Feed on
Subscription

How to configure Linux safety to serve government



A of any computer safety precautions important facet is to maintain what dominate a service actually to move.The article was revealed to you inLinuxOf the operating systemPCHow is safe service configured to manage on machine.

...

FreeBSD6.1 desktop installs a guideline



Catalog
1 regards his desktop as FreeBSD6.0
1.1 preface
1.2.1 cut pursues
1.3 installs FreeBSD---%26gt; join network is asked after installing FreeBSD (how does ADSL link a network?%26gt; join network is asked after installing FreeBSD (how does ADSL link a network?
1.4 installs X11
1.5 configures X11
The configuration of 1.5.1 mouse
1.6 installs desktop environment
1.6.1 enables GDM
1.6.2 begins to use GNOME
1.7 Chinese and font problem
1.7.1 sets style
1.8 installs an input method: SCIM
1.9 installs instant communication tool (include OICQ):gAim-openq
Adscript

Introductive

FreeBSD is one is based on 4.4BSD-Lite,Have a lot of extraordinary characteristic operating systems.Breathe out ah,The impression that Unix gives a person is a kind of OS that always applies at high-end server,The occurrence of FreeBSD makes Unix system also can run on the PC that is based on X86.The world that desktop system is like the Windows series that is M$ ,The popularity of Linux of the last few years also makes the system held kind of Unix partial desktop,What I want to say is,FreeBSD is the operating system that a desktop uses no less than Linux absolutely.This also is the account that I write this article.

Check scheme
=650) Window.open('http://www.bsdfree.org/images/Screenshot.png');" Src="http://www.bsdfree.org/images/Screenshot.png" Width=650 Onload="if(this.width>'650')this.width='650';" Border=0>

Install FreeBSD
Ask reference----%26gt; install FreeBSD%26lt;----Install FreeBSD to ask join network later, if be a server,You should configure a net to get stuck with Ifconfig directly,Relocate Rc.conf .(how can be Server used when the desktop to you?: -) ) if you do not know how to link a network,Please fast contact . with your ISP

How does ADSL link a network?

If you are ADSL user,So you are OK such:

1. configures network join
Configuration Ppp.conf
Log onto a system with Root identity first,Such:Because be ADSL,get online,Configuring a file is / the Ppp.conf below Etc/ppp,In / the likelihood below Etc/ppp had had Ppp.conf to have Ppp.conf.sample possibly also only, anyhow, I abandon using existing Ppp.conf to build from Ppp.conf.sample. Such you are OK doing: %26Nbsp;

...

How to choose fictitious memory way



The enterprise choice that how ? ? is you is right fictitious change memory way,The enterprise memory environment that which kinds of configuration fits you more?The article basically will pay close attention to lead plane environment to the lead plane below environment of bare perhaps chance stores or share memory.

...

The settlement of DOS incident method



0. analyses a process
Above all,Method of the type that analysed DOS, feature, attack.

Use Netstat -na | Grep SYN_RECV | Wc,Discovery is put in many SYN_RECV condition to join currently,Source address is forge,Netstat -na | Grep SYN_RECV | Wc shows the amount is 1024,This is of course,The Syn_Backlog with acquiescent Linux is to the row 1024,Exceeded SYN discarded.

The attack port that be aimed at is 80:WWW serves,Of course,Web server also cannot have been visited.

After opening SYN_Cookie to defend,Attack got a few alleviate,But subsequently attack discharge increased again,Circumstance it may not be a bad idea does not go where,And the Iptables of Linux cannot do Syn_proxy again,So be forced to do it from other side,Paid the data flow at that time with Tcpdump -w,Computation analysis discharge is controlled in 1.8w Pps about,Among them 99% above are the Syn bag that forges source address.

Since be to forge an address,That is more unmanageable,The statistic with careful nevertheless course and analysis,Still analyse the feature of main data in giving this attack,Basically have the following:

...

The UNIX that standardizes you commands a tool



Article introduction is used at standardizing an interface to be in in order to simplify different UNIX%26reg;The method that moves between the system.If you run a variety of UNIX systems (it is especially in different compose environment) ,The most formidable task may be between different environment switch carries out different job,Still must consider all difference between the system at the same time.The article does not introduce specific difference,Consider to be able to offer compatible layer however (or pack) in order to support the method of consistent environment.

...

System of file of Linux system daily record and function are analysed



The integrality that log file system can cut off the power in systematic happening or integral data assures when other system breakdown,Linux is one of operating systems with at present most system of supportive log file,The log file system that article key studied Linux is commonly used:EXT3, ReiserFS, XFS and JFS log technology,The test tool PostMark that uses a level and Bonnie++ had a test to them,Gave out detailed function is analysed,To Linux server application has fundamental referenced value.

One, overview
System of file of so-called daily record is on the foundation of traditional file system,The daily record that adds file system to change is recorded,Its design thought is:Dog the change that records file system,Record metabolic content the daily record.Log file system stores a log to record in disk partition,Keeping an operation is above all to recording a file to undertake operating,If whole because some is planted,keep an operation reason (if the system drops report) and interrupt,When the system restarts,Before can restore to interrupt according to log record keep an operation.In log file system,The change of all file systems is recorded to the log,At regular intervals,The metadata after the meeting will be newer and file content keep file system into disk.Making any changes to metadata previously,File system driver can write an entry to the middle of the log,This entry described it what to will do,Next its modification metadata.At present the log file system of Linux basically has:In the Ext3 that develops on Ext2 foundation,According to the ReiserFS that object-oriented thought designs,By the XFS that transplanting of SGI IRIX system comes over,By the JFS that transplanting of IBM AIX system comes over,Among them EXT3 is completely compatible EXT2,Its disk structure and EXT2 just the same,Just add log skill;After that system of three kinds of files used B extensively to cultivate in order to improve the efficiency of file system.

Two, Ext3
System of Ext3 file is direct develop from Ext2 file system and come,Ext3 file system is already special and at present stable reliable,It is completely compatible Ext2 file system,The user transfers smoothly the file system with sound function of a log.The thought of system of Ext3 log file undertakes to file system namely any advanced revise divide two paces to undertake.Above all,Wait for write piece a carbon is deposited in the log;Next,When the I/O number that should send past daily record is finished according to conveying (namely data submits a daily record) ,Piece keep file system.When the I/O number that should send past file system is stopped according to conveying (namely data refers file system) ,A carbon in the log be discarded.

2.1Ext3 log mode
Ext3 can make a daily record to metadata only already,OK also to the file at the same time data piece makes a daily record.Specific for,Ext3 is offerred the following mode of three kinds of logs:

Log (Journal)
Know exactly about sth of file system place is occupied and the change of metadata notes a daily record.This kind of mode decreased to lose every file place to make modification opportunity,But it needs a lot of additional disk to visit.For example,When a new document is founded,Its place data piece must duplicate to regard a log as the record.This is the safest with the slowest Ext3 log mode.
Book (Ordered)
Just note a daily record to the change of file system metadata only.However,Ext3 file system mixes metadata relevant data piece undertake in group,So that write metadata,data piece is written before disk.Such,The chance that can reduce the data inside the file to damage;For example,Ensure any writes a visit to get a daily record completely protection that increase a file.This is default mode of Ext3 log.
Write time (Writeback)
Just note a daily record to the change of file system metadata only;This is the method that discovers in system of other log file,Also be the fastest mode.

2.2 log piece equipment (JBD)
Itself of system of Ext3 file does not handle a daily record,Use log piece device however (Journaling Block Device) or the general kernel layer that calls JBD.Ext3 file system calls JDB exemple Cheng to be in in order to ensure system in case its follow-up operation when occurrence breakdown won't damage disk data structure.Between Ext3 and JDB be based on three main unit substantially interactively:The log is recorded,Atomic operation and general affairs.
The description that log record is the elementary operation that file system will give out substantially.In system of certain log file,The byte range that log record includes to operate place to revise only and byte are in the position of rest in file system.However,The whole buffer that the log record that JDB layer uses revises by elementary operation is comprised.This kind of means may waste space of a lot of logs (for example,A when change bitmap merely when elementary operation when) ,But,It is quite fast still,Because JBD layer is direct strong to buffer gentle area undertakes first times operating.
The system calls the either of modification file system to differentiate normally to operate a series of elementary operations of disk data structure.If these elementary operations return machine of accident without the whole system that finish delay,With respect to data of meeting attaint disk.To prevent data to damage,Ext3 file system must ensure every system moves means of atomic of in order to to undertake handling.A group of atomic operation is pair of disk data structures elementary operations,This group of elementary operations are corresponding a separate advanced operation.
The reason that stems from efficiency,JBD layer is used to the processing of the log in group method,In putting the log record that attributes processing of a few atomic operations in an alone general affairs in group namely.In addition,All log record related to a processing must be included in same a general affairs is medium.All log record of a general affairs is deposited in the log successive piece in.JBD layer comes to every general affairs handle as whole.For example,This office just reclaims to use when all data in should including the log in a general affairs to record only refer file system piece.

Three, ReiserFS
ReiserFS is a very excellent file system,Its developer has daring and resolution very much,Whole file system is completely design from the beginning.At present,The file system that ReiserFS can run about a hundred G easily,This is in company level application is very important.ReiserFS is the thought design with object-oriented basis,By semantic layer (Semantic Layer) and memory layer (Storage Layer) is comprised.The definition that semantic layer basically is the government that names a space to the object and object interface,In order to decide the function of the object.The management that stores the layer basically is pair of disk spaces.Semantic layer and memory layer are to pass key (Key) of connection.Semantic layer is passed undertake to object name analytic make key,Memory layer finds a target through key in space of the storage on disk,Key value is overall situation is unique.

3.1 semantic layer is main interface
Every file owns port of 1) file an interface ID,This ID marks collect of a method,All interface that this method collect includes file of visit ReiserFS.
ReiserFS of interface of 2) attribute realized a kind of new interface,The attribute of avery kind of the file should make a file,The content that the value of attribute is this file,Visit in order to come true to the catalog type of file attribute.
Catalog of 3) Hash interface is file name to the map watch of the file,ReiserFS is to pass B + tree to realize this piece of map to express.Because file name is,lengthen,And sometimes file name will be very long,So file name does not suit to regard key as the value,Reason introduced Hash function to produce key to be worth.
Interface of safety of 4) safe port handles all security to check,It is normally spark by file interface.It is with reading a document below exemple:The Read method of file interface can call the method of Read Chech of safe port to undertake security is checked before reading in file data, and so that check,the Read method that latter can call attribute file again reads in file attribute.
5) (Item) interface interface basically is a few pairs a method that has balancing handling,Include:fractionation,evaluate,Fu is written,increase,delete,Insert reach search.
6) key allocates (Key Assignment) interface should allocate a key when,Key allocation interface can be sparked.Avery kind of an as corresponding as its key allocates a method.
Layer of 3.2 memory
ReiserFS is with B+ the tree stores of data, if its structure pursues:



There is to call in each node in B+ tree (Item) data structure.It is container of a data,Belong to a node only,The main unit that is node management space.The place that be like a graph is shown,Include the following content:
1) Item_body:data region
2) Item_key:key value
3) Item_offset:The start of data region is measured in the deflection in node
4) Item_length:The length of data region
5) Item_Plugin_id:Interface ID.



A differs in order to store data that ReiserFS designed a variety of differring,Basically the following is plant:
1) Static_stat_data:Static statistic data,Those who include a file is possessory,Visit attributive,Found time,The closest modification time,Link number
2) Cmpnd_dir_item:Include each list
3) Extend_pointers:Point to dish of area (Extend)
4) Node_pointers:Point to a node
5) Bodies:Those who include is the fraction data of the file

3.3ReiserFS log
Like Ext3,ReiserFS also has pattern of three kinds of logs,Namely Journal, ordered, writeback.At the same time,ReiserFS introduced two kinds of logs to optimize a method:Copy-on-capture and Steal-on-capture.Copy-on-capture: ?ale of Ru of ? of a surname of contraction of money post Mou looks Xing of Duo of contraction of bad neon of Jiao of post Xin thorn protects firewood Zou a flat stone on iron rammer with ropes attached at the sides ? bucket Teal-on-capture of ? of excuse me of laborious of ? of ? of round ? of tip of besmear of contraction of Mou of reef of shelfing ? of ? of Jin of annulus of thick Bu of last of colour Sun Zhui putting in order climbing over a wall:Become piece when be being revised by many general affairs,That general affairs that refers the latest only just this piece keep file system actually,Other work does not write this piece.
Four, XFS
XFS is a kind of high-powered 64 file system,Develop to replace system of original EFS file by SGI company.Data of the consistency through maintaining Cache, fixed position and request of distributinging processing disk come to XFS the visit that offers the low defer of data, tall to file system bandwidth.At present SGI has transplanted XFS file system from IRIX Linux.
Group of 4.1 allocation (Allocation Groups)
When establishing system of XFS file,Equipment of ground floor piece is broken up eight or more the linear area with many equal size (Region) ,The user can imagine them " piece " (Chunk) or " linear limits (Range) " ,In XFS,Every area calls " of group of a " allocation.Allocate group it is exclusive,Because every allocate group of index node that manage his (Inode) with free space,It is actually allocate these group translate into subsystem of a kind of file,These subsystem transparently inside system of file of consist in XFS.Had allocate group,XFS code will allow many lines Cheng and process to move with collateral means continuously,Although they make multi-line Cheng and process mediumly carrying out large-scale IO on same document system,operate.Because of this,XFS and union of photograph of hardware of certain high end,Will obtain high-powered and won't make file system becomes bottleneck.Allocate group interiorly to use efficient B+ tree to dog main data,Have superior performance and huge but expansibility.
4.2 log is recorded
XFS also is system of file of record of a kind of log,Restore after it allows to guide afresh accidentally quickly.Like ReiserFS,XFS uses logistic daily record;It unlike Ext3 in that way literal file systematic piece records a daily record,What use a kind of efficient disk format to record metadata however is fluctuant.With respect to XFS character,Logistic log record is suit very much;On high-end hardware,The log often is the contention in whole file system.

Textual link:Http://www.linuxfans.org/nuke/modules.php? Name=Forums%26file=viewtopic%26t=167667

...

Linux system load is balanced group system solution



One, brief introduction of Linux fictitious server

The fictitious server of soft Linux in be based on (Linux Virtual Server,Namely LVS) it is a system of laden and balanced group that has tall usability characteristic.The laden capability that this system can provide the amount with server node, function to become direct ratio,The handling capacity that increases a service effectively, dependability, redundancy, adaptability,Performance/price ratio is high.At the same time,LVS also is to use low end the efficient way of function of server of equipment implementation high end.

...

How to change Linux code compulsively regularly




Countersign effectiveness for a given period of time is mechanism of a kind of system,Use at compulsive countersign to be after specific time length invalidation.To the user,This may bring a few troubles,But it ensured countersign can undertake changing regularly,It is a very good safety precaution.Below acquiescent circumstance,The Linux cent of great majority assembles version and did not open countersign effectiveness for a given period of time,Want to open nevertheless very simple however.

...

In Linux from conceal a password migratory to Tcb



The established fact level that locks a password to regard Linux as the product had had a lot of years,The use of Md5 password also is such.But,The conceals password method to also have inadequacy part of use tradition,Even Md5 also unlike is so safe before.

...

Encyclopedia of Linux group,Which kinds suit you?



Rawn Shah serves as an expert,The open source that has in Linux and close respect of source group solution shows a labyrinth for you.

The amount of project of the group in computational Linux is just like computation the amount that the company does poineering work in Silicon Valley is same.A block up of closed circuit condition that already endured its oneself unlike Windows NT,Linux has many group system to be able to offer an alternative,Agree with different utility and need.But the job that should use which group certainly did not become simple accordingly however.

...
« 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 »