Linux

πŸ“¦ Chroot Jail
πŸ“¦ Chroot Jail
Change the root directory of a command or a process, and its children. In no case should `chroot` be relied upon as a security boundary β€” a process running as root can escape the jail. Example: creating a chroot 1# create the "jail" directory 2J=$HOME/jail 3mkdir -p $J 4mkdir -p $J/{bin,lib64,lib} 5cd $J 6 7# copy the binaries and their libraries into the jail 8cp -v /bin/{bash,ls} $J/bin 9 10list="$(ldd /bin/bash | egrep -o '/lib.*\.[0-9]')" 11for i in $list; do cp -v "$i" "${J}${i}"; done 12 13list="$(ldd /bin/ls | egrep -o '/lib.*\.[0-9]')" 14for i in $list; do cp -v "$i" "${J}${i}"; done 15 16# enter the jail 17sudo chroot $J /bin/bash
πŸ” Runlevels & Shutdown
πŸ” Runlevels & Shutdown
Shutdown / reboot Solaris Red Hat Ubuntu / Debian HP-UX AIX Power down shutdown -i5 -g0 -y shutdown -h shutdown -h shutdown -h now shutdown -F Reboot shutdown -i6 -g0 -y shutdown -r shutdown -r shutdown -r now shutdown -Fr OK prompt shutdown -i0 -g0 -y β€” β€” β€” β€” Fast reboot -- -r (reconfigure) shutdown -f (no fsck) shutdown -P (power off) shutdown -F (force fsck) β€” Force fsck touch /reconfigure touch /forcefsck edit /etc/default/rcS β†’ FSCKFIX=yes β€” β€” Change runlevel Tool Solaris Red Hat Ubuntu / Debian HP-UX AIX halt βœ… βœ… βœ… βœ… βœ… init βœ… βœ… βœ… βœ… βœ… poweroff βœ… βœ… βœ… βœ… βœ… reboot βœ… βœ… βœ… βœ… βœ… shutdown βœ… βœ… βœ… βœ… βœ… telinit βœ… βœ… βœ… β€” βœ… uadmin βœ… β€” β€” β€” β€” Runlevels Level Solaris Red Hat Ubuntu / Debian HP-UX AIX 0 shutdown halt halt halt reserved 1 single user single user single user single user reserved 2 n/a multiuser (no networking) multiuser (default) multiuser (networking) multiuser + NFS 3 multi-user multiuser (networking) same as 2 multiuser + NFS + CDE GUI (default) user defined 4 n/a unused same as 2 multiuser + NFS + VUE GUI user defined 5 power off GUI same as 2 n/a user defined 6 reboot reboot reboot n/a user defined 7-9 β€” β€” β€” β€” user defined Change the default runlevel Solaris / Red Hat / HP-UX / AIX : edit the initdefault line in vi /etc/inittab. Ubuntu / Debian : edit vi /etc/event.d/rc-default. On systemd systems (RHEL 7+, Ubuntu 15+), the SysV runlevels are replaced by targets β€” e.g. systemctl isolate multi-user.target (runlevel 3), systemctl isolate graphical.target (runlevel 5), systemctl set-default multi-user.target. See the Systemd page.
πŸ• NTP & Time Synchronisation
πŸ• NTP & Time Synchronisation
Client verification (ntpd / chrony) 1ntpstat # see which NTP server we synchronise with, and whether the sync is good. 1synchronised to NTP server (192.168.1.12) at stratum 4 2 time correct to within 68 ms 3 polling server every 1024 s 1ntpq -p # see the state of the peers. 2ntpq -c peers remote refid st t when poll reach delay offset jitter ============================================================================== +192.168.1.11 192.168.2.4 4 u 259 1024 373 0.731 -0.980 0.557 *192.168.1.12 192.168.3.21 3 u 385 1024 377 0.773 0.146 0.365 192.168.4.255 .BCST. 16 u - 64 0 0.000 0.000 0.000 The server preceded by an asterisk (*) is the one being used. Those preceded by a - are currently discarded by the server-selection algorithm. Those whose name is preceded by a + are possible synchronisation candidates. A server preceded by a space is either unreachable or too distant. Column meaning remote β€” the server name. refid β€” the parent server’s identifier. st β€” the server’s stratum. t β€” the server type. when β€” seconds elapsed since the last contact. poll β€” seconds between each contact. reach β€” bitmask of successful contacts (octal): the server considers itself synchronised when reach reaches 177; a quality, stable connection shows 377. delay β€” estimated round-trip time (ms) of the UDP packet. offset β€” estimated difference between the peer’s clock and the internal clock. jitter β€” dispersion of the reference values obtained from this peer. Restart the NTP daemon 1service ntpd restart # or: systemctl restart ntpd Configuration & logs 1cat /etc/ntp.conf # "server example.com" + restart ntpd + enable 2/var/log/ntpstats ntpdate (legacy) Old service that synchronises NTP at boot (install the package first).
πŸ‘₯ Users & Groups
πŸ‘₯ Users & Groups
Configuration files File Check command Purpose /etc/passwd pwck user accounts /etc/group grpck groups /etc/shadow β€” password hashes and aging /etc/gshadow β€” group passwords /etc/skel β€” files installed by default when a user is created Basic commands 1useradd -g <GID> -G <GID2> <user> # create a user in primary group GID (and supplementary group GID2). 2usermod <options> <user> # modify a user. 3userdel -r <user> # delete a user (and its home directory). 4groupadd / groupmod / groupdel # manage groups. 5 6id -a # show all info about the current user (UID, GUID, groups, etc.) - more precise than "who am i". 7sg <group> -c '<command>' # execute a command as a different group ID (to run scripts or write to a file with group rights). Password management 1passwd -u <user> # unlock a user account. 2echo "password" | passwd --stdin <user> # scripted password change. Account aging 1chage -l <user> # see the expiration dates. 1# list the expiry of every account 2for account in $(cut -f1 -d: /etc/passwd); do 3 echo "ACCOUNT: $account , EXPIRES: $(chage -l $account | grep 'Account expires' | awk '{print $4, $5, $6}'), CHANGED: $(chage -l $account | grep 'Last password change' | awk '{print $5, $6, $7}')"; 4done 1# change the aging info interactively 2chage <user> To unlock an account, set “Last Password Change” to -1 in chage (or use passwd -u <user>).
πŸ“– LDAP & Kerberos
πŸ“– LDAP & Kerberos
Kerberos 1kinit <user> # obtain a ticket. 2klist # list the tickets in the cache. Services 1systemctl status slapd # OpenLDAP server. 2systemctl status sssd # System Security Services Daemon. LDAP - search 1ldapsearch -x -h <ldap-host> -b "ou=People,dc=example,dc=com" uid=<user> DN components: cn : common name ou : organizational unit o : organization c : country dc : domain component LDAP - add / modify 1# LDIF = the commands between EOF 2# -W prompts for the LDAP admin password 3# -w passes the password (put it in a variable) 4# bind_dn : the DN that acts as the LDAP bind user 5 6export bind_dn="CN=directory manager,DC=example,DC=org" 7 8# Modify an entry 9ldapadd -W -D "$bind_dn" -h $ldap_server -p 389 <<EOT 10dn: cn=user,ou=wiki,dc=example,dc=com 11changetype: modify 12add: memberUid 13memberUid: $login 14EOT 15 16# Create a new entry 17ldapadd -w $LDAPpwd -D "$bind_dn" -h $ldap_server -p 389 <<EOT 18dn: uid=${login},ou=People,dc=example,dc=org 19uid: ${login} 20loginShell: /bin/bash 21uidNumber: ${uid} 22gidNumber: 47110 23homeDirectory: /home/${login} 24shadowLastChange: 0 25shadowMax: -1 26objectClass: account 27objectClass: posixaccount 28objectClass: shadowaccount 29objectClass: top 30gecos: ${gecos} 31cn: ${gecos} 32userPassword: {CRYPT}`perl -e 'print crypt("${login}", "${login}")'` 33EOT
πŸ” PAM
πŸ” PAM
/etc/pam.d In /etc/pam.d, there is one PAM file per service. Syntax: module_type control_flag path_to_module_agent Module types auth β€” authentication. account β€” account-based restrictions (validity, time of day, etc.). session β€” things that run at login/logout. password β€” password updates. Control flags required β€” success needed; a failure is reported but only after the rest of the stack has run. requisite β€” like required, but a failure returns immediately without running the rest of the stack. sufficient β€” if this module succeeds, it is the last module tested in the stack. optional β€” its result is only taken into account if no other module succeeded or failed. [value=action value=action2 ...] β€” advanced control: map a module result to a specific action. Sample:
πŸ›‘οΈ sudo
πŸ›‘οΈ sudo
/etc/sudoers The /etc/sudoers file contains the set of UNIX operating-system privileges that the local administrator has granted to UNIX users. In no case should this file be edited directly with vi; it must be edited with visudo. 1sudo : execute a command as root. 2sudo su : become root and stay root. 3sudoers : file listing the commands allowed for certain users as the superuser (or another user). 4visudo -cs : strict syntax check of the sudoers file. sudo -i is equivalent to su - in terms of rights. with sudo -i, the user password is asked. with su -, the root password is asked. Verification 1sudo -l -U <user> Rules 1# "user" runs "sudo -u target All_the_commands" 2user server=(target) NOPASSWD: ALL With aliases 1Host_Alias LOAD_BALANCERS = server1,server2 2 3Cmnd_Alias SET_VIP = \ 4/sbin/ip addr add 192.168.10.12/20 broadcast 192.168.15.255 dev eth0 label eth0\:0, \ 5/sbin/ip addr del 192.168.10.12/20 dev eth0, \ 6/sbin/arping -U -c 1 -I eth0 192.168.10.12 7 8loaduser LOAD_BALANCERS=(root) NOPASSWD: SET_VIP 9syncuser LOAD_BALANCERS=(root) NOPASSWD: SET_VIP
⏰ Jobs & Background
⏰ Jobs & Background
Schedule a task (at / batch) 1at : schedule a task to run at a later time (/!\ it executes what you give it on stdin). 2 ex : at 18:22 < "date; ps -ef | wc -l" 3 or : at now + 5 hours then type your commands then ctrl + d 4at -q a 16:05 tomorrow : -q defines the queue (a-z), i.e. the priority. 5at -c <job_number> : see the context and the commands of the task. 6atq : list the pending jobs (= at -l). 7atrm : delete a job. 8 9batch : schedule a task when the load average is below a threshold. Run jobs in the background 1jobs -l : list the running tasks. 1# Nohup in series 2for i in {1..6}; do echo "nohup sh -c \"shred -vfz -n 3 /dev/cciss/c0d${i} > nohup${i}.out 2>&1 \" &" ; done | bash Three points to remember:
🎯 CPU Affinity
🎯 CPU Affinity
Source : http://www.glennklockwood.com/hpc-howtos/process-affinity.html Taskset 1sudo apt-get install util-linux # or: yum install util-linux 2taskset -c 1 script.sh # run script.sh on CPU number 1 (-c: CPU, -p: PID) 3taskset -c 1,2,3 script.sh # give it several CPUs. Numactl 1numactl --cpunodebind=0 simulation.x 2numactl --cpunodebind=0 --membind=0 simulation.x 3numactl -C 0 -N 0 simulation.x 4numactl -C +0,1,2,3 simulation.x # similar to taskset 5numactl -H # see which memory corresponds to a CPU Note: with numactl, unlike taskset, you cannot change the CPU affinity of a process on the fly.
πŸ› Tracing (strace / ltrace / gstack)
πŸ› Tracing (strace / ltrace / gstack)
Strace - trace system calls 1strace -tt -p 24503 2 3strace -o strace01.out -e open -f bash --login -i # see the files opened during a bash connection. 4 # -o redirects the output / -e filters the system calls / -f follows forks (child processes) 5 6strace -f <binary_script> 2> trace.log : stdout -> the binary command result, stderr -> the binary's system calls. Ltrace - trace library calls ltrace traces shared-library calls (like strace, but at the library-call level).
πŸ“Š Process Monitoring (pidstat)
πŸ“Š Process Monitoring (pidstat)
pidstat reports the CPU, memory, I/O and context-switch activity of processes. Report the process context-switching activity 1# pidstat -w -p 3446 2 5 2Linux 3.10.0-123.13.2.el7.x86_64 (localhost.localdomain) 12/26/2014 3_x86_64_ (1 CPU) 407:23:38 AM UID PID cswch/s nvcswch/s Command 507:23:40 AM 0 3446 0.50 0.00 sshd 607:23:42 AM 0 3446 0.50 0.00 sshd 707:23:44 AM 0 3446 0.50 0.00 sshd 807:23:46 AM 0 3446 0.50 0.00 sshd 907:23:48 AM 0 3446 0.50 0.00 sshd 10Average: 0 3446 0.50 0.00 sshd cswch/s : number of voluntary context switches the task made per second. (A voluntary context switch occurs when a task blocks because it requires a resource that is unavailable.) nvcswch/s : number of non-voluntary context switches the task made per second. (An involuntary context switch takes place when a task executes for the duration of its time slice and is then forced to relinquish the processor.) Page faults and memory 1pidstat -r -p <PID> 3600 72 # every hour, 72 times - practical for long-term monitoring. 2 3pidstat -r -p <PID> 50 12 407:26:44 PM PID minflt/s majflt/s VSZ RSS %MEM Command 507:27:34 PM 13775 1.64 0.00 34957320 18183312 55.30 java minflt/s : number of minor faults the task has made per second β€” those which did not require loading a memory page from disk. majflt/s : number of major faults the task has made per second β€” those which required loading a memory page from disk. VSZ : Virtual Size β€” the virtual memory usage of the entire task in kilobytes. RSS : Resident Set Size β€” the non-swapped physical memory used by the task in kilobytes. Disk I/O 1pidstat -d -p <PID> 50 12 pidstat -d reports I/O statistics (kernels 2.6.20 and later only). The following values are displayed:
πŸ” Find & Inspect Processes
πŸ” Find & Inspect Processes
Find a process 1ps -fp <pid> # find a process by its PID. 2pidof httpd # find the PIDs of httpd. 3pidstat -lp <pid> # process name with all its complete arguments. 4 # for a tomcat or weblogic process, you can split the arguments with: sed 's/ -/\n -/g' 5pidstat -C "mysql" # find a process by its name (gives the PID and CPU load). The process tree 1pstree -pu # the process tree with PID and user (if pstree is not installed, use the alternatives below). 1ps -ejH 2 PID PGID SID TTY TIME CMD 3 1 1 1 ? 00:00:37 init 411016 11009 11009 ? 00:00:00 sshd 511017 11017 11017 pts/12 00:00:00 bash 611125 11125 11017 pts/12 00:00:00 telnet 1ps axjf 2 PPID PID PGID SID TTY TPGID STAT UID TIME COMMAND 3 0 1 1 1 ? -1 Ss 0 0:37 init [5] 4 8617 10610 10610 10610 ? -1 Ss 0 0:00 \_ sshd: support [priv] 510610 10710 10610 10610 ? -1 S 5027 0:00 \_ sshd: support@notty 610710 10711 10711 10711 ? -1 Ss 5027 0:00 \_ sshd: support@internal-sftp-server 1ps faux 2USER PID %CPU %MEM VSZ RSS TTY STAT START TIME COMMAND 3root 1 0.0 0.0 10372 696 ? Ss Aug09 0:37 init [5] 4user1 4168 0.0 0.0 8728 968 ? Ss Aug24 0:00 | \_ /bin/bash -c perl /data/supports/scripts/SRAM_asr5k.pl &>/dev/null 5user1 4174 0.0 0.0 34068 5044 ? S Aug24 0:00 | \_ perl /data/supports/SRAM_asr5k.pl 6user1 4188 0.0 0.0 8728 984 ? S Aug24 0:00 | \_ sh -c grep -c SRAM /data/syslogCOLLECT/LTE_*/*/*.20160824.log /proc The /proc filesystem exposes per-process information: