<?xml version="1.0" encoding="utf-8"?>
<rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom">
  <channel>
    <atom:link href="https://www.zystvan.com/feed.xml" rel="self" type="application/rss+xml" />

    <title>Zeke Y&apos;s Blog</title>
    <description></description>
    <link>https://www.zystvan.com</link>
    
    
      <item>
        <title>How to Set Up KVM on a Remote Server</title>
        <description>&lt;p&gt;&lt;a href=&quot;https://www.linux-kvm.org/page/Main_Page&quot;&gt;KVM&lt;/a&gt; (for Kernel-based Virtual Machine) is a simple way to run virtual machines on a server. Virtual machines are great because they let you keep different projects separated, but still run on the same server, saving you hardware costs. Installing KVM on a remote server is pretty easy, but there aren’t that many guides for it. In this article, I’ll show you how to install KVM on a remote server, then create a new virtual machine on it that you can access as if it’s a separate server.&lt;/p&gt;

&lt;p&gt;&lt;em&gt;Note: I’ve tested this guide on Ubuntu Server 16.04 and 18.04. It should work on other Debian/Ubuntu distributions, but I haven’t tested it on those.&lt;/em&gt;&lt;/p&gt;

&lt;h2 id=&quot;installing-kvm-on-the-host-server&quot;&gt;Installing KVM on the Host Server&lt;/h2&gt;

&lt;p&gt;Once you’ve SSHed into the host server, the first thing to do is make sure that the server’s CPU supports virtualization by running this command in the terminal:&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;egrep &lt;span class=&quot;nt&quot;&gt;-c&lt;/span&gt; &lt;span class=&quot;s1&quot;&gt;&apos;(vmx|svm)&apos;&lt;/span&gt; /proc/cpuinfo
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;If it prints out &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;0&lt;/code&gt;, then you won’t be able to run KVM on the server. If the number is &amp;gt;= &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;1&lt;/code&gt;, then the CPU supports virtualization but you may still need to enable it in the BIOS.&lt;/p&gt;

&lt;p&gt;Next, install the necessary packages (this will take a while, and when it finishes you’ll need to reboot the server):&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;sudo &lt;/span&gt;apt-get &lt;span class=&quot;nb&quot;&gt;install &lt;/span&gt;qemu-kvm libvirt-bin ubuntu-vm-builder bridge-utils
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Once the server has restarted, check to make sure the installation worked by using the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virsh&lt;/code&gt; command:&lt;/p&gt;

&lt;div class=&quot;language-text highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;$ virsh list --all
 Id    Name                           State
----------------------------------------------------

$
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Now, before we can create a virtual machine, we need an ISO file. I recommend Ubuntu Server, but you can install any OS you want in your virtual machines:&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;cd&lt;/span&gt; /var/lib/libvirt/images/
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;wget http://releases.ubuntu.com/16.04.3/ubuntu-16.04.3-server-amd64.iso
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h2 id=&quot;creating-virtual-machines&quot;&gt;Creating Virtual Machines&lt;/h2&gt;

&lt;p&gt;Now that KVM is set up on the server, you need to create a virtual machine. Although this can be done from the terminal on the remote server, it’s much easier if you use a GUI. Thankfully, there’s a perfect tool for this called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virt-manager&lt;/code&gt;. Install it on your own computer, not the server:&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;&lt;span class=&quot;nb&quot;&gt;sudo &lt;/span&gt;apt &lt;span class=&quot;nb&quot;&gt;install &lt;/span&gt;virt-manager
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Open it up by running &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virt-manager&lt;/code&gt; from the terminal, or looking for “Virtual Machine Manager” in the applications menu. You’ll need to create a new connection by going to File &amp;gt; Add Connection in the menu. Once there, you’ll need to connect to a remote host. The default method of SSH is fine, just fill in your username and the IP address of the server (or hostname if you’ve configured your &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;/etc/hosts&lt;/code&gt; file properly).&lt;/p&gt;

&lt;p&gt;Once it’s successfully connected, you can create a new virtual machine by going to File &amp;gt; New Virtual Machine. Proceed through the steps:&lt;/p&gt;

&lt;ol&gt;
  &lt;li&gt;Use the default option of &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Local install media (ISO image or CDROM)&lt;/code&gt;.&lt;/li&gt;
  &lt;li&gt;Click the “Browse” button and choose the ISO file we downloaded earlier, then select the correct OS and version&lt;/li&gt;
  &lt;li&gt;Choose how much RAM and the number of CPU cores you want assigned to the VM (if possible, I recommend a minimum of 2GB RAM and 2 CPUs)&lt;/li&gt;
  &lt;li&gt;Give the VM an appropriate amount of storage space (for small projects, the default amount is usually fine).&lt;/li&gt;
  &lt;li&gt;Set the name to whatever you want, then, under &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Network selection&lt;/code&gt;, choose &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;Host device [name]: macvtap&lt;/code&gt;, and make sure the source mode is set to Bridge.&lt;/li&gt;
&lt;/ol&gt;

&lt;p&gt;Now proceed through the OS installation like you normally would. Once it’s finished, you’ll be able to run commands through the virt-manager window, but you won’t be able to connect using normal methods (SSH). To do that, you’ll need to give the VM a serial console so it accepts connections. Using your virt-manager window, run these commands in the guest:&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;                                 &lt;span class=&quot;c&quot;&gt;# ↓ capital s, not number 5&lt;/span&gt;
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;systemctl &lt;span class=&quot;nb&quot;&gt;enable &lt;/span&gt;serial-getty@ttyS0.service
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;systemctl start serial-getty@ttyS0.service
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;You’ll now be able to connect to the VM using SSH or the &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;virsh&lt;/code&gt; command on the host, like this:&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;virsh console my_vm_name
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;h2 id=&quot;update-april-14-2020&quot;&gt;&lt;em&gt;Update April 14, 2020&lt;/em&gt;&lt;/h2&gt;

&lt;p&gt;The default &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;macvtap&lt;/code&gt; interface doesn’t allow host-guest communication through the network. The solution is to create a &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;macvlan&lt;/code&gt; interface for the host to use by default. That can be done using these commands (assuming your physical interface is called &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;eno1&lt;/code&gt;, your default gateway is at 192.168.1.1, and you want your KVM host to have the ip address 192.168.1.100):&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip &lt;span class=&quot;nb&quot;&gt;link &lt;/span&gt;add &lt;span class=&quot;nb&quot;&gt;link &lt;/span&gt;eno1 macvlan0 &lt;span class=&quot;nb&quot;&gt;type &lt;/span&gt;macvlan mode bridge
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip addr show dev macvlan0
XX: macvlan0@eno1: &amp;lt;BROADCAST,MULTICAST&amp;gt; &lt;span class=&quot;o&quot;&gt;[&lt;/span&gt;...]
    &lt;span class=&quot;nb&quot;&gt;link&lt;/span&gt;/ether &amp;lt;MAC address&amp;gt; brd ff:ff:ff:ff:ff:ff
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip &lt;span class=&quot;nb&quot;&gt;link &lt;/span&gt;add &lt;span class=&quot;nb&quot;&gt;link &lt;/span&gt;eno1 address &amp;lt;MAC&amp;gt; macvlan0 &lt;span class=&quot;nb&quot;&gt;type &lt;/span&gt;macvlan mode bridge
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip address add 192.168.1.100/24 dev macvlan0
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip &lt;span class=&quot;nb&quot;&gt;link set &lt;/span&gt;dev macvlan0 up
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip route flush dev eno1
&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;ip route add default via 192.168.1.1 dev macvlan0 proto static
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;Sources:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;https://superuser.com/a/368023&lt;/li&gt;
  &lt;li&gt;https://superuser.com/a/1128513&lt;/li&gt;
&lt;/ul&gt;

&lt;h2 id=&quot;conclusion&quot;&gt;Conclusion&lt;/h2&gt;

&lt;p&gt;That’s all it takes to set up KVM on Ubuntu! You can now quickly and easily set up as many VMs as your server can run.&lt;/p&gt;

&lt;h3 id=&quot;references&quot;&gt;References&lt;/h3&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;a href=&quot;https://help.ubuntu.com/community/KVM/Installation&quot;&gt;https://help.ubuntu.com/community/KVM/Installation&lt;/a&gt;&lt;/li&gt;
  &lt;li&gt;&lt;a href=&quot;https://help.ubuntu.com/community/KVM/Access&quot;&gt;https://help.ubuntu.com/community/KVM/Access&lt;/a&gt;&lt;/li&gt;
&lt;/ul&gt;

</description>
        <pubDate>Fri, 16 Feb 2018 00:00:00 -0500</pubDate>
        <link>https://www.zystvan.com//blog/how-to-set-up-kvm-on-a-remote-server.html</link>
        <guid isPermaLink="true">https://www.zystvan.com//blog/how-to-set-up-kvm-on-a-remote-server.html</guid>
      </item>
    
      <item>
        <title>Discovering an XSS Vulnerability</title>
        <description>&lt;p&gt;I recently discovered an XSS vulnerability on a website I occasionally use. They let you edit your biography using a WSYWIG editor, which also means you can edit the raw HTML of the biography. As I was fiddling with it, I noticed that they didn’t allow inline event listeners such as &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;onerror&lt;/code&gt;. That meant that this code:&lt;/p&gt;

&lt;div class=&quot;language-html highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nt&quot;&gt;&amp;lt;img&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;https://fake&quot;&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;onerror=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;alert(&apos;XSS&apos;);&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;got converted to&lt;/p&gt;

&lt;div class=&quot;language-html highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nt&quot;&gt;&amp;lt;img&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;https://fake&quot;&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;eventsnotallowed=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;alert(&apos;XSS&apos;);&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;It’s good that they block JavaScript that way. But did they also strip mixed-case event attributes from tags? Turns out they didn’t. So by randomly capitalizing &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;onerror&lt;/code&gt;, I was able to run any JavaScript code of my choosing&lt;sup id=&quot;fnref:1&quot; role=&quot;doc-noteref&quot;&gt;&lt;a href=&quot;#fn:1&quot; class=&quot;footnote&quot; rel=&quot;footnote&quot;&gt;1&lt;/a&gt;&lt;/sup&gt; on the website by using something like this:&lt;/p&gt;

&lt;div class=&quot;language-html highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nt&quot;&gt;&amp;lt;img&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;src=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;https://fake&quot;&lt;/span&gt; &lt;span class=&quot;na&quot;&gt;oNeRRoR=&lt;/span&gt;&lt;span class=&quot;s&quot;&gt;&quot;alert(&apos;XSS&apos;);&quot;&lt;/span&gt;&lt;span class=&quot;nt&quot;&gt;&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;It felt good to find an XSS vulnerability, submit it to them, and see it be fixed. As an added bonus, I was granted a year of premium membership on the site.&lt;/p&gt;

&lt;div class=&quot;footnotes&quot; role=&quot;doc-endnotes&quot;&gt;
  &lt;ol&gt;
    &lt;li id=&quot;fn:1&quot; role=&quot;doc-endnote&quot;&gt;
      &lt;p&gt;The WSYWIG editor would try to clean up anything it thought was invalid HTML. So, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;oNeRRoR=&quot;document.innerHTML += &apos;&amp;lt;script src=\&apos;...\&apos;&amp;gt;&amp;lt;/script&amp;gt;&apos;;&quot;&lt;/code&gt; resulted in random jumbled HTML. Of course, using &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;innerHTML&lt;/code&gt; isn’t necessary to put a tag at the end of the page, it just makes it slightly easier. &lt;a href=&quot;#fnref:1&quot; class=&quot;reversefootnote&quot; role=&quot;doc-backlink&quot;&gt;&amp;#8617;&lt;/a&gt;&lt;/p&gt;
    &lt;/li&gt;
  &lt;/ol&gt;
&lt;/div&gt;
</description>
        <pubDate>Fri, 08 Sep 2017 00:00:00 -0400</pubDate>
        <link>https://www.zystvan.com//blog/discovering-an-xss-vulnerability.html</link>
        <guid isPermaLink="true">https://www.zystvan.com//blog/discovering-an-xss-vulnerability.html</guid>
      </item>
    
      <item>
        <title>How to Create an Archive of a Website</title>
        <description>&lt;p&gt;Recently, I was asked to archive a website in such a way that the static HTML
files could be browsed with links to scripts, stylesheets, and images 
continuing to work properly. Options such as the &lt;a href=&quot;https://web.archive.org&quot;&gt;Wayback Machine&lt;/a&gt; or
&lt;a href=&quot;https://webrecorder.io&quot;&gt;Webrecorder&lt;/a&gt; required me to manually visit every page I wanted archived,
and weren’t as reliable about getting every resource as I wanted. Eventually, 
I found &lt;a href=&quot;https://www.httrack.com&quot;&gt;HTTRack&lt;/a&gt;, which was perfect for my needs.&lt;/p&gt;

&lt;p&gt;HTTRack offers a command line interface and does a fantastic job of getting 
&lt;em&gt;everything&lt;/em&gt; on a website. I tried running the command with several different
combinations of flags, but found that something like this worked best for my 
needs:&lt;/p&gt;

&lt;div class=&quot;language-bash highlighter-rouge&quot;&gt;&lt;div class=&quot;highlight&quot;&gt;&lt;pre class=&quot;highlight&quot;&gt;&lt;code&gt;&lt;span class=&quot;nv&quot;&gt;$ &lt;/span&gt;httrack https://zystvan.com &lt;span class=&quot;nt&quot;&gt;-O&lt;/span&gt; ./ &lt;span class=&quot;nt&quot;&gt;--mirrorlinks&lt;/span&gt; -%v -&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt; +zystvan.com/&lt;span class=&quot;k&quot;&gt;*&lt;/span&gt;
&lt;/code&gt;&lt;/pre&gt;&lt;/div&gt;&lt;/div&gt;

&lt;p&gt;This command will look through https://zystvan.com, and act upon the flags:&lt;/p&gt;

&lt;ul&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-O&lt;/code&gt; (capital letter O) will output the copy to the current folder, &lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;.&lt;/code&gt;.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;--mirrorlinks&lt;/code&gt; will ensure links between documents continue to work in your
local copy.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-%v&lt;/code&gt; displays filenames as they’re downloaded.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;-*&lt;/code&gt; excludes everything from being downloaded.&lt;/li&gt;
  &lt;li&gt;&lt;code class=&quot;language-plaintext highlighter-rouge&quot;&gt;+zystvan.com/*&lt;/code&gt; overrides our exclude and allows files on zystvan.com to be
downloaded.&lt;/li&gt;
&lt;/ul&gt;

&lt;p&gt;The exclude/include part at the end was necessary to prevent HTTrack from also
archiving any sites linked from the main one, for example seeing a Twitter
profile and then trying to archive the entirety of Twitter. I suspect there 
might be a flag to do the same thing, but haven’t checked.&lt;/p&gt;

&lt;p&gt;Tada! You’ll now have a completely working local copy of the website you
chose to archive.&lt;/p&gt;

</description>
        <pubDate>Sat, 15 Jul 2017 00:00:00 -0400</pubDate>
        <link>https://www.zystvan.com//blog/how-to-create-an-archive-of-a-website.html</link>
        <guid isPermaLink="true">https://www.zystvan.com//blog/how-to-create-an-archive-of-a-website.html</guid>
      </item>
    
  </channel>
</rss>
