Showing posts with label Open Source. Show all posts
Showing posts with label Open Source. Show all posts

Sunday, 18 December 2016

// // Leave a Comment

What happens when you start your computer???

In this post we will discuss about what happens when you start your computer system and how that Linux operating system launched.
When you start computer system then control goes to BIOS that Basic Input Output System.
After that control goes to boot loader.
So question arises in mind that what is boot loader.
Here we will try to understand about boot loader.


What is Boot Loader?

Boot Loader is small code which is resides in MBR (Master Boot Record) which will load kernel code of operating system and then control goes to operating system.
When we switched on the computer system then first control  goes to BIOS. BIOS will check all peripherals and check booting order of devices.then select highest priority booting device and execute code stored in MBR of that device.

For Example :-



From Windows Vista onward they use BOOTMGR as a boot loader.


Microsoft Windows up to Windows XP comes with  NTLDR boot loader

These boot loaders are specifically designed to load Windows OS.



For the Ubuntu operating system the boot loader is GRUB2 (Grand Unified Boot loader 2).



What is Master Boot Record (MBR)?



Its located in first sector of HDD, CD, other device.Master Boot Record (MBR) is one block with 512 bytes. The Size of MBR is 512 bytes because smallest sector size on hard disk is 512 bytes Its holds the partition entries and boot code.

Following MBR block, the actual partition are begin.





If you disconnect your hard disk from one machine and attached to another machine then that machine will understand about the partition table and file system from MBR. Because MBR held the data regarding file system and partition table.




As we know that size of MBR is 512 bytes. Out of which 446 bytes are used for boot code (Boot Loader) , 4 partition entry (each entry required 16 bytes so total 16*4=64) and 2 bytes for MBR signature. Total =446+64+2=512 bytes.



As MBR can store only four entries for partition due to that resoan in one Hard disk you can create only four partitons. All four will be primary or 3 primary and 1 logical. But you cannot create more than that partitions.


Here each volume (or) partition has separate boot sector its called volume boot record apart from MBR. its used for chain-loader of boot loader. The reason is grub boot loader can boot all Linux .




 GRUB Boot loader --> Load Linux Kernel




but GRUB Boot loader cannot load windows opearting system because GRUB dont knows windows boot process.




How GRUB Works?




In 446 bytes in MBR is not enough to put entire grub code. so MBR contain small code called boot.img and its capable to read first block of core.img file from any partition (logical volume too) before partition is mounted. Because that time they cant understand the file system. so they read directly one sector (block) where core.img file is located.

boot.img location   

core.img location
diskboot.img location




The first block of core.img is called diskboot.img for HDD or cdboot.img for cd-rom or pxeboot.img for network boot. This block contain many address of blocks , to iterate these address and load blocks then the complete core.img (around 32 KB) comes into memory. This is job for boot code in GRUB.

Actually core.img file is generated when GRUB is installed . This file contain one or more necessary module to mount the File system, where GRUB is installed. So core.img file is responsible for mount the File system and access the GRUB configuration file. Once file system is mounted then we can access the files normal like Linux. All other modules are located /boot/grub. Its loaded when its needed.

All grub related configuration (menu entries, graphics resolution, timeout, etc...) are stored grub.cfg file in /boot/grub/ location. No need to put this line in MBR. because once File system is mounted then we can access through path /boot/grub/grub.cfg 

Read More

Friday, 18 November 2016

// // 1 comment

Admin Commands for linux

In this post we will discuss about important admin commands for Ubuntu operating system.
1. Hardinfo
This is GUI based command through which admin can easily all hardware details in Graphical way.
But this package is not by default present. you have to install this package through command.
for user: sudo apt-get install hardinfo
for root user: apt-get install hardinfo

When you are going to run this command make sure that your system have internet connection.
After successfully installation of package you just need to type 
hardinfo in terminal
It will display the GUI  based Hardware details.

2. nmon

nmon command is used to check and monitor system performance.
Nmon or nigel’s monitor is a tool which displays performance information of the system.
Command to install nmon tool.
$ sudo apt-get install nmon

to check cpu information you can type nmon cpu info (press c)
nman disk info (press d)
3. lsblk
This command will be give installed devices on system It will generates tree based output.
command need to type
lsblk

output:

NAME   MAJ:MIN RM   SIZE RO
sda      8:0    0 465.8G  0 disk
├─sda1   8:1    0     1K  0 part
├─sda4   8:4    0 307.5G  0 part /media/supertux/BA1CCF4D1CCF037D
├─sda5   8:5    0   5.3G  0 part /boot
├─sda6   8:6    0  14.9G  0 part [SWAP]
└─sda7   8:7    0 138.1G  0 part /

4. slurm
A command line utility used for command based network interface bandwidth monitoring, it will display ascii based graphic.command need to type: 
$ apt-get install slurm
5. ranwhen.py
A python based terminal utility that can be used to display system activities graphically. Details are presented in a very colourful histogram.

First you need to install python for that run following command in terminal.

$ sudo apt-add-repository ppa:fkrull/deadsnakes

Update system:
$ sudo apt-get update

Download python:
$ sudo apt-get install python3.2

Download ranwhen.py

Run the tool.

$ python3.2 ranwhen.py

output:




Read More

Thursday, 10 November 2016

// // Leave a Comment

What is "Dirty Cow" vulnerability in Linux?



If you are using android phone or Linux operating system then read this very carefully.“Dirty COW” is a serious Linux kernel vulnerability that was recently discovered to have been lurking in the code for more than nine years. It is pretty much guaranteed that if you’re using any version of Linux or Android released in the past decade, you’re vulnerable.
Dirty COW (CVE-2016-5195) is a privilege escalation vulnerability in the Linux Kernel.
CVE-2016-5195 is the official reference to this bug. CVE (Common Vulnerabilities and Exposures) is the Standard for Information Security Vulnerability Names.
This vulnerability is identified by Phil Oester.


Before understanding this vulnerability we will try to understand atomic transaction.
In the atomic transaction the system will maintain initial state of system until the particular action completed.for that purpose we will going to lock the particular resource until the execution completed.
but there is one flaw for the same in Linux.
there is race condition present in memory mapping.
A race condition is an undesirable situation that occurs when a device or system attempts to perform two or more operations at the same time, but because of the nature of the device or system, the operations must be done in the proper sequence to be done correctly.
 Linux uses the “Copy on Write” (COW) approach to reduce unnecessary duplication of memory 
objects.  Lets understand this concept:
a = ‘COW’

b = a
Lets consider above syntax in which there are two different objects but they are referencing same memory location that is memory location of variable a.there is no need to take up twice the amount of RAM for two identical values.so ram will maintain same memory location.
Next, the OS will wait until the value of the duplicate object is actually modified:
b += ‘ Dirty’
Following steps are performed :
  1. allocate memory for the new, modified version of the object
  2. read the original contents of the object being duplicated (‘COW’)
  3. perform any required changes to it (append ‘ Dirty’)
  4. write modified contents into the newly allocated area of memory
Unfortunately, there is a race condition between step 2 and step 4 which tricks the memory mapper to write the modified contents into the original memory range instead of the newly allocated area, such that instead of modifying memory belonging to “b” we end up modifying the value of "a".

How this will affect to your system:

In the Linux the permissions are read only or read-write.
For example, as a non-privileged user you should be able to read “/bin/bash” in order to start a shell session when you log in, but not write to it. Only a privileged user that is “root” should be able to modify this file, otherwise any malicious user could replace the bash binary with a modified version that,and create  backdoor to your system through which he can access your system remotely.
The race condition  allows the attacker to bypass this permissions by using the COW mechanism to modify the original read-only objects instead of their copies. In other words, a carefully crafted attack can indeed replace "/bin/bash" with a malicious version by an unprivileged user.


The Solution:

The patch is available with latest Linux kernel. so update your kernel.
for the Android OS which is  using Linux kernel there is not any patch yet present. hope google will solve this in the latest release of android.




Read More