Well, my primary mail account remains spam-free (that is, outside of… - The Veritable TechNinja
The Veritable TechNinja

[Feb. 19th, 2003|12:43 am]
The Veritable TechNinja
Well, my primary mail account remains spam-free (that is, outside of undeliverable mail that some clod in Korea tried to slip through my SMTP server, which only ends up in my box because I'm root), but my secondary account on gothic.net is getting hit hard. You know it's too late when even the spam stops making sense. I'm getting what looks to be failed attempts to populate form letters with database values, complete with error codes. I've had that address since 97 I think, maybe earlier. It's sad, really. So I say this to you: if you run a mailserver, any mailserver, look in to RBL, and shut down any open relays you can. Do your bandwidth bill a favor.

[User Picture]From: recovry
2003-02-18 10:24 pm (UTC)
btw o' mighty Arcsine person, my household is debating the merits of broadband (uhm...faster?) vs. sticking with a second phoneline and paying about $45 a month either way. Any suggestions on what I should be looking at? Obviously, I need to find a cable modem that will work with AT&T broadband... anything else?

also, in the event that I can't get AT&T to host my webpage are there any suggestions you can make as far as hosting without pop-ups?
[User Picture]From: itszer0
2003-03-25 02:40 am (UTC)
hehe thats why you never get a by-the-byte connection ;P

trying to shuffle through email to find a message that had no meaning but random garbage, but i fail. its great though!
[User Picture]From: arcsine
2003-03-27 01:55 pm (UTC)
Holy shit, I just realized who you are. Our company just sent out a warning to the network security and rentacops about you guys.
[User Picture]From: itszer0
2003-03-30 03:18 pm (UTC)
whoami and who are thouse 'guys'?
[User Picture]From: arcsine
2003-03-31 08:18 am (UTC)
Durr... Guess. Take a look at your friends list. Where were you last weekend? While we're at it, what the hell did you do? I had _lots_ of fun fixing that one.
(Screened comment)
[User Picture]From: arcsine
2003-03-31 11:38 am (UTC)
Something like that, yeah.

Seriously, you thought I was going to tell you what wireless standard we use? For the part I work on, there's no wireless at all, yet still I had an assload of work to do this morning. Server hung, it's switch ports disabled due to repeated collisions, &c &c &c... None too pleased. Won't be happening again.

Glad you guys had fun.
[User Picture]From: itszer0
2003-03-31 12:43 pm (UTC)
hey, gotta try, right? i mean, if i really cared, i could find out.

and to be fair, i had no part of that, nor anything out side of the hotel at rubi-con... i wasent even there 99% of the time. nor with fellow hax0rs.
[User Picture]From: arcsine
2003-03-31 01:05 pm (UTC)
Trust me, it wouldn't be hard.

It may not have even been hacked, but I don't see why a collision would happen when they're on a switch. Something broke one way or the other.
[User Picture]From: itszer0
2003-03-31 02:53 pm (UTC)
ever seen an arp table over flow on a switch? *hint hint*
[User Picture]From: arcsine
2003-03-31 03:35 pm (UTC)
In the middle of the night, on a Sunday? There's no way the server clogged the buffer, there was nobody accessing it. Unless the backup utility magically began spouting network traffic, nothing normal could have caused enough traffic on the port to get high enough to overflow. I set it to full duplex after this, whether the net ops like it or not.
[User Picture]From: itszer0
2003-03-31 05:01 pm (UTC)
1) arp table has nothing to do with traffic, it has to do with flooding the CAM of the switch
2) sunday? every one was gone, i doubt it was totally RC-5 related
3) why half duplex? what does it matter? if your getting slammed by arp, it will fuck anyways, you dont even need 10BT HDX to fuck a cam.
[User Picture]From: arcsine
2003-03-31 05:19 pm (UTC)
1. I think we've established I don't have my CCNA yet. I'm a 2K Administrator, what did you expect? Second, why the hell would the CAM overrun with stored MACs?
2. Okay, then it was just the net ops being exraordinarily dumb. I'll be sure to blame them when it comes up.
3. It was set to half duplex because nobody bothered to up it last time I moved the servers. It's a stop-gap solution, but it'll do until I find out what the hell was hosing the port.
[User Picture]From: itszer0
2003-03-31 05:26 pm (UTC)
1) im 19 years old working at officemax for 12K/yr. :P
1a) The cam table is where it stores the macs, FYI, ok, so, now, most switches, if you overflow the cam tables, it will start not 'switching' and just pass packets like a hub, ie allowing collisions, and mailfourmed packets.
2) probably, most people there were not out for doing damage, but there are a few bad people in the croud, the hotel was owned before con started, the dumb crackers changed the password on there AP along with SSID, and crashed there network
3) Auto-sensing :P
[User Picture]From: arcsine
2003-03-31 05:42 pm (UTC)
1. What's holding you back from getting your CCNA and starting a nice white-hat career? I'm 22 and I've got a nice 460GB fiberchannel RAID array to play with. I started at 17 with one year at Staples making $6/hr, next job was network admin for my uni at $7/hr plus free room/board, then $12/hr helpdesk, then $13/hr Y2K upgrade tech, then $30k/yr helpdesk, now I'm a network administrator.
1a. I think I got that part down now. But what would feed it enough MACs to overflow?
2. Come on, there was a speech about "not getting caught", by a guy who once approached me in a coffehouse in Canton to yak at me about SunOS. I could honestly care less what happened to the hotel network, they were dumb enough to host a hacker con in a building with an unsecured wireless network and no engineer on-site to keep an eye on things.
3. No shit. It was enabled on the server... Just not the switch. I swear, network engineers these days...
[User Picture]From: itszer0
2003-04-01 02:28 am (UTC)
1.a) CCNA costs money. i dont have money.
b) i have toys, lots of toys, reason for A
1a) Spoofing MAC address's

---quick hack, made for wireless with changing essid+chan+mac, yeah, i know its not all in hex, this was a 2 second hack just to fuck with kismet/netstumblers at con --
while (0 == 0) {
$essid = int((rand)*999999999999);
$chan = int((rand)*10)+1;
$int1 = int((rand)*99);
$int2 = int((rand)*99);
$int3 = int((rand)*99);
$int4 = int((rand)*99);
$int5 = int((rand)*99);
$int6 = int((rand)*99);
$mac = "$int1:$int2:$int3:$int4:$int5:$int6";
printf ("Mac: $mac - Chan: $chan - ESSID: $essid\n");
`ifconfig eth0 hw ether $mac`;
`iwconfig eth0 channel $chan essid $essid`;

2) haha, darkcube yeah, hes quite a charecter.
3) yeah, your company should hire me while im cheap.
[User Picture]From: arcsine
2003-04-01 06:14 am (UTC)
The book's $50, the test is $125. There's a testing center right in Southfield. Considering the rate you absorb information, even if you didn't know what you know, you'd still blaze through the book and be ready for the test in a week. Besides, the only cert I hold is my paltry A+, I didn't even need it.

That's very uncool. "Just fucking around" with some hastily-written script made me run around for two hours desperately trying to have a job tomorrow.

Yeah, he was a real cut-up. Don't think he mentioned anything about being a former Sun security researcher, though.

My company hires helpdesk at about $10.75 an hour with no experience. Survive one year, they rotate you to deskside for $30k-$40k, then you either stagnate while you acquire certs or maybe get rotated to some managerial/developer role.
[User Picture]From: itszer0
2003-04-01 08:47 am (UTC)
thats $175 i don't have

...wait, are you saying you ran that script? heh... looking at it should tell you what it does... :P

Yeah, hes done *alot* of drugs.

Heh, and where should I apply? ill throw my resume over to them :P
From: meta_x
2003-06-19 05:16 pm (UTC)
