Tuesday, June 11, 2013

Automated Dynamic IP Whitelisting for CSF Firewall Using PHP and Bash

When administering remote Linux production servers protected by ConfigServer Security & Firewall (CSF), dynamic residential IPs frequently get blocked or locked out of management portals. Here is a lightweight, automated mechanism to dynamically whitelist your current IP address simply by visiting a private URL on your server.

Architecture: PHP capture endpoint • Fast-polling background Bash daemon • CSF Perl reload

1. The PHP Endpoint (whatis.php)

Create a secure PHP script in your web root that logs the visitor's remote client IP to a temporary staging file:

<?php
// Protect with an authentication token or secret parameter in production
file_put_contents("/tmp/iplog", $_SERVER["REMOTE_ADDR"]);
echo "IP captured: " . htmlspecialchars($_SERVER["REMOTE_ADDR"]);
?>

2. The Shell Whitelister Daemon (/script/ip)

Create a root shell script to inspect the staging file, update /etc/csf/csf.allow, and reload firewall rules:

#!/bin/bash
i=1
while [ $i -le 10 ]
do
    status=$(cat /tmp/iplog 2>/dev/null)
    if [ -n "$status" ] && [ "$status" != "0" ]; then
        echo "$status" >> /etc/csf/csf.allow
        echo "$status" >> /etc/csf/csf.ignore
        echo "0" > /tmp/iplog
        # Note: Use csf.pl -r inside scripts for reliable Perl-based reload
        /etc/csf/csf.pl -r > /tmp/csf.log 2>&1
    fi
    sleep 5
    (( i++ ))
done

Make the script executable:

chmod +x /script/ip

3. Cronjob Schedule

Add a root crontab entry to execute the daemon once every minute:

* * * * * /script/ip
Implementation Tip: Calling csf -r from non-interactive shell scripts often fails to reload properly. Invoking the underlying Perl script /etc/csf/csf.pl -r ensures firewall tables reload reliably.

Tuesday, June 4, 2013

How to Run mini_sendmail in a Chrooted PHP-FPM Environment (CentOS & Debian)

Chrooting PHP-FPM worker pools provides robust filesystem isolation on multi-tenant servers. However, standard mail dispatch breaks because PHP's mail() function relies on executing a local sendmail binary (which requires extensive shared libraries and access to /etc). mini_sendmail solves this by providing a lightweight, statically linkable MTA forwarder that relays directly to localhost port 25.

Stack: PHP-FPM Chroot • mini_sendmail • CentOS 6 / Debian 6

1. Preparing the Chroot Filesystem

Inside the jail directory, ensure character devices and DNS resolvers are accessible:

cd /path/to/jail
chmod 0666 dev/{tty,null,zero}
echo "nameserver 8.8.8.8" > etc/resolv.conf

2. Compiling and Patching mini_sendmail

Download and extract the source:

cd /usr/src
wget http://acme.com/software/mini_sendmail/mini_sendmail-1.3.6.tar.gz
tar -zxf mini_sendmail-1.3.6.tar.gz
cd mini_sendmail-1.3.6

When running inside a chroot jail without /etc/passwd, getlogin() fails with can't determine username. Fix this by hardcoding the pool user in mini_sendmail.c around line 148:

// Replace: username = getlogin();
// With your PHP-FPM pool user:
username = "fpm_user";

Compile and install into the jail's usr/sbin/sendmail:

make
cp mini_sendmail /path/to/jail/usr/sbin/sendmail
chmod 755 /path/to/jail/usr/sbin/sendmail
chown fpm_user:fpm_user /path/to/jail/usr/sbin/sendmail

Now PHP scripts running inside the chroot jail can execute mail() and messages are cleanly forwarded to your server's primary MTA.

How Google Antigravity Solved the Mysterious NVIDIA Sleep Reboot on My Dell Inspiron 7567 (Ubuntu Linux)

If you run modern Ubuntu or Linux on a Dell Inspiron 15 Gaming (7567) or a similar 7th-gen Intel laptop paired with an NVIDIA GeForce GTX ...