Nikto is a web server scanner which performs comprehensive tests against web servers for multiple items, including over 3500 potentially dangerous files/CGIs, versions on over 900 servers, and version specific problems on over 250 servers.
1. Install Nikto
apt-get install nikto
2. Test the local web server
nikto -h localhost
Nikto also supports testing on different ports. Click here for Nikto usage information.
EHCP is a powerful, yet easy to install control panel that allows the user to manage services such as Web, FTP, Database and DNS servers.
The install script handles the installation and configuration of the required services. I recommend starting with a clean Debian system to avoid conflicts.
1. Download required EHCP files
wget http://www.ehcp.net/download
2. Uncompress the files
tar zxvf ehcp_latest.tgz
3. Move into the install directory and run the install script
cd ehcp
./install.sh
Read the instructions carefully, your server will send statistical information to the EHCP developers. If you choose to move on, the install script will install all required packages including Apache, MySql and Postfix. You will need to provide some information to configure the services and set the admin passwords.
4. When the installer is finished, enter the control panel using: http://yourserver.
In this tutorial we'll create a simple one-way master/slave database replication. You must have at least one master and one slave but you can use multiple slaves.
Master
1. Configure master to listen on all ip addresses (pico /etc/mysql/my.cnf)
#bind-address = 127.0.0.1
Comment out this line or remove it
2. Configure server id, log file location and which databases are allowed to be replicated (pico /etc/mysql/my.cnf)
server-id = 1
log_bin = /var/log/mysql/mysql-bin.log
binlog_do_db = {database}
Replace {database} with the one you would like to replicate
3. Restart MySql
/etc/init.d/mysql restart
4. Create a user and allow it to act as slave for this server (mysql -u root -p)
GRANT REPLICATION SLAVE ON *.* TO {username}@'{ip}' IDENTIFIED BY '{password}';
FLUSH PRIVILEGES;
{username} = Your preferred username
{password} = Your password
{ip} = IP address of the slave system or % to allow all ip addresses
5. Show current log file and position (mysql -u root -p)
SHOW MASTER STATUS;
This will return something like this:
+------------------+----------+--------------+------------------+
| File | Position | Binlog_Do_DB | Binlog_Ignore_DB |
+------------------+----------+--------------+------------------+
| mysql-bin.000004 | 2751 | {database} | |
+------------------+----------+--------------+------------------+
Keep the file name and position. It will be used later on the slave
6. Transfer data from the master to the slave
You can do this using various methods including exporting and importing using phpMyAdmin, creating a database dump from the master and import to the slave and "LOAD DATA FROM MASTER".
Slave
1. Configure this server to be a slave for the master MySql server (pico /etc/mysql/my.cnf)
server-id = 2
master-host = {master_ip}
master-user = {username}
master-password = {password}
master-connect-retry = 60
replicate-do-db = {database}
{master_ip} = The ip of the master server
{username} = The username you provided earlier on the master server
{password} = The password you provided earlier on the master server
{database} = The database you want to replicate
2. Restart MySql
/etc/init.d/mysql restart
3. Final configurations to make the slave replicate with the master (mysql -u root -p)
SLAVE STOP;
CHANGE MASTER TO MASTER_HOST='{master_ip}', MASTER_USER='{username}', MASTER_PASSWORD='{password}', MASTER_LOG_FILE='{log_file}', MASTER_LOG_POS={log_position};
SLAVE START;
{master_ip} = The ip of the master server
{username} = The username you provided earlier on the master server
{password} = The password you provided earlier on the master server
{log_file} = Log file name from the master (ex. mysql-bin.000004)
{log_position} = Log position from the master (ex. 2751)
mod_spamhaus is an Apache module for DNS Block Listing that protects web services by denying access to particular IP addresses. It can stop spam relaying via web form URL injection, and block HTTP DDoS attacks from bot-nets.
It queries sbl-xbl.spamhaus.org, taking advantage of the Spamhaus Block List (SBL) and the Exploits Block List (XBL).
1. Download the latest mod_spamhaus deb package from sid package repository (mod_spamhaus is not available for lenny but we can use the sid package)
wget http://ftp.us.debian.org/debian/pool/main/m/mod-spamhaus/libapache2-mod-spamhaus_0.7-1_i386.deb
This package is for i386. If you are using other architecture, you can find a suitable package on the bottom of this page: http://packages.debian.org/sid/libapache2-mod-spamhaus
2. Install the package
dpkg -i libapache2-mod-spamhaus_0.7-1_i386.deb
Apache is automatically restarted and the module is enabled. If you would like to test the module you can add a line to your hosts file to make it think that your IP address is blocked (pico /etc/hosts)
127.0.0.4 1.0.168.192.sbl-xbl.spamhaus.org
Replace 1.0.168.192 with your IP address and reverse it. The IP address 192.168.0.1 should read 1.0.168.192.
By default, only POST, PUT, OPTIONS, CONNECT methods are blocked. You can add GET to the list of methods blocked in /etc/apache2/mods-enabled/mod-spamhaus.conf to block the spammers from seeing your website.
HAVP (HTTP Antivirus Proxy) is a proxy with a ClamAV anti-virus scanner. The main aims are continuous, non-blocking downloads and smooth scanning of dynamic and password protected HTTP traffic. Havp antivirus proxy has a parent and transparent proxy mode. It can be used with squid or standalone.
1. Install HAVP
apt-get install havp
2. Start HAVP if it didn't start after the installation
/etc/init.d/havp start
It's ready, by default HAVP listens on port 8080. You can configure your web browser to use the server as a proxy.
You can customize the error pages by editing the html files in this directory: /etc/havp/templates/en/
apache2-mpm-itk is an MPM (Multi-Processing Module) for the Apache web server. mpm-itk allows you to run each of your vhost under a separate uid and gid — in short, the scripts and configuration files for one vhost no longer have to be readable for all the other vhosts.
1. Install the apache2-mpm-itk package
apt-get install apache2-mpm-itk
2. Configure user and group for each virtual host by adding the following line somewhere between <VirtualHost *:80>...</VirtualHost>
AssignUserId [user] [group]
Replace [user] and [group] with a username and group name that already exists on the system.
3. Change the owner of the web root
chown [user].[group] [location]
Replace [user] and [group] with the username and group name configured on the virtual host. Replace [location] with the location specified as DocumentRoot for the virtual host, eg. /var/www
4. Make sure the location isn't accessible by other users (optional)
chmod o= [location]
Replace [location] with the location specified as DocumentRoot for the virtual host, eg. /var/www
5. Restart apache
/etc/init.d/apache restart
Pure-FTPd is a free, secure, production-quality and standard-conformant FTP server. It doesn't provide useless bells and whistles, but focuses on efficiency and ease of use. It provides simple answers to common needs, plus unique useful features for personal users as well as hosting providers.
In this tutorial we'll install Pure-FTPd with MySQL backend.
Install Pure-FTPd with mysql backendapt-get install pure-ftpd-mysql
Create user and group used to run the ftp servergroupadd -g 2001 ftpgroup
useradd -u 2001 -s /bin/false -d /bin/null -c "pureftpd user" -g ftpgroup ftpuser
Create database and a table that will store user informationmysql -u root -p
GRANT SELECT ON ftpd.* TO vhosts@localhost IDENTIFIED BY 'mypasswd';
FLUSH PRIVILEGES;
CREATE DATABASE ftpd;
USE ftpd;
CREATE TABLE users (
user varchar(30) NOT NULL,
password varchar(64) NOT NULL,
home varchar(128) NOT NULL,
bandwidth_limit_upload smallint(5) NOT NULL default 0,
bandwidth_limit_download smallint(5) NOT NULL default 0,
ip_allow varchar(15) NOT NULL default 'any',
quota smallint(5) NOT NULL default '0',
quota_files int(11) NOT NULL default 0,
active enum('yes','no') NOT NULL default 'yes',
PRIMARY KEY (user),
UNIQUE KEY User (user)
) TYPE=MyISAM;
INSERT INTO users (user, password, home) VALUES ('username', MD5('mypasswd'), '/home/username');
quit;
You will be able to control bandwidth limits and quotas for each user. Using zero for these fields will allow unlimited use of resources. The bandwidth limits are specified in KB/s and the quota in MB.
Configure Pure-ftpd (pico /etc/pure-ftpd/db/mysql.conf). Remove everything from the default configuration file and add these lines:MYSQLSocket /var/run/mysqld/mysqld.sock
MYSQLUser vhosts
MYSQLPassword mypasswd
MYSQLDatabase ftpd
MYSQLCrypt md5
MYSQLDefaultUID 2001
MYSQLDefaultGID 2001
MYSQLGetPW SELECT password FROM users WHERE user = "\L" AND active = "yes" AND (ip_allow = "any" OR ip_allow LIKE "\R")
MYSQLGetDir SELECT home FROM users WHERE user = "\L"AND active = "yes" AND (ip_allow = "any" OR ip_allow LIKE "\R")
MySQLGetBandwidthUL SELECT bandwidth_limit_upload FROM users WHERE user = "\L"AND active = "yes" AND (ip_allow = "any" OR ip_allow LIKE "\R")
MySQLGetBandwidthDL SELECT bandwidth_limit_download FROM users WHERE user = "\L"AND active = "yes" AND (ip_allow = "any" OR ip_allow LIKE "\R")
MySQLGetQTASZ SELECT quota FROM users WHERE user = "\L"AND active = "yes" AND (ip_allow = "any" OR ip_allow LIKE "\R")
MySQLGetQTAFS SELECT quota_files FROM users WHERE user = "\L"AND active = "yes" AND (ip_allow = "any" OR ip_allow LIKE "\R")
Create these simple text files that will force the server to create home directories for users if they don't exist and chroot the user to it's home directory:
pico /etc/pure-ftpd/conf/ChrootEveryoneyes
pico /etc/pure-ftpd/conf/CreateHomeDiryes
Since we are using pure-ftpd-mysql insted of pure-ftpd, make the following change (pico /usr/sbin/pure-ftpd-wrapper):my $daemon = '/usr/sbin/pure-ftpd-mysql';
Restart Pure-ftpd/etc/init.d/pure-ftpd-mysql restart
We're all done. You should be able to make connections to the servers with your favorite FTP client.
--
Update - 29th October 2008
I've had problems with debian-minimal installations where the ftp server simply won't start and doesn't leave any trace in the log files. To fix that I had to make one minor change to the inetd config file (pico /etc/inetd.conf):ftp stream tcp nowait root /usr/sbin/tcpd /usr/sbin/pure-ftpd-mysql
Open the config file and in the ftp line, change pure-ftpd-wrapper to pure-ftpd-mysql
When done, restart inetd:/etc/init.d/openbsd-inetd restart
--
Update - 20th April 2010
In lenny, use this command to restart the service or change the variable STANDALONE_OR_INETD to standalone in /etc/default/pure-ftpd-common:/etc/init.d/openbsd-inetd restart
1. On the source database server run the following command to export all databases:
mysqldump -h localhost -u {username} -p --all-databases > database_dump.sql
Replace {username} with your MySql username.
You can also export a single database using this command:
mysqldump -h localhost -u {username} -p {database} > database_dump.sql
Replace {username} with your MySql username and {database} with the database you are going to export.
2. Move the database_dump.sql file to your destination server. You could grab it from FTP server or put it on a public web location and use wget on the destination server to receive the file. This process it outside the scope of this tutorial.
3. Import the dump to the destination MySql server by running the following command:
mysql -h localhost -u {username} -p < database_dump.sql
Replace {username} with your MySql username.
If you are only exporting a single database, use this command instead:
mysql -h localhost -u {username} -p {database} < database_dump.sql
Replace {username} with your MySql username and {database} with the database you are going to export.