**** BEGIN LOGGING AT Wed Dec 07 03:00:00 2016 Dec 07 11:05:25 http://motherboard.vice.com/read/hacker-claims-to-push-malicious-firmware-update-to-32-million-home-routers Dec 07 11:08:11 heh. Dec 07 11:08:34 he just works for the manufacturers Dec 07 11:08:41 that want to sell more more more Dec 07 11:09:01 This is why I run my own router and don't trust the stuff my ISP wants to give me. Dec 07 11:09:24 but it might be some silly news site Dec 07 11:16:44 https://badcyber.com/new-mirai-attack-vector-bot-exploits-a-recently-discovered-router-vulnerability/ Dec 07 11:18:04 >>TR-064 protocol<< ?? Dec 07 11:20:04 oohfsck https://avm.de/fileadmin/user_upload/Global/Service/Schnittstellen/AVM_TR-064_overview.pdf Dec 07 11:20:46 how many of that TR crap exists? Dec 07 11:21:33 TR-069 for wan side, TR-064 for the lan side as an alternative to UPNP & stuff. Dec 07 11:22:19 oooh LAN side Dec 07 11:22:41 so those twits exposed TR-054 to WAN? Dec 07 11:22:52 64* Dec 07 11:23:01 Apparently, yes. Dec 07 11:23:12 :-(( Dec 07 11:26:17 DocScrutinizer05: they want give you the sensation that even at home you are not alone ;) Dec 07 11:27:15 woudn't TR-054 show up in a full portrange nmap? Dec 07 11:27:24 64* dang Dec 07 11:29:50 or is it protected by stuff like port-knocking? Dec 07 11:30:11 or UDP key Dec 07 11:31:04 DocScrutinizer05: https://avm.de/fileadmin/user_upload/Global/Service/Schnittstellen/AVM_Technical_Note_-_Konfiguration_ueber_TR-064.pdf Dec 07 11:31:38 * Wizzup wonders if his fritzbox is OK ;) Dec 07 11:31:46 at least I have openwrt between fritzbox and LAN Dec 07 11:36:27 hmm, they claim access via TR-064 isn't possible when you have a password set on Fritte Dec 07 11:36:45 they also seem to say access is via port 443 Dec 07 11:37:45 then I'm a happy camper since tcp port 443 is closed on my frontend router Dec 07 11:39:43 it's forwarded to my home server Dec 07 11:41:36 only ssh access to my LAN Dec 07 11:41:40 ;-) Dec 07 11:42:23 well, and a few forwarded ports with no active service Dec 07 11:42:34 like 10000 for STUN Dec 07 11:42:58 5060 Dec 07 11:43:07 (actually active) Dec 07 11:44:05 just waiting for some hacker finding an exploit for/in _that_ Dec 07 11:44:46 I'd be surprised if it had no buffer overflows or anything else at all Dec 07 11:46:24 sucks when you have SIP daemon and WLAN and possibly even router on same CPU Dec 07 11:46:36 and same NIC Dec 07 11:54:27 warfare: https://de.wikipedia.org/wiki/Hackerangriff_auf_DSL-Router_am_27._November_2016 Dec 07 11:54:56 >>Ziel des Angriffs war der Aufbau einer Verbindung mittels Fernwartungsprotokoll (TR-069) und das Einschleusen einer Schadsoftware über einen in der TR-069-Spezifikation nicht vorgesehenen Befehl des TR-064-Protokolls...<< Dec 07 11:57:24 anyway http://paste.opensuse.org/72514013 I think I'm safe Dec 07 11:57:49 no, my IP changed since ;-) Dec 07 12:39:24 I wouldn't use an ISP provided router myself Dec 07 12:41:18 never did Dec 07 12:43:06 what I'm worried most about are my LAN devices with proprietary firmware, like printer, home automation, whatnot Dec 07 12:45:07 my printer even has a NTP built in, it does a nozzle clean every day 12:00 noon Dec 07 13:00:20 IMO CCTV is the most vulnerable IP device in a home. DVR's are basically out of date Linux machines, that can watch your every move. Dec 07 13:00:40 many cctv devices come pre-trojaned for your convenienece! Dec 07 13:00:43 ;) Dec 07 13:01:49 I'd still use analog SAT TV if that existed Dec 07 13:02:09 akk that digital TV stuff sucks big time Dec 07 13:02:12 all* Dec 07 13:23:04 anyway, there are devices where also the stock features could give great satisfaction... http://www.bit-tech.net/news/hardware/2013/12/17/bt-back-door/1 Dec 07 13:24:16 got windows? Dec 07 13:24:18 ;) Dec 07 13:24:47 KotCzarny: read the pdf ^ Dec 07 13:25:17 Yep many popular Chinese brands have back door in them Dec 07 13:25:34 nah, i know we are backdoored Dec 07 13:25:54 be it software, system, devices or even chips layer Dec 07 13:26:39 and systemd just proves people dont care about security. 'it only has to boot quick' (even if you boot once a year) Dec 07 13:28:30 fritzbox is diarrea anyway Dec 07 13:38:22 better than all other isp-provided ones though Dec 07 13:39:45 possibly , not convinced that much Dec 07 13:40:03 telfort once gave me a zyxel router with 100% stock config, nothing preconfigured or modded Dec 07 13:42:36 systemd is a non-issue in comparison, it's open source and not mandatory. Routers and other equipment is a requirement to many. Dec 07 13:45:36 swb: also buggy, unstable ... Dec 07 13:45:57 now imagine what will happen when it gets included on routers Dec 07 13:46:07 'because it boots faster' Dec 07 13:49:22 Many of the items in this botnet is still on 2.x kernel and not updated or patched if exploits are found. I am all for init freedom but there are bigger fish that systemd for IoT IMO. Dec 07 13:49:36 s/that/than Dec 07 13:50:11 we will see Dec 07 13:52:45 systemd is too bloated to be on routers etc for the near future. Dec 07 13:55:47 my last router i bought had 128MB flash already Dec 07 13:55:56 i dont think this will really be any issue Dec 07 13:57:14 systemd mandates writable root fs. pretty incompatible with routers that often have no real r/w fs at all Dec 07 13:57:24 tmpfs Dec 07 13:57:42 or dying routers ahoy Dec 07 14:01:54 buZz: you can flash all Fritz to AVM plain firmware if it comes too 'branded' Dec 07 14:02:14 ooo nice Dec 07 14:02:24 i think we dumpsterdived couple fritz's Dec 07 14:02:38 a pity Dec 07 14:02:41 last time i looked they had 0 support to run OpenWRT Dec 07 14:02:46 but you say they do? Dec 07 14:02:48 google freetz Dec 07 14:03:13 freetz is just a slight mod to firmware Dec 07 14:03:26 you need the AVM pre-6.51 recovery *.exe Dec 07 14:04:10 so, no openwrt? i'll just consider them lost causes then Dec 07 14:04:20 no idea Dec 07 14:04:55 ah no, actually a couple are supported a bit Dec 07 14:05:09 they come with a number of blobs, just like maemo ;-) Dec 07 14:05:48 the newer ones for example have offload (hw accel for packet routing) Dec 07 14:06:07 I don't think that's FOSS Dec 07 14:06:07 looks like nearly all of them are highly unrecommended openwrt platforms :P Dec 07 14:06:33 sure, aiui openwrt is best on very basic hw Dec 07 14:07:02 I don't see openwrt work fine with e.g. the DECT in mine Dec 07 14:07:21 ah DECT <3 Dec 07 14:07:36 i still need to grab me a couple of those CardBus DECT sniffers Dec 07 14:09:24 should i spend like 200€ for one of those super high end fritzbox routers with VDSL Dec 07 14:09:32 🤔 Dec 07 14:09:43 dsl? what do you need dsl for? Dec 07 14:11:44 connectivity Dec 07 14:11:58 get fibre Dec 07 14:12:03 countries with good phonelines can use DSL for highspeed network connectivity Dec 07 14:12:10 not all countries can do fibre yet Dec 07 14:12:13 "high speed" Dec 07 14:12:24 yeah, higher than a nullmodem Dec 07 14:12:24 80/20 is not high speed :< Dec 07 14:12:31 * buZz is on 10/1 Dec 07 14:12:43 10/1 is also not high speed :< Dec 07 14:16:39 ;) exactly Dec 07 14:16:45 but hey Dec 07 14:16:54 beats downloading pr0n jpegs on a 14k4 modem Dec 07 14:21:41 mmm, dialup pr0n Dec 07 14:22:03 where half of the fun was imagining what will be below Dec 07 14:25:55 KotCzarny: and -then- i would still have to dither the image for 20-30 minutes to display it on my monochrome monitor Dec 07 14:25:58 gud times Dec 07 14:26:34 yeah, imagination at work Dec 07 14:26:53 we actually had to use our brains instead of consuming ;) Dec 07 14:27:17 ^_^ Dec 07 14:27:37 i love ppl that get angry at me for not helping them understand some program Dec 07 14:27:44 after i just linked them the manual etc Dec 07 14:27:51 'CANT YOU JUST SAY HOW I SHOULD DO IT' Dec 07 14:28:03 'that wouldnt help you really' Dec 07 14:28:13 'OK I GIVE UP, THIS PROGRAM DOES NOT WANT USERS!' Dec 07 14:28:17 playing games without any manual or tutorial. bah, even without knowing the game's language Dec 07 14:33:11 buZz: c'mon, you should feel happy! My users state "THAT DAMN PROGRAM SHALL JUST DO WHAT I WANT!" Dec 07 14:33:29 DocScrutinizer05: ah not users, these are 'friends' Dec 07 14:33:36 that 'work in IT so have high skills' Dec 07 14:33:41 friends with benefits Dec 07 14:33:58 friends too, eveb gf, but no skills obviously Dec 07 14:34:30 ah well Dec 07 14:35:28 simplifying everything around us would result in reducing our skills to stating 'i want that' Dec 07 14:37:02 they would lose denoting skills , and drop it to 'i want' Dec 07 14:37:49 and in effect degradation, degeneration and decadentism Dec 07 14:38:39 decadence? Dec 07 14:38:56 dead can dance Dec 07 19:27:06 Hello. Does anyone has access to vcs.maemo.org logs to diagnose my push trouble ? Dec 07 19:27:09 git push origin 0.4.3 Dec 07 19:27:09 error: Cannot access URL https://vcs.maemo.org/git/keepassx/, return code 22 Dec 07 19:27:09 fatal: git-http-push failed Dec 07 19:27:12 error: failed to push some refs to 'https://vcs.maemo.org/git/keepassx' Dec 07 19:27:15 Dec 07 19:29:40 might be that someone has to authorize that project Dec 07 19:30:04 dont know which one of the techstaff is able Dec 07 19:30:10 I am member of the project already Dec 07 19:30:21 I have already pushed there in 2013 and 2014 Dec 07 19:31:15 but, you dont have to post code there, regular apt with sources is sufficient Dec 07 19:31:51 also, i think it doesnt matter if you did it before, new projects have to be authorized Dec 07 19:32:02 (i might be wrong, but that's what my memory remembers) Dec 07 19:32:06 is *.maemo.org fully functional again? Dec 07 19:38:37 hmm Dec 07 19:39:07 https://vcs.maemo.org/git/?p=keepassx;a=shortlog Dec 07 20:00:28 OK... quite few more years earlier... Dec 07 20:01:10 are you sure you are the dev of THIS particular project and not one typo away? Dec 07 20:01:11 By the way how may I get grants to push to APT extra-devel repository ? Dec 07 20:01:28 i think everyone can push to extras-devel Dec 07 20:02:18 and that's the fun part of extras-devel. never ever do apt-upgrade on it ;) Dec 07 20:02:30 I logged in with my keepassx credential into project and account member is mine, sure of it: https://garage.maemo.org/projects/keepassx/ Dec 07 20:03:25 KotCzarny: OK so I have to learn the right way to push into extras-devel... that is new to me Dec 07 20:03:50 ~ping Dec 07 20:03:56 bot is still missing. eh Dec 07 20:04:00 check wiki Dec 07 20:04:48 Found http://wiki.maemo.org/Uploading_to_Extras-devel Dec 07 20:04:50 Thanks Dec 07 23:16:36 guys omp really not support web links? Dec 07 23:18:29 sad that smplayer/mplayer cant use hw acceleration for playing webstreams... **** ENDING LOGGING AT Thu Dec 08 03:00:01 2016