Archive for the ‘Linux’ Category

Installing VMware Tools in Slackware (14)

2013-05-31 5 comments

So I finally decided to create a slackware VM just to mess around with and maybe use it for slackware-current. I have always used virtualbox since installing vmware tools always failed too install and figured why mess with it when it works in Vbox? Surprisingly the fix was not difficult I just felt lazy that day I guess.

The following is how to install vmware-tools on slackware (14) but should work for previous ones as well.

## This is what caused it to fail since the dir didn't exist.
$ mkdir /etc/pam.d
$ su -
# mount /dev/dvd /mnt/dvd
# cd /mnt/dvd/ 
# ls 
  ... VMwareTools-x.x.x-xxxxx.tar.gz ...
# tar -xzvf VMwareTools-x.x.x-xxxxx.tar.gz -C /tmp
# umount /mnt/dvd/
# cd /tmp
# cd vmware-tools-distrib/
# ./

The install should be successful after that, if you start X-window then you will need to start vmware tools with the following command.

$ /usr/bin/vmware-toolbox-cmd
Categories: Linux

My Linux Tricks (always growing)

2013-03-22 Leave a comment

Here are a few little tricks I’ve used in the past that might be helpful. I use some of them often and others only on occasion and wanted a good reference for if I forgot what it was (an example was setting up a new webdev env and forgot about the g+s part).

Add/Remove a secondary group from a user with out having to copy the whole group list they have assigned to them.

$ gpasswd -a <USER> <GROUP>
$ gpasswd -d <USER> <GROUP>

Set VIM as the default ubuntu editor instead of NANO, this drives me nuts if they change it from vi they should have a prompt at install for which editor. Making NANO the default/recommended but allow others to select one they prefer.

$ sudo apt-get install vim
$ sudo update-alternatives --config editor

A nice little password safe encryption program. xdotools is required if you want it to use auto fill other wise it can be skipped.

$ sudo <System Package Manager> install keepass2
$ sudo <System Package Manager> install xdotool

Surprisingly the sshd didn’t get installed by default with my Ubuntu system. Of course it’s a desktop OS.

$ sudo apt-get install openssh-server

A simple way to watch a directory for any new files created.

$ sudo <System Package Manager> install inotify-tools

Good old Conky for system information.

$ sudo <System Package Manager> install conky

Set all subdirectories to have the setgui bit. The following assumes your current directories is the one you want want all subdirectories to be changed. Just change the path to the directory you want if you’re not currently in it. The setuid/setgui/sticky bits are the “1st” octet of the permissions and numbered 4/2/1 respectively . So g+s would make a 775 file become 2775.

For more information read the chmod man page sections SETUID AND SETGID BITS and RESTRICTED DELETION FLAG OR STICKY BIT.

The stats command shows the octet code of each file in the current directory. I prefer octet codes just because it’s easier for me other wise you can just do an ls -l and you’ll see the file with -rwxrwxr-x will become -rwxrwsr-x.

$ find . -type d -exec chmod g+s {} \;
$ stat -c "%a %n" *

Nice way to tail multiple files in a single console.

$ sudo <System Package Manager> install multitail

Have a terminal always running in the background on your desktop with devilspie.

$ sudo <System Package Manager> install devilspie
$ mkdir ~/.devilspie
## geometry is made of up window size (x1,y1) position(x2,y2) x1+y1+x2+y2
$ vim ~/.devilspie/desktopTerm.ds
        ( if
        ( matches ( window_name ) "desktopTerm" )
        ( begin
        ( set_workspace 1 )
        ( pin )
        ( skip_pager )
        ( skip_tasklist )
        ( undecorate )
        ( below )
        ( geometry "700x1090+1240+0" )
## Make devilspie starts up the -a option has it apply the rules to all  existing windows 
devilspie -a
## I am setting this up with Xubuntu so my desktop is XFCE4 and it's terminal
## -T sets the title of the terminal so devilspie can target it.
xfce4-terminal -T desktopTerm
Categories: Linux

Ubuntu Configuration

2013-03-11 Leave a comment

So I installed Xubuntu a little while ago and started configuring it for one of my main systems instead of quick VMs that I destroy after I’m done testing what I wanted on them. I’m not that use to deb systems and the apt package management. Here are a few of the things I did when configuring my system.

Installed a web services for development. Includes all basic LAMP services apache2, mysql and php5. Note you’ll save yourself some time/stress/headaches if you also include the php5-mysqlnd (native driver) as well. php5-gd is an image library.

$ sudo apt-get install apache2 php5 libapache2-mod-php5 mysql-server php5-mysqlnd php5-gd

## Another nice thing is being able to edit the web root with your user and have the group assigned correctly.
## this example the webroot is /var/www we set the group to www-data what apache will be running as.
## Then we set the sticky bit for the group so all files created under it will be assigned that group.
## Just be sure to either include your user in the group so you have access to it or set the files to your user.
$ sudo gpasswd <USER> www-data
$ sudo chown :www-data /var/www
$ sudo chmod g+s /var/www

To use the most current Nvidia drivers. Make sure you have the source for your kernel before downloading so we don’t get issues.

$ sudo apt-get install build-essential linux-headers-`uname -r`
$ sudo apt-get install nvidia-experimental-310

I was going to install the direct Nvidia drivers and needed to disable the GUI init run levels for a second so I only started with a CLI. I could do it by simply editing the GRUB file.

$ sudo vim /etc/default/grub
## Edit the following line
## becomes
## Run the GRUB2 builder
$ sudo update-grub

Setup wireshark so any user can capture packets (prevents the requirement of running it as root).

## If it's not already installed
$ sudo apt-get install libcap2-bin
## Create a wireshark group so anyone in the group can capture packets, and get the new group rights in your current login session
$ sudo passwd -a <USER> wireshark
$ usermod -a -G wireshark <USER>
$ newgrp wireshark
## Set the group for the dumpcap so only root and the group can execute it.
$ sudo chown root:wireshark /usr/bin/dumpcap
$ chmod 750 /usr/bin/dumpcap
## Set the file up correctly
$ sudo setcap cap_net_raw,cap_net_admin,cap_dac_override+eip /usr/bin/dumpcap
Categories: Linux

Installing RVM (Ruby Version Manager) in Xubuntu 12.04 or Slackware 14

2013-01-23 Leave a comment

When I first started learning Ruby I found out about RVM which was a great project as I could easily switch between ruby versions based on what I wanted. To get RVM installed in Xubuntu (Ubuntu) 12.04 took more work then I’m normally use to with Slackware. I’ve had to install it on multiple systems with a space between each install making my memory fuzzy about what is required to get everything working. So I decided to dump my information here for later reference and who knows the next time I do it and something changes I’ll update this page. With out delay the processes can be copied and pasted below.

All the required dependencies to get it working that don’t get installed with ubuntu. I’ll create a VM where I can test to see which packages aren’t required since I was installing a few other packages I needed at the time all in the same line.

$ sudo apt-get install build-essential openssl libreadline6 libreadline6-dev curl git git-core zlib1g zlib1g-dev libssl-dev libyaml-dev libsqlite3-dev sqlite3 libxml2-dev libxslt-dev autoconf libc6-dev ncurses-dev automake libtool bison subversion pkg-config

For Slackware you can skip the dependencies since everything we need is already installed. Since packages/libraries are managed the slack way the need to disable the autolibs functionality of rvm is required. More about autolibs can be found here

Installing RVM and ruby, taken from the RVM install documentation found here.
Slackware 14

$ \curl -L | bash -s stable --ruby
$ ~/.rvm/bin/rvm autolibs 0
$ ~/.rvm/bin/rvm install ruby

*buntu 12.04

$ \curl -L | bash -s stable --ruby
$ rvm install ruby
Categories: Computers, Linux, Programming, Ruby

SSH private/public keys with passphrase and agent manager

2012-12-04 Leave a comment

Managing multiple systems that you only have access to by ssh can be annoying when you have to keep typing in ssh <HOST/IP>; then typing your password on each system.

This article explains how to use ssh pub/priv key pairs with a passphrase and ssh-agent.
The goal is to make logging in remotely more secure by using key pairs along with a passphrase but only having to use the passphrase once in a given time period.

First you’ll need to generate your own private/public key pair on the system you’ll be sshing FROM using the following command.

$ ssh-keygen -t rsa -b 4096 -f ~/.ssh/<ROLE>_rsa -C "Comment goes here"
Enter file in which to save the key (/home//.ssh/id_rsa):
Enter passphrase (empty for no passphrase):

You should never give your private key file or it’s contents to anyone. Think of it like a key to your house anyone that has it can access your “house”(server).

  • The comment just helps to let you know what the key is used for. I normally put the server(s) I’m going to push the public key too in the comments. This could be considered a minor security risk labeling where the key is used.
  • Some systems default to DSA, I recommend RSA 2048 bits or higher for the keys hence the keygen options -t rsa -b 4096. Two short write ups about DSA vs RSA can be found and .
  • Do not leave the passphrase empty as the worst case someone gets hold of your private key or gains access to your account they at least have to know the passphrase (back to the previous way of using just a password for security) to use it. An empty passphrase means anyone with the key can enter the server if they know which server the key is used on (hence the comment security risk).
  • If you generate more than one key pair and use the same passphrase, entering the passphrase will make all the key pairs that use that passphrase active at the same time.

Now that we have the keys generated the next step is to copy the .pub key text to the remote servers .ssh/authorized_keys file. I wrote this little bash script as a wrapper for the command used to publish the key. It prompts for what user to ssh with and the server host/ip then the ssh-copy-id command will prompt for the users password. It will automatically create the .ssh directory and append the key to the authorized_keys file. If your system doesn’t have ssh-copy-id I have included a bash 1 liner below the script that will check if the .ssh directory exists and create it then append the public key to the authorized_keys file.

if [[ -z "$sshusername" ]] && [[ -z "$serverIPaddress" ]] ; then
## Prompt for the user name to use
echo -en "\nIs $USER the account you want to use? \n" ;
select yn in "Yes" "No"; do
case "$yn" in
Yes ) sshusername="$USER" ; break ;;
No ) read -p "Type the username you want to use: " sshusername ; break;;
done ;
echo -en "\n" ;

## Prompt for the server name or IP
read -p "Type the Hostname or IP address of the server: " serverIPaddress ;
echo -en "\n" ;

## The actual command to copy the key over
ssh-copy-id "$sshusername"@"$serverIPaddress" ;

## Clean up of the vars we used
unset sshusername ;
unset serverIPaddress ;
## The system uses the variables?!?
echo -en "Your system currently has the following variables set.\n sshusername AS $sshusername\n serverIPaddress AS $serverIPaddress\n\n";
fi ;

One way to push the new pub key to the server is by using the ssh-copy-id binary command. If you are using some other port besides 22 you’ll need to include the username/host and port option all in quotes.

#ssh-copy-id -i <path to pub key> "username@host/ip -p <port>"
ssh-copy-id -i .ssh/
ssh-copy-id -i .ssh/ " -p 9999"

Bash one liner for pushing public key to remote system if youre unable to use ssh-copy-id. Be sure to put the correct and <HOST/IP> settings for the ssh command.

cat ~/.ssh/ | ssh @<HOST/IP> 'if [[ -z "$HOME/.ssh" ]] ; then mkdir $HOME/.ssh ; fi ; cat - >> ~/.ssh/authorized_keys'

Now we should have a priv/pub key par in our .ssh folder and on the remote system our public key should be in the authorized_keys file. To test if it’s working ssh to the system. You should be prompted with the following instead of the @<HOST/IP>’s password:

$ssh server
Enter passphrase for key '/home//.ssh/id_rsa':

Upon entering the correct passphrase you will now be logged in to the remote system. Exit out of the system and try sshing again you’ll notice you get prompted again for the passphrase. Great all this seemed to do was add an extra layer of security but didn’t stop the annoying issue of each time having to enter a password/passphrase.

Now it’s time to use a key manager such as ssh-agent which allows us to enter the passphrase once and after that anytime we try to ssh to any server that has our public key we’ll get direct access (for a given amount of time before we have to reenter the passphrase).

On my systems I create two alias commands some people want to have their system prompt for the password when they open a session the first time I prefer to start start it when I need too that way if a day I don’t need to ssh to a server (it happens some times…) my shell doesn’t have access.

The two aliases I use are below.

## type agent once on the machine your are using unless the time elapses or the system was rebooted
## Removes the old hostname agent file
## starts the agent with 28800 seconds (8hrs) to be active in memory
##   and story the environment variables to access the keys in memory in the .agent file
## run the .agent file as a Tlc script and then add the private key identities to the authentication agent
alias agent='rm -f "$HOME"/.ssh/`hostname`.agent ; ssh-agent -t 28800 | grep -v echo > "$HOME"/.ssh/`hostname`.agent ; source "$HOME"/.ssh/`hostname`.agent ; ssh-add'

## Any new shells you just need to run this alias to have them use the agent in memory
alias sshagent='if [ -e "$HOME"/.ssh/`hostname`.agent ]; then source "$HOME"/.ssh/`hostname`.agent ; fi'

Now you have the generated keys with the remote system(s) having the public key in the auth file and you are able to use an agent so you only have to enter your passphrase once allowing you to ssh to any systems with the public key with out any prompts.

A system is only as secure as it’s user.

Categories: Bash, Computers, Linux, Security

ddclient config for namecheap

2012-06-15 Leave a comment

Ok so I was hitting my head on the desk trying to figure this out even after chatting with namecheap. I’m guessing what they were trying to tell me to do was for a different version number of ddclient or they just didn’t know.

I have tested this on two systems with two different versions of ddclient both work.

Distro ddclient
Slackware 14 3.8.1
CentOS 6.2 3.7.3
Raspbian (wheezy) 3.8.0

Don’t add quotes around the password or add commas/backslashes after each line.

The only thing you really need to look at is the namecheap section at the bottom of my complete ddclient.config file below. I also give a full example to help with any confusion that might happen.

Due to a bug in ddclient any identical subdomains under different domains will be ignored and only the last one updated unless you patch it. You can find more information about the bug and how to patch it here.


daemon=600                              # check every 600 seconds make sure
syslog=yes                              # log update msgs to syslog
mail=root                               # mail all msgs to root
mail-failure=root                       # mail failed update msgs to root
pid=/var/run/               # record PID in file.
ssl=yes                                 # use ssl-support.

## To obtain an IP address from Web status page make sure daemon checks a minimum of 600 other wise dyndns might block your client from getting the ip.
use=web,, web-skip='IP Address' # found after IP Address

## NameCheap (
password=DNSPASSWORD #Do not add single/double quotes

Example for the site with the host of dev (

## NameCheap (
Categories: DNS, Linux, Perl

Bash Color Logs

2012-05-17 Leave a comment

Simple little function that will tail a log and color the lines accordingly. With the option to exclude any lines with a given regex, currently does not work on active tails using the -f option. Copy it into your .bashrc or .bash_profile.

## Program:
##    Log tail with color and option to remove lines
## Author:
##    Kyle Rizzo
##    lifeforce0 {at} gmail {dot} com
## Summary:
##    Simple little function that will tail a log and color
##    the lines accordingly. With the option to exclude any
##    lines with a given regex.
   if  [ $# -eq "3" ] ; then
      tail $1 $2 | eval "perl -pe 's/.*$3.*\n//g'" | perl -pe 's/^.*SEVERE.*$/\e[0;31;40m$&\e[0m/g; s/^.*FATAL.*$/\e[0;31;40m$&\e[0m/g; s/^.*ERROR.*$/\e[0;31;40m$&\e[0m/g; s/^.*CRIT.*$/\e[1;31;40m$&\e[0m/g; s/^.*WARN.*$/\e[1;33;40m$&\e[0m/g; s/^.*DEBUG.*$/\e[1;36;40m$&\e[0m/g; s/^.*INFO.*$/\e[0;32;40m$&\e[0m/g; s/^.*VERB.*$/\e[1;37;40m$&\e[0m/g';
   elif [ $# -eq "2" ]; then
      tail $1 $2 | perl -pe 's/^.*SEVERE.*$/\e[0;31;40m$&\e[0m/g; s/^.*FATAL.*$/\e[0;31;40m$&\e[0m/g; s/^.*ERROR.*$/\e[0;31;40m$&\e[0m/g; s/^.*CRIT.*$/\e[1;31;40m$&\e[0m/g; s/^.*WARN.*$/\e[1;33;40m$&\e[0m/g; s/^.*DEBUG.*$/\e[1;36;40m$&\e[0m/g; s/^.*INFO.*$/\e[0;32;40m$&\e[0m/g; s/^.*VERB.*$/\e[1;37;40m$&\e[0m/g';
   elif [ $# -eq "1" ]; then
      tail $1 | perl -pe 's/^.*SEVERE.*$/\e[0;31;40m$&\e[0m/g; s/^.*FATAL.*$/\e[0;31;40m$&\e[0m/g; s/^.*ERROR.*$/\e[0;31;40m$&\e[0m/g; s/^.*CRIT.*$/\e[1;31;40m$&\e[0m/g; s/^.*WARN.*$/\e[1;33;40m$&\e[0m/g; s/^.*DEBUG.*$/\e[1;36;40m$&\e[0m/g; s/^.*INFO.*$/\e[0;32;40m$&\e[0m/g; s/^.*VERB.*$/\e[1;37;40m$&\e[0m/g';
      echo -en "Usage: \e[1;36;40mctail -f /Path/to/log/file\e[0m\n       \e[1;36;40mctail -f /Path/to/log/file excludeText\e[0m\n       \e[1;36;40mctail -100 mylog.txt '(SEVERE|FATAL|ERROR)'\e[0m\n       \e[0mNote: Removing lines will only work if you're not actively tailing a file with the \e[1;36;40m-f\e[0m option.\e[0m\n";

Create a temp log file to test each level.

for level in VERBOSE DEBUG INFO WARN CRITICAL ERROR CRIT FATAL WARNING VERB SEVERE;do tempdate=`date`; echo $tempdate $level Random text that is about the msg >> mylog.txt; tempnum=$RANDOM;sleep $((tempnum %= 9)); done
Categories: Bash, Computers, Linux, Perl, Programming