irclog2html for #gllug on 20060126

01:04.29ErwinOK, any Spooks episode involving computers are just hopeless. Stealing 20 billion dollars of IMF Funds by using the password of a low-level clerk, from a laptop over the Internet? Sheesh.
01:10.39*** join/#gllug Leeds (n=richardc@202.82.163.139)
06:23.24SlayerXPcompletely unrealistic
06:23.35SlayerXPhad they done it over AOL is might be believable
06:24.27Leedswhat's that then?
06:24.57SlayerXPi'm told it's a bit like the internet, but faster
06:25.44Leedswhat are you talking about?
06:26.41SlayerXPyou don't do much trolling, do you? :)
06:27.15Leedsnot so much
06:27.22Leedsbut I feel like I'm missing a lot of context
06:27.46SlayerXPi'd explain but you're probably too intelligent to understand
06:29.07Leedshttp://www.saffron-cruises.com/fireworks_hong_kong.php
06:41.04*** join/#gllug skugg (n=stig@ggtl.org)
06:45.04*** join/#gllug andrew (n=andrew@vm.black1.org.uk)
06:55.18*** join/#gllug new2unix (n=unixadmi@host-87-74-42-253.bulldogdsl.com)
07:35.42Leedsooh, this could be painful
07:35.55Leedsspamd eating all the memory on my system, so I've turned it off for a bit
08:45.42Leedsibot what time is it in London right now?
08:45.45ibotI think you lost me on that one, Leeds
08:45.53Leedsibot gmt
08:45.54ibotGeneric Mapping Tools. URL: http://imina.soest.hawaii.edu/gmt/.  Greenwich Mean Time
08:45.58Leedsibot time
08:45.59ibot2006.01.26  8:45:59 GMT
08:49.57SlayerXPLeeds: why is it doing that?
08:50.18Leedswhat?
08:50.30SlayerXP<Leeds> spamd eating all the memory on my system, so I've turned it off for a bit
08:51.05Leedsdunno... I've upgraded it, and it's eating less memory, but the free memory is going down and I don't know how to see where it's going - this is freebsd, I know on Linux
08:51.33SlayerXPfree memory is wsted memory
08:51.36SlayerXPwasted
08:51.53wethrinSlayerXP: It gets very very drunk?
08:51.56Leedsand in about 8 minutes, I'll see if whatever dragged the system down on the last hour does it again
08:52.11SlayerXPwethrin: exactly.
08:52.20LeedsI don't mind if it's going somewhere, but I had spamd processes with over 500MB of memory in use
08:52.34Leedsd'apartment?
08:52.39SlayerXPLeeds: you should limit the size of the messages passed to spamd
08:52.50SlayerXPspam is only very rarely more than a few k in size
08:53.19murbanyone know how much ssl certs cost now days?
08:53.27Leedsit's limited to 256KB
08:53.39SlayerXPmurb: free -->  $$$$$
08:53.41murbLeeds: so it was just being leaking.
08:53.47murbs/ing/y/
08:53.48SlayerXPLeeds: too high
08:54.00murbSlayerXP: something that most webbrowsers will work with i mean.
08:54.11SlayerXPmurb: yes. what I said.
08:54.17Leedsmurb: $28 per year from Jason, reselling someone who is reselling godaddy
08:54.26murbI rember 80$ being about that much, but i can't find anyone selling them for less than 180$
08:54.42murbLeeds: i had some idea that it was like that but nothing on ukpost.com
08:54.44Leedsbey leaking?  yes, I think so
08:54.49Leedshttp://www.ukfsn.org/extras/
08:56.02murbdanke.
08:56.09Leedsbitte
08:58.33Leedsmurb: they do work, but you need to install an intermediate cert on your server
08:59.24murbwhat is that?
09:00.32*** join/#gllug morsing (n=morsing@emil.morsing.cc)
09:00.46Leedsthe cert is not signed by a CA - it's signed by a cert which is signed by a CA, so you need to provide the intermediate cert on your server as well to allow people to track the signing back to a trusted CA
09:01.04morsingLeeds: Ok
09:01.08murboh, otherwise they don't see the trust path.
09:01.11Leedsright
09:01.16Leedsmorning morsing ;-)
09:01.25morsing'morning
09:01.32Leedsquit your job to live off the proceeds of your rigged lottery tomorrow yet?
09:01.41morsingNot yet
09:01.53murboh  i asked about euro millions yesterdsy, nobody had ever heard of it.
09:01.59murband are the prizes tax free?
09:02.00Leedsare you allowed to play the euromillions?
09:02.07morsingLeeds: I'm not
09:02.20Leedsso you'll have to quit your job between rigging it and winning it, right?
09:02.22morsingmurb: Germany is not a part of Euromillions
09:02.30morsingDanes have never heard of it either
09:02.33murbmorsing: so why is it called *Euro* millions?
09:02.37morsingLeeds: Yes
09:02.48murbif it just works in uk ireland and a few other insignificant countires.
09:02.50morsingmurb: Because it a lottery for european countries
09:02.53murbmorsing: can you buy tickets on line?
09:02.59morsingNoone can *force* a country to join!
09:02.59murbmorsing: so why do they exclude countries?
09:03.05Leedsibot change 100000000 gbp to hkd
09:03.07morsingWe don't
09:03.11Leedsmorsing: how much is a ticket anyway?
09:03.15morsing1.50
09:03.20murbwell with a free market you'd think people would let you join.
09:03.29morsingmurb: It's 9 countries
09:03.32murbi mean sell them in any place.
09:03.38LeedsI assume you can pick your numbers or take a lucky dip?
09:03.44morsingLeeds: Yes
09:03.52Leedsthey are into their lotteries over here - nothing like as big as that though
09:03.58murbLeeds: i bet the lucky dip is rigged.
09:04.02morsingmurb: Of course you can buy online
09:04.04murbto make the rollovers bigger!
09:04.08murbmorsing: url?
09:04.14murband is the prize tax free?
09:04.15morsingwww.national-lottery.co.uk
09:04.20Leedscan *anyone* buy online?
09:04.27morsingmurb: Not in the UK
09:04.29Leedsresidency, location, etc.?
09:04.47morsingLeeds: To buy on our website you need a UK address and bank account
09:04.58Leedshmm... should I resell some tickets to people here? :-)
09:05.08morsingLeeds: Yes!
09:06.10murbmorsing: the website claims you must be in the uk.
09:06.34murbit would be a bit pointless if i won then camalot said fuck off you don't live here.
09:07.45Leedsditto
09:08.31murbsod it if i win 100m i will live in the uk.
09:08.38LeedsI wouldn't!
09:08.57LeedsI'd live on my own fucking island :-)
09:09.13murbLeeds: well for long enough to avoid paying tax anyway :-)
09:09.33Leedsjust buy an island here... HK$1.385billion should be enough
09:15.10Leedshmm... seems like maybe Hamas won the Palestinian elections
09:20.51morsingmurb: Well, yes. As I just mentioned
09:21.11morsingmurb: All they want is an address and a bank account
09:21.26murbmorsing: i guessing the requirements might be a bit tougher if you w in.
09:21.41morsingLeeds: How much would it cost to buy HK?
09:22.02murbmany many billions.
09:22.36murbor just become a colonial power and borrow it.
09:26.00Leedsfor a start, the government has US$124.3billion in the bank...
09:26.41Leedshttp://www.info.gov.hk/hkma/eng/statistics/index_efdhk.htm
09:29.04Leedsthe HK$ is 100% backed by the US$
09:57.08murbLeeds: gov.cn got all the gov.hk cash as a free gift?
10:01.19Leedsnope
10:03.03Leedsit's not spendable cash - it's the basis of the HK economy... plus, under the Anglo-Sino agreement, they can't touch it anyway
10:03.05LeedsAFAIK
10:08.26Leedshometime, I think...
10:08.33morsingNow?
10:08.56Leedsyes
10:09.11Leeds9 hours...
10:10.08Leedsa suggestion has been made that we should consume Australian-themed alcohol this evening, in honour of the national day of our neighbours a few thousand miles to the south
10:11.34murboh have you done a find / -type f -name \*.au -print0 | xargs -r0 cat >/dev/audio # yet?
10:11.42Leedsnope
10:16.12Leedshttp://www.timesonline.co.uk/newspaper/0,,171-961562,00.html
10:27.54*** join/#gllug mikejw (n=mikejw@84-51-159-23.michae611.adsl.metronet.co.uk)
10:53.47morsingmikejw!
10:53.54mikejwlo :)
11:14.50*** join/#gllug z00dax (n=z00dax@kbsingh.plus.com)
11:17.03morsingz00dax!
11:47.11z00daxmorsing, !
12:11.27*** join/#gllug gary_ (n=gary@host-84-9-87-61.bulldogdsl.com)
12:11.47gary_Good afternoon people
12:12.15z00daxgary_,
12:15.33gary_otherwise known as floo
12:33.11ErwinOh, how cool, I'm sure you all know "watch" but: watch -n1 -d free -- the -d will highlight changes between each update.
12:43.09*** join/#gllug Leeds (n=richardc@ipvpn095206.netvigator.com)
12:44.48rhoweErwin: Indeed it will
12:47.45Leedsrhowe: have you been here for CNY?
12:48.21rhoweLeeds: No.. I've been there around CNY time, but I don't think I was ever in HK for CNY itself
12:48.38rhoweLeeds: I've been there for [^C]NY
12:49.22LeedsI haven't done that - I was told it's relatively quiet
12:49.40Leedsalthough LKF was apparently stuffed
12:49.51rhoweYeah, we were in LKF and it was ridiculous
12:50.07rhoweA few years ago, several people died in LKF during new year because of the crush
12:50.28LeedsI thought that was Halloween
12:51.22rhoweoh, maybe I'm misremembering
12:51.43rhoweIt's been a couple of years :)
12:54.53Leedseither way, they put up crowd control now on really big nights
12:56.09Leedsnye 1992 apparently - I'm wrong
12:57.24rhoweaha
12:58.27Leedswhat's one of them?
13:00.36rhoweI need it to get a 3c509 (ISA!) card to netboot
13:00.54rhoweEither that, or I need to get a PROM programmer
13:01.02Leedsah
13:01.06rhoweFloppies are easier, albeit marginally
13:01.38LeedsI have 4 computers in this flat and a grand total of 0 floppy drives and 0 ISA slots :-)
13:02.46rhoweYeah, and I bet they're not missed, either :)
13:03.05rhoweI have about 5 floppy drives at home, although I should really stick them on ebay or freecycle
13:03.39Leedsonly in one way - my motherboard vendor for the one traditional ATX PC provide firmware as a bootable floppy image
13:06.39morsingANR2023E DEFINE SCRIPT: Extraneous parameter - node_name,.
13:07.29Leedsmmm... cauliflower cheese
13:07.35morsingMmm... Mushrooms
13:08.19Leedshttp://www.eyescoffee.com/vr/index.php - lkf tragedy
13:15.13rhoweI'll either be very relieved, or very upset in about 10mins
13:17.29Leedsoops
13:18.49morsingAre they any insurance companies where you can actually go and talk to an adviser?
13:19.13Leedsendsleigh
13:19.21morsingendsleigh?
13:20.03Leedsyes
13:22.55Leedswho, for reference, started as a commercial spin-off from the NUS, AFAIK
13:25.45Leedsmorsing: they have a branch on St. Albans Road in Watford
13:29.34boudiccasLeeds; you're right, and showing your age too :o)
13:30.01boudiccascome to think of it, by posting that, I'm showing my age too :o(
13:34.05*** join/#gllug eye69 (i=magnus@ipv6.upcore.net)
13:36.07*** join/#gllug z00dax (n=z00dax@kbsingh.plus.com)
13:38.03morsingLeeds: NUS?
13:38.08morsingLeeds: Are they good?
13:39.04murbmorsing: they certainly used to have a repuation for not paying out.
13:39.17morsingmurb: Were you a costumer?
13:39.44murbmorsing: i know people who had stuff stolen from halls due to the crap locks
13:39.52murband due to "no sign of forced entry" they refused to pay up.
13:41.18morsingmurb: Of course
13:43.47rhowepdr: *poke*
13:44.20rhowehm, no sign of my stuff in the bar
13:44.55rhoweanyone have pdr's number or email address?
13:45.35JAVafternoon!
13:51.04wethrin:-)
13:51.18wethrinz00dax: ping?
13:51.53murbmorsing: if they are the cheapest go with them..
13:52.02z00daxwethrin, fish ?
13:52.31morsingmurb: What kind of stupid reason is that? I want a place where I can go and talk to them. I'm tired of call centers and websites
13:52.34wethrinz00dax: herring
13:52.40wethrinWhat's the verdict on Brussels?
13:54.00SlayerXPwethrin: excellent when slightly crunchy and served with gravy
13:54.21wethrinSlayerXP: Still frozen? :)
13:54.38SlayerXPof ourse
13:54.43SlayerXPerr course
13:57.16SlayerXPmy mail reports are starting to look pretty ace
13:57.58SlayerXPdid you know that 50.91% of my mail traffic is encrypted from source to destination
13:58.42murbdid you know that opertunistic encryption is the source of 25.5% of the worlds evil?
13:58.57murbSlayerXP: how much of that was subject to MitM attacks?
13:59.24SlayerXPmurb: did you know that 85% of people can't spell "opportunistic" ?
14:00.06murbSlayerXP: i thought it was 87%?
14:00.34SlayerXPlots of amercians have snuffed it recently
14:01.43wethrinDid you know that 67% of statistics are made up? :)
14:03.52z00daxwethrin, staying with friend
14:08.28wethrinz00dax: Fine
14:09.08z00daxsince i had mentioned to him that i would be staying there, he has made arrangements - i think it would be a bit unfair to change now
14:09.20wethrinThat's fine. It'll be cheaper :)
14:09.43z00daxi am not sure about the cheaper bit :) - he aparenrly isnt all that close into town. ( dunno what cost of travel is like )
14:29.50Georgehiiiiiiiiiii
14:30.12wethrinYou're excited
14:39.15morsingI am
14:40.11*** join/#gllug Cope (n=sanelson@vm.wibbleworld.org.uk)
14:42.01Georgeoh deary me
14:42.09Copehello
14:42.16GeorgeCope: 580W was sufficient
14:42.30Copegood good
14:43.18morsingCope!
14:43.22Copehello morsing
14:43.35Copehrm
14:44.59Copeerm, why?
14:46.43Georgedunno
14:46.45Georgewhy not? :P
14:46.52Copefair point
14:50.41Georgehaha
15:04.07pdrrhowe: hey
15:04.42pdrrhowe: you took your camera and phone with you, i think you may have put them in your laptop bag
15:06.12morsingpdr: How are you?
15:07.33pdrhey morsing, i'm well, and you?
15:08.57rhowepdr: Shite
15:09.02rhowepdr: Well they didn't make it home with me
15:09.35morsingpdr: At work but otherwise ok
15:10.56pdrrhowe: schizerfuck
15:11.07pdrthat sucks
15:11.23rhowepdr: Yes, yes it does
15:11.40pdrthey're not in a jacket pocket or something?
15:11.49rhowenope
15:12.40pdrhave you tried ringing the phones?
15:14.15*** join/#gllug Catalyst (n=Catalyst@jamesmorse.plus.com)
15:14.54wethrinhello Catalyst
15:15.00AngelChildheyo
15:15.17angelchildlowercase is much prettier than uppercase
15:15.22wethrinmeh :)
15:15.24angelchildkinda more unixy, for some reason
15:16.33angelchildmy housemate's old phone ONLY DID UPPER CASE
15:16.49angelchildit was like he was shouting every time he sent a text message
15:16.52ErwinIf you login to a unix terminal in UPPER CASE with the username, it assumes your terminal can only handle upper case -- and prints everything as such
15:16.52angelchildwas vaguely amusing :)
15:17.29wethrinMy first phone did that
15:17.33morsingangelchild!
15:17.38angelchildmorsing!
15:17.44wethrinErwin: This is also troublesome if your password includes mixed-case characters
15:19.19ErwinAnyone using RHEL? u2pdate supposedly can read yum repositories; is there one for RHEL & AMD64 with useful extra packages?
15:23.36ErwinAh, yes, this seems to fit the bill -- http://dag.wieers.com/home-made/apt/
15:24.26rhowepdr: Damn, not handed into lost property either :(
15:27.41rhoweheya Steve
15:28.15Copewoo, hi rhowe
15:28.49CopeErwin: real rhel or centos?
15:29.17rhowepdr: Your createservices address bounces - I used mutt's 'bounce' feature to send the same message to your .cx address
15:31.49ErwinCope: RHEL 4.1. Yep, the dag repo looks good -- you need to turn off "retrieve source package" though, since it apparently doesn't have them.
15:32.56Erwinrhowe: You could try calling your phone number and see who answers
15:33.15*** join/#gllug IAmAI (i=hidden-u@83.222.114.3)
15:34.02IAmAIHello
15:34.24wethrinhi
15:34.32IAmAIHow is all?
15:35.58wethrinI'm waiting for an email
15:36.28IAmAILOL
15:37.04IAmAIDo you know, is a there a command that I can use to start desktop session.
15:37.18IAmAIIf that's what I mean :S
15:37.46IAmAII'm using CygwinX and PuTTY with x11 forwarding and I want to get my desktop :P
15:38.04IAmAII can get individual apps but I haven't worked out how to get a whole desktop, if it's possible.
15:38.25CopeIAmAI: startx?
15:38.38IAmAII think I've tried that.
15:38.55CopeIAmAI: assuming you have written (or have) a suitable .xinitrc file - or whatever YDOC uses
15:39.08IAmAIEr...
15:39.27angelchildyou can do startx remotely? I thought you could only do the full desktop thing through something like VNC
15:39.38angelchildthough I'm not very knowledgable on the subject
15:39.50IAmAIangelchild: To be honest, I've no idea. I'm just hoping one can :P
15:40.01CopeIAmAI: in my case, I run hummingbird exceed, use putty to ssh to my linux machine, with X11 forwarding enabled, and just run my window manager from the command line.
15:40.26Copeangelchild: I run 'full desktop' x server on windows
15:40.31IAmAIMy uni has Exceed. It's not free though, is it?
15:40.33wethrinAye - the window manager is Just Another X Application(TM)
15:40.55wethrinIAmAI: No, but it's better than Cygwin's X
15:41.00CopeIAmAI: no definitely not free beer or speech, but its very good.
15:41.13angelchildCope: fair enough :)
15:41.21IAmAIAlthough, I think I recall that my uni could give me a copy.
15:41.47angelchildI suppose it makes sense that the window manager is an X application in itself, I've never thought about it that way before
15:42.18angelchilddoes it emulate a separate X session for each window openned then? since I know you can run just the application by itself in an X session
15:42.42Copeangelchild: exceed is just an xserver - the same as x.org or whatever
15:42.49Copeeveryithing else is just a client
15:43.07pdrrhowe: ah, that explains it. i should have looked at the headers more carefully
15:43.11wethrinangelchild: What, the window manager?
15:43.13wethrinNo
15:43.15pdrrhowe: so did you try ringing the phones?
15:43.23wethrinYou can run multiple applications without a window manager
15:43.33wethrinHowever, you need the WM to do anything useful with them :)
15:43.48Copedoesn't matter where it is, or on what machine - its just a client that talks to the server; you don't need a window manager at all - you will just struggle to manipulate the apps if you don;t have one
15:44.08IAmAIOh dear. I tried 'sudo startx' and it crashed. I get timeouts when I try to reconnect :S
15:44.08wethrinSo just run a full-screen emacs session :)
15:44.10Copeangelchild: ie you can tile / cascade / move them around
15:44.48Copeangelchild: I just use ratpoison - which is basically screen for x-apps
15:46.40angelchildactually I was thinking about how the window manager itself works - remotely or not :) since X apps must redraw themselves and recieve events and such - presumably the window manager is like a shell in that respect? providing the input and output for multiple apps instead of a single app running in a single X session, which can't co-exist with others
15:47.24angelchildhow good is the X documentation? I may have a look around when I find the time, I think I just found a new interest :o
15:48.16morsingCheck it!
15:48.39IAmAIDoes anyone know if Cygwin can be used to allow SSH access to your Windows machine.
15:48.57wethrinyes
15:49.16IAmAII have the openssh package installed but I can't seem to connect with PuTTY
15:49.18wethrinangelchild: X is horrid
15:49.23wethrinHave you run sshd?
15:50.11IAmAIwethrin: No such command, assuming you're refering to me
15:50.15angelchildwethrin: most things are horrid. horrid and working's better than pretty and broken though :)
15:50.23angelchildwell, I think anyway
15:50.28angelchildI should stop talking in absolutes
15:50.32IAmAIOn my Linux machine, I just installed openssh and I could connect immediately
15:50.45Copeangelchild: I have never found good x docs, but never looked very hard, and never really wanted to
15:51.22Cope$colleague says there's a good book
15:51.32angelchildis it an o'reilly one?
15:51.41Copeunlikely
15:52.58wethrinIAmAI: Then you need to install the ssh-server package
15:53.37wethrinThe X protocol is rather horrid. Once you've torn your hair out, you'll end up buying a wig, just to tear its hair out too
15:53.49Copeangelchild: $colleague says if you read X documentation you'll read for weeks before you understand; the book he read is very  good.
15:53.57Copeangelchild: he's finding out the title / equivalent
15:54.44IAmAIwethrin: I cannot find such name package
15:54.50angelchildCope: cheers
15:55.24angelchild$colleague: cheers :)
15:55.56IAmAIBRB
15:56.14morsingwethrin?
15:58.21wethrinyes?
15:58.40morsingHow do I check if an email has been delivered in qmail?
15:59.13wethrinRead /var/log/maillog
15:59.13Copemorsing: phone the recipient?
15:59.30morsingwethrin: That log is not used
15:59.39wethrinI use it
15:59.43wethrinIt's going to log somewhere
15:59.45Copemorsing: come back when you use a decent MTA :)
16:00.35wethrin:)
16:00.48morsingwethrin: The logs are in /logs/qmail and have weird names
16:00.55wethrinOkay :)
16:01.16morsingwethrin: How come a msg id in the same log is reused for completely different messages?
16:01.24wethrinIs it?
16:01.50morsingYes. If I grep for an id it pops up 10-12 times for different deliveries!
16:01.59morsingQmail is beyond crap
16:02.23wethrinIt's not the same delivery?
16:02.28wethrinIt writes multiple lines
16:02.39morsingwethrin: No. They are completely different
16:02.46morsingIt even says:
16:02.52morsing@4000000043d8b50e10ae83f4 end msg 43619
16:02.52morsing@4000000043d8b6ce2ca33924 new msg 43619
16:03.02ErwinMaybe that's file size.
16:03.16morsingMaybe you're right :-)
16:04.12wethrinhmm
16:04.24morsingIf a mail was rejected or dropped would the recipient be in the log?
16:04.28wethrinNo, it's not the filesize
16:04.31wethrinI'd guess so
16:04.51Copemorsing: are you forced to use qmail?
16:05.32morsingCope: No, the guy who normally deals with Qmail is away today
16:05.51morsingCope: I've told them that it's crap but they know nothing about mail servers
16:06.12CopeI've never used it, so I'm only joking, although i've heard some horrid things about it.
16:06.25CopeI've only ever used sendmail, and it has always worked beautifully for me.
16:06.33wethrinI use qmail, and it WFM
16:06.47morsingibot WFM
16:06.48ibotwfm is probably (Wired For Management Baseline) This is an Intel hardware specification that is designed to allow for compliance with easier management of desktop PCs in a networked environment. The specification calls for computers to be compatible with a pre-boot protocol that can be used to update the system or perform other management options. Also, the ...
16:07.03wethrinWorks For Me
16:07.14morsingwethrin: So tell me how
16:07.38morsingThe Exchange guy says a mail has left exchange and was delivered to Qmail
16:07.49morsingNo trace of it that I can find on Qmail
16:07.53morsingWhat happened to it?
16:07.57morsingIAmAI!
16:07.59Copeexchange in lost mail shocker!
16:08.05Copestop the press!
16:08.06wethrinDo you know the from: or to: address?
16:08.12morsingwethrin: To
16:08.36wethrinThat doesn't turn up in the logs?
16:08.38wethrinOr it does too much?
16:08.49morsingIT doesn't
16:08.59morsingI can find to emails in the logs sent to him
16:09.07morsingBut not the one that's gone missing
16:09.11morsings/to/two/
16:09.16Copeby definition
16:10.13morsingwethrin?
16:10.24wethrinI don't know
16:10.28wethrinsorry
16:12.17*** join/#gllug stephen__ (i=stephen@windsor.org.uk)
16:16.05morsingstephen!
16:16.14stephenhey
16:20.57morsingstephen: Qmail sucks
16:21.42morsing:-)
16:21.44morsingMe too!
16:22.47IAmAII've found out how to install a ssh server on Windows :) http://pigtail.net/LRP/printsrv/cygwin-sshd.html
16:23.15Copewoo!
16:24.17morsingLeeds!
16:26.56Leedsmorning morsing
16:27.44ErwinYep. It's very handy, I do my software builds for Windows via ssh from my Linux workstation
16:28.29LeedsI have my ridiculous access->odbc->jdbc->jython->xml-rpc thing running on a windows box, and it's sometimes nice not to have to fire up vnc to talk to it
16:29.34IAmAII bet it's much more secure as well.
16:30.43Leedssure, but I'm happy as an armadillo
16:31.06pdrcrunchy on the outside, but soft in the middle?
16:31.16Leedsyup
16:31.24Leedsnot a Dime bar
16:31.33pdrhow's things?
16:32.00IAmAII don't if this is possible, but say I have two machines with an SSH server behind NAT, rather than put them on different ports, could I redirect to the appropriate machine by username?
16:32.03Leedsnot bad... I'm a little tipsy
16:32.20wethrinIAmAI: No
16:32.27LeedsIAmAI: not really, no - the username comes after the secure channel is established
16:33.05IAmAIWell, I suppose one can then ssh the other machine over the LAN at that point.
16:33.10morsinghttp://www.reghardware.co.uk/2006/01/26/kerala_trance_watch/
16:33.18pdryou could set the shell for one of the users to ssh to the other machine
16:33.33IAmAIYes, that came to mind
16:33.40pdrnot ideal though
16:33.44Leedsunless you're going to setup no-passphrase keys, that would mean another login
16:33.47IAmAIWhy not?
16:33.48pdrbetter not to use nat
16:34.01IAmAIWhat's wrong with NAT?
16:34.03pdrwhat's wrong with multiple ports?
16:34.20pdrNAT is a hack
16:34.30IAmAINothing, really, I suppose. One just has to remember the port numer and to remember to tell ssh to use a none standard port number.
16:34.40IAmAIWell, what's the alternative to NAt?
16:34.48Leedshmm... does the fact that they've announced the 2006 free software award mean they're not giving it at FOSDEM?
16:34.56LeedsPAT
16:35.01pdrreal IP addresses and normal routes
16:35.14wethrinLeeds: Not necessarily
16:35.21IAmAIWouldn't I have to buy additional IP addresses.
16:35.24wethrinpdr: And how many ISPs are likely to give you that? :)
16:35.29LeedsTridge won it, BTW, for those who care and don't know
16:35.36pdrmine gives me a /29
16:35.54IAmAII suppose one could set up a proxy server on one of the machines.
16:35.58morsingukfsn gives you /28 with a business account
16:35.59Leedsmine gives me a private-subnet /32
16:36.22pdrthis is a home "light usage" connection
16:36.27pdrwhois 81.2.75.97
16:36.51IAmAICouldn't some one invent 'port aliasing' or something?
16:36.55wethrinpdr: Who're you with?
16:36.58wethrinIAmAI: What's that?
16:36.59Leedsalternatively, go ipv6 - lots and lots of addresses to go around there
16:37.09LeedsIAmAI: you mean PAT? :-)
16:37.17IAmAIFor example, I could do 'www.example.com:ssh' instead of 'www.example.com:22'
16:37.31Leedsiana
16:37.47pdrwethrin: andrews and arnold
16:37.59pdri have a ipv6 /64 as well
16:38.01wethrinIAmAI: like you can run 'telnet www.example.com smtp', or 'telnet www.foo.com ssh'?
16:38.20wethrinpdr: Hm. Cunning
16:38.24IAmAIwethrin: How does that work?
16:38.32wethrincat /etc/services
16:38.35morsingCheck it!
16:38.39Leedsaren't A&A expensive?
16:38.53Leedsgood - but you pay for it
16:38.55pdra little on the expensive side yes, but not too bad
16:39.19rhoweoh ffs, the NIC was dead#
16:39.20IAmAIwethrin. I see
16:39.20pdrthey're all on irc and they're happy to give you their mobile numbers for tech support
16:39.28pdrso pretty good service
16:39.32rhoweOnly took me about a day's work to notice
16:40.09wethrinpdr: So're Blackcat
16:40.24Leedsrhowe: this is the one you were trying to load drivers for earlier?
16:40.30rhoweLeeds: Yeah
16:40.39Leedsrhowe: oops
16:40.52IAmAIwethrin: However, I assume it's the client that does resolving. If the server was using a non standard port for ssh, I assume they wouldn't work
16:41.00rhoweIAmAI: What you probably want is the zeroconf stuff.. stick a SRV record in _ssh._tcp.domain.com, although I don't think it allows you to specify a port to use, just a host to contact
16:41.07wethrinIAmAI: Correct
16:41.22wethrinrhowe: No - zeroconf assumes standard ports
16:41.50IAmAIMy idea is that one could do 'www.foo.com:ssh' and the server redirects to the apprioriate port depending on it's configuration.
16:42.15rhoweIAmAI: Pointless
16:42.32wethrinport translations would do that
16:42.32LeedsIAmAI: the problem is that it would have to ask the server on which port ssh was running - that's how sun-rpc works, with the portmapper
16:42.40IAmAIrhowe: Why? It means I don't need to know what port a service is on.
16:42.52rhoweIAmAI: You don't need to know anyway, with well-known port numbers
16:43.23IAmAIrhowe: It's not always possible to use standard port numbers
16:43.34Leedsrhowe: what's wrong with the portmapper?
16:43.51rhoweLeeds: It seems to be trying to solve a problem which doesn't need solving
16:44.38rhoweIAmAI: I don't think I've ever come across a situation where I couldn't use a standard port number for a non-private service
16:44.49rhowehm.. lots of negatives in that sentence
16:45.13IAmAIrhoew: I suppose for public services it's not a problem
16:45.48rhoweIAmAI: So, if it's not a public service, why do you want to make it automatically discoverable?
16:46.23IAmAIrhowe: The only reason is saving having to remember port numbers.
16:46.40rhoweIAmAI: Then use a well known port :)
16:47.03IAmAIrhowe: But that's not always possible!
16:47.18IAmAIAnd I can't remember all 'well known' port numbers!
16:47.32IAmAII can't remember my remote emule admin port
16:47.38rhoweYou don't need to - any sensible client will use the well-known port by default
16:48.00IAmAIrhowe: That's true.
16:48.21rhoweor give it a name in /etc/services (but you'd have to do this on every client box), you may be able to stick it in ssh_config on the client (need to do it on every client too, but /home may be shared via NFS for some of them), or use another well known port and refer to it by its name
16:48.25IAmAIAlthough, I'm sure there must be cases where you might want to run multiple instances of a service.
16:48.47IAmAIFor example, you're a game server hoster, and you run multiple servers of the same game.
16:49.09wethrinYes, and then the game is likely to try multiple ports
16:49.10rhoweIAmAI: Sure, although for that I would use different IP addresses if I could
16:49.51IAmAIrhowe: True. I expect if you can afford a server that will handle multiple games servers, you can afford a few IP addresses :P
16:50.05IAmAIrhowe: And master server lists include the IP anyway.
16:50.09rhoweIAmAI: What you could do is (say) run sshd on the POP3 port - you'll find most clients have an entry in /etc/services for that, so you could use -p pop3 (I expect) instead of -p 110. Perhaps the name is easier to remember than the number?
16:50.40IAmAII assume I can add stuff to /etc/services
16:50.49rhoweIAmAI: IP addresses are free, you just need to justify your need, and multiple servers is a reasonable need IMHO
16:51.00LeedsBad port 'pop3'
16:51.08IAmAIrhowe: Don't you have to buy them off your ISP
16:51.19IAmAIrhowe: My ISP charges £5 for a static one!
16:51.27rhoweLeeds: ah, so ssh doesn't use /etc/services
16:52.04rhoweIAmAI: Yeah, many providers do unfortunately charge for IP addresses, although I don't think they're supposed to (someone who knows more about internet procedures than I would be worth asking if you're curious)
16:52.14rhoweIAmAI: I pay a few quid a month for a /29
16:52.16stephenIAmAI: some ISPs charge, some don't, they're allowed to charge an "administration" fee for IP addresses under RIPE rules afaik
16:52.32IAmAI£5 seems a lot to me
16:52.57rhoweIAmAI: It is - I doubt it's much work for the ISP to manage a larger address pool
16:53.22rhoweIAmAI: What with always-on connections, I doubt using dynamic addresses even saves them much address space nowadays
16:53.23IAmAII can use dyndns.com thankfully
16:53.41IAmAIrhowe: I know. It's stupid
16:53.56IAmAIIt's there only to make money - it has an advantage so they charge for it.
16:54.15rhoweIAmAI: Really, everyone should be on a static IP address. It'd make the internet a much more accountable place if you could look up an IP address and see who to contact. Just getting the ISP's details isn't a solution, since ISPs can't usually be bothered to contact a user to say they have a virus
16:54.59IAmAINope
16:55.12rhoweIAmAI: Yes, it makes you an easy target for a DDoS, but I can't think it'd be that much harder to figure out what someone's address was if you had a close enough relationship with them to want to DDoS them in the first place
16:55.31angelchildrhowe: isn't that the intention of IPv6?
16:55.34rhoweIAmAI: It also makes you an easier target for a concerted hacking/cracking attempt, since the bad guys would always know where to find you
16:55.55IAmAIWould changing one's IP on request be possible/easy?
16:56.01rhoweangelchild: IPv6 has all sorts of intentions. Dynamic IP addresses (DHCP-style stuff) is part of the spec
16:56.28rhoweIAmAI: It should be, and it should also be possible to instruct your ISP to do upstream filtering..
16:56.46rhoweIAmAI: I bet some ISP's software makes changing the IP address of a customer a bitch to do though
16:56.58angelchildoh, okay :)
16:57.18rhoweIAmAI: That's just an administrative thing though, and if they needed to do it a lot, they'd make the process easier
16:57.31angelchildrhowe: I'd imagine it's something they don't expect to have to do
16:57.59rhoweIAmAI: I'm also of the belief that NAT is evil and should be used very rarely, but that's probably an even more extremist argument, and one to argue over another time :)
16:58.14rhowemmm, food
16:58.17angelchildmmm, chocolate
16:58.29angelchildcongratulations! :)
16:58.42rhoweIt's a big day
16:58.51IAmAII thought NAT was secure, but it only exposes you to what you set up?
16:58.59IAmAI-but +as
17:00.23rhoweIAmAI: From a security standpoint, NAT is a way to really simplify your firewall ruleset and apply a "block incoming data which wasn't a response to something someone here said" policy
17:01.17rhoweIAmAI: But it breaks so many things (I think to say that the protocol is broken because it doesn't cope with the packets being mangled in transit is wrong, although NAT certainly does expose some design flaws in protocols)
17:01.22Leedsugh, everything has gone grey
17:01.41Leedsand firefox has gone nuts
17:01.43rhoweIAmAI: NAT also provides a little anonymity (in the most common way it's set up)
17:02.02IAmAII've have no problems with NAT
17:02.34IAmAIWell, I don't expect NAT to provide any anonymity. Should I? I don't really understand what you mean by that.
17:02.44rhoweNo? Do you use Bittorrent, VoIP, file transfers on an IM program like ICQ?
17:03.03rhoweIAmAI: Well, the internet just sees data coming from the NAT box, and doesn't really know who sent it
17:03.12Leedszzzz *hic* g'night all
17:03.26rhowe<PROTECTED>
17:03.43IAmAIIt depends what you mean by 'who'. '165.6.21.45' doesn't really mean much, does it.
17:04.04IAmAIOne might be able to find out my ISP is bulldog broadband, but I guess that's about it, is it not?
17:04.12rhoweIAmAI: Well, think about (say) a room of computers being used at a uni by students
17:04.30rhoweIAmAI: If they're all behind a NAT box which NATs them to the same address, then you can't tell which computer initiated which connection
17:04.54IAmAISo isn't that a good thign?
17:04.56rhoweIAmAI: Well, you probably can, but it would probably require more work than simply looking at the IP headers.
17:05.37rhoweYes, it can be, but where you are anonymous, you can also easily be come unaccountable for your actions
17:05.51morsingCheck it!
17:06.04rhoweAnyone having problems with the traffic has to contact the NAT box owner, since they don't know whose traffic it is
17:06.18IAmAIrhowe: Well, isn't that even better if you want to get away with things? :P
17:06.57rhoweIAmAI: It's not a very good way to do it, really. An anonymising proxy you have some faith in would be a better way
17:07.38IAmAIFair enough.
17:07.40rhoweIAmAI: You might find (for example) that all your traffic is NATed to the same small port range on the NAT box, and is therefore identifiable as you, or that your IP datagrams have something distinguishing about them which allows people to tell them apart.. that kind of thing
17:07.52IAmAIBut if you're not trying to hide, it's not a problem, is it?
17:08.15rhoweIAmAI: Anonymity is a side effect of most NAT configurations, and as such, it doesn't necessarily do it well
17:08.31IAmAIFair enough.
17:08.48IAmAIBut I don't need anonymity, but that fact it's there doesn't matter to me either.
17:09.10rhoweI'd prefer to communicate more freely than be anonymous
17:09.21rhoweAt least, when it comes to IP traffic
17:09.37rhoweI could never go back to using NAT at home
17:10.06rhoweHaving 9 IP addresses to dole out really gives you so much more freedom and removes so many hacks put in place because of NAT
17:10.48rhoweNone of this "internal DNS" crap to hand out the internal address of the web server when local clients request www.$localdomain.com instead of the public address it's accessed by outside the company
17:10.56IAmAIWell, I wouldn't mind extra IP addresses. Can I go about acuiring them without cost?
17:11.11rhoweIAmAI: Ask your ISP. Probably not.
17:11.26rhoweIAmAI: They may require you to have a static IP address, too
17:11.26IAmAIWell then I must make do with NAT, and I feel no the worse.
17:11.34IAmAIOther than the face I have to remember my port numbers :P
17:11.37IAmAI*fact
17:12.01rhoweOh and bear in mind ssh will likely break horribly if you have multiple daemons listening on multiple ports (some forwarded to other machines)
17:12.18IAmAIWhy?
17:12.27rhowessh stores the host's public key in ~/.ssh/known_hosts and indexes it by IP address or hostname
17:12.48IAmAINot by port number?
17:12.55wethrinMmm. Chloroform
17:13.03wethrinNot by port number
17:13.03rhoweif you ssh to sshserver.foo.com:22 and then sshserver.foo.com:222, ssh will probably complain that sshserver.foo.com's identity has changed
17:13.04wethrin+s
17:13.06rhoweIAmAI: Nope
17:14.05rhoweIAmAI: You can get around this by either having multiple names in DNS and always remembering to use port <x> with name <y>, or if you only have two ports open, you could always remember to use port <x> with a hostname and port <y> with the IP address.
17:14.18morsingBeer
17:14.28rhoweIAmAI: Or, by using the same keys on all your SSH servers - that would probably do it
17:14.31morsingwethrin: Durham 3rd March!
17:15.20rhoweIAmAI: The basic problem is still there though - NAT is often deployed in situations where it causes more hassle than it solves.
17:16.07rhoweIAmAI: I'm not saying NAT's useless, btw, it has some very useful abilities when it comes to doing things like clustering several hosts to appear as though they were one, or for working around broken black box devices, etc
17:16.46rhoweAnyway, back to figuring out how I made this 8MB bootable kernel
17:16.55rhoweI think it has an initrd in there somewhere
17:17.19rhoweyes, yes we are
17:17.24rhowes/we are/it has/
17:17.34rhoweibot: WOW! Finally you got one right
17:17.45rhoweibot: thank you
17:17.45ibotrhowe: sure thing
17:17.53wethrinmorsing: What about it?
17:18.20angelchilds/about/cheese/
17:18.33angelchildoh, you can't change other people's :(
17:20.19rhoweNope, and it ignores things said as an action
17:20.53IAmAIrhowe: Another solution is a create another login on one of my machines, which automatically ssh's into the other upon login.
17:20.53rhoweYesterday I ate out
17:21.00morsingwethrin: Drinking beer
17:21.18rhowes/out/Jia out/
17:21.22rhoweFor example
17:21.29rhoweibot: lart ibot
17:22.02IAmAIibot: lart?
17:22.18morsingwethrin?
17:23.02*** part/#gllug morsing (n=morsing@emil.morsing.cc)
17:23.26IAmAIOh. Well see you guys.
17:23.31angelchildbai
17:23.43angelchildI really should learn english
17:23.59*** join/#gllug IAmAI (i=hidden-u@83.222.114.3)
17:24.09IAmAIWait, it isn't half past yet.
17:24.17angelchildwelcome back :)
17:25.00IAmAIHee hee LOL
17:25.05IAmAIShall I sneak out early? :P
17:25.31angelchildI have no idea, should you? :)
17:25.45angelchildhow rebellious
17:25.55IAmAIWell, I probably would need to sneak out.
17:35.41wethrinHrm. morsing's gone
18:38.15ErwinSo who here believes in "intelligent design" or knows anyone who does? Apparnety 40% Brits do, which sounds like an astounding number
18:39.33angelchildmy jury is out on the subject, since I've not been around to witness most of Earth's history and I don't believe we have enough evidence to conclusively say much at all
18:39.54ErwinThat's why I worship the Flying Spaghetti Monster.
18:40.03angelchildtouched by his noodly appendage
18:55.00*** join/#gllug zachary (n=zachary@ip68-99-100-38.hr.hr.cox.net)
18:55.48zacharyg'evening
18:56.56angelchildheya
18:57.44wethrinZACH!
18:57.52wethrinLong time no see!
18:58.07zacharyYa, been a little busy fixin the house.
18:59.27zacharywhen I say "fixing" I should be taken as updating the 1960's look. Had fun taking out wood paneling.
19:00.30zacharyDan, how's things over there?
19:01.09wethrinThey're not too bad
19:01.29zacharyDr. Dan yet?
19:01.33wethrinIn a rush at the moment, but will be back in a couple of hours if you'll still be around
19:01.38wethrinNah. Give me another couple of years still :)
19:01.48wethrinOtherwise I need to leave in about 4 mins. And finish eating :)
19:03.51zacharyok, shovel away! Good talking with you!
19:04.46wethrinyeah. Will you still be around later?
19:05.31zacharyDon't know. I need to pick my kids up at 4pm. By the time I get them to bed it might be a bit late.
19:05.58wethrinokay :) Talk to you soon, hopefully
19:24.22Copehmm?
19:24.55Copeoooh zachary
20:01.05Copehmm
20:01.08Copelack of activity
20:05.43angelchild<activity>
20:24.22Georgeradioactive activity?
20:24.36GeorgeA = A_0e^(-Lt)
20:24.37George:D
20:25.00CopeGeorge: you're learning perl?
20:25.43angelchildperl is great :D
20:26.46Georgeit's a real gem
20:27.04George/win 37
20:27.06Georgewoops.
21:07.32*** part/#gllug zachary (n=zachary@ip68-99-100-38.hr.hr.cox.net)
21:35.32wethrinhmm
22:08.49rhoweNow I just need to find my camera and the office 'phone
22:09.38wethrinhurrah
22:17.37Georgehuzzah
22:40.40rhoweMy camera :(
22:42.53wethrinIf it's any consolation, my camera's lost too
22:44.00rhoweMy camera's lost with a good few hundred photos
22:44.12rhoweand over 1 1/4 GB of storage :(
22:44.45wethrin:(
22:45.16rhoweYeah, it would really suck if it stays lost
22:47.12wethrinindeed
23:19.35Leedsrhowe: no more lunchtime beer!
23:33.03Leedsargh, it's going to rain over the long weekend :-(
23:53.40LeedsWarren Ellis is a deeply disturbed but very creative man
23:59.49Leedsibot change 2630 hkd to gbp

Generated by irclog2html.pl by Jeff Waugh - find it at freshmeat.net! Modified by Tim Riker to work with blootbot logs, split per channel, etc.