Linux

How to Write Secure Perl Scripts

Fadıl

Perl is the main server scripting language for web servers. It is used because of its ease of use and its power, but because of the ease of use, a power perl can be exploited. This document will tell you how to secure your web server from attacks.

Perl scripts can be identified by the outside world as they normally have .pl or .cgi extensions.
Tainting
IF you have ever seen a perl script, you will have noticed that on the first line there is the path to the perl program. eg:
#!/usr/local/bin/perl -w
The -w tells perl to give warnings if there are errors in the code. The security equivalent is to disallow insecure commands from user input. The way this works is that user input cannot execute a command, but any variable created in the script can. eg;
$input= ; STDIN is from the user, so it is considered as insecure
$untainted = "hi";
To enable this secure mode (or tainting, to call it its proper name) add -t to the line, eg; #!/usr/local/bin/perl -T or #!/usr/local/bin/perl -Tw
You can untaint a variable by putting the data it contains into a variable name $number, e.g. $input = $1; The following perl script parses user input if it doesn’t contain dangerous characters tells perl it is secure:

Mount Remote File Systems Over SSH with SSHFS

Fadıl

If you work on remotely connected machines, most likely you’re going to use SSH to secure your connections. But, what if you just want to work with files on a remote server, but find SSH file transfer tedious in repetition and establishing a VPN tunnel is too complicated?

What you’re looking for is a simple tool for mounting remote file systems easily, transparently and securely as if they were just another part of your local machine. In this hack, we’ll show you how to configure Fuse and SSHFS to access remote file systems securely over SSH.

Configuring VSFTPD server for secure connection (TLS / SSL / SFTP)

Fadıl

This article is related to FTP programs, namely VSFTPD on RPM-Based, especially CentOS. Except for installation instructions must be adjusted to the existing Linux distribution.

Traditional FTP is generally not safe, because when you log in with your username and password the transmitted data is in text form, this increases the security gap which can allow the sniffing process on your network by people who are not entitled and with it’s easy to read the data you’re transferring. Therefore there was an addition to the new security for this FTP problem. Here we will make it easy for you to create/configure your VSFTPD server using OpenSSL encryption so that your username and password and even data files will be encrypted during the transfer.

Mounting LVM partitions with rescue CD media (Fedora / CentOS / RedHat)

Fadıl

Whether you need to enlarge or shrink a partition that is usually in “/” (slash root) format LVM or just troubleshooting your Linux system, you can use the following method to mount LVM partitions through rescue mode. following the steps:
Boot the system through the rescue CD media, and do a VG scan (volume group):

root@techsoftcenter ~]# lvm vgscan -v

Activate the existing VG () volume, group:

root@techsoftcenter ~]# lvm vgchange -vy

Melihat list logical volume (LV):

Build an FTP server with vsftpd on CentOS / RHEL / Fedora

Fadıl

At this time we will implement one of the features of a Linux server, the FTP server. FTP servers, as we know, are one of the services on Linux that are more specifically for data exchange. In this article, we are building an FTP server with vsftpd on CentOS / RHEL / Fedora, where we will try to install and configure an FTP server with vSFTPD as its daemon, along with the steps:
Install vsftpd