List of Debian archive sites

http://ftp.XX.debian.org/debian/ stable (lenny) stable (lenny) release
http://ftp.XX.debian.org/debian/ testing (squeeze) testing (squeeze) release
http://ftp.XX.debian.org/debian/ unstable (sid) unstable (sid) release
http://ftp.XX.debian.org/debian/ experimental experimental pre-release (optional, only for developer)
http://ftp.XX.debian.org/debian/ stable-proposed-updates Updates for the next stable point release (optional)
http://security.debian.org/ stable/updates security updates for stable release (important)

настройка gre в debian

auto tun0
iface tun0 inet static
address 10.0.0.1
netmask 255.255.255.255
up ifconfig tun0 multicast
pre-up iptunnel add tun0 mode gre remote 222.222.222.222 local 111.111.111.111 ttl 255
pointopoint 10.0.0.2
post-down iptunnel del tun0

настройка vlan в debian

auto vlan2
iface vlan2 inet static
address 111.111.111.111
netmask 255.255.255.192
gateway 111.111.111.65
vlan_raw_device eth0

сборка deb-src

Вспомогательные программы
apt-get install debhelper build-essential

Скачать исходники из репозитория
apt-get source package

Распаковать
dpkg-source -x fluxbox_0.9.15.1+1.0rc2-1.dsc

Установить зависимые пакеты для сборки
apt-get build-dep fluxbox

cd fluxbox_0.9.15.1

Проверить зависимости
dpkg-checkbuilddeps

dch -i
fakeroot ./debian/rules binary

http://www.debian.org/doc/manuals/maint-guide/build.ru.html

bridge on debian with shorewall

man bridge-utils-interfaces

bridge config
/etc/network/interfaces

iface br0 inet static
    bridge_ports eth1 tap0
    address 10.10.10.10
    netmask 255.0.0.0

routeback option for br0
/etc/shorewall/interfaces

#ZONE   INTERFACE       BROADCAST       OPTIONS
loc     br0            detect          routeback

Building Debian packages of Perl modules

apt-get install dh-make-perl

dh-make-perl --build --cpan HTML::Template::JIT

or

cpan2deb Foo::Bar

tftp: client does not accept options

The --refuse option can be used to disable specific options; this may be necessary to work around bugs in specific TFTP client implementations.

/usr/sbin/in.tftpd --refuse blksize ...

apache: fix CVE-2011-3192

Добавить в /etc/apache2/conf.d/security:

Для Apache 2.2:

SetEnvIf Range (?:,.*?){5,5} bad-range=1
RequestHeader unset Range env=bad-range
RequestHeader unset Request-Range
CustomLog logs/range-CVE-2011-3192.log common env=bad-range

Для Apache 2.x и 1.3:

RewriteEngine on
RewriteCond %{HTTP:range} !(bytes=[^,]+(,[^,]+){0,4}$|^$)
RewriteRule .* - [F]
RequestHeader unset Request-Range

включить модуль headers:
a2enmod headers

перезапустить.

installing Adaptec StorMan v7_00_18781 on debian

wget http://download.adaptec.com/raid/storage_manager/asm_linux_x64_v7_00_187...
upack StorMan-7.00.x86_64.rpm
alien StorMan-7.00.x86_64.rpm

dpkg -i storman_7.00-18782_amd64.deb

aptitude -R install sun-java6-jre
aptitude install libxtst6 libxi6

--- StorMan.sh  2011-03-21 03:26:12.000000000 +0300
+++ StorMan.sh.new      2011-09-14 12:47:42.000000000 +0400
@@ -133,9 +133,9 @@
            if [ "$Arch" = "ia64" ];then 
              JAVA_HOME="./IBMJava2-ia64-13"   # use bundled JRE 64
           else            

Обновление информации о временных зонах в ручную

Для устарелых систем можно воспользоваться:

The compiled zoneinfo file appears to be platform and architecture independent, so if you have multiple machines to update you should be able to move the file as-is without running zic again. Similarly, you can just to pull updated zoneinfo files from a machine running a different Debian release, or even download the latest tzdata package from unstable, extract the zoneinfo files from within the .deb file, and install them into the /usr/share/zoneinfo directory tree.

User tags

sysrq taskset Swift equalizer tzdata search mysql pam exim4 bug debootstrap arping tftp firefox sftp cluster replication mdadm vim soa grub munin zRam SuperMicro rtl8723be sysfs freedos qemu vtysh dns mount glusterfs kernel sysctl.conf dstat iSCSI chromium openvpn numa profiling cgroups route KVM alsa docker leap second pulseaudio NFS security erase nginx xhost language /etc/network/interfaces gpg wordpress hdparm iptables drupal LSI boot php vrrpd qcow2 rkhunter iostat backtrace nfs4 opreport perl initrd CentOS MegaRAID glxinfo StorMan RT sg lubuntu rpm radeon raid5 sublime opcontrol 3Ware find OpenStack SpamAssassin git bscan ardour cpu gdb cpanm ansible top oprofile lxc OpenSSL gre X forwarding Areca limit_conn video virtualbox cfq centos 7 dhcp MODx fido7 tar corosync SYN storage HDFS ip HTTPS virsh sysresccd xfs source hotplug perlbrew ipmi dovecot cache arp DRBD ssh rtsp virt-install ulimit ubuntu netfilter fail2ban fio graylog2 scsi swap jackd debian lenny tin mkfs chroot su Salt dpkg deb performance rsync CPAN noop encrypt build usb xargs sysctl docker-compose PXE mariadb ps PTR java bind LVM conntrack vlan shellshock bridge youtube xen tiger nvidia exim proxy flash lstat raid newgrp idmapd ipmitool parallel ddos groups puppet keyboard slab tun ha in-addr.arpa pacemaker elliptics core dump vrrp backup regex lts squeeze cpu usage .htaccess wget apache AMD pvmove bonding htop shorewall asoundrc routing APU iowait bash gtk tool Adaptec etch alien quagga arch SSD bacula iops dhclient apt