今天登入librenms時出現以下的訊息
看起是因為自動更新導致某些depcndy出了問題
先跑一下
/opt/librenms/validate.php
出現以下問題
再來就依照提示跑一下
/opt/librenms/scripts/composer_wrapper.php install --no-dev
跑完後在文字介面再執行一次/opt/librenms/validate.php
已經沒有錯誤了
可是web介面再登入
還是會出現第一張圖的錯誤訊息
此時執行網頁介面右上的齒輪裡的validate config
出現以下的錯誤訊息
可是看了一下權限並沒有問題
google了一下
https://community.librenms.org/t/validate-config-page-report-wrong-issue/4085/3
把檔案砍了
目前看來是正常
2018/07/19
2018/07/02
2018/06/11
graylog預設會捉取log的第一個欄位來當成source
最近碰到 Cisco的ASA 吐出來log的第一個欄位是月分的英文
導致每個月都會換一次source
如下
May 09 2018 15:00:40 context-admin : %ASA-4-106023: Deny tcp src inside:172.16.213.212/52854 dst outside:192.168.213.203/445 by access-group "inside_access_in" [0x0, 0x0]
May 09 2018 15:00:40 context-admin : %ASA-4-106023: Deny tcp src inside:172.16.213.212/52855 dst outside:192.168.213.203/445 by access-group "inside_access_in" [0x0, 0x0]
查到二個解決方法
一個是讓ASA吐出來的log不要帶timestamp 不過因為是別廠商維護的
他們也不太想改
再來就是加個extractor
直接更換source這個欄位
最近碰到 Cisco的ASA 吐出來log的第一個欄位是月分的英文
導致每個月都會換一次source
如下
May 09 2018 15:00:40 context-admin : %ASA-4-106023: Deny tcp src inside:172.16.213.212/52854 dst outside:192.168.213.203/445 by access-group "inside_access_in" [0x0, 0x0]
May 09 2018 15:00:40 context-admin : %ASA-4-106023: Deny tcp src inside:172.16.213.212/52855 dst outside:192.168.213.203/445 by access-group "inside_access_in" [0x0, 0x0]
查到二個解決方法
一個是讓ASA吐出來的log不要帶timestamp 不過因為是別廠商維護的
他們也不太想改
再來就是加個extractor
直接更換source這個欄位
2018/06/10
2018/06/01
2018/05/16
2018/05/15
本來在電腦上是安裝office 2016 但因為使用kms認証 每半年要重新執行認証程式 有點麻煩
後來就把office 2016移除改安裝office 365
但最近跳出授權到期的訊息
進到帳戶去看
才發現之前移除的office 2016竟然還在
找了半天
找到m$提供的工具
https://support.office.com/en-us/article/uninstall-office-from-a-pc-9dd49b83-264a-477a-8fcc-2fdf5dbf61d8
但看說明是執行後會移除所有office
又要重裝
XD
後來找到一個方法可以把原來的key砍了
https://gist.github.com/giordanocardillo/c3209cb215226d47322d98499c7a1df7
想說試看看
砍了之後再到帳戶去看就沒了
也不再跳訊息了
搞定
收工
後來就把office 2016移除改安裝office 365
但最近跳出授權到期的訊息
進到帳戶去看
才發現之前移除的office 2016竟然還在
找了半天
找到m$提供的工具
https://support.office.com/en-us/article/uninstall-office-from-a-pc-9dd49b83-264a-477a-8fcc-2fdf5dbf61d8
但看說明是執行後會移除所有office
又要重裝
XD
後來找到一個方法可以把原來的key砍了
https://gist.github.com/giordanocardillo/c3209cb215226d47322d98499c7a1df7
想說試看看
砍了之後再到帳戶去看就沒了
也不再跳訊息了
搞定
收工
2018/05/09
vsftpd預設是沒有把登入記錄寫到一個檔案
在centos只能在 /var/log/audit/audit.log找到如下資訊
May 9 10:43:36 hostname vsftpd[15873]: [user] OK LOGIN: Client "::ffff:192.168.1.2"
type=SERVICE_STOP msg=audit(1525834233.143:7923): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=vsftpd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
可以在 /etc/vsftpd/vsftpd.conf 加上
syslog_enable=YES
重啟vsftpd後
就可以在 /var/log/messages看到登入的相關資料
May 9 10:43:33 hostname vsftpd[15874]: CONNECT: Client "::ffff:192.168.1.2"
May 9 10:43:36 hostname vsftpd[15873]: [user] OK LOGIN: Client "::ffff:192.168.1.2"
在centos只能在 /var/log/audit/audit.log找到如下資訊
May 9 10:43:36 hostname vsftpd[15873]: [user] OK LOGIN: Client "::ffff:192.168.1.2"
type=SERVICE_STOP msg=audit(1525834233.143:7923): pid=1 uid=0 auid=4294967295 ses=4294967295 msg='unit=vsftpd comm="systemd" exe="/usr/lib/systemd/systemd" hostname=? addr=? terminal=? res=success'
可以在 /etc/vsftpd/vsftpd.conf 加上
syslog_enable=YES
重啟vsftpd後
就可以在 /var/log/messages看到登入的相關資料
May 9 10:43:33 hostname vsftpd[15874]: CONNECT: Client "::ffff:192.168.1.2"
May 9 10:43:36 hostname vsftpd[15873]: [user] OK LOGIN: Client "::ffff:192.168.1.2"
今天有個新需求
要把apache 的log丟到graylog
找到很多文件
以下的方式算是最簡單的做法
apache跑在centos 上
把以下的內容加到 /etc/rsyslog.conf 或在/etc/rsyslog.d/裡加上一個新的檔案 如 apachelog.conf
$ModLoad imfile
# apache error.log
$InputFileName /var/log/httpd/error_log
$InputFileTag apache-errors:
$InputFileStateFile state_file_error_apache
$InputFileFacility local6
$InputFileSeverity info
$InputRunFileMonitor
$InputFilePollInterval 10
# apache access.log
$InputFileName /var/log/httpd/access_log
$InputFileTag apache-access:
$InputFileStateFile state_file_access_apache
$InputFileFacility local6
$InputFileSeverity info
$InputRunFileMonitor
$InputFilePollInterval 10
if $programname == 'apache-access' then @1.2.3.4:514
& stop
if $programname == 'apache-errors' then @1.2.3.4:514
& stop
依需求修改 log檔的路徑
外部 log server 的ip及port
改完後rsyslogd要重啟
要把apache 的log丟到graylog
找到很多文件
以下的方式算是最簡單的做法
apache跑在centos 上
把以下的內容加到 /etc/rsyslog.conf 或在/etc/rsyslog.d/裡加上一個新的檔案 如 apachelog.conf
$ModLoad imfile
# apache error.log
$InputFileName /var/log/httpd/error_log
$InputFileTag apache-errors:
$InputFileStateFile state_file_error_apache
$InputFileFacility local6
$InputFileSeverity info
$InputRunFileMonitor
$InputFilePollInterval 10
# apache access.log
$InputFileName /var/log/httpd/access_log
$InputFileTag apache-access:
$InputFileStateFile state_file_access_apache
$InputFileFacility local6
$InputFileSeverity info
$InputRunFileMonitor
$InputFilePollInterval 10
if $programname == 'apache-access' then @1.2.3.4:514
& stop
if $programname == 'apache-errors' then @1.2.3.4:514
& stop
依需求修改 log檔的路徑
外部 log server 的ip及port
改完後rsyslogd要重啟
2018/04/27
rules.emergingthreats.net 這個網站每天會整理有問題的ip
參考的是
Spam nets identified by Spamhaus (www.spamhaus.org)
Top Attackers listed by DShield (www.dshield.org)
Abuse.ch
還有suspicious doamin
https://secure.dshield.org/suspicious_domains.html
https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
看來還不錯用
參考的是
Spam nets identified by Spamhaus (www.spamhaus.org)
Top Attackers listed by DShield (www.dshield.org)
Abuse.ch
還有suspicious doamin
https://secure.dshield.org/suspicious_domains.html
https://rules.emergingthreats.net/fwrules/emerging-Block-IPs.txt
看來還不錯用
2018/04/21
今天找到honeyports
程式碼是2013年的 用python寫
拿來當陷阱看來還不錯用
拿這個檔來修改
honeyports-0.4.py
預設執行時若偵測到try port的ip
會下iptables 並在畫面上出現訊息問管理者是要列出還是清掉加上的iptables
改一下程式
首先把出現訊息的地方mark掉
再來把加iptables的地方改成寫到log去
另外還有一個就是原作者在連線的回應訊息寫的是
nasty_msg = "\n\n***** Fuck You For Connecting *****\n\n"
這就看個人要不要改了
程式中的這些行因為是直接產生訊息在畫面上
Got connection from
Blocking the address:
Creating a Linux Firewall Rule
I just blocked:
如果不拿掉 在背景執行會有問題
不想拿也可以 就用screen來跑
改完後執行
sudo python honeyports-0.4.py -p 21
-p是監聽的port
可以多執行几次起在不同的port
大於1024可以不需要使用sudo
目前想到的是
21
22
23
137
138
139
445
1433
3389
3306
5800
5900
網卡多bind几個ip
然後.......就可以在log檔拿到這些ip了
接下來要作什麼
自己想
https://github.com/adhdproject/adhdproject.github.io/blob/master/Tools/HoneyPorts.md
https://github.com/ethack/honeyports
程式碼是2013年的 用python寫
拿來當陷阱看來還不錯用
拿這個檔來修改
honeyports-0.4.py
預設執行時若偵測到try port的ip
會下iptables 並在畫面上出現訊息問管理者是要列出還是清掉加上的iptables
改一下程式
首先把出現訊息的地方mark掉
再來把加iptables的地方改成寫到log去
另外還有一個就是原作者在連線的回應訊息寫的是
nasty_msg = "\n\n***** Fuck You For Connecting *****\n\n"
這就看個人要不要改了
程式中的這些行因為是直接產生訊息在畫面上
Got connection from
Blocking the address:
Creating a Linux Firewall Rule
I just blocked:
如果不拿掉 在背景執行會有問題
不想拿也可以 就用screen來跑
改完後執行
sudo python honeyports-0.4.py -p 21
-p是監聽的port
可以多執行几次起在不同的port
大於1024可以不需要使用sudo
目前想到的是
21
22
23
137
138
139
445
1433
3389
3306
5800
5900
網卡多bind几個ip
然後.......就可以在log檔拿到這些ip了
接下來要作什麼
自己想
https://github.com/adhdproject/adhdproject.github.io/blob/master/Tools/HoneyPorts.md
https://github.com/ethack/honeyports
2018/04/12
2018/03/29
graylog如果要export大量資料時 百萬筆以上
不建議直接在web管理介面上Export as CSV
因為會花很多時間而且有可能導致管理介面當掉
建議使用rest
進到API browser後找到search keyword export
在網頁上輸入 搜尋關鍵字 時間 欄位及限制輸出筆數
確認輸出沒問題
就可以複制語法
把limit刪除後 使用curl來export
語法範例如下
curl -u user:passwd 'http://1.2.3.4:9000/api/search/universal/keyword/export?query=source%3A10.0.0.2%20&keyword=last%201%20day&fields=message' > log.csv
不建議直接在web管理介面上Export as CSV
因為會花很多時間而且有可能導致管理介面當掉
建議使用rest
進到API browser後找到search keyword export
在網頁上輸入 搜尋關鍵字 時間 欄位及限制輸出筆數
確認輸出沒問題
就可以複制語法
把limit刪除後 使用curl來export
語法範例如下
curl -u user:passwd 'http://1.2.3.4:9000/api/search/universal/keyword/export?query=source%3A10.0.0.2%20&keyword=last%201%20day&fields=message' > log.csv
2018/03/22
graylog偶爾還是會發生buffer滿載的情況
想說來監控一下
目前觀察到當 process buffer 和 output buffer都滿就會往回塞到disk journal 因此就直接monitor disk jounrnal
第一步就是要把graylog目前的相關資料取出來
但因為graylog只提供jason的格式 並不方便操作
所以再使用 jq 轉換 以利值的讀取
指令如下 直接取出值
curl -u user:passwd 'http://1.2.3.4:9000/api/system/metrics'|jq . |grep -A 1 journal.entries-uncommitted |grep value |awk '{print $2}'
再利用以上的值來比對設定的基準 高於就發alarm
https://stedolan.github.io/jq/
想說來監控一下
目前觀察到當 process buffer 和 output buffer都滿就會往回塞到disk journal 因此就直接monitor disk jounrnal
第一步就是要把graylog目前的相關資料取出來
但因為graylog只提供jason的格式 並不方便操作
所以再使用 jq 轉換 以利值的讀取
指令如下 直接取出值
curl -u user:passwd 'http://1.2.3.4:9000/api/system/metrics'|jq . |grep -A 1 journal.entries-uncommitted |grep value |awk '{print $2}'
再利用以上的值來比對設定的基準 高於就發alarm
https://stedolan.github.io/jq/
2018/03/09
今天測了一下obs及nginx nginx-rtmp-module
obs是一個相當方便的跨平台錄影及產生live streaming的軟体
但是並沒有stream server的功能
一般都是把產生的stream丟到 youtube 或其他的stream server上
但如果是在內部使用 就必須自行架設stream server
網路上找到的資料大多是 obs + nginx + nginx-rtmp-module
記錄一下安裝及測試的流程
先安裝nginx
這次使用的是 linux mint ldme2
再來
sudo apt-get install build-essential libpcre3 libpcre3-dev libssl-dev
wget http://nginx.org/download/nginx-1.13.1.tar.gz
wget https://github.com/arut/nginx-rtmp-module/archive/master.zip
解開後編譯安裝
./configure --with-http_ssl_module --add-module=../nginx-rtmp-module-master
$ make
$ sudo make install
啟動 nginx 看看有沒問題
$ sudo /usr/local/nginx/sbin/nginx
修改config 以支援 rtmp
在 /usr/local/nginx/conf/nginx.conf 下方加上以下程式碼
rtmp {
server {
listen 8080;
chunk_size 4096;
application live {
live on;
record off;
}
}
}
在來源選擇顯示器擷取
建立新來源

再來設定把 stream 丟到之前設好的server
假設 server ip 192.168.12.74 port 要與config 設定的相同 金鑰設定為 test
設好後就可以開始串流
如果出現以下畫面且無錯誤訊息 就表示成功串流出去了
用VLC進行觀看
vlc rtmp://192.168.12.74:8080/live/test
如果來源有多個可以同時設定 同時擷取
https://obsproject.com/
https://obsproject.com/forum/resources/how-to-set-up-your-own-private-rtmp-server-using-nginx.50/
obs是一個相當方便的跨平台錄影及產生live streaming的軟体
但是並沒有stream server的功能
一般都是把產生的stream丟到 youtube 或其他的stream server上
但如果是在內部使用 就必須自行架設stream server
網路上找到的資料大多是 obs + nginx + nginx-rtmp-module
記錄一下安裝及測試的流程
先安裝nginx
這次使用的是 linux mint ldme2
再來
sudo apt-get install build-essential libpcre3 libpcre3-dev libssl-dev
wget http://nginx.org/download/nginx-1.13.1.tar.gz
wget https://github.com/arut/nginx-rtmp-module/archive/master.zip
解開後編譯安裝
./configure --with-http_ssl_module --add-module=../nginx-rtmp-module-master
$ make
$ sudo make install
啟動 nginx 看看有沒問題
$ sudo /usr/local/nginx/sbin/nginx
修改config 以支援 rtmp
在 /usr/local/nginx/conf/nginx.conf 下方加上以下程式碼
rtmp {
server {
listen 8080;
chunk_size 4096;
application live {
live on;
record off;
}
}
}
重啟 nginx
$ sudo /usr/local/nginx/sbin/nginx -s stop
$ sudo /usr/local/nginx/sbin/nginx
接下來在windows 裝好obs後
以串流桌面為例(含音訊)
在來源選擇顯示器擷取
建立新來源
再來設定把 stream 丟到之前設好的server
假設 server ip 192.168.12.74 port 要與config 設定的相同 金鑰設定為 test
設好後就可以開始串流
如果出現以下畫面且無錯誤訊息 就表示成功串流出去了
用VLC進行觀看
vlc rtmp://192.168.12.74:8080/live/test
如果來源有多個可以同時設定 同時擷取
https://obsproject.com/
https://obsproject.com/forum/resources/how-to-set-up-your-own-private-rtmp-server-using-nginx.50/
2018/03/06
2018/02/22
今天ubuntu 升級後畫面就一直停在背景
左方完全沒有圖示
本來以為是升kernel的關係
降為舊版本還是一樣
找了一下
unity不見了
XD
補回去
sudo apt install unity
重開後就ok
https://ifun01.com/JC7MFH2.html
左方完全沒有圖示
本來以為是升kernel的關係
降為舊版本還是一樣
找了一下
unity不見了
XD
補回去
sudo apt install unity
重開後就ok
https://ifun01.com/JC7MFH2.html
2018/02/17
之前要發mail都使用二種方法
1. 直接在需要寄信的主機上起一個mail server 來寄
2. 使用python
import smtplib,sys
sender = "test_from_hinet@hinet.net"
receipt = "abc@de.com
smtp = smtplib.SMTP("168.95.4.10")
header = "Subject: test outside in mail from hinet\r\n\r\n"
msg = "test outside in mail from hinet"
smtp.sendmail(sender, receipt, header+msg)
smtp.quit()
今天才知道 mutt 也可以設定到別台mail server寄信
設定方法是安裝好mutt後在user的家目錄設定 ~/.muttrc
加上以下這行
set smtp_url = "smtp://mail.server.ip:25/"
1. 直接在需要寄信的主機上起一個mail server 來寄
2. 使用python
import smtplib,sys
sender = "test_from_hinet@hinet.net"
receipt = "abc@de.com
smtp = smtplib.SMTP("168.95.4.10")
header = "Subject: test outside in mail from hinet\r\n\r\n"
msg = "test outside in mail from hinet"
smtp.sendmail(sender, receipt, header+msg)
smtp.quit()
今天才知道 mutt 也可以設定到別台mail server寄信
設定方法是安裝好mutt後在user的家目錄設定 ~/.muttrc
加上以下這行
set smtp_url = "smtp://mail.server.ip:25/"
或在
/etc/Muttrc加上相同的內容
醬就可以了
mutt -s test abc@de.com -a test < test
訂閱:
文章 (Atom)









