Saturday, July 26, 2008

How To Install Adobe Flash Player 10 in Fedora

Adobe had release the latest flash player version 10. If you currently have a lower version, it is adviseable to install the latest release as it fixes some issues with the lower version.

Install Flash Player 10

Step One


Using Fedora, it is important to uninstall the lower Flash Player version. To remove old flash player

# rpm -qa flash*

# rpm -e flash-lower-version.rpm

Step Two

Download Flash Player 10 rpm for linux from here. Alternatively, install it direct using rpm package installer

# rpm -ivh http://download.macromedia.com/pub/labs/flashplayer10/flashplayer10_install_linux_070208.i386.rpm

If you choose to download the latest Flash Player 10, launch rpm package installer to install your downloaded file like so

# rpm -ivh flashplayer10_install_linux_070208.i386.rpm

Step Three

Close and start your browser. Go to flash-enabled websitesand test Flash Player 10 Beta.

It works out right like a charm. All is done.

How To Add and Install Alternative Liberation Fonts

Fedora project endorses liberation fonts. Fedora encourages to install liberation fonts as one of alternative linux fonts that also comes with Fedora installer images. By default X installation, liberation fonts are installed by default.

The Liberation Fonts are intended to be replacements for the three most commonly used fonts on Microsoft systems namely Times New Roman, Arial, and Courier New. If you wish to have these fonts into your system, read on.

To install liberation fonts, simply launch yum to do so

# yum -y install liberation-fonts

All is done.

Friday, July 25, 2008

Digg it: Top 1 Supercomputer is powered by Fedora

Fedora is stable linux distro around which offers the latest, razor-sharp and bleeding edge linux applications and softwares around the OS world. Yes, Fedora is stable and is good alternative on server setup.

Inviting you to quick digg Fedora's super empowering the #1 super computer of the world.

Digg Here


Thanks

How To Send System Message To FTP Clients via TCP Wrapper

From recent posts, granting access (allow and deny) restrictions to particular services is a good additional security practice anybody could use of nowadays. There are some system admins that prefer sending system message or account status when denying access to particular clients or hosts.

Sending service message or service system status to particular hosts or group of hosts can lessen on-site technical phone calls during scheduled system maintenance works while making connecting clients informed and be reminded of your service message.

Send System Message to FTP Clients via TCP Wrapper

Step One

Backup and modify /etc/hosts.allow to reflect the below similar lines. Assuming that VsFTPd daemon service is running as current FTP server.

vsftpd: 83.83.83.83 :  twist /bin/echo "220 %h FTP account has expired, please renew."

vsftpd: 192.168.100.100 :  twist /bin/echo "220 %h has been banned, go away!"

vsftpd: 192.168.100.10 :  twist /bin/echo "220 %h We are on scheduled maintenance, try later. Thanks"

The above instructs TCP wrapper to deny access to

83.83.83.83

192.168.100.100

192.168.100.10

Each has separate log message to be sent to the connecting clients.

Save and exit.

No restart is needed from any daemon services. Portmap and Rpcbind daemon services are not required to be enabled from this setup.

Step Two

Verify changes with your host access restrictions via TCP wrapper. Using a separate linux host

# telnet domain.com 21

# ftp domain.com

Alternatively, from a separate windows host, launch your FTP client software and verify the message by connecting to domain.com as an example.

A similar output would be

Trying domain.com...
Connected to domain.com
Escape character is '^]'.
220 We are on scheduled maintenance, come back later.
Connection closed by foreign host.

This would work out right from RedHat, CentOS, White OS and Fedora boxes.

All is done

Intel Switches From Ubuntu To Fedora For Mobile Linux

An anonymous reader writes

"According to a report on heise, Intel is switching from using Ubuntu to the Fedora Project for the second version of the Intel supported Mobile & Internet Linux Project Moblin, citing a desire to use RPM package management."

Read more.

Intel Switches From Ubuntu To Fedora For Mobile Linux

An anonymous reader writes

"According to a report on heise, Intel is switching from using Ubuntu to the Fedora Project for the second version of the Intel supported Mobile & Internet Linux Project Moblin, citing a desire to use RPM package management."

Read more.

How To Create Separate SSH Log File for Specific SSH Clients

By default, OpenSSH dumps log messages to /var/log/secure authentication log file. The need to log particular host or group of IP address to separate SSH log file is needed at times to further log SSH details for further record and monitoring.

Create Separate SSH Log File for Particular SSH Client Log Attempts

Here's how to log particular SSH client to separate SSH log file.

Step One

Create the separate SSH log file

# touch /var/log/abusive.log

and make sure it is readable and writable by root.

# chmod 600  /var/log/abusive.log

Step Two

Modify /etc/hosts.allow and append a similar line shown below

sshd:  83.83.83.83 : spawn /bin/echo `/bin/date` from %h %u >> /var/log/abusive.log

Alternatively, you can log a group of hosts to separate SSH log file

sshd: *.google.com : spawn /bin/echo `bin/date` from %h %c >> /var/log/abusive.log

To group SSH clients to particular log gile

sshd: *.yahoo.com : spawn /bin/echo `bin/date` from %h %c >> /var/log/yahoo-ssh.log

Save and exit. Noticed that we use the SPAWN tcp wrapper operator to log every hosts under google.com and dump the corresponding date of SSH login attempt to /var/log/abusive.log SSH log file.

Now, to log to separate SSH log file and completely deny particular host under google.com domain, simply

sshd: *.google.com : spawn /bin/echo `bin/date` from %h %c >> /var/log/abusive.log : deny

Save and exit.

No need to restart any services like SSH or XInet .

Supported Parameter Expansions

Below is a list of supported expansions:


  • %a — The client's IP address.

  • %A — The server's IP address.

  • %c — Supplies a variety of client information, such as the username and hostname, or the username and IP address.

  • %d — The daemon process name.

  • %h — The client's hostname (or IP address, if the hostname is unavailable).

  • %H — The server's hostname (or IP address, if the hostname is unavailable).

  • %n — The client's hostname. If unavailable, unknown is printed. If the client's hostname and host address do not match, paranoid is printed.

  • %N — The server's hostname. If unavailable, unknown is printed. If the server's hostname and host address do not match, paranoid is printed.

  • %p — The daemon process ID.

  • %s — Various types of server information, such as the daemon process and the host or IP address of the server.

  • %u — The client's username. If unavailable, unknown is printed.


Monitoring Separate SSH Log File

# tailf /var/log/abusive.log

Log File

Similar SSH log lines from /var/log/abusive.log would be

Fri Jul 25 10:26:52 WAT 2008 from hostname.google.com

The above should work out right with RedHat, CentOS, Fedora, White OS distros.

All is done.

How To Allow and Deny SSH Access To Selected Hosts and IP Addresses

With default OpenSSH installation, SSH allows access to any clients. This retriction can be configured to allow SSH access only to certain hosts and IP addresses to decrease unauthorized SSH login attempts to known and particular computer hosts and IP addresses only.

SSH Access Restrictions via TCP Wrapper

Step One

1. Backup and modify /etc/hosts.allow

# nano -w /etc/hosts.allow

Allow and Deny SSH Access to Specific Hosts / IP Addresses

To allow SSH access to IP address 83.83.83.83 , modify /etc/hosts.allow to reflect the below lines

sshd: 83.83.83.83

Access will be granted if both pairs represent a match. TCP wrappers should allow access if a matching SSH protocol and an IP address 83.83.83.83 is present from the requesting connection.

To allow SSH access to all hosts and/or subdomain(s) that is part of the parent domain yahoo.com

sshd:  .yahoo.com

To grant SSH access to multiple IP address, simply append multiple address as shown

sshd: 83.83.83.83 127.0.0.1 83.83.83.84 192.168.1.1

To allow SSH access to starting IP address

sshd: 192.168.

To allow SSH access with network IP netmask

sshd: 192.168.1.0/255.255.255.0

To use asterisk (*) from /etc/hosts.allow

sshd: *.yahoo.com

To specify a large set of IP addresses and known hosts from a file

sshd:  /etc/allowed.txt

To specify multiple hosts and IP addresses with excemption using except TCP wrapper operator

sshd: .yahoo.com EXCEPT search.yahoo.com

To allow access to everyone under .yahoo domain except 83.83.83.83

sshd: *.yahoo.com EXCEPT 83.83.83.83

To specify multiple SSH access restriction with multiple lines

sshd: 111.111.111.111

sshd: 222.222.222.222

If the above access lists rules appears inside /etc/hosts.allow, TCP wrappers allows the request. If the above lines appears from /etc/hosts.deny, TCP wrappers deny the request.

Step Two

To deny any other ssh access except from the ones listed from /etc/hosts.allow, backup and modify /etc/hosts.deny file

ALL: sshd

Save and exit.

All is done.

Thursday, July 24, 2008

Fedora 10 - Friends, Freedom, Features, and First

Fedora is planning to have a new project motto foundation. Instead of having infinity / freedom and voice as a front motto banner, an alternative plan to move it to friend, freedom, features and first is currently being escalated.

See more here.

Fedora 10 - Friends, Freedom, Features, and First

Fedora is planning to have a new project motto foundation. Instead of having infinity / freedom and voice as a front motto banner, an alternative plan to move it to friend, freedom, features and first is currently being escalated.

See more here.

The Mess That is Linux Volume Management

The GNU/Linux operating system is blessed to have sound partition management tools like GParted which are very easy to use. However, when it comes to the management of 'virtual partitions' known as volumes, things are quite different. There is Linux Volume Management, or LVM for short, however it can only really be used from the command line...


Complete Story

Are We About to Witness a Real OS X virus?

Mac Antivirus developer Intego might have stumbled across an OS X specific virus being offered for auction that targets a previously unknown ZIP archive vulnerability. From Intego's posting, it appears that an enterprising auctioneer seems determined to make sure that his name is one that is not forgotten when it comes to Apple security, claiming that his exploit is a poisoned ZIP archive that will "KO the system and Hard Drive" when unarchived...


Complete Story

Security is No Secret

NSA takes its Flask architecture to the open-source community to offer an inexpensive route to trusted systems. "What it really helps out with is something called zero-day exploits," said Daniel Walsh, a principal software engineer at Red Hat and leader of the company's SELinux team. "If you have a bug in your software that allows a machine to be taken over, SELinux [provides] another layer of controls to make sure that application only does what is was designed to do. SELinux is your last line of defense."..


Complete Story

Enterprise Storage Solution Using Nand Flash and ZFS

Sun CEO Jonathan Schwartz has an interesting blog entry about how Sun Microsystems will start introducing Nand Flash with ZFS as an enterprise storage solution by the end of this year. With the price of Flash memory already plummeting this could be an economical alternative to the expensive NAS solutions...


Complete Story

Shuttleworth Sets Bar For Linux 'Beyond Apple'

Mark Shuttleworth today urged development of Linux models to rival what Apple has done on the desktop and mobile devices. Certainly on the desktop experience, we need to shoot beyond the Mac, but I think it's equally relevant [in] the mobile space, Shuttleworth said, outlining the challenge as figuring out how to deliver a 'crisp and clean' experience, without sacrificing the community process. Key to this will be services-based mechanisms for creating revenue for free software that go beyond advertising, Shuttleworth said, adding that cadence in free software releases spurs innovation, and that a regular release schedule, as well as meaningful ties to Windows, will be essential to fulfilling the vision...


Complete Story

Why We Still Need the iPhone App Black Market

There are no less than five apps to turn my iPhone into a flashlight, yet I can't turn it into a 3G-powered Wi-Fi hotspot. Why? Because the SDK has more restrictions than Guantanamo-devs can't integrate with the OS and have to steer way, way clear of copyright and trademark issues-so the most innovative, game-changing apps might not ever make it to your squeaky clean iPhone." An editorial by Gizmodo. Many kinds of apps (from multi-IM apps running on the background, to copy/paste) require the level of system integration that either is not possible via the existing official API, or that Apple artificially limits via lawyers...


Complete Story

DragonFly BSD 2.0 Released

Matthew Dillon has announced the availability of DragonFly BSD 2.0. Also HAMMER filesystem is released with the new DragonFly. Read the full Release Notes...


Complete Story

Interview with Mandriva's KDE Developer Helio Castro

The How Software is Built blog secured an interview with Helio Chissini de Castro, one of the KDE developers employed by Linux distributor Mandriva. Helio talks about Mandriva, about KDE 4, and about the state of open source software in Brazil, where he is based...


Complete Story

Mandriva and PTech Announce Low-cost Desktop

Mandriva and Precedent Technologies (PTech) are pleased to announce a new partnership, working together on the release in September in the United States of a new low-cost desktop - the TechSurfer - with Intel Atom CPUs and Mandriva Linux preinstalled. TechSurfer is a web-centric computing platform that is designed for customers who mostly surf the web; download music; and utilize VOIP services, such as Skype. The TechSurfer platform is also suitable for light desktop applications. TechSurfer is powered by the Intel Atom processor. The Atom processor was designed especially for web-centric computers. TechSurfer prices starts at $399.99 with Mandriva Linux pre-installed: Microsoft Windows will cost an extra $100. The system will come with a three-year manufacturer's warranty. Find out more in the press release.
Editor's note: Looks like Mandriva is taking full-advantage of the Low-cost hardware arena. First the Intel's ClassmatePC then the GDium and now PTech...


Complete Story

The Coco Bidet and Toilet Technology

"The Japanese love those things!" That's what I've heard a lot of people say when I've talked to them about my latest obsession, the Coco 6035Re Bidet toilet seat. As part of OSNews' ongoing project, "Building The Wired Home," I wanted to try to see what the march of technological progress has brought to the bathroom, so we installed a bidet seat in OSNews' House of the Future. It turns out, I'm pretty impressed...


Complete Story

The Mess That is Linux Volume Management

The GNU/Linux operating system is blessed to have sound partition management tools like GParted which are very easy to use. However, when it comes to the management of 'virtual partitions' known as volumes, things are quite different. There is Linux Volume Management, or LVM for short, however it can only really be used from the command line...


Complete Story

Are We About to Witness a Real OS X virus?

Mac Antivirus developer Intego might have stumbled across an OS X specific virus being offered for auction that targets a previously unknown ZIP archive vulnerability. From Intego's posting, it appears that an enterprising auctioneer seems determined to make sure that his name is one that is not forgotten when it comes to Apple security, claiming that his exploit is a poisoned ZIP archive that will "KO the system and Hard Drive" when unarchived...


Complete Story

Security is No Secret

NSA takes its Flask architecture to the open-source community to offer an inexpensive route to trusted systems. "What it really helps out with is something called zero-day exploits," said Daniel Walsh, a principal software engineer at Red Hat and leader of the company's SELinux team. "If you have a bug in your software that allows a machine to be taken over, SELinux [provides] another layer of controls to make sure that application only does what is was designed to do. SELinux is your last line of defense."..


Complete Story

Enterprise Storage Solution Using Nand Flash and ZFS

Sun CEO Jonathan Schwartz has an interesting blog entry about how Sun Microsystems will start introducing Nand Flash with ZFS as an enterprise storage solution by the end of this year. With the price of Flash memory already plummeting this could be an economical alternative to the expensive NAS solutions...


Complete Story

Shuttleworth Sets Bar For Linux 'Beyond Apple'

Mark Shuttleworth today urged development of Linux models to rival what Apple has done on the desktop and mobile devices. Certainly on the desktop experience, we need to shoot beyond the Mac, but I think it's equally relevant [in] the mobile space, Shuttleworth said, outlining the challenge as figuring out how to deliver a 'crisp and clean' experience, without sacrificing the community process. Key to this will be services-based mechanisms for creating revenue for free software that go beyond advertising, Shuttleworth said, adding that cadence in free software releases spurs innovation, and that a regular release schedule, as well as meaningful ties to Windows, will be essential to fulfilling the vision...


Complete Story

Why We Still Need the iPhone App Black Market

There are no less than five apps to turn my iPhone into a flashlight, yet I can't turn it into a 3G-powered Wi-Fi hotspot. Why? Because the SDK has more restrictions than Guantanamo-devs can't integrate with the OS and have to steer way, way clear of copyright and trademark issues-so the most innovative, game-changing apps might not ever make it to your squeaky clean iPhone." An editorial by Gizmodo. Many kinds of apps (from multi-IM apps running on the background, to copy/paste) require the level of system integration that either is not possible via the existing official API, or that Apple artificially limits via lawyers...


Complete Story

DragonFly BSD 2.0 Released

Matthew Dillon has announced the availability of DragonFly BSD 2.0. Also HAMMER filesystem is released with the new DragonFly. Read the full Release Notes...


Complete Story

Interview with Mandriva's KDE Developer Helio Castro

The How Software is Built blog secured an interview with Helio Chissini de Castro, one of the KDE developers employed by Linux distributor Mandriva. Helio talks about Mandriva, about KDE 4, and about the state of open source software in Brazil, where he is based...


Complete Story

Mandriva and PTech Announce Low-cost Desktop

Mandriva and Precedent Technologies (PTech) are pleased to announce a new partnership, working together on the release in September in the United States of a new low-cost desktop - the TechSurfer - with Intel Atom CPUs and Mandriva Linux preinstalled. TechSurfer is a web-centric computing platform that is designed for customers who mostly surf the web; download music; and utilize VOIP services, such as Skype. The TechSurfer platform is also suitable for light desktop applications. TechSurfer is powered by the Intel Atom processor. The Atom processor was designed especially for web-centric computers. TechSurfer prices starts at $399.99 with Mandriva Linux pre-installed: Microsoft Windows will cost an extra $100. The system will come with a three-year manufacturer's warranty. Find out more in the press release.
Editor's note: Looks like Mandriva is taking full-advantage of the Low-cost hardware arena. First the Intel's ClassmatePC then the GDium and now PTech...


Complete Story

The Coco Bidet and Toilet Technology

"The Japanese love those things!" That's what I've heard a lot of people say when I've talked to them about my latest obsession, the Coco 6035Re Bidet toilet seat. As part of OSNews' ongoing project, "Building The Wired Home," I wanted to try to see what the march of technological progress has brought to the bathroom, so we installed a bidet seat in OSNews' House of the Future. It turns out, I'm pretty impressed...


Complete Story

Sign up for PayPal and start accepting credit card payments instantly.
ILoveTux - howtos and news | About | Contact | TOS | Policy