Tuesday, October 16, 2018

Installing letscrypt certificate in grails

   Installing letsrcrypt certificate in grails.
   assumptions:
    domain name: app.example.com
    password   : supersecret
    linux app user account : appuser
 Use this URL to generate command for your site:

   As root:

   =============================================
   Step 1.
   Renew certificate using this command.
#certbot certonly
   (choose to renew option 1)
   It will create two file:
   /etc/letsencrypt/live/app.example.com/fullchain.pem
   and
   /etc/letsencrypt/live/app.example.com/privkey.pem
  
   Step 2.
   Combine cert and private key using this command.
#mkdir -p /home/appuser/etc/app.example.com
#openssl pkcs12 -export -in /etc/letsencrypt/live/app.example.com/fullchain.pem -inkey /etc/letsencrypt/live/app.example.com/privkey.pem -out /home/appuser/etc/app.example.com/app.example.com.cert.p12 -name app.example.com
<secret
as password>>
#chown -R appuser.appuser /home/appuser/etc/app.example.com

   As app user:

   =============================================
   Step 3.
   Convert p12 file into jks file using this command. Change supersecret to something that is really kept super secret.
$keytool -importkeystore -deststorepass supersecret -destkeypass supersecret -destkeystore /home/appuser/etc/app.example.com/app.example.com.cert.jks -srckeystore /home/appuser/etc/app.example.com/app.example.com.cert.p12 -srcstorepass secret  -srcstoretype PKCS12  -alias app.example.com
$rm /home/appuser/etc/app.example.com/app.example.com.cert.p12

   Step 4.
   Now pass these arguments to grails .
  
$./grailsw \
        -Dserver.address=0.0.0.0 \
        -Dserver.port=8443 \
        -Dserver.ssl.enabled=true \
        -Dserver.ssl.key-store-password=supersecret \
        -Dserver.ssl.key-store=/home/appuser/etc/app.example.com/app.example.com.cert.jks \
        -Dserver.ssl.key-alias=app.example.com \
        prod run-app



The form below hosted at https://jsfiddle.net/a2bfxdeq/2 generates command for you.


Sunday, March 18, 2018

Fixing grub2 on windows 10

Problem: Installed Linux on a external HDD connected to windows 10 using live CD and Grub got installed on internal HDD pointing to grub.cfg on external HDD. So if I remove the external HDD, grub.cfg is not found and can't boot windows.

Resolution:
1. Boot Linux by connecting the external HDD.
2. Mount the efi partition (Lets say its /dev/sda1. In my case it was first partition on internal HDD, about 256M in size)
  #mkdir /tmp/efi
  #mount /dev/sda1 /tmp/efi
3. Install grub.
  #grub-install --boot-directory /tmp/efi/grub --efi-directory /tmp/efi --uefi-secure-boot

4. Create the cfg file
  #grub-mkconfig > /tmp/efi/grub/grub/grub.cfg
 
 
Not tried but may be useful:
when you have grub prompt, try this:
echo $prefix

By default grub will look for $prefix/grub.cfg. If you can copy your grub.cfg from external HDD to the default location, that may work.

Monday, May 22, 2017

The Honeybees.




As per an article from Visual Capitalists (http://www.visualcapitalist.com/what-happens-internet-minute-2016/) there 20.8 million messages are handled by Whatspp, 2.4 million searches by Google and 70000 hours of video served by Netflix, every minute.
If one looks at last decade, Social Media and Smartphones has been the ‘the’ phenomenon of last decade. Most of the growth of S&P 500 since last crash has been from this revolution. Except for few companies like Apple, which is really Prada of smartphones, most of other players in these industries have a simple underlying business model: Monetize their user’s interaction with them while offering a ‘free’ service.
Very few their users realize that the companies own right to sell any content produced by them. Social media users search all over the internet archives, old albums, parks, beaches, oceans, mountains, back yard, front yard and gather pictures, quotes, analysis, comment and then happily handover to one of the social media giant for free. Then their friends review it (for free) and mark as interesting and uninteresting. The social media giants makes sweet profit while the users end up with lost privacy and ruined relationships.
Sometimes certain ‘data leaks’ and ‘hacks’ happen where the users also end up losing information that they hate to go public.
Enjoy being honeybee.

Sunday, July 12, 2015

Transfering file to remote machine using tcpdump and dd

Sometimes you need to transfer a file to a remote machine and do not have a file transfer tool available at the remote machine or may be restricted due to firewall rules.
If the remote machine has tcpdump and dd available then you can transfer the file following the process described below.

What do you need  on sender machine?
split and netcat

What do you need on receiver machine?
tcpdump , dd and one reachable port. Most like the dhcp port (67) is going to be open since there has to be a way for the remote to get IP :)

Steps:
On remote machine
1.a:
Create a shell script file like this:
cat > extract.sh <<EOF
# On the receving machine capture tcpdump file using
# tcpdump -i doc0 -w tcpdump.bin port 67

FILE_SIZE=$1
START=82
PACKET_SIZE=1000
FRAME_HEADER=58
BYTES_EXTRACTED=0
while [ $BYTES_EXTRACTED -lt $FILE_SIZE ]
do
        let partName=10000000+$START
        dd if=tcpdump.bin of=$partName.part bs=1 count=1000 skip=$START
        let START=$START+$PACKET_SIZE+$FRAME_HEADER
        let BYTES_EXTRACTED=$BYTES_EXTRACTED+$PACKET_SIZE
done

rm outfile.bin
for name in `ls -1 *.part`
do
        cat $name >> $2
done

EOF


1.b :
Launch tcpdump in a folder where you have write access (typically /dev/ is writable so you can create a folder called /dev/worktmp and launch tcpdump from there).
#mkdir /dev/worktmp
#cd  /dev/worktmp
tcpdump -i doc0 -w tcpdump.bin port 67

Steps on sender machine:
2.a:
Create a file like this:
cat  > sendAFile.sh <<EOF
#On the sending machine
#send the file using this
INFILE=$1
DEST=$2
rm x*
split -b 1000 $INFILE
for name in `ls x*`
do
        cat $name |  nc -w 1 -u $DEST  67 &
        sleep 1 ;
        pkill nc;
        sleep 1;
done
md5sum $INFILE
ls -l $INFILE

EOF

2.b :
Send the file (say the file name is strace) to the remote machine (10.2.2.3) using the script create above:
#bash sendAFile.sh strace 10.2.2.3

Steps on remote machine:
1.c:
Create the final file. The first argument is the file size and second argument is name of the file:
sh extract.sh 45654 strace

Wednesday, April 15, 2015

Transfer a file to a remote machine using console access

How to transfer a file to a remote machine using console access (telnet etc) when you have no file transfer tools?

Sometimes you are stuck on machine that is badly locked due to "security" reasons and does not contain any tools like wget, ftp, tftp. But you want to transfer a file on that machine. What to do now?
Assuming that the remote machine lets you some kind of console access via a tools that lets you copy paste (like putty) and also has these 3 tools:
  1. dd
  2. awk
  3. sh/bash/ash etc.

We are assuming you intend to transfer netcat.bin to remote machine.

Step 1) On remote machine, create a working folder at some volume that is writable. Even if everything else is write protected /tmp and /dev are generally writable.

Step 2) Change the working folder to the newly created folder.

Step 3) Create a file called hex2bin.dat (Yes, I am not naming it a .sh file you can name it if you want) on the remote machine. Contents of the file are as shown below.
#usage:
# cat data.txt | sh hex2bin.txt
#where data.txt is like this without # signs:
#cat data.txt
#0x64
#0x0a
#0x65
#0x0d
#0x66
#EEEE
#
# You also nee a file called zero.file which can be created like this:
# dd if=/dev/zero bs=1 count=1 of=zero.file

OFILE=$1
rm $OFILE
while [ 1 -eq 1 ]
do
        read aLine
        if [ x$aLine = "xEEEE" ]
        then
                exit
        else
                if [ x$aLine = x0x00 ]
                then
                        cat zero.file>>$OFILE
                else
                        echo $aLine| awk '{printf "%c", $1;}'>>$OFILE
                fi
        fi
done

Step 4) Create a file named zero.file by using the command shown below:
dd if=/dev/zero bs=1 count=1 of=zero.file

Step 5) Now on you local machine create a file named data.txt as shown below:
xxd -c 1 netcat.bin | awk '{print "0x" $2;}' > data.txt

Step 6) Now cat data.txt and take all the contents on clipboard.

Step 7) On remote machine create the same data.txt as shown below:
cat > data.txt << EOL
<<<< Paste the clipboard contents here      >>>>
<<<< Now type "EEEE" here, without quotes   >>>>
<<<< Now type "EOL"  here, without quotes   >>>>


Step 8) Now you should have a file named data.txt on remote machine. Do grep -vn "0x" data.txt and you should not see any empty lines. If you see any empty lines then you need to correct the empty lines using a text editor on remote machine by comparing contents of your local data.txt.

Step 9) Now just use following:
cat data.txt | sh hex2bin.txt netcat.bin


If you have a checksum tools on the remote machine (like md5sum or cksum) then you may want to do checksum comparison to make sure that file is good.

Sunday, September 14, 2014

Command line java/c/c++ code formatting

One can use eclipse to format java code on command line. Following is the syntax:
eclipse.exe -application org.eclipse.jdt.core.JavaCodeFormatter -verbose  -config

All the files in all subfolders below specified source folder will be formatted.

for example:
eclipse.exe -application org.eclipse.jdt.core.JavaCodeFormatter -verbose  -config .settings/org.eclipse.jdt.core.prefs .\src

I don't remember where I picked it from but I guess it was from
http://blogs.operationaldynamics.com/andrew/software/java-gnome/eclipse-code-format-from-command-line

Also apparently there is a way to format C/C++ code also using eclipse, although I have not tried it.
https://github.com/x8o1Y/EclipseCCodeFormatter

Wednesday, August 13, 2014

How to add ssl certificate from StartCom in Grails

StartCom provide free SSL/TLS certificate for you website that is valid for a year. This certificate is good enough to get going with SSL without warning etc.

Part1) get the certificate from StartCom
How to get a free certificate from StartCom?
1) visit https://www.startssl.com/?app=12
2) Click on express lane.
3) Supply the info to get your email address verified
4) Verify the email address, it will install a certificate in your browser.
5) Now visit https://www.startssl.com/?app=12 again and go to authneticate
6) Now go to Certificate Wizard and follow the instructions for getting Web Server SSL/TLS Certificate.
7) I opted for generating the the private key file from StartCom to make my life easier. It created a private key text that I saved as file mydomain.key and then they generated certificate for my domain  that I saved as mydomain.crt. Be careful about saving the private key text since I don't think you can retrieve that later. The certificate you can retrieve later also.

Part2) Create java key store file
1) create a pkcs12 file: You need to create a pkcs12 file using the private key and certificate. You can use the following command:
 openssl pkcs12 -export -inkey mydomain.key -in mydomain.crt -name mydomain_name -out mydomain.p12
It will ask for password, supply your favorite password. For simplicity I used the same password everywhere. StartCom also provides a tool to create this pkcs12 file under tools sections.

 2) Create a java keystore file: You can use keytool or you cal use kse (http://keystore-explorer.sourceforge.net/) GUI. Open the pk12 file in kse and change the type (Tools/Change Type/JKS). Then right click on the only entery you have and set password to your favorite password as above. The save this file as one with jks extension.

Part 3) To install this file in grails, 
add these two entries in conf/BuildConfig.groovy
grails.tomcat.keystorePath = "full file path of .jks file"
grails.tomcat.keystorePassword = "your password"