<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-27796345</id><updated>2011-04-22T11:56:17.534+08:00</updated><title type='text'>life of a linux wanna-be user</title><subtitle type='html'>For linux noobs and wannabees like me</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://back2basics2.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://back2basics2.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>ibiangski</name><uri>http://www.blogger.com/profile/00192886950685750765</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>3</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-27796345.post-114828536514820886</id><published>2006-05-22T15:34:00.000+08:00</published><updated>2006-05-22T16:15:53.336+08:00</updated><title type='text'>Peeping Tom Setup (Qmail, Vpopmail)</title><content type='html'>&lt;span style="font-family:arial;font-size:85%;"&gt;This will send copies of all incoming and outgoing mails on the mail server (qmail) to a vpopmail user (that is one wants to read the mail via vpopmail).&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Pre-requisites:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Install everything you need: Qmailrocks.org has an excellent, even-noobs-can-do-this instructions.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;After shock steps:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;1. Go to qmail source directory. Set QUEUE_EXTRA as "T&lt;em&gt;&lt;recipient&gt;&lt;/em&gt;\0". (Not don't act too noobish! Replace &lt;recipient&gt;as a valid linux user.) Then set QUEUE_EXTRALEN as the length of &lt;em&gt;&lt;recipient&gt;&lt;/em&gt;(in characters) plus "2". ('T' and '\0' count as one each)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail qmail-1.03]# cat extra.h&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;#ifndef EXTRA_H&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;#define EXTRA_H&lt;br /&gt;#define QUEUE_EXTRA "Tpeeping.tom\0"&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;#define QUEUE_EXTRALEN 13&lt;br /&gt;#endif&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;2. Create a linux user with the same name as your recipient. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail qmail-1.03]# useradd peeping.tom&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;3. Create a Maildir directory for your recipient. This is where mails will be delivered to. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail qmail-1.03]# su - peeping.tom&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[peeping.tom@mail ~]# maildirmake Maildir&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;4. Create a .qmail-peeping.tom file under /var/qmail/alias/.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail ~]# cat /var/qmail/alias/.qmail-peeping.tom&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;~/Maildir/&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;5. Recompile qmail. Stop qmail before recompiling.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail qmail-1.03] qmailctl stop&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail qmail-1.03] make server setup&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail qmail-1.03] qmailctl start&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;By this time, you can see files under the Maildir/new directory of the recipients. To forward it to a vpopmail user, just copy these files to the Maildir/new directory of the vpopmail user. Change make sure to change the ownership of those files after transfer to allow access to the vpopmail service.&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail new] chown vpopmail.vchkpw /home/vpopmail/domains/mydomain.com/peeping.tom/Maildir/new/*&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;[root@mail new] chown vpopmail.vchkpw /home/vpopmail/domains/mydomain.com/peeping.tom/Maildir/cur/* &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;Tips:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;- You can now use Horde+Imp to access these emails via IMAP server. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;- You can use crontab to automate the transfer of files/emails to the vpopmail user.&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27796345-114828536514820886?l=back2basics2.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default/114828536514820886'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default/114828536514820886'/><link rel='alternate' type='text/html' href='http://back2basics2.blogspot.com/2006/05/peeping-tom-setup-qmail-vpopmail.html' title='Peeping Tom Setup (Qmail, Vpopmail)'/><author><name>ibiangski</name><uri>http://www.blogger.com/profile/00192886950685750765</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-27796345.post-114800682605101861</id><published>2006-05-19T10:44:00.000+08:00</published><updated>2006-05-19T10:47:06.053+08:00</updated><title type='text'>Remnants of a MS user</title><content type='html'>&lt;span style="font-family:arial;font-size:85%;"&gt;Links to Configure Log Shipping on SQL Server 2000:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Part 1 - &lt;/span&gt;&lt;a href="http://www.microsoft.com/technet/prodtechnol/sql/2000/maintain/logship1.mspx"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.microsoft.com/technet/prodtechnol/sql/2000/maintain/logship1.mspx&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Part 2 -&lt;/span&gt;&lt;a href="http://www.microsoft.com/technet/prodtechnol/sql/2000/maintain/logship2.mspx"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.microsoft.com/technet/prodtechnol/sql/2000/maintain/logship2.mspx&lt;/span&gt;&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27796345-114800682605101861?l=back2basics2.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default/114800682605101861'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default/114800682605101861'/><link rel='alternate' type='text/html' href='http://back2basics2.blogspot.com/2006/05/remnants-of-ms-user.html' title='Remnants of a MS user'/><author><name>ibiangski</name><uri>http://www.blogger.com/profile/00192886950685750765</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-27796345.post-114716774924049313</id><published>2006-05-09T15:34:00.000+08:00</published><updated>2006-05-09T18:02:59.630+08:00</updated><title type='text'>sshd Security Basics</title><content type='html'>&lt;span style="font-family:arial;font-size:85%;"&gt;On the sshd_config file, configure the following:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;1. Disable root account login&lt;br /&gt;PermitRootLogin yes&lt;br /&gt;&lt;br /&gt;2. Disable Protocol 1&lt;br /&gt;Protocol 2&lt;br /&gt;Here's the reason behind Protocol 1exploit: &lt;a href="http://www.ciac.org/ciac/techbull/CIACTech02-001.shtml"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.ciac.org/ciac/techbull/CIACTech02-001.shtml&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;3. List allowed users and groups&lt;br /&gt;AllowUsers &amp;lt;user_name_pattern1&amp;gt;&amp;lt;space&amp;gt;&amp;lt;user_name_pattern2&amp;gt;&amp;lt;space&amp;gt;&amp;lt;user_name_pattern3&amp;gt;&lt;br /&gt;AllowGroups &amp;lt;grp_name_pattern1&amp;gt;&amp;lt;space&amp;gt;&amp;lt;grp_name_pattern2&amp;gt;&amp;lt;space&amp;gt;&amp;lt;grp_name_pattern3&amp;gt;&lt;br /&gt;&lt;br /&gt;4. Disconnect after continuous failed login attempts in a specified time interval (in seconds) &lt;br /&gt;LoginGraceTime 20&lt;br /&gt;&lt;br /&gt;5. Do not allow blank passwords&lt;br /&gt;PermitEmptyPasswords no&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;Add-ons:&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;&lt;br /&gt;1. No logins for known users such as admin, test, guest, user, webmaster, postgres, mysql, www, apache, backup, web, nobody, etc.&lt;br /&gt;&lt;br /&gt;root@localhost&amp;gt; passwd -l &amp;lt;user_name&amp;gt;&lt;br /&gt;&lt;br /&gt;2. Restrict host access to the ssh service (port 22) if possible (Done via iptables)&lt;br /&gt;&lt;br /&gt;3. Make use of chroot. &lt;a href="http://chrootssh.sourceforge.net/"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://chrootssh.sourceforge.net/&lt;/span&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;4. Configure key-based authentication. &lt;a href="http://www.ssh.com/support/documentation/online/ssh/adminguide/32/Public-Key_Authentication-2.html"&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;http://www.ssh.com/support/documentation/online/ssh/adminguide/32/Public-Key_Authentication-2.html&lt;/span&gt;&lt;/a&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/27796345-114716774924049313?l=back2basics2.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default/114716774924049313'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/27796345/posts/default/114716774924049313'/><link rel='alternate' type='text/html' href='http://back2basics2.blogspot.com/2006/05/sshd-security-basics.html' title='sshd Security Basics'/><author><name>ibiangski</name><uri>http://www.blogger.com/profile/00192886950685750765</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry></feed>
