<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-20127583</id><updated>2012-05-27T02:43:52.867+07:00</updated><category term='linux'/><category term='apache'/><category term='mail'/><category term='carijejak'/><category term='proxy'/><category term='mysql'/><category term='web'/><category term='php'/><category term='security'/><category term='device'/><category term='NMS'/><category term='pf'/><category term='GD'/><category term='file share'/><category term='life'/><category term='www'/><category term='cisco'/><category term='mrtg'/><category term='pengenalan'/><category term='dns'/><category term='tembokgeni'/><category term='wireless'/><category term='FTP'/><category term='tips'/><category term='debian'/><category term='script'/><category term='samba'/><category term='instalasi'/><category term='snmp'/><category term='freebsd'/><category term='satpam'/><category term='port'/><category term='radius'/><category term='update'/><category term='hardware'/><category term='utility'/><category term='database'/><title type='text'>My Blog</title><subtitle type='html'>dicatat dibagi semoga bermanfaat</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><link rel='next' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default?start-index=26&amp;max-results=25'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>113</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>25</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-20127583.post-1629906042149009235</id><published>2012-04-24T14:27:00.000+07:00</published><updated>2012-04-24T14:41:38.138+07:00</updated><title type='text'>instalasi dan sinkronisasi file menggunakan rsync dan ssh</title><content type='html'>Tulisan ini sekaligus update tulisan lama saya. Yang sepertinya kurang lengkap :) Disini misal ada 2 Server 10.10.10.14(server) dan 10.10.10.16(backup/mirror). Dan port ssh 22  Langkah2nya sbb :  1. Masuk ke /home di 10.10.10.16 (server backup) Di directory /home inilah nanti file authentifikasi akan disimpan. Dan perintah rsync dijalankan. 2. Ketik ssh-keygen -f loginku -t rsa dan tekan enter. Pada pilihan passwd langsung tekan enter 2x. Dan akan ada 2 file loginku dan loginku.pub 3. Copykan file loginku.pub ke /root/.ssh pada server utama (10.10.10.14) dan rename menjadi authorized_keys2. hasilnya sbb /root/.ssh/authorized_keys2 4. Sekarang coba login dari server backup masuk ke /home dan ketik : ssh -i loginku root@10.10.7.14 -p 22  Jika berhasil maka tanpa passwd harusnya login bisa dilakukan tanpa password.  5. Perintah rsync sbb :  /usr/local/bin/rsync -e "ssh -i loginku -l root -p 22" -avz root@10.10.10.14:/home/coba /home/coba  sent 188 bytes  received 35168 bytes  70712.00 bytes/sec total size is 42515051  speedup is 1202.48  Nah ada satu tips lagi agar lebih secure. Yaitu hanya mengijinkan root untuk login dari ip 10.10.10.16 (server backup saja). Caranya sbb :  1. Tambahkan baris berikut pada /etc/security/access.conf -:root:ALL EXCEPT 10.10.7.16 Perintah diatas adalah mengijinkan semua user untuk login dr ip manapun kecuali untuk root harus login dari 10.10.7.16 2. Tambahkan baris berikut pada /etc/pam.d/sshd account required pam_access.so&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-1629906042149009235?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/1629906042149009235/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=1629906042149009235' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/1629906042149009235'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/1629906042149009235'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2012/04/instalasi-dan-sinkronisasi-file.html' title='instalasi dan sinkronisasi file menggunakan rsync dan ssh'/><author><name>Run</name><uri>http://www.blogger.com/profile/17015113499951735876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-914510737858888537</id><published>2012-04-21T11:24:00.002+07:00</published><updated>2012-04-21T11:24:40.155+07:00</updated><title type='text'>Installasi NFS server di SLES</title><content type='html'>Instalasi NFS server di SLES 11 SP 1  Jika dari yast : # yast2 # pilih network service # pilih NFS # Setting directory, IP NFS client # Finish  Jika dari Zypper   # zypper install -y nfs-kernel-server # nano /etc/exports /home 10.10.7.1(rw,sync,no_root_squash) atau bisa juga /home/www       10.10.7.1 10.10.7.22 10.10.7.23 *(fsid=0,crossmnt,ro,root_squash,sync,no_subtree_check)  Start daemon # /etc/init.d/rpcbind start # /etc/init.d/nfsserver start  Edit startup # chkconfig rpcbind on # chkconfig nfsserver on&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-914510737858888537?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/914510737858888537/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=914510737858888537' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/914510737858888537'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/914510737858888537'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2012/04/installasi-nfs-server-di-sles.html' title='Installasi NFS server di SLES'/><author><name>Run</name><uri>http://www.blogger.com/profile/17015113499951735876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-3463784692160410664</id><published>2011-12-15T11:39:00.002+07:00</published><updated>2011-12-15T11:43:33.212+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='www'/><category scheme='http://www.blogger.com/atom/ns#' term='port'/><category scheme='http://www.blogger.com/atom/ns#' term='apache'/><title type='text'>Apache22 Port di FreeBSD 8.2 Stable</title><content type='html'>Kemarin setelah update ke FreeBSD stable 8.2 dan CVsup  it coz me trouble.&lt;br /&gt;In da middle on installation i got&lt;br /&gt;&lt;br /&gt;/usr/ports/www/apache22/work/httpd-2.2.16/support/htpasswd.c:133: undefined reference to `apr_generate_random_bytes'&lt;br /&gt;*** Error code 1&lt;br /&gt;1 error&lt;br /&gt;&lt;br /&gt;it made me frustated, after a day search and following instruction from freebsd forum i got nothing. so i assume that maybe something wrong with the port and i have to fix it. &lt;br /&gt;&lt;br /&gt;Here is the solution i've found from the inet to fix a broken port.&lt;br /&gt;It works for me .. :)&lt;br /&gt;&lt;br /&gt;# Change into the ports directory&lt;br /&gt;cd /usr/ports/&lt;br /&gt;# First fetch ports index&lt;br /&gt;make fetchindex&lt;br /&gt;# Build the ports database&lt;br /&gt;portsdb -u&lt;br /&gt;# Show out of date ports&lt;br /&gt;pkg_version -l "&amp;lt;"&lt;br /&gt;# Upgrade ports&lt;br /&gt;portupgrade -arR&lt;br /&gt;# Check for stale dependencies&lt;br /&gt;pkgdb -F&lt;br /&gt;# Clean out work directories and delete old distfiles&lt;br /&gt;portsclean -CDD                                 _________________&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-3463784692160410664?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/3463784692160410664/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=3463784692160410664' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/3463784692160410664'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/3463784692160410664'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/12/apache22-port-di-freebsd-82-stable.html' title='Apache22 Port di FreeBSD 8.2 Stable'/><author><name>Run</name><uri>http://www.blogger.com/profile/17015113499951735876</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-2963869949815210623</id><published>2011-11-08T10:48:00.003+07:00</published><updated>2011-11-08T10:52:57.209+07:00</updated><title type='text'>Next...</title><content type='html'>Ternyata banyak sekali aplikasi di OS yg kupake ini yg sangat berguna&lt;br /&gt;tapi aku belum tahu, dan sekarang sudah tahu tambah bingung..&lt;br /&gt;mau yg mana duluan..&lt;br /&gt;baru coba ngoprek openLDAP kok malah macet..&lt;br /&gt;hikss...&lt;br /&gt;&lt;br /&gt;belum lagi HAST untuk clustering storage..&lt;br /&gt;uCARP untuk balancingnya..&lt;br /&gt;Wow..&lt;br /&gt;Wow..&lt;br /&gt;Wowowowow...&lt;br /&gt;Speechless...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-2963869949815210623?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/2963869949815210623/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=2963869949815210623' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2963869949815210623'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2963869949815210623'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/11/next.html' title='Next...'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-5441736273612714775</id><published>2011-11-04T11:12:00.003+07:00</published><updated>2011-11-08T10:51:43.099+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>mengaktifkan log pada mysql</title><content type='html'>Buat directory log mysql, misal&lt;br /&gt;mkdir /var/log/mysql&lt;br /&gt;chown mysql:mysql /var/log/mysql&lt;br /&gt;&lt;br /&gt;Tambahkan baris berikut pada config file mysql my.cnf&lt;br /&gt;&lt;br /&gt;[mysqld_safe]&lt;br /&gt;log-error=/var/log/mysql/error.log&lt;br /&gt;&lt;br /&gt;# The MySQL server&lt;br /&gt;[mysqld]&lt;br /&gt;log-error=/var/log/mysql/error.log&lt;br /&gt;&lt;br /&gt;restart mysql&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-5441736273612714775?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/5441736273612714775/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=5441736273612714775' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/5441736273612714775'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/5441736273612714775'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/11/mengaktifkan-log-pada-mysql.html' title='mengaktifkan log pada mysql'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-6748655175683297577</id><published>2011-07-02T13:07:00.001+07:00</published><updated>2011-07-02T13:07:47.678+07:00</updated><title type='text'>Instalasi dan Konfigurasi SYSLOG-NG dengan database MYSQL.</title><content type='html'>SYSLOG-NG adalah daemon yang bisa digunakan untuk menggantikan syslogd di FreeBSD atau di Linux yang berfungsi untuk merekam log2 yang ada, baik itu server berbasis linux, bsd ataupun mikrotik ;)&lt;br /&gt;Dengan SYSLOG-NG yang digabung dengan database MySQL maka kita bisa menyimpan semua log secara terpusat dalam satu database, sehingga mudah untuk di manage.&lt;br /&gt;&lt;br /&gt;Untuk Web Interface tampilan log saya memakai php-syslog-ng yg bisa di download di http://php-syslog-ng.googlecode.com/files/php-syslog-ng-2.9.8.tgz&lt;br /&gt;Syaratnya server anda sudah ada webserver support php&lt;br /&gt;&lt;br /&gt;# cd /usr/local/www&lt;br /&gt;# fetch http://php-syslog-ng.googlecode.com/files/php-syslog-ng-2.9.8.tgz&lt;br /&gt;# tar -xzvf php-syslog-ng-2.9.8.tgz&lt;br /&gt;# chown -R www:www php-syslog-ng&lt;br /&gt;# edit httpd.conf &lt;br /&gt;Alias /log "/usr/local/www/php-syslog-ng/html/"&lt;br /&gt;&lt;Directory "/usr/local/www/php-syslog-ng/html/"&gt;&lt;br /&gt;    Options None&lt;br /&gt;    AllowOverride None&lt;br /&gt;    Order allow,deny&lt;br /&gt;    Allow from all&lt;br /&gt;&lt;/Directory&gt;&lt;br /&gt;&lt;br /&gt;Jika sudah selesai langsung restart webserver dan akses http://ipserver/log&lt;br /&gt;Akan muncul menu instalasi php-syslog, pastikan fitur2 PHP dan file web sudah sesuai (tidak ada warning) klik next, centang konfirmasi, next.&lt;br /&gt;Isikan user root dan password mysql, nama database yang akan digunakan untuk menyimpan log, dan user untuk database dan password (user dan password ini diingat2 yah, karena untuk &lt;br /&gt;konfigurasi syslog servernya), &lt;br /&gt;Misalkan disini &lt;br /&gt;user mysql : syslog&lt;br /&gt;pass mysql : 123abc&lt;br /&gt;nama db : syslogserv&lt;br /&gt;&lt;br /&gt;Hilangkan centang dimenu bawah, klik next. next akan muncul :&lt;br /&gt;&lt;br /&gt;URL   : http://ipserver/log&lt;br /&gt;site    : log/ (ingat belakang harus ada backslash)&lt;br /&gt;email : abc@aaaa.com&lt;br /&gt;passwd : syslogadmin&lt;br /&gt;&lt;br /&gt;Klik next, akan muncul user : admin passwd: syslogadmin&lt;br /&gt;&lt;br /&gt;Selesaaiiii.. hehe untuk web interface sama database doang hehe..&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Selanjutnya install via port :&lt;br /&gt;# cd /usr/ports/sysutils/syslog-ng&lt;br /&gt;# make install clean&lt;br /&gt;# cd /usr/local/etc/syslog-ng/&lt;br /&gt;# cp syslog-ng.conf.sample syslog-ng.conf&lt;br /&gt;&lt;code&gt;&lt;br /&gt;options { long_hostnames(off); &lt;br /&gt;   sync(0);&lt;br /&gt;   use_dns(yes);&lt;br /&gt;   use_fqdn(no); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# sources&lt;br /&gt;#&lt;br /&gt;source src { unix-dgram("/var/run/log");&lt;br /&gt;             unix-dgram("/var/run/logpriv" perm(0600));&lt;br /&gt;             internal(); file("/dev/klog"); };&lt;br /&gt;&lt;br /&gt;source netsrc { udp(ip("0.0.0.0") port(514));&lt;br /&gt;                tcp(ip("0.0.0.0") port(514)); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# destinations&lt;br /&gt;#&lt;br /&gt;destination messages { file("/var/log/messages"); };&lt;br /&gt;destination security { file("/var/log/security"); };&lt;br /&gt;destination authlog { file("/var/log/auth.log"); };&lt;br /&gt;destination maillog { file("/var/log/maillog"); };&lt;br /&gt;destination lpd-errs { file("/var/log/lpd-errs"); };&lt;br /&gt;destination xferlog { file("/var/log/xferlog"); };&lt;br /&gt;destination cron { file("/var/log/cron"); };&lt;br /&gt;destination debuglog { file("/var/log/debug.log"); };&lt;br /&gt;destination consolelog { file("/var/log/console.log"); };&lt;br /&gt;destination all { file("/var/log/all.log"); };&lt;br /&gt;destination newscrit { file("/var/log/news/news.crit"); };&lt;br /&gt;destination newserr { file("/var/log/news/news.err"); };&lt;br /&gt;destination newsnotice { file("/var/log/news/news.notice"); };&lt;br /&gt;destination slip { file("/var/log/slip.log"); };&lt;br /&gt;destination ppp { file("/var/log/ppp.log"); };&lt;br /&gt;destination console { file("/dev/console"); };&lt;br /&gt;destination allusers { usertty("*"); };&lt;br /&gt;#destination loghost { udp("loghost" port(514)); };&lt;br /&gt;# CISCO Destinations...&lt;br /&gt;destination netlog { file("/var/log/network/$HOST/$YEAR$MONTH$DAY.log" owner(root) group(wheel) perm(0644) create_dirs(yes)); };&lt;br /&gt;&lt;br /&gt;destination netsql&lt;br /&gt;                {&lt;br /&gt;                program("/usr/local/bin/mysql --user=syslog --password=123abc syslogserv &lt; /var/log/mysql.pipe");&lt;br /&gt;                pipe ("/var/log/mysql.pipe"&lt;br /&gt;                template ("INSERT INTO syslogserv.logs (host, facility, priority, level, tag, datetime, program, msg) VALUES ('$HOST', '$FACILITY', '$PRIORITY', '$LEVEL', '$TAG', '$ISODATE', '$PROGRAM', '$MESSAGE' );\n")&lt;br /&gt;                template_escape(yes));&lt;br /&gt;                };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# log facility filters&lt;br /&gt;#&lt;br /&gt;filter f_auth { facility(auth); };&lt;br /&gt;filter f_authpriv { facility(authpriv); };&lt;br /&gt;filter f_not_authpriv { not facility(authpriv); };&lt;br /&gt;filter f_console { facility(console); };&lt;br /&gt;filter f_cron { facility(cron); };&lt;br /&gt;filter f_daemon { facility(daemon); };&lt;br /&gt;filter f_ftp { facility(ftp); };&lt;br /&gt;filter f_kern { facility(kern); };&lt;br /&gt;filter f_lpr { facility(lpr); };&lt;br /&gt;filter f_mail { facility(mail); };&lt;br /&gt;filter f_news { facility(news); };&lt;br /&gt;filter f_security { facility(security); };&lt;br /&gt;filter f_user { facility(user); };&lt;br /&gt;filter f_uucp { facility(uucp); };&lt;br /&gt;filter f_local0 { facility(local0); };&lt;br /&gt;filter f_local1 { facility(local1); };&lt;br /&gt;filter f_local2 { facility(local2); };&lt;br /&gt;filter f_local3 { facility(local3); };&lt;br /&gt;filter f_local4 { facility(local4); };&lt;br /&gt;filter f_local5 { facility(local5); };&lt;br /&gt;filter f_local6 { facility(local6); };&lt;br /&gt;filter f_local7 { facility(local7); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# log level filters&lt;br /&gt;#&lt;br /&gt;filter f_emerg { level(emerg); };&lt;br /&gt;filter f_alert { level(alert..emerg); };&lt;br /&gt;filter f_crit { level(crit..emerg); };&lt;br /&gt;filter f_err { level(err..emerg); };&lt;br /&gt;filter f_warning { level(warning..emerg); };&lt;br /&gt;filter f_notice { level(notice..emerg); };&lt;br /&gt;filter f_info { level(info..emerg); };&lt;br /&gt;filter f_debug { level(debug..emerg); };&lt;br /&gt;filter f_is_debug { level(debug); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# program filters&lt;br /&gt;#&lt;br /&gt;filter f_ppp { program("ppp"); };&lt;br /&gt;filter f_slip { program("startslip"); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# host filters&lt;br /&gt;#&lt;br /&gt;&lt;br /&gt;# CISCO Filters&lt;br /&gt;filter f_netswitch001 {host("10.1.5.1"); };&lt;br /&gt;filter f_netswitch002 {host("10.1.5.2"); };&lt;br /&gt;filter f_netswitch003 {host("10.1.5.3"); };&lt;br /&gt;filter f_netswitch004 {host("10.1.5.4"); };&lt;br /&gt;filter f_netswitch005 {host("172.16.4.1"); };&lt;br /&gt;filter f_netrouter001 {host("10.1.5.9"); };&lt;br /&gt;filter f_netrouter002 {host("172.16.4.2"); };&lt;br /&gt;filter f_netserver001 {host("server1.example.com"); };&lt;br /&gt;filter f_netserver002 {host("server2.example.com"); };&lt;br /&gt;#&lt;br /&gt;# *.err;kern.warning;auth.notice;mail.crit  /dev/console&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_err); destination(console); };&lt;br /&gt;log { source(src); filter(f_kern); filter(f_warning); destination(console); };&lt;br /&gt;log { source(src); filter(f_auth); filter(f_notice); destination(console); };&lt;br /&gt;log { source(src); filter(f_mail); filter(f_crit); destination(console); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# *.notice;authpriv.none;kern.debug;lpr.info;mail.crit;news.err /var/log/messages&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_notice); filter(f_not_authpriv); destination(messages); };&lt;br /&gt;log { source(src); filter(f_kern); filter(f_debug); destination(messages); };&lt;br /&gt;log { source(src); filter(f_lpr); filter(f_info); destination(messages); };&lt;br /&gt;log { source(src); filter(f_mail); filter(f_crit); destination(messages); };&lt;br /&gt;log { source(src); filter(f_news); filter(f_err); destination(messages); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# security.*      /var/log/security&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_security); destination(security); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# auth.info;authpriv.info    /var/log/auth.log&lt;br /&gt;log { source(src); filter(f_auth); filter(f_info); destination(authlog); };&lt;br /&gt;log { source(src); filter(f_authpriv); filter(f_info); destination(authlog); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# mail.info      /var/log/maillog&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_mail); filter(f_info); destination(maillog); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# lpr.info      /var/log/lpd-errs&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_lpr); filter(f_info); destination(lpd-errs); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# ftp.info      /var/log/xferlog&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_ftp); filter(f_info); destination(xferlog); }; &lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# cron.*      /var/log/cron&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_cron); destination(cron); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# *.=debug      /var/log/debug.log&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_is_debug); destination(debuglog); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# *.emerg      *&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_emerg); destination(allusers); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# !startslip&lt;br /&gt;# *.*       /var/log/slip.log&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_slip); destination(slip); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# !ppp&lt;br /&gt;# *.*       /var/log/ppp.log&lt;br /&gt;#&lt;br /&gt;log { source(src); filter(f_ppp); destination(ppp); };&lt;br /&gt;&lt;br /&gt;#&lt;br /&gt;# CISCO Program Filters&lt;br /&gt;#&lt;br /&gt;log { source(netsrc); destination(netlog); };&lt;br /&gt;log { source(netsrc); destination(netsql); };&lt;br /&gt;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;taken from : http://www.freebsdwiki.net/index.php/Syslog-NG_Installation#Installation&lt;br /&gt;&lt;br /&gt;# mkfifo /var/log/mysql.pipe&lt;br /&gt;# ee /etc/rc.conf&lt;br /&gt;syslogd_enable="NO"&lt;br /&gt;syslog_ng_enable="YES"&lt;br /&gt;syslogd_program="/usr/local/sbin/syslog-ng"&lt;br /&gt;syslogd_flags=""&lt;br /&gt;&lt;br /&gt;Setelah saya cek ternyata field yg digenerate oleh php-syslog ada yg kurang jadi silahkan login ke mysql server dan tambahkan sbb :&lt;br /&gt;&lt;br /&gt;&lt;code&gt;&lt;br /&gt;CREATE TABLE `logs` (&lt;br /&gt;  `host` varchar(128) default NULL,&lt;br /&gt;  `facility` varchar(10) default NULL,&lt;br /&gt;  `priority` varchar(10) default NULL,&lt;br /&gt;  `level` varchar(10) default NULL,&lt;br /&gt;  `tag` varchar(10) default NULL,&lt;br /&gt;  `datetime` datetime default NULL,&lt;br /&gt;  `program` varchar(15) default NULL,&lt;br /&gt;  `msg` text,&lt;br /&gt;  `seq` bigint(20) unsigned NOT NULL auto_increment,&lt;br /&gt;  `counter` int(11) NOT NULL default '1',&lt;br /&gt;  `fo` datetime default NULL,&lt;br /&gt;  `lo` datetime default NULL,&lt;br /&gt;  PRIMARY KEY  (`seq`),&lt;br /&gt;  KEY `host` (`host`),&lt;br /&gt;  KEY `program` (`program`),&lt;br /&gt;  KEY `datetime` (`datetime`),&lt;br /&gt;  KEY `priority` (`priority`),&lt;br /&gt;  KEY `facility` (`facility`)&lt;br /&gt;) ENGINE=MyISAM AUTO_INCREMENT=9 DEFAULT CHARSET=latin1;&lt;br /&gt;&lt;/code&gt;&lt;br /&gt;&lt;br /&gt;Ok insya Allah sudah finish. Silahkan reboot server anda. Pastikan mysql server jalan dulu baru syslog-ng server.&lt;br /&gt;&lt;br /&gt;bersambungg...&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-6748655175683297577?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/6748655175683297577/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=6748655175683297577' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/6748655175683297577'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/6748655175683297577'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/07/instalasi-dan-konfigurasi-syslog-ng.html' title='Instalasi dan Konfigurasi SYSLOG-NG dengan database MYSQL.'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-4232094881382336353</id><published>2011-07-01T09:06:00.000+07:00</published><updated>2011-07-01T09:07:39.049+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='freebsd'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='database'/><title type='text'>Merubah data directory pada mysql server FreeBSD Server</title><content type='html'>Secara default, jika kita install mysql server via port maka data-data dari database yang ada dalam mysql server akan tersimpan pada dir /var/db/mysql&lt;br /&gt;Akan merepotkan kalau ternyata partisi /var kita terlalu kecil, sehingga data nambah sedikit aja partisi /var udah penuh.&lt;br /&gt;Ada 2 cara untuk mensiasati hal tsb, &lt;br /&gt;pertama ada merubah letak data directory pada file konfigurasi mysql kita my.cnf.&lt;br /&gt;Hal ini memerlukan perubahan pada file konfigurasi my.cnf &lt;br /&gt;# ee /var/db/mysql/my.cnf&lt;br /&gt;[mysqld]&lt;br /&gt;datadir=/data/mysqlbaru&lt;br /&gt;Create directory tempat data baru disimpan&lt;br /&gt;# mkdir /data/mysqlbaru&lt;br /&gt;merubah owner directory tsb menjadi milik mysql&lt;br /&gt;#chown -R mysql:mysql /data/mysqlbaru&lt;br /&gt;kemudian start mysql&lt;br /&gt;# /usr/local/etc/rc.d/mysql-server start&lt;br /&gt;&lt;br /&gt;Cara kedua adalah dengan memindah dan melakukan linking directory mysql.&lt;br /&gt;Detailnya sbb :&lt;br /&gt;&lt;br /&gt;matikan server : &lt;br /&gt;# /usr/local/etc/rc.d/mysql-server stop&lt;br /&gt;# cd /var/db&lt;br /&gt;pindahkan directory data mysql ke directory baru yang kapasitasnya lebih lega : &lt;br /&gt;# mv mysql /data&lt;br /&gt;lakukan linking directory&lt;br /&gt;# ln -s /data/mysql /var/db/mysql&lt;br /&gt;start server : &lt;br /&gt;# /usr/local/etc/rc.d/mysql-server start&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-4232094881382336353?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/4232094881382336353/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=4232094881382336353' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/4232094881382336353'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/4232094881382336353'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/07/merubah-data-directory-pada-mysql.html' title='Merubah data directory pada mysql server FreeBSD Server'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-7635482435700352222</id><published>2011-06-22T14:29:00.004+07:00</published><updated>2011-06-22T15:03:00.781+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='pf'/><category scheme='http://www.blogger.com/atom/ns#' term='freebsd'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><title type='text'>Block http brute force dengan PF</title><content type='html'>Lumayan ada ilmu baru hasil diskusi dengan admin sebelah dan baca manual PF.&lt;br /&gt;Rulenya sbb :&lt;br /&gt;&lt;br /&gt;out_if = bce0&lt;br /&gt;table &lt;bruteforces&gt; persist&lt;br /&gt;pass quick from 10.10.3.0/29&lt;br /&gt;block quick from &lt;bruteforces&gt;&lt;br /&gt;&lt;br /&gt;pass in on $int_if proto { tcp } from any to 10.10.7.4 port 80 flags S/SA keep state \&lt;br /&gt;        (max-src-conn 2, max-src-conn-rate 5/5, overload &lt;bruteforces&gt; flush global)&lt;br /&gt;&lt;br /&gt;Penjelasan sbb :&lt;br /&gt;max-src-conn number&lt;br /&gt;    Limit the maximum number of simultaneous TCP connections which have completed the 3-way handshake that a single host can make. &lt;br /&gt;&lt;br /&gt;max-src-conn-rate number / interval&lt;br /&gt;    Limit the rate of new connections to a certain amount per time interval. &lt;br /&gt;&lt;br /&gt;Bagi saya yg awam sulit sekali memahami maksudnya, Hiks..&lt;br /&gt;So dicoba aja testing dengan rule diatas saya coba sebagai berikut :&lt;br /&gt;&lt;br /&gt;Saya membuka http://10.10.7.4 di 5 tab firefox dan saya reload dalam waktu bersamaan.Dan halaman masih bisa dibuka. &lt;br /&gt;Akan tetapi jika saya buka 6 halaman http://10.10.7.4 dengan browser berbeda maupun browser yg sama maka saya cek :&lt;br /&gt;&lt;br /&gt;# pfctl -t bruteforces -Tshow&lt;br /&gt;   10.10.7.1&lt;br /&gt;&lt;br /&gt;IP saya terjaring dalam rule tsb.&lt;br /&gt;&lt;br /&gt;Kemudian rule coba saya ubah &lt;br /&gt;pass in on $int_if proto { tcp } from any to 10.10.7.4 port 80 flags S/SA keep state \&lt;br /&gt;        (max-src-conn 1, max-src-conn-rate 5/5, overload &lt;bruteforces&gt; flush global)&lt;br /&gt;&lt;br /&gt;max-src-conn nya saya set 1 saja.&lt;br /&gt;&lt;br /&gt;Saya coba buka http://10.10.7.4 pada 1 tab saja di firefox dan coba buka halaman tsb di chrome.&lt;br /&gt;Alhasil :&lt;br /&gt;# pfctl -t bruteforces -Tshow&lt;br /&gt;  10.10.7.1&lt;br /&gt;&lt;br /&gt;Saya coba juga buka dengan IP berbeda, ternyata ip ke 2 langsung kena jaring&lt;br /&gt;&lt;br /&gt;# pfctl -t bruteforces -Tshow&lt;br /&gt;  10.10.7.10&lt;br /&gt;&lt;br /&gt;Saya menyimpulkan sbb :&lt;br /&gt;max-src-conn : berapa banyak browser yg akan di launch untuk mengakses web kita ternyata.&lt;br /&gt;Tidak membedakan IP. oh ternyata sekali buka browser dan akses itu dihitung 1 TCP connection hehe..&lt;br /&gt;max-src-conn-rate a/b : dalam b detik berapa a tab yg akan dibuka/direfresh.&lt;br /&gt;ada juga max-src-node : asumsi saya ini melimit berapa banyak ip yg boleh mengakses, tidak disarankan kalau web kita untuk umum.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-7635482435700352222?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/7635482435700352222/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=7635482435700352222' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7635482435700352222'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7635482435700352222'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/06/block-http-brute-force-dengan-pf.html' title='Block http brute force dengan PF'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-1693086522140904279</id><published>2011-03-18T09:56:00.003+07:00</published><updated>2011-03-18T10:50:02.046+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='instalasi'/><category scheme='http://www.blogger.com/atom/ns#' term='tips'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Membangun Server dari Awal dengan FreeBSD (part1)</title><content type='html'>1. Optimasi Kernel&lt;br /&gt;Setelah instalasi yg perlu di perhatikan adalah kompile kernel.&lt;br /&gt;Buang device2 yang tidak diperlukan. eth driver, pcmcia dll.&lt;br /&gt;1. DIsable IPv6 &lt;br /&gt;2. DISABLE NFS&lt;br /&gt;&lt;br /&gt;Untuk option tambahan mgkn bisa ditambahkan pada kernel sbb : &lt;br /&gt;&lt;br /&gt;options         IPFIREWALL&lt;br /&gt;options         IPFIREWALL_VERBOSE&lt;br /&gt;options         IPFIREWALL_FORWARD&lt;br /&gt;options         IPFIREWALL_DEFAULT_TO_ACCEPT&lt;br /&gt;options         DUMMYNET&lt;br /&gt;options         IPFILTER&lt;br /&gt;options         IPFILTER_LOG&lt;br /&gt;&lt;br /&gt;#### PF OPTION ####&lt;br /&gt;device pf&lt;br /&gt;device pflog&lt;br /&gt;device pfsync&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;2. Setting SSHD&lt;br /&gt;ee /etc/ssh/sshd.config&lt;br /&gt;&lt;br /&gt;Port 1234&lt;br /&gt;Protocol 2&lt;br /&gt;MaxAuthTries 2&lt;br /&gt;MaxSessions 8&lt;br /&gt;PermitRootLogin no&lt;br /&gt;#StrictModes yes&lt;br /&gt;#RSAAuthentication yes&lt;br /&gt;#PubkeyAuthentication yes&lt;br /&gt;#AuthorizedKeysFile     .ssh/authorized_keys&lt;br /&gt;PermitEmptyPasswords no&lt;br /&gt;UseDNS no&lt;br /&gt;Banner none&lt;br /&gt;# override default of no subsystems&lt;br /&gt;Subsystem       sftp    /usr/libexec/sftp-server&lt;br /&gt;AllowUsers user1&lt;br /&gt;AllowUsers user2&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;3. Setting TTYS&lt;br /&gt;# If console is marked "insecure", then init will ask for the root password&lt;br /&gt;# when going to single-user mode.&lt;br /&gt;console none                            unknown off insecure&lt;br /&gt;#&lt;br /&gt;ttyv0   "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;# Virtual terminals&lt;br /&gt;ttyv1   "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;ttyv2   "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;#ttyv3  "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;#ttyv4  "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;#ttyv5  "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;#ttyv6  "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;#ttyv7  "/usr/libexec/getty Pc"         cons25  on  secure&lt;br /&gt;ttyv8   "/usr/local/bin/xdm -nodaemon"  xterm   off secure&lt;br /&gt;&lt;br /&gt;Saran dari Dru Lavigne sbb :&lt;br /&gt;&lt;br /&gt;General Hardening Tips&lt;br /&gt;&lt;br /&gt;• restricting ssh access using the AllowUsers keyword in / etc/ssh/sshd_config&lt;br /&gt;• using chflags to set the schg flag on system binaries and configuration files that&lt;br /&gt;don't require modifications&lt;br /&gt;• implementing a file integrity checking system such as tripwire&lt;br /&gt;(http:/ /www.tripwire.com), aide (http:/ /www.cs.tut.fi/~rammer /aide.html)or&lt;br /&gt;implementing your own using mtree&lt;br /&gt;• changing /etc/motd removing the COPYRIGHT notice&lt;br /&gt;• subscribing to the FreeBSD security advisories mailing list&lt;br /&gt;(http:/ /lists.freebsd.org/mailman/listinfo/freebsd- security- notifications)&lt;br /&gt;• reviewing mount(8) to see if any options are applicable to your filesystems&lt;br /&gt;• reviewing your sysctl(8) settings; http:/ /sysctl.enderunix.org/ provides some&lt;br /&gt;helpful descriptions&lt;br /&gt;• reviewing your rc.conf(5) settings&lt;br /&gt;Finally, do:&lt;br /&gt;• read root's emails daily and have a log review action plan&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-1693086522140904279?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/1693086522140904279/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=1693086522140904279' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/1693086522140904279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/1693086522140904279'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/03/membangun-server-dari-awal-dengan.html' title='Membangun Server dari Awal dengan FreeBSD (part1)'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-6713078119599228262</id><published>2011-03-18T09:24:00.001+07:00</published><updated>2011-03-18T09:24:49.198+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>General hardening tips from Dru..</title><content type='html'>does this system really need IPv6 support?&lt;br /&gt;• do I really want NFS (and its inherent security risks) on an Internet facing server?&lt;br /&gt;• should I be loading filesystems I'll never use? (e.g. DOS, CD9660)&lt;br /&gt;• do I need SCSI drivers on a non- SCSI system?&lt;br /&gt;• do I need hardware RAID drivers if I'm using software RAID?&lt;br /&gt;• do I really need to load dozens of NIC drivers if I always buy the same brand of NIC?&lt;br /&gt;• do I need PCMCIA or wireless support on a non- laptop system?&lt;br /&gt;• will I be using USB or Firewire?&lt;br /&gt;&lt;br /&gt;KERNEL&lt;br /&gt;&lt;br /&gt;1. DIsable IPv6 &lt;br /&gt;2. DISABLE NFS&lt;br /&gt;&lt;br /&gt;There are many tools available to create a custom backup solution, ranging&lt;br /&gt;built- in FreeBSD utilities to third- party software applications available through&lt;br /&gt;ports collection. In a more complex scenario you may wish to investigate:&lt;br /&gt;• bacula http://www.bacula.org&lt;br /&gt;• rsnapshot http://www.rsnapshot.org&lt;br /&gt;• boxbackup http://www.fluffy.co.uk/boxbackup/&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;General Hardening Tips&lt;br /&gt;&lt;br /&gt;• restricting ssh access using the AllowUsers keyword in / etc/ssh/sshd_config&lt;br /&gt;• using chflags to set the schg flag on system binaries and configuration files that&lt;br /&gt;don't require modifications&lt;br /&gt;• implementing a file integrity checking system such as tripwire&lt;br /&gt;(http:/ /www.tripwire.com), aide (http:/ /www.cs.tut.fi/~rammer /aide.html)or&lt;br /&gt;implementing your own using mtree&lt;br /&gt;• changing /etc/motd , adding an ssh banner, and removing the COPYRIGHT notice&lt;br /&gt;• subscribing to the FreeBSD security advisories mailing list&lt;br /&gt;(http:/ /lists.freebsd.org/mailman/listinfo/freebsd- security- notifications)&lt;br /&gt;• reviewing mount(8) to see if any options are applicable to your filesystems&lt;br /&gt;• reviewing your sysctl(8) settings; http:/ /sysctl.enderunix.org/ provides some&lt;br /&gt;helpful descriptions&lt;br /&gt;• reviewing your rc.conf(5) settings&lt;br /&gt;Finally, do:&lt;br /&gt;• read root's emails daily and have a log review action plan&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-6713078119599228262?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/6713078119599228262/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=6713078119599228262' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/6713078119599228262'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/6713078119599228262'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/03/general-hardening-tips-from-dru.html' title='General hardening tips from Dru..'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-2427416479100889360</id><published>2011-03-03T09:27:00.000+07:00</published><updated>2011-03-03T09:29:22.990+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='proxy'/><title type='text'>Lusca/cacheboy</title><content type='html'>Lagi nyoba cacheboy tapi belum berhasil yang Tproxy karena mesinku amd. Googling nemu artikel berikut. Semoga bermanfaat&lt;br /&gt;Diambil dari : http://hikmah-teknologi.blogspot.com/&lt;br /&gt;&lt;br /&gt;LUSCA TPROXY on FREEBSD-7-STABLE&lt;br /&gt;patch kernel:&lt;br /&gt;cd /usr/src&lt;br /&gt;fetch http://squid-proxy-pkg.googlecode.com/files/freebsd-tproxy-sys.patch&lt;br /&gt;path -p0 &lt; freebsd-tproxy-sys.patch&lt;br /&gt;&lt;br /&gt;di kernel : /sys/i386/conf/PROXY&lt;br /&gt;options IP_NONLOCALBIND&lt;br /&gt;options IPDIVERT&lt;br /&gt;options IPFIREWALL&lt;br /&gt;options IPFIREWALL_NAT&lt;br /&gt;options IPFIREWALL_VERBOSE&lt;br /&gt;options IPFIREWALL_FORWARD&lt;br /&gt;options IPFIREWALL_DEFAULT_TO_ACCEPT&lt;br /&gt;options IP_NONLOCALBIND&lt;br /&gt;options LIBALIAS&lt;br /&gt;&lt;br /&gt;#option tunning for squid&lt;br /&gt;options VFS_AIO&lt;br /&gt;options MAXFILES=262144&lt;br /&gt;options MSGMNB=32768&lt;br /&gt;options MSGMNI=82&lt;br /&gt;options MSGSEG=4096&lt;br /&gt;options MSGSSZ=128&lt;br /&gt;options MSGTQL=2048&lt;br /&gt;options SHMSEG=32&lt;br /&gt;options SHMMNI=256&lt;br /&gt;options SHMMAX=4194304&lt;br /&gt;options SHMALL=16384&lt;br /&gt;makeoptions COPTFLAGS="-O2 -pipe -funroll-loops -ffast-math"&lt;br /&gt;makeoptions NO_MODULES=yes&lt;br /&gt;&lt;br /&gt;build kernel&lt;br /&gt;cd /usr/src&lt;br /&gt;make buildkernel KERNCONF=PROXY &amp;&amp; make installkernel KERNCONF=PROXY&lt;br /&gt;&lt;br /&gt;di /etc/sysctl.conf&lt;br /&gt;net.inet.ip.nonlocalok=1&lt;br /&gt;&lt;br /&gt;cp /usr/src/sys/netinet/in.h /usr/include/netinet&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;install squid&lt;br /&gt;pkg_add -v http://squid-proxy-pkg.googlecode.com/files/lusca-with-tproxy-r14371_3.tbz&lt;br /&gt;&lt;br /&gt;di /usr/local/etc/squid/squid.conf&lt;br /&gt;&lt;br /&gt;http_port XXX.INTERNAL.IP.XXX:3128 transparent tproxy&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# em0 -&gt; External interface (to mikrotik)&lt;br /&gt;# em1 -&gt; Internal interface (to client)&lt;br /&gt;&lt;br /&gt;di /etc/ipfw.tproxy&lt;br /&gt;ipfw add fwd 192.168.1.1,3128 tcp from 192.168.1.0/24 to any 80 in via em1 # default rule to transparent proxy&lt;br /&gt;ipfw add fwd 192.168.1.1 tcp from any 80 to 192.168.1.0/24 in via em0 # catch the packets that come back using the clients IPs&lt;br /&gt;&lt;br /&gt;di rc.conf&lt;br /&gt;gateway_enable="YES"&lt;br /&gt;ifconfig_em0="192.168.0.1 255.255.255.252"&lt;br /&gt;ifconfig_em1="192.168.1.1 255.255.255.0"&lt;br /&gt;firewall_enable="YES"&lt;br /&gt;firewall_script="/etc/ipfw.tproxy"&lt;br /&gt;firewall_type="open"&lt;br /&gt;firewall_logging="YES"&lt;br /&gt;&lt;br /&gt;fsck_y_enable="YES"&lt;br /&gt;background_fsck="NO"&lt;br /&gt;&lt;br /&gt;squid_enable="YES"&lt;br /&gt;#disini tidak menggunakan bind taoi dnsmasq&lt;br /&gt;&lt;br /&gt;dnsmasq_enable="YES"&lt;br /&gt;dnsmasq_flags="--conf-file=/usr/local/etc/dnsmasq.conf"&lt;br /&gt;&lt;br /&gt;dan jangan lupa di router paling atas untuk membuat NAT dan static routes utk ip di bawah proxy&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-2427416479100889360?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/2427416479100889360/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=2427416479100889360' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2427416479100889360'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2427416479100889360'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/03/luscacacheboy.html' title='Lusca/cacheboy'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-7143697750927416862</id><published>2011-03-02T09:50:00.004+07:00</published><updated>2011-03-02T10:32:44.039+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='freebsd'/><category scheme='http://www.blogger.com/atom/ns#' term='utility'/><category scheme='http://www.blogger.com/atom/ns#' term='proxy'/><title type='text'>Tproxy</title><content type='html'>Back to proxy, especially squid. Eh ada lagi yang namanya cacheboy.&lt;br /&gt;Cacheboy adalah optimasi dari squid stable 2. Menurut pemahaman saya sih cacheboy itu versi moddingnya squid 2 begitulah gampangnya. Nah waktu mencoba instalasi via port ada banyak option yang bisa di enable/disable. Nah berhubung sudah lama gak ngutik squid jadi perlu cari2 lagi fungsi2 option tsb. Antara lain :&lt;br /&gt;&lt;br /&gt;1. Delay pool : Fitur ini digunakan untuk limitasi bandwidth&lt;br /&gt;2. AUFS dan COSS : Ini adalah tipe file penyimpanan cache dari squid&lt;br /&gt;3. PF dan IPF transparent : Ini untuk mengaktifkan support PF firewall atau IPF firewall untuk transparent proxy&lt;br /&gt;4. Enable Tproxy : untuk mengaktifkan Tproxy.&lt;br /&gt;&lt;br /&gt;Penjelasan Tproxy dari internet sbb :&lt;br /&gt;&lt;br /&gt;Transparent Proxy (TProxy)&lt;br /&gt;&lt;br /&gt;Tproxy is truly transparent proxy. A transparent proxy or more precisely an interception proxy is the one that becomes transparent to the clients by transparently intercepting the http requests and serving the response, which means the client need not be explicitly configured to use the proxy but they are transparently sent to the proxy without the client's knowledge. Since the interception proxy forwards the request on behalf of the client, the web server see's the source of the request come from the proxy and hence it is not transparent to the web server.&lt;br /&gt;&lt;br /&gt;The tproxy feature comes into solving this issue and makes itself transparent to both for the client and the web server. However, the interception and/or tproxy feature requires kernel support and packet redirection feature of the operating system.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Note: To make still more truly transparent, the proxy should be configured not to add any extra headers while forwarding the request and serving the response.&lt;br /&gt;&lt;br /&gt;Nha kira2 terjemahannya spt ini.&lt;br /&gt;&lt;br /&gt;Tproxy adalah transparent proxy yg sebenar2nya. Transparent proxy atau proxy penangkap adalah proxy yang bekerja dengan menangkap paket http/browsing dari client secara transparan. Dengan kata lain, di sisi client tidak memerlukan adanya konfigurasi pengaktifkan proxy karena secara otomatis dan mau tidak mau akan lewat proxy.&lt;br /&gt;&lt;br /&gt;Karena proxy tsb menangkap paket dan melakukan koneksi ke webserver tujuan maka yg dikenali oleh webserver tujuan adalah IP dari proxy bukan dari client.&lt;br /&gt;&lt;br /&gt;Fitur dari Tproxy inilah kuncinya, sehingga webserver tujuan mengenali langsung ip client (tentu saja ip public). Fitur ini memerlukan pengaktifan pada kernel dari OS yang dipakai.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-7143697750927416862?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/7143697750927416862/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=7143697750927416862' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7143697750927416862'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7143697750927416862'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/03/tproxy.html' title='Tproxy'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-2372208774664772152</id><published>2011-03-01T13:55:00.005+07:00</published><updated>2011-03-01T13:59:24.848+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='freebsd'/><category scheme='http://www.blogger.com/atom/ns#' term='utility'/><title type='text'>Install NTP Server di FreeBSD</title><content type='html'>Caranya mudah. Install saja ntp via port&lt;br /&gt;Kemudian &lt;br /&gt;# ee /etc/ntp.conf&lt;br /&gt;server 3.id.pool.ntp.org&lt;br /&gt;server 0.asia.pool.ntp.org&lt;br /&gt;server 2.asia.pool.ntp.or&lt;br /&gt;&lt;br /&gt;driftfile /var/db/ntp.drift&lt;br /&gt;&lt;br /&gt;Save file /etc/ntp.conf dengan konfigurasi di atas.&lt;br /&gt;Kemudian start service dengan perintah&lt;br /&gt;&lt;br /&gt; /etc/rc.d/ntpd start&lt;br /&gt;&lt;br /&gt;Kemudian jalankan perintah&lt;br /&gt;ntpdate -d localhost&lt;br /&gt;&lt;br /&gt;Jika ada pesan no server bla2. Maka coba tunggu kisaran 10 s/d 15 menit. Dan coba ulangi lagi sampai terjadi sinkronisasi sbb&lt;br /&gt;&lt;br /&gt;1 Mar 14:01:36 ntpdate[19223]: step time server localhost offset -225.715219 sec&lt;br /&gt;&lt;br /&gt;Jangan lupa untuk membuka port 123 udp.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-2372208774664772152?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/2372208774664772152/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=2372208774664772152' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2372208774664772152'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2372208774664772152'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2011/03/install-ntp-server-di-freebsd.html' title='Install NTP Server di FreeBSD'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-7643368473362171851</id><published>2010-11-05T18:19:00.002+07:00</published><updated>2010-11-05T18:23:39.824+07:00</updated><title type='text'>Angin duduk</title><content type='html'>Dapat info penting dari mas chakim yg istrinya kena angin duduk. berikut ini hal2 yang perlu diketahui.&lt;br /&gt;Penyebab :&lt;br /&gt;(1) Sering begadang/pengaruh angin malam&lt;br /&gt;(2) Hobi nahan kentut/boel&lt;br /&gt;(3) Lingkungan/cuaca dingin yang ekstrim dan terus menerus&lt;br /&gt;(4) Telat makan&lt;br /&gt;(5) Masuk angin biasa yang dibiarkan&lt;br /&gt;&lt;br /&gt;ciri2nya&lt;br /&gt;(1) rasanya seperti ada yg ngganjel di antara perut+dada &lt;br /&gt;(2) ingin sendawa/kentut tapi susah sekali dan meskipun bisa hampir tidak mengurangi rasa sakit no.1 &lt;br /&gt;(3) dibawa duduk/...bungkuk/jalan/bahkan berbaring pun sulit &lt;br /&gt;(4) badan rasanya dingin (bhs jawa: anyep)&lt;br /&gt;Beda sama masuk angin biasa : angin duduk tidak bisa hilang meski sudah dikerokin/minum obat masuk angin/dioles minyak angin yang panas sekalipun&lt;br /&gt;&lt;br /&gt;Cara mengatasi :&lt;br /&gt;Sebelumnya olesin perut + dada + pinggang + punggung dengan minyak cap kap*k, bila perlu kerokan, trus masak air, air hangat hasil masak tsb dimasukkan dalam 2 buah botol (botol kaca lebih bagus), botol pertama letakkan di ulu hati atau bagian perut depan tempat angin duduk ga mau keluar, botol kedua diletakkan pada kedua telapak kaki, posisi badan rebah menghadap ke atas, bila perlu pakai jaket + celana training + kaos kaki + selimut tebal, tunggu sampai keringat dingin keluar dan bisa kentut, jika setelah setengah jam tidak kunjung reda, ganti air dalam botol yang udah kurang dingin dengan air hangat baru, dan tempel lagi di tempat spt diatas, semoga bermanfaat, mengingat resiko angin duduk ini adalah meninggal dunia jika terlambat mengatasi (based on a true story)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-7643368473362171851?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/7643368473362171851/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=7643368473362171851' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7643368473362171851'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7643368473362171851'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/11/angin-duduk.html' title='Angin duduk'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-212662395902290422</id><published>2010-10-27T10:32:00.002+07:00</published><updated>2010-10-27T10:37:25.382+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='mail'/><category scheme='http://www.blogger.com/atom/ns#' term='php'/><category scheme='http://www.blogger.com/atom/ns#' term='web'/><title type='text'>postfix, sendmail dan php</title><content type='html'>Barusan lagi update script untuk checking quota di mysql.&lt;br /&gt;Scriptnya ini menggunakan PHP. Jika ada database yang melebihi quota yang disediakan maka akan di lock dan dikirim email pemberitahuan. &lt;br /&gt;Nah ternyata waktu check quota ada notifikasi error &lt;br /&gt;locking database /usr/sbin/sendmail not found.&lt;br /&gt;&lt;br /&gt;Sepertinya error tersebut terjadi karena saya baru migrasi dari sendmail ke postfix.&lt;br /&gt;Ternyata solusinya mudah. Pertama cari dulu binary sendmail&lt;br /&gt;&lt;br /&gt;# whereis sendmail&lt;br /&gt;sendmail: /usr/local/sbin/sendmail&lt;br /&gt;&lt;br /&gt;Kemudian edit php.ini pada bagian berikut :&lt;br /&gt;&lt;br /&gt;sendmail_path = /usr/local/sbin/sendmail -t -i -f noreply@domain.com&lt;br /&gt;&lt;br /&gt;restart webserver dan silhakan test kembali..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-212662395902290422?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/212662395902290422/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=212662395902290422' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/212662395902290422'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/212662395902290422'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/10/postfix-sendmail-dan-php.html' title='postfix, sendmail dan php'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-2322287513002322192</id><published>2010-07-16T11:45:00.003+07:00</published><updated>2010-07-16T11:51:11.727+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='www'/><category scheme='http://www.blogger.com/atom/ns#' term='freebsd'/><title type='text'>install eaccelerator di freebsd</title><content type='html'>cd /usr/ports/www/eaccelerator&lt;br /&gt;&lt;br /&gt;You have installed the eaccelerator package.&lt;br /&gt;Edit /usr/local/etc/php.ini and add:&lt;br /&gt;zend_extension="/usr/local/lib/php/20060613/eaccelerator.so"&lt;br /&gt;Then create the cache directory:&lt;br /&gt;mkdir /tmp/eaccelerator&lt;br /&gt;chown www /tmp/eaccelerator&lt;br /&gt;chmod 0700 /tmp/eaccelerator&lt;br /&gt;&lt;br /&gt;u can try to config :&lt;br /&gt;zend_extension="/usr/local/lib/php/20060613/eaccelerator.so"&lt;br /&gt;eaccelerator.shm_size="16"&lt;br /&gt;eaccelerator.cache_dir="/tmp/eaccelerator"&lt;br /&gt;eaccelerator.enable="1"&lt;br /&gt;eaccelerator.optimizer="1"&lt;br /&gt;eaccelerator.check_mtime="1"&lt;br /&gt;eaccelerator.debug="0"&lt;br /&gt;eaccelerator.filter=""&lt;br /&gt;eaccelerator.shm_max="0"&lt;br /&gt;eaccelerator.shm_ttl="0"&lt;br /&gt;eaccelerator.shm_prune_period="0"&lt;br /&gt;eaccelerator.shm_only="0"&lt;br /&gt;eaccelerator.compress="1"&lt;br /&gt;eaccelerator.compress_level="9"&lt;br /&gt;&lt;br /&gt;&lt;span style="font-weight: bold;"&gt;eaccelerator.shm_size&lt;/span&gt;&lt;br /&gt;This setting will allow you to control the amount of shared memory eAccelerator should allocate to cache PHP scripts. The number sets the amount of memory in megabytes. Setting this value to 0 will use the default size.&lt;br /&gt;&lt;br /&gt;&lt;h2 id="eaccelerator.shm_size"&gt;eaccelerator.shm_size&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.shm_size"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;This setting will allow you to control the amount of shared memory   eAccelerator should allocate to cache PHP scripts. The number sets the  amount of  memory in megabytes. Setting this value to 0 will use the  default size.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.shm_size = "0"&lt;/pre&gt; &lt;p&gt;On Linux the maximum amount of memory a process can allocate is  limited by  the number set in /proc/sys/kernel/shmmax. Allocating more  than this value will  result in eAccelerator failing to initialise. The  size in this file is given in  bytes. You can raise this amount with:&lt;/p&gt; &lt;pre class="wiki"&gt;echo value &gt; /proc/sys/kernel/shmmax&lt;/pre&gt; &lt;p&gt;Where &lt;em&gt;value&lt;/em&gt; is the size in bytes you want to use. This value  is reset  to the default value evertime you reboot, but you can raise  it permanently by  adding the amount you need in /etc/sysctl.conf. This  is done by adding:&lt;/p&gt; &lt;pre class="wiki"&gt;kernel.shmmax = value&lt;/pre&gt; &lt;h2 id="eaccelerator.cache_dir"&gt;eaccelerator.cache_dir&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.cache_dir"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;This directory is used for the disk cache. eAccelerator stores  precompiled  code, session data, content and user entries here. The same  data can be stored  in shared memory (for quicker access). The default  value is “/tmp/eaccelerator”.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.cache_dir = "/tmp/eaccelerator"&lt;/pre&gt; &lt;p&gt;This is easy because that directory is easily writable to everyone,  and  mounted with noexec. However, it isn’t the best because on a lot of  systems this  directory is cleared on reboot. A better place is  &lt;em&gt;/var/cache/eaccelerator&lt;/em&gt;.  Create the directory and make sure it’s writable  to the process  eAccelerator runs under.&lt;/p&gt; &lt;p&gt;A safe bet is making it world writeable, a safer and cleaner way is  making  the user php runs under (most of the time the same user as  apache or lighttpd)  the owner and set 0644 permissions.&lt;/p&gt; &lt;p&gt;The lazy way:&lt;/p&gt; &lt;pre class="wiki"&gt;mkdir /tmp/eaccelerator&lt;br /&gt;chmod 0777 /tmp/eaccelerator&lt;/pre&gt; &lt;h2 id="eaccelerator.enable"&gt;eaccelerator.enable&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.enable"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;With this setting you can enable or disable eAccelerator. This may  seem like  a pretty stupid setting, but it can be very useful. For  example this setting can  also be used in the vhost section of the  Apache configuration. It allows you to  disable eAccelerator for a  certian vhost by placing &lt;em&gt;php_admin_value  eaccelerator.enable 0&lt;/em&gt;  in the vhost section.&lt;/p&gt; &lt;p&gt;Setting this value to “1″ enables eAccelerator, which is also the  default  value. Setting it to “0″ will disable eAccelerator.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.enable = "1"&lt;/pre&gt; &lt;h2 id="eaccelerator.optimizer"&gt;eaccelerator.optimizer&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.optimizer"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;Enables or disables the optimizer which may speed up code execution.  Setting  it “1″ will enable eAccelerator, “0″ disables it. By default  the optimizer is  enabled. The optimizer will only run when the script  is compiled before it’s  cached.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.optimizer = "1"&lt;/pre&gt; &lt;h2 id="eaccelerator.debug"&gt;eaccelerator.debug&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.debug"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;Enables or disables debug logging. Setting this to 1 will print  information  to the log file about the cache hits of a file. This is  only useful when  debugging eAccelerator for bug reports.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.debug = 0&lt;/pre&gt; &lt;h2 id="eaccelerator.log_file"&gt;eaccelerator.log_file&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.log_file"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;Set the log file for eaccelerator. When this option isn’t set then  the data  will be logged to stderr, when using PHP with Apache these  lines will be added  to the Apache error log.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.log_file = "/var/log/httpd/eaccelerator_log"&lt;/pre&gt; &lt;h2 id="eaccelerator.name_space"&gt;eaccelerator.name_space&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.name_space"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;When using the user cache api for storing data in shared memory, all  keys are  prepended by the hostname used for the current request. This  hostname equals the  &lt;a class="missing wiki" rel="nofollow" href="http://techgurulive.com/wiki/ServerName"&gt;ServerName?&lt;/a&gt; set  in  the vhost section of apache. This is done to avoid duplicate keys  between  vhosts. Sometimes this behaviour is desired to share data  between vhosts. When  setting this option this namespace is used to  prepend to each key. By default  this is set to “” which instructs  eAccelerator to use the hostname as namespace.&lt;/p&gt; &lt;p&gt;When setting this in the main PHP configuration file this namespace  will be  used by all vhosts. This value can also be set in the vhost  section or even in a  .htaccess file to allow sharing of data between  only two vhosts.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.name_space = ""&lt;/pre&gt; &lt;h2 id="eaccelerator.check_mtime"&gt;eaccelerator.check_mtime&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.check_mtime"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;On every hit eAccelerator will check the modification time of a  script to see  if it changed and needs to be recompiled. Although this  is a lot faster then  opening the file and compiling it, this still adds  some overhead because a  &lt;em&gt;stat&lt;/em&gt; call needs to be done every  time. This setting allows you to disable  this check. The downside of  disabling this check is that you need to manually  clean the  eAccelerator cache when you update a file.&lt;/p&gt; &lt;p&gt;By default this check is enabled.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.check_mtime = "1"&lt;/pre&gt; &lt;h2 id="eaccelerator.filter"&gt;eaccelerator.filter&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.filter"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;Determine which PHP files can be cached. You can specify the pattern  (for  example “*.php *.phtml”) the PHP script filename needs to match.  If a pattern  starts with “!”, the files that match that pattern are  excluded from the cache.  Default value is “” which will cache all  scripts PHP compiles.&lt;/p&gt; &lt;p&gt;Please note that eaccelerator.filter doesn’t work on a URL basis but  rather  on the absolute filesystem path, so a filter of !/home* would  exclude all  scripts in /home from being cached.&lt;/p&gt; &lt;p&gt;Multiple patterns need to be seperated by spaces or tabs, but not  commas.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.filter = ""&lt;/pre&gt; &lt;h2 id="eaccelerator.shm_max"&gt;eaccelerator.shm_max&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.shm_max"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;By default there is no limit on the maximum size a user can put in  shared  memory with functions like &lt;em&gt;eaccelerator_put&lt;/em&gt;, the  maximum size is  controlled by this setting. This value is the maximum  size that can be put in  the cache, the size is given in bytes (10240,  10K, 1M). The default value is “0″  which disables the limit.&lt;/p&gt; &lt;p&gt;&lt;strong&gt;This setting doesn’t affect the maximum size for a script”’ &lt;/strong&gt;&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.shm_max = "0"&lt;/pre&gt; &lt;h2 id="eaccelerator.shm_ttl"&gt;eaccelerator.shm_ttl&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.shm_ttl"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;When eAccelerator doesn’t have enough free shared memory to cache a  new  script it will remove all scripts from shared memory cache that  haven’t been  accessed in at least &lt;em&gt;shm_ttl&lt;/em&gt; seconds. By default  this value is set to “0″  which means that eAccelerator won’t try to  remove any old scripts from shared  memory.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.shm_ttl = "0"&lt;/pre&gt; &lt;h2 id="eaccelerator.shm_prune_period"&gt;eaccelerator.shm_prune_period&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.shm_prune_period"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;When eAccelerator doesn’t have enough free shared memory to cache a  script it  tries to remove old scripts if the previous try was made more  then  “shm_prune_period” seconds ago. Default value is “0″ which means  that  eAccelerator won’t try to remove any old script from shared  memory.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.shm_prune_period = "0"&lt;/pre&gt; &lt;h2 id="eaccelerator.shm_only"&gt;eaccelerator.shm_only&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.shm_only"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;Enable or disable caching of compiled scripts on disk. This has no  effect on  session data and content caching. Default value is “0″ which  allows eAccelerator  to use disk and shared memory cacche for scripts.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.shm_only = "0"&lt;/pre&gt; &lt;h2 id="eaccelerator.compress"&gt;eaccelerator.compress&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.compress"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;When using the eaccelerator_content_* api eAccelerator can compress  the  content before saving it to memory. By default this is set to “1″,  to disable  compression set it to “0″.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.compress = "1"&lt;/pre&gt; &lt;h2 id="eaccelerator.compress_level"&gt;eaccelerator.compress_level&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.compress_level"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;Compression level used for content caching. Default value is “9″  which is the  maximum compression level.&lt;/p&gt; &lt;pre class="wiki"&gt;eaccelerator.compress_level = "9"&lt;/pre&gt; &lt;h2 id="eaccelerator.keyssessioncontent"&gt;eaccelerator.keys | session |  content&lt;a class="anchor" title="Link to this section" href="http://techgurulive.com/wiki/Settings#eaccelerator.keyssessioncontent"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;These settings control the places eAccelerator may cache user  content.  Possible values are:&lt;/p&gt; &lt;ul&gt;&lt;li&gt;&lt;strong&gt;shm_and_disk&lt;/strong&gt; cache data in shared memory and on  disk  (default value)&lt;/li&gt;&lt;li&gt;&lt;strong&gt;shm&lt;/strong&gt; cache data in shared memory or on disk if  shared memory  is full or data size greater then “eaccelerator.shm_max”&lt;/li&gt;&lt;li&gt;&lt;strong&gt;shm_only&lt;/strong&gt; cache data in shared memory&lt;/li&gt;&lt;li&gt;&lt;strong&gt;disk_only&lt;/strong&gt; cache data on disk&lt;/li&gt;&lt;li&gt;&lt;strong&gt;none&lt;/strong&gt; don’t cache data&lt;/li&gt;&lt;/ul&gt; &lt;pre class="wiki"&gt;eaccelerator.keys     = "shm_and_disk"&lt;br /&gt;eaccelerator.sessions = "shm_and_disk"&lt;br /&gt;eaccelerator.content  = "shm_and_disk"&lt;/pre&gt; &lt;h2 id="Thewebinterface"&gt;The webinterface&lt;a class="anchor" title="Link  to this section" href="http://techgurulive.com/wiki/Settings#Thewebinterface"&gt;&lt;br /&gt;&lt;/a&gt;&lt;/h2&gt; &lt;p&gt;eAccelerator can be managed through a webinterface. From version  0.9.5 this  webinterface has been fully implemented in php so the  settings have been  changed.&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;taken from : http://techgurulive.com/2009/02/02/how-to-install-and-configure-the-eaccelerator-php-cache-on-apache/&lt;/p&gt;&lt;p&gt;Belum sempat nerjemahin.. ntar aja soale lagi seru coba2&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;p&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-2322287513002322192?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/2322287513002322192/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=2322287513002322192' title='4 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2322287513002322192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2322287513002322192'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/07/install-eaccelerator-di-freebsd.html' title='install eaccelerator di freebsd'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-664401755837315983</id><published>2010-07-14T12:08:00.000+07:00</published><updated>2010-07-14T12:09:13.714+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='www'/><title type='text'>Generate pdf problem</title><content type='html'>Pernah mengalami generate file dari script php ke pdf dan tidak berhasil?&lt;br /&gt;padahal jika dilocalhost yg memakai xamp berjalan normal.&lt;br /&gt;&lt;br /&gt;Setelah saya cek lebih lanjut ternyata jika record yg digenerate tidak begitu banyak, dibawah 100 record berhasil.&lt;br /&gt;Nah lo, mulai berpikir.. apa mgkn konfigurasi buffer file atau cache file di php.ini nya atau webserver confignya.&lt;br /&gt;&lt;br /&gt;Setelah mencoba mengulik2, alhamdulillah ketemu.Ini dia, dengan memory limit 96MB, maka generate 2ribu record berhasil dieksekusi. Tinggal disesuaikan dgn kebutuhan saja.&lt;br /&gt;&lt;br /&gt;; Maximum amount of memory a script may consume (128MB)&lt;br /&gt;; http://php.net/memory-limit&lt;br /&gt;memory_limit = 96M&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-664401755837315983?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/664401755837315983/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=664401755837315983' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/664401755837315983'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/664401755837315983'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/07/generate-pdf-problem.html' title='Generate pdf problem'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-7978631437970698425</id><published>2010-06-26T11:24:00.004+07:00</published><updated>2010-06-26T11:27:52.359+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='freebsd'/><category scheme='http://www.blogger.com/atom/ns#' term='snmp'/><category scheme='http://www.blogger.com/atom/ns#' term='mrtg'/><title type='text'>libperl.so not found.</title><content type='html'>Snmp tiba2 ngga jalan. errornya gini :&lt;br /&gt;/libexec/ld-elf.so.1: Shared object "libperl.so" not found, required by "libnetsnmphelpers.so.20"&lt;br /&gt;&lt;br /&gt;Hmm file library ga nemu pathnya.. kalo ga abis upgrade2 paling yo kedelete..&lt;br /&gt;Solusinya coba cari sbb :&lt;br /&gt;&lt;br /&gt;server2# &lt;span style="font-weight:bold;"&gt;ldd /usr/local/sbin/snmpd&lt;/span&gt;&lt;br /&gt;/usr/local/sbin/snmpd:&lt;br /&gt;        libnetsnmpagent.so.20 =&gt; /usr/local/lib/libnetsnmpagent.so.20 (0x2807e000)&lt;br /&gt;        libnetsnmphelpers.so.20 =&gt; /usr/local/lib/libnetsnmphelpers.so.20 (0x280b5000)&lt;br /&gt;        libnetsnmpmibs.so.20 =&gt; /usr/local/lib/libnetsnmpmibs.so.20 (0x280d3000)&lt;br /&gt;        libperl.so =&gt; /usr/local/lib/libperl.so (0x281b3000)&lt;br /&gt;        libm.so.4 =&gt; /lib/libm.so.4 (0x282b4000)&lt;br /&gt;        libcrypt.so.3 =&gt; /lib/libcrypt.so.3 (0x282ca000)&lt;br /&gt;        libutil.so.5 =&gt; /lib/libutil.so.5 (0x282e2000)&lt;br /&gt;        libnetsnmp.so.20 =&gt; /usr/local/lib/libnetsnmp.so.20 (0x282ee000)&lt;br /&gt;        libkvm.so.3 =&gt; /lib/libkvm.so.3 (0x2838d000)&lt;br /&gt;        libcrypto.so.4 =&gt; /lib/libcrypto.so.4 (0x28394000)&lt;br /&gt;        libc.so.6 =&gt; /lib/libc.so.6 (0x28487000)&lt;br /&gt;        libcrypto.so.7&lt;br /&gt;server2#&lt;span style="font-weight:bold;"&gt;cp /usr/local/lib/perl5/5.8.9/mach/CORE/libperl.so /usr/local/lib&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;server2# snmpd&lt;br /&gt;server2# ps ax | grep snmpd&lt;br /&gt;8945  ??  S      0:00.11 snmpd&lt;br /&gt;&lt;br /&gt;Alhamdulillah oke..&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-7978631437970698425?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/7978631437970698425/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=7978631437970698425' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7978631437970698425'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7978631437970698425'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/06/libperlso-not-found.html' title='libperl.so not found.'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-1812412873450744215</id><published>2010-05-24T10:00:00.000+07:00</published><updated>2010-05-24T10:01:25.478+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Disable SELINUX</title><content type='html'>Here is the way to disable selinux:&lt;br /&gt;&lt;br /&gt;1-Edit /etc/selinux/config and set the SELINUX variable to 'disabled'&lt;br /&gt;2-Use the setenforce command to disable on-the-fly&lt;br /&gt;&lt;br /&gt;With solution 1, your changes are permanent but only effective if you reboot the machine.&lt;br /&gt;&lt;br /&gt;With solution 2, your changes are NOT permanent but effective immediately.&lt;br /&gt;&lt;br /&gt;Hope this clears it up :-).&lt;br /&gt;&lt;br /&gt;taken from : http://www.linuxquestions.org&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-1812412873450744215?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/1812412873450744215/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=1812412873450744215' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/1812412873450744215'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/1812412873450744215'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/05/disable-selinux.html' title='Disable SELINUX'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-4251955348274321350</id><published>2010-05-07T10:59:00.001+07:00</published><updated>2010-05-07T10:59:53.050+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>SE Linux</title><content type='html'>Install SE Linux &lt;br /&gt;&lt;br /&gt;# apt-get install selinux-basics selinux-policy-default&lt;br /&gt;# reboot&lt;br /&gt;# nano /etc/default/rcS&lt;br /&gt;edit FSCKFIX=yes&lt;br /&gt;# nano /etc/cron.daily/mlocate (digunakan agar locate database tidak berjalan terus)&lt;br /&gt;tambahkan exit 0 pd baris ke 2&lt;br /&gt;&lt;br /&gt;Jika sudah selesai ketikkan :&lt;br /&gt;# check-selinux-installation&lt;br /&gt;# rm /var/run/motd&lt;br /&gt;# ln -s /etc/motd.baru /etc/motd&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-4251955348274321350?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/4251955348274321350/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=4251955348274321350' title='1 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/4251955348274321350'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/4251955348274321350'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/05/se-linux.html' title='SE Linux'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-2709301593115451657</id><published>2010-05-06T12:02:00.004+07:00</published><updated>2010-05-06T12:17:35.681+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='security'/><title type='text'>Security Linux</title><content type='html'>1. Matikan dan buang service2 yang tidak perlu.&lt;br /&gt;bisa install rcconf u/ mengatur startup.&lt;br /&gt;dan apt-get remove packagegakpenting&lt;br /&gt;&lt;br /&gt;2. Edit partisi, matikan eksekusi untuk partisi dimana user menaruh data (terutama web server)&lt;br /&gt;&lt;br /&gt;3. Ubah file descriptor di sysctl.conf &lt;br /&gt;your file descriptor must be beyond 65535&lt;br /&gt;&lt;br /&gt;4. Upgrade ke kernel paling baru.&lt;br /&gt;&lt;br /&gt;5. Atur firewall se secure mungkin. Allow port yang diperlukan saja.&lt;br /&gt;&lt;br /&gt;6. Atur akses login user.&lt;br /&gt;&lt;br /&gt;7. Sebisa mungkin jangan gunakan default port.&lt;br /&gt;&lt;br /&gt;8. Disable root login from remote&lt;br /&gt;&lt;br /&gt;9. Edit motd.&lt;br /&gt;&lt;br /&gt;10. Coba main2 dgn sysctl.conf (beware, resiko ditanggung sendiri).&lt;br /&gt;&lt;br /&gt;11. Secure kan service2 dan option pada program yg terinstall, misalnya : my.cnf, php.ini, httpd.conf, ftp.conf, snmpd.conf named.conf&lt;br /&gt;&lt;br /&gt;12. Install tool pendukung monitoring :&lt;br /&gt;- snmpd, ifstat, iptraf, snort, lsof, htop, deborphan, mtr, nikto. well why do i forget other tool in this critical moment.. &lt;br /&gt;&lt;br /&gt;Nanti ditambahkan kalau ada lagi.&lt;br /&gt;&lt;br /&gt;Thx to cakri n google. u;re all da best.&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-2709301593115451657?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/2709301593115451657/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=2709301593115451657' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2709301593115451657'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/2709301593115451657'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/05/security-linux.html' title='Security Linux'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-4180078835969946033</id><published>2010-05-06T11:29:00.002+07:00</published><updated>2010-05-06T11:33:41.232+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='debian'/><title type='text'>mencari Package tidak perlu</title><content type='html'># apt-get install deborphan&lt;br /&gt;# deborphan -sz&lt;br /&gt;# apt-get remove namapackage &lt;br /&gt;atau &lt;br /&gt;# apt-get remove --purge $(deborphan)&lt;br /&gt;atau bisa juga&lt;br /&gt;# orphaner&lt;br /&gt;perintah di atas ada tampilan grafisnya ;)&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-4180078835969946033?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/4180078835969946033/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=4180078835969946033' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/4180078835969946033'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/4180078835969946033'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/05/mencari-package-tidak-perlu.html' title='mencari Package tidak perlu'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-8971838674320191717</id><published>2010-04-29T09:58:00.002+07:00</published><updated>2010-04-29T10:00:48.467+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='cisco'/><title type='text'>Cisco2an</title><content type='html'># sh run&lt;br /&gt;# conf term&lt;br /&gt;# int Fastethernet0/1&lt;br /&gt;# [config] ip address 10.10.10.1 255.255.255.240 secondary&lt;br /&gt;# exit&lt;br /&gt;# exit&lt;br /&gt;# copy run start&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;# sh vlan&lt;br /&gt;# conf term&lt;br /&gt;# int Fastethernet0/1&lt;br /&gt;dst2.. lali..&lt;br /&gt;&lt;br /&gt;postingan ini hanya buat nyubie yg belajar cisco tanpa arah&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-8971838674320191717?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/8971838674320191717/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=8971838674320191717' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/8971838674320191717'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/8971838674320191717'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/04/cisco2an.html' title='Cisco2an'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-8521482356375470722</id><published>2010-03-31T14:40:00.004+07:00</published><updated>2010-03-31T14:45:14.453+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='FTP'/><category scheme='http://www.blogger.com/atom/ns#' term='mysql'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><title type='text'>PureFTPd di Linux.</title><content type='html'>Hari ini nyoba install via tarball, yg q jadikan eksperimen adalah pureftpd.&lt;br /&gt;&lt;br /&gt;1. Download Source &lt;br /&gt; wget http://download.pureftpd.org/pub/pure-ftpd/releases/pure-ftpd-1.0.29.tar.gz&lt;br /&gt;2. Ekstrak&lt;br /&gt;tar -xzvf pure-ftpd-1.0.29.tar.gz&lt;br /&gt;3. masuk ke directory hasil ekstrak&lt;br /&gt;4. ./configure &lt;br /&gt;&lt;br /&gt;Nah lo..koq pas configure error. :(&lt;br /&gt;Ternyata compiler gak support, jadi harus install dulu&lt;br /&gt;&lt;br /&gt;apt-get install gcc&lt;br /&gt;apt-get install g++&lt;br /&gt;&lt;br /&gt;Ulangi lagi deh configurenya, kemudian lanjutkan dgn perintah make &amp;&amp; make install&lt;br /&gt;&lt;br /&gt;kelanjutannya ada di postingan &lt;a href="http://runia2001.blogspot.com/2007/05/pyurftp-p.html"&gt;ini&lt;/a&gt; &lt;br /&gt;&lt;br /&gt;Bagi yang compile dgn support mysql coba install dulu mysql-devel&lt;br /&gt;apt-get mysql-devel&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-8521482356375470722?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/8521482356375470722/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=8521482356375470722' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/8521482356375470722'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/8521482356375470722'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/03/pureftpd-di-linux.html' title='PureFTPd di Linux.'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-20127583.post-7100452836913484624</id><published>2010-03-25T11:08:00.002+07:00</published><updated>2010-03-25T11:23:23.711+07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='instalasi'/><category scheme='http://www.blogger.com/atom/ns#' term='linux'/><category scheme='http://www.blogger.com/atom/ns#' term='mrtg'/><category scheme='http://www.blogger.com/atom/ns#' term='NMS'/><title type='text'>Install Snmpd..</title><content type='html'>Install snmpd cara praktis aja ya..&lt;br /&gt;# apt-get install snmpd (linux)&lt;br /&gt;# pkg_add -rv net-snmpd (fbsd)&lt;br /&gt;&lt;br /&gt;Stl itu copy file konfigurasi :&lt;br /&gt;# cp /etc/snmp/snmpd.conf.orig /etc/snmp/snmpd.conf (linux)&lt;br /&gt;# cp /usr/local/share/snmpd/snmpd.conf.example /usr/local/share/snmpd/snmpd.conf (bsd)&lt;br /&gt;&lt;br /&gt;Edit /etc/snmp/snmpd.conf :&lt;br /&gt;com2sec local  localhost         public&lt;br /&gt;com2sec local ipmrtgserver       public&lt;br /&gt;&lt;br /&gt;Edit /etc/default/snmpd : (freebsd ga perlu proses ini)&lt;br /&gt;remove ip 127.0.0.1&lt;br /&gt;&lt;br /&gt;Restart snmp : /etc/init.d/snmpd restart&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/20127583-7100452836913484624?l=runia2001.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://runia2001.blogspot.com/feeds/7100452836913484624/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=20127583&amp;postID=7100452836913484624' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7100452836913484624'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/20127583/posts/default/7100452836913484624'/><link rel='alternate' type='text/html' href='http://runia2001.blogspot.com/2010/03/install-snmpd.html' title='Install Snmpd..'/><author><name>ainoer</name><uri>http://www.blogger.com/profile/01330647731817385931</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
