Thursday, January 22, 2004

Open files?

A couple of ways to find out what files are currently opened on your system:



In the base system, there is fstat :
FreeBSD Hypertext Man Pages: fstat



You can also list information about open files by using lsof found in ports/sysutils/lsof : Port description for sysutils/lsof





Wednesday, January 21, 2004

Checking connecttions

I always wondered how to check to see if anyone is currently using either ftp or http. Sometimes, if my DSL modem light is blinking furiously, I like to see what's going on. Early on in my server days, I noticed a problem once and it turned out some hackerz had slipped into my ftp site and were using it to trade malware! So I keep a close watch these days.



Anyway, I recently came across two methods that I think do this:




$ netstat -anf inet


and


$ sockstat


They both show current connections, and who is using them.




Tuesday, January 20, 2004

fwbuilder

More in the firewall vein; here's a tool to help you build your firewall rules, by far the most complicated part of using a firewall - fwbuilder. It supports ipfw out of the box, and also purports to support ipfilter. Gotta get started on this trip myself.



Description for ports/security/fwbuilder



A note by Phil Payne on using fwbuilder:


One quirk, when using fwbuilder with IPFW, the divert to natd isn't
supported so I'm installing the rules with a little script that inserts the
natd rule appropriately.



---
#!/bin/sh
.fw # Installs the rules generated by fwbuilder
ipfw delete 1 # delete the check-state rule at 00001
ipfw add 1 divert natd ip from any to any via # add new
divert rule at 1
ipfw add 2 check-state # re-add the check-state 2
---

ipfw.HOWTO

I still haven't decided what firewall, if any, to use. Yeah, I know, I should have one, but I don't. I think there are pretty much 2 choices with FreeBSD - ipfw (explained in the FreeBSD docs) and ipfilter. Here's a good link to get you started if you go down the ipfw road:



ipfw-HOWTO



FreeBSD LiveCD project

What a great idea! A set of scripts that builds an image to burn on a CD. This image is a complete, bootable FreeBSD installation. This would be especially nice for doing full backups.



The FreeBSD LiveCD Project



Burning CDs

Quick List of apps for burning CDs on FreeBSD:


  • mkisofs --- for creating iso's

  • burncd --- for ATAPI CDRW

  • cdrecord --- for SCSI CDRW, and SCSI emulation of ATAPI CDRW



Thanks to Shantanoo Mahajan on the Freebsd-questions list for such a concise listing.