1. Free as in freedom :
Almost 99.9% of Linux’s source code is released as open source. This means you can modify the code and redistribute it as you see fit. This means lesser lawsuits and lesser hassles in gaining updates.
There was a point in software time when anything free was considered buggy, incomplete or plain pointless. That might be then, but this is now. Linux has grown into one of the most advanced OS out there, and how! The penguin has come a long way indeed.
2. Surf the net without fear:
Yes, you read it right. Linux separates the root user from other users, thus restricting user privileges, and drastically reducing the chances of catching a virus. There are around 40 malwares in circulation, but almost 32 of them do nothing harmful, and are intended to point out security loopholes within Linux’s kernel. 6 of the remaining rest are dangerous and 2 are Trojans. If you’re still worried of catching a Linux virus, why don’t you resort to the age old solution- Go get yourself a free antivirus.
3. No more bloated OS: Linux makes a lot of room for your programs:
In fact, I’ve been using a PCLinuxOS installation on my PC for the past 2 months, and I’ve Installed a lot of software’s for Linux from Unreal Tournament 2004 to NVidia’s latest graphic drivers. Linux leaves a lot of room for your stuff, and doesn’t slow down one bit!!
Showing posts with label Linux - The better alternative. Show all posts
Showing posts with label Linux - The better alternative. Show all posts
02 February, 2009
30 January, 2009
How badly do you need an antivirus?
How many times have you wondered which is the best antivirus? Nod? Symantec Norton? Kaspersky? Bit defender?? My answer: None of the above. Why?? Read on.
Recently my curiosity got the best of me and I finally decided to read “The Big black book of virus programming” that I bought a while back. I’m told the book is illegal in most countries, and you could end up in jail for so much as possessing it!! The book details pretty much everything you need to know and also gives you a start by giving off some virus source code on the CD accompanying the book.
I started off writing my first virus and coded it such that it would look for a folder and deleted it. The folder was aptly named “Do Not Delete” and resided on my root drive.
I have a PC with the latest hardware. Thus , running 3 anti viruses is a walk in the park. Just for your info, I was running MacAfee, Symantec Corporate, and Nod 32. Some of the most reputed names in the antivirus industry.
The virus was written in assembler to make it faster than programs which I previously wrote in Java or C#. I fired up my “Virus”, and it promptly did its work. For a moment this really startled me because none of the antivirus programs even warned me that a potentially unsafe operation was being performed by a third party program. I convinced myself thinking that of course they didn’t detect it! It’s just another program that’s occupying memory and manipulating files. As far as other “programs” such as anti-viruses are concerned, there is NO harm being done to your computer!!
Most viruses are offshoots of “virus creation” kits available in shady websites running in third world countries like Nigeria or Kenya. So, the programmers for these “antivirus” programs have to detect a pattern in the viruses and voila, the antivirus detects the threat. But what if people like you and me started writing viruses? Would the antivirus programs have any chance at all in detecting these new “breed” of viruses?? Of course not! This is exactly the reason why the market for “network security” has grown exponentially over the past decade. We need to have fewer OS loopholes (poke at Microsoft) and fewer ways for programs to run in the background without your permission. Of course, if windows (like Symantec internet security 2008) were to ask you each and everything, you would curse your OS while click “ OK” and “Ignore” buttons , endlessly.
Yes, there is a certain tradeoff between OS security and usability, but that’s for novice users. NOT for pros like me. Well, we could probably have 5 modes for the OS, something like:
1. Novice
2. Intermediate
3. Power User
4. Expert User
5. Geek demigod ?
Recently my curiosity got the best of me and I finally decided to read “The Big black book of virus programming” that I bought a while back. I’m told the book is illegal in most countries, and you could end up in jail for so much as possessing it!! The book details pretty much everything you need to know and also gives you a start by giving off some virus source code on the CD accompanying the book.
I started off writing my first virus and coded it such that it would look for a folder and deleted it. The folder was aptly named “Do Not Delete” and resided on my root drive.
I have a PC with the latest hardware. Thus , running 3 anti viruses is a walk in the park. Just for your info, I was running MacAfee, Symantec Corporate, and Nod 32. Some of the most reputed names in the antivirus industry.
The virus was written in assembler to make it faster than programs which I previously wrote in Java or C#. I fired up my “Virus”, and it promptly did its work. For a moment this really startled me because none of the antivirus programs even warned me that a potentially unsafe operation was being performed by a third party program. I convinced myself thinking that of course they didn’t detect it! It’s just another program that’s occupying memory and manipulating files. As far as other “programs” such as anti-viruses are concerned, there is NO harm being done to your computer!!
Most viruses are offshoots of “virus creation” kits available in shady websites running in third world countries like Nigeria or Kenya. So, the programmers for these “antivirus” programs have to detect a pattern in the viruses and voila, the antivirus detects the threat. But what if people like you and me started writing viruses? Would the antivirus programs have any chance at all in detecting these new “breed” of viruses?? Of course not! This is exactly the reason why the market for “network security” has grown exponentially over the past decade. We need to have fewer OS loopholes (poke at Microsoft) and fewer ways for programs to run in the background without your permission. Of course, if windows (like Symantec internet security 2008) were to ask you each and everything, you would curse your OS while click “ OK” and “Ignore” buttons , endlessly.
Yes, there is a certain tradeoff between OS security and usability, but that’s for novice users. NOT for pros like me. Well, we could probably have 5 modes for the OS, something like:
1. Novice
2. Intermediate
3. Power User
4. Expert User
5. Geek demigod ?
09 June, 2008
How to Move from Windows to Linux
- Choose a Linux Distro. Research is key.
Look into what distribution of GNU/Linux would be best for you.
Everyone is different, and all Linux distributions are different,
but there will probably be one (or two) that appeals to the most.
If you're new to the operating system, it's probably best to go for
something PCLinuxOS,
Mandriva or Ubuntu - these
distributions of Linux are aimed at inexperienced users and will
help you along the way. The Ubuntu distribution will send you a set
of CDs free of charge, there are other sites on the internet which
charge a small fee for postage. - Try the "Live CD" versions first, assuming your computer will
boot from the CD drive; most will. Most distributions offer Live CD
ISOs on their website, which you can burn to CD. A Live CD means
that Linux will run entirely from a CD and will not touch your
Windows installation - this allows you to test out some of the
functionality Linux offers without wiping your existing Windows
install. - Use Linux applications that have been ported over to Windows.
Fine example are Inkscape and the
GIMP. Using these will get you used to the kind of applications
available on Linux (Although there is a school of thought to the
effect that the GIMP is a bad piece of software). Using open source
applications will be a real boost when you actually switch over, as
it will be relatively painless for, say, an XChat user to use XChat
on his new system, rather than a mIRC (Or other Windows-only IRC client) user having
to learn an entirely new program. - Back up your important data before you do anything else. If you
make a mistake while installing Linux, it's possible you'll have to
format your hard drive to put things right. In which case, you will
lose all data on it. It is very important you back up if you need
to. - Get hold of a Linux install CD - when you boot from this, it
will take you through the steps required to install Linux. Some
distributions, like Ubuntu, actually install from the Live CD, so
you do not need to download an additional CD image. - Partition your hard drive into two partitions, one containing
your existing Windows install, the other containing the Linux
installation. Under Windows, this can be easily done with various
partitioning tools (Partition Magic, Paragon Partition Manager and
others) preserving both Windows installation and existing data.
Note that Windows Vista comes with a partition tool. - Choose which operating system to boot into when once the Linux
installation has finished. This is called dual-booting. It is wise
to do this before completely converting to Linux to give you
something to fall back on if something goes wrong. - Get comfortable with Linux. As time goes on you will find you
need to boot into Windows less and less. Using Linux is a learning
experience, make sure you make the most of the "community" help
which is available from most distributions of Linux. There is
usually a wide community which you can ask questions and there will
be people more than willing to help you out with any problems
you've got. Make sure you use Google and the "search" functions on
community websites because people may get irate at answering the
same questions all the time in forums and on irc. Visit your
distribution's support page or FAQ. - Wipe your Windows partition (devote your entire hard disk to
Linux) once you're comfortable with Linux. You'll probably never
look back!
26 May, 2008
Open Source alternatives to MS OFFICE?? Are you kidding me?
| Writer | A word processor similar in look and feel to Microsoft Word and offering a comparable range of functions and tools. It also includes the ability to export Portable Document Format (PDF) files with no additional software, and can also function as a WYSIWYG editor for creating and editing web pages. | |
| Calc | A spreadsheet similar to Microsoft Excel with a roughly equivalent range of features. Calc provides a number of features not present in Excel, including a system which automatically defines series for graphing, based on the layout of the user’s data. Calc is also capable of writing spreadsheets directly as a PDF file. | |
| Impress | A presentation program similar to Microsoft PowerPoint. It can export presentations to Adobe Flash (SWF) files allowing them to be played on any computer with the Flash player installed. It also includes the ability to create PDF files, and the ability to read Microsoft PowerPoint's .ppt format. Impress suffers from a lack of ready-made presentation designs. However, templates are readily available on the Internet.[12][13][14] | |
| Base | A database program similar to Microsoft Access. Base allows the creation and manipulation of databases, and the building of forms and reports to provide easy access to data for end-users. As with Access, Base may be used as a front-end to a number of different database systems, including Access databases (JET), ODBC data sources and MySQL/PostgreSQL. Base became part of the suite starting with version 2.0. Native to the OpenOffice.org suite is an adaptation of HSQL. While ooBase can be a front-end for any of the databases listed, there is no need for any of them to be installed. | |
| Draw | A vector graphics editor comparable in features to early versions of CorelDRAW. It features versatile "connectors" between shapes, which are available in a range of line styles and facilitate building drawings such as flowcharts. It has similar features to Desktop publishing software such as Scribus and Microsoft Publisher. | |
| Math | A tool for creating and editing mathematical formulae, similar to Microsoft Equation Editor. Formulae can be embedded inside other OpenOffice.org documents, such as those created by Writer. It supports multiple fonts and can exp |
21 April, 2008
Advanced Shell Coding Techniques
Introduction
This paper assumes a working knowledge of basic shellcoding techniques, and x86 assembly, I will not rehash these in this paper. I hope to teach you some of the lesser known shellcoding techniques that I have picked up, which will allow you to write smaller and better shellcodes. I do not claim to have invented any of these techniques, except for the one that uses the div instruction.
The multiplicity of mul
This technique was originally developed by Sorbo of darkircop.net. The mul instruction may, on the surface, seem mundane, and it's purpose obvious. However, when faced with the difficult challenge of shrinking your shellcode, it proves to be quite useful. First some background information on the mul instruction itself.
mul performs an unsigned multiply of two integers. It takes only one operand, the other is implicitly specified by the %eax register. So, a common mul instruction might look something like this:
movl $0x0a,%eax
mul $0x0a
This would multiply the value stored in %eax by the operand of mul, which in this case would be 10*10. The result is then implicitly stored in EDX:EAX. The result is stored over a span of two registers because it has the potential to be considerably larger than the previous value, possibly exceeding the capacity of a single register(this is also how floating points are stored in some cases, as an interesting sidenote).
So, now comes the ever-important question. How can we use these attributes to our advantage when writing shellcode? Well, let's think for a second, the instruction takes only one operand, therefore, since it is a very common instruction, it will generate only two bytes in our final shellcode. It multiplies whatever is passed to it by the value stored in %eax, and stores the value in both %edx and %eax, completely overwriting the contents of both registers, regardless of whether it is necessary to do so, in order to store the result of the multiplication. Let's put on our mathematician hats for a second, and consider this, what is the only possible result of a multiplication by 0? The answer, as you may have guessed, is 0. I think it's about time for some example code, so here it is:
xorl %ecx,%ecx
mul %ecx
What is this shellcode doing? Well, it 0's out the %ecx register using the xor instruction, so we now know that %ecx is 0. Then it does a mul %ecx, which as we just learned, multiplies it's operand by the value in %eax, and then proceeds to store the result of this multiplication in EDX:EAX. So, regardless of %eax's previous contents, %eax must now be 0. However that's not all, %edx is 0'd now too, because, even though no overflow occurs, it still overwrites the %edx register with the sign bit(left-most bit) of %eax. Using this technique we can zero out three registers in only three bytes, whereas by any other method(that I know of) it would have taken at least six.
The div instruction
Div is very similar to mul, in that it takes only one operand and implicitly divides the operand by the value in %eax. Also like, mul it stores the result of the divide in %eax. Again, we will require the mathematical side of our brains to figure out how we can take advantage of this instruction. But first, let's think about what is normally stored in the %eax register. The %eax register holds the return value of functions and/or syscalls. Most syscalls that are used in shellcoding will return -1(on failure) or a positive value of some kind, only rarely will they return 0(though it does occur). So, if we know that after a syscall is performed, %eax will have a non-zero value, and that the instruction divl %eax will divide %eax by itself, and then store the result in %eax, we can say that executing the divl %eax instruction after a syscall will put the value 1 into %eax. So...how is this applicable to shellcoding? Well, their is another important thing that %eax is used for, and that is to pass the specific syscall that you would like to call to int $0x80. It just so happens that the syscall that corresponds to the value 1 is exit(). Now for an example:
xorl %ebx,%ebx
mul %ebx
push %edx
pushl $0x3268732f
pushl $0x6e69622f
mov %esp, %ebx
push %edx
push %ebx
mov %esp,%ecx
movb $0xb, %al #execve() syscall, doesn't return at all unless it fails, in which case it returns -1
int $0x80
divl %eax # -1 / -1 = 1
int $0x80
Now, we have a 3 byte exit function, where as before it was 5 bytes. However, there is a catch, what if a syscall does return 0? Well in the odd situation in which that could happen, you could do many different things, like inc %eax, dec %eax, not %eax anything that will make %eax non-zero. Some people say that exit's are not important in shellcode, because your code gets executed regardless of whether or not it exits cleanly. They are right too, if you really need to save 3 bytes to fit your shellcode in somewhere, the exit() isn't worth keeping. However, when your code does finish, it will try to execute whatever was after your last instruction, which will most likely produce a SIG ILL(illegal instruction) which is a rather odd error, and will be logged by the system. So, an exit() simply adds an extra layer of stealth to your exploit, so that even if it fails or you can't wipe all the logs, at least this part of your presence will be clear.
Unlocking the power of leal
The leal instruction is an often neglected instruction in shellcode, even though it is quite useful. Consider this short piece of shellcode.
xorl %ecx,%ecx
leal 0x10(%ecx),%eax
This will load the value 17 into eax, and clear all of the extraneous bits of eax. This occurs because the leal instruction loads a variable of the type long into it's desitination operand. In it's normal usage, this would load the address of a variable into a register, thus creating a pointer of sorts. However, since ecx is 0'd and 0+17=17, we load the value 17 into eax instead of any kind of actual address. In a normal shellcode we would do something like this, to accomplish the same thing:
xorl %eax,%eax
movb $0x10,%eax
I can hear you saying, but that shellcode is a byte shorter than the leal one, and you're quite right. However, in a real shellcode you may already have to 0 out a register like ecx(or any other register), so the xorl instruction in the leal shellcode isn't counted. Here's an example:
xorl %eax,%eax
xorl %ebx,%ebx
movb $0x17,%al
int $0x80
xorl %ebx,%ebx
leal 0x17(%ebx),%al
int $0x80
Both of these shellcodes call setuid(0), but one does it in 7 bytes while the other does it in 8. Again, I hear you saying but that's only one byte it doesn't make that much of a difference, and you're right, here it doesn't make much of a difference(except for in shellcode-size pissing contests =p), but when applied to much larger shellcodes, which have many function calls and need to do things like this frequently, it can save quite a bit of space.
Conclusion
I hope you all learned something, and will go out and apply your knowledge to create smaller and better shellcodes. If you know who invented the leal technique, please tell me and I will credit him/her.
This paper assumes a working knowledge of basic shellcoding techniques, and x86 assembly, I will not rehash these in this paper. I hope to teach you some of the lesser known shellcoding techniques that I have picked up, which will allow you to write smaller and better shellcodes. I do not claim to have invented any of these techniques, except for the one that uses the div instruction.
The multiplicity of mul
This technique was originally developed by Sorbo of darkircop.net. The mul instruction may, on the surface, seem mundane, and it's purpose obvious. However, when faced with the difficult challenge of shrinking your shellcode, it proves to be quite useful. First some background information on the mul instruction itself.
mul performs an unsigned multiply of two integers. It takes only one operand, the other is implicitly specified by the %eax register. So, a common mul instruction might look something like this:
movl $0x0a,%eax
mul $0x0a
This would multiply the value stored in %eax by the operand of mul, which in this case would be 10*10. The result is then implicitly stored in EDX:EAX. The result is stored over a span of two registers because it has the potential to be considerably larger than the previous value, possibly exceeding the capacity of a single register(this is also how floating points are stored in some cases, as an interesting sidenote).
So, now comes the ever-important question. How can we use these attributes to our advantage when writing shellcode? Well, let's think for a second, the instruction takes only one operand, therefore, since it is a very common instruction, it will generate only two bytes in our final shellcode. It multiplies whatever is passed to it by the value stored in %eax, and stores the value in both %edx and %eax, completely overwriting the contents of both registers, regardless of whether it is necessary to do so, in order to store the result of the multiplication. Let's put on our mathematician hats for a second, and consider this, what is the only possible result of a multiplication by 0? The answer, as you may have guessed, is 0. I think it's about time for some example code, so here it is:
xorl %ecx,%ecx
mul %ecx
What is this shellcode doing? Well, it 0's out the %ecx register using the xor instruction, so we now know that %ecx is 0. Then it does a mul %ecx, which as we just learned, multiplies it's operand by the value in %eax, and then proceeds to store the result of this multiplication in EDX:EAX. So, regardless of %eax's previous contents, %eax must now be 0. However that's not all, %edx is 0'd now too, because, even though no overflow occurs, it still overwrites the %edx register with the sign bit(left-most bit) of %eax. Using this technique we can zero out three registers in only three bytes, whereas by any other method(that I know of) it would have taken at least six.
The div instruction
Div is very similar to mul, in that it takes only one operand and implicitly divides the operand by the value in %eax. Also like, mul it stores the result of the divide in %eax. Again, we will require the mathematical side of our brains to figure out how we can take advantage of this instruction. But first, let's think about what is normally stored in the %eax register. The %eax register holds the return value of functions and/or syscalls. Most syscalls that are used in shellcoding will return -1(on failure) or a positive value of some kind, only rarely will they return 0(though it does occur). So, if we know that after a syscall is performed, %eax will have a non-zero value, and that the instruction divl %eax will divide %eax by itself, and then store the result in %eax, we can say that executing the divl %eax instruction after a syscall will put the value 1 into %eax. So...how is this applicable to shellcoding? Well, their is another important thing that %eax is used for, and that is to pass the specific syscall that you would like to call to int $0x80. It just so happens that the syscall that corresponds to the value 1 is exit(). Now for an example:
xorl %ebx,%ebx
mul %ebx
push %edx
pushl $0x3268732f
pushl $0x6e69622f
mov %esp, %ebx
push %edx
push %ebx
mov %esp,%ecx
movb $0xb, %al #execve() syscall, doesn't return at all unless it fails, in which case it returns -1
int $0x80
divl %eax # -1 / -1 = 1
int $0x80
Now, we have a 3 byte exit function, where as before it was 5 bytes. However, there is a catch, what if a syscall does return 0? Well in the odd situation in which that could happen, you could do many different things, like inc %eax, dec %eax, not %eax anything that will make %eax non-zero. Some people say that exit's are not important in shellcode, because your code gets executed regardless of whether or not it exits cleanly. They are right too, if you really need to save 3 bytes to fit your shellcode in somewhere, the exit() isn't worth keeping. However, when your code does finish, it will try to execute whatever was after your last instruction, which will most likely produce a SIG ILL(illegal instruction) which is a rather odd error, and will be logged by the system. So, an exit() simply adds an extra layer of stealth to your exploit, so that even if it fails or you can't wipe all the logs, at least this part of your presence will be clear.
Unlocking the power of leal
The leal instruction is an often neglected instruction in shellcode, even though it is quite useful. Consider this short piece of shellcode.
xorl %ecx,%ecx
leal 0x10(%ecx),%eax
This will load the value 17 into eax, and clear all of the extraneous bits of eax. This occurs because the leal instruction loads a variable of the type long into it's desitination operand. In it's normal usage, this would load the address of a variable into a register, thus creating a pointer of sorts. However, since ecx is 0'd and 0+17=17, we load the value 17 into eax instead of any kind of actual address. In a normal shellcode we would do something like this, to accomplish the same thing:
xorl %eax,%eax
movb $0x10,%eax
I can hear you saying, but that shellcode is a byte shorter than the leal one, and you're quite right. However, in a real shellcode you may already have to 0 out a register like ecx(or any other register), so the xorl instruction in the leal shellcode isn't counted. Here's an example:
xorl %eax,%eax
xorl %ebx,%ebx
movb $0x17,%al
int $0x80
xorl %ebx,%ebx
leal 0x17(%ebx),%al
int $0x80
Both of these shellcodes call setuid(0), but one does it in 7 bytes while the other does it in 8. Again, I hear you saying but that's only one byte it doesn't make that much of a difference, and you're right, here it doesn't make much of a difference(except for in shellcode-size pissing contests =p), but when applied to much larger shellcodes, which have many function calls and need to do things like this frequently, it can save quite a bit of space.
Conclusion
I hope you all learned something, and will go out and apply your knowledge to create smaller and better shellcodes. If you know who invented the leal technique, please tell me and I will credit him/her.
17 April, 2008
SUSE 10.1 Guide :Get your TUX on !
When you're done downloading and installing SUSE Linux 10.1 OSS, your desktop system is not complete. You might still need support for Java programs, MP3 audio files, and browser plug-ins for Macromedia Flash, Adobe Acrobat, RealPlayer, and Windows Media Video. You may also want to add support for playing DVD videos on your computer, and to try out the new XGL graphical toys. Here's how to effectively make SUSE Linux 10.1 into the perfect desktop OS.
Why you need this guide
SUSE Linux 10.1 OSS -- as the name implies -- is comprised entirely of free, open source software. What you will be doing in this tutorial (with the exception of configuring XGL and Compiz) is installing proprietary add-ons that add functionality. All of the browser plugins are proprietary and will require you to agree to restrictive software licenses. The DVD playback capabilities are in violation of the U.S. Digital Millennium Copyright Act (and similar laws in other countries), which many believe to be unconstitutional and a violation of consumer fair use rights. (Further information on DMCA reform is available here.)
In other words, installing the DVD decoding software could be illegal where you live; therefore I'm not telling you to do it, but I'll tell you how it's done -- for educational and informational purposes only, of course.
Furthermore, if you morally or ethically disagree with proprietary software and refuse to use it, this guide will be meaningless to you.
If you need a more thorough guide that covers installation and system-wide configuration, I've written one for Sam's Publishing entitled SUSE Linux 10.1 Kick Start. It will be available as an electronic download for a very low cost, starting on June 7.
Prerequisites
This guide assumes that you have already installed SUSE Linux 10.1, and are now seeking to add support for Java, Macromedia Flash, Adobe Acrobat, Windows Media, RealPlayer, ATI or Nvidia graphics cards, XGL/Compiz interface enhancements, and commercial DVD movies. Feel free to ignore the portions of the guide that do not apply to your situation, but don't skip over the parts that show you how to add sources to YaST or any other general instructions.
Furthermore, this guide assumes you are using the default desktop environment, KDE. If you're using GNOME or a window manager, you're on your own as far as getting to the YaST utility and any other KDE-specific instructions listed below. In general, however, the majority of the information in this guide is environment-agnostic.
Lastly, Hacking SUSE Linux 10.1 applies only to the x86 and AMD64/EM64T processor architectures. It does not cover the PowerPC architecture. If someone who has a PPC machine is willing to contribute a section specific to PPC, please email me.
The non-OSS extras CD
The standard SUSE Linux 10.1 OSS CD set (or DVD) does not include the non-free extras CD. This applies to the CD torrent provided by OpenSUSE.org as well -- it only includes the five installation CDs. While this guide recommends using Internet sources for all of your software adding and updating, if you want to do everything from discs, you will need to download the 400MB extras ISO from here (.iso download link). It's good for both AMD64 and x86.
Write that ISO to a CD only if you need to work from physical installation media after the operating system is already installed (like if you don't have a broadband Internet account, or if the computer you're installing to will not have a regular network connection).
Adding sources to YaST
The next order of business is to prepare SUSE to install software from alternate sources. In addition to making this guide easier to follow in the long-run, it also eliminates the need for your physical installation media (CDs or DVD).
Go into the YaST utility by clicking on the green Gecko menu in the lower left corner of your screen. Select System, then click on YaST (Control Center). You'll be prompted for your root password. Go ahead and type it in and press the Enter key.
You're now in YaST, and the Software category is already selected by default. Click on the Installation Source icon. This will bring up a window that will allow you to add software repositories so that you can download the add-on software. You'll notice that your CD or DVD installation media is already listed. Go ahead and disable it by clicking the Enable Or Disable button -- we're going to add an Internet address that will replace your discs. That way if you need to add software from the CDs or DVD, you can get the packages from the Internet instead of putting a disc into your computer. If you need to, you can just as easily enable the CD/DVD source later.
Click the Add button, then click on HTTP in the popup menu. Add the following Internet address to the Server Name field and then click on OK:
packman.unixheads.com/suse/10.1 (or select a mirror from this list)
Now repeat this process and add the following servers to your installation sources:
Required packages
Most of the steps below demand that the following packages be installed:
Atheros wireless network drivers
The original release of SUSE Linux 10.1 OSS did not contain drivers for Atheros-based wireless network cards. There is now a package available, however. Go to the Software Manager in YaST, then search for this term: madwifi
In the right pane, most people will need to select these two packages:
ATI video drivers
SUSE Linux 10.1 ships with the newly revamped open source
Go to the ATI website, click on Drivers & Software, then Linux Display Drivers and Software, then on the driver appropriate to your video card. 32-bit SUSE installations need the x86 drivers, and 64-bit SUSE needs the x86_64 versions. After you have clicked the link for your card, yet another link comes up. Click it, scroll down to the downloads table, then right-click the ATI Driver Installer download link and save it to your home directory. You do not need to download any of the other packages.
After the file transfer completes, close all open programs, then press ctrl-alt-F1 to switch to the first virtual terminal. You'll see a text-mode login prompt; log in as root. When you're at the command prompt, type in this command:
You'll see a bunch of text scroll by, and then a message saying that runlevel 3 has been reached. Press Enter to get the command prompt back, then type the following command in to switch to the directory you downloaded the ATI driver to:
Substitute your user name for "username" in the above example. Now you need to change the ATI installer permissions so that it can be run from the command line.
For long file names, you don't have to type the whole name into a terminal window. Instead, just type the first few letters and then press the Tab key, and the file name will be automatically completed for you. This is useful in situations like the one you're in now, where there is a long and complex file name to type in. So type the following command into your terminal, and use the Tab key to complete the ATI driver file name, then press Enter to execute the command:
That will make the program executable; this must be done before you can run it. Now it's time to run the installer. Again, use tab completion instead of typing the name in. You have to add the ./ before the filename to tell the terminal program that the file you are referring to is in the current directory. If you don't specify that, the terminal will look in other places for the file. It sounds crazy, yes, but that's the way GNU/Linux is (and Unix before it). For the below example, the entire file name is typed in. Please note that this may not be the same file name that you downloaded -- it is only an example. You should use tab completion when you type this command in so that you don't accidentally mis-type the long file name. The part of the example that will not change is the switch statement after the file name (the part with the dashes). Here's the example command for the ATI driver installer for a 32-bit system:
And for a 64-bit system:
After a few dozen lines of text, a driver package will be created. Go ahead and run it with the following command (the first example is for 32-bit systems):
And for 64-bit systems:
Update your system environment variables with this command:
Next, you need to tell SUSE that you want to use this driver instead of the standard one:
Lastly, you have to tell YaST which driver to load (that's a zero in the example, not a letter):
Now reboot your computer by typing the following command:
The next time your system starts, you'll have hardware 3D video acceleration. Please note that every time you update your kernel, you must re-install the ATI video driver.
Nvidia video drivers
SUSE Linux 10.1 no longer includes the proprietary Nvidia graphics driver, nor is it available through YaST anymore. If you want hardware 3D acceleration for your Nvidia-based graphics card, you will have to enable it the old fashioned way -- by going to the Nvidia website; clicking on Download Drivers; then on Linux, FreeBSD, and Solaris Drivers; then on your architecture; and lastly, on the driver download itself. Save it to your home directory (or somewhere that isn't too difficult to get to via the command line).
The Nvidia installer demands to be installed outside of a graphical environment. Close all open programs, then press ctrl-alt-F1 to get to the virtual terminal. You'll be prompted for login information; log in as root. After you've logged in, use this command to exit X.org:
Press enter when it says that init level 3 has been reached, and you'll find yourself at a command prompt again. Navigate to the directory that contains the Nvidia driver (replace "username" with your user name):
For long file names, you don't have to type the whole name into a terminal window. Instead, just type the first few letters and then press the Tab key, and the file name will be automatically completed for you. This is useful in situations like the one you're in now, where there is a long and complex file name to type in. So type the following command into your terminal, and use the Tab key to complete the Nvidia driver file name, then press Enter to execute the chmod command:
The installer is now executable, so go ahead and run it with this command, again using tab completion to fill in the file name after the first few characters:
The installation utility will come up. Choose Yes (or whatever is the default) for all of the options. When the installer is finished, it will bring you back to the command line. Use this command to restart your computer:
When next you log into SUSE Linux, you should have hardware 3D acceleration enabled. To check, run this program from a terminal program (the computer screen icon in the lower left, between the house icon and the life preserver):
Dozens of lines of text should result from this command. Look near the top for the Direct Rendering line. If it says Yes, you're all set. If it says no, go back and re-check all of your steps to make sure there were no errors, that you downloaded the correct driver for your processor architecture, and that you followed the directions exactly.
Please note that every time you update your kernel, you must re-install the Nvidia video driver.
Java support
To add support for the Java language both for standalone applications and as a browser plugin for Web applets, go into YaST, then select Package Management. In the Search box, type in sun and click Search. A bunch of packages will show up in the right-hand pane. Click the checkbox next to the following packages:
There is no harm in selecting all of the java-1_5_0-sun packages (you'll notice that there are a few more that weren't selected), but they are not necessary for running Java programs. If you're a Java programmer you may want at least some of the other packages. When you're done selecting them, click on Accept. When it's done installing, click on Finish in the popup window to go back to YaST. Your computer will now be able to run Java programs and applets.
Flash, Acrobat, Windows Media, MP3, and RealMedia support
Go back into the YaST software manager. In the Search box, type in
Erase your previous search term in the Search box, type in
Now search for
Search for
Search for
When you've done all of this, click on Accept. Other packages will be dependent on some of these, so you may have to click Continue in the Automatic Changes screen that comes up. After that, all of the packages you just selected will be installed and your Firefox Web browser will have all of the plugins it needs. You'll also have the ability to play MP3 music files. A popup window will appear when it's done -- just click on Finish and you'll be brought back to YaST.
DVD playback on 32-bit machines
You must add the sources listed above and then perform a software update via the ZENworks update tool (from the Gecko menu, go to System, then Configuration, then Update Software). This will replace your Xine libraries with DVD-capable versions from Packman.
After you've installed all software updates, go to your Gecko menu, then select Internet, then Web Browser, then click on Web Browser (Konqueror). When Konqueror opens, copy and paste in this address if you are using 32-bit SUSE Linux:
http://download.videolan.org/pub/libdvdcss/1.2.9/rpm/libdvdcss2-1.2.9-1.i386.rpm
Or just click here if you want a link. Konqueror will ask you what you want to do with the file. Click the Open With button, and in the ensuing popup window, click on System, then Configuration, then KPackage (if you do not have KPackage installed, bookmark the DeCSS RPM, then go back to the YaST software manager and install the kdeadmin3 package, then restart this process). The KPackage program will read the DVD decoding package from the Web. Click on the Install button at the bottom of the KPackage window, then click on Install in the next window too. You will be asked for your root password; type it in and press Enter. Shortly thereafter, the DVD decoding library will be installed. Click on the Done button, then close KPackage and Konqueror.
You now have the ability to play commercial DVD movies on your computer -- put one in and try it, if it's legal where you are. A popup message should appear when you put in a DVD movie. If it asks you if you want to play the movie with Kaffeine, click on Yes and you'll go straight to the video player. In some instances the disc may be recognized as a data disc, and SUSE will ask you if you want to open the DVD with K3b. In that case, click on Ignore, then go to the Gecko menu, select Multimedia, then Video Player, then click on Media Player (Kaffeine). When Kaffeine starts, click on the Open DVD icon.
DVD playback on 64-bit machines
You must add the sources listed above and then perform a software update via the ZENworks update tool (from the Gecko menu, go to System, then Configuration, then Update Software). This will replace your Xine libraries with DVD-capable versions from Packman.
After you've installed all software updates, go to your Gecko menu, then select Internet, then Web Browser, then click on Firefox. When it opens, copy and paste in this address if you are using 64-bit SUSE Linux (there is currently no 64-bit binary RPM):
http://download.videolan.org/pub/libdvdcss/1.2.9/libdvdcss-1.2.9.tar.gz
Select the Save As option, then click on the Home icon in the left pane and save it there. The file isn't very big, so it should download almost immediately. You can close the Web browser now, and open a terminal by clicking the monitor icon in the lower left corner of your screen (it's between the house icon and the life preserver). Now use this command to switch to root permissions:
It'll ask for your root password -- go ahead and type it in, then press Enter. Now you need to decompress the file you just downloaded. Type this in:
Then unpack it from its archive by using this command:
The file will un-tar to its own directory, so you can now safely delete the tar arc.
Why you need this guide
SUSE Linux 10.1 OSS -- as the name implies -- is comprised entirely of free, open source software. What you will be doing in this tutorial (with the exception of configuring XGL and Compiz) is installing proprietary add-ons that add functionality. All of the browser plugins are proprietary and will require you to agree to restrictive software licenses. The DVD playback capabilities are in violation of the U.S. Digital Millennium Copyright Act (and similar laws in other countries), which many believe to be unconstitutional and a violation of consumer fair use rights. (Further information on DMCA reform is available here.)
In other words, installing the DVD decoding software could be illegal where you live; therefore I'm not telling you to do it, but I'll tell you how it's done -- for educational and informational purposes only, of course.
Furthermore, if you morally or ethically disagree with proprietary software and refuse to use it, this guide will be meaningless to you.
If you need a more thorough guide that covers installation and system-wide configuration, I've written one for Sam's Publishing entitled SUSE Linux 10.1 Kick Start. It will be available as an electronic download for a very low cost, starting on June 7.
Prerequisites
This guide assumes that you have already installed SUSE Linux 10.1, and are now seeking to add support for Java, Macromedia Flash, Adobe Acrobat, Windows Media, RealPlayer, ATI or Nvidia graphics cards, XGL/Compiz interface enhancements, and commercial DVD movies. Feel free to ignore the portions of the guide that do not apply to your situation, but don't skip over the parts that show you how to add sources to YaST or any other general instructions.
Furthermore, this guide assumes you are using the default desktop environment, KDE. If you're using GNOME or a window manager, you're on your own as far as getting to the YaST utility and any other KDE-specific instructions listed below. In general, however, the majority of the information in this guide is environment-agnostic.
Lastly, Hacking SUSE Linux 10.1 applies only to the x86 and AMD64/EM64T processor architectures. It does not cover the PowerPC architecture. If someone who has a PPC machine is willing to contribute a section specific to PPC, please email me.
The non-OSS extras CD
The standard SUSE Linux 10.1 OSS CD set (or DVD) does not include the non-free extras CD. This applies to the CD torrent provided by OpenSUSE.org as well -- it only includes the five installation CDs. While this guide recommends using Internet sources for all of your software adding and updating, if you want to do everything from discs, you will need to download the 400MB extras ISO from here (.iso download link). It's good for both AMD64 and x86.
Write that ISO to a CD only if you need to work from physical installation media after the operating system is already installed (like if you don't have a broadband Internet account, or if the computer you're installing to will not have a regular network connection).
Adding sources to YaST
The next order of business is to prepare SUSE to install software from alternate sources. In addition to making this guide easier to follow in the long-run, it also eliminates the need for your physical installation media (CDs or DVD).
Go into the YaST utility by clicking on the green Gecko menu in the lower left corner of your screen. Select System, then click on YaST (Control Center). You'll be prompted for your root password. Go ahead and type it in and press the Enter key.
You're now in YaST, and the Software category is already selected by default. Click on the Installation Source icon. This will bring up a window that will allow you to add software repositories so that you can download the add-on software. You'll notice that your CD or DVD installation media is already listed. Go ahead and disable it by clicking the Enable Or Disable button -- we're going to add an Internet address that will replace your discs. That way if you need to add software from the CDs or DVD, you can get the packages from the Internet instead of putting a disc into your computer. If you need to, you can just as easily enable the CD/DVD source later.
Click the Add button, then click on HTTP in the popup menu. Add the following Internet address to the Server Name field and then click on OK:
packman.unixheads.com/suse/10.1 (or select a mirror from this list)
Now repeat this process and add the following servers to your installation sources:
- download.opensuse.org/distribution/SL-10.1/inst-source/
- download.opensuse.org/distribution/SL-10.1/non-oss-inst-source/
Required packages
Most of the steps below demand that the following packages be installed:
- gcc
- make
- kernel-source
- kernel-syms
- kdeadmin3
Atheros wireless network drivers
The original release of SUSE Linux 10.1 OSS did not contain drivers for Atheros-based wireless network cards. There is now a package available, however. Go to the Software Manager in YaST, then search for this term: madwifi
In the right pane, most people will need to select these two packages:
- madwifi
- madwifi-kmp-default
ath_pci module by hand or just restart the computer to activate your wireless network.ATI video drivers
SUSE Linux 10.1 ships with the newly revamped open source
radeon driver. That may be fine for 2D rendering, but it doesn't do direct rendering for 3D graphics. To get hardware 3D acceleration (and for XGL support), you still need the proprietary ATI fglrx driver.Go to the ATI website, click on Drivers & Software, then Linux Display Drivers and Software, then on the driver appropriate to your video card. 32-bit SUSE installations need the x86 drivers, and 64-bit SUSE needs the x86_64 versions. After you have clicked the link for your card, yet another link comes up. Click it, scroll down to the downloads table, then right-click the ATI Driver Installer download link and save it to your home directory. You do not need to download any of the other packages.
After the file transfer completes, close all open programs, then press ctrl-alt-F1 to switch to the first virtual terminal. You'll see a text-mode login prompt; log in as root. When you're at the command prompt, type in this command:
init 3You'll see a bunch of text scroll by, and then a message saying that runlevel 3 has been reached. Press Enter to get the command prompt back, then type the following command in to switch to the directory you downloaded the ATI driver to:
cd /home/username/Substitute your user name for "username" in the above example. Now you need to change the ATI installer permissions so that it can be run from the command line.
For long file names, you don't have to type the whole name into a terminal window. Instead, just type the first few letters and then press the Tab key, and the file name will be automatically completed for you. This is useful in situations like the one you're in now, where there is a long and complex file name to type in. So type the following command into your terminal, and use the Tab key to complete the ATI driver file name, then press Enter to execute the command:
chmod +x ./ati-driverThat will make the program executable; this must be done before you can run it. Now it's time to run the installer. Again, use tab completion instead of typing the name in. You have to add the ./ before the filename to tell the terminal program that the file you are referring to is in the current directory. If you don't specify that, the terminal will look in other places for the file. It sounds crazy, yes, but that's the way GNU/Linux is (and Unix before it). For the below example, the entire file name is typed in. Please note that this may not be the same file name that you downloaded -- it is only an example. You should use tab completion when you type this command in so that you don't accidentally mis-type the long file name. The part of the example that will not change is the switch statement after the file name (the part with the dashes). Here's the example command for the ATI driver installer for a 32-bit system:
./ati-driver-installer-8.24.8-x86.run --buildpkg SuSE/SUSE101-IA32And for a 64-bit system:
./ati-driver-installer-8.24.8-x86_64.run --buildpkg SuSE/SUSE101-AMD64After a few dozen lines of text, a driver package will be created. Go ahead and run it with the following command (the first example is for 32-bit systems):
rpm -ivh fglrx_6_9_0_SUSE101-8.24.8-1.i386.rpmAnd for 64-bit systems:
rpm -ivh fglrx64_6_9_0_SUSE101-8.24.8-1.x86_64.rpmUpdate your system environment variables with this command:
ldconfigNext, you need to tell SUSE that you want to use this driver instead of the standard one:
aticonfig --initial --input=/etc/X11/xorg.confLastly, you have to tell YaST which driver to load (that's a zero in the example, not a letter):
sax2 -r -m 0=fglrxNow reboot your computer by typing the following command:
rebootThe next time your system starts, you'll have hardware 3D video acceleration. Please note that every time you update your kernel, you must re-install the ATI video driver.
Nvidia video drivers
SUSE Linux 10.1 no longer includes the proprietary Nvidia graphics driver, nor is it available through YaST anymore. If you want hardware 3D acceleration for your Nvidia-based graphics card, you will have to enable it the old fashioned way -- by going to the Nvidia website; clicking on Download Drivers; then on Linux, FreeBSD, and Solaris Drivers; then on your architecture; and lastly, on the driver download itself. Save it to your home directory (or somewhere that isn't too difficult to get to via the command line).
The Nvidia installer demands to be installed outside of a graphical environment. Close all open programs, then press ctrl-alt-F1 to get to the virtual terminal. You'll be prompted for login information; log in as root. After you've logged in, use this command to exit X.org:
init 3Press enter when it says that init level 3 has been reached, and you'll find yourself at a command prompt again. Navigate to the directory that contains the Nvidia driver (replace "username" with your user name):
cd /home/username/For long file names, you don't have to type the whole name into a terminal window. Instead, just type the first few letters and then press the Tab key, and the file name will be automatically completed for you. This is useful in situations like the one you're in now, where there is a long and complex file name to type in. So type the following command into your terminal, and use the Tab key to complete the Nvidia driver file name, then press Enter to execute the chmod command:
chmod +x ./NVIDIAThe installer is now executable, so go ahead and run it with this command, again using tab completion to fill in the file name after the first few characters:
./NVIDIAThe installation utility will come up. Choose Yes (or whatever is the default) for all of the options. When the installer is finished, it will bring you back to the command line. Use this command to restart your computer:
rebootWhen next you log into SUSE Linux, you should have hardware 3D acceleration enabled. To check, run this program from a terminal program (the computer screen icon in the lower left, between the house icon and the life preserver):
glxinfoDozens of lines of text should result from this command. Look near the top for the Direct Rendering line. If it says Yes, you're all set. If it says no, go back and re-check all of your steps to make sure there were no errors, that you downloaded the correct driver for your processor architecture, and that you followed the directions exactly.
Please note that every time you update your kernel, you must re-install the Nvidia video driver.
Java support
To add support for the Java language both for standalone applications and as a browser plugin for Web applets, go into YaST, then select Package Management. In the Search box, type in sun and click Search. A bunch of packages will show up in the right-hand pane. Click the checkbox next to the following packages:
- java-1_5_0-sun
- java-1_5_0-sun-alsa
- java-1_5_0-sun-devel
- java-1_5_0-sun-plugin
Note to 64-bit users:
The Java 1.5.0 packages in the AMD64/EM64T edition of SUSE Linux 10.1 are 64-bit, whereas the Java 1.4.2 packages are 32-bit. Since the Firefox package is 32-bit, you will have to install version 1.4.2 if you want to be able to use Java applets. Firefox will use 1.4.2 if you have both versions installed, so you can install both Java 1.4.2 and 1.5.0, though outside of Firefox I'm not sure what effect that will have on Java-aware programs.
There is no harm in selecting all of the java-1_5_0-sun packages (you'll notice that there are a few more that weren't selected), but they are not necessary for running Java programs. If you're a Java programmer you may want at least some of the other packages. When you're done selecting them, click on Accept. When it's done installing, click on Finish in the popup window to go back to YaST. Your computer will now be able to run Java programs and applets.
Flash, Acrobat, Windows Media, MP3, and RealMedia support
Go back into the YaST software manager. In the Search box, type in
w32codec-all and click on Search. A single package should appear in the right-hand pane. Click the checkbox next to it if it is not already installed. Some people may see a lock icon there instead; this means that the package is already installed.Erase your previous search term in the Search box, type in
acroread and click on Search. Click the checkbox next to the acroread package in the right-hand pane.Now search for
flash and click Search. Select that package for installation by clicking its checkbox and agreeing to its license.Search for
realplayer and click Search. Click its checkbox. You only need the RealPlayer package itself -- the other search results are not necessary.Search for
mplayer and click Search. Click the checkbox next to mplayerplug-in. You can also install the other package -- MPlayer -- if you want to, but you've already got a number of video players on your computer.When you've done all of this, click on Accept. Other packages will be dependent on some of these, so you may have to click Continue in the Automatic Changes screen that comes up. After that, all of the packages you just selected will be installed and your Firefox Web browser will have all of the plugins it needs. You'll also have the ability to play MP3 music files. A popup window will appear when it's done -- just click on Finish and you'll be brought back to YaST.
DVD playback on 32-bit machines
You must add the sources listed above and then perform a software update via the ZENworks update tool (from the Gecko menu, go to System, then Configuration, then Update Software). This will replace your Xine libraries with DVD-capable versions from Packman.
After you've installed all software updates, go to your Gecko menu, then select Internet, then Web Browser, then click on Web Browser (Konqueror). When Konqueror opens, copy and paste in this address if you are using 32-bit SUSE Linux:
http://download.videolan.org/pub/libdvdcss/1.2.9/rpm/libdvdcss2-1.2.9-1.i386.rpm
Or just click here if you want a link. Konqueror will ask you what you want to do with the file. Click the Open With button, and in the ensuing popup window, click on System, then Configuration, then KPackage (if you do not have KPackage installed, bookmark the DeCSS RPM, then go back to the YaST software manager and install the kdeadmin3 package, then restart this process). The KPackage program will read the DVD decoding package from the Web. Click on the Install button at the bottom of the KPackage window, then click on Install in the next window too. You will be asked for your root password; type it in and press Enter. Shortly thereafter, the DVD decoding library will be installed. Click on the Done button, then close KPackage and Konqueror.
You now have the ability to play commercial DVD movies on your computer -- put one in and try it, if it's legal where you are. A popup message should appear when you put in a DVD movie. If it asks you if you want to play the movie with Kaffeine, click on Yes and you'll go straight to the video player. In some instances the disc may be recognized as a data disc, and SUSE will ask you if you want to open the DVD with K3b. In that case, click on Ignore, then go to the Gecko menu, select Multimedia, then Video Player, then click on Media Player (Kaffeine). When Kaffeine starts, click on the Open DVD icon.
DVD playback on 64-bit machines
You must add the sources listed above and then perform a software update via the ZENworks update tool (from the Gecko menu, go to System, then Configuration, then Update Software). This will replace your Xine libraries with DVD-capable versions from Packman.
After you've installed all software updates, go to your Gecko menu, then select Internet, then Web Browser, then click on Firefox. When it opens, copy and paste in this address if you are using 64-bit SUSE Linux (there is currently no 64-bit binary RPM):
http://download.videolan.org/pub/libdvdcss/1.2.9/libdvdcss-1.2.9.tar.gz
Select the Save As option, then click on the Home icon in the left pane and save it there. The file isn't very big, so it should download almost immediately. You can close the Web browser now, and open a terminal by clicking the monitor icon in the lower left corner of your screen (it's between the house icon and the life preserver). Now use this command to switch to root permissions:
suIt'll ask for your root password -- go ahead and type it in, then press Enter. Now you need to decompress the file you just downloaded. Type this in:
gzip -d libdvdcss-1.2.9.tar.gzThen unpack it from its archive by using this command:
tar xvf libdvdcss-1.2.9.tarThe file will un-tar to its own directory, so you can now safely delete the tar arc.
14 April, 2008
Why is LINUX better?
>Forget Viruses
>THE MOST STABLE OS's OUT THERE ARE LINUX BASED!!
>Dont pay $300 for your OS
>FREEDOM as in FREE
>Almost no fragmentation of your disk! This results in max performance!
>Tired of restarting all the time?
>GET a LIFE !
>THE MOST STABLE OS's OUT THERE ARE LINUX BASED!!
>Dont pay $300 for your OS
>FREEDOM as in FREE
>Almost no fragmentation of your disk! This results in max performance!
>Tired of restarting all the time?
>GET a LIFE !
OpenSUSE 10.3 ROCKS!!!!
yaw ppl. Im writing this form within openSUSE 10.3 and I gotta admit, this OS ROCKS!!! Its got everything of what you would expect in windows - the piracy !!
> A gr8 office suite (http://openoffice.org)
> Easy YaST installations, easier than Windows Setup!!
>An intuitive interface that hides the underlying power, yet doesnt compromise flexibility
>Very easy to use even for a novice XP user!
> NOT hard on resources. You can run this OS with 128 megs of RAM!
> Wine compatible. That means, you can run all your Windows games, apps from within Linux!!
> A gr8 office suite (http://openoffice.org)
> Easy YaST installations, easier than Windows Setup!!
>An intuitive interface that hides the underlying power, yet doesnt compromise flexibility
>Very easy to use even for a novice XP user!
> NOT hard on resources. You can run this OS with 128 megs of RAM!
> Wine compatible. That means, you can run all your Windows games, apps from within Linux!!

