Time-saving tips for Linux
quora.com
quora.com
Going back to Windows makes you really appreciate the speed of bash, vim and grep.
When I have to use Windows, one of the first things I always do is to install cygwin, so I can use bash, grep, etc.
ipconfig | grep IP
Not possible in windows. Then there's the rest of the userland tools unix people take for granted like rsync, screen, diff, tr, wget, etc. The standard shells and scripting languages all work. Plus I always set up an ssh server to run on localhost, so that I can use putty as my terminal rather than the windows' crummy cmd.exe.Yes, ultimately it's still a windows box and cygwin's distribution definitely isn't on par with ubuntu or fedora. It's not going to be cutting edge and there will be difficulties integrating with hardware and the windows environment. It's generally not a good choice for running desktop apps or servers, and will probably require some extra work to set up a serious development environment.
But if you have other reasons to use windows (Outlook calendar, games, etc.), cygwin makes it a LOT more tolerable.
ifconfig is deprecated (use "ip" instead).
There is not much value in knowing vim if you know Emacs. If you want to edit something in your terminal, well, emacsclient -t to your Emacs session. Or use mg, which is a very fast and light Emacs workalike -- just enough for editing your /etc/apt/sources.list to get Emacs installed :)
'ip' just gives me the standard syntax description.
The power of the basic shell is that there's usually a few hundred ways to skin a cat. And just because there's documentation saying something is deprecated as often as not it's still so widely used that in practice, it's not.
We use chroot to support multiple web apps with their own ip/domain on a single box. real simple to just add a new /etc/sysconfig/network-script/ifcfg-eth#:# with the proper network config. We can then ifup and ifdown them as necessary, they come up on boot if the config is set...
Just always made sense :)
On RHEL and related systems, ifup, ifdown, and everything in /etc/sysconfig/network-scripts/ are all implemented with the `ip` command.
'ip addr' should give you all the information that 'ifconfig' does. You can also make the output a little less chatty by doing 'ip -o -4 addr' to get IPv4 addresses on one line per interface, or 'ip -o -0 addr' to get MAC addresses displayed similarly. This can make awking / cutting for addresses to use in scripts a little more elegant.
Commands I use regularly instead of using ifconfig:
# link up/down
ip link set dev eth0 up|down
# add a new address
ip addr add dev eth0 172.16.43.124/24
# to clear all IP addresses from eth0
ip addr flush dev eth0
# delete an address
ip addr del dev eth0 172.16.43.124/24
# add default route
ip route add default via 172.16.43.254
Edit: I fail at formattingReally not you. It's one way this site is too minimal.
ifconfig eth0 up|down?
Why would I want to type more to accomplish the same task?This is the same reason as to why I hated that Linux decided to have an ifconfig for physical interfaces, an iwconfig for wireless interfaces. It seems redundant...
Anyway, the point of my post was showing some basic things which can be done with ip, and how to do them.
Nothing, as long as it's working for you (your Linux distribution probably patched some of the remaining ifconfig problems themselves). You likely won't have a problem until you want to use network features that were implemented after 2001.
ip a
can be used instead of ip addr
Even shorter than ifconfig!Sorry you didn't get anything out of it, but I suspect you don't need tips like "learn vim" and "be familiar with chown".
There's also zile, another mini-emacs (great if you run Linux on small embedded computers.) I haven't used mg yet, so I don't know how they stack up against each other.
I do have a creeping feeling I should some day bite the bullet and learn more than 4 vi commands, though.
you also don't need root rights to use it for display - although ifconfig can be run as a regular user, it's not on the path by default so it usually won't show up.
I really don't understand why there is a need to throw out a perfectly good tool to replace it with something that is completely different and requires re-learning, and re-writing of scripts that are already using ifconfig.
As for the quick Emacs workalikes - they are exotic and you can't always be expected to know the packaging commands of the odd Unix system you happen to be working with. And sometimes installing new packages is not an option.
Deprecated by whom? Is there any source on this? Nothing is mentioned in the man page, and googling for it turns up a wikipedia article with a [citation needed], a reddit discussion from today linking to wikipedia, and this discussion.
don't do that. if anything, lock it down even more by enabling tty_tickets.
You can't make good security guidelines without regard for context.
Once you have access to a local shell, the game is over. Acquiring root is easy, between local exploits or simply piggybacking on (or sniffing) a valid, passworded sudo login.
uh, maybe you should work on that.
alias sudo="sudo and do something evil instead"
Once an attacker has local access, you've lost. It's a short leap from there to root. What's more, by requiring that users supply passwords to use sudo, you're practically guaranteeing that they will reuse passwords that thy use elsewhere, exposing your network to further compromise should those passwords be acquired from a compromised server.http://www.devio.us/ http://sdf.lonestar.org/
if your operating system has no local user security, you should really upgrade it or switch to a different operating system.
Yes. In the late 90s, I worked in security for a company that ran one of the largest (at the time) shared hosting providers.
do you really think all of those servers have been rooted?
If someone was interested enough to capture an administrator's user account, then yes, they have been rooted.
if your operating system has no local user security, you should really upgrade it or switch to a different operating system.
There's no such thing. The local user attack surface is just too large.
As related to sudo, it's silly to think that local OS security can protect you from someone with access to an administrator's shell -- even if using sudo requires a password.
Let me break this down into simple steps:
Scenario 1:
- I acquire access to your password.
- I log in as you, then use your password to sudo to root. Game over.
Scenario 2:
- I acquire access to your SSH key or an active terminal on your server. I do not have your password.
- Logged in as you, I notice that sudo requires your password.
- Since you use zsh, I add the following to your zshrc:
sudo () { /usr/bin/sudo sh -c "echo \"pwned. Game over.\" && $==*" }
- You log in, and run some innocious sudo command. You enter your password, and then get a surprise: nupark@fish:~> sudo ls /var/cores
Password:
pwned. Game over.
tar-3493.core
nupark@fish:~>
Under what scenario will the password requirement protect you? If the attacker can't take advantage of the situation immediately, they can just as easily leave a landmine that you won't notice until it's too late, if ever.Once someone has a local shell -- especially an administrator's shell -- the machine is effectively compromised.
Requiring a password for sudo is at best a minor speed bump, not an obstacle, and it results in the propagation of password usage throughout your infrastructure. Many of those passwords, once acquired by an attacher, will likely grant access to other, possibly more critical systems.
$ man 1 ls
$ man 3 perror
$ man 1 printf
$ man 3 printf
http://en.wikipedia.org/wiki/Man_pagemore info at: http://en.wikipedia.org/wiki/Man_page
$ man manThe manual's a little light on the details.
All it says is:
--output=expr
Output the evaluation of expr for each line
What expression are they talking about? A regular expression? If so, how is that different from a normal grep? # Print included files.
ack --output '$1' '#include <(.*)>'
You could presumably do much trickier things as well, since the --output argument can contain any Perl expression.Don't go for ack, which is some Kanji character converter.
A faster way would be to hit Alt-# (does the same thing with just one key combo).
Even though it seems simple to someone who knows Linux, you can always impress marketing/business people by flying through Linux with these helpful commands, shortcuts, and tips.
\esc \tab
This will complete based on your history, argument wise. Very useful when tab completion itself doesn't satisfy you.
Or, add these lines to your .bashrc to use Ctrl-p and Ctrl-n:
bind "\C-p":history-search-backward
bind "\C-n":history-search-forward
$ stty stop undef
in many shells (bash, tcsh, etc), !foo will execute the most recent command from your history that matches foo, for example:
> grep -lots -of -options /complicated_regex/ ./some/path/* | /pipe/filter
# realize you are in the wrong directory
> cd /the/right/directory
> !g
and similarly, !! is the most recent command, which comes in handy for "sudo !!"[1] function s() { ssh $1 -t screen -dRR } $ set -o viNevertheless, I switched to zsh on Sunday, and with it, vi keybindings. It's getting better, but it still doesn't feel quite right.
I'm a recent convert. I don't like using control sequences for anything but screen management.
What I'd really like, though, would be a vim mode for the shell, not just a vi mode. Then I could use some of vim's more advanced features, which would make the mode even more useful.
esc to get into command mode.
v (just the letter v) will open the current command line in a vi or vim session (depending on your default editor).
Now vim to your heart's content.
:wq will get you out of the vi/vim session, and execute whatever you did in your vi/vim session.
The modes still trip me up sometimes, but a quick <Esc> or <Ctrl+c> fixes that!