<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-7382743552317375371</id><updated>2011-11-27T15:14:41.922-08:00</updated><category term='Segurança'/><category term='FreeBSD'/><category term='CISCO'/><category term='críticas e sugestões'/><category term='Firewall'/><category term='informações gerais'/><title type='text'>FreeBSD: O Poder dos Servidores em Suas Mãos</title><subtitle type='html'>Este livro tem a finalidade de apresentar o sistema operacional FreeBSD, conduzindo o leitor no universo dos sistemas BSD (Berkeley Software Distribuition) usando técnicas para a proteção de dados, tuning, troubleshooting, ITIL (Information Technology Infrastructure Library) e com a norma NBR ISO/IEC 27002.</subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>26</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-6685701189570722658</id><published>2010-11-26T08:14:00.000-08:00</published><updated>2010-11-26T08:16:48.356-08:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='CISCO'/><category scheme='http://www.blogger.com/atom/ns#' term='FreeBSD'/><category scheme='http://www.blogger.com/atom/ns#' term='Firewall'/><category scheme='http://www.blogger.com/atom/ns#' term='Segurança'/><title type='text'>Segurança de Dados: Solução ou Obstáculo</title><content type='html'>&lt;p class="MsoNormal" style="text-align:justify"&gt;Quando se projeta um ambiente seguro, a primeira solução que chega à mente é a compra de um hardware onde acredita-se que vai bloquear todos os acessos não autorizados, proteger a rede de dados e os usuários que dela depende. &lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;Entretanto, isto é apenas uma parte da solução e não a solução como um todo.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Para entender melhor, um sistema de segurança tem em sua composição três pilares: o hardware, as pessoas e as normas ou processos que regem o que e como serão feitas as atividades. Olhando do ponto de vista da segurança da informação como gestão, também é comum encontramos na literatura uma extensão deste conceito diluído da sigla &lt;b style="mso-bidi-font-weight:normal"&gt;CIDAL&lt;/b&gt;-&lt;b style="mso-bidi-font-weight: normal"&gt;C&lt;/b&gt;onfidencialidade &lt;b style="mso-bidi-font-weight:normal"&gt;I&lt;/b&gt;ntegridade &lt;b style="mso-bidi-font-weight:normal"&gt;D&lt;/b&gt;isponibilidade &lt;b style="mso-bidi-font-weight: normal"&gt;A&lt;/b&gt;utenticidade e &lt;b style="mso-bidi-font-weight:normal"&gt;L&lt;/b&gt;egalidade.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;A &lt;i style="mso-bidi-font-style: normal"&gt;Confidencialidade&lt;/i&gt; garante que a informação deve ser disseminada somente para aqueles que realmente necessitam da informação. A &lt;i style="mso-bidi-font-style:normal"&gt;Integridade&lt;/i&gt; garante que o controle da adulteração seja feito. Já a &lt;i style="mso-bidi-font-style:normal"&gt;Disponibilidade&lt;/i&gt; controla o quanto e como a informação estará acessível no momento desejado. A &lt;i style="mso-bidi-font-style:normal"&gt;Autenticidade&lt;/i&gt; prevê a autenticação para acesso a informação e a &lt;i style="mso-bidi-font-style:normal"&gt;Legalidade&lt;/i&gt; auxilia a criar procedimentos, normas ou diretrizes que terão respaldo legal.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Retornando a figura do firewall, é bom ter em mente que é possível compor uma solução segura, proativa, inteligente e resistente a ataques usando diversos fornecedores como Microsoft ISA Server, Check Point, CISCO ASA, Juniper e muitos outros, mas também podemos ter um resultado muito bom com uma solução de firewall open source como o OpenBSD, um sistema operacional BSD (Berkeley Software Distribution) criado especificamente para a tarefa de firewall. &lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Estudando um pouco mais a fundo este modelo de firewall, verifica-se estruturas presentes no arquivo de configuração do OpenBSD (&lt;span style="'font-size:10.0pt;line-height:115%;"&gt;/etc/pf.conf&lt;/span&gt;) que facilitam a elaboração de um firewall. Este arquivo é lido no processo de inicialização do firewall ou interpretado pelo comando &lt;i style="mso-bidi-font-style:normal"&gt;&lt;span style="'font-family:"&gt;pfctl&lt;/span&gt;&lt;/i&gt;. São exemplos destas estruturas: &lt;i style="mso-bidi-font-style:normal"&gt;macros&lt;/i&gt;, &lt;i style="mso-bidi-font-style:normal"&gt;tabelas&lt;/i&gt;, regras de bloqueio previamente elaboradas e uma sintaxe de fácil entendimento. Fazemos uso de &lt;i style="mso-bidi-font-style:normal"&gt;macros&lt;/i&gt; quando é desejado o uso de uma variável para guardar endereços IP ou representação de interfaces:&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;&lt;span style="'font-size:10.0pt;line-height:115%;font-family:"&gt;Servidores_Web=”{10.1.10.3, 10.1.10.4, 10.100.10.1, 192.168.20.1}”&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;&lt;span style="'font-size:10.0pt;line-height:115%;font-family:"&gt;Notebook_para_Gerenciamento=”192.168.1.10”&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="'font-size:10.0pt;"&gt;Interface_Externa=”fxp0”&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Como os ambientes BSD possuem uma codificação de interface para cada fornecedor de hardware, veja que &lt;i style="mso-bidi-font-style:normal"&gt;fxp0&lt;/i&gt; representa uma interface de rede fabricada pela Intel e esta codificação pode ser depositada em uma macro para facilitar. Havendo outra placa deste mesmo fornecedor, o dispositivo encontrado seria &lt;i style="mso-bidi-font-style:normal"&gt;fxp1&lt;/i&gt; e assim em diante.&lt;span style="mso-spacerun:yes"&gt;  &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Quando se deseja algo mais flexível, com uma composição mais dinâmica, incluindo ou removendo endereços IP a qualquer momento, faz-se uso de estruturas chamadas de &lt;i style="mso-bidi-font-style: normal"&gt;tabelas&lt;/i&gt;:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="'font-size:10.0pt;"&gt;&lt;span style="mso-spacerun:yes"&gt; &lt;/span&gt;table &lt;maquinas_importantes&gt; { 192.168.10.1, 10.1.15.20/24}&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Observe que foi feito uso de um endereço de rede (&lt;span style="'font-size:10.0pt;line-height:115%;font-family:"&gt;10.1.15.20/24&lt;/span&gt;) junto com um endereço de host dentro da tabela. Como temos flexibilidade, pode-se em tempo de execução, excluir um endereço:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="'font-size:10.0pt;"&gt;# pfctl -t Maquinas_Importantes -T delete 192.168.10.1 &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Ou incluir novos endereços:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="'font-size:10.0pt;"&gt;# pfctl -t Maquinas_Importantes -T add 192.168.15.10 &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Pode-se ainda verificar o conteúdo de uma tabela:&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span style="'font-size:10.0pt;"&gt;# pfctl -t Maquinas_Importantes -T show &lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Veja como seria simples implementar regras mais complexas incluindo as linhas seguintes no arquivo &lt;span style="'font-size:10.0pt;line-height:115%;font-family:"&gt;/etc/pf.conf&lt;/span&gt;:&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/p&gt;  &lt;table class="MsoTableGrid" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none;mso-yfti-tbllook:1184;mso-padding-alt:  0cm 5.4pt 0cm 5.4pt;mso-border-insideh:none;mso-border-insidev:none"&gt;  &lt;tbody&gt;&lt;tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span style="'font-size:10.0pt;font-family:"&gt;Servidor_Web=”192.168.1.10”&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:1"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#D99594;mso-themecolor:accent2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;2&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span style="'font-size:10.0pt;font-family:"&gt;Interface_Externa=”rl0’”&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:2"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;3&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;table &lt;&gt; &lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:3"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#D99594;mso-themecolor:accent2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;4&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;block in   quick from &lt;&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:4;mso-yfti-lastrow:yes"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;5&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;pass in on $Interface_Externa   proto tcp to $Servidor_Web port www flags S/SA keep state \&lt;/span&gt;&lt;/p&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;(max-src-conn   150, max-src-conn-rate 10/5, overload &lt;&gt; flush)&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;&lt;span lang="EN-US" style="mso-ansi-language:EN-US"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Ver-se com esta composição que:&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpFirst" style="text-align:justify;text-indent:-18.0pt; mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Wingdings; mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;ü&lt;span style="'font:7.0pt"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;As duas primeiras linhas definem o endereço do servidor Web e a interface de rede usada para mitigar o ataque;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align:justify;text-indent:-18.0pt; mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Wingdings; mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;ü&lt;span style="'font:7.0pt"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;A terceira linha define a tabela que será usada para bloqueio;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpMiddle" style="text-align:justify;text-indent:-18.0pt; mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Wingdings; mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;ü&lt;span style="'font:7.0pt"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;Na quarta linha pode-se fazer um bloqueio imediato (&lt;span style="'font-size:10.0pt;"&gt;quick&lt;/span&gt;) de todos os endereços IP presentes nesta tabela;&lt;/p&gt;  &lt;p class="MsoListParagraphCxSpLast" style="text-align:justify;text-indent:-18.0pt; mso-list:l0 level1 lfo1"&gt;&lt;span style="font-family:Wingdings; mso-fareast-font-family:Wingdings;mso-bidi-font-family:Wingdings"&gt;&lt;span style="mso-list:Ignore"&gt;ü&lt;span style="'font:7.0pt"&gt;  &lt;/span&gt;&lt;/span&gt;&lt;/span&gt;A ultima linha faz diversas atividades, dentre elas deixa passar para o servidor Web somente às conexões com o protocolo &lt;span style="'font-size:10.0pt;"&gt;tcp &lt;/span&gt;que respeitam uma regra previamente estabelecida: limite de conexões menor ou igual a 150 e sem superar a taxa de 10 conexões a cada 5 segundos. O desrespeito a esta regra, coloca o endereço IP do usuário dentro de uma lista de bloqueio e cancela as conexões existentes.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Imaginando um ambiente que tem como hardware um CISCO ASA, tem-se algo bem similar para o seu arquivo de configuração:&lt;/p&gt;  &lt;table class="MsoTableGrid" border="0" cellspacing="0" cellpadding="0" style="border-collapse:collapse;border:none;mso-yfti-tbllook:1184;mso-padding-alt:  0cm 5.4pt 0cm 5.4pt;mso-border-insideh:none;mso-border-insidev:none"&gt;  &lt;tbody&gt;&lt;tr style="mso-yfti-irow:0;mso-yfti-firstrow:yes"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;1&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;ASA(config)#   access-list &lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="color:#76923C;   mso-themecolor:accent3;mso-themeshade:191;text-transform:uppercase"&gt;conn-limit-acl&lt;/span&gt;&lt;/b&gt;&lt;span style="color:#76923C;mso-themecolor:accent3;mso-themeshade:191"&gt; &lt;/span&gt;extended   permit &lt;b style="mso-bidi-font-weight:normal"&gt;tcp&lt;/b&gt; any host &lt;b style="mso-bidi-font-weight:normal"&gt;192.168.1.10&lt;/b&gt; eq &lt;b style="mso-bidi-font-weight:   normal"&gt;80&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:1"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#D99594;mso-themecolor:accent2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;2&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;ASA(config)#   class-map &lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="color:#548DD4;   mso-themecolor:text2;mso-themetint:153;text-transform:uppercase"&gt;conn-limit-class&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:2"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;3&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;ASA(config-cmap)#   match access-list &lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="color:#76923C;mso-themecolor:accent3;mso-themeshade:191;text-transform:   uppercase"&gt;conn-limit-acl&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:3"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#D99594;mso-themecolor:accent2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;4&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;ASA(config)#   policy-map &lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="color:#943634;   mso-themecolor:accent2;mso-themeshade:191;text-transform:uppercase"&gt;conn-limit-policy&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:4"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;5&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;ASA(config-pmap)#   class &lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span style="color:#548DD4;   mso-themecolor:text2;mso-themetint:153;text-transform:uppercase"&gt;conn-limit-class&lt;/span&gt;&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:5"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#D99594;mso-themecolor:accent2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;6&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;"&gt;ASA(config-pmap)#   set connection embryonic-conn-max &lt;b style="mso-bidi-font-weight:normal"&gt;150&lt;/b&gt;   per-client-max &lt;b style="mso-bidi-font-weight:normal"&gt;10&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt;  &lt;tr style="mso-yfti-irow:6;mso-yfti-lastrow:yes"&gt;   &lt;td width="26" valign="top" style="width:19.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align:   justify;line-height:normal"&gt;&lt;b style="mso-bidi-font-weight:normal"&gt;&lt;span lang="EN-US" style="color:#548DD4;mso-themecolor:text2;mso-themetint:153;   mso-ansi-language:EN-US"&gt;7&lt;/span&gt;&lt;/b&gt;&lt;/p&gt;   &lt;/td&gt;   &lt;td width="550" valign="top" style="width:412.6pt;padding:0cm 5.4pt 0cm 5.4pt"&gt;   &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;line-height:   normal"&gt;&lt;span lang="EN-US" style="'font-size:10.0pt;font-family:"&gt;ASA(config)# service-policy &lt;b style="mso-bidi-font-weight:   normal"&gt;&lt;span style="color:#943634;mso-themecolor:accent2;mso-themeshade:   191;text-transform:uppercase"&gt;conn-limit-policy&lt;/span&gt;&lt;/b&gt; interface &lt;b style="mso-bidi-font-weight:normal"&gt;EXT&lt;/b&gt;&lt;/span&gt;&lt;/p&gt;   &lt;/td&gt;  &lt;/tr&gt; &lt;/tbody&gt;&lt;/table&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;&lt;span lang="EN-US" style="mso-ansi-language:EN-US"&gt;&lt;o:p&gt; &lt;/o:p&gt;&lt;/span&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;A primiera linha cria a access-list &lt;i style="mso-bidi-font-style:normal"&gt;&lt;span style="'font-size:10.0pt;"&gt;conn-limit-acl&lt;/span&gt;&lt;/i&gt; para permitir o acesso a porta 80 comprotocolo TCP para o servidor Web 192.168.1.10. A segunda linha cria um &lt;i style="mso-bidi-font-style:normal"&gt;&lt;span style="'font-size:10.0pt;line-height:115%;font-family:"&gt;class-map&lt;/span&gt;&lt;/i&gt;, uma classe que auxiliará na análise do tráfego. Na terceira linha o comando &lt;i style="mso-bidi-font-style:normal"&gt;&lt;span style="'font-size:10.0pt;line-height:"&gt;match access-list&lt;/span&gt;&lt;/i&gt; identifica o tráfego que será analisado. A quarta e quinta linhas definem a política (policy) para enviar o tráfego para o AIP SSM (Advanced Inspection and Prevention Security Services Module). Na sexta linha define o número máximo de conexões TCP a 150 e limita o número de 10 conexões por host. Para concluir a sétima linha aplica a política na interface externa definida pelo nome &lt;i style="mso-bidi-font-style:normal"&gt;&lt;span style="'font-size:10.0pt;line-height:"&gt;EXT&lt;/span&gt;&lt;/i&gt;.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;O que foi visto aqui é um pequeno leque do que vem a ser segurança da informação e deve-se ter em mente que manter um sistema seguro é acima de tudo manter as pessoas conscientes de que todos possuem um papel importante e que existem técnicas chamadas de Engenharia Social que testam, a cada segundo o quão seguro este sistema é, analisando o que muitos denominam como “aspecto comportamental do indivíduo”. Mas isto é tema para outro artigo.&lt;/p&gt;  &lt;p class="MsoNormal" style="text-align:justify"&gt;Referências:&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;OpenBSD: &lt;a href="http://www.openbsd.org"&gt;www.openbsd.org&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;Filtro de pacotes do OpenBSD: &lt;a href="http://www.openbsd.org/faq/pf/pt/tables.html"&gt;http://www.openbsd.org/faq/pf/pt/tables.html&lt;/a&gt; &lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;Os Pilares da Segurança: &lt;a href="http://www.via6.com/topico/60533/os-pilares-da-seguranca"&gt;http://www.via6.com/topico/60533/os-pilares-da-seguranca&lt;/a&gt;&lt;/p&gt;  &lt;p class="MsoNormal" style="margin-bottom:0cm;margin-bottom:.0001pt;text-align: justify"&gt;Microsoft ISA Server: &lt;a href="http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/"&gt;http://www.microsoft.com/forefront/edgesecurity/isaserver/en/us/&lt;/a&gt; &lt;/p&gt;  &lt;p class="MsoNormal"&gt;CISCO ASA exemplos: &lt;a href="http://informationsecuritytips.com/2010/07/cisco-asa-embryonic-tcp-connection-and-per-client-connection-limits-config-example/"&gt;http://informationsecuritytips.com/2010/07/cisco-asa-embryonic-tcp-connection-and-per-client-connection-limits-config-example/&lt;/a&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-6685701189570722658?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/6685701189570722658/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2010/11/seguranca-de-dados-solucao-ou-obstaculo.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6685701189570722658'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6685701189570722658'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2010/11/seguranca-de-dados-solucao-ou-obstaculo.html' title='Segurança de Dados: Solução ou Obstáculo'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-8556889750733725474</id><published>2009-10-07T11:49:00.000-07:00</published><updated>2009-10-07T11:53:54.697-07:00</updated><title type='text'>Palestra FreeBSD x Linux</title><content type='html'>&lt;p&gt;Pessoal,&lt;/p&gt;&lt;p&gt;   Já foi publicado o debate que participei comparando Linux com FreeBSD, anotem o link:&lt;/p&gt;&lt;p&gt;http://www.4linux.com.br/noticias/2009/linux-versus-freebsd-este-foi-tema-boteconet-realizado-dia-01-outubro-2009&lt;/p&gt;&lt;p&gt;[]´,s&lt;/p&gt;&lt;p&gt; Denis&lt;/p&gt;&lt;p&gt;&lt;br /&gt;&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-8556889750733725474?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/8556889750733725474/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/10/palestra-freebsd-x-linux.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/8556889750733725474'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/8556889750733725474'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/10/palestra-freebsd-x-linux.html' title='Palestra FreeBSD x Linux'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-7712432669633205670</id><published>2009-07-11T04:45:00.000-07:00</published><updated>2009-07-11T05:05:37.561-07:00</updated><title type='text'>Errata</title><content type='html'>A &lt;strong&gt;errata &lt;/strong&gt;do livro foi atulizada e pode ser obtida no site da editora Novatec: &lt;a href="http://www.novatec.com.br/"&gt;www.novatec.com.br&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;Um anova versão deve estar disponível depois de 15/07/09!&lt;br /&gt;&lt;br /&gt;Abração,&lt;br /&gt; Denis&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-7712432669633205670?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/7712432669633205670/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/errata.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/7712432669633205670'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/7712432669633205670'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/errata.html' title='Errata'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-7516840942668072780</id><published>2009-07-09T17:45:00.000-07:00</published><updated>2009-09-23T10:31:09.485-07:00</updated><title type='text'>Qual a diferençla entre RAID 1+0 e RAID 0+1?</title><content type='html'>Qual a diferença entre &lt;span style="font-family:arial;"&gt;RAID 1+0&lt;/span&gt; e &lt;span style="font-family:arial;"&gt;RAID 0+1&lt;/span&gt;&lt;a style="mso-footnote-id: ftn1" title="" href="http://www.blogger.com/post-create.g?blogID=7382743552317375371&amp;amp;pli=1#_ftn1" name="_ftnref1"&gt;[1]&lt;/a&gt;? A Wordpress tem um ótimo exemplo que explica bem esta diferença. Digamos que tenhamos 10 discos e vamos arranja-los em &lt;span style="font-family:arial;"&gt;RAID 1+0&lt;/span&gt; e RAID &lt;span style="font-family:arial;"&gt;0+1&lt;/span&gt;.&lt;br /&gt;&lt;br /&gt;Iniciando por &lt;span style="font-family:arial;"&gt;RAID 1+0&lt;/span&gt;, veremos que teremos 5 pares de HDs (figura 1):&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/__MKYiCVymqo/SlaPrPBXCzI/AAAAAAAAABM/HGgdup9XXaA/s1600-h/Figura_09_08.png"&gt;&lt;img style="WIDTH: 334px; HEIGHT: 197px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5356626779733166898" border="0" alt="" src="http://4.bp.blogspot.com/__MKYiCVymqo/SlaPrPBXCzI/AAAAAAAAABM/HGgdup9XXaA/s320/Figura_09_08.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Figura 1 – &lt;span style="font-family:arial;"&gt;RAID 1+0&lt;/span&gt; em detalhes&lt;br /&gt;&lt;br /&gt;O &lt;span style="font-family:arial;"&gt;RAID-0&lt;/span&gt; (stripe) será feito do espelhamento A ao E. Podemos ter &lt;span style="font-family:arial;"&gt;5 &lt;/span&gt;HDs falhando ao mesmo tempo que o sistema vai continuar funcionando. Entretanto, se tivermos a disposição destes HDs em &lt;span style="font-family:arial;"&gt;RAID 0+1&lt;/span&gt; veremos que na falha de dois HDs simultaneamente, um em cada stripe, tudo será perdido (figura 2).&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a href="http://3.bp.blogspot.com/__MKYiCVymqo/SlaQO2PXjAI/AAAAAAAAABk/0zcXGPMtquA/s1600-h/Figura_09_09.png"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 110px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5356627391556324354" border="0" alt="" src="http://3.bp.blogspot.com/__MKYiCVymqo/SlaQO2PXjAI/AAAAAAAAABk/0zcXGPMtquA/s320/Figura_09_09.png" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Figura 2 – &lt;span style="font-family:arial;"&gt;RAID 0+1&lt;/span&gt; em detalhes&lt;br /&gt;&lt;br /&gt;Uma boa fonte de estudos sobre RAID é o site AC&amp;amp;NC (&lt;a href="http://www.acnc.com/04_00.html"&gt;http://www.acnc.com/04_00.html&lt;/a&gt;). São discutidas as metodologias de RAID, juntamente com testes de benchmarks para sistemas operacionais como Windows, Unix e DOS.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;Abração,&lt;br /&gt;Denis&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;a style="mso-footnote-id: ftn1" title="" href="http://www.blogger.com/post-create.g?blogID=7382743552317375371&amp;amp;pli=1#_ftnref1" name="_ftn1"&gt;[1]&lt;/a&gt; &lt;a href="http://decipherinfosys.wordpress.com/2008/01/15/difference-between-raid-01-vs-raid-10/"&gt;http://decipherinfosys.wordpress.com/2008/01/15/difference-between-raid-01-vs-raid-10/&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-7516840942668072780?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/7516840942668072780/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/qual-diferencla-entre-raid-10-e-raid-01.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/7516840942668072780'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/7516840942668072780'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/qual-diferencla-entre-raid-10-e-raid-01.html' title='Qual a diferençla entre RAID 1+0 e RAID 0+1?'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/__MKYiCVymqo/SlaPrPBXCzI/AAAAAAAAABM/HGgdup9XXaA/s72-c/Figura_09_08.png' height='72' width='72'/><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-6652309516845961934</id><published>2009-07-09T13:25:00.001-07:00</published><updated>2009-07-09T13:26:23.686-07:00</updated><title type='text'>Introdução ao FreeBSD 7.0</title><content type='html'>Uma palestra do Kris Kennaway introduzindo o FreeBSD 7.0 para quem ainda não conhece o FreeBSD!!! &lt;div style="TEXT-ALIGN: left; WIDTH: 425px" id="__ss_172895"&gt;&lt;a style="MARGIN: 12px 0px 3px; DISPLAY: block; FONT: 14px Helvetica,Arial,Sans-serif; TEXT-DECORATION: underline" title="Introduction to FreeBSD 7.0" href="http://www.slideshare.net/sim303/7020-preview"&gt;Introduction to FreeBSD 7.0&lt;/a&gt;&lt;object style="MARGIN: 0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=7020-preview-11955518208653-2&amp;amp;stripped_title=7020-preview"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=7020-preview-11955518208653-2&amp;stripped_title=7020-preview" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="FONT-FAMILY: tahoma,arial; HEIGHT: 26px; FONT-SIZE: 11px; PADDING-TOP: 2px"&gt;View more &lt;a style="TEXT-DECORATION: underline" href="http://www.slideshare.net/"&gt;documents&lt;/a&gt; from &lt;a style="TEXT-DECORATION: underline" href="http://www.slideshare.net/sim303"&gt;sim303&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-6652309516845961934?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/6652309516845961934/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/introduction-to-freebsd-70.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6652309516845961934'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6652309516845961934'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/introduction-to-freebsd-70.html' title='Introdução ao FreeBSD 7.0'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-9186622556484959879</id><published>2009-07-09T11:53:00.000-07:00</published><updated>2009-07-09T12:18:37.139-07:00</updated><title type='text'>Usando mais de um HD iSCSI ao mesmo tempo com FreeBSD</title><content type='html'>Quem já usou o iSCSI-target &lt;em&gt;(/usr/ports/net/iscsi-target&lt;/em&gt;) presente no ports do FreeBSD? Quem usou sabe que ele transforma o FreeBSD em um poderoso servidor iSCSI, mas sabemos que por padrão o FreeBSD já vem prontinho para ser cliente iSCSI.&lt;br /&gt;&lt;br /&gt;Como exemplo, vamos definir um servidor iSCSI identificado pelo &lt;strong&gt;TargetName&lt;/strong&gt; &lt;em&gt;iqn.1994-04.org.netbsd.iscsi-target&lt;/em&gt; equipado com dois discos "virtuais" iSCSI (&lt;strong&gt;&lt;span style="font-family:arial;"&gt;target0&lt;/span&gt;&lt;/strong&gt; e &lt;strong&gt;target1&lt;/strong&gt;) sendo usado por um FreeBSD. Primiero vamos depositar as informações necessárias no arquivo&lt;strong&gt; /etc/iscsi.conf&lt;/strong&gt;:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;# more /etc/iscsi.conf&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;target0&lt;/span&gt; {&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;targetaddress=192.168.241.50&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;targetname= iqn.1994-04.org.netbsd.iscsi-target:target0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;span style="font-family:arial;"&gt;target1&lt;/span&gt; {&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;targetaddress=192.168.241.50&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;targetname= iqn.1994-04.org.netbsd.iscsi-target:target1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;}&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Agora vamos fazer o acesso aos discos iSCSI com:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# kldload iscsi_initiator&lt;br /&gt;# iscontrol -n target0&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# iscontrol -n target1&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Imaginando que os discos iSCSI não estão formatados, vamos fazer:&lt;br /&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# mkdir /mnt/&lt;/span&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;iSCSI_HD1&lt;br /&gt;# fdisk –vBI /dev/&lt;/span&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;da0&lt;br /&gt;# disklabel –w da0s1&lt;br /&gt;# newfs –U –L iSCSI1 /dev/da0s1&lt;br /&gt;# mount /dev/da0s1 /mnt/iSCSI_HD1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:Arial;font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# mkdir /mnt/iSCSI_HD2&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# fdisk –vBI /dev/da1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# disklabel –w da1s1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# newfs –U –L iSCSI2 /dev/da1s1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-family:arial;font-size:85%;"&gt;# mount /dev/da1s1 /mnt/iSCSI_HD2&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;Verifique o arquivo de logs &lt;strong&gt;/var/log/messages&lt;/strong&gt; para identificar os dispositivos que ficaram disponíveis para uso do acesso iSCSI. No exemplo deste artigo, os dispositivos foram &lt;strong&gt;da0&lt;/strong&gt; e &lt;strong&gt;da1&lt;/strong&gt;.&lt;br /&gt;&lt;br /&gt;Abração,&lt;br /&gt;Denis&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-9186622556484959879?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/9186622556484959879/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/usando-mais-de-um-hd-iscsi-ao-mesmo.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/9186622556484959879'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/9186622556484959879'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/usando-mais-de-um-hd-iscsi-ao-mesmo.html' title='Usando mais de um HD iSCSI ao mesmo tempo com FreeBSD'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-2231607962463728030</id><published>2009-07-09T10:19:00.000-07:00</published><updated>2009-07-09T06:19:25.275-07:00</updated><title type='text'>Palestra FreeBSD com Alta Disponibilidade</title><content type='html'>Check out this SlideShare Presentation: &lt;div style="TEXT-ALIGN: left; WIDTH: 425px" id="__ss_809321"&gt;&lt;a style="MARGIN: 12px 0px 3px; DISPLAY: block; FONT: 14px Helvetica,Arial,Sans-serif; TEXT-DECORATION: underline" title="FreeBsd com Alta Disponibilidade" href="http://www.slideshare.net/4linux/freebsd-com-alta-disponibilidade-presentation"&gt;FreeBsd com Alta Disponibilidade&lt;/a&gt;&lt;object style="MARGIN: 0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=freebsd-com-alta-disponibilidade-v1-1228222555729723-8&amp;amp;stripped_title=freebsd-com-alta-disponibilidade-presentation"&gt;&lt;param name="allowFullScreen" value="true"&gt;&lt;param name="allowScriptAccess" value="always"&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=freebsd-com-alta-disponibilidade-v1-1228222555729723-8&amp;stripped_title=freebsd-com-alta-disponibilidade-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="FONT-FAMILY: tahoma,arial; HEIGHT: 26px; FONT-SIZE: 11px; PADDING-TOP: 2px"&gt;View more &lt;a style="TEXT-DECORATION: underline" href="http://www.slideshare.net/"&gt;presentations&lt;/a&gt; from &lt;a style="TEXT-DECORATION: underline" href="http://www.slideshare.net/4linux"&gt;Boteco 4linux&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-2231607962463728030?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/2231607962463728030/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/freebsd-com-alta-disponibilidade.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/2231607962463728030'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/2231607962463728030'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/freebsd-com-alta-disponibilidade.html' title='Palestra FreeBSD com Alta Disponibilidade'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-7799854317817970190</id><published>2009-07-09T06:16:00.001-07:00</published><updated>2009-07-09T06:16:47.176-07:00</updated><title type='text'>Integrando FreeBSD com Active Directory e OpenLDAP</title><content type='html'>Uma boa fonte de estudo é a palestra do Rafael Sales sobre integração de FreeBSD com AD e OpenLDAP. Vale dar uma olhada...&lt;div style="width:425px;text-align:left" id="__ss_824438"&gt;&lt;a style="font:14px Helvetica,Arial,Sans-serif;display:block;margin:12px 0 3px 0;text-decoration:underline;" href="http://www.slideshare.net/adorepump/integrando-freebsd-com-active-directory-e-openldap-presentation" title="Integrando FreeBSD com Active Directory e OpenLDAP"&gt;Integrando FreeBSD com Active Directory e OpenLDAP&lt;/a&gt;&lt;object style="margin:0px" width="425" height="355"&gt;&lt;param name="movie" value="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=freebsdldaprafaelfloriano-1228580573150094-9&amp;stripped_title=integrando-freebsd-com-active-directory-e-openldap-presentation" /&gt;&lt;param name="allowFullScreen" value="true"/&gt;&lt;param name="allowScriptAccess" value="always"/&gt;&lt;embed src="http://static.slidesharecdn.com/swf/ssplayer2.swf?doc=freebsdldaprafaelfloriano-1228580573150094-9&amp;stripped_title=integrando-freebsd-com-active-directory-e-openldap-presentation" type="application/x-shockwave-flash" allowscriptaccess="always" allowfullscreen="true" width="425" height="355"&gt;&lt;/embed&gt;&lt;/object&gt;&lt;div style="font-size:11px;font-family:tahoma,arial;height:26px;padding-top:2px;"&gt;View more &lt;a style="text-decoration:underline;" href="http://www.slideshare.net/"&gt;documents&lt;/a&gt; from &lt;a style="text-decoration:underline;" href="http://www.slideshare.net/adorepump"&gt;adorepump&lt;/a&gt;.&lt;/div&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-7799854317817970190?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/7799854317817970190/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/integrando-freebsd-com-active-directory.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/7799854317817970190'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/7799854317817970190'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/integrando-freebsd-com-active-directory.html' title='Integrando FreeBSD com Active Directory e OpenLDAP'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-6022735339969686546</id><published>2009-07-02T09:58:00.000-07:00</published><updated>2009-07-02T10:01:26.186-07:00</updated><title type='text'>Material Adicional - SnapShot em ZFS</title><content type='html'>Pessoal,&lt;br /&gt;&lt;br /&gt;Encontrei alguns vídeos que direcionam como trabalhar com snapshots com ZFS:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.youtube.com/watch?v=NW_-vPIiW-s"&gt;http://www.youtube.com/watch?v=NW_-vPIiW-s&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-6022735339969686546?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/6022735339969686546/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/material-adicional-snapshot-em-zfs.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6022735339969686546'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6022735339969686546'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/07/material-adicional-snapshot-em-zfs.html' title='Material Adicional - SnapShot em ZFS'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-1703669280296380819</id><published>2009-06-26T01:03:00.000-07:00</published><updated>2009-06-26T02:15:59.275-07:00</updated><title type='text'>Palestra "TI Verde e Virtualização com FreeBSD" no Primeiro BSD Meeting no Brasil</title><content type='html'>O décimo FISL (Fórum Internacional de Software Livre) apresentou muitas novidades, além de estar na maravilhosa cidade de Porto Alegre, contou com mais de 8100 participantes. Diversos eventos internos contemplaram o FISL e um deles foi o primeiro BSD Meeting, uma reunião entre todos aqueles que gostam de sistemas BSD.&lt;br /&gt;&lt;br /&gt;Estive lá com a palestra "TI Verde e Virtualização com FreeBSD", centrando os conceitos de gestão de TI e demonstrando como justificar para o departamento financeiro a viabilidade do uso direto da virtulização.&lt;br /&gt;&lt;br /&gt;Foi fantástico poder conhecer figuras notáveis do mundo BSD como Marcelo Araújo, Felippe de Meirelles Motta, Daniel Bristot e o grande Ion-Mihai Tetcu. Ion tem a responsabilidade de guiar os rumos do ports no FreeBSD e foi fantástico ouví-lo comentar como tudo funciona.&lt;br /&gt;&lt;br /&gt;Na minha palestra não pude exibir alguns vídeos, assim, estou colocando-os para aqueles que desejarem ver, segue o primeiro vídeo (The Network is Down):&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-b320c5c50450bf5a" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v23.nonxt2.googlevideo.com/videoplayback?id%3Db320c5c50450bf5a%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D3E8FEEBC3227DE252B1DC242F706AC4660B1E586.652212820A1206637B6D8FBA5C0EB505F814C12B%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Db320c5c50450bf5a%26offsetms%3D5000%26itag%3Dw160%26sigh%3DxaC1mInQrwoz7Hc6rRAGoP8Lw2Y&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v23.nonxt2.googlevideo.com/videoplayback?id%3Db320c5c50450bf5a%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D3E8FEEBC3227DE252B1DC242F706AC4660B1E586.652212820A1206637B6D8FBA5C0EB505F814C12B%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Db320c5c50450bf5a%26offsetms%3D5000%26itag%3Dw160%26sigh%3DxaC1mInQrwoz7Hc6rRAGoP8Lw2Y&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;/p&gt;&lt;p&gt;O outro vídeo aborda o quanto é complicado colocar em funcionamento um servidor depois de um crash:&lt;/p&gt;&lt;p&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-d089d316c0fbf023" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v8.nonxt6.googlevideo.com/videoplayback?id%3Dd089d316c0fbf023%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D80E79A2B9AA66C99F51C104EA82F720DB4175338.6317EA5EDED7E0E917A77BF9A5362FE8AB8CE8C%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Dd089d316c0fbf023%26offsetms%3D5000%26itag%3Dw160%26sigh%3DvhQd3Ml8Vqv-KZtm9djkxhM1Yqs&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v8.nonxt6.googlevideo.com/videoplayback?id%3Dd089d316c0fbf023%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D80E79A2B9AA66C99F51C104EA82F720DB4175338.6317EA5EDED7E0E917A77BF9A5362FE8AB8CE8C%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Dd089d316c0fbf023%26offsetms%3D5000%26itag%3Dw160%26sigh%3DvhQd3Ml8Vqv-KZtm9djkxhM1Yqs&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;/p&gt;&lt;p&gt;Para concluir, tem um que eu particurlamente gosto muito, chama-se Song The Day The Routers Died:&lt;/p&gt;&lt;p&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-6d7024e74ea5eac" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v22.nonxt2.googlevideo.com/videoplayback?id%3D06d7024e74ea5eac%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D85C948B1B00C7673151169877ECDE6256315FC30.799C5B6355F7B0A062278A02008A9060C7BC1C4F%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D6d7024e74ea5eac%26offsetms%3D5000%26itag%3Dw160%26sigh%3D-Ws6WwdRpCjt8stRKRLWm517Vp4&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v22.nonxt2.googlevideo.com/videoplayback?id%3D06d7024e74ea5eac%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D85C948B1B00C7673151169877ECDE6256315FC30.799C5B6355F7B0A062278A02008A9060C7BC1C4F%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3D6d7024e74ea5eac%26offsetms%3D5000%26itag%3Dw160%26sigh%3D-Ws6WwdRpCjt8stRKRLWm517Vp4&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;/p&gt;&lt;p&gt;Grande abraço,&lt;/p&gt;&lt;p&gt;Denis&lt;/p&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-1703669280296380819?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=6d7024e74ea5eac&amp;type=video%2Fmp4' length='0'/><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=b320c5c50450bf5a&amp;type=video%2Fmp4' length='0'/><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=d089d316c0fbf023&amp;type=video%2Fmp4' length='0'/><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/1703669280296380819/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/06/palestra-ti-verde-e-virtualizacao-com.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/1703669280296380819'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/1703669280296380819'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/06/palestra-ti-verde-e-virtualizacao-com.html' title='Palestra &quot;TI Verde e Virtualização com FreeBSD&quot; no Primeiro BSD Meeting no Brasil'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-1073809665499225148</id><published>2009-05-29T07:22:00.000-07:00</published><updated>2009-05-29T12:23:12.612-07:00</updated><title type='text'>Palestra VLAN e Kerberos com FreeBSD na 4LINUX</title><content type='html'>A 4Linux ministrou uma aula gratuita sobre o Sitema Operacional FreeBSD na quinta-feira (28/05/09). O Instrutor Denis Augusto, especialista em segurança de redes, abordará a criação de &lt;strong&gt;VLANs&lt;/strong&gt; e o uso do &lt;strong&gt;Kerberos&lt;/strong&gt; em FreeBSD. Durante o treinamento o instrutor fará ainda uma imagem em VMware do FreeBSD que será posteriormente publicada para download (&lt;a href="http://www.4linux.com.br/noticias/2009/acompanhe-on-line-ao-vivo-uma-aula-freebsd-quinta-feira-2805.html"&gt;http://www.4linux.com.br/noticias/2009/acompanhe-on-line-ao-vivo-uma-aula-freebsd-quinta-feira-2805.html&lt;/a&gt;). Abaixo podemos ver um vídeo demonstrando a criação de VLANs com o uso do FreeBSD.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;object width="320" height="266" class="BLOG_video_class" id="BLOG_video-b0978077c8f8dace" classid="clsid:D27CDB6E-AE6D-11cf-96B8-444553540000" codebase="http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab#version=6,0,40,0"&gt;&lt;param name="movie" value="http://www.youtube.com/get_player"&gt;&lt;param name="bgcolor" value="#FFFFFF"&gt;&lt;param name="allowfullscreen" value="true"&gt;&lt;param name="flashvars" value="flvurl=http://v12.nonxt5.googlevideo.com/videoplayback?id%3Db0978077c8f8dace%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D76849DAA35603DCC4767E8FCA4338DF1B67DD3BF.851EB2A663DAD37733E49E84E2A39C56F63F5758%26key%3Dck1&amp;amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Db0978077c8f8dace%26offsetms%3D5000%26itag%3Dw160%26sigh%3DDPolXObs9lw6VP_NnF_pn9-M98s&amp;amp;autoplay=0&amp;amp;ps=blogger"&gt;&lt;embed src="http://www.youtube.com/get_player" type="application/x-shockwave-flash"width="320" height="266" bgcolor="#FFFFFF"flashvars="flvurl=http://v12.nonxt5.googlevideo.com/videoplayback?id%3Db0978077c8f8dace%26itag%3D5%26app%3Dblogger%26ip%3D0.0.0.0%26ipbits%3D0%26expire%3D1331110120%26sparams%3Did,itag,ip,ipbits,expire%26signature%3D76849DAA35603DCC4767E8FCA4338DF1B67DD3BF.851EB2A663DAD37733E49E84E2A39C56F63F5758%26key%3Dck1&amp;iurl=http://video.google.com/ThumbnailServer2?app%3Dblogger%26contentid%3Db0978077c8f8dace%26offsetms%3D5000%26itag%3Dw160%26sigh%3DDPolXObs9lw6VP_NnF_pn9-M98s&amp;autoplay=0&amp;ps=blogger"allowFullScreen="true" /&gt;&lt;/object&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-1073809665499225148?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='enclosure' type='video/mp4' href='http://www.blogger.com/video-play.mp4?contentId=b0978077c8f8dace&amp;type=video%2Fmp4' length='0'/><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/1073809665499225148/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/palestra-vlan-e-kerberos-com-freebsd-na.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/1073809665499225148'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/1073809665499225148'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/palestra-vlan-e-kerberos-com-freebsd-na.html' title='Palestra VLAN e Kerberos com FreeBSD na 4LINUX'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-8529292427707481970</id><published>2009-05-26T18:50:00.000-07:00</published><updated>2009-05-26T06:13:32.947-07:00</updated><title type='text'>Palestra de Lançamento</title><content type='html'>&lt;br&gt;&lt;br /&gt;&lt;a href="http://2.bp.blogspot.com/__MKYiCVymqo/ShNiXU_H2NI/AAAAAAAAAAc/TBTFi81Eu0o/s1600-h/Convite_FreeBSD.JPG"&gt;&lt;img style="MARGIN: 0px 10px 10px 0px; WIDTH: 320px; FLOAT: left; HEIGHT: 226px; CURSOR: hand" id="BLOGGER_PHOTO_ID_5337718136274147538" border="0" alt="" src="http://2.bp.blogspot.com/__MKYiCVymqo/ShNiXU_H2NI/AAAAAAAAAAc/TBTFi81Eu0o/s320/Convite_FreeBSD.JPG" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Não deixe de comparecer!! &lt;/div&gt;&lt;div&gt;Teremos sorteios de brindes e um belo bate papo a respeito de FreeBSD.&lt;/div&gt;&lt;div&gt;&lt;/div&gt;&lt;div&gt;Abração,&lt;/div&gt;&lt;div&gt;Denis&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-8529292427707481970?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/8529292427707481970/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/palestra-de-lancamento.html#comment-form' title='2 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/8529292427707481970'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/8529292427707481970'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/palestra-de-lancamento.html' title='Palestra de Lançamento'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://2.bp.blogspot.com/__MKYiCVymqo/ShNiXU_H2NI/AAAAAAAAAAc/TBTFi81Eu0o/s72-c/Convite_FreeBSD.JPG' height='72' width='72'/><thr:total>2</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-5340693156464534130</id><published>2009-05-19T19:53:00.000-07:00</published><updated>2009-05-19T19:59:36.018-07:00</updated><title type='text'>News: VirtualBox agora no FreeBSD</title><content type='html'>&lt;br&gt;&lt;br /&gt;Agora já podemos ter a nossa disposição do VirtualBox da Sun para FreeBSD. Antes seu projeto estava fechado para ambientes Microsoft Windows ou Linux.&lt;br /&gt;&lt;br /&gt;Ainda está em fase de validação, mas podem iniciar os testes. bata instalar o &lt;a href="http://people.freebsd.org/~miwi/vbox/virtualbox_2.tgz"&gt;código-fonte&lt;/a&gt; no diretório /usr/ports/emulators e compilar! Veja alguns &lt;a href="http://www.virtualbox.org/wiki/Screenshots"&gt;screenshots&lt;/a&gt;.&lt;br /&gt;&lt;br /&gt;Abraços,&lt;br /&gt; Denis&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-5340693156464534130?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/5340693156464534130/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/news-virtualbox-agora-no-freebsd.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/5340693156464534130'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/5340693156464534130'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/news-virtualbox-agora-no-freebsd.html' title='News: VirtualBox agora no FreeBSD'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-3469118793036167629</id><published>2009-05-15T19:24:00.000-07:00</published><updated>2009-05-15T10:58:12.029-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='informações gerais'/><title type='text'>Dados a Respeito do Livro</title><content type='html'>&lt;div&gt;&lt;/div&gt;&lt;br /&gt;&lt;a href="http://4.bp.blogspot.com/__MKYiCVymqo/Sgvc8s-ctVI/AAAAAAAAAAU/lURM7ZXpDQU/s1600-h/capa_final_a.gif"&gt;&lt;img id="BLOGGER_PHOTO_ID_5335601118973834578" style="FLOAT: left; MARGIN: 0px 10px 10px 0px; WIDTH: 150px; CURSOR: hand; HEIGHT: 211px" alt="" src="http://4.bp.blogspot.com/__MKYiCVymqo/Sgvc8s-ctVI/AAAAAAAAAAU/lURM7ZXpDQU/s320/capa_final_a.gif" border="0" /&gt;&lt;/a&gt;&lt;br /&gt;&lt;div&gt;Este livro tem a finalidade de apresentar o sistema operacional FreeBSD, conduzindo o leitor no universo dos sistemas BSD (Berkeley Software Distribuition). O leitor saberá o que levou empresas como Yahoo!, Apache, Warner (filme The Matrix), CBC, Sony (Japão), Netcraft e muitas outras a usar o FreeBSD.Uma das premissas deste livro é conduzir o leitor no projeto de estruturas para manusear backups, gerenciamento de storages e conceber sistemas com alta disponibilidade. Abordaremos, sempre que possível, nossos estudos na ótica da segurança da informação com métodos para a proteção e estudaremos em um capítulo específico algumas metodologias de ataque representadas por técnicas de Pentest visando fornecer as ferramentas que auxiliarão na validação de servidores. E para concluir não poderíamos esquecer de estudar a virtualização usando sistemas FreeBSD.&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/div&gt;&lt;br /&gt;&lt;br /&gt;&lt;div&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 class="post-title entry-title"&gt;&lt;br /&gt;Ficha Cadastral&lt;br /&gt;&lt;/h3&gt;&lt;br /&gt;ISBN: 978-85-7522-162-4&lt;br /&gt;&lt;br /&gt;Novatec Editora Ltda.&lt;br /&gt;Rua Luís Antônio dos Santos 110&lt;br /&gt;02460-000 – São Paulo, SP – Brasil&lt;br /&gt;Tel.: +55 11 2959-6529&lt;br /&gt;Fax: +55 11 2950-8869&lt;br /&gt;E-mail: novatec@novatec.com.br&lt;br /&gt;Site: www.novatec.com.br&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 class="post-title entry-title"&gt;&lt;br /&gt;Créditos&lt;br /&gt;&lt;/h3&gt;&lt;br /&gt;Autor: Denis Augusto A. de Souza&lt;br /&gt;Editor: Rubens Prates&lt;br /&gt;Revisão: Lia Gabriele Regius&lt;br /&gt;Editoração eletrônica: Carolina KuwabataCapa: Tami Arita&lt;br /&gt;Revisor Estrutural: Anselmo Leite&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;h3 class="post-title entry-title"&gt;&lt;br /&gt;Onde Comprar?&lt;/h3&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;&lt;br /&gt;&lt;br /&gt;&lt;p&gt;&lt;/p&gt;O livro poderá ser comprado pela editora Novatec (&lt;a href="http://www.novatec.com.br/"&gt;http://www.novatec.com.br/&lt;/a&gt;) e seus parceiros. Maiores informações podem ser obtidas no link &lt;a href="http://www.novatec.com.br/contato.php"&gt;http://www.novatec.com.br/contato.php&lt;/a&gt; ou pelo telefone da editora Novatec.&lt;br /&gt;&lt;br /&gt;&lt;span style="color:#cc6600;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;br /&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;span style="color:#cc6600;"&gt;&lt;/span&gt;&lt;span style="color:#cc6600;"&gt;&lt;/span&gt;&lt;/div&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-3469118793036167629?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3469118793036167629'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3469118793036167629'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/dados-respeito-do-livro.html' title='Dados a Respeito do Livro'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><media:thumbnail xmlns:media='http://search.yahoo.com/mrss/' url='http://4.bp.blogspot.com/__MKYiCVymqo/Sgvc8s-ctVI/AAAAAAAAAAU/lURM7ZXpDQU/s72-c/capa_final_a.gif' height='72' width='72'/></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-5437698833427615204</id><published>2009-05-15T11:21:00.000-07:00</published><updated>2009-05-15T11:30:43.931-07:00</updated><title type='text'>Livro Pronto</title><content type='html'>&lt;br&gt;&lt;br /&gt;É com grande alegria que comunico a publicação do livro &lt;strong&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;/strong&gt; (14/05/09), somando-se 544 páginas de um projeto que em 2 anos envolveu muito estudo, pesquisa, escrita e muita revisão.&lt;br /&gt;&lt;br /&gt;Espero que todos gostem desta obra e saiba que este espaço é de vocês para melhorarmos seu conteúdo e retirar dúvidas.&lt;br /&gt;&lt;br /&gt;Sabemos que nem tudo pode ser depositado em um livro, pois temos varíaveis como valor final, tamanho etc, assim, minha idéia é usar o espaço do site não só para discutir a respeito do livro, mas falar também de outros temas ligados ao FreeBSD.&lt;br /&gt;&lt;br /&gt;Grande abraço e boa leitura.&lt;br /&gt;&lt;br /&gt;Denis Augusto.&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-5437698833427615204?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/5437698833427615204/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/livro-do-freebsd-pronto.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/5437698833427615204'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/5437698833427615204'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/05/livro-do-freebsd-pronto.html' title='Livro Pronto'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-8058927131493328011</id><published>2009-05-15T10:19:00.000-07:00</published><updated>2009-05-15T10:57:13.872-07:00</updated><category scheme='http://www.blogger.com/atom/ns#' term='críticas e sugestões'/><title type='text'>O que você mais gostou do livro, o que poderia ser melhorado?</title><content type='html'>Estar sempre perto dos leitores tem que ser um amta de qualquer escritor. Deixe seus comentários a respeito &lt;em&gt;do que mais o auxiliou&lt;/em&gt; , &lt;em&gt;críticas&lt;/em&gt;, ou de &lt;em&gt;temas que poderiam ser incluídos ou melhorados neste livro&lt;/em&gt;. Obrigado!&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-8058927131493328011?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/8058927131493328011/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/o-que-voc-mais-gostou-do-livro-o-que.html#comment-form' title='4 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/8058927131493328011'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/8058927131493328011'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/o-que-voc-mais-gostou-do-livro-o-que.html' title='O que você mais gostou do livro, o que poderia ser melhorado?'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>4</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-1940991251461725498</id><published>2009-04-17T10:21:00.000-07:00</published><updated>2009-05-14T01:59:49.011-07:00</updated><title type='text'>Apresentação dos Capítulos</title><content type='html'>&lt;br&gt;&lt;br /&gt;• Capítulo 1: “Instalação”&lt;br /&gt;&lt;br /&gt;Trata da instalação do sistema operacional FreeBSD analisando os conceitos necessários e os cuidados para o preparo de um bom servidor. O processo de instalação aqui discutido aborda as melhores práticas propostas pelo ITIL, buscando o que é mais adequado para o negócio de cada empresa. Se você já conhece FreeBSD o único ponto que recomendo é o check-list de pré-instalação e as dicas que referenciam a norma ISO/IEC 27002:2005.&lt;br /&gt;&lt;br /&gt;• Capítulo 2: “Manuseio do sistema operacional”&lt;br /&gt;&lt;br /&gt;Aborda o universo dos sistemas operacionais Unix/Unix-like, discutindo os comandos para operação ou manuseio. Discutiremos também como usar mídias removíveis e como configurar o FreeBSD (interfaces de rede, gateway, nome de host etc.). Existem facilidades nativas no FreeBSD como flags, sistemas de arquivos union (unionfs) e sistemas snapshot que serão vistos por nós para proporcionar melhores ferramentas para a composição de servidores, principalmente do ponto de vista de segurança de dados. Se o leitor já trabalha com FreeBSD a mais de 3 anos, poucas novidades serão vistas aqui.&lt;br /&gt;&lt;br /&gt;• Capítulo 3: “Instalação de aplicativos”&lt;br /&gt;&lt;br /&gt;Analisa os padrões de instalação mais comuns de ambientes BSD. Seja pela facilidade de se usar instalações automatizadas com ports ou pacotes de programas compilados previamente com packages. Veremos os pontos positivos e negativos de cada metodologia. Este conhecimento é extremamente importante para quem deseja fazer uso de um sistema operacional BSD. Se você já conhece FreeBSD, veja as dicas das ferramentas para gerenciamento de ports.&lt;br /&gt;&lt;br /&gt;• Capítulo 4: “Ambiente X”&lt;br /&gt;&lt;br /&gt;Sabemos que a instalação de um ambiente gráfico em um servidor é uma prática pouco comum, mas muitos leitores pretenderão usar o FreeBSD como desktop. Existem versões do FreeBSD específicas para esta tarefa, entretanto podemos com alguns ajustes adaptar o FreeBSD para isto. O ambiente X é exibido neste capítulo tomando como base o Xorg (padrão de instalação do FreeBSD). Como ambiente de janelas são discutidos como usar o Gnome e o KDE no FreeBSD. Se não é foco do seu ambiente usar sistemas X, pule este capítulo e siga para o capítulo 5.&lt;br /&gt;&lt;br /&gt;• Capítulo 5: “Gerenciamento e personalização”&lt;br /&gt;&lt;br /&gt;No capítulo 5 o leitor poderá encontrar os conhecimentos para customizar um sistema operacional visando retirar o máximo de desempenho, com segurança e estabilidade. Para isto, contaremos com recursos existentes no próprio FreeBSD, como ferramentas que auxiliam no monitoramento de atividades e no estado funcional de um servidor Internet. Estas ferramentas foram pesquisadas em listas de discussão, em outros sistemas operacionais e na nossa experiência prática, durante os anos que estivemos envolvidos com o monitoramento de servidores Internet.&lt;br /&gt;&lt;br /&gt;O controle de quotas aplicado aos usuários do sistema operacional é uma ferramenta que não pode ser esquecida. A compilação do kernel também é abordada, juntamente com a compatibilidade entre FreeBSD e Linux. Este capítulo mostra de forma prática como aplicar uma correção de segurança em um componente do sistema operacional ou em um serviço nele existente.&lt;br /&gt;&lt;br /&gt;• Capítulo 6: “Segurança com FreeBSD”&lt;br /&gt;&lt;br /&gt;Visa configurar um servidor e protegê-lo com regras de um firewall. Aqui veremos como fazer isto com os recursos do filtro de pacotes existente no firewall “open source” mais seguro do mundo, o OpenBSD. Com este filtro de pacotes estudaremos, por exemplo, métodos específicos para ataques, balanceamento de cargas com priorização de pacotes e análise de logs. Além disto, veremos outros mecanismos para customizar a segurança do sistema operacional, como o uso de “Access List”, criptografia, métodos de auditoria, uso de Kerberos, TCP Wrappers e muito mais. Discutiremos segurança aqui seguindo a norma ISO/IEC 27002:2005 e abordaremos o tema hardening, um importante elemento para qualquer sistema operacional.&lt;br /&gt;&lt;br /&gt;• Capítulo 7: “Construindo servidores”&lt;br /&gt;&lt;br /&gt;Este capítulo aborda como instalar diversos serviços no FreeBSD com o uso de ports ou packages, visando compor servidores Internet. A construção de um servidor de VPN IPsec ponto-a-ponto é vista de forma mais técnica, abordando customizações no kernel do sistema operacional e ajustes no sistema de firewall local.&lt;br /&gt;&lt;br /&gt;Entender como criar servidores de discos virtuais iSCSI é hoje uma tarefa importante, principalmente para aqueles que trabalham com storage ou com o tempo de recuperação bem pequeno, assim, estudaremos a importância deste modelo de servidor e veremos como contruí-lo seguindo padrões de segurança. Outro ponto importante da área de segurança é saber o que fazer para deixar um sistema mais seguro contra ataques.&lt;br /&gt;&lt;br /&gt;• Capítulo 8: “Troubleshooting”&lt;br /&gt;&lt;br /&gt;Veremos os problemas mais comuns de um servidor e como solucioná-los com ferramentas para identificar os pontos de saturação ou stress. Usaremos nossa experiência profissional para orientar o leitor na solução de imprevistos com o uso de file system, acesso a discos, unidades de CD-ROM etc.&lt;br /&gt;&lt;br /&gt;• Capítulo 9: “Alta disponibilidade com FreeBSD”&lt;br /&gt;&lt;br /&gt;Saber projetar um ambiente de servidores seguindo o conceito de alta disponibilidade é uma ferramenta mais do que indispensável. Para isto podemos fazer uso de programas específicos com o objetivo de auxiliar esta tarefa, além de usarmos as composições que são implementadas em storages, um dos pontos fortes do FreeBSD. Uma prova disto é a existência do record de armazenamento de 2TBytes em um único sistema operacional. Assim, estudaremos os vários tipos de RAID e, como exemplo, veremos como usar RAID tipos 0, 1, 0+1 e o Raid-z da Sun Microsystems no FreeBSD.&lt;br /&gt;&lt;br /&gt;Outro ponto importante referente ao projeto de um servidor resistente a falta ou falha é o uso de CARP (Common Address Redundancy Protocol). Estudaremos como usá-lo no FreeBSD aplicando sincronismo de pacotes e exemplificaremos seu uso com o projeto de um pool de servidores web.&lt;br /&gt;&lt;br /&gt;Conhecer como manter sincronizado arquivos de configuração e automatização de scripts é de grande utilidade para qualquer administrador que trabalha com diversos servidores. Veremos como fazer isto com uso da ferramenta Rsync no FreeBSD.&lt;br /&gt;&lt;br /&gt;Outra ferramenta que veremos é a concatenação de discos e o compartilhando um discos pela rede utilizando o GEOM gate.&lt;br /&gt;&lt;br /&gt;Para solução de software centrado em alta disponibilidade, estudaremos o Heartbeat, um tema muito comum em ambientes Linux para monitoramento de servidores e verificaremos quando existem problemas de funcionamento para a elaboração de alertas ou substituição automática de servidores. Analisaremos e implantaremos isto no FreeBSD.&lt;br /&gt;&lt;br /&gt;• Capítulo 10: “Virtualização”&lt;br /&gt;&lt;br /&gt;Aborda o uso de virtualização, um tema muito popular e uma tendência nas empresas que buscam a redução de custo e facilidades na recuperação de problemas. Diversos ambientes para virtualização foram estudados com exemplos práticos para implantação, juntamente com análises de segurança.&lt;br /&gt;&lt;br /&gt;• Capítulo 11: “Usando FreeBSD para Pentests”&lt;br /&gt;&lt;br /&gt;Quando nos aprofundamos em auditoria de segurança, verificamos que são poucos os profissionais com o conhecimento para elaborar testes intrusivos locais ou remotos visando avaliar o ambiente computacional e conhecer sua superfície de vulnerabilidade. Este conhecimento é denominado de Penetration Tests ou PenTests.&lt;br /&gt;&lt;br /&gt;Estudaremos neste capítulo esta técnica e veremos que o FreeBSD pode ser uma grande aliado para este tema.&lt;br /&gt;&lt;br /&gt;• Capítulo 12: “Estratégias para backup”&lt;br /&gt;&lt;br /&gt;Saber fazer backups da forma correta é extremamente importante. Quem não conhece casos de empresas que projetam seus backups sem testes de recuperação. Alertas para a maneira correta de se fazer um projeto de backup são estudados neste capítulo com o uso de ferramentas importantes como o Bacula, Rsync, AMANDA e Rdiff.&lt;br /&gt;&lt;br /&gt;• Apêndice A: ITIL aplicado ao projeto de servidores Internet&lt;br /&gt;&lt;br /&gt;Sabemos que o projeto de servidores Internet pode ser visto como um labirinto com diversos caminhos a serem seguidos e muitos deles nem sempre representam a melhor escolha para o administrador. Então, como guiar o projeto de servidores de uma forma segura?&lt;br /&gt;&lt;br /&gt;Pensando nesta questão, usaremos uma das melhores práticas internacionais, o ITIL (Information Technology Infrastructure Library) para nos auxiliar.&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-1940991251461725498?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/1940991251461725498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/1940991251461725498'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/sumrio.html' title='Apresentação dos Capítulos'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-4686715302640976210</id><published>2009-04-17T02:10:00.000-07:00</published><updated>2009-05-14T02:00:09.605-07:00</updated><title type='text'>Cursos de FreeBSD</title><content type='html'>&lt;br&gt;&lt;br /&gt;No estado de São Paulo, a 4LINUX (&lt;a href="http://www.4linux.com.br/"&gt;http://www.4linux.com.br/&lt;/a&gt;) tem cursos para usuários intermediários e avançados em FreeBSD. O curso avançado fala até da construção de servidores iSCSI, ZFS, estruturas em storages e de virtualização. Veja a ementa dos cursos e confira o que os usuários da Net falam!!! ;)&lt;br /&gt;&lt;br /&gt;Abraços,&lt;br /&gt;&lt;br /&gt;Denis&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-4686715302640976210?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/4686715302640976210/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/04/cursos-de-freebsd.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/4686715302640976210'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/4686715302640976210'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/04/cursos-de-freebsd.html' title='Cursos de FreeBSD'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-4596674021161672083</id><published>2009-04-14T12:38:00.000-07:00</published><updated>2009-05-14T02:00:23.977-07:00</updated><title type='text'>Certificações</title><content type='html'>&lt;br&gt;&lt;br /&gt;Temos algumas certificações em FreeBSD, uma delas está centrada no grupo &lt;a href="http://www.bsdcertification.org/"&gt;www.bsdcertification.org&lt;/a&gt;, com membros fundadores da FreeBSD Brasil e o grupo de certificações &lt;a href="http://www.bsdcertification.com/"&gt;http://www.bsdcertification.com/&lt;/a&gt;, mas amplo com certificações em toda a família BSD (FreeBSD, NetBSD e OpenBSD).&lt;br /&gt;&lt;br /&gt;Mais Links: &lt;a href="http://www.pcguide.com/vb/showthread.php?t=60562"&gt;http://www.pcguide.com/vb/showthread.php?t=60562&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-4596674021161672083?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/4596674021161672083/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/04/certificacoes.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/4596674021161672083'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/4596674021161672083'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/04/certificacoes.html' title='Certificações'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-4752247197773045079</id><published>2009-04-14T06:04:00.000-07:00</published><updated>2009-05-14T02:00:40.484-07:00</updated><title type='text'>Dados sobre o autor</title><content type='html'>&lt;br&gt;&lt;br /&gt;Denis Augusto é especialista em segurança de redes, projetista de soluções para automatização de tarefas e auditor de segurança para ambiente de servidores.&lt;br /&gt;&lt;br /&gt;Graduado pela Universidade Federal da Paraíba (UFPb) em engenharia elétrica com especialização em microeletrônica, Denis sempre esteve envolvido com o mundo computacional auxiliando na administração do mainframe IBM 4381 desta universidade.&lt;br /&gt;&lt;br /&gt;É formado em Segurança de Dados pela Academia Latino-Americana de Segurança da Informação, sendo participante da primeira turma no Brasil.&lt;br /&gt;&lt;br /&gt;Denis é especialista em integração de sistemas heterogêneos, unindo ambientes Windows e Linux, pois usa de seus conhecimentos contidos nas certificações internacional Microsoft Certified Systems Engineer-Security (MCSE:Security), Microsoft Certified Systems Administrator – Security (MCSA:Security) e MCSA:Messaging.&lt;br /&gt;&lt;br /&gt;A especialidade em segurança é reforçada pela certificação internacional GIAC Cutting Edge Hacking Techniques, que garante conhecimentos específicos para a proteção e auditoria em sistemas computacionais. Seus conhecimentos sobre gestão da tecnologia da informação (TI) e controle de processos baseiam-se na certificação internacional ITIL Foundation, que evidencia técnicas para a melhoria da qualidade dos serviços em TI e redução de custos.&lt;br /&gt;&lt;br /&gt;Denis detém trabalhos publicados na área de segurança em eventos como SSI (Simpósio sobre Segurança em Informática, em São José dos Campos, São Paulo), ICIE (International Congress on Informatic Engineering em Lisboa, Portugal), Latinamerican Conference of Informatics CLEI (Quito-Equador) e InfoNordeste.&lt;br /&gt;&lt;br /&gt;Possui conhecimentos para a construção de redes VPNs ponto-a-ponto e para dispositivos móveis, além de ser projetista de ambientes wireless com múltiplas camadas de proteção. É instrutor da 4LINUX (&lt;a href="http://www.4linux.com.br/"&gt;http://www.4linux.com.br/&lt;/a&gt;) e criador de cursos para FreeBSD e OpenBSD.&lt;br /&gt;&lt;br /&gt;Palestras on-line:&lt;br /&gt;&lt;br /&gt;&lt;a href="http://www.4linux.com.br/cursos/freebsd-projetando-servidores-seguros-410.html#video-curso"&gt;http://www.4linux.com.br/cursos/freebsd-projetando-servidores-seguros-410.html#video-curso&lt;/a&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-4752247197773045079?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/4752247197773045079'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/4752247197773045079'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/04/dados-sobre-o-autor.html' title='Dados sobre o autor'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-3848131809722420498</id><published>2009-01-11T04:13:00.000-08:00</published><updated>2009-05-15T11:07:34.445-07:00</updated><title type='text'>Capítulo 10 - Arquivo Xen freebsd01.bsd</title><content type='html'>&lt;span style="font-size:78%;"&gt;# Kernel image file.&lt;br /&gt;# Arquivo /etc/xen/freebsd01.bsd&lt;br /&gt;kernel = "/usr/src/xen/freebsd/kernel/kernel-xen"&lt;br /&gt;&lt;br /&gt;# Initial memory allocation (in megabytes) for the new domain.&lt;br /&gt;memory=310&lt;br /&gt;&lt;br /&gt;# A name for your domain. All domains must have different names.&lt;br /&gt;name = "freebsd"&lt;br /&gt;&lt;br /&gt;# List of which CPUS this domain is allowed to use, default Xen picks&lt;br /&gt;#cpus = "" # leave to Xen to pick&lt;br /&gt;#cpus = "0" # all vcpus run on CPU0&lt;br /&gt;#cpus = "0-3,5,^1" # run on cpus 0,2,3,5&lt;br /&gt;&lt;br /&gt;# Number of Virtual CPUS to use, default is 1&lt;br /&gt;#vcpus = 1&lt;br /&gt;&lt;br /&gt;#----------------------------------------------------------------------------&lt;br /&gt;# Define network interfaces.&lt;br /&gt;&lt;br /&gt;# By default, no network interfaces are configured. You may have one created&lt;br /&gt;# with sensible defaults using an empty vif clause:&lt;br /&gt;#&lt;br /&gt;# vif = [ '' ]&lt;br /&gt;#&lt;br /&gt;# or optionally override backend, bridge, ip, mac, script, type, or vifname:&lt;br /&gt;#&lt;br /&gt;# vif = [ 'mac=00:16:3e:00:00:11, bridge=xenbr0' ]&lt;br /&gt;#&lt;br /&gt;# or more than one interface may be configured:&lt;br /&gt;#&lt;br /&gt;# vif = [ '', 'bridge=xenbr1' ]&lt;br /&gt;&lt;br /&gt;vif = [ '' ]&lt;br /&gt;&lt;br /&gt;#----------------------------------------------------------------------------&lt;br /&gt;disk = [ 'file:/usr/src/xen/freebsd/rootfs/mdroot-7.0,hda1,w' ]&lt;br /&gt;&lt;br /&gt;#----------------------------------------------------------------------------&lt;br /&gt;# Set if you want dhcp to allocate the IP address.&lt;br /&gt;#dhcp="dhcp"&lt;br /&gt;# Set netmask.&lt;br /&gt;#netmask=&lt;br /&gt;# Set default gateway.&lt;br /&gt;#gateway=&lt;br /&gt;# Set the hostname.&lt;br /&gt;#hostname= "vm%d" % vmid&lt;br /&gt;&lt;br /&gt;# The nfs server.&lt;br /&gt;#nfs_server = '169.254.1.0'&lt;br /&gt;# Root directory on the nfs server.&lt;br /&gt;#nfs_root = '/full/path/to/root/directory'&lt;br /&gt;&lt;br /&gt;#1 Sets runlevel 4.&lt;br /&gt;#extra = "4"&lt;br /&gt;#============================================================================&lt;br /&gt;#on_crash = 'preserve'&lt;br /&gt;extra = "boot_verbose"&lt;br /&gt;extra += ",boot_single"&lt;br /&gt;extra += ",vfs.root.mountfrom=ufs:/dev/xbd769a"&lt;br /&gt;extra += ",kern.hz=100"&lt;br /&gt;&lt;br /&gt;# Other settings&lt;br /&gt;localtime = '1' # Whether system clock is set to local time or UTC&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-3848131809722420498?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/3848131809722420498/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/arquivo-xen-freebsd01bsd.html#comment-form' title='1 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3848131809722420498'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3848131809722420498'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/arquivo-xen-freebsd01bsd.html' title='Capítulo 10 - Arquivo Xen freebsd01.bsd'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>1</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-2568691834629956192</id><published>2009-01-11T04:12:00.000-08:00</published><updated>2009-05-15T11:10:51.797-07:00</updated><title type='text'>Capítulo 9 - arquivo monitrc</title><content type='html'>&lt;span style="font-size:78%;"&gt;# Arquivo /usr/local/etc/monitrc&lt;br /&gt;set daemon 60 # Define o tempo de 1 minuto para cada verificacao.&lt;br /&gt;set logfile syslog facility log_daemon # Define o arquivo de logs.&lt;br /&gt;set mailserver localhost # Informa o servidor de correio usado&lt;br /&gt;set eventqueue&lt;br /&gt;basedir /var/monit # set the base directory where events will be stored&lt;br /&gt;slots 100 # Limita o tamanho da fila para trabalho.&lt;br /&gt;set mail-format { from: monit@localhost } # Especifica o format do e-mail indicando o From.&lt;br /&gt;set alert root@localhost # Define o endereco de correio que recebera os alertas.&lt;br /&gt;&lt;br /&gt;# Define as configuracoes do servico http dentro do Monit&lt;br /&gt;set httpd port 2812 and&lt;br /&gt;use address 192.168.241.91 # Define o endereco IP do servidor Web dentro do Monit&lt;br /&gt;allow localhost # Aceita conexoes vindas do localhost.&lt;br /&gt;allow 192.168.241.1 # Aceita acessos do host 192.168.241.1.&lt;br /&gt;allow admin:Monit21 # Usuário para acesso a interface Web.&lt;br /&gt;&lt;br /&gt;# Configuracao para o monitoramento do sistema onde o Monite esta instalado.&lt;br /&gt;check system localhost&lt;br /&gt;if loadavg (1min) &gt; 4 then alert&lt;br /&gt;if loadavg (5min) &gt; 2 then alert&lt;br /&gt;if memory usage &gt; 75% then alert&lt;br /&gt;if cpu usage (user) &gt; 20% then alert&lt;br /&gt;if cpu usage (system) &gt; 25% then alert&lt;br /&gt;if cpu usage (wait) &gt; 20% then alert&lt;br /&gt;&lt;br /&gt;# Monitoramento do arquivo sshd&lt;br /&gt;check file sshd with path /usr/sbin/sshd&lt;br /&gt;# Se o checksum falhar pare o monitoramento para não gerar loop infinito.&lt;br /&gt;if failed checksum and expect the sum de8a6046679c80d5ae21b49ec1192ba2 then unmonitor&lt;br /&gt;# Verifique a permissao, dono e grupo, se falhar informe e pare o monitoramento.&lt;br /&gt;if failed permission 555 then unmonitor&lt;br /&gt;if failed uid root then unmonitor&lt;br /&gt;if failed gid wheel then unmonitor&lt;br /&gt;# Configuracoes para o recebimento de alertas.&lt;br /&gt;alert root@localhost on {&lt;br /&gt;checksum, permission, uid, gid, unmonitor&lt;br /&gt;} with the mail-format { subject: Alarm! }&lt;br /&gt;group server&lt;br /&gt;#&lt;br /&gt;# Monitoramento do arquivo mount.&lt;br /&gt;check file mount with path /sbin/mount&lt;br /&gt;alert root@localhost on {&lt;br /&gt;checksum, size, unmonitor&lt;br /&gt;} with the mail-format { subject: Alarm! }&lt;br /&gt;if size &gt; 17036 B then exec "/sbin/ifconfig le1 down"&lt;br /&gt;group server&lt;br /&gt;&lt;br /&gt;# Monitorando o servidor 192.168.241.92 com o protocolo icmp e verificacao de funcionamento do serviço Web&lt;br /&gt;check host servidor2 with address 192.168.241.92&lt;br /&gt;if failed icmp type echo count 3 with timeout 3 seconds then alert&lt;br /&gt;if failed port 80 protocol http with timeout 15 seconds then alert&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-2568691834629956192?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/2568691834629956192/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/arquivo-monitrc.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/2568691834629956192'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/2568691834629956192'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/arquivo-monitrc.html' title='Capítulo 9 - arquivo monitrc'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-3278316238343325926</id><published>2009-01-11T04:11:00.000-08:00</published><updated>2009-05-15T11:12:36.096-07:00</updated><title type='text'>Capítulo 6 - script de hardening</title><content type='html'>&lt;span style="font-size:78%;"&gt;#!/bin/sh&lt;br /&gt;case $1 in&lt;br /&gt;start)&lt;br /&gt;clear&lt;br /&gt;chflags simmutable /boot/kernel&lt;br /&gt;chflags simmutable /bin&lt;br /&gt;chflags simmutable /sbin&lt;br /&gt;chflags simmutable /usr/sbin&lt;br /&gt;chflags simmutable /usr/sbin&lt;br /&gt;chflags simmutable /etc&lt;br /&gt;chflags simmutable /usr/lib&lt;br /&gt;chflags simmutable /usr/libexec&lt;br /&gt;chflags simmutable /usr/libdata&lt;br /&gt;chflags simmutable /usr/X11R6/bin&lt;br /&gt;chflags simmutable /usr/X11R6/lib&lt;br /&gt;chflags simmutable /usr/local/bin&lt;br /&gt;chflags simmutable /usr/local/sbin&lt;br /&gt;chflags simmutable /usr/local/lib&lt;br /&gt;chflags simmutable /usr/local/libexec&lt;br /&gt;chflags simmutable /usr/local/libdata&lt;br /&gt;echo -e "\012"&lt;br /&gt;echo "================================================================="&lt;br /&gt;echo "= Diretorios configurados como imutaveis... ="&lt;br /&gt;echo "================================================================="&lt;br /&gt;echo -e "\012"&lt;br /&gt;chflags sappend /var/log&lt;br /&gt;echo -e "\012"&lt;br /&gt;echo "===================================================================="&lt;br /&gt;echo "= Diretorio /var/log configurado so para adiconamento de dados... ="&lt;br /&gt;echo "===================================================================="&lt;br /&gt;echo -e "\012"&lt;br /&gt;;;&lt;br /&gt;var)&lt;br /&gt;clear&lt;br /&gt;chflags sappend /var/log&lt;br /&gt;echo -e "\012"&lt;br /&gt;echo "===================================================================="&lt;br /&gt;echo "= Diretorio /var/log configurado so para adiconamento de dados... ="&lt;br /&gt;echo "===================================================================="&lt;br /&gt;echo -e "\012"&lt;br /&gt;;;&lt;br /&gt;stop1)&lt;br /&gt;clear&lt;br /&gt;chflags nosimmutable /boot/kernel&lt;br /&gt;echo -e "\012"&lt;br /&gt;echo "=========================================================================================="&lt;br /&gt;echo "= Removida a configuração de flags imutaveis e de adicionamento para /boot/kernel... ="&lt;br /&gt;echo "=========================================================================================="&lt;br /&gt;;;&lt;br /&gt;stop2)&lt;br /&gt;clear&lt;br /&gt;chflags nosappend /var/log&lt;br /&gt;echo -e "\012"&lt;br /&gt;echo "====================================================================================="&lt;br /&gt;echo "= Removida a configuração de flags imutaveis e de adicionamento para /var/log... ="&lt;br /&gt;echo "======================================================================================"&lt;br /&gt;;;&lt;br /&gt;*)&lt;br /&gt;echo "ERRO: Use $0 {startvarstop1stop2}"&lt;br /&gt;;;&lt;br /&gt;esac&lt;br /&gt;exit 1&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-3278316238343325926?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/3278316238343325926/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/script-de-hardening.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3278316238343325926'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3278316238343325926'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/script-de-hardening.html' title='Capítulo 6 - script de hardening'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-3102214905323248982</id><published>2009-01-11T04:10:00.000-08:00</published><updated>2009-05-15T11:19:17.395-07:00</updated><title type='text'>Capítulo 12 - bacula-sd.conf</title><content type='html'>&lt;span style="font-size:78%;"&gt;# Arquivo bacula-sd.conf (Storage)&lt;br /&gt;# Definicoes Gerais&lt;br /&gt;Storage {&lt;br /&gt;Name = testes-dir&lt;br /&gt;SDPort = 9103&lt;br /&gt;WorkingDirectory = "/var/db/bacula"&lt;br /&gt;Pid Directory = "/var/run"&lt;br /&gt;Maximum Concurrent Jobs = 20&lt;br /&gt;}&lt;br /&gt;# Lista os Directors que podem entrar em contato com o Agente.&lt;br /&gt;Director {&lt;br /&gt;Name = testes-dir&lt;br /&gt;Password = "DirectorStoragePW"&lt;br /&gt;}&lt;br /&gt;# Dispositivos suportados para storage. O arquivo bacula-dir.conf deve ter o mesmo nome (Name) e tipo de&lt;br /&gt;# mídia (MediaType).&lt;br /&gt;# Define diretórios para serem usados como storages&lt;br /&gt;Device {&lt;br /&gt;Name = FileStorage&lt;br /&gt;Media Type = File&lt;br /&gt;Archive Device = /bacula-backup&lt;br /&gt;LabelMedia = yes;&lt;br /&gt;Random Access = Yes;&lt;br /&gt;# Quando o dispositivo estiver aberto faz a leitura automaticamente&lt;br /&gt;AutomaticMount = yes;&lt;br /&gt;RemovableMedia = no;&lt;br /&gt;AlwaysOpen = no;&lt;br /&gt;}&lt;br /&gt;# Para definir a unidade de fita no FreeBSD podemos fazer:&lt;br /&gt;Device {&lt;br /&gt;Name = DDS-4&lt;br /&gt;Description = "DDS-4 for FreeBSD"&lt;br /&gt;Media Type = DDS-4&lt;br /&gt;Archive Device = /dev/nsa1&lt;br /&gt;AutomaticMount = yes;&lt;br /&gt;AlwaysOpen = yes&lt;br /&gt;Offline On Unmount = no&lt;br /&gt;Hardware End of Medium = no&lt;br /&gt;BSF at EOM = yes&lt;br /&gt;Backward Space Record = no&lt;br /&gt;Fast Forward Space File = no&lt;br /&gt;TWO EOF = yes&lt;br /&gt;}&lt;br /&gt;# Envia mensagens para o Director&lt;br /&gt;Messages {&lt;br /&gt;Name = Standard&lt;br /&gt;director = testes-dir = all&lt;br /&gt;}&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-3102214905323248982?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/3102214905323248982/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/bacula-sdconf.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3102214905323248982'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/3102214905323248982'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/bacula-sdconf.html' title='Capítulo 12 - bacula-sd.conf'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-9104090152229764279</id><published>2009-01-11T04:07:00.001-08:00</published><updated>2009-05-15T11:19:50.342-07:00</updated><title type='text'>Capítulo 12 - bacula-dir.conf</title><content type='html'>&lt;span style="font-size:78%;"&gt;# Arquivo bacula-dir.conf (Director)&lt;br /&gt;# Configuraçoes gerais&lt;br /&gt;Director {&lt;br /&gt;Name = testes-dir&lt;br /&gt;DIRport = 9101&lt;br /&gt;QueryFile = "/usr/local/share/bacula/query.sql"&lt;br /&gt;WorkingDirectory = "/var/db/bacula"&lt;br /&gt;PidDirectory = "/var/run"&lt;br /&gt;Maximum Concurrent Jobs = 10&lt;br /&gt;Password = "Director01i2007"&lt;br /&gt;Messages = Daemon&lt;br /&gt;}&lt;br /&gt;# Definição dos Jobs&lt;br /&gt;JobDefs {&lt;br /&gt;Name = "DefaultJob"&lt;br /&gt;Type = Backup&lt;br /&gt;Level = Incremental&lt;br /&gt;Client = testes-fd&lt;br /&gt;FileSet = "Full Set"&lt;br /&gt;Schedule = "WeeklyCycle"&lt;br /&gt;Storage = File&lt;br /&gt;Messages = Standard&lt;br /&gt;Pool = Default&lt;br /&gt;Priority = 10&lt;br /&gt;}&lt;br /&gt;Job {&lt;br /&gt;Name = "Client1"&lt;br /&gt;JobDefs = "DefaultJob"&lt;br /&gt;Write Bootstrap = "/var/db/bacula/Client1.bsr"&lt;br /&gt;}&lt;br /&gt;Job {&lt;br /&gt;Name = "BackupCatalog"&lt;br /&gt;JobDefs = "DefaultJob"&lt;br /&gt;Level = Full&lt;br /&gt;FileSet="Catalog"&lt;br /&gt;Schedule = "WeeklyCycleAfterBackup"&lt;br /&gt;# This creates an ASCII copy of the catalog&lt;br /&gt;RunBeforeJob = "/usr/local/share/bacula/make_catalog_backup bacula bacula"&lt;br /&gt;# This deletes the copy of the catalog&lt;br /&gt;RunAfterJob = "/usr/local/share/bacula/delete_catalog_backup"&lt;br /&gt;Write Bootstrap = "/var/db/bacula/BackupCatalog.bsr"&lt;br /&gt;Priority = 11&lt;br /&gt;}&lt;br /&gt;# Opções padrão para restauração&lt;br /&gt;Job {&lt;br /&gt;Name = "RestoreFiles"&lt;br /&gt;Type = Restore&lt;br /&gt;Client=testes-fd&lt;br /&gt;FileSet="Full Set"&lt;br /&gt;Storage = File&lt;br /&gt;Pool = Default&lt;br /&gt;Messages = Standard&lt;br /&gt;Where = /bacula-restores&lt;br /&gt;}&lt;br /&gt;# Lista dos arquivos para fazer backup&lt;br /&gt;FileSet {&lt;br /&gt;Name = "Full Set"&lt;br /&gt;Include {&lt;br /&gt;Options {&lt;br /&gt;signature = MD5&lt;br /&gt;}&lt;br /&gt;#&lt;br /&gt;# Litas dos arquivos e diretórios para backup. Não use areas de links logicos.&lt;br /&gt;# Para fazer backups&lt;br /&gt;File = /usr/ports/sysutils/bacula-server/work/bacula-2.2.5&lt;br /&gt;# Áreas do sistema&lt;br /&gt;File = /usr/home&lt;br /&gt;}&lt;br /&gt;# Aqui podemos definir os diretórios que nao é desejado o backup&lt;br /&gt;Exclude {&lt;br /&gt;File = /proc&lt;br /&gt;File = /tmp&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;# Aqui é definida a politica de backup, onde nesse exemplo temos um “full backup” (backup completo)&lt;br /&gt;# no primeiro domingo de cada mes, diferencial em cada domingo e incremental nos outros dias.&lt;br /&gt;Schedule {&lt;br /&gt;Name = "WeeklyCycle"&lt;br /&gt;Run = Full 1st sun at 23:05&lt;br /&gt;Run = Differential 2nd-5th sun at 23:05&lt;br /&gt;Run = Incremental mon-sat at 23:05&lt;br /&gt;}&lt;br /&gt;# Aqui faz-se o catalogo de backups. Deve ser iniciado depois do WeeklyCycle (Ciclo Semanal)&lt;br /&gt;Schedule {&lt;br /&gt;Name = "WeeklyCycleAfterBackup"&lt;br /&gt;Run = Full sun-sat at 23:10&lt;br /&gt;}&lt;br /&gt;# Aqui é o backup do catalogo&lt;br /&gt;FileSet {&lt;br /&gt;Name = "Catalog"&lt;br /&gt;Include {&lt;br /&gt;Options {&lt;br /&gt;signature = MD5&lt;br /&gt;}&lt;br /&gt;File = /var/db/bacula/bacula.sql&lt;br /&gt;}&lt;br /&gt;}&lt;br /&gt;# Agentes para o backup&lt;br /&gt;Client {&lt;br /&gt;Name = testes-fd&lt;br /&gt;Address = testes.novatec.com.br&lt;br /&gt;FDPort = 9102&lt;br /&gt;Catalog = MyCatalog&lt;br /&gt;Password = "Director01i2007Client"&lt;br /&gt;File Retention = 30 days&lt;br /&gt;Job Retention = 6 months&lt;br /&gt;AutoPrune = yes&lt;br /&gt;}&lt;br /&gt;# Definicao dos dispositivos de storage em arquivo&lt;br /&gt;Storage {&lt;br /&gt;Name = File&lt;br /&gt;# Nunca use localhost aqui&lt;br /&gt;Address = testes.novatec.com.br&lt;br /&gt;SDPort = 9103&lt;br /&gt;Password = "DirectorStoragePW"&lt;br /&gt;# Em Device definimos o local para o backup especificado no agente.&lt;br /&gt;Device = FileStorage&lt;br /&gt;Media Type = File&lt;br /&gt;}&lt;br /&gt;# Definicao dos dispositivos de storage em fita&lt;br /&gt;Storage {&lt;br /&gt;Name = DDS-4&lt;br /&gt;Address = testes.novatec.com.br&lt;br /&gt;SDPort = 9103&lt;br /&gt;Password = "DirectorStoragePW"&lt;br /&gt;Device = DDS-4&lt;br /&gt;Media Type = DDS-4&lt;br /&gt;}&lt;br /&gt;# Generic catalog service&lt;br /&gt;Catalog {&lt;br /&gt;Name = MyCatalog&lt;br /&gt;dbname = bacula; user = bacula; password = "SenhaPW"&lt;br /&gt;}&lt;br /&gt;# Gera e-mails com relatorios e informa a console do Bacula&lt;br /&gt;Messages {&lt;br /&gt;Name = Standard&lt;br /&gt;mailcommand = "/usr/local/sbin/bsmtp -h localhost -f \"\(Bacula\) \&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-9104090152229764279?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/9104090152229764279/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/bacula-dirconf.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/9104090152229764279'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/9104090152229764279'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/bacula-dirconf.html' title='Capítulo 12 - bacula-dir.conf'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry><entry><id>tag:blogger.com,1999:blog-7382743552317375371.post-6578773209258048776</id><published>2009-01-11T01:03:00.000-08:00</published><updated>2009-05-15T11:14:37.606-07:00</updated><title type='text'>Capítulo 6 - script de hardening - lockdown</title><content type='html'>&lt;span style="font-size:78%;"&gt;#!/bin/sh&lt;br /&gt;&lt;br /&gt;# Shortcuts for often used commands&lt;br /&gt;sshd="/usr/local/bin/editfile /etc/ssh/sshd_config"&lt;br /&gt;rc="/usr/local/bin/editfile /etc/rc.conf"&lt;br /&gt;auth="/usr/local/bin/editfile /etc/auth.conf"&lt;br /&gt;sysctl="/usr/local/bin/editfile /etc/sysctl.conf"&lt;br /&gt;fstab="/usr/local/bin/editfstab"&lt;br /&gt;ttys="/usr/local/bin/editttys"&lt;br /&gt;login="/usr/local/bin/editlogin"&lt;br /&gt;kern="/usr/local/bin/editkernel /usr/src/sys/i386/conf/some_kernel_file"&lt;br /&gt;&lt;br /&gt;noworld="/bin/chmod o="&lt;br /&gt;disable="/bin/chmod ugo="&lt;br /&gt;&lt;br /&gt;####################&lt;br /&gt;# Mounting options #&lt;br /&gt;####################&lt;br /&gt;# If the mount point exists, add the specified options.&lt;br /&gt;# Please remember that /tmp has to be executable to "make world"&lt;br /&gt;# and if you need to jail a process in a partition, don't mount it with "nodev"&lt;br /&gt;&lt;br /&gt;${fstab} /tmp +noexec,nosuid,nodev,nosymfollow&lt;br /&gt;${fstab} /var/tmp +noexec,nosuid,nodev,nosymfollow&lt;br /&gt;${fstab} /home +noexec,nosuid,nodev&lt;br /&gt;${fstab} /usr/home +noexec,nosuid,nodev&lt;br /&gt;${fstab} /var +nosuid,nodev&lt;br /&gt;${fstab} /var/mail +noexec,nodev,nosuid&lt;br /&gt;&lt;br /&gt;########################&lt;br /&gt;# Build a debug kernel #&lt;br /&gt;########################&lt;br /&gt;#${kern} options DDB&lt;br /&gt;#${kern} makeoptions DEBUG=-g&lt;br /&gt;#${kern} options DDB_UNATTENDED&lt;br /&gt;#${kern} options SC_DISABLE_DDBKEY&lt;br /&gt;#Remember that your swap partition must be larger than you amount of ram!&lt;br /&gt;#${rc} dumpdev=\"YOUR_SWAP\" #Read /etc/fstab or run swapinfo&lt;br /&gt;#${rc} dumpdir=\"/var/crash\"&lt;br /&gt;&lt;br /&gt;########################&lt;br /&gt;# /etc/rc.conf options #&lt;br /&gt;########################&lt;br /&gt;# This will just add some options to /etc/rc.conf&lt;br /&gt;${rc} sendmail_enable=\"NONE\"&lt;br /&gt;${rc} kern_securelevel_enable=\"YES\"&lt;br /&gt;${rc} kern_securelevel=\"1\"&lt;br /&gt;${rc} portmap_enable=\"NO\"&lt;br /&gt;${rc} inetd_enable=\"NO\"&lt;br /&gt;${rc} clear_tmp_enable=\"YES\"&lt;br /&gt;${rc} update_motd=\"NO\"&lt;br /&gt;${rc} syslogd_flags=\"-ss\" #Comment this if this is a log server (or change it)&lt;br /&gt;&lt;br /&gt;##################&lt;br /&gt;# Stealth server #&lt;br /&gt;##################&lt;br /&gt;# If this is a log server, firewall or gateway you can put it into stealth mode.&lt;br /&gt;# This is NOT recommended for normal server use.&lt;br /&gt;# Note: For a stealthier server you should also block some icmp request like:&lt;br /&gt;# Echo, Time and Netmask requests&lt;br /&gt;#${rc} tcp_drop_synfin=\"YES\"&lt;br /&gt;#${sysctl} net.inet.tcp.blackhole=2&lt;br /&gt;#${sysctl} net.inet.udp.blackhole=1&lt;br /&gt;#${kern} options IPSTEALTH&lt;br /&gt;#${kern} options TCP_DROP_SYNFIN&lt;br /&gt;&lt;br /&gt;######################&lt;br /&gt;# Networking options #&lt;br /&gt;######################&lt;br /&gt;${rc} icmp_drop_redirect=\"YES\"&lt;br /&gt;${rc} icmp_log_redirect=\"YES\"&lt;br /&gt;${rc} log_in_vain=\"YES\"&lt;br /&gt;${kern} options RANDOM_IP_ID&lt;br /&gt;${sshd} AllowGroups wheel&lt;br /&gt;${sshd} Protocol 2&lt;br /&gt;&lt;br /&gt;#######################&lt;br /&gt;# Login Class options #&lt;br /&gt;#######################&lt;br /&gt;${login} default minpasswordlen=8&lt;br /&gt;${login} default mixpasswordcase=true&lt;br /&gt;${login} default umask=077&lt;br /&gt;# Encryption of passwords&lt;br /&gt;${auth} crypt_default=blf&lt;br /&gt;${login} default passwd_format=blf&lt;br /&gt;&lt;br /&gt;##############&lt;br /&gt;# Root Login #&lt;br /&gt;##############&lt;br /&gt;${ttys} console insecure&lt;br /&gt;${ttys} tty insecure&lt;br /&gt;&lt;br /&gt;#####################&lt;br /&gt;# Restrict the user #&lt;br /&gt;#####################&lt;br /&gt;#Don't allow users to use cron&lt;br /&gt;if test ! -f /var/cron/allow&lt;br /&gt;then&lt;br /&gt;/usr/bin/touch /var/cron/allow&lt;br /&gt;fi&lt;br /&gt;#Don't allow users to use at&lt;br /&gt;if test ! -f var/at/at.allow&lt;br /&gt;then&lt;br /&gt;/usr/bin/touch /var/at/at.allow&lt;br /&gt;fi&lt;br /&gt;&lt;br /&gt;${sysctl} security.bsd.see_other_uids=0 # Use kern.ps_showallprocs for 4.X&lt;br /&gt;&lt;br /&gt;##################&lt;br /&gt;# Kernel options #&lt;br /&gt;##################&lt;br /&gt;#${kern} options SC_NO_HISTORY # Don't keep history, so there can't be scrolled&lt;br /&gt;#${kern} options SC_DISABLE_REBOOT # Disable ctrl+alt+del&lt;br /&gt;&lt;br /&gt;#################################&lt;br /&gt;# Restrict access to suid files #&lt;br /&gt;#################################&lt;br /&gt;${disable} /bin/rcp&lt;br /&gt;${noworld} /sbin/mksnap_ffs&lt;br /&gt;${noworld} /sbin/ping&lt;br /&gt;${noworld} /sbin/ping6&lt;br /&gt;${noworld} /sbin/shutdown&lt;br /&gt;${noworld} /usr/bin/at&lt;br /&gt;${noworld} /usr/bin/atq&lt;br /&gt;${noworld} /usr/bin/atrm&lt;br /&gt;${noworld} /usr/bin/batch&lt;br /&gt;${noworld} /usr/bin/chpass&lt;br /&gt;${noworld} /usr/bin/chfn&lt;br /&gt;${noworld} /usr/bin/chsh&lt;br /&gt;${noworld} /usr/bin/ypchpass&lt;br /&gt;${noworld} /usr/bin/ypchfn&lt;br /&gt;${noworld} /usr/bin/ypchsh&lt;br /&gt;${noworld} /usr/bin/lock&lt;br /&gt;${noworld} /usr/bin/login&lt;br /&gt;${noworld} /usr/bin/opieinfo&lt;br /&gt;${noworld} /usr/bin/opiepasswd&lt;br /&gt;${noworld} /usr/bin/passwd&lt;br /&gt;${noworld} /usr/bin/yppasswd&lt;br /&gt;${noworld} /usr/bin/quota&lt;br /&gt;${disable} /usr/bin/rlogin&lt;br /&gt;${disable} /usr/bin/rsh&lt;br /&gt;${noworld} /usr/bin/su&lt;br /&gt;${noworld} /usr/bin/crontab&lt;br /&gt;${noworld} /usr/bin/lpq&lt;br /&gt;${noworld} /usr/bin/lpr&lt;br /&gt;${noworld} /usr/bin/lprm&lt;br /&gt;${noworld} /usr/libexec/pt_chown&lt;br /&gt;${noworld} /usr/sbin/mrinfo&lt;br /&gt;${noworld} /usr/sbin/mtrace&lt;br /&gt;${noworld} /usr/sbin/sliplogin&lt;br /&gt;${noworld} /usr/sbin/timedc&lt;br /&gt;${noworld} /usr/sbin/traceroute&lt;br /&gt;${noworld} /usr/sbin/traceroute6&lt;br /&gt;${noworld} /usr/sbin/ppp&lt;br /&gt;${noworld} /usr/sbin/pppd&lt;br /&gt;&lt;br /&gt;################################&lt;br /&gt;# Restrict access to gid files #&lt;br /&gt;################################&lt;br /&gt;${noworld} /usr/bin/fstat&lt;br /&gt;${noworld} /usr/bin/netstat&lt;br /&gt;${noworld} /usr/bin/vmstat&lt;br /&gt;${noworld} /usr/bin/wall&lt;br /&gt;${noworld} /usr/bin/write&lt;br /&gt;${noworld} /usr/bin/lpq&lt;br /&gt;${noworld} /usr/bin/lpr&lt;br /&gt;${noworld} /usr/bin/lprm&lt;br /&gt;${noworld} /usr/libexec/sendmail/sendmail&lt;br /&gt;${noworld} /usr/sbin/trpt&lt;br /&gt;${noworld} /usr/sbin/lpc&lt;br /&gt;&lt;br /&gt;########################################&lt;br /&gt;# Restrict access to information files #&lt;br /&gt;########################################&lt;br /&gt;${noworld} /sbin/sysctl&lt;br /&gt;${noworld} /usr/bin/uname&lt;br /&gt;${noworld} /sbin/kldstat&lt;br /&gt;#${noworld} /usr/bin/netstat #Uncomment if using 4.X&lt;br /&gt;${noworld} /sbin/route&lt;br /&gt;${noworld} /usr/sbin/arp&lt;br /&gt;${noworld} /sbin/dmesg&lt;br /&gt;${noworld} /var/run/dmesg.boot&lt;br /&gt;${noworld} /etc/hosts&lt;br /&gt;${noworld} /etc/fstab&lt;br /&gt;${noworld} /etc/ssh/sshd_config&lt;br /&gt;${noworld} /etc/crontab&lt;br /&gt;${noworld} /etc/ftpusers&lt;br /&gt;${noworld} /etc/hosts.allow&lt;br /&gt;${noworld} /etc/host.conf&lt;br /&gt;${noworld} /etc/hosts.equiv&lt;br /&gt;${noworld} /etc/hosts.lpd&lt;br /&gt;${noworld} /etc/inetd.conf&lt;br /&gt;${noworld} /etc/login.access&lt;br /&gt;${noworld} /etc/login.conf&lt;br /&gt;${noworld} /etc/sysctl.conf&lt;br /&gt;${noworld} /etc/syslog.conf&lt;br /&gt;${noworld} /etc/ttys&lt;br /&gt;${noworld} /etc/rc.conf&lt;br /&gt;${noworld} /etc/mac.conf&lt;br /&gt;${noworld} /etc/group&lt;br /&gt;${noworld} /etc/passwd&lt;br /&gt;${noworld} /etc/newsyslog.conf&lt;br /&gt;${noworld} /etc/periodic/&lt;br /&gt;${noworld} /var/db/pkg/&lt;br /&gt;${noworld} /usr/sbin/pkg_version&lt;br /&gt;${noworld} /usr/sbin/pkg_info&lt;br /&gt;${noworld} /usr/bin/last&lt;br /&gt;${noworld} /usr/sbin/lastlogin&lt;br /&gt;${noworld} /sbin/ipfw&lt;br /&gt;${noworld} /sbin/mount&lt;br /&gt;${noworld} /usr/bin/users&lt;br /&gt;${noworld} /usr/bin/w&lt;br /&gt;${noworld} /usr/bin/who&lt;br /&gt;${noworld} /usr/bin/lastcomm&lt;br /&gt;${noworld} /usr/sbin/jls&lt;br /&gt;${noworld} /home/&lt;br /&gt;${noworld} /var/mail/&lt;br /&gt;${noworld} /var/log/&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;FreeBSD: O Poder dos Servidores em Suas Mãos&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/7382743552317375371-6578773209258048776?l=freebsdbook.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://freebsdbook.blogspot.com/feeds/6578773209258048776/comments/default' title='Postar comentários'/><link rel='replies' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/script-de-hardening-lockdown.html#comment-form' title='0 Comentários'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6578773209258048776'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/7382743552317375371/posts/default/6578773209258048776'/><link rel='alternate' type='text/html' href='http://freebsdbook.blogspot.com/2009/01/script-de-hardening-lockdown.html' title='Capítulo 6 - script de hardening - lockdown'/><author><name>Denis Augusto</name><uri>http://www.blogger.com/profile/14130287418062517679</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
