vncserver centos7

http://www.linuxtechi.com/install-configure-vnc-server-centos-7-rhel-7/

yum groupinstall "GNOME Desktop"
yum isntall tigervnc-server xorg-x11-Type1

cp /lib/systemd/system/vncserver@.service /etc/systemd/system/vncserver@:1.service

vi /ec/systemd/system/vncserver@:1.service

改變vnc為使用者名稱
Execstart=/sbin/runuser -l vnc -c "/usr/bin/vncserver
%i"
PIDFile=/home/vnc -c ‘/usr/bin/vncserver -kill %i >/dev/null 2>&1 || :’

3. su -vnc
vncpasswd
打密碼

4.
systemctl daemon-reload
systemctl start vncserver@:1.service
systemctl enable vncserver@:1.service
ln -s ‘/etc/systemd/system/vncserver@:1.service’ ‘/etc/systemd/system/multi-user.target.wants/vncserver@:1.service’

發表於 未分類 | 已標籤 | 發表迴響

dns 被當跳板查詢

步驟2-4.安全性設定–限制所有查詢要求 allow-recursion
就是允許哪些來源可以使用 DNS 主機進行遞迴查詢動作。簡單說就是透過這台 DNS 來查詢任何資料,包含不是該 DNS 主機負責的 zone 也代為查詢,你不想讓別人用你的 DNS 去探查別人的 DNS 主機資訊吧?
在 options 加入 allow-recursion { 127.0.0.1/32; 192.168.1.0/24; };
options {
allow-recursion { 127.0.0.1/32; 192.168.1.0/24; };
};

之後再 /var/log/message 會發現
message repeated 8 times
client 94.129.115.38#4444: query (cache) ‘cpsc.gov/ANY/IN’ denied
可以看到他一次查詢次數和查詢的name
—————————————————————————————-
起因是發現named 佔 cpu loading 太高,去查詢發現 /var/log/message 一堆之類訊息
May 25 10:46:13 ns1 named: client 192.168.16.149#64416: view tech: no more recursive clients: quota reached

發表於 未分類 | 已標籤 | 發表迴響

centos 6.7 快速設定

centos 6.7 install

建立資料夾
/sysvol/hs
#W3000/Data/內容需全部 user:user
chown root:user

/sysvol/share
chown user:user

mkdir /backup/log
mkdir /backup/bak/month
mkidr /backup/mis
mkdir /backup/mis/log
—————————————–
vi /etc/sh/uptime.sh

/usr/sbin/ntpdate tock.stdtime.gov.tw && /sbin/hwclock -w &> /dev/null

————————————–
vi /etc/sysconfig/selinux
SELINUX=disabled
————————————
CentOS 6關閉IPv6功能
/etc/sysctl.conf
#Disable IPv6
net.ipv6.conf.all.disable_ipv6 = 1

service ip6tables stop
chkconfig ip6tables off
———————————–

updatedb && yum install epel-* -y && yum update -y && init 6

———————————–
vi /etc/ssh/sshd_confg
拿掉#
#Port 22 ——>Port 7822
拿掉#並改為no
#PermitRootLogin no

———————————–

安裝apc-ups
yum install apcupsd -y
systemctl enable apcupsd
systemctl start apcupsd

install unix2dos screen lm-sensors vncserver
———————————–
vi /etc/default/useradd
SHELL=/bin/bash—————>SHELL=/bin/nologin
=================================
samba———————————–satart
vi /etc/samba/smb.conf
啟動 smbd 時加上 -D 參數
# vi /etc/sysconfig/samba
SMBDOPTIONS="-D"
設置 rlimit_max 數值
# vi /etc/security/limits.conf
# 加入以下內容

* – nofile 16384
( "*" 要加)
立即生效
# ulimit -n 16384

vi /etc/samba/smb.conf
dns proxy = no
getwd cache = yes
#優化傳輸速度
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192
———————————————-
範例1.Linux作業系統編碼為 big5 (換句話說,/etc/sysconfig/i18n裡面所設定的預設編碼是 Big5 時),而Samba Server要分享檔案給繁體中文的 Windows 系統時,則伺服器該如下設定:
display charset = cp950
dos charset = cp950
unix charset = cp950

範例2.Linux作業系統編碼為Unicode,而Samba Server要分享檔案給繁體中文的 Windows 系統時,則伺服器該如下設定:
display charset = UTF8
dos charset = cp950
unix charset = UTF8

——————————————-
# 徹底停用印表機分享
load printers = no
;cups options = raw
printcap name = /dev/null
;disable spools = yes
printing = bsd
——————————————
#匿名存取
[publlic]
path = /sysvol/public
browsable =yes
writable = yes
guest ok = yes
read only = no
create mask = 0700
directory mask = 0700

#設定目錄
chown nobody.nobody /sysvol/public
chmod 700 /sysvol/public

samba———————————–end

#uptime
vi /etc/sh/uptime.sh

#!/bin/bash
/usr/sbin/ntpdate tock.stdtime.gov.tw && /sbin/hwclock -w &> /dev/null

crontab -e

0 9 * * * /etc/sh/uptime.sh
———————————————————————————————————————-
一般人可能碰到一個問題叫做檔案鎖住?
為了避免一個檔案時被同時開啟,並各自變更資料而不知道,因
此有一種,機制叫lock,一個檔案開啟後另一個檔案只能以唯讀,
或被限制開啟
而Windows的網路芳鄰則有另一種機制,oplock:這一種方法是
予陶s接端可以暫存一些原本要存在server端的資料,且關閉時
不會直接關掉連線,如同所有的cache的作用,可以增加效能,然而
我的結果是檔案明明關閉很久,檔案卻一直被鎖住了,
以下是samba的oplock說明
oplocks (S)
This boolean option tells smbd whether to issue oplocks
(opportunistic locks) to file open requests on this share. The
oplock code can dramatically (approx. 30% or more) improve
the speed of access to files on Samba servers. It allows the
clients to aggressively cache files locally and you may want to
disable this option for unreliable network environments (it is
turned on by default in Windows NT Servers). For more
information see the file Speed.txt in the Samba docs/
directory.

這是我找到原說明中可以改善的這個問題
oplock break wait time (G)

This is a tuning parameter added due to bugs in both
Windows 9x and WinNT. If Samba responds to a client too
quickly when that client issues an SMB that can cause an
oplock break request, then the network client can fail and not
respond to the break request. This tuning parameter (which is
set in milliseconds) is the amount of time Samba will wait
before sending an oplock break request to such (broken)
clients.

DO NOT CHANGE THIS PARAMETER UNLESS YOU HAVE READ
AND UNDERSTOOD THE SAMBA OPLOCK CODE.

Default: oplock break wait time = 0

原意好像是說:有一些機器反應太快以至於無法中斷連線,因此
我調整oplock break wait time =20 至50,結果問題有效解決了
然而95還是有問題,因此我又加了keepalive=120 ,兩分鐘
因為網路內只有五,六台電腦,因此設兩分鐘,讓server檢
查使用者的電腦的連線回應

————————————————————
#======================= Global Settings =====================================

[global]

# ———————– Network Related Options ————————-
#
workgroup = WORKGROUP
# server string = Samba Server Version %v

netbios name = win2000
getwd cache = yes
socket options = TCP_NODELAY SO_RCVBUF=8192 SO_SNDBUF=8192

; dos charset = cp950
; unix charset= utf8
; display charset = cp950

display charset = UTF8
dos charset = cp950
unix charset = UTF8

; interfaces = lo eth0 192.168.12.2/24 192.168.13.2/24
; hosts allow = 127. 192.168.12. 192.168.13.

# ————————— Logging Options —————————–

# logs split per machine
log file = /var/log/samba/log.%m
# max 50KB per log file, then rotate
max log size = 50

# ———————– Standalone Server Options ————————

security = user
passdb backend = tdbsam
#passdb backend = smbpasswd

#將guest權限設nobody
guest account = nobody

#電腦無須號密碼登入
; map to guest = bad user

# ———————– Domain Members Options ————————
; security = domain
; passdb backend = tdbsam
; realm = MY_REALM

; password server =

# ———————– Domain Controller Options ————————
#
; security = user
; passdb backend = tdbsam

; domain master = yes
; domain logons = yes

# the login script name depends on the machine name
; logon script = %m.bat
# the login script name depends on the unix user used
; logon script = %u.bat
; logon path = \\%L\Profiles\%u
# disables profiles support by specifing an empty path
; logon path =

; add user script = /usr/sbin/useradd "%u" -n -g users
; add group script = /usr/sbin/groupadd "%g"
; add machine script = /usr/sbin/useradd -n -c "Workstation (%u)" -M -d /nohome -s /bin/false "%u"
; delete user script = /usr/sbin/userdel "%u"
; delete user from group script = /usr/sbin/userdel "%u" "%g"
; delete group script = /usr/sbin/groupdel "%g"

# ———————– Browser Control Options —————————-
; local master = no
; os level = 33
; preferred master = yes

#—————————– Name Resolution ——————————-

; wins support = yes
; wins server = w.x.y.z
; wins proxy = yes

dns proxy = no

# ————————— Printing Options —————————–

# load printers = yes
load printers = no
# cups options = raw

; printcap name = /etc/printcap
#obtain list of printers automatically on SystemV
; printcap name = lpstat
printcap name = /dev/null
; printing = cups
printing = bsd

# ————————— Filesystem Options —————————

; map archive = no
; map hidden = no
; map read only = no
; map system = no
; store dos attributes = yes

#============================ Share Definitions ==============================

;[homes]
; comment = Home Directories
; browseable = no
; writable = yes
; valid users = %S
; valid users = MYDOMAIN\%S

;[printers]
; comment = All Printers
; path = /var/spool/samba
; browseable = no
; guest ok = no
; writable = no
; printable = yes

# Un-comment the following and create the netlogon directory for Domain Logons
; [netlogon]
; comment = Network Logon Service
; path = /var/lib/samba/netlogon
; guest ok = yes
; writable = no
; share modes = no

# Un-comment the following to provide a specific roving profile share
# the default is to use the user’s home directory
; [Profiles]
; path = /var/lib/samba/profiles
; browseable = no
; guest ok = yes

# A publicly accessible directory, but read only, except for people in
# the "staff" group
; [public]
; comment = Public Stuff
; path = /home/samba
; public = yes
; writable = yes
; printable = no
; write list = +staff

[hs]
#chown root:user
comment = W3000
path = /sysvol/hs
public = no
writable = yes
create mode=0775
directory mode=0775
browseable=yes
printable = no

[share]
#chown user:user
comment = share
path = /sysvol/share
public = no
writable = yes
create mode=0775
directory mode=0775
browseable=yes
printable = no

[bak]
comment = 每周備份
path = /backup/bak
public = no
writable = no
create mode=0775
directory mode=0775
browseable=yes
printable = no

[log]
comment = 備份訊息
path = /backup/log
public = no
writable = no
create mode=0775
directory mode=0775
browseable=yes
printable = no

[mis$]
comment = mis
path = /backup/mis
public = no
writable = no
create mode=0775
directory mode=0775
browseable=yes
printable = no

發表於 未分類 | 已標籤 | 發表迴響

Windows 10:三步教你《右鍵加入「移動到」與「複製到」

1,按WIN鍵+R,輸入「regedit」,打開「登錄檔」
2,找到HKEY_CLASSES_ROOT\AllFilesystemObjects\shellex\ContextMenuHandlers
3,右鍵,新建一項「機碼」為「Move To」,雙擊右邊「(默認)」,輸入
{C2FBB631-2971-11d1-A18C-00C04FD75D13}
4,右鍵,新建一項「機碼」為「Copy To」,雙擊右邊「(默認)」,輸入
{C2FBB631-2971-11d1-A18C-00C04FD75D13}

發表於 未分類 | 發表迴響

win 7,win8 輸入法問題

<<無法切換輸入法>>
1.regedit
2. HKEY_CURRENT_USER\Keyboard Layout\Toggle\ 底下 "Language Hotkey" 改成1

<<輸入法不見>>
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
新增字串 "Ctfmon" 並填入 "c:\windows\system32\ctfmon.exe"

發表於 未分類 | 已標籤 | 發表迴響

安裝Office 2007 或 2010時會出現error 1402

這是今天在客戶那發生的神奇案例,在win7 x64 上要安裝Office 2007 或 2010時會出現error 1402 如下所示

Error 1402.Setup cannot open the registry key
UNKNOWN\Components\7ABFE44842C12B390AF18C3B9B1A1EE8\00002109A20000000F01FEC. Verify that you have sufficient permissions to access the registry.

Google了很久,試了很多方法,終於搞定了….

主要是參考這篇 : 點我

在win7 下進入command prompt 輸入

secedit /configure /cfg %windir%\inf\defltbase.inf /db defltbase.sdb /verbose

跑完後再安裝office 2007就ok了.

若只是單純要手動移除Office 2007,可以參考微軟KB 按我

發表於 未分類 | 已標籤 | 發表迴響

Windows Script Host

Windows Script Host
勒索軟體預防工具 Disable WSH – 防堵Locky、CryptoLocker、CoinVault等勒索軟體的運作,對抗勒索病毒的新方法!大多數的勒索軟體運用RSA加密技術造成重要檔案被加密後無法解密的困境,但根據美國F-Secure防毒軟體公司的研究發現,勒索軟體的觸發都是透過網頁或郵件中的ZIP壓縮檔來執行Java Script(副檔名為JS或JSE),因此,若透過登錄檔的修改禁止「Windows Script Host」就能禁止Java Script被執行,一旦電腦執行JS或JSE副檔名的檔案,就會被攔截並跳出「已停用此電腦的Windows Script Host存取。詳細資料請洽詢管理員。」的警告視窗而無法執行,設定的方式是修改登錄檔機碼「HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Script Host\Settings」,新增一個「DWORD值」將數值名稱命名為「Enabled」,再將數值資料設定為「0」

發表於 未分類 | 發表迴響

讓 Windows Server 2012 允許多重遠桌登入

附錄: 讓 Windows Server 2012 允許多重遠桌登入
1. 執行 regedit.exe
2. 找到 HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Terminal Server
3. 將 fSingleSessionPerUser 設成 0
Ref: PeteNetLive – KB0000471 – Windows Server 2012 And 2008 R2 Enable Multiple RDP Sessions | PeteNetLiv

發表於 未分類 | 已標籤 | 發表迴響

ddns update

原本網名叫 me.idv.tw 想在上面加上 test 開頭 test.me.idv.tw

##1.產生Key
### dnssec-keygen -a HMAC-MD5 -b 512 -n HOST test
#ktest.++157+44587
#
#產生 Ktest.+157+44587.key
# Ktest.+157+44587.private
# cat Ktest.+157+44587.key
# test. IN KEY 512 3 157 BJ7y6dzxchy3u0B4hRLksQ==
#記下 "BJ7y6dzxchy3u0B4hRLksQ==" 這組KEY,丟到 自架dnserver
PS: 新版本 dnssec-keygen 已不支援 HMAC-MD5
流程: apt install bind9 rsyslog

1.
dnssec-keygen -a HMAC-MD5 test >test_key

2. 編輯/etc/named.conf (原本網域名叫 test.)
在原本zone 上 加入
——————————/etc/name.conf—————————–
key "test" {
algorithm hmac-md5;
secret "BJ7y6dzxchy3u0B4hRLksQ==";
};
zone
zone "me.idv.tw" {
type master;
file "me.idv.tw.host";

update-policy {
grant test name test.me.idv.tw. A;
// test key 僅允許更新 test.me.idv.tw 的 A record.
};
};
—– End of File ———-
重新Restart named
#service named restart

3.用nsupdate 上傳test
$ nsupdate -k Ktest.+157+44587.key
> server me.idv.tw // 指定 DNS server
> update delete test.me.idv.tw A // 先刪除舊dns
> update add test.me.idv.tw 0 A 1.1.1.1 // 再新增dns
> send // 送出到 Primary DNS
$ // Ctrl-C or Ctrl-D 離開
可以用dig @me.idv.tw test.me.idv.tw 看有沒有ip

如果沒有成功,請先 tail -f /var/log/message 錯誤訊息
大部分是key權限 ,或 /var/named 底下權限
—————————————————————-
4. 接下來 routeros 上傳
官方這邊有指令可以先測試
/tool dns-update dns-server=1.1.1.254 name=test zone=me.id
v.tw address=1.1.1.1 key-name=test key="BJ7y6dzxchy3u0B4hRLksQ=="

http://wiki.mikrotik.com/wiki/Manual:Tools/Dynamic_DNS

底下是試成功的script
—————–routeros dns-update ————————
——————————–script————————————–
:log info "DDNS: Begin"
:local ddnsuser "test"
:local ddnspass "BJ7y6dzxchy3u0B4hRLksQ=="
:local ddnshost "test
:local ddnszone "me.idv.tw"
:local ddnsinterface "pppoe-out1″
#一定要先宣告,不然後面程式無法使用
:global ddnslastip
:global ddnsip [ /ip address get [/ip address find interface=$ddnsinterface] address ]
#舊的IP有存在就用舊的,不存在就建0.0.0.0/0
:if ([:typeof [:global ddnslastip]] = nil ) do={ :global ddnslastip 0.0.0.0/0 } else={ :set ddnslastip $ddnslastip }
:if ([:typeof [:global ddnsip]] = nil ) do={
:log info ("DDNS: No ip address present on " . $ddnsinterface . ", please check.")
} else={
:if ($ddnsip != $ddnslastip) do={
:log info "DDNS: 開始更新DDNS!"
:log info ([/tool dns-update dns-server=1.1.1254 key-name=$ddnsuser key=$ddnspass name=$ddnshost address=[:pick $ddnsip 0 [:find $ddnsip "/"] ] zone=$ddnszone] . "更新IP:" . $ddnsip)

:global ddnslastip $ddnsip
} else={
:log info "DDNS: IP無變動"
}
}
:log info "DDNS: End"
#————————————————————————

發表於 ros | 已標籤 | 發表迴響

mail 架設注意事項!

其實 email 它是一個"系統", 不只是單純的伺服器. 它有困難度, 對於新手來說, 是不知道架設一個 email 系統要小心的點在那邊. 下面我釐清一下要注意的地方
.
1. SMTP port 25, 是 server to server 的部分, 這邊最好的防護就是使用 RBL 擋住 spam email server 的 IP (SpamAssassin + TCPServer/IPtable)
.
2. Submission Port 587, 這邊是 email client to server 寄信, 需要使用 TLS 作為 smtp-auth 認證的加密, 這邊就需要建立自己的 PKI Cert 來做 TLS 加密了. 再來防止 brute force 攻擊, 就要搭配 Fail2ban. 需要 white list 自己 router ip 以及其它分公司的 ip 避免鎖到自己。
.
3. 如果有 webmail 的部分, 那麼要建立 HTTPS 的 secure certificate. 如果使用 IMAPS, 也可以使用同一個 certificate.
.
4. 避免自己的 email 淪為 RBL 上面的黑名單, 需要建立 DKIM 放到 DNS 的 record 中. 如果能夠 reverse ip 如 1.1.1.1 -> mail.mydomain.com 會很好, 比較容易進白名單, 如果沒有的話要隨時 monitor RBL 是否有自己的 mail server domain/ip
.
5. 盡量不要使用 .hk .tw .cn .jp 的 domain, 因為有些 spam filter, 或是一些 custom RBL, 會直接封掉這些 tld. 盡量把 DNS 的服務放在 Domain Registrar 那邊, 不過如果使用非常多 subdomian 的話, 再考慮把 dns 服務拿回自己建立, 因為很多 domain registrar 會限制使用者最多可以有幾個 dns record.
.
6. SMTP/Submission 收到的 email, 直接先 pipe 給 clamav 後, 確認沒有病毒才放到 maildir 或是寄出. 每一個小時自動更新 clamav 的 database.
.
7. Webmail 的 template 最好買有服務的 source code, 會定期更新, 使用因為有太多時候有 webmail 被 hack 透過 sql-injection 而控制了整個 mail server.
.
8. 盡量使用 IMAPS, 方便集中備份, storage 的檔案系統最好是支援壓縮, 以及快照. 這樣子可以追溯歷史記錄, 避免離職員工或是將要離職員工刪除 email
.
9. 所有的 mail server 都會使用到 database, 不管是 mysql 或是 mariadb, 要設定好其固定定期備份模式, 同時建立好 password policy, 八碼 含大小寫+數字+特殊符號.
.
10. 防止內部 IT 人員閱讀公司高階主管的 email 或是被外部人員釣魚假裝高階主管的 email 指令, 建議使用 RSA 2048 bit 的 S.MIME (X509) PKI 模式加密以及簽署 email.
.
11. 開 watchdog 確認 email 收發服務正常, 若有問題時, 第一時間 script 自動重開服務.
.
12. log reporting (graylog) 定期檢查伺服器是否有被入侵的跡象.
.
13. 使用 Filelink 模式傳送大的檔案附件 (需搭配 email client). 這部分有所謂的 DL 服務, 也可以自己架設 WebDAV 來做.
.
14. 使用 Open-Xchange 或是 Zimbra Email 這一類型的 email server, 它可以分成很多個 component, 如 message storage node, database node, smtp node 或是 mail proxy node 等模式, 把 email 服務的 loading 分散到各分公司的小 mail 的伺服器上, 避免單點網路頻寬飽和, 造成每天早上剛上班時, email 大塞車 (特別是禮拜一早上或是長假過後)

發表於 未分類 | 已標籤 | 發表迴響