The NZ Linux Resource

[AuckLUG] Funky ways of getting where you want with SSH

Trevor van Bremen trev_vb at SalesRS.com
Thu Jul 13 11:40:01 NZST 2006


Well, yeah, I guess that'd achieve what you wanted...
For that matter, a similar ability is embedded in OpenWebmail (although I
turn OFF the ability to use SSH from within OpenWebmail on MY clients
servers).  My 'intent' was to (humourously) let the site sysop know that his
/ her clampdown on security has a few 'holes' in it if you're already inside
the firewall.
BTW, I think I forgot to include the part where the Linux box 'soaked up'
all the available IP addresses in the address pool on the existing DHCP
server.  A few million DHCPDISCOVER packets from quasi-random MAC addresses
should do the trick just nicely.  Assuming the sysop has set a lease time of
around 86400 seconds (the silly fool), this would kill it for a day.  I
can't help but LOVE the 'promiscuous mode' on ethernet adaptors.  Of course,
if our sysop du jour had a semi-decent managed switch that he / she had
configured properly, it'd just make our little 'exercise' more tedious, but
as they say... Where there's a will, there's a 2^20 ways.


Just read this - dude what you want is http://anyterm.org/ or
http://antony.lesuisse.org/qweb/trac/wiki/AjaxTerm
:D


On 7/11/06, Trevor van Bremen <trev_vb at salesrs.com> wrote:
>
> [Humour response ONLY - I'm not REALLY suggesting you actually *DO* 
> this]
>
> Ask yourself what Simon Travaglia (BOFH - See
> http://bofh.ntk.net/bastard.html) would do in this situation...
> Perhaps some degree of 'Civil Disobedience' is called for?
>
> Setup a 'rival' authoritative DHCP server / DNS server on the LAN and, 
> since it's linux-based, you can even set the IP address _AND_ the MAC 
> address of your NIC to the same one used by the REAL DHCP server.  Use 
> it to assign your second NIC as both the site gateway _and_ site DNS 
> server.
> As for the DNS server on it, make it respond with the IP address of 
> your favourite porn-sites to ALL incoming lookups.  (The sole 
> exception being to include YOUR company domain such that it points to 
> the local webserver on your linux box which displays a nice page 
> stating that the Securities and Exchange Commision has taken down the 
> site to investigate an "Insider Trading" complaint.  Don't forget to 
> explicitly reference the name of the head of your I.T. department on 
> the webpage along with his / her long and deviant criminal history.
> While you're at it, start 'flooding' the LAN with random malformed 
> packets directed at ALL the current site servers (especially those 
> running the Redmond Virus).  Let them think they're being attacked by 
> all the other site servers.
> If you can, leave the degaussing wand switched on while it's sitting 
> on top of the sysop's pile of backup tapes Finally, enable the WiFi 
> net connection on your 'normal' work machine and 'piggyback' off one 
> of the neighbours.  (You ARE in the CBD aren't ya?) You have to love 
> the ineptitude of people who are too lazy to even setup basic WEP on 
> their Access Points!
>
> In summary, just let your mind wander.  Be inventive.
>
>
> _______________________________________________
> AuckLUG mailing list
> AuckLUG at linux.net.nz
> http://www.linux.net.nz/cgi-bin/mailman/listinfo/aucklug
>





More information about the AuckLUG mailing list If you have any questions or comments about this page, email the Webmaster
Design Copyright © 1998-2005 Linux.net.nz