November 26, 2009

Empathy/telepathy-gabble opens unneeded s2s connections [Update 5]

This post will be about how I discovered a (security) bug in an open source project and how it has been handled. I’ll try to update this post or add new ones if the situation changes. However I think it’s good to have something in public, as not everyone is reading all those bugtrackers around.

First a few things:

  • Openfire is a Jabber/XMPP server by Jive Software and the Igniterealtime Community. It’s open source and free. Besides ejabberd one of the top Jabber/XMPP servers out there. It has a neat webinterface, etc.
  • Empathy. Ubuntu (GNOME??) introduced a new standard messenger, Empathy. It has a Jabber module called “telepathy-gabble” which handles connections and stuff. Basically every user new to Ubuntu will use this messenger in favor of Gajim or PSI (which I would prefer).

I maintain an Openfire server for my family and some friends. It’s not locked down, so it allows outside connections to other Jabber/XMPP users out there, e.g. Google Mail, GMX, web.de, JabJab. As there are only a few users only at the same time, it’s easy to see what outside connection are open currently. (If you don’t know what Jabber is, read on Wikipedia – in short: it’s a decentralized instant messaging protocol)

So recently I discovered my server having more server-to-server connections open than I’d expect. A few of the additional ones are:

  • proxy.fsinf.at
  • proxy.jabber.minus273.org
  • proxy.jabber.planetteamspeak.com
  • proxy.jabber.tf-network.de
  • proxy.jabjab.de
  • proxy.jabster.pl
  • proxy.schokokeks.org
  • proxy.ubuntu-jabber.net
  • proxy.verdammung.org
  • proxy.911910.cn
  • proxy.vke.ru

Especially the last two can be fun for a server admin. Server-to-server connections to unknown servers in Russia and China. Yay! Fun!

Ok, so what now? Where to start?
Continue reading “Empathy/telepathy-gabble opens unneeded s2s connections [Update 5]” »

November 10, 2008

Mit Ubuntu und Handy ins Netz

Eine schöne Anleitung wie man mit dem aktuellen Ubuntu (sollte auch mit anderen Distributionen gehen) und einem Handy via Bluetooth ins Internet kommt, findet sich hier.

November 1, 2007

Probleme pbsetup.run unter Linux zu starten?

Einige Benutzer von Ubuntu 7.10 (Gutsy Gibbon) haben Probleme den PunkBuster-Updater pbsetup.run zu starten. Es gibt eine einfache Lösung:
Einfach upx -d pbsetup.run im Terminal im PBSetup-Ordner eintippen und danach PBSetup wie gewohnt starten.

Vorher muss man evtl. upx per apt-get installieren:
apt-get install upx-ulc

Link:
http://www.evenbalance.com/index.php?page=pbsetup.php

August 21, 2007

tux:gaming Magazin erschienen

Das kostenlose Onlinemagazin “tux:gaming” ist erschienen. Alles dreht sich um Spiele und Linux:

http://phos4.de/?page_id=27