Search


Tuesday, January 3, 2012

DirectAdmin Server Hardening

1. Connect to the server using SSH and login as the admin user.
2. Switch to the root user using the su command.
3. Using your Web browser, browse to the DirectAdmin control panel at     http://<server ip>:2222.
3. Sign into the control panel using the DirectAdmin admin username and password.

 Change Shell Passwords

1. Make sure you are connected to the server as the root user using SSH.
2. Change the admin user’s password:
     # /usr/bin/passwd admin
     (set new password)
3. Change the root user’s password:
     # su -
     # /usr/bin/passwd
     (set new password)

Setup Secure Shell (SSH) Service

1. Add the admin user to the wheel group:
    # usermod -G wheel admin
2. Edit the server’s SSH configuration file:
    # nano -w /etc/ssh/sshd_config
3. To allow only SSH protocol 2 connections, find the line:
     #Protocol 2, 1
4. Uncomment it and change it to:
     Protocol 2
5. Next, to disable direct root login, find the line:
     #PermitRootLogin yes
6. Uncomment it and change it to:
PermitRootLogin no
7. Next, to change the port that SSH listens on, find the line:
    #Port 22
8. Uncomment it and change it to:
Port 1022
9. Save the file and exit the editor.
10. Restart the SSH service:
     # service sshd restart


 Change the Server Admin Username

1. Change the admin username:
    # cd /usr/local/directadmin/scripts
    # ./change_username.sh admin newuser
2. Edit the server’s SSH configuration file:
    # nano -w /etc/ssh/sshd_config
3. Find the line:
     AllowUsers admin
4. Change it to:
    AllowUsers newuser
5. Save the file and exit the editor.
6. Restart the SSH service:
    # service sshd restart
7. Edit the DirectAdmin list of allowed admins file:
    # nano -w /usr/local/directadmin/data/admin/admin.list
8. Change the line with the admin username to the new username for the  admin account.
9. Save the file and exit the editor.

Set the Server’s Date and Time

1. Set the server’s time zone:
    # rm -f /etc/localtime
    # ln -s /usr/share/zoneinfo/America/New_York /etc/localtime
2. Update the current system time:
    # /usr/bin/rdate -s clock.psu.edu
3. Set the ZONE entry in the file /etc/sysconfig/clock to  “America/New_York”.
4. Set the hardware clock:
     # /sbin/hwclock –-systohc
5. Setup a new hourly cron job to keep the server’s time accurate:
    # touch /etc/cron.hourly/rdate
    # chmod 755 /etc/cron.hourly/rdate
    # nano -w /etc/cron.hourly/rdate
6. Paste the following lines into the new cron file:
     #!/bin/sh
     host=”clock.psu.edu”
     /usr/bin/rdate -s $host >/dev/null 2>&1 && /sbin/hwclock –-systohc >/dev/null 2>&1
7. Save the file and exit the editor.



**  Not complete

DirectAdmin control Panel Installtion

Make sure you are having the following packages installed  in the server.  Ie you have to meet the minimum system requirements. 
SSH, gcc, g++, openssl-devel installed

If you are not having the following packages you have to install it in the server. The following are the typical commands used before we install DirectAdmin.

On Rehat/Fedora/Centos:
yum install wget gcc gcc-c++ flex bison make bind bind-libs bind-utils openssl openssl-devel perl quota libaio libcom_err-devel libcurl-dev

Make sure you have purchased Directadmin license.  


Your server is now prepared to install DirectAdmin, so let’s begin.
Run:
wget http://directadmin.com/setup.sh
chmod +x setup.sh

./setup.sh

Now installation procedure will start.

Sunday, January 1, 2012

Joomla .htaccess Rules

 Htaccess   rules in joomla an example:  Add the below rules to the .htaccess file in the default document root 


##
# @version $Id: htaccess.txt 14401 2010-01-26 14:10:00Z louis $
# @package Joomla
# @copyright Copyright (C) 2005 - 2010 Open Source Matters. All rights reserved.
# @license http://www.gnu.org/copyleft/gpl.html GNU/GPL
# Joomla! is Free Software
##
#####################################################
# READ THIS COMPLETELY IF YOU CHOOSE TO USE THIS FILE
#
# The line just below this section: 'Options +FollowSymLinks' may cause problems
# with some server configurations. It is required for use of mod_rewrite, but may already
# be set by your server administrator in a way that dissallows changing it in
# your .htaccess file. If using it causes your server to error out, comment it out (add # to
# beginning of line), reload your site in your browser and test your sef url's. If they work,
# it has been set by your server administrator and you do not need it set here.
#
#####################################################
## Can be commented out if causes errors, see notes above.
Options +FollowSymLinks
#
# mod_rewrite in use
RewriteEngine On
########## Begin - Rewrite rules to block out some common exploits
## If you experience problems on your site block out the operations listed below
## This attempts to block the most common type of exploit `attempts` to Joomla!
#
## Deny access to extension xml files (uncomment out to activate)
#<Files ~ "\.xml$">
#Order allow,deny
#Deny from all
#Satisfy all
#</Files>
## End of deny access to extension xml files
RewriteCond %{QUERY_STRING} mosConfig_[a-zA-Z_]{1,21}(=|\%3D) [OR]
# Block out any script trying to base64_encode crap to send via URL
RewriteCond %{QUERY_STRING} base64_encode.*\(.*\) [OR]
# Block out any script that includes a <script> tag in URL
RewriteCond %{QUERY_STRING} (\<|%3C).*script.*(\>|%3E) [NC,OR]
# Block out any script trying to set a PHP GLOBALS variable via URL
RewriteCond %{QUERY_STRING} GLOBALS(=|\[|\%[0-9A-Z]{0,2}) [OR]
# Block out any script trying to modify a _REQUEST variable via URL
RewriteCond %{QUERY_STRING} _REQUEST(=|\[|\%[0-9A-Z]{0,2})
# Send all blocked request to homepage with 403 Forbidden error!
RewriteRule ^(.*)$ index.php [F,L]
#
########## End - Rewrite rules to block out some common exploits
# Uncomment following line if your webserver's URL
# is not directly related to physical file paths.
# Update Your Joomla! Directory (just / for root)
# RewriteBase /
########## Begin - Joomla! core SEF Section
#
RewriteCond %{REQUEST_FILENAME} !-f
RewriteCond %{REQUEST_FILENAME} !-d
RewriteCond %{REQUEST_URI} !^/index.php
RewriteCond %{REQUEST_URI} (/|\.php|\.html|\.htm|\.feed|\.pdf|\.raw|/[^.]*)$ [NC]
RewriteRule (.*) index.php
RewriteRule .* - [E=HTTP_AUTHORIZATION:%{HTTP:Authorization},L]
#
########## End - Joomla! core SEF Section

Friday, December 30, 2011

Enable slow query log in Mysql

How to Enable slow query log in Mysql  ?

Check whether the "slow query log" is enabled  in mysql. Access mysql and try to execute the following command.


mysql> show global variables like '%slow%';
+------------------+-------+
| Variable_name    | Value |
+------------------+-------+
| log_slow_queries | OFF   |
| slow_launch_time | 2     |
+------------------+-------+


The command result shows slow query log is currently disabled in the server.  You have add the following entries in the "/etc/my.cnf"  file in-order to enable "slow query log".  Place the entries below the  section "mysqld"

[mysqld]
long_query_time=2
log-slow-queries=/var/log/mysql/log-slow-queries.log

You must create the file manually and change owners this way:

mkdir /var/log/mysql
touch /var/log/mysql/log-slow-queries.log
chown mysql.mysql -R /var/log/mysql

 Restart mysql

Check again  whether the "slow query log" is enabled.

mysql> show global variables like '%slow%';
+------------------+-------+
| Variable_name    | Value |
+------------------+-------+
| log_slow_queries | ON    |
| slow_launch_time | 2     |
+------------------+-------+
2 rows in set (0.00 sec)

This steps will log all Mysql queries that took more than 2 seconds to complete the execution.  

Wednesday, December 28, 2011

Install SSL manually in Linux

Install  SSL certificate for a doamin/Server manually into Linux Servers



The Entrust SSL Certificate is in the section named "Entrust SSL Certificate".

Example:  

Your certificate will look something like this: (Do not use the code below)
-----BEGIN CERTIFICATE----- 
MIIC4zCCAkygAwIBAgIBAzANBgkqhkiG9w0BAQUFADBFMQs
wCQYDVQQGEwJVUzEYMBYGA1UEChMPR1RFIENvcnBvcmF0aW
9uMRwwGgYDVQQDExNHVEUgQ3liZXJUcnVzdCBSb290MB4XD
AxMDgyMTIwMDIwOVoXDTA2MDEwMTIzNTkwMFowgcMxCzAJB
gNVBAYTAlVTMRQwEgYDVQQKEwtFbnRydXN0Lm5ldDE7MDkG
1UECxMyd3d3LmVudHJ1c3QubmV0L0NQUyBpbmNvcnAuIGJ5
HJlZi4gKGxpbWl0cyBsaWFiLikxJTAjBgNVBAsTHChjKSAx
Tk5IEVudHJ1c3QubmV0IExpbWl0ZWQxOjA4BgNVBAMTMUVu
J1c3QubmV0IFNlY3VyZSBTZXJ2ZXIgQ2VydGlmaWNhdGlvb
BdXRob3JpdHkwgZ0wDQYJKoZIhvcNAQEBBQADgYsAMIGHAo
M0ogzRUG4nzD683kTH/rzFgyajoshBo7Z/nkzbxCmS7R/UE
jR03FJxmBJgxUcg2ILdkfmhKfvLNx04AZP0dme4w1KNK5Ct
pzWUHmBelrTN/fCStgpkiZk0eSYbDoAivU0m2X47eMQ//24
coN6COWuBsRYZYblUtuZDAgEDo2YwZDAPBgNVHRMECDAGAQ
EDMA4GA1UdDwEB/wQEAwIBBjBBBgNVHR8EOjA4MDagNKAyh
HRwOi8vY2RwLmJhbHRpbW9yZS5jb20vY2dpLWJpbi9DUkwv
Um9vdC5jZ2kwDQYJKoZIhvcNAQEFBQADgYEAgbZwffFU+Fj
SoUFyRAAysIauOknVaLteQPQJxBGLMhXGdfejVBTWLb1UTF
NCiqm8Co+dYikuVB+0/1habRkb+k4vFe6tn5IvQMnfhZbSJ
5IlGVDWQYlfC0/R1wjfv+U6rzTJbJ7WXX0Ka5jKLKuckXNv
OA4=
-----END CERTIFICATE-----
  1. Copy the Entrust SSL Certificate to your clipboard. You must include the "----BEGIN CERTIFICATE-----" and "-----END CERTIFICATE-----" lines.
  2. Paste the certificate into a simple text editor, and ensure that the entire text is flushed to the left with no leading or trailing white space. If there are any extra spaces or missing dashes the server will not recognize the format of the file and you will not be able to install the certificate.
  3. Save the file as /path/to/your/apacheconf/ssl.crt/servername.crt
You have just installed your Entrust SSL Certificate.
It is strongly recommended that the httpd.conf file is backed up before attempting modifications.
In the section of /path/to/your/apacheconf/httpd.conf ensure that the following entries are correct:

Enable / Disbale SSL for this host
SSLEngine on

Certificate Paths:
SSLCertificateFile /path/to/your/apacheconf/ssl.crt/servername.crt
SSLCertificateKeyFile /path/to/your/apacheconf/ssl.key/servername.pem




Locate PHP configration file in Directadmin

Compile and enable soap on php with DirectAdmin Control Panel Custombuild
 
Locate PHP configration file  in Directadmin. When you recompile php, make sure you are editing the correct php configuration files. You have to make sure CustomApache or CustomBuild 
 
 cd /usr/local/directadmin/custombuild

./build used_configs
 
 Results:

Apache configuration file: /usr/local/directadmin/custombuild/custom/ap2/configure.apache

PHP4 configuration file: /usr/local/directadmin/custombuild/custom/ap2/configure.php4

suPHP configuration file: /usr/local/directadmin/custombuild/custom/suphp/configure.suphp

PHP5 configuration file: /usr/local/directadmin/custombuild/custom/suphp/configure.php5
 
Edit your php5 config file: (example)

nano /usr/local/directadmin/custombuild/custom/suphp/configure.php5

Add: (Note that only the last rule has no slash!)

--enable-soap
 
Save the file and rebuild PHP:

./build php all
 
 
For more information, please verify the url:  http://help.directadmin.com/item.php?id=252
    
 

Tuesday, December 27, 2011

How to change Nagious Password


root# touch /usr/local/nagios/sbin/.htaccess

root# vi /usr/local/nagios/share/.htaccess



And I wrote the follwing text in the .htaccess file


AuthName "Nagios Access"
AuthType Basic
AuthUserFile /usr/local/nagios/etc/htpasswd.users
require valid-user


Then, I did the following:


root# touch /usr/local/nagios/share/.htaccess

root# vi /usr/local/nagios/sbin/.htaccess


And I wrote the same text in that file too. Then, I did the following
 (Which is the command for changing the password ):
 
 
root# htpasswd -c /usr/local/nagios/etc/htpasswd.users nagiosadmin

New password:
Re-type new password:
Adding password for user nagiosadmin

root#&nbsp; ls -l /usr/local/nagios/etc/htpasswd.users
-rwxrwxr--&nbsp; 1 nagios nagios 26 Dec 21 15:54 /usr/local/nagios/etc/htpasswd.usersroot#

root# chmod o+r /usr/local/nagios/etc/htpasswd.users

root# service httpd restart

 
This steps will help you