Switch branches/tags
Nothing to show
Find file
Fetching contributors…
Cannot retrieve contributors at this time
executable file 313 lines (238 sloc) 12.4 KB
<?xml version="1.0" encoding="utf-8"?>
<!-- Created by Leo ( -->
<?xml-stylesheet ekr_test?>
<leo_file xmlns:leo="" >
<leo_header file_format="2" tnodes="0" max_tnode_index="0" clone_windows="0"/>
<globals body_outline_ratio="0.5" body_secondary_ratio="0.5">
<global_window_position top="50" left="50" height="500" width="700"/>
<global_log_window_position top="0" left="0" height="0" width="0"/>
<v t="template.20120807112617.1347" a="E"><vh>Shiva - Install &amp; Configuration</vh>
<v t="template.20120807112807.1352"><vh>Installation</vh></v>
<v t="template.20120807112807.1351" a="E"><vh>Configuration</vh>
<v t="template.20120807120617.1358"><vh>ShivaReceiver</vh></v>
<v t="template.20120807120617.1357"><vh>ShivaAnalyzer</vh></v>
<v t="template.20120807120617.1363"><vh>exim4</vh></v>
<v t="template.20120807114143.1356" a="E"><vh>Run</vh>
<v t="template.20120807120617.1361"><vh>ShivaReceiver</vh></v>
<v t="template.20120807120617.1360"><vh>ShivaAnalyzer</vh></v>
<v t="template.20120924125452.1377"><vh>BackUp</vh></v>
<v t="template.20120807120617.1362"><vh>Debugging</vh></v>
<v t="template.20120809005311.1369"><vh>Lamson Commands</vh></v>
<v t="template.20120809005311.1370"><vh>Network Config of Shiva</vh></v>
<v t="template.20120815011138.1373"><vh>MySQL Privileges</vh></v>
<v t="template.20120924125452.1378"><vh>MySQL Data Export</vh></v>
<v t="template.20120815011138.1374"><vh>Things to be automated</vh></v>
<v t="template.20121018145151.1381"><vh>Remote commands</vh></v>
<t tx="template.20120807112617.1347"></t>
<t tx="template.20120807112807.1351"></t>
<t tx="template.20120807112807.1352">1. Install Virtual Environment python-virtualenv
# apt-get install python-virtualenv
sudo pip install virtualenv
2. Install two virtual environments for Shiva
# cd Shiva/
# virtualenv ShivaReceiver
# virtualenv ShivaAnalyzer
For a different version of python in virtualenv
# virtualenv --python=/usr/bin/python2.7 myvirtualenv
3. Install lamson under both virtual environments
# Shiva/ShivaReceiver# source bin/activate
(Receiver)root@mail:/home/template/Desktop//ShivaReceiver# pip install lamson
# Shiva/ShivaAnalyzer# source bin/activate
(ShivaAnalyzer)root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer# pip install lamson
4. Generate projects under both virtual environments
(ShivaReceiver)root@mail:/home/template/Desktop/Shiva/ShivaReceiver# lamson gen -project iReceiver
(ShivaAnalyzer)root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer# lamson gen -project iAnalyzer
5. Install MySQLdb for Analyzer
(ShivaAnalyzer)root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer/iAnalyzer# apt-get build-dep python-mysqldb
(ShivaAnalyzer)root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer/iAnalyzer# pip install MySQL-python
Anyway, on following worked sometimes:
# sudo apt-get install libmysqlclient-dev
# pip -E /srv/someDir/ install -I MySQL-python
6. Install APScheduler for Analyzer to make counters '0' after fixed number of hours
pip install apscheduler
7. Install exim4 on local server for mail relay
# apt-get install exim4-daemon-light
When nothing is there on system:
#sudo apt-get install build-essential
#sudo apt-get install libreadline5-dev libncursesw5-dev libssl-dev libsqlite3-dev tk-dev libgdbm-dev libc6-dev libbz2-dev
Then download using the following command:
cd Downloads/
Extract and go to the dirctory
tar -xvf Python-2.7.2.tgz &amp;&amp; cd Python-2.7.2/
Now install using the command you just tried:
sudo make altinstall
# Install virtualenv-1.5.2 from source
<t tx="template.20120807114143.1356"></t>
<t tx="template.20120807120617.1357">1. Copy config files
# cp /home/template/Desktop/Temp/analyzer/LamsonAnalyser/lamson-analyser/config/ /home/template/Desktop/Shiva/ShivaAnalyzer/iAnalyzer/config/
# cp /home/template/Desktop/Temp/analyzer/LamsonAnalyser/lamson-analyser/config/ /home/template/Desktop/Shiva/ShivaAnalyzer/iAnalyzer/config/
2. Copy lamson/* files
Control flow: -&gt; ShivaTackleQueue -&gt; ShivaMailParser -&gt; ShivaMailRelayer -&gt; (ShivaOldSpam | ShivaNewSpam) -&gt;
6. Copy file
root@mail:~# cp /home/template/Desktop/Temp/analyzer/LamsonAnalyser/lamson-analyser/logs/ /home/template/Desktop/Shiva/ShivaAnalyzer/iAnalyzer/logs/
7. Edit settings in files
queuePath -&gt; config/
Relay IP -&gt; config/
<t tx="template.20120807120617.1358">1. Copy config files
# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/config/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/config/
# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/config/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/config/
2. Copy app/handlers files
root@mail # cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/app/handlers/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/app/handlers/
root@mail:~# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/app/handlers/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/app/handlers/
root@mail:~# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/app/handlers/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/app/handlers/
root@mail:~# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/app/handlers/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/app/handlers/
3. Replace buggy file lamson/
template@mail:~/Desktop/Shiva/ShivaReceiver/lib/python2.7/site-packages/lamson$ cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/lib/python2.6/site-packages/lamson/ ./
4. Copy lamson/ and lamson/
This file prepares and stores spams with IP and SensorID extensions
4. Copy global configuration files
root@mail:~# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/lib/python2.6/site-packages/lamson/ /home/template/Desktop/Shiva/ShivaReceiver/lib/python2.7/site-packages/lamson
5. Copy file
root@mail:~# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/
6. Copy file
root@mail:~# cp /home/template/Desktop/Temp/receiver/LamsonHoneyMail/MyMailServer/logs/ /home/template/Desktop/Shiva/ShivaReceiver/iReceiver/logs/
7. Edit settings in files
Sensor name -&gt; lamson/
Listening IP -&gt; config/
8. Edit signature of
/usr/lib/python2.7/ - line 84:
#__version__ = 'Python SMTP proxy version 0.2'
__version__ = 'ESMTP'
<t tx="template.20120807120617.1360">root@mail:/home/template/Desktop/Shiva# cd ShivaAnalyzer/
root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer# source bin/activate
(ShivaReceiver)root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer# cd iAnalyzer/
(ShivaReceiver)root@mail:/home/template/Desktop/Shiva/ShivaReceiver/iReceiver# lamson start --Force
To stop:
lamson stop -ALL run
root@mail:/home/template/Desktop/Shiva/ShivaAnalyzer/lib/python2.7/site-packages/lamson# ./
<t tx="template.20120807120617.1361">root@mail:/home/template/Desktop/Shiva# cd ShivaReceiver/
root@mail:/home/template/Desktop/Shiva/ShivaReceiver# source bin/activate
(ShivaReceiver)root@mail:/home/template/Desktop/Shiva/ShivaReceiver# cd iReceiver/
(ShivaReceiver)root@mail:/home/template/Desktop/Shiva/ShivaReceiver/iReceiver# ./
<t tx="template.20120807120617.1362">6.0 Gb is used space on local machine (df -h). Unusual high usage indicates larger size of log files
* Check ShivaReceiver/iReceiver/logs for errors
* Schedule regular log deletion and undelivered mails in /iReceiver/run/undelivered/*
# Foreign IPs connected to server:
netstat -natp | grep -i established | awk '{ print $5}' | cut -d":" -f1 | sort | wc -l
# IPtables to restrict maximum number of connections per IP:
iptables -A INPUT -p tcp --syn --dport 25 -m connlimit --connlimit-above 3 -j REJECT --reject-with tcp-reset
iptables -L
# Deleting tons of files:
find . -type f -print -delete
# Moving or deleting tons of files:
find . -name "*" -print | xargs rm
# Checking size of a directory:
du -h
du -h *
# While processing spams which are entitled to get relayed, </t>
<t tx="template.20120807120617.1363"># dpkg-reconfigure exim4-config
Opted for "internet site; mail is ent and received directly using SMTP"
Configured hostname to before configuring exim4
(hostname, vim /etc/hostname)
# vim /etc/exim4/exim4.conf.template
# running on local host and listening on interface If needed to run on all interfaces:
local_interfaces =
and commentout following in config file:
# listen on all all interfaces?
local_interfaces = MAIN_LOCAL_INTERFACES
# Removal:
apt-get remove exim4 exim4-base exim4-config exim4-daemon-light
sudo aptitude purge exim4
sudo aptitude purge exim4-config
rm -r /var/log/exim4</t>
<t tx="template.20120809005311.1369">lamson start
lamson start --Force
lamson stop
lamson stop -ALL run</t>
<t tx="template.20120809005311.1370">vim /etc/network/interfaces
/etc/init.d/networking restart
This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
# The primary network interface
#auto eth0
#iface eth0 inet dhcp
# Static IP manually assigned - b0nd 08082012
auto eth0
iface eth0 inet static
address x.x.x.x
broadcast x.x.x.x
gateway x.x.x.x
auto eth1
iface eth1 inet static
<t tx="template.20120815011138.1373">On local console of BackEnd MySQL Server:
# mysql -u root -p
(mysql -u root -p -h &lt;IP&gt;
mysql&gt; GRANT ALL PRIVILEGES ON *.* TO 'root'@'' IDENTIFIED BY 'password';
# Solution to MySql has gone away:
By default it keep connection for 8 hours (8*3600 seconds)
mysql&gt; show variables like 'wait_timeout';
Edit my.cnf and add
86400 / 3600 = 24 hours
restart mysqld
# Indexing from command line:
ALTER TABLE `spam` ADD INDEX(htmlMessage(996));
# Optimizing tables:
OPTIMIZE TABLE table_name;
<t tx="template.20120815011138.1374">In addition to initial stuff of installation, configuring and running lamson, following too needs automation:
1. Deleting ShivaDistortedSamples directory as its size keeps on building up:
rm -r ShivaDistortedSamples ; mkdir ShivaDistortedSamples
2. Flush out established connections regularly or put a limit if &gt;1000 then disestablish all
3. Delete files from Shiva/ShivaReceiver/iReceiver/run/undeliverable:
find . -name "*" -print | xargs rm
4. Restart both, iReceiver and iAnalyzer each xx number of hours. That would resolve following problems:
1. Kill all "ESTABLISHED" connections
2. MySQL has gone away - the connection to SQL server is established only when iAnalyzer is started</t>
<t tx="template.20120924125452.1377"># Using rar to take backup of whole tree:
rar a -r LamsonAnalyzer.rar LamsonAnalyzer/
rar a -r LamsonReceiver.rar LamsonReceiver/</t>
<t tx="template.20120924125452.1378"># mysqldump --opt --where="1 limit 400" databaseName -u root -p &gt; output.sql</t>
<t tx="template.20121018145151.1381">
# mysql -u root -p -h
# ssh -l template</t>