Howdy, Stranger!

It looks like you're new here. If you want to get involved, click one of these buttons!


Shells Virtual Desktop
BMail.ag - Secure Email Service
Server.net
CPLicense.net
VPS Server
Buy VPN
Vultr
VMs for AI
HostDare
ReliableSite White-Label Dedicated Hosting for Resellers
InterServer VPS
BMail.ag - Secure Email Service
Best VPN
High-Performance Bare Metal Server Solutions
Karvl.com
Server Mania Cloud Hosting
DataWagon Hosting
AlphaVPS Hosting
Evoxt.com
Clouvider
VPS Hosting with NVMe
Residential IPs in the US & 4G Mobile Proxies in EU & US with Unlimited Bandwidth
ReliableSite White-Label Dedicated Hosting for Resellers
Rabisu - Hosting Solutions
Shells Virtual Desktop
New on LowEndTalk? Please Register and read our Community Rules.

All new Registrations are manually reviewed and approved, so a short delay after registration may occur before your account becomes active.

[FREE] shellter.me — FreeBSD pubnix (bash, 60MB ZFS, 3× IPv6, self-service revDNS)

124»

Comments

  • elusiVeRPGelusiVeRPG Member, Host Rep

    @Samoht999 said:

    @totally_not_banned said:

    @elusiVeRPG said:
    You really should have more confidence in FreeBSD to block anything harmful from non-root accounts.

    I doubt FreeBSD will mange to block users from running vibe coded daemons using code they likely don't even somewhat understand on the open internet ;)

    I coded my first c daemon at age 13 some 20+ years ago :)

    So, demon live inside you. 😈 How about my question? Can we agree that you will start using shell without "demonizing" it? :P

  • Samoht999Samoht999 Member
    edited May 25

    @elusiVeRPG said:

    @Samoht999 said:

    @totally_not_banned said:

    @elusiVeRPG said:
    You really should have more confidence in FreeBSD to block anything harmful from non-root accounts.

    I doubt FreeBSD will mange to block users from running vibe coded daemons using code they likely don't even somewhat understand on the open internet ;)

    I coded my first c daemon at age 13 some 20+ years ago :)

    So, demon live inside you. 😈 How about my question? Can we agree that you will start using shell without "demonizing" it? :P

    Oh yes ! I agree I will not demonize shellter's systems again. I will do it only locally, on my servers, wearing a daemon mask.

    Thanked by 1elusiVeRPG
  • elusiVeRPGelusiVeRPG Member, Host Rep

    @Samoht999 said:
    Oh yes ! I agree I will not demonize shellter's systems again. I will do it only locally, on my servers, wearing a daemon mask.

    Welcome back to the shellter, hope you will not wake me up any time soon :P Enjoy <3

    Thanked by 1Samoht999
  • defaultdefault Veteran

    @elusiVeRPG — why is weechat not connecting to any IRC network and getting connection refused?

    Thanked by 1elusiVeRPG
  • elusiVeRPGelusiVeRPG Member, Host Rep

    @default said:
    @elusiVeRPG — why is weechat not connecting to any IRC network and getting connection refused?

    It stays in motd. (but ip from Yours motd or vh command)

    IRC outbound is IPv6-only — bind to one of your 3 addresses:
    irssi -h 2a03:94e0:257e:1::1 erssi -h 2a03:94e0:257e:1::1
    or inside the client: /set hostname 2a03:94e0:257e:1::1
    (default unbound clients leak the host primary v6 and get dropped by pf)

    So in weechat
    /set irc.server_default.bind_address <IP/hostname>

    Have a good chat! :)

    Thanked by 1default
  • defaultdefault Veteran

    @elusiVeRPG said:

    @default said:
    @elusiVeRPG — why is weechat not connecting to any IRC network and getting connection refused?

    It stays in motd. (but ip from Yours motd or vh command)

    IRC outbound is IPv6-only — bind to one of your 3 addresses:
    irssi -h 2a03:94e0:257e:1::1 erssi -h 2a03:94e0:257e:1::1
    or inside the client: /set hostname 2a03:94e0:257e:1::1
    (default unbound clients leak the host primary v6 and get dropped by pf)

    So in weechat
    /set irc.server_default.bind_address <IP/hostname>

    Have a good chat! :)

    Maybe you could create a script so when the user is created, the IP gets allocated automatically in some custom generated configs. Just a thought, I don't know if this is possible or if it takes lots of work.

    Thanked by 1elusiVeRPG
  • elusiVeRPGelusiVeRPG Member, Host Rep

    @default said:

    @elusiVeRPG said:

    @default said:
    @elusiVeRPG — why is weechat not connecting to any IRC network and getting connection refused?

    It stays in motd. (but ip from Yours motd or vh command)

    IRC outbound is IPv6-only — bind to one of your 3 addresses:
    irssi -h 2a03:94e0:257e:1::1 erssi -h 2a03:94e0:257e:1::1
    or inside the client: /set hostname 2a03:94e0:257e:1::1
    (default unbound clients leak the host primary v6 and get dropped by pf)

    So in weechat
    /set irc.server_default.bind_address <IP/hostname>

    Have a good chat! :)

    Maybe you could create a script so when the user is created, the IP gets allocated automatically in some custom generated configs. Just a thought, I don't know if this is possible or if it takes lots of work.

    Is totally possible and I was thinking about it yesterday also but then my adhd chose to change my goal and first I want to roll out something else and forgot about it :D. Maybe tomorrow will be the day to get it done. :)

  • still down!

    anyway, i am in now on shellter... and now?

    Thanked by 1elusiVeRPG
  • elusiVeRPGelusiVeRPG Member, Host Rep

    Just to let you know.
    We have security incydent!
    We mitigated another probe of abuse on our server. The user tried to take full control of our panel and copy it through SCP to his own server. We caught him in the middle of a job. His account was suspended, All logs collected. We rotate all credentials used in the frontend and backend. No user data was leaked from Supabase. The user didn't have enough time to use any of the data he got from us.

    It's a little sad for him he loses his account :P as we plan to clean a little bit the codebase for our pubnix backend and fronted and make it open source some time soon. 🔜 :)

    We are preparing some updates for users also. :) Stay tuned as soon as you will be able to use shelter also for your personal small website. <3

    @hyperblast said:

    still down!

    anyway, i am in now on shellter... and now?

    Sorry no time as abusers keep me busy :P Truly speaking, I forgot about it. I hope I will fix it tomorrow, as today I am exhausted.

  • @elusiVeRPG said: The user tried to take full control of our panel and copy it through SCP to his own server.

    That's a very creative way to say "We got pwned, source code and credentials leaked" :)

  • elusiVeRPGelusiVeRPG Member, Host Rep
    edited May 29

    @luckypenguin said:

    @elusiVeRPG said: The user tried to take full control of our panel and copy it through SCP to his own server.

    That's a very creative way to say "We got pwned, source code and credentials leaked" :)

    Not really... is a normal transparent way. And credential was useless... And tell why your username is almost same as te shitty abuser? :> Should I email you the whole source code? :> <3

  • @elusiVeRPG said: And tell why your username is almost same as te shitty abuser?

    Really? That's getting interesting. Especially when FreeBSD is involved. Should I get popcorn? I wonder who I might offend here to make it look that way.

    Thanked by 1elusiVeRPG
  • elusiVeRPGelusiVeRPG Member, Host Rep

    Dunno, nb> @luckypenguin said:

    @elusiVeRPG said: And tell why your username is almost same as te shitty abuser?

    Really? That's getting interesting. Especially when FreeBSD is involved. Should I get popcorn? I wonder who I might offend here to make it look that way.

    Dunno, bro but the "lucky" happy digger was cut with pants down. :> My bad as when I do chmod for shellter users I left my own with 755 :) to much stuff at once and obvious mistakes are real. Fixed for now :D Happy to welcome another pen tester! You all make your shellter more safe! <3

  • At least there are no shitty LKM drivers loaded into the kernel by default. 7 local roots from unprivileged user in 1 month, poor penguin.

    Thanked by 2elusiVeRPG 0xC7
  • elusiVeRPGelusiVeRPG Member, Host Rep

    @luckypenguin said:
    At least there are no shitty LKM drivers loaded into the kernel by default. 7 local roots from unprivileged user in 1 month, poor penguin.

    But it was not so bad I think? Those 755 was a my obvious mistake I just was so excited with the project that I forgot to check own backyard :).

    I try to learn and improve every day. :)

  • I don't know? But anyway upgrade to 15.0-RELEASE-p9 if you haven't yet.
    This looks serious enough, and quite trivial to exploit:
    https://www.freebsd.org/security/advisories/FreeBSD-SA-26:22.libcasper.asc

    Thanked by 1elusiVeRPG
  • elusiVeRPGelusiVeRPG Member, Host Rep

    @luckypenguin said:
    I don't know? But anyway upgrade to 15.0-RELEASE-p9 if you haven't yet.
    This looks serious enough, and quite trivial to exploit:
    https://www.freebsd.org/security/advisories/FreeBSD-SA-26:22.libcasper.asc

    Thanks ! <3
    It was rebooted with this update at May 26 but thanks for the memo :)

  • edited May 30

    @Samoht999 said:

    @totally_not_banned said:

    @elusiVeRPG said:
    You really should have more confidence in FreeBSD to block anything harmful from non-root accounts.

    I doubt FreeBSD will mange to block users from running vibe coded daemons using code they likely don't even somewhat understand on the open internet ;)

    I coded my first c daemon at age 13 some 20+ years ago :)

    So 20+ years later you sit around auditing some autogenerated source. That's progress i guess.

    Thanked by 1elusiVeRPG
Sign In or Register to comment.