顯示具有 指令用法 標籤的文章。 顯示所有文章
顯示具有 指令用法 標籤的文章。 顯示所有文章

2008年7月25日 星期五

ubuntu 裝置驅動資料收集

ubuntu 裝置驅動資料收集
$hwdb-gui -h
說明:之後會有一個gui介面的裝置驅動的硬體資料收尋,如果你希望把你的硬體資料提交給官方只要輸入幾項欄位即可,至於在網路上哪個位置我也不知道。

這是一個讓官方方便開發的方式之一。

來源:
/usr/share/doc/hwdb-client-common

不過這個命令似乎只適用於 ubuntu

2008年1月18日 星期五

使用chkrootkit系統安全工具

一個好用的安全性檢查工具 chkrootkit 執行它可快速檢查可疑的程序、後門、rootkit...等等,是一個非常有效率的安全管理工具。

至於如何執行它,我們通常就在終端機輸入像是這樣:
$sudo chkrootkit
可檢查可疑的二進位檔
$sudo chkrootkit -x |more
路徑內的系統命令
$sudo chkrootkit -x |egrep'^'

當發現系統已中rootkit木馬,這時就很難處理,因系統已無法信任得重新安裝系統。

更多的chkrootkit使用說明、訊息以及用法,在chkrootkit官方網站README這個網頁。

2007年11月23日 星期五

命令列資源

關於文字命令的使用都是許多新手共同的困擾,不過你也不必太擔心,因為網路上已經都替你準備好了!如果你有以下的問題像是系統管理類的命令有哪些呢?網路管理的命令又有哪些?檔案搜尋、管理、替換、輸入、輸出等又是哪些?about linux是一個非常棒的網站,它至少都替你準備好了,你甚至可以不用購買linux命令或unix命令之類的書,但你得有網路,或是你已經把它們整理好印出來了,否則像是命令的屬性及語法等等都已經給你參考,只差會不會應用了!

書籍方面小弟有一本《LINUX IN A NUTSHELL指令參考手冊》由台灣歐萊禮出版,或許是本不錯的選擇,但缺點在書籍排版上很不容易找到要找的命令。

提供一些關於linux commands的網站
linux系统管理命令集
http://os.51cto.com/art/200512/14196.htm

LinuxCommand.org
http://linuxcommand.org/index.php

Alphabetical Directory of Linux Commands
http://www.linuxdevcenter.com/linux/cmd/

2007年11月19日 星期一

Firxfox
Firefox on Linux
http://wiki.moztw.org/index.php/Firefox_on_Linux

設定檔詳解
http://wiki.moztw.org/index.php/%E8%A8%AD%E5%AE%9A%E6%AA%94%E8%A9%B3%E8%A7%A3

如何撰寫install.rdf
http://wiki.moztw.org/index.php/%E5%A6%82%E4%BD%95%E6%92%B0%E5%AF%ABinstall.rdf

解決Firefox耗用資源的對策
http://wiki.moztw.org/index.php/%E5%B9%AB%E4%BD%A0%E7%9A%84Firefox%E6%B8%9B%E6%B8%9B%E8%82%A5-%E8%A7%A3%E6%B1%BAFirefox%E8%80%97%E7%94%A8%E8%B3%87%E6%BA%90%E7%9A%84%E5%B0%8D%E7%AD%96


WN Server應用手冊(英)
User's Guide for the WN server
http://hopf.math.northwestern.edu/docs/complete.html
架設快取等本機網路服務,如proxy server

Linux系統規格
About the Linux Standard Base (LSB)
http://www.linux-foundation.org/en/LSB
linux基礎標準規格

iptables manpage 中譯
http://linux.tnc.edu.tw/techdoc/firewall/iptables-manpage.html

Ubuntu Security
http://ubuntuforums.org/showthread.php?t=510812

IRC 幫助(英)
IRC clients primarily for the Unix shell
http://www.irchelp.org/irchelp/ircii/

IRC FAQ 中文版
http://my.freebsd.org.hk/html/wwwfaq/document/ircfaq/index.htm

TCP/IP規格
RFC 1413 - Identification Protocol
http://www.faqs.org/rfcs/rfc1413.html
clone process的防範

如何編譯內核
http://www.study-area.org/linux/linuxfr1.htm

UNIX 高手的 10 个习惯
http://www.unixreference.net/articles/misc/2007/0304/633.html

使用者及使用者群組概念

以下是小弟讀《UNIX與INTERNET安全防護-系統篇》由台灣歐萊禮出版之筆記。

UNIX(clone) system 大部分有兩種形式的存取控制分別是:

第一種所謂的強制性存取控制(Mandatory Access Controls,MAC)它以資料標籤為基礎。
第二種為隨意存取控制(Discretionary Access Controls,DAC)。

多個帳號使用相同的UID(使用者識別碼)情況:

  1. 登入UUCP系統,這種方法可以讓你追蹤各個不同站台的登入活動,且仍允許他們存共享的檔案。
  2. 希望不同使用者都可存取root權限以追蹤使用者情形,可以在不影響其他使用者的情況下,關閉其中一個帳戶的存取權限。


wheel群組是表示所有系統管理者所屬的群組,而UNIX是以GID(群組識別碼)來進行權限設定。例如當你需要blogger群組的權限可以利用
$newgrp blogger
切換群組來暫時獲得該群組所有權限。

在使用su命令時我們必須小心,請確認切換的目錄以及路徑。例如當我們在建構程式、測試、及個人的清理工作應該以個人的身份來完成,而非自己的身份下應該切回原本的身份。

一台機器上同時有好幾位使用者帳號,我們應該適當的給與其管理權限以及限制su的轉換,否則當使用者有了root密碼它可以隨時利用su來轉換成root。而某些su版本允許wheel或uid為0的成員,利用自己的密碼成為超級使用者,只要把某位使用者給移出此群組就可以取消他們的存取權限。

這是一個列出使用者嘗試su轉換身份而失敗的log
$grep BAD /var/adm/messages
這是一個正常的su嘗試
$grep + /var/adm/sulog
BSD版本的sulog
$grep su: /var/adm/messages

另外,每位使用者都各有一個主要群組。
相關的命令包含:sulog、groups、id、gksu、su等等。
相關的檔案位置:/etc下的login.defs、passwd、group、adduser.conf、etc/pam.d

2007年11月17日 星期六

ircII命令

雖然做翻譯對小弟來說根本是件不可能的事,但真的沒辦法了,因為想使用irc的關係,非得為自己整理一下翻出來的結果不可,因此這份文件充其量只是自己日後使用上得參考資料罷了!

翻譯真的很耗時,尤其親身靠工具及辭典翻譯後感受更深。向那些為使用者辛苦執行翻譯工程的人員,至上萬分敬意。

花了約5個小時時間耗在這份翻譯文件上,好不容易翻好了卻是我要睡得時候了。

這份在man上的說明文件很長,小弟只是想把它翻譯一下方便使用,如有侵權小弟馬上刪除。

Ubuntu使用者可以在套件管理程式取得ircII的套件。
因小弟英文能力非常破,使用的工具是google 翻譯及一些手邊上的英漢字典,如語意翻得不正確敬請糾正^^

以下原文譯自ircII命令說明(請參考man irc)


ircII命令
NAME
ircII - interface to the Internet Relay Chat system

ircII 網際網路即時聊天系統介面

語法
irc [-c chan] [-p portno] [-P portno] [-b] [-f] [-F] [-s] [-S] [-t]
[-T] [-d] [nickname [server list]] [-a] [-v] [-q] [-h hostname ] [-icb]
[-irc]

描述
The ircII program is a full screen, termcap based interface to Internet
Relay Chat. It gives full access to all of the normal IRC functions,
plus a variety of additional options.

該ircii計劃是一個全屏幕, termcap支援基礎的界面,以互聯網
即時聊天。它給人充分接觸到所有正常存取的功能,
再加上各種附加選項。

選項

-c chan
Automatically join channel chan .

自動加入頻道chan。

-p portno
Set the IRC port number to portno (default: 6667, the standard
IRC port). Only supply this if you connect to a server which
uses a port other than 6667.

設定irc port編號到portno(預設是:6667,是一個標準的irc port)只有供應這個,如果 您連接到一台服務器,其中
利用port以外的6667 。

-P portno
Set the ICB port number to portno (default: 7326, the standard
ICB port).

設定一個ICB port編號到portno(預設是:7326,是一個標準的icb port)。

-b
Load the .ircrc file before connection to a server, not after-
wards.

載入.ircrc檔案之前存取一個伺服器,而不是事後產生。

-f
Use flow control (^S and ^Q) to stop/start the display. Nor-
mally these are both bound to other functions within irc. This
switch is ignored if the -d switch is used.

使用流量控制( ^ s和^ q )的停止/開始顯示。也不是通常這些都勢必給其他職能irc。這
開關被忽略,如果使用-d交換機。

-F
Don't use flow control (^S and ^Q) to stop start the display.
This switch is ignored if the -d switch is used.

不要使用流量控制( ^ s和^ q )的停止開始顯示。這個開關被忽略,如果使用-d交換機。

-s
Don't start up the ircio process to connect to the IRC server
(default).

不啟動ircio進程以連接到irc服務器(預設) 。

-S
Start up the ircio process to connect to the IRC server.

開始ircio進程,以連接到irc服務器。

-t
Don't use the termcap ti and te sequences when starting and
exiting (default).

當開始和離開(預設)不使用termcap ti和te序列。

-T
Do use the termcap ti and te sequences when starting and exiting
if they exist.

如果它們存在的話,不使用termcap ti和te序列時進出。

-d
Start in "dumb" mode. All input is taken directly from stdin
and all output goes to stdout without using any of the term-
cap(5) screen control codes.

開始,在"啞巴"的模式。所有進來是採取直接從stdin和所有輸出到標準輸出無需使用任何的termcap 螢幕控制碼。

nickname
Set the nickname (overrides the environment variable IRCNICK;
default: the username).

設定暱稱(凌駕於環境變量ircnick ;預設:用戶名) 。
server
Set the list of servers with which irc will try to connect upon
startup. This list is also used by the program's /server com-
mand. The format for lines in the list is:

設定服務器名單與irc嘗試連接後開機,這份名單也用該節目的/服務器組件mand 。格式行中的名單是:
hostname [:portno[:password[:nick]]]
for IRC connections. For
ICB connections, the format is:

對於IRC連接為ICB連接,格式是:
ICB/hostname [:portno[::nick[:group[:mode]]]]
with group being
the initial group and mode being the initial group mode. See
/HELP ICB for more information about ICB.

與群組正在初次組 初次組和模式正初步集團模式。見
/HELP ICB for more information about ICB.

If the hostname is in the format :servergroup:host.com then
servergroup is taken to be the Server Group for this server
entry.

如果主機是這個格式: servergroup : host.com則servergroup是不會採取該服務器組,為這個服務器進入。

-a
This adds the normal irc server list to the command line list of
irc servers.

這是增加一個普通irc服務器清單到命令列的irc servers。
-v
Print the version and release date of ircII and exit.

印出版本和發佈日期在ircii和離開。
-q
Start up irc quickly -- don't load the IRCRC file.

快速啟動irc-不載入IRCRC檔案。
-h hostname
This option instructs ircII to use the given hostname as the
local address. Useful only on multi-homed hosts.

這個選項指示ircll使用特定主機作為本地地址。只有在多元主機上有用(Useful only on multi-homed hosts.)
-icb
Use ICB connections by default.

預設使用ICB連接。
-irc
Use IRC connections by default.

預設使用IRC連接。

詳細描述
屏幕上:
The screen is split into two parts, separated by an inverse-video sta-
tus line (if supported). The upper (larger) part of the screen dis-
plays responses from the IRC server. The lower part of the screen (a
single line) accepts keyboard input.

Some terminals do not support certain features required by ircII, in
which case you receive a message stating this. If this occurs, try
changing the terminal type or run ircII with the -d option.

畫面上是分割成兩部分,分別相隔一個inverse-video 、狀態列(如果支持) 。上(較大)螢幕顯示反應從irc服務器,螢幕下方部分(一條單線)接受鍵盤輸入。

有些終端不支持某些功能所需要的ircll ,這種情況下您收到訊息說明這一點。如果有這種情況,嘗試改變終端類型或運行ircll與-d選項。

IRC的命令:
Any line beginning with the slash character '/' is regarded as an ircII
command (the command character may be changed; type '/help set cmd-
char'). Any line not beginning with this character is treated as a
message to be sent to the current channel. To produce a listing of
commands, type '/help ?'. To receive information about the commands
type '/help '.

任何列開始與斜線字元'/'被視為一種ircll命令(命令字元可以改變);樣式'/help set cmdchar').
任何時候在命令列開始輸入訊息,如果輸入'/'則不當作訊息也不會送到頻道上。製作一個命令可以輸入'/help ?'查詢某個命令則輸入'/help <命令> '.

The .ircrc File:
When ircII is executed, it checks the user's home directory for a
.ircrc file, executing the commands in the file. Commands in this file
do not need to have a leading slash character '/'. This allows predef-
inition of aliases and other features.

當ircll執行時,為它檢查用戶的主目錄。 .ircrc文件,執行該命令文件。命令在此檔案不需要有一個斜線字符' / ' 。這使得predef -inition的別名以及其它的功能。

範例
irc -c #users -p 5555
Connect IRC to port number 5555 of the default host and enter on
channel #users.

連接IRC,以端口號5555的默認主機進入到頻道#使用者。

irc Mermaid
Use the nickname "Mermaid".

使用暱稱"美人魚" 。

irc Mermaid server1:5000 server2::passwd server3
Use the nickname "Mermaid" and the modified server list.

使用暱稱"美人魚"和修改服務器列表。

irc piglet3 :ln:irc1.lamenet.org :ln:irc1.lamenet.org
Use the nickname "piglet3", initially connecting to
irc.au.lamenet.org, with also irc.us.lamenet.org added to the
server list, both having a server group name "ln".

使用綽號" piglet3 " ,最初連接 irc.au.lamenet.org ,然後irc.us.lamenet.org添加到服務器列表,兩個服務器群組都有名稱"ln " 。

irc oink ICB/www.icb.net
Use the nick "oink" making an ICB connection to www.icb.net.

使用nick" oink " ,用ICB連接到www.icb.net 。

irc -d Use dumb mode.

irc -f Allow use of ^S/^Q to stop/start screen display.

irc -e elisa
Interface IRC with a program called elisa.

irc介面呼叫elisa程式

setenv IRCNICK Mermaid

setenv IRCNAME "The one and only :)"

irc
Set the username (if not specified elsewhere) to "Mermaid". The
user's name (when provided inside parentheses in response to a
WHOIS command) is set to "The one and only :)".

設置用戶名(如果沒有指定其他地方) ,以"美人魚" 。該用戶的名稱(當提供的括號內,在回應一位whois查詢命令)設置為"唯一和只有: ) " 。

檔案
/usr/bin/ircII
the executable program

可執行程序

~/.ircrc
default initialization file

預設初始檔

~/.irc/
directory you can put your own ircII scripts
into, that can then be loaded with /load

你能夠把你自己的ircii腳本再裝載/負載到目錄。

/etc/irc/
directory containing message-of-the-day, master
initialization, help files and ircII scripts
/etc/irc/script/local is the master initializa-
tion file for the site, loaded before .ircrc is.
This is a Debian GNU/Linux conffile.
/usr/share/ircII/ shared repository for help,
translation tables and distributed scripts.

目錄中包含每天的信息,管理者初始化,幫助文件和ircii腳本在 /etc/irc/script/local 是網站管理者initializa-tion檔案是.ircrc裝載前 。這是一個在Debian GNU/Linux conffile.
/usr/share/ircII/ 共享知識庫幫助文件、翻譯表,和分發腳本。

幫助檔案
All of the ircII commands are fully described in the help files pack-
age. The best way to start here is with the /HELP ? command as this
prints a listing of all available help files.

所有的ircii命令,全面敘述了在幫助文件包-
年齡。最好的方式,開始在這裡是同/HELP?命令,因為這
版畫列出所有可用的幫助文件。

信號
ircii
handles the following signals

處理以下信號

SIGUSR1
Closes all DCC connections and EXEC'ed processes.

關閉所有DCC的連接與EXEC'ed進程。

SIGUSR2
Drops ircII back to the command line.

放棄ircii回到命令列。

環境變數
It can be helpful to predefine certain variables in in the .cshrc,
.profile, or .login file:

它有助於預先為某些變數。 在.cshrc、.profile或.login文件:

IRCNICK
The user's IRC nickname.

用戶的IRC暱稱。

IRCNAME
The user's IRC realname (otherwise retreived from /etc/passwd)

用戶的IRC realname (否則retreived / etc / passwd中)

IRCSERVER
The default IRC server(s) (see server option for details)

預設的IRC服務器 (見服務器選擇詳情)

IRCSERVERSFILE
The file containing the default list of server(s), usually PRE-
FIX/lib/irc/ircII.servers. This file should contain one server
entry per line.

該文件包含預設的名單服務器,通常為PRE-FIX/lib/irc/ircll.servers 。這個文件應該包含一個服務器進入每條線。

HOME
Overrides the default home path in /etc/passwd.

Overrides預設主頁路徑/ etc / passwd中。

TERM
The type of terminal in use.

使用的終端機類型。

檔案
uses the following files under the library directory, usually
PREFIX/share/irc.

ircll通常使用的函式庫在下列目錄,PREFIX/share/irc.
ircII.servers
The initial list of servers if none are provided on the command
line.

初步名單上的服務器,如果沒有提供一個命令列。
ircII.motd
Message of the day. This file is displayed only once each time
it is changed.

當天的訊息,這個檔案只會顯示一次,每次隨著時間而改變。

相關命令見
ircd


AUTHORS
Program written by Michael Sandrof (ms5n+@andrew.cmu.edu). Now being
maintained by Matthew Green (mrg@eterna.com.au). Debian specific exten-
sions by the Debian Maintainer Bernd Eckenfels (ecki@debian.org).
Names of contributors and contact address can be retrieved with the
/info command. This manual page written by Darren Reed
(avalon@coombs.anu.EDU.AU), revised by R. P. C. Rodgers
(rodgers@maxwell.mmwb.ucsf.edu), by the lynX, and by Matthew Green
(mrg@eterna.com.au).

2007年11月15日 星期四

recovery mode取回sudo

呼,小弟在linux上root權限因之前不夠謹慎的原因,而失去sudo的權限完全不能管理系統,該事件顯得很不安全因為如此的話既不能做系統的安全更新,而只有一般使用者的權限是根本不能管理系統的,舉凡更改檔案權限等。

事件說明
小弟在使用者及使用者群組管理工具中(user-admin)把管理此系統的權限取消,而把管理此系統的權限在root帳戶上打勾,也就因為這樣的操作失去了sudo的權限,在當初是萬萬沒有料到的,因為我是在想既然root才能管理系統,為何預設沒有把管理此系統給選上呢?

現在小弟明白了,呼,真是有驚無險阿!

解決的方法是在這份網頁上找到的
如何救回root帳戶呢?
沒錯,就是救回。如果你已失去root管理權限,在該系統是完全沒辦法修改的,因為你沒有root群組的權限,所以怎麼想辦法也是沒用的,只能在開機時進入救援模式(文字命令)。


步驟
開機時來到了grub介面,但你得按下「Esc」才能與它相見,這時你應該會看到「kernel 版本 recovery mode」,選擇它即啟動文字介面系統。這時你會發現你已經是root了 root#

那有了root後就好辦事,依序輸入以下命令(/為命令說明/)
root#cp /etc/group /etc/group.old
/複製舊有的群組文件/

root#nano /etc/group
/如果這時你想直接修改群組文件的話/

root#cp /etc/sudoers /etc/sudoers.old
/複製sudoers舊有文件/

root#sudo visudo
/修改sudoers文件,應該在該文件寫入「username ALL=(ALL)ALL」這樣一來才能使用sudo命令。/

root#nano /etc/group
/加入group/

root#chmod 0440 /etc/sudoers
/修改權限/

root#reboot
/重新啟動/

相關文章
root帳戶驗證失敗

2007年11月14日 星期三

accept命令

accept命令
名稱
accept/reject-接受/拒絕傳送目的地

內容提要
accept[-E] [-U 用戶名] [ - h主機名[ :port]目的地
reject[-E] [-U用戶名] [ - h主機名[ :port] [ - r原因] 目的地

描述
接受指示printing system到接受到特別的檔案目的地。

拒絕指示印刷系統拒絕列印作業向特別檔案目的地。一個 - r參數設 定為原因,拒絕列印作業。如果沒有指定之所以默認為"原因不明" 。


選項
下列選項都支持接受及拒絕:

-E
Forces加密當連接到服務器上。
-U 用戶名
設定使用者名稱那是傳送至連接的服務器上
-H 主機名[:port]
選擇一個候補服務器
-r 原因
設定一個字符串那將顯示在拒絕的工作

兼容性
不像System V印刷系統,CUPS允許印表機名稱,包含任何可打印 的字符,除了空格、tab、 " / " ,或" # " 。此外,印表機和類別名是不區分大小寫的。

CUPS版本的接受和拒絕可能會要求使用者給一個存取密碼通道
取決於印刷系統的配置。這有別於從System V版本,其中規定root用戶執行這些命令。

看更多
cancel(1), cupsenable(8), lp(1), lpadmin(8), lpstat(1),


版權說明
由Apple Inc所有

使用方法
$man accept

心得
這項命令小弟目前還在學習中,因此還不太會使用,大概翻了一下英文意思翻得不好請見諒^^
如果系統預設已有CUPS套件你應該可以在本地端透過瀏覽器配置它。

2007年11月7日 星期三

Continuation study
The First Ten Steps to Securing a UNIX Host
http://people.arsc.edu/~lforbes/cug/HHPaper.html
http://www.linux-sec.net/hacking_tools.gwif.html
http://wiki.linuxquestions.org/wiki/Security

$lastlog -b 6
顯示過去6天以來系統login資訊

freecdb
可以自己建立一個屬於自己的搜尋引擎、用戶端的個人資料庫套件

如果遇到不能更新套件時,可使用文字命令
sudo apt-get -f -y upgrade
意思就是遇到錯誤也繼續升級

sudo apt-get -f -y dist-upgrade
遇到錯誤也繼續版本升級

sudo dpkg --configure -a

MS06-001駭客實作-01
http://tw.youtube.com/watch?v=DT7SUka7J-s

Hacker TV
http://www.youtube.com/watch?v=QgMOSB5yg_4

Pizza Party (Unix)
http://www.youtube.com/watch?v=x7pPajOvQGo
這是真的嗎?還是噱頭?

LPI - Exam Emulation
http://www.linux-praxis.de/lpisim/lpi.html

banner命令

在Linux命令列輸入$banner yugu會產生以#字符號輸出的yugu圖案,並可以把它列印出來,只要加個lpr就會送到佇列區等待列印。
但只能產生大型的文字圖案,並不能產生叫小型的,輸出選項有個寬度可以設定當字符產生時是橫向的,因此不適合當作是簽名檔,適合拿來當寬度較寬的banner海報。

banner命令是bsd授權版

2007年11月6日 星期二

ARP study

什麼是ARP呢? http://tw.trendmicro.com/tw/support/tech-support/board/tech/article/20070926085046.html

ARP概念
http://www.inetdaemon.com/tutorials/lan/arp.shtml
http://forum.icst.org.tw/phpBB2/viewtopic.php?t=12710

perl spider http://www.google.com.tw/search?complete=1&hl=zh-TW&sa=X&oi=spell&resnum=0&ct=result&cd=1&q=perl+spider&spell=1

arp man
http://spectral.mscs.mu.edu/NetworksClass/Materials/arp.html

ARP cache命令列使用
-v 詳細模式
-t 類型 ether or ax25
-a 顯示主機項目
-d 移除主機項目
-s 新增一筆主機硬體位址也就是MAC ADDRESS
-f 從檔案讀取並新增至ARP cache

管理arp的套件有arpalert、arping、arp-scan、arptables、arpwatch、farpd、nemesis等

2007年8月6日 星期一

變換來源清單的方法

變換來源清單的方法
using the following command:

echo 'deb http://archive.ubuntu.com/ubuntu/gutsy main restricted' | sudo tee -a /etc/apt/sources.list
sudo apt-get update

if you want to upgrade kernel via here

我的儲藏庫

適用系統版本:
Ubuntu-feisty

服用方式:

sudo gedit /etc/apt/sources.list

把以下清單貼上並儲存後離開。

從底下開始拖拉
# Trevi隳's Ubuntu Feisty Fawn Sources list
# http://3v1n0.tuxfamily.org/blog/?page_id=13
#
# Repository List based on standard feisty with many extra packages
#
# If you get errors about missing keys, lookup the key in this file
# and run these commands (replace KEY with the key number):
#
# gpg --keyserver subkeys.pgp.net --recv KEY
# gpg --export --armor KEY | sudo apt-key add -
#
# If you have a gpg key URL use (replace URL with the key address):
#
# wget URL --quiet -O - | sudo apt-key add -
#
# If you have a gpg key file use (replace FILE with the key file):
#
# sudo apt-key add FILE
#
# In the repository list page there's also a script that can do this
# work automatically, this is suggested only if you know what you're doing

# Ubuntu supported packages (GPG key: 437D05B5)
deb http://archive.ubuntu.com/ubuntu feisty main restricted
deb http://archive.ubuntu.com/ubuntu feisty-updates main restricted
deb http://archive.ubuntu.com/ubuntu feisty-security main restricted
deb-src http://archive.ubuntu.com/ubuntu feisty main restricted
deb-src http://archive.ubuntu.com/ubuntu feisty-updates main restricted
deb-src http://archive.ubuntu.com/ubuntu feisty-security main restricted

# Ubuntu community supported packages (GPG key: 437D05B5)
deb http://archive.ubuntu.com/ubuntu feisty universe multiverse
deb http://archive.ubuntu.com/ubuntu feisty-updates universe multiverse
deb http://archive.ubuntu.com/ubuntu feisty-security universe multiverse
deb-src http://archive.ubuntu.com/ubuntu feisty universe multiverse
deb-src http://archive.ubuntu.com/ubuntu feisty-updates universe multiverse
deb-src http://archive.ubuntu.com/ubuntu feisty-security universe multiverse

# Ubuntu backports project (GPG key: 437D05B5)
deb http://mi.mirror.garr.it/ubuntu feisty-backports main restricted universe multiverse
deb-src http://mi.mirror.garr.it/ubuntu feisty-backports main restricted universe multiverse

# Bleeding edge wine packages (GPG key: 387EE263)
# GPG key-file: http://wine.budgetdedicated.com/apt/387EE263.gpg
deb http://wine.budgetdedicated.com/apt feisty main
deb-src http://wine.budgetdedicated.com/apt feisty main

# Seveas' packages (GPG key: 1135D466)
# GPG key-file: http://mirror.ubuntulinux.nl/1135D466.gpg
deb http://mirror.ubuntulinux.nl feisty-seveas all
deb-src http://mirror.ubuntulinux.nl feisty-seveas all

# The Opera browser (packages) (GPG key: 6A423791)
deb http://deb.opera.com/opera etch non-free

# Google picasa packages (GPG key: 7FAC5991)
deb http://dl.google.com/linux/deb/ stable non-free

# Medibuntu (Multimedia, Entertainment & Distraction In Ubuntu - ex Penguin Liberation Front)
# GPG key-file: http://medibuntu.sos-sts.com/repo/medibuntu-key.gpg
deb http://medibuntu.sos-sts.com/repo/ feisty free non-free
deb-src http://medibuntu.sos-sts.com/repo/ feisty free non-free

# The repository from Kubuntu Germany
# GPG key-file: http://archive.czessi.net/ubuntu/kczessi.gpg
deb http://archive.czessi.net/ubuntu feisty main restricted universe multiverse preview
deb-src http://archive.czessi.net/ubuntu feisty main restricted universe multiverse preview

# Ubuntu feisty University Klagenfurt packages
# GPG key-file: http://ubuntu.uni-klu.ac.at/uniklu-debuild.pub
# $ sudo apt-key add uniklu-debuild.pub
# uniklu: backports and new packages
# uniklu-intern: not freely redistributable (jvm), or modified packages
# uniklu-testing: packages not ready for general use
deb http://ubuntu.uni-klu.ac.at/ubuntu.uniklu/ feisty uniklu
deb http://ubuntu.uni-klu.ac.at/ubuntu.uniklu/ feisty uniklu-intern
deb-src http://ubuntu.uni-klu.ac.at/ubuntu.uniklu/ feisty uniklu
deb-src http://ubuntu.uni-klu.ac.at/ubuntu.uniklu/ feisty uniklu-intern

# MythTV Repository for Ubuntu Linux (GPG key: 80DF6D58)
deb http://home.eng.iastate.edu/~superm1 feisty all
deb-src http://home.eng.iastate.edu/~superm1 feisty all

# Tvfreeplayer Packages (GPG key: )
# GPG key-file: http://www.tvfreeplayer.com/linux/falcon/tvfreeplayer.gpg
deb http://www.tvfreeplayer.com/linux/falcon feisty all
deb-src http://www.tvfreeplayer.com/linux/falcon feisty all

# gnomemeeting - ekiga (GPG key: 52ABFCB1)
deb http://snapshots.ekiga.net/ubuntu/ feisty main
deb-src http://snapshots.ekiga.net/ubuntu/ feisty main

# Debuntu Ubuntu feisty packages
# GPG Key: http://repository.debuntu.org/GPG-Key-chantra.txt
deb http://repository.debuntu.org/ feisty multiverse
deb-src http://repository.debuntu.org/ feisty multiverse

# Morgoth Repository (GPG key: 7E2E4741)
# Provides Monkey's Audio, xmms pugins, vlc plugins, gqview, audacius, audacity...
# GPG key-file: http://morgoth.free.fr/files/morgoth-signkey.gpg.asc
deb http://morgoth.free.fr/ubuntu feisty-backports main
deb-src http://morgoth.free.fr/ubuntu feisty-backports main

# Musicbrainz Repository
# GPG key-file: http://ftp.musicbrainz.org/pub/musicbrainz/users/luks/public.key
deb http://ftp.musicbrainz.org/pub/musicbrainz/users/luks/ubuntu feisty musicbrainz
deb-src http://ftp.musicbrainz.org/pub/musicbrainz/users/luks/ubuntu feisty musicbrainz

# The Ubuntu NLP Repository (GPG key: 8ABD1965)
# GPG key-file: http://cl.naist.jp/~eric-n/ubuntu-nlp/8ABD1965.gpg
deb http://cl.naist.jp/~eric-n/ubuntu-nlp feisty all
deb-src http://cl.naist.jp/~eric-n/ubuntu-nlp feisty all

# Ubuntu System Administrator packages (GPG key: 2F306651)
# GPG key-file: http://ubuntu.moshen.de/2F306651.gpg
deb http://ubuntu.moshen.de feisty multimedia misc
deb-src http://ubuntu.moshen.de feisty multimedia misc

# The Consciousness Repository (GPG key: DD385D79)
# GPG key-file: http://debs.peadrop.com/DD385D79.gpg
deb http://debs.peadrop.com feisty all
deb-src http://debs.peadrop.com feisty all

# IVTV Repository for Ubuntu Linux (GPG key: 80DF6D58)
# GPG key-file: http://dl.ivtvdriver.org/ubuntu/80DF6D58.gpg
deb http://dl.ivtvdriver.org/ubuntu feisty all
deb-src http://dl.ivtvdriver.org/ubuntu feisty all

# syzygy42 repository: avant-window-navigator, exaile, closure... (GPG key: 8434D43A)
# GPG key-file: http://download.tuxfamily.org/syzygy42/8434D43A.gpg
deb http://download.tuxfamily.org/syzygy42/ feisty all
deb-src http://download.tuxfamily.org/syzygy42/ feisty all

# FoLKeN 'Repozytorium' (GPG key: 6FB65A0F)
deb http://deb.svx.pl/ feisty main universe bleeding
deb-src http://deb.svx.pl/ feisty main universe bleeding

# Le d廧omaniak repository (GPG key: 1D59E694)
# GPG key-file: http://ubuntu.davromaniak.eu/1D59E694.gpg
deb http://ubuntu.davromaniak.eu feisty-depomaniak all
deb-src http://ubuntu.davromaniak.eu feisty-depomaniak all

# Mez's Repository (GPG key: 6AAAA569)
# GPG key-file: http://apt.sourceguru.net/6AAAA569.gpg
deb http://apt.sourceguru.net feisty all
deb-src http://apt.sourceguru.net feisty all

# Ryan Kavanagh's packages (GPG key: 02544D0E)
# GPG key-file: http://packages.ryanak.ca/02544D0E.gpg
deb http://packages.ryanak.ca ryan-feisty all
deb-src http://packages.ryanak.ca ryan-feisty all

# Trevi隳's Ubuntu Feisty Fawn Repository (GPG key: 81836EBF - DD800CD9)
# Many "random" bleeding edge software: aMule, aMSN, Mercury, flash...
# Further informations and complete packages list: http://3v1n0.tuxfamily.org
deb http://download.tuxfamily.org/3v1deb feisty 3v1n0
deb-src http://download.tuxfamily.org/3v1deb feisty 3v1n0
拖拉結束,貼上於文本後save file and exit.

關於gpg key command:
gpg --keyserver hkp://subkeys.gpg.net --recv-keys [key id]
gpg --export --armor [key id] | sudo apt-key add-

更新來源:
sudo apt-get update

升級軟件包:
sudo apt-get upgrade

更新版本:
sudo apt-get dist-upgrade

移除所有套件站存檔:
sudo apt-get clean

移除所有舊版套件站存檔:
sudo apt-get autoclean

以上知識來自於internet

2007年7月12日 星期四

tripwire系統稽核工具

tripwire 簡易安裝指南
http://www.rtfiber.com.tw/~changyj/linuxtips/html/tripwire-easy.html
系統稽核工具

Tripwire安裝
http://blog.longwin.com.tw/archives/000005.html

Tripwire 系統指紋比對系統!
http://www.adj.idv.tw/phpBB2/viewtopic.php?p=189&sid=88053850eb56956b56f49cc4348734fe


Learning Notes:
ubuntu套件管理程式搜尋tripwire,安裝過程設置密碼分別為:
site pass phrase(加密twpol.txt及twcfd.txt用);
另一個密碼選項是local pass phrase(加密指紋資料庫用)
兩個密碼選項共輸入兩次加以確認。

twcfg.txt:可用來設定tripwire工作環境
twpol.txt:指定tripwire對哪些檔案進行監控

DBFILE為指紋資料庫檔名
REPORTFILE為檢測報告檔

以下以root終端為例,或者也可以使用sudo方式
#tripwire m i /*建立指紋資料庫*/
#tripwire -m c --interactive /*檢查並更新指紋*/

rm [file] /*是移除檔案命令*/

2007年4月24日 星期二

基本命令

在終端機上登入root

以sudo登入root:sudo -i

切換到root:sudo -s -h

rpm轉deb

安裝alien:sudo apt get install alien

sudo alien rpm檔(檔案名?)之後會產生相同的deb檔,再使用

sudo dpkg -i xxx.deb

啟動程式

輸入程式名

改變檔案資料夾擁有者

sudo chown 使用者/檔案位置

rpm查找軟件

rpm -qa xxx

移除軟件

例:rpm -e firefox -1.0.1-1.3.2

tar.gz(bz.bz2)為沒編譯過的源碼,需編譯後安裝

  1. cd 目錄
  2. tar -zxvf xxx.tar.gz、tar -jxvf xxx.tar.bz(bz2)
  3. cd 解壓後目錄
  4. 編譯文件/.configure
  5. make install
移除的話使用make uninstall

bin的安裝包
  1. cd 目錄
  2. chnod xxx.bin 為它加上可執行的屬性
  3. 執行命令/xxx.bin 移除只要把目錄刪除

不知道命令的使用可按tab鍵或鍵入man


網路連線設定

sudo pppoeconf
-------------------------------------
aplay #硬體裝置清單

來源為網路上的資料,經實際操作後所留的筆記。
更多命令指南請參考此一文件





Technorati Tags: