Unix

Updating Clamav

I install clamav from ports and get error message that said my definition older than 7 days.

After trying manual update, I see something icon smile Updating Clamav

jedimaster# /usr/local/bin/freshclam –verbose
Current working dir is /var/db/clamav
Max retries == 3
ClamAV update process started at Mon Jul 23 16:44:22 2007
Querying current.cvd.clamav.net
TTL: 300
WARNING: DNS record is older than 3 hours.
WARNING: Invalid DNS reply. Falling back to HTTP mode.
If-Modified-Since: Fri, 13 Jul 2007 15:01:34 GMT
Reading CVD header (main.cvd): Connected to database.clamav.net (IP: 222.124.18.201).
Trying to retrieve CVD header of http://database.clamav.net/main.cvd
OK
Retrieving http://database.clamav.net/main-44.cdiff
Trying to download http://database.clamav.net/main-44.cdiff (IP: 222.124.18.201)
Downloading main-44.cdiff [100%]
cdiff_apply: Parsed 28691 lines and executed 28691 commands
main.cvd updated (version: 44, sigs: 133163, f-level: 20, builder: sven)
WARNING: Your ClamAV installation is OUTDATED!
WARNING: Current functionality level = 16, recommended = 20
DON’T PANIC! Read http://www.clamav.net/support/faq
Assuming modification time in the past
If-Modified-Since: Mon, 27 Dec 2004 03:52:10 GMT
Reading CVD header (daily.cvd): Connected to database.clamav.net (IP: 222.124.18.201).
Trying to retrieve CVD header of http://database.clamav.net/daily.cvd
OK
Retrieving http://database.clamav.net/daily-3697.cdiff
Trying to download http://database.clamav.net/daily-3697.cdiff (IP: 222.124.18.201)
ERROR: getfile: daily-3697.cdiff not found on remote server (IP: 222.124.18.201)
ERROR: getpatch: Can’t download daily-3697.cdiff from database.clamav.net
Retrieving http://database.clamav.net/daily-3697.cdiff
Trying to download http://database.clamav.net/daily-3697.cdiff (IP: 222.124.18.201)
ERROR: getfile: daily-3697.cdiff not found on remote server (IP: 222.124.18.201)
ERROR: getpatch: Can’t download daily-3697.cdiff from database.clamav.net
Retrieving http://database.clamav.net/daily-3697.cdiff
Trying to download http://database.clamav.net/daily-3697.cdiff (IP: 222.124.18.201)
ERROR: getfile: daily-3697.cdiff not found on remote server (IP: 222.124.18.201)
ERROR: getpatch: Can’t download daily-3697.cdiff from database.clamav.net
WARNING: Incremental update failed, trying to download daily.cvd
Retrieving http://database.clamav.net/daily.cvd
Trying to download http://database.clamav.net/daily.cvd (IP: 222.124.18.201)
Downloading daily.cvd [100%]
Removing incremental directory daily.inc
Removing backup directory ./clamav-0fe9f7e2e016493cc3a194fb862a06f7
daily.inc updated (version: 3741, sigs: 6959, f-level: 16, builder: ccordes)
Database updated (140122 signatures) from database.clamav.net (IP: 222.124.18.201)

WARNING: Clamd was NOT notified: Can’t connect to clamd through /var/run/clamav/clamd
connect(): No such file or directory

jedimaster# cd /var/run/clamav/
jedimaster# ls
jedimaster# whereis clamd
clamd: /usr/local/sbin/clamd /usr/local/man/man8/clamd.8.gz /usr/ports/security/clamav/work/clamav-0.90.3/clamd
jedimaster# ln -s /usr/local/sbin/clamd /var/run/clamav/clamd
jedimaster#

Trying update :
jedimaster# /usr/local/bin/freshclam –verbose
Current working dir is /var/db/clamav
Max retries == 3
ClamAV update process started at Mon Jul 23 16:46:16 2007
Querying current.cvd.clamav.net
TTL: 187
WARNING: DNS record is older than 3 hours.
WARNING: Invalid DNS reply. Falling back to HTTP mode.
Assuming modification time in the past
If-Modified-Since: Mon, 27 Dec 2004 03:52:10 GMT
Reading CVD header (main.cvd): Ignoring mirror 222.124.18.201 (too often connections with outdated version)
Trying host database.clamav.net (193.1.193.64)…
Connected to database.clamav.net (IP: 193.1.193.64).
Trying to retrieve CVD header of http://database.clamav.net/main.cvd
OK
main.inc is up to date (version: 44, sigs: 133163, f-level: 20, builder: sven)
WARNING: Current functionality level = 16, recommended = 20
Please check if ClamAV tools are linked against proper version of libclamav
DON’T PANIC! Read http://www.clamav.net/support/faq
If-Modified-Since: Mon, 23 Jul 2007 16:44:32 GMT
Reading CVD header (daily.cvd): Connected to database.clamav.net (IP: 193.1.193.64).
Trying to retrieve CVD header of http://database.clamav.net/daily.cvd
OK
daily.cvd is up to date (version: 3741, sigs: 6959, f-level: 16, builder: ccordes)

Make symlink to clamd fixed the problem.

Hmmm… it’s work, other message will be identified soon icon smile Updating Clamav

 

Unix

trying portsnap

With recent freebsd 6.2 stable installation I like to try portsnap. Since it’s already in base, no need to install this program icon smile trying portsnap

Just trying it icon smile trying portsnap

alamster# portsnap fetch
Looking up portsnap.FreeBSD.org mirrors… 3 mirrors found.
Fetching public key from portsnap3.FreeBSD.org… done.
Fetching snapshot tag from portsnap3.FreeBSD.org… done.
Fetching snapshot metadata… done.
Fetching snapshot generated at Sun Jul 22 00:35:13 UTC 2007:
488520ca868e6c935f35667a1c969541f0996cb51776fc100% of   48 MB   66 kBps 00m00s
Extracting snapshot… done.
Verifying snapshot integrity… done.
Fetching snapshot tag from portsnap3.FreeBSD.org… done.
Fetching snapshot metadata… done.
Updating from Sun Jul 22 00:35:13 UTC 2007 to Sun Jul 22 11:58:18 UTC 2007.
Fetching 3 metadata patches.. done.
Applying metadata patches… done.
Fetching 0 metadata files… done.
Fetching 43 patches…..10….20….30….40. done.
Applying patches… done.
Fetching 0 new ports or files… done.

alamster# portsnap extract
……………………..
………………

/usr/ports/audio/cplay/
/usr/ports/audio/cpp-xmms2/
/usr/ports/audio/crip/
/usr/ports/audio/csound-manual/
/usr/ports/audio/csound/
/usr/ports/audio/cue2toc/
/usr/ports/audio/cuetools/
/usr/ports/audio/cymbaline/
/usr/ports/audio/cynthiune/
/usr/ports/audio/daapd/
/usr/ports/audio/daaplib/
/usr/ports/audio/dagrab/
/usr/ports/audio/dap/
/usr/ports/audio/darkice/
/usr/ports/audio/dekagen/
………………………
……………………
/usr/ports/x11/yalias/
/usr/ports/x11/yelp/
/usr/ports/x11/zenity/
Building new INDEX files… done.

alamster# pkg_info
pkg_info: no packages installed

great, I don’t have to install cvsup for updating ports icon smile trying portsnap

but hey, csup already in base too. Only need ports-supfile and stable-supfile.

Let portsnap work for ports and csup work for source file.

Very handy end neat tools

thanks FreeBSD icon smile trying portsnap

PHP Unix

Install gd support in php without xorg

Recent upgrade to php 5.2.3 require to install gd support too but it always need xorg. Here’s a lttle note on how to add gd support in php5 ports in freebsd without xorg.

1. Checking installed php extension

proxy# pkg_info | grep php5
php5-5.2.3          PHP Scripting Language (Apache Module and CLI)
php5-bz2-5.2.3      The bz2 shared extension for php
php5-ctype-5.2.3    The ctype shared extension for php
php5-curl-5.2.3     The curl shared extension for php
php5-dom-5.2.3      The dom shared extension for php
php5-ftp-5.2.3      The ftp shared extension for php
php5-iconv-5.2.3    The iconv shared extension for php
php5-imap-5.2.3     The imap shared extension for php
php5-pcre-5.2.3     The pcre shared extension for php
php5-simplexml-5.2.3 The simplexml shared extension for php
php5-spl-5.2.3      The spl shared extension for php

2. Find php5-gd and install it.

proxy# whereis php5-gd
php5-gd: /usr/ports/graphics/php5-gd
proxy# cd /usr/ports/graphics/php5-gd && make clean
===>  Cleaning for php5-gd-5.2.3

proxy# cd /usr/ports/graphics/php5-gd && make install

===>  Vulnerability check disabled, database not found
===>  Found saved configuration for php5-gd-5.2.3
===>  Extracting for php5-gd-5.2.3
=> MD5 Checksum OK for php-5.2.3.tar.bz2.
=> SHA256 Checksum OK for php-5.2.3.tar.bz2.
===>  Patching for php5-gd-5.2.3
===>  Applying FreeBSD patches for php5-gd-5.2.3
===>   php5-gd-5.2.3 depends on executable in : phpize – found
===>   php5-gd-5.2.3 depends on file: /usr/local/bin/autoconf259 – found
===>   php5-gd-5.2.3 depends on shared library: freetype.9 – not found
===>    Verifying install for freetype.9 in /usr/ports/print/freetype2

wow, alot of things it will installed and tend to install xorg icon sad Install gd support in php without xorg

read more »

Unix

PC-BSD 1.4 beta – Release name: da Vinci

After months of hard work, the PC-BSD team is pleased to make available the 1.4 BETA release. This version includes many exciting new features and software, such as:

  • 3D desktop support via Beryl
  • KDE 3.5.7
  • FreeBSD 6.2
  • Xorg 7.2
  • New GUI tools & utilities
  • Optional Components, and much more

Changelog :

PCBSD 1.4 BETA  – Changelog
7-20-07 (Kris Moore)
————————–
 * Updated FreeBSD base OS to 6.2-STABLE
 * Updated Xorg to version 7.2
 * Updated KDE to 3.5.7
 * Includes support for Flash7 in native BSD browsers. (Konq, Opera, FireFox)
 * Includes official NVIDIA drivers to simplify activating HW acceleration.
 * Optional 3D desktop using Beryl
 * Improved & Simplified system installer, now with the ability to load optional components from CD2
 * NEW! Network configuration manager, including tray apps for WIFI and ethernet connections
 * NEW! Firewall Manager, enables easy GUI configuration of firewall Settings
 * NEW! Xorg GUI Configuration tool, allows easy setup of screen resolution & 3D support
 * NEW! Added support to Add / Remove programs tool to easily install optional KDE / System components
 * NEW! User manager GUI
 * NEW! Battery Tray Application for Laptops
 * Numerous fixes / tweaks to KDE configuration, making downloading & running PBIs easier
 * Numerous other fixes / improvements to the core OS.


Download Link for ISO :

For other mirror, click here

PHP

php 5.2.3 upgrade more issue

Warning: session_save_path() [
href="function.session-save-path">function.session-save-path
]:
open_basedir restriction in effect.

with error reporting set, blank page won’t give anything icon sad php 5.2.3 upgrade more issue

A little work need to be done since session not working properly after upgrade php from php 4.4.7 to php 5.2.3.

After doing install and uninstall php5 ports in freebsd 6.2 box. I can see that error.

Googling more to find some clue, I have one plus solution.

The idea is overwrite session_path

just make sure these lines exist in vhost directive :

php_admin_value open_basedir  /home/student

php_value session.save_path /home/student/session

make sure session in /home/student/session exist or make symlink to a directory.

It works now icon smile php 5.2.3 upgrade more issue

PHP Unix

Upgrading to php5

Recent announcement from php.net about end support for php4 make me thinking about upgrading to php5.

All server already use latest php4 version php 4.4.7 with mysql support (4.0.27) and apache1.37

Upgrading start from student server :

1. Uninstall all related php4 ports

2. Install php5 ports

kongja# cd /usr/ports/lang/php5 && make clean
===>  Cleaning for apache-1.3.37_4
===>  Cleaning for php5-5.2.3
kongja# cd /usr/ports/lang/php5 && make install
===>  php5-5.2.3 : Your apache does not support DSO modules.
*** Error code 1

Stop in /data3/ports/lang/php5.
read more »

Unix

Finally Jeff commit SCHED_SMP work as SCHED_ULE

FreeBSD 7 release will get shaping up to be an awesome release icon smile Finally Jeff commit SCHED SMP work as SCHED ULE

From Jeff blog :

"Well 5 years ago this summer I stopped by userinfo Finally Jeff commit SCHED SMP work as SCHED ULEevan‘s house in seattle’s university district and told him I was going to write a scheduler that saturday. Today I committed my SCHED_SMP work as SCHED_ULE and I feel it finally reflects my original hopes and intentions. Much of that time was spent getting the kernel locked well enough that we could exploit some affinity. However I have experimented with a great number of schemes and ideas in the process. For now I’m satisfied. I will take a little break and work on other projects."

Thanks for your efforts Jeff  icon wink Finally Jeff commit SCHED SMP work as SCHED ULE

Need to order second CPU for preparing hehehehehe.

Web Server

1610 temperature violation detected

New server arrive, HP proliant ML 350 G4 P . With four SCSI HD.

ready to replace our old email server icon smile 1610 temperature violation detected

Just a problem that arise with heatsink that prompt message " 1610 temperature violation detected "

sighhh…

wait more than 5 minutes for cold the machine has no impact.

A few result from google lead me to this post,

After remove "sticker like" stuff  between heatsink and cpu make everything goes normal.

simple thing but make me nuts for  few days icon sad 1610 temperature violation detected

Moral of story : keep fight icon smile 1610 temperature violation detected

 

Unix

Trying gstripe

New HP server came with 4 SCSI HD, need to use it for email server. Replace old Intel Pre Server host around 3000 email account.

I’ve been playing around with gconcat for ftp server, now wanna try gstripe icon smile Trying gstripe

jedimaster# gstripe label -v email /dev/da1s1d /dev/da2s1d /dev/da3s1d
Metadata value stored on /dev/da1s1d.
Metadata value stored on /dev/da2s1d.
Metadata value stored on /dev/da3s1d.
Done.

jedimaster# newfs -U /dev/stripe/email

jedimaster# mount /dev/stripe/email /email
jedimaster# df -H
Filesystem           Size    Used   Avail Capacity  Mounted on
/dev/da0s1a           10G     65M    9.5G     1%    /
devfs                1.0k    1.0k      0B   100%    /dev
/dev/da0s1d           52G    905M     47G     2%    /home
/dev/da0s1e           16G    3.9G     10G    27%    /usr
/dev/da0s1f           62G     20M     57G     0%    /var
/dev/stripe/email    427G    4.1k    392G     0%    /email

editing /etc/fstab

# Device                Mountpoint      FStype  Options         Dump    Pass#
/dev/da0s1b             none            swap    sw              0       0
/dev/da0s1a             /               ufs     rw              1       1
/dev/da0s1d             /home           ufs     rw              2       2
/dev/da0s1e             /usr            ufs     rw              2       2
/dev/da0s1f             /var            ufs     rw              2       2
/dev/acd0               /cdrom          cd9660  ro,noauto       0       0
/dev/stripe/email       /email          ufs     rw              2       2

jedimaster# echo ‘geom_stripe_load="YES"’ >> /boot/loader.conf

testing ::

jedimaster# time dd if=/dev/zero of=/email/test.img bs=1M count=1024
1024+0 records in
1024+0 records out
1073741824 bytes transferred in 21.451587 secs (50054191 bytes/sec)
0.000u 2.677s 0:21.46 12.4%     21+2974k 33+8192io 0pf+0w

hmmm….

is it scsi thing or I left something?

Links :

FreeBSD Gstripe

Interesting to see ZFS in action, I’ll try it too.

Blog Software

more exploring massive keyword list builder

More exploring massive keyword list builder lead me to a bunch of information icon smile more exploring massive keyword list builder

 more exploring massive keyword list builder 

 more exploring massive keyword list builder

Click this icon you’ll get a lot of infos :

Keyword tools subdirectory :

 more exploring massive keyword list builder

Link analysis tools :

read more »

Software

pdf spam, reincarnation of image spam?

gmail is great, when my old email server suffering with email pdf spam. Spam folder in gmail already filled with this pdf type  icon smile pdf spam, reincarnation of image spam?

Some opinion :

from securiteam :

"I have been getting lately more and more PDF based spam, the PDF itself appears to be just a cover for the normal image spam. The idea I believe is that PDF is not investigated by most spam filtering agents, and is not regarded by spam filtering as a “score giver” (i.e. what makes the email look more spamish than others)"

from heise security :

"The goal of those behind this spam is clear: the spammers purchase shares at a low price and then try to drive the price up so that they can sell at a quick profit. The companies whose stock is being promoted in this way generally do not have anything to do with such attempts at manipulation, but by the start of 2006, studies were showing that spam about company shares can actually affect share prices."

ic..ic, playing with stock for profit.

 pdf spam, reincarnation of image spam?

 

  pdf spam, reincarnation of image spam?

Maybe I should forward my other email to gmail for autoclean this spam icon smile pdf spam, reincarnation of image spam?

Links :