Search This Blog

Wednesday, August 10, 2016

Cloudflare 522 ERROR - Nginx - Fail2Ban



In my case I was using Ubuntu 16.04 with Fail2ban installed as if fail2ban takes the ips from nginx access log, Which has repeated cloudflare ips listed on the file (As if Cloudflare used as reverse proxy). Fail2Ban started block Cloudflare ips 

The solution would be logging the original ips of the request on the access file instead of Cloudflare ip

First check your Nginx has "ngx_http_realip_module"
nginx -V

If Enabled add the ips below to a file under conf.d 

set_real_ip_from 103.21.244.0/22;
set_real_ip_from 103.22.200.0/22;
set_real_ip_from 103.31.4.0/22;
set_real_ip_from 104.16.0.0/12;
set_real_ip_from 108.162.192.0/18;
set_real_ip_from 131.0.72.0/22;
set_real_ip_from 141.101.64.0/18;
set_real_ip_from 162.158.0.0/15;
set_real_ip_from 172.64.0.0/13;
set_real_ip_from 173.245.48.0/20;
set_real_ip_from 188.114.96.0/20;
set_real_ip_from 190.93.240.0/20;
set_real_ip_from 197.234.240.0/22;
set_real_ip_from 198.41.128.0/17;
set_real_ip_from 199.27.128.0/21;
set_real_ip_from 2400:cb00::/32;
set_real_ip_from 2606:4700::/32;
set_real_ip_from 2803:f800::/32;
set_real_ip_from 2405:b500::/32;
set_real_ip_from 2405:8100::/32;
set_real_ip_from 2c0f:f248::/32;
set_real_ip_from 2a06:98c0::/29;

# use any of the following two
real_ip_header CF-Connecting-IP;
#real_ip_header X-Forwarded-For;


CloudFlare ip might change so please check this link

Wednesday, August 3, 2016

nginx error - ERR_SPDY_INADEQUATE_TRANSPORT_SECURITY

If you get the following error 

This site can’t be reached
The webpage at https://yourdomain.com/ might be temporarily down or it may have moved permanently to a new web address.
ERR_SPDY_INADEQUATE_TRANSPORT_SECURITY

Change your nginx conf as follows

server
{
    listen 443 ssl http2;
    server_name yourdomain.com;
    ...
    ssl_ciphers 'ECDHE-RSA-AES128-GCM-SHA256:AES256+EECDH:AES256+EDH';
    ...
}

Reference : CloudFlare 

Sunday, June 12, 2016

Remove Skype ads



  1. Exit Skype
  2. Open Internet Explorer
  3. Open Internet Options
  4. Go to Security and select Restricted sites
  5. Click Sites
  6. Add https://apps.skype.com/, click OK
  7. Go to General, click Delete, and click Delete again
  8. Open Skype, the blank space should be gone and there will be no ads

I don't know what the implications are and whether there any issues with other skype apps, but so far this is the only possible solution that I can think of."

Saturday, June 4, 2016

Find malicious or hacked file in linux

First find the outgoing connections with the following command

netstat -nputwN

Check the connections and find the connection which is trying to attack the other systems. For example PID 11009 in this scenario.

Use the following command to identify the list of files involved in the process execution

lsof -p 11009


Tuesday, April 5, 2016

why mcrypt_create_iv is slow



If you don't specify argument for mcrypt_create_iv(), it will use /dev/random(on Linux) by default as a random number generator. The problem of /dev/random is that it's random pool depends on the system interrupts, when there is not enough system interrupts, it cannot generate enough random numbers, then the process tries to get the random numbers will wait and hang.

So instead of 
mcrypt_create_iv($size)
use 
mcrypt_create_iv($size, MCRYPT_DEV_URANDOM); 

See the difference then