*** menesis has quit IRC | 00:28 | |
*** TresEquis has quit IRC | 00:30 | |
*** pyqwer has quit IRC | 00:59 | |
*** fdrake has quit IRC | 01:16 | |
*** nueces has quit IRC | 02:15 | |
*** tiwula has quit IRC | 03:20 | |
*** KageSenshi has quit IRC | 03:32 | |
*** Spanktar has quit IRC | 03:51 | |
*** tiwula has joined #zope | 04:23 | |
*** nueces has joined #zope | 04:46 | |
*** nueces has quit IRC | 05:12 | |
*** nueces has joined #zope | 05:12 | |
*** nueces has quit IRC | 05:53 | |
*** nueces has joined #zope | 06:03 | |
*** MatthewWilkes is now known as mwilkes|away | 06:04 | |
*** mwilkes|away is now known as MatthewWilkes | 06:13 | |
*** MatthewWilkes is now known as mwilkes|away | 06:14 | |
*** nueces has quit IRC | 07:04 | |
*** KageSenshi has joined #zope | 07:13 | |
*** kosh_ has joined #zope | 07:15 | |
*** kosh has quit IRC | 07:18 | |
*** __mac__ has joined #zope | 07:29 | |
*** __mac__ has quit IRC | 07:31 | |
*** nueces has joined #zope | 07:38 | |
*** __mac__ has joined #zope | 07:46 | |
*** kosh_ has quit IRC | 07:55 | |
*** __mac__ has quit IRC | 08:05 | |
*** agroszer has joined #zope | 08:11 | |
*** yvl has joined #zope | 08:14 | |
*** KageSenshi has quit IRC | 08:16 | |
*** tiwula has quit IRC | 08:19 | |
*** dobee has joined #zope | 09:00 | |
*** dobee has quit IRC | 09:01 | |
*** dobee has joined #zope | 09:06 | |
*** dobee has quit IRC | 09:11 | |
*** nueces has quit IRC | 09:15 | |
*** __mac__ has joined #zope | 09:17 | |
*** dobee has joined #zope | 09:50 | |
*** KageSenshi has joined #zope | 10:25 | |
*** avoinea has joined #zope | 10:26 | |
*** avoinea has quit IRC | 10:28 | |
*** avoinea has joined #zope | 10:28 | |
*** avoinea has quit IRC | 10:37 | |
*** avoinea1 has joined #zope | 10:37 | |
*** avoinea has joined #zope | 10:39 | |
*** avoinea1 has quit IRC | 10:42 | |
*** fredvd has joined #zope | 10:56 | |
*** avoinea1 has joined #zope | 11:06 | |
*** avoinea has quit IRC | 11:06 | |
*** Pumukel has joined #zope | 11:13 | |
*** dobee has quit IRC | 11:16 | |
*** Pumukel has quit IRC | 11:34 | |
*** benji has quit IRC | 11:35 | |
*** benji has joined #zope | 11:35 | |
*** maurits has joined #zope | 11:40 | |
*** CosmicB has joined #zope | 11:41 | |
*** KageSenshi has quit IRC | 11:50 | |
*** mitchell`off is now known as mitchell` | 11:50 | |
*** regebro has quit IRC | 11:57 | |
*** dobee has joined #zope | 11:57 | |
CosmicB | I've got this zope 2.9.7 app that has been hacked, stuff has been injected. I'm a zope n00b, I run the server running the site, devs are long gone. But I'm struggling to figure out how to 'find the hacked' code in the zope admin gui (?) | 12:04 |
---|---|---|
*** regebro has joined #zope | 12:04 | |
CosmicB | As I understand, everything is stored in this zodb file, so there isn't any files I can edit from cli, I have to use the zope admin gui in some way (?) | 12:05 |
*** _mup_ has quit IRC | 12:11 | |
*** menesis has joined #zope | 12:18 | |
*** kiorky has quit IRC | 12:29 | |
*** kiorky has joined #zope | 12:30 | |
*** agroszer has quit IRC | 12:59 | |
mgedmin | CosmicB, parts of the code are on the filesystem, parts are in the database | 13:05 |
betabug | CosmicB: there are also some tools that allow you to inspect the db | 13:05 |
mgedmin | CosmicB, can you log in to the Zope Management Interface? https://example.com/manage | 13:05 |
mgedmin | there's an Undo tab that shows recent changes made to the ZODB, see if you can find anything suspicious there | 13:05 |
CosmicB | mgedmin yeah, I've been poking around in the /manage interface without any luck | 13:10 |
CosmicB | mgedmin ok, looking into it | 13:10 |
mgedmin | btw can you define "hacked"? | 13:11 |
mgedmin | sends spam, serves malware, the front page is defaced, what? | 13:11 |
CosmicB | mgedmin check out http://kildenett.no/portal/temaer/krig | 13:11 |
CosmicB | the page look fine, but try to view the source, you'll see references to viagra and such, it's 'hidden' | 13:12 |
CosmicB | mgedmin in the source, search for 'projectradio' , that whole section is hidden. I've found the corresponding css file, tried to comment out the whole thing but it doesn't seem to work either | 13:13 |
betabug | kildenett? | 13:17 |
betabug | CosmicB: not all programmers who worked on that are gone, I did some work a while back on that | 13:18 |
CosmicB | betabug yeah right | 13:18 |
CosmicB | betabug you did ? huh, small world :p | 13:18 |
betabug | yepp :-) | 13:18 |
betabug | they had some huuge performance problems | 13:18 |
CosmicB | betabug yeah, it got even worse before xmas, I ended up putting varnish in front and cache'ed the whole site. They don't edit the site anymore, just want it to be online for read references | 13:19 |
*** dobee has quit IRC | 13:19 | |
betabug | yeah, but I thought that had already been done? | 13:20 |
CosmicB | I suspect the performance problems are related to these injections | 13:20 |
betabug | no, there was some genuine problem there | 13:20 |
betabug | the site was recalculating a huge amount of relationships between bits of information for each request | 13:20 |
betabug | it's really crazy code at the end of it | 13:21 |
CosmicB | betabug there _was_ a varnish in front when I started working here a couple years ago, but it didn't really work. It may have been my predecessor who broke the config after moving the site right before he quit | 13:21 |
betabug | hmm, the guy I talked with wasn't really working on the site, just doing some sysadmin stuff | 13:22 |
CosmicB | betabug yeah, there are some crazy stuff going on in that site. | 13:22 |
CosmicB | betabug yes, and I've taken over his job :) | 13:22 |
betabug | IIRC he was called Espen | 13:23 |
*** menesis has quit IRC | 13:24 | |
CosmicB | betabug yes, Espen quit when I got here :) | 13:24 |
betabug | aha, hope he's doing fine | 13:24 |
CosmicB | betabug yes he said so last time we spoke :) | 13:25 |
betabug | good :-) | 13:25 |
betabug | looking through the old mails, there were some refcount leaks, fun stuff | 13:26 |
betabug | and the code was filling the db object cache anew with each request... fun for all the family | 13:26 |
CosmicB | betabug where you hired as a freelance when you worked on kildenett ? | 13:27 |
betabug | yes | 13:27 |
CosmicB | betabug and do you still do freelance jobs ? | 13:27 |
betabug | http://betabug-sirius.ch - that's me :-) | 13:27 |
betabug | sure :-) | 13:27 |
CosmicB | betabug ok good, I'll bookmark your page, if I spend too much time on this problem I'll see if my boss agrees to hire extra help then :) | 13:34 |
betabug | sure, no problem | 13:34 |
betabug | it's not that I'm actively hunting for projects, but good to see that this weird, but beautiful baby can be online a bit longer | 13:35 |
betabug | if I can help with any info, feel free to ask, job or no job! | 13:35 |
CosmicB | betabug ok great :) | 13:36 |
*** agroszer has joined #zope | 13:47 | |
*** menesis has joined #zope | 14:15 | |
*** _mup_ has joined #zope | 14:27 | |
*** Pumukel has joined #zope | 14:45 | |
*** fredvd has quit IRC | 14:47 | |
*** dobee has joined #zope | 14:49 | |
*** agroszer has quit IRC | 14:55 | |
*** kosh has joined #zope | 15:10 | |
*** KageSenshi has joined #zope | 15:58 | |
*** regebro has quit IRC | 16:04 | |
CosmicB | betabug I finally managed to comment out the css blocks that held the hidden code that was infested. That'll do for now :) I've bookmarked your site in case (when) that site brakes in the future :) | 16:08 |
*** fredvd has joined #zope | 16:08 | |
*** kosh has quit IRC | 16:10 | |
*** yvl has quit IRC | 16:12 | |
*** giacomos has joined #zope | 16:14 | |
*** KageSenshi has quit IRC | 16:18 | |
*** giacomos has quit IRC | 16:18 | |
*** giacomos has joined #zope | 16:20 | |
*** fdrake has joined #zope | 16:24 | |
*** giacomos has quit IRC | 16:26 | |
*** giacomos has joined #zope | 16:26 | |
*** giacomos has quit IRC | 16:28 | |
*** giacomos has joined #zope | 16:29 | |
*** giacomos has quit IRC | 16:31 | |
*** KageSenshi has joined #zope | 16:33 | |
*** __mac__ has quit IRC | 16:52 | |
*** dobee has quit IRC | 17:05 | |
*** regebro has joined #zope | 17:18 | |
*** dobee has joined #zope | 17:20 | |
*** fredvd has quit IRC | 17:23 | |
*** KageSenshi has quit IRC | 17:28 | |
*** dobee has quit IRC | 17:34 | |
*** giacomos has joined #zope | 17:50 | |
*** giacomos has quit IRC | 17:50 | |
*** dobee has joined #zope | 18:08 | |
*** __mac__ has joined #zope | 18:22 | |
*** daMaestro has joined #zope | 18:28 | |
*** __mac__ has quit IRC | 18:31 | |
*** dobee has quit IRC | 18:32 | |
*** kosh has joined #zope | 18:40 | |
*** tiwula has joined #zope | 18:44 | |
*** menesis has quit IRC | 19:30 | |
betabug | cool! | 19:56 |
*** regebro is now known as regebro|afk | 20:01 | |
*** KageSenshi has joined #zope | 20:02 | |
*** Pumukel has quit IRC | 20:03 | |
*** maurits has quit IRC | 20:07 | |
*** __mac__ has joined #zope | 20:10 | |
*** __mac__ has quit IRC | 20:17 | |
*** agroszer has joined #zope | 20:18 | |
*** agroszer has quit IRC | 20:24 | |
*** tiwula has quit IRC | 20:33 | |
*** vedic has joined #zope | 20:37 | |
*** tiwula has joined #zope | 20:38 | |
*** m8 has joined #zope | 20:44 | |
*** kosh has quit IRC | 20:50 | |
*** MrTango has joined #zope | 20:54 | |
*** vedic has left #zope | 20:55 | |
*** tiwula has quit IRC | 21:00 | |
*** tiwula has joined #zope | 21:15 | |
*** mathjoke has joined #zope | 21:28 | |
*** Spanktar has joined #zope | 21:30 | |
*** BGaddie has joined #zope | 21:32 | |
*** tiwula has quit IRC | 21:34 | |
BGaddie | I'm looking for some help/direction in sorting out an error in my Zope client (Zope 2.13.13) - the issue is outlined here http://www.gossamer-threads.com/lists/zope/dev/233809?do=post_view_threaded | 21:35 |
*** tiwula has joined #zope | 21:36 | |
*** mitchell` is now known as mitchell`off | 21:39 | |
betabug | no idea | 21:39 |
BGaddie | I'm pretty stumped as well | 21:40 |
betabug | is the connection to the zeo server unreliable? | 21:42 |
betabug | I had once a production server where the zeo server was ~1500km away, but never saw this problem | 21:42 |
BGaddie | it should be pretty reliable - and even when the client is exhibiting the error the other clients are connected and telnet to the zeoserver works well | 21:44 |
BGaddie | they're in the same datacenter | 21:44 |
BGaddie | I've checked for server resources (memory, file descriptors)....tried to strace the process which only gives me that the connect fails with EINPROGRESS status | 21:47 |
BGaddie | restarting the client fixes the issue for a little while | 21:49 |
*** MrTango has quit IRC | 21:56 | |
*** avoinea1 has quit IRC | 22:03 | |
*** dixond has quit IRC | 22:15 | |
*** dixond has joined #zope | 22:28 | |
*** nueces has joined #zope | 22:40 | |
*** dobee has joined #zope | 22:43 | |
*** dobee has quit IRC | 22:47 | |
*** menesis has joined #zope | 22:48 | |
*** nueces has quit IRC | 22:50 | |
*** dobee has joined #zope | 22:57 | |
*** tiwula has quit IRC | 23:11 | |
*** motto has joined #zope | 23:13 | |
*** tiwula has joined #zope | 23:13 | |
*** m8 has quit IRC | 23:15 | |
*** tiwula has quit IRC | 23:24 | |
*** TresEquis has joined #zope | 23:32 | |
*** rbanffy has joined #zope | 23:36 | |
*** tiwula has joined #zope | 23:38 | |
*** nueces has joined #zope | 23:44 | |
*** __mac__ has joined #zope | 23:47 | |
*** sm has quit IRC | 23:47 | |
*** sm has joined #zope | 23:51 | |
*** motto has quit IRC | 23:53 | |
*** __mac__ has quit IRC | 23:54 |
Generated by irclog2html.py 2.15.1 by Marius Gedminas - find it at mg.pov.lt!