11 ms·
Lazy Linux: essential tricks for admins
- mlLK 18y agoWhile how-to lists hardly see the light of day (the front page) on HN, I had hate to see one like this go unrecognized.
- mark_h 18y agoAgreed; way better than the usual lists.
- babo 18y agoA pretty unique collection, worth a look!
- lallysingh 18y agoQuick question, is it just me or is gig ethernet 1000 Mbps, not 1024? Man "mebibits" sounds terrible.
- iigs 18y agoTrick 5 (opening a remote port on a "public" machine to connect back to your local machine) is great. Combine it: office$ ssh -R 9999:localhost:22 user@home ## do this in a screen for good measure and another lesser known ssh feature: home$ ssh -D 8888 -p 9999 user@localhost and now you have a SOCKS proxy on home:8888 that will access everything visible to the computer named "office". For extra credit add PingTunnel and a hotspot that happens to allow ICMP and enjoy free internet wherever you go.
- gommm 18y agoThanks for the tip on ping tunnel, I hadn't heard of it.... Going to have fun checking it out
- mark_h 18y agoYeah, that was exactly the one that stood out for me! I've wanted this several times recently, at work and at play.
- sven 18y agocombine your ssh-tunnel-socks-proxy with tsocks, and you have a nearly transparent access for your applications on your home-box into the office.
- raamdev 18y agoVery nice collection. A tech at the datacenter that hosts one my servers showed me trick #3 and I remember being thrilled sitting there watching him do stuff on my server and sharing the keyboard to type messages back and forth in vi. My company uses trick #5 as a primary feature for accessing the remote Linux machines that our product is built upon. We have it set up so that every single machine automatically creates a reverse SSH tunnel to the server on boot, so that the tunnel is always accessible in case we need it. Very cool stuff.
- Goladus 18y agoIf you thought #8 was really cool and useful, you should go learn bash, sed, and awk. Stuff like #8 is what makes unix fun.
- LogicHoleFlaw 18y agoWhen I was doing AIX administration, I liked that one command to kill processes with open files keeping a mountpoint mounted was: fuser -fuck /dev/whatever http://moka.ccr.jussieu.fr/doc_link/C/a_doc_lib/cmds/aixcmds2/fuser.htm#a30794a1 http://moka.ccr.jussieu.fr/doc_link/C/a_doc_lib/cmds/aixcmds... Oh, admin humor.
- mlLK 18y agoAny admins care to share some pornographic passwords? p4ss1ng g4s 1n h3r 4ss w/ my sp34r d4n4 d03s d1ld0s @t d4 d1ld0 st0re d1ck r4p3d j4n3 w/ h1s d1ng d4ng
- mlLK 18y agoAre you're kidding me? If I must really share. . .most sys admins encourage their users to come up with passwords that read like 'pornographic catch phrases' written in 1337 speak as means of ensuring system security while the end-user is less likely to forget their password since it's something offensive yet expressive.
- yters 18y agoPeople are hitting the downvote button more.
- ionfish 18y agoMy general attitude to passwords is "Never choose something you'd be ashamed to recite to your mother over the phone", since you never know when you'll be in a position where you may have to do exactly that.
- khafra 18y agoAs an information assurance guy, I'd encourage users to use the most embarassing possible passwords, since you should never share them. If you need to make resources available to more entities, do it by sharing access, not authentication.
- ionfish 18y agoGenerally speaking I agree with you, but in the real world (with real users!) this is not always possible.
- Xichekolas 18y agoThis is what I love about Hacker News... even a semi-trollish post generates two great replies that I am glad to have read.
- sunkencity 18y agogreat list! I especially liked the tip about sharing a screen session, been wanting a solution like that many times! another great tip is how to list all subdomains on registered (not all dns servers allow this, many times you need to be on the same network, or it isn's allowed at all, but for solving you own dns issues it's a boon) dig mydomain.com. axfr
- delano 18y agoA better title: 9 interesting Linux commands and 1 reason to absolutely avoid CentOS.
- jrp 18y agoYou mean booting to singleuser? If you don't want it just use a grub password; nothing to do with CentOS.
- delano 18y agoIs the procedure for changing the root password with grub the same regardless of the flavour of Linux?
- khafra 18y agoThe primary bootloaders for Linux distributions are http://en.wikipedia.org/wiki/GNU_GRUB http://en.wikipedia.org/wiki/GNU_GRUB and http://en.wikipedia.org/wiki/LILO_(boot_loader) http://en.wikipedia.org/wiki/LILO_(boot_loader) with a large edge in popularity to GRUB these days. Unless it's a fork or modification, GRUB works like this: http://www.gnu.org/software/grub/manual http://www.gnu.org/software/grub/manual Single User Mode isn't unique to CentOS/Redhat, or even Linux. In fact, the concept behind it isn't even unique to Unix: One of Microsoft's 10 security rules is "if the bad guy has unrestricted physical access to your box, it isn't your box anymore." edit for clarity, due to reply GRUB doesn't change the Unix root password. GRUB--like any other bootloader--lets you boot to single user mode, which doesn't require a password. Single user mode lets you change the Unix root password.
- delano 18y agoI'm aware of GRUB and LILO. But as bootloaders, I didn't realize they were able to modify the Linux root password so easily. The question still stands: is it possible in any flavour of Linux to change the root password by modifying the kernel parameters at boot-time?
- davidw 18y agoWhat are your favorite, but lesser known Linux commands? fuser, strace, ltrace, nc come to mind offhand.
- xelfer 18y agolsof, ngrep, history (only found out this one a month ago after 6 years of being a sysadmin)
- palish 18y agoWhat terrible names. Sorry, but from a non-Unix perspective, symbols such as 'lsof' and 'ngrep' seem arbitrary and nonsensical.
- tome 18y agoWhat, LiSt Open Files and Net grep (Global Regular Expression Print)? They sound like fairly sensible abbreviations to me.
- palish 18y agoHow about "listopenfiles" and "netfind"? And "list" instead of "ls", and "delete" instead of "rm", and... et cetera. "Global Regular Expression Print" is a terrible name on its own, too.
- skorgu 18y agoSee the thing is that if you're knee deep in an unfamiliar system trying to fix it you type "ls" about a dozen times a minute. Adding two unnecessary keystrokes (doubling the length!) not only adds up it makes typos more common. There are some nice conventions though, once you know grep there's egrep, ngrep, etc. Then there's the -stat family, prstat, iostat, vmstat, mpstat, etc. Grep is its own special case, I'm not going to argue that it's a good name a priori but it does have the benefit of being completely unique not to mention far too entrenched to change now. Not to mention that it's "burp" in Yiddish. Unix is difficult to pick up but once your brain operates in that special warped way things do make sense by extension.
- m0nty 18y agoTo get back a hosed screen, also try: stty sane ^j (That's Ctrl-j there.) You might be flying blind, but just do it and you might get your screen back. You probably know this, but to rescue a hosed system with Knoppix or similar live-cd: - Boot from CD. - Open root console. - Mount your usual root partition: mount -t somefs /dev/hda1 /mnt/oldsys - chroot /mnt/odlsys /bin/bash Showed that to another admin who'd lost a production box, and his chin kind of hit the floor :) I gifted him the Knoppix disk... You can also use that to reset passwords (as per the article), by editing /etc/shadow or /etc/passwd in the /mnt/oldssys directory.
- easyrider2 18y agoA detailed article on rescuing a hosed system with Knoppix: How Knoppix saved the day http://www.dancingbison.com/writings/knopresc.txt http://www.dancingbison.com/writings/knopresc.txt
- bonaldi 18y ago# while [ 1 ]; do echo "All your drives are belong to us!"; sleep 30; done Hee, things I didn't think I'd ever see on ibm.com, #12234 in a series. People with company songbooks and nice ties must be spinning in their graves