<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>influenced dot net &#187; SysAdmin</title>
	<atom:link href="http://www.influenced.net/category/sysadmin/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.influenced.net</link>
	<description>Mark Hutton</description>
	<lastBuildDate>Wed, 14 Jul 2010 10:59:45 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Windows 7 File Sharing Issue</title>
		<link>http://www.influenced.net/2009/09/22/windows-7-file-sharing-issue/</link>
		<comments>http://www.influenced.net/2009/09/22/windows-7-file-sharing-issue/#comments</comments>
		<pubDate>Tue, 22 Sep 2009 18:36:34 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[Windows]]></category>
		<category><![CDATA[file sharing]]></category>
		<category><![CDATA[lanmanserver]]></category>
		<category><![CDATA[public folder]]></category>
		<category><![CDATA[windows 7]]></category>
		<category><![CDATA[x64]]></category>

		<guid isPermaLink="false">http://www.influenced.net/?p=157</guid>
		<description><![CDATA[I have come across the following issue on Windows 7 Pro x64 File sharing broke itself very quickly.. I enabled Public Folder sharing, disabled need for password, copied a few files into it. Next I tried to copy the files to 2 different Vista 32 machines &#038; an XP machine The first Vista machine managed [...]]]></description>
			<content:encoded><![CDATA[<p>I have come across the following issue on Windows 7 Pro x64</p>
<p>File sharing broke itself very quickly.. I enabled Public Folder sharing, disabled need for password, copied a few files into it.</p>
<p>Next I tried to copy the files to 2 different Vista 32 machines &#038; an XP machine</p>
<p>The first Vista machine managed to successfully copy the files, the 2nd would show the folders but no files and the XP machine just failed completely citing &#8220;You might not have permission to use this network resource. Contact the administrator of this server to find out if you have access permissions. Not enough server storage is available to process this command.&#8221;</p>
<p>After a bit of googling I ended up modifying the following registry key</p>
<p>HKLM\SYSTEM\CurrentControlSet\Services\LanmanServer\Parameters\Size</p>
<p>Set it to: 3</p>
<p>Source: <a href="http://alan.lamielle.net/2009/09/03/windows-7-nonpaged-pool-srv-error-2017">lamielle.net</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2009/09/22/windows-7-file-sharing-issue/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Apache2 Won&#8217;t Properly Stop</title>
		<link>http://www.influenced.net/2008/07/09/apache2-wont-properly-stop/</link>
		<comments>http://www.influenced.net/2008/07/09/apache2-wont-properly-stop/#comments</comments>
		<pubDate>Wed, 09 Jul 2008 17:28:15 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[apache2]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[php]]></category>

		<guid isPermaLink="false">http://www.influenced.net/2008/07/09/apache2-wont-properly-stop/</guid>
		<description><![CDATA[Just a quick note: Apache 2.2 with PHP 5.2.6-2 on Debian fails to shutdown properly on one of my servers apache2ctl stop or /etc/init.d/apache2 stop or equivalents would result in &#8220;waiting&#8230;&#8230;&#8230;&#8230;&#8230;.&#8221; until a timeout and then the new process is launched anyway which fails because the port is already in use, apache2 never finished shutting [...]]]></description>
			<content:encoded><![CDATA[<p>Just a quick note:</p>
<p>Apache 2.2 with PHP 5.2.6-2 on Debian fails to shutdown properly on one of my servers</p>
<p>apache2ctl stop or /etc/init.d/apache2 stop or equivalents would result in &#8220;waiting&#8230;&#8230;&#8230;&#8230;&#8230;.&#8221; until a timeout and then the new process is launched anyway which fails because the port is already in use, apache2 never finished shutting down properly</p>
<p>Not sure exactly what the problem is, but downgrading to PHP 5.2.6-0.dotdeb.1 via DotDeb mirrors solved the issue</p>
<p>Hopefully it will be fixed in the next version/patch</p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2008/07/09/apache2-wont-properly-stop/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Lots of SSH dictionary attacks recently</title>
		<link>http://www.influenced.net/2007/10/23/lots-of-ssh-dictionary-attacks-recently/</link>
		<comments>http://www.influenced.net/2007/10/23/lots-of-ssh-dictionary-attacks-recently/#comments</comments>
		<pubDate>Tue, 23 Oct 2007 08:23:53 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[debian]]></category>
		<category><![CDATA[denyhosts]]></category>
		<category><![CDATA[dictionary attack]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.influenced.net/2007/10/23/lots-of-ssh-dictionary-attacks-recently/</guid>
		<description><![CDATA[I thought I was getting a lot of DenyHosts emails recently and the statistics page on the DenyHosts website seems to agree with me! I wonder what&#8217;s caused this sudden surge in attacks]]></description>
			<content:encoded><![CDATA[<p>I thought I was getting a lot of <a href="http://denyhosts.sourceforge.net/">DenyHosts</a> emails recently and the <a href="http://stats.denyhosts.net/stats.html">statistics page on the DenyHosts website</a> seems to agree with me!</p>
<p><img src="http://www.influenced.net/content/lots-of-ssh-dictionary-attacks-recently/daily-abuse-231007.png" alt="SSH daily attacks via DenyHosts stats for Oct23 2007" /></p>
<p>I wonder what&#8217;s caused this sudden surge in attacks</p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2007/10/23/lots-of-ssh-dictionary-attacks-recently/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
		<item>
		<title>*nix &#8211; deleting all files in a folder (0000&#8242;s)</title>
		<link>http://www.influenced.net/2007/05/08/nix-deleting-all-files-in-a-folder-0000s/</link>
		<comments>http://www.influenced.net/2007/05/08/nix-deleting-all-files-in-a-folder-0000s/#comments</comments>
		<pubDate>Tue, 08 May 2007 10:00:30 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.influenced.net/2007/05/08/nix-deleting-all-files-in-a-folder-0000s/</guid>
		<description><![CDATA[When &#8216;rm&#8217; says &#8216;too many arguments&#8217;, use the following to erase all the files in a folder: find . -type f -print &#124; xargs -n 20 rm]]></description>
			<content:encoded><![CDATA[<p>When &#8216;rm&#8217; says &#8216;too many arguments&#8217;, use the following to erase all the files in a folder:</p>
<pre><code>find . -type f -print | xargs -n 20 rm</code></pre>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2007/05/08/nix-deleting-all-files-in-a-folder-0000s/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Why isn&#8217;t Amavis scanning certain mails?</title>
		<link>http://www.influenced.net/2006/10/19/why-isnt-amavis-scanning-certain-mails/</link>
		<comments>http://www.influenced.net/2006/10/19/why-isnt-amavis-scanning-certain-mails/#comments</comments>
		<pubDate>Thu, 19 Oct 2006 13:12:55 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[SysAdmin]]></category>
		<category><![CDATA[Website]]></category>

		<guid isPermaLink="false">http://www.influenced.net/2006/10/19/why-isnt-amavis-scanning-certain-mails/</guid>
		<description><![CDATA[Doh.. because they&#8217;re too big! I noticed in my mail server logs that some emails weren&#8217;t getting SA scanned and tagged and wondered why.. they weren&#8217;t internal emails and should have been scanned.. then I remembered that there&#8217;s a size limit to the scanning]]></description>
			<content:encoded><![CDATA[<p>Doh.. because they&#8217;re too big!</p>
<p>I noticed in my mail server logs that some emails weren&#8217;t getting SA scanned and tagged and wondered why.. they weren&#8217;t internal emails and should have been scanned.. then I remembered that there&#8217;s a size limit to the scanning <img src='http://www.influenced.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2006/10/19/why-isnt-amavis-scanning-certain-mails/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Spam email subjects list</title>
		<link>http://www.influenced.net/2006/07/07/spam-email-subjects-list/</link>
		<comments>http://www.influenced.net/2006/07/07/spam-email-subjects-list/#comments</comments>
		<pubDate>Fri, 07 Jul 2006 09:37:21 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Internet]]></category>
		<category><![CDATA[SysAdmin]]></category>

		<guid isPermaLink="false">http://www.influenced.net/2006/07/07/spam-email-subjects-list/</guid>
		<description><![CDATA[The spam quarantine directory on my mail server just reached around ~200MB and ~22k emails so I decided it was time for a cleanout.. before that though I compiled a list of the subjects from all the emails for your viewing pleasure! spam subjects list spam subjects top 100]]></description>
			<content:encoded><![CDATA[<p>The spam quarantine directory on my mail server just reached around ~200MB and ~22k emails so I decided it was time for a cleanout.. before that though I compiled a list of the subjects from all the emails for your viewing pleasure!</p>
<p><a href="http://www.influenced.net/misc/spam-subjects-cleaned.txt">spam subjects list</a></p>
<p><a href="http://www.influenced.net/misc/spam-subjects-top100.txt">spam subjects top 100</a></p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2006/07/07/spam-email-subjects-list/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Fine tuning Postfix mail logs</title>
		<link>http://www.influenced.net/2006/02/23/postfix-mail-log-syslog-syslogng/</link>
		<comments>http://www.influenced.net/2006/02/23/postfix-mail-log-syslog-syslogng/#comments</comments>
		<pubDate>Thu, 23 Feb 2006 10:36:01 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[SysAdmin]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[For some reason, by default, after installation via apt-get of Postfix on Debian, Postfix log output gets logged to /var/log/syslog, /var/log/mail.log and /var/log/mail.info.. all with the same information On one of my servers, syslog-ng takes care of the syslog.. the edits to this (syslog-ng.conf) comprised: Before: filter f_syslog { not facility(auth, authpriv); }; After: filter [...]]]></description>
			<content:encoded><![CDATA[<p>For some reason, by default, after installation via apt-get of Postfix on Debian, Postfix log output gets logged to /var/log/syslog, /var/log/mail.log and /var/log/mail.info.. all with the same information</p>
<p>On one of my servers, syslog-ng takes care of the syslog.. the edits to this (syslog-ng.conf) comprised:</p>
<p><em>Before:</em></p>
<pre><code>filter f_syslog { not facility(auth, authpriv); };
</code></pre>
<p><em>After:</em></p>
<pre><code>filter f_syslog { not facility(auth, authpriv,mail); };
</code></pre>
<p><em>and also comment out this:</em></p>
<pre><code>#log { source(src); filter(f_mail); destination(mail); };
</code></pre>
<p>On another one of my servers, the default syslog is in use.. the edits to this (syslog.conf) comprised:</p>
<p><em>Before:</em></p>
<pre><code>*.*;auth,authpriv.none; /var/log/syslog
</code></pre>
<p><em>After:</em></p>
<pre><code>*.*;auth,authpriv.none;mail.none; /var/log/syslog
</code></pre>
<p><em>and also comment out this:</em></p>
<pre><code>#mail.*                         -/var/log/mail.log
</code></pre>
<p>now restart the daemons and your log files won&#8217;t have a shedload of duplicated information!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2006/02/23/postfix-mail-log-syslog-syslogng/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Bind8 Logging problems</title>
		<link>http://www.influenced.net/2006/02/23/bind8-logging-problems/</link>
		<comments>http://www.influenced.net/2006/02/23/bind8-logging-problems/#comments</comments>
		<pubDate>Thu, 23 Feb 2006 10:05:12 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[SysAdmin]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[On my vds (virtual dedicated server) I run Bind8 due to issues getting Bind9 to run properly I&#8217;ve been trying to debug a problem with the zone transfer of a certain domain (turns out I had input the wrong secondary nameserver). I wanted get Bind8 to log basically everything.. so I stuck in a custom [...]]]></description>
			<content:encoded><![CDATA[<p>On my vds (virtual dedicated server) I run Bind8 due to issues getting Bind9 to run properly</p>
<p>I&#8217;ve been trying to debug a problem with the zone transfer of a certain domain (turns out I had input the wrong secondary nameserver).  I wanted get Bind8 to log basically everything..  so I stuck in a custom &#8220;logging {}&#8221; section in named.local.options but for some reason, the file was never created.</p>
<p>Unfortunately, it took me quite a while to realise that there was already a logging section in named.conf and that my section was being read but ignored (would give syntax errors if they existed in the new section but wouldn&#8217;t make my damned log file!)</p>
<p>I merged the two logging sections together in named.conf and it actually worked, the file being created in /var/cache/bind/</p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2006/02/23/bind8-logging-problems/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Postfix XForward annoyance</title>
		<link>http://www.influenced.net/2006/02/20/postfix-xforward-annoyance/</link>
		<comments>http://www.influenced.net/2006/02/20/postfix-xforward-annoyance/#comments</comments>
		<pubDate>Mon, 20 Feb 2006 06:26:52 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[SysAdmin]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I run our company&#8217;s email server &#8211; it&#8217;s Postfix on Debian. I decided to create a script which would scan the mail logs and list clients that tried to send SPAM, so that I could add them to a blacklist. A brief spell of messing about trying to implement this made me realise that the [...]]]></description>
			<content:encoded><![CDATA[<p>I run our company&#8217;s email server &#8211; it&#8217;s Postfix on Debian.</p>
<p>I decided to create a script which would scan the mail logs and list clients that tried to send SPAM, so that I could add them to a blacklist.</p>
<p>A brief spell of messing about trying to implement this made me realise that the easiest way for me to parse the log would be for AMAVIS to output the actual client IP.  However, since the source can be faked in the mail envelope, I wanted Postfix to pass the client IP onto AMAVIS, which brings me to XForward.</p>
<p>XForward is an SMTP extension which allows a trusted client/server to pass on the original client IP to a destination server (which could pass this on further, etc.)</p>
<p>I spent a while wondering why AMAVIS wasn&#8217;t getting the XForward&#8217;d IP, eventually realising that it wasn&#8217;t implemented in the version that I was running..  trying up apt-get the latest unstable/testing version yielded a nice message telling me that e2fsprogs needed to be updated (which is not something trivial).. I therefore decided to manually update amavis to a version which didn&#8217;t require the Perl library update which relied on the e2fsprogs, etc, etc being updated (see <a href="http://www200.pair.com/mecham/spam/upgrade-amavis.html">here</a> for more details)</p>
<p>Eventually I got the whole thing working but then I realised a small problem &#8211; spammers often don&#8217;t care about which prority MX they use, i.e. they&#8217;ll use a backup MX sometimes, trying to bypass filters, etc.</p>
<p>I decided to try to get Postfix on the backup MX  to XForward the original client to the primary mail server.  This turned out to be a complete ball-ache.. After hours of pissing about trying to get it to work, I decided to install the very latest version of Postfix on the backup MX &#8211; even though 2.1 onward (according to all the Postfix documentation) supports XForward&#8230; lo and behold it worked! So either the documentation is wrong or there&#8217;s a bug in the version of Postfix I was using&#8230; very annoying</p>
<p>Thankfully, it&#8217;s all working fine now and my blacklist is growing <img src='http://www.influenced.net/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2006/02/20/postfix-xforward-annoyance/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>PostfixAdmin, Courier, MySQL, MD5</title>
		<link>http://www.influenced.net/2006/01/04/postfixadmin-courier-mysql-md5/</link>
		<comments>http://www.influenced.net/2006/01/04/postfixadmin-courier-mysql-md5/#comments</comments>
		<pubDate>Wed, 04 Jan 2006 08:13:06 +0000</pubDate>
		<dc:creator>Mark</dc:creator>
				<category><![CDATA[Linux]]></category>
		<category><![CDATA[Opinion]]></category>
		<category><![CDATA[SysAdmin]]></category>

		<guid isPermaLink="false"></guid>
		<description><![CDATA[I am writing this mostly for personal reference &#8211; I couldn&#8217;t figure out how Courier successfully authenticated POP3/IMAP access via MySQL as PostfixAdmin stores the passwords in the MySQL table using a custom function (or so it says &#8211; pacrypt).. However I have discovered that although the function is custom, Courier also has a method [...]]]></description>
			<content:encoded><![CDATA[<p>I am writing this mostly for personal reference &#8211; I couldn&#8217;t figure out how Courier successfully authenticated POP3/IMAP access via MySQL as PostfixAdmin stores the passwords in the MySQL table using a custom function (or so it says &#8211; pacrypt)..</p>
<p>However I have discovered that although the function is custom, Courier also has a method to produce the exact same digest using an 8 character salt (md5<em>crypt</em>redhat)</p>
<p>So that&#8217;s how it works!</p>
]]></content:encoded>
			<wfw:commentRss>http://www.influenced.net/2006/01/04/postfixadmin-courier-mysql-md5/feed/</wfw:commentRss>
		<slash:comments>1</slash:comments>
		</item>
	</channel>
</rss>
