-
Posts
13,543 -
Joined
Content Type
Forums
News
20th
EduGeek EDIT Conference
Blogs
Everything posted by Geoff
-
There are compromised systems out on the internet that will scan whole ip blocks looking for open ports to well known services (SSH, Telnet, FTP, Netbios, Kerberos, SIP, NIS, HTTP, etc) and once they find a system will attempt to brute force it via dictonary attacks. It's just a fact of life on the internet these days. So as long as you have your firewalls setup right it should not be an issue. On my Linux boxes I go beyond this though. I have IPTables rate limits, fail2ban, etc setup so these scans don't waste too many system resources..
-
Short answer is yes. In three easy steps: Make sure you basic routing works on the packetfence machine. IPTables to transparent proxy HTTP to squid. Setup squid to use your upstream proxy.
- 23 replies
-
- boyd
- packetfence
-
(and 1 more)
Tagged with:
-
I have the 10k mAh Anker charger and it's awesome. It's about the same size a Galaxy Note 2 (thicker though) so it's easily pocketable too. http://www.amazon.co.uk/Lightning-Sensation-Blackberry-connectors-customized/dp/B0063AAIRG/ref=sr_1_1
-
No not really, they will just take advertising money from less savoury industries (gambling, porn, etc). Besides, there are far worse places on the internet than ask.fm, for example 4chan. (NSFL)
-
[android] Automatically reject private numbers?
Geoff replied to pete's topic in Mobile Devices & Tablets
Can confirm CyanogenMod 10 has this setting on my Samsung S2. However it's not where the article lists: Phone -> Menu Key -> Settings -> Blacklist Enable Blacklist Enable Private Numbers -
If you have multiple default routes on one IP subnet then the router (should) load balance traffic between them. The only other scenario is more advanced where you add QoS or Costs to routes. Then the router will follow these rules to route traffic.
- 4 replies
-
- 5412zl
- multiple gateways
-
(and 1 more)
Tagged with:
-
It is a requirement for packetfence to function that you can assign multiple dynamic VLANs to an ESSID via 802.1X/RADIUS auth and/or SNMP.
- 23 replies
-
- boyd
- packetfence
-
(and 1 more)
Tagged with:
-
Only happens when you muck with the settings (which have a big fat warning on them) and change them away from the defaults. The defaults for JBIG2 compression are set to lossless. http://www.dkriesel.com/_media/blog/2013/colorqube.jpg
-
Lossy compression leads to data loss. Hardly news.
-
No, you shouldn't have the MAC detection VLAN be routable anywhere.
- 23 replies
-
- boyd
- packetfence
-
(and 1 more)
Tagged with:
-
Little bit rough but: $img = imagecreatefromstring(base64_decode($data)); if($img !== false) { imagejpg($img,$output_file); imagedestroy($img); }
-
I also ran into this yesterday I did tweet @ZeroHour and he tweeted to both myself and others with the above.
-
This is only relevant if you have switches set to use Link Change SNMP Traps and MAC notification SNMP Traps. Basically there's a delay between the device being connected (Link Change) and the switch working out what the MAC address (MAC notification) of the device is. During that time packetfence will isolate the device in the MAC detection VLAN. The MAC detection VLAN should have absolutely nothing on it and be unroutable. Your 'public' (and optionally 'guest') ESSID should have no wifi authentication on it. Basically clients connect to the 'public' ESSID then packetfence allows them access to the 'private' ESSID on successful authentication (via captive portal). Your public ESSID should have minimal services available (just enough to get people to the captive portal and fix whatever 'issues' they might have preventing them from getting authorised). Packetfence will control the VLAN assignment for clients via RADIUS attributes. Packetfence will throw clients off with SNMP deauthentication traps. I would not recommend hiding ESSIDs, it doesn't help with security and will confound your users. If you're using 802.1X then there is only really RADIUS/SNMP traffic involved. You will need to run some form of DHCP/DNS/etc for your public clients before they auth but this doesn't have to be packetfence.
- 23 replies
-
- boyd
- packetfence
-
(and 1 more)
Tagged with:
-
As long as he gets lines like he did in The Loop, this'll be awesome.
-
The OPs hoverfly actually feeds on nectar. So no eating the bad bugs. It will help with plant pollination though.
-
It's only been spotted in the SE UK since 1940 and has steadily been moving North and West.
-
It's a hoverfly, pretending to look like a bee. Volucella Hovers
-
I saw it at the iMax in manchester in 3D. There's no need to watch it in 3D unless you like 3D rain (and an occasional fish) in your face for most of the film.
-
Ok, as I suspected pulseaudio doesn't know about your HDMI audio. This sounds a lot like this kernel bug. https://bugs.launchpad.net/ubuntu/+source/linux/+bug/1173769 Additionally this blog post seems relevant. http://www.benjiegillam.com/2008/10/working-hdmi-audio-on-ati-graphics-card/
-
MP behind the announcement gets her blog hacked and filled with porn. Displays a complete lack of technical understanding on twitter. Blames another blogger. Is probably going to get sued. BBC News - Net block MP Claire Perry in spat over porn hack
-
hrum ok, what's the output of 'pactl list cards'
-
The figures from OFCOM (July 2013) compared to the previous report (May 2013) show an overall increase of 18% in piracy for the 3 month period, although Ofcom pointed out that the rise in piracy coincides with an overall boost in the proportion of internet users accessing digital media content from 57% to 60% in the 3 month period.
-
Measured how? and by who? How legal are those streaming services? I have different numbers here (from OFCOM).
-
It will just drive people to use methods (like TOR or VPNs) to get the content that are even harder to police. Look at what's happening with online piracy for example, the drive by the music and movie industries to stamp it out is just driving the technology forward even faster. Depends on the mirror you get. Some of the IPs are blacklisted.
