Tuesday, October 8, 2013

How to Log PHP mail() Sender Scripts and Headers to Detect Outgoing Spam

When a web server hosting multiple PHP applications or CMS sites is compromised by spammers, identifying the exact malicious PHP script sending unauthorized emails can be notoriously difficult. In PHP 5.3 and newer, built-in configuration directives allow you to track the exact script filename and originating source of every outgoing message.

Key Directives: mail.log for auditing script paths • mail.add_x_header for tracking script UID in email headers.

1. Enable mail.log

Open your server's php.ini (or pool configuration in PHP-FPM) and configure a dedicated mail log:

; Log all mail() function invocations, including script path and line number
mail.log = /var/log/php_mail.log

Ensure the web server user (e.g. apache or www-data) has write permissions to the destination file:

touch /var/log/php_mail.log
chown www-data:www-data /var/log/php_mail.log
chmod 660 /var/log/php_mail.log

2. Enable X-PHP-Originating-Script Header

To embed the sender script path directly into outgoing mail headers, enable mail.add_x_header:

; Adds X-PHP-Originating-Script header containing the UID and filename
mail.add_x_header = On

When an email is sent, the recipient headers will contain:

X-PHP-Originating-Script: 1000:contact_form.php

This allows you to immediately trace spam reports back to the offending script or compromised user account.

Thursday, August 29, 2013

Troubleshooting FSI System Coupling Errors in ANSYS Fluent and CFX (Excessive Distortion)

During two-way Fluid-Structure Interaction (FSI) simulations using ANSYS System Coupling between Transient Structural and Fluent or CFX, a sudden simulation abort often occurs at the very first coupling iteration with excessive mesh distortion errors.

Simulation Environments: ANSYS Workbench • System Coupling • Transient Structural • Fluent / CFX

Error Symptoms

Fluent System Coupling Exception:

System Coupling Exception: Origin: Transient Structural (Solution)
Error Code: 2
Error Description: One or more elements have become highly distorted.
Excessive distortion of elements is usually a symptom indicating the need for corrective action elsewhere.
Try ramping the load up instead of step applying the load (KBC,1).

CFX System Coupling Error:

ERROR #001100279 has occurred in subroutine ErrAction.
Message: CFX encountered the error: Read. Fatal error occurred when requesting Total Mesh Displacement for FSI.

Root Causes and Solutions

  1. Operating / Reference Pressure Mismatch:

    Both Fluent and CFX compute pressures relative to a designated operating/reference pressure. If your structural model expects gauge pressure but receives absolute pressure (or vice versa), the structural boundary experiences an instantaneous massive pressure spike at time step zero, causing severe structural element distortion. Ensure your fluid reference pressure aligns with your structural reference state.

  2. Velocity Inlet Vector Misalignment:

    Ensure velocity inlet boundary conditions match the physical geometry coordinate axes. For example, if a cylindrical fluid channel lies along the X-axis and the inlet velocity is erroneously assigned to Y or Z, fluid impacts the boundary wall immediately, creating an unphysical pressure surge and massive displacement.

  3. Load Ramping:

    In Transient Structural, avoid step-applying initial loads (KBC,1). Instead, ramp fluid forces gradually over the first few coupling sub-iterations to prevent transient shockwaves from inverting flexible mesh elements.

Thursday, August 22, 2013

Fixing ANSYS Fluent FSI Error: Unassigned Interface Zone Detected

When preparing an ANSYS Fluent mesh for two-way Fluid-Structure Interaction (FSI) coupled with ANSYS Mechanical, clicking Check Mesh may trigger the following warning and cause the mesh validation to fail:

Context: ANSYS Fluent mesh validation • Dynamic Mesh • Boundary Conditions
WARNING: Unassigned interface zone detected for interface 6.
WARNING: Mesh check failed.
To get more detailed information about the mesh check failure,
increase the mesh check verbosity via the TUI command /mesh/check-verbosity.

Root Cause & Solution

This error occurs when the boundary condition type for the FSI surface is set to Interface rather than Wall.

  • In Fluent, the boundary type Interface is exclusively reserved for grid interface pairs (such as sliding meshes or non-conformal meshes joined via Mesh Interfaces).
  • For an FSI coupling surface where fluid interacts with a solid structure, the boundary condition type must be set to Wall.
  • Under the Dynamic Mesh panel, designate this Wall as a dynamic boundary zone and assign it to System Coupling.

Once changed from Interface to Wall, re-running Check Mesh passes cleanly with zero warnings.

Monday, August 19, 2013

Troubleshooting ADINA FSI Simulation: INPUT ERROR: No Node Found in BCD

When running a Fluid-Structure Interaction (FSI) simulation in the ADINA FEM software suite, generating the solver DATA file may abort with the following error:

Environment: ADINA Structures • ADINA CFD • FSI Boundary Condition Definition
*** INPUT ERROR: No node found in BCD 1

Cause and Resolution

This error occurs when the FSI Boundary Condition (BCD) is assigned to the incorrect model body or geometric surface:

  • In ADINA FSI modeling, the fluid-structure boundary condition must be explicitly defined on the shared interface surface corresponding to the proper model domain (e.g. defining structural boundary nodes on the solid body and fluid boundary nodes on the fluid body).
  • If the FSI boundary surface is mapped to a geometry surface that lacks associated mesh nodes in that model component, ADINA cannot bind any degrees of freedom and throws the No node found in BCD error.

Verify that your interface boundary assignments match the mesh geometry of the active model component before regenerating the DATA file.

Wednesday, July 31, 2013

How to Install mod_flvx and mod_h264_streaming on cPanel Apache 2

Serving progressive download video files (such as MP4 and FLV) with seeking capabilities directly from Apache on a cPanel/WHM server requires compiling custom Apache modules: mod_flvx for FLV streaming and mod_h264_streaming for pseudo-streaming H.264/MP4 files.

Environment: cPanel / WHM • EasyApache • Apache 2.2 / 2.4 • H.264 / FLV Streaming

1. Persistent Hook Script

To ensure modules are compiled and reinstalled automatically whenever cPanel runs EasyApache, add the build commands to /scripts/after_apache_make_install:

#!/bin/bash
cd /usr/local/src

# Compile mod_flvx
wget http://people.apache.org/~pquerna/modules/mod_flvx.c
/usr/local/apache/bin/apxs -i -c mod_flvx.c

# Compile mod_h264_streaming
wget http://h264.code-shop.com/download/apache_mod_h264_streaming-2.2.7.tar.gz
tar -zxvf apache_mod_h264_streaming-2.2.7.tar.gz
cd mod_h264_streaming-2.2.7
./configure --with-apxs='/usr/local/apache/bin/apxs'
make && make install

# Update cPanel Apache configuration distiller
/usr/local/cpanel/bin/apache_conf_distiller --update

Ensure the hook script is executable:

chmod +x /scripts/after_apache_make_install

2. Apache Global Configuration

Add the module declarations and file extension handlers to /usr/local/apache/conf/includes/pre_virtualhost_global.conf:

LoadModule h264_streaming_module modules/mod_h264_streaming.so
<IfModule mod_h264_streaming.c>
    AddHandler h264-streaming.extensions .mp4
</IfModule>

LoadModule flvx_module modules/mod_flvx.so
<IfModule mod_flvx.c>
    AddHandler flv-stream .flv
</IfModule>

3. Rebuild with EasyApache

Execute EasyApache through WHM or the command line to finalize the build. Once complete, video seeking will work seamlessly over HTTP.

Tuesday, June 11, 2013

Automated Dynamic IP Whitelisting for CSF Firewall Using PHP and Bash

When administering remote Linux production servers protected by ConfigServer Security & Firewall (CSF), dynamic residential IPs frequently get blocked or locked out of management portals. Here is a lightweight, automated mechanism to dynamically whitelist your current IP address simply by visiting a private URL on your server.

Architecture: PHP capture endpoint • Fast-polling background Bash daemon • CSF Perl reload

1. The PHP Endpoint (whatis.php)

Create a secure PHP script in your web root that logs the visitor's remote client IP to a temporary staging file:

<?php
// Protect with an authentication token or secret parameter in production
file_put_contents("/tmp/iplog", $_SERVER["REMOTE_ADDR"]);
echo "IP captured: " . htmlspecialchars($_SERVER["REMOTE_ADDR"]);
?>

2. The Shell Whitelister Daemon (/script/ip)

Create a root shell script to inspect the staging file, update /etc/csf/csf.allow, and reload firewall rules:

#!/bin/bash
i=1
while [ $i -le 10 ]
do
    status=$(cat /tmp/iplog 2>/dev/null)
    if [ -n "$status" ] && [ "$status" != "0" ]; then
        echo "$status" >> /etc/csf/csf.allow
        echo "$status" >> /etc/csf/csf.ignore
        echo "0" > /tmp/iplog
        # Note: Use csf.pl -r inside scripts for reliable Perl-based reload
        /etc/csf/csf.pl -r > /tmp/csf.log 2>&1
    fi
    sleep 5
    (( i++ ))
done

Make the script executable:

chmod +x /script/ip

3. Cronjob Schedule

Add a root crontab entry to execute the daemon once every minute:

* * * * * /script/ip
Implementation Tip: Calling csf -r from non-interactive shell scripts often fails to reload properly. Invoking the underlying Perl script /etc/csf/csf.pl -r ensures firewall tables reload reliably.

Tuesday, June 4, 2013

How to Run mini_sendmail in a Chrooted PHP-FPM Environment (CentOS & Debian)

Chrooting PHP-FPM worker pools provides robust filesystem isolation on multi-tenant servers. However, standard mail dispatch breaks because PHP's mail() function relies on executing a local sendmail binary (which requires extensive shared libraries and access to /etc). mini_sendmail solves this by providing a lightweight, statically linkable MTA forwarder that relays directly to localhost port 25.

Stack: PHP-FPM Chroot • mini_sendmail • CentOS 6 / Debian 6

1. Preparing the Chroot Filesystem

Inside the jail directory, ensure character devices and DNS resolvers are accessible:

cd /path/to/jail
chmod 0666 dev/{tty,null,zero}
echo "nameserver 8.8.8.8" > etc/resolv.conf

2. Compiling and Patching mini_sendmail

Download and extract the source:

cd /usr/src
wget http://acme.com/software/mini_sendmail/mini_sendmail-1.3.6.tar.gz
tar -zxf mini_sendmail-1.3.6.tar.gz
cd mini_sendmail-1.3.6

When running inside a chroot jail without /etc/passwd, getlogin() fails with can't determine username. Fix this by hardcoding the pool user in mini_sendmail.c around line 148:

// Replace: username = getlogin();
// With your PHP-FPM pool user:
username = "fpm_user";

Compile and install into the jail's usr/sbin/sendmail:

make
cp mini_sendmail /path/to/jail/usr/sbin/sendmail
chmod 755 /path/to/jail/usr/sbin/sendmail
chown fpm_user:fpm_user /path/to/jail/usr/sbin/sendmail

Now PHP scripts running inside the chroot jail can execute mail() and messages are cleanly forwarded to your server's primary MTA.

Tuesday, April 16, 2013

How to Compile the Latest FFmpeg with x264 and libvpx on CentOS 6

Compiling FFmpeg with high-performance H.264 (libx264) and VP8/VP9 (libvpx) encoding support on CentOS 6 often encounters dependency version collisions and compilation errors if older library packages remain installed on the host.

Environment: CentOS 6.x • FFmpeg • x264 • libvpx • faac

1. Removing Conflicting RPM Packages

Before compiling from source, remove older distribution codec libraries to prevent undefined reference linker errors like libx264.c: undefined reference to 'x264_encoder_open_130':

yum remove libvpx libogg libvorbis libtheora libx264 x264 x264-devel x264-libs ffmpeg -y

2. Patching and Compiling faac 1.28

If building the faac AAC encoder, a syntax error occurs in mpeg4ip.h: error: new declaration 'char* strcasestr(const char*, const char*)'. Remove line 126 from ./common/mp4v2/mpeg4ip.h before building:

sed -i '/strcasestr/d' common/mp4v2/mpeg4ip.h
./configure && make && make install

3. Compiling x264 and libvpx

# Build x264
cd x264
./configure --enable-static --enable-shared
make && make install

# Build libvpx
git clone https://chromium.googlesource.com/webm/libvpx
cd libvpx
./configure
make && make install
ldconfig

Once libraries are installed into /usr/local, configure FFmpeg with --enable-gpl --enable-libx264 --enable-libvpx for a fully modern encoding stack.

Wednesday, March 6, 2013

How to Compile and Install Wine 1.5 from Source on Debian Squeeze

Debian 6 (Squeeze) repositories originally froze Wine at version 1.0.1, an outdated release lacking DirectX enhancements and modern Windows API compatibility. Because official WineHQ .deb binaries were not available for Squeeze, compiling Wine 1.5 directly from source is the cleanest path to modernization.

Platform: Debian 6.0 (Squeeze) • Wine 1.5.25 Source Build

1. Install Build Dependencies

Use apt-get build-dep to fetch all required development headers:

apt-get update
apt-get build-dep wine -y

2. Download and Compile Wine

Fetch the source tarball and compile cleanly:

cd /usr/src
wget http://downloads.sourceforge.net/project/wine/Source/wine-1.5.25.tar.bz2
tar -jxf wine-1.5.25.tar.bz2
cd wine-1.5.25

./configure
make
make install

Verify installation:

wine --version

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...