Linux

Working with Snort Rules

Fadıl

Automatically Updating Snort Rules

There are multiple tools available to update Snort signatures. When using any of these tools you must be careful because you may accidentally modify or delete your customized rules. I shall discuss two methods of updating the rules.

The Simple Method

This method consists of a simple shell script. It requires that you have wget program installed on your system. The wget program is used to retrieve any file using the HTTP protocol. In essence, it is just like a web browser, but it retrieves one file from a command line argument.

Ubuntu Install Firefox, and Create A Shortcut

Fadıl

We’ll see how to download Firefox for Ubuntu by following the steps below.

1) Download Firefox
2) tar-xvf firefox-3.6.3.tar.bz2
3) mv firefox / opt
4) cd / usr / share / applications
5) sudo touch firefox.desktop
6) the sudo nano firefox.desktop, editorial content
[Desktop Entry]
Name = Firefox
Comment = this is firefox
Exec = / opt / firefox / firefox
Icon = / opt/firefox/icons/mozicon128.png
Terminal = false
Type = Application
Categories = Application; Network;

Linux Network Configuration Commands

Fadıl

Under Linux NIC naming rules: eth0, eth1. First Ethernet card, and the second block. lo is the loopback interface, its fixed IP address is 127.0.0.1, mask 8. It represents your machine itself.

Ifconfig is the view card information

ifconfig [Interface]

The interface is optional, and if not this information is displayed for all network cards in the system. If you add this option to display the specified card information.

For example; ifconfig eth0

How to Apply Resource Limits Via limits.conf for a Docker Container

How to Apply Resource Limits Via limits.conf for a Docker Container

Fadıl

There are several ways in which resource limits can be applied to the docker container. Majorly below 3 ways can be used to set resource limits globally or individually for each container.

Setting Global limits for all containers

1. In docker 1.6 or later, we could set ulimit in /etc/sysconfig/docker as:

# vi /etc/sysconfig/docker
OPTIONS='--insecure-registry=172.30.0.0/16 --selinux-enabled --default-ulimit nproc=1024:2048'

This will set a soft limit of 1,024 and a hard limit of 2,048 child processes for all containers.

How to Configure Openfiles Limit for Docker Containers

Fadıl

The Ask

From the docker host (CentOS 7) is possible to see that the open files limit is set to 1024.

# ulimit -a | grep open
open files    (-n) 1024

But the docker container has this limit set to 1048576

[root@e86ee2f0f6a0 /]# ulimit -a | grep open
open files   (-n) 1048576

Is it possible to change this value for the docker containers?

The Answer

The open files limit is set by default to 1048576. This limit is not related to the host’s limit. There are 2 possible way how to change this limit: