Skip to content
  • Categories
  • Recent
  • Tags
  • Popular
  • World
  • Users
  • Groups
Skins
  • Light
  • Brite
  • Cerulean
  • Cosmo
  • Flatly
  • Journal
  • Litera
  • Lumen
  • Lux
  • Materia
  • Minty
  • Morph
  • Pulse
  • Sandstone
  • Simplex
  • Sketchy
  • Spacelab
  • United
  • Yeti
  • Zephyr
  • Dark
  • Cyborg
  • Darkly
  • Quartz
  • Slate
  • Solar
  • Superhero
  • Vapor

  • Default (No Skin)
  • No Skin
Collapse
Brand Logo

agnos.is Forums

  1. Home
  2. Programmer Humor
  3. Peak security

Peak security

Scheduled Pinned Locked Moved Programmer Humor
programmerhumor
93 Posts 57 Posters 3 Views
  • Oldest to Newest
  • Newest to Oldest
  • Most Votes
Reply
  • Reply as topic
Log in to reply
This topic has been deleted. Only users with topic management privileges can see it.
  • P [email protected]

    Before you make a change, do this in a screen-session:

    sleep 300 && iptables-restore old_fw_rules.bak

    I This user is from outside of this forum
    I This user is from outside of this forum
    [email protected]
    wrote on last edited by
    #71

    Yeah except it would be iptables-restore < old_fw_rules.bak

    P 1 Reply Last reply
    1
    • eager_eagle@lemmy.worldE [email protected]

      permission denied

      fuuuu

      I This user is from outside of this forum
      I This user is from outside of this forum
      [email protected]
      wrote on last edited by
      #72

      Found the debian user.

      eager_eagle@lemmy.worldE 1 Reply Last reply
      1
      • Q [email protected]

        ^This^ ^is^ ^a^ ^joke,^ ^I^ ^didn't^ ^really^ ^lock^ ^myself^ ^out^

        T This user is from outside of this forum
        T This user is from outside of this forum
        [email protected]
        wrote on last edited by
        #73

        Most secure box is the one that does nothing.

        1 Reply Last reply
        12
        • I [email protected]

          Found the debian user.

          eager_eagle@lemmy.worldE This user is from outside of this forum
          eager_eagle@lemmy.worldE This user is from outside of this forum
          [email protected]
          wrote on last edited by
          #74

          user permissions is a debian thing now?

          I 1 Reply Last reply
          3
          • I [email protected]

            Yeah except it would be iptables-restore < old_fw_rules.bak

            P This user is from outside of this forum
            P This user is from outside of this forum
            [email protected]
            wrote on last edited by [email protected]
            #75

            Fun fact: When you do iptables-save, you have to redirect the output if you want to save it to a file. But when you use iptables-restore, you don't need to pipe it back in, you can just use the filename!

            I 1 Reply Last reply
            5
            • P [email protected]

              Fun fact: When you do iptables-save, you have to redirect the output if you want to save it to a file. But when you use iptables-restore, you don't need to pipe it back in, you can just use the filename!

              I This user is from outside of this forum
              I This user is from outside of this forum
              [email protected]
              wrote on last edited by
              #76

              It wasn't always that way. At one time you had to so I still do.

              P 1 Reply Last reply
              3
              • eager_eagle@lemmy.worldE [email protected]

                user permissions is a debian thing now?

                I This user is from outside of this forum
                I This user is from outside of this forum
                [email protected]
                wrote on last edited by
                #77

                A long time ago, Debian 8 or so it was a bug with Debian. Something about the command running without root despite the sudo command.

                1 Reply Last reply
                2
                • N [email protected]

                  Happened to me once. Had a little Pi at my parent's house and that was a nice excuse to visit them.

                  A This user is from outside of this forum
                  A This user is from outside of this forum
                  [email protected]
                  wrote on last edited by
                  #78

                  Except when you get there and don’t want to talk or do all the meeting and greeting until you know the server still works.

                  T 1 Reply Last reply
                  4
                  • A [email protected]

                    It's iDRAC.

                    I'd say that RAC is the overarching term for different Dell Solutions, see Dell Remote Access Configuration Guide

                    DRACT supports the following types of RACs that support RACADM commands:

                    • Integrated Dell Remote Access Controller 8 (iDRAC8)

                    • Integrated Dell Remote Access Controller 7 (iDRAC7)

                    • [...]

                    • Chassis Management Controller (CMC) for Dell PowerEdge M1000e and PowerEdge VRTX

                    • [...]

                    And it's just shorter and easier to say ¯\_(ツ)_/¯

                    but that's not as dumb as when he calls the SuperMicro system "iLO". That's IPMI. We don't even own any HPE. I've no idea why he's stuck on iLO.

                    Perhaps his first encounter with remote management was with iLO and he just thinks that this is how it's called. It's "integrated Lights Out", and "Lights-Out Management" as well as "Remote Access Controller" both are generic terms (and I suspect that this is why Dell adds an “iD” in front of its product names).

                    But we are way to close to the “GNU/Linux Copypasta” than I would like.

                    dbtng@eviltoast.orgD This user is from outside of this forum
                    dbtng@eviltoast.orgD This user is from outside of this forum
                    [email protected]
                    wrote on last edited by
                    #79

                    Mmm. Ya ya. No argument. But its iDRAC. I've had to sit through enough propaganda. I'm pretty sure about this.

                    1 Reply Last reply
                    0
                    • I [email protected]

                      It wasn't always that way. At one time you had to so I still do.

                      P This user is from outside of this forum
                      P This user is from outside of this forum
                      [email protected]
                      wrote on last edited by
                      #80

                      Totally! I still catch myself doing that sometimes. Old habits die hard

                      1 Reply Last reply
                      1
                      • B [email protected]

                        Wireguard is a VPN protocol, so you are able to tunnel into their router to…do what exactly?

                        A This user is from outside of this forum
                        A This user is from outside of this forum
                        [email protected]
                        wrote on last edited by
                        #81

                        It let's me remote into their LAN, thus bypassing the firewall

                        B 1 Reply Last reply
                        0
                        • appoxo@lemmy.dbzer0.comA [email protected]

                          If you have the HTML5 option you should be on a pretty recent firmware.

                          Interesting that you'd prefer going (literally) analog connection rather than over the IPMI.

                          Q This user is from outside of this forum
                          Q This user is from outside of this forum
                          [email protected]
                          wrote on last edited by
                          #82

                          The latest version of iLO4 is from 2023

                          appoxo@lemmy.dbzer0.comA 1 Reply Last reply
                          0
                          • Q [email protected]

                            The latest version of iLO4 is from 2023

                            appoxo@lemmy.dbzer0.comA This user is from outside of this forum
                            appoxo@lemmy.dbzer0.comA This user is from outside of this forum
                            [email protected]
                            wrote on last edited by
                            #83

                            You know, I wanted to say "Bet!" and proove your wrong as I couldnt believe they never went past 2023 for the firmware.
                            Turns out that was the latest.

                            But I do know they have more recent firmware uploads for the UEFI than 2023. ^(A year younger but no less nore recent/s)

                            1 Reply Last reply
                            1
                            • A [email protected]

                              Except when you get there and don’t want to talk or do all the meeting and greeting until you know the server still works.

                              T This user is from outside of this forum
                              T This user is from outside of this forum
                              [email protected]
                              wrote on last edited by
                              #84

                              Relevant XKCD

                              1 Reply Last reply
                              12
                              • A [email protected]

                                It let's me remote into their LAN, thus bypassing the firewall

                                B This user is from outside of this forum
                                B This user is from outside of this forum
                                [email protected]
                                wrote on last edited by
                                #85

                                Please forgive the ignorance here. What are you trying to do? I thought you were trying to reboot an offline server. I’m probably just confused!

                                A 1 Reply Last reply
                                1
                                • B [email protected]

                                  Please forgive the ignorance here. What are you trying to do? I thought you were trying to reboot an offline server. I’m probably just confused!

                                  A This user is from outside of this forum
                                  A This user is from outside of this forum
                                  [email protected]
                                  wrote on last edited by
                                  #86

                                  Well, the original post (as in the image) is about locking yourself out of a remote server by changing a firewall rule, thus needing to drive to the server to access it locally.

                                  By using wireguard to tunnel into the router, you can remotely enter the LAN, thus bypassing the firewall, as if you were accessing the server locally.

                                  B 1 Reply Last reply
                                  0
                                  • A [email protected]

                                    Well, the original post (as in the image) is about locking yourself out of a remote server by changing a firewall rule, thus needing to drive to the server to access it locally.

                                    By using wireguard to tunnel into the router, you can remotely enter the LAN, thus bypassing the firewall, as if you were accessing the server locally.

                                    B This user is from outside of this forum
                                    B This user is from outside of this forum
                                    [email protected]
                                    wrote on last edited by
                                    #87

                                    Ohhhhh gotcha! Thanks for explaining. I think I just invented the offline part in my head lol

                                    1 Reply Last reply
                                    0
                                    • B [email protected]

                                      Do you mind explaining the details? I’m trying to learn as much as possible!

                                      H This user is from outside of this forum
                                      H This user is from outside of this forum
                                      [email protected]
                                      wrote on last edited by [email protected]
                                      #88

                                      Most corporate network devices like Cisco will reset their config to the one written in memory when they lose power.

                                      So in that case, just unplug and replug them to restore to previous config.

                                      Just make sure you write your new config to memory or it will reset when there is ever a power failure.

                                      1 Reply Last reply
                                      2
                                      • Q [email protected]

                                        ^This^ ^is^ ^a^ ^joke,^ ^I^ ^didn't^ ^really^ ^lock^ ^myself^ ^out^

                                        rmuk@feddit.ukR This user is from outside of this forum
                                        rmuk@feddit.ukR This user is from outside of this forum
                                        [email protected]
                                        wrote on last edited by
                                        #89

                                        I'll always be grateful for the firewalls like OpenWRT that will automatically revert any changes if you don't log back in after a few minutes (at least on the web interface). I'm not proud of how many times that's saved me.

                                        1 Reply Last reply
                                        9
                                        • B [email protected]

                                          Do you mind explaining the details? I’m trying to learn as much as possible!

                                          randint@lemmy.frozeninferno.xyzR This user is from outside of this forum
                                          randint@lemmy.frozeninferno.xyzR This user is from outside of this forum
                                          [email protected]
                                          wrote on last edited by
                                          #90

                                          So I connected through ssh back home to fiddle with the router settings, and in the PPPoE settings (where you set a pair of username and password that your router sends to the ISP such that the ISP knows you and knows what IP to assign to you) I made a typo, and apparently that instantly killed the internet connection at home and also for me. I had to call my mom to instruct her to fix the typo in the username. TBH I don't know that much about PPPoE either, I only do it so that the ISP assigns us the same IP address every time.

                                          1 Reply Last reply
                                          1
                                          Reply
                                          • Reply as topic
                                          Log in to reply
                                          • Oldest to Newest
                                          • Newest to Oldest
                                          • Most Votes


                                          • Login

                                          • Login or register to search.
                                          • First post
                                            Last post
                                          0
                                          • Categories
                                          • Recent
                                          • Tags
                                          • Popular
                                          • World
                                          • Users
                                          • Groups