Debian Installation :: SVN - Port 22 Restricted For Security Reasons
Jul 1, 2010
I was trying to install subversion on my machine which have lenny installed on it but when I tried to forward port 22. I got a message connection refused and when I tried to open it in iceweasel it shown me that the port has been restricted for security reasons. I wish to enable it but don't know how to.
I've recently built a VM appliance using Ubuntu 8.04 that is given to customers for an easy deployment of our software. Ubuntu works great in a VM and its perfect for our software (which is a web application).
Some customers are paranoid (rightfully so) and they will run a vulnerability assessment on the web application. A particular customers' assessment fails as it finds that the appliance isn't running the latest version the Apache web server. I thought that just running "apt-get upgrade" would upgrade all of the software packages to the latest so that failures in the assessment caused by outdated software packages would be resolved... However this is not the case...
I realize that there is a probably a whole process for submitting/approving the latest versions of software packages in Ubuntu, that then get pushed to the repositories - But how does this work? What exactly does "apt-get upgrade" do if it doesnt upgrade packages to the latest?
For example: I need Apache 2.2.11 to fix a particular vulnerability. But when running apt-get upgrade, it doesnt actually upgrade the Apache version number (or any of the other packages). I'm stuck on Apache 2.2.8, and I can't find a .DEB installer for 2.2.11 or later.
Now a dayz I am observing that mUbuntu performance was not satisfactory. My ubuntu is daily up to date. What was the reasons for my Ubuntu becoming slow?
I'd like to be able to limit access to a particular website, based on the time of day. I would also like to be able to password protect this if possible.So for instance, from 7am until 10pm daily, I can access URL... but after 10pm it redirects to 127.0.0.1 or something. And this configuration be protected by only allowing a certain user (other than root) to change the config?
I am currently running Debian 6. I would like to know if there is a way and how i would go about blocking a certain IP range from connecting to my server within a certain port range. Say for example.
i want to block ip range 123.123.123.* from connecting to my server on the ports 33000 - 43000. But, i want to allow them to connect on any other port range, and i want to be able to allow connections from my server to the blocked ip range on those same ports. so, blocking incoming only on the above port range.
sudo ssh -L 750:192.168.123.103:873 username@192.168.123.103It does exactly what it's supposed to do, but how do i edit / remove this rule?Is there some config file where i can alter the forwarding? How does it get stored?Im using Ubuntu 10.10Server Edition (allthough i recon it would be pretty much the same across all versions
Is there any way to verify if packets being trafficked over a certain port are valid for the service you want to use this port for?
One obvious example that probably clarifies my question: When I open port 443 (outgoing or incoming) for https/ssl traffic, I don't want this port to be used for say openvpn traffic. Thus: when someone wants to surf to a website with https, it should be ok but if someone wants to connect to his home openvpn server over that same port, it should be blocked.
I'll explain this in one sentence: Is it possible to program a port-binding shellcode in which people across the Internet can connect to, without being thwarted by the router blocking their data because the port its bound to doesn't allow port-forwarding
As it stands I have a small home network operating behind my modem/router. Some of the ports on this are forwarded to my PS3 for gaming but I was looking at forward some for my file server.
At the moment I've forwarded port xxx22 to port 22 on my server for SSH for instance. ANd similarly 21 for FTP (although it doesnt seem to want to connect for any more than a few seconds using that). What I was thinking of doing was placing a small website for a handful of ppl to use on the server too and port forward again - xxx80 to 80. It works just fine but I'm a little concerned on the security front.
As I've moved the port to something different from the outside world I'm presuming I will have already cut the potential for malicious folks to wander in but is there anything else I should be doing? At the moment there's no firewall operating on the server, usually as its hidden behind the modem/router. But if I open this thign up more permanently what should I be doing? I've read a few articles on it but I'm always left with the overwhelming thought of "Thats if theres no firewall in my router" as they just seem to do the same.
I am running an updated Lenny. Just discovered that as user I am able to add new users via gui: System > Administration > Users and Groups. I was under the impression adding new users was restricted to root. Is this is a bug, and if so who do I report this to?
As I mentioned on another thread, I have 2 Ubuntus - Jaunty and Meerkat - as separate drives on my secondary IDE channel. I am removing Jaunty. Meerkat blows it away. And is certainly my preferred OS. However I am looking for a replacement for Jaunty that is more flexible in certain key areas than Ubuntu appears to be.I dont want to be restricted to Debian versions of things like Perl, MySQL, PHP and others. I can run LAMPP, but I would prefer to compile and have the versions of my choice as part of a main test system (apart from Meerkat that is).
I have had enough nightmares in Jaunty with things getting broken and spiralling out of control. I want a distro that doesnt rely on the GUI and its attendant utilities, but can run them when called. Meerkat is stable and has resisted me breaking it so far, but I do not want to push my luck. I have too much time invested in it. I intend to use Meerkat as my primary system on the machine, but want an alternative to *PLAY* with.
Fresh Install of lucid today,everything went fine. Installed compiz, fine, now I'm downloading the restricted extras through synaptic and wow, its going 10 to 20 kB/s. Tried downloading a file from cnet, no problem. 800+ kB/s. Think this is just related to heavy volume today?
I would like to find out if any of the packages installed on my system are from the restricted repository. I would like to get rid of all of them if possible. Does anyone know how I could find out? I am running Ubuntu 11.04
i am currently running 9.10 and was thinking of upgrading to 10.10. i was going to initally install 10.10 but i saw that it ran fluendo. does that mean the ubuntu restricted extras aren't in the future versions? i was also wondering if i would have to reinstall all my old programs.
After installing Ubuntu,Firstly i went to the terminal & typed "$ sudo apt-get install Ubuntu Restricted Extras"then i input my password,to installbut sometime later the Ubuntu Restricted Extras Package installation was failed.How can i successfully install Ubuntu Restricted Extras Package?
What are the benefits to upgrading to F15 from F14 if any? Has there been some huge step forward in performance, security or some other reason that makes it worth while to upgrade? I know many people make the move simply because they wish to have the latest and greatest, but is there any reason specifically to upgrade to the latest and greatest?
I have 3 cronjobs set up on my Unix server . Out of which 2 cron jobs run the same script but at different times and the other one runs another script. So in the 2 jobs which are set to run PMDaily.sh for eg , One runs on Sunday at 8AM and the other runs monday to friday at 6 AM . How ever the Sunday cronjob works (runs through the crontab) but the Cron job set for Monday to Friday is not working. However manually if i run this script it workd perfectly.
Please let me know what could be the possible reasons for this?
when i try to run a program in linux it runs and prints some messages successfully but in the middle it shows the message 'Killed' and stops running. what may be the reasons for this..?
Multi-media and Restricted Format Installation Guide
I tried to reproduce MP3 files on video like .AVI or MP4 and everything was fine.Every program and library seems that has been installed correctly.
But when I checked , following the instructions in the link, I found different results. I can understand that the guide has been written a long time ago and some packages are not available anymore in the repository, but I think there are too many differences.
This is what I got:
Code:
And I got the following list
Another differerence that I have noticed is: when I was listening a MP3 file using Amarok the music was quite clear and loud, but when I reproduce a MP4 or MP3 video file using VLC I could bearily hear something and the volume was at its maximum. How can it be ?
I have NFS fileserver that has served me well for more than year. But recently I noticed that it has started to reboot on its own very frequently, almost once a day! It is most likely not a power related issue as I tried changing UPS/power sources, but no help!So my question is:Is there any log file where I can check which is causing the reboot? There may not be a single logfile, but I need some point to start the investigation!
I have just finished installing Karmic on new computer. I have already installed java jre, flash plugin, and unrar/rar. My question is can I still install restricted extras to get addition applications installed, without corrupting my apps already installed? Or should I just manually install the remaining items from restricted extras manually?
As this question pops up quite often on IRC and, as a quick search told me, on this board as well, I decided to put together some directions that, with some or the other variation, also apply to other Linux distributions and have never failed me. The following is confirmed to work for Kubuntu 11.04 Natty Narwhal 64bit with a NVIDIA GeForce GT 240 and on Kubuntu 11.04 Natty Narwhal 32bit with a NVIDIA GeForce FX 5900XT graphics card.
This HowTo will describe how to install the proprietary NVIDIA graphics card drivers using exclusively the command line. I strongly suggest you try this method for a fresh install of graphics drivers before trying any other method, especially a GUI-driven one (I never used a GUI for package management on a Debian-ish system, but I hear that the Ubuntu Software Center supposedly has a way of installing proprietary graphics drivers).
The restricted packages repository should be enabled by default. To the more experienced users: This HowTo uses apt-get for demonstrating the install process. If you prefer using aptitude, feel free to replace the commands accordingly. First steps. As well be doing everything on the command line, first open a terminal application from your desktop environments menu or from a shortcut icon on your panel, if you have one. You should be greeted by a prompt that looks like this:
My web server does not currently run Suexec. All files within the /var/www directory are owned by vsftpd and belong to nogroup. Apparently, this setup causes issues with some scripts that attempt to upload files and change files, such as the SMF Forum package.
Here's some background information that goes into further details regarding the issues I'm having:[URL]..Why would uploading a file using PHP in SMF not work with the owner being vsftpd belonging to the nogroup when the folder has been chmod to 777? I tested my own simple PHP upload script, and it was able to upload a file without issues. Yet, I've been told that my server is improperly configured if I'm not using Suexec. Why is this? Also, if I did use Suexec, what creates the users? Would I have to add them manually, or would they be created automatically as users based on their FTP login and added as subusers to the vsftpd group? Why should I use Suexec? I don't understand what's wrong with my current setup. How does it work in terms of users? Are users created and just added to a subgroup, or are they created like normal user accounts on the actual server? Do they get their own /home/username directory as well? I'm so confused about Suexec. What I've read about it doesn't make sense.[URL]..
My suspend-to-disk and suspend-to-RAM stopped working months ago. I've grasped at straws about why ever since, but I really don't think it's a software problem, because I've reinstalled my system (MEPIS) repeatedly. What sort of hardware failures could cause this? What should I be looking for? I notice that at boot, Linux always says "no resume image found," even if I left the system in suspension or hibernation. I can post parts of the dmesg if someone tells me what to look for; I can't display the whole thing because it's too long to fit here.
I've had Ubuntu installed on my desktop for a month now, and its all worked like a charm, so I'm thrilled. I then decided to install it on my old laptop as well to see if I could breath a bit more life into it, and to get used to working Ubuntu a bit more. The laptop had 18.6GB partitioned to C:// drive or windows XP, and an empty 18.6GB D:// drive, so I deleted the D:// drive in XP using the Microsoft disk utilities tool, all well and good. I then did a clean install of Ubuntu-9.10-desktop with an Ubuntu CD into the largest continuous free space, and it set it up nicely. When I first booted it up there were a ton of updates to install, as there had been on the desktop first time, which I dutifully installed. As on the desktop a little notice popped up telling me to install the NVidia Proprietary driver for the NVidia card (specifically "NVIDIA accelerated graphics driver (version 96)[Recommended]"), as it had when I installed it on the desktop, so I chose to install that and then restarted the computer.
On restarting GRUB2 loaded, and it booted Ubuntu. I then saw the little white logo on the black screen for a couple of seconds, and then the screen goes completely white, with some pixels left behind fading to white slightly slower. First time through I held down the power button to force shut down, and on restart exactly the same thing happened. This time I held down alt+sysrq and went through the R, E, I, S, U, B sequence, however as opposed to usual I didn't get a black terminal-like screen after hitting any of the buttons, although it did reboot on B. It did boot correctly in recovery mode, however I was at a loss what to do here. Incidentally, the same problem occurred when I booted to previous version of the kernel as well.
Then I decided that as I didn't have any data to lose, and it was still early in the day, I'd do a clean re-install. This time I chose to ignore the updates, and just install the NVidia driver as prompted to check that it was the driver causing the trouble. Having installed the driver and restarted I got exactly the same problem as before - definitely this pesky NVidia driver, not any of the updates.So here I am at clean install 3, having just got all the updates, but not having downloaded the NVidia driver as prompted, with little desire to go through yet more reinstalls. My questions are:
1) Do I need to install this NVidia driver? The rest of the computer specifications are fairly paltry by modern standards, and I won't be doing anything graphics intensive on it (the most graphical program will probably be Battle for Wesnoth) and I I don't need to install it, not installing it seems to be the easiest way to solve the problem.
2) If I do need to install it how would I go around doing this without getting my charming white screen?
3) Is there a way of removing the driver from recovery mode that doesn't involve a clean install again? I have tried sudo apt-get purge nvidia-driver, which tells me there isn't any installed. I have tried sudo rm /etc/X11/xorg.conf which made no difference. I have tried dpkg-reconfigure xserver-xorg and this didn't help. I have tried a couple of other commands as well but I can't remember them, however I would probably recognise them if I saw them again.
Onto System information - pulled from listed specifications and SysInfo:
General System Information Release:Ubuntu 9.10 (karmic) GNOME: 2.28.1 (Ubuntu 2009-11-03)
I have noticed in the recent updates there is a Kernel update 2.6.32-22 but there is no restricted modules included. On my Desktop I have a Nvidia card which I installed the driver using the Hardware Drivers Application. As far as I know these Drivers are ether reinstalled or updated whenever there is a kernel update.
I also have a Laptop with a ATI Radeon card which I did run the updates and ended up (after the reboot) in low graphics mode, after a bit of work I was able to reinstall the drivers and get my desktop back so that's ok now.
I had this problem a few years ago with an old version of Ubuntu, kernel updates but no restricted drivers. The drivers turned up the next day and all was fine. I was just wandering if this is a known issue with Lucid or if anyone else has had this problem, It's been a couple of days since I noticed the Kernel update but still Restricted Modules. Oh I'm using Ubuntu Lucid 10.04
Has anyone experienced random wireless dropouts? Like one minute, you are connected and then not, with no obvious reason as to why it happened, just network manager popping up requesting a password to reconnect.