IRC log for #gllug on 20110413

00:02.47lagnushello?
00:03.00lagnusliving?
02:50.47*** join/#gllug Leeds (~richardc@www.scorefive.com)
05:23.24*** join/#gllug PcSett (~Don@host86-162-31-32.range86-162.btcentralplus.com)
05:25.09*** part/#gllug PcSett (~Don@host86-162-31-32.range86-162.btcentralplus.com)
05:57.37Copedying
06:31.30AndyMillartoo much hooch?
07:06.38Copenever hooches... just fails to be funny
07:07.04Copeoooh
07:07.17Copebreakfast time in the canteen! yummy food and hott ladies!
07:07.21Copedashes
07:10.56AndyMillar:p
07:18.38*** join/#gllug ChoHag (~mking@109-170-148-201.xdsl.murphx.net)
07:23.13*** join/#gllug alexaj (~alexaj@81-178-209-1.dsl.pipex.com)
07:38.32morsingalexaj!
07:38.49haliargh, we have two new spanish guys in the office... hearing them speak does my head in
07:39.18haliit's about 50% english with a very rough spanish accent and 50% turbo spanish
07:39.35morsingHeadphones
07:39.42haligood idea
07:39.51halitime for some run to the hills
07:44.49alexajmorsing !
07:46.21morsingIn Debian -> interfaces file, how do I set-up multiple addresses per interface without getting interface aliases? Can I just do multiple 'address' statements per 'iface'?
07:46.59morsingIt seems rather un-documented
07:50.48ChoHag<Pimp> The client can pay up to £350.
07:50.54ChoHag<Job spec> Initially the budget goes up to £400
08:00.51*** join/#gllug alexaj (~alexaj@81-178-209-1.dsl.pipex.com)
08:06.52morsingalexaj!
08:08.25*** join/#gllug gmarkall (~graham@84.45.235.192)
08:09.54ChoHagYes, xfce, I did actually want the panel vertically through the middle of the screen.
08:15.00*** join/#gllug stu_ (~stu@dyn1242-128.vpn.ic.ac.uk)
08:22.38morsingstu_!
08:22.40morsinggmarkall!
08:38.20gmarkallmorsing! stu_!
09:05.37*** join/#gllug Nafallo (~nafallo@ubuntu/member/nafallo)
09:15.21morsingNafallo!
10:44.26morsingI can't find any evidence or documentation that getaddrinfo() on Linux should pick IPv6 over IPv4. Is this the case? Things seem to always go the Ipv6 route but would like to verify it's by design and not luck...
10:56.51AzundrisUse the source?
10:58.24antiphaseCAI
11:00.15antiphasehttp://www.rfc-editor.org/rfc/rfc3484.txt
11:00.20antiphaseUSe the RFCs, Luke
11:01.53antiphaseI meant GAI of course. Typing phail
11:02.18antiphaseman 5 gai.conf
11:02.37antiphaseI'm not sure why I'm helping someone who couldn't use Google to get them out of a wet paper bag
11:03.45AzundrisWhy would you need Google to get out of a wet paper bag?
11:19.06Copeis hot
11:33.27morsingshags Cope
11:35.22AndyMillar:op
11:37.38*** join/#gllug gmarkall (~graham@84.45.235.192)
11:39.18morsinggmarkall!
11:42.49Copehands morsing KY
11:42.55Copeplease be more gentle
11:59.43*** join/#gllug dick_turpin (~sales@host217-34-163-30.in-addr.btopenworld.com)
12:18.22*** join/#gllug dick_tur1in (~sales@host217-34-163-30.in-addr.btopenworld.com)
14:19.46*** join/#gllug Leeds (~richardc@pcd417142.netvigator.com)
14:40.55morsingLeeds!
14:50.06*** join/#gllug PcSett (~Don@host86-162-31-32.range86-162.btcentralplus.com)
14:51.01*** part/#gllug PcSett (~Don@host86-162-31-32.range86-162.btcentralplus.com)
15:29.41ArsonaLmorsing!
15:29.46morsingArsonaL!!!!!!!!!!!
15:29.57ArsonaLthat was fast
15:30.00*** join/#gllug sabinef72 (~sabinef72@sabinef72.ipv6.popipo.fr)
15:30.03morsingsabinef72:!
15:30.11ArsonaLdo you have a pc speaker beep when someone says your name?
15:30.36morsingNo
15:30.49ArsonaLI do :$
15:31.03morsingI've never been able to get it to work :(
15:33.29ArsonaLhaha, I just sent my tax stuff back to Canada
15:33.33ArsonaLthis was the reply:
15:33.41ArsonaL(16:31:52) Robert: u sure pay a lot of tax
15:36.04morsingArsonaL: ...?
15:39.54*** join/#gllug zooz (~zooz@host86-161-205-103.range86-161.btcentralplus.com)
15:51.15morsingzooz!
15:57.27ArsonaLI was referncing that the tax here in the UK is substantially higher than Canada
15:57.59morsingOk - would be fun to tell the guy that tax in the UK is substantially lower than the rest of western Europe...
15:58.09morsingWould give him a heart attack ;)
16:05.03*** join/#gllug sabinef72 (~sabinef72@ns.popipo.fr)
16:10.04murbArsonaL: hmm canada has a higher margianl rate of tax if you run a company.
16:10.48zoozare here any iptables gurus?
16:10.59zoozgot stuck understanding how iptables increases counters
16:11.26ChoHaghttp://www.youtube.com/watch?v=TywmpMQYojs
16:11.29antiphaseState your question, peon
16:11.33ChoHagThe Assumption Song
16:13.19zoozright :-)
16:13.21zoozhttp://p.defau.lt/?ObvzGn7iYVzxa_j9OVvrUw
16:14.00zooz<PROTECTED>
16:14.15zoozwhile they are only increasing in Chain SYN_ACCEPT if I initiate a connection to 22/tcp
16:15.00antiphasewonders why you're doing it in the first place
16:15.19zoozto save lots of typing ?
16:16.22antiphaseThe best way to save lots of typing is to ACCEPT all packets which are in state ESTABLISHED or RELATED then assume all the rest are connection attempts
16:16.39zoozsure, that's what I do
16:16.53antiphaseSo why do you check twice if they're new connections as well?
16:17.07zoozwhat do you mean?
16:17.28zooz-m state --state NEW is not the same as -m state --state NEW -p tcp --syn
16:17.41antiphase--state NEW and --syn are equivalent if I'm not mistaken, and if you accept established/related connections, you can assume all other packets are connection attempts without testing them
16:17.55zoozno, you are wrong re NEW
16:18.14antiphaseYou obviously know more than me then
16:18.41zoozstate NEW matches new connections attempts even if packets arrive with SYN flag unset and e.g. ACK set
16:18.57zoozwhich is obviously not a new connection attempt
16:19.06antiphase--state INVALID -j DROP
16:19.08antiphaseJob done
16:19.15antiphaseguesses
16:19.18zooznope
16:19.22antiphaseWhat are you trying to do then?
16:19.25zoozINVALID does not match the above
16:19.41zoozINVALID does not match new connections with ACK flag set on
16:19.54antiphaseNeither does the TCP stack
16:20.02antiphaseaccept them
16:20.21zoozsure, but why would you let them through?
16:20.40antiphaseI don't. I probably generate RSTs in response to them
16:20.53antiphaseKeeps people guessing
16:21.07antiphaseIf you're that paranoid, you should odrop everything and permit only from known sources
16:21.19zoozyeah, that generates much more unnecessary traffic
16:21.37zoozthat's what I do pretty much
16:21.59zoozbut my question was why the counters are increasing in INPUT chain target SYN_ACCEPT?
16:23.24antiphaseBecause it matches all inbound port 22 traffic to that interface and address
16:23.58antiphasetoo tired today so will be quiet
16:24.59zoozright
16:25.09antiphaseAll traffic will generate hits on the INPUT rule, and all new connection attempts will generate hits on the SYN_ACCEPT rule and then be accepted by default
16:25.34antiphases/All/All TCP\/22/
16:25.36zoozI moved the rule which accepts ESTABLISHED,RELATED to the top and now SYN_ACCEPT target in INPUT does not get increased
16:26.09zoozit only does if I actually generate a new 22/tcp connection to that IP address
18:09.01*** join/#gllug Mohan (~nixh0st@unaffiliated/mohan)
19:09.11*** join/#gllug lagnus (~lagnus@88-96-64-203.dsl.zen.co.uk)
19:40.39*** join/#gllug ___marcus (~marcus@lenny.uk-debtcollection.com)
20:29.24*** join/#gllug lagnus (~lagnus@88-96-64-205.dsl.zen.co.uk)
21:57.50*** join/#gllug s___marcu (~marcus@lenny.uk-debtcollection.com)
22:41.24*** join/#gllug zooz (~zooz@host86-161-202-225.range86-161.btcentralplus.com)

Generated by irclog2html.pl Modified by Tim Riker to work with infobot.