Monday, 2009-03-16

*** rossand has quit IRC04:15
*** Alex|off is now known as Alex|06:13
*** Alex| is now known as Alex|off06:41
*** Alex|off is now known as Alex|07:05
*** grantc_offline is now known as grantc08:20
*** Alex| is now known as Alex|off09:40
*** Alex|off is now known as Alex|09:52
*** Alex| is now known as Alex|off09:58
*** Alex|off is now known as Alex|10:07
*** Alex| is now known as Alex|off11:07
*** Alex|off is now known as Alex|11:08
*** troal01 has joined #ingres11:59
*** rossand has joined #ingres12:06
*** ChanServ sets mode: +o rossand12:06
*** Mart|n has joined #ingres12:12
Mart|nhi12:12
grantcHi Mart|n12:13
Mart|nhi12:13
Mart|nhows u12:13
grantcI am fine, and you?12:13
Mart|nim ok12:13
Mart|nsuch a ambiquos  reply12:13
grantcenglish is a great language :)12:14
grantcwhat brings you to #ingres?12:15
Mart|nu12:17
Mart|nelse i would leave12:17
grantco i c12:17
Mart|nso how are u12:17
grantcso Mart|n what time is it where you are?12:20
Mart|nearly12:21
grantcit's earlier here12:22
*** elPiola has joined #ingres14:05
*** toumi01 has joined #ingres14:09
*** DarylM has joined #ingres14:12
*** test_dummy has joined #ingres15:13
*** grantc changes topic to "Ingres Chat | Wiki - http://community.ingres.com/wiki | Forums http://community.ingres.com/forum | Goto http://irc.planetingres.org for the channel archives"15:13
*** test_dummy has left #ingres15:13
*** Mart|n has quit IRC15:14
*** mull has joined #ingres15:22
*** Alex| is now known as Alex|off16:11
*** DerMeister has joined #ingres17:03
*** Alex|off is now known as Alex|17:09
*** NoeJeko has joined #ingres17:31
NoeJekohi Alex17:32
Alex|hi17:32
NoeJekoI can't open that .ics file - I'm on OWA from home17:32
NoeJekosick =[17:32
Alex|guess thunderbird doesn't forward invites as outlook expects them17:32
Alex|let's see if I can do it from owa17:33
Alex|next try17:33
NoeJekoah that worked17:34
NoeJekothat's during our weekly IT staff meeting so 30 mins prior may not work, but i should be able to slip away for that17:34
Alex|we can also do it on Wed17:35
NoeJekowednesday would be perfect17:35
Alex|ok. You already have switched to/off DST, right?17:36
NoeJekoyeah we switched last weeked or so17:37
Alex|then your 8am should be my 4pm... we can also do it 9am/5pm17:37
NoeJekowhatever works out best for you - im flexible =]17:38
grantcstill too early for him :)17:38
Alex|;)17:38
Alex|flexible is good... I'm in at 8am my time :p17:38
NoeJekoi tried that for the first few months... always floated in around 9am =[17:39
grantcNoeJeko, i have the same problem - commuter traffic is a nightmare17:39
Alex|let's do 9am then...17:39
NoeJekoit also doesn't help that californians cannot drive - every day there's 1-6 crashes along the freeway17:40
Alex|shouldn't take too long... can you set up webex with desktop sharing?17:40
NoeJekoah - i can; i'll get that set up and forward you the invite email17:41
NoeJeko9 am until...? 10:30?17:41
Alex|great... maybe we can take a quick look at the code.... 10 should be enough17:41
NoeJekoi forwarded you the webex invite17:46
Alex|thanks17:46
NoeJekosure thing17:57
*** troal01 has left #ingres18:24
*** troal01 has joined #ingres18:29
*** troal01 has left #ingres19:55
*** troal01 has joined #ingres20:01
*** [1]Gerhard has joined #ingres20:24
Alex|NoeJeko ?20:31
NoeJekoworking on it20:32
Alex|a bot grabbing content or a kiddy?20:32
Alex|all from the same ip20:32
*** NoeJeko has quit IRC20:32
*** NoeJeko has joined #ingres20:33
NoeJekowth20:33
Alex|how many connections do you allow?20:34
NoeJekoIP address was denied in server config20:35
NoeJekoim not sure, its whatever is default for mysql20:35
NoeJekohowever my forum currently has 385 online with spikes up to 61520:35
NoeJekoand we don't have this issue20:35
Alex|the server doesn't seem to be impressed, load is under 120:35
Alex|it's just the connection limit20:36
NoeJekousually i see these in direct attacks on the mysql server20:36
NoeJekodoes this IP seem familiar?20:37
NoeJeko10.255.253.23420:37
Alex|no20:38
NoeJekothat's not usda01's address20:38
NoeJekobut it's connecting to the mysql server20:38
Alex|from the subnet I would think it's rackspace20:39
NoeJekoyeah um..20:39
NoeJekoif you're on vpn20:39
NoeJekoand you go http://10.255.253.234/20:39
NoeJeko... it gives you ingres.com20:39
Alex|ah20:39
NoeJekobut it doesn't show up on /sbin/ifconfig20:40
NoeJekoi sent a ote to phil trying to figure out where that host resides20:43
NoeJekoits impossible to tell whether that was malicious or not20:45
NoeJekoas our site users have this disgustingly annoying habit of spamming <F5> or <Ctrl+R> when a page doesn't load20:45
Alex|when it's just one IP I don't think it was a real attack but I know of some bots that grab huge amounts of data over many connections.. caching, etc..20:47
Alex|a satelite ISP once grabed several GBs per hour from our forum... we had to blacklist them20:47
NoeJekoyeah i don't think it was a real attack either20:47
NoeJekoprobably an annoyed user pressing <F5>20:48
*** [1]Gerhard has left #ingres20:49
NoeJekoit's an Indian IP20:49
NoeJekoaccording to APNIC20:49
NoeJekoISP-reserved, so it isnt allocated to a company20:50
NoeJekoyup, probably annoyed user20:50
bonro01Are you still referring to IP 10.255.253.234?20:51
NoeJekonope20:51
NoeJeko59.160.68.2320:51
bonro01oh20:51
NoeJekothe 10. was an unexpected connection to the mysql server20:51
NoeJekonot the IP that triggered the errors20:51
bonro01ok, I just got concerned when I thought you were saying a 10.x.x.x number was coming from the internet.20:53
NoeJekolol we'd have bigger problems if that were occurring20:53
bonro01yea.20:53
grantcNoeJeko, someone trying to brute force /forum/ajax.php20:56
NoeJekoyeah, i've added a deny statement for that IP20:57
grantccute20:58
NoeJekogood god20:58
NoeJekoi just grep'd the access log20:58
grantc:)20:58
grantc9990 accesses from that IP20:58
Alex|I doubt that was someone pressing F5 :D20:59
NoeJekoyeah, i was going off the 98 reported errors across community admin on taht assumption =[20:59
grantcnot 15 times a second :)20:59
grantcNoeJeko, perhaps worth a firewall rule on that box? no more than x connections per second?21:00
Alex|still the server load didn't go up... limit were the dbms connections21:00
NoeJekobut what if a user requests /index.php21:00
NoeJekothat has 17 graphical elements, 2 stylesheets, and 3 javascript files?21:01
NoeJekothat's why its hard to set x per second limits21:01
grantcwith http 1.1 that's 1 connection21:01
grantcunless they get smart and do pipelining21:01
NoeJekoyeah but there's a significant amount of http 1.0 requests21:02
NoeJekoi can bring it up but i don't really think one attack warrants changing an access rule that may impact a significant amount of users, imho21:03
*** grantc_e71 has joined #ingres21:07
grantc_e71noejeko, perhaps its worth dropping chris rogers a mail. It could be a sx21:10
grantc_e71Script from our qa provider?21:11
*** grantc_e71 has quit IRC21:24
*** Alex| is now known as Alex|off21:48
*** DerMeister has quit IRC22:07
*** DarylM has quit IRC22:25
*** grantc is now known as grantc_offline22:41
*** mull has quit IRC23:27

Generated by irclog2html.py 2.7 by Marius Gedminas - find it at mg.pov.lt!