Tuesday, January 30, 2018

import ldap db dump

 you have an ldap db dump called import.ldif . you need to replace  
 an existing ldap database with import.ldif . do this:  
   
 !/bin/bash  
   
 TIMESTAMP=$(date '+%Y%m%d%H%M')  
   
 /etc/init.d/slapd stop ;  
 mv /var/lib/ldap /var/lib/ldap-$TIMESTAMP ;  
 mkdir /var/lib/ldap ;  
 cp /etc/ldap/DB_CONFIG /var/lib/ldap ;  
 slapadd -c -l /tmp/import.ldif ;  
 chown -R openldap.openldap /var/lib/ldap ;  
 /etc/init.d/slapd start  
   

Friday, January 26, 2018

bind9 logging reprise

 in a previous post i mentioned how to do bind9 logging.  
 i found there was too much information in the single file.  
 instead, i have culled out the different notices in to separate files.  
   
 for logrotate, since all the log files are in one directory, all you  
 need to do is place a wildcard attribute in the configuration file.  
   
 and apparmor may hate you and deny you ability to create logs.  
 if you're like me and like logs to be created under the daemon's name  
 e.g. /var/log/bind for bind...  
   
 edit:  
 /etc/apparmor.d/usr.sbin.named   
 and give it /var/log/bind/** rw,  
 as opposed to /var/log/named ** rw,  
   

 # bind.local.log 
  
 logging {  
   channel query_log {  
     file "/var/log/bind/query.log" versions 3 size 5m;  
     // Set the severity to dynamic to see all the debug messages.  
       print-category yes;  
     print-severity yes;  
     print-time yes;  
     severity dynamic;  
     };  
   channel update_debug {  
     file "/var/log/bind/update_debug.log" versions 3 size 5m;  
     severity debug ;  
     print-category yes;  
     print-severity yes;  
     print-time yes;  
     };  
   channel security_info {  
     file "/var/log/bind/security_info.log" versions 3 size 5m;  
     severity info;  
     print-category yes;  
     print-severity yes;  
     print-time yes;  
     };  
   channel bind_log {  
     file "/var/log/bind/bind.log" versions 3 size 5m;  
     severity info;  
     print-category yes;  
     print-severity yes;  
     print-time yes;  
     };  
   category queries {  
     query_log;   
     };  
   category security {  
     security_info;  
     };   
   category update-security {  
     update_debug;  
     };  
   category update {  
     update_debug;  
     };  
   category lame-servers {  
     null;  
     };  
   category default {  
     bind_log;  
     };  
 };  
   
 # /etc/logrotate.d/bind    
     
 /var/log/bind/*.log {   
  daily   
  missingok   
  rotate 7   
  compress   
  delaycompress   
  notifempty   
  create 644 bind bind   
  postrotate   
   /usr/sbin/invoke-rc.d bind9 reload > /dev/null   
  endscript   
 }   

Tuesday, January 23, 2018

flush rndc

 my bind9 dns server is reporting different ips for a host when i...
  
 localhost $ dig @localhost.ip address  
   
 and  
   
 remotehost $ dig @localhost.ip address  
   
 this is due to a weirdo cache on localhost.  
 the best thing to do is flush the dns cache.  
   
 localhost $ rndc flush  
   
 easy.  

bind9 logs be freed of syslog

 I want to know who is requesting what on my bind9 server.  
 Time to cull out those logs from /var/log/syslog .  
   
 $ vi /etc/bind/named.conf  
   
 just before named.conf.local , put in this line:  
   
 include "/etc/bind/named.conf.log";  
   
 $ vi /etc/bind/named.conf.log  
   
 logging {  
  channel bind_log {  
   file "/var/log/bind/bind.log" versions 3 size 5m;  
   severity info;  
   print-category yes;  
   print-severity yes;  
   print-time yes;  
  };  
  category default { bind_log; };  
  category update { bind_log; };  
  category update-security { bind_log; };  
  category security { bind_log; };  
  category queries { bind_log; };  
  category lame-servers { null; };  
 };  
   
   
 see that directory? create it and perm it  
   
 $ mkdir /var/log/bind ; chown bind:bind /var/log/bind  
   
 your logs will be large with all that debug stuff. rotate them!  
   
 $ vi /etc/logrotate.d/bind   
   
 /var/log/bind/bind.log {  
  daily  
  missingok  
  rotate 7  
  compress  
  delaycompress  
  notifempty  
  create 644 bind bind  
  postrotate  
   /usr/sbin/invoke-rc.d bind9 reload > /dev/null  
  endscript  
 }  
   
 $ /etc/init.d/bind9 restart  
   
 excitement.  

Thursday, January 18, 2018

robocopy a local user profile between servers

 robocopy c:\Users\source \\newserver\C$\Users\source *.* /mir /sec /r:1 /w:1 /LOG:C:\Mirlog.txt /XD “RECYCLER” “Recycled” “System Volume Information” /XF “desktop.ini” “thumbs.db”  

get all ip addresses from netlogon.log and mail it

name this something.ps1 and run it to get all ipdresses from netlogon.log and mail them to yourself.
 # Script to get the IP addresses of clients from the Netlogon.log file of all domain controllers in the current domain  
 # from the current month and the previous month  
   
 ################################Start Functions####################################  
   
 function GetDomainControllers {  
   $DCs=[system.directoryservices.activedirectory.domain]::GetCurrentDomain() | ForEach-Object {$_.DomainControllers} | ForEach-Object {$_.Name}  
   return $DCs  
 }  
   
 function GetNetLogonFile ($server) {  
   #build Path variable  
   $path= '\\' + $server + '\c$\windows\debug\netlogon.log'  
   #Try to connect to $path and get the file contents or throw an error  
   try {$netlogon=get-content -Path $path -ErrorAction stop}  
   catch { "Can't open $path"}  
   #reverse the array's order so we are now working from the end of the file back  
   [array]::Reverse($netlogon)  
  #clear out the holding variable  
   $IPs=@()  
   #go through the lines  
   foreach ($line in $netlogon) {  
     #split the line into pieces using a space as the delimiter  
     $splitline=$line.split(' ')  
     #Get the date stamp which is in the mm/dd format  
     $logdate=$splitline[0]  
     #split the date  
     $logdatesplit=($logdate.split('/'))  
     [int]$logmonth=$logdatesplit[0]  
     #only worry about the last month and this month  
     if (($logmonth -eq $thismonth) -or ($logmonth -eq $lastmonth)) {  
       #only push it into an array if it matches an IP address format  
       if ($splitline[5] -match '\b\d{1,3}\.\d{1,3}\.\d{1,3}\.\d{1,3}\b'){  
         $objuser = new-object system.object  
         $objuser | add-member -type NoteProperty -name IPaddress -value $splitline[5]  
         $objuser | add-member -type NoteProperty -name Computername -value $splitline[4]  
         $objuser | add-member -type NoteProperty -name Server -value $server  
         $objuser | add-member -type NoteProperty -name Date -value $splitline[0]  
         $objuser | add-member -type NoteProperty -name Time -value $splitline[1]  
         $IPs+=$objuser  
       }  
     } else {  
       #break out of loop if the date is not this month or last month  
       break  
     }  
   }  
   return $IPs  
 }  
   
 ###############################End Functions#######################################  
   
 ###############################Main Script Block###################################  
 #Get last month's date  
 $thismonth=(get-date).month  
 $lastmonth=((get-date).addmonths(-1)).month  
   
 #get all the domain controllers  
 $DomainControllers=GetDomainControllers  
 #Get the Netlogon.log from each DC  
 Foreach ($DomainController in $DomainControllers) {  
   $IPsFromDC=GetNetLogonFile($DomainController)  
   $allIPs+=$IPsFromDC  
 }  
 #Only get the unique IPs and dump it to a CSV file  
 $allIPs | Sort-Object -Property IPaddress -Unique | Export-Csv "C:\NetlogonIPs.csv"  
   
 #Set up mail variables  
 $from="me@here"  
 $to="me@here"  
 $subject="IP addresses in Netlogon.log file from the last month"  
 $attach="C:\NetlogonIPs.csv"  
 $body="File containing all unique IPs listed in the netlogon.log file for all the Domain Controllers in the company domain."  
 #Send mail message  
 Send-MailMessage -from $from -To $to -subject $subject -SmtpServer smtpserver -Body $body -BodyAsHtml -Attachments $attach  

Thursday, October 26, 2017

openssl is too old. of course.

 I was having a good morning. I got to work on time and had a cup of coffee.  
 The world was good.  
   
 Then I see this:  
   
 Downloading: https://zlib.net/fossils/zlib-1.2.11.tar.gz  
 javax.net.ssl.SSLException: hostname in certificate didn't match: <zlib.net> != <amanekaneko.com> OR <amanekaneko.com> OR <cpanel.amanekaneko.com> OR <mail.amanekaneko.com> OR <webdisk.amanekaneko.com> OR <webmail.amanekaneko.com> OR <www.amanekaneko.com>  
   
 browsing amanekaneko.com is fascinating, to say the least  
   
   
 me@:~/certs$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz  
 --2017-10-26 12:20:05-- https://zlib.net/fossils/zlib-1.2.11.tar.gz  
 Resolving zlib.net... 69.73.182.198  
 Connecting to zlib.net|69.73.182.198|:443... connected.  
 ERROR: certificate common name `amanekaneko.com' doesn't match requested host name `zlib.net'.  
 To connect to zlib.net insecurely, use `--no-check-certificate'.  
   
 What?!  
   
 I see the same across a bunch of build systems. ffs.  
 Maybe it is the firewall doing something weird.  
   
 Nope.  
   
 me@:/etc/ssl/certs$ openssl version -a  
 OpenSSL 0.9.8k 25 Mar 2009  
 built on: Thu Mar 19 15:32:30 UTC 2015  
 platform: debian-i386-i686/cmov  
 options: bn(64,32) md2(int) rc4(idx,int) des(ptr,risc1,16,long) blowfish(idx)  
 compiler: cc -fPIC -DOPENSSL_PIC -DZLIB -DOPENSSL_THREADS -D_REENTRANT -DDSO_DLF  
 CN -DHAVE_DLFCN_H -DL_ENDIAN -DTERMIO -O3 -march=i686 -Wa,--noexecstack -g -Wall  
 -DOPENSSL_BN_ASM_PART_WORDS -DOPENSSL_IA32_SSE2 -DSHA1_ASM -DMD5_ASM -DRMD160_A  
 SM -DAES_ASM  
   
 OPENSSLDIR: "/usr/lib/ssl"  
   
 All certs are here: /etc/ssl/certs  
 All symlinked to: /usr/share/ca-certificates/  
   
 $JAVA_HOME/lib/security/cacerts is the same.  
   
   
 SSL_CERT_FILE:/etc/ssl/certs/ca-certificates.crt  
   
 openssl   
 apt-get reinstall openssl  
 apt-get reinstall ca-certificates  
 cd /usr/lib/ssl/certs  
 c_rehash  
   
 yet.  
   
 me@:~$ openssl s_client -connect zlib.net:443  
 CONNECTED(00000003)  
 depth=2 /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority  
 verify error:num=20:unable to get local issuer certificate  
 verify return:0  
   
 I need the /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority certificate.  
 It is present. Very present.  
   
 but.  
   
 me@:~$ openssl s_client -CApath /etc/ssl/certs/ -connect zlib.net:443 < /dev/null | sed -ne '/-BEGIN CERTIFICATE-/,/-END CERTIFICATE-/p' > zlibnet.pem  
   
 depth=3 /C=SE/O=AddTrust AB/OU=AddTrust External TTP Network/CN=AddTrust External CA Root  
 verify return:1  
 depth=2 /C=GB/ST=Greater Manchester/L=Salford/O=COMODO CA Limited/CN=COMODO RSA Certification Authority  
 verify return:1  
 depth=1 /C=US/ST=TX/L=Houston/O=cPanel, Inc./CN=cPanel, Inc. Certification Authority  
 verify return:1  
 depth=0 /CN=amanekaneko.com  
 verify return:1  
 DONE  
   
 cat the output and yep. the pem is pem-a-licious.  
   
 me@:~$ sudo cp zlibnet.pem /usr/lib/ssl/certs  
   
 me@:~$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz  
 --2017-10-26 12:15:48-- https://zlib.net/fossils/zlib-1.2.11.tar.gz  
 Resolving zlib.net... 69.73.182.198  
 Connecting to zlib.net|69.73.182.198|:443... connected.  
 ERROR: certificate common name `amanekaneko.com' doesn't match requested host name `zlib.net'.  
 To connect to zlib.net insecurely, use `--no-check-certificate'.  
   
 Nope. Weird. Well, that's new. Let's see what happens if we specify the cert dir.  
   
 me@:~$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz --ca-certificate=/usr/lib/ssl/certs  
 --2017-10-26 12:15:48-- https://zlib.net/fossils/zlib-1.2.11.tar.gz  
 Resolving zlib.net... 69.73.182.198  
 Connecting to zlib.net|69.73.182.198|:443... connected.  
 ERROR: certificate common name `amanekaneko.com' doesn't match requested host name `zlib.net'.  
 To connect to zlib.net insecurely, use `--no-check-certificate'.  
   
 No? So. certificate common name doesn't match requested host name. Why?  
   
 OpenSSL is too old.  
 OpenSSL 0.9.8k 25 Mar 2009 <- too old  
   
   
 me@:~$ wget https://zlib.net/fossils/zlib-1.2.11.tar.gz --no-check-certificate  
 me@:~$ curl https://zlib.net/fossils/zlib-1.2.11.tar.gz --insecure  
   
 or  
   
 curl -L --remote-name https://zlib.net/fossils/zlib-1.2.11.tar.gz