venerdì 16 dicembre 2011

Configure DHCP server onto Ubuntu Server 11.04

Hi all,
today I will show you how to configure a DHCP server onto Ubuntu Server 11.04 already running.

first you should check that the server has a static ip address,

vi /etc/network/interfaces


in my case is something like this:

auto eth0
iface eth0 inet static
address 192.168.0.100
netmask 255.255.255.0
network 192.168.0.255
gateway 192.168.0.1

then check for the name servers:

vi /etc/resolv.conf


I have this:
nameserver 192.168.0.1


if you change yours files (interfaces and/or resolv.conf) , you need to type this:

/etc/init.d/networking restart


check also your hostname file:

vi /etc/hosts

should be something like this:

127.0.0.1          localhost.localdomain  localhost
192.168.0.100  server1.example.com server1

bcause in my case the server is called "server1"

DHCP installation and configuration


First download and install the dhcp service:

sudo apt-get install dhcp3-server


after the installation you will see a failed status, but it's ok, because we still need to configure the service.

vi /etc/dhcp/dhcpd.conf


Now we are going to change the file to configure our subnet,
in my case my server is 192.168.0.100 so my configuration will be something like this:

subnet 192.168.0.0 netmask 255.255.255.0 {
 range 192.168.0.10 192.168.0.50;
 option broadcast-address 192.168.0.255;
 option routers 192.168.0.1;
}

This way the service will release addresses in the range 192.168.0.10 -> 192.168.0.50

save the file and restart the dhcp service:

/etc/init.d/isc-dhcp-server start


Now the dhcp should be working fine.

There are a lot of other options that can be configured in the dhcpd.conf file, check the documentaiton for that

bye
Digger

mercoledì 14 dicembre 2011

Sniff switched network with ettercap-ng for windows

Hi all,
a quick guide about one (there are other) way to sniff network traffic in a switched lan.

The enviroment is:

PCA
PCB
monitoring-PC (os: win xp, 2 NICs installed)

my monitoring pc is a laptop with only 1 nic, so I used a DLINK external USB NIC (name: DUB-E100) as second NIC.

PCA is connecting to PCB

on your "monitoring-PC" you want to see(sniff) the traffic between A and B but you cannot install anything on them and they are connected using a switch.

The problem is that in a switched enviroment you usually cannot sniff packets like you do using an HUB.
If you have an hub you can connect it in the middle, else if you have a way to setup a monitoring port on the switch, ok, but else it's a problem.

You could ARP poisoning the devices to then sniff (or also do a mac flooding to put the switch in a failed open state), but in my experience this could be dangerous sometimes and it often doesn't work very well.

SOLUTION


A solution I found today is to use ETTERCAP-NG for windows.
You can install it on your monitoring pc, using 2 network card, configure it for a "bridged sniffing" and then run a sniffer like "Wireshark".
You simply need to disconnect A or B and put your monitoring pc in the middle using the 2 NICs.

example:

A--- (nic1)monitoringPC(nic2) ---- switch ----B
or

A--- switch ---(nic1)monitoringPC(nic2) ------B
or
...etc (exchange nic1 and nic2)


This way the monitoringPC is acting as a bridge and the packets between A and B are visible on the monitoringPC.



ETTERCAP-NG
http://sourceforge.net/projects/ettercap/files/
open "unofficial binaries", then "windows", then download "ettercap-NG-0.7.3-win32.exe"

WIRESHARK
http://www.wireshark.org/


INSTRUCTIONS (on the monitoring pc with 2 nics installed, in my case XP operating system)

Download and install ettercap-ng, then download and install wireshark.

Start Ettercap-ng
from the "Sniff" menu select "Bridged sniff"



Then from the windows that appear select the nics to be used for creating the bridge



Now from the "Start" menu select "Start sniffing"


Now you can open "Wireshark" (or other sniffing tool) to see the traffic



The red arrows indicate what I changed from the default.
Important is to select "promiscuous" else you'll not see all the packets as they are not directed to you (the monitorinc pc), then I changed the nic to the USB one (but also the other is ok).
Unflagged "Automatic scrolling" because I prefere this way, but this is up to you.

That's all, at this point you should see all the packets between the 2 machines.

bye
Digger





venerdì 2 dicembre 2011

Windows 7 Search - missing files - resolution

Hi all,
are you in the same situation as me?

Are you searching in a particular folder (and subfolders) for a filename, or for content, and AS ALWAYS windows 7 search doesn't find it? also if you know for sure the file is there and/or the content is there in some file??

Honestly I hate the way Windows 7 indexes everything (slowing down the pc) just to speed up searching something from time to time, and then also you don't find it because at the end it doesn't work as it should...

Ok, there are some tips to make windows search working better, like unflagging all the folders in the indexing option, in this way windows will search not using the indexing at all.
Then you'll not find content anymore I suspect, so you should flag the folder "one shot" just to start indexing on demand (but you should also disable indexing backoff to make it works).

Ok, the REAL solution?

DON'T USE WINDOWS SEARCH... use something else

Unflag ALL the flags in the indexing options so that no folder is indexed (this will speed up you pc in some way), just keep Outlook flag so you can search mails.

Then istall some search tool (I'm using Agent Ransack as it does its job well) and use it instead!

venerdì 25 novembre 2011

Cannot boot OpenSuse 12 after cloning disk due to by-id access to the disk

Hi all,
today I tried to clone a pc with OpenSuse12 using Clonezilla as cloning solution.
Then I tried to boot the target cloned machine but it wasn't able to boot and the errors was something like this (the disk names are from another post, just as an example) :



Trying manual resume from /dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part1
resume device dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part1 not found (ignoring)
Trying manual resume from /dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part1
resume device dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part1 not found (ignoring)
Waiting for device dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part2 to appear : ........................ Could not find dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part2 .
Want me to fall back to dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part2 ? (Y/N)
y
Waiting for device dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part2 to appear : ...............not found -- exiting to /bin/sh




The typical messages are:

Trying manual resume from
resume device dev/disk/by-id/ata-...-part1 not found (ignoring)
Waiting for device dev/disk/by-id/ata-...-part2 to appear
Could not find dev/disk/by-id/ata-...-part2
Want me to fall back to dev/disk/by-id/ata-...-part2 ? (Y/N)


This happens due to a new default setting in OpenSuse: from Ver.10Sp1 on, the new default is to reference the storage device (the disks)  "by-id" instead of by-name

I mean, in the past the disks was referenced like this:
sda
sdb
...


then the partitions of the first disk (sda) was:
sda1
sda2
sda3


and so on.

Now the new way to reference disk and partition is:

The disks are (just an example, it changes based on the disk manifacturer and other data):
/dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T
/dev/disk/by-id/ata-ST380013AS_4MR2NSD8

where the first row is the first disk, a Toshiba disk, the second is another disk, a Seagate disk.

The partitions will be, for the first disk, for example:

/dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part1
/dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part2

for the second disk:
/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part1
/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part2

The problem with cloning is that around the system, in some configuration files, there are references to the original disks "by-id", unfortunately on the target computer (where we restore the image) the disks will be different, will have different "by-id" name, so linux will be unable to find the disks and boot correctly.

SOLUTION


The solution is quite simple.
After creating the MASTER computer, we need to change 2 files in order to modify the "by-id" reference in "by-name" reference.
The files are:


/etc/fstab
/boot/grub/menu.lst


in both the files we need to find every instance of names like (example)

/dev/disk/by-id/ata-TOSHIBA-MK1246GSX-28FGTI70T-part1

and change in something like:

/dev/sda1

take care about the partition number:
-part1  ->  sda1
-part2  ->  sda2

and so on.

To modify those files from a command prompt we need to run the editor using sudo else we will get an error (missing rights):

sudo vi /etc/fstab


(then i to go into insert mode, change the disk name, then press ESC to exit insert mode, then :wq to write the changes to disk and quit, else to discard changes :qa!)

sudo vi /boot/grub/menu.lst


(same instruction as above)

Reboot the computer to check that everything is still working fine.
You are now ready to create the image with Clonezilla (or other cloning solution) and restore on the target pc.


SAMPLE
Here how my files appeared before and after the change:

/etc/fstab
BEFORE


/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part1 swap                 swap       defaults              0 0
/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part2 /                    ext4       acl,user_xattr        1 1
/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part3 /home                ext4       acl,user_xattr        1 2
proc                 /proc                proc       defaults              0 0
sysfs                /sys                 sysfs      noauto                0 0
debugfs              /sys/kernel/debug    debugfs    noauto                0 0
usbfs                /proc/bus/usb        usbfs      noauto                0 0
devpts               /dev/pts             devpts     mode=0620,gid=5       0 0


/etc/fstab
AFTER


/dev/sda1 swap                 swap       defaults              0 0
/dev/sda2 /                    ext4       acl,user_xattr        1 1
/dev/sda3 /home                ext4       acl,user_xattr        1 2
proc                 /proc                proc       defaults              0 0
sysfs                /sys                 sysfs      noauto                0 0
debugfs              /sys/kernel/debug    debugfs    noauto                0 0
usbfs                /proc/bus/usb        usbfs      noauto                0 0
devpts               /dev/pts             devpts     mode=0620,gid=5       0 0



/boot/grub/menu.lst
BEFORE




# Modified by YaST2. Last modification on Fri Nov 25 21:23:32 CET 2011
# THIS FILE WILL BE PARTIALLY OVERWRITTEN by perl-Bootloader
# For the new kernel it try to figure out old parameters. In case we are not able to recognize it (e.g. change of flavor or strange install order ) it it use as fallback installation parameters from /etc/sysconfig/bootloader


default 0
timeout 8
##YaST - generic_mbr
gfxmenu (hd0,1)/boot/message
##YaST - activate


###Don't change this comment - YaST2 identifier: Original name: linux###
title openSUSE 12.1 - 3.1.0-1.2
    root (hd0,1)
    kernel /boot/vmlinuz-3.1.0-1.2-default root=/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part2 resume=/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part1 splash=silent quiet showopts vga=0x31a
    initrd /boot/initrd-3.1.0-1.2-default


###Don't change this comment - YaST2 identifier: Original name: failsafe###
title Failsafe -- openSUSE 12.1 - 3.1.0-1.2
    root (hd0,1)
    kernel /boot/vmlinuz-3.1.0-1.2-default root=/dev/disk/by-id/ata-ST380013AS_4MR2NSD8-part2 showopts apm=off noresume nosmp maxcpus=0 edd=off powersaved=off nohz=off highres=off processor.max_cstate=1 nomodeset x11failsafe vga=0x31a
    initrd /boot/initrd-3.1.0-1.2-default


/boot/grub/menu.lst
AFTER


# Modified by YaST2. Last modification on Fri Nov 25 21:23:32 CET 2011
# THIS FILE WILL BE PARTIALLY OVERWRITTEN by perl-Bootloader
# For the new kernel it try to figure out old parameters. In case we are not able to recognize it (e.g. change of flavor or strange install order ) it it use as fallback installation parameters from /etc/sysconfig/bootloader


default 0
timeout 8
##YaST - generic_mbr
gfxmenu (hd0,1)/boot/message
##YaST - activate


###Don't change this comment - YaST2 identifier: Original name: linux###
title openSUSE 12.1 - 3.1.0-1.2
    root (hd0,1)
    kernel /boot/vmlinuz-3.1.0-1.2-default root=/dev/sda2 resume=/dev/sda1 splash=silent quiet showopts vga=0x31a
    initrd /boot/initrd-3.1.0-1.2-default


###Don't change this comment - YaST2 identifier: Original name: failsafe###
title Failsafe -- openSUSE 12.1 - 3.1.0-1.2
    root (hd0,1)
    kernel /boot/vmlinuz-3.1.0-1.2-default root=/dev/sda2 showopts apm=off noresume nosmp maxcpus=0 edd=off powersaved=off nohz=off highres=off processor.max_cstate=1 nomodeset x11failsafe vga=0x31a
    initrd /boot/initrd-3.1.0-1.2-default



bye
Digger



giovedì 17 novembre 2011

Chrome - disable or remove plugins (Orbit downloader for example)

Hi all,
it happened to me to notice that after uninstalling Orbit downloader, google Chrome still tried to use Orbit to download files, obviously without success.

So there are 2 things you can do now:
1. disable the plugin
2. delete the plugin

The instructions are for Orbit, but the same is valid for every plugin.

== DISABLE PLUGINS ==


in the address bar write:

chrome://plugins


search for Orbit downloader and click on "Disable"

== DELETE PLUGINS ==


FIRST close Chrome!

from the start menu execute:

%localappdata%


to go in the local application data folder
(something like: C:\Users\username\AppData\Local)

then go to the subfolder

Google\Chrome\Application\Plugins


search for the plugin's .dll file  (in this case, for Orbit it's "nporbit.dll") and delete it.
Open Chrome, the plugin disappeared

bye
Digger

lunedì 24 ottobre 2011

Windows Live Messenger error 0x81000306

Hi all,
after days of headache trying to solve this stupid error about messenger on my pc I finally found the solution working for me and it was simply this:

run the command prompt (cmd) with administrative rights
type and confirm this command:

netsh interface tcp set global autotuninglevel=disabled 


and it started immediately to work!


hope this could help someone else


bye
Digger

lunedì 10 ottobre 2011

Server uptime - Last Boot time

Hi all,
I would like to share with you this nice and useful command from the console to retrieve the local/remote system last boot time.
It's useful for example to calculate the uptime of a remote server


wmic /node:"servername" os get lastbootuptime

to retrive the local boottime simply don't use the /node option

bye