Friday, March 9, 2012

How Do I Enable remote access to PostgreSQL database server

Step # 1: Login over ssh if server is outside your IDC

Login over ssh to remote PostgreSQL database server:
$ ssh user@remote.pgsql.server.com

Step # 2: Enable client authentication

Once connected, you need edit the PostgreSQL configuration file, edit the PostgreSQL configuration file /var/lib/pgsql/data/pg_hba.conf (or /etc/postgresql/8.2/main/pg_hba.conf for latest 8.2 version) using a text editor such as vi.

Login as postgres user using su / sudo command, enter:
$ su - postgres
Edit the file:
$ vi /var/lib/pgsql/data/pg_hba.conf
OR
$ vi /etc/postgresql/8.2/main/pg_hba.conf
Append the following configuration lines to give access to 10.10.29.0/24 network:
host all all 10.10.29.0/24 trust
Save and close the file. Make sure you replace 10.10.29.0/24 with actual network IP address range of the clients system in your own network.

Step # 2: Enable networking for PostgreSQL

You need to enable TCP / IP networking. Use either step #3 or #3a as per your PostgreSQL database server version.

Step # 3: Allow TCP/IP socket

If you are using PostgreSQL version 8.x or newer use the following instructions or skip to Step # 3a for older version (7.x or older).

You need to open PostgreSQL configuration file /var/lib/pgsql/data/postgresql.conf or /etc/postgresql/8.2/main/postgresql.conf.
# vi /etc/postgresql/8.2/main/postgresql.conf
OR
# vi /var/lib/pgsql/data/postgresql.conf
Find configuration line that read as follows:
listen_addresses='localhost'
Next set IP address(es) to listen on; you can use comma-separated list of addresses; defaults to 'localhost', and '*' is all ip address:
listen_addresses='*'
Or just bind to 202.54.1.2 and 202.54.1.3 IP address
listen_addresses='202.54.1.2 202.54.1.3'
Save and close the file. Skip to step # 4.


Step #3a - Information for old version 7.x or older

Following configuration only required for PostgreSQL version 7.x or older. Open config file, enter:
# vi /var/lib/pgsql/data/postgresql.conf
Bind and open TCP/IP port by setting tcpip_socket to true. Set / modify tcpip_socket to true:
tcpip_socket = true
Save and close the file.


Step # 4: Restart PostgreSQL Server

Type the following command:
# /etc/init.d/postgresql restart

Step # 5: Iptables firewall rules

Make sure iptables is not blocking communication, open port 5432 (append rules to your iptables scripts or file /etc/sysconfig/iptables):

iptables -A INPUT -p tcp -s 0/0 --sport 1024:65535 -d 10.10.29.50 --dport 5432 -m state --state NEW,ESTABLISHED -j ACCEPT
iptables -A OUTPUT -p tcp -s 10.10.29.50 --sport 5432 -d 0/0 --dport 1024:65535 -m state --state ESTABLISHED -j ACCEPT

Restart firewall:
# /etc/init.d/iptables restart

Step # 6: Test your setup

Use psql command from client system. Connect to remote server using IP address 10.10.29.50 and login using vivek username and sales database, enter:
$ psql -h 10.10.29.50 -U vivek -d sales
Saturday, March 3, 2012

Online Virus Scan URL

http://www.avg.com.au/resources/web-page-scanner/

http://sucuri.net

https://www.virustotal.com/
Monday, February 27, 2012

Linux virus scan

yum -y install gmp-devel
wget http://freshmeat.net/redir/clamav/29355/url_tgz/clamav-0.97.3.tar.gz
adduser -M -s /bin/false clamav
tar zxf clamav-0.97.3.tar.gz
cd clamav-0.97.3
./configure --prefix=/usr/local/clamav
make install
for binaries in `find /usr/local/clamav/bin/*` ; do ln -s ${binaries} /usr/bin/; done

Read more: http://crazytoon.com/2007/10/19/linux-virus-scan-how-do-i-check-my-linux-installation-for-viruses-using-clamav-centos-linux-redhat/#ixzz1nf1gPXFp

At this point Clam AntiVirus is installed and ready for use. Edit the configuration file and remove the line which says: Example It is there to ensure. If you want, you can look at other options but we don’t need to change anything else here to make ClamAV work for us.

vi /usr/local/clamav/etc/freshclam.conf #remove Example

Now let us run the freshclam which will download virus database and bring our virus database up to date. We should do this manually and make sure it didn’t give any errors. If this works, you will a lot of “downloading” messages.

/usr/bin/freshclam

If everything checks out, let us add this to our crontab to ensure our virus database is updated hourly. I chose to be updated every 9 minutes in to every hour. You can change to fit your needs or leave it as it is.

crontab -e

9 * * * * /usr/bin/freshclam –quiet

At this point our ClamAV virus database is up to date and now we can scan whichever directory we want. Go to the directory you want to scan and type:

clamscan -r -i

Once it is done scanning, it will display something similar to below.
-r parameter tells clamscan to recurse into directories
-i will print out infected filenames

Read more: http://crazytoon.com/2007/10/19/linux-virus-scan-how-do-i-check-my-linux-installation-for-viruses-using-clamav-centos-linux-redhat/#ixzz1nf1lINvr
Tuesday, February 21, 2012

Upgrade a WordPress Blog

SSH into the Linux server.

Change the directory to the blog directory.

Backup the MySQL database by running the following command substituting in your own information (where root is the MySQL root username and [databasename] is the actual WordPress database being used for the site):

mysqldump –u root –p [databasename] > [databasename].sql

Download the latest version of Wordpress by running this command:

wget http://wordpress.org/latest.tar.gz
Unzip the download.

tar -xzvf latest.tar.gz

Make a backup of your data just in case something goes wrong or if you have custom content where blogdirectory is the directory the blog is installed):

tar -czvf blog_backup.tgz blogdirectory/

Overwrite the files, thus upgrading the blog, by running this command (where blogdirectory is the directory the blog is installed):

yes | cp -r wordpress/* blogdirectory/

Now go to your blog admin section and verify everything is correct. You may be asked when viewing the admin section to upgrade the database. Click OK to do so.

Your blog is now upgraded to the latest version.
To password protect your website, please follow these steps:

Log into your Linux web server via Secure Shell (SSH).

Change into the directory you wish to password protect.

Note: If you wish to protect your entire website us the following command:

cd /vservers/username/htdocs

Create a file called .htaccess using the following command:

pico .htaccess

Enter the following information:

AuthType Basic
AuthName "Please enter your Username and Password"
AuthUserFile /vservers/username/htdocs/.htpasswd
AuthGroupFile /dev/null
Require valid-user

Press ctrl+o to save the file.

Press ctrl+x to exit the file.

Create the .htpasswd file using the following command:

/usr/bin/htpasswd -c /vservers/username/htdocs/.htpasswd username

Enter the password you wish to use.

Re-enter the password.

Grant read access to each file using the following commands:

chmod a+r .htaccess

chmod a+r .htpasswd
Create a notepad file and save it as .htaccess if you do not already have an existing one.

Update the .htaccess file with the following code and save; be sure to replace domain.com with your domain name.

RewriteEngine On

RewriteCond %{HTTP_HOST} ^domain.com [NC]

RewriteRule ^(.*)$ http://www.domain.com/$1 [L,R=301]

Upload the .htaccess file via ftp to the site root and now your traffic will be redirected to www.domain.com.

Configure NFS Server Shares

NFS, or Network File System, is a protocol for sharing and mounting remote file systems over a network.
Installation

To run an NFS server on Redhat or CentOS Linux, the systems package 'nfs-utils' must be installed. The 'yum' package manager can be used to ensure this is installed.

yum install nfs-utils
Configure Shares

NFS shares are created via the /etc/exports configuration file. To create a share you must specify a path to share, as well as a list of hosts to grant access and the type of access they should have. The path to share must be a full system path, and the list of hosts can be specified as a single host (IP, FQDN, or hostname), with wildcards (*.domain.com), IP networks (1.2.3.4/24), or netgroups.

For example, to share the directory '/data' with the host 10.10.1.5 (read-only) and the hosts within 10.10.1.15/29 (read-write), the following line would be added to /etc/exports.

/data 10.10.1.5(ro) 10.10.1.15/29(rw)

The list of access hosts must be separated with spaces, and no space must exist between the host address and the opening '(' of its options. If no options are specified, the host will have read only access. If options are specified without a host preceding it, they will be the share's default.

For a full list of options, please refer to the exports man page.

man exports
Starting the NFS Server

The NFS server is controlled with the service init script '/etc/init.d/nfs', or through the 'service' command. However before nfsd can run, the 'portmap' service must be running as well.

service portmap start
service nfs start

The NFS server will now be running, and shares (or 'exports') can be mounted by remote hosts that are given access. If the exports file is modified after the service is started, you can apply them with the command

exportfs -r

Also be sure to use the 'chkconfig' command to add both services to the system runlevel to run on startup.

chkconfig portmap on
chkconfig nfs on
Firewall notes

If your NFS server is behind a firewall (hardware or iptables), relative to the connecting hosts, the port "2049" must be opened for TCP and UDP.