Showing posts with label ubuntu. Show all posts
Showing posts with label ubuntu. Show all posts

Monday, August 4, 2008

MySQL vs Ubuntu 8.04: Default settings really annoy me!

By default Ubuntu 8.04 sets MySQL to listen to local connections only.
This really is an annoying and stupid thing I found in the server (!) version of Ubuntu Hardy Heron.

Here the solution.

Here some thoughts of mine:
  • Does a server mantainer need Ubuntu to prevent him from using MySQL for the purpose it has been meant?
  • Does someone still use all-in-one machines, equipped with DBMS, appserver, webserver and whatever else (maybe someone like this still exists...)?
I have to admit it: the only OS I saw doing stupid things like this one is... Windows.

Wednesday, December 19, 2007

Istruzioni di installazione per PyGridware (su Ubuntu)

Andrea tempo fa mi ha gentilmente fornito un utile tutorial per l'installazione di un toolkit per il Grid-Computing con Python (su Ubuntu!!!).
Credo sarà di gradimento a molti.

Notare 3 cose:
  • il tutorial è interamente realizzato da Andrea
  • me lo ha fatto avere da un bel po; ergo Andre: mi incenso il capo e scusami per la lunga attesa
  • se doveste avere domande o commenti sarà mia premura mettervi in contatto con Andrea (ve l'ho detto: è lui l'autore del tutorial!)

Friday, October 5, 2007

Ubuntu security bulletins (USN-525-1 - libsndfile vulnerabilities)

USN-525-1: libsndfile vulnerabilities
Threat-level (*): Moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
It's recommended that you perform (at least) a standard system upgrade to avoid possible:
  • Remote attacks based on wrong memory buffers handling of the libsndfile library, with the following consequences:
    • arbitrary code execution with the user privileges if a specially crafted FLAC file is executed on the attacked system

________
(*) = IMHO = It's just my opinion...

Ubuntu security bulletins (USN-524-1 - OpenOffice vulnerabilities)

USN-524-1: OpenOffice vulnerabilities
Threat-level (*): Moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
It's recommended that you perform (at least) a standard system upgrade to avoid possible:
  • Remote attacks based on an integer overflow of the OpenOffice suite, with the following consequences:
    • arbitrary code execution with the user privileges

NOTE: OpenOffice needs to be restarted for the changes to be applied.
________
(*) = IMHO = It's just my opinion...

Thursday, October 4, 2007

Ubuntu security bulletins (USN-523-1 - ImageMagick vulnerabilities)

USN-523-1: ImageMagick vulnerabilities
Threat-level (*): Less-than-moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
It's recommended that you perform (at least) a standard system upgrade to avoid possible:
  • Remote attacks based on flaws of the ImageMagick libraries, with the following consequences:
    • arbitrary code execution with user privileges

________
(*) = IMHO = It's just my opinion...

Thursday, September 27, 2007

Una soluzione ai problemi dell'open-source

"Quindi, tutti voi, proponete nuove idee, segnalate bug, dite cosa c’è che non va senza peli sulla lingua, insomma, aiutiamoci ad avere il miglior sistema operativo di sempre. Questo è lo spirito Open Source, aiutare, ognuno con i propri mezzi, anche se non si è programmatori." (oneOpenSource blog)

Tempo fa avevo espresso dei dubbi sul "movimento" Open Source nel mondo Linux, secondo me sempre più influenzato (negativamente) dalle varie "caste" dei progetti che lo compongono.
Bene, con le parole citate in cima a questo post mi sono definitivamente convinto che il movimento Open Source (e quindi anche quello Linux) sia diviso in infinite sfumature che partono e si mescolano a partire da due estremi principali:
  • Un movimento che proviene "dal basso", fatto prima di tutto dagli utenti che utilizzano il software e che contribuiscono enormemente alla "causa" dell'Open Source segnalando bugs e suggerimenti
  • Quello che proviene "dall'alto", fatto delle elite di sviluppatori che si formano intorno ai progetti Open più importanti (soprattutto il kernel Linux, ma non solo)
Quello che mi pare di capire è che la corrente "dall'alto" dia sempre meno ascolto a quella "dal basso", risultando nella progressiva nascita di un gigante dai piedi di argilla.
Io utilizzo molto come esempio la cerchia di sviluppatori del kernel, ma le mie considerazioni si applicano indifferentemente a moltissimi altri progetti (vedasi a titolo esemplificativo Gimp e alcune scelte a dir poco bislacche fatte dagli sviluppatori Ubuntu).

Concluderei dicendo che secondo me l'unico modo per far si che la testa del gigante ricominci ad ascoltare anche le altre parti del proprio corpo è farsi sentire, a iniziare dalle segnalazioni e dalle "proteste" che possiamo fare.
Come giustamente ha fatto osservare Dario Freddi con le parole che ho citato in alto.


P.S. Vi farei notare che il discorso sulla "partecipazione attiva" si applica paro-paro all'attuale situazione della politica italiana (leggasi: "prima di condannare i politici, pensiamo a quanto siamo disonesti ogni giorno nel nostro piccolo noi tutti cittadini italiani").

Tuesday, September 25, 2007

Ubuntu security bulletins (USN-518-1 - Kernel vulnerabilities)

USN-518-1: Linux kernel vulnerabilities
Threat-level (*): moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
It's strongly recommended that you perform (at least) a standard system upgrade to avoid possible:
  • Local attacks based on ptrace routines, with the following consequences:
    • denial of service
  • Local attacks on PowerPC computers, with the following consequences:
    • denial of service
  • Local attacks performed exploiting a CIFS filesystems vulnerability, with the following consequences:
    • privileges escalation (gain of additional privileges on the local system)
  • Local attacks that exploits some x86_64 kernels vulnerabilities, with the following consequences:
    • privileges escalation (gain of root privileges on the local system)
NOTE: After the upgrade for the changes to affect your system you must restart your computer.

________
(*) = IMHO = It's just my opinion...

Thursday, September 20, 2007

Open source is makin' me loose my temper

UPDATE:
Try InkScape: is way much better than Gimp when it comes to editing box, lines, gradients and, in general, simple linear patterns.
(But it's buggy, too... grrrrr!)

ORIGINAL:
Pleas someone tell them to simply make Gimp work: I've spent the last 40 minutes trying to draw 3 (T-H-R-E-E !!!) bands on the upper right corner of an A4.

Selections that, when moved, move the entire layer instead of just what they are meant to select (why call them "Selections" if they don't "select"?!?), the ridiculous elaboration speed of a "Fill" operation (I was simply filling the entire A4 surface with a plain colour and it took me about 5 seconds!), the total absence of a "transform selection" command (instead, you have to play with mysterious options of the transformation tools option-box)... and other frustrating ones.
And someone dares to compare Gimp to Photoshop!!!

Please "open-source guys", less buzz-words, less auto-contratulating on minimal things, less religion wars, less "Winzozz" and "M$"; please start taking your work seriously, and stop harming users with your incompetence!

Wednesday, September 19, 2007

Ubuntu security bulletins (USN-514-1 - X.org server)

USN-514-1: X.org-related privilege escalation
Threat-level (*): Moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
It's recommended that you perform (at least) a standard upgrade of your system to avoid possible:
  • Exploits based on a bug found in the server core (and in its composite extension), with the following possible consequences:
    • arbitrary code execution with root user privileges
________
(*) = IMHO = It's just my opinion...

Tuesday, September 18, 2007

Ubuntu security bulletins (USN-513-1 - QT libraries)

USN-513-1: QT libraries possible buffer overflows
Threat-level (*): Less-than-moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
Notice that QT3 libraries are used by all KD3-based applications.
It's recommended that you perform (at least) a standard upgrade of your system to avoid possible:
  • Attacks based on specially crafted UTF-8 strings that can lead to small buffer overflows, with the following possible consequences:
    • arbitrary code execution
    • denial of service
After the upgrade for the changes to affect your system you need to restart your user-session (i.e. log-out and then re-log-in to your system).

________
(*) = IMHO = It's just my opinion...

Sunday, September 9, 2007

Enabling VT capabilities in VirtualBox 1.5

Today I dramatically increased the speed at which VirtualBox runs my Windows XP virtual machine.
I'm not saying that yesterday VirtualBox performances were not satisfactory: even without VT options enabled Innotek did a very good job for the new release of their software.
But (!) , if you really want to boost the speed at which your virtual machines are emulated up, well, you essentially need 3 ingredients:
  1. A VT-capable CPU (my Intel Core Duo T2300 is VT-enabled)
  2. VirtualBox 1.5
  3. me
Let's go:
  1. First of all check whether your CPU supports VT (or AMD-V, if you are using an AMD CPU): see this page for a list of VT enabled CPUs and this one for the AMD ones, or check Intel and AMD websites for more info. [Psssst: I'll explain you a method to check if VT is enabled by using the command line in a Ubuntu environment; all you have to do is to use these instructions more /proc/cpuinfo | grep vmx (or more /proc/cpuinfo | grep svm if you are an AMD-powered guy) and check whether the command returns some text or not. If at least one line of text is displayed you are ready to proceed with the next step]
  2. Install VirtualBox and open the preferences window (File > Preferences...). Now, in the right-side pane locate the "Extended Features" section and enable the check-box named "Enable VT-x/AMD-V".
  3. That's all: I noticed a very impressive performance improvement in my Ubuntu-box.
I also enabled "Seamless integration" ("'host key' + L" inside your virtual machine), a new feature in VirtualBox 1.5, and you can see the results in this gallery:




Friday, September 7, 2007

Memento (AKA "l'open-source a un bivio")

Firefox comincia a usare un po troppa memoria.
E io potrei stancarmi.

Alla faccia di quelli che criticano sempre IE... ok lui ha i suoi problemi ("narcisismo" e incompetenza, due a caso), ma almeno non mangiava tonnellate di memoria quando lo avviavo.

Credo che gran parte del movimento open-source abbia frainteso il motto "release earlier, release often": vedi la stabilità penosa di molte, troppe distribuzioni.
Non passa giorno che sulla mia UbuntuStudio si verifichi qualche inconveniente grave: oggi mi si è chiusa la sessione utente dopo 2 minuti di lavoro ininterrotto del disco fisso, killando alcuni processi e lasciandone in vita altri. Stavo semplicemente utilizzando VirtualBox (la colpa non è di certo la sua, i problemi li ha il kernel).

E questo è un gran peccato: l'open-source che diventa ciò che ha sempre sbeffeggiato: una mera operazione commerciale e/o di immagine.
Spero di essere io paranoico, altrimenti siamo al principio della fine.

Monday, August 27, 2007

Ubuntu security bulletins (USN-503-1 - Thunderbird)

USN-503-1: Thunderbird Javascript flaws
Threat-level (*): Less-than-moderate

Affected Ubuntu versions:
  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
Affected Thunderbird version:
  • mozilla-thunderbird 1.5
It's recommended that you perform (at least) a standard upgrade of your system to avoid possible:
  • Attacks based on malicious-emails (based on Thunderbird Javascript flaws):
    • arbitrary execution of applications placed on the attacked computer with the privileges of the user that opened the malicious mail
    • execution of arbitrary code with the privileges of the user
________
(*) = IMHO = It's just my opinion...

Sunday, August 26, 2007

Ubuntu security bulletins (USN-499-1 - Apache)

Today I inaugurate a new service: thanks to the Ubuntu Security Notices, I am able to provide an updated list of the Ubuntu vulnerabilities as they are discovered and posted to the ubuntu-security-announce mailing list.
I won't provide every report submitted to this list, but I think I'll select just the more interesting among them.

The first post is for the Apache-aholik ones:

USN-499-1: Apache vulnerabilities
Threat level (*): MODERATE

Affected Ubuntu versions:

  • Ubuntu 6.06 LTS
  • Ubuntu 6.10
  • Ubuntu 7.04
  • (and the corresponding versions of Kubuntu, Edubuntu, and Xubuntu)
It's recommended that you perform (at least) a standard upgrade of your system to avoid possible:
  • XSS attacks (consequences: data/passwords stealing and other minor threats)
  • Denial-of-service attacks
  • Apache signal handling flaws
________
(*) = IMHO = It's just my opinion...

Sunday, August 12, 2007

Ubuntu: Switch from Gnu GCJ and GIJ to Sun JRE

If you experienced (I did, grrrrr...) some problems like Eclipse not running very well (e.g. CPU at 100% all the time) or Java-based apps stopping with errors, well Alec the Geek has a possible solution (a definitive solution won't be born until the guys at the GNU Foundation will decide to stop messing around with "Free as in speach..." or "Free as in beach..." or "Libertè, Egalitè, Penguinitè" and maybe will turn back to writing code and FIX GIGANTIC BUGS).

The idea is simple and useful even for other needs: you point the wrappers to the Java compiler and the Java bytecode interpreter to the official Sun JRE, instead of using the GNU implementation (which is the default Ubuntu behavior).
You do that by using the following command, sudo update-alternatives --config java , and by choosing the Sun JRE from the list (only if you have installed it, of course...).

Guys, repeat with me: "Thaaanks Aleeec"

Monday, August 6, 2007

Make two different Thunderbird versions cohabit in the same Ubuntu installation

In my recent post "Make two different Firefox versions cohabit in the same Ubuntu installation" I explained why (and how) I have two different Firefox installations sharing the same settings, bookmarks and add-ons.
This time things get a little more tricky, but don't worry and let's get the party started.
  1. Download Thunderbird
  2. Unzip to your home directory (tar xf thunderbird-2.0.0.6.tar.gz , TAB is your friend, use TAB)
  3. Now you have to make mailboxes, settings and the other stuff be shared between your two Thunderbird installations (the "native" one and the "new" one). NOTE: follow these steps before you start your newly downloaded Thunderbird
    1. Locate in your home directory the folder ".mozilla-thunderbird" (you must select "View > Show hidden files" or press "Ctrl + H" if you are using a file manager)
    2. Look at the files that the folder contains: we are interested at the file "profiles.ini" and at a folder named "XXXXXX.default" or "default.XXXXXX" (where "XXXXXX" can be "whatever-Thunderbird-decided" sequence of letters and numbers)
    3. We must link this folder and "profiles.ini" to the folder "/home/$USERNAME/.thunderbird" (if this folder doesn't exist, create it):
      1. cd
      2. ln -s ./.mozilla-thunderbird/profiles.ini ./.thunderbird/profiles.ini
      3. ln -s ./.mozilla-thunderbird/XXXXXX.default ./.thunderbird/XXXXXX.default
  4. Start Thunderbird: /home/$USERNAME/thunderbird/thunderbird
NOTE: You can use both Thunderbird installations and this HOWTO can be applied to any version of Thunderbird and Firefox. This comes pretty useful especially when testing beta (and/or alpha) versions of the two products.

As previously said: let me know if that works (it seems that my comments aren't accessible from the home-page of the blog: to comment you must open the post in its own window by clicking the post title and scroll the page down until you see the "Comments" box).

Saturday, July 28, 2007

Make two different Firefox versions cohabit in the same Ubuntu installation

Few days ago I was founding quite disappointing the performance of my Firefox web browser under my Ubuntu distro. In addition, the installed Firefox version won't be updated until Gutsy (or until a security update will be published). (this is a policy I sincerely don't understand: why I can have the always up to date software in Windows and not in Ubuntu? Mah!)

BTW, I came to a solution: installing from the binaries provided by the Mozilla foundation would be enough... Nearly enough: I also didn't want to loose my current Firefox installation, nor I wanted to loose all the plugins and the extensions I had already installed and configured.
So I turned to this solution: install the new version (downloaded from here) side by side with the "old" one, letting them share the same settings folder.
  1. Download Firefox
  2. Move "firefox-2.0.0.5.tar.gz" to your home directory
  3. Extract it (tar xf firefox-2.0.0.5.tar.gz)
That's all: from your home folder run firefox/firefox or type ./firefox from the "firefox" folder or place an icon on your desktop.

From now on the two versions of Firefox will share preferences, settings and extensions (all the settings and the extensions are located into your /home/$USERNAME/.mozilla/firefox folder).

Let me know if that works.

(Coming soon: the same way for... Thunderbird!)

Thursday, July 26, 2007

The professional Ubuntu (first part)

Ubuntu Studio is an unofficial flavor of Ubuntu, based on Gnome and few other apps, all available through the official Ubuntu repositories.
I will not discuss on how installing Ubuntu Studio in details (see UbuntuStudio.org or/and this wiki for more infos on this topic), but I will tell you one thing: this distro best embodies my concept of "modularity". They took the very few of the Ubuntu core (the "main module") and built up around it a consistent distro, made itself of other modules (that are known, in the Ubuntu language, as "meta-packages").
Ubuntu Studio is made up of 4 meta-packages:
  • Graphics, featuring Gimp, Inkscape, Agave, CinePaint, Scribus and so on
  • Audio, featuring Audacity, Jack, Ardour, Muse and others
  • Video, a metapackage that contains Cinepaint, Kino, Stopmotion and others
  • Audio plugins, containing the most useful plugins for the apps of the Audio meta-package

When I came to install Ubuntu Studio on my laptop I found very interesting to choose at install-time which of those sets of apps will be installed: the installer did all of the hard work on his own, by taking all the .deb packages from the installation CD.
So, this is the first goal of modularization that has been obtained : simple and powerful 20-minutes installations that lets your system in a consistent and immediately productive state.

Also, Ubuntu Studio does so by targeting a precise and unique target of users: the creative professionals.
I want modularity... just give me all AND ONLY the packages I need for my work!

<< Link to the Intro | Link to the second article >> [COMING SOOOOON...]

The professional Ubuntu (Intro)


When I came the first time to UbuntuStudio.org I promised myself the next time I'll be upgrading my Ubuntu I will install this professional flavour of the "human distro".
So, when the Feisty Fawn was born I decided to move from classical Ubuntu to Ubuntu Studio.
Currently the first screenshot (click to see the full size version) you see on the left is the result of some customizations.


Some lines back I highlighted the word "professional"; I did so to focus your attention on an aspect of Ubuntu that is often guiltily omitted: Ubuntu lacks an "I-don't-know-what" that will make it truly professional.
I know, I know, Ubuntu has several "pro-level" apps, offers a highly usable and friendly desktop, is becoming more mature every day, is already a competitive alternative to MS Windows, but I think it really misses a "behavior" that puts it on the same level as Mac OS X is.
No, I'm not jocking, I really do mean that with some adjustments Ubuntu could be a competitive alternative even for those people that every day need a stable, simple, homogeneous and "serious" working environment (talking about you, OS X).

The point in this post is that we can't wait to Ubuntu to become this way, so we can go two different ways:
  1. Help Ubuntu change and become more professional (I absolutely do not mean to make it more OS X like): Launchpad is supposed to be the center of the community, so manifest there your requests for a better Ubuntu and help developers with bugs (the least you can do is help who provides you such a good system with such a little expense (zero, nada, nothing, zéro, null, nil, nothing ...))
  2. Try to customize yourself Ubuntu or any derivative distro, like I did and like we are going to explore in this post
Notice the two preceding points are complimentary: I really encourage you to follow both of them!

Before we develop the central topic of the post I want you to acknowledge the human distro to be a heavy modular one: Linux is modular to a near-to-the-maximum extent and Synaptic and the system of packages and meta-packages that constitute Ubuntu is a perfect and user-friendly complement to this modularity.

We were speaking of "professionalism", why turning to "being modular"?
Because I think the two things are strictly correlated when it comes to operating systems.
So I'll explain how to achieve professionalism through being modular.

Link to the first article >>

Saturday, July 14, 2007

Intel Core Duo optimizations and CK patches for Ubuntu Feisty

If you are, like me, a performance-hungry guy, well, today I have very good news for you.
I found a repository that provides optimized Linux kernel builds for Ubuntu Feisty.
Provided optimizations are the following:
  1. CK patches (read more at this link)
  2. Kernel compiled with Intel Core Duo optimizations
This work is provided by Giuseppe, an Italian blogger you can found at http://www.iuculano.it.
Check Giuseppe's post to read more details; the author of the blog is Italian (like me!), so expect to read these details in Italian... But, even if you don't understand Italian, well this is the sequence of steps to add Giuseppe's repositories to your list and for installing the patched kernel:

wget http://ubuntu.iuculano.it/AE3BE9AA.gpg -O- | sudo apt-key add -

After that, add this repositories to your sources.list:
deb http://ubuntu.iuculano.it feisty all
deb-src http://ubuntu.iuculano.it feisty all

Finally:
sudo apt-get update && sudo apt-get install linux-686-ck linux-headers-686-ck
or
sudo apt-get update && sudo apt-get install linux-core2-ck linux-headers-core2-ck
(depending on your CPU)

Note that even if the kernel is labeled "*-core2-*" it works fine in my Core Duo "first generation", so it sure suits well both Core Duo and Core 2 Duo CPU families.

I tried myself the so-optimized kernel and I found that it provides actual noticeable performance increment only for those applications CPU-intensive (e.g. GIMP, video editing and audio conversations). It also seems that my desktop is more responsive, but I didn't take any test to verify an eventual performance gain for the X server.
I warn you: don't expect sparks and a performance boost from every application of your system (especially from IO-intensive applications... )!

At the bottom of the Giuseppe's post is also provided a tip to increase the responsiveness of the X server:
sudo dpkg-reconfigure -plow x11-common
and answer -10 when it asks for the X server "nice" value.
This is a tip that works with every kernel (it affects the X server, not the kernel) and could probably increase your desktop responsiveness, but I didn't try it, so I can't tell you more.

(If you wanna know more about CK (Con Kolivas) kernel patches: ck.wikia.com)