Don't miss
Showing posts with label Linux. Show all posts
Showing posts with label Linux. Show all posts

Tuesday, December 10, 2013

Oracle Linux 6.5 Launched, Free Distribution - Includes Major Security, Performance And Stability Features


Oracle launched its much talked about OS, Oracle Linux 6.5 recently. The OS is free and is downloadable at https://edelivery.oracle.com/linux/. The new version is much improved from the previous versions and Oracle confirms that they have put in effort for more scalability and stability of the business critical applications.

The Unbreakable Enterprise Kernel Release 3, included in Oracle Linux 6.5, is based on mainline Linux 3.8, which provides a host of scalability and stability improvements, as well as new functionality.

Another highlight of the OS is that it is the only linux distribution that supports DTrace. The DTrace framework is used by applications for superior observability, troubleshooting and performance analysis. The inclusion should be a real positive for the developers to move to Oracle Linux.

The feature lists doesn't stop here, as the team has also included more production support for linux containers enabling a better Operating system level virtualization.

On the security side, the highlighted feature is the cryptographic datastore which can allow various crypto tools to communicate with the datastore and to process trusted certificates better. Also the OS has extended smartcard authentication to a large count of application subsystems. Thus accounting for their better performance and reliability.

Oracle also claims that the new OS is a performance reliable solution to business critical workloads like Oracle database 12c and the new distribution is widely available for all x86 Oracle engineered systems.


For a detailed feature list: Ciol Article on Oracle Linux 6.5



Updated at: Tuesday, December 10, 2013

Sunday, October 20, 2013

Plesk : List Of Systems Processes To Add To CSF Ignore list


Here is a quick list of processes that you want to add to your CSF configuration which should avoid the sudden rush of mails on to the admin inbox after installation of CSF. Hope you find this useful!
ADVERTISEMENT

# vim /etc/csf/csf.pignore
#### Custom for Plesk ####
user:admin
exe:/var/qmail/bin/qmail-smtpd
exe:/usr/bin/imapd
exe:/var/qmail/bin/qmail-queue
exe:/usr/bin/pop3d
exe:/var/qmail/bin/qmail-send
cmd:qmail-send
cmd:/usr/bin/pop3d Maildir
cmd:/var/qmail/bin/qmail-queue
cmd:/var/qmail/bin/qmail-smtpd /var/qmail/bin/smtp_auth /var/qmail/bin/true /var/qmail/bin/cmd5checkpw /var/qmail/bin/true
cmd:/usr/bin/imapd Maildir
exe:/var/qmail/bin/qmail-rspawn
cmd:qmail-rspawn
exe:/var/qmail/bin/qmail-clean
cmd:qmail-clean
exe:/usr/sbin/clamd
cmd:clamd
exe:/var/qmail/bin/splogger
cmd:splogger qmail
exe:/var/qmail/bin/qmail-remote.moved
user:qmaill
user:popuser
user:qmaild
user:qmails
user:qmailr
user:qmailq
user:qscand
exe:/usr/sbin/avahi-daemon
user:avahi
exe:/usr/local/sbin/zabbix_agentd
cmd:/usr/local/sbin/zabbix_agentd
user:zabbix
exe:/usr/bin/sw-engine-cgi
cmd:/usr/bin/sw-engine-cgi
user:sso
exe:/usr/sbin/sw-cp-serverd
cmd:/usr/sbin/sw-cp-serverd -f /etc/sw-cp-server/config
user:sw-cp-server
exe:/usr/bin/sw-engine-cgi
cmd:/usr/bin/sw-engine-cgi -c /usr/local/psa/admin/conf/php.ini -d auto_prepend_file=auth.php3 -u psaadm
user:psaadm
exe:/usr/libexec/mysqld
cmd:/usr/libexec/mysqld –basedir=/usr –datadir=/var/lib/mysql –user=mysql –pid-file=/var/run/mysqld/mysqld.pid –skip-external-locking –socket=/var/lib/mysql/mysql.sock
user:mysql
exe:/usr/libexec/hald-addon-acpi
exe:/usr/sbin/hald
cmd:hald
user:haldaemon
exe:/usr/bin/postgres
user:postgres
exe:/sbin/portmap
cmd:portmap
user:rpc
exe:/usr/bin/xfs
cmd:xfs -droppriv -daemon
user:xfs
exe:/usr/bin/python
cmd:/usr/bin/python /usr/lib/mailman/bin/qrunner –runner=VirginRunner:0:1 -s
user:mailman
user:tomcat
ADVERTISEMENT

Updated at: Sunday, October 20, 2013

Thursday, October 10, 2013

Google Rewards For Open Source Security Patches, $500 to $3133.70 (Sleet!)


The good days are back for the developers and security analysts as Google has started its promotion to help out security analysts who finds a bug and fixes the same. The bounty is set at a range of $500 to $3133.70 for the fixes found for all Opensource programs like OpenSSL, OpenSSH, Bind and several other softwares that are directly connected to the OS security.

The program announced Wednesday expands on Google's current bug-bounty program, which pays from $500 to $3,133.70 to people who privately report bugs found in the company's software and Web properties. Security researchers inside the company considered modifying the program to reward bug reports in open-source software, but eventually decided against that approach. The reason: bug bounty programs often invite a flood of reports of varying quality that can overwhelm the finite resources of open-source developers. What's more, it's frequently much harder to patch a vulnerability than merely to find it.

"So we decided to try something new: provide financial incentives for down-to-earth, proactive improvements that go beyond merely fixing a known security bug," Michael Zalewski, a member of the Google security team, wrote in a blog post. "Whether you want to switch to a more secure allocator, to add privilege separation, to clean up a bunch of sketchy calls to strcat(), or even just enable ASLR—we want to help."
ADVERTISEMENT
"We intend to roll out the program gradually, based on the quality of the received submissions and the feedback from the developer community. For the initial run, we decided to limit the scope to the following projects:

Core infrastructure network services: OpenSSH, BIND, ISC DHCP
Core infrastructure image parsers: libjpeg, libjpeg-turbo, libpng, giflib
Open-source foundations of Google Chrome: Chromium, Blink
Other high-impact libraries: OpenSSL, zlib
Security-critical, commonly used components of the Linux kernel (including KVM) "

says the article here.

Google has plans of extending the program to further by including software's like:

Widely used web servers: Apache httpd, lighttpd, nginx
Popular SMTP services: Sendmail, Postfix, Exim
Toolchain security improvements for GCC, binutils, and llvm
Virtual private networking: OpenVPN

The program is sure to have a wide scale impact and also help in the overall development of Linux community.

So once you have found a vulnerability, reported it, released your own version of patch for the same. You will have to submit it to the maintainers of the software, wait for it to be approved and added to main repository. Once this is done you can contact google at google-patches@google.com with all relevant details to get qualified for the reward program.

"If we think that the submission has a demonstrable, positive impact on the security of the project, you will qualify for a reward ranging from $500 to $3,133.7. " says Michal Zalewski, Google Security Team.

You can find the detailed list of rules here


Updated at: Thursday, October 10, 2013

Wednesday, September 25, 2013

Nvidia Finally Prepares For Linux Era, Prepares Documentation


Nvidia, the company once branded as the "the single worst company we've ever dealt with" by Linus Torvalds, has released the specifications for its VBIOS Device Control Block.

The company sees this release as a first step, and intends to provide further documentation in the future, as well as guidance to the developers of nouveau.



Using an Nvidia graphics card on a Linux system involves making a choice between a unified, proprietary kernel driver supported by Nvidia itself, or the open-source nouveau driver for users of legacy cards or those wishing to have a pure, untainted open-source operating system and kernel.

"Nvidia is releasing public documentation on certain aspects of our GPUs, with the intent to address areas that impact the out-of-the-box usability of Nvidia GPUs with Nouveau," wrote Nvidia's Andy Ritger on the nouveau mailing list.

"I suspect much of the information in that document is not news for the Nouveau community, but hopefully it will be helpful to confirm your understanding or flesh out the implementation of a few unhandled cases."

Ritger said that a few of the developers who are responsible for Nvidia's driver would be paying attention to the nouveau mailing list.

"If there are specific areas of documentation that would most help you, that feedback would help Nvidia prioritize our documentation efforts," he said.

"I can't promise we'll be able to answer everything, but we'll provide best-effort in areas where we are able."

The hype cycle behind Linux as a force on the desktop has returned in recent weeks.

Earlier this week, gaming studio Valve backed up its claims that Linux was the future of the gaming industry when it announced its own Linux distribution called SteamOS.

Although details of SteamOS are few, Linux Foundation executive director Jim Zemlin hailed it.

Latest News


Updated at: Wednesday, September 25, 2013

Steam OS : Linux Based OS Enters Into Gaming Market, Will It Change the Industry?


Meet SteamOS, a Linux-based operating system from Valve, designed for the living room, and therefore with clear designs on Microsoft, Nintendo and Sony’s turf.

Valve took the lid off yesterday, the first of three living room-related gaming announcements. The next one happens tomorrow afternoon, with the final presumably taking place Friday. One of these reveals may be the fabled Steam Box, a kind of living room PC-console ostensibly built and sold by Valve to carry its software digital distribution platform beyond the increasingly staid traditional keyboard-and-mouse paradigm.



This is not Valve dipping a toe in the water, in other words; this is Valve taking full measures and diving in.

That said, we don’t know a lot about what SteamOS is, exactly. Not yet anyway. We know it’ll be freely distributed because Valve says so in plain language, but then so is the Steam client, and that’s been the case since its inception. We don’t know if we’ll be able to modify SteamOS in the same sense that one can modify Linux. In what sense will SteamOS manifest, in Valve’s words, “the rock-solid architecture of Linux”? SteamOS is derived from Linux, sure, but not, one assumes, another Linux distribution with the Steam-for-Linux client folded in.

Here’s a question we can answer in part now: What would gaming on SteamOS (vis-a-vis Linux) be like today? We already know what Steam’s like on Linux — have known since Valve rolled its inaugural Linux client out last February. Forget SteamOS’ ability to stream Windows and Mac games from separate Windows or Mac systems to a SteamOS box for a moment. I’m interested in that technology, but no one knows what it’ll be like, or how tenable, latency-wise (on the PC gaming side of things, players are even less forgiving when it comes to even slight deficiencies in the latter column). Let’s talk instead about Linux games on Steam.

Most of you have no idea what Linux gaming is like on Steam because most of you don’t run Linux. But what if you did? What could you play natively?

Valve maintains a catalog of Steam games online, including one sorted according to Linux support. The latter list’s appeal depends on your gaming proclivities. Do you like strategy games? You’ll find two of Paradox Plaza’s finest here: Europa Universalis IV and Crusader Kings II. Ambient first-person horror puzzlers? See the recently released Amnesia: A Machine for Pigs. Sprawling, hardcore space flight sims? Egosoft’s X series remains unsurpassed. Top-notch MOBAs? Try Valve’s own Dota 2. Indies galore? There’s Legend of Grimrock, Castle Story, Trine 2 and dozens more.

Latest News

LOADING LATEST NEWS....
Loading Blog Posts...


Loading Images...
Loading Videos...


Updated at: Wednesday, September 25, 2013

Friday, September 20, 2013

Intel Sees Linux As The Top OS For Desktop In Coming Years


New Orleans: The Sept. 18 LinuxCon keynote sessions were kicked off by Intel Chief Linux and Open Source Technologist and Linux kernel developer Dirk Hohndel who said that client computing today is mostly Linux. Thanks to Android on smartphones and tablets, plus the rise of Chromebooks, Intel sees Linux as the leading end-user operating system.

Hohndel admitted that "in 1999 he was the first to predict the 'Year of the Linux desktop.' Predictions are hard," he continued wryly, "especially about the future. But if I changed it from the year of Linux desktop and changed it to a decade and a half from now client computing will be mostly Linux, which has happened."


Intel is singing a different tune from when the company, thanks to its close Microsoft partnership known as Wintel. Hohndel was simply saying what Goldman Sachs and Kleiner Perkins Caufield & Byers have already reported: Windows has declined while Linux has rose.

As Goldman Sach stated in December 2012, "It took a computer revolution to unseat Microsoft from its dominant market position." It was not that Linux-based Android or Apple ever managed to knock Windows off its desktop throne. They haven't. It was the smartphone and tablet rebellion which has unseated the desktop. "Fundamentally, Microsoft’s business was disrupted by other vendors who successfully introduced compelling new device categories" But "thus far, Microsoft has failed to establish a meaningful foothold in [these new] key growth categories."

In his speech to top Linux engineers and developers, Hohndel said, "Outside of the community, most people don't see Linux's impact. Linux is usually invisible. When you go to any large Web site--Google, Facebook, Twitter--you're using Linux."

It's not just that even the most die-hard Windows users are invisibly using Linux every day, Hohndel said that, thanks to Android, Chrome OS, and the Linux that dares not speak its name (Ubuntu), the Linux end-user experience has never been more popular.

In particular, when it comes to Chromebooks, Google and Intel are working closely on improving these lightweight laptops. The two companies "have seen Chromebooks race to a quarter of all computer sales and one fifth of all new PC school deployments."

Again, these users, just like Android users, may not be aware that they're using Linux, but then they're using Android smatphones and tablets, Chromebooks or Ubuntu, they're using Linux.

Latest News

LOADING LATEST NEWS....
Loading Blog Posts...


Loading Images...
Loading Videos...


Updated at: Friday, September 20, 2013

Monday, February 4, 2013

Linux :: How to harden SSH security on CentOS


Secure Shell for Linux has been one of the most attacked on servers, we find many cases where the bruteforce finally compromises the server for root access. One of the most common queries that come on to desk is how to harden out SSH - here are few tips that should help - I wont recommend enabling every bit of it, but will include the list which is most required and ones that are optional.

The configurations of SSH is available either on /usr/local/ssh/sshd_config or /etc/ssh/sshd_config - so that is where we start. So we need a connection on KVM or SSH on to the server and knowledge of popular editors like pico or vim to start with it.

Most Important Changes

These are the list of configurations that you should never do away with, so start with the first:
1. Block SSH Version1:
SSH protocol version 1 (SSH-1) has man-in-the-middle attacks problems and security vulnerabilities. SSH-1 is obsolete and should be avoided at all cost. Open sshd_config file and make sure the following line exists:
Protocol 2

2. SSH Port
From what I have seen, most of the bruteforce happens on to the port 22, considering the fact that most of the server owners doesn't care to change the SSH port. So this is the second most important thing to be done- change the SSH port to a number different from 22 - which is the default port id:
Port 1111
be sure to remove the comment mark preceding the Port entry and also ensure that you update your firewall or firewall wrapper configuration for the new port to be accessible. Another option of securing sites will be to disable access from all public entries and allow access to port 22 via LAN or WAN connection - this is possible only for local servers or locations where you have static IP range - the iptables entries will need to be updated as :
pico /etc/sysconfig/iptables 

(or find the locations of iptables by running /etc/init.d/iptables save)and add the following entries:

-A RH-Firewall-1-INPUT -s 192.168.1.0/24 -m state --state NEW -p tcp --dport 22 -j ACCEPT
-A RH-Firewall-1-INPUT -s 202.54.1.5/29 -m state --state NEW -p tcp --dport 22 -j ACCEPT
if you do not want to alter the firewall configuration, you can restrict access on to the server from specific network by removing the command on 'ListenAddress' keyword:
ListenAddress 192.168.1.5
ListenAddress 202.54.1.5
where the first entry should be updated by your LAN IP and the second by your WAN IP address.
3. Protect SSH with Firewall
Apart from the iptables rules said above, it will be wise to install a bruteforce prevention firewall wrapper like CSF or similar where you can define the count of failures on to SSH and block the originating IP address. I am recommending CSF since its getting updates on a regular basis and has a simple configuration that can be used to carry out much complex operations.

4. Disable Root Login
Disabling root login is another good option which should protect the server even if your workstation is compromised with key loggers. The root password, even if it is correct, wont be accepted by the system which inturn will need a non-root user to login to the server first and then use the 'su -' command to gain root access. You can achieve this by updating the configuration entry:
PermitRootLogin no
to take this option to the next level, you can also define the set of users which do have access on to the ssh server, thereby minimizing the chances of compromise, you can do this by adding in the entry:
AllowUsers root raj rahul
or
AllowGroup sshusers
which should help you from not defining each individual user - and add the new users to the group if you want them to have SSH access

5. Defining Idle Timeout for users:
Another important setting that shouldn't be ignored is having an idle timeout set for your logins so that the active sessions doesn't allow hackers to change settings. We can get this done by updating:
ClientAliveInterval 300
ClientAliveCountMax 0
HostbasedAuthentication no
this is required by most of the systems unless you have a more secure network behind a hardware firewall. The above timeout is for 5 minutes and post this period all active sessions will be terminated.
6. Ensure that the defaults are not modified:
IgnoreRhosts yes
RhostsRSAAuthentication no
HostbasedAuthentication no
PermitEmptyPasswords no
UsePam yes
ensure that these settings are not altered as you wouldn't want the rhosts entry and empty passwords to be active on for SSH logins.

7. Issue a notice on each login:
Issuing a well defined banner on each SSH login should be good as well, add in the guidelines and also define the penalty of breaching into the system - that should help at times:
Banner /etc/issue
and a sample entry would look:
----------------------------------------------------------------------------------------------
You are accessing a XYZ Government (XYZG) Information System (IS) that is provided for authorized use only.
By using this IS (which includes any device attached to this IS), you consent to the following conditions:
+ The XYZG routinely intercepts and monitors communications on this IS for purposes including, but not limited to,
penetration testing, COMSEC monitoring, network operations and defense, personnel misconduct (PM),
law enforcement (LE), and counterintelligence (CI) investigations.
+ At any time, the XYZG may inspect and seize data stored on this IS.
+ Communications using, or data stored on, this IS are not private, are subject to routine monitoring,
interception, and search, and may be disclosed or used for any XYZG authorized purpose.
+ This IS includes security measures (e.g., authentication and access controls) to protect XYZG interests--not
for your personal benefit or privacy.
+ Notwithstanding the above, using this IS does not constitute consent to PM, LE or CI investigative searching
or monitoring of the content of privileged communications, or work product, related to personal representation
or services by attorneys, psychotherapists, or clergy, and their assistants. Such communications and work
product are private and confidential. See User Agreement for details.
----------------------------------------------------------------------------------------------
courtesy:cyberciti.biz

Optional Settings for Added Security

8. Using Key based login
This is usually a recommended option which allows each user to create a sign in key and if it matches with the key on the server, the access is granted in. We had skipped this option earlier as it becomes tough when you are not on the machine or laptop that you are used to working from and will be troublesome if you have to get to the system from a new machine.

You can refer : http://www.cyberciti.biz/faq/ssh-passwordless-login-with-keychain-for-scripts/ for setting up the key authentication.

Another interesting addition will be : Using Google Authenticators So the settings you will need to update is to enable key based authentication are:
PasswordAuthentication no
ServerKeyBits 2048
RSAAuthentication yes
PubkeyAuthentication yes
That should help you get running.

9. Disabling SSH open Server
So if it is just for SSH that you need the server running for and to avoid users from sending out or receiving files over SSH, you can disable SSH server entity which is enabled by default, you can do that by running the commands:
chkconfig sshd off
 yum erase openssh-server
 service iptables restart
 service ip6tables restart


10. Use Log-level info
Read your logs using logwatch or logcheck. This should help you keep constant check on the SSH activity and modify the security rules based on incoming traffic. Make sure LogLevel is set to INFO or DEBUG in sshd_config:
LogLevel INFO
Additionally, you can recompile the source code of SSH to enable the following options which should help you gain added security:
#  Turn on privilege separation
UsePrivilegeSeparation yes
# Prevent the use of insecure home directory and key file permissions
StrictModes yes
# Turn on  reverse name checking
VerifyReverseMapping yes
# Do you need port forwarding?
AllowTcpForwarding no
X11Forwarding no
#  Specifies whether password authentication is allowed.  The default is yes.
PasswordAuthentication no
Once the modifications are complete, save the configuration and run the following command to ensure the compatibility of changes:
`which sshd` -t
if the syntax returns no error, then feel free to restart the services:
service sshd restart
Hope this did help!


Updated at: Monday, February 04, 2013

Wednesday, January 2, 2013

Linux : How to install ClamAV using yum


                            


ClamAV is a powerful antivirus and is handy while you try to check the vulnerable files on a Linux server, so as long as you have a root access to the server, this will work quite easily. Here is the quickest method available to install clamav and scan a folder and it happens over few minutes. First we start by updating the repository for the latest version of ClamAV, I am using DAG: 64bit:
rpm -Uhv http://apt.sw.be/redhat/el5/en/x86_64/rpmforge/RPMS/rpmforge-release-0.3.6-1.el5.rf.x86_64.rpm
32bit: rpm -Uhv http://apt.sw.be/redhat/el5/en/i386/rpmforge/RPMS/rpmforge-release-0.3.6-1.el5.rf.i386.rpm once this is done, the next step is :
yum install clamav-db clamav clamd
optionally you may want to run yum update before the command, but I do not prefer it is going to be few more minutes and lots of updates if you haven't used the yum update feature yet. Once the software gets installed, run the command:
-bash-3.2# freshclam
ClamAV update process started at Wed Jan  2 06:25:53 2013
main.cvd is up to date (version: 54, sigs: 1044387, f-level: 60, builder: sven)
daily.cvd is up to date (version: 16293, sigs: 474141, f-level: 63, builder: neo)
bytecode.cvd is up to date (version: 209, sigs: 40, f-level: 63, builder: neo)
optionally you can set the following on /etc/clamd.conf :

TCPAddr 127.0.0.1
TCPSocket 3310
User root
MaxThreads 30
That should be the ideal result. And once the clamAV is updated, you can run the scan :
-bash-3.2# clamscan -i -r /home > reports.txt
I prefer redirecting it to a text and the report will include only the infected files list and the scan will be done recursively. Hope this helps!

Updated at: Wednesday, January 02, 2013

Tuesday, December 11, 2012

HowTo : Cpanel not displaying active databases


Once in a while Cpanel does act bad and decides to play a hide n seek game, and as seekers we have to find the hidden stuff. Going back to technical jargon, you might find one day that all your databases listed under Cpanel is missing. So if you have root access to your server, then here is a cool way how you can fix it up in a matter of seconds. Ready?

Here we go

As always run the command :
-bash-3.2# /scripts/upcp --force &&
 /scripts/checkperlmodules --force && 
/usr/local/cpanel/bin/setupdbmap --force


usually these should fix the issue without even you knowing what was causing it, but if you are curious, try running:

cat /usr/local/cpanel/logs/error_log|grep mysql|less

or
tail -f /usr/local/cpanel/logs/error_log|grep mysql
check for the recent errors you see on the page, do you see any authentication errors from root user? If yes, then try running command:
-bash-3.2# mysql


normally if you are signed in as root then you shouldn't have any trouble reaching mysql prompt from there. But if you do then you will have to try the following steps:

Login to WHM as root >> MySQL Root Password

And reset the password, once you have the new password, check back on the ssh screen and run the command:

-bash-3.2# mysql_fix_privilege_tables --verbose --password=newpassword


Once this is done, try logging on to Cpanel for the account and add a database, and check back on the listing, you should find your databases back on the list.

UPDATE : If the error persists, then please try running
-bash-3.2# /scripts/update_db_cache
-bash-3.2# vi /etc/my.cnf
and add the entry:
innodb_force_recovery = 4

and restart mysql.

References:

CPanel Docs, Cpanel Forums


Updated at: Tuesday, December 11, 2012