2013年9月25日 星期三

Redhat 4,5 Bonding 雙網卡網路

RedHat 4 的作法
vim /etc/modprobe.conf
alias bond0 bonding

若有多張網卡,可定議如下
alias bondx bonding
x為數字
依此類推

新增/etc/sysconfig/network-script/ifcfg-bond0
若有多張網卡,可以定議如下
/etc/sysconfig/network-script/ifcfg-bondx
x為數字
/etc/sysconfig/network-script/ifcfg-bond0 設定如下
DEVICE=bond0
IPADDR=192.168.1.2
NETMASK=255.255.255.0
USERCTL=no
BOOTPROTO=none
ONBOOT=yes
BONDING_OPTS="mode=1 miimon=100"

/etc/sysconfig/network-script/ifcfg-eth0
DEVICE=eth0
BOOTPROTO=none
ONBOOT=yes
MASTER=bond0
SLAVE=yes
USERCTL=no

/etc/sysconfig/network-script/ifcfg-eth1
DEVICE=eth1
BOOTPROTO=none
ONBOOT=yes
MASTER=bond0
SLAVE=yes
USERCTL=no

重啟網路
service network restart


RedHat 5 的作法
新增/etc/modprobe.d/aliases.conf ,這檔名可以自定,只要最後是帶.conf就可以被系統認出
alias bond0 bonding 若有多張網卡,設定與RH4相同

新增/etc/sysconfig/network-scripts/ifcfg-bond0
DEVICE=bond0
TYPE=bonding
BOOTPROTO=static
IPADDR=192.168.1.3
NETMASK=255.255.255.0
GATEWAY=192.168.1.1
ONBOOT=yes
USERCTL=no
NM_CONTROLLED=no
BONDING_OPTS="mode=6 miimon=100 updelay=200 downdelay=200"

vim /etc/sysconfig/network-scripts/ifcfg-eth0
# Broadcom Corporation NetXtreme II BCM5709 Gigabit Ethernet
DEVICE=eth0
HWADDR=5C:F3:FC:4B:FA:xx 這是你要綁定那一張網卡,可別照抄了
BOOTPROTO=none
NM_CONTROLLED=no
ONBOOT=yes
MASTER=bond0
SLAVE=yes
USERCTL=no


/etc/sysconfig/network-scripts/ifcfg-eth1
DEVICE=eth1
HWADDR=5C:F3:FC:4B:FA:xx  這是你要綁定那一張網卡,可別照抄了
BOOTPROTO=none
NM_CONTROLLED=no
ONBOOT=yes
MASTER=bond0
SLAVE=yes
USERCTL=no

重啟網路
service network restart


模式有以下幾種,我各人比較偏好模式6
以下摘自http://marcustsai.blogspot.tw/2012/11/rhel5-6-nic-bonding.html
3.Bond Mode:

0balance-rr‧負載平衡模式, 需有 switch 設定 (trunk) 支援才能發揮實質效果
‧具容錯功能, 其中一張 Slave 網卡失效仍可持續運作
1active-backup‧同一時間只有單一 Slave 網卡運作
‧Active Slave 網卡失效時自動啟用次一順位 Slave 網卡
‧不需 switch 支援
2balance-xorTransmit based on [(source MAC address XOR'd with destination MAC address) modulo slave count]. This selects the same slave for each destination MAC address. This mode provides load balancing and fault tolerance.
3broadcast‧所有 Slave 網卡一齊收送網路封包
‧具容錯功能, 其中一張 Slave 網卡失效仍可持續運作
4802.3adIEEE 802.3ad Dynamic link aggregation. Creates aggregation groups that share the same speed and duplex settings. Utilizes all slaves in the active aggregator according to the 802.3ad specification.

*Pre-requisites:

1. Ethtool support in the base drivers for retrieving the speed and duplex of each slave.

2. A switch that supports IEEE 802.3ad Dynamic link aggregation. Most switches will require some type of configuration to enable 802.3ad mode
此模式可以參考 http://phorum.study-area.org/index.php?topic=43051.0
5balance-tlb‧傳出自動負載平衡
‧傳入由 Current Active Slave 負責
‧具容錯功能, 其中一張 Slave 網卡失效仍可持續運作
‧不需 switch 支援及設定
6balance-alb‧傳出及傳入皆自動負載平衡
‧具容錯功能, 其中一張 Slave 網卡失效仍可持續運作
‧Slave 網卡 driver 需支援 setting hardware address 功能
‧不需 switch 支援及設定

2013年7月25日 星期四

Servlet/JSP Gossip: URL 模式


常常與工程師們在講到URL 的部份,總會有些誤會,怎麼說呢?以我們的公司為例,主機歸系統部門管理,程式由開發部門管理,網頁程式是Java開發的。這樣看來一點也沒有錯,也很正常。但系統部門對於要部署上線的模組(程式)僅知道被布署的檔案名稱,對網頁要呈現的網址,是不清楚的,對你沒看錯,檔案名稱不一定是網頁上的網址。

因此對於跟工程師提到,"你的程式網址是什麼?"這樣的對話通常會得到一個回應,"主機是你管的,我怎麼會知道網址是什麼..."這邊認知的誤會是,網址通常包含http://1.2.3.4,這部份是系統管理人員才會知道。而其後的字串比如/Login.do 是程式的網址,完整的網址應該是http://1.2.3.4/Login.do。

因此,這邊找了一篇文章,用來描述一個完整的網址應該怎麼去稱呼
以下文章摘自http://openhome.cc/Gossip/ServletJSP/URLPattern.html



Servlet/JSP Gossip: URL 模式

一個請求URI實際上是由三個部份所組成,你可以使用HttpServletRequest的getRequestURI()來取得:
requestURI = contextPath + servletPath + pathInfo

其中contextPath是環境路徑(Context path),是容器用來決定該挑選哪個Web應用程式的依據(一個容器上可能部署多個Web應用程式),環境路徑的設定並非標準,依伺服器實作而有所不同。例如在Glassfish v3中,可以設定sun-web.xml的來決定。
你可使用HttpServletRequest的getContextPath()來取得。如果應用程式環境路徑與Web伺服器環境根路徑相同,則應用程式環境路徑為空字串,如果不是,則應用程式環境路徑以/開頭,不包括/結尾。

一旦決定是哪個Web應用程式來處理請求,接下來就進行Servlet的挑選,Servlet必須設定URL模式(URL pattern),可以設定的格式是:

  • "/"開頭但"/*"結尾的URL模式被用於路徑對應(Path mapping)。例如若設定URL模式為"/guest/*",則請求URI扣去環境路徑的部份若為/guest/test.view、/guest/home.view等以/guest/作為開頭的,都會交由該Servlet處理。
  • 以"*."開頭的URL模式被用於延伸對應(extension mapping)。例如若URL模式設定為"*.view",則所有以.view結尾的請求,都會交由該Servlet處理。
  • 空字串""是個特殊的URL模式,對應至環境根目錄(Context root),也就是/的請求,但不用於設置或urlPattern屬性。例如若環境根目錄為App,則http://host:port/App/的請求,路徑資訊是/,而Servlet路徑與環境路徑都是空字串。
  • 僅包括"/"的URL模式,表示預設Servlet,當找不到適合的URL模式對應時,就會使用預設Servlet。
  • 其它的字串設定,都是用在於嚴格匹配(Exact match)。

如果URL模式在設定比對的規則在某些URL請求時有所重疊,例如若有"/admin/login.do"、"/admin/*"與"*.do"三個URL模式設定,則請求時比對的原則是從最嚴格的URL模式開始符合。如果你請求/admin/login.do,則一定是由URL模式設定為/admin/login.do的Servlet來處理,而不會是/admin/*或*.do。如果你請求/admin/setup.do,則是由/admin/*的Servlet來處理,而不會是*.do。
在最上面的requestURI中,servletPath的部份是指Servlet路徑(Servlet path),不包括路徑資訊(Path info)與請求參數(Request parameter)。Servlet路徑直接對應至URL模式資訊,可使用HttpServletRequest的getServletPath()來取得,Servlet路徑基本上是以"/"開頭,但"/*"與""的URL模式比對而來的請求除外,在"/*"與""的情況下,Servlet路徑是空字串。
例如若某個請求是根據"/hello.do"對應至Servlet,則Servlet路徑就是"/hello.do",如果是透過"/servlet/*"對應至Servlet,則Servlet路徑就是/servlet,但如果是透過"/*"或"",則Servlet路徑就是空字串。

在最上面的requestURI中,pathInfo的部份是指路徑資訊(Path info),路徑資訊不包括請求參數,指的是不包括Context Path與Servlet Path部份的額外路徑資訊。可使用HttpServletRequest的getPathInfo()來取得。如果沒有額外路徑資訊,則為null(延伸對應、預設Servlet、嚴格匹配的情況下),如果有額外路徑資訊,則是個以"/"為開頭的字串。



mysql下缩小ibdata1

以下文張摘自http://blog.chinaunix.net/uid-20776139-id-3556494.html
1:mysql运行一段时间后,ibdata1 变得很大,尤其是繁忙的数据库,会变得更大
开始我在my.cnf中没有配置 innodb_file_per_table ,所有表的都放到ibdata1,该文件变得更大,我删除表,ibdata1也不会变小
ibdata1太大,看着不爽,我想缩小它!
2:我使用mysql自带的数据库test,在test库中创建了一个person表!然后多查点记录
见附件

最后记录的数目和ibdata1大小见附件!

2:将test数据库导出来,见附件

3:将现在的test数据库删除,然后重新创建 一个,见附件

4:下面是整个处理过程

显然ibdata1变小了!
查看person表记录(记录没丢失),见附件!

2013年7月18日 星期四

JBoss 安全性問題

JBoss 預設有一個網頁,上面可以看到主機安裝的模組,透過這些資訊,駭客將可以瞭解這部主機有那些弱點或漏動可以攻擊,在線上環境,這些服務應該都要被關閉才對。


How to disable status page for jboss (http://:8080/status)

Due to a possible information disclosure issue, remove access to the JBoss status page by following these steps for your version of the application server.

Step1: Go to jboss deploy folder (ex: cd /usr/local/jboss/server/default/deploy)

Step2: execute locate command as below
    # find . -iname ROOT.war

Step3: Based on the output switch to the ROOT.war directory

Step4: Go to WEB_INF directory which will be under ROOT.war directory (ex: .../deploy/jboss-web.deployer/ROOT.war/WEB-INF/)

Step5: find web.xml file and open using vim editor

Step 6: Comment out the servlet and servlet-mapping tags as follows:

<!-- <servlet>
<servlet-name>Status Servlet</servlet-name>
<servlet-class>org.jboss.web.tomcat.service.StatusServlet
</servlet-class>
</servlet>
<servlet-mapping>
<servlet-name>Status Servlet</servlet-name>
<url-pattern>/status</url-pattern>
</servlet-mapping> -->
3
Save and close the file.


另外來有以下的這一個文件,也有安全性上的問題,建議一併移除
以下文章摘自http://superuser.com/questions/501417/resolving-httpadaptor-jmxinvokerservlet-is-accessible-to-unauthenticated-remote


The http-invoker.sar Service
The http-invoker.sar found in the deploy directory is a service that provides RMI/HTTP access for EJBs and the JNDI Naming service. This includes a servlet that processes posts of marshaled org.jboss.invocation.Invocation objects that represent invocations that should be dispatched onto the MBeanServer. This effectively allows access to MBeans that support the detached invoker operation via HTTP because someone could figure out how to format an appropriate HTTP post. To secure this access point, you would need to secure the JMXInvokerServlet servlet found in the http-invoker.sar/invoker.war/ WEB-INF/web.xml descriptor. A secure mapping is defined for the /restricted/ JMXInvokerServlet path by default; to use it, you would simply have to remove the other paths and configure the http-invoker security domain setup in the http-invoker.sar/invoker.war/WEB-INF/jboss-web.xml descriptor.

2013年7月4日 星期四

查詢MySQL 資料庫的編碼

SHOW CREATE DATABASE DBNAME;

mysql> SHOW CREATE DATABASE DbName;
+----------+-----------------------------------------------------------------+
| Database | Create Database                                                 |
+----------+-----------------------------------------------------------------+
| DbName   | CREATE DATABASE `DbName` /*!40100 DEFAULT CHARACTER SET utf8 */ |
+----------+-----------------------------------------------------------------+
1 row in set (0.00 sec)



也可以用
use DBNAME;
status;

mysql> use DBNAME;
Reading table information for completion of table and column names
You can turn off this feature to get a quicker startup with -A

Database changed
mysql> status;
--------------
mysql  Ver 14.14 Distrib 5.5.32, for Linux (x86_64) using readline 5.1

Connection id:          313
Current database:       DBNAME
Current user:           root@localhost
SSL:                    Not in use
Current pager:          stdout
Using outfile:          ''
Using delimiter:        ;
Server version:         5.5.32-log MySQL Community Server (GPL)
Protocol version:       10
Connection:             Localhost via UNIX socket
Server characterset:   latin1
Db     characterset:    utf8
Client characterset:    latin1
Conn.  characterset:   latin1
UNIX socket:            /var/lib/mysql/mysql.sock
Uptime:                 50 min 29 sec

Threads: 51  Questions: 62069  Slow queries: 492  Opens: 274  Flush tables: 1  Open tables: 216  Queries per second avg: 20.491
--------------

第二個指令可以看的比較細

2013年6月20日 星期四

HOWTO: Remove the X-Powered-By Header in JBoss


This HOWTO was taken directly from a blog post written by me back in February, 2011. It has been edited and expanded to include JBoss Application Server versions up to version 7.1. Adapting them for JBoss Enterprise Application Platform versions should be simply a matter of determining which version of JBoss App Server - Community your version of JBoss EAP is based on.

Before Beginning

JBoss inserts an X-Powered-By header in every HTTP response header. Normally, this includes information like the Servlet specification that JBoss complies with, the JBoss app server version number, a build number, and the version of tomcat or jboss web that the app server utilizes. Some security scanners and professionals like to see this information removed or suppressed—the concern being that attackers may be able to provide more targeted attacks against your servers. Instructions for removing the X-Powered-By header are below but the techniques vary depending upon the version of JBoss you are running.

JBoss 4.2

Suppressing the X-Powered-By header in JBoss 4.2.x can be done by modifying the web.xml file located in${jboss.home}/server/${server.instance.name}/deploy/jboss-web.deployer/conf/.  For example, if you are using the 'default' instance and running jboss 4.2.3 from /usr/local, the path to the configuration file would be /usr/local/jboss-4.2.3.GA/server/default/deploy/jboss-web.deployer/conf/.  Locate the Common Filter Configuration line (line 25 on a stock 'default' server instance configuration file) and comment out the lines for the init-param, param-name, and param-value entries.  Example below
1
2  <filter>
3     <filter-name>CommonHeadersFilter</filter-name>
4     <filter-class>org.jboss.web.tomcat.filters.ReplyHeaderFilter</filter-class>
5  
6  
7  
8  
9  </filter>
Restart JBoss and the header will no longer show up.

JBoss 5.0 & JBoss 5.1

The web.xml file that needs to be updated is located in a different location than with JBoss 4,2 but the technique is the same. To suppress the X-Powered-By header under JBoss 5.0, comment out the init-param, param-name, and param-value line entries from the web.xml located in${jboss.home}server/${server.instance.name}/deployers/jbossweb.deployer/.
01
02  <filter>
03     <filter-name>CommonHeadersFilter</filter-name>
04     <filter-class>
05        org.jboss.web.tomcat.filters.ReplyHeaderFilter</filter-class>
06  
07  
08  
09  
10  
Once you have made the configuration changes, restart JBoss so they can take effect.

JBoss 6.0, JBoss 7.0, JBoss 7.1

In order to suppress the X-Powered-By header in JBoss 6, 7, or 7.1, you no longer make changes to web.xml files but instead modify the catalina.properties file included with your server instance. Edit thecatalina.properties file located in${jboss.home}/server/${server.instance.name}/deploy/jbossweb.sar/.  Locate the property named:org.apache.catalina.connector.X_POWERED_BY and set its value to false. Restart the server and you're all set.