linux poison RSS
linux poison Email
0

Block Spammers/Hackers With mod_defensible On Apache2

mod_defensible is an Apache 2.x module intended to block spammers using DNSBL servers.

It will look at the client IP and check it in one or several DNSBL servers and return
a 403 Forbidden page to the client.

Installation
Download the package: here

Follow the steps below to compile and install the package.

# tar -zxvf mod_defensible-1.4.tar.gz
# cd mod_defensible-1.4/
# ./configure
# make
# make install

You can use --with-udns to enable udns (asynchronous resolver library) usage, which should be faster. However, this is not mandatory.

Configuration
Open (apache configuration file) apache2.conf and go to the end where the virtual hosts are configured, and put the mod_defensible configuration right before the virtual hosts:

# Activate DNSBL usage
DnsblUse On
# Specify DNSBL servers
DnsblServers xbl-bl.spamhaus.org. mydnbl.server.org.

With udns support, you can also use:

# Specify another nameserver to use instead of default system resolver
DnsblNameserver 192.168.3.254

Restart Apache afterwards: /etc/init.d/apache2 restart

That's it. If an IP address which is blacklisted tries to access your webserver, it will receive an HTTP error 403.
Read more
0

Linux System monitoring using Dstat

dstat  is a versatile replacement for vmstat, iostat, netstat, nfsstat, and ifstat. It includes various counters (in separate plugins) and allows you to select and view all of your system resources instantly; you can, for example, compare disk usage in combination with interrupts from your IDE controller, or compare the network bandwidth numbers directly with the disk throughput (in the same interval).

Dstat also cleverly gives you the most detailed information in columns and clearly indicates in what magnitude and unit the output is displayed. Less confusion, less mistakes, more efficient.

Dstat is unique in letting you aggregate block device throughput for a certain diskset or network bandwidth for a group of interfaces, ie. you can see the throughput for all the block devices that make up a single filesystem or storage system.

Dstat allows its data to be directly written to a CSV file to be imported and used by OpenOffice, Gnumeric or Excel to create graphs.



Download:
OpenSuse 11: here
Fedora: here

After downloading the rpm file, install it using command: rpm -ivh dstat-0.6.8-3.1.noarch.rpm

Using Dstat
Using dstat to relate disk-throughput with network-usage (eth0), total CPU-usage and system counters:

dstat -dnyc -N eth0 -C total -f 5

Checking dstat's behaviour and the system's impact on dstat:

dstat -taf --debug

Using the time plugin together with cpu, net, disk, system, load, proc and topcpu plugins:

dstat -tcndylp -M topcpu

this is identical to: dstat -M time,cpu,net,disk,sys,load,proc,topcpu

Using dstat to relate cpu stats with interrupts per device:

dstat -tcyif

Get a Report by Mail
There may be cases wherein you want to observe how your server is performing over a period of time. You can setup a background process in Linux that will give you a reading with a certain interval, generate a report, and mail out the file to you.

The following script will run Dstat for three hours, reading the data every 30 seconds, and will mail out the report to me@myemailid.com.

    #!/bin/bash
    dstat –output /tmp/dstat_data_mail.csv -CDN 30 360
    mutt -a /tmp/dstat_data_mail.csv -s “Dstat Report for 3 hour run” me@myemailid.com <  /dev/null


Save the above script in a file called dstat_script.sh on your server, give it executable permission and then run it as a background process:

# chmod +x dstat_script.sh
# nohup ./dstat_script.sh &

Done. Yes, it’s that simple. You will now be mailed this report after it’s done running. You can optionally schedule this script as a daily cron job so that you can receive this data every day.
Read more
0

Upgrade Fedora 9 with Fedora 10

Fedora  10 codenamed "Cambridge" has been released. This new version of the community oriented, Red Hat backed Linux distribution comes with new features which enhance the end user experience.

Fedora 10 is built on Linux kernel version 2.6.27. It comes with improved support for a choice of webcams, improved infrared remote support, better Bluetooth support which incorporates a new, easier to use wizard for setting up keyboards, mice, and other supported Bluetooth devices, A new improved graphical boot system called Plymouth, OpenOffice 3, Firefox 3.0.4, GNOME 2.24, KDE 4.1, LXDE, GIMP 2.6, you got it all in Fedora 10.


Before we upgrade, we must install the latest updates:  # yum -y update
Next clean the yum cache:  # yum clean all

Install the Fedora 10 release packages:

For i386: 
# rpm -Uvh ftp://download.fedora.redhat.com/pub/fedora/linux/releases/10/Fedora/i386/os/Packages/fedora-release-*.noarch.rpm

For x86_64: 
# rpm -Uvh ftp://download.fedora.redhat.com/pub/fedora/linux/releases/10/Fedora/x86_64/os/Packages/fedora-release-*.noarch.rpm

Then run
# yum clean all
# yum -y upgrade

After scucessfull upgrade, Install the new GRUB bootloader to the MBR of your hard drive:

# /sbin/grub-install /dev/sda

Replace /dev/sda with your own hard drive - you can find that out by running: # fdisk -l
Finally, we reboot the system: # reboot
Read more
10

Multimedia Support in Fedora 10

Why doesn’t Fedora support MP3 ‘out of the box’?
Fedora cannot include support for MP3 or DVD video playback or recording. MP3 formats are patented, and the patent holders have not provided the necessary licenses. Fedora also excludes other multimedia software due to patent, copyright, or license restrictions, such as Adobe Flash Player and RealNetworks RealPlayer.
That doesn’t mean you can’t play .mp3 files in Fedora, it just takes a bit of work (not much).

Follow these instructions to get mp3 and other multimedia support on your Fedora 10.

Open a terminal and become root, then run this command:


# rpm -ivh http://download1.rpmfusion.org/free/fedora/rpmfusion-free-release-stable.noarch.rpm 
# rpm -ivh http://download1.rpmfusion.org/nonfree/fedora/rpmfusion-nonfree-release-stable.noarch.rpm 


Now, Install all other plug ins..

# yum -y install gstreamer-plugins-bad gstreamer-plugins-ugly xine-lib-extras-nonfree

After successful installation, open Amarok or any other multimedia player and try to play the mp3 file and see if all goes fine and you are able to hear the music.

XMMS

To install xmms and make it MP3-capable, start by doing this:

# yum install xmms xmms-mp3

MPEG, QuickTime, AVI, and DVDs

MPEG (the format used on DVDs) represents itself as an open standard, but most Linux distributions won't ship software that read it because of blocking patents held by MPEGLA. AVI and Apple QuickTime have proprietary codecs covered by patents, so most Linux distributions won't ship software that decodes them, either.

Unfortunately, the alternate front end xine is even more broken. It can be installed this way:

# yum install xine xine-lib libdvdcss

Doing this will also install a number of support libraries, including the libdvdcss plugin
Read more
2

FTP port forwarding using Iptables

Well, let’s imagine rather trivial situation: you have Linux router connected to Internet via e.g. ADSL modem and some local network comprising several computers and servers connected to that router via switches and/or Wi-Fi access points.

Done? Ok.

There is one public IP assigned to WAN interface of the router while FTP server (of course run by Linux as well) has IP something like 192.168.123.14 or 172.16.*.* or 10.*.*.*. Moreover you want to allow people to access your FTP from every corner of Internet… So, there are several ways how to apply this but let’s talk about how to achieve this by means of using port forwarding feature that is available in any router’s functions list.

So, let’s say we have the following configuration:

Internet <-> [a] router [b] <-> [c] FTP server

[a] is WAN interface with 212.213.214.215 (just an example) IP assigned to it, [b] is NIC with 192.168.0.1 and [c] is server’s interface with IP 192.168.0.2. All what we need is that users from Internet can access FTP server using 212.213.214.215 IP and default 21 TCP port.

One of the main problems is that passive mode of FTP service uses any port from range 1024 to 65535 so it’s not enough to forward 21/20 ports to FTP server and let the ball rolling. So, go to servers’ CLI and open configuration file of an FTP service. It would be vsftpd, proftpd whatever. Let’s say we have vsftpd so we have to add the following lines to /etc/vsftpd.conf:

pasv_min_port=12000
pasv_max_port=13000

When changes are saved restart vsftpd server.

Now access router’s CLI and type the following:

iptables -t nat -I PREROUTING -d 212.213.214.215 -p tcp -m tcp --dport 21 -j DNAT --to-destination 192.168.0.1

iptables -t nat -I PREROUTING -d 212.213.214.215 -p tcp -m tcp --dport 12000:13000 -j DNAT --to-destination 192.168.0.1

This will add netfilter port forwarding rules which will redirect traffic coming at routers’ public IP through 21 TCP port to FTP server and will properly handle passive FTP mode.
Read more
Related Posts with Thumbnails