Sunday, January 23, 2011

Simplest way to respawn configured number of instances of a specific process.

So we have an app. which we wan to run multiple instance of it in linux. The number should be configurable. We also want that whenever one of the instance disappears, a new one is booted up.

I was looking into C based programs, shell script, python script etc. but I was wondering what would be the most simple, easiest way to do it. Are there any tools out there? Can one simply use some linux built-in functionality?

Linux distribution is Red Hat.

  • Monit is the tool for the job. With monit, you can control a lot of variables and act upon changes. More info here.

NameServer SOA records misconfigured

This is my config of NS.

hostingdk.com. SOA zone1.hostingdk.com admin.hostingdk.com
2010051905;
43100;
7200;
2419100;
86400;

hostingdk.com. NS zone1.hostingdk.com.
hostingdk.com. NS zone2.hostingdk.com.

zone1.hostingdk.com. A 96.30.49.11
zone2.hostingdk.com. A 96.30.46.238

Both zone1 & zone2 have registered name server in Enom domain control panel.

My problem is, one domain .lv cant not change DNS to my NS. They said:

Error : Nameserver zone1.hostingdk.com cannot be queried for SOA
Error : Nameserver zone2.hostingdk.com cannot be queried for SOA

Please help me, how to fix it ?

  • If your are in bind format, the SOA must not have semicolon between the fields. In my case, it is :

     @       SOA     dns1.grenoble.cnrs.fr. dnsmaster.grenoble.cnrs.fr. ( 2010051802 3600 900 604800 3600 )
    
    From Dom
  • The error being reported is because your two servers (zone1 and zone2 above) are not correctly serving your zone file:

    % dig +norec @96.30.46.238 hostingdk.com. soa
    
    ; <<>> DiG 9.6.0-APPLE-P2 <<>> +norec @96.30.46.238 hostingdk.com. soa
    ; (1 server found)
    ;; global options: +cmd
    ;; Got answer:
    ;; ->>HEADER<<- opcode: QUERY, status: REFUSED, id: 5139
    ;; flags: qr; QUERY: 1, ANSWER: 0, AUTHORITY: 0, ADDITIONAL: 0
    

    This may be because of the semi-colon issue pointed out by @Dom - in which case the server logs on those two boxes should tell you that. If you're running BIND, use named-checkzone to check the syntax of your zone files.

    If you've actually got the right syntax now, but it's still not working, you need to look at the ACLs in your server - make sure that you're actually permitting access to that zone from 0.0.0.0/0 (aka "any").

    From Alnitak

How to remove this attack from the server?

Hey Guys
I have made website.
But after few months successfully run now its showing virus attack.
Now how to remove this things?
And what to do to avoid this attacks in future?
I have put screen-shot so that u can understand well.

  • If you removed virus and warning is still shown you should go to google webmaster tools and request malware review.

    More info here: http://www.stopbadware.org/home/reviewinfo

  • The only satisfactory solution is to reinstall from a backup taken when you knew the machine was clean. If you don't have a backup wipe it and start again. Properly and fully removing a virus is seldom a simple job, despite the claims made by antivirus software vendors.

    I suggest you enlist the services of an experienced system administrator to help you fix the problems you have and to secure the server a lot better than it is now. This is not a job for the inexperienced, unless you want to go through this again... and again...

SELinux vs. AppArmor vs. grsecurity

I have to set up a server that should be as secure as possible. Which security enhancement would you use and why, SELinux, AppArmor or grsecurity? Can you give me some tips, hints, pros/cons for those three?

AFAIK:

  • SELinux: most powerful but most complex
  • AppArmor: simpler configuration / management than SELinux
  • grsecurity: simple configuration due to auto training, more features than just access control
  • Personally, I would use SELinux because I would end up targeting some flavor of RHEL which has this set up out of the box for the most part. There is also a responsive set of maintainers at Red Hat and a lot of very good documentation out there about configuring SELinux. Useful links below.

    Rook : yeah but yum and selinux are so damn annoying.
    Ophidian : I find yum's CLI significantly more intuitive than apt. SELinux is annoying when you're trying to go your own way with non-stock apps, but I've never had issues with the stock stuff beyond needing to turn on some sebool's to enable non-default functionality (e.g. Let httpd php scripts connect to the database)
    From Ophidian
  • A "server" to provide what kind of service? To what audience, in what environment? What constitutes "secure" to you in this context? Lots more information would be necessary to provide a useful answer. For instance, a pure IP Time-of-Day server can be very secure -- all ROM firmware, radio imput, self contained battery power with automatic charging. But that's probably not a useful answer for you.

    So, what kind of service? Internet wide, enterprise wide, trusted work team, dedicated point-to-point networking, etc.? Is high availability a need? Reliability? Data Integrity? Access control? Give us some more information about what you want, and recognize that "secure" is a word whose meaning has many dimensions.

    From mpez0
  • I have done a lot of research in this area. I have even exploited AppArmor's rulesets for MySQL. AppArmor is the weakest form of processes separation. The property that I'm exploiting is that all processes have write privileges to some of the same directories such as /tmp/. What nice about AppArmor is that it breaks some exploits without getting in the user/administrators way. However AppArmor has some fundamental flaws that aren't going to be fixed any time soon.

    SELinux is very secure, its also very annoying. Unlike AppAmoror most legitimate applications will not run until SELinux has been reconfigured. Most often this results in the administrator misconfiguration SELinux or disabling it all together.

    grsecurity is a very large package of tools. The one i like the most is grsecuirty's enhanced chroot. This is even more secure then SELinux, although it takes some skill and some time to setup a chroot jail where as SELinux and AppAprmor "just work".

    There is a 4th system, a Virtual Machine. Vulnerabilities have been found in VM environments that can allow an attacker to "break out". However a VM has a even greater separation than a chroot becuase in a VM you are sharing less resources between processes. The resources available to a VM are virtual, and can have little or no overlap between other VMs. This also relates to <buzzword> "cloud computing" </buzzword>. In a cloud environment you could have a very clean separation between your database and web application, which is important for security. It also maybe possible that 1 exploit could own the entire cloud and all VM's running on it.

    From Rook

.htaccess help required for apache server

I searching for a redirection code for my url:

what I want is when some one search in my site it should redirect

example: if some one search google.com on mysite

then in address line it should look like www.mydomain.com/google.com

can be in $_POST method or $_GET

how do I do that??

  • RewriteEngine On
    RewriteCond %{HTTP_REFERER} google\.com
    RewriteRule ^.*$ http://www.mydomain.com/google.com [R,L]
    

    in an .htaccess file might work, i have not tested it.

    you could try:

    RewriteCond %{THE_REQUEST} ^[A-Z]+\ /(.*)\/search\.php\?q=(www\.)?([^/\ ]+)[^\ ]*\ HTTP/
    RewriteRule ^.*$ http://www.mydomain.com/%1 [R,L]
    

    this link also has some other example 'smart' .htaccess rules: http://www.askapache.com/htaccess/http-https-rewriterule-redirect.html

    mathew : RewriteCond %{THE_REQUEST} ^[A-Z]+\ /search\.php\?q=(www\.)?([^/\ ]+)[^\ ]*\ HTTP/ this is for request of any kind of search domains..but what I dont know is how do I convert to http://www.mydomain.com/domain.com
    cpbills : added another potential answer
    mathew : nop it doesnt work
    cpbills : does it do /anything/ can you provide more information as to how it doesn't help? maybe enable logging for RewriteRules `RewriteLog file-path` and `RewriteLogLevel 9` http://httpd.apache.org/docs/2.0/mod/mod_rewrite.html you also have to be willing to play with the regular expression in the `RewriteCond` to see if you can at least get it to trigger. i don't know where you got that pattern, so i have no idea if it should work or not, you provided it.
    From cpbills

Can IIS6 compression file types be configured on a per-site basis?

The following article explains how to customise the file types that can be compressed in IIS 6:

Customizing the File Types IIS Compresses (IIS 6.0) [MS TechNet]

The metabase settings discussed are global settings.

Can I configure this on a per-site basis?

  • Yes, you can.

    See "To enable HTTP Compression for Individual Sites and Site Elements" here.

    Edit: I misread the details of the question. I am pretty sure I have configured different file extensions for compression on different sites in the past, but I also can't seem to find any definitive answer right now. I'll check when I'm at work tomorrow.

    Kev : I read that. That's just the settings to turn on/off compression by site. There's no mention about whether you can customise the file types on a site by site basis.
  • After some digging about it looks like this is a global setting and can only be configured at the following metabase location:

    /LM/W3SVC/Filters/Compression/gzip
    /LM/W3SVC/Filters/Compression/deflate

    For more info:

    HcFileExtensions - MSDN Library

    From Kev

How to take snapshot of the filesystem in linux (files, their sizes only, not their data)

We need to take a snapshot of your linux server. We don't want to backup the data, just a snapshot we can compare against changes.

  • i would recommend checking for md5 sums of files, and not just file size. however:

    find / -printf "%h/%f %s\n" > /some/path/filesize would generate a list of files and their sizes.

    you could also do find / | xargs md5sum 2> /dev/null 1> /some/path/file-md5s to generate a list of filenames and their md5 sums.

    From cpbills
  • use

    du <filesystem mount point>
    

    it should give you size and file in full location

    From A.Rashad
  • find / -ls > fileinfo.txt
    

    But take a look at tripwire and aide, since that seems to be what you are aiming for anyway. Also note that rpm can check files against checksums and for debian based distributions there is debsums.

    Pier : Agree. Probably tripwire and aide are what he looks for
    From ptman