Blocking access by user agent in Nginx
How to block access by user agent in Nginx. In this configuration, i will use ngx_http_map_module.
Inside http section:
include /etc/nginx/blacklist;
Inside server section (virtual host). We will return 444 status code.
if ($block_ua) {
return 444;
}
The blacklist file (example)
map $http_user_agent $block_ua {
default 0;
~*profound 1;
~*scrapyproject 1;
~*netcrawler 1;
~*nmap 1;
~*sqlmap 1;
~*slowhttptest 1;
~*nikto 1;
~*jersey 1;
~*brandwatch 1;
~*magpie-crawler 1;
~*mechanize 1;
~*python-requests 1;
~*redback 1;
}
For testing:
aelius@macbook:~$ curl --head -A "profound" https://www.unixteacher.org/ curl: (52) Empty reply from server
What is http status 444 ?
A non-standard status code used to instruct nginx to close the connection without sending a response to the client, most commonly used to deny malicious or malformed requests.
Harden bash_history and bash configuration files
Harden bash_history and bash configuration files by making them append-only:
chattr +a /home/user/.bash_history
chattr +a /home/user/.bash_profile
chattr +a /home/user/.bash_login
chattr +a /home/user/.profile
chattr +a /home/user/.bash_logout
chattr +a /home/user/.bashrc
Harden env variables by adding the following lines to /home/user/.bashrc:
shopt -s histappend
readonly PROMPT_COMMAND="history -a"
readonly HISTFILE
readonly HISTFILESIZE
readonly HISTSIZE
readonly HISTCMD
readonly HISTCONTROL
readonly HISTIGNORE
histappend tells bash to append the last $HISTSIZE lines to the $HISTFILE file when an interactive shell exits. PROMPT_COMMAND executes the given command prior to issuing each prompt. history -a appends the command typed just before the current one to $HISTFILE.
Disable access to other shells:
chmod 750 csh
chmod 750 tcsh
chmod 750 ksh
Tomcat as non root user
run
setcap cap_net_bind_service+ep /path/to/bin/javaex: setcap cap_net_bind_service+ep /usr/lib/jvm/java-8-openjdk-amd64/jre/bin/java
Reconnect Wazuh agent
- Add the manager's ip address in the configuration file /var/ossec/etc/ossec.conf <address>MANAGER_IP</address>
- Register the agent in the manager. The simplest method is /var/ossec/bin/agent-auth -m MANAGER_IP
- Restart the wazuh agent systemctl restart wazuh-agent.
Delete DFSR replication folders
md d:\emptyfolder
Robocopy.exe d:\emptyfolder "D:\System Volume Information\dfsr\Private" /purge
rd d:\emptyfolder
I found that at:
Enable ‘Minimize on Click’ on Ubuntu Quickly
gsettings set org.gnome.shell.extensions.dash-to-dock click-action 'minimize'
Hit enter for the change to take effect instantly.
If you don’t want to lose the ‘window’ picker (option 5 in the list above) run this command instead, which will introduce minimise on click but show the window picker if more than one window of a given app is open:
gsettings set org.gnome.shell.extensions.dash-to-dock click-action 'minimize-or-previews'
To undo the change (i.e. revert back to the default settings for the Ubuntu Dock) copy/paste this command:
gsettings reset org.gnome.shell.extensions.dash-to-dock click-action
Remove computer from Azure Arc
To fully remove a computer from Azure Arc-enabled servers, follow the official steps in the Uninstall the Azure Connected Machin...
Mais vistos
-
Find Users Who Have Never Logged On Use the following PowerShell Command; Get-ADUser -Filter { LastLogonDate -notlike "*" -and En...
-
Java Keytool Command These commands allow you to generate a new Java Keytool keystore file, create a CSR, and import certificates. A...
-
First you have to configure a wpad site in your IIS Open the proxypac.pac file you have previously created and save as wpad.dat. Copy wpa...
For those not using wordpress at all and just want to block annoying scraper bots:
or better yet: