SOHO : Small Office Home Office
Freeware - Opensource software tips, tricks, tweaks & fixes for managing, securing, improving the performance of SOHO Desktop, Laptop, Networks

Sunday, April 18, 2010

How to, Tips and Tricks - ssh and scp


This tutorial is about SSH and SCP. You will learn how to connect to a remote host and how to copy between hosts. This tutorial also documents a few important differences between the commands.
Difficulty: Basic
Before we start: in this tutorial, you will come across both SSH and ssh. The difference is this: SSH is the general protocol, and ssh is the linux SSH client command.

SSH

SSH is some kind of an abbreviation of Secure SHell. It is a protocol that allows secure connections between computers. In this tutorial, we'll be dealing with the ssh command on Linux, the OpenSSH version. Most Linux distributions feature the OpenSSH client today, but if you want to be sure, have a look at the SSH manpage on your system. You can do this by typing:
[rechosen@localhost ~]$ man ssh
Note: this should be done in a terminal. This tutorial assumes that you have some basic terminal knowledge, like knowing how to start a terminal session on your system and being familiar with the basic commands and syntaxes.
If it displays something like this
NAME
ssh - OpenSSH SSH client (remote login program)
then you can be quite sure you're running the OpenSSH version. For more background information about SSH, see http://en.wikipedia.org/wiki/SSH.

The most simple case

In the most simple case, you can connect to a server that supports ssh with a syntax as short as this:
[rechosen@localhost ~]$ ssh yourserver
Note: If you do not have any ssh server nearby that you can access, you can also try this command with your own computer as a server. To do this, replace "yourserver" with "localhost".
Of course, yourserver should be replaced by a hostname or an ip address of the server you want to connect to. As you can see in the terminal snippet, I am logged in as rechosen. If you do not specify a username (I'll explain how to do that later in this tutorial), SSH will assume that you want to login with the username you're currently logged in with. So, in this case, SSH will try the username rechosen.
Of course, you need to be sure that the server supports ssh connections. The ssh client tries to connect to port 22 defaultly. This means that, if you want to connect to a remote host with the default settings, you should make sure that, if applicable, port 22 is forwarded to the server you're trying to connect to. You will find more regarding the SSH port further in this tutorial.
Now, back to the command we ran. If the server supports SSH connections and you can reach it by port 22, you should be prompted for a password (if this is the first time you try to connect to the server, ssh will first ask the question if you want to continue connecting, which can generally just be answered with a 'yes'). If you type a password here, you won't see asterisks appearing. Don't panic, this is ssh's normal behaviour. It makes connecting using ssh even more safe, because any accidental spectators won't be able to see the length of the password. After entering the password, if the username and the password were correct, you should be running a shell on the server. If not, make sure you are connecting to a server of which you know that you should be able to login with your username and the specified password. You could try connecting to your own computer (see the note beneath the terminal quote) or read on to learn how to specify an other username.
Once you're done trying the ssh shell, you can exit it by pressing Ctrl + D.

Specifying a username

It's actually quite simple to specify a different username. You might even already be familiar with it. See the following example:
[rechosen@localhost ~]$ ssh yourusername@yourserver
The above will make ssh try to connect with the username "yourusername" instead of (in my case) rechosen. This syntax is also used by a lot of other protocols, so it'll always come in handy to know it. By the way, you will still be asked for a password. For security reasons, it is not even possible to directly specify the password in the syntax. You will always be asked interactively, unless you start configuring the server in an advanced way (which is exactly why that topic is out of this tutorials scope: this tutorial documents how to use the clients, not how to configure the server).

Specifying a port

There are many reasons to move the ssh service to an other port. One of them is avoiding brute-force login attempts. Certain hackers try to get access to ssh servers by trying a lot of common usernames with common passwords (think of a user "john" with password "doe"). Although it is very unlikely that these hackers will ever get access to the system, there is an other aspect of the brute-force attacks that you'll generally want to avoid: the system and connection load. The brute-force attacks usually are done with dozens or even thousands of tries a second, and this unnecessarily slows down the server and takes some bandwidth which could've been used a lot better. By changing the port to a non-default one, the scripts of the hackers will just be refused and most of the bandwidth will be saved.
As the ssh command can't just guess the port, we will have to specify it if it's not the default 22 one. You can do that this way:
[rechosen@localhost ~]$ ssh -p yourport yourusername@yourserver
Of course, you will have to replace "yourport" with the port number. These is an important difference between ssh and scp on this point. I'll explain it further on.

Running a command on the remote server

Sometimes, especially in scripts, you'll want to connect to the remote server, run a single command and then exit again. The ssh command has a nice feature for this. You can just specify the command after the options, username and hostname. Have a look at this:
[rechosen@localhost ~]$ ssh yourusername@yourserver updatedb
This will make the server update its searching database. Of course, this is a very simple command without arguments. What if you'd want to tell someone about the latest news you read on the web? You might think that the following will give him/her that message:
[rechosen@localhost ~]$ ssh yourusername@yourserver wall "Hey, I just found out something great! Have a look at www.examplenewslink.com!"
However, bash will give an error if you run this command:
bash: !": event not found
What happened? Bash (the program behind your shell) tried to interpret the command you wanted to give ssh. This fails because there are exclamation marks in the command, which bash will interpret as special characters that should initiate a bash function. But we don't want this, we just want bash to give the command to ssh! Well, there's a very simple way to tell bash not to worry about the contents of the command but just pass it on to ssh already: wrapping it in single quotes. Have a look at this:
[rechosen@localhost ~]$ ssh yourusername@yourserver 'wall "Hey, I just found out something great! Have a look at www.examplenewslink.com!"'
The single quotes prevent bash from trying to interpret the command, so ssh receives it unmodified and can send it to the server as it should. Don't forget that the single quotes should be around the whole command, not anywhere else.

SCP

The scp command allows you to copy files over ssh connections. This is pretty useful if you want to transport files between computers, for example to backup something. The scp command uses the ssh command and they are very much alike. However, there are some important differences.
The scp command can be used in three* ways: to copy from a (remote) server to your computer, to copy from your computer to a (remote) server, and to copy from a (remote) server to another (remote) server. In the third case, the data is transferred directly between the servers; your own computer will only tell the servers what to do. These options are very useful for a lot of things that require files to be transferred, so let's have a look at the syntax of this command:
[rechosen@localhost ~]$ scp examplefile yourusername@yourserver:/home/yourusername/
Looks quite familiar, right? But there are differences. The command above will transfer the file "examplefile" to the directory "/home/yourusername/" at the server "yourserver", trying to get ssh acces with the username "yourusername". That's quite a lot information, but scp really needs it all. Well, almost all of it. You could leave out the "yourusername@" in front of "yourserver", but only if you want to login on the server with your current username on your own computer. Let's have a closer look at the end of the command. There's a colon over there, with a directory after it. Just like Linux's normal cp command, scp will need to know both the source file(s) and the target directory (or file). For remote hosts, the file(s)/directory are given to the scp command is this way.
You can also copy a file (or multiple files) from the (remote) server to your own computer. Let's have a look at an example of that:
[rechosen@localhost ~]$ scp yourusername@yourserver:/home/yourusername/examplefile .
Note: The dot at the end means the current local directory. This is a handy trick that can be used about everywhere in Linux. Besides a single dot, you can also type a double dot ( .. ), which is the parent directory of the current directory.
This will copy the file "/home/yourusername/examplefile" to the current directory on your own computer, provided that the username and password are correct and that the file actually exists.
You probably already guessed that the following command copies a file from a (remote) server to another (remote) server:
[rechosen@localhost ~]$ scp yourusername@yourserver:/home/yourusername/examplefile yourusername2@yourserver2:/home/yourusername2/
Please note that, to make the above command work, the servers must be able to reach each other, as the data will be transferred directly between them. If the servers somehow can't reach each other (for example, if port 22 is not open on one of the sides) you won't be able to copy anything. In that case, copy the files to your own computer first, then to the other host. Or make the servers able to reach each other (for example by opening the port).
Well, those are the main uses of scp. We'll now go a bit more in-depth about the differences between ssh and scp.
*: Actually you can also use it just like the normal cp command, withhout any ssh connections in it, but that's quite useless. It requires you to type an extra 's' =).

Specifying a port with scp

The scp command acts a little different when it comes to ports. You'd expect that specifying a port should be done this way:
[rechosen@localhost ~]$ scp -p yourport yourusername@yourserver:/home/yourusername/examplefile .
However, that will not work. You will get an error message like this one:
cp: cannot stat `yourport': No such file or directory
This is caused by the different architecture of scp. It aims to resemble cp, and cp also features the -p option. However, in cp terms it means 'preserve', and it causes the cp command to preserve things like ownership, permissions and creation dates. The scp command can also preserve things like that, and the -p option enables this feature. The port specification should be done with the -P option. Therefore, the following command will work:
[rechosen@localhost ~]$ scp -P yourport yourusername@yourserver:/home/yourusername/examplefile .
Also note that the -P option must be in front of the (remote) server. The ssh command will still work if you put -p yourport behind the host syntax, but scp won't. Why? Because scp also supports copying between two servers and therefore needs to know which server the -P option applies to.

Another difference between scp and ssh

Unlike ssh, scp cannot be used to run a command on a (remote) server, as it already uses that feature of ssh to start the scp server on the host. The scp command does have an option that accepts a program (the -S option), but this program will then be used instead of ssh to establish the encrypted connection, and it will not be executed on the remote host.

Tips & Tricks with ssh and scp

Quite a handy thing about scp is that it supports asterisks. You can copy all files in a remote directory in a way like this:
[rechosen@localhost ~]$ scp yourusername@yourserver:/home/yourusername/* .
And you can also just copy a whole directory by specifying the -r (recursive) option:
[rechosen@localhost ~]$ scp -r yourusername@yourserver:/home/yourusername/ .
Both of these also work when copying to a (remote) server or copying between a (remote) server and another (remote) server.
The ssh command can come in handy if you don't know the exact location of the file you want to copy with scp. First, ssh to the (remote) server:
[rechosen@localhost ~]$ ssh yourusername@yourserver
Then browse to the right directory with cd. This is essential Linux terminal knowledge, so I won't explain it here. When you're in the right directory, you can get the full path with this command:
[rechosen@localhost ~]$ pwd
Note: pwd is an abbreviation of Print Working Directory, which is a useful way to remember the command.
You can then copy this output, leave the ssh shell by pressing Ctrl + D, and then paste the full directory path in your scp command. This saves a lot of remembering and typing!
You can also limit the bandwidth scp may use when copying. This is very useful if you're wanting to copy a huge amount of data without suffering from slow internet for a long time. Limiting bandwidth is done this way:
scp -l bandwidthlimit yourusername@yourserver:/home/yourusername/* .
The bandwidth is specified in Kbit/sec. What does this mean? Eight bits is one byte. If you want to copy no faster than 10 Kbyte/sec, set the limit to 80. If you want to copy no faster than 80 Kbyte/sec, set the limit to 640. Get it? You should set the limit to eight times the maximum Kbyte/sec you want it to be. I'd recommend to set the -l option with all scp'ing you do on a connection that other people need to use, too. A big amount of copying can virtually block a whole 10 Mbit network if you're using hubs.

source : http://www.linuxtutorialblog.com/post/ssh-and-scp-howto-tips-tricks
Continue Reading...

Friday, April 16, 2010

Linux Bash script – How to read a linux file – script


Here is the sample script to how how to read an unix or linux file using shell script:
First Method – Assumption mydatafile.txt exists in the same directory:
#!/bin/sh
FILENAME="mydatafile.txt"
while read line
do
echo $line
done < $FILENAME
Second Method – Assumption mydatafile.txt exists in the same directory:
#!/bin/sh
FILENAME="mydatafile.txt"
LN=0
cat $FILENAME ‘ while read FILE_NAME
do
LN=$(($LN + 1))
echo "Line $LN=$FILE_NAME"
done
Continue Reading...

Working quicker in Ubuntu by using bash scripts

I’m sure that there are a couple of commands you use on a regular basis when working in Ubuntu. I for instance often open the file browser by pressing ALT+F2 and entering ‘gksu nautilus’ which opens the file browser as root. The same goes for the ‘gksu gnome-terminal’ command. Entering commands with ALT+F2 is cool and all but when the commands start to leave a lot of room for typo’s it can be annoying.

I knew that I could make bash scripts in Linux to execute certain commands so I figured I’d simply make some bash scripts for these commands. The way to do that is like so:

Press ALT+F2 and enter ‘gksu gedit /usr/local/bin/sunau’. This opens the text editor with new file called ’sunau’ in the location /usr/local/bin. We’ll make a script in this file that opens the file browser as root. Enter the following into the empty file:

#!/bin/bash
gksu nautilus

Now save the script and close the editor. The only thing left now is to make the script executable. Press ALT+F2 again and enter ’sudo chmod +x /usr/local/bin/sunau’. After this you can call your script by pressing ALT+F2 and entering ’sunau’. This will start the file browser as root. By changing the contents of the file you can execute all kinds of commands with bash scripts.
Continue Reading...

Monday, April 12, 2010

Knife bevel angel explained



Type of Knife or ToolRecommended Angle
  • Cleaver
  • Machete

    30 - 35 Degrees
    • Hunting Knives
    • Pocket Knives
    • Survival Knives
    • Sport Knives

      25 - 30 Degrees
      • Chef's Knives
      • Kitchen Knives
      • Smaller Knives
      • Boning Knives
      • Carving Knives

        18 - 25 Degrees
        • Fillet Knives
        • Paring Knives
        • Razors
        • X-Acto Knives

          12 - 18 Degrees





          More Advice And Theory On Sharpening Angles For Knives




          We have found that many customers really want to know more about selecting the angle for their knife. In this article we will discuss in more detail why you may want to choose one angle over another.



          Before getting into the detail, we’d like to make it clear how we talk about the angles on a knife. Most knives have a bevel on both sides. When we tell someone that they should put a 20 degree angle on a knife, we mean that they should sharpen each side to 20 degrees. This creates a total angle of 40 degrees. So when we’re talking about the angle on your knife, we’re talking about the angle at which you hold the knife to your stone.




          There are special cases where the total angle of the knife is not double the angle that you sharpen each side of your knife. Some traditional Asian knives are only beveled on one side. In this example, one side may be sharpened to 20 degrees while the other side is at 0 degrees for a total angle of 20. However, in practice, we have found that the vast majority of Asian knives sold in the United States are not single bevel but rather traditional knives with a bevel on both sides. If you’re not sure, it is generally safe to assume that your knife has a bevel on both sides. Asian knives do typically have a slightly lower angle and both sides are sharpened to roughly 17 degrees.


          Choosing and angle to sharpen your knife is essentially a compromise between the sharpness and the durability of an edge. The most important factor when determining the angle comes down to how you will be using your knife. Will you be shaving your face, filleting a fish, cutting vegetables, carving or chopping wood? From these examples, it is easy to see how each case requires a different edge.


          Hardness vs. Toughness
          Many people enjoy having a very high quality knife and appreciate good steels. Regardless of the steel, certain facts of steel hardness still apply. The hardness of steel is very easy to understand and is measured on a scale called the Rockwell C Scale. The toughness in metallurgy is the materials ability to withstand fracture. A simple example of a material that is very hard but not tough is glass. Given the same knife, making it harder will reduce its toughness. When a knife maker heat treats steel, they must strike a balance between hardness and toughness. Too hard and it could break easily, too soft and it won’t hold an edge. The compromise between hardness and toughness in knife making is very similar to the compromise in choosing a sharpening angle.




          Under 10 Degree Angles
          The lowest angles are reserved for edges that are typically cutting softer materials. In this case, the edges are not subject to abuse so the lower angle can be maintained without damage or edge failure. The lowest angles that we typically see are on straight edge razors. These are sharpened to an angle which is roughly 7 to 8 degrees (although the back of the blade is used as a guide so knowing the angle isn’t important and nor is it adjustable). A straight razor has a very delicate edge that is very easy to damage. In proper usage, a straight razor would never see the type of use that would damage the edge.





          10 to 17 Degrees Angles
          A sharpening angle of 10 to 17 degrees is still quite low for most knives. With a total angle of 20 to 34 degrees, this is still a very fine edge. This edge is typically too weak for any knife that might be used in any type of chopping motion. Also consider that harder steels are also more susceptible to impact damage because they are more brittle. If your knife is used for cutting soft items or slicing meats, this lower angle can hold up and provide a very smooth cutting action.





          17 to 22 Degree Angles
          A 17 to 20 degree angle covers most kitchen knives. Some knives (typically Japanese manufacturers) will sharpen their knives to roughly 17 degrees. Most western knives are roughly 20 degrees. It is our experience that kitchen knives sharpened to 15 to 20 degrees cut very well and are still durable. These angles are still not highly durable as a total angle under 40 degrees will not respond well to rougher treatment in harder materials.





          22 to 30 Degree Angles
          In this range, the knife edges are considerably more durable. A pocket knife or a hunting knife will inevitably see abuse not seen by knives meant primarily for slicing or chopping softer materials. While the edge may not ultimately be cut as well (but you may not notice a difference) it will be considerably more durable.


          Over 30 Degrees Angles
          Any edged tool or knife that is sharpened past 30 degrees will be very durable. Its cutting ability will be noticeably reduced. This durability has an advantage because more force can be used to make the cut. While the majority of knives won’t benefit from this sharpening angle, an edged tool like a machete, cleaver or axe must be durable as the typical cutting action of these tools would damage other edges.


          Continue Reading...

          Sunday, April 4, 2010

          how to enable ssh for a user other than root?

          Most users do not need SSH access, and yet, many end-users would select all options, not knowing the risks. To enable SSH access for a user, login as root and type:

          passwd
          usermod -s /bin/bash

          Continue Reading...

          How to auto mount windows share under Linux?


          How to mount remote windows partition (windows share) under Linux


          All files accessible in a Linux (and UNIX) system are arranged in one big tree, the file hierarchy, rooted at /. These files can be spread out over several devices. The mount command serves to attach the file system found on some device to the big file tree.
          Use the mount command to mount remote windows partition or windows share under Linux as follows:

          Procedure to mount remote windows partition (NAS share)

          1) Make sure you have following information:
          ==> Windows username and password to access share name
          ==> Sharename (such as //server/share) or IP address
          ==> root level access on Linux
          2) Login to Linux as a root user (or use su command)
          3) Create the required mount point:
          # mkdir -p /mnt/ntserver
          4) Use the mount command as follows:
          # mount -t cifs //ntserver/download -o username=vivek,password=myPassword /mnt/ntserver
          Use following command if you are using Old version such as RHEL <=4 or Debian <= 3:
          # mount -t smbfs -o username=vivek,password=D1W4x9sw //ntserver/download /mnt/ntserver
          5) Access Windows 2003/2000/NT share using cd and ls command:
          # cd /mnt/ntserver; ls -l
          Where,
          • -t smbfs : File system type to be mount (outdated, use cifs)
          • -t cifs : File system type to be mount
          • -o : are options passed to mount command, in this example I had passed two options. First argument is password (vivek) and second argument is password to connect remote windows box
          • //ntserver/download : Windows 2000/NT share name
          • /mnt/ntserver Linux mount point (to access share after mounting)

          /etc/fstab file contains static information about the filesystems. The file fstab contains descriptive information about the various file systems. fstab is only read by programs, and not written; it is the duty of the system administrator to properly create and maintain this file.
          To mount a Samba share to be mounted when a Linux system comes up after reboot edit the /etc/fstab file and put entry as follows for your Windows/Samba share:
          //ntserver/share /mnt/samba smbfs username=username,password=password 0 0
          For example, if you want to mount a share called //ntserver/docs then you need to write following entry in /etc/fstab file://ntserver/docs /mnt/samba smbfs username=docsadm,password=D1Y4x9sw 0 0Where,
          • //ntserver/docs: Windows 2003/NT/Samba share name
          • /mnt/samba: Local mount point (you may need to create this directory first)
          • smbfs: File system type (samba file system)
          • username=docsadm,password=D1Y4x9sw: Share username and password

          Configure a system to automount a Samba share with /etc/fstab


          Open file /etc/fstab using vi text editor:# vi /etc/fstabAppend line //ntserver/docs /mnt/samba smbfs username=docsadm,password=D1Y4x9sw 0 0, at the end your file should read as follows:
          proc            /proc           proc    defaults        0       0
          /dev/hdb1       /               ext3    defaults,errors=remount-ro 0       1
          /dev/hdb2       none            swap    sw              0       0
          /dev/hdc        /media/cdrom0   iso9660 ro,user,noauto  0       0
          //ntserver/docs /mnt/samba      smbfs   username=docsadm,password=D1Y4x9sw 0 0
          Replace sharename, username and password with your actual parameters.

          source: 
          • http://www.cyberciti.biz/tips/how-to-mount-remote-windows-partition-windows-share-under-linux.html
          • http://www.cyberciti.biz/faq/configure-a-system-to-automount-a-samba-share-with-etcfstab/
          Continue Reading...