LPI: Learn Linux and get certified. Part 3: filesystem layout, partitioning and shared libraries

Posted by Unknown Kamis, 17 Mei 2012 0 komentar
http://tuxradar.com/content/lpi-learn-linux-and-get-certified-part-3-filesystem-layout-partitioning-and-shared-libraries


 Guess how many files you end up with on your hard drive after a single-CD Debian 6 installation. Go on – we’ll wait. Well, the answer is 82,698. That seems almost unbelievable – and impossible to manage – but fortunately the Linux filesystem layout handles this vast number of files well, providing everything with a sensible place to live. You don’t need to know what each individual file does in great detail, but from its location you can determine its overall purpose in the grand scheme of things.

This month, we’re looking at how the Linux filesystem fits together, partitioning your hard drive and modifying the Grub bootloader’s configuration. We’ll also look at how shared libraries improve security and reduce disk space requirements. As with the other tutorials in this series, some filesystem locations and commands may vary depending on the distro you’re using. However, for training purposes we recommend one used in enterprise, such as Debian, on which this tutorial is based.

Section 1: The Linux filesystem layout

First, let’s look at how a Linux installation is organised on a hard drive. As opposed to Windows, which has different ‘starting points’ or drive letters for each device, in Linux there’s one single source of everything – like a Big Bang of data. This is /, or the root directory, which is not to be confused with the root user, aka administrator. All of the other directories stem from this, such as /home/username, your home directory. In other words, root is the top-level directory, and everything on the system is a subdirectory of it. Here are the items you’ll find in the root directory:

  • /bin This holds binary files – that is, executable programs. These are critical system tools and utilities, such as ls, df, rm and so forth. Anything that’s needed to boot and fix the system should be in here, whereas /usr/bin has a different purpose – as we’ll see in a moment.
  • /boot This contains the kernel image file (vmlinuz – the z is because it’s compressed), which is the program loaded and executed by the bootloader. It also contains a RAM disk image (initrd), which provides the kernel with a minimal filesystem and set of drivers to get the system running. Many distros drop a file called config here – which contains the settings used to build the kernel – and there’s a grub subdirectory for bootloader configuration, too.
  • /dev Device nodes. You can access most hardware devices in Linux as if they were files, reading and writing bytes from them. See part one of this series for more on /dev.
  • /etc Primarily configuration files in plain text format, although there are exceptions. Boot scripts (see part two of this series) also live here. These are system-wide configuration files for programs such as Apache; settings for desktop apps typically live in a user’s home directory.
  • /home Where home directories usually reside. Each user account has a directory here for personal files and settings.
  • initrd.img A symbolic link (not a real file, more like a Windows shortcut) to the aforementioned RAM disk file in /boot. You can see its full link target with ls -l.
  • /lib Shared libraries; see the What are shared libraries? box at the bottom of this page to learn more. Like /bin, these are critical libraries used to boot and run the system at a basic level. /lib also contains kernel modules (see part one of this series for more).
  • /lost+found If your PC crashes or loses power during a heavy disk write operation and does a disk check (fsck) on next boot, pieces of partially lost files are deposited here.
  • /media When external drives, such as USB keys, are plugged in, the auto-mounting process will give them a directory here from which you can access the files.
  • /mnt A bit like /media, except this is usually used for manually mounted, long-term storage, including hard drives and network shares.
  • /opt Optional software. This is quite rarely used, but in some distros and packages you’ll find large suites such as KDE and OpenOffice.org placed here in order to keep everything neatly together (and therefore easy to remove or upgrade outside a package manager).
  • /proc Access to process information. Each process (running task) on the system can be examined here, maintaining Unix’s ‘everything is a file’ philosophy.
  • /root Personal files used by the superuser or root account. Many administrators will keep backups of config files here too. When it comes to multiple-user installations, it’s vital that normal user accounts can’t poke around here.
  • /sbin Binary executable files, similar to in /bin, but explicitly for use by the superuser. This contains programs that normal users shouldn’t run, such as network configuration tools, partition formatting tools and so on.
  • /selinux A placeholder for files used by the Security-Enhanced Linux framework.
  • /srv This is intended to be used for data served by the system (for example, a web server). However, most programs use /var instead.
  • /sys Like a more modern /dev, with extra capabilities. You can get lots of information about hardware and the kernel here, but it’s not important for normal admin jobs.
  • /tmp Temporary files. Any program can write here, so you’ll see random bits and bobs from background services, web browsers and so on. Most distros clean it at boot.
  • /usr This is a different world. /usr contains its own versions of the bin, sbin and lib directories, but these are for applications that exist outside of the base system. Anything that’s vital to get the machine running should be in /bin, /sbin and /lib, whereas nonessential programs such as Firefox and Emacs should live here. There’s a good reason for this: you can have the important base system on one partition (/) and add-on programs on another (/usr), providing more flexibility. /usr, for example, might be mounted over the network. In here, there’s also /usr/local, which is typically used for programs you’ve compiled yourself, keeping them away from the package manager.
  • /var Here be files that vary. In other words, files that change a lot, such as log files, databases and mail spools. Most distros place Apache’s document root here too (/var/www). On busy servers, where this directory is accessed often with lots of write operations, it’s frequently given its own partition with filesystem tweaks for fast performance.
  • vmlinuz A symbolic link to the kernel image file in /boot.
  • Depending on your distro, you may find additional items in the root directory. However, most distros try to abide by the guidelines of the Filesystem Hierarchy Standard (FHS). This is an attempt to standardise the filesystem layout across distros. You can delve deeper into /var, /usr and other directories by looking at the hierarchy manual page – just enter man hier in a terminal.

    What are shared libraries?

    A library is a piece of code that doesn’t run on its own, but can be used by other programs. For instance, you might be writing an application that needs to parse XML, but don’t want to create a whole XML parser. Instead, you can use libxml, the XML handling library, which someone else has already written. There are hundreds of libraries like this in a typical Linux installation, including ones for basic C functions (libc) and graphical interfaces (libgtk, libqt).
    Libraries can be statically linked to a program – rolled into the final executable – but usually they’re provided as shared entities in /lib,
    /usr/lib and /usr/local/lib with .so in the filename, which stands for shared object. This means multiple programs can share the same library, so if a security hole is discovered in it, only one fix is needed to cover all the apps that use it. Shared libraries also mean program binary sizes are smaller, saving disk space.
    You can find out what libraries are used by a program with ldd. For instance, ldd /usr/bin/gedit shows a list of libraries including:
    libgtk-x11-2.0.so.0 => /usr/lib/libgtk-x11-2.0.so.0 (0xb7476000)
    Gedit depends on GTK, so it needs libgtk-x11, and on the right you can see where the library’s found on the system. What determines the locations for libraries, though? The answer is in /etc/ld.so.conf, which nowadays points to all files in /etc/ld.so.conf.d. These files contain plain text lines of locations in the filesystem where libraries can be found, such as /usr/local/lib. You can add new files with locations here if you install libraries elsewhere, but must run ldconfig (as root) afterwards to update a cache that’s used by the program loader.
    Sometimes you might want to run a program that needs a library in a specific place that’s not part of the usual locations. You can use the LD_LIBRARY_PATH environment variable for this. For instance, entering the following will run the myprog executable that’s in the current directory, and temporarily add mylibs to the list of library locations as well: LD_LIBRARY_PATH=/path/to/mylibs ./myprog. Many games use this method to bundle libraries alongside a binary, without needing the binaries.
    Most programs derive a good chunk of their functionality from shared libraries, as running the ldd command shows.Most programs derive a good chunk of their functionality from shared libraries, as running the ldd command shows.

    Section 2: Partitioning schemes

    Drive partitioning is one of those tasks that an administrator rarely has to perform, but one that can have huge long-term consequences. Allocate the wrong amount of space for a particular partition and everything can get very messy later on. How you go about partitioning depends on the installer your distro uses, so we won’t list thousands of keybindings here. Instead, we’ll look at a partitioning tool common to all distros, and the options you have when divvying up a drive. Open up a terminal, switch to root and enter:
    fdisk /dev/sda
    Replace sda with the device node for your drive. (This should be sda on single-hard drive machines, or sdb if you’re booting Linux from a second drive. Consult dmesg’s output if you’re unsure.) fdisk itself is a simple command-driven partitioning utility. Like Vi, it’s austere in appearance, but it’s ubiquitous. Enter p and you’ll see a list of partitions on the drive, as in the screenshot, below. Type m to list the available commands: you can delete partitions (d), create new ones (n), save changes to the drive (w) and so forth. This is a powerful tool, but it assumes that you know what you’re doing and won’t mollycoddle you. fdisk also doesn’t format partitions – it just gives them a type number. To format, type in mkfs and hit Tab to show the possible completion options. You’ll see that there are commands to format partitions in typical Linux formats (such as mkfs.ext4) plus Windows FAT32 (mkfs.vfat) and more. Along with filesystem partitions, there’s also the swap partition to be aware of. This is used for virtual memory. In other words, when a program can no longer fit in the RAM chips because other apps are eating up memory, the kernel can push that program out to the swap partition by writing the memory as data there. When the program becomes active again, it’s pulled off the disk and back into RAM. There’s no magical formula for exactly how big a swap partition should be, but most administrators recommend twice the size of the RAM, but no bigger than 2GB. You can format a partition as swap with mkswap followed by the device node (/dev/sda5, for instance), and activate it with swapon plus the node. You can also use a single file as swap space – see the mkswap and swapon man pages for more information.
    Most distros have their own graphical partitioning tools, but wherever you are, you'll always find the trusty fdisk.Most distros have their own graphical partitioning tools, but wherever you are, you'll always find the trusty fdisk.

    Partition approaches

    Now, what approach do you take when partitioning a drive? There are three general approaches:

  • All-in-one. This is a large single partition that contains the OS files, home directory data, temporary files and server data, plus everything else. This isn’t the most efficient route in some cases, but it’s by far the easiest, and means that each directory has equal right to space in the whole partition. Many desktop-oriented distros take this approach by default.
  • Splitting root and home. A slightly more complex design, this puts /home in its own partition, keeping it separate from the root (/) partition. The big advantage here is that you can upgrade, reinstall and change distros – completely wiping out all the OS files if necessary – while the personal data and settings in /home remain intact. For a more detailed look at the benefits of creating a separate /home partition, turn to our tutorial on page 80.
  • Partitions for all. If you’re working on a critical machine, such as a live internet-facing server that needs to be up 24-7, you can develop some very efficient partitioning schemes. For instance, say your box has two hard drives: one that’s slow and one that’s fast. If you’re running a busy mail server, you can put the root directory on the slow drive, since it’s only used for booting and the odd bit of loading. /var/spool, however, could go on the faster drive, since it could see hundreds of read and write operations every minute.
  • This flexibility in partitioning is a great strength of Linux and Unix, and it just keeps getting more useful. Consider, for example, the latest fast SSD drives: you could put /home on a traditional hard drive to give yourself plenty of room at a cheap price, but put the root directory onto an SSD so that your system boots and runs programs at light speed.

    The magic of /etc/fstab

    After reading about the partitioning schemes available, and how to set them up using fdisk and mkfs, you may be wondering how they hook into a working Linux installation. The controller of all this is /etc/fstab, a plain text file that associates partitions with mount points. Have a look inside and you’ll see various lines that look like this:
    UUID=cb300f2c-6baf-4d3e-85d2-9c965f6327a0 /  ext3    errors=remount-ro 0       1
    This is split into five fields. The first is the device, which you can specify in /dev/sda1-type format or with a more modern UUID string (use the blkid command with a device node to get its UUID – it’s just a unique way of identifying a device). Then there’s its mount point, which in this case is the root directory. Following that is the filesystem format, and then options.
    Here, we’re saying that if errors are spotted when the boot scripts mount the drive, it should be remounted as read-only, so that write operations can’t do more damage. Use the man page for mount to see all the options available for each filesystem format. The final numbers deal with filesystem checks, and you don’t need to change these defaults.
    You can add your own mount points to /etc/fstab with a text editor, but beware that some distros make automatic changes to the file, so be sure to keep an original copy backed up too.

    Section 3: Configuring the boot loader

    Almost all Linux distributions today use Grub 2 (the Grand Unified Bootloader to give it its full name) to get the kernel loaded and start the whole Linux boot process. We looked at Grub in last issue’s tutorial, and specifically how to edit its options from inside Grub itself. However, such edits are only temporary. If there’s a change you need to do every time, it’d be a pain to interrupt the boot sequence at each startup. The solution is to edit the
    /etc/default/grub file.
    This isn’t actually Grub’s own configuration file – that’s located at /boot/grub/grub.cfg. However, that file is automatically generated by scripts after kernel updates, so it’s not something you should ever have to change by hand. In most cases, you’ll want to add an option to the kernel boot line, such as one to disable a piece of hardware or boot in a certain mode. You can add these by opening up /etc/default/grub as root in a text editor, and looking at this line:
    GRUB_CMDLINE_LINUX_DEFAULT=”quiet”
    This contains the default options that are passed to the Linux kernel. Add the options you need after quiet, separated by spaces and inside the double-quotes. Once done, run:
    /usr/sbin/update-grub
    This will update /boot/grub/grub.cfg with the new options.
    The place to add kernel boot options is /etc/default/grub -- remember to run update-grub afterwards in order to transfer your changes to /boot/grub/grub.cfg.The place to add kernel boot options is /etc/default/grub -- remember to run update-grub afterwards in order to transfer your changes to /boot/grub/grub.cfg.

    Old and grubby

    If you’re using an older distro with Grub 1, the setup will be slightly different. You’ll have a file called /boot/grub/menu.lst, which will contain entries such as:
    title Fedora Core (2.6.20-1.2952.fc6)
    root (hd0,0)
    kernel /vmlinuz-2.6.20-1.2952.fc6 ro root=/dev/md2 rhgb quiet
    initrd /initrd-2.6.20-1.2952.fc6.img
    Here, you can add options directly to the end of the kernel line, save and reboot for the options to take effect. Should Grub get corrupted or removed by another bootloader, you can reinstall it by running the following as root:
    grub-install /dev/sda
    Replace sda with sdb if you want to install it on your second hard drive. This writes the initial part of Grub to the first 512 bytes of your hard drive, which is also known as the master boot record (MBR). Note that Grub doesn’t always need to be installed on the MBR; it can be installed in the superblock (first sector) of a partition, allowing a master bootloader in the MBR to chain-load other bootloaders. That’s beyond the scope of LPI 101, however, and you’re unlikely to come across it, but it’s worth being aware of.
    Finally, while Grub is used by the vast majority of distros, there are still a few doing the rounds that use the older LILO – the Linux Loader. Its configuration file is /etc/lilo.conf, and after making any changes you should run /sbin/lilo to update the settings stored in the boot sector.

    Test yourself!

    As you progress through this series of tutorials, you may want to assess your knowledge along the way. After all, if you go for full-on LPI certification when our time together is over, you’ll need to be able to use your knowledge on the spot without consulting the guides. We’re planning to include a comprehensive set of example questions when this series concludes, but for now here are some tasks to try and questions to answer based on the three sections in these pages:

  • Where are the kernel image and RAM disk files located?
  • Explain the difference between /lib, /usr/lib and /usr/local/lib.
  • Explain the available Linux partitioning schemes. Why would you put /home on a separate partition?
  • Describe how to add a new location for libraries on the system.
  • See if you can answer these without having to turn back to the relevant sections. If you struggle, no worries – just go back and read it again. The best way to learn is to take the information we’ve provided and experiment on your machine (or a distro in VirtualBox if you don’t want to risk breaking an installation). 

    Baca Selengkapnya ....

    5 Best Linux Business Intelligence Suites

    Posted by Unknown Selasa, 08 Mei 2012 0 komentar
    http://www.smallbusinesscomputing.com/biztools/5-best-linux-business-intelligence-suites.html


    Even a small business generates giant quantities of data, and a good business intelligence suite helps you analyze and make sense of it all. When you have an accurate picture of where you are, you'll see where you can go, and any of these excellent Linux-based small business intelligence suites will take you there.
    Business intelligence (BI) software isn't magical, so don't go throwing a ton of money into it before thinking about what you want to accomplish with it. All of these suites are modular, so you can start small and add more modules as you get familiar with the software and figure out what sort of information you want.
    Measuring actual results is a surprisingly neglected task in a lot of businesses, and is often an eye-opener -- is the new product really paying off, and what markets is it doing best in? What are your real costs and rewards in supporting a branch office, or in clinging to old equipment, or in staying open on Sundays and holidays? BI can identify bottlenecks and inefficiencies, and show you what's working and what isn't.
    BI software requires some expertise to install, set up, and maintain. When you're shopping for BI software you need to consider:
    • Do you have in-house expertise, or do you need to hire help?
    • Integration with your existing databases and data sources
    • Integration with other software (for example CRM/ERP apps like SugarCRM, Salesforce, Sage)
    • Open data formats, support for multiple data formats
    • Licensing mode: per server, per user, or something else? Per user licenses for a server product get expensive fast, and they make no sense. It's like charging per person for tap water.
    • If you hire custom engineering services, how quickly will they have you up and running? All of the BI vendors in this roundup promise speedy service, as quickly as three to eight weeks.
    All of these BI suites have more in common than they have differences: they run on proven open source technologies such as Apache Tomcat and JBoss, AJAX, Java, and various scripting languages, they support multiple databases and data sources, and multiple Web browsers. Competition is pretty fierce and you have good choices, so it may come down to which vendor understands your needs the best, and who gives you the best deal.
    Pentaho Data Mining and Predictive Analytics
    Figure 1: Pentaho Data Mining and Predictive Analytics. Image courtesy Pentaho
    BI depends on well-organized databases, so you may have some cleanup and organizing to do before you get to play with shiny new BI software. When it's well-setup then non-technical users should be able to slice and dice data however they need to. It isn't a quick fix, but a long-term investment that, used well, pays for itself many times over.

    Pricing BI Software

    Pricing takes a bit of work to nail down; it pays to talk to the nice salespeople and let them help you sort it all out. All of these BI suites have free software downloads, and free community support. All of them offer multiple modules, custom support and engineering services, and training and documentation. So the answer to "how much will it cost" is always "it depends."

    For example, Jaspersoft sells self-support packages for its free community edition that range from $99 to $999 per year for 1,800+ pages of product documentation, access to the knowledge base, and a number of Web-based support incidents. SpagoBI offers three levels of email support that range from about $1,300 to $6,500 per year.
    Online training courses range from free to a few hundred dollars and even to $1,200+ for live online sessions.

    Software licenses and custom engineering are especially "it depends." Your total first-year costs can easily hit $10,000 for a small shop. Presumably you'll spend less on support and training after your first year. Still, that's considerably less than the traditional proprietary offerings from SAP, IBM Cognos,  SAS and other old-time proprietary BI vendors.

    Jaspersoft

    Jaspersoft claims to be the world's most-used BI software. JasperReports is everywhere; this is the popular core Java-based reporting engine used in many BI suites to pull data from multiple sources, and output it into multiple formats such as Web pages, PDF, XML, spreadsheet, DOC, and ODT.
    JasperReports powers the Jaspersoft iReport Designer, which gives non-technical users the capability to create complex, sophisticated reports. In fact Jaspersoft's strength is its excellent tools for end-users to slice, dice, and present data without having to be ace database gurus.
    Talend is the Jaspersoft ETL (extract, transform, load) module, which is also used in numerous BI suites. This is the middleware that integrates data from multiple sources. Nobody has a single harmonious squeaky-clean database; it's always ad-hoc and scattered, so an ETL layer is essential.
    Jaspersoft is available as on-premises software, and of course as a hosted cloud service (which everyone, it seems, offers these days) and as a slick mobile BI interface for viewing and building reports. There is a free community edition, and multiple professional editions with different features and support levels.


    SpagoBI

    Spago is a pure open-source BI platform. All of the software is open source and free of cost, as opposed to the more common model of a limited-feature community edition, and then advanced features that cost money. Support services, custom development, and recorded training courses are available for purchase. Spago is based in Italy, and the documentation is published in French and English.
    Spago provides a number of different prefab domains, which are SpagoBI tailored for different use cases. For example, a retail business could use Real-time BI to track sales trends hourly, and make sure that hot items are always stocked. The Mobile BI works in concert with Real-time BI, so that managers can track trends from any location. GeoBI builds maps showing location-based analysis of patterns and trends. Spago also offers custom services and will build your BI however you need.

    Pentaho

    Pentaho is the other big open source BI vendor. Pentaho, like Jaspersoft, has excellent dashboards and report builders for non-technical users. Pentaho incorporates a lot of nice charting features like scatterplots, geo-mapping, bubble charts, lasso filtering, heat grids, and multiple ways to highlight data points.
    Pentaho has some of the best built-in support for, well, everything: Hadoop clustering, all kinds of databases, cloud vendors, all kinds of middleware; it's also very supportive of ISVs (independent service vendors), so if you are an ISV you might look at being a Pentaho integrator.
    Pentaho has invested a lot of resources into making Pentaho embeddable into nearly any environment, and it has extensive APIs (application programming interfaces) and Web services support, with the goal of making it a seamless component in any datacenter.

    OpenI

    OpenI has the most eye-catching name in this roundup, and a different approach than the others. OpenI started out as a complete BI platform, but this led to a lot of duplicated effort with other open source BI products. So now OpenI is is a collection of plugins for Jasper and Pentaho, the two leading open source BI suites.
    OpenI aims to provide functionality not found in Jasper and Pentaho, such as better user interfaces and better tools for exploring OLAP (Online Analytic Processing) cube data. What is this OLAP cube thingy, you ask? An excellent question. In a nutshell it's a multi-dimensional representation of your data that is designed to answer any question you might have, and to answer it quickly. Figure 2 should help you visualize it.
    OLAP (Online Analytic Processing) cube data
    Figure 2: OLAP lets you slice and dice complex data almost any you want, quickly. (Image courtesy Wikipedia, author Infopedian, CC BY-SA 3.0)
    OLAP lets you make arbitrary, unstructured queries so you can parse your data any way that makes sense to you. For example, sales data might be aggregated per salesperson, per district, per different time periods, per different products or product lines, per wholesale costs, tax data...it's a rare BI suite that doesn't have good OLAP support.
    OpenI designs dashboards, predictive models, interactive reporting, and custom design services, claiming "Data to Insights in 72 Hours."

    Actuate

    Actuate is built on BIRT, the open source Business Intelligence and Reporting Tools engine. Actuate's emphasis is on presentation, and you can make some pretty flashy animated presentations that incorporate the latest Web 2.0 technologies.
    The BIRT Viewer is a read-only presentation that can't be altered by the people viewing it. The BIRT Interactive Viewer allows viewers to modify the content. BIRT Designer Pro is aimed at software developers for building Web reports and dashboards, but it's also a nice tool for tech-savvy managers. Actuate includes a full complement of necessary BI tools such as a mobile interface, data integration, and powerful analytics.
    Actuate also emphasizes consistency: one server, a consistent look and feel, and a consistent user experience. Actuate has both free community-supported open source downloads, and an assortment of commercial options.


    Baca Selengkapnya ....

    Linux debugfs Hack: Undelete Files

    Posted by Unknown Senin, 07 Mei 2012 0 komentar
    http://www.cyberciti.biz/tips/linux-ext3-ext4-deleted-files-recovery-howto.html


    Undeletion means restoring files which have been deleted from Linux ext3 file system using rm command. Deleted files can be recovered on ext3 file systems using the debugfs program. This quick tutorial describes how to recover a file that was recently deleted using nothing but standard Linux command line utilities.

    Only sys administrators and root user can view and recover the deleted files using debugfs command. You need to immediately unmount the file system the deleted file was located on to minimizes the risk that the data of the deleted file are overwritten by other users or system process.

    A step-by-step guide for recovering files using debugfs

    Create a text file called data.txt, enter:
    echo 'This is a test' > data.txt
    Display the index number (inode) of data.txt, enter:
    ls -li data.txt
    Sample outputs:
    7536648 -rw-r--r-- 1 root root 15 May  3 12:40 data.txt
    Please note down inode # 7536648. To find out the contents of the ext3 journal (block of data) using debugfs command. The syntax is as follows:
     
    debugfs -w /dev/device/name/here
    debugfs /dev/sda1
    debugfs /dev/mapper/SysVolGroup-LogVolRoot
     
    If your file system is on /dev/sda2, enter:
    # debugfs -w /dev/sda2
    If your file system is on /dev/mapper/wks01-root, enter:
    # debugfs -w /dev/mapper/wks01-root
    After some time, you will be presented with debugfs: prompt as follows:
    debugfs 1.41.12 (17-May-2010)
    debugfs:
    Type the following command at debugfs: prompt to get block of data:
    debugfs:  logdump -i <7536648>
    Sample outputs:
    Inode 7536648 is at group 230, block 7536642, offset 896
    Journal starts at block 10875, transaction 38398034
    FS block 7536642 logged at sequence 38398245, journal block 12418
    (inode block for inode 7536648):
    Inode: 7536648 Type: regular Mode: 0600 Flags: 0x0 Generation: 1050194965
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x4fa249ab -- Thu May 3 04:02:35 2012
    atime: 0x4fa249ab -- Thu May 3 04:02:35 2012
    mtime: 0x4fa249ab -- Thu May 3 04:02:35 2012
    dtime: 0x4fa249ab -- Thu May 3 04:02:35 2012
    Blocks:
    FS block 7536642 logged at sequence 38398250, journal block 12537
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398253, journal block 12592
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398258, journal block 12711
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398261, journal block 12765
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398266, journal block 12855
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398270, journal block 12913
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398274, journal block 12981
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398276, journal block 13034
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398280, journal block 13190
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398285, journal block 13252
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398287, journal block 13302
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398290, journal block 13355
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398293, journal block 13409
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398298, journal block 13471
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398302, journal block 13604
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398307, journal block 13700
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398311, journal block 13756
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398314, journal block 13809
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398317, journal block 13864
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398320, journal block 13921
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38398325, journal block 13980
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38401277, journal block 23924
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38401314, journal block 24107
    (inode block for inode 7536648):
    Inode: 7536648 Type: bad type Mode: 0000 Flags: 0x0 Generation: 0
    User: 0 Group: 0 Size: 0
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    atime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    mtime: 0x00000000 -- Wed Dec 31 18:00:00 1969
    Blocks:
    FS block 7536642 logged at sequence 38401325, journal block 24146
    (inode block for inode 7536648):
    Inode: 7536648 Type: regular Mode: 0644 Flags: 0x0 Generation: 1050269005
    User: 0 Group: 0 Size: 15
    File ACL: 0 Directory ACL: 0
    Links: 1 Blockcount: 8
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x4fa2c307 -- Thu May 3 12:40:23 2012
    atime: 0x4fa2c307 -- Thu May 3 12:40:23 2012
    mtime: 0x4fa2c307 -- Thu May 3 12:40:23 2012
    Blocks: (0+1): 7559168
    Found sequence 38395723 (not 38401480) at block 24688: end of journal.
    Please note down Blocks: (0+1): 7559168 line. Type the following command to remove data.txt file, enter:
    rm data.txt
    ls data.txt

    Sample outputs:
    ls: cannot access data.txt: No such file or directory
    To recover file, enter:
    # dd if=/dev/mapper/wks01-root of=data.txt bs=4096 count=1 skip=7559168
    Sample outputs:
    1+0 records in
    1+0 records out
    4096 bytes (4.1 kB) copied, 0.010884 seconds, 376 kB/s
    Verify that data is recovered, enter:
    cat data.txt
    Sample outputs:
    This is a test

    Howto: Recover a file when you don't know inode number

    Delete a file called 521.sh:
    rm 521.sh
    Type the following command:
    # debugfs -w /dev/mapper/wks01-root
    At debugfs: prompt type lsdel command:
    debugfs: lsdel
    Sample outputs:
     Inode  Owner  Mode    Size    Blocks   Time deleted
    23601299 0 120777 3 1/ 1 Tue Mar 13 16:17:30 2012
    7536655 0 120777 3 1/ 1 Tue May 1 06:21:22 2012
    2 deleted inodes found.
    Get block data, enter:
    debugfs: logdump -i <7536655>
    Sample outputs:
    Inode 7536655 is at group 230, block 7536642, offset 1792
    Journal starts at block 10875, transaction 38398034
    FS block 7536642 logged at sequence 38398245, journal block 12418
    (inode block for inode 7536655):
    Inode: 7536655 Type: symlink Mode: 0777 Flags: 0x0 Generation: 3532221116
    User: 0 Group: 0 Size: 3
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    atime: 0x4f9fc730 -- Tue May 1 06:21:20 2012
    mtime: 0x4f9fc72f -- Tue May 1 06:21:19 2012
    dtime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    Fast_link_dest: bin
    Blocks: (0+1): 7235938
    FS block 7536642 logged at sequence 38398250, journal block 12537
    (inode block for inode 7536655):
    Inode: 7536655 Type: symlink Mode: 0777 Flags: 0x0 Generation: 3532221116
    User: 0 Group: 0 Size: 3
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    atime: 0x4f9fc730 -- Tue May 1 06:21:20 2012
    mtime: 0x4f9fc72f -- Tue May 1 06:21:19 2012
    dtime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    Fast_link_dest: bin
    Blocks: (0+1): 7235938
    FS block 7536642 logged at sequence 38398253, journal block 12592
    (inode block for inode 7536655):
    Inode: 7536655 Type: symlink Mode: 0777 Flags: 0x0 Generation: 3532221116
    User: 0 Group: 0 Size: 3
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    atime: 0x4f9fc730 -- Tue May 1 06:21:20 2012
    mtime: 0x4f9fc72f -- Tue May 1 06:21:19 2012
    dtime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    Fast_link_dest: bin
    Blocks: (0+1): 7235938
    ...
    ...
    ....
    output truncated
    Fast_link_dest: bin
    Blocks: (0+1): 7235938
    FS block 7536642 logged at sequence 38402086, journal block 26711
    (inode block for inode 7536655):
    Inode: 7536655 Type: symlink Mode: 0777 Flags: 0x0 Generation: 3532221116
    User: 0 Group: 0 Size: 3
    File ACL: 0 Directory ACL: 0
    Links: 0 Blockcount: 0
    Fragment: Address: 0 Number: 0 Size: 0
    ctime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    atime: 0x4f9fc730 -- Tue May 1 06:21:20 2012
    mtime: 0x4f9fc72f -- Tue May 1 06:21:19 2012
    dtime: 0x4f9fc732 -- Tue May 1 06:21:22 2012
    Fast_link_dest: bin
    Blocks: (0+1): 7235938
    No magic number at block 28053: end of journal.
    Type the following command:
    # dd if=/dev/mapper/wks01-root of=recovered.file.001 bs=4096 count=1 skip=7235938
    # file recovered.file.001

    Sample outputs:
    file: ASCII text, with very long lines
    View file, enter:
    # more recovered.file.001

    A note about easy to use tool called photorec

    Now, you know basic hacks for recovering files under ext3 or ext4. However, I strongly recommend that you make backups. It cannot be stressed enough how important it is to make a backup. Another, option is PhotoRec software. It is file data recovery software designed to recover lost files including video, documents and archives from hard disks, CD-ROMs, and lost pictures from digital camera memory. PhotoRec ignores the file system and goes after the underlying data, so it will still work even if your media's file system has been severely damaged or reformatted. PhotoRec is free - this open source multi-platform application is distributed under GNU General Public License (GPLV v2+). PhotoRec is a companion program to TestDisk, an app for recovering lost partitions on a wide variety of file systems and making non-bootable disks bootable again. You can download them from this link. You can install testdisk using the following apt-get command or yum command:
    # yum install testdisk
    OR
    # apt-get install testdisk
    To recover files simply type:
    # photorec
    Stay tuned, for more information on photorec and testdisk data recovery tools. I recommend that you view the manual page on debugfs using the following command for more information:
    $ man debugfs

    Baca Selengkapnya ....

    Making Apache and Tomcat Work Together

    Posted by Unknown 0 komentar
    http://olex.openlogic.com/wazi/2012/making-apache-and-tomcat-work-together


    Last year I was approached by a Swiss customer looking for help. Starting with an already working Tomcat application, the company wanted to configure the Apache HTTP Server in front of it as reverse proxy, virtual host broker, and URI translator.
    Why use Apache as a front-end server? It might seem more convenient to keep things simple, letting a back-end server like Tomcat serve clients directly – and in some cases it is, depending on the type of back-end server and the specific requirements of the project.
    If your main server software is secure and fast enough for your environment and provides all the features you need, you probably don’t need a proxy layer. It usually doesn’t make sense to run Apache in front of lighttpd, for example, especially considering that a layer of proxying increases the performance and maintenance load.
    Yet in a lot of cases you will be running a specialized back-end server to provide functionality that Apache isn’t capable of. You might deploy Tomcat, for example, so you can run Java Servlets. In these cases it is often beneficial to pay the performance and complexity costs of adding Apache to the mix.
    Apache is a secure, flexible, and fast general-purpose HTTP server. It comes with a huge variety of modules that provide functionality for all kinds of special purposes, from LDAP authentication to request compression. Its configuration is straightforward, using the traditional near-flat Unix configuration syntax instead of XML. Specialized back-end servers are usually slower than Apache when it comes to serving static files such as images or office software files.

    Choosing a Communication Protocol

    There are several ways to make Apache and Tomcat talk to each other, of which three are most popular:
    • mod_proxy is the most basic way to make Apache pass on requests to a back-end server and relay back its responses to the client. The latter process is called reverse proxying. It works not only with Tomcat but with every back-end server that supports the HTTP protocol.
    • mod_proxy_ajp – The Apache JServ Protocol (AJP) is a simple binary packet format that offers greater speed compared to plain HTTP(S) back-end communication. mod_proxy_ajp adds support for the AJP protocol to mod_proxy. It is part of Apache’s default distribution.
    • mod_jk is another way to make Apache talk to a Servlet back-end server, and the recommended way to make Apache talk to Tomcat, but
      it is more complex to configure than the other two due to its flexibility. mod_jk is maintained by the Tomcat community.
    Obsolete modules that are no longer maintained and thus not recommended for Apache-Tomcat communication include mod_webapp (also called warp), mod_jserv, and jk2.
    One good way to proceed is to set up everything using mod_proxy first; configuration is simple and all communication is clear-text HTTP. If you need additional speed later, you can add mod_proxy_ajp to the mix within minutes. If you want to take advantage of mod_jk’s performance, stability, and flexibility, you can invest more time to install and configure it properly.

    Basic Setup

    Let’s assume that Tomcat is running on local port 8080, serving our application and accessed directly. Apache is running on port 80 with all modules in the standard distribution available, including mod_proxy and mod_rewrite.
    As long as you stay with standard HTTP proxying using mod_proxy and don’t switch to AJP, any back-end server is fine for initial testing of the
    proxying chain. But at some point you need to switch to your actual Tomcat setup, since it will have its own requirements that you need to cater to using proxying and rewrite rules.
    With that in mind, the basic starting point for our two-way proxying calls for configuration settings that look like this:
    ProxyPass / http://localhost:8080/
    ProxyPassReverse / http://localhost:8080/
    These configuration line examples, and the ones that follow, are snippets that need to go into your Apache’s global server context or virtual host section. The first line above relays all client requests to / and below to a back-end server running on port 8080 using HTTP. The second line provides the same functionality for the reverse direction. Try this first to make sure that everything works as intended on a basic level.

    Path Translation and Exceptions

    Let’s add a common requirement. We’re still going to serve our application to the client at the top level /, but the corresponding
    back-end path will be /application/. Servlet applications running under Tomcat are often set up in this way to provide multiple applications in one
    server instance. Our setup now looks like this:
    ProxyPass / http://localhost:8080/application/
    ProxyPassReverse / http://localhost:8080/application/
    This seemingly small change has larger implications than it might seem at first glance, because your back-end application is not aware of this translation and still hands out its usual paths. In some cases the application can be adjusted to match the new paths; often this isn’t possible, or changing all paths in CSS and JS files would be too cumbersome and error-prone.
    In this case we need to find all the spots that need additional proxying rules. Broken images or CSS files show up plainly enough, and Firebug or similar tools can help you spot broken script files. Other issues may come up when AJAX requests are made to a non-existent location, so it’s important to do a lot of testing and verification.
    For each spot that needs additional proxying rules you can either add a rule for mod_rewrite to rewrite it or add mod_proxy directives. In our particular project we decided to use the latter approach to keep special proxy mappings apart from other rewrite rules.
    Let’s presume that our back-end application refers to some static image files served by a second application running in Tomcat at the location /application2/images/, and another set of static JavaScript files at /application2/js/. We don’t want to expose the whole tree under /application2/ for security reasons, so we use tighter mappings as follows:
    ProxyPass /application2/images http://localhost:8080/application2/images
    ProxyPassReverse /application2/images http://localhost:8080/application2/images
    ProxyPass /application2/js http://localhost:8080/application2/js
    ProxyPassReverse /application2/js http://localhost:8080/application2/js
    The first matching proxying rule terminates the mod_proxy decision process, so we have to add those special case lines in front of the previous directive block.
    Proxying exceptions provide another way to influence the proxy decision process. Suppose that our Apache instance serves a couple of static PDFs at /productpresentation/; we don’t need or want to relay those requests to Tomcat. A special form of the ProxyPass directive lets us specify locations that must not be proxied:
    ProxyPass /productpresentation !
    Again, this needs to go in front of our other rules.

    Cookie Support

    Chances are that your application uses cookies to track client sessions across requests. Cookies include a hostname and a path to let the client know when to send the cookie back as part of a request. Due to our path rewrites, however, the cookie paths are no longer valid and need to be rewritten as well. Your application may act in funny ways, such as keeping you stuck on one page, if its cookies are not being sent back, especially if user login tracking is involved.
    You can determine the cookies sent by your back-end application in a variety of ways; browser inspection tools or cookie-specific extensions let you see them, but a cURL request will do fine as well.
    The cookie path is set by the application. Once more we might not be able to change the back-end application’s behavior, but mod_proxy can be instructed to rewrite these paths as well so the client will send the cookie later as desired:
    ProxyPassReverseCookiePath /application/ /
    The first argument is a match specification for a cookie path that has to be rewritten. The second argument specifies what the result needs to look like after rewriting.
    You might also have issues with the cookie domain. A similar directive exists to adjust this, called ProxyPassReverseCookieDomain. Suppose your Apache instance takes requests for virtual host publicvhost.com, but your backend application thinks its hostname is backendhostname.local. The syntax would be:
    ProxyPassReverseCookieDomain publicvhost.com backendhostname.local

    Error Handling

    Another common requirement is a unified look among error pages that doesn’t give away the back-end server software’s name and version. To accomplish this we use the ProxyErrorOverride directive, telling Apache to let its own error-handling mechanism take over:
    ProxyErrorOverride Off
    With this directive we can use the full range of error handling directives. A most basic example for quick testing:
    ErrorDocument 404 "Nothing here!"

    Enter mod_rewrite

    We used a couple of mod_rewrite rules in the project I was working on. Those rules tend to be highly project-specific, so we won’t go through all of them. The most important thing to know is how mod_rewrite interacts with Tomcat proxying.
    From the detailed flow diagram of Apache rewrite processing you can see that rewrite rules are applied early in the request handling process. Contrary to the order of proxying or rewrite rules among themselves, it doesn’t matter where we place the proxying and rewrite blocks in relation to each other.
    Let’s say we have a rewrite map generated by some other process that needs to be applied. We can implement this using the following rewrite directive block anywhere in the section where our proxying rules reside:
       RewriteEngine On
    RewriteMap lcmap int:tolower
    RewriteMap shorturls txt:/var/www/rewrite_map.txt
    RewriteRule ^/([^/]+)$ ${shorturls:/$1} [R,L]
    What we discussed here barely scratches the surface of what you can do with Apache as a reverse proxy for Tomcat, but we did cover the most important building blocks to start with, which may save you precious hours of initial setup. Once you have this setup running, you can spend more time on the gritty bits of your project-specific setup, such as load balancing or complex address rewriting and redirection.

    Baca Selengkapnya ....

    6 Best Free Linux Benchmark Tools

    Posted by Unknown Minggu, 06 Mei 2012 0 komentar
    http://www.linuxlinks.com/article/2012042806090428/BenchmarkTools.html

    A benchmark is the act of running computer programs in order to assess the performance of computer hardware and software applications. Hardware benchmarking assesses many different attributes such as the performance of the processor, memory, graphics card, hard disk, and the network. There are two different types of benchmarks: synthetic and application. Synthetic benchmark stress a component, such as continuously writing and reading data. Application benchmarks measure the performance of real-world applications, such as databases and servers.
    The use of benchmark software enables system testers and users to obtain an objective and independent way of assessing the performance of hardware. By making changes to the system, users can determine whether there has been an improvement in the performance of that hardware. The results from benchmark software can help make important decisions about any necessary changes to the hardware to identify any bottlenecks in the system. However, it should be borne in mind that benchmarks are not always precise and can be open to manipulation by hardware developers who can design hardware to do particularly well in specific tests which are not replicated generally.
    There is a wide range of Linux benchmarking tools that are released under an open source license. To provide an insight into the quality of software that is available, we have compiled a list of 6 proficient benchmarking tools. Hopefully, there will be something here to help users fine tune their system and network, and make sensible comparisons.


    A particularly useful website for accessing benchmark results is OpenBenchmarking.org. It provides a collaborative, open test platform with a standardized test profile and suite management system for distributing and standardising benchmarks.
    Now, let's explore the 6 benchmark tools at hand. For each title we have compiled its own portal page, a full description with an in-depth analysis of its features, a screenshot of the software in action, together with links to relevant resources and reviews.
    Benchmark Tools
    Phoronix Test Suite Comprehensive testing and benchmarking platform
    IOzone Filesystem benchmark tool that measures a wide variety of file operations
    netperf A network performance benchmark
    LLCbench Low Level Architectural Characterization Benchmark Suite
    HardInfo System Profiler and Benchmark
    GtkPerf GTK+ performance benchmark

    Baca Selengkapnya ....

    Tips for Writing Safe, Secure PHP Code

    Posted by Unknown Kamis, 03 Mei 2012 0 komentar
    http://olex.openlogic.com/wazi/2012/tips-for-writing-safe-secure-php-code


    PHP has established itself as a cornerstone of web development, and powers popular platforms such as WordPress and Joomla. However, because today’s Internet is rife with hackers searching for weaknesses in web applications’ security, PHP programmers must code defensively and guard against potentially destructive errors.
    Before embarking on a discussion on how to code with a security mindset, consider some of the common techniques hackers use to try and breach a website.
    One of the most common forms of attack is SQL injection. Many websites rely on a database to store information for the site and for user authentication. An injection attack tries to modify SQL code that is sent to the database in order to manipulate the site or circumvent user authentication. It works through HTML forms, in which data is entered by users, or in this case by an attacker.
    For example, a programmer might use the following PHP statement when trying to authenticate a user:
    $auth = mysql_query("SELECT username, password  FROM users WHERE username = '" . $_POST['username'] . "' and password = '" . md5($_POST['password']) . "'");
    The danger here is that the input entered by the user is directly used in the SQL statement without any validation or checking.
    If an attacker were to enter, for example, ' OR 1=1 # for the username, the SQL statement would be transformed into:
    SELECT username, password  FROM users WHERE username = '' OR 1=1 # and password = '286755fad04869ca523320acce0dc6a4';
    Everything after the # is ignored, and 1=1 is always true, so the hacker would trick the code into thinking the user is authenticated.
    Similar to SQL injection, cross-site scripting (XSS) attempts to inject JavaScript code into a web page and use that code to load more code from an unrelated site (hence the term cross-site). If he’s successful, the hacker can run his own code in the victim’s browser, which lets him launch more complex attacks and even infect the victim’s computer with malware.
    A simple example of XSS might target users when they register for a site. At that time users can enter information into form fields, including their name, which is often displayed on the user’s profile page as simple HTML. Suppose a hacker tried to use the following code for a username:
    By entering the



    Replacing the call to alert() with code to download a complex JavaScript from another site (e.g.

    Baca Selengkapnya ....

    Learn Linux/Unix Find command with 60+ Practical examples

    Posted by Unknown Rabu, 02 Mei 2012 0 komentar
    http://www.linuxnix.com/2012/04/learn-linuxunix-find-command-50-practical-examples-part-i.html


    find command is very much powerful command which can do good work when its needed to find files with conditions. Find command  is useful when finding files with complex requirement such as size, permissions etc. Suppose we want to find a file which is a regular file and its size is more than 1GB and its accessed more than 90 days back and its owner is none and then delete it. This entire requirement is done with single command without even writing a shell script. Let’s see how we can use find command from basics to advanced in this post.
    find command can find files according to
    1) File names

    2) File types

    3) Permissions

    4) Owners

    5) Modified date and time

    6) Size
    Advanced finds command usages
    1) Mix of all the above things
    2) AND operator
    3) Search for files and execute commands on them
               a) chown, chmod, grep, ls, rm, mv, cp,md5sum

    4) Multiple execute commands

    5) Search for multiple files
                a) With different files with same extension
                b) Same file With different extensions
    6) Search in multiple locations
                a) Exclude one location
                b) Search in multiple locations
            
    7) OR( –o ) operator
     8) ! Negation operator
    9) Linux find command with Regular Expressions
    10) Linux find commnd practical examples

    Basics of file/folders search using find command

     find files with name

    Syntax:
    find path options filename
    Example1: find all the files in /home with name test.txt. Here –name is used to specify the filename.
    find /home –name test.txt
    Example2: find the files whose name is test.txt and in present working directory
    find . –name test.txt
    Or
    find –name test.txt
    Example3: find all the files whose name contains both capital letters and small letters in it.
    find /home –iname test.txt
    -iname option is used to mention ignore the case sensitivity of a file.
    Search for files depending on their File types:
    Example4: Search for only directories whose name is var in / directory
    find / -type d –name var
    Example5: Search for an mp3 files whose name is temp.mp3
    find / -type f –name temp.mp3
    Below are the file types supported by find command, to know more about file types in Linux/Unix please have a look at our other post on File types.
    Sl.noSymbolType
    1fRegular file
    2dDirectory file
    3bBlock file
    4cCharacter file
    5pPipe file
    6lSymbolic link file
    7sSocket file.

    Search for files depending on their Permissions

    Example6:Search for a file name test.txt and its permissions are 775 in a given box
    find / -perm 775 –name test.txt
    Example7: How about searcing files with SUID bit set and file permissions are 755?
    find / -perm 4755
    Example8:How can i find SGID bit set files with 644 permissions?
    find / -perm 2644
    Example9: How can i find Sticky bit set files in my system with permissions 551?
    find / -perm 1551
    Example10:Search for all the files whose SUID bit is set
    find / -perm /u=s
    Example11: Search for all the files whose SGID bit is set
    find / -perm /g+s
    Note: We can use = or + interchangeably to check if a permissions is set or not as shown in above two examples.
    Example12: Search for all the files  whose StickyBit is set
    find / -perm /o=t
    Example13: Search for all the files whose owener permissions is read only.
    find / -perm /u=r
    Example14:Search for all the files which have user, group and others with executable permissions
    find / -perm /a=x
    To know about more on the permissions you have look at our other posts on chmod command.

    Search according to Owners and group owners.

    Example15: Search for all the files with name test.txt and the owner of this file is Surendra
    find / -user Surendra –name test.txt
    Example16: find all the files whos name is test.txt and owned by a group called redcluster
    find / -group redcluster –name test.txt
    to know more about owners and groups you have to look at our previous post on chown command.

    Search according to Modified date and time.

    Below is the matrix which give you brief idea on how to search according to modified date, accessed date etc.
    Sl. No-ctime-mtime-atime
    +90File status changed more then 90 days backModified more than 90 days backAccessed more than 90 days back
    90File status changed exactly 90 days backModified exactly 90 days backAccessed exactly 90 days back
    -90File status changed less than 90 daysModified less than 90 daysAccessed less than 90 days back
    Example17: Search for a file: test.txt whose file status is changed more than 90 days back
    find / -ctime +90 –name test.txt
    Example18: Search for all the files which are modified exactly 90 days back
    find / -mtime 90
    Example19: Search for all the files with name test.txt which is accessed less than 90 days
    find / -atime -90
    Example20: find all the files which are modified more than 90 days back and less than 180 days
    find / -mtime +90 –mtime -180
    Below is the matrix which gives you brief idea on how to search according to modified time, accessed time in minutes etc.
    Sl. No-cmin-mmin-amin
    +30File status changed more then 30 mins backModified more than 30 mins backAccessed more than 30 mins back
    30File status changed exactly 30 mins backModified exactly 30 days backAccessed exactly 30 mins back
    -30File status changed less than 30 minsModified less than 30 minsAccessed less than 30 mins

    Example21: find all the files changed less than 30mins
    find / -cmin -30
    Example22: find all the files modified exactly 30 mins back
    find / -mmin 30
    Example23: find all the files accessed more than 30 mins back
    find / -amin +30
    Example24: find all the files which are modified more than 5mins back and less than 25mins
    find / -mmin +5 –mmin -25
    Example25: I have new file called test.txt which is just created, now I want to get all the files which are created later this file creation.
    find / -newer test.txt

    Search for files/folders depending on the size with –size option

    Sl.no+1010-10
    c for bytes(8 bits)Search for files more than 10c sizeSearch for files exactly 10b sizeSearch for files less than 10b size
    k for kilobytesSearch for files more than 10k sizeSearch for files exactly 10k sizeSearch for files less than 10k size
    M for MegabytesSearch for files more than 10M sizeSearch for files exactly 10M sizeSearch for files less than 10M size
    G for GigabytesSearch for files more than 10G sizeSearch for files exactly 10G sizeSearch for files less than 10G size

    Example26: Search for files whose size is more than 10bytes
    find / -size +10c
    Example27: Search for files which are exactly 10kb in /opt folder
    find /opt –size 10k
    Example28: Search for files which are less than 10MB in /var folder
    find /var –size -10M
    Example29: Search for files which are more than 1GB size in /usr folder
    find /usr –size +1G
    Example30: find all the empty files in my system
    find / -size 0k
    Example31:find all the files which are with more 
    than size 100MB and less than 1GB and the owner of the file is xyz and
    the file name is Adda.txt in /red folder


    find /red –size +100M –size -1G –user xyz –iname adda.txt
    Example32:find all the files with SGID for the group sales and with size exactly 100MB with file name as pass.txt under /opt
    find /opt –size 100M –group sales –perm g+s –name pass.txt

    Linux find command AND Operator

    By default find command will use AND option between two options. No need of mentioning any option. For example see below examples.
    Example33: find all the files which are more than 100MB and less than 1GB in size.
    find / -size +100M –size -1G
    or
    find / -size +100M -a -size -1G
    Like above we can combine many options and your find command use AND operator by default no need of mentioning -a option.

    Search for files and execute commands on Found files

    Caution: Be careful when using -exec option which you are going to learn below. This is very dangerous option which can change/remove anything if don’t use wisely. There are some instances when you want to execute commands on the found files with find command. -exec is the option used in find command to execute shell commands directly on found files. Let’s discuss this with a basic example.
    Example34:find a file with passwd.txt in /var folder and long list this file for checking file properties.
    find /var –iname passwd.txt –exec ls –l {} \;
    Let me explain above command. Up to find /var –iname passwd.txt, this command you are aware. This command will search for passwd.txt file in /var folder and give the paths and file names where this file is located.
    -exec: with this option we are saying to find command to execute a command(here its ls -l) followed by this option
    {} –This is used as input to the command which we get as files/folders from find command output.
    \; –This indicates that find command is completed.
    Actually ; is a command chaining capability and it’s a special character. In order to negate this special character we are using \ before;.
    Example35: Find all the files with name test.txt in /mnt and change the ownership of the files from Surendra to Narendra
    find /mnt –user surendra –name test.txt –exec chown narendra: {} \;
    -exec command {} \; –for executing a command on find files -inum -For finding a file with inode number
    Example36:Find all the files with name test.sh in /abc folder and then grep if for word is there in that file or not
    find /abc –name test.sh –exec grep ‘for’ {} \;
    chmod, grep, ls, rm, mv, cp,md5sum
    Example37: Find all the files with name xyz.txt owned by Surendra in /var/ftp/pub and change the permissions to 775 to them.
    find /var/ftp –user surendra –name xyz.txt –exec chmod 775 {} \;
    Example 38:Find all the files with name temp.txt in /xyz folder and backup then compress them to send it for saving
    Find /xyz –name xyz.txt –exec tar xvfz temp.tar.gz {} \;
    Example39:Find files with name abc.txt in /home directory and take backup of each file before modifying it.
    find /home –name abc.txt –exec cp {} {}.bkf \;
    This above command will create files with .bkf extension whenever it finds abc.txt file.
    Example40:Find files which are more than 1GB and not accessed for the past 6 months and delete them.
    find / -size +1G -mtime +180 –exec rm –rf {} \;
    Example41:Find all the files with executable permissions and display their checksum value
    find / -perm /a=x -exec md5sum {} \;
    Example42:find all the files with name abc.txt and owner as surendra then move them to /opt folder
    find / -user surendra -name abc.txt -exec mv {} /opt/ \;
    There are many other commands you can try your own. Some other commands which can work with –exec option is mv, md5sum etc.

    Find command with multiple -exec option

    Find command is capable of using multiple times using the same option(We seen it for finding files which are more than 200M and less then 1GB). In our previous examples we used –size to mention the size between two sizes. Similarly we can use –exec command multiple times.
    Example43:Find files with abc.txt name in /opt directory change the owner permissions from Surendra to Narendra and change the permissions to 775
    find /opt –user Surendra –name abc.txt –exec chown Narendra: {} \; -exec chmod 775 {} \;
    Note: We can use this multiple –exec option more than two times.

    Search for multiple files

    Till this point if you observe we just search for single file. But sometimes there is a requirement to search for multiple files with single find command to save some valuable time. The following two examples we will see how to do that. Example44: Find all the commands which ends with .sh file extension in /opt folder
    find /opt –name *.sh
    Note: Sometimes the above command will not work properly because your shell will try to parse the * before find command is executed. So you have made * as not a special character or wild character. In order to understand more about this type of characters you have to learn RegExp. Please find our other posts on Basic RegExp and Advanced RegExp.
    Example45:
    find /opt –name \*.sh
    Or
    find /opt –name “*.sh”
    Note: These two will work, because you negated your shell parsing * wild character.
    Example46:Search for all the files which start with abc and ends with different extension in /opt folder
    find /opt –name abc.\*
    Example47:Search for files which start with red and ends with many names such as redhat, redtop, redsoap etc.
    find / -name red\*
    Example 48:How about search for files which always end with dump.
    find / -name \*dump

    Search for files in multiple locations

    Search multiple locations using single find command We can accomplish searching multiple folders with single command without any options. Lets see below command.
    Example49: Find abc.txt file in /opt and /var folder at a time
    find /opt /var –name abc.txt
    The above command will search in only two locations i.e. in /opt and /var Search multiple locations but not in particular location. Example50:Search in entire system expect /proc folder
    find / -path /proc -prune -name cpuinfo
    Let me explain above command. The -path variable to define the path of a location. And -prune combined with -path will say not to descend in to the mention path /proc
    Example51:Search for abc.txt in /opt and /var expect in /var/tmp folder
    find /opt /var -path /var/tmp -prune -name abc.txt

    Find command OR –o operator

    Find have OR operator to do multiple file searches at a time.
    Example52:I want to search for abc.txt and hash.c file at a time. This can be achieved by using -o operator
    find / -name abc.txt -o -name hash.c
    Here when ever find command sees -o it just or the options on its left and right hand side.
    Example53:How about i want to find two directories say opt and var how can i find them?
    find / -type d - name opt -o -type d -name var 
    This above command may trow error. Try below syntax
    find / -type d \( -name opt -o -name var \)
    let me explain above command. () are used to combine two or more options in to one. So \( -name opt -o -name var \) are combined in to single option and are treated as directories as we given -type is d. We will see more about this operator in our coming post on find command advanced usage.

    Linux find command ! Negation operator

    Example54: Negation operator is useful for negating a search team. for example we want to find all the files with name abc.txt which don’t have 755 permissions
    find . -type f ! -perm 755 -name abc.txt
    In above command -perm 755 is negated so that all the files with name abc.txt is displayed expect file abc.txt with permissions 755.
    Stay tuned our next tutorial on find command to do following things
    1)Dont search in .cvs folder
    2)Search for files with out owner
    3)Search for zero size files
    4)Search for files and don’t show me permission denied error
    5)Searching in hidden folders
    6)Creating alias for frequently used find commands
    7)Search for files with spaces
    8)Search for files and grep for multiple pattern in one find command.
    9) Miscellaneous examples

    Baca Selengkapnya ....
    Trik SEO Terbaru support Online Shop Baju Wanita - Original design by Bamz | Copyright of android japan.