linux poison RSS
linux poison Email
0

File Access Permissions on Linux

File protection with chmod
chmod 400 file    To protect a file against accidental overwriting.
chmod 500 dir     To protect yourself from accidentally removing,  renaming or moving files from this directory.
chmod 600 file    A private file only changeable by the user who entered this command.
chmod 644 file    A publicly readable file that can only be changed by the issuing user.
chmod 660 file    Users belonging to your group can change this files, others don't have any access to it at all.
chmod 700 file    Protects a file against any access from other users, while the issuing user still has full access.
chmod 755 dir     For files that should be readable and executable by others, but only changeable by the issuing user.
chmod 775 file    Standard file sharing mode for a group.
chmod 777 file    Everybody can do everything to this file. 

Special modes sticky bit
•         sticky bit
–        chmod +t
•         when set on
–        file:  if sticky bit set, after job execution, the command is kept in memory
–        directory: can only change files in this dir when user is owner of the file or has  appropriate permissions see /tmp

Special modes set id
•         set user id bit SUID
–        chmod u+s
•         set group id bit (SGID)
–        chmod g+s
•         when set on
–        binary file: when run it runs with the group and or user of the file not the group/user of the person running it.
–        directory: (SGID only) every file created in the directory takes same group as the directory, not the  creator's group. 
            note: existing and copied files keep their group id)

Special modes numeric (octal) representation
0 setuid, setgid, sticky bits are cleared
1 sticky bit is set
2 setgid bit is set
3 setgid and sticky bits are set
4 setuid bit is set
5 setuid and sticky bits are set
6 setuid and setgid bits are set
7 setuid, setgid, sticky bits are set

Special modes textual representation
•         SUID: If set, then replaces "x" in the owner permissions to "s", if owner has execute ermissions, or to "S" otherwise. Examples:
-rws------ both owner execute and SUID are set
-r-S------ SUID is set, but owner execute is not set
•         SGID: If set, then replaces "x" in the group permissions to "s", if group has execute permissions, or to "S" otherwise. Examples:
-rwxrws--- both group execute and SGID are set
-rwxr-S--- SGID is set, but group execute not set
•         Sticky bit: If set, then replaces "x" in the others permissions to "t", if others have execute permissions, or to "T" otherwise. Examples:
-rwxrwxrwt both others execute and sticky bit are set
-rwxrwxr-T sticky bit is set, but others execute is not set
Read more
2

How To Write, Compile and Execute C Programs under Linux

Most Linux and Unix programs are written in C. When you download source for a project, it will often be C or C++ source code. You don't necessarily need to know a darn thing about C or anything else to compile the source if you aren't changing it. It may be helpful for you to understand a bit if you are having problems with the compile, but even that isn't really necessary.

You can type you C program using any of the editors that are available under Linux such as vi or emacs or any other editor. My favourite is vi.

Source Code:
Write a Hello World C Program: Create a file call "firstprogram.c" in vi and type the following content into this file and save it.
#include<stdio.h>
main()
{
   printf("Hello World\n");
   printf("My First C Program\n");
}
Once you have written and saved your C program using any editor return to the prompt. An “ls” command should display your C program. It should have the .c extension. Now at the prompt type the following

$ gcc firstprogram.c

You would be having a a.out in the same directory as the source C file. This is the default name of the executable that gcc creates. This would create problems when you compile many programs in one directory. So you override this with the -o option followed by the name of the executable

$ gcc -o hello firstprogram.c

Would create an executable by the name hello for your source code named firstprogram.c
Running the executable that you created is as simple as typing the following at the prompt.

$ ./hello

Or whatever you named your executable.
Read more
6

How To do "Man in Middle" Attack using Ettercap

"Man in Middle" Attack is a form of active eavesdropping in which the attacker makes independent connections with the victims and relays messages between them, making them believe that they are talking directly to each other over a private connection when in fact the entire conversation is controlled by the attacker. The attacker must be able to intercept all messages going between the two victims and inject new and modified messages to one or both of them, which is straightforward in many circumstances (for example, an attacker within reception range of an unencrypted Wi-Fi wireless access point, can insert himself as a man-in-the-middle). example in form of picture is shown below.

 
Ettercap is a suite for man in the middle attacks on LAN. It features sniffing of live connections, content filtering on the fly and many other interesting tricks. It supports active and passive dissection of many protocols (even ciphered ones) and includes many feature for network and host analysis.

Installation: OpenSuSe 11.1 user can use "1-click" installer to install Ettercap - Here

Running Ettercap:You need to select a user interface (no default) using -T for Text only, -C for the Ncurses based GUI, or -G for the nice GTK2 interface (e.g) - # ettercap -G

Open Ettercap in graphical mode: # ettercap -G


Select the sniff mode: Sniff → Unified sniffing and Scan for host inside your subnet Hosts → Scan for hosts


See the MAC and  IP addresses of the hosts inside your subnet: Hosts → Hosts List, from this list Select the machines to poison

We chose to ARP poison only the windows machine 192.168.1.2 and the router 192.168.1.1.
Highlight the line containing 192.168.1.1 and click on the "target 1" button.
Highlight the line containing 192.168.1.2 and click on the "target 2" button.


Start the ARP poisoning: Mitm → Arp poisoning and start the sniffer to see the activities


ARP TRAFFIC before the poisoning:
As you can see that the router and the Windows machine send an ARP broadcast to find the MAC address of the other.

No
1
2
3
4
Source
11:22:33:44:55:66
11:22:33:44:11:11
11:22:33:44:11:11
11:22:33:44:55:66
Destination
11:22:33:44:11:11
11:22:33:44:55:66
11:22:33:44:55:66
11:22:33:44:11:11
Prot
ARP
ARP
ARP
ARP
Info
who has 192.168.1.1? Tell 192.168.1.2
192.168.1.1 is at 11:22:33:44:11:11
who has 192.168.1.2? Tell 192.168.1.1
192.168.1.2 is at 11:22:33:44:55:66

ARP TRAFFIC after the poisoning
The router ARP broadcast request is answered by the Windows machine similarly than in the previous capture.

The difference between the two steps comes from the fact that there is no request coming from Windows (192.168.1.2) to find the MAC address associated to the router (192.168.1.1) because the poisoner continuously sends ARP packets telling the Windows machine that 192.168.1.1 is associated to his own MAC address (11:22:33:44:99:99) instead of the router MAC address (11:22:33:44:11:11).

No
1
2
3
4
Source
11:22:33:44:11:11
11:22:33:44:55:66
11:22:33:44:99:99
11:22:33:44:99:99
Destination
11:22:33:44:55:66
11:22:33:44:11:11
11:22:33:44:55:66
11:22:33:44:55:66
Prot
ARP
ARP
ARP
ARP
Info
who has 192.168.1.2? Tell 192.168.1.1
192.168.1.2 is at 11:22:33:44:55:66
192.168.1.1 is at 11:22:33:44:99:99
192.168.1.1 is at 11:22:33:44:99:99
Read more
0

Command line Audio CD Ripper for OpenSuSe Linux - RipIT

RipIT is a  Perl  script which makes it a lot easier to create "mp3" files from an audio CD. RipIT supports Flac, Lame, Oggenc and Faac. Artist and song titles are retrieved with the CDDB_get.pm  and it is possible to submit and edit CDDB entries at freedb.org. Hidden tracks and ghost songs are detected and splitted into chunks of sound, a toc (cue) file permits to burn the wavs with text and no gaps in DAO mode. Several encoder formats and qualities can be used at the same time and encoded into different directories.

RipIT will do the following without user intervention:
    * getting the audio CD Album/Artist/Tracks information from CDDB
    * ripping the audio CD Tracks
    * encoding to Flac, mp3 or Ogg
    * id3 tags encoded songs
    * creating an playlist (m3u) file
    * optionally generating a toc (cue) sheet for nice DAO burning
    * optionally preparing and send a CDDB submission and save it locally
    * optionally extracting hidden songs and split ghost songs
    * optionally creating md5sum files for all tracks
    * running several encoder processes at the same time and same run

Installation:
Download RipIT rpm file (from here) and install it using command:
# rpm -ivh ripit-3.7.0-3.noarch.rpm 
or to update an existing old package, type:
# rpm -Uvh ripit-3.7.0-3.noarch.rpm
Usage:
To specify a CD device, type: ripit --device /dev/sr1
To specify the output directory, type ripit --outputdir /foo/paths/
To rip'n'code a special track selection, type ripit 1,3-6,8-11
To use several encoders in the same run, type ripit --coder 1,0,2 --quality 3,5,6

There are many more useful options that you can pass to ripit, look at the man pages for more detail.
Read more
1

How To Monitor Your System Performance In OpenSuSe Linux

System performance monitoring is normally done in response to a performance problem. Either the system is running too slowly, or programs (and sometimes even the entire system) fail to run at all. In either case, performance monitoring is normally done as the first and last steps of a three-step process:

  * Monitoring to identify the nature and scope of the resource shortages that are causing the performance problems.
  * The data produced from monitoring is analyzed and a course of action (normally performance tuning and/or the procurement of additional hardware) is taken to resolve the problem.
  * Monitoring to ensure that the performance problem has been resolved.

You can monitor your OpenSuSe system in one of the following fast and easy ways.

System Monitor
System Monitor is a default installed utility to monitor the system. It can be loaded from
Applications → System → Monitor → System Monitor.

It has a very groovy graphical interface with two main tabs, Process Table and System Load.

Process Table shows the CPU,  memory, and network performance in the form of graphs. Have a look at the following screen shot.


Now, go to the System Load tab, it will show you all running programs along with their memory usage. From here you can get an idea which program is consuming more resources of your system and for here you can even kill or change the priority of the process (Rt click on the process and check all those things that you can do to a selected process).

Read more
Related Posts with Thumbnails