Luffyのメモ

カウンター
RSS feed meter for http://d.hatena.ne.jp/Luffy/
LUFFYのアンテナ
此処は物事をすぐに忘れるので何回も同じ事を書く為の個人メモです。

 

2014-10-31

nginx,elasticsearch,kibanaインストール

==============================================================

nginxインストール

#vi /etc/yum.repos.d/nginx.repo

[nginx]

name=nginx repo

baseurl=http://nginx.org/packages/centos/5/$basearch/

gpgcheck=0

enabled=1

# yum update

# yum search nginx

# yum install nginx

# service nginx start

# curl 127.0.0.1

# chkconfig nginx on

==============================================================

JAVAインストール

# java -version

# yum remove java

# yum install java-1.7.0-openjdk.i386

==============================================================

elasticsearch インストール

# wget https://download.elasticsearch.org/elasticsearch/elasticsearch/elasticsearch-1.3.4.tar.gz

# tar zxvf elasticsearch-1.3.4.tar.gz

# mv elasticsearch-1.3.4 /opt/

# /opt/elasticsearch-1.3.4/bin/elasticsearch

# curl 127.0.0.1:9200

{

"status" : 200,

"name" : "Aleksander Lukin",

"version" : {

"number" : "1.3.4",

"build_hash" : "a70f3ccb52200f8f2c87e9c370c6597448eb3e45",

"build_timestamp" : "2014-09-30T09:07:17Z",

"build_snapshot" : false,

"lucene_version" : "4.9"

},

"tagline" : "You Know, for Search"

}

==============================================================

kibanaのインストール

# wget https://download.elasticsearch.org/kibana/kibana/kibana-3.1.1.tar.gz

# tar zxvf kibana-3.1.1.tar.gz

# mv kibana-3.1.1 /opt/

# vi config.js

elasticsearch: "http://IP_address:9200",

# vi /etc/nginx/conf.d/default.conf

location / {

root /opt/kibana-3.1.1/;

index index.html index.htm;

}

==============================================================

nginx 再起動

#service nginx restart

2014-05-27

[] [Mobile Forensics] [Android] Santoku-Linux

https://santoku-linux.com/

2014-04-22

[] [Memory Forensics] メモリフォレンジック

lsass.exeの正しい位置
winlogon.exe
   |
    --- lsass.exe
    --- services.exe
         |
          --- Process_A.exe
          --- Process_B.exe
          --- Process_B.exe
          --- Process_B.exe
          --- Process_B.exe
          --- Process_B.exe
 ※「lsass.exe」は一つのみ、複数ある場合はおかしい。
 ※「lsass.exe」は「winlogon.exe」の下に作成される
 ※他のサービスは「services.exe」の下に作成される
 ※「lsass.exe」のスタートタイムはBOOT時間の近くになる
Explorer.exeの正しい位置
C:\Windows
   |
    --- Explorer.exe
iexplore.exeの正しい位置
C:\Program Files
   |
    --- iexplore.exe
svchost.exeに関して
explorer.exe
   |
    --- svchost.exe
 ※「svchost.exe」はシステム権限なので
 ※ユーザ権限であるexplorer.exe」の下にはつかない

2014-04-04

[] [forensics] SuperTimeline

【旧】
# mount -o loop,ro,show_files,streams_interface=windows,offset=32256 /mnt/hgfs/image.dd /mnt/windows_mount
# log2timeline -z Japan -p -r -f winxp /mnt/windows_mount -w supertimeline.txt
# l2t_process -b supertimeline.txt > supertimeline.csv

【新】
# log2timeline.py -o 63 --parsers "win7" /cases/timeline/myhost.dump image.dd
# psort.py -w /cases/timeline/myhost.sorted.csv /cases/timeline/myhost.dump

【Windows】
log2timeline.exe -o 63 -z Japan -p --vss myhost.dump image.dd
psort.exe -z Japan -w supertimeline.txt myhost.dump

http://plaso.kiddaland.net/usage/upgrading-from-0-x-branch

2014-02-14

[] Fluentd mongodb

/etc/td-agent/td-agent.conf

<source>
  type tail
  path /var/log/httpd/access_log
  pos_file /var/log/td-agent/apache2.access_log.pos
  format apache2
  tag mongo.apache.access
</source>
<match mongo.apache.access>
    type mongo
    database apache
    collection access
    host localhost
    port 27017
</match>
 
無料アクセス解析2php
OpenSSH
はてな開始日付:2004-03-24
Cisco関連 :2004-03-23
Nokia関連 :2004-03-22
SEIL関連 :2004-03-21