Saturday, May 17, 2008

ssh2 library for php

Most extensions for php (PEAR or PECL packages) are generally available through yum and apt-get on red-hat and debian distros respectively.

Extensions installed: snmp, curl, mysql, mysqli, pdo, pdo-mysql

On Ubuntu 7.10, apt-get of any of these php extensions does the following:

1. Copies the name.so (e.g. snmp.so) file in /usr/lib/php5/20060613/ directory.

(No idea why is the directory name a date, instead of 'ext' as mentioned in several forums. Anyways, in /usr/bin/php-config5, you can find the line:
entension_dir=/usr/lib/php5/20060613/)

2. In /etc/php5/conf.d, creates a file name.ini (e.g. snmp.ini), with a single line: extension=snmp.so

The php ssh2 library was not found using apt-get. The following steps were followed in install it. (assuming that openssl, pear, pecl are already installed)

(prerequisite: install the libssh2 library)
1. wget http://surfnet.dl.sourceforge.net/
sourceforge/libssh2/libssh2-0.14.tar.gz
2. tar -zxvf libssh2-0.14.tar.gz
3. cd libssh2-0.14/
4. ./configure
5. sudo make all install

(now, php ssh2)
6. sudo pecl install -f ssh2 - this created ssh2.so in /usr/lib/php5/20060613/
7. created a file /etc/php5/conf.d/ssh2.ini with a line: extension=ssh2.so

Most of the instructions were followed from this page. PHP's own documentation page for ssh2 couldn't help much, but the rest of the documentation can be found there.

Thursday, May 15, 2008

Sudo access for apache user

Web-based admin interfaces, like a network management web console, often require to execute certain commands with elevated previleges. Adding an entry in the sudoers file is one straight forward way to do this.


The apache user on debian is 'www-data' and on fedora it is 'apache'. Let apache_user denote the web server user, irrespective of the distro.


In /etc/sudoers, we need to add:
%apache_user ALL=NOPASSWD: ALL


This seems very naive from security perspective.Apache has a feature suEXEC for such purposes. But -

  • It does not support if the target user is root (work around – let the target user be userx, such that userx is configured to have admin previleges)
  • It requries re-compiling the apache server, and a very careful and complex configuration. Not really suitable for people who use off-the-shelf apache, with default configurations, like me :)

We can modify the line in 'sudoers' file to enhance security a little bit. Instead of sudo access to all commands, we can restrict the sudo access for very few number of commands.


%apache_user ALL=NOPASSWD: /bin/ls, /bin/cat


In my project – php based wireless-mesh network management suite – I've used this :-


%apache_user ALL=NOPASSWD: /usr/bin/php -f /path/to/my/script/daemon.php *


where, daemon.php handles all the tasks requiring admin previleges. The '*' at the end of the line is used to pass command line arguments to the daemon. This type of usage of the sudoers file gives enough security for most practical purposes. After all, I'm not managing a bank here!


Links: Useful thread on apache forum


Tuesday, May 13, 2008

Uploading files to blogs

Blogger does not have any direct feature to upload and share files (other than images). For PDF and PPT files I would recommend using slideshare.

For other files, you need to use an online storage service which allows access through blogs.

In the previous post, I've used the service of Box.net.
Create an account, upload files. Go to the services tab, and add export to blogs service. Currently it supports WordPress, Blogger and LiveJournal. Then right click on the uploaded file, you'll find an option to export the file to these sites.

In case of Blogger, just enter your blogger username and password, and the name of the post. In case you have multiple blogs, it itself decides which blog to post to.

Note: Even if there exists a post with the name you entered there, Box.net will create a new post with the name provided. So you should start by uploading and exporting files for your post, and edit that post to add your contents.

MRTG RRD Log Querying Tool

There are a lot of free MRTG front-end tools available on the web, but most of them are for the traditional MRTG logs and not for the rrd (round-robin database) log format. Though not as straight forward as sql, some complex queries can nevertheless be issued on the rrd log files using rrdtool.

This tool is a php-based rrd log querying tool developed as a part of my M.Tech thesis.

Requirements

  1. A functional web server, preferably apache
  2. MRTG and RRDTOOL should be installed on the system.
  3. In the mrtg configuration file, add LogFormat: rrdtool
  4. Enable passwordless sudo access for apache user (DEBIAN:www-data or REDHAT:apache) if you wish to add interfaces to the mrtg config through the web interface. (Read this post for the right way to do this step)

Installation

  1. In the queryMrtg.php:
    • Set $mrtgdir to the location where mrtg is configured to store its rrd logs, e.g. /var/www/mrtg
    • Set $mrtgcfg to the absolute path of the mrtg configuration file, e.g. /etc/mrtg.cfg
    • Set $rrdcommand to the rrdtool binary, e.g. /usr/bin/rrdtool
    • Set $cfgmaker to the cfgmaker binary, e.g. /usr/bin/cfgmaker
    • Set $imgdir to the directory where images will be stored. Create this as a sub-directory of the exported directory in apache (e.g. /var/www/html/images). Add the path relative to the exported directory i.e. if /var/www/html is exported in httpd.conf, then simply write 'images'.
    • In the $interfaces array, add all the interfaces that you wish to monitor and query.
  2. Copy queryMrtg.php to the web-exported directory. e.g. /var/www/html/queryMrtg.php


Usage

  1. On your browser, type - http://localhost/queryMrtg.php
  2. First time usage - Just click 'Submit'. It would report that MRTG configuration has not been added for the specified interface, and will show a button to add it. Just click!
  3. Once you have added interfaces to MRTG configuration, just play around with queries.
Contact
mailto: venkatesh@iitg.ernet.in OR rvenkatesh25@users.sourceforge.net

Screen Shots


Download

querymrtg.tar.gz

Downloading mp3 from Internet - the google way

For music, google -

intitle:"index of" (mp3|mp4|wav) name.of.file -html -htm -asp -jsp -cf -php

Explanation: you are searching for directory listings only. All web pages (html, php etc) are filtered out. Apache's directory listings have "Index of" in the title.

vimrc

This is the vimrc I use:

" Set syntax on
syntax on

" Indent automatically depending on filetype
filetype indent on
set autoindent

" Case insensitive search
set ic

" Higlhight search
set hls

" Incremental search
set incsearch

" Wrap text instead of being on one line
set lbr

" Change colorscheme from default to delek
colorscheme delek

" statusline shown in blue
highlight StatusLine ctermfg=darkblue ctermbg=white

" Show ruler
set ruler

" Set the shell to use
set shell=bash

" Show brace matching as you edit
set showmatch

" Show working mode
set showmode

" Show the command
set showcmd

" Display a status bar
set laststatus=2

" Number of screen lines to use for the command-line
set cmdheight=1

" Shift width when you press <<>> to indent a line.
set shiftwidth=3

" Set Shift rounding off
set shiftround

" Patten matching
set magic

" Switch buffer to edit a new file, and use open file if it already open
set switchbuf=useopen,split

" Changes how backspace works.
set bs=2

" Expand Tab
set expandtab

" Number of spaces for a tab
set tabstop=8

" lines longer than the width of the window will not wrap
set wrap

" Searches does not wrap around the end of the file
set nowrapscan

"Not always equal
set noequalalways

"F2 to Save file
map :w
map B :w

map! :wa
map! B :wa

"F6 to switch window
map w

"Ctrl-Shift-F6 to show only curent file for editing in many windows
map :only!

"- to decrease the current window height
map - -

"= to increase the current window height
map = +

"_ to decrease the current window width
map _ <

"+ to increase the current window width
map + >

"Alt-Up to go to upper window
map k

"Alt-Down to go to the lower window
map j

"Alt-Left to go to the left window
map h

"Alt-Down to go to the right window
map l

Acknowledgments to my friend and mentor Shriram V. This vimrc is the set of those lines which I understood from his highly sophisticated version :)

SSH too slow?

Does it take too long for ssh to ask for password after you've entered ssh user@host?

Edit /etc/ssh/sshd_config

Uncomment this line if present, add it otherwise -
UseDNS no

restart sshd
/etc/init.d/ssh restart

Done!

Some essential packages for ubuntu

To mount and read/write ntfs partitions => ntfs-3g

Installed gparted. To enable create/resize ntfs partitions => ntfsprogs

To enable mp3 support for rythmbox and other gstreamer based players => gstreamerX.YZ-fluendo-mp3
(e.g. gstreamer0.10-fluendo-mp3 or gstreamer0.8-fluendo-mp3)

To install flash player in 64-bit browsers => nspluginwrapper and flashplayer-nonfree (for Ubuntu Gutsy onwards. Others refer here)

exec and shell_exec

In php, both exec() and shell_exec() are used to execute shell commands. When to use which one?

shell_exec() is same as backtick operator. i.e.

echo `ls -l`; is same as
$r = shell_exec("ls -l"); echo $r;

use this when you don't need the return value (0 or some number) of the command.


exec() takes three parameters:
1. command
2. address of the array where the output will be stored
3. address of a integer variable in which the return value will be stored
e.g:

$output = array();
exec("ls -l", &$output, &$ret);

exec returns only the last line of the output, so if you need to process the output, use the $output array.

Here are the manuals for shell_exec and exec.

Passwordless ssh

1. generate keys
localhost$ ssh-keygen -t rsa
Generating public/private rsa key pair.
Enter file in which to save the key (/home/localuser/.ssh/id_rsa):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/localuser/.ssh/id_rsa.
Your public key has been saved in /home/localuser/.ssh/id_rsa.pub.
The key fingerprint is:
1d:75:9f:51:3d:16:40:85:7c:aa:17:84:38:2
c:4e:6b localuser@localhost

2. copy public key to remote host
localhost$ cat ~/.ssh/id_rsa.pub | ssh remoteuser@remotehost "cat - >> ~/.ssh/authorized_keys"

3. now test
localhost$ ssh remoteuser@remotehost

remotehost$



Troubleshooting
1. ensure the following on the remote host

chmod 700 /home/remoteuser
chmod 700 /home/remoteuser/.ssh
chmod 644 /home/remoteuser/.ssh/authorized_keys

In /etc/ssh/sshd_config

RSAAuthentication yes
AuthorizedKeysFile .ssh/authorized_keys