Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Post
  • Reply
Into The Mild
Mar 4, 2003





I recieved a old-ish laptop from my sister, who was going to throw it away because it was "broken" I ended fixing the battery problem and scored a new laptop.


So I installed Kubuntu KDE4, then quickly went to KDE3... then decided to just try Ubuntu.. and man I'm seriously impressed with Gnome now

The problem is that laptop uses a 855GM graphics chipset and man does the ubuntu copy of the intel driver suck, freezes most times i sleep the laptop, and when starting a video it will crash probably 20% of the time.. just a blank screen, and the cpu fan goes crazy.

I looked into it, and it turns out theres a few people on the ubuntu forums complaining about the intel driver for X with the same problems as me, random blank screen crashes, cpu gets maxed out and you have to hard shut it down.

It's a shame really.

Adbot
ADBOT LOVES YOU

covener
Jan 10, 2004

You know, for kids!

Mr Man posted:

The problem is that laptop uses a 855GM graphics chipset and man does the ubuntu copy of the intel driver suck, freezes most times i sleep the laptop, and when starting a video it will crash probably 20% of the time.. just a blank screen, and the cpu fan goes crazy.

try the vesa driver? I sometimes use it on my flaky ATI video card.

Prince John
Jun 20, 2006

Oh, poppycock! Female bandits?

Alowishus posted:

I'd add DenyHosts to the equation.

Just seconding denyhosts, easy to use and does the job exactly as advertised.

As a slight aside, has anyone else found that browsing a remote folder through ssh via nautilus, telling nautilus to remember the password for 'this time only' (or similar, the shortest length of time) and then browsing to another folder produces a ton of incorrect password attempts in the ssh logs?

It let the browsing/copying proceed fine, but then when I tried to log back in at a later date, denyhosts had locked me out due to all the failed password attempts.

Beve Stuscemi
Jun 6, 2001




Thanks for the help guys! I denied root logins, changed the port to something completely non-standard, only allow SSH2, turned the number of sessions way down, and installed DenyHosts.

DenyHosts already sent me an email that it denied someone.

Megaman
May 8, 2004
I didn't read the thread BUT...

Phat_Albert posted:

Thanks for the help guys! I denied root logins, changed the port to something completely non-standard, only allow SSH2, turned the number of sessions way down, and installed DenyHosts.

DenyHosts already sent me an email that it denied someone.

Did you set authentication option AllowUsers to allow only you and a few certain others?

Personally I believe these are the most important entries in sshd_config

Port 30000
Protocol 2
AllowUsers [users]
LoginGraceTime 15
PermitRootLogin no
StrictModes yes
MaxAuthTries 0
PermitEmptyPasswords no

This will pretty much keep out anyone and stop most bots.

Into The Mild
Mar 4, 2003





covener posted:

try the vesa driver? I sometimes use it on my flaky ATI video card.

Well I ended up doing something on a hunch. I ended up downloading the full dvd version of ubuntu rather than the desktop version, and guess what.. the sleep issue seems to have fixed itself.


ALTHOUGH

it shits itself when watching video's, which is ok since inbeded flash videos work fine (albeit slow)

AND

Sometimes when im shutting it down or logging off (terminating the x session basically) it crashes.

I might edit xorg.conf and add in Driver "VESA"

other people
Jun 27, 2004
Associate Christ
Can some one inform me on how to safely and securely use NFS shares over a wireless network? I know NFS doesn't really have any built-in security. I have WPA2 on my wireless network, but is there a simple way to tunnel things through SSH or use a VPN?

The network has both linux and OS X computers on it, so a solution has to be compatible with both.

What is required to run a VPN? Do you need some special software running on a server, and then client software for each computer?

SynVisions
Jun 29, 2003

Kaluza-Klein posted:

Can some one inform me on how to safely and securely use NFS shares over a wireless network? I know NFS doesn't really have any built-in security. I have WPA2 on my wireless network, but is there a simple way to tunnel things through SSH or use a VPN?

The network has both linux and OS X computers on it, so a solution has to be compatible with both.

What is required to run a VPN? Do you need some special software running on a server, and then client software for each computer?

Found this on google, NFS through SSH: http://www.linuxsecurity.com/content/view/117705/171/

OpenVPN also has excellent documentation on setting up a VPN: http://openvpn.net/index.php/documentation/howto.html

Mr. Eric Praline
Aug 13, 2004
I didn't like the others, they were all too flat.

Kaluza-Klein posted:

Can some one inform me on how to safely and securely use NFS shares over a wireless network? I know NFS doesn't really have any built-in security. I have WPA2 on my wireless network, but is there a simple way to tunnel things through SSH or use a VPN?

The network has both linux and OS X computers on it, so a solution has to be compatible with both.

What is required to run a VPN? Do you need some special software running on a server, and then client software for each computer?
Actually, NFSv4 is a pretty significant improvement on security. If you set up a kerberos master as well, then you get a ticketed authentication, and can encrypt all the traffic.

It's pretty easy to do, but kerberos can be a bit of a steep learning curve.

other people
Jun 27, 2004
Associate Christ
http://gentoo-wiki.com/HOWTO_OpenVPN_Server_for_Ethernet_Bridging_with_Server_Certificates

That is the guide I am trying to follow to setup the server.

It fails at trying to bring up tap0.

code:
depend_br0() {
   need net.tap0 net.eth0
}

tuntap_tap0="tap"
config_eth0=( "null" )
[b]config_tap0=( "0.0.0.0 promisc" )[/b]
bridge_br0="eth0 tap0"
# or dynamically add them when the interface comes up
#bridge_add_eth0="br0"
config_br0=( "10.20.30.3" )
What is "promisc" refering to? I get an error "nothing provides `promisc'".

uncleTomOfFinland
May 25, 2008

Kaluza-Klein posted:

What is "promisc" refering to?

Probably this:
http://en.wikipedia.org/wiki/Promiscuous_mode

other people
Jun 27, 2004
Associate Christ
Things are going a bit better now. I had to add the bridge module to my kernel.

I have Tunnelblick installed on my mac, and it seems to be happy enough to connect to the vpn server. But uh, how do I know it is "working", so to speak?

SynVisions
Jun 29, 2003

Kaluza-Klein posted:

Things are going a bit better now. I had to add the bridge module to my kernel.

I have Tunnelblick installed on my mac, and it seems to be happy enough to connect to the vpn server. But uh, how do I know it is "working", so to speak?

Just ping the IP that your server has on it's VPN interface from your mac. If all is good mount your NFS share via that IP.

ExileStrife
Sep 12, 2004

Happy birthday to you!
Happy birthday to you!
Some lightweight utility (or other way) to track the amount of bandwidth used. SMTP+MRTG is already running on this server, but I am currently not getting counts of bandwidth used, just a rate counter (I figure the solution is pretty close already). I'd like something that could break it down by month automatically too.

deong
Jun 13, 2001

I'll see you in heck!

ExileStrife posted:

Some lightweight utility (or other way) to track the amount of bandwidth used. SMTP+MRTG is already running on this server, but I am currently not getting counts of bandwidth used, just a rate counter (I figure the solution is pretty close already). I'd like something that could break it down by month automatically too.

What about ipacsum? I use it on my router (IpCop) and it seems to give a decent breakdown.

code:
# ipacsum -t "last month"
IP accounting summary
Host: host.host / Time created: 2008/08/11 09:03:54 GMT-7
Data from 2008/07/01 00:00:00 GMT-7 to 2008/07/31 23:59:59 GMT-7
  forwarded incoming GREEN (eth0)                 :             13G
  forwarded incoming RED (eth1)                   :             22G
  forwarded outgoing GREEN (eth0)                 :             23G
  forwarded outgoing RED (eth1)                   :             13G
  incoming GREEN (eth0)                           :            257M
  incoming RED (eth1)                             :              5G
  outgoing GREEN (eth0)                           :              6G
  outgoing RED (eth1)                             :            212M

SynVisions
Jun 29, 2003

vnStat is another well known utility for that.

ExileStrife
Sep 12, 2004

Happy birthday to you!
Happy birthday to you!
Oh boy, both of these give me just what I'm looking for, thanks! (I went with vnStat and it's rocking out)

UNCUT PHILISTINE
Jul 27, 2006

Stupid question, and I'm probably going to make this confusing but...-

How do I run a script from crontab, and have the dir the script is in be the default dir?

For example, I have /home/me/.rss2email with the python script "r2e" in that dir. The dir contains other scripts required by "r2e", so when I add "/home/me/.rss2email/r2e run" I want it to not say "otherscript.py not found".

JoeNotCharles
Mar 3, 2005

Yet beyond each tree there are only more trees.

Without Pants posted:

Stupid question, and I'm probably going to make this confusing but...-

How do I run a script from crontab, and have the dir the script is in be the default dir?

For example, I have /home/me/.rss2email with the python script "r2e" in that dir. The dir contains other scripts required by "r2e", so when I add "/home/me/.rss2email/r2e run" I want it to not say "otherscript.py not found".

Try making your command "cd /home/me/.rss2email/r2e && ./r2e". If that doesn't work (I can never remember when it does and when it doesn't) make a wrapper script:

code:
#!/bin/sh
cd /home/me/.rss2email
./r2e

vanjalolz
Oct 31, 2006

Ha Ha Ha HaHa Ha
PATH=/home/me/.rss2email/:$PATH /home/me/.rss2email/r2e
should/could work too

Mr. Eric Praline
Aug 13, 2004
I didn't like the others, they were all too flat.

vanjalolz posted:

PATH=/home/me/.rss2email/:$PATH /home/me/.rss2email/r2e
should/could work too
Actually, you should always export
PATH=$PATH:/additional/path/. The existing PATH should come first for security reasons.

/additional/path/ is more likely to be something that can be written to by a user, so if that person (or process) sticks a trojaned ls or ps in there, you'll be executing that rather than the real one.

Regardless, I don't think Python looks for it's scripts in the system path. Set PYTHONPATH=$PYTHONPATH:/home/me/.rss2email. Using that is cleaner than using cd anyway.

Edit: And I'm not sure cd will work. You'd have to cd, and then source ./otherscript.py. Chances are, you're currently just calling it without ./ in front, which means it won't be found in the cwd anyway.

Edit2: http://docs.python.org/tut/node8.html#SECTION008120000000000000000

Mr. Eric Praline fucked around with this message at 15:20 on Aug 12, 2008

pukeduke
Nov 20, 2003

¡GOOOOOOALLLLLLL!
I have an old Hauppage USBLive device, which converts the yellow RCA-type cable to USB. Can I use this to see the video feed on linux? I can't seem to find anything...

yippee cahier
Mar 28, 2005

pukeduke posted:

I have an old Hauppage USBLive device, which converts the yellow RCA-type cable to USB. Can I use this to see the video feed on linux? I can't seem to find anything...

What shows up when you plug it in and run 'lsusb'? Find a program that can capture from a V4L device and give it a shot to see if it's detected.

Combat Pretzel
Jun 23, 2004

No, seriously... what kurds?!
I finally set up public key authentication on my web server after owning it for a year. Should have known it is so loving trivial, then I wouldn't have pushed it back again and again until today. :psyduck:

Mr. Eric Praline
Aug 13, 2004
I didn't like the others, they were all too flat.

Combat Pretzel posted:

I finally set up public key authentication on my web server after owning it for a year. Should have known it is so loving trivial, then I wouldn't have pushed it back again and again until today. :psyduck:
Just don't lose the key. That's the less trivial part. :P

Combat Pretzel
Jun 23, 2004

No, seriously... what kurds?!
Password auth is still possible. It's mainly just to stop scp from being annoying with passwords. :)

Peanutmonger
Dec 6, 2002

Combat Pretzel posted:

Password auth is still possible. It's mainly just to stop scp from being annoying with passwords. :)

Check out ControlMaster in ssh_config, you can have new calls to ssh/scp use an existing connection. Just don't use it on a multi-user system if you don't trust the people who have root access to that system...

Falcon2001
Oct 10, 2004

Eat your hamburgers, Apollo.
Pillbug
This is driving me up a wall - my friend found some music streaming software for linux called Ginjoza or something and I can't remember the drat name.

You installed it, pointed it at a directly and it used apache/php to stream music via HTTP. Any idea?

Edit: THE ABOVE AND BELOW ARE UNRELATED - THE ABOVE IS FOR STREAMING TO MY WORK PC THE BELOW IS FOR AT HOME.
Another, unrelated note, crossposted from the PSP homebrew thread, because I think this is more relevant.

I have a Linux server - it has to run linux, some distribution thereof. It has a wireless speaker, which I move around my apartment. I can play music on the linux server and it will play from the speaker. I like this feature and it's nice and fun. I have a directory structure, which is basically /mnt/drivename/Music/GENRE/ARTIST/ALBUM/files. I like having playlists based on genre, which I can then sift through or randomize at my leisure.

I have a PSP and a wireless network.

I would like to control what is playing on my linux server from my PSP via a web-based interface or something of the sort.

I don't want to stream to the PSP, because the sound degrades and the psp speakers suck anyway. I would just like to control what I'm playing.

I already tried VLC, but the documentation is either missing or completely psychotic. Seriously, no explanation of how to add MRL, and they've apparently started using Reverse Polish Notation for their markup, which means I'm effectively shitcocked when it comes to understanding what the gently caress is going on.

In ADDITION to that, the method by which VLC handles playlists is completely hosed. Not only does it not parse the playlist until you try to play it, but it completely extrudes all open playlists at the same time. I can't seem to find a way to add a playlist per genre but only have one open - NO. I must have all humpteen hojillion songs open at once, which makes my PSP effectively frozen since the drat thing operates a web browser like my grandmother drives.

I'm kind of irritable right now, but I'm hoping for another option. Anyone have any ideas? I got it working with Foobar2000 in like...5 minutes. Just frustrated it's taking so long on linux.

Falcon2001 fucked around with this message at 10:40 on Aug 14, 2008

deong
Jun 13, 2001

I'll see you in heck!

Falcon2001 posted:

This is driving me up a wall - my friend found some music streaming software for linux called Ginjoza or something and I can't remember the drat name.

You installed it, pointed it at a directly and it used apache/php to stream music via HTTP. Any idea?

I think you mean Jinzora? Another one I've used is GNUMP3D. But really, there are a ton out there.

waffle iron
Jan 16, 2004

sund posted:

What shows up when you plug it in and run 'lsusb'? Find a program that can capture from a V4L device and give it a shot to see if it's detected.
Also useful is the output of dmesg|tail

Falcon2001
Oct 10, 2004

Eat your hamburgers, Apollo.
Pillbug

deong posted:

I think you mean Jinzora? Another one I've used is GNUMP3D. But really, there are a ton out there.

You are awesome, and this is exactly it.

skipdogg
Nov 29, 2004
Resident SRT-4 Expert

Here's one for you guys...

Squid cache running squidguard as the rewriter on a RHEL 4 box.

We access a sharepoint site over a VPN tunnel to one of our partners. No proxy server and we can connect just fine... I turn the proxy on, and it just doesn't connect.

The access log shows a CONNECT to the site in question, but no other errors are displayed, and the site and IP have been whitelisted in squidguard.

I'm running Squid 2.6 Stable12 which shouldn't have any NTLM issues that I read about when I googled "squid" and "sharepoint"

worth mentioning is when you go to the URL of the sharepoint site you get bounced to our partners SSO portal, and when you authenticate there get redirected back. We use the SSO portal with alot of other sites so I know that's not the issue... I've been through all the squid and squidguard logs and I can't find any errors...

worth noting is I checked my squid.conf everything NTLM is commented out...

code:
#Recommended minimum configuration per scheme:
#auth_param negotiate program <uncomment and complete this line to activate>
#auth_param negotiate children 5
#auth_param negotiate keep_alive on
#auth_param ntlm program <uncomment and complete this line to activate>
#auth_param ntlm children 5
#auth_param ntlm keep_alive on
#auth_param digest program <uncomment and complete this line>
#auth_param digest children 5
#auth_param digest realm Squid proxy-caching web server
#auth_param digest nonce_garbage_interval 5 minutes
#auth_param digest nonce_max_duration 30 minutes
#auth_param digest nonce_max_count 50
#auth_param basic program <uncomment and complete this line>
#auth_param basic children 5
#auth_param basic realm Squid proxy-caching web server
#auth_param basic credentialsttl 2 hours
#auth_param basic casesensitive off


Anyone have any ideas? Boy I hope they approve the Barracuda box in the budget for next year.

UNCUT PHILISTINE
Jul 27, 2006

Thanks guys, I appreciate it.

rugbert
Mar 26, 2003
yea, fuck you
bah, anytime theres a kernel update I lose my wireless (ndiswrapper) and resolution (nvidia). is there an easy way to roll back so I can reinstall my graphics and wireless capabilities?

JoeNotCharles
Mar 3, 2005

Yet beyond each tree there are only more trees.

rugbert posted:

bah, anytime theres a kernel update I lose my wireless (ndiswrapper) and resolution (nvidia). is there an easy way to roll back so I can reinstall my graphics and wireless capabilities?

Depends on what system are you using. Debian/Ubuntu? Red Hat/SuSE? You should be able to just uninstall the new kernal package and reinstall the old one. If you built it yourself, use the same procedure you used to install it to build and install an older version.

Why don't you just recompile ndiswrapper and nvidia though?

Twlight
Feb 18, 2005

I brag about getting free drinks from my boss to make myself feel superior
Fun Shoe
I've been given the task of setting up account management for our Linux systems. we have 4-5 CentOS 5 systems and about a 1/2 dozen Red Hat systems as well. All of our windows servers are authenticating through AD. Searching on Google really hasn't brought the kind of information I've been looking for. I'm not sure where to begin, would radius be a good idea? we have a radius server already in house handling some Cisco log in information, or should I use something else?

Mr. Eric Praline
Aug 13, 2004
I didn't like the others, they were all too flat.

Twlight posted:

I've been given the task of setting up account management for our Linux systems. we have 4-5 CentOS 5 systems and about a 1/2 dozen Red Hat systems as well. All of our windows servers are authenticating through AD. Searching on Google really hasn't brought the kind of information I've been looking for. I'm not sure where to begin, would radius be a good idea? we have a radius server already in house handling some Cisco log in information, or should I use something else?
If you can get your AD admins to add the POSIX extensions (they might be called something else) to Active Directory, then you can auth your servers via AD using LDAP and Kerberos. It's not terribly hard, and it works reasonably well.

KS
Jun 10, 2003
Outrageous Lumpwad

skipdogg posted:

Here's one for you guys...

Squid cache running squidguard as the rewriter on a RHEL 4 box.

There has to be more to your config than that if you're doing authentication. Everything's commented out there.

We've run into several sites that have NTLM issues, usually with java applets or activex controls that don't handle it well. To eliminate it as the problem really quick, you can:

acl noauthsites dstdomain mysharepointsite.com
http_access allow noauthsites

reconfigure squid and test.

Twlight
Feb 18, 2005

I brag about getting free drinks from my boss to make myself feel superior
Fun Shoe

chryst posted:

If you can get your AD admins to add the POSIX extensions (they might be called something else) to Active Directory, then you can auth your servers via AD using LDAP and Kerberos. It's not terribly hard, and it works reasonably well.

haha I am the AD admin. Ill look this up thanks.

Adbot
ADBOT LOVES YOU

rugbert
Mar 26, 2003
yea, fuck you

JoeNotCharles posted:

Depends on what system are you using. Debian/Ubuntu? Red Hat/SuSE? You should be able to just uninstall the new kernal package and reinstall the old one. If you built it yourself, use the same procedure you used to install it to build and install an older version.

Why don't you just recompile ndiswrapper and nvidia though?

Because I didnt know how to do that :/ but for some reason after I lost my wireless and wired up I soon there after lost my ability to use ethernet too (my eth0 got named forcedeth and wouldnt activate).

I just grubbed to my old kernel till I figure out how to fix this stuff.


also - does anyone know how to change wireless mouse sensitivity? this is driving me crazy.

  • 1
  • 2
  • 3
  • 4
  • 5
  • Post
  • Reply