<?xml version="1.0" encoding="UTF-8"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
    <title>Univers Libre - sysadmin</title>
    <subtitle>Yet another sysadmin&#39;s personal blog</subtitle>
    <link rel="self" type="application/atom+xml" href="https://univers-libre.net/tags/sysadmin/atom.xml"/>
    <link rel="alternate" type="text/html" href="https://univers-libre.net"/>
    <generator uri="https://www.getzola.org/">Zola</generator>
    <updated>2019-04-20T00:00:00+00:00</updated>
    <id>https://univers-libre.net/tags/sysadmin/atom.xml</id>
    <entry xml:lang="en">
        <title>Containerize ZNC with systemd-nspawn</title>
        <published>2019-04-20T00:00:00+00:00</published>
        <updated>2019-04-20T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/containerize-znc-with-systemd-nspawn/"/>
        <id>https://univers-libre.net/posts/containerize-znc-with-systemd-nspawn/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/containerize-znc-with-systemd-nspawn/">&lt;p&gt;On my previous server, I had an IRC client (weechat) running in a &lt;code&gt;screen&lt;/code&gt;
session. I recently migrated this setup to a &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://wiki.znc.in/ZNC&quot;&gt;ZNC
bouncer&lt;/a&gt; running on my server + weechat running on my
laptop, mainly to avoid network lags through SSH and to have a better desktop
integration (notifications, etc.).&lt;/p&gt;
&lt;p&gt;My server hosts my e-mails, important and confidential documents (among other
things) and I always thought that running an always connected IRC client on the
same machine was a bad idea.&lt;/p&gt;
&lt;p&gt;So in the same time I got rid of my weechat+screen to migrate to ZNC, I had a
look at &lt;code&gt;systemd-nspawn&lt;/code&gt;, also known as systemd containers. It’s actually
pretty much like LXC containers, but managed with the systemd logic in mind.&lt;/p&gt;
&lt;p&gt;Here is a quick tutorial of how I containerized ZNC into a systemd container on
a Debian stretch system:&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;
&lt;p&gt;First, install &lt;em&gt;systemd-container&lt;/em&gt; and &lt;em&gt;debootstrap&lt;/em&gt; packages:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# apt install systemd-container debootstrap&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Create directories used by &lt;code&gt;systemd-container&lt;/code&gt; (which aren’t create on
install):&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mkdir /var/lib/machines/ /etc/systemd/nspawn/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;em&gt;/var/lib/machines/&lt;/em&gt; will host the containers’ hierarchy and containers
unit files will be stored into &lt;em&gt;/etc/systemd/nspawn/&lt;/em&gt;.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Install a Debian system + &lt;em&gt;znc&lt;/em&gt; package using &lt;code&gt;debootstrap&lt;/code&gt; into
&lt;em&gt;/var/lib/machines/znc/&lt;/em&gt;:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# cd /var/lib/machines/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# debootstrap --include znc stretch znc&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;To make the container start on boot, you have to enable the corresponding
&lt;em&gt;systemd-nspawn&lt;/em&gt; instance and the &lt;em&gt;machines&lt;/em&gt; target (which will start all
enabled instances of &lt;em&gt;systemd-nspawn&lt;/em&gt; unit:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# systemctl enable systemd-nspawn@znc machines.target&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;At this stage, your container is ready. You can start your container (run
its init process) with:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# systemd-nspawn -D /var/lib/machines/znc/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Or execute a command in the container:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# systemd-nspawn -D /var/lib/machines/znc/ hostname&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;systemd-nspawn comes with the &lt;code&gt;machinectl&lt;/code&gt; command which allows you to
easily manage your containers:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# machinectl [list|list-images|start|stop|status|…]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;See its man page for all supported sub-commands and options.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Now, let’s configure some few extra stuff to run ZNC. Create a dedicated
user in the container:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# systemd-nspawn -D /var/lib/machines/znc/ useradd -u 1002 -g 1002 -m znc&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;And customize the container’s options by putting a config file into
&lt;em&gt;/etc/systemd/nspawn/&lt;/em&gt;:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Exec]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Don&amp;#39;t start the init process inside the container, instead execute&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# `znc`&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Boot=off&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Parameters=/usr/bin/znc --foreground&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Drop all default capabilities: the container will run with no&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# capabilities, ZNC doesn&amp;#39;t need any&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;DropCapability=CAP_CHOWN CAP_DAC_OVERRIDE CAP_DAC_READ_SEARCH CAP_FOWNER CAP_FSETID CAP_IPC_OWNER CAP_KILL CAP_LEASE CAP_LINUX_IMMUTABLE CAP_NET_BIND_SERVICE CAP_NET_BROADCAST CAP_NET_RAW CAP_SETGID CAP_SETFCAP CAP_SETPCAP CAP_SETUID CAP_SYS_ADMIN CAP_SYS_CHROOT CAP_SYS_NICE CAP_SYS_PTRACE CAP_SYS_TTY_CONFIG CAP_SYS_RESOURCE CAP_SYS_BOOT CAP_AUDIT_WRITE CAP_AUDIT_CONTROL&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Start `znc` as znc&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;User=znc&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Those 2 options aren&amp;#39;t supported by the version of systemd shiped&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;with Debian stretch. Ephemeral=on makes the container discard on&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;shutdown any modification made during its runtime (Docker style) and&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoNewPrivileges ensures that the code executed inside the container&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;won&amp;#39;t be able to gain greater privileges (with setuid bit for instance)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#Ephemeral=on&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#NoNewPrivileges=on&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Use private user namespace (equivalent to LXC&amp;#39;s unprivilegied mode)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;PrivateUsers=on&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Files] &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Mount my .znc configuration directory onto the container (with write&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;access) and the znc.pem containing the private key, certificates chain&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;and DH param (read-only)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Bind=/home/romain/.znc/:/home/znc/.znc/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;BindReadOnly=/var/lib/acme/live/irc.univers-libre.net/combined:/home/znc/.znc/znc.pem&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[Network]&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# Use the same network stack as the host&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;VirtualEthernet=no&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;This file will automatically be read by &lt;code&gt;systemd-nspawn&lt;/code&gt; before starting
the container. All these options can be specified as commandline
parameters to &lt;code&gt;systemd-nspawn&lt;/code&gt; as well.&lt;/p&gt;
&lt;/li&gt;
&lt;/ol&gt;
&lt;p&gt;Resources:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://wiki.archlinux.org/title/Systemd-nspawn&quot;&gt;https://wiki.archlinux.org/title/Systemd-nspawn&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://www.freedesktop.org/software/systemd/man/systemd-nspawn.html&quot;&gt;https://www.freedesktop.org/software/systemd/man/systemd-nspawn.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://www.freedesktop.org/software/systemd/man/systemd.nspawn.html&quot;&gt;https://www.freedesktop.org/software/systemd/man/systemd.nspawn.html&lt;/a&gt;&lt;/li&gt;
&lt;li&gt;&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://www.freedesktop.org/software/systemd/man/machinectl.html&quot;&gt;https://www.freedesktop.org/software/systemd/man/machinectl.html&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>List changed configuration files and restore the maintainer&#39;s version</title>
        <published>2019-01-24T00:00:00+00:00</published>
        <updated>2019-01-24T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/list-changed-conffiles/"/>
        <id>https://univers-libre.net/posts/list-changed-conffiles/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/list-changed-conffiles/">&lt;p&gt;Recently I had to clean one of my server (a virtual machine hosted by
&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://tetaneutral.net/&quot;&gt;Tetaneutral&lt;/a&gt;) to make it as close to a fresh install
as possible, but without reinstalling it or migrate it somewhere else. It is an
old server and it has been installed by hand. Since I now use Ansible to manage
my other servers, I wanted to include it to the inventory and apply the same
configuration on it.&lt;/p&gt;
&lt;p&gt;On Archlinux, I used to use this command which list me all configuration files
(in /etc) which have diverged from the version shipped by the package:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ pacman -Qii | awk &amp;#39;/^MODIFIED/ {print $2}&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I didn’t find a simple equivalent way to do it in Debian with dpkg tools,
however I found &lt;code&gt;debsums&lt;/code&gt;, an extra package that does the job pretty well:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ debsums -se&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;I then can restore the package’s version by reinstalling the corresponding
package with &lt;code&gt;--force-confask&lt;/code&gt; option:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# apt install --reinstall -o Dpkg::Options::=&amp;quot;--force-confask&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Here is an oneliner to automate the process (careful, it doesn’t ask for any confirmation!):&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# debsums -se 2&amp;gt;&amp;amp;1 |awk &amp;#39;{print $4}&amp;#39; |xargs -n 1 dpkg -S |awk -F: &amp;#39;{print $1}&amp;#39; |sort -u |xargs apt install --reinstall -o Dpkg::Options::=&amp;quot;--force-confask&amp;quot; -o Dpkg::Options::=&amp;quot;--force-confnew&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Since &lt;code&gt;xargs&lt;/code&gt; doesn’t work well with interactive commands, I force the choice by passing both &lt;code&gt;--force-confask&lt;/code&gt; and &lt;code&gt;--force-confnew&lt;/code&gt; options.&lt;/p&gt;
&lt;p&gt;As a conclusion, keep in mind the configuration files &lt;strong&gt;added&lt;/strong&gt; in &lt;em&gt;*.d/&lt;/em&gt; directories won’t be listed nor removed, so you still have to clean these directories manually.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Safe paste in terminal</title>
        <published>2018-12-22T00:00:00+00:00</published>
        <updated>2018-12-22T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/safe-paste-in-terminals/"/>
        <id>https://univers-libre.net/posts/safe-paste-in-terminals/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/safe-paste-in-terminals/">&lt;p&gt;In my daily life of sysadmin, I copy-paste many chunk of text (commands, IP
addresses, URLs, file paths, whole scripts or file contents sometimes because it’s
easier to copy-paste them rather than to scp them). I usually copy them from
other servers or from my company’s internal documentation (trusted
sources). However, I may sometimes follow howtos or read Stackoverflow answers
and copy text and commands from those less trusted websites.&lt;/p&gt;
&lt;p&gt;I want to talk about how easy one could trick you by replacing copied text in
your clipboard or inserting terminal escape sequences so that your shell will
run additional and potentially malicious commands. And how I protecting myself
against these tricks.&lt;/p&gt;
&lt;h2 id=&quot;tricks-i-have-identified&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#tricks-i-have-identified&quot; aria-label=&quot;Anchor link for: tricks-i-have-identified&quot;&gt;Tricks I have identified&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Here is a list of tricks an attacker can use to fool you and make you paste a
malicious command in your terminal.&lt;/p&gt;
&lt;h3 id=&quot;replacing-copied-text-with-javascript&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#replacing-copied-text-with-javascript&quot; aria-label=&quot;Anchor link for: replacing-copied-text-with-javascript&quot;&gt;Replacing copied text with Javascript&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;Dylan Ayrey demonstrates that with a &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://github.com/dxa4481/Pastejacking&quot;&gt;few lines of
Javascript&lt;/a&gt;, a malicious website can
alter your clipboard content. The code runs on key release event (keyboard
shortcut or right click) and override clipboard content with the malicious
code the attacker wants you to execute.&lt;/p&gt;
&lt;p&gt;Obviously this attack doesn’t work if you disable Javascript on unstrusted
websites, which is by the way always a good idea.&lt;/p&gt;
&lt;h3 id=&quot;hiding-malicious-code-with-css&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#hiding-malicious-code-with-css&quot; aria-label=&quot;Anchor link for: hiding-malicious-code-with-css&quot;&gt;Hiding malicious code with CSS&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;But even with Javascript disabled it’s easy for an attacker to put hidden text
in your clipboard. The idea is to put the malicious code in the middle of the
displayed command in a &lt;code&gt;&amp;lt;span /&amp;gt;&lt;/code&gt; element and apply different
CSS properties on it, so that the malicious code isn’t visible for the user. For
instance make it float and move it away from the viewport, make it transparent,
with no height or width…&lt;/p&gt;
&lt;p&gt;&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://www.ush.it/team/ascii/hack-tricks_253C_CCC2008/wysinwyc/what_you_see_is_not_what_you_copy.txt&quot;&gt;Here is an interesting
article&lt;/a&gt;
about this attack. It also show how to hide the malicious code once pasted in
the victim’s terminal so that the victim can’t
even known he has been p0wned.&lt;/p&gt;
&lt;p&gt;What about disabling CSS then?&lt;/p&gt;
&lt;h3 id=&quot;inserting-non-printable-characters&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#inserting-non-printable-characters&quot; aria-label=&quot;Anchor link for: inserting-non-printable-characters&quot;&gt;Inserting non-printable characters&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;That’s no enough since you could have non-printable characters (like
backspaces) in raw text. &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://security.stackexchange.com/questions/39118/how-can-i-protect-myself-from-this-kind-of-clipboard-abuse&quot;&gt;Here is an
example&lt;/a&gt;
(the whole thread is an interesting reading by the way).
Basically, the idea is to insert extra characters and a backspace character
after each of them to make the code appear inoffensive.&lt;/p&gt;
&lt;h2 id=&quot;how-i-protect-myself&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#how-i-protect-myself&quot; aria-label=&quot;Anchor link for: how-i-protect-myself&quot;&gt;How I protect myself&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;So what next? What solutions I use to protect myself against those attacks?&lt;/p&gt;
&lt;h3 id=&quot;pasting-into-a-text-editor-the-bad-idea&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#pasting-into-a-text-editor-the-bad-idea&quot; aria-label=&quot;Anchor link for: pasting-into-a-text-editor-the-bad-idea&quot;&gt;Pasting into a text editor: the bad idea&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;In most shell, I can easily start &lt;code&gt;$EDITOR&lt;/code&gt; with &lt;code&gt;^X^E&lt;/code&gt; to edit the current
command. But that’s totally ineffective since the pasted text can contain
&lt;code&gt;^ESC:!&amp;lt;malicious code&amp;gt;&lt;/code&gt; which will work in vim, or simply send the right
shortcut to close the editor and get back to the shell.&lt;/p&gt;
&lt;h3 id=&quot;shell-s-bracketed-paste-mode&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#shell-s-bracketed-paste-mode&quot; aria-label=&quot;Anchor link for: shell-s-bracketed-paste-mode&quot;&gt;Shell’s bracketed paste mode&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;This is an elegant solution. Bash (actually readline) can configure the
terminal to enclose the pasted text between paste sequences (hence the
&lt;em&gt;bracketed paste mode&lt;/em&gt;):&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;enable-bracketed-paste (Off)
When  set to On, readline will configure the terminal in a way that will enable
it to insert each paste into the editing buffer as a single string  of  charac‐
ters,  instead  of treating each character as if it had been read from the key‐
board.  This can prevent pasted characters from being  interpreted  as  editing
commands.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;To enable it:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ echo &amp;quot;set enable-bracketed-paste on&amp;quot; &amp;gt;&amp;gt;~/.inputrc&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you then try to paste multi-lines commands in your terminal, the commands won’t be executed unless you press enter. You have a chance to review and edit them before their execution.&lt;/p&gt;
&lt;p&gt;But it has two main drawbacks:&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;obviously enabling bracketed paste mode will work on your own computer only,
unless you enable it on all your remote servers as well.&lt;/li&gt;
&lt;li&gt;you may still be vulnerable to code injection if the pasted text contains the
bracketed-paste-mode end sequence, whether your terminal automatically filter
this sequence or not.&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;You can test this &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://thejh.net/misc/website-terminal-copy-paste&quot;&gt;here&lt;/a&gt;.&lt;/p&gt;
&lt;h3 id=&quot;confirm-paste-plugin-in-urxvt&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#confirm-paste-plugin-in-urxvt&quot; aria-label=&quot;Anchor link for: confirm-paste-plugin-in-urxvt&quot;&gt;confirm-paste plugin in URxvt&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;URxvt has a nice plugin called paste-confirm. It is shipped with URxvt and can be found in its plugin directory (&lt;em&gt;/usr/lib/urxvt/perl/&lt;/em&gt;). Once loaded, the plugin will detect multi-lines pastes and will ask you whether to really paste it to the shell or not.&lt;/p&gt;
&lt;p&gt;To enable it, simply add it to the plugin list in your &lt;em&gt;~/.Xdefaults&lt;/em&gt;:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;URxvt.perl-ext-common: […],confirm-paste&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h3 id=&quot;print-your-clipboard-content-before-you-paste&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#print-your-clipboard-content-before-you-paste&quot; aria-label=&quot;Anchor link for: print-your-clipboard-content-before-you-paste&quot;&gt;Print your clipboard content before you paste&lt;/a&gt;&lt;/h3&gt;
&lt;p&gt;It’s always a good idea to double-check your clipboard content before pasting
it somewhere. I sometimes don’t remember or I’m not sure about what was my
previous selection, and I remember pasting whole file content into my terminal
a couple of times…&lt;/p&gt;
&lt;p&gt;I now use &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://github.com/mrichar1/clipster&quot;&gt;clipster&lt;/a&gt; for my cliboard
manager with &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://github.com/gilbertw1/roficlip&quot;&gt;roficlip&lt;/a&gt;. Thus with a
simple shortcut I can quickly double-check and select the previous entries in
my clipboard.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Convert SSH keys from a format to another</title>
        <published>2017-09-06T21:46:24+00:00</published>
        <updated>2017-09-06T21:46:24+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/convert-ssh-keys/"/>
        <id>https://univers-libre.net/posts/convert-ssh-keys/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/convert-ssh-keys/">&lt;p&gt;An SSH key can be stored in multiple format. &lt;code&gt;ssh-keygen&lt;/code&gt; from OpenSSH
generates keys in its own format, but other SSH implementations can use other
formats. PuTTY for example generates keys in RFC4716 format, which looks like
this:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-----BEGIN RSA PUBLIC KEY-----&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;MIIBCgK349HFUE929fXGEvWmegnBGSuS+rU9soUg2FnODva32D1AqhwdziwHINFa&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;D1MVlcrYG6XRKfkcIFEO929JFNEJONBSEVCgJjtHAGZIm5GL/KA86KDp/CwDFMSw&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;luowcXwDwoyinmeOY9eKyh6aY72xJh7noLBBq1N0bWi1e2i+83txOCg4yV2oVXhB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;o8pYEJ8LT3el6Smxol3C1oFMVdwPgc0vTl25XucMcG/ALE/KNY6pqC2AQ6R2ERlV&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;gPiUWOPatVkt7+Bs3h5Ramxh7XjBOXeulmCpGSynXNcpZ/06+vofGi/2MlpQZNhH&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Ao8eayMp6FcvNucIpUndo1X8dKMv3Y26ZQIDAQAB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-----END RSA PUBLIC KEY-----&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You can’t simply copy-paste this in an &lt;em&gt;authorized_keys&lt;/em&gt; file. Hopefully you
can easily convert the public key from a format to another. This is done by
I-do-about-anything-and-everything command, aka &lt;code&gt;ssh-keygen&lt;/code&gt;:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ ssh-keygen -i -m &amp;lt;format&amp;gt; -f input_key.pub &amp;gt; output_key.pub&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;&lt;code&gt;-m&lt;/code&gt; specify the input key format among &lt;em&gt;RFC4716&lt;/em&gt; (the format used by PuTTY, this
is the default if &lt;code&gt;-m&lt;/code&gt; isn’t specified), &lt;em&gt;PKCS8&lt;/em&gt; and &lt;em&gt;PEM&lt;/em&gt;.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Upgrade to Debian Jessie, introducing relay_access_restrictions in Postfix</title>
        <published>2016-06-10T10:51:42+00:00</published>
        <updated>2016-06-10T10:51:42+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/upgrade-to-jessie-postfix-relay-access-restrictions/"/>
        <id>https://univers-libre.net/posts/upgrade-to-jessie-postfix-relay-access-restrictions/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/upgrade-to-jessie-postfix-relay-access-restrictions/">&lt;p&gt;Abstract for TL;DR readers: since debconf append a relay_access_restrictions at
the end of your main.cf file with same values of recipient_access_restriction,
you have to do the same on all your services listed in master.cf.
relay_access_restrictions intends to replace recipient_access_restriction on
next Postfix releases.&lt;/p&gt;
&lt;p&gt;After upgrading my mail server to Debian Jessie, I faced a weird problem with
Postfix: emails sent from authenticated clients were rejected with a “Relay
access denied” error.&lt;/p&gt;
&lt;p&gt;I have a particular setup, though not-so-uncommon I think, since it should be the standard:
port 25 is for server-to-server communications, no authentication is supported
here. Instead, clients which want to send emails have to submit them on
submission port (obviously). Concretely on my master.cf file, I override
recipient_access_restriction for submission service to allow sending of emails
with minimum restrictions if clients got authenticated.&lt;/p&gt;
&lt;p&gt;So in my case, it seemed that the recipient_access_restriction option passed
to submission process was ignored, or the one setup on my main.cf file won.
Enabling debugging didn’t tell me anything. It even confirmed me that the
recipient_access_restriction option for submission process was ignored since I
saw Postfix testing all conditions specified on my main.cf&lt;/p&gt;
&lt;p&gt;Then after some time, I have seen a new line at the end of my main.cf file : relay_access_restrictions, with all the tests of recipient_access_restrictions. Searching this on postconf(5) manual confirmed me that it replace recipient_access_restriction, although this one is always supported and not planed to be removed on the next coming versions.
So debconf has added this new directive on my main.cf file, without any debconf advertisment as far as I remember, and without reason (Postfix don’t even raised a depreciation warning about that), and that breaks other services setted up on master.cf.&lt;/p&gt;
&lt;p&gt;No ones seem to mention that on the Internet.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>How to enlarge your raw disk image</title>
        <published>2015-09-10T17:04:19+00:00</published>
        <updated>2015-09-10T17:04:19+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/extend-disk-image/"/>
        <id>https://univers-libre.net/posts/extend-disk-image/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/extend-disk-image/">&lt;p&gt;Extending a disk image file (of a KVM guest for example) is a tricky operation,
especially if we haven’t enough disk space to keep a backup of the image we
will working on. So I write a little howto for the next time we have to do this
operation.&lt;/p&gt;
&lt;h2 id=&quot;prerequisites&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#prerequisites&quot; aria-label=&quot;Anchor link for: prerequisites&quot;&gt;Prerequisites&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;First, you need to have the following packages installed: &lt;code&gt;qemu-utils kpartx parted&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Make sure your VM is halted and no processes have opened the file:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# lsof $img&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Note: for following commands, I assume &lt;code&gt;$img&lt;/code&gt; contains the path to your image file.&lt;/p&gt;
&lt;h2 id=&quot;extend-the-image-file&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#extend-the-image-file&quot; aria-label=&quot;Anchor link for: extend-the-image-file&quot;&gt;Extend the image file&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Pretty easy step, you can simply use qemu-img tool:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# qemu-img resize $img +50G&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Image resized.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;You can mount the image and check that it has the correct size:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# kpartx -v -a $img&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;add map loop0p1 (254:13): 0 195318207 linear /dev/loop0 63&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# fdisk -l /dev/loop0 &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disk /dev/loop0: 214.7 GB, 214748364800 bytes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[...]&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&quot;extend-the-partition&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#extend-the-partition&quot; aria-label=&quot;Anchor link for: extend-the-partition&quot;&gt;Extend the partition&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Then, you have to extend the partition. That supposes of course either the disk
image contains only one partition (which could be a LVM PV) or the partition
you want to extend is at the end of the image.&lt;/p&gt;
&lt;p&gt;Before all, backup your partition table:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# sfdisk -d /dev/loop0 &amp;gt;~/loop0.parts&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;(It could be restored with &lt;code&gt;sfdisk /dev/loop0 &amp;lt;~/loop0.parts&lt;/code&gt;).&lt;/p&gt;
&lt;p&gt;And remove and recreate the partition using all free space with parted:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# parted /dev/loop0 print&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Model:  (file)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Disk /dev/loop0: 215GB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Sector size (logical/physical): 512B/512B&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Partition Table: msdos&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Number  Start   End    Size   Type     File system  Flags&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt; 1      32.3kB  100GB  100GB  primary  ext3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;..&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# parted /dev/loop0 rm 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# parted /dev/loop0 mkpart primary ext3 32.3kB 215GB&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# parted /dev/loop0 print&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Remount the image to see her new size:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# kpartx -d $img&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;loop deleted : /dev/loop0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# kpartx -v -a $img&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;add map loop0p1 (254:13): 0 419430337 linear /dev/loop0 63&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;h2 id=&quot;extend-the-filesystem&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#extend-the-filesystem&quot; aria-label=&quot;Anchor link for: extend-the-filesystem&quot;&gt;Extend the filesystem&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;We are almost there, remaining the filesystem. First, this is a good thing to
run a fsck before all:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# e2fsck -f /dev/mapper/loop0p1 &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;e2fsck 1.42.5 (29-Jul-2012)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;/dev/mapper/loop0p1: recovering journal&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pass 1: Checking inodes, blocks, and sizes&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pass 2: Checking directory structure&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pass 3: Checking directory connectivity&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pass 4: Checking reference counts&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Pass 5: Checking group summary information&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;/dev/mapper/loop0p1: 41753/6111232 files (9.1% non-contiguous), 23479003/24414775 blocks&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Then, resize the filesystem:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# resize2fs /dev/mapper/loop0p1 &lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;resize2fs 1.42.5 (29-Jul-2012)&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Resizing the filesystem on /dev/mapper/loop0p1 to 52428792 (4k) blocks.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;The filesystem on /dev/mapper/loop0p1 is now 52428792 blocks long.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;It’s done!
We can check if we see the correct size after mounting the partition:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mount /dev/mapper/loop0p1 /mnt&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# df -h /mnt&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Filesystem           Size  Used Avail Use% Mounted on&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;/dev/mapper/loop0p1  197G   89G  109G  45% /mnt&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# umount /mnt&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Finally, unmount the image:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# kpartx -d $img&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;loop deleted : /dev/loop0&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Get verbose output from an already launched cp/mv/rsync process</title>
        <published>2015-05-27T19:26:18+00:00</published>
        <updated>2015-05-27T19:26:18+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/get-verbose-output-with-strace/"/>
        <id>https://univers-libre.net/posts/get-verbose-output-with-strace/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/get-verbose-output-with-strace/">&lt;p&gt;This could be a bit obvious for others sysadmins, but I use this trick quite
often and it’s really helpfull.&lt;/p&gt;
&lt;p&gt;Imagine you connect on a server and see a running process (a cronjob for example) doing some
file copy operations, running for a while and launched without -v option (or
you can’t see his stdout).&lt;/p&gt;
&lt;p&gt;Or imagine you launched a big cp/mv (from a partition to another)/rsync or whatever, you know it will probably run for a while, but you missed to add the -v
option.&lt;/p&gt;
&lt;p&gt;No problem, here is how we could get an equivalent with strace:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;strace -p $(pidof cp) 2&amp;gt;&amp;amp;1 |grep open&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Or for a rm:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;strace -p $(pidof rm) 2&amp;gt;&amp;amp;1 |grep unlink&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;If you want just to see the current file your command is currently on:&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lsof -p $(pidof cp)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Reverse proxy avec re-chiffrement du flux vers le backend</title>
        <published>2014-07-11T20:50:27+00:00</published>
        <updated>2014-07-11T20:50:27+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/reverse-proxy-https/"/>
        <id>https://univers-libre.net/posts/reverse-proxy-https/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/reverse-proxy-https/">&lt;p&gt;Dans un environnement web critique/à fort trafic, il est courant d’avoir de
multiples serveurs web, et un ou deux load-balancer devant permettant
de répartir la charge et d’avoir une tolérance de panne sur les serveurs web.&lt;br /&gt;
Dans le cas d’un site en HTTPS, le flux est en général déchiffré par les
load-balancer, puis transite en clair vers les frontaux. Cela permet de
décharger les frontaux du traitement cryptographique et au load-balancer
d’interpréter le HTTP, donc d’avoir certaines fonctionnalités intéressantes
(répartition du trafic en fonction du virtualhost ou de l’URL, gestion des
cookies de session, interprétation des codes d’erreurs HTTP renvoyés par les
frontaux pour anticiper un problème, etc…).&lt;br /&gt;
Cependant le fait que le flux HTTP transite en clair entre les load-balancers et les frontaux peut poser problème dans certains cas :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;les données qui y transitent nécessitent un haut degré de confidentialité (numéros de cartes bancaires par exemple) ;&lt;/li&gt;
&lt;li&gt;le réseau entre le load-balancer et les frontaux n’est pas sûr (le flux repasse sur Internet par exemple).&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Dans ces cas, la solution est de re-chiffrer le trafic après traitement par le
load-balancer, puis chaque frontal le déchiffre à nouveau. Il faut bien noter
que cette charge supplémentaire en traitement cryptographique (déchiffrement,
re-chiffrement, re-déchiffrement), n’est pas anodine et la quantité de requêtes
par seconde que peut encaisser la plateforme sera bien moindre que dans le cas
d’un simple déchiffrement du flux par le load-balancer.&lt;/p&gt;
&lt;p&gt;Pour en venir au cœur de l’article, j’ai dû mettre en place récemment une
architecture de ce type, et j’ai été confronté à un problème dont je ne
m’attendais pas vraiment : peu de reverse proxies HTTP savent re-chiffrer le
flux HTTP vers les backends !&lt;/p&gt;
&lt;p&gt;Parmi les logiciels existants :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;HAProxy : dans sa version stable actuelle (1.4), il ne sait pas déchiffrer
le trafic entrant, et donc encore moins re-chiffer derrière. Sa version
encore en dév (1.5) supporte le déchiffrement du HTTPS néanmoins ;&lt;/li&gt;
&lt;li&gt;Nginx : il sait bien sûr déchiffrer le HTTPS mais pas le re-chiffrer vers
les backends ensuite ;&lt;/li&gt;
&lt;li&gt;Pound : pareil que Nginx, ne sais que déchiffrer ;&lt;/li&gt;
&lt;li&gt;Apache : le seul après recherche à savoir faire les 2 !&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Voici la conf (en somme très simple) d’Apache pour lui dire de re-chiffrer le
flux vers les backends. Elle nécessite bien évidemment d’avoir mod_proxy_http
et mod_ssl :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&amp;lt;VirtualHost *:443&amp;gt;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # Activation de SSL pour le trafic entrant, cas dans le cas d&amp;#39;un&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # serveur web classique.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLEngine On&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLCertificateFile    /etc/ssl/certs/example.com.crt&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLCACertificateFile  /etc/ssl/certs/example.com-intermediate.crt&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLCertificateKeyFile /etc/ssl/private/example.com.key&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # Activation de SSL pour la communication avec les backends.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # On vérifie au passage que le certificat fourni par le backend est&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # bien valide.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLProxyEngine          On&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLProxyCheckPeerExpire On&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    SSLProxyVerifyDepth     10&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # Configuration classique du mod_proxy, mis à part qu&amp;#39;on spécifie bien&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    # https dans l&amp;#39;URL du backend.&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ProxyRequests     Off&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ProxyPreserveHost On&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ProxyPass         / https://192.0.2.42:443/ keepalive=On retry=5&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ProxyPassReverse  / https://192.0.2.42:443/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    ErrorLog  /var/log/apache2/example.com_error.log&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    CustomLog /var/log/apache2/example.com_access.log combined&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&amp;lt;/VirtualHost&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Ajout d&#39;une carte son à chaud dans un conteneur LXC</title>
        <published>2014-01-21T21:02:08+00:00</published>
        <updated>2014-01-21T21:02:08+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/lxc-ajout-carte-audio/"/>
        <id>https://univers-libre.net/posts/lxc-ajout-carte-audio/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/lxc-ajout-carte-audio/">&lt;p&gt;Voici un article express pour rajouter une carte son dans un conteneur LXC,
plus un aide-mémoire en fait, car c’est pas le genre de chose que je fais tous
les 4 matins.&lt;/p&gt;
&lt;ol&gt;
&lt;li&gt;Brancher la carte son à la machine hôte. Dans mon cas une carte USB, si
c’est en PCI, la procédure n’a que peu d’intérêt puisqu’il faudra dans tout
les cas redémarrer.&lt;/li&gt;
&lt;li&gt;le kernel doit la détecter et créer des fichiers spéciaux de type caractère
dans &lt;code&gt;/dev/snd&lt;/code&gt; :&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# ls -l /dev/snd/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;total 0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;drwxr-xr-x 2 root root       60 Jan 21 19:44 by-id&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;drwxr-xr-x 2 root root       60 Jan 21 19:44 by-path&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116,  4 Jan 21 19:44 controlC0&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116,  3 Jan 21 19:44 pcmC0D0c&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116,  2 Jan 21 19:44 pcmC0D0p&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw------T 1 root root  116,  1 Dec 17 09:24 seq&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;crw-rw---T 1 root audio 116, 33 Dec 17 09:24 timer&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Notez le numéro majeur et mineur de chaque pseudo fichier (dans mon cas 116&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;et de 1 à 4 et 33).&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;3&quot;&gt;
&lt;li&gt;Ajoutez les autorisations nécessaires dans votre conf LXC pour le conteneur
en question :&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# /dev/snd/*&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:4 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:3 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:2 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:1 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;lxc.cgroup.devices.allow                = c 116:33 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Adaptez bien sûr avec les bons numéro majeurs et mineurs.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;4&quot;&gt;
&lt;li&gt;À ce stade, il faut redémarrer le conteneur pour que les nouveaux cgroups
s’appliquent. Comme j’avais pas envie de faire ça et que les cgroups
cesttropbien, On va appliquer les nouvelles règles à chaud via son pseudo
système de fichier :&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# cat &amp;gt;/sys/fs/cgroup/lxc/&amp;lt;nom du conteneur&amp;gt;/devices.allow&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:4 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:3 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:2 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:1 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;c 116:33 rwm&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;^D&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;```&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;5&quot;&gt;
&lt;li&gt;
&lt;p&gt;Maintenant, on peut créer manuellement les pseudo fichiers dans le conteneur :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mkdir /dev/snd; cd /dev/snd&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod controlC0 c 116 4&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod pcmC0D0c c 116 3&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod pcmC0D0p c 116 2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod seq c 116 1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# mknod timer c 116 33&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# chgrp audio controlC0 pcm* timer&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# chmod 1660 controlC0 pcm* timer&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# chmod 600 seq&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Et ajoutez vous dans le groupe audio si besoin.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;ol start=&quot;6&quot;&gt;
&lt;li&gt;
&lt;p&gt;Installer alsa-utils puis :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ alsactl init&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;/ol&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Votre carte devrait à présent être détectée, vous pouvez vérifier que tout&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;fonctionne avec un `speaker-test`.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Et voila.&lt;/p&gt;
&lt;p&gt;Bon c’est pas tout ça, allons mettre à jour le kernel et rebooter :-).&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Changer simplement la couleur du curseur dans rxvt</title>
        <published>2013-11-01T17:53:37+00:00</published>
        <updated>2013-11-01T17:53:37+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/rxvt-couleur-curseur/"/>
        <id>https://univers-libre.net/posts/rxvt-couleur-curseur/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/rxvt-couleur-curseur/">&lt;p&gt;Où comment identifier facilement le serveur de prod de celui de preprod (ou le
master du slave, ou celui de prod et son futur remplaçant…).&lt;br /&gt;
Bref, comment différencier facilement votre terminal avec une connexion SSH sur
un serveur critique, et celui vers un serveur où vous pouvez tout
casser^W^W^W^W^W moins critique.&lt;br /&gt;
C’est surtout valable quand les hostnames ne diffèrent que d’une lettre ou d’un
chiffre, où la confusion est plus facile.&lt;/p&gt;
&lt;p&gt;Si il s’agit d’un serveur perso, le plus simple reste de modifier le prompt de
votre shell. Mais ce n’est pas envisageable sur un serveur sur lequel vous vous
contentez d’intervenir, ou où plusieurs admin sont susceptibles d’utiliser le
compte root.&lt;/p&gt;
&lt;p&gt;La solution est d’agir au niveau de votre terminal, ici urxvt. Les options de
rxvt peuvent être quasiment toutes changées à chaud grâce à des commandes envoyées
dans des séquences d’échappement du shell. Par exemple, pour avoir un curseur
rouge, la commande à envoyer est &lt;code&gt;\033]12;red\007&lt;/code&gt;. Vous pouvez tester avec un
simple &lt;code&gt;echo&lt;/code&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;$ echo &amp;#39;\033]12;red\007&amp;#39;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;C’est magique, mais ça reste compliquer à écrire, et encore plus à retenir. On
va donc affecter la commande à une séquence de touche, par exemple Alt+!
(et Alt+Shift+!). Dans votre &lt;code&gt;.Xdefaults&lt;/code&gt;/&lt;code&gt;.Xressources&lt;/code&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;URxvt.keysym.M-S-exclam: command:\033]12;red\007&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;URxvt.keysym.M-exclam: command:\033]12;#657b83\007  # #657b83 à remplacer par la couleur de votre police par défaut.&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;À noter qu’ainsi, même en étant dans un éditeur de texte, vous identifierez
rapidement le serveur de prod car le curseur restera rouge, ce qui n’est pas le
cas avec un prompt coloré.&lt;/p&gt;
&lt;p&gt;L’inconvénient est que le changement de couleur du curseur n’est pas
automatique, même si il est bien simplifié. Si vous avez une liste précise de
serveurs en prod, une idée peut être, à l’aide d’une extension Perl à rxvt, de
comparer le titre de la fenêtre X11 (qui contient le hostname du serveur) à
cette liste, pour pouvoir changer la couleur du curseur en conséquence.&lt;/p&gt;
&lt;p&gt;Référence :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://web.archive.org/web/20171111070243/http://artisan.karma-lab.net/urxvt-et-styles-curseur/&quot;&gt;Article de Ulhume&lt;/a&gt;
très intéressant et plus complet à propos des styles de curseur, avec une
utilisation différente.&lt;/li&gt;
&lt;/ul&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Limiter le nombre de connexions SSH avec pf</title>
        <published>2013-09-05T22:19:19+00:00</published>
        <updated>2013-09-05T22:19:19+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/pf-ratelimit/"/>
        <id>https://univers-libre.net/posts/pf-ratelimit/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/pf-ratelimit/">&lt;p&gt;Le port SSH doit probablement être parmi les plus testés par les scripts kiddies. Même si le
mieux reste de restreindre l’accès par IP et de n’autoriser l’authentification que
par clé, ce n’est des fois pas possible. Dans ce cas, on se retrouve avec une
avalanche de tentative de connexion et le auth.log qui explose en taille.
Ça devient lourd (dans les 2 sens du terme :-) ).&lt;/p&gt;
&lt;p&gt;Afin de bannir une IP au bout d’un trop grand nombre de connexions par unité de
temps, il existe différents outils qui analysent les logs et ajoutent des
règles dynamiquement comme &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://www.fail2ban.org/&quot;&gt;fail2ban&lt;/a&gt;, mais je préfère agir directement au niveau
pare-feu quand c’est possible. Avec iptables sous Linux, il existe le module
limit. Avec Packet Filter, voici comment procéder :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Créer une table, qui contiendra les IP bannies :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;table &amp;lt;badguys&amp;gt; persist&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;on drope donc tous ce qui provient des IP présentes dans la table :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;block in quick on $wan_if from &amp;lt;badguys&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;et enfin la règle intéressante :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;pass in on $wan_if proto tcp to self port ssh flags S/SA keep state (max-src-conn 3, max-src-conn-rate 5/30, overload &amp;lt;badguys&amp;gt; flush global)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;La règle permet de limiter l’établissement d’une connexion sur le port SSH à
3 connexion simultanée (&lt;code&gt;max-src-conn 3&lt;/code&gt;) et avec une limite de 5 connexion
par tranche de 30 secondes (&lt;code&gt;max-src-conn-rate 5/30&lt;/code&gt;). Si une IP dépasse
cette limite, elle est ajoutée à la table badguys (&lt;code&gt;overload &amp;lt;badguys&amp;gt;&lt;/code&gt;) et
tous les états que l’IP aurait déjà pu avoir sont supprimés (&lt;code&gt;flush global&lt;/code&gt;).&lt;/p&gt;
&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Ensuite, on peut faire expirer les IP présentes dans la table avec un simple cron :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;33 3 * * *  /sbin/pfctl -t badguys -T expire 86400 2&amp;gt;&amp;amp;1 |grep -v &amp;quot;0/0 addresses expired.&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Archlinux dans un conteneur LXC et paquet filesystem</title>
        <published>2013-06-03T21:04:00+00:00</published>
        <updated>2013-06-03T21:04:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/archlinux-lxc-filesystem/"/>
        <id>https://univers-libre.net/posts/archlinux-lxc-filesystem/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/archlinux-lxc-filesystem/">&lt;p&gt;Parmis mes conteneurs LXC, il y en a un qui tourne sous Archlinux. Comme
j’avais un peu joué avec les &lt;code&gt;capabilities (7)&lt;/code&gt; du noyau, qu’on peut retirer
avec &lt;code&gt;lxc.cap.drop&lt;/code&gt; dans le fichier de conf du conteneur, mon &lt;em&gt;/sys/&lt;/em&gt; (entre
autre) est en lecture seule pour le système chrooté.&lt;br /&gt;
Par jouer il faut comprendre rajouter des &lt;code&gt;lxc.cap.drop&lt;/code&gt; sur des &lt;code&gt;capabilities&lt;/code&gt;
choisies au feeling, jusqu’à ce que ça ne marche plus. J’exagère mais c’était
un peu ça l’idée au final :-).&lt;/p&gt;
&lt;p&gt;Donc, comme mon &lt;em&gt;/sys/&lt;/em&gt; est en lecture seule, la mise à jour du paquet
&lt;em&gt;filesystem&lt;/em&gt; chie lamentablement dans la colle :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;error: cannot remove file &amp;#39;/sys/&amp;#39;: Read-only file system&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;error: could not commit transaction&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;error: failed to commit transaction (transaction aborted)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Par flème, lorsque une mise à jour du paquet était disponible, je l’excluais
manuellement avec :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# pacman --ignore filesystem -Syu&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Puis vint le jour où la mise à jour d’un paquet demandait une version à jour du
paquet filesystem. Forcement, ça devait arriver un jour…&lt;/p&gt;
&lt;p&gt;Et c’est là qu’en cherchant un peu, j’ai découvert que dans la configuration de
&lt;code&gt;pacman&lt;/code&gt;, on peut lui dire d’empêcher un paquet de toucher à un fichier. Ça se
rapproche un peu du &lt;code&gt;dpkg-divert&lt;/code&gt; de Debian.&lt;/p&gt;
&lt;p&gt;Dans &lt;em&gt;/etc/pacman.conf&lt;/em&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoUpgrade    = sys/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;NoExtract    = sys/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;le répertoire &lt;em&gt;/sys/&lt;/em&gt; sera ignoré, et la mise à jour de &lt;em&gt;filesystem&lt;/em&gt; se fait
sans soucis !&lt;/p&gt;
&lt;p&gt;Pour plus de détails, voir &lt;code&gt;pacman.conf(5)&lt;/code&gt;.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Tracer un processus sur un système BSD</title>
        <published>2013-05-09T21:01:04+00:00</published>
        <updated>2013-05-09T21:01:04+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/ktrace/"/>
        <id>https://univers-libre.net/posts/ktrace/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/ktrace/">&lt;p&gt;Récemment sur un système OpenBSD, j’ai voulu suivre les appel système que
faisait un process :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# strace isakmpd -vd&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ksh: strace: not found&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;# pkg_add strace&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Can&amp;#39;t find strace&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;OMG, comment faire ?!&lt;/p&gt;
&lt;p&gt;En fait, &lt;code&gt;strace&lt;/code&gt; est spécifique à Linux, et un équivalent existe sur les
systèmes BSD. Il s’agit du couple &lt;code&gt;ktrace&lt;/code&gt;/&lt;code&gt;kdump&lt;/code&gt;. En gros, &lt;code&gt;ktrace&lt;/code&gt; permet de
contrôler l’enregistrement ou non des appels que fait un process, et kdump
permet de lire le fichier binaire que son cousin a généré (nommé &lt;em&gt;ktrace.out&lt;/em&gt;
par défaut).&lt;/p&gt;
&lt;p&gt;Petit exemple d’utilisation :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ktrace &amp;lt;PID&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Équivalent de l’option &lt;code&gt;-f&lt;/code&gt; de &lt;code&gt;strace&lt;/code&gt; (pour tracer également les processus
fils) :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ktrace -id &amp;lt;PID d&amp;#39;une processe qui fait plein de petits&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Équivalent de l’option &lt;code&gt;-p&lt;/code&gt; de &lt;code&gt;strace&lt;/code&gt; (pour tracer un process existant, sans
devoir le relancer). Bon là ça ne change pas trop :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ktrace -p &amp;lt;PID d&amp;#39;un process applicatif super critique, lancé depuis une éternité, que plus personne ne sait comment le relancer et que si il crash c&amp;#39;est la fin du monde&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Quand vous avez récupéré suffisamment de traces à lire (ou quand vous vous
apercevez que votre ktrace.out a pris 100 % de l’espace libre restant sur la
partition), pour arrêter l’enregistrement :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ktrace -C&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Maintenant que vous avez votre bon gros fichier binaire avec plein de traces dedans :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;kdump |less&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Si l’enregistrement des traces est toujours en cours, vous pouvez avoir l’équivalent d’un &lt;code&gt;tail -f&lt;/code&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;kdump -l&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Pour plus de détail, voir bien sûr les man de &lt;code&gt;ktrace (1)&lt;/code&gt; et &lt;code&gt;kdump (1)&lt;/code&gt;.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Passer root sans terminal</title>
        <published>2012-01-26T00:00:00+00:00</published>
        <updated>2012-01-26T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/passer-root-sans-terminal/"/>
        <id>https://univers-libre.net/posts/passer-root-sans-terminal/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/passer-root-sans-terminal/">&lt;p&gt;Dans certains rares cas, on peut vouloir exécuter des commandes en tant que
root sans avoir la possibilité d’allouer un terminal sur la machine en
question.&lt;/p&gt;
&lt;p&gt;Pour ceux qui aiment bien lire la fin en premier, je mets la fin au début :-) :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;quot;mypassword&amp;quot; |sudo -S id&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Pour illustrer le problème, prenons un cas concret qui m’est arrivé.&lt;br /&gt;
Un serveur s’est soudainement mis dans un état bizarre, à savoir que tout
marchait, les processus déjà en cours continuaient de s’exécuter, d’autres
processus pouvaient se créer, mais certaines choses ne marchaient pas,
notamment l’allocation de pseudo-terminaux (les &lt;strong&gt;/dev/pts/*&lt;/strong&gt;) ; si je tente
une connexion SSH au serveur, le serveur répond bien, l’authentification se
fait, et au moment d’avoir mon prompt, la connexion se freeze.&lt;br /&gt;
Après divers tests, je m’aperçois qu’en passant directement une commande à ssh,
ça marche :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ssh serveur-foireux dmesg&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;La différence vient du fait que dans le deuxième cas, ssh n’ouvre pas de
pseudo-terminal sur le serveur distant, puisqu’il se contente de récupérer
directement stderr et stdout.&lt;br /&gt;
On peut faire en sorte de se connecter sans allouer de terminal sur le serveur
avec l’option &lt;em&gt;-T&lt;/em&gt; de la commande ssh :&lt;/p&gt;
&lt;blockquote&gt;
&lt;p&gt;     -T      Disable pseudo-tty allocation.&lt;/p&gt;
&lt;/blockquote&gt;
&lt;p&gt;On a ainsi un shell qui s’exécute sur la machine, et on récupère la sortie
brute de stderr et stdout (pas de prompt, d’édition de la commande en cours,
etc…). Pareil pour stdin, ce qui fait que les commandes &lt;code&gt;sudo&lt;/code&gt; ou &lt;code&gt;su&lt;/code&gt;
retournent une erreur, étant donné qu’elles font une manipulation spécifique
sur stdin (pas d’echo pour la saisie du mot de passe). De ce fait, on est un
peu coincé pour passer root.&lt;/p&gt;
&lt;p&gt;Il existe une solution (que j’ai bien sûr trouvé après avoir brutalement
redémarrer le serveur), une simple option à sudo qui permet de lire le mot de
passe depuis stdin. Et là, pas besoin d’exécuter la commande dans un terminal
donc !&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo &amp;quot;mypassword&amp;quot; |sudo -S id&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[sudo] password for rdessort: uid=0(root) gid=0(root) groupes=0(root)&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Et comme cela affiche votre mot de passe en clair sur l’écran, voici un petit
script pour améliorer la chose :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#!/bin/bash&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo -n &amp;quot;Enter password: &amp;quot;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;read -s passwd&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ssh serveur-foireux &amp;quot;echo $passwd |sudo -S id&amp;quot;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Une autre application probablement beaucoup plus courante pourrait être de
pouvoir scripter des commandes nécessitant d’être root sur le serveur.
Notamment exécuter la même commande sur plusieurs dizaines de serveurs
d’affilée.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Utiliser AWStats sans CGI</title>
        <published>2011-01-09T00:00:00+00:00</published>
        <updated>2011-01-09T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/awstats-sans-cgi/"/>
        <id>https://univers-libre.net/posts/awstats-sans-cgi/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/awstats-sans-cgi/">&lt;p&gt;AWStats est un générateur de statistiques, le plus souvent utilisé pour générer
des stats sur des serveurs web (il peut aussi être utilisé pour des serveurs
mail, ftp…). C’est une appli en Perl, qui peut donc être appelé par le serveur
web via CGI pour générer les pages HTML.&lt;/p&gt;
&lt;p&gt;Sur Apache ou Lighttpd ça marche sans problème, mais sur un serveur web qui
ne supporte pas CGI (NginX par exemple, à moins de passer par des hacks assez
tordus) ça ne marche plus.&lt;/p&gt;
&lt;p&gt;La solution est donc de dire à AWStats de générer les page HTML
automatiquement après chaque mise à jour de sa base de données. Voici la
procédure :&lt;/p&gt;
&lt;ul&gt;
&lt;li&gt;
&lt;p&gt;Créez tout d’abord le répertoire qui contiendra les pages HTML, avec les
bons droits :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;mkdir /var/www/awstats/&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;chown www-data:www-data /var/www/awstats/&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;Modifiez ensuite le fichier &lt;em&gt;/etc/cron.d/awstats&lt;/em&gt; pour appelez le script
&lt;em&gt;awstats_buildstaticpages.pl&lt;/em&gt; au lieu de &lt;em&gt;awstats.pl&lt;/em&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;[ -x /usr/share/doc/awstats/examples/awstats_buildstaticpages.pl \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-a -f /etc/awstats/awstats.yoursite.conf -a -r /var/log/nginx/yoursite.access.log ] \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;&amp;amp;&amp;amp; perl /usr/share/doc/awstats/examples/awstats_buildstaticpages.pl -update \&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;-config=yoursite -dir=/var/www/awstats -awstatsprog=/usr/lib/cgi-bin/awstats.pl &amp;gt;/dev/null&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;À adapter bien sûr avec les bons noms de fichiers de conf et de log.&lt;/p&gt;
&lt;/li&gt;
&lt;li&gt;
&lt;p&gt;N’oubliez pas d’ajouter un alias dans la conf de votre serveur web pour les
icônes. Sous NginX, ça donne ça :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  location /awstats-icon/ {&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      alias /usr/share/awstats/icon/;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  }&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;&lt;/li&gt;
&lt;/ul&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Utiliser la fonction PHP imagerotate() sous Debian</title>
        <published>2010-09-18T00:00:00+00:00</published>
        <updated>2010-09-18T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/php-imagerotate-debian/"/>
        <id>https://univers-libre.net/posts/php-imagerotate-debian/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/php-imagerotate-debian/">&lt;p&gt;imagerotate est une fonction PHP qui, comme son nom l’indique, permet de
tourner une image selon un angle. Cependant elle n’est disponible que si PHP a
été compilé avec la version embarqué de la bibliothèque GD.&lt;/p&gt;
&lt;p&gt;Sous Debian ce n’est pas le cas, car cette version est difficilement
maintenable au niveau sécurité (cf le &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=321237&quot;&gt;bug report
Debian&lt;/a&gt;)&lt;/p&gt;
&lt;p&gt;Pour contourner le problème, en cherchant un peu sur le net (&lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://web.archive.org/web/20140125012344/http://www.mattiouz.com/blog/2010/01/28/recompiling-php5-to-get-imagerotate-and-other-functions-on-debian&quot;&gt;ici par
exemple&lt;/a&gt;),
beaucoup de monde recompile PHP avec la version embarqué de GD. Ce n’est à mon
avis pas la meilleure solution au niveau “maintenabilité”.&lt;/p&gt;
&lt;p&gt;Voici donc 2 autres possibilités.&lt;/p&gt;
&lt;h2 id=&quot;utiliser-les-depots-dotdeb&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#utiliser-les-depots-dotdeb&quot; aria-label=&quot;Anchor link for: utiliser-les-depots-dotdeb&quot;&gt;Utiliser les dépôts dotdeb&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Les &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://www.dotdeb.org/&quot;&gt;dépôts dotdeb&lt;/a&gt; contiennent des versions plus
récentes et/ou modifiés de paquets Debian pour serveurs LAMP. Le paquet php5
présent dans dotdeb est justement compilé avec la version embarqué de la
bibliothèque.&lt;/p&gt;
&lt;h2 id=&quot;reecrire-la-fonction-imagerotate&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#reecrire-la-fonction-imagerotate&quot; aria-label=&quot;Anchor link for: reecrire-la-fonction-imagerotate&quot;&gt;Réécrire la fonction imagerotate()&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Si vous n’avez besoin que de cette fonction et que vous n’avez pas envi
d’utiliser la version embarqué de GD, il est tout à fait envisageable de
réécrire la fonction en question :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;readImage($temp_src);&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      $imagick-&amp;gt;rotateImage(new ImagickPixel($bgd_color?$bgd_color:&amp;#39;black&amp;#39;), $angle);&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      $imagick-&amp;gt;writeImage($temp_dst);&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      //trigger_error( &amp;#39;imagerotate(): could not write to &amp;#39; . $file1 . &amp;#39;, original image returned&amp;#39;, E_USER_WARNING );&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      $result = imagecreatefromjpeg($temp_dst);&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      unlink($temp_dst);&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      unlink($temp_src);&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;      return $result;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;  }&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;?&amp;gt;&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>trier numériquement la sortie d’un du -h</title>
        <published>2010-09-11T00:00:00+00:00</published>
        <updated>2010-09-11T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/trier-sortie-du-h/"/>
        <id>https://univers-libre.net/posts/trier-sortie-du-h/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/trier-sortie-du-h/">&lt;p&gt;Afficher la taille que prend un répertoire ainsi que ses sous répertoires est
une tache assez courante, du moins pour un administrateur système. Cela se
fait simplement avec la commande :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;du -sh foo/*&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Ou bien, si on veut avoir aussi les sous sous répertoires :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;du -h --max-depth 2 foo/*&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;L’option -h permettant d’avoir la taille exprimé en kilo, méga, giga, etc…&lt;/p&gt;
&lt;p&gt;Là où les choses se compliquent, c’est lorsqu’on veut trier numériquement le
résultat par ordre décroissant. Si on fait un :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;du -sh foo/* |sort -rn&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;le tri sera faussé du fait de la présence des lettres qui suivent la taille.&lt;/p&gt;
&lt;p&gt;&lt;em&gt;D’où l’astuce du jour : comment trier numériquement la sortie d’un du tout
en ayant la taille exprimé en “human readable” ?&lt;/em&gt;&lt;/p&gt;
&lt;p&gt;Si vous avez le paquet coreutils en version ≥ 7.5, vous êtes sauvé, sort
implémente l’option -h qui répond exactement au problème :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;du -sh foo/* |sort -rh&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Dans le cas contraire (si vous êtes sur une Debian Lenny par exemple), c’est
un peu moins simple.&lt;br /&gt;
En cherchant un peu sur le net, il existe un tas d’astuces différentes
utilisant perl ou awk. Voici celle que j’utilise, qui me semble la moins tordue
(mais un peu quand même) :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;du -s foo/* |sort -rn |cut -f2 |xargs -d &amp;#39;\n&amp;#39; du -sh&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Le principe est d’obtenir d’abord la liste des répertoires avec leur taille
“brute”, de trier cette liste, puis de refaire un du (avec -h cette fois) sur
chaque répertoire de la liste).&lt;br /&gt;
Le fait d’exécuter 2 fois un du n’est pas super élégant point de
performance, mais en pratique, comme le résultat du premier du est caché en
mémoire, le second est très rapide.&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Hard reboot à distance</title>
        <published>2010-08-09T00:00:00+00:00</published>
        <updated>2010-08-09T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/hard-reboot-distant/"/>
        <id>https://univers-libre.net/posts/hard-reboot-distant/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/hard-reboot-distant/">&lt;p&gt;Voici une astuce bien utile si votre serveur est complètement planté.
Il faut néanmoins pouvoir se connecter en SSH sur la machine et avoir un shell
en root.&lt;/p&gt;
&lt;p&gt;Dans mon cas, il s’agissait d’un problème d’accès disque, la plupart des
commandes exécutées renvoyaient des erreurs d’entrée/sortie, y compris la
commande reboot, qui a besoin d’exécuter les scripts d’init de niveau 6.&lt;/p&gt;
&lt;p&gt;Mais tout n’est pas perdu, si vous n’avez pas d’accès physique à la machine !
On va passer par le pseudo système de fichier /proc pour parler directement au
noyau et lui dire de redémarrer la machine.
Avant tout (et si il ne s’agit pas d’un problème disque), on tente de forcer
la synchronisation du cache vers le disque :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;sync&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;On active ensuite les &lt;a class=&quot;external-link&quot; rel=&quot;external&quot; href=&quot;https://fr.wikipedia.org/wiki/Magic_SysRq_key&quot;&gt;magic sysrq
key&lt;/a&gt; si elles ne le sont pas
déjà :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo 1 &amp;gt; /proc/sys/kernel/sysrq&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Puis on modifie l’état de la machine :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;echo b &amp;gt; /proc/sysrq-trigger&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Cette dernière action a exactement le même effet que la combinaison &lt;code&gt;Alt + Syst + b&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Après cela, priez pour que la machine redémarre correctement :-).&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Compter le nombre de connections par IP</title>
        <published>2010-06-18T00:00:00+00:00</published>
        <updated>2010-06-18T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/compter-connexions-par-ip/"/>
        <id>https://univers-libre.net/posts/compter-connexions-par-ip/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/compter-connexions-par-ip/">&lt;p&gt;Aujourd’hui au boulot, j’ai été confronté à un petit problème : sur un serveur
victime d’une attaque DDoS (visiblement), je voulais savoir quelles IP
ouvraient le plus de connections. Ne trouvant rien de bien intéressant dans les
commandes Unix, j’ai écris un petit script en Perl.&lt;/p&gt;
&lt;p&gt;Il se charge de récupérer la sortie de netstat (la commande est à adapter à
votre besoin) et compte le nombre de lignes identiques (donc d’IP), qu’il se
charge ensuite de trier par ordre décroissant et d’afficher.&lt;/p&gt;
&lt;p&gt;Voici le script en question :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;#!/usr/bin/perl&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;use strict;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;use warnings;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;my %addrs = ();&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;my @netstatOut = split( /\n/, `netstat -taupen | grep SYN | tr -s &amp;quot; &amp;quot; | cut -d&amp;quot; &amp;quot; -f 5 | cut -d: -f1` );&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;for (@netstatOut) {&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    chomp $_;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    $addrs{$_} += 1;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;for my $key ( sort {$addrs{$b} &amp;lt;=&amp;gt; $addrs{$a}} keys %addrs ) {&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;    print $addrs{$key}.&amp;quot;\t$key\n&amp;quot;;&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;}&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Le script retourne alors son résultat sous la forme :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;nbConnection    IP1&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;nbConnection    IP2&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;...&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Il ne vous reste plus qu’à blacklister les IP les plus actives avec la commande&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;iptables -I INPUT -s IP -j DROP&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Connexion ssh derrière un proxy</title>
        <published>2009-11-17T00:00:00+00:00</published>
        <updated>2009-11-17T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/corkscrew/"/>
        <id>https://univers-libre.net/posts/corkscrew/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/corkscrew/">&lt;p&gt;Peut-être avez vous déjà rencontré ce problème, il n’est pas possible de se
connecter en SSH sur un serveur lorsqu’on se trouve derrière un proxy.&lt;/p&gt;
&lt;p&gt;Je m’en suis aperçu quelques jours après le début des cours à l’IUT de Nancy
lorsque j’ai voulu créer un tunnel SSH (on verra comment par la suite) pour
pouvoir accéder à mes mails, les messageries instantanées, etc… Le réseau de
l’université se trouve en effet derrière un proxy qui bloque tout et n’importe
quoi (en fait seul les ports http et https sont autorisés).&lt;br /&gt;
&lt;em&gt;Souvenir du réseau wifi de l’IUT de Marseille où on pouvait télécharger en P2P
les &lt;del&gt;films&lt;/del&gt; ISO Linux en quelques minutes… :(&lt;/em&gt;.&lt;/p&gt;
&lt;p&gt;Pour résoudre le problème (du ssh, pas du P2P), il y a deux choses à faire.&lt;/p&gt;
&lt;h2 id=&quot;cote-serveur&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#cote-serveur&quot; aria-label=&quot;Anchor link for: cote-serveur&quot;&gt;Coté serveur&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;Bien entendu, comme le proxy bloque tout sauf http et https, il n’y a pas de
miracles, il faut faire écouter le serveur SSH sur le port https (les transfert
sont chiffrés pour https et SSH, le proxy ne peut pas voir la différence). Pour
ça, modifiez votre &lt;em&gt;/etc/ssh/sshd_config&lt;/em&gt; pour changer la valeur de &lt;em&gt;Port&lt;/em&gt; :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Port 443&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Redémarrez OpenSSH et assurez vous de changer les ports également dans votre
pare feu et votre routeur.&lt;/p&gt;
&lt;h2 id=&quot;cote-client&quot;&gt;&lt;a class=&quot;zola-anchor&quot; href=&quot;#cote-client&quot; aria-label=&quot;Anchor link for: cote-client&quot;&gt;Coté client&lt;/a&gt;&lt;/h2&gt;
&lt;p&gt;À priori, on peut croire que le problème est maintenant résolu, le serveur
écoute sur le port https, le proxy laisse passer les données sur le port https,
et le client indique de ce connecter par le port https. Et bien non, ce n’est
pas aussi simple, et je n’ai eu la réponse qu’aujourd’hui, pendant un cours sur
les serveurs web.&lt;/p&gt;
&lt;p&gt;En fait, le fait de passer par un proxy interdit de faire une connection direct
entre le client et le serveur (un proxy étant fait pour s’intercaler entre les
échanges). Il faut donc dire explicitement au proxy d’établir une connection
direct entre les deux machines, et de ne plus s’en mêler ensuite. C’est grâce à
la commande HTTP CONNECT que c’est possible (vous voyez mieux le rapport avec
les serveurs web à présent ;) ).&lt;/p&gt;
&lt;p&gt;Pour réaliser ça en pratique, on va utiliser corkscrew. Installez le puis
modifiez votre fichier client &lt;em&gt;/etc/ssh/ssh_config&lt;/em&gt; comme ceci :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Host univers-libre.net-proxy&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Hostname univers-libre.net&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Port 443&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        ProxyCommand /usr/bin/corkscrew vivianen.iuta.univ-nancy2.fr 3128 %h %p&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;Host univers-libre.net&lt;/span&gt;&lt;/span&gt;
&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;        Port 443&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Explications :&lt;br /&gt;
on a définit 2 configurations (host, dans le fichier) : une dans le cas normal
(univers-libre.net) et une autre avec un proxy (univers-libre.net-proxy).&lt;br /&gt;
Ainsi, si vous êtes derrière le proxy, vous devrez taper :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ssh univers-libre.net-proxy&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Dans le cas contraire :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;ssh univers-libre.net&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Dans la configuration avec proxy, on indique que, en fait le vrai nom n’est pas
univers-libre.net-proxy mais univers-libre.net (avec la directive hostname). Le
port est bien sûr fixé à 443 (https) dans les 2 cas.&lt;br /&gt;
Viens la ligne ProxyCommand : on dit à OpenSSH de faire appel à corkscrew en
lui passant en paramètre l’adresse du proxy (ici vivianen.iuta.univ-nancy2.fr),
le port du proxy (3128 qui est le port par défaut des proxies). %h et %p
indiquent respectivement l’hôte à atteindre et son port (univers-libre.net et
443).&lt;/p&gt;
&lt;p&gt;Maintenant que vous avez un accès SSH sur votre serveur à vous la liberté :) .
Vous pouvez alors créer un tunnel SSH pour certaines applications, en rajoutant
une ligne de ce type dans le fichier &lt;em&gt;/etc/ssh/ssh_config&lt;/em&gt; de votre client :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;LocalForward 143 localhost:143&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Dans cet exemple je dis de rediriger toutes les demandes de connections qui
sont envoyées sur le port 143 (imap), vers le même port et sur le même serveur
que le serveur SSH (localhost). Ainsi mon client mail pourra accéder à mon
serveur imap, le tout de façon transparente, mais crypté dans le tunnel :-).&lt;/p&gt;
</content>
        
    </entry>
    <entry xml:lang="en">
        <title>Passer une partition de ext2 à ext3 sans la reformater</title>
        <published>2009-01-19T00:00:00+00:00</published>
        <updated>2009-01-19T00:00:00+00:00</updated>
        
        <author>
          <name>Romain</name>
        </author>
        
        <link rel="alternate" type="text/html" href="https://univers-libre.net/posts/conversion-ext2-ext3/"/>
        <id>https://univers-libre.net/posts/conversion-ext2-ext3/</id>
        
        <content type="html" xml:base="https://univers-libre.net/posts/conversion-ext2-ext3/">&lt;p&gt;Même si plus beaucoup de monde utilise encore le système de fichier ext2, il
se peut qu’il vous reste de vielles partitions ext2 qui traine dans un coin de
votre disque dur.&lt;/p&gt;
&lt;p&gt;Si c’est votre cas, et que vous avez toujours eu la flemme de sauvegarder les
données de la partition, la formater, puis restaurer les données, voici la
commande magique, à appliquer tel quel, sans sauvegarde des données :&lt;/p&gt;
&lt;pre class=&quot;giallo z-code&quot; &gt;&lt;code data-lang=&quot;plain&quot;&gt;&lt;span class=&quot;giallo-l&quot;&gt;&lt;span&gt;tune2fs -j votre_partition&lt;/span&gt;&lt;/span&gt;&lt;/code&gt;&lt;/pre&gt;
&lt;p&gt;Petite explication (et la commande semblera moins magique :-) ) :&lt;br /&gt;
Il faut savoir que la différence entre ext2 et ext3 vient uniquement du fait
que ext3 est journalisé, c’est à dire (en gros) que toutes les écritures
réalisées sur le disque (appelées transactions) sont inscrites (journalisées)
dans un journal stocké sur la partition. Cela permet, si un crash du disque
survient (coupure de courant, freeze, …), de garder une cohérence dans les
données écrites sur le disque (en analysant uniquement le journal, pas besoin
d’aller scanner tout le disque).&lt;br /&gt;
Pour revenir à notre commande, celle ci ne fait que créer ce fameux journal
sur la partition, rien de plus. Au prochain montage de la partition, celle ci
sera monté en tant qu’ext3.&lt;/p&gt;
</content>
        
    </entry>
</feed>
