samba 3.0.28a and windows 7 are having a bad day. i've done all the usual registry tricks and uninstalled KB2536276. it is time. of course, i'm running ubuntu 8.04; so no amount of apt-get updating is going to bring samba to higher level. let's sort of roll our own, shall we? 3.4.4 is a nice, stable rev. pre-prep system. # apt-get update ; apt-get upgrade ; apt-get apt-get dist-upgrade what?! it is time. this system does nothing but samba anyway... and yes, i have backups. # apt-get install libldap2-dev libkrb5-dev uuid-dev libpam0g-dev zlib1g-dev build-essential # apt-get build-dep samba # cd ~/ # apt-get source samba # cat ~/samba-3.0.28a/debian/rules | less take note of all the switches, we're going to use them later. time to download the source. # mkdir -p /usr/local/src/samba # cd /usr/local/src/samba # wget http://samba.org/samba/ftp/stable/samba-3.4.4.tar.gz # tar zxvf samba-3.4.4.tar.gz # cd samba-3.4.4/source3 if you're working with windows server 2012, just download the samba-3.6.8.tar.gz and follow the same instructions... now, run configure using the os-specific switches: ./configure -–cache-file=./config.cache \ -–prefix=/usr \ --sysconfdir=/etc \ --localstatedir=/var \ --with-privatedir=/etc/samba \ --with-piddir=/var/run/samba \ --with-fhs \ --enable-shared \ --enable-static \ --disable-pie \ --with-rootsbindir=/sbin \ --with-pammodulesdir=/lib/security \ --with-pam \ --with-syslog \ --with-utmp \ --with-readline \ --with-pam_smbpass \ --with-libsmbclient \ --with-winbind \ --with-shared-modules=idmap_rid,idmap_ad \ --with-automount \ --with-ldap \ --with-ads \ --with-dnsupdate \ --with-cifsmount \ <-- is not recognized in samba 3.6.8 (rev compat with win 2012) --with-acl-support \ --with-quotas take note: sometimes in the process of doing configure your system will bark. in my case, uuid.h . note apt-get command above only includes my missing packages; your mileage may vary. # apt-cache search uuid | grep -- -dev libblkid-dev - block device id library - headers and static libraries libossp-uuid-dev - OSSP uuid ISO-C and C++ - headers and static libraries uuid-dev - universally unique id library - headers and static libraries neat. it works. # make Using CFLAGS = -O -I. -I/root/samba-3.4.3/source3 -I/root/samba-3.4.3/source3/../lib/popt -I/root/samba-3.4.3/source3/iniparser/src -Iinclude -I./include -I. -I. -I./../lib/replace -I./../lib/talloc -I./../lib/tevent -I./../lib/tdb/include -I./libaddns -I./librpc -I./.. -DHAVE_CONFIG_H -D_LARGEFILE64_SOURCE -D_FILE_OFFSET_BITS=64 -D_GNU_SOURCE -Iinclude -I./include -I. -I. -I./../lib/replace -I./../lib/talloc -I./../lib/tevent -I./../lib/tdb/include -I./libaddns -I./librpc -I./.. -I./../lib/popt -DLDAP_DEPRECATED -I/root/samba-3.4.3/source3/lib -I.. -I../source4 -D_SAMBA_BUILD_=3 -D_SAMBA_BUILD_=3 ... snip ... that went okay. # make install neat. i just installed over my old binaries. take note: The binaries are installed. You may restore the old binaries (if there were any) using the command "make revert". You may uninstall the binaries using the command "make uninstallbin" or "make uninstall" to uninstall binaries, man pages and shell scripts. register samba libs. # echo "/etc/samba" > /etc/ld.so.conf.d/samba.conf # ldconfig make sure we've got all the handles for our windows clients set. to make those permanent, reboot. otherwise, command-line it. in "/etc/security/limits.conf" add line: * - nofile 16384 # ulimit -n 16384 then start the daemon. # /etc/init.d/samba start * Starting Samba daemons [ OK ] neat. it works. take note: you may need to re-add the system to your domain; as alluded to in spiffy messages such as the below: [2013/12/31 10:51:08.876223, 0] auth/auth_domain.c:212(connect_to_domain_password_server) connect_to_domain_password_server: could not fetch trust account password for domain 'DOMAIN' [2013/12/31 10:51:08.876964, 0] auth/auth_domain.c:292(domain_client_validate) domain_client_validate: Domain password server not available. whoops.
Tuesday, December 31, 2013
ubuntu 8.04 upgrade samba process
Wednesday, December 18, 2013
ssh is offline on my sol11 box. great.
from here http://pg8873.blogspot.com/2011/02/solaris-ssh-is-offline.html
Solaris ssh is offline I'm sure you must have seen a situation like this, where for some reason ssh died and you cannot login to the server remotely. If you have console access to box, you see the ssh is offline. root@app1 # svcs -a | grep ssh offline 1:40:22 svc:/network/ssh:default svcs -d will tell us what other services depends on ssh root@app1 # svcs -d ssh STATE STIME FMRI online 1:40:19 svc:/network/loopback:default online 1:40:24 svc:/network/physical:default disable 1:41:04 svc:/system/cryptosvc:default online 1:41:16 svc:/system/filesystem/local:default online 1:42:44 svc:/system/filesystem/autofs:default online 1:42:43 svc:/system/utmp:default Offline means that the service is enabled, but something it depends on is missing, disable or in maintenance mode Here in our case crypto is disable. You might have a service with lots of dependencies that are disabled, or you might have dependencies disabled many levels deep. Do you want to walk through all those services, find out why they're not on, and enable every dependency by hand? Of course you don't. So svcadm has a "recursive enable" option that goes through and enables everything that your service depends on. # svcadm enable -r network/ssh #svcs network/ssh STATE STIME FMRI online 1:02:23 svc:/network/ssh:default #svcs -d network/ssh:default STATE STIME FMRI online 1:40:19 svc:/network/loopback:default online 1:40:24 svc:/network/physical:default disabled 1:41:04 svc:/system/cryptosvc:default online 1:41:16 svc:/system/filesystem/local:default online 1:42:44 svc:/system/filesystem/autofs:default online 1:42:43 svc:/system/utmp:default As you can see, we recursively enabled not only ssh, but everything it depended on, allowing it to come online. One last option of note for enable/disable is the "temporary" option. Say that you want to enable/disable a service just for this session, but have it revert to its previous state on reboot, in case there are problems. If ssh is disabled and you issue: #svcadm enable -t network/ssh The enable will only be temporary. If you reboot the machine, the service will once again be disabled. refresh Refresh serves two purposes. One is if you've changed any of the properties of your service, say that you've added a dependency or changed the timeout for starting, you refresh the service, and the properties become active. The other purpose is that there's an optional method, in addition to "start" and "stop", called "refresh" that you can define. If your daemon can be sent a HUP signal to re-read its configuration file, you put this in the refresh method, and when you refresh the service, this method is called. restart Restart is pretty self evident. Restarting a service means that you stop it and start it again. Where in the past you might have issued a /etc/init.d/sendmail stop followed by /etc/init.d/sendmail start, now you would use: #svcadm restart network/smtp:sendmail ... which will restart sendmail. mark (degraded | maintenance) Mark is used to force a service into a certain state. (The states are here if you've forgotten them) An administrator might want to force a service into the maintenance state to let other administrators know that there's something wrong with it that needs to be addressed before it's started again. You can force a service into either maintenance (which will shut the service down) or degraded (which will leave it running, but let others know that it's running in a degraded state). Keeping with our earlier example of ssh: #svcadm mark maintenance network/ssh #svcs network/ssh STATE STIME FMRI maintenance 1:12:47 svc:/network/ssh:default clear Clear is used to "reset" the state of a service, and have it be re-evaluated. For example, say that syslog is in maintenance: #svcs system/system-log STATE STIME FMRI maintenance 1:15:33 svc:/system/system-log:default You debug the problem, and realize that syslog failed to start because someone had accidentally deleted syslog.conf, which syslog needs to start. It attempted to start, saw that the conf file was missing, and fell into maintenance. You repair the file, and issue a clear: # svcadm clear system/system-log # svcs system/system-log STATE STIME FMRI online 1:25:07 svc:/system/system-log:default
Friday, November 8, 2013
exchange mailbox access change
i would like access to a mailbox, please?
Add-MailboxPermission -Identity targetuser@some.where -User DOMAIN\me -AccessRights FullAccess -InheritanceType All
vmware disk rename
sometimes you need to do this.
yeah
Renaming using the virtual disk using the ESX/ESXi host console interface To rename the disk and its files using the vmkfstools command in ESX/ESXi host's console interface: Verify the virtual machine referring to the virtual machine disk is powered off and does not have outstanding snapshots. Remove the virtual disk from the virtual machine's configuration: Locate the virtual machine in the inventory using the vSphere Client. Right-click the virtual machine select Edit Settings. Select the virtual disk in question and take note of virtual device node (eg, SCSI 0:1) and the name of the datastore and directory in the Disk File field at the top-right. Click the Remove button to disconnect the virtual disk from the virtual machine. Open a console to the ESX or ESXi host. For more information, see Unable to connect to an ESX host using Secure Shell (SSH) (1003807) or Using Tech Support Mode in ESXi 4.1 (1017910). Navigate to the virtual machine's directory using a command similar to: cd "/vmfs/volumes/Datastore Name/Directory Name/" Obtain a listing of the files within a directory using the command: ls -l For example: total 320 -rw------- 1 root root 8684 Aug 30 10:53 examplevm.nvram -rw------- 1 root root 21474836480 Aug 30 10:26 examplevm-flat.vmdk -rw------- 1 root root 482 Aug 30 11:26 examplevm.vmdk -rw------- 1 root root 0 Aug 30 10:33 examplevm.vmsd -rwxr-xr-x 1 root root 2724 Aug 30 12:20 examplevm.vmx -rw------- 1 root root 264 Aug 30 12:20 examplevm.vmxf -rw-r--r-- 1 root root 39168 Aug 30 10:53 vmware.log Rename a virtual disk using a command similar to: vmkfstools -E OldName.vmdk NewName.vmdk For example: vmkfstools -E examplevm.vmdk examplevm-renamed.vmdk Note: Specify the descriptor file; the associated extent file is renamed
in the process. Validate the files were renamed by listing the files within the directory
using the command: ls -l For example: total 320 -rw------- 1 root root 8684 Aug 30 10:53 examplevm.nvram -rw------- 1 root root 21474836480 Aug 30 10:26 examplevm-renamed-flat.vmdk -rw------- 1 root root 482 Aug 30 11:26 examplevm-renamed.vmdk -rw------- 1 root root 0 Aug 30 10:33 examplevm.vmsd -rwxr-xr-x 1 root root 2724 Aug 30 12:20 examplevm.vmx -rw------- 1 root root 264 Aug 30 12:20 examplevm.vmxf -rw-r--r-- 1 root root 39168 Aug 30 10:53 vmware.log Re-add the virtual machine disk to the virtual machine's configuration. Using the vSphere Client, select the virtual machine and click Edit Settings. Click the Add... button above the virtual hardware list. Select Hard Disk and Use an existing virtual disk. Select the datastore and disk that was renamed. Confirm that the same SCSI controller type and Device Node noted in step 2c. Click the OK button to complete the configuration change.
Wednesday, November 6, 2013
hashed known_hosts
le sigh. by default on my linux boxes, known_hosts are hashed. cool if there's a worm worming around using your ssh known_hosts or there's a cracker that wants access to your pubkeyed stuff. but what do you do when someone leaves? sure you rotate passwords, sure you guard your gateways. but what about all of those pubkeyed systems?
this is useful:
http://blog.rootshell.be/2010/11/03/bruteforcing-ssh-known_hosts-files/
http://blog.rootshell.be/wp-content/uploads/2010/11/known_hosts_bruteforcer.pl.txt
make sure your path to perl is correct and you've installed those modules (cpan install is your friend)
this is useful:
http://blog.rootshell.be/2010/11/03/bruteforcing-ssh-known_hosts-files/
http://blog.rootshell.be/wp-content/uploads/2010/11/known_hosts_bruteforcer.pl.txt
make sure your path to perl is correct and you've installed those modules (cpan install is your friend)
#!/usr/bin/perl # # SSH known_hosts file bruteforcer # # v1.0 - Xavier Mertens# # This Perl script read a SSH known_host file containing hashed hosts and try to find hostnames # or IP addresses # # 20101103 : Created # # Todo # ---- # - Support for IPv6 addresses # - Increase performances # use Getopt::Std; use Digest::HMAC_SHA1; use MIME::Base64; use Net::IP; $MAXLEN = 8; # Maximum hostnames length to check $MAXIP = 4294967296; # 2^32 # The whole IPv4 space @saltStr = (); @base64Str = (); $idx = 0; # Process the arguments getopts("d:f:l:s:ivh", \%options); # Some help is sometimes useful if ($options{h}) { print < Specify a domain name to append to hostnames (default: none) -f Specify the known_hosts file to bruteforce (default: $HOME/.ssh/known_hosts) -i Bruteforce IP addresses (default: hostnames) -l Specify the hostname maximum length (default: 8) -s Specify an initial IP address or password (default: none) -v Verbose output -h Print this help, then exit EOF exit; } # SSH Keyfile to process (default: $HOME/.ssh/known_hosts) $knownhostFile = ($options{f} ne "") ? $options{f} : $ENV{HOME} . "/.ssh/known_hosts"; if (! -r $knownhostFile) { print STDERR "Cannot read file $knownhostFile ...\n"; exit 1; } # Max password length (default: 8) $passwordLen = ($options{l} ne "") ? $options{l} : $MAXLEN; if ($passwordLen < 1 || $passwordLen > 30) { print STDERR "Invalid maximum password length: $passwordLen ...\n"; exit 1; } # Domain name to append $domainName = $options{d}; # Verbose mode $verbose = ($options{v}) ? 1 : 0; # IP address mode $ipMode = ($options{i}) ? 1 : 0; # Starting IP or password? # To increase the speed of run the script across multiple computers, # an initial hostname or IP address can be given $initialStr = $options{s}; # First read the known_hosts file and populate the lists # Only hashed hosts are processed ($verbose) && print STDERR "Reading hashes from $knownhostFile ...\n"; open(HOSTFILE, "$knownhostFile") || die "Cannot open $knownhostFile"; while( ) { ($hostHash, $keyType, $publicKey) = split(/ /); if ($hostHash =~ m/\|1\|/) { ($dummy, $one, $saltStr[$idx], $base64Str[$idx]) = split(/\|/, $hostHash); $idx++; } } close(HOSTFILE); # --------- # Main Loop # --------- $loops=0; while(1) { if ($ipMode) { # Generate an IP address using the main loop counter # Don't go beyond the IPv4 scope (2^32 addresses) if ($loops > $MAXIP) { print "Done.\n"; exit 0; } # If we have an initial IP, check the syntax and use it if ($initialStr ne "") { my $ip = new Net::IP($initialStr); $initialIP = $ip->intip(); } else { $initialIP = 0; } $tmpHost = sprintf("%vd", pack("N", $loops + $initialIP)); } else { # Generate a temporary hostname (starting with an initial value if provided) $tmpHost = generateHostname($initialStr); if (length($tmpHost) > $passwordLen) { print "Done.\n"; exit 0; } # Append the domain name if provided if ($domainName) { $tmpHost = $tmpHost . "." . $domainName; } } # In verbose mode, display a line every 1000 attempts ($verbose) && (($loops % 1000) == 0) && print STDERR "Testing: $tmpHost ($loops probes) ...\n"; if ($line = searchHash($tmpHost)) { printf("*** Found host: %s (line %d) ***\n", $tmpHost, $line + 1); } $loops++; } # # Generate SHA1 hashes of a hostname/IP and compare it to the available hashes # Returns the line index of the initial known_hosts file # sub searchHash() { $host = shift; ($host) || return 0; # Process the list containing our hashes # For each one, generate a new hash and compare it for ($i = 0; $i < scalar(@saltStr); $i++) { $decoded = decode_base64($saltStr[$i]); $hmac = Digest::HMAC_SHA1->new($decoded); $hmac->add($host); $digest = $hmac->b64digest; $digest .= "="; # Quick fix ;-) if ($digest eq $base64Str[$i]) { return $i; } } return 0; } # # Generate a hostname based on a given set of allowed caracters # This sub-routine is based on: # bruteforce 0.01 alpha # Written by Tony Bhimani # (C) Copyright 2004 # http://www.xenocafe.com # sub generateHostname { $initialPwd = shift; $alphabet = "abcdefghijklmnopqrstuvwxyz0123456789-"; @tmpPwd = (); $firstChar = substr($alphabet, 0, 1); $lastChar = substr($alphabet, length($alphabet)-1, 1); # If an initial password is provided, start with this one if ($initialPwd ne "" && $currentPwd eq "") { $currentPwd = $initialPwd; return $currentPwd; } # No password so start with the first character in our alphabet if ($currentPwd eq "") { $currentPwd= $firstChar; return $currentPwd; } # If the current password is all of the last character in the alphabet # then reset it with the first character of the alphabet plus 1 length greater if ($currentPwd eq fillString(length($currentPwd), $lastChar)) { $currentPwd = fillString(length($currentPwd) + 1, $firstChar); return $currentPwd; } # Convert the password to an array @tmpPwd = split(//, $currentPwd); # Get the length of the password - 1 (zero based index) $x = @tmpPwd - 1; # This portion adjusts the characters # We go through the array starting with the end of the array and work our way backwords # if the character is the last one in the alphabet, we change it to the first character # then move to the next array character # if we aren't looking at the last alphabet character then we change the array character # to the next higher value and exit the loop while (1) { $iTemp = getPos($alphabet, $tmpPwd[$x]); if ($iTemp == getPos($alphabet, $lastChar)) { @tmpPwd[$x] = $firstChar; $x--; } else { @tmpPwd[$x] = substr($alphabet, $iTemp + 1, 1); last; } } # Convert the array back into a string and return the new password to try $currentPwd = join("", @tmpPwd); return $currentPwd; } # # Fill a string with the same caracter # sub fillString { my ($len, $char) = (shift, shift); $str = ""; for ($i=0; $i<$len; $i++) { $str .= $char; } return $str; } # # Return the position of a caracter in a string # sub getPos { my ($alphabet, $char) = (shift, shift); for ($i=0; $i # Eof
Tuesday, October 15, 2013
likewise registry changes
There are two ways to edit home directory and shell in Likewise: 1. lwconfig 2. lwregshell and no, hacking the xml files do not work. lwconfig command line joy. fun. sadly, sometimes it has null and cache issues. /opt/likewise/bin/lwconfig --detail AssumeDefaultDomain /opt/likewise/bin/lwconfig AssumeDefaultDomain true /opt/likewise/bin/lwconfig --show AssumeDefaultDomain /opt/likewise/bin/lwconfig LoginShellTemplate /bin/bash /opt/likewise/bin/lwconfig HomeDirPrefix /home /opt/likewise/bin/lwconfig HomeDirTemplate %H/%U /opt/likewise/bin/lwconfig CreateHomeDir false echo 'MYDOMAINS\\domain^admins ALL=(ALL) ALL' >> /etc/sudoers restart the Likewise services" /opt/likewise/bin/lwsm restart lwio lwregshell the registry editing tool. /opt/likewise/bin/lwregshell In the lsass branch, there are two keys that contain entries for the home directory and shell. One is for the Active Directory provider, the other is for the Local provider. to get to the locations: cd HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\ActiveDirectory set_value LoginShellTemplate /bin/bash set_value HomeDirTemplate %H/%U cd HKEY_THIS_MACHINE\Services\lsass\Parameters\Providers\Local set_value LoginShellTemplate /bin/bash set_value HomeDirTemplate %H/%U Refresh configuration without agent restart (unlike with lwconfig): /opt/likewise/bin/lw-refresh-configuration
show hidden directories osx
osx hides directories in finder. do an ls -lO and you'll see: "hidden" to make unhiddened: # chflags unhidden directory
Subscribe to:
Posts (Atom)