slazer2au

joined 1 year ago
MODERATOR OF
[–] slazer2au 3 points 9 hours ago

That includes the cleanup right?

[–] slazer2au 1 points 9 hours ago

O.o a QR code that takes you to a url shortener of https://yip.su/25X8U6 which then directs you to a discord invite of https://discord.com/invite/ctkp

Botnet much?

[–] slazer2au 7 points 9 hours ago (1 children)

New communities rather than trending.

[–] slazer2au 5 points 9 hours ago (2 children)

Strands #246
“In a(n) ...”
🔵🔵🔵🔵
🔵🔵🟡🔵

they knew right?

[–] slazer2au 2 points 10 hours ago

Currently listening to Starter Villain

Guy inherited his "billionaire" estranged uncles "parking garage" business, only for his ancillary businesses to be more interesting.

[–] slazer2au 1 points 13 hours ago

Up next, can it run Zelda or Pokemon?

[–] slazer2au 4 points 21 hours ago (1 children)

This may come off as a dumb question, but would javelin be a better search term?

[–] slazer2au 40 points 21 hours ago (3 children)

The trick is to have an automatic feeder and not bother to adjust the clock for DST

 

cross-posted from: https://lemmy.ca/post/32248097

[–] slazer2au 29 points 1 day ago (3 children)

It was only a matter of time

[–] slazer2au 6 points 1 day ago

Absolutely mate.

[–] slazer2au 3 points 2 days ago

I still prefer the term Advanced Persistent Failures for this kind of stuff.

Patch your shit and hire red teams to break into your shit safely.

 

These stories are originally posted over the past decade on Reddits TalesfromTechSupport so I am copying over to Lemmy to help bring some life into this /c/


Some of you know I work for an ISP in a land down under. This incident took place a few ~~months~~ years ago when Apple ios 7.1 came out


Just got back from lunch one day and one of our layer 2 wholesalers call up to log a "fault"

Me: G'day slazer speaking
ResellerIT: Hi mate, I am wanting to log a speed fault with one of our private schools.
Me: no worries mate. What school?
ResellerIT: RegionalPrivateSchool. Your favourite one, they are only getting really high latency and between 5 to 10mb/s

damn it not those guys again

Back story. When this school went live their hardware firewall had a bug where after x amount of data was pushed, it could only do about 20mb/s in either direction.

Me: Considering previous problems with that school have they rebooted their firewall?
ResellerIT: Yes, odd thing happened though, when the firewall came up it ran at the 100mb/s for about 10 - 15 min before dropping back again.
Me: Odd, let me check it out.

I log onto the radio and see the school usage is bouncing between 80 to 100mb/s.

Me: Mate, have you looked at their current usage?
ResellerIT: No, why would I?
Me: Just look. You will work it out.
ResellerIT: Bugger me, that's quite a but of usage. I'll take it from here, sorry to call you mate.

/call

I kept the radio screen open in the background in case he called back and went back to my "active internet monitoring" AKA Reddit while listening to LRRLive on Twitch.

A few hours later I get an email from my boss asking what is happening at RegionalPrivateSchool, he got a call from the account manager. The only time the account manager gets involved is when he isn't getting in info out of his IT team (ResellerIT).

I flicked him an email back recapping my chat with ResellerIT and look at the radio it is still flatlining 80mb/s both ways.

I decided to take a look as to why a school with no students in it is still using 80% of their bandwidth in both directions. So I run the SuperSecretSexySpecial command on the radio that shows the top 20 source and destination IPs along with packets per second in real time.

When looking at the SuperSecretSexySpecial output I do some reverse look ups on the addresses. The school seemed to be pulling an arse tone of traffic from the local Akamai cache and pushing just as much up to addresses that map back to dsl services.

I start thinking, why is the school doing so much data? First thought, second Wednesday of the month Windows updates. But then I thought surely a school should run WSUS in case a bad patch comes out. As for the upload maybe some of the staff have discovered torrents aren't blocked on the firewall and let them run overnight.

I shoot my findings though to my boss, the account manager and ResellerIT. I include in the email that this is all speculation as well as some pointers for fixing it they can pass onto the schools IT guys. I get an email back from the account manager with some comments from the schools IT people saying they don't run windows, it is an Apple school and they are already running the apple version of WSUS. They also boasted that their school was one of the ipad trial schools. 1,300 students all with ipads, my second worse nightmare.

Then I remembered what my work iphone did this morning and an article I was reading at lunch, ios 7.1 for iphone, ipad and ipod came out a few days ago and we all know what happens next. The flood of app updates.

I decided to call the school and talk with their IT guys about running some tests for me. First step was to remove the apple update server network cable. When he did, the traffic dropped back from 80mb/s both ways to about 15mb/s. I asked them to plug the server back in and surely when it came back online the usage started again.

At that point I speculated that the student devices are calling back to the school to get the ios7.1 update and any apps that also require updates.


The following Friday I get an email from the account manager, thanking me for helping with the issue at the school. It turns out I was spot on with the student devices calling back to the school for app updates. After the schools IT guy reconfigured the apple server their speed tests were back up to 100mb/s both ways and sub 15ms response times.

The boss was so happy with my work he let me off early on Friday with a bottle of something special.

 
1
Humble Bundle Cisco Press sale (www.humblebundle.com)
submitted 1 month ago by slazer2au to c/cisco
 

Bunch of Cisco Press books available on Humble Bundle for the next few weeks.

and yes, you can set Pearsons cut to 0%.

 

Microwaves tend to come in 2 types, ones with a rotating plate and ones without. Assuming everything else is equal about a microwave does rotating the food assist with the reheating?

 

Talking about food and why he should get more.

41
submitted 1 month ago* (last edited 1 month ago) by slazer2au to c/talesfromtechsupport
 

Another tale from the the land downunder. This time for all you RF geeks. I apologise in advance if I use dB, dBm, and dBi incorrectly, I tend to use them interchangeably at work.


One of those random things I have to do is support wireless gear that our ISP sells on the side to system integrators for point to point wireless between buildings.
It is fairly easy work, we over engineer the links to perform better than the system integrators expect. This is a story about how the original engineer over engineered the link too much.
The link was installed about 6 years ago and from what I understand hasn't performed as expected.


In the office, at my desk working on how one of our transit providers fudged up their route map and was advertising our address space back to us, a story for another time maybe.

phone rings

Me: G'day slazer speaking.
Customer: Hi, its Customer from [redacted], we bought a wireless link from your firm few years ago and it has been working mostly well till last week when it fell over and we haven't been able to get it back.
Me: Ooooookk, let me grab your details and I will give it a crack.
Customer: The box in the rack says Redline AN50E and the link light is off.
Me: all right, do you still have management access to the radio?
Customer: I do on this side, not the remote site obviously.
Me: Makes sense. on the status page what are the RSSI and SNR values
Customer: RSSI says -86 dbm for all 3 values and SNR is 0 dBm
Me: Is the other end powered on?
Customer: Yes, the guys in the other office can login to the management as well.
Me: That's good, can they tell you the values on that side too?

hold music starts

Customer: They are seeing the same values.

damn

Me: Do you mind if we come down and have a look?
Customer: No worries mate, just ask for me at reception.

I make a list of kit we will need for the job and "delegate" it to my minion to load into the van and we head out.


We get to site and Customer shows us around the master end of the link. I spot the first of many problems. The ethernet is running in half duplex mode (may account for their poor performance.) and the radio is running at 20dB transmit power.

I turn to Customer.

Me: have you played with any of these settings?
Customer: When it was originally installed the tech said if we have any problems with the link we should turn the transmit power up to 20.

I stare blankly at him for a few seconds before double checking I'm not going insane. I make note of the usual misconfiguration suspects, frequency, channel size, encryption enabled, correct encryption key and drop the transmit power down to 1 dB. We head over to the slave end.
Most of the settings are correct, with the exception of transmit power, again it is running at 20dB. I drop it back to 1dB and see the SNR come up above zero for a few seconds before disappearing.

We do a test on the indoor coax cable going to the roof and see no RF coming back down the cable. Damn a faulty outdoor unit. So we head up to the roof and see what we can do about the outdoor unit.

I let my minion and Customer go up the ladder first and as I pop my head out of the roof access hole I see a disaster.

The original tech installed a 60cm panel for a rf link which is no more than 50M. Rf geeks will know why this is a disaster. 20dB of transmit power along with a 28dBi antenna, no way that is legal in Australia.

We swap out the outdoor unit on the slave site, because we were on that side, and as soon as we plugged in the new outdoor unit it started chirping away with its alignment buzzer saying it has the maximum modulation.

Me: That's not good.
Minion: What do you mean? The link is working with this new outdoor unit, so we found the faulty part.
Me: Yea, but where is the antenna connected at the moment?
Minion: In the faulty unit.
Me: Yes, so with 1 dB transmit power on both end and only one 30cm panel on the master side we are forming a link.
Minion: So?
Me: What do you think will happen when we attach the 60 cm panel and put the transmit power back to 20dB?
Minion: It will get saturated and the link will fail.
Me: Yes, so all the drop outs they are talking about is because the link was overengineered too much.

We reattached the panel and looked at the management RSSI -36dB, SNR 30dB.

Me: That has sorted it.

phone rings, Customer comes up on caller ID

Me: Hi mate, we got it back up, how is it looking?
Customer: The link light is on, but I cant ping across the link.

damn it Rf is up and talking but no traffic is passing, the encryption key must be wrong. I get him to correct the encryption key and his traffic starts flowing again.

I confirm the modulation and transmit power are ok and head back over to the master end to talk with Customer.


Me: The outdoor unit is most likely to have burnt out because the RF levels were too strong.
Customer: I notice now when I put the transmit power to 20dB the link goes offline.
Me: Never change that value to above 1 ever
Customer: Ok then. The speeds are better, before it was running between 6 and 12 Mb/s now it is saying 54Mb/s
Me: Yes, because of RF magic we turned the signal power down to get a better signal.
Customer: I'll accept that.

And with that done, Minion and I went back to the office.


Context for those who aren't in the RF world. Imagine having a conversation with someone across an alleyway with one person shouting at the top of their lungs and the other using a megaphone. At some point hearing damage kicks in.

47
submitted 2 months ago* (last edited 2 months ago) by slazer2au to c/talesfromtechsupport
 

When using new wireless kit, never assume the vendor knows what they are doing, most of the time they do not know what the local laws regarding wireless equipment even are. We have some vendors ignore standards while others follow the standard so closely the kit becomes unusable.


We installed a new 900Mhz radio to a customer who was in a particular bad spot. All seem well, the customer was getting the speed over the wireless and the latency was rather good.

A few weeks after install I get a call from the customer.

ring ring

Me: G'day slazer speaking.
Cus: Hi, this is [manager] calling from [customer] we have a guy here saying the radio on our roof is interfering with [national mobile carrier] in the area.
Me: Ooook, that doesn't sound good. Can I talk with him?
Cus: Sure. I'll shoot the call down to reception where he is.

call transfer

Me: G'day this is Slazer, we run the kit on the roof, what is the issue?
CarrierTech: This is CarrierTech from [contracting firm] we have been sent out by [national carrier] to find out why their customers are experiencing call problems in this area.
Me: I see, is [Cus] still hanging around?
CarrierTech: Yes,
Me: Sweet, I need to have a quick word with him and we can sort this out.

Phone passed back to Cus

Me: Hi mate, Thanks for calling us. We will handle everything from here and you wont have to do anything.
Cus: Ok, sounds good, I will pass you back to CarrierTech

Phone ping pong finishes.

Me: Right mate, lets get this sorted. What are you seeing and how can we resolve it.
CarrierTech: I noticed the radio on this roof and our kit is saying it is running in the 900Mhz band. What brand and model is the radio?
Me: It is a Ubiquiti Nanobridge M900.
CarrierTech: Is the firmware up to date and you are running in the Australian country code?
Me: Yes.
CarrierTech: Ok, so it looks like it currently isn't complying with Aussie rules because it is sitting in the middle of the 900Mhz band assigned to [national carrier].
Me: Not good, What is there band?
CarrierTech: [freq band]
Me: Yea, we are sitting in the middle of that, luckily this is a backup link so I can mess with it during business hours. Let me lock out those frequencies and reboot the unit.

few min later

Me: Ok, I have gone as far away as I can from their band, how is it looking?
CarrierTech: I will have to check from outside. Can I have a number I can call you back on?
Me: sure, [insert company number]
CarrierTech: OK, I will call back a little later.


About 20 min later he calls back.

CarrierTech: It looks like that has cleared up the problem. Where does this link go back to?
Me: [insert address from city 10Km away]
CarrierTech: sigh I spent the entire day there yesterday chasing down the same problem and narrowed it down to that street. I should of started at this end.
Me: Well, my apologies mate, I will have to get in touch with the vendor and get this fixed for the next firmware release.
CarrierTech: Yes. I am sure [National Carrier] will also push them and the ACMA about it.
Me: On that note. I assume because the problem is fixed we won't be getting a call from them?
CarrierTech: No, if they complained to the ACMA it would be 6 months before they could do anything about it.
Me: Sounds about right for a government department, just out of curiously how many sites were affected by this?
CarrierTech: About 20 to 30 sites.
Me: wow, now I am really glad you called us first.

insert ending formalities

/End call


I let the boss know what happened and he was glad how it worked out.

Last time we had a run in with the ACMA it ended badly for them, but that is another tale for another time.

 
 
141
My 5ghz kit is interfering with what? (self.talesfromtechsupport)
submitted 2 months ago* (last edited 2 months ago) by slazer2au to c/talesfromtechsupport
 

My incident over ~~2~~ 9 years ago involves the federal regulator making impossible claims.


Working in the wonderful world of Wireless Internet Service Provider (WISPs), you get those calls once in a blue moon that makes you question everything.

phone rings

Me: G'day, this is slazer.
Caller: Hi, this is Fred calling from the ACMA (the Aussie version of the FCC). Can I talk to your senior radio engineer please.
Me: We don't have one, but I am the senior network engineer. I will do what I can do help.
Fred: Ok, I am at [site] and we are detecting some interference on the local council 80Mhz band and we believe your equipment is responsible.
Me: I am sorry, run that by me again.
Fred: We believe the equipment operated by your company on [site] is interfering with the local councils 80Mhz emergency push to talk system.
Me: Ooook. That sounds impossible our equipment is running at 5Ghz. How did you get to that conclusion?
Fred: Well, we have shut down all the other wireless operators on the tower but the interference is still there. In your cabinet there is what looks like an amp which takes up about the bottom 6RU. Would you be able to turn that off?
Me: We don't have an amp in our cabinet. That is our UPS in case there is a power outage.
Fred: A UPS? That explains why your equipment didn't go down when we turned off your breaker.
Me: It also kept beeping at you till you turned the power back on didn't it?
Fred: Yes. So is there a way we can turn your kit off so we can finish our tests?
Me: Not at this time of the day. We have clients actively using the service.
Fred: Ok, I will run some more tests and get back to you.

/call

I take down his number in case he calls back and let my minions know that if he calls put him directly though to me. I call our vendor rep, just to make sure I am correct.

Vendor: Hello this is (dude) from (vendor)
Me: G'day , it is slazer from (WISP). Do you have some time to chat, I just got off the phone with the ACMA.
Vendor: Oh boy, whats up?
Me: Well one of the ACMA "engineers" have said the kit we have installed is interfering with an 80Mhz push to talk system.
Vendor: That doesn't sound possible. If it were possible, we would have people all over the world complaining.
me: I know, just doing a sanity check. I will let you know if it turns out to be your stuff, which I doubt.
Vendor: No worries mate, thanks.

/call

I also call the boss and let him know what is going on. He has the same mind set as the vendor, impossible for us to interfere with an 80Mhz system.

A couple hours pass and he calls back.

Me: g'day mate, how did you go?
Fred: You have a radio pointed between 50 and 60 degrees off the tower, I think that is responsible for the problem.

I look up the radio in question and it is a 5.4Ghz radio.

Me: That can't be. It is a 5Ghz radio.
Fred: can you turn it off so see if the interference goes away?
Me: Like I said before I can't turn off any of our radios unexpectedly during the day, that particular radio goes to the school in [suburb].
Fred: Hmm, when can we turn it off to test?
Me: provided the school is OK with the outage, 2 weeks from now at 3AM.
Fred: Your shitting me?
Me: No, part of the contact we have with the school says we have to give 2 weeks notice for any planed maintenance that could impact their service.
Fred: But why 3AM?
Me: Because that is the time when it will disrupt the schools service the least.
Fred: There has to be a better time then 3AM.
Me: Not really, the schools nightly backup goes from 8PM till 2AM.
Fred: Seriously?
Me: Yes. I will call the school now and organise the outage. I will give you a call back when I have confirmed everything.

/call


I organised the outage with the customer and kept everyone in the loop.


Outage window came along and I got a call from Fred.

Fred: How far off are you?
Me: I am ready to go.
Fred: Eh? Aren't you meeting us here?
Me: No, why spend 2 hours travelling up there at night when I can do it from the comfort of my home?
Fred: OK, well lets get started.
I turn off all the radios except the the one I am using to log into the site via.
Me: They are all off except one, how is it looking?
Fred: Still seeing the interference. When you say they are off, I am still seeing the same amount of lights on your gear in the hut.
Me: I have turned off the radio unit on the outdoor unit. So at the moment all our radios bar one are not transmitting.
Fred: Which one is on?
Me: Our backhaul, if I turn it off I wont be able to turn it back on remotely. What I can do is bounce it. Have are you looking at your kit?
Fred: Yes.

I reboot the final backhaul radio.

Me: OK, you have about 2 min before it comes back online. How is it looking?
Fred: No different...... What in the world is causing this interference.
Me: No clue mate, we operate in the 5Ghz band. Seeing as you haven't found anything I am going to turn our kit back on now.
Fred: but we haven't finished testing yet.
Me: Yes we have, all our kit was off and you said there was no difference in the interference.
Fred: It must be your kit. It is the only unlicensed kit in the area. Everyone else is using licensed spectrum.
Me: ............. I would ask how you came to the conclusion of they don't use licensed spectrum so they must be the problem, but it is 3AM and I would like to go back to bed.
Fred: But we aren't done yet.
Me: Yes, we are. Good night.

/call

I turn on our equipment again and write up a report for the boss, then return to bed.


A couple days later, we received a warning notice from the ACMA about the events that transpired. Sadly, this is where my part in the story ends and the boss picks it up.

After several back and forth between the boss, our lawyers, and the ACMA rep. The warning is withdrawn and the 80Mhz kit gets moved to another tower a couple hundred meters down the road only to run into the same interference problem.

I don't know if they ever fixed the problem, it has been a few years and it doesn't bother me.

1
FortOS 7.2.9 released (docs.fortinet.com)
submitted 2 months ago by slazer2au to c/fortinet
 

80/81F-DSL, 90/91G, and 120/121G devices are finally merged

view more: next ›