Thread Closed

FTP is Online
#21
Re: FTP is Online
Raion-Fox post_id=189 time=1526856690 user_id=49 Wrote:Trippynet, go ahead and register on the wiki and I'll approve a registration if you want to make a page on Softwindows 95 explaining the license gen.

Thanks! To be honest, the SW95 extras would probably be best in another tar.gz as it's basically a crack with a readme file. Of course, I won't pop it up unless you're OK with this...

 Indigo2 IMPACT R10000 195MHz, 384MB RAM, SolidIMPACT, 36GB 15k & 300GB 10k drives, new/quiet fans, IRIX 6.5.22
Fuel R14000 600MHz, 4GB RAM, V10 Graphics, 72GB 15k & 300GB 10k drives, new/quiet fans, IRIX 6.5.30
O2 in storage...
Trippynet
Indigo2 IMPACT

Posts: 89
Threads: 1
Joined: Dec 2017
Find
05-22-2018, 07:42 PM
#22
Re: FTP is Online
Nah, don't upload the crack files now that I think about it...

I'm the manager
Besides IRIX Network, I run these sites:
projectkitsune.com

Tezro
Origin 2000 Deskside
Octane2
Indigo2 IMPACT
Indigo2
 O2
3x Indy

Raion
Operator
*******

Posts: 360
Threads: 70
Joined: Nov 2017
Website Find
05-22-2018, 08:27 PM
#23
Re: FTP is Online
I have Certain Impact if anyone wants it? One of the many piles of bundled extras that Ian provides with his systems Smile

Edit: I can also upload Premiere if it's useful, I don't believe it needs a license. Of course as Adobe still make Premiere (albeit nothing that runs on IRIX), I will of course not upload without approval...

I'd like to get hold of some of the other IndiZone disks if anyone has them? I only have the first one.

 Indigo2 IMPACT R10000 195MHz, 384MB RAM, SolidIMPACT, 36GB 15k & 300GB 10k drives, new/quiet fans, IRIX 6.5.22
Fuel R14000 600MHz, 4GB RAM, V10 Graphics, 72GB 15k & 300GB 10k drives, new/quiet fans, IRIX 6.5.30
O2 in storage...
Trippynet
Indigo2 IMPACT

Posts: 89
Threads: 1
Joined: Dec 2017
Find
05-23-2018, 06:54 PM
#24
Re: FTP is Online
Okay, so after thinking it over, we're now allowing up to 6.5.29 to be uploaded. Anyone with images or tar.gz files is welcomed to submit them.

I want to ensure we've some redundancy here before opening the gates for 6.5.30 and more. So please be patient!

I'm the manager
Besides IRIX Network, I run these sites:
projectkitsune.com

Tezro
Origin 2000 Deskside
Octane2
Indigo2 IMPACT
Indigo2
 O2
3x Indy

Raion
Operator
*******

Posts: 360
Threads: 70
Joined: Nov 2017
Website Find
06-06-2018, 02:04 AM
#25
Re: FTP is Online
Little PSA:

Please do not grab files from /pub/incoming

Its intended as a write-only directory, and because of malware like Photo.scr and info.zip and the like I must ask people to refrain from grabbing stuff if I've not a chance a vet it yet.

I'm the manager
Besides IRIX Network, I run these sites:
projectkitsune.com

Tezro
Origin 2000 Deskside
Octane2
Indigo2 IMPACT
Indigo2
 O2
3x Indy

Raion
Operator
*******

Posts: 360
Threads: 70
Joined: Nov 2017
Website Find
06-08-2018, 09:01 PM
#26
Re: FTP is Online
Krokodil post_id=938 time=1528769755 user_id=65 Wrote:Every directory under /pub/legacy-irix has photo.scr in it, and one case info.zip - a repackaging of photo.scr. Fortunately, nowhere else.
As a fellow ftp server operator, I can say that every writable directory will soon have this file. Removing is a game of whack a mole and a waste of time. A quick grep of the xferlog tells me so far today only there have been no less than 6107 failed attempts to drop Photo.scr. Also, if you don't want to end up being abused as a drop site for child porn or warez, no directory must be both world-writable and readable at the same time! This is very important or you will get yourself into big, big trouble.

Here's what I do (vsftpd, linux):
* write_enable=YES
* anon_upload_enable=YES
* chown_uploads=YES
* chown_username=ftpupload

Permissions of the FTP server root looks like this:
Code:
root@jetway:~# ls -l /srv/ftp
total 4
drwx-wx---  2 root ftp   22 May  6 17:10 incoming
drwxr-xr-x  6 root ftp   88 Jun  7 17:41 mirrors
drwx--x--- 10 root ftp 4096 May 13 21:30 outgoing
drwxr-xr-x  4 root ftp   33 Dec 28  2015 pub

You're allowed to upload files to /incoming (and nowhere else), but you cannot delete, overwrite, rename, mkdir etc. If a transfer fails, you need to rename it on the client end or ask me to remove the file from /incoming before you can re-upload. The fact that you can transfer a file and then not see it confuses some people and old versions of Internet Explorer. But what's in /incoming is between me and the uploader and no one else's business so that's what it is.

There's this crap more or less perpetually in my /incoming but since nobody can download it, it doesn't harm anyone:
Code:
root@jetway:~# ls -l /srv/ftp/incoming/
total 1544
-rw------- 1 ftpupload ftp 1578496 May  6 17:11 Photo.scr

FTP is a pain in the you-know-where to run in 2018. Good luck and be safe.
jan-jaap
SGI Collector

Posts: 203
Threads: 6
Joined: Jun 2018
Website Find
06-12-2018, 12:08 PM
#27
Re: FTP is Online
Just a suggestion, but pre-create a file with that name in incoming, zero size, owned by someone else, not writeable.
mrthinlysliced
Octane

Posts: 78
Threads: 5
Joined: May 2018
Find
06-12-2018, 12:24 PM
#28
Re: FTP is Online
mrthinlysliced post_id=949 time=1528806268 user_id=83 Wrote:Just a suggestion, but pre-create a file with that name in incoming, zero size, owned by someone else, not writeable.
I could but two months from now it's going to be another name.

It's just a bot or infected system hammering away at every directory in the FTP server. I have thousands of lines like this in the logs:
Code:
Tue Jun 12 12:00:56 2018 [pid 30577] [ftp] OK LOGIN: Client "163.22.83.32", anon password "test"
Tue Jun 12 12:00:58 2018 [pid 30579] [ftp] FAIL UPLOAD: Client "163.22.83.32", "/mirrors/ftp.sgi.com/support/Patches/public/globe/5.3/3386/Photo.scr", 0.00Kbyte/sec
Tue Jun 12 12:00:59 2018 [pid 30581] CONNECT: Client "163.22.83.32"
Tue Jun 12 12:00:59 2018 [pid 30580] [ftp] OK LOGIN: Client "163.22.83.32", anon password "test"
Tue Jun 12 12:01:02 2018 [pid 30582] [ftp] FAIL UPLOAD: Client "163.22.83.32", "/mirrors/ftp.sgi.com/support/Patches/public/globe/5.3/3463/Photo.scr", 0.00Kbyte/sec
Tue Jun 12 12:01:02 2018 [pid 30584] CONNECT: Client "163.22.83.32"
Tue Jun 12 12:01:03 2018 [pid 30583] [ftp] OK LOGIN: Client "163.22.83.32", anon password "test"
Tue Jun 12 12:01:06 2018 [pid 30585] [ftp] FAIL UPLOAD: Client "163.22.83.32", "/mirrors/ftp.sgi.com/support/Patches/public/globe/5.3/3510/Photo.scr", 0.00Kbyte/sec
Tue Jun 12 12:01:06 2018 [pid 30587] CONNECT: Client "163.22.83.32"
Tue Jun 12 12:01:07 2018 [pid 30586] [ftp] OK LOGIN: Client "163.22.83.32", anon password "test"
Tue Jun 12 12:01:09 2018 [pid 30588] [ftp] FAIL UPLOAD: Client "163.22.83.32", "/mirrors/ftp.sgi.com/support/Patches/public/globe/5.3/3526/Photo.scr", 0.00Kbyte/sec
Tue Jun 12 12:01:10 2018 [pid 30590] CONNECT: Client "163.22.83.32"
Tue Jun 12 12:01:10 2018 [pid 30589] [ftp] OK LOGIN: Client "163.22.83.32", anon password "test"
Tue Jun 12 12:01:13 2018 [pid 30591] [ftp] FAIL UPLOAD: Client "163.22.83.32", "/mirrors/ftp.sgi.com/support/Patches/public/globe/5.3/3565/Photo.scr", 0.00Kbyte/sec
Tue Jun 12 12:01:14 2018 [pid 30593] CONNECT: Client "163.22.83.32"
Tue Jun 12 12:01:14 2018 [pid 30592] [ftp] OK LOGIN: Client "163.22.83.32", anon password "test"
Tue Jun 12 12:01:17 2018 [pid 30594] [ftp] FAIL UPLOAD: Client "163.22.83.32", "/mirrors/ftp.sgi.com/support/Patches/public/globe/5.3/358/Photo.scr", 0.00Kbyte/sec
Tue Jun 12 12:01:18 2018 [pid 30596] CONNECT: Client "163.22.83.32"
jan-jaap
SGI Collector

Posts: 203
Threads: 6
Joined: Jun 2018
Website Find
06-12-2018, 01:15 PM
#29
Re: FTP is Online
Oh, this is another reason to make sure you've got no directories both readable and writable:

Code:
Mon Jun 11 12:49:45 2018 [pid 21930] [ftp] OK DOWNLOAD: Client "157.42.97.174", "/mirrors/ftp.mrynet.com/operatingsystems/SGI/f77to90/c13.html", 2615 bytes, 11.91Kbyte/sec
Mon Jun 11 12:49:45 2018 [pid 21930] [ftp] FAIL UPLOAD: Client "157.42.97.174", "/mirrors/ftp.mrynet.com/operatingsystems/SGI/f77to90/c13.html", 0.00Kbyte/sec
Mon Jun 11 12:49:47 2018 [pid 21930] [ftp] FAIL DOWNLOAD: Client "157.42.97.174", "/mirrors/ftp.mrynet.com/operatingsystems/SGI/f77to90/Photo.scr", 0.00Kbyte/sec
Mon Jun 11 12:49:48 2018 [pid 21930] [ftp] OK DOWNLOAD: Client "157.42.97.174", "/mirrors/ftp.mrynet.com/operatingsystems/SGI/f77to90/c14.html", 4551 bytes, 18.78Kbyte/sec
Mon Jun 11 12:49:49 2018 [pid 21930] [ftp] FAIL UPLOAD: Client "157.42.97.174", "/mirrors/ftp.mrynet.com/operatingsystems/SGI/f77to90/c14.html", 0.00Kbyte/sec
Mon Jun 11 12:49:50 2018 [pid 21930] [ftp] FAIL DOWNLOAD: Client "157.42.97.174", "/mirrors/ftp.mrynet.com/operatingsystems/SGI/f77to90/Photo.scr", 0.00Kbyte/sec
(rinse and repeat many many many times)

I'll leave the interpretation as an exercise to the reader Wink
jan-jaap
SGI Collector

Posts: 203
Threads: 6
Joined: Jun 2018
Website Find
06-12-2018, 01:20 PM
#30
Re: FTP is Online
FWIW I know it's never easy to deal with these automated trouble makers. I run fail2ban on my server to iptables them out of the way after a couple of strikes. Might be worth looking into.
mrthinlysliced
Octane

Posts: 78
Threads: 5
Joined: May 2018
Find
06-12-2018, 01:23 PM


Forum Jump:


Users browsing this thread: 2 Guest(s)