00:21 | ben_roose has left IRC (ben_roose!~roose@roose.cs.wichita.edu, Remote host closed the connection) | |
00:28 | fnurl has left IRC (fnurl!3cf8605f@gateway/web/freenode/ip.60.248.96.95, Ping timeout: 246 seconds) | |
00:59 | yanu has left IRC (yanu!~yanu@178-116-58-90.access.telenet.be, Ping timeout: 246 seconds) | |
00:59 | yanu has joined IRC (yanu!~yanu@178-116-58-90.access.telenet.be) | |
01:50 | telex has left IRC (telex!teletype@freeshell.de, Remote host closed the connection) | |
01:52 | telex has joined IRC (telex!teletype@freeshell.de) | |
02:32 | url has joined IRC (url!3cf8605f@gateway/web/freenode/ip.60.248.96.95) | |
02:51 | fiesh has left IRC (fiesh!~fiesh@hq.wsoptics.de, Ping timeout: 252 seconds) | |
02:51 | fiesh has joined IRC (fiesh!~fiesh@hq.wsoptics.de) | |
03:08 | AlexPortable has left IRC (AlexPortable!uid7568@gateway/web/irccloud.com/x-kpetumemupeueksn, Quit: Connection closed for inactivity) | |
04:28 | work_alkisg is now known as alkisg | |
04:55 | vmlintu has joined IRC (vmlintu!~vmlintu@a91-152-200-13.elisa-laajakaista.fi) | |
05:47 | telex has left IRC (telex!teletype@freeshell.de, Ping timeout: 244 seconds) | |
05:48 | telex has joined IRC (telex!teletype@freeshell.de) | |
06:02 | uXus has left IRC (uXus!~uXus@217.77.222.72, Remote host closed the connection) | |
06:03 | uXus has joined IRC (uXus!~uXus@217.77.222.72) | |
06:23 | <alkisg> Yup, about the virus yesterday, the person that installed it was used to debian, so he set a root password of 1234... :(
| |
06:38 | <url> any idea what the attack vector was that allowed the priv escalation?
| |
06:41 | <alkisg> They logged in as root. What escalation? :)
| |
06:41 | root/1234... lame credentials
| |
07:00 | <url> oh ha, damn, I was assuming some exploit, and then a weak root
| |
07:01 | *shakes head*
| |
07:10 | <vmlintu> does debian somehow encourage one to set root password to 1234?
| |
07:11 | <alkisg> Of course not, but it's not good to ignore the fact that many users select weak passwords
| |
07:13 | <vmlintu> That's one of the reasons why I like readonly images everywhere - laptops and ltsp servers included. Even if there's an exploit, the damage is easy to repair..
| |
07:13 | <alkisg> Stealing user's bank accounts is not easy to repair :)
| |
07:14 | <vmlintu> well, that requires something else than getting one username and password..
| |
07:14 | <alkisg> Bots do DDOS attacks, they install keyloggers...
| |
07:15 | I don't want to rely on only getting infected by "good" viruses
| |
07:16 | <vmlintu> Of course security needs to be in order. Just that it's easier to get back to a known state when you don't need to do a 3 hour reinstall..
| |
07:16 | <alkisg> Fortunately there's always a backup in /opt/ltsp/images/i386.img :)
| |
07:18 | <vmlintu> But are there banks that don't verify transactions by sms or some other channel?
| |
07:18 | <alkisg> paypal is one
| |
07:19 | <vmlintu> Paypal is PITA.. I never use them besides getting fraudulent charges off my cards..
| |
07:19 | <alkisg> There are others that allow small transfers without second verification though
| |
07:20 | <vmlintu> You should put some code in LTSP to make donations to developers.. ;)
| |
07:20 | ricotz has joined IRC (ricotz!~rico@ubuntu/member/ricotz) | |
07:20 | <alkisg> Hahaha
| |
07:20 | The new ltsp version will be ransomware :P
| |
07:21 | <vmlintu> To boot your client you need to send bitcoins..
| |
07:22 | Or you could start mining bitcoins with all the clients..
| |
07:26 | <Hyperbyte> That'd be pretty awesome.
| |
07:40 | Parker955_Away has left IRC (Parker955_Away!~parker@2001:470:8:a61::8bdc:c4f, Ping timeout: 246 seconds) | |
07:48 | Grembler has joined IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net) | |
08:02 | Parker955_Away has joined IRC (Parker955_Away!~parker@2001:470:8:a61::8bdc:c4f) | |
08:05 | <url> alkisg, forgive my ignorance, other than remembering you hail from greece, oversee the hellenic LTSP (i'm not give to e-stalking)
| |
08:05 | where vmlintu suggests you put some code in, are you a contrib/lead dev or similar
| |
08:06 | <alkisg> I'm one of the ltsp devs, yup...
| |
08:06 | <url> cool, nice to know
| |
08:06 | danau11 has joined IRC (danau11!~durban@12.197.179.122) | |
08:06 | <url> being a goon (somethingawful) we have one of the lead devs from WINE hangs around a good bit
| |
08:07 | and a couple of weeks ago, i found out a former colleague here has enhanced commit on freeBSD - the world is indeed a small place :)
| |
08:09 | danau11 has left IRC (danau11!~durban@12.197.179.122) | |
08:15 | danau11 has joined IRC (danau11!~durban@12.197.179.122) | |
08:18 | danau11 has left IRC (danau11!~durban@12.197.179.122) | |
08:22 | danau11 has joined IRC (danau11!~durban@12.197.179.122) | |
08:24 | danau11 has left IRC (danau11!~durban@12.197.179.122) | |
08:24 | khildin has joined IRC (khildin!~khildin@ip-80-236-219-151.dsl.scarlet.be) | |
08:26 | danau11 has joined IRC (danau11!~durban@12.197.179.122) | |
08:28 | danau111 has joined IRC (danau111!~durban@66.251.57.114) | |
08:28 | vervelak has left IRC (vervelak!~vervelak@139.91.248.3, Quit: Lost terminal) | |
08:30 | vervelak has joined IRC (vervelak!~vervelak@139.91.248.3) | |
08:30 | danau11 has left IRC (danau11!~durban@12.197.179.122, Ping timeout: 244 seconds) | |
08:39 | Parker955_Away has left IRC (Parker955_Away!~parker@2001:470:8:a61::8bdc:c4f, Ping timeout: 246 seconds) | |
08:47 | uXus has left IRC (uXus!~uXus@217.77.222.72, Remote host closed the connection) | |
08:47 | uXus has joined IRC (uXus!~uXus@217.77.222.72) | |
08:58 | khildin has left IRC (khildin!~khildin@ip-80-236-219-151.dsl.scarlet.be, Remote host closed the connection) | |
09:09 | danau111 has left IRC (danau111!~durban@66.251.57.114, Read error: Connection reset by peer) | |
09:14 | Parker955_Away has joined IRC (Parker955_Away!~parker@2001:470:8:a61::8bdc:c4f) | |
09:29 | gdi2k has joined IRC (gdi2k!~gdi2k@119.94.31.20) | |
09:40 | Grembler has left IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net, Read error: Connection reset by peer) | |
09:51 | Grembler has joined IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net) | |
09:55 | telex has left IRC (telex!teletype@freeshell.de, Remote host closed the connection) | |
09:56 | telex has joined IRC (telex!teletype@freeshell.de) | |
10:05 | alkisg is now known as work_alkisg | |
10:27 | Grembler has left IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net, Read error: Connection reset by peer) | |
10:37 | Grembler has joined IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net) | |
11:24 | AlexPortable has joined IRC (AlexPortable!uid7568@gateway/web/irccloud.com/x-ohbdkidnqmmgrhvy) | |
11:24 | NeonLicht has joined IRC (NeonLicht!~NeonLicht@darwin.ugr.es) | |
11:35 | danau11 has joined IRC (danau11!~durban@12.197.179.122) | |
11:35 | danau11 has left IRC (danau11!~durban@12.197.179.122) | |
11:51 | Faith has joined IRC (Faith!~paty_@unaffiliated/faith) | |
12:08 | url has left IRC (url!3cf8605f@gateway/web/freenode/ip.60.248.96.95, Ping timeout: 246 seconds) | |
12:17 | mikkel has joined IRC (mikkel!~mikkel@mail.dlvs.dk) | |
12:20 | adrianorg has left IRC (adrianorg!~adrianorg@177.132.216.242, Ping timeout: 255 seconds) | |
12:22 | adrianorg has joined IRC (adrianorg!~adrianorg@186.215.18.167) | |
12:51 | dgroos has joined IRC (dgroos!~dgroos@x-134-84-1-32.vpn.umn.edu) | |
13:15 | <dgroos> Hi.
| |
13:17 | Still having problem that local users can’t log into fat clients. Now neither can users in the AD domain.
| |
13:17 | work_alkisg: available to help?
| |
13:21 | terminal output from when trying to log in at client, both local user and AD user: http://paste.ubuntu.com/12328041/
| |
13:23 | Terminal output when unjoining and rejoining AD domain—shows ip/port numbers. I wonder if there is a conflict with address/ports? http://paste.ubuntu.com/12328071/
| |
13:26 | Problem seems to come and go. For the first few hours of use there were no problems, then they have been intermittent since then. Currently no kind of user can authenticate at the fat client.
| |
13:33 | ogra_ has left IRC (ogra_!~ogra_@p5098ed03.dip0.t-ipconnect.de, Ping timeout: 250 seconds) | |
13:33 | ogra_ has joined IRC (ogra_!~ogra_@p5098ed03.dip0.t-ipconnect.de) | |
13:43 | <dgroos> Oh, now people in AD group can authenticate! (but local users still can’t).
| |
13:49 | mikkel has left IRC (mikkel!~mikkel@mail.dlvs.dk, Quit: Leaving) | |
13:51 | ben_roose has joined IRC (ben_roose!~roose@roose.cs.wichita.edu) | |
13:57 | <dgroos> I’ll be touching back throughout (my) day, thanks…
| |
14:06 | championofcyrodi has left IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net, Ping timeout: 244 seconds) | |
14:15 | championofcyrodi has joined IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net) | |
14:22 | cyberorg has left IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg, Ping timeout: 250 seconds) | |
14:23 | cyberorg has joined IRC (cyberorg!~cyberorg@opensuse/member/Cyberorg) | |
14:50 | work_alkisg is now known as alkisg | |
14:50 | <alkisg> dgroos: here?
| |
14:51 | When the problem happens, open epoptes, right client on a client that can't login, and right click -> execute -> open root terminal locally
| |
14:51 | From that root terminal, try: ssh user@server
| |
14:51 | replace the user with an existing user, first local, then AD
| |
14:51 | leave the word "server" exactly as it is, don't replace it
| |
14:52 | See what happens there, what messages show up etc
| |
14:56 | bobby_C has joined IRC (bobby_C!~bobby@85-124-22-227.teleworker.xdsl-line.inode.at) | |
14:58 | alkisg is now known as work_alkisg | |
15:39 | <dgroos> work_alkisg: for local user:
| |
15:39 | http://imagebi.../2FBK6FmAiaRc
| |
15:40 | try this: http://imagebin.ca/v/2FBK6FmAiaRc
| |
15:41 | AD user: http://imagebin.ca/v/2FBKWARxnpXl
| |
15:41 | Both users were able to log in!
| |
15:58 | When I try to log into that client while at the keyboard, login doesn’t work either for local or AD user.
| |
16:02 | epoptes_user3 has joined IRC (epoptes_user3!bed256d5@gateway/web/freenode/ip.190.210.86.213) | |
16:29 | <dgroos> BB in 60…
| |
16:35 | telex has left IRC (telex!teletype@freeshell.de, Remote host closed the connection) | |
16:36 | telex has joined IRC (telex!teletype@freeshell.de) | |
17:28 | work_alkisg is now known as alkisg | |
17:28 | <alkisg> dgroos: here?
| |
17:29 | dgroos: it sounds like the problem is not authentication, but that the session crashes or exits
| |
17:29 | <dgroos> YES!
| |
17:30 | <alkisg> Is it broken now?
| |
17:30 | <dgroos> Good, I think…
| |
17:30 | At the client, I’ll check…
| |
17:30 | yes.
| |
17:30 | <alkisg> !vnc-alkisg
| |
17:30 | <ltsp> vnc-alkisg: To share your screen with me, run this: sudo apt-get --yes install x11vnc; x11vnc -connect alkisg.no-ip.org This is a reverse connection, it doesn't need port forwarding etc.
| |
17:30 | <alkisg> nope
| |
17:30 | !vnc-dide
| |
17:30 | <ltsp> vnc-dide: To share your screen with me, run this: sudo apt-get --yes install x11vnc; x11vnc -connect srv1-dide.ioa.sch.gr - this is a reverse connection, it doesn't need port forwarding etc.
| |
17:31 | <alkisg> This one ^
| |
17:31 | <dgroos> k
| |
17:31 | <alkisg> But I'm connected to my server via vnc, so it'll be slow... :D
| |
17:31 | Unfortunately our working schedules don't match at all
| |
17:32 | Grembler has left IRC (Grembler!~Ben@cpc29-aztw22-2-0-cust128.18-1.cable.virginm.net, Quit: I Leave) | |
17:48 | <alkisg> dgroos: there's something that fills up your client file system
| |
17:48 | that then breaks everything, not just logins
| |
18:05 | alkisg is now known as work_alkisg | |
18:07 | championofcyrodi has left IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net, Quit: Leaving.) | |
18:07 | championofcyrodi has joined IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net) | |
18:07 | dgroos has left IRC (dgroos!~dgroos@x-134-84-1-32.vpn.umn.edu, Quit: dgroos) | |
18:08 | championofcyrodi has left IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net, Client Quit) | |
18:08 | championofcyrodi has joined IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net) | |
18:08 | dgroos has joined IRC (dgroos!~dgroos@x-134-84-1-32.vpn.umn.edu) | |
18:13 | championofcyrodi has left IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net, Remote host closed the connection) | |
19:00 | championofcyrodi has joined IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net) | |
19:01 | championofcyrodi has left IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net) | |
19:02 | <maldridge> work_alkisg: fills up the client filesystem, or the server filesystem?
| |
19:14 | khildin has joined IRC (khildin!~khildin@ip-80-236-219-151.dsl.scarlet.be) | |
19:25 | bobby_C has left IRC (bobby_C!~bobby@85-124-22-227.teleworker.xdsl-line.inode.at, Remote host closed the connection) | |
19:34 | NeonLicht has left IRC (NeonLicht!~NeonLicht@darwin.ugr.es, Ping timeout: 246 seconds) | |
20:18 | championofcyrodi has joined IRC (championofcyrodi!~cott@50-205-35-98-static.hfc.comcastbusiness.net) | |
20:19 | ricotz has left IRC (ricotz!~rico@ubuntu/member/ricotz, Quit: Ex-Chat) | |
20:23 | khildin has left IRC (khildin!~khildin@ip-80-236-219-151.dsl.scarlet.be, Quit: I'm gone, bye bye) | |
20:24 | Nade has joined IRC (Nade!6d9c3b1c@gateway/web/freenode/ip.109.156.59.28) | |
20:53 | alex______ has joined IRC (alex______!4e6a1104@gateway/web/freenode/ip.78.106.17.4) | |
21:16 | Faith has left IRC (Faith!~paty_@unaffiliated/faith, Quit: Leaving) | |
22:22 | ben_roose has left IRC (ben_roose!~roose@roose.cs.wichita.edu, Remote host closed the connection) | |
22:33 | gehidore has left IRC (gehidore!~username@unaffiliated/man, Quit: WeeChat 1.3) | |
22:34 | gehidore has joined IRC (gehidore!~username@unaffiliated/man) | |
22:50 | telex has left IRC (telex!teletype@freeshell.de, Remote host closed the connection) | |
22:52 | telex has joined IRC (telex!teletype@freeshell.de) | |