18 February 2014

09:21:17 <twitchyliquid64> MK_FG or anyone: whats good practice to detecting intrusions on a linux box? Anything like logfile monitoring or some kind of AV for linux servers? whats good practice?
09:24:47 <MK_FG> I certainly don't have a good one-liner answer, probably depends on when you want to detect it - attacks (successful or not), as it happens (and maybe have something act then too), or after the fact
09:25:03 <MK_FG> There are very different things for these three
10:20:47 monod (~pmpf@monod.users.cryto) has joined #crytocc
10:21:10 <monod> seems like eating and drinking is working O_O 35.5 this morning O_O
10:22:19 <MK_FG> Did you have a pain in the throat? Because if not, super-high fever might also be a food poisoning
10:22:50 <MK_FG> Though I think you wouldn't have been able to hold down much of a dinner in the latter case ;)
10:23:32 <monod> hehe
10:24:21 <monod> btw, I thought of a *little* food poisoning because I ate a little piece of chocolate that was not open by anyone until I did, last saturday I guess
10:24:37 <monod> but it was being stored for only 2 months, like
10:24:55 <monod> so I'm not quite sure of this indeed :hmm:
10:25:13 <monod> I can only feel little body-ache, but no head-ache atm ^^
10:25:36 <MK_FG> Well, it's also the morning ;)
10:25:45 <monod> uhm right
10:25:57 <monod> so let's wait
13:48:52 <iceTwy> wow
13:49:02 <iceTwy> Ars just started a series of articles about setting up your own mail server
13:49:12 <iceTwy>
13:49:18 <iceTwy> just /take a look/ at the number of comments
13:49:21 <iceTwy> 6 pages of 'em
13:49:49 <iceTwy> mostly people who don't have a single clue about email servers or have never even tried setting one up come and blame the author for trying
13:49:54 <iceTwy> like, seriously?
14:02:22 <MK_FG> .welcome_to_the_internet iceTwy
14:03:06 <iceTwy> haha MK_FG
14:04:17 <MK_FG> But I agree, most people arguing for not even trying seem to be wrong, and proven so in the long flamewar there by the other group ;)
14:06:13 <iceTwy> well, I know for a fact that setting up your own mail server is just fucking horrible
14:06:21 <iceTwy> it was the first thing I did when I got my first VPS
14:06:27 <MK_FG> I think ten years ago there could've been similar article titled "how to install your own open-source os with linux" and it'd have got a crapton of haters just like this one
14:06:48 <iceTwy> heh, probably, yes.
14:07:05 <iceTwy> it just seems that people are comfortable with current major mail services
14:08:05 <iceTwy> honestly I think that the trolls who're saying that setting up your own mail server does not protect you from threats you might face when using Gmail/others (i.e. account pass reset, undisclosed FBI/CIA/NSA request..) are plain stupid
14:08:31 <iceTwy> sure it's not like your own mail server is going to be secure against an adversary such as the NSA
14:08:49 <iceTwy> but at least you get to keep your data and you don't have to share it with Google or whatever
14:09:04 <iceTwy> that's still a major bonus and haters don't seem to realize that
14:12:42 <MK_FG> Yeah, probably
14:14:09 <MK_FG> Still not sure it's worth the effort to replace my gmail address everywhere it's used with a proper one
14:14:48 <iceTwy> yeah
14:15:14 <iceTwy> well I've got my own mail server, though I don't use it for important stuff
14:15:37 <MK_FG> Why not?
14:15:38 <iceTwy> even though my host is fantastic I can't be sure that it's not going to be up 24/7
14:15:43 <iceTwy> unlike, well, Google
14:15:51 <MK_FG> Have an mx on a second vps
14:15:57 <iceTwy> duh
14:16:09 <iceTwy> then bis repetitia
14:16:19 <iceTwy> problems could happen with the 2nd host too
14:16:20 <iceTwy> and a 3rd one
14:16:22 <iceTwy> and a 4th one
14:16:36 <MK_FG> Does it seem likely to you? ;)
14:16:47 <MK_FG> 4 hosts down at the same time
14:17:00 <MK_FG> With different providers
14:17:02 <iceTwy> totally
14:17:17 <iceTwy> :D
14:17:24 <MK_FG> Even so
14:17:37 <MK_FG> smtps will keep trying for a like 3 days, iirc
14:17:42 <iceTwy> well, my point is that I still don't fully trust my implementation
14:17:52 <MK_FG> So even with all 4 down, you get a lot of time to do anything
14:17:59 <iceTwy> I'll always reason in a "what if that happens" manner
14:17:59 <iceTwy> :P
14:18:15 <MK_FG> Yeah, and of course, google will never loose anything
14:18:27 <iceTwy> indeed
14:18:40 <MK_FG> I meant it sarcastically ;)
14:18:48 <iceTwy> well I didn't :P
14:18:55 <MK_FG> It looses my shit all the time via its "spam" folder
14:19:07 <iceTwy> ah, well, then check your Spam folder more often :P
14:19:29 <iceTwy> but seriously, Google is just reliable because of its infrastructure
14:19:45 <MK_FG> Like, you have a notification about payment bouncing that you really should pay attention to, and yep - gmail takes that particular one into spam, unlike all other msgs from the same place ;)
14:19:51 <iceTwy> I mean who the hell has 123034592459934 datacenters w/ bleeding-edge tech all around the world, besides Google
14:20:01 <MK_FG> It's still one SPOF
14:20:08 <iceTwy> yeah..
14:20:12 <MK_FG> Called google, it's not your datacenters
14:20:14 <iceTwy> though that's the risk with any spam filter around
14:20:38 <iceTwy> I'm using dspam on my mail server, and I'm currently training it. what tells me it won't, at some point, eat some of my mail
14:20:51 <MK_FG> It doesn't need to loose anything
14:20:52 <iceTwy> there's no 100% accurate spam detection software
14:21:08 <MK_FG> Just put anything it marks into "Spam" too, easy
14:21:11 <iceTwy> oh, are you talking about the fact that Google deletes spam after like 30 days?
14:21:22 <MK_FG> And with SPOF I meant a lot of failure scenarios google has
14:22:34 <iceTwy> yeah
14:22:50 <MK_FG> Don't think I caught it deleting something useful to me from Spam, just delaying it
14:23:07 <iceTwy> the ideal implementation if you're looking for reliability (not talking about matters such as spam) would be
14:23:10 <MK_FG> Should probably disable that thing one day, but then maybe disabling google is still easier ;)
14:23:39 <iceTwy> have a bunch of different VPS that will mirror your Gmail account (i.e. download mail from Gmail)
14:23:59 <MK_FG> Yeah, I use getmail to get into same proper account I have
14:23:59 <iceTwy> and then if Gmail happens to fail, one VPS should become the main mail server
14:24:24 <iceTwy> then again that would imply not having a address
14:25:15 <iceTwy> btw MK_FG, I surely DON'T want to have everything I receive in the same mail box
14:25:21 <iceTwy> :P
14:26:02 <MK_FG> Well, I just have long list of sieve rules to stuff it all into proper folders
14:26:20 <MK_FG> Oh, and crapton of aliases
14:26:52 <MK_FG> Like "reg.mozilla.WTsXC: me" for every registration on every site
14:27:22 <MK_FG> ("reg.mozilla.WTsXC: /dev/null" should they start spamming)
14:27:54 <MK_FG> So in a way, it seem to work as multiple mailboxes
14:28:11 <iceTwy> hm
14:28:17 <iceTwy> the only sieve rule I have is for dspam
14:28:47 <iceTwy> if it detects a dspam header that confirms the email is a spam, it redirects that mail to the Spam folder
14:29:10 <MK_FG> Mine is 370 lines and uses exec-filters (script with awk) to decide on where to put stuff! :P
14:29:12 <iceTwy> (i.e. X-DSPAM-Result: Spam)
14:29:19 <iceTwy> yes, but you're crazy
14:29:20 <iceTwy> :D
14:29:26 <MK_FG> Sure why not
14:29:40 <iceTwy> is it because you're Russian
14:29:42 <iceTwy> IS IT?!?
14:30:22 <MK_FG> spam "rule" -
14:30:44 <iceTwy> I fear the worst
14:31:00 <iceTwy> oh, right
14:33:19 <iceTwy> btw MK_FG, don't you love backups?
14:33:31 <MK_FG> Probably
14:33:53 <iceTwy> rightio
14:34:03 <iceTwy> What's a simple way to do a regular backup of my VPS's?
14:34:11 <MK_FG> rsync --link-dest
14:34:15 <iceTwy> I'm not exactly sure what I'd want to backup yet, but yeah, generally
14:34:23 <iceTwy> rsync then
14:34:25 <iceTwy> okay
14:34:37 <MK_FG> But of / with a list of exclusions
14:34:46 <iceTwy> I need to really dig into that because I seriously need to start doing backups
14:34:51 <MK_FG> Not whitelist-based
14:36:05 <MK_FG> "Not whitelist-based" because "rsync of everything except ..." fails on the safe side, can't probably stress this enough
20:02:56 monod (~pmpf@monod.users.cryto) has joined #crytocc
20:03:24 <monod> first day with no flu! :D
20:03:36 <monod> I'll only have to check before bed
20:03:45 <monod> and then it will be aaaaall day
20:03:46 <monod> yay
20:04:07 * monod back lurking on his computer
20:48:03 <MK_FG> Don't think one can recover from flu in a day or two ;)
20:55:12 <iceTwy> armahgard
20:55:27 <iceTwy> this imgur thing is starting to get on my nerves
20:55:28 <iceTwy> a bit
21:16:25 monod (~pmpf@monod.users.cryto) has joined #crytocc
21:54:09 <iceTwy> suuuuuuuuuuch joepie91
22:51:24 <monod> gotta go sleep! =_=
23:07:08 <joepie91> anything important?
23:07:10 * joepie91 pops in for a sec
23:07:29 <joepie91> iceTwy: duplicity
23:07:48 <joepie91> which uses rsync, gpg and some other stuff behind the scenes
23:07:52 <joepie91> but lets you restore to arbitrary points in time
23:16:03 <joepie91> so here are the stats of the languages used for the pastes in my pastebin archive
23:16:04 <joepie91>
23:16:08 <joepie91> it only took, what, 6 days to calculate?
23:16:08 <joepie91> lol
23:44:27 <iceTwy> I'm being genuinely trolled by YouTube's API
23:44:31 <iceTwy> lol
23:44:53 <iceTwy> OHHHHHhh
23:44:55 <iceTwy> RIGHT
23:45:04 <iceTwy> ...
23:45:07 * iceTwy facepalms
23:45:12 <joepie91> iceTwy: ohai
23:45:20 <joepie91> not terribly impressed with pyimgur docs
23:45:23 <joepie91> or its error reporting, for that matter
23:45:28 <iceTwy> pyimgur?
23:45:30 <iceTwy> I'm not using it at all
23:45:35 <joepie91> raise Exception("blah")
23:45:35 <joepie91> like, wat
23:45:47 <joepie91> I am :)
23:46:05 <iceTwy> okay so, I just understood why the YouTube API was shitting on me
23:46:16 <iceTwy> the API url begins w/ www.
23:46:19 <iceTwy> ...
23:46:23 <iceTwy> Google, we're in fucking 2014