Language:
switch to room list switch to menu My folders
Go to page: 1 3 4 5 6 [7] 8 9 10 11 ... Last
[#] Tue Sep 29 2020 20:03:28 EDT from warbaby

Subject: New Fail2ban filter for Citadel .. in the citadel Security room.

[Reply] [ReplyQuoted] [Headers] [Print]

We've been getting brute-forced quit a bit lately.  Maybe it's the Democrats, or the Red Chinese?

Anyway.. wrote a filter for you guys, because you are are very special people. and I like you a lot. 

it's in the Citadel Security Room!

- God bless

-warbaby



[#] Tue Sep 29 2020 20:10:49 EDT from warbaby

Subject: Re: CPU Spikes.. Default admin username and the bloody Russians..

[Reply] [ReplyQuoted] [Headers] [Print]

I got sick of messing around with them and wrote a basic fail2ban filter, its posted in the Security room. 

Spent some time to try and determine if there was anything really specific to Citadel, as though it was being targeted..

It "felt" like it, but I can't say definitively. 

It's not hard to "enumerate" users with a big list of usernames.. try to send mail by smtp, and just keep a list of the good users for each box.. it's child's play.. we did that years and years ago..

Anyway.. trying to build some kind of real security perspectve, not just be dramatic..

:)

Also, very interesting about uid -1..  Thanks Art!

 

 

Tue Sep 29 2020 07:28:26 PM EDT from IGnatius T Foobar @ Uncensored Subject: Re: CPU Spikes.. Default admin username and the bloody Russians..
Also, what is up with UID "-1"??

Clearly from Russia..  drilling me non-stop.


It looks to me like someone is hunting for open proxies. Why they are stuck in a loop on your site ... who knows ... maybe Citadel confuses their scanner?

UID "-1" means that there is no UID on the underlying operating system associated with the Citadel account in question.

 



[#] Wed Sep 30 2020 12:39:37 EDT from rimugu

Subject: Citadel language

[Reply] [ReplyQuoted] [Headers] [Print]

Hi, I just installed Citadel for use in my club ham radio mesh network.

But I wonder if Citadel is available in other languages (some don't speak English).

Regards,



[#] Thu Oct 01 2020 01:13:10 EDT from spbear50

Subject: I installed citadel. How do I open admin area?

[Reply] [ReplyQuoted] [Headers] [Print]

The title pretty much says it. I installed the program on Ubuntu 20.04 LAMP and I can't figure out how to get to the admin of the program. I think its called Webcit, but how do you access it?



[#] Thu Oct 01 2020 18:05:16 EDT from warbaby

Subject: Re: I installed citadel. How do I open admin area?

[Reply] [ReplyQuoted] [Headers] [Print]

see if webcit is running..

ps aux | grep webcit

netstat -lnp

should be running on the port(s) you chose during setup..

http://localhost:8080/

https://localhost:443/

https://localhost:2001/

something like that..

it's actually two services.. webcit-http and webcit-https

cd /etc/

grep -i 'webcit' # should tell you something..

once you get it open in a web browser, log in using the username and password you specified during setup. admin/citadel is the default.

The Administartion button is in the left column under 'Advanced' if the account has privileges. 

 

Thu Oct 01 2020 01:13:10 AM EDT from spbear50 @ Uncensored Subject: I installed citadel. How do I open admin area?

The title pretty much says it. I installed the program on Ubuntu 20.04 LAMP and I can't figure out how to get to the admin of the program. I think its called Webcit, but how do you access it?



 



[#] Thu Oct 01 2020 20:41:51 EDT from plentipeppa

[Reply] [ReplyQuoted] [Headers] [Print]

Hi all,

Set up citadel mail server on Raspberry pi 4 everything work well i can send and receive mail but with this nasty annoyance because i dont have ssl.

I not got ssl cert from a certificate authority.

I cant figure out where i put this cert and the other files.

Can someone point me where i should place my certificate.

Thanks for your help in advance.

 

Del



[#] Thu Oct 01 2020 23:13:58 EDT from warbaby

[Reply] [ReplyQuoted] [Headers] [Print]

do you have a certificate?  If not, check out let'sencrypt.   You can make them with certbot. 

Then.. assuming you used easyinstall..

root@mail:/usr/local/citadel/keys# tree
.
├── citadel.cer
├── citadel.key

same structure for webcit

citadel.cer is the certificate (use fullchain.pem if you have it)

citadel.key is your private key.

Your files should be copied (not linked) to both locations, with those exact names.

then (as root)

chown root:staff *

chmod 600 *

-rw------- 1 root    staff   3.5K Jul  8 20:20 citadel.cer
-rw------- 1 root    staff   1.7K Jul 12 07:46 citadel.key

/usr/local/citadel/keys is for your mail server (imap/smtp)

/usr/local/webcit/keys is for https on webcit

restart your machine (or the services)

then re-connect with your mail client, and browser.. and check your new cert.

Thu Oct 01 2020 08:41:51 PM EDT from plentipeppa @ Uncensored

Hi all,

Set up citadel mail server on Raspberry pi 4 everything work well i can send and receive mail but with this nasty annoyance because i dont have ssl.

I not got ssl cert from a certificate authority.

I cant figure out where i put this cert and the other files.

Can someone point me where i should place my certificate.

Thanks for your help in advance.

 

Del



 



[#] Mon Oct 12 2020 10:49:15 EDT from s3cr3to to Citadel_Support <room_Citadel_Support@uncensored.citadel.org>

Subject: Re: New Fail2ban filter for Citadel .. in the citadel Security room.

[Reply] [ReplyQuoted] [Headers] [Print]

Good day warbaby!

I wonder if it will be possible to whitelist the IP of our company in
the script. Sure, for testing I can try a blocking of a few minutes (1
minute tops), but if tests are done or by mistake we write a wrong
password when configuring a new client, this would block ALL users who
are behind the correct IP.



On 9/29/20 6:03 PM, warbaby wrote:
We've been getting brute-forced quit a bit lately.  Maybe it's the
Democrats, or the Red Chinese?

Anyway.. wrote a filter for you guys, because you are are very special
people. and I like you a lot.

it's in the Citadel Security Room! <dotgoto?room=Citadel%20Security>

- God bless

-warbaby

[#] Mon Oct 12 2020 12:11:24 EDT from LoanShark

[Reply] [ReplyQuoted] [Headers] [Print]


It's definitely the Democrats. I know. I wrote the bot.

[#] Mon Oct 12 2020 13:25:42 EDT from warbaby

Subject: Re: New Fail2ban filter for Citadel .. in the citadel Security room.

[Reply] [ReplyQuoted] [Headers] [Print]

HI s3crt3o!

Yes, you can add

ignoreip =

To your jail.conf (or jail.local), then restart fail2ban.

but even so, you might want to set up a dev box for testing on any inexpensive vps.. just a few cents to install citadel, fail2ban and test, then take a snapshot and shut it down..

Also, you might like to familiarize yourself with the fail2ban client.. it lets you list the jails and display information about them.. also, a relatively easy "unban" action..

root@mail:~# fail2ban-client status
Status
|- Number of jail:	2
`- Jail list:	citadel, sshd
root@mail:~# fail2ban-client status citadel
Status for the jail: citadel
|- Filter
|  |- Currently failed:	0
|  |- Total failed:	8
|  `- File list:	/var/log/syslog
`- Actions
   |- Currently banned:	0
   |- Total banned:	0
   `- Banned IP list:	
root@mail:~# 

fail2ban-client set citadel unbanip <ipaddress>

Some of the details will be version/distro dependent..but that's probably the simplest way to keep you from needing to hack around in iptables..

 

Mon Oct 12 2020 10:49:15 AM EDT from "s3cr3to" <s3cr3to@uncensored.citadel.org> Subject: Re: New Fail2ban filter for Citadel .. in the citadel Security room.
Good day warbaby!

I wonder if it will be possible to whitelist the IP of our company in
the script. Sure, for testing I can try a blocking of a few minutes (1
minute tops), but if tests are done or by mistake we write a wrong
password when configuring a new client, this would block ALL users who
are behind the correct IP.



On 9/29/20 6:03 PM, warbaby wrote:
We've been getting brute-forced quit a bit lately.  Maybe it's the
Democrats, or the Red Chinese?

Anyway.. wrote a filter for you guys, because you are are very special
people. and I like you a lot.

it's in the Citadel Security Room! <dotgoto?room=Citadel%20Security>

- God bless

-warbaby

 



[#] Mon Oct 12 2020 13:17:33 EDT from s3cr3to to Citadel_Support <room_Citadel_Support@uncensored.citadel.org>

Subject: Re: New Fail2ban filter for Citadel .. in the citadel Security room.

[Reply] [ReplyQuoted] [Headers] [Print]

Found it!

https://www.fail2ban.org/wiki/index.php/Whitelist
Whitelisting

Whitelisting is setup in the jail.conf file using a space separated list.

[DEFAULT]
# "ignoreip" can be an IP address, a CIDR mask or a DNS host. Fail2ban
will not
# ban a host which matches an address in this list. Several addresses
can be
# defined using space separator.

ignoreip = 127.0.0.1 192.168.1.0/24 8.8.8.8

# This will ignore connection coming from common private networks.
# Note that local connections can come from other than just 127.0.0.1, so
# this needs CIDR range too.
ignoreip = 127.0.0.0/8 10.0.0.0/8 172.16.0.0/12 192.168.0.0/16



On 10/12/20 8:49 AM, s3cr3to wrote:

Good day warbaby!

I wonder if it will be possible to whitelist the IP of our company in
the script. Sure, for testing I can try a blocking of a few minutes (1
minute tops), but if tests are done or by mistake we write a wrong
password when configuring a new client, this would block ALL users who
are behind the correct IP.



On 9/29/20 6:03 PM, warbaby wrote:
We've been getting brute-forced quit a bit lately.  Maybe it's the
Democrats, or the Red Chinese?

Anyway.. wrote a filter for you guys, because you are are very special
people. and I like you a lot.

it's in the Citadel Security Room! <dotgoto?room=Citadel%20Security>

- God bless

-warbaby

[#] Mon Oct 12 2020 15:31:31 EDT from platonov

Subject: Is there a problem of incorrect displaying of Subject: header?

[Reply] [ReplyQuoted] [Headers] [Print]

I have 2 citadel systems 8.24 and 9.17.

What I am seeing on 9.17 is incorrect displaying or not displaying at all of Subject: header in RSS feed rooms.

Following are few examples of how Subject is displayed on 8.24 and 9.17

Mon Oct 12 2020 04:00:00 UTC from rss
Subject: JOE BIDEN’S ODD-SOUNDING CAMPAIGN SLOGAN ‘BUILD BACK BETTER’ WAS ACTUALLY TAKEN FROM UNITED NATIONS NEW WORLD ORDER AGENDA
Subject: JOE BIDEN

Sun Oct 11 2020 04:00:00 UTC from rss
Subject: World Health Organization Doctor: COVID Lockdowns Caused “Ghastly Global Catastrophe”
Subject: World Health Organization Doctor: COVID Lockdowns Caused

Fri Oct 09 2020 04:00:00 UTC from rss
Subject: PRESIDENT TRUMP: “TOTAL DECLASSIFICATION” OF ANY/ALL DOCUMENTS RELATED TO RUSSIA INVESTIGATION
Subject: PRESIDENT TRUMP:

Fri Oct 09 2020 07:00:00 AM EEST from rss
Subject: ‘Secret’ ATF move could turn 3M to 4M gun owners into felons
NO Subject: header present at all

Furthermore, the RSS feed rooms that are in Russian language particularly do not display the Subject: header AT ALL. It is simply missing like the article does not have this header at all.

Anybody has any feedback on this?

Thanx in advance.'



[#] Mon Oct 19 2020 16:16:52 EDT from Richard Saunders <saunders.richard.p@gmail.com> to room_citadel_support@citadel.org

Subject: unsubscribe?

[Reply] [ReplyQuoted] [Headers] [Print]

I have looked at the web site and at the list emails and cannot find any clue about how to unsubscribe from this list! Most lists have an unsubscribe heading in each email or a link or something. Can someone please enlighten me?


[#] Mon Oct 19 2020 16:33:46 EDT from warbaby

Subject: Re: unsubscribe?

[Reply] [ReplyQuoted] [Headers] [Print]

http://uncensored.citadel.org/listsub

Mon Oct 19 2020 04:16:52 PM EDT from "Richard Saunders" <saunders.richard.p@gmail.com> Subject: unsubscribe?
I have looked at the web site and at the list emails and cannot find any clue about how to unsubscribe from this list! Most lists have an unsubscribe heading in each email or a link or something. Can someone please enlighten me?


 



[#] Tue Oct 20 2020 07:53:06 EDT from attikus

Subject: SMTP email queue

[Reply] [ReplyQuoted] [Headers] [Print]

Hello friends of Citadel!


I have Citadel running since a few years as my main mail server and I'm totally satisfied with it.
This morning I experienced another reason to be totally satisfied:
Yesterday the disk in my server broke and the mail server was - obviously - offline. I didn't have time until this morning to restore the server, but after the server was restored a few minutes later a bulk of emails came in from the time when the server was offline.
It's totally cool that I didn't lose any emails - but how is that possible?
Where is the email queue that held the emails back? Or do incoming emails just get stuck in port 25 (or 587) in the event of a server failure?
I have a Mikrotik Router just for info, but I don't believe that the Router is the cause for that effect. Does anybody know why incoming emails are kept back in such an event?

Thank you,
have a nice day!



[#] Tue Oct 20 2020 07:43:00 EDT from Marisa Giancarla <fstltna@yahoo.com> to room_Citadel_Support@citadel.org

Subject: Re: [Citadel Support] SMTP email queue

[Reply] [ReplyQuoted] [Headers] [Print]

That is how mail servers work - if they have a issue sending mail they
leave it in a queue on the senders system and try it again later. They
keep trying for a period of time. Short answer is that they are on the
individual senders mail servers...


Marisa

On 10/20/20 4:53 AM, attikus wrote:

Hello friends of Citadel!


I have Citadel running since a few years as my main mail server and
I'm totally satisfied with it.
This morning I experienced another reason to be totally satisfied:
Yesterday the disk in my server broke and the mail server was -
obviously - offline. I didn't have time until this morning to restore
the server, but after the server was restored a few minutes later a
bulk of emails came in from the time when the server was offline.
It's totally cool that I didn't lose any emails - but how is that
possible?
Where is the email queue that held the emails back? Or do incoming
emails just get stuck in port 25 (or 587) in the event of a server
failure?
I have a Mikrotik Router just for info, but I don't believe that the
Router is the cause for that effect. Does anybody know why incoming
emails are kept back in such an event?

Thank you,
have a nice day!

[#] Tue Oct 20 2020 08:03:35 EDT from attikus

Subject: Re: [Citadel Support] SMTP email queue

[Reply] [ReplyQuoted] [Headers] [Print]

Thank you Marisa for the really quick answer!

That makes a lot of sense. Interestingly some of those mails were sent from a different server of mine (Monitoring) via Exim4. That means that Exim4 has such a queue implemented, I never thought about that :)
I have to research that and then I should be able to see the queue on the Monitoring Server.
Once again thanks!



[#] Tue Oct 20 2020 08:20:39 EDT from attikus

Subject: Port 25

[Reply] [ReplyQuoted] [Headers] [Print]

Haha well, the mail queue for Exim4 was not very hard to find - now all of this makes sense to me!

 

But I want to ask another theoretical question that I have in my mind since years.
I think it's strange that it is just not possible to find the answer for this online even though mail servers are common and the technology is not new - still the knowledge is very hard to find.
On my Router I redirect port 25 to 587 to prevent SMTP hijacking because the server is exposed to the internet. Since then I didn't have any problems with bots using my SMTP for sending spam mails because on port 587 they have to authenticate.
Once I tried to add a rule that only my trusted IPs can use port 25. Unfortunately then I didn't receive any emails from other people anymore because it seems like the whole world is using port 25 to send emails and not 587.
So I never found a better solution for this than redirecting port 25 to 587 - how are you guys handling this?

Thank you and have a nice day!



[#] Tue Oct 20 2020 11:55:50 EDT from warbaby

Subject: Re: Port 25

[Reply] [ReplyQuoted] [Headers] [Print]

 Any client can connect to, but should still have to authenticate to send on port 25. If not you are basically running an open relay...

Tue Oct 20 2020 08:20:39 AM EDT from attikus @ Uncensored Subject: Port 25

Haha well, the mail queue for Exim4 was not very hard to find - now all of this makes sense to me!

 

But I want to ask another theoretical question that I have in my mind since years.
I think it's strange that it is just not possible to find the answer for this online even though mail servers are common and the technology is not new - still the knowledge is very hard to find.
On my Router I redirect port 25 to 587 to prevent SMTP hijacking because the server is exposed to the internet. Since then I didn't have any problems with bots using my SMTP for sending spam mails because on port 587 they have to authenticate.
Once I tried to add a rule that only my trusted IPs can use port 25. Unfortunately then I didn't receive any emails from other people anymore because it seems like the whole world is using port 25 to send emails and not 587.
So I never found a better solution for this than redirecting port 25 to 587 - how are you guys handling this?

Thank you and have a nice day!



 



[#] Tue Oct 20 2020 12:00:25 EDT from platonov

Subject: how to compact database that has lots of deleted records?

[Reply] [ReplyQuoted] [Headers] [Print]

The database on my 8.24 node has gotten too big to manage. Is there a way to compact it so that it only contains the records that exist without all the deleted records?

 



Go to page: 1 3 4 5 6 [7] 8 9 10 11 ... Last