<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
	<channel>
		<atom:link href="https://dev1galaxy.org/extern.php?action=feed&amp;tid=6317&amp;type=rss" rel="self" type="application/rss+xml" />
		<title><![CDATA[Dev1 Galaxy Forum / Potentially compromised repository]]></title>
		<link>https://dev1galaxy.org/viewtopic.php?id=6317</link>
		<description><![CDATA[The most recent posts in Potentially compromised repository.]]></description>
		<lastBuildDate>Mon, 08 Jan 2024 16:02:03 +0000</lastBuildDate>
		<generator>FluxBB</generator>
		<item>
			<title><![CDATA[Re: Potentially compromised repository]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=47064#p47064</link>
			<description><![CDATA[<p>Hello @pcalvert</p><p>Re-examinging your posts reveal something...<br />the terminal output shows the repo as &quot;repo.jing.rocks&quot; as http,<br />but the two links you posted as visiting are both links as https. </p><p>Presumably, your browser is configured to&#160; redirect to the secure page, but the http mirror is being blocked by default eero policy.&#160; If you have auto updates enabled, the company might be restricting your connections without your input, and you should be able to disable it from within the&#160; eero&#039;s settings.</p><p>At the risk of going offtopic, you might consider a router with custom firmware (OpenWRT is my favorite) for more granular control.</p><p>Additionally, if you can provide me with your DNS servers, I can examine whether they might be blocking this mirror.</p><p>Regards,<br />nietz</p>]]></description>
			<author><![CDATA[dummy@example.com (Nietz)]]></author>
			<pubDate>Mon, 08 Jan 2024 16:02:03 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=47064#p47064</guid>
		</item>
		<item>
			<title><![CDATA[Re: Potentially compromised repository]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=47047#p47047</link>
			<description><![CDATA[<p>all working ok now(checked w/ dillo, firefox, links, and lynx)</p>]]></description>
			<author><![CDATA[dummy@example.com (stargate-sg1-cheyenne-mtn)]]></author>
			<pubDate>Mon, 08 Jan 2024 02:19:28 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=47047#p47047</guid>
		</item>
		<item>
			<title><![CDATA[Re: Potentially compromised repository]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=47027#p47027</link>
			<description><![CDATA[<p>Hi Nietz,</p><p>The website <strong>repo.jing.rocks</strong> is being blocked for &quot;Phishing &amp; Deception&quot;. That is the only reason it is being blocked. I have not configured the manual blocking of any websites via the router. If I wanted to block a website, I would use another means, like <em>dnsmasq</em>.</p><p>If I try to visit <strong>repo.jing.rocks</strong> using Firefox, I am presented with this message:</p><div class="quotebox"><blockquote><div><p>Whoopsie<br />Your device is not allowed to access this site.</p><p>We hate to be the bearers of bad news, but this site has been blocked. If you believe that this site was categorized incorrectly, you can report it as inaccurate.</p></div></blockquote></div><p>When I last tried to access that URL (right after the aptitude upgrade failure), the block message was different, and indicated that the site was not safe to visit.</p><p>I also tried to visit <a href="https://jing.rocks" rel="nofollow">jing.rocks</a> and <a href="https://status.jing.rocks" rel="nofollow">status.jing.rocks</a>. Those websites are <em>not</em> being blocked.</p>]]></description>
			<author><![CDATA[dummy@example.com (pcalvert)]]></author>
			<pubDate>Sun, 07 Jan 2024 22:11:15 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=47027#p47027</guid>
		</item>
		<item>
			<title><![CDATA[Re: Potentially compromised repository]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46998#p46998</link>
			<description><![CDATA[<p>Hello pcalvert,</p><p>Do you have access to your router&#039;s settings?&#160; I see you are using an eero router, correct? <br />Can you please inspect the list of blocked websites according to the manufacturer&#039;s help page here:<br /><a href="https://support.eero.com/hc/en-us/articles/360045634132-Block-Allow-Websites" rel="nofollow">https://support.eero.com/hc/en-us/artic … w-Websites</a></p><p>Is your router configured for geographical restrictions?&#160; A download from a server overseas might be blocked for that reason.&#160; Do you have a custom DNS provider configured?</p><p>Finally, what happens when you visit <a href="http://repo.jing.rocks" rel="nofollow">repo.jing.rocks</a> in an Internet browser?</p>]]></description>
			<author><![CDATA[dummy@example.com (Nietz)]]></author>
			<pubDate>Sun, 07 Jan 2024 14:40:56 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46998#p46998</guid>
		</item>
		<item>
			<title><![CDATA[Potentially compromised repository]]></title>
			<link>https://dev1galaxy.org/viewtopic.php?pid=46977#p46977</link>
			<description><![CDATA[<p>Yesterday I attempted to upgrade my Daedalus-based Refracta system, but the connections were blocked by my router for security reasons.</p><div class="codebox"><pre class="vscroll"><code># aptitude upgrade
Resolving dependencies...                
The following NEW packages will be installed:
  linux-headers-6.1.0-17-amd64{a} linux-headers-6.1.0-17-common{a} 
  linux-image-6.1.0-17-amd64{a} 
The following packages will be upgraded:
  bluez bluez-obexd curl exim4 exim4-base exim4-config exim4-daemon-light 
  libbluetooth3 libcurl3-gnutls libcurl4 libgstreamer-plugins-bad1.0-0 
  libssh-gcrypt-4 linux-compiler-gcc-12-x86 linux-headers-amd64 
  linux-image-amd64 linux-kbuild-6.1 linux-libc-dev openssh-client 
The following packages are RECOMMENDED but will NOT be installed:
  apparmor bsd-mailx mailutils 
18 packages upgraded, 3 newly installed, 0 to remove and 0 not upgraded.
Need to get 90.2 MB of archives. After unpacking 469 MB will be used.
Do you want to continue? [Y/n/?] y
Ign http://deb.devuan.org/merged daedalus-security/main amd64 bluez amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 openssh-client amd64 1:9.2p1-2+deb12u2
Ign http://deb.devuan.org/merged daedalus-security/main amd64 bluez-obexd amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 curl amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libcurl4 amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 bluez amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 openssh-client amd64 1:9.2p1-2+deb12u2
Ign http://deb.devuan.org/merged daedalus-security/main amd64 bluez-obexd amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 curl amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libcurl4 amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-config all 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4 all 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-base amd64 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-daemon-light amd64 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libbluetooth3 amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libcurl3-gnutls amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libgstreamer-plugins-bad1.0-0 amd64 1.22.0-4+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libssh-gcrypt-4 amd64 0.10.6-0+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-compiler-gcc-12-x86 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-common all 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-kbuild-6.1 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-6.1.0-17-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-libc-dev amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 bluez amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 openssh-client amd64 1:9.2p1-2+deb12u2
Ign http://deb.devuan.org/merged daedalus-security/main amd64 bluez-obexd amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 curl amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libcurl4 amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-config all 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4 all 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-base amd64 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-daemon-light amd64 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libbluetooth3 amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libcurl3-gnutls amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libgstreamer-plugins-bad1.0-0 amd64 1.22.0-4+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libssh-gcrypt-4 amd64 0.10.6-0+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-compiler-gcc-12-x86 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-common all 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-kbuild-6.1 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-6.1.0-17-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-libc-dev amd64 6.1.69-1
Err http://deb.devuan.org/merged daedalus-security/main amd64 bluez amd64 5.66-1+deb12u1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 openssh-client amd64 1:9.2p1-2+deb12u2
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 bluez-obexd amd64 5.66-1+deb12u1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 curl amd64 7.88.1-10+deb12u5
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 libcurl4 amd64 7.88.1-10+deb12u5
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-config all 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4 all 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-base amd64 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 exim4-daemon-light amd64 4.96-15+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libbluetooth3 amd64 5.66-1+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libcurl3-gnutls amd64 7.88.1-10+deb12u5
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libgstreamer-plugins-bad1.0-0 amd64 1.22.0-4+deb12u4
Ign http://deb.devuan.org/merged daedalus-security/main amd64 libssh-gcrypt-4 amd64 0.10.6-0+deb12u1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-compiler-gcc-12-x86 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-common all 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-kbuild-6.1 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-6.1.0-17-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-amd64 amd64 6.1.69-1
Ign http://deb.devuan.org/merged daedalus-security/main amd64 linux-libc-dev amd64 6.1.69-1
Err http://deb.devuan.org/merged daedalus-security/main amd64 exim4-config all 4.96-15+deb12u4
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 exim4 all 4.96-15+deb12u4
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 exim4-base amd64 4.96-15+deb12u4
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 exim4-daemon-light amd64 4.96-15+deb12u4
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 libbluetooth3 amd64 5.66-1+deb12u1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 libcurl3-gnutls amd64 7.88.1-10+deb12u5
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 libgstreamer-plugins-bad1.0-0 amd64 1.22.0-4+deb12u4
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 libssh-gcrypt-4 amd64 0.10.6-0+deb12u1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-compiler-gcc-12-x86 amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-common all 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-kbuild-6.1 amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-6.1.0-17-amd64 amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-headers-amd64 amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-6.1.0-17-amd64 amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-image-amd64 amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
Err http://deb.devuan.org/merged daedalus-security/main amd64 linux-libc-dev amd64 6.1.69-1
  Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
0% [Working]E: Failed to fetch https://blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks/: Could not resolve &#039;blocked.eero.com?cat=advanced_security&amp;reason=52&amp;url=repo.jing.rocks&#039;
E: Unable to fetch some packages; try &#039;-o APT::Get::Fix-Missing=true&#039; to continue with missing packages</code></pre></div><p>The potentially compromised repository is <strong>repo.jing.rocks</strong>. According to the app for my router, the reason for the block is &quot;Phishing &amp; Deception&quot;.</p>]]></description>
			<author><![CDATA[dummy@example.com (pcalvert)]]></author>
			<pubDate>Sun, 07 Jan 2024 04:32:15 +0000</pubDate>
			<guid>https://dev1galaxy.org/viewtopic.php?pid=46977#p46977</guid>
		</item>
	</channel>
</rss>
