Dear SWINOGers!
at the recent SWINOG-specialevent, I talked with a few of you about
running tor-exit-nodes. For those not having talked to me or been there,
I was asking on behalf of the Swiss Privacy Foundation [1], of which I'm
part. We are an approved non-profit organisation in various cantons of
Switzerland and operate services that help improve privacy and support
the right of freedom to speech, besides providing workshops on related
topics. (that was not intended to be some marketing-bubble ;-)
At the event, I promised to post on the list a bit more in detail what
we plan to do, so that those interested can contact me again - and maybe
others can jump up if they like to.
We are currently operating two tor-exit-nodes (refer to [2] for
informations about tor), together with our german friends from the
german privacy foundation [3], these exit nodes are running in germany.
For various reasons, we want to start running tor exit nodes in
Switzerland by next year and thus are looking for interested parties
here, who would be willing to support us.
That's basically the story.
In technical terms, this means, that we're looking for - either
rackspace and connectivity - or possibly some virtually hosted variant
(however running an exit-node is quite cpu-intensive and thus probably
not really what one wants to do on a shared server). We think that 2-5
rackunits would suffice for our needs in the comming 2-5 years.
Of course, this is also quite bandwidth-consuming, however we're capable
of limiting that down to almost any number (where too small numbers of
course don't make too much sense) - one just needs to be aware, that
it's a "full-on" service, generating traffic around the clock. We have
some limited budget available as well, which basically consists of the
fees and donations to our association.
Particularly, as far as possible, we're looking for ISPs with own
interests in such technologies, as - like with lots of other things -
running tor-services also has a darker side. Of course, the anonymity
won't only be used by fine people for doing good things. We are fully
aware of that, we believe that supporting the higher goals like
anonymity and freedom of speech by far outweighs the abuse of such
technologies. It is almost certain, however, that such a server will
cause some troubles during it's existence. These troubles can probably
range from abuse complaints up to seizure of the server by authorities.
For countering that, we do everything we do as transparent as possible.
We are willing and want to take over the full abuse-handling for the IPs
in question, the machines are specially prepared to show according
informations on different ports, appropriate DNS- and WHOIS-entries
should be made.
I think that's all that needs to be said for now, please apologise if it
got a bit lengthy. If you are interested and willing to participate on
the subject, please drop me a mail, so we can fix further details and
talk about.
Thanks a lot and keep up the good work all of you do daily!
Pascal
[1] http://www.privacyfoundation.ch
[2] http://www.torproject.org
[3] http://www.privacyfoundation.de
hi all,
I'm currently working on a new open-source project. Many of you
know the imperfections of RANCID software, and this project is made to
dramatically change this.
In README section at http://github.com/ssinyagin/gerty
you will find the short concept overview and more in-depth documentation.
At the moment the proof of concept is ready: it can store Cisco configuration
into files, as well as output of other commands, such as "show isis neighbors".
It will be polished and finalized during next months, and I'll be able to
present it at a SwiNOG meeting in Spring or Summer.
your feedback will be appreciated.
cheers,
stan
Hi all
Hostpoint is looking for a system administrator. See the text below
for more information - Sorry for the german-only text. English
speaking candidates are welcome, as well, of course :-)
cheers, Michi
---
Wir (Hostpoint AG, http://www.hostpoint.ch/ ) suchen für den
Standort Rapperswil-Jona per November oder nach Vereinbarung eine
junge, aufgestellte Persönlichkeit (Sie oder Er) als
System Administrator
Als System Administrator (m/w) beteiligst Du Dich aktiv an Betrieb,
Wartung, Kozeptionierung und der stetigen Weiterentwicklung unserer
Hosting-Platform. Dein Denken, Sagen und Handeln stimmen überein.
Du bist in der Lage Abläufe kritisch zu hinterfragen und
konstruktive Kritik zu üben und zu empfangen. Neben Deinem
technischen Know-How im Bereich Unix und Internet ist Dir Neues und
Unbekanntes kein Gräuel sondern eine spannende Herausforderung. Du
magst es Dinge richtig zu lösen. Du analysierst breit und mit
offenen Augen, betrachtest Dinge aus verschiedenen Perspektiven um
Problemen auf die Spur zu kommen und Lösungen zu finden.
Deine Aufgabe:
* Administration und Weiterentwicklung bestehender Dienste und
Systeme
* Integration neuer Dienste in unsere heterogene Umgebung
* Wartung und Sicherstellung des Betriebs unserer Infrastruktur
rund um die Uhr
* Mitarbeit im Betriebssystem- und Software-Management aller Server
* Unterstützung des Kunden-Supports in anspruchsvollen
Problemfällen
Dein Profil:
* Interesse an komplexen technischen Herausforderungen
* Ausgeprägtes analytisches Denken und strukturiertes Vorgehen
* Vertieftes Verständnis von Netzwerkprotokollen: nebst TCP/IP auch
Layer5-7 Protokolle wie HTTP, FTP, SMTP, POP, IMAP etc.
* Der Umgang mit Unix, Shells und Skriptsprachen gehört zu Deinem
Alltag
* Du bist eigeninitiativ, selbständig und eignest Dir neue
Technologien im Selbststudium an
* Du bist engagiert, flexibel und belastbar
* Du arbeitest mit Professionalität und Leidenschaft
* Du agierst lösungsorientiert und eigenverantwortlich
* Bereitschaft zum Piket-Dienst
Wir bieten:
* Eine sehr abwechslungsreiche und vielseitige Tätigkeit in einem
jungen, gut eingespielten Team
* Attraktive Anstellungsbedingungen
* Flexible Arbeitszeiten und 5 Wochen Ferien
* Unterstützung bei Weiterbildungen
* Verantwortung für den Betrieb und der zukünftigen Entwicklung
einer der grössten Hosting- Infrastrukturen der Schweiz.
* Einen angenehmen Arbeitsplatz in grosszügigen Büros mit
Hostpoint-Lounge, Fitnessraum, Getränke- und Kaffee-Flatrate,
Küche und vielem mehr
Haben wir Dein Interesse geweckt? Dann sende uns Deinen SSH Public-
Key mit einer kurzen und aussagekräftigen Beschreibung Deiner
Person und Qualifikation an personal(a)hostpoint.ch. Wir werden Dich
über die nächsten Schritte informieren!
Hello
I quite often stumble over DNS entries without SOA.
$ dig hamedicshopere.ru
; <<>> DiG 9.5.1-P3 <<>> hamedicshopere.ru
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 58271
;; flags: qr rd ra; QUERY: 1, ANSWER: 1, AUTHORITY: 2, ADDITIONAL: 2
;; QUESTION SECTION:
;hamedicshopere.ru. IN A
;; ANSWER SECTION:
hamedicshopere.ru. 300 IN A 109.196.142.11
;; AUTHORITY SECTION:
hamedicshopere.ru. 343295 IN NS ns2.dnssubmit.com.
hamedicshopere.ru. 343295 IN NS ns1.dnsonic.com.
;; ADDITIONAL SECTION:
ns2.dnssubmit.com. 108 IN A 109.196.142.11
ns1.dnsonic.com. 108 IN A 109.196.142.12
Let's try to find the hostmaster or serial or whatever of that zone:
$ dig SOA hamedicshopere.ru
; <<>> DiG 9.5.1-P3 <<>> SOA hamedicshopere.ru
;; global options: printcmd
;; Got answer:
;; ->>HEADER<<- opcode: QUERY, status: NOERROR, id: 64992
;; flags: qr aa; QUERY: 1, ANSWER: 0, AUTHORITY: 1, ADDITIONAL: 0
;; QUESTION SECTION:
;hamedicshopere.ru. IN SOA
;; AUTHORITY SECTION:
ru. 300 IN SOA ns1.ru. root.ru. 2010092811
3600 900 604800 1200
Hmm, no soa returned...
$ host -t soa hamedicshopere.ru
;; connection timed out; no servers could be reached
$ host kjhsdf.hamedicshopere.ru ns1.dnsonic.com.
Using domain server:
Name: ns1.dnsonic.com.
Address: 109.196.142.12#53
Aliases:
kjhsdf.hamedicshopere.ru has address 109.196.142.11
Well, one server is reachable and apparently has a wildcard entry for the
hosts of that zone. But I also don't get the SOA information:
$ host -t soa hamedicshopere.ru ns2.dnssubmit.com.
;; connection timed out; no servers could be reached
a dig +trace also ends at the ru. SOA and entries pointing to the two NS.
So what is broken with that zone (and many many more ru. and cn. zones). Or is
it OK for a DNS Server not to return any SOA information? Isn't that
mandatory?
Mit freundlichen Grüssen
Benoit Panizzon
--
I m p r o W a r e A G - Leiter IT Customer Care
______________________________________________________
Zurlindenstrasse 29 Tel +41 61 826 93 07
CH-4133 Pratteln Fax +41 61 826 93 02
Schweiz Web http://www.imp.ch
______________________________________________________
Hi all,
Has someone of you planed to go/visit to the webhosting day 2011 (this time
in the Europapark in Rust, DE) , either as exhibitor or just as visitor ?
Please write me back off-list.
--
Martin
Problem solved, thanks for all your tests!
An old bogon-list version managed to sneak into one of routers, which was blocking 46.0.0.0/8 and cablecom has been using 46.126.128.0 - 46.127.127.255 since a short while...
Cheers,
Mike
--
Mike Kellenberger mike.kellenberger(a)escapenet.ch
Escapenet - Professional Web Company Tel +41 52 235 0700/04
http://www.escapenet.ch Skype mikek70atwork
-----Ursprüngliche Nachricht-----
Von: Mike Kellenberger
Gesendet: Montag, 11. Oktober 2010 14:48
An: swinog(a)swinog.ch
Betreff: Strange connectivity issues
Hi all
Some of our clients are saying they can't reach us (www.escapenet.ch). Haven't been able to pinpoint the problem yet, most of the clients are using Cablecom as their access-provider, but it can't be a problem for all cablecom users or our phone would be ringing non-stop.
I'd be glad, if a few of you could check if www.escapenet.ch is reachable from your networks - thanks!
Cheers,
Mike
--
Mike Kellenberger mike.kellenberger(a)escapenet.ch
Escapenet - Professional Web Company Tel +41 52 235 0700/04
http://www.escapenet.ch Skype mikek70atwork
Hi all
Some of our clients are saying they can't reach us (www.escapenet.ch).
Haven't been able to pinpoint the problem yet, most of the clients are
using Cablecom as their access-provider, but it can't be a problem for
all cablecom users or our phone would be ringing non-stop.
I'd be glad, if a few of you could check if www.escapenet.ch is
reachable from your networks - thanks!
Cheers,
Mike
--
Mike Kellenberger mike.kellenberger(a)escapenet.ch
Escapenet - Professional Web Company Tel +41 52 235 0700/04
http://www.escapenet.ch Skype mikek70atwork