**** BEGIN LOGGING AT Wed Jun 23 02:59:56 2010 Jun 23 11:14:29 blathijs: hi! Jun 23 11:14:35 hey giuseppeg88 Jun 23 11:14:40 I may have solved that problem of security... Jun 23 11:14:46 do tell Jun 23 11:14:54 with two commands: Jun 23 11:15:25 iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --set Jun 23 11:15:27 iptables -I INPUT -p tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 3 -j DROP Jun 23 11:18:20 it is strange that the lock does not work just by itself... instead in the Fonera 2.0g, I don't need to give these commands: why is already working Jun 23 11:19:02 Yeah, there should be rules for this already Jun 23 11:20:17 But it seems the rules aren't present in my 2.0n either (they should be in the input_daemon chain) Jun 23 11:21:23 Oh wait, I don't have external SSH enabled it seems Jun 23 11:22:34 lol Jun 23 11:23:05 Hmm, now I do get the rules Jun 23 11:23:44 giuseppeg88: Could you see what "iptables -n -v -L input_daemon" gives you on a clean boot (so without the manual iptables commands)? Jun 23 11:23:55 I can try rebooting the fonera (so it forgets these commands) and can I do iptables-L to see if there is this rule... ok? Jun 23 11:24:04 ok Jun 23 11:24:46 exactly :-) Jun 23 11:27:15 giuseppeg88 Jun 23 11:27:24 you are italian? Jun 23 11:27:30 http://paste-it.net/public/oed47c2/ Jun 23 11:27:36 barbon: yes! Jun 23 11:27:47 you play wow right? Jun 23 11:28:40 no ;-) Jun 23 11:29:03 because i have thinked that you are the same giuseppe88 of another server Jun 23 11:29:05 xD Jun 23 11:29:12 ahahah Jun 23 11:29:46 also have a fonera 1.0 Jun 23 11:29:50 so :P Jun 23 11:30:34 in the past I played sporadically with cod4 Jun 23 11:31:02 lol Jun 23 11:32:57 blathijs: did you see what I sent? Jun 23 11:33:17 giuseppeg88: Yeah, but I don't know why it wouldn't be working :-) Jun 23 11:34:01 giuseppeg88: Perhaps it is working, but these rules had been somehow disappeared earlier? Jun 23 11:35:05 blathijs: I have neither added to or taken from the rules lately ... Jun 23 11:36:17 what are you speaking about? Jun 23 11:36:49 blathijs: did you try with your fonera? Jun 23 11:37:23 barbon: http://logs.nslu2-linux.org/livelogs/fonosfera-prev.txt Jun 23 11:39:02 now I have to go to lunch ... see you later! Jun 23 11:39:18 giuseppeg88: Perhaps some firewall reload went wrong and missed a few rules, dunno Jun 23 11:39:41 giuseppeg88: I'll see what mine does (but I do remember it working, since I regularly locked myself out :-p) Jun 23 11:39:54 http://trac.fonosfera.org/fon-ng/ticket/516 Jun 23 11:39:58 barbon: We're talking about the SSH hammer protection, that didn't seem to be working for giuseppeg88 yesterday Jun 23 11:42:58 ok Jun 23 12:18:04 hello blathijs.. Jun 23 12:27:00 hey amanullang Jun 23 12:27:11 I'm off for lunch, brb Jun 23 12:43:05 back :-) Jun 23 12:44:33 so.. Jun 23 12:45:17 what about my firmware...any progress? Jun 23 12:49:08 amanullang: I'm talking to blogic right now Jun 23 12:49:30 amanullang: Do you know if you can configure a PIN code for your 3G modem? Jun 23 12:53:22 but,theres is no pin Jun 23 12:55:37 But if you would have a SIM card with a PIN, could you set it somewhere (in Windows for example?) Jun 23 12:56:19 yess...but i dont put any pin right now...should i? Jun 23 12:59:54 amanullang: If you could try, just any pin will do. And then copy the Windows modem log again, like you did before? Jun 23 13:03:30 do you mean i should make my own PIN? Jun 23 13:05:22 yes, I want to see how the Windows driver sends the PIN to your modem, even if it is incorrect Jun 23 13:08:00 ok Jun 23 13:17:57 blathijs Jun 23 13:18:03 i'm forgot how to make it.. Jun 23 13:18:08 can you tell me again? Jun 23 13:18:20 Let me find the link Jun 23 13:19:37 amanullang: http://support.microsoft.com/kb/162694 Jun 23 13:45:30 blathijs Jun 23 13:45:34 http://pastebin.com/DrK5tCCt Jun 23 13:46:06 i've got a problem when connecting modem to fonera too Jun 23 13:46:39 i have to waiting the fonera on stabil and then plug in my modem Jun 23 13:46:46 then connected Jun 23 13:48:18 Hmm, there's no mention ofthe PIN in the log. So the driver perhaps sends the PIN before logging or something. Thanks for checking! Jun 23 13:48:35 amanullang: You mean that it doesn't work when the modem is plugged in on startup? Jun 23 13:48:47 yes Jun 23 13:49:00 i have to make the fonera on first Jun 23 13:49:10 and wait til stable Jun 23 13:49:28 and the plug in my modem Jun 23 13:50:09 I have a hunch why that might be Jun 23 13:50:21 Hold on, I'll give you a file for testing in a minute Jun 23 13:50:29 ok Jun 23 13:50:31 anyway Jun 23 13:50:49 i've a problem when make pin to this modem Jun 23 13:51:16 the modem cant connect when there is a pin Jun 23 13:51:38 You can just remove the PIN again, it was just for testing Jun 23 13:51:38 then i should disable the pin first toconnecting the modem with fonera Jun 23 13:51:44 ok Jun 23 14:23:20 amanullang: Could you put www.stdout.nl/fon/fonstated in /sbin, reboot your Fonera with the 3G modem connected and give me a logread? Jun 23 14:24:40 i dont get it Jun 23 14:25:00 oohh...ok Jun 23 14:29:08 http://pastebin.com/EGep1NTp Jun 23 14:29:20 blathijs... Jun 23 14:37:00 blathijs? Jun 23 14:37:23 amanullang_: Ah, I thought you had quit again :-) Jun 23 14:37:35 amanullang_: From the log, it looks like it should have been connected normally Jun 23 14:37:44 yess Jun 23 14:37:46 Could it be that it breaks only sometimes Jun 23 14:37:47 ? Jun 23 14:38:09 its normal...for rebooting then connected Jun 23 14:38:20 normal now Jun 23 14:38:29 dont know later Jun 23 14:39:15 what about the PIN thing? Jun 23 14:39:46 huh? Jun 23 14:39:55 What did you mean with this then? Jun 23 14:39:58 15:49:00 < amanullang> i have to make the fonera on first Jun 23 14:39:59 15:49:10 < amanullang> and wait til stable Jun 23 14:40:01 15:49:28 < amanullang> and the plug in my modem Jun 23 14:40:47 ok Jun 23 14:41:46 that was a question :-) Jun 23 14:42:18 sometimes i get dc too..and need to refresh the browser first Jun 23 14:42:32 dc? Jun 23 14:42:38 disconnected? Jun 23 14:42:39 disconnect Jun 23 14:42:42 yup Jun 23 14:42:49 hmkay Jun 23 14:47:01 do you know what is the problem? Jun 23 14:51:24 other things...what about 'usb hub',how should fix the problem? Jun 23 14:53:18 blathijs...brb Jun 23 14:57:13 blathijs? Jun 23 17:22:34 blathijs: hi! Jun 23 17:22:58 blathijs: I saw the ticket Jun 23 17:23:31 giuseppeg88: Are you running bridge mode? :-) Jun 23 17:23:43 yes Jun 23 17:23:49 then there's the problem :-) Jun 23 17:24:22 understood... Jun 23 17:25:49 but beyond this problem, what is wrong in the firewall when the Fonera is in bridge mode? Jun 23 17:26:45 temporarily (to block attacks outside), going well the two commands I wrote this morning? Jun 23 17:29:09 giuseppeg88: Adding those lines to /etc/firewall.fon is probably fine Jun 23 17:29:31 might be a while before we fix this problem, though, we might need to rethink bridge mode a bit Jun 23 17:31:18 what do you mean by "we might need to rethink bridge mode a bit"? Jun 23 17:34:48 giuseppeg88: It's currently implemented using the hardware switch configuration, we're considering using kernel bridging instead Jun 23 17:36:31 this would lead improvements? Jun 23 17:37:24 also, the firewall configuration now puts every netwerk interface in a single zone (wan, lan, hotspot), but that doesn't apply for bridge mode exactly Jun 23 17:37:46 it would make the code a bit cleaner, hopefully making it easier to get things like firewalling right Jun 23 17:41:32 ok, I now everything is clear ... thanks for the info! Jun 23 17:41:59 np Jun 23 17:42:37 ops! I now everything is clear -- > now everything is clear to me Jun 23 17:50:53 hehe Jun 23 17:52:09 blathijs: last question (I do not know if it is a question by dummy ;-) ): this could lead to greater use of the CPU? Jun 23 18:03:31 I don't really think so Jun 23 18:03:48 perhaps a bit, though Jun 23 18:04:43 but the MyPlace <-> LAN connection is a kernel bridge already, so he stuff is loaded anyway Jun 23 18:07:31 ok! **** ENDING LOGGING AT Thu Jun 24 02:59:58 2010