand so the truth comes out09:39
ra1v3non the HDD the will be a folder called Win Xp etc ... it will contain the virtual HDD and associated files09:39
Kiloshidden xp 09:39
ra1v3nLOL Kilos09:39
Kilossigh09:39
ra1v3nWithin the menu tab of Vbox you can select to backup this applaiance and vbox will create a single compressed bundled file similar to a tarball  09:40
LangjanOK I will give it a go and see how far I can get before knocking on your door  09:40
ra1v3ntake that and write it to a backup dvd or place it on another HDD 09:41
ra1v3ngoogle if you get stuck .... tons of tutorials on all of these online09:41
LangjanOK many thks09:41
ra1v3nI normally do this all as soon as I have my setup installed and everything is working09:41
Kilosi made a systemback flash disk and installed from it and asll pics and everything same on desktop as on lappy09:42
ra1v3n'm here often aswell if you need help09:42
ra1v3nyeah systemback is awesome especially if you need to clone a system in a hurry09:42
LangjanMany thanks ra1v3n, will do 09:43
Kiloshidden xp09:43
Kilosnow youve ruined a friendship09:43
ra1v3nI make the Dummy User so that I'm working from a clean homefolder 09:43
Kilosthink up an excuse quickly09:43
ra1v3nbecause after a few weeks of working your homefolder will never fit on a dvd09:44
Kiloshi exupboy welcome to ubuntu-za09:44
Kilosdvds are old fashioned things09:45
Kilosflash sicks come in many sizes09:45
LangjanSo thats my story for the day Kilos  - nothing broke. Fortunately I'm not using kde, lmga!09:45
Kilossticks/disks09:46
Langjandrives?09:46
Kiloshaha so cheeky this bally09:46
Kilosja man memory sticks09:46
Kilosflash disks09:46
Langjan'cause I know I can outrun you09:46
Kilosflash drives 09:46
Kilosusb memory modules09:47
Langjanflash drives, usb sticks, stiffies, whatchamacallits09:47
Kilosand you must remember the turmeric stuff Langjan the you wont find things you have no idea how or where they came from09:48
Langjankatottertjies09:48
exupboyHi There, thanks09:48
LangjanWe chat again when youre pushing 74 Kilos 09:48
Kilosnono you wont be around09:49
LangjanI will, dunno about you09:49
Kiloschat now before you forget who i am09:49
Langjanlmga109:49
Kiloshee hee09:49
Langjan!09:49
LangjanOk im gonna log off and practice some systemrestore09:50
Kilosenjoy09:50
Langjanwhere do I find the dam thing?09:50
Kiloswhat09:50
Kilosluckily you head is glued on09:51
Langjansystem restore - and my computer!09:51
magespawnin the dam things place, where else09:51
Kiloslol09:51
Langjanif its in the dam its broken, not waterproof. Hi magespawn how are you keeping?09:51
magespawngood and you Langjan ?09:52
Langjanfine thks09:53
Langjanjust battling a bit with the laatslapers09:53
Kiloshahaha09:53
Langjansee the guilty conscience?09:53
Kiloshehehehe09:53
Langjanlmga09:53
Langjanglad youre honest my friend, thats why I like you so much09:54
Kilosoh only because of my honestly09:54
Langjaneven if you keep nagging 09:54
Kiloshonesty09:54
Kiloshaha09:54
Kilosthose with blocked ears need nagging09:55
Langjannow youre fishing for compliments...09:55
Kilosoh09:55
Langjanhow many you want?09:55
Kilosand those with bad memories09:55
Kilosi dont need compliments ty sir09:55
LangjanI have 8 Gb 09:55
LangjanArrogant young man!09:56
Kilosthat will make a good backup iso09:56
Langjanon my RAM?09:56
Kilosi have systemback iso on an 8g stick as well09:56
LangjanCan see you chase too many rams and ewes around09:57
Kiloswhat are you talking about09:57
Kilosyou have 8g ram09:57
Langjanmaybe its 4, I forgot09:58
Langjanlmga09:58
Kiloshahaha09:58
Langjanjy moet mooi bly en die dag geniet09:58
Kilosi have found the best time to help peeps that need nagging is when they are in the bath09:59
Kilosmake them wash their ears well so they can hear properly09:59
Langjangood idea, will tell my caregiver09:59
Kiloslol10:00
Langjanbye for now10:00
Kiloscheers Langjan have a good day sir10:00
LangjanYou too thks Kilos 10:01
chesedosuperfly: i'm suspecting bad internet10:01
chesedoafternoon all btw...10:01
Kiloshi chesedo 10:01
andrewlsdFun reading: http://www.eweek.com/security/black-hat-do-usb-keys-left-in-parking-lots-get-picked-up.html10:02
ra1v3nNever under any circumstances insert a USB key that you don't own or haven't just removed from its packaging after purchase10:10
andrewlsd^ yip10:30
magespawnbut why, could be so much of fun10:50
Kiloswhats a usb key? a thing you open car doors with?11:17
ra1v3nIm back11:17
ra1v3nusb key, stick, drive flashdrive11:18
ra1v3nsame thing11:18
Kiloswhy would they be left lying around in parking lots11:19
Kilosi go read that link11:19
ra1v3nlol11:19
Kilostoo much to read11:22
ra1v3nlol11:25
andrewlsdKilos: TL;DR : make USB with malicious software / firmware.  "lose" them at strategic points. Wait for users to insert USB dongles into their computers. Profit from the pwnage.11:28
Kilosah11:34
Kiloseven linux pcs?11:35
ra1v3nyes11:35
Kilosoh my11:35
ra1v3nthere are some rootkits that can easily infect a linux box11:35
ra1v3nand there are certain virii that are at the firmware level 11:36
andrewlsd+1 ra1v3n11:40
andrewlsdnothing like physical access to bypass many layers of security11:40
ra1v3noh yeah 11:41
ra1v3nbare metal access11:41
ra1v3nlater all 11:51
ra1v3nciao 4 now 11:51
andrewlsdciao11:51
andrewlsdHave a good afternoon everyone :-)12:32
Kiloshehe12:34
Kilosyou too andrewlsd 12:34
Kilosdunno how you did that12:35
magespawngo to go out chat later12:35
KilosHave a good afternoon everyone 12:35
Kilosgo well magespawn 12:35
andrewlsdenjoy the weekend everyone13:02
ra1v3nHello again all14:01
Kiloshi ra1v3n 14:02
ra1v3nHello kilos14:04
pavlushkacan anyone tell me which part is the driver code here, https://github.com/lwfinger/rtlwifi_new/pull/74/files ?15:07
pavlushkaand Greetings ZA!15:07
ra1v3nI'm Back!15:54
kulelu88theblazehen: you around?16:02
pavlushkacan anyone tell me which part is the driver code here, https://github.com/lwfinger/rtlwifi_new/pull/74/files ?16:54
Kilospavlushka ask that at #ubuntu as well16:55
pavlushkaKilos: copy16:55
Kilosno one knows who is doing what here on friday evening16:56
ra1v3npavlushka, there is no driver code there16:56
pavlushkara1v3n: in the result of "lspci | grep Wireless"16:58
ra1v3nthe code is at the beginning of the output16:59
ra1v3nthen just follow the instructions17:00
ra1v3nshould be in this format: 00.00.0 (Unless I'm mistaken)17:01
pavlushkara1v3n: you mean something like "01:00.0" ?17:01
ra1v3nyep17:01
pavlushkara1v3n: thanks :)17:01
ra1v3ngive it a go 17:02
ra1v3nyour'e welcome ^^17:02
ra1v3nlet me know how you do17:04
theblazehenkulelu88: what's up?17:26
ra1v3nHello pavlushka did you win?18:03
pavlushkara1v3n: its on someone else's pc, will confirm you after getting the result, :)18:09
ra1v3nkewl18:10
ra1v3nkewl18:10
ra1v3nGoodnight guys have a good one18:17
magespawnchat later all18:20
Kiloshi SEptic inetpro superfly 18:41
SEpticevening ... *tips hat*18:41
Symmetriammmmm19:07
Symmetriaanyone here run their own DNS recusors?19:07
SEpticpft, silly kdewallt19:10
SEptickdewallet19:10
Kiloslol19:10
SEpticbeautifully engineered concept of software... it's finding the start button thats the problem :P19:11
SEptici think it's just being a bit of a woman with 16.04, but sure it'll get fixed up as we go19:12
SEpticgot my office colleagues to wipe windows and come over to the dark-side19:13
Kiloscool19:13
superflySEptic: there's a cunning trick with KWallet, if you don't mind the security aspects of it too much. Just set your password to be blank, and it no longer prompts for your password.19:14
SEptici did try that cunning plan me Lord, it did work for a couple reboots19:15
SEptici'm having issues with it not opening wallets, not even prompting to open them19:16
SEpticif i create a new wallet and do things then its 100%19:16
SEpticbut after a couple boots it just doesn't prompt to open the wallet at all19:17
SEpticif i gooi the wallet manager and click "open", then my laptop just sits and stares blankly at me19:17
SEptici am new to the wallet-y thing though19:18
superflyI last saw KWallet ages ago. if it is in use, I am not seeing it.19:18
superflyI no longer use KMail for my e-mail, so that's probably also why.19:19
SEptichaha, yea, i tried disabling completely, but then have to enter wifi passwords everytime i connect19:19
pavlushka__hehe, theblazehen ping19:30
pavlushka__now I am a quassel dude, yo19:30
theblazehenpavlushka__:  nice :)19:31
Kiloshaha19:31
Symmetriadammit, this is driving me nuts, I have two identical servers19:31
Symmetriaif I direct ALL dns queries to one of them, it seems to peak out at 4k queries/second19:31
Symmetriaif I direct them all to the other it does 800 / second19:32
Symmetriaconfigs are identical19:32
theblazehenSymmetria: Would you be fine with sharing the IPs?19:32
Symmetriatheblazehen yeah try and do recursive queries against 41.216.125.17919:34
Symmetriathats the problem server19:34
theblazehenSymmetria: All configs, or just the dns server?19:37
Symmetriatheblaze will send you configs in a second19:39
Symmetriajust waiting to see something first (I just modified something on one of the servers)19:39
theblazehensure19:39
theblazehenSymmetria: What's the other server?19:44
Symmetriatry recurse3-zw-anycast.liquidtelecom.net 19:46
Symmetriarecurse1 is the problem one19:46
Symmetria3 is ok 19:46
Symmetriarecurse1-za-anycast quite happily handles *SHITLOADS* of queries per second19:47
Symmetriaam waiting for the cacti polling to show me latest stats19:47
theblazehenWhere are you testing from?19:48
Symmetriaheh, both local to the servers and outside, but what I'm really looking at is the queries per second before I start seeing them top out where i'm cacti graphing19:49
theblazehenSymmetria: Could it be a network issue? They go through different routes19:50
Symmetriano, they are both ESXI servers, on the same ESXI platform, just different (yet identical) blades, so same network interface 19:50
SymmetriaIm wondering if its not some operating system setting with regards to buffers or something19:52
theblazehenAnd this is from a fresh deployment? As in wipe both, and let confg management do its thing?19:52
theblazehenWhat does sysctl -a say?19:52
theblazehenMaybe diff those19:53
Symmetriajust did, and sysctl's are now identical, still doeesnt seem to have helped *ponders*19:54
Symmetria(btw, just as a note, these servers form a part of the largest african recursive anycast in existence)19:55
Symmetriabasically, they are the zimbabwe nodes of 5.11.11.5 and 5.11.11.11 (africas equiv. of 8.8.8.8 / 4.2.2.2)19:55
theblazehenNice. And running bind from what I can see?19:55
theblazehenawesome19:55
Symmetriayeah they are running bind 19:56
theblazehenAnd all the others seem to run around 4k/s as well?19:57
Symmetriayeah, something aint right on the linux box though, looking at the packets per second through the interface, the RX PPS is about half (which I expect if I'm handling a lot less queries), but the TX is a fraction, like, 10% of the other19:59
Symmetriaso something is bottlenecking the UDP outbound19:59
theblazehenHmm19:59
theblazehenI wonder, try iperf maybe?20:00
theblazehenSee if it's a PPS or bandwidth issue20:00
Kilosnight all. sleep tight20:00
theblazehencheers Kilos20:00
theblazehenUpdating network configuration over ssh is always fun20:01
theblazehenMore so if the remote management tool sometimes (for large values of sometimes) drops keystrokes20:02
SymmetriaLOL, I generally write a new network config file on a third party platform and then copy it onto the system and either reboot or go in via console to apply it20:04
theblazehenYeah, well, console is kind of not a possibility here..20:05
theblazehenHosting company got bought out, and can't log in at new company20:06
theblazehenBut I had old link to customer portal that didn't redirect me to new company20:06
theblazehenSo I can turn it off and on again remotely20:06
theblazehenThat's about it20:07
Symmetriaheh buyouts are always interesting20:10
Symmetriathough in my case I'm generally the guy that goes into the companies we just bought and integrate/change/restructure etc on the networking side20:11
theblazehenCool20:11
Symmetrialol our next project is going to be very very interesting 20:11
Symmetriaheh next project - neotel ;p20:12
theblazehenfun20:12
theblazehenLooks like it's all going in a bash script then..20:15
theblazehenWell. It looks like I'm the type of guy that uses uses regex to extract info from anything (Seriously. I'm writing a smtp relay (*not* esmtp), using sed. And parsing notification emails with a regex and python), uses chattr +i when I don't want the file to be modified the right way, and uses bash scripts when there isn't a nice way to do something the right way20:20
SymmetriaLOL20:21
SymmetriaI do a lot of bash scripting shit as well20:21
theblazehenUnless someone knows how to bring up an openvpn bridge in /etc/network/interfaces, and then have a bridge to that defined?20:21
theblazehenOr can I use the openvpn tap device as a bridge directly? I don't *think* so20:22
SymmetriaARGHHHHH I think I found the problem and if I'm right Im gonna shoot myself in the head for being an idiot20:23
Symmetriaheh, I don't know openvpn sadly, so can't comment20:24
theblazehenSymmetria: Don't worry. I spent around 10 hours easy this weak to track down a single line of code in a module that I wasn't even looking in even though I should have..20:24
theblazehenweek*20:24
Symmetriahaha holy shit, that made a difference ;p20:25
SymmetriaI had fucked up something on the DNS rate limiting on recurse120:25
theblazehenAh..20:25
theblazehenWhy are you rate limiting?20:26
theblazehenAlso, I'm sure you have, but if not, the cloudflare blog has some really interesting stuff on dns20:26
theblazehenhave read it*20:27
Symmetriaheh, we exempt all on net20:27
Symmetriaand rate limit off net to a specific number of queries per second20:28
theblazehenAh. Yeah, makes sense20:28
Symmetriato avoid people using the servers for recursion attacks20:28
theblazehen_all_ on net?20:28
Symmetriabasically, we limit to 255 queries a second for offnet stuff - which is still pretty bloody high20:28
theblazehenSo say, if a customer hasn't paid for their account20:29
theblazehensometimes the isp will redirect to a landing page etc20:29
theblazehenCan they still query dns?20:29
Symmetriadoesnt matter, rate limits on the DNS on these recursors are PURELY based on ip subnets20:29
Symmetriaits basically an ip tables list of aggregated subnets that are a straight pass through, and then a connection tracking rule to limit everything else20:29
theblazehensure. I'm just thinking if people on the inside can run dns tunneling?20:30
theblazeheneg. iodine 20:30
Symmetrialol, they probably could but if they are that desperate *shrug* 20:30
theblazehenIt's faster than you'd think actually20:31
theblazehenAnd might be faster if you use a kind of parallel implementation20:31
theblazehenOr use a closer host20:32
theblazehenOr increase the window size I guess20:32
Symmetriaheh yeah but we would see it, very fast20:32
Symmetriaiodine uses specific query types 20:32
Symmetriaand we graph every server in terms of queries per second and in terms of number of queries per second of each TYPE of query20:33
theblazehenYeah, but you can tell it to use A, AAAA etc too. But, by numbers, sure20:33
Symmetriayeah, but to get DECENT throughput, you'd still need to be doing thousands of queries a second 20:33
Symmetriaand thats gonna show up20:34
Symmetriaand the other thing that would break it - and this is interesting, is the anycast 20:34
Symmetriabecause when you send the queries to the normal anycast addresses20:34
Symmetriayou can't guarantee WHICH server the query will end up as20:34
theblazehenyeah. Just saying that it might not be the query *type* that's gonna tip you off, but it'll definitely throw up red flags20:34
Symmetriathat will break state tracking which is a requirement for TCP20:34
Symmetriaheh, the whole DNS cluster, is made up of 14 seperate servers at the moment20:35
Symmetriaand its about to go to 18 20:35
theblazehenWould it break it? Iodine supports tracking connections on an identifier, and has sequence numbers etc20:36
theblazehenCool20:36
Symmetriatheblazehen, keep in mind, if you're doing TCP20:36
theblazehenI mean, with a single dns server there isn't any connection either if you're tunneling20:36
Symmetriayou need to keep the connection properly orientated to a specific server20:36
Symmetriabecause TCP has to be able to syn/ack to specific addresses20:36
theblazehenYeah, but this isn't running TCP itself20:37
Symmetriaand here is the other trick involved, if you hit server 120:37
Symmetriayeah but hold on20:37
theblazehenIt's just doing dns queries to NS you specify20:37
Symmetriaif you hit server 1 server 1's QUERY address20:37
theblazehenWhich is then running the vpn20:37
Symmetriais NOT the address it goes and establishes connections from20:37
theblazehenAh wait20:37
Symmetriaand server 2 has a different query address20:37
Symmetriaetc20:37
theblazehenYou're No nevermind20:37
Symmetriaand the server will have to maintain TCP state for a TCP connection to work20:37
Symmetriaso this breaks that :)20:37
theblazehenYeah, but the tcp doesn't have anything to do with the dns20:38
theblazehenSince you connect to the vpn server over dns, which then does the actual connections20:38
Symmetriayeah but the backend does, because you query the DNS, it sends packets and effectively "tunnnels" tcp20:38
Symmetriaand if all the syn/ack packets are coming from different servers and different ips20:38
Symmetriait will break 20:38
Symmetriammmm20:39
SymmetriaI'd need to test it20:39
theblazehenBut all the syn/acks will be going to your vpn20:39
Symmetriaheh, I'll do a throughput test and see what happens on it20:39
theblazehenWell, even if it works at all..20:39
Symmetriaif I can get 10mbit through it, I'd be suprised :) 20:39
theblazehenDo you restrict query sizes?20:39
Symmetriaand if I can't get more than 10mbit lol, I wouldnt really care :)20:39
theblazehenfor outside networks I mean20:39
Symmetriayes there are limits, would need to check what I set them to20:40
theblazehenwell, I got 500 kbit, with unmodified iodine client, to a server in USA (270ms)20:40
theblazehenThat's going through a proper dns server, not going direct20:40
Symmetriaheheh 500kbit wouldnt really register in our traffic terms20:40
theblazehenAnd it wasn't optimal because of the small window size (of iodine, NOT TCP). COuld go faster with that increased probably20:41
SymmetriaI start worrying about people abusing bandwidth when they start hitting 100mbit+ 20:41
Symmetria(and thats on a per client basis)20:41
theblazehenheh20:42
SymmetriaLOL, lemme show you something quick20:42
theblazehenI can do up to 993 byte dns requests on cell c dns servers20:42
theblazehenwhich then gets base64'd, reducing that a bit20:43
SEpticsheesh, you guys are in to some pretty serious stuff :)20:43
Symmetriaso, coupla notes about this20:43
Symmetriafirstly, my upload speed is FAR better than this will show, but the window sizes on the wmem aren't optimised20:44
Symmetriafor the latency20:44
Symmetriasecondly, on the download speed, whats limiting me here is the interface on the mweb speed test server20:44
Symmetriaiptables -A INPUT -p udp --dport 53 -m state --state NEW -m recent --set --name DNSQF --rsource20:44
Symmetriaiptables -A INPUT -p udp --dport 53 -m state --state NEW -m recent --update --seconds 1 --hitcount 255 --name DNSQF --rsource -j DROP20:44
Symmetriaooops20:44
Symmetriahttp://www.speedtest.net/result/5531549486.png20:44
Symmetriathere 20:44
Symmetria;p20:44
Symmetriathats me testing from my house in Nairobi to mweb in South Africa 20:45
Symmetria:P and doing that, is still only using 5% of the bandwidth into my house 20:45
Symmetrianow you know why I aint worried about 500kbit :)20:46
theblazehennice..20:46
Symmetriaheh, basically, my house has 2 x 10G links into it20:46
theblazehenAnd here I am about to pay R600 or so extra per month to increase my upload from 1 mbit to 2 mbit..20:46
Symmetriaand my desktop and server both have 10G links into them20:46
theblazehenNice20:46
theblazehenEthernet?20:46
SymmetriaFiber 20:47
Symmetriabut yeah Ethernet encap20:47
theblazehenCool. Yeah, heard FC is cheaper20:47
Symmetriaheh, and I have the advantage of the fact that unlike normal clients, who go through normal client infrastructure20:47
SymmetriaI dont, I plug straight into the backbone routers20:47
theblazehenAwesome20:48
Symmetriaheh, Im dying to get my hands into Neotel's network though and see how I can optimize it 20:48
Symmetriafew months away :)20:48
theblazehenNice. 20:48
Symmetriawe've completed the purchase (you might have seen the media announcing we bought em)20:49
* theblazehen always tries to optimize stuff too..20:49
theblazehenHmm, didn't really look at news much20:49
Symmetriaheh vodacom tried to buy em, they failed 20:49
SymmetriaLiquid succeeded :)20:49
theblazehenCool20:49
Symmetria(I head up network strategy for Liquid Telecommunications at group level)20:50
theblazehencool20:50
Symmetriaheh we're involved in some fun stuff at the moment though, wheeeee we're building our own submarine cable 20:51
Symmetriaand capacity wise, lol, it makes seacom look *tiny*20:51
theblazehenMust be fun..20:52
=== pavlushka_ is now known as Guest47235
Symmetrialol yeah, but stressful and complicated :)20:53
theblazehenEver break something big?20:53
SymmetriaLOL, it happens occasioally :P20:54
Symmetriaits not often, but like anyone who works at the level I do, we've all made our mistakes20:54
Symmetriamost of them BGP based ;p20:54
=== Guest47235 is now known as pavlushka
theblazehenyeah20:55
Symmetrialol, though one of my team made a chronic fuckup at 4am this morning that resulted in me getting very panicky phone calls a few minutes later 20:55
theblazehenOuch :/20:55
Symmetria:P he accidently nuked the wrong config and took out enough customers to wipe out 7gigs of bandwidth usage 20:56
SymmetriaI had it back online 10 minutes later but haha man, what a fuckup20:56
theblazehenMy funnest time I ended up sleeping around 6 hours spread over 4-5 days :(20:56
theblazehenwow20:56
Symmetriathats the biggest problem working with huge networks and massive routers, type the wrong thing, and you can do *SERIOUS* damage with a single command20:56
theblazehenYeah. Or config management stuff too20:57
theblazehenYou saw that stackoverflow post, that ended up being an advertisement?20:57
Symmetrialol I mean, on certain routers, a single command can take out *6 MILLION* peoples net access via their phones20:57
Symmetriakinda scary :p20:57
Symmetriaheh, nah?20:57
kulelu88did Symmetria just say he is donating the Zim DNS servers for me to build my botnet?20:58
theblazehenhttp://meta.serverfault.com/questions/8696/what-to-do-with-the-rm-rf-hoax-question20:58
Symmetriaheh kule I wouldnt suggest you trying something like that :)20:59
Symmetriaif you know a bit about me, lol, I play nasty with people who try that haha20:59
Symmetriahaha oh I saw that a while back theblaze21:00
Symmetriabtw, theblaze, with regards to 10G stuff and ethernet vs FC21:02
SymmetriaFC only really works for storage stuff21:02
Symmetriathe other thing about 10G, copper 10G on CAT6 is relatively cheap 21:02
Symmetriaits when you go fiber that the price starts climbing, and particularly if you go from multi-mode to single-mode21:02
kulelu88Symmetria: you won't find me, I am running my Tor network via Peru via Ethiopia :D21:03
Symmetriabecause the cost of the optic is where the money is at :)21:03
kulelu88Symmetria: how much will it cost for FTTH if you don't live far from wholesale fibre?21:03
Symmetriakule in ZA?21:04
theblazehenSymmetria: ah21:04
kulelu88yeah21:04
Symmetrianot sure yet :) ask me in 6 or 8 months once we complete the Neotel stuff 21:04
SymmetriaI can tell you what we're selling in KE at :P 21:04
theblazehenkulelu88: Well, kinda useless to mention those locations. That's kinda the point of an onion network, no?21:04
Symmetria100mbit uncapped with 4:1 contention is selling for around R2k a month 21:04
kulelu88theblazehen: what if that was a doozi?21:05
kulelu88uncapped is a word that needs to die21:05
Symmetrialol kule, question, how long you need in the hacking scene in ZA?21:05
kulelu88I'm not a hacker, i'm a skript kittie ;P21:05
Symmetrialol for how long :)21:05
Symmetriathe reason Im asking is because haha I wanna see if you may recognise something 21:06
=== Symmetria is now known as Vortexia
* Vortexia eyes you 21:06
Vortexialol, god its been more than a decade since I last used this nic ;p21:06
=== Vortexia is now known as Symmetria
kulelu88if you can find my IP via IRC then u haz haxxed me21:06
theblazehenkulelu88: Is that a challenge?21:07
kulelu88;'D21:07
Symmetria:P dammit21:09
Symmetriastupid irc client died21:09
kulelu88I sent you my USERINFO :D21:10
=== Symmetria is now known as SymmTest
Symmetriakule, grab that quick, I wanna test speed to you21:11
kulelu88you wanna traceroute me <321:12
SymmTesterrr 21:12
SymmTestno, I wanna test a file transfer speed21:12
SymmTest;p21:12
kulelu88so you work for liquid telecom :D21:14
theblazehenSymmTest: dcc? ;)21:14
SymmTestheh kule I head up network strategy for them21:14
SymmTestglobally21:14
SymmTesttheblaze yes *grin*21:14
kulelu88Liquid telecom were looking for a data scientist / corporate-jockey to crunch their data21:15
SymmTestwhat data? 21:15
kulelu88I saw the link pointing at pnet or some other shitty job portal and sighed 21:15
SymmTestmmmm got a link?21:16
kulelu88must be another case of "we have data, lets do data analysis on it"21:16
kulelu88how many CTCPs are you guys going to send me? :D21:16
SymmTestheh kule would need a lot more details to figure out what they were actually looking for21:17
SymmTestwe do some... rather interesting things :)21:17
kulelu88are you guys wholesale?21:17
SymmTestkule LOL, we're... a bit of everything21:17
SymmTestwe own the largest fiber network on the african continent21:17
kulelu88wait wait... I know the answer to this21:17
kulelu88"corporate IT solutions, telecoms and services provider"21:18
SymmTestwe do everything from wholesale to retail to voice switching to transaction processing21:18
SymmTestnah, wrong answer :P21:18
kulelu88theblazehen: are you still sending me CTCPs?21:18
SymmTestdo don't go near corporate IT solutions as such21:18
SymmTestheh kule Liquid is part Telco, part ISP in reality21:19
theblazehenkulelu88: Yup. So, you're exiting through a bot in your botnet then?21:19
theblazehenSure21:19
theblazehenlooks like it21:19
theblazehenhigh latency21:19
theblazehenNode in france21:20
kulelu88theblazehen: how do I request your CTCP?21:20
theblazehenkulelu88: What you don't know wont hurt you :)21:21
SymmTestheh, I kinda miss my days on the darkside21:21
SymmTestits been far 2 long since I had the time or motivation to sit and write exploits 21:22
* theblazehen wishes that I had continued with that a bit21:22
theblazehenWas never more than a skiddie myself21:22
theblazehenBut still21:22
SymmTestlol, I wrote the first ever exploit against the cisco pix firewalls back in the 90s21:22
SymmTestthat was fun 21:22
theblazehenWell, I found something decent recently21:22
SymmTestit reset all the state tables 21:22
theblazehenBut I did the whole "responsible disclosure" thing...21:22
SymmTestwe used to sit on irc and kick everyone off who was behind pix firewalls for amusement ;p21:22
theblazehennice21:22
SymmTestby resetting their state tables and killing all their tcp connections21:23
SymmTestheh, was actually a really simple exploit, their checking of source and destination and sequencing on RST packets was chronic21:23
kulelu88corporate corner-cutting 21:23
SymmTestso the right spoofed RST packets and you could nuke state entries, cycle through port numbers and you could kill anything21:23
theblazehenCool21:24
SymmTest(that stil works against severael state based firewalls out there)21:24
SymmTestheh, almost all the exploits and stuff I wrote though were network based - attacking the network stack was always more interesting than attacking systems for me21:25
kulelu88why you 2 hour behind? theblazehen 21:25
SymmTestbecause there is sooooo much you can do and its actually relatively unexplored territory21:25
kulelu88layer3? SymmTest 21:25
theblazehenkulelu88: C'mon, you can't figure it out? :)21:25
SymmTestLOL, I've written some pretty fucking nasty code to test ipv6 problems21:25
SymmTestkule heh, I've done attacks at layer 3, layer 4 and even layer 2 21:26
theblazehenLayer 8?21:26
SymmTestlayer 3 tends to have more attack vectors 21:26
SymmTestLOL, theblaze I'm pretty good at layer 9 attacks ;p21:26
SymmTestpolitics is fun ;p21:26
kulelu88I only do layer1 attacks21:27
theblazehenkulelu88: Really? ...21:27
SymmTestlol, so you go vandalize physical infrastructure? 21:27
SymmTestare you by any chance an EFF member? 21:28
SymmTest;p21:28
* SymmTest snickers21:28
=== SymmTest is now known as Symmetria
kulelu88when I protest and kick a dustbin down, layer1 attack ;P21:28
kulelu88Symmetria: what layer does attacking actual PC-hardware fall under? layer1 also?21:30
Symmetriaheh, its not part of the network stack so it doesnt have a classification21:30
Symmetria;p21:30
theblazehenYeah, you said it in better words Symmetria21:30
kulelu88oh so that doesn't fall within the network. noted21:31
Symmetriaheh Layer 1 = Physical (Fiber Cables, Network Cards, CAT5/6 etc)21:32
SymmetriaLayer 2 = the network layer (vlan related shit, arp, etc)21:32
SymmetriaLayer 2.5 = MPLS 21:32
SymmetriaLayer 3 = IP layer 21:32
SymmetriaLayer 4 = now you're into shit like TCP/UDP etc 21:33
Symmetriaand so it goes until you hit Layer 7 which is basically applications21:33
Symmetria(this isn't technically the OSI model which is slightly more extensive)21:33
kulelu88layer5 and 6 get no love21:34
paddatrapperMaaz: Tell Kilos I've forked Ibid to IbidNext on Launchpad: https://code.launchpad.net/~krobbertze/ibidnext/+git/ibidnext21:38
Maazpaddatrapper: Got it, I'll tell Kilos on freenode21:38
paddatrapperMaaz: tell Kilos Overview: https://launchpad.net/ibidnext21:39
Maazpaddatrapper: Okay, I'll tell Kilos on freenode21:39
superflyUgh git21:42
theblazehenkulelu88: https://linx.home.theblazehen.com/kulelu.pcap boom21:47
kulelu88that's a link to trap me :D clever21:48
theblazehenWhat? Me? Never...21:48
paddatrappersuperfly: Mainly because I still need to learn bzr :) And I am not doing that tonight. Though with the pain that is launchpad's git I think I may have to learn it quickly before anyone actually looks at the repo :)21:50
kulelu88somebody visit theblazehen link for me :D21:52
pavlushkakulelu88: the pcap size is only 524 kB, :)21:56
kulelu88what's the contents? pavlushka 21:57
pavlushkakulelu88: I may have to run wireshark for that which I will not, :p21:58
superflypaddatrapper: I've never used git with Launchpad, and I know Launchpad was written for bzr22:00
theblazehenAh what the hell. Off to bed, kulelu88: 196.210.166.192 do your worst22:02
kulelu88:D22:03
kulelu88theblazehen: I'm looking at you right now through your webcam :O22:03
theblazehenYou got the wrong person.22:04
theblazehenI don't have a webcam22:04
kulelu88it's your CCTV :D22:04
theblazehenDon't have that either22:04
kulelu88i thought you going to bed :D22:08
theblazehenRight. Wanna continue tomorrow?22:08
Symmetriaheh22:12
SymmetriaI'm throwing a HUGE load test 22:12
Symmetriaat my DNS servers now22:12
Symmetriafor the next 10 minutes22:12
paddatrappersuperfly: Well it is now bzr based. Easier than I thought to transition22:31
qwebirc47668Morning23:54

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!