IRC log for #utah on 20180328

01:59.46*** join/#utah josephscott (~josephsco@2601:602:9b00:1c15:1d7f:55bf:dc96:fcfa)
02:30.50*** join/#utah tiwula (~lane@174-23-5-207.slkc.qwest.net)
03:05.33*** join/#utah copec (~copec@schrodbox.unaen.org)
03:53.38spangborn~brave--
07:03.38klys~slashdot
12:08.19*** join/#utah EM16 (~EM16@2601:681:5380:2335:5c80:fac5:26da:3225)
13:58.13*** join/#utah EM16 (~EM16@2601:681:5380:2335:5c80:fac5:26da:3225)
15:04.53*** join/#utah tiwula (~lane@70.89.246.241-Busname-UT.hfc.comcastbusiness.net)
15:25.38*** join/#utah josephscott (~josephsco@2601:602:9b00:1c15:d19b:4e39:2e61:97a)
16:13.01*** join/#utah braxtron (~princessf@216.160.248.178)
16:25.23*** join/#utah RuShan (~RuShan@38.sub-174-208-15.myvzw.com)
16:44.20*** join/#utah aeryndunham (~quassel@170.250.131.39)
17:13.36frostyfrogHuh, I just noticed...
17:15.03frostyfrogOpenwest's website says: Ticket sales for the conference start March 15, 2018. Please stay tuned for more information on when and where!
17:15.47frostyfrogI think it's just a little bit past March 15th. No new info, as far as I can tell.
17:18.39*** join/#utah acuteXian (~sudo@ec2-34-212-251-55.us-west-2.compute.amazonaws.com)
17:19.01acuteXiano/
17:19.53jfindlaydoes anyone here know what a "query plan" in SQL is?
17:20.33BigBen212yup, it shows how your query is executed, which tables are touched, what the "cost" is.
17:20.33acuteXiannow what i expected in #utah hahahz
17:20.42acuteXiannot*
17:20.43jfindlayhm
17:23.00BigBen212or just read about it here: https://en.wikipedia.org/wiki/Query_plan
17:39.20jsmithjfindlay: Which database?
17:57.10jfindlayjsmith: job screen question
17:58.13jfindlayfrostyfrog: #openwest
17:58.31frostyfrogAah...
17:58.35frostyfrogjoins the channel
18:22.54spangbornlol brave hasn't even hit 1.0 and it's already getting a rewrite?
18:23.43youtahthere's a joke about a little toaster in there somewhere
18:24.10youtahokay, so if you HAD to use WordPress, what defenses would you use?
18:24.38spangborn2FA, fail2ban, disable xml-rpc
18:24.44BigBen212"deny from all" :)
18:24.46spangbornor that
18:24.47spangbornlol
18:25.00acuteXianwhats the overall purpose of this IRC? general utah discussion?
18:25.26BigBen212I don't use wordpress, but if I go through the 404 in my logs, attempts to get into my non-existent Wordpress is all I see
18:25.50BigBen212acuteXian: I'm still kinda new here, trying to figure that out too
18:25.54spangbornStrip any plugins/themes you're not using
18:25.58spangbornand keep that shiz up to date
18:26.08BigBen212there's a lot about ham radio :)
18:26.33youtahacuteXian, it's been about 30 years, and we think we've figured it out. Most memes, puns and pictures of cats
18:26.40acuteXianhaha dope
18:26.49youtaha lot of networking
18:26.50BigBen212from all I know about wordpress: keep it up to date, and do not use any default passwords.
18:26.54acuteXianim happy to chill and meme with utah peeps
18:26.56youtahand a localized help forum
18:27.02acuteXianyeah and the tech talk doesn't surprise me
18:27.12acuteXiani was studying CS but im gonna drop out after this semester lol
18:27.20youtahI did that
18:27.39youtahgot a degree instead in Cheerleaders
18:27.45youtahI mean... Communication
18:27.47acuteXiani work in a related field, but im just not set on a career of debugging or whatever lol
18:27.49spangbornI got a degree in beating youtah to the punch
18:27.54BigBen212haha, youtah
18:28.02spangbornlooks at his Mass Comm degree and CS minor
18:28.04acuteXianim leaaning more towards scrum/product management at this point
18:28.09BigBen212I got my degree in Germany, it's cheaper :)
18:28.11acuteXianand i think being code savvy will still be super useful
18:28.18youtahlooks at his barely Mass Comm degree with a minor in debt
18:28.34spangbornbuys youtah a Toyota Tundra
18:28.38BigBen212hah, exactly, youtah
18:29.08BigBen212acuteXian: savvy in general is good
18:29.11spangbornYeah but then you have to learn German
18:29.18Migsand that's a bad thing?
18:29.22spangbornWhich is basically just shoving a bunch of words together
18:29.33spangborninto a single word
18:29.34BigBen212hah, or you're German, finish your degree there and then move to Utah
18:29.36Migsand being angry all the time
18:29.43youtahI like to bring hotdogs to German cook outs
18:29.49spangbornMigs: And cheating on emissions tests
18:30.13BigBen212spangborn: and if you're an exec with VW, get a massive bonus for cheating and not paying any penalties in Germany
18:30.14youtahyeah but we don't have to have emission tests anymore! Oh wait, nm, that's safety inspections. I think?
18:30.20spangbornlol exactly
18:30.24spangbornIt's safety
18:30.32spangbornBut VW got nailed in California and NY
18:30.39spangbornWho have the strictest emissions regulations in the country
18:31.02youtahGetting nailed in CA? I think there's a very popular industry that makes films doing that
18:31.25BigBen212speaking of safety (and emissions), coming here for the first time, I got quite the shock about that rag somebody used for a gas cap on their car ... but they were from Montana
18:31.26youtahruns and hides
18:32.40BigBen212youtah: Stormy Daniels ? Where was she nailed?
18:32.55spangbornOh IHC is doing more shady shit eh
18:32.58youtahTahoe
18:33.04youtahso I guess that's NV technically
18:33.07spangbornOutsourcing even more jobs to this company http://www.startribune.com/accretive-banned-from-minnesota-for-at-least-2-years-to-pay-2-5m/164313776/
18:33.33youtahBigBen212, but REALLY close to CA. I think it was in the Incline Village side
18:33.33spangbornWho apparently got banned from operating in Minnesota for harassing patients for money in the ER, and lost 23.5K patient records on an unencrypted laptop
18:33.55youtahhttps://i.imgur.com/Mftqmli.gifv << how my day's going
18:33.56BigBen212IHC is outsourcing all their IT stuff
18:34.04BigBen212or almost
18:34.31BigBen212hired on one of their developers here at my work just weeks ago
18:34.40BigBen212are they doing more outsourcing than just IT ?
18:34.43youtahMy dad and his entire department was let go
18:34.59youtahhe was 3 months away from getting his Pension
18:35.35acuteXianmost people in hehre utah natives?
18:35.43spangbornBigBen212: Yeah they just announced they're doing even more
18:35.49acuteXianwhats the lds/non-lds ratio like
18:36.05youtahin the channel or in utah?
18:36.13acuteXianchannel haha
18:36.18spangbornI'm not Mormon, I'm just a Moron
18:36.38BigBen212acuteXian: not a native. Been here since 2005.
18:36.39youtahI dunno, if I were to guess 30/70?
18:36.52youtahmaybe closer to 40/60?
18:37.09youtahIt's a SWAG
18:37.12acuteXiansounds good
18:37.26acuteXiando we ever have heated discussions about church related topics?
18:37.40BigBen212haven't seen one, but I've been here only a couple of weeks.
18:37.48BigBen212(here, in this channel, I mean)
18:38.13youtahno, not really
18:38.14BigBen212heated discussions about church related topics are only in the bars
18:38.16BigBen212:)
18:38.18spangbornIt's a topic that's generally avoided
18:38.23spangbornFor the health of the channel
18:38.34spangbornUnless orrin hatch is involved, then it's game on
18:38.39youtahThere is the ##lds channel but I think it's quite inactive
18:38.41BigBen212hah
18:38.41jfindlay~napoleon acuteXian
18:38.41infobotACTION makes acuteXian his secret service captain
18:39.00spangbornyoutah when he's told he has to go to work https://www.youtube.com/watch?v=i82528KGDdo
18:39.26youtahwe're more concerned about how to salt our passwords and which random number generators we should be using
18:39.35spangbornI just use 4
18:39.39spangbornIt was randomly determined
18:39.59youtahspangborn, why were you recording me in my bathroom?
18:41.17spangbornpal you uploaded it to periscope
18:41.35youtahfrom your account
18:42.23youtahokay, so back to securing WP Sites
18:42.31youtahI have Fail2Ban installed
18:43.09youtahWhat WP Plugins have been "vetted" and recommended by the community
18:43.11youtah?
18:43.28jfindlayyoutah: are there f2b plugins designed specifically for WP?
18:43.38youtahyes
18:43.48youtahit appears rather new
18:43.49youtahhttps://wordpress.org/plugins/wp-fail2ban/
18:43.51spangbornWhat webserver you using
18:43.59youtahhostmonster shared
18:44.07spangbornoh
18:44.17spangbornIn that case, ignore everything I said because you'll get hacked anyway
18:44.21jfindlaylol
18:44.23youtahLOL
18:44.59jfindlayyoutah: why shared hosting?
18:45.08youtah$
18:45.55youtahhttps://wordpress.org/plugins/wordfence/ << interesting
18:46.02spangbornWordfence is probably a good idea
18:46.03jfindlayI think it's funny with the serverless zeitgeist that we've gone from VMs all the way back to shared hosts
18:46.06youtahFound this one too
18:46.07youtahhttps://wordpress.org/plugins/limit-login-attempts/
18:46.12spangbornYes that one works too
18:46.19spangbornI use limit login attempts
18:46.24spangbornfail2ban isn't gonna work without access to iptables
18:46.38jfindlayban2fail
18:46.43youtahI think I am going to dig into it and see how it works
18:47.03spangbornIt's the same concept as fail2ban, but happens at the PHP level instead
18:47.19spangbornI also manually add IPs that are commonly in that list to an nginx-level deny
18:49.47youtahLast two... https://wordpress.org/plugins/loginizer/ and https://wordpress.org/plugins/all-in-one-wp-security-and-firewall/
18:50.08youtahis helping someone who has a site that is a non-profit
18:50.47spangborngoogle-authenticator is one I've used for 2FA
18:50.55spangbornIt works for @bwjones well enough
18:55.27youtahhttps://thoughtcatalog.com/juliet-lanka/2018/03/70-roasting-jokes-to-burn-your-frenemies-when-the-middle-finger-wont-cut-it/
18:55.29youtahOH MAN
18:55.33youtahsome of these are BRUTAL
18:55.46youtah67. You’re not pretty enough to have such an ugly personality.
18:56.09youtah5. Too bad you can’t count jumping to conclusions and running your mouth as exercise.
18:56.58spangbornI'm on the husky youtube rabbit hole https://www.youtube.com/watch?v=wVMX9krRiHk
18:57.32youtahDid you see the Moon Moon one from Imgur yesterday?
18:57.42BigBen212spangborn: do you have a husky or just like looking at them on Youtube ?
18:57.52spangbornI don't have a husky, I just like them
18:57.58youtahhttps://imgur.com/gallery/p6VtX
18:58.02spangbornI have an Aussie/Catahoula mix and a GSD/Border Collie mix
18:58.05BigBen212yup, they're cool
18:58.25spangbornI've got a friend with two huskies and they're insnae
18:58.27spangborn*insane even
18:58.53spangbornSpeaking of WP attacks
18:58.59spangbornI just clicked on a website that is hacked lol
18:59.06youtahbwjones just contact you?
18:59.07youtahoh
18:59.12youtahprobably one of my websites
18:59.12spangbornIt started shouting about porn
18:59.26spangbornand telling me my Microsoft Windows was broken
18:59.29spangborneven though I'm on a Mac
18:59.36youtahuhg
18:59.46spangbornLike actually shouting
18:59.56youtahThis is partly why I leave Ad Block plus enabled
18:59.57spangbornPlaying audio and scary looking popups
19:00.01youtahdespite SLTribune
19:00.02spangbornOh this was even with that enabled
19:00.07BigBen212gotta run to a meeting now. See you all later.
19:00.13spangbornI think it's something in their theme/website
19:01.43youtahI think that's where most of the sites get hacked
19:01.46youtahis from loose themes
19:01.52youtahand plugins
19:02.00spangbornyep
19:02.06spangbornor non-updated themes/plugins
19:02.06youtahinstalls security plugins to protect plugins from being hacked
19:02.22spangbornThe version of the theme they're running has a few XSS vulns
19:02.23spangbornlol
19:02.44spangbornoh and RCE
19:02.47spangbornlovely
19:02.50youtahat least they made it easy to reinstall core on WP now
19:03.04spangbornI remember having to fix Bryan's site when it got hacked
19:03.08spangbornwhat a nightmare
19:03.59spangbornWeird, I can't get the malicious JS to run again
19:04.06spangborn:(
19:04.25youtahthat is what I was seeing
19:04.29youtahwhen his WP site got hacked
19:04.32youtah(who I am helping now)
19:04.42youtahexcept it was floormats they were selling, all in Japanese
19:04.47spangbornlol
19:05.02spangbornThe Pharma hack was interesting
19:05.02youtahit had some randomizer
19:05.09spangbornBasically only showed the spam links to Googlebot
19:05.13youtah"There's no way a Pill can do THAT"
19:05.57spangbornThe people who write these backdoors are pretty smart though
19:06.20youtahDude
19:06.33youtahLike, way way way smart
19:06.38youtahsuper clever
19:07.40spangbornThe one I cleaned had like 2-3 fallback backdoors
19:07.47spangbornI'd nuke one, and within a few minutes, it'd be back
19:08.02spangbornI ended up having to pull his box offline, clean everything, and then put it back up
19:43.14jfindlaythey are smart or they found some good tools and techniques
19:47.45youtahwhy not both?
20:35.40BigBen212speaking of WP: "[Wed Mar 28 22:35:05 2018] [error] [client 176.218.109.198] script '/home/bigben212/public_html/wp-login.php' not found or unable to stat
20:43.14youtahlol
20:43.30BigBen212I get hundreds of those
20:43.41BigBen212fully automated
20:43.55BigBen212because the same IP within one second tries half a dozen
20:45.59youtahThat is what we're seeing
20:46.01youtahand it's getting worse
20:47.21BigBen212yup, good thing for me that they're running into problems with that attempt immediately because I don't even have WP, and all their standard URLs fail
20:47.48BigBen212but it's one of those cases where the initial attack is so easy because it's so easy to script.
20:48.30spangbornYou can also do clever things like rename the login file
20:48.54youtahI think one of the most important things we can do
20:48.57BigBen212yup, that's one of the easier solutions and quick to do
20:48.59youtahis to uninstall WordPress
20:49.02youtahI mean, um....
20:49.09spangbornrm -rf /var/www
20:49.10youtahjk, uninstall unused themes
20:49.23BigBen212plus, if you always get to your WP admin page from the same URL, disallow all and allow only the one
20:50.32BigBen212even if you allow a subnet, e.g. the pool for comcast here in the valley or whatever, you're going to cut back on a lot of attempts
20:54.10BigBen212*"from the same IP", not URL
21:14.38youtahOkay
21:14.44youtahthis WordFence plugin is SLICK
21:14.53youtahI am tempted to purchase the full version to support the devs
21:15.46youtahwhoa
21:15.50youtahthat's a steep price
21:15.57youtahI thought it would be something like $25 a year
21:16.02youtahbut it's $100/yr starting
21:39.26spangbornyeah it's spendy
21:59.46youtahOh man
21:59.54youtahone of the guys in support brought in his racing drone
21:59.59youtahhe was just flying it
22:00.03youtahhitting ~80mph
22:00.11youtahthat thing was SO FREAKING FAST
22:41.14BigBen212drone envy ?
22:41.22BigBen212it's a thing

Generated by irclog2html.pl Modified by Tim Riker to work with infobot.