Tuesday, July 12, 2011

How to put .htpasswd protection for a web directory!

Protecting content on the web is something that most savvy users will have to do at one point or another. Whether the content is personal or professional, there comes a time when that content must only be seen by "authorized" eyes. The Apache web server ( that daemon that serves up your marvelous content ) allows a user to configure two files to facilitate this very purpose. Those files are .htaccess and .htpasswd.

.htaccess
The .htaccess file is a simple text file placed in the directory you want the contents of the file to affect. The rules and configuration directives in the .htaccess file will be enforced on whatever directory it is in and all sub-directories as well. In order to password protect content, there are a few directives we must become familiar with. One of these directives in the .htaccess file ( the AuthUserFile directive ) tells the Apache web server where to look to find the username/password pairs.
.htpasswd
The .htpasswd file is the second part of the affair. The .htpasswd file is also a simple text file. Instead of directives, the .htpasswd file contains username/password pairs. The password will be stored in encrypted form and the username will be in plaintext.
Apache Server
We have to make some changes on the apache conf file, & rester the service.The procedure is explained below.

Creating an .htaccess file:-
goto the directory you need to password protect. create a file named .htaccess.
add the following lines into it.

AuthName "Hello user!"
AuthType Basic
AuthUserFile /usr/local/humanlinux/.htpasswd   (this is the location of the .htpasswd, you have to specify accourdingly)
Require user john  (replace the john with desired username)

Save the file.

Creating an .htpasswd file:-

To create a .htpasswd file in /usr/local/humanlinux

htpasswd -c /usr/local/humanlinux/.htpasswd john
Note the '-c' is only used when creating a new .htpasswd file.
To add dave to an existing .htpasswd file located in /usr/local/humanlinux/ the following command will be used.
htpasswd /usr/local/humanlinux/.htpasswd dave

Sample .htpasswd File
Below is a sample .htpasswd file that contains users john and dave
john:n5MfEoHOIQkKg
dave:9fluR/1n73p4c

Changes in the apache conf file:-
open the httpd.conf file using your favourote editor.goto the diretory area.

AllowOverride All

you have to specify the correct path for the directory you need to pasword protect.Here i have protected the directory /home/humanlinux/public_html/protected.
Restart the apache service.

Troubleshooting
  • Make sure that the path specified in AuthUserFile is the correct full path. This is a major cause of problems. If Apache cannot find the.htpasswd file, then all attempts will fail.
  • Make sure the permissions on the .htaccess and .htpasswd files are set so that Apache can read them.
    • chmod 0644 .htaccess
    • chmod 0644 .htpasswd
  • Other issues may be out of your control. Web administrators can lock down Apache so that it ignores all .htaccess files it encounters. This can be achieved with an AllowOverride None directive and option on the ServerRoot/DocumentRoot directories. If this is the case (.htaccess not allowed) you will have to kindly ask your web administrator to allow .htaccess files with authorization directives in your personal web directory. This can be achieved with AllowOverride AuthConfig directive and option.

How to browse files in an ISO image?

Its always easy to do things using the command lines in Linux. To browse files of an ISO image is an easy task in Linux. Open a terminal window and type in the following commands.
sudo mkdir /media/iso
sudo modprobe loop
sudo mount filename.iso /media/iso -t iso9660 -o loop
cd /media/iso
Hereafter you will be able to navigate to the /media/iso folder and see the contents of the ISO image. To unmount the ISO, use the following command:
sudo umount /media/iso
I will explain the commands and options used specificly:
sudo modprobe loop  ->loads/ installs the module for loopback file system support
iso9660  -> the file system used by CD roms
-t  -> specify the file system type
-o loop  -> for additional options while using a loopback filesystem

How to install AIDE?

What is AIDE:-

AIDE (Advanced Intrusion Detection Environment) is an intrusion detection program. It is a free replacement for Tripwire.It can find out any changes made on the system binaries, libraries, header files , and configuration files etc by "comparing" regularly with the database of these files which was made at the time of its instllation.

How Does AIDE works:-

Once AIDE is installed, It creates a database of the files specified in AIDE’s configuration file. The AIDE database stores various file attributes like permissions, inode number, user, group, file size, mtime and ctime, atime, growing size, number of links and link name. AIDE also creates a cryptographic checksum or hash of each file using message digest algorithms like sha, md5, rmd160, tiger etc. Also acl, xattr and selinux can be used if enabled during compile time.This databse is created before the server/system is bought into the network.The AIDE should be installed to the system before it is exposed to the internet.

So Initially the administrator need to create an AIDE database on a new server before it is setup for networking eg hosting.This AIDE database is an excat summary of the Linux system before it is bought into the network.This database(db) will hold information about system binaries, libraries, header files etc that are expected to remain the same throughout.Suppose someone has broken-into the system, though it is easier to manipulate file dates, sizes etc, it will be quite difficult for him to manipulate cryptographic checksum like md5. Thus by rerunning AIDE after a break-in, the administrator can quickly identify changes to files with high degree of accuracy.

How to Install AIDE in UBUNTU?

1)You need the root access to install AIDE:- sudo su -

2)Install These prerequisites (packages) for AIDE:

GCC compiler for C : apt-get install gcc byacc
GNU Flex : apt-get install flex
GNU Bison   : apt-get install bison
GNU Make : apt-get install make
Mhash library : apt-get install libmhash2 libmhash-dev
PostgreSQL Development Library : apt-get install postgresql-server-dev-8.3

Some of the above packages maybe already installed on your box, in that case when you execute the above commands it shows " 0 upgraded".so need not worry about that packages.

Or else you can check manually whether the packages are installed or not by using the follawing command: dpkg –get-selections | grep gcc

If the result is : gcc-4.3  install
then gcc is installed otherwise if you get no output ,then it means that gcc is not installed.

3)Once all the packages are installed then download aide from here . The downloaded packaege will be zipped in tar.

4)Create a folder 'downloades' and extract the tar achieve into this folder using the command: tar -xzvf aide-x.xx.x.tar.gz (replace x with version number)
Now you wil get the folder aide-x.xx.x
goto that folder by: cd aide-x.xx.x
Then execute the following commands :
./configure
make
make install
make clean

5)NOw you need to open the aide configuration file and determine the location where the aide database is stored. Go to that location

6)To initialise the database perform:
aide -i
mv aide.db.new aide.db

7)Now we can check wether the AIDE works by using the following command:-
 aide

8)Configuration of AIDE
AIDE has its config file located inside (if installed via package management software like synaptic, config file is /etc/aide/aide.conf) /usr/local/etc/aide.conf .
And it’s default executable is located inside /usr/local/bin/aide.

9)Explanation of the aide.conf file
database=file:/var/lib/aide/aide.db
location of the database to be read (This is the database taken as benchmark)
database_new=file:/var/lib/aide/aide.db.comp
location of the database for –compare is read (This is not present by default and is used only when we have to compare two distinct databases.)
database_out=file:/var/lib/aide/aide.db.new
location of the database to be written

10)Useful Commands
aide -C : Performs a check on the filesystem ? (also same as: aide)
aide -i : Initialises or creates the benchmark database supplied by database_out directive (here it is aide.db.new)
aide -u -c /etc/aide.conf : update the database and use the specified config file

11)Usage
Before putting one’s server into the network, the admin will have to save a secure configuration of the system by:

aide -i
mv aide.db.new aide.db

The second command transfers the server’s earlier state(aide.db database) with the new one(aide.db.new). So be careful when you do this. It is advisable to keep a backup of the earlier database.
Next time in-order to check for any break-in perform
aide 
or
aide -C
To compare the current database with some earlier backed-up database, give the path of the backed-up database to database_new option in aide.conf and perform:
aide –compare
The task of saving the old database and comparing with a new one has to be done periodically (preferably daily with the help of a cron task).

How to put the grub password in linux!

In Linux anyone can reset the root password from single usermode . So it is considered as a security fault if the machine is public. There comes the importance of putting the grub password, so that only admin is allowed to login if the machine is rebooted.

Here are the steps to put the grub password.

1) open the command prompt and type the following commands

2) grub

3) md5crypt

4) type the password

5) copy the encrypted password generated

6) Ctrl c

7) vi /boot/grub/grub.conf

8) paste the following line just above the 'title'

password --md5 "encrypted password here"

9) save and quit. Done.

I have give the sample grub file here.

======================================

#boot=/dev/hdb
default=0
timeout=15
splashimage=(hd1,8)/boot/grub/splash.xpm.gz
hiddenmenu
password --md5 %&mkj89(*$*J)$OO*=*

title CentOS (2.6.18-92.el5)
root (hd1,8)
kernel /boot/vmlinuz-2.6.18-92.el5 ro root=LABEL=/ rhgb quiet
initrd /boot/initrd-2.6.18-92.el5.img

Faster YUM search!

Yum fastest mirror plugin (yum-plugin-fastestmirror) allow yum to select the closest and freshest mirror around you for your yum update. Once the yum fastest mirror plugin is activated, whenever you perform yum update or install, you will get a better connection. As yum will search the mirror based on your IP thru the GeoIP system. Yum select the fastest mirror based on:-

1. The connecting location of the client.
2. The current freshness/staleness of the mirrors for that region.

yum fastest mirror plugin (yum-plugin-fastestmirror) sound interesting? Want to try?
To install yum fastest mirror plugin (yum-plugin-fastestmirror) you can use this command:-

yum install yum-plugin-fastestmirror
or
yum install yum-fastestmirror

Once the installation completed, you have to edit the file /etc/yum.conf and add the following line to the file:

plugins=1

If it is already there , no need to add!

Done. you have just installed yum fastest mirror plugin.
if you perform yum install or yum update now,
you will notice there is a new line added like below

Loading “fastestmirror” plugin
Setting up Install Process
Setting up repositories

/proc/sysrq-trigger the file can do things?

# Restart the computer (Reboots the kernel without first unmounting file systems or syncing disks attached to the system) 
echo "b"> / proc / sysrq-trigger
# Immediately shut down the computer (shuts off the system) 
echo "o"> / proc / sysrq-trigger
# Export the memory allocation information (you can use / var / log / message view) (Outputs memory statistics to the console) 
echo "m"> / proc / sysrq-trigger
# Export the current CPU registers and flag bits of information (Outputs all flags and registers to the console) 
echo "p"> / proc / sysrq-trigger
# Export the thread state information (Outputs a list of processes to the console) 
echo "t"> / proc / sysrq-trigger
# Deliberately crash (Crashes the system without first unmounting file systems or syncing disks attached to the system) 
echo "c"> / proc / sysrq-trigger
# Immediately re-mount all file systems (Attempts to sync disks attached to the system) 
echo "s"> / proc / sysrq-trigger
# Immediately re-mount all the file system is read-only (Attempts to unmount and remount all file systems as read-only) 
echo "u"> / proc / sysrq-trigger
Oh, in addition to two, similar to the forced cancellation feature e - Kills all processes except init using SIGTERM i - Kills all processes except init using SIGKILL

Detailed three core documents

In the network, the server uses a lot of Linux systems. To further improve the performance of the server, may need specific hardware and needs to recompile the Linux kernel. Compile the Linux kernel, the steps required under the regulations, the kernel process involves several important documents. For example, RedHat Linux , the / boot directory there are some Linux kernel-related files into the / bootexecute: ls-L . Compiled RedHat Linux kernel people in one of the System.map , vmlinuz , initrd-2.4.7-10.img impression may be more profound, because the kernel involved in the process of these documents to establish such an operation. So how these documents are produced? What effect? This paper describes do

A, vmlinuz
1 , vmlinuz is the bootable compressed kernel. "Vm" on behalf of "Virtual Memory . " Linux supports virtual memory, unlike the old operating system, such as: DOS has 640KB memory limit. Linux can use hard disk space as virtual memory, hence the name "vm" . vmlinuz is the executable Linux kernel in / boot / vmlinuz , which is generally a soft link
2 , vmlinuz establishment of two ways:
The first method: the kernel is compiled by "make zImage" to create, and then: "cp / usr/src/linux-2.4/arch/i386/linux/boot/zImage / boot / vmlinuz " generation. zImage for the case of a small kernel, it exists for backward compatibility
The second method: kernel compile-time with the command " make bzImage " to create, and then: " cp / usr/src/linux-2.4/arch/i386/linux/boot/bzImage / boot / vmlinuz " generation. bzImage is the compressed kernel image, note, bzImage not use bzip2 compression, bzImage in bz misleading, BZ said"Big zImage" . bzImage in b is a "big" means
3 , zImage ( vmlinuz ) and bzImage ( vmlinuz ) is to use gzip compression. They are not only a compressed file, and in the beginning of the two files embedded gzip decompression code. So you can not use gunzip or gzip-dc unpack vmlinuz
4 , core file contains a miniature gzip to decompress the kernel and boot it. The difference is that the old zImage kernel to extract low-memory (first 640K ), bzImage decompression kernel into high memory (1MAbove). If the kernel is small, you can use zImage or bzImage , one of two ways to boot the system is running is the same. Large kernel using bzImage , not use zImage
5 , vmlinux is the uncompressed kernel, vmlinuz is vmlinux compressed files.
Two, initrd-xxximg
initrd is the " initial ramdisk " shorthand. initrd is generally used for temporary guide to the actual hardware kernel, vmlinuz to take over and continue to lead the state. initrd-2.4.7-10.img is mainly used to load the ext3 file system and other scsi device driver. For example, using a scsi hard drive, while the kernel vmlinuz and do not have this in the scsi hardware drivers, then load the scsi module, the kernel can not load the root file system, but the scsi module is stored in the root file system / lib / modulesunder the . To solve this problem, can lead one to read the actual kernel initrd and kernel with initrd fixscsi booting problems. initrd-2.4.7-10.img is gzip compressed file
linuxrc script initrd to achieve a number of modules to load and install the file system. initrd image file is to use mkinitrd to create. mkinitrd utility to create initrd image file. This command is RedHat -specific.Other Linux distributions may have a corresponding command. This is a very handy utility. See the specific circumstances of help: man mkinitrd

Three, System.map
System.map is a specific kernel of the kernel symbol table. It is your currently running kernel System.maplinks.
How the kernel symbol table is created it ? System.map is "nm vmlinux" generated and the symbol was not related to filter out. For the examples in this article, compiling the kernel, System.map is created in / usr/src/linux-2.4/System.map . Like this: nm / boot/vmlinux-2.4.7-10> System.map
The following lines from / usr/src/linux-2.4/Makefile : 
nm vmlinux | grep-v '\
 ( compiled \ ) \ | \ ( \. O $ $ \ ) \ | \ ( [aUw] \ ) \ | \ ( \. \. ng $ $ \ ) \ | \ (LASH [RL] DI \ ) '| sort> System.mapand then copy it to / boot : cp / usr / src / Linux / System.map / boot / System . map-2.4.7-10
During programming, it will name a few variables or function names like symbols. Linux kernel is a very complex block of code, there are many global symbols. Linux kernel does not use a symbolic name, but by the address of a variable or function to identify the variable or function names. Such as not using size_t BytesRead such symbols, but as c0343f20 that refer to this variable.
For the use of computers for people who prefer to use those as size_t BytesRead such a name, not like asc0343f20 such names. Core is mainly used c to write, so the compiler / encoder connector allows us to use symbolic names, use the address when the kernel is running.
However, in some cases, we need to know the address of the symbol, or need to know the address of the corresponding symbol. This is done by the symbol table, symbol table of all symbols along with their addresses. Variable name checkCPUtype in the kernel address c01000a5
Linux uses the symbol table to 2 files:    / proc / ksyms   System.map
( 1 ) / proc / ksyms is a "proc file" , created when the kernel boots. In fact, it is not really a file, it is only the kernel of data that gave people the illusion of a disk file, the file size that it is from 0 can be seen. However, System.map is present in the file system on your actual file. When you compile a new kernel, the address of each symbolic name to change, your old System.map has wrong symbol information.Generated when compiling a kernel for each new System.map , you should use the new System.map to replace the old System.map . Although the kernel itself does not really use System.map , but other programs such as: klogd , lsof and ps and other software requires a correct System.map . If you use the wrong or no System.map , klogd output will be unreliable, which would exclude the difficult process failure. No System.map , you may face some troubling message.
( 2 ) In addition, a few drivers need System.map to resolve symbols, not specific to your currently running kernel to create the System.map they will not work. Linux kernel log daemon: klogd to perform name ---- address resolution, klogd to use System.map . System.map should be placed to use its software can find its place. Executive: man klogd known, if not the System.map position as a variable to klogd , it will in the following order, in three places to find System.map : / boot / System.map , / System.map ,/ usr / src / Linux / System.map ; System.map also has version information, klogd can be smart to find the right image ( map ) file