00:06<|Anthony|>I'm preparing a home server where people on the outside will be able to use ssh and ftp to access it. Is SELinux something i should read up on, or is it unnecessary?
00:07<ext5>i mean like if i use apt-get remove "something". in order to complete the comman i would also have to issue apt-get autoremove. i dont understand a simple program have so many dependency
00:08-!-two [] has joined #debian
00:08<sney>ext5: most "simple" programs depend on multiple libraries that might not be used by other programs.
00:08<sney>|Anthony|: it's not a bad idea to at least read up on it and make the decision yourself.
00:11<|Anthony|>sney, i am. i started here but the info is kinda terse. I'm off to now
00:11<k00n>|Anthony|: selinux might be overkill for a home server, but heh no amount of security is too much. I would first focus on the simpler steps like ssh-keys and disabling root login for ssh, and jails for FTP
00:12<|Anthony|>k00n, i'm comfortable with configuring ssh, and my firewall rules are fairly stringent. I thought jails is a bsd thing?
00:12<k00n>|Anthony|: jails as in jail FTP users to specific dirs
00:13<k00n>that can be done with vsftpd
00:13<sney>or just eschew FTP altogether and use sftp, so you only need to secure one daemon
00:13<k00n>or that ^^^
00:13<|Anthony|>setting up a ftp server is a virgin voyage for me and i'll probably forgo it at the start
00:14<k00n>i suggest SFTP over FTP any day. you can do sftp-only jails fairly easily too.
00:15<|Anthony|>i will remember that for when i am ready
00:15<|Anthony|>ftp would make it easier for the folks to manage
00:15-!-abrotman [] has joined #debian
00:20<chealer>|Anthony|: I don't know SELinux, but it's a security mecanism to limit damage in case something goes wrong. if you have no special security needs, just follow basic security guidelines and avoid something going wrong in the first place.
00:21<|Anthony|>honestly, i'd like to define acl such that folks can only access stuff in a shared folder, use the top command and just a few others
00:22<|Anthony|>setting up ssh so that only I can get in and keeping the firewall tight is something i'm familiar with. allowing others in and keeping a tight ship is new to me
00:23<|Anthony|>so i'm kinda treading lightly on the project
00:24<sney>and even if it turns out to be unnecessary, it's still useful knowledge to have
00:24-!-Calinou [] has joined #debian
00:25<|Anthony|>i'm confident that i'll be able to keep folks in just the one machine. ie prohibit them from traversing the rest of the network, but i'm not familiar with securing a single machine for multiple users
00:25<|Anthony|>agreed sney. that's kinda the point of the whole project
00:26<chealer>ext5: you never have to issue apt-get autoremove, unless you need to free disk space
00:28<Fernand72>any help with fwbuilder anyone?
01:04-!-debhelper [] has joined #debian
01:04-!-Villadelfia [Villadelfi@] has joined #debian
01:05-!-mode/#debian [+o debhelper] by ChanServ
01:05-!-dpkg [] has joined #debian
01:06-!-dondelelcaro [] has joined #debian
01:06-!-don_armstrong [] has joined #debian
01:06-!-dondelelcaro [] has quit []
01:06-!-don_armstrong [] has quit []
01:06-!-dondelelcaro [] has joined #debian
01:07-!-fayaz [~quassel@] has joined #debian
01:07-!-mcoffin [] has quit [Quit: Leaving]
01:07-!-hazard2 [] has quit [Quit: This computer has gone to sleep]
01:10-!-mode/#debian [+l 469] by debhelper
01:10<jm_>yes ROFFLE
01:11<siddy>I was given this computer to fix... and an upgrade messed up the xserver... well, it boots up and you're lucky to get a root shell...
01:11<siddy>I forget this stuff... grrrr
01:12<siddy>I have a good idea what happened... the hardware is nforce 4 and geforce 6150se and nvidia doesn't support this hardware anymore with the proprietary driver so I need to either reduce it to vesa or use nouveau
01:12<siddy>so, if I remove the nvidia stuff... it should switch to using nouveau...right?
01:13<thinkerweb>siddy, if you try to remove nvidia stuff it will probably remove all X I think
01:13<jm_>which version of nvidia driver? and legacy proprietary driver will most likely work if the regular oen doesn't
01:14<siddy>it should re-write xorg? I mean, it should load the nouveau driver?
01:15-!-ext5 [] has joined #debian
01:15<siddy>jm_, I have no idea... lol.... I just can't remember the commands to remove it... so far, I think there is autoremove and purge
01:16<siddy>apt-get remove nvidia-* -> would that work?
01:16<siddy>afaik, this is the main stuff here... but, I want it removed... :) -> nvidia-glx, nvidia-kernel-common, nvidia-kernel-dkms, nvidia-kernel-source, xserver-xorg-video-nvidia
01:16<siddy>either I have to use a nvidia legacy driver or nouveau
01:16<thinkerweb>yeah, there is apt-get purge package-name, which will delete the config files too
01:18<ext5>yup the i usually use apt-get purge after i remove any app to make the system more clean and lean
01:19<siddy>apt-get purge what, though? nvidia-*?
01:20<siddy>you wouldn't believe it but I've done this before... lol
01:20<siddy>my memory is crap sometimes... well, most of the time, i guess
01:20<thinkerweb>yeah, my memory fails me too
01:21<thinkerweb>I did some video driver stuff, but I can't remember it at all
01:21<siddy>I've installed nvidia drivers both the debian and nvidia way... had to deal with driver / module conflicts that resulted in X Server being screwed up... usually being thrown to a root shell
01:21<simonlnu>why not just run aptitude and hit / and search 'nvidia' ?
01:21<thinkerweb>siddy, whats wrong with your video and what driver?
01:21<jm_>siddy: I don't think apt-get can do nvidia-*, aptitude sure can
01:22<ext5>siddy, a short workaround is to use a wild card like "apt-get remove nvidia*"
01:22<jm_>actually apt-get can
01:22<siddy>this is on another computer... don't have it set up yet... :)
01:22<siddy>ext5, yeah, that's what I was thinking.... smth like that
01:23<siddy>thinkerweb, someone thought it would be good to upgrade everything ... lol
01:24<siddy>i think both nvidia and nouveau were installed or the nvidia driver was overriding nouveau
01:24<siddy>wait, no... i think the upgrade had just installed the nvidia driver since it wasn't installed before and so it is not supported by this hardware
01:26<siddy>2.6.32 is debian stable... I think
01:44<siddy>I would use it
01:44-!-ngranek [~bigjocker@] has joined #debian
01:48<jm_>EmleyMoor: experimental has 16.0.1-1 so it's probably missing the fix
02:25-!-mlundblad [~marcus@] has joined #debian
02:42-!-thinkerweb [] has quit [Quit: Leaving]
02:43-!-perlwizard [~x@] has quit [Ping timeout: 480 seconds]
02:52<jm_>iceweasel 16.0.1 for i386 is already there, hopefully amd64 will show up shortly too
03:37-!-pinqvin [] has joined #debian
03:41-!-samsul [~samsul@] has joined #debian
03:44-!-ypwong [~anthony@2001:c08:3700:ffff::563] has joined #debian
03:45-!-leeping [] has quit [Read error: Connection reset by peer]
03:45-!-leeping [] has joined #debian
03:45-!-jmux [] has joined #debian
03:46-!-babilen [] has quit [Quit: leaving]
03:46-!-Netsplit <-> quits: Knogle, hide, Airwave, phorce1_home, davroman1ak, zW, kriger, m0, avtobiff, warp10, (+47 more, use /NETSPLIT to show all of them)
03:47-!-Ehtyar [] has quit [Quit: Going!]
03:47-!-drewdavis [~drew@] has quit [Quit: Konversation terminated!]
03:47-!-Netsplit over, joins: davi, tylerstrayhan-, prem, devil, mlundblad, kriger, ext5, swex, Knogle, warp10 (+11 more)
03:47-!-Netsplit over, joins: Hydroxide, cdlu, gnusosa, crib, funkyHat, Zeroedout, jticket, m0, Pryon, shepherd1977 (+26 more)
03:48-!-devil [] has quit [Remote host closed the connection]
03:48-!-devil [] has joined #debian
03:50-!-_Qman [~Q@] has joined #debian
03:50-!-trifolio6 [] has joined #debian
03:52-!-sharpthings [] has joined #debian
03:52-!-kamis [~kam@] has quit [Remote host closed the connection]
03:52-!-kam [~kam@] has joined #debian
03:53-!-funkyHat [] has quit [Read error: Connection reset by peer]
03:54-!-funkyHat [] has joined #debian
03:54-!-omry [] has joined #debian
03:54-!-eof_ [~eof@] has joined #debian
03:54-!-sharpthings [] has quit [Remote host closed the connection]
03:55-!-hide [~arnoldas@] has quit [Ping timeout: 480 seconds]
03:55-!-fred__ [] has joined #debian
03:56-!-eof [~eof@] has quit [Ping timeout: 480 seconds]
03:56-!-fred_ [] has quit [Read error: Connection reset by peer]
04:01-!-cybersphinx [] has joined #debian
04:04-!-jimmaw [~jimmaw@] has joined #debian
04:05-!-samsul [~samsul@] has quit [Ping timeout: 480 seconds]
04:07-!-noahfx [~noahfx@] has quit [Quit: Lost terminal]
04:08-!-ao2 [~u@2001:1418:117::1] has joined #debian
04:10-!-resmo [] has joined #debian
04:10-!-jimmaw [~jimmaw@] has quit [Quit: Leaving]
04:10-!-wintellect [] has joined #debian
04:10-!-cybersphinx_ [] has joined #debian
04:11-!-toabctl [~toabctl@] has joined #debian
04:14-!-magnetic [] has joined #debian
04:15-!-domo [] has joined #debian
04:16-!-toabctl [~toabctl@] has quit [Quit: Ex-Chat]
04:17-!-domo [] has quit []
04:18-!-cybersphinx [] has quit [Ping timeout: 480 seconds]
04:18-!-kohakhan [~waqarazee@] has joined #debian
04:19-!-acil [~anois@] has joined #debian
04:20-!-mode/#debian [+l 484] by debhelper
04:20-!-acil [~anois@] has quit []
04:22-!-WaqarAzeem [~waqarazee@] has quit [Ping timeout: 480 seconds]
04:28-!-WaqarAzeem [~waqarazee@] has joined #debian
04:48<derpalicious>wireless tools doesnt see AR9485
04:48<derpalicious>anyone know of a fix?
04:48<dpkg>Atheros AR9485-based wireless LAN devices (e.g. PCI ID 168c:0032) are supported by the Linux kernel as of version 2.6.39, ask me about <ath9k>.
04:48<themill>^^ that would imply you need the kernel from backports; /msg dpkg bdo kernel
04:49<derpalicious>2.6.32-5 and it sure isnt seeing it
04:49<derpalicious>oh my kernel is too old
04:49<derpalicious>see the term "backports" makes a noob think of older software
04:50<derpalicious>so, erm, Ive built my own kernels before and 9 times out of 10 they fail
04:50<derpalicious>any easy way to do it with aptitude?
04:50<derpalicious>oh /msg dpkg bdo kernel got cha
04:51<derpalicious>k its running wit aptitude -t squeeze-backports install linux-image-`uname -r|sed 's,[^-]*-[^-]*-,,'`
04:51<derpalicious>yay 3.2
04:52<derpalicious>u guise r awesome, whomever maintains this irc
04:52<derpalicious>I just had one of my silly windows users get infected with a NASTY and verulent rootkit
04:52<derpalicious>/tmp/tmpbXMLtd (END)
04:52<derpalicious> what do I press to exit this??
04:53<derpalicious>q ok
04:53-!-Slex [] has joined #debian
04:53<derpalicious>switchin them to debian
04:55-!-babilen [] has joined #debian
04:56-!-debalance [] has quit [Ping timeout: 480 seconds]
05:02<derpalicious>yay I got wifi
05:02-!-fike [~Fernando@] has joined #debian
05:02<derpalicious>awesome, thanks
05:06-!-Knogle [] has left #debian []
05:42-!-S_WO [] has joined #debian
05:43-!-ian [] has joined #debian
05:43-!-aloy [] has joined #debian
05:43-!-ian is now known as iflema
05:52<zW>Hi :)
05:53<zW>Is there a way to block users opening a socket in linux ?
05:53<zW>I have a chrooted ssh server where people only have x amount of commands they have
05:53-!-Japs_88 [] has joined #debian
05:53<zW>but they can create a socket in php on a certain port, it is firewalled ofcourse, but is there a linux way to disable/limit that ?
05:54<jm_>zW: it is possible to certain extent using capabilities, or these days using seccomp for example
06:01-!-rubs [~ruben@] has joined #debian
06:27-!-Jekyll [~whodare@] has quit [Read error: Connection reset by peer]
06:44<grammoboy>any idea what this could be?
06:44<grammoboy>/opt/Funambol/tools/jre-1.5.0/jre/bin/java: 1: Syntax error: “(” unexpected
06:45-!-magnetic [] has joined #debian
06:45<SynrG>why does Funambol embed its own copy of java?
06:48-!-kom [~kom@] has quit [Remote host closed the connection]
06:48<grammoboy>I did install openjdk-6-jdk openjdk-6-jre though
06:49-!-kom [~kom@] has joined #debian
07:09-!-rx [~rx@] has joined #debian
07:18-!-tilbo [] has joined #debian
07:22-!-zem_ [] has joined #debian
07:24-!-zem [] has quit [Ping timeout: 480 seconds]
07:41-!-macfreak [~macfreak@] has joined #debian
07:42<devil>siddy: the 2nd one without autoremove will work.
07:50-!-babilen [] has joined #debian
07:50-!-mode/#debian [+l 504] by debhelper
08:10-!-ejeanvoi [] has left #debian []
08:15-!-angasule [] has quit [Ping timeout: 480 seconds]
08:40-!-WaqarAzeem [~waqarazee@] has quit []
08:53-!-Leader-One [] has joined #debian
08:53-!-powerthrash [~powerthra@] has quit [Quit: Leaving]
09:14-!-pasigero [~pasigero@] has left #debian []
09:47-!-dragondon [~dragondon@] has joined #debian
10:02-!-tensorpudding_ [~michael@] has joined #debian
11:31-!-heiserhorn [~michele@] has quit [Ping timeout: 480 seconds]
11:56-!-sitinavra [] has joined #debian
11:57-!-arios [~arios@] has joined #debian
11:57-!-arios [~arios@] has quit []
11:59-!-wissem [~localhost@] has joined #debian
11:59-!-kriller__ [] has joined #debian
12:11-!-Calinou [] has joined #debian
13:03-!-Emmanuel_Chanel [] has quit [Quit: Leaving]
13:42-!-xubuntu [] has joined #debian
14:22-!-Biondina [~Biondina@] has joined #debian
14:32<rhollan>trying to use the SAME value in different places, but first obtained interactively
14:43-!-rhollan [~hollan@] has quit [Quit: Leaving]
14:51<cinch>+ all integrated audio cards suck
15:40-!-myk42 [] has joined #debian
16:51-!-Greg [] has quit [Quit: Ex-Chat]
17:23-!-m42 [] has joined #debian
18:16-!-warp10` [] has joined #debian
19:32-!-sidmo [] has joined #debian
20:44-!-thunderrd [~thunderrd@] has quit [Ping timeout: 480 seconds]
21:28-!-dioz [~dioz@2001:470:d:e3::1] has quit [Read error: Connection reset by peer]
23:10-!-mode/#debian [+l 468] by debhelper
23:26-!-debsan [~debsan@] has joined #debian
