log☇︎
4100+ entries in 0.021s
Framedragger: uh. how about, fuck your mother
Framedragger: > 173 new root certificates were added to your trust store.
Framedragger: in unrelated newz, while installing an ubuntu package,
Framedragger: certainly. (also while on topic, large part of tor relay network. "decentralization!!!")
Framedragger will consider testing it. would be useful knowledge, i.e. OVH *is* cost effective for not-super-important "lower grade hardware ok" deployments
Framedragger: yeah sure.
Framedragger: (oh oh, and also trying out masscan (the first-stage scanner, i.e. the one which sends TCP SYNs) with maybe 30-100k packets per second stable))
Framedragger: mircea_popescu: well, didn't *serve*, but benchmarked myself. i can try again tho, that was long ago
Framedragger: (i use tor to access things like library genesis while still in airstrip one, but that says more about airstrip one than anything else.)
Framedragger: even Framedragger doesn't push tor anymore. *and that's telling you somethin'* :D
Framedragger: mircea_popescu: yeah, good point. well the hosting provider is ~shitty and quality of bw offered is not great (OVH), but it *does* make a more-or-less successful attempt at providing an actual full duplex 100 mbps, which isn't a lot, but still decent to my liking. so at least there's that.
Framedragger: mircea_popescu: thanks. in point of fact a blog is now in actual plans, not only oneday-maybewaybe. :) re. capacity to handle, at least the connection is unmetered, and it's just static nginx. but it's not anything big. so this is useful and appreciated.
Framedragger: mircea_popescu: ah, that's cool and useful, ty
Framedragger: https://i.imgur.com/QC51FZz.png ☟︎
Framedragger: /me done with logspam
Framedragger: http://btcbase.org/log/2016-12-16#1583915 << whoops, correction: these contain all the >20M IPs answering to port 22. (otherwise these would be redundant cf. banner CSVs). ☝︎☟︎
Framedragger: mircea_popescu: obtw, re. http://trilema.com/2016/internet-census-2016/#selection-21.0-21.13 it should probably say "Back in June", as it was june. the second scanning event was in july, but all of phuctor's finds thus far have been from the first scan in june
Framedragger just discovered http://trilema.com/2012/the-mpex-rota/ - pretty neat. i take it this expensive experiment had been thus discontinued :) ☟︎
Framedragger: http://qntra.net/2016/12/ubuntu-crash-reports-allow-remote-code-execution/ << good stuff. fwiw Donncha is cool. here's him fucking around with coinbase: https://donncha.is/2013/06/coinbase-owning-a-bitcoin-exchange-bug-bounty-program/
Framedragger: (and http://siphnos.mkj.lt/datadrop/s1_ip.tar.bz2 and http://siphnos.mkj.lt/datadrop/s2_ip.tar.bz2 are all the 15`646`188 ssh IPs for anyone interested.) ☟︎
Framedragger: oh and, http://siphnos.mkj.lt/datadrop/s1_scan.tar.bz2 and http://siphnos.mkj.lt/datadrop/s2_scan.tar.bz2 (note, large files) are the stdout of ssh-keyscan and contains the public keys in raw log format. just for completeness' sake. #actualscientificreplicabilitymotherfuckers ☟︎
Framedragger: and 2., re. http://btcbase.org/log/2016-12-15#1583653 << asciilifeform: fyi internal line order does *not* map to order of openpgp files - sorry about this. but the filenames and numbers *do* map to parcels previously given. just to be clear. ☝︎
Framedragger: http://btcbase.org/log/2016-12-15#1583663 << two small notes: 1. i've now deleted the uncompressed *.log's, everything's in archive format (and raw logs still available of course). just not to waste disk space. ☝︎
Framedragger: trinque: that's sorta fuckin' weird. "empty set as first class citizen" something something...
Framedragger: epic lulz.
Framedragger: WRQReflectionforSecureIT_7.0 << hahahahaha
Framedragger: ("mkj" is a pretty random acronym of the first names of three people who started up the server in ~2008)
Framedragger: no connection to mkj.lt :p but pretty lulzy
Framedragger: ah, https://github.com/mkj/dropbear
Framedragger: (a friend sysadmin and google dude uses mkj.lt, too, but this would be quite amusing)
Framedragger: wut
Framedragger: ^ http://siphnos.mkj.lt/datadrop/crap-from-scans-to-be-sorted/
Framedragger: (i should write down some stuff before i forget, such as, figuring out ssh-keyscan limits etc.; luckily i wasn't dumb enough to delete any scripts written etc...)
Framedragger: http://btcbase.org/log/2016-05-20#1469693 ☝︎
Framedragger: mircea_popescu: http://btcbase.org/log/2016-05-20#1469663 ☝︎
Framedragger: gotta love it
Framedragger: i accidentally overwrote legit log file with `tar cfz` like 20min ago
Framedragger: *no way
Framedragger: (ah no need to -excludeterms in btcbase search i guess :p )
Framedragger: hm notrly but one min
Framedragger Framedragger is dig util over irc
Framedragger: << http://btcbase.org/log/2016-11-20#1571616 (second part of msg) ☝︎
Framedragger: mircea_popescu: (mkj.lt is different server from siphnos.mkj.lt)
Framedragger: mircea_popescu: 5.196.95.135
Framedragger: so no need for this (but obvs would be cool, too)
Framedragger: fwiw i plan to make these available through a search interface - will put stuff into db. i think i'll make it so that one can link to particular db entry via that deterministic-alf-fingerprint you concocted
Framedragger: (and @all, http://siphnos.mkj.lt/datadrop/ is the canonical URL for all data gathered from the ssh scans. includes raw stderr logs from ssh-keyscan utility, e.g. http://siphnos.mkj.lt/datadrop/banners/s1/1_err_scan.log ; scripts for processing these are http://siphnos.mkj.lt/datadrop/banners/write_ssh_banners.py and http://siphnos.mkj.lt/datadrop/banners/process_all_banners.sh ) ☟︎
Framedragger: (note, some of those version strings contain OS string, some of them don't; these TXTs store versionstrings-as-they-were-seen, without any ssh-server/OS version separation.)
Framedragger: mircea_popescu: yeah, same here, fairly curious re. unique versionstring numbers, etc...
Framedragger: asciilifeform: ah, correction: s1_banners.tar.gz is only the first ~13.3M servers - i.e. the first set of thirteen parcels i gave you - here's the rest - i.e. the three additional parcels (i know phuctor won't be processing these for a while, but, for completeness): http://siphnos.mkj.lt/datadrop/banners/s2/s2_banners.tar.gz
Framedragger: (the criterion for choosing which banner to report is a simple "max string length.") (again, note, all of those "multiple" banners were from a single scan event, same date, so no historical knowledge is lost by only reporting single banner per single (ip,port) pair.) hope this makes sense.
Framedragger: (format in TXTs is simple CSV: ipv4address,banner -- the latter may contain spaces, commas etc, but any surrounding whitespace (incl newlines) is stripped. there's only one banner per ipv4 even though *same* scan sometimes returned multiple (slightly different, e.g. includes or excludes OS string) banners.)
Framedragger: (numbers in filenames and internal line order maps to openpgp files i gave you, fwiw) ☟︎
Framedragger: asciilifeform: not sure if you'd make use of this, but since i needed this myself, may as well link to it -- ssh banners for all ~16M ssh servers: http://siphnos.mkj.lt/datadrop/banners/s1/s1_banners.tar.gz
Framedragger just discovered how phuctor's 404 page looks like: http://nosuchlabs.com/asdf - appreciates ☟︎
Framedragger: ah.
Framedragger: oh. ...of course
Framedragger: (no sources for this..)
Framedragger: reminds me of some guy who put a wire under his hand's skin, and made compass needle modulate the current (or somesuch). claims that after 2-3 weeks he had gained a genuinely new sense (of absolute direction)...
Framedragger: gotta admire your industrious approach asciilifeform...
Framedragger did a bit of privileged-teen-mode some years ago. "paying for life expenses with money earned from doing work" helpz
Framedragger: (undergrad student circles, etc.; luckily those fall out of relevancy/radar as one ages)
Framedragger: hehe, don't know particulars, but it should be noted that he studied philosophy and in some of the circles he had to have business with, ayn rand sorta-has a place as a non-crackpot. hence the (arbitrary, otherwise) particular object of hate
Framedragger: s/this//
Framedragger: [that reminds me, i bought a postcard of ayn rand and am yet to send this to a friend who is in full hate mode of her stuff. need to get this done for the festive season...]
Framedragger: aha okay, good to know, thx.
Framedragger: asciilifeform: quick unrelated q: in phuctor, do the phuctored debianized keys appear in /phuctored ? from what i recall and understand, all of them are there. and one wouldn't have to look at /sadmods or /dupes - correct?
Framedragger: well, iac it's a shame no decent game controllers are available, true that :/
Framedragger: aite, that's a chunk of money for sure, i'd've thought it to have been lower than that :(
Framedragger: i don't know how it is in the .us and it's prolly *quite* a bit more complicated than that, also i had the lucky chance of having a relative who'd invite to fly with him and show me basic flight control stuff, but are you not able to get lessons as a total noob?
Framedragger: asciilifeform: except you're not paying for the full retail price of a harley, and you don't need to train for 10 years? :)
Framedragger: the "UI/programming-language" juxtaposition is quite apparent when writing pl/pgsql. i dunno, it's a weird feeling.
Framedragger: "there are always leaks." yeah, i mean, no objections i guess.
Framedragger: (there's lack of general flexibility, it's full of baked-in developer-choices so to speak, etc.)
Framedragger: yeah, aliasing is an important mental-compression operation. i see what you mean
Framedragger: aha right, you sort of define it upon every use, which sucks balls and is an example of stupid inflexibility
Framedragger: can materialized views use joins in the way you want to? i haven't looked into them for some time, so dunno.
Framedragger: trinque: right right, so you're talking about SQL as a language, fair enough
Framedragger: i'd actually like to see a coherent and all-in-one-place SQL / RDBMS-as-a-general-model critique some time. maybe it exists. usually it's mongodb hipsters complaining randomly, so i'd developed a (too-)generic "ignore 'em all" filter :p ☟︎
Framedragger: ah yeah, i recall you mentioning 'sql explorer' (for phuctor data iirc) trinque. ambitious but delicious project
Framedragger: as long as the 'check hash' operation is quick enough, otherwise DoS magnet (that's a very alf'y comment i guess)
Framedragger: that kind of metering would be neat to have..
Framedragger: does postgrest still use 'basic auth'? :/
Framedragger: http://btcbase.org/log/2015-07-11#1197431 << :( ☝︎
Framedragger: ^ just discovered this. "remove the CRUD", serve APIs directly from postgres. includes user/role/cookie management etc. pretty neat. ☟︎
Framedragger: !#s postgrest
Framedragger: good education tho
Framedragger: encoding, fml
Framedragger: phf: thanks for pointing me in the right direction. scriba now reads log as byte sequence, tries decoding each line as utf-8, if that fails, then does latin-1. seems to be fine.
Framedragger: ^ ok, finally fixed. took forever. >.<
Framedragger: test with new log reader http://log.mkj.lt/trilema/20161211/#7 test
Framedragger: (also removing debug log)
Framedragger: oh ffs. sec.
Framedragger: http://log.mkj.lt/trilema/20161211/#7
Framedragger: sounds pretty awesome.
Framedragger: wtf, god, who did m$ not conspire with :/
Framedragger: (it's sorta-kinda seeing a revival, with folks doing HRTF etc on bare CPU without need for audio chip accelerated whatever, but i believe there's still a.. niche. for someone whoever realizes that graphics isn't everything, etc.)
Framedragger: so sad :(
Framedragger: hah that reminds me, i'm too young to properly remember but after looking into this i've concluded that best 3d audio was in 90s (before creative labs patent-trolled aureal semiconductor). (maybe i already ranted about this).
Framedragger: uci == universal computing interface? something something infrastructure on demand at your irc fingertips, right (ironically google is failing me) ☟︎