2021年1月9日 星期六

MySQL修改密碼與忘記密碼重設

忘記密碼重設 如果忘記root密碼可以用以下方式重設 # /etc/init.d/mysql stop # mysqld_safe --skip-grant-tables & 用上面方式啟動mysql後可以不用輸入密碼直接連入 # mysql -u root 接者使用修改使用者密碼的方法二修改root密碼,例如 mysql> use mysql; mysql> UPDATE user SET Password=PASSWORD("password") WHERE User='root'; mysql> flush privileges; mysql> quit 最後重新啟動mysql # /etc/init.d/mysql stop # /etc/init.d/mysql start 參考連結:https://emn178.pixnet.net/blog/post/87659567

2018年11月4日 星期日

[rsync]Linux 使用 rsync 遠端檔案同步與備份工具教學與範例

Linux 使用 rsync 遠端檔案同步與備份工具教學與範例 轉自:https://blog.gtwang.org/linux/rsync-local-remote-file-synchronization-commands/ 本篇介紹如何使用 Linux 的 rsync 同步與備份各種檔案,自動製作快照式累進備份。 rsync 是 Linux 系統上最常被用來複製與備份檔案的工具,它可以處理本機或遠端的檔案同步工作,藉由 rsync 指令可以讓管理者很方便的將兩地的資料同步,不管是同一台電腦或是透過網際網路連線的兩台伺服器,使用方式都類似,以下是 rsync 的使用教學以及常用的指令範例。 rsync 簡介 rsync 的角色就像是一般 Linux 的 cp 與 scp 指令,可以將檔案或目錄從來源位置複製到目的位置,不過 rsync 在複製檔案時會比 cp 與 scp 更有效率,並且支援連結檔與設備檔(devices),也可以保留檔案的擁有者、群組與權限設定, rsync 在第一次複製檔案時,會複製完整的檔案內容,而之後再次複製檔案時,就會先以 delta transfer 演算法檢查新舊檔案之間的差異,只傳送有變動的部份,可加快備份速度,尤其是在累進備份大檔案時,效果更明顯。另外 rsync 在使用網路傳送資料時,也支援資料的自動壓縮與解壓縮,這樣可以有效減少耗費的網路頻寬。 安裝 rsync 大部分的 Linux 發行版都會內建 rsync 工具,如果您的系統沒有安裝,通常也都可以透過系統的套件來安裝。Red Hat 系列的 Linux 可用 yum 安裝: sudo yum install rsync Debian 系列的 Linux 則可用 apt-get: sudo apt-get install rsync rsync 基本用法 rsync 的基本語法結構如下: rsync 參數 來源檔案 目的檔案 以下是最常見的幾個參數: -v:verbose 模式,輸出比較詳細的訊息。 -r:遞迴(recursive)備份所有子目錄下的目錄與檔案。 -a:封裝備份模式,相當於 -rlptgoD,遞迴備份所有子目錄下的目錄與檔案,保留連結檔、檔案的擁有者、群組、權限以及時間戳記。 -z:啟用壓縮。 -h:將數字以比較容易閱讀的格式輸出。 rsync 最簡單的用法就是複製本地端的檔案: rsync -avh myfile.gz /home/pi/tmp/ sending incremental file list myfile.gz sent 14.34M bytes received 35 bytes 28.67M bytes/sec total size is 14.33M speedup is 1.00 其效果就跟 cp -r 類似,可將 myfile.gz 複製到 /home/pi/tmp/ 目錄中,不過如果執行第二次時,rsync 就會自動跳過沒有變動的檔案: rsync -avh myfile.gz /home/pi/tmp/ sending incremental file list sent 74 bytes received 12 bytes 172.00 bytes/sec total size is 14.33M speedup is 166,658.15 這種用法對於檔案或目錄都適用: rsync -avh /path/to/myfolder /home/pi/tmp/ rsync 遠端備份 rsync 也可以用於不同台機器之間的遠端備份,這樣的用法就跟 scp 指令很像,不過 rsync 會更有效率: rsync -avzh /mypath/myfile.gz pi@192.168.1.12:/mybackup/ 這樣就會將本地端的 myfile.gz 備份至 pi@192.168.1.12 的 /mybackup/ 目錄中,在遇到這種遠端備份的狀況時,rsync 預設會以 ssh 的方式登入遠端的機器,所以在執行這行備份指令之後,要接著輸入pi@192.168.1.12 的密碼,接著就會開始備份資料,輸出會類似這樣: pi@192.168.1.12's password: sending incremental file list myfile.gz sent 13.62M bytes received 34 bytes 48.56K bytes/sec total size is 14.33M speedup is 1.05 而這裡我們多加入一個 -z 參數,目的是讓 rsync 可以自動將資料壓縮後再傳送,並在遠端接收到資料後自動解壓縮,減少網路傳輸的資料量。 rsync 也可以將遠端的檔案備份至本地端,其語法也跟 scp 類似: rsync -avzh pi@192.168.1.12:/mypath/myfile.gz /mybackup/ pi@192.168.1.12's password: receiving incremental file list myfile.gz sent 30 bytes received 23.74M bytes 571.98K bytes/sec total size is 24.14M speedup is 1.02 這裡的 rsync 在複製檔案時,由於我們加入了 -a 參數,所以可以用於檔案或是整個目錄的備份,相當於 scp -r 的效果,而且由於 rsync 只會傳輸有變動的部份,所以通常在異地備份資料時都會使用這種方式來處理。 限制網路頻寬 如果不想讓 rsync 在透過網路備份資料時,佔用太大的網路頻寬而影響正常的服務,可以加上 --bwlimit 參數來指定資料傳輸的速度上限: rsync -avzh --bwlimit=100K pi@192.168.1.12:/mypath/myfile.gz /mybackup/ pi@192.168.1.12's password: receiving incremental file list myfile.gz sent 30 bytes received 14.34M bytes 99.22K bytes/sec total size is 14.33M speedup is 1.00 自訂 SSH 連接埠 正常 ssh 遠端登入服務的連接埠(port)號碼是 22,但有些人為了保護伺服器避免受到太多的網路攻擊,會將 ssh 的連接埠改成其他的號碼,例如 12345,不過這樣的話在使用 rsync 進行遠端備份資料時,就也要跟著指定連接埠號碼。 假設 192.168.1.12 這台伺服器的 ssh 服務連接埠號碼為 12345,以下是透過 rsync 將資料備份資料的範例: rsync -avzh -e 'ssh -p 12345' /mypath/myfile.gz pi@192.168.1.12:/mybackup/ 這裡我們多加入一個 -e 參數,其用途是指定遠端登入所要使用的指令,預設的指令就是 ssh,而這裡我們將指令變更為 ssh -p 12345,也就是使用 12345 這個連接埠登入 ssh 的意思(請參考 ssh 指令的 -p 參數用法)。 顯示傳輸進度 如果要讓 rsync 在傳輸檔案時可以即時顯示進度,可以加上 --progress 參數: rsync -avzh --progress pi@192.168.1.12:/mypath/myfile.gz /mybackup/ 這樣在備份每的檔案的過程就會顯示傳輸的進度、傳輸速度與剩餘時間等資訊: pi@192.168.1.12's password: receiving incremental file list myfile.gz 24.14M 100% 623.52kB/s 0:00:37 (xfr#1, to-chk=0/1) sent 30 bytes received 23.74M bytes 558.52K bytes/sec total size is 24.14M speedup is 1.02 同步刪除檔案 rsync 預設只會將來源端現存的檔案同步更新至目的端(同步所有新增或修改的檔案),但是如果在來源端有檔案被刪除的話,rsync 並不會主動刪除目的端的檔案,這樣可以確保資料被勿刪時,備份檔不會也跟著被刪除。 如果您想要讓 rsync 也同步將不存在於來源端的檔案刪除的話,可以加上 --delete 參數,如果沒有來源檔案只有新增、沒有減少的話,它就跟一般的複製動作相同: rsync -avh --delete myfolder/ backup/ sending incremental file list ./ data1.txt data2.txt data3.txt data4.txt sent 432 bytes received 95 bytes 1.05K bytes/sec total size is 116 speedup is 0.22 這時候若我們將來源檔案的 data1.txt 與 data2.txt 刪除,並且增加 data5.txt,在執行一次 rsync: rsync -avh --delete myfolder/ backup/ sending incremental file list deleting data2.txt deleting data1.txt ./ data5.txt sent 190 bytes received 64 bytes 508.00 bytes/sec total size is 87 speedup is 0.34 這時候 rsync 就會同步將備份端的 data1.txt 與 data2.txt 刪除,並且同時新增 data5.txt。 如果這裡我們沒有加上 --delete 參數的話,rsync 就只會新增 data5.txt,不會刪除任何檔案。 備份特定檔案 假設我們的檔案與目錄結構如下: tree myfolder myfolder ├── chinese.py ├── data1.txt ├── data2.txt ├── find_edimax.c └── src ├── pack.c ├── test1.txt └── test2.txt 若要讓 rsync 在備份檔案時,排除所有 *.txt 的文字檔檔案,可以使用 --exclude 參數: rsync -avh --exclude '*.txt' myfolder/ backup/ sending incremental file list ./ chinese.py find_edimax.c src/ src/pack.c sent 3.91K bytes received 88 bytes 7.99K bytes/sec total size is 3.59K speedup is 0.90 我們可以使用多個 --exclude 來排除多種檔案,例如: rsync -avh --exclude '*.txt' --exclude '*.py' myfolder/ backup/ sending incremental file list ./ find_edimax.c src/ src/pack.c sent 3.74K bytes received 65 bytes 7.61K bytes/sec total size is 3.50K speedup is 0.92 如果只想要備份某些特定的檔案,可以將 --exclude 與 --include 配合使用,例如只備份所有 *.c 的 C 語言原始碼: rsync -avh --include '*.c' --include '*/' --exclude '*' myfolder/ backup/ sending incremental file list ./ find_edimax.c src/ src/pack.c sent 3.74K bytes received 69 bytes 7.62K bytes/sec total size is 3.50K speedup is 0.92 這裡我們加入兩個 --include 來指定要備份的檔案比對規則,*.c 就是包含所有 C 語言的原始碼檔案,而另外一個 */ 的意思是指包含所有的目錄,若沒有加上包含目錄的參數,所有的目錄就會被後面 --exclude 排除,造成所有子目錄中的 *.c 也跟著被排除。最後加上一個 --exclude 排除其餘所有的檔案,請注意 --exclude 要放在 --include 之後,順序不可以對調。 限定備份檔案大小 rsync 也可以依照檔案的大小來選擇備份的檔案,假設在 myfolder 目錄中有以下這些檔案: ls -l myfolder/ total 15632 -rw-r--r-- 1 pi pi 1658348 Feb 5 09:09 bluez-5.43.tar.xz -rw-r--r-- 1 pi pi 94 Feb 5 07:57 chinese.py -rw-r--r-- 1 pi pi 2736 Feb 5 07:57 find_edimax.c -rw-r--r-- 1 pi pi 14332601 Feb 5 09:09 myfile.gz -rw-r--r-- 1 pi pi 763 Feb 5 08:02 pack.c --min-size 可以指定備份檔案的大小下限,例如只備份 1MB 以上的檔案: rsync -avh --min-size=1M myfolder/ backup/ sending incremental file list ./ bluez-5.43.tar.xz myfile.gz sent 16.00M bytes received 57 bytes 31.99M bytes/sec total size is 15.99M speedup is 1.00 而 --max-size 可以指定備份檔案的大小上限,例如只備份 4KB 以下的檔案: rsync -avh --max-size=4K myfolder/ backup/ sending incremental file list ./ chinese.py find_edimax.c pack.c sent 3.91K bytes received 76 bytes 7.97K bytes/sec total size is 15.99M speedup is 4,012.68 --min-size 與 --max-size 也可以同時使用,例如只備份 1KB 到 2MB 之間的檔案: rsync -avh --min-size=1K --max-size=2M myfolder/ backup/ sending incremental file list ./ bluez-5.43.tar.xz find_edimax.c sent 1.66M bytes received 57 bytes 3.32M bytes/sec total size is 15.99M speedup is 9.62 自動刪除來源檔案 如果想讓 rsync 在備份檔案之後,自動將來源檔案刪除(也就是相當於 mv 的效果),可以加上 --remove-source-files 參數: rsync -avh --remove-source-files myfolder/ backup/ sending incremental file list ./ bluez-5.43.tar.xz chinese.py find_edimax.c myfile.gz pack.c sent 16.00M bytes received 154 bytes 10.67M bytes/sec total size is 15.99M speedup is 1.00 這樣執行 rsync 之後,myfolder/ 目錄會被清空,所有的資料都會被移到 backup/ 目錄中,所以請小心使用,別勿刪重要檔案。 測試 rsync 參數 初學者如果不確定自己的 rsync 參數是否正確,在實際執行之前可以加上 --dry-run 來測試一下,加上這個參數之後 rsync 執行時還是會輸出正常的訊息,不過並不會更動到任何的檔案: rsync -avh --dry-run --remove-source-files myfolder/ backup/ sending incremental file list bluez-5.43.tar.xz chinese.py find_edimax.c myfile.gz pack.c sent 194 bytes received 31 bytes 450.00 bytes/sec total size is 15.99M speedup is 71,086.85 (DRY RUN) 這樣可以方便使用者檢查自己的參數是否配置得宜。 crontab 定期備份 通常如果要在本地端進行備份,就可以在 crontab 中定期執行這樣的指令,將重要的資料定期備份至指定目錄: # m h dom mon dow command 0 5 * * 1 rsync -a /path/to/folder /path/to/backup/ 這樣系統就會在每週一的早上 5 點執行 rsync 備份檔案。 只更新既有檔案 如果在備份檔案時,只想要更新過去已經備份過得檔案,排出新增的檔案,可以使用 --existing 參數。 假設我們過去已經將 myfolder/ 的檔案備份至 backup/ 了: rsync -avh myfolder/ backup/ 而這時候又新增了一個新的檔案: touch myfolder/new.file 若此時我們只要更新 backup/ 中已經存在的檔案,排除後來新增的,就可以使用 --existing 參數: rsync -avh --existing myfolder/ backup/ sending incremental file list ./ sent 201 bytes received 19 bytes 440.00 bytes/sec total size is 15.99M speedup is 72,702.46 顯示檔案變動資訊 執行 rsync 時加入 -i 參數可以個別檔案變動的資訊: rsync -avhi myfolder/ backup/ sending incremental file list .d..t...... ./ .f...p..... find_edimax.c >f..t...... myfile.gz >f+++++++++ new.file >f.st...... pack.c sent 14.34M bytes received 79 bytes 3.19M bytes/sec total size is 15.99M speedup is 1.12 加入 -i 之後,每個檔案項目之前會多出一個標示字串,而這個標示字串的欄位有 11 個,分別為 YXcstpoguax,其意義如下: Y:< 代表檔案傳送至遠端,> 代表檔案傳送至本地端,c 代表本地端變動(建立目錄等),h 代表硬式連結(hard link),. 代表沒有變動,* 代表其餘欄位有包含訊息(例如 deleting)。 X:檔案類型,f 為一般檔案,d 為目錄,L 為連結檔,D 為設備檔(device),S 為特殊檔案(如 sockets 或 fifo)。 c:代表檔案內容有變動。 s:代表檔案大小有變動。 t:代表檔案時間戳記有變動。 p:代表檔案權限有變動。 o:代表檔案擁有者有變動。 g:代表檔案群組有變動。 u:保留欄位。 a:代表檔案 ACL 資訊有變動。 x:代表檔案擴充屬性(extended attribute)有變動。

[RoundcubeMail]Webmail 網頁信箱 roundcube 設定安裝 - CentOS7

轉自:https://blog.xuite.net/tolarku/blog/542972521-Webmail+%E7%B6%B2%E9%A0%81%E4%BF%A1%E7%AE%B1+roundcube+%E8%A8%AD%E5%AE%9A%E5%AE%89%E8%A3%9D+-+CentOS7

password using chpasswd how to

引用:http://www.roundcubeforum.net/index.php?topic=21861.0 password using chpasswd how to Since I got no response on the PAM method, I tried the chpasswd method. After much research, trial and error, and the like, I did get it to work. Here are the instructions to save future researchers the trouble: 1) enable password function vi /var/www/html/roundcube/config/config.inc.php - alter the following line as follows: $config['plugins'] = array('password'); cd /var/www/html/roundcube/plugins/password cp config.inc.php.dist config.inc.php 2) enable the password plugin cd /var/www/html/roundcube/plugins/password cp config.inc.php.dist config.inc.php vi config.inc.php - alter the following as follows: $config['password_driver'] = 'chpasswd'; 3) allow apache to run the script visudo - add to bottom Defaults:apache !requiretty apache ALL=(root) NOPASSWD: /usr/sbin/chpass-wrapper.py 4) add blacklisted users and minimum UID below vi /var/www/html/roundcube/plugins/password/helpers/chpass-wrapper.py BLACKLIST = ( # add blacklisted users here comma separated 'root' ) if user.pw_uid < 494: sys.exit('Changing the password for user id < 494 is forbidden') 5) copy the helper to executable directory & set make it executable cp /var/www/html/roundcube/plugins/password/helpers/chpass-wrapper.py /usr/sbin chmod 755 /usr/sbin/chpass-wrapper.py 6) alter the driver to run the helper which in turn runs the driver (wraps it) vi /var/www/html/roundcube/plugins/password/config.inc.php old: $config['password_chpasswd_cmd'] = 'sudo /usr/sbin/chpasswd 2> /dev/null'; new: $config['password_chpasswd_cmd'] = 'sudo /usr/sbin/chpass-wrapper.py 2> /dev/null';

2018年3月21日 星期三

[PHP]Jquery ajax

小心使用 Ajax 防止 Bug 產生 https://dotblogs.com.tw/jasonyah/2013/06/02/use-ajax-you-need-to-be-care
$.ajax({ url: '', // url位置 type: 'post', // post/get data: { querytag: data }, // 輸入的資料 error: function (xhr) { }, // 錯誤後執行的函數 success: function (response) { }// 成功後要執行的函數 });

[PHP]JQUERY

以jQuery實現可編輯 http://blog.darkthread.net/post-2011-06-22-editable-table-with-jquery.aspx 神奇的jQuery Selector http://www.darkthread.net/jQuery/Tutorial04/default.htm 如何撰寫有效率的CSS選擇器(CSS Selector) http://www.mrmu.com.tw/2011/10/11/writing-efficient-css-selectors/

[PHP]JSON相關

回傳JSON 快速取得物件中的資料 若想要快速取得物件中的資料, 則可以參考 JQuery 的 $.each() 函數, 例如要取得 JSON 回傳資料中的APPLIER 物件. 程式可以這樣寫 $.each(userData, function(i, val){ if (i=="APPLIER"){ $.each(val[0] , function(applier, a_val){ alert("key:"+applier+" , value:"+a_val) }); } }); json_encode() 使用該函式將 PHP 陣列(Array)和物件(Object),編碼成 JSON 字串。 json_decode() 使用該函式將 JSON 格式的字串進行解碼,轉換為 PHP 變數。 http://www.smalljacky.com/programming-language/php/php-json-teaching/

2017年9月19日 星期二

[轉貼]將 MySQL 資料表內容匯出為 CSV 檔案

1.直接將 mysql 查詢結果儲存為 TXT 檔案, 再由 Libre Office Calc 或 MS Office Excel 讀入後轉存為 CSV 檔案 2.以 select into outfile 語法匯出資料表內容, 直接在 Linux CLI 產生 CSV 檔案 操作環境: CentOS, bash, mysql / mariadb 直接將 mysql 查詢結果儲存為 TXT 檔案, 再由 Libre Office Calc 或 MS Office Excel 讀入後轉存為 CSV 檔案 Step 1. echo "select * from ps_customer" | mysql -u root -p -A prestashop > result.txt Step 2. 由 Libre Office Calc / MS Office Excel 讀入 result.txt (Tab 分隔) Step 3. 於 Libre Office Calc / MS Office Excel 另存檔案為 CSV 格式 註: 若 SQL Query 語法較複雜, 可先將 SQL 內容寫入檔案再由 mysql 讀入. 例如: mysql -u root -p -A prestashop < complex-query.sql > result.txt 以 select into outfile 語法匯出資料表內容, 直接在 Linux CLI 產生 CSV 檔案 建立工作路徑 # mkdir /tmp/csv # chown mysql /tmp/csv 範例一: 匯出所有欄位 匯出 column_name mysql> use mysql mysql> select group_concat(concat(column_name)) into outfile '/tmp/csv/header.txt' from information_schema.columns where table_name='ps_customer' and table_schema='prestashop'; 匯出 table 內容 mysql> use prestashop mysql> select * into outfile '/tmp/csv/content.txt' fields terminated by ',' enclosed by '"' lines terminated by '\n' from ps_customer; 範例二: 匯出指定欄位 匯出 column_name 與 table 內容 mysql> use prestashop mysql> select 'id_customer,firstname,lastname,email,birthday' into outfile '/tmp/csv/header.txt'; mysql> select id_customer, firstname, lastname, email, birthday into outfile '/tmp/csv/content.txt' fields terminated by ',' enclosed by '"' lines terminated by '\n' from ps_customer; 彙整 header 與 content # cd /tmp/csv/ # (sed 's/^/"/;s/$/"/;s/,/","/g' header.txt; cat content.txt) > result.csv # unix2dos result.csv Ref: •linux - How to output MySQL query results in csv format? - Stack Overflow •mysql - Include headers when using SELECT INTO OUTFILE? - Stack Overflow •Linux / Unix: Sed Substitute Multiple Patterns [ Find & Replace ] 文章來源:http://jamyy.us.to/blog/2015/09/7687.html

roundcubemail webmail

Database Configuration Next thing we need to do is decide what database backend we'll use. The most common is MySQL but others are PostgreSQL and SQLite. So once you decide, create a database with any name you want and grant privileges to a separate database user. It's recommended not to use an existing user or root. With MySQL you can set up the database by issuing the following commands: CREATE DATABASE roundcubemail; GRANT ALL PRIVILEGES ON roundcubemail.* TO username@localhost IDENTIFIED BY 'password'; (of course you have to replace the database, username and password accordingly) See the INSTALL file for information about setting up PostgreSQL or SQLite If you are using MySQL, be sure to flush the users privileges when you add a new user or you will get a database connection error: FLUSH PRIVILEGES; Note that preconfigured database tables are included in the SQL folder. Import or restore your version or you may get a 500 Error. ======================== QUOTA /etc/dovecot.conf protocol imap { mail_plugins = quota imap_quota } plugin { quota = fs:user } https://wiki1.dovecot.org/Quota/FS

2016年10月12日 星期三

[轉載]Mail Server [postfix] 使用者帳號遭受盜用

文章來源:http://blog.xuite.net/tolarku/blog/81551578 Mail Server [postfix] 使用者帳號遭受盜用 Manual Page 針對各個 Mail program 的簡單描述 •smtpd:Postfix SMTP server,Postfix daemon. The SMTP server accepts network connection requests and performs zero or more SMTP transactions per connection. Each received message is piped through the cleanup(8) daemon, and is placed into the incoming queue as one single queue file. For this mode of operation, the program expects to be run from the master(8) process manager. 利用 port:25 對外提供接收郵件的服務程式。 •pickup:Postfix local mail pickup,The pickup(8) daemon waits for hints that new mail has been dropped into the maildrop directory, and feeds it into the cleanup(8) daemon. 接受本地端使用者送過來的信件。 •cleanup:canonicalize and enqueue Postfix message. The cleanup(8) daemon processes inbound mail, inserts it into the incoming mail queue, and informs the queue manager of its arrival. 依循 main.cf 訂定的規則,來處理、排隊依序進來的信件。 •trivial-rewrite:Postfix address rewriting and resolving daemon. Rewrite an address to standard form, according to the address rewriting context. 針對 recipient address 做重寫的格式化輸出。 •qmgr:Postfix queue manager. The qmgr(8) daemon awaits the arrival of incoming mail and arranges for its delivery via Postfix delivery processes. The actual mail routing strategy is delegated to the trivial-rewrite(8) daemon. Postfix 最重要的排隊處理程式。 • -------------------------------------------------------------------- Mail Queues / 郵件暫存的資料夾 •incoming:Inbound mail from the network, or mail picked up by the local pickup(8) daemon from the maildrop directory. 處理 pickup 收進來的信件,會先放到 incoming 這個資料夾 (以 Binary file 格式儲存,可以用 postcat 來觀看信件內容)。或者 Queue Manager 來不及處理的信件也會暫時先放在這個目錄 /var/spool/postfix/incoming 。 •active:Messages that the queue manager has opened for delivery. Only a limited number of messages is allowed to enter the active queue (leaky bucket strategy, for a fixed delivery rate). 正準備寄送的信件會被放在這個目錄。 •deferred:Mail that could not be delivered upon the first attempt. The queue manager implements exponential backoff by doubling the time between delivery attempts. 傳送失敗的信件會被放到這個目錄,每失敗一次都會利用 exponential backoff 算出應該等待的時間,時間倒數完才會進行下一次的嘗試傳送。 想要清除這麼目錄下的信件可以參考「Postfix Mail Queue - 一些簡單的管理指令」 ,但不建議一次刪除這目錄下的檔案,除非你知道那些信件都是不要的。 •corrupt:Unreadable or damaged queue files are moved here for inspection. 損毀或是無法讀取的信件。 •hold:Messages that are kept "on hold" are kept here until someone sets them free. 管理者可以利用「/usr/sbin/postsuper -h queue_id」來將信件 Hold 住不讓他寄送出去,這時該信件就會被暫時放到這個目錄下。 •bounce:Per-recipient status information about why mail is bounced. These files are maintained by the bounce(8) daemon. •defer:Per-recipient status information about why mail is delayed. These files are maintained by the defer(8) daemon. •trace:Per-recipient status information as requested with the Postfix "sendmail -v" or "sendmail -bv" command. These files are maintained by the trace(8) daemon. ----------------------------------------------------------------------------- 既然這篇定義是說「事件記錄」怎麼會前面突然跑出一大堆 mail 的 programs / folders 或流程的描述呢?耐心的看下.... 狀況一:當使用者誤信了詐騙信件,導致將自己的帳密提供給別人,依我的觀察~~ ## 大約不到一天這個帳號就會被利用來散發廣告信,因為我有擋每封信收件者的上線,所以瞬間可能會有幾百封的廣告信從我的 mail server 送出去。 狀況二:若在狀況一發生時,無法及時處理過了一晚大約會有數千到數萬筆信件 queue 住等待散發垃圾信 ##這時反應比較快的 mail server 已經將我的 mail server 阻擋,不再接受我的主機送信過去。像這項的情況需要用 mailq | grep "xxx@123.com" | cut -d " " -f1 | cut -d’*’ -f1 | postsuper -d - 或 /usr/sbin/postqueue -p | grep "xxx@123.com" | cut -d " " -f1 | cut -d"*" -f1 | /usr/sbin/postsuper -d - 將特定寄件者的信件清除掉,當然你得同時封鎖該使用者的帳號。 狀況三:在狀況二已封鎖使用者帳號情況下,也清除了 mail Queue 裡的信件,卻持續的被對方利用來寄發垃圾信 ##這時是因為 smtpd 的 SASL認證 或 webmail 的 session 還沒過期所致,你可以簡單的重新啟動 postfix / sendmail 來解決。 狀況四:某次發現 mail queue 裡怎麼會有 AA@domain, AX@domain ....ZC@domain 的寄件者送出的信件 ##這是某位使用者帳號遭受盜用,通過SASL認證後,其竄改寄件者的來源 (以往都是用單一寄件者來發信,這已進化到以程式來偽裝寄件者,而且每個偽裝的 XX@domain 不多不少都只寄50封信,減少被偵測出來的機會。 ##這樣的處理就複雜的多,因為某些 XX@domain 是真的有這個帳號的,所以就必須個別的清除不存在寄件者所送出的信件。而這一次 mail queue 就 queue 住了快10萬筆的信件。 狀況五:這次的情況跟狀況二相似,不同的在於很慢才發現,系統的 loading 已經破百 102.x(使用 w 指令觀察,而一般的狀況 loading 連1都不到,只有 0.1x) ##利用「/usr/sbin/postqueue -p | grep "xxx@123.com" | cut -d " " -f1 | cut -d"*" -f1 | /usr/sbin/postsuper -d -」方式清除特定使用者的信件,用這一行程式清除 mail queue 裡的信件跑了快 6個小時 ##一則是 CPU loading 已被超爆,再來是信件大量到信並不是卡在 /var/spool/postfix/active ,而是連 /var/spool/postfix/incoming 都被放了上百萬封,所以單獨清 active 是不夠的, 在 incoming 會再進來,在 deferred 的也會再嘗試傳送 ##最後我的作法是先清除非當天的 deferred 信件「find /var/spool/postfix/deferred -type f -mtime +1 -exec rm -f \{\} \;」,為了怕誤刪正常的信件就必須過濾,只將某特定使用者的信才刪除。 當遇到使用者帳號遭受盜用的情形,第一時間當然是先封鎖帳號、封鎖發信IP或重新啟動郵件服務程式 postfix / sendmail ,再來就清 active 的 mail queue 跟過了幾天送不出去的信件,如果情形很嚴重則需要去觀察 incoming 目錄下 queue 住的信件。 朋友建議「撈出log裡的sasl認證,找出sasl username對應的mail queue ID」然後利用此方式來刪,找時間寫段 shell script 來試試看。 ~ End

2016年9月27日 星期二

[LINUX]Fail2Ban

OS:CENTOS 6.8 安裝 yum install epel-release yum install fail2ban 設定 設定fail2ban.conf fail2ban.conf的位置在 /etc/fail2ban/fail2ban.conf 當中,請以以下指令開啟: [root@server ~]# vim /etc/fail2ban/fail2ban.conf 這個設定檔需要調整的部份不多,請修改 logtarget 的參數如下: #預設的參數 #logtarget = SYSLOG #調整後的參數 logtarget = /var/log/fail2ban.log 這樣子fail2ban在執行時就會將記錄檔記錄到 /var/log/fail2ban.log 中。 fail2ban中阻擋SSH連線的ssh-iptables的狀態: fail2ban-client status ssh-iptables 參考資料: http://blog.pulipuli.info/2011/07/centosfail2ban.html

2015年11月1日 星期日

HP 指令集

看效能記錄 sar -f s1.mon -s 10:00 -e 10:30 看目前CPU及記憶體使用率 glance samba連線 smbstatus

2013年6月25日 星期二

PHP Warning: fwrite() expects parameter 1 to be resource, boolean given in

CENTOS 6 + PHP5要寫入檔案時錯誤
 PHP Warning:  fwrite() expects parameter 1 to be resource, boolean given in

原因是SELINUX要設定開放PHP連接DB
/usr/sbin/setsebool -P allow_url_fopen = 1

2013年6月19日 星期三

Can't connect to MySQL server on 'xxx.xxx.xxx.xxx' (13)

CENTOS 6

PHP 連接mySQL出現Can't connect to MySQL server on 'xxx.xxx.xxx.xxx' (13)

原因是SELINUX要設定開放PHP連接DB
/usr/sbin/setsebool -P httpd_can_network_connect_db=1

2013年3月28日 星期四

SSH金鑰登入

以金鑰做認證登錄

步驟:

 1.ssh-keygen -t rsa (RSA加密) 或 ssh-keygen -d (dsa加密) => 產生公鑰及私鑰 ~./ssh/id_rsa, ~./ssh/id_rsa.pub

 2.scp id_rsa.pub server_hostname:~/.ssh/

 3.ssh server_hostname

 4.cat .ssh/id_rsa.pub >> .ssh/authorized_keys 或 authorized_keys2

 這樣就可以 金鑰認證方式登入, 不需輸入密碼

注意: ssh-keygen 時會問 Enter passphrase (empty for no passphrase): # 此處直接 enter 跳過,下次才不會詢問password

簡單解說一下:

  • id_rsa: private key
  • id_rsa.pub: public key

將 public key(id_rsa.pub) 拷貝到遠端的電腦後, 加到那 user 的 .ssh/authorized_keys 或 authorized_keys2中.

之後連線時, 就會用本機的 private key(id_rsa) 與遠端電腦的 public key(authorized_keys) 做認證, 確認完成就可以直接登入, 不需輸入帳號密碼



2012年12月23日 星期日

[phpBB]如何改標題圖片

\phpbb\templates\subSilver\images下的logo_phpBB.gif置換一下即可

註冊條款
language\zh_cmn_hant\ucp.php
找'TERMS_OF_USE_CONTENT'

2012年12月13日 星期四

取出EXCEL欄位中的超連結

Sub 取出超連結網址()
 Dim xR As Range
 For Each xR In Range([A2], [a65536].End(xlUp))
   If xR.Hyperlinks.Count > 0 Then
    xR(1, 5) = xR.Hyperlinks(1).Address
   End If
 Next
End Sub


資料來源:http://tw.knowledge.yahoo.com/question/question?qid=1511092001951

2012年12月10日 星期一

[mySQL]資料取出是問號

編碼問題
請在連接資料庫後,加上一行
@mysql_query ("set names utf8;", $this->db_connect_id);


2012年11月15日 星期四

[LINUX]查看 Linux 系統資訊常用指令

查看 Linux 系統資訊常用指令
lspci -v => 檢查系統 PCI 介面的各項裝置
lsusb => 檢查系統USB介面的裝置
lsscsi => 檢查系統SCSI介面的裝置
cat /proc/cpuinfo => 顯示CPU的資訊
cat /proc/meminfo => 顯示記憶體的資訊
free => 顯示記憶體的相關資訊
dmidecode => 查看硬體的相關資訊
hdparm -i /dev/hda => 硬碟的各項資訊
dmesg => Linux Kernel 運作過程當中所顯示的各項訊息記錄
uname -a => 顯示Linux系統資訊
cat /proc/version => 查看 Linux 核心
cat /etc/issue => 查看 Linux 系統版本
smartctl -a /dev/sda => 查看硬碟詳細資訊及型號

引用:http://taiwanwolf.blogspot.tw/2009/02/linux.html