Warning: Constant ABSPATH already defined in /home/public/wp-config.php on line 27

Warning: Cannot modify header information - headers already sent by (output started at /home/public/wp-config.php:27) in /home/public/wp-includes/feed-rss2-comments.php on line 8
Comments on: Replacement Post https://whynow.dumka.us/2013/03/26/replacement-post/ On-line Opinion Magazine...OK, it's a blog Thu, 25 Apr 2013 05:55:39 +0000 hourly 1 https://wordpress.org/?v=6.4.3 By: Badtux https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62728 Thu, 25 Apr 2013 05:55:39 +0000 http://whynow.dumka.us/?p=28929#comment-62728 Well, you have to be on the inside of the firewall to exploit any of these passwords, and need to be in possession of a list of the other passwords to guess the firewall password (which isn’t one of the other passwords but follows the same pattern), so I’m not in too big a rush. I have to say that I’m quite disappointed in our IT consultant though, he’s been silent as a tomb since finding out that I guessed the password and did the firewall rule change without his help.

We signed up our first few customers and got a big deposit from a major storage company that already has been mentioned in this stream that wants to get into the security business and wants to leverage our expertise, so maybe this is going to work, especially once we get the Gen2 monitoring software out the door next week. I’m waiting for the library whose sole book is “My Pet Goat” to sign on, just so I can chortle that we’re monitoring the security network for a library whose sole book is “My Pet Goat” ;).

]]>
By: Bryan https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62727 Thu, 25 Apr 2013 03:37:41 +0000 http://whynow.dumka.us/?p=28929#comment-62727 In reply to Badtux.

So the good news is that you got in and were able to make the changes … OTOH the bad news was you were able to get in and make changes. I assume you intend to change the passwords on the machines in the infrastructure – when you get a chance, of course.

]]>
By: Badtux https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62716 Wed, 24 Apr 2013 23:15:24 +0000 http://whynow.dumka.us/?p=28929#comment-62716 Well, I guessed the password for the firewall/router based on other passwords for other machines in the infrastructure, so all is well :twisted:. He never did get back to me with that password, but that’s okay, I got in, disabled the dns packet inspection, and presto dnssec works right. Yay :).

]]>
By: Bryan https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62705 Wed, 24 Apr 2013 05:37:42 +0000 http://whynow.dumka.us/?p=28929#comment-62705 You guys get to do interesting things with interesting problems while I’m running around trying to locate stainless steel thrust head screws to fit the stems of Sterling bathtub faucets. The people who make the replacement handles don’t include the screws, advising you to reuse the old screws – the screws you had to drill out to get the original handles off so you could replace the leaky stems.

At least I now think I know the size and thread-count I need.

So, when you are commenting over here, you are playing hooky and avoiding your school work. That isn’t good, Kryten, no indeed. 😉

I worked with a couple of local non-profits reclaiming donated computer equipment for clients or their thrift shops, and passwords were always a problem. It usually meant re-formatting the hard drive or cannibalizing for parts because we couldn’t trace the equipment back to the original owner, or the owner forgot what it was. Having to get it from someone who sees a potential profit, is a hassle you don’t really need, Badtux.

]]>
By: Badtux https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62698 Wed, 24 Apr 2013 02:38:14 +0000 http://whynow.dumka.us/?p=28929#comment-62698 Kryten, I’m the guy who would be teaching those courses, if I was between jobs and needing something to do that is, otherwise I’m too busy living those courses :twisted:. Yah, I spent all day today getting Nagios to monitor some things on my new infrastructure, as well as cleaning up some database issues and running more tests of the application. I don’t think we’ll get it clean enough this week to release, but next week… could be.

Also found out that the old Cisco ASA router/firewall that we inherited eats dnssec packets(!). Which is a pain given that several of the root servers now only accept dnssec connections due to recent attacks upon the DNS system. Will get that fixed as soon as I get the password out of the person who installed it — or else it will get trashed and replaced by a generic Linux whitebox with a couple of four-port NIC cards if the dude tries to hold us hostage :twisted:.

]]>
By: Kryten42 https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62691 Tue, 23 Apr 2013 20:25:19 +0000 http://whynow.dumka.us/?p=28929#comment-62691 You know… Life is just weird sometimes. 😐

A friend who’s family use several devices (desktop PC’s, laptop’s, tablet’s smart-phones etc.) Has a big problem with central data storage and backup. So I was asked what I thought of these new online cloud backup systems popping up all over. “Not much” I thought… was told that they were looking at a product called carbonite (never heard of it thinks I) Aha, I say. I said I’d look into it and get back to them.

I found that Carbonite have a free 15 day trial, but it’s US only (and people say China is bad!) So, I connect my VPN to the server in Chicago, and sign up with one of my Gmail acct’s. No worries… S/W is d/l and installed. I set it up and let it run a backup in my sandbox with a dummy user acc’t with some junk txt, mp3, avi, pdf and a couple other data file types, about 500MB worth. So I decided to have a look around and see what else is available as I’m not that impressed with this Carbonite app! I found a few including one called CrashPlan. They have a 30 day trial (US only of course), so I sign up again and I get asked if I am a Carbonite user. Hmmm… thinks I. So I click on the ‘Yes’ button, and I am informed that I can get a 12 mth free unlimited subscription by providing my carbonite e-mail/login name (nothing else). Curiouser, etc. 😆

And low and behold, I now have a free, 12mth Unlimited Storage/backup plan!

and on paper, CrashPlan is way better! They have Linux/Solaris & Mac versions of their app, and better features. 🙂 Anyway, now I have a year to play! 😉 😆

It’s called “CrashPlan+ Family Unlimited Plan” (normally $150/yr). They claim 448-bit file encryption, the others claim either 128 or 256-bit (I plan to test that out of course). 🙂

http://www.crashplan.com/consumer/compare.html

Life is weird. *shrug*

]]>
By: Kryten42 https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62686 Tue, 23 Apr 2013 17:48:39 +0000 http://whynow.dumka.us/?p=28929#comment-62686 BTW, if you are interested, Sitepoint have a 50% off deal on all books & courses ($97). But it ends soon.

https://learnable.com/sitepoint

]]>
By: Kryten42 https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62685 Tue, 23 Apr 2013 17:43:00 +0000 http://whynow.dumka.us/?p=28929#comment-62685 LOL Yeah, I know. I used Nagios for the LM project a few years ago. I didn’t want to use it… But it is the best (open source) tool out there for my needs. 🙂 I really like the reporting features (and extensive monitoring of course, else pretty reports would be less than useless!) 😉 🙂

And yeah, MRTG is in my standard toolkit. 🙂

I’m using this course, it’s not bad. Came with PDF’s and a lot of examples! 🙂
LinuxCBT Monitoring Edition

(Also using the Sitepoint video/eBook course/guides).

This one is next:
LinuxCBT NIDS Edition

I’m tossing up whether to get the CentOS 6 course… I probably should. Last ver I used was 5.3. It’s changed quite a bit from playing with it the past week.

I also have the Exim course. That’s changed a lot too! *SIGH* Ahhh well… 😉

Who said starting a Biz was easy? 😆

Good luck to us all (again!) 😉 😀

]]>
By: Badtux https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62682 Tue, 23 Apr 2013 15:22:18 +0000 http://whynow.dumka.us/?p=28929#comment-62682 Oh you have my sympathies when it comes to Nagios, Kryten. The problem with Nagios is scale-out. Every single server and service that you add to the system requires yet another trip to the Nagios config files, and woe to thee if you haven’t been in there lately. Plus those inscrutable config files quickly grow to the size of a small novel for any reasonably sized network. I need to revisit Nagios for my new IT infrastructure (it’s currently only monitoring Engineering infrastructure because that’s where I implemented it at the old company).

BTW, writing new Nagios “sensors” is ridiculously easy, I wrote one that monitors the iSCSI targets on my iSCSI storage boxes (a bash script that just executes the storage CLI for each box and asks it for a list of targets and whether they’re still online and connected), as well as one that runs on the machines that have the initiators to check whether the initiators are still logged in (that’s touchier than you’d think with OpenIscsi, whose CLI was apparently written by someone who thought mdadm was too easy to use, LOL!). That flexibility the only reason I put up with Nagios, otherwise I’d use something much easier to configure.

I’m also using mrtg to monitor my switch ports, but at least it has a nice little script thingy that’ll generate config file snippets for you when you point it at a switch or server that has snmp enabled.

Dag nab it, now that you mentioned Nagios, I need to go finish implementing it for the new infrastructure. Curses! (Yes, the actual language I just used to myself was considerably more salty than that, little pitchers have big ears and my dad was ex-Navy 😉 ).

Ah, here’s a little Nagios sensor script, this one monitors an iSCSI link state on a proprietary storage box…

#!/bin/sh

PATH=/usr/kerberos/sbin:/usr/kerberos/bin:/usr/local/sbin:/usr/local/bin:/sbin:/bin:/usr/sbin:/usr/bin:/root/bin
LINK1=`echo “interface display” | /usr/bin/storage-cli -h storage1e | /bin/grep ‘^link1’ | /usr/bin/head -1`

# Now get status info:
HEALTH=`echo “$LINK1” | /bin/grep “Healthy”`

if [ “$HEALTH” = “” ] ; then
# Not healthy
echo “FAILED: NO LINK: $LINK1 $PATH”
exit 2
else
echo “SUCCESS: $LINK1”
exit 0
fi

]]>
By: Kryten42 https://whynow.dumka.us/2013/03/26/replacement-post/comment-page-2/#comment-62681 Tue, 23 Apr 2013 14:18:10 +0000 http://whynow.dumka.us/?p=28929#comment-62681 They couldn’t get away with it here. the Lib’s tried it and ended p in court so fast, everyone was amazed! We have very strong anti-discrimination & anti-competitive laws here, and the civil court’s take them very seriously. It’s actually one of the main reasons we got the GST (the ‘S’ for ‘Services” part). ‘Consultants’ were getting away with near murder (legally), now they have to pay the same 10% tax as everyone else. The deal was that the Gov was *supposed* to do away with the 21% sales tax, and the PAYE (payroll) tax… anyone who actually thought THAT was gonna happen was a blind moron!

The laws are curious in a way. It’s illegal, for example, to charge someone extra (a fine) for paying late or after a certain time (say 7 days), but it is legal to offer a discount if you pay early (like having payment terms of 14 days, with a 5% discount to pay within 7 days). That doesn’t mean people can get away with not paying debs of course. 🙂 We do have laws for that! 😀 It’s also why all prices here are always RRP (Recommended Retail Price) as fixing a price is also illegal (mainly because our Common Law Rights, which cannot be abrogated, allow for Barter Trade). Of course, the Corp’s with deep pockets can find ways around it, but it’s usually not worth the effort or cost as some have found, especially when the skate too close to the line and get slapped by the Courts. In a Civil Court, the prosecutor only has to prove *intent* (mens rea) to 51% if no agreement between parties can be reached and the Court has to decide. In a Criminal Court, it’s the old Common Law ‘beyond a reasonable doubt’, whatever that means! 😉 (Well, it usually means who is the best *story teller* at the closing arguments (as in the USA), and whether the defendant is known, and how much the juror likes/dislikes them. *shrug* It’s one of the problems with the Adversarial System as opposed to the European style Inquisitorial System.

OK. So much for my much needed coffee break, back to school! 😀 I’m currently studying Nagios & NRPE. It’s really come a long way! it can even monitor remote dB (MySQL, PostgreSQL, etc). That’s new, and with me offloading MySQL, that will be useful. 🙂

]]>