Fedora, ISPConfig, Linux, News, Pen Testing, PHP, Red Audit, Red Hat, Security, Technology
Low Bandwidth Zoneminder Stills On iPhone
The following will allow you to view your Zoneminder stills from the previous blog post on most web browsers including an iPhone. You need the stylesheet and expand settings if you plan on viewing stills through an iPhone without having to double-tap the image on every refresh. The php variable following ?time= is necessary to prevent Safari from displaying cached images.
Create a file called webcam1.php:
Create a file called style.css or append the following to your current stylesheet:
Low Bandwidth Zoneminder Webcam Stills Using Inotifywait
This bash script will get the latest Zoneminder webcam images using inotifywait and copy it to a local or remote folder every 5 seconds. Implement this script when streaming is unnecessary and you don't want to expose your Zoneminder systems to the internet (low bandwidth monitoring and low disk space archival).
Notes: You must have inotify-tools installed: yum install inotify-tools. I use sshfs to automatically mount remote system folders.
VMware ESXi 4.0 and Dell Inspiron 530 Core 2 Quad: ESXi Only Sees One Core Per Socket
I was converting several of my testbed systems over to VMware ESXi 4.0 and ran into an issue where two of the ESXi servers were reporting one core per socket with one logical processor, even though they were Core 2 Quad's.
ESXi's "Summary" page returns -
Processor Sockets: 1
Cores Per Socket: 1
Logical Processors: 1
To allow VMware ESXi 4.0 to see the correct number of processors for Dell Inspiron 530 systems:
1. Hold "F2" during boot for the Setup menu.
2. Select "Advanced BIOS Features."
3. Press Enter at "CPU Feature."
4. Ensure "Limit CPUID Value" is set to Disabled (Disabled By Default).
ESXi's "Summary" page should now report -
Processor Sockets: 1
Cores Per Socket: 4
Logical Processors: 4
KeePassX 0.4.0 On CentOS 5
OS: CentOS 5.3 i386
Kernel: 2.6.18-128.1.10.el5PAE
KeePassX is a useful tool for any individual with numerous accounts, and critical for systems administration where 20+ character passwords are changed often. These instructions will allow you to run KeePassX 0.4.0 in a CentOS 5.3 X Windows Environment.
1) Remove qt-devel to prevent conflicts:
2) Install required packages:
3) Add the bleeding edge ATrpms repo, then install qt44 related packages:
OR
3) Download the RPMs from ftp.pbone.net. WARNING: If you don't trust the package, don't install it or review the code before installing with a rpm2cpio packagename | cpio -idmv.
4) Download the latest version of KeePassX from http://keepassx.sourceforge.net.
5) Verify the package's sha1sum:
6) Extract the package contents:
7) Change your directory to the keepassx-0.4.0 folder:
8) Configure and install:
After a successful installation, you will find KeePassX listed in your Gnome menu - Applications | Accessories | KeePassX.
Privacy Policy
Our Privacy Policy will assist you in understanding how we collect and use the personal information you provide to us and to assist you in making informed decisions when using our site and services.
Terms of Use
Red Audit LLC ("Red Audit") requires all visitors to RedAudit.com (referred to as "Web Site") to agree to be bound by the following terms and conditions ("Terms of Use"). By browsing, accessing, submitting, downloading and using any material on the Web Site you agree to the Terms of Use. Please exit this Web Site if you do not agree to be bound by the Terms of Use.
This Web Site contains material that is derived in whole or in part from material supplied by Red Audit and is protected by U.S. and international copyright and trademark laws. No material (including but not limited to the copyrights, trademarks, images, text, audio and/or video individually and collectively the "Materials") may be copied, reproduced, republished, uploaded, posted, transmitted, or distributed without the express written consent of Red Audit. Modification of the Materials or use of the Materials for any other purpose is a violation of Red Audit's or such other sources copyright, trademark and other proprietary rights.
Red Audit authorizes you to download, view, copy, print, distribute, and modify documentation, software, and programs from this Web Site, as long as you agree to:
- Retain all copyright, trademark, and any propietary notices on such documentation, software, and programs.
- Get written permission before using any images or logos from this Web Site.
Under no circumstances, including, but not limited to, negligence, shall Red Audit be liable for any direct, indirect, incidental, special or consequential damages that result from the use of, or the inability to use RedAudit.com's Materials, documentation, software, programs or any resource or site linked, accessed, or referred to from this Web Site. You acknowledge and agree that Red Audit is not responsible for any contact or interaction that occurs between you and any other members. You specifically acknowledge and agree that Red Audit is not liable for any defamatory, offensive or illegal conduct of any user. If you are not satisfied with any of RedAudit.com's information, or with any of Red Audit's Terms of Use, your sole and exclusive remedy is to discontinue using RedAudit.com.
Use of this Web Site is at your SOLE RISK and all Materials, software, and programs are presented "AS IS" without warranty or guarantee of any kind. Red Audit disclaims any warranties, guarantees, or representations, including, but not limited to merchantibility, fitness for a particular purpose, or non-infringement of propietary rights.
You agree to indemnify, defend and hold harmless, Red Audit and its respective officers, employees, agents, licensors, representatives and third party providers to the Site from and against all losses, expenses, damages and costs, including reasonable attorneys' fees, resulting from any violation of these Terms of Service by you.
- Material you submit, post, or make available for inclusion on publicly accessible areas of the Site, you grant Red Audit the following world-wide, royalty free and non-exclusive license(s) to use, distribute, adapt, modify, reproduce, copy and publicly display such Content on the Site. This license is used to promote and enhance the RedAudit.com Site.
- Material you directly submit, mail to, or email to Red Audit, the license to use, distribute, adapt, modify, reproduce, copy, publicly perform and publicly display such Content on the Site. This license is a perpetual, irrevocable and fully sublicensable license to use, distribute, adapt, reproduce, modify, copy, publish, translate and publicly display such Material (in whole or part) and to incorporate such Content into other works in any format or medium known or developed in the future.
You agree that RedAudit.com may review and delete any content, messages, comments or profiles (collectively known as "Content") that RedAudit.com deems offensive, illegal, or that might violate the rights, injure or threaten the safety of other users. You are solely responsible for information you post, display, or transmit to other Members.
The following list is the kind of Content that is illegal or prohibited on the Site:
- Patently offensive to the public or online community
- Slander, libel or displaying personal information without an individual's written consent
- Stalking or harrassing another individual
- Spamming, junk mail, chain letters
- Promoting illegal activities or conduct that is abusive
- Promoting unauthorized copying of copyrighted work or pirating software/music
- Material that exploits minors
- Solicitation of passwords or identity theft for unlawful purposes
- Promoting illegal contests, sweepstakes, raffles, pyramid schemes
RedAudit.com at its sole discretion will investigate any reports of abuse and may give a warning or terminate the account of any violators.
You agree that Red Audit may, under certain circumstances and without prior notice, can immediately terminate your RedAudit.com account. Causes for such termination shall include, but is not be limited to:
- breaches or violations of the TOS or other agreements or Individual Content guidelines
- requests by government agencies or law enforcement
- a request by you for account deletion
- discontinuance or Material modification to the Service (or any part thereof)
- unexpected technical, security or network problems
- extended periods of inactivity
Recognizing the global nature of the Internet, you agree to comply with all local laws and regulations regarding online conduct and acceptable Content. You agree to comply with all applicable laws regarding the transmission of data, video, images exported from the United States or the country in which you reside.
RedAudit.com contains links to other sites, advertisers, or sponsors. The use of any information or materials that you may access at these external sites is purely voluntary. These external sites may also refer to specific commercial products, processes, or services by trade name, trademark, service mark, manufacturer or otherwise. In no way, does RedAudit.com indicate our endorsement, recommendation or preference for these external links.
This agreement shall be governed by and construed in accordance with the laws of the State of Virginia without giving effect to any principles or conflicts of law. If any provision of this agreement shall be unlawful, void or for any reason unenforceable, then that provision shall be deemed severable from this agreement and shall not affect the validity and enforceability of any remaining provisions.
Red Audit may revise the Terms of Use at any time.
Lacie itsaKey - Simple Idea: USB Flash Drive For Your Keychain
I tried using other flash drives in my keychain prior to purchasing the Lacie itsaKey, but those other cheap, plastic flash drives couldn't withstand all the jostling that happens in a pocket. While the itsaKey, iamaKey, and PassKey flash drives are more expensive than normal flash drives, they're durable and worth the price.
The 8 GB itsaKey holds more than enough data for my pentesting needs. Having Backtrack connected to a keychain is so useful, when it's not convenient to carry a laptop. I'm hoping Lacie comes out with more designs in the near future, because my flash key collection needs to grow.
Uninstalling ISPConfig 2.2.23 Causes Mass Bounced Mails
After uninstalling ISPConfig, you may notice hundreds to thousands of e-mails in your /var/mail files.
These e-mails will contain two messages:
AND
To resolve these spam/bounce/annoying e-mails -- remove the .mailsize.rc files from your /httpdroot/webx/user/username folder:
Change /var/www/ to your httpdroot folder -
Restart postfix:
Uninstalling ISPConfig 2.2.23 Causes Apache To Fail
After uninstalling ISPConfig 2.2.23, your httpd services may fail during startup.
To resolve this issue:
Comment out the two lines below ispconfig_log by putting a # symbol in front:
Then write quit the file:
Attempt to restart your httpd services:
The httpd service should start correctly :
Verify that your websites are up and running.
Surveys Say: Be Concerned About Internal Threats
No surprise here, internal breaches from disgruntled employees and human stupidity are worrisome for security professionals around the world. There's so many attack vectors to consider when an individual has physical and virtual access to systems sitting in your company's LAN.
Become an Infosec Nazi, if you aren't already (for your peace of mind):
- Time to lock Administrative permissions down to core staffers (no installation privileges for end-users).
- Block Facebook, Myspace, and other social networking sites on the router.
- No USB drives/CDR/DVDR allowed on premises.
- Configure all systems to not use bluetooth and USB.
- Encrypt your vital data using Truecrypt or PGP.
- Ensure copies of encrypted vital data are in offline systems.
- Probe with Nessus/BackTrack for systems running unwanted services and unusual open ports on a regular basis
