Category: Technology

  • Custom firmware for Asus RT-AC66U

    Merlin has a custom Asuswrt firmware for the RT-AC66U router which can be found at its new home at http://www.mediafire.com/asuswrt-merlin/#

    With this firmware Merlin adds some needed feature that Asus lefted out see below.

    Using IPv6 can be a pain without a firewall between you and the world. This is one of the reasons I like Merlin’s version of the firmware,
    You can create a file /jffs/scripts/firewall-start on the router to run a custom firewall rules at start up.

    Here’s an example of what that file would look like for IPv6 6in4 tunnel with ip6tables:

    ip6tables -A INPUT -j DROP
    ip6tables -I FORWARD 2 -m state --state RELATED,ESTABLISHED -j ACCEPT

    # Allowed inbound rules here, such as this one:
    ip6tables -I FORWARD 2 -p tcp -m state --state NEW -i v6in4 --dport 22-j ACCEPT

    ip6tables -A FORWARD -i v6in4 -o br0 -p all -j DROP
    ip6tables -A FORWARD -i br0 -o any -p all -j ACCEPT
    ip6tables -A FORWARD -i br0 -o v6in4 -p all -j ACCEPT
    ip6tables -A FORWARD -i any -o br0 -p all -j ACCEPT
    ip6tables -A FORWARD -j DROP

     

    Here is a list of features that Asuswrt-merlin brings over the original firmware:
    System:
       – Based on the 3.0.0.4.246 source release from Asus
       – Various bugfixes (like the crash on VPN/NAT Loopback access of LAN devices)
       – Persistent JFFS partition
       – User scripts that run on specific events
       – Cron jobs
       – Customized config files for router services
       – LED control – put your Dark Knight in Stealth Mode by turning off all LEDs
    Disk sharing:
       – Act as a Master Browser
       – Act as a WINS server
       – Optionally use shorter share names (folder name only)
       – Disk spindown after user-configurable inactivity timeout
    Networking:
       – WakeOnLan web interface (with user-entered preset targets)
       – SSHD
       – Allows tweaking TCP/UDP connection tracking timeouts
       – CIFS client support (for mounting remote SMB share on the router)
       – Layer7 iptables matching
       – User-defined options for WAN DHCP queries (required by some ISPs)
       – Improved NAT loopback (based on code from phuzi0n from the DD-WRT forums)
       – Dual WAN support (both failover and load
         balancing supported) (EXPERIMENTAL) (RT-N66U, RT-AC66U)
       – OpenVPN client and server, based on code originally written by
         Keith Moyer for Tomato and reused with his permission. (RT-N66U, RT-AC66U)
       – Option to control Spanning-Tree Protocol support.
    Web interface:
       – Clicking on the MAC address of an unidentified client will do a lookup in
         the OUI database (ported from DD-WRT).
       – Optionally save traffic stats to disk (USB or JFFS partition)
       – Display monthly traffic reports
       – Display active/tracked network connections
       – Name field on the DHCP reservation list and Wireless ACL list
       – System info summary page
       – Wireless client IP, hostname, rate and rssi on the Wireless Log page
       – Wifi icon reports the state of both radios
    Thank you Merlin for your hard work in creating this firmware.
  • Using Google Authenticator on Ubuntu for SSH

    Run:

    $ apt-get update
    $ apt-get -yy install gcc mercurial libpam0g-dev git
    $ git clone https://code.google.com/p/google-authenticator/
    $ cd google-authenticator/libpam
    $ make install

    Edit /etc/ssh/sshd_config file and change the ChallengeResponseAuthentication from no to yes

    edit /etc/pam.d/common-auth so it looks like

    # here are the per-package modules (the "Primary" block)
    auth required pam_google_authenticator.so
    auth [success=1 default=ignore] pam_unix.so nullok_secure
    # here's the fallback if no module succeeds

    Run google-authenticator as the user you want to use two factor authentication on.
    Paste the generated URL into your browser and a QRCode will be generated.
    Scan the QR code with the Google Authenticator app on your iPhone.
    Reboot the server and test.

  • Protecting SSH from brute force attacks via iptables

    Put the following in /etc/sysconf/iptables and /etc/sysconf/ip6tables:

    -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --set --name SSH
    -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -m recent --update --seconds 60 --hitcount 5 --rttl --name SSH -j DROP
    -A INPUT -p tcp -m tcp --dport 22 -m state --state NEW -j ACCEPT

    restart iptables
    /bin/systemctl restart iptables.service
    /bin/systemctl restart ip6tables.service

  • Clearing cached memory on Linux system

    The Linux OS the tends keep Cached memory because the it decides that the Cached memory is being used and is needed which can lead to memory issues and slow do your system.

    To fix this problem you can force the system to free up the stored Cached memory.

    Create a script called /usr/local/bin/clearcache.sh with the following two lines:
    #!/bin/sh
    sync; echo 3 > /proc/sys/vm/drop_caches

    run “crontab -e” and add the following line:
    0 * * * * /usr/local/bin/clearcache.sh
    Also make the script executable by running “chmod +x /usr/local/bin/clearcache.sh”

    This should clear the Cached memory every hour.

  • Windows 7 as a Samba File Server for Linux machines

    If you get the this error message “mount error(12): Cannot allocate memory” while trying to mount a Windows SMB to a linux box.

    You need to configure Windows to act as a file server and it will allocate the resources needed.

    Change the registry key HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlSession ManagerMemory ManagementLargeSystemCache  to ‘1′

    and Change HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLanmanServerParametersSize  to ‘3′

    once you have done that do a reboot and try mounting the Samba drive again.

     

  • VMWare Workstation 8 Server

    Recently I have started using VMWare Workstation 8, this is really cool and seem to function better than VirtualBox.
    If you setup a virtual machine and set it to be shared, you can make it boot up with the Windows OS, hence this could be a headless sever hosting a Linux OS.
    You will need to log in as the Administrator to set permission to allow your own user account to use the shared VMware server. Once you have done that you can make any virtual machine boot up as a shared virtual machine without having to be logged in to Windows.

  • Fastest SD Card Reader

    I just got the IOGEAR SuperSpeed USB 3.0 SD/Micro SD Card Reader / Writer yesterday and it’s the fastest SD card reader i have ever seen. This was very cheap too, you can get it for around $15 from amazon.

    I was able to get 20MB/s write and 30MB/s read speed using a Patriot LX 16GB SD card on a USB 2.0 port on my MacBook, I properly could get a lot faster read speeds on a USB 3.0 port.

    Good work IOGEAR!

    You can read more about this product at http://www.iogear.com/product/GFR304SD/

     

    Update:

    I have tested this card reader on a windows 7 machine with a USB 3.0 port.

    I got 63MB/s read and 38MB/s write speed which is really cool.

  • Running a Ubuntu server on VirtualBox

    I created a virtual Ubuntu server on my Windows HTPC box using VirtualBox and VBoxVmService. This is a great setup as I can have a HTPC that’s always on with a Ubuntu server running on top.

    The Zbox is very energy efficient, quiet and small. This uses the AMD APU chip which is a all-in-one CPU/GPU combo.

    My setup is:

    • Zotac Zbox AD02
    • 8GB DDR3
    • 500GB WD HDD 7200k rpm
    • Windows 7 ultimate

    Installation was easy, I just installed VirtualBox, create a VM using the ISO from Ubuntu (make sure you install/enable SSH or NoMachine for remote access to the headless server), and then setup the VM to run as a service with VBoxVmService.

     

    http://vboxvmservice.sourceforge.net/

    https://www.virtualbox.org/

  • Nagios

    I Nagios is a wonderful tool to monitor your network devices.

     

    Nagios is a powerful monitoring system that enables organizations to identify and resolve IT infrastructure problems before they affect critical business processes.

    Designed with scalability and flexibility in mind, Nagios gives you the peace of mind that comes from knowing your organization’s business processes won’t be affected by unknown outages.

    Nagios is a powerful tool that provides you with instant awareness of your organization’s mission-critical IT infrastructure. Nagios allows you to detect and repair problems and mitigate future issues before they affect end-users and customers.

  • Latest Toastman Tomato Firmware

    The latest version of Toastman Tomato Firmware is really nice (i’m using 1.28.7500.4).

    You can now monitor IP Traffic by IP, so you can find out if you have a rouge device on your network that’s sucking up all your bandwidth or data usage.

    Also support for IPv6 is great.

    Thank you Toastman for keeping the firmware updated!

    http://www.4shared.com/dir/v1BuINP3/Toastman_Builds.html