[00:36] *** nerdd_ has joined #arpnetworks [00:47] *** nerdd has quit IRC (Nick collision from services.) [00:47] *** nerdd_ is now known as nerdd [00:54] * sroute warms up good coffee in the microwave too. Trick is not to leave it sit on a burner for hours. I make it and turn it off right away... good for a cup or two reheated later in the morning [00:54] Not ideal, but I hate making a second pot in the am. [00:55] up_the_irons: got your message, thanks. [00:56] sroute: np! [02:01] *** schmir has joined #arpnetworks [02:17] if I change my password in the portal, will that also change my password for vnc and serial console? [03:37] *** ballen has quit IRC ("Leaving...") [04:04] *** dbgi has joined #arpnetworks [04:04] hi [04:06] *** schmir has quit IRC (Remote closed the connection) [05:44] *** baklava has joined #arpnetworks [06:16] *** vtoms has joined #arpnetworks [06:17] *** vtoms has quit IRC (Client Quit) [06:17] *** vtoms has joined #arpnetworks [06:49] *** ballen has joined #arpnetworks [06:49] *** ChanServ sets mode: +o ballen [07:14] *** ballen_ has joined #arpnetworks [07:14] *** ChanServ sets mode: +o ballen_ [07:22] *** DanielHolth has joined #arpnetworks [07:22] hello [07:34] *** ballen_ is now known as ballen|away [08:57] *** vtoms has quit IRC (Remote closed the connection) [09:39] *** vtoms has joined #arpnetworks [10:51] *** dbgi has quit IRC (Read error: 60 (Operation timed out)) [11:09] *** dbgi has joined #arpnetworks [11:49] firebug sucks [11:50] whats firebug [11:52] It's an HTML/CSS/JavaScript debugger for Firefox. [11:52] Since been copied for IE and Webkit. [11:52] ah [11:53] crashing too much? [12:00] na [12:00] i'm trying to understand how it's formatted in css [12:00] and firebug is being a weenie [12:00] i wish it would jus tell me, here. this is the code you need [12:02] What about developer tools for FF? "View Style Information" ctl shift y [12:02] click on the element in question... [12:03] you know what i'm not ? [12:03] a developer [12:03] sroute, if i could cut your brain and eat it and i'd learn to code [12:03] i'd do it right now [12:03] I hear that works with sroute . [12:03] Firebug also gives you inspect element [12:03] Firebug is pretty great. [12:05] ... and with inspect element you can see the style / inherited styles in a pane in firebug; much the same info as the other view I pointed you at. [12:05] Chrome inspect element is getting pretty good these days too [12:07] one plus Firefox and its tools gives you is the ability to edit html/css on the fly in a page, and preview it in the browser; to my knowledge Chrome doesn't do that. Somethings in chrome seem a little nicer. and memory usage is better too in chrome [12:07] for example, i have writing: [12:07] the next line, writing is longer.. so it's not formatting it properly [12:07] rather than aligning everything.. it makes it weird [12:17] magically, it worked [12:33] so this guy who set uip this code with a nasty framework.. i'm trying to pretty much make it with cheap p hp [12:33] when you type in a date, it automatically adds / [12:33] what should i be lookig [12:33] for [12:36] perhaps paste a snippet - use this one http://paste.pocoo.org/ [12:37] it's framework man i can't figure anything out [12:37] i think it's jquery [12:40] ui found it, some javascript stuff [12:41] *** DanielHolth has left "Ex-Chat" [13:06] *** vtoms has left [15:36] fun http://pastebin.com/m4e67ab92 [15:36] http://seclists.org/fulldisclosure/2009/Nov/371 [15:39] Heh, nice. [15:40] typical freebsd faggotry [15:55] freebsd rules [15:55] *** ballen|away has quit IRC ("Leaving...") [15:56] jesus [15:56] http://pastie.org/721083 [15:56] rooted my box in like 2 seconds [15:57] who was it [16:19] heh [16:19] freebsd rules [16:22] *** ballen has quit IRC (Read error: 113 (No route to host)) [16:33] i think so [16:37] oh shit [16:37] haha [16:38] guess i'm glad to be running openbsd [16:39] This exploit only works if they have access to your machine. [16:39] I'm fortunate not to have local users. [16:39] Although I still secure the machine as if I do... [16:39] must admit my local freebsd workstation is however a security mess. Time for a wipe one of these days. [16:40] yeah it's a local root [16:40] lol@ [16:40] `i don't have local users' [16:40] mike-burns: lots of people have local users though [16:40] ergo [16:40] yeah [16:40] `i'm not exploitable' [16:40] ^ [16:41] lol@all of you [16:42] Hey, whoa, I'm not saying I'm invincible. I'm just observing that this only works for local users. [16:43] mike-burns: and actually, every system has local users; tons of system users; even if they can't login, doesn't mean you can't use 'em. Wordpress + SQL injection could probably that code run as some user like "mysql", then escalate to root, then create a new user, that _may_ be able to login [16:43] learn how to read [16:43] 01:43.41 <@up_the_irons> mike-burns: and actually, every system has local users; [ ... ] [16:43] ^^^ [16:44] Yes, these systems are quite exploitable, I know. [16:44] But a local exploit is less of a "drop everything to fix this now" than a remote exploit, no? [16:44] I'm fortunate not to have "local human users" other than myself. ;-) [16:45] mike-burns: yeah, that's probably fair [16:45] remote root exploit has higher priority, definitely [16:45] uh [16:46] nice naivette [16:47] if we are going to be precise. Only one machine runs PHP for only one app. All other public apps are secure from sql injection; many apps use no sql whatsoever. XSS and other exploits also protected from. Ports locked down; no password logins; auto ban repeat offenders; keep up to date as possible; run portaudit nightly; subscribe to number of security mailing lists and feeds; and so on - no [16:48] naivette, I assume everyone out to get me. My own stupidity? Certainly no protection from that but I try. [16:48] didnt read that stop blogging [16:48] lol [16:49] I'd kick vxp but she is mildly amusing. [16:49] nice punctuation [16:50] *** feem has joined #arpnetworks [16:50] feem Hi [16:50] hello nc [16:50] underscore underscore [16:50] is that an important part of your name [16:50] unfortunately another user is in posession of the nickname 'nc' [16:50] also, someone else is using 'nc_' [16:51] my chat client forced the use of 'nc__' [17:25] Ah, that r00t just hit freebsd-security. [17:28] freebsd rules [17:30] why dont you [17:30] repeat that [17:30] another [17:30] 500 times [17:31] that's me in the corner. [17:43] is that you in the spot. light? [17:46] i'm losin' my religion [17:46] gross [17:47] arab isent a chik [18:08] *** ballen has joined #arpnetworks [18:08] *** ChanServ sets mode: +o ballen [18:14] *** ballen has quit IRC (Read error: 104 (Connection reset by peer)) [18:18] Subject: Recall: CoreSite-70 Innerbelt Emergency Maintenance Advisement [18:18] Man, these guys are so bad at e-mail. [18:23] coresite ? [18:23] in LA ? [18:23] Boston. [18:24] ahh [18:24] i got an offer for la [18:24] with one uplink though [18:25] what part of boston? [18:25] It's actually in Somerville. [18:25] oh nice [18:25] i live 5 minutes from Somerville [18:25] (70 Inner Belt Rd. Somerville) [18:26] Ah. [18:26] I didn't realize there were more Bostonians in here. [18:27] hehe [18:27] mike-burns and I live in Boston. [18:27] ah cool i didn't know mike-burns was in massachusetts [18:27] i only know one or two other people on irc who are from the boston area [18:29] maybe next time nc__ does a sad or smiley fac [18:29] e [18:29] you can go slap him [18:29] lol [18:29] i disabled that script [18:30] http://bash.org/?4281 [18:30] Except for real! [18:32] haha [18:42] http://ivoras.sharanet.org/blog/tree/2009-11-18.how-much-performance-do-you-lose-with-vmware.html -- interesting. [18:43] mhoran: you have stuff at CoreSite too? [18:43] and yeah, they suck at emails [18:43] i once complained.. was like, "why are you sending me a word doc? email doesn't work?" [18:43] Heh. [18:43] like srsly, why can't they put the maintenace advisement in the fucking email [18:43] instead they have to put it in a word doc attached to the email [18:43] Yeah, not impressed with their e-mail abilities, but their site is solid. [18:43] #fucktards [18:44] that's true, guess i should pick my battles... [18:44] I set my previous employer up with a cab there. I still have the master account, I guess, so I get all the spam. [18:44] cool [18:44] They had just purchased it I think when we moved in. [18:44] Was cool to watch it grow. [18:45] I think it used to be an Internap site, then Internap built a new facility next door, and has been slowly moving over. [18:45] They're pretty much the cheapest colo in Boston, plus the pay-for-what-you-use power is unheard of around here, so that's great. [18:46] Berklee is at Hosted Solutions, and they suck. They're primarily focused on their own "hosted solutions", so they don't really care about people who run their own networks. [18:47] It's obnoxious not being able to just walk into the DC. I have to sign in, sign out, and have them open our cab. Plus, their remote hands service has screwed stuff up for us pretty bad before. [18:47] Never used CoreSite remote hands. [18:48] up_the_irons: How have you found the Any2Exchange? I was hoping to get hooked up with that but it never worked out. [18:51] mhoran: yeah, metered power is awesome [18:51] mhoran: Any2 has worked out great so far [18:52] lots of peers for the LAX/SJC one [18:53] do you find it helps offload enough traffic to make it worthwhile? [18:55] I joked about bringing ours back online and peering with Youtube to offset our traffic to/from them. :-) [18:58] :-) [18:59] It's back! [19:02] blovett: i find it worth it, yeah [19:06] *** baklava has quit IRC (Read error: 104 (Connection reset by peer)) [20:57] *** heavysixer has quit IRC () [21:27] *** dbgi has quit IRC (Read error: 60 (Operation timed out)) [22:44] i want a 1 million square foot datacenter [22:44] who's in with me to do it [22:44] we'll build it out [23:07] sure. I need 10 square feet. 999,990 left to sell! [23:07] i'll take a 100 [23:08] 999,890 left to sell. [23:08] This is going to take awhile. [23:09] *** baklava has joined #arpnetworks