Personal Notes-1
This is my first personal note. As the title suggests, this is my own personal note (personal-oriented) to record some knowledge points I encounter in my daily life that need to be recorded.
I think writing it in a blog is better than anywhere else (actually, there is no other place to write). If needed, please read it by yourself.
The content in personal notes is generally fragmented and messy, so please bear with me.
DD Reinstallation
Download Script
wget --no-check-certificate -qO InstallNET.sh 'https://raw.githubusercontent.com/leitbogioro/Tools/master/Linux_reinstall/InstallNET.sh' && chmod a+x InstallNET.sh
For domestic machines:
wget --no-check-certificate -qO InstallNET.sh 'https://gitee.com/mb9e8j2/Tools/raw/master/Linux_reinstall/InstallNET.sh' && chmod a+x InstallNET.sh
Quick Installation
Debian13
bash InstallNET.sh -debian
Ubuntu 22.04
bash InstallNET.sh -ubuntu
CentOS 9 stream
bash InstallNET.sh -centos
Windows 11 Pro for Workstations
bash InstallNET.sh -windows
Windows 10 LTSC
bash InstallNET.sh -windows10
Windows Server 2022
bash InstallNET.sh -windows2022
Windows Server 2012 R2
bash InstallNET.sh -windows2012
Default Configuration
Default username and password:
Linux: root LeitboGi0ro
Windows: Administrator Teddysun.com
Default port:
Linux: 22
Windows: 3389
Setting Hostname in Linux
Modify hostname
nano /etc/hostname
Modify hosts
nano /etc/hosts
Some cloud providers will reset the hosts file upon reboot. You can make the hosts file immutable.
sudo chattr +i /etc/hosts
Restore
sudo chattr -i /etc/hosts
Then reboot.
Setting SSH Keys for Debian/Ubuntu
Generate ED25519 key pair
ssh-keygen -t ed25519
Find the key pair under ~/.ssh/, download it, and delete the file on the server.
Next, fill the public key content into authorized_keys
and set the correct permissions.
nano ~/.ssh/authorized_keys
chmod 700 ~/.ssh
chmod 600 ~/.ssh/authorized_keys
Configure sshd_config
nano /etc/ssh/sshd_config
Ensure PubkeyAuthentication yes
If you want to disable password and only allow key login (recommended)
Find #PasswordAuthentication yes, uncomment it, and change yes to no
Restart SSH
sudo systemctl restart ssh
Locking Root in Debian12
First, switch to root
su -
Enter the root password.
SSH
nano /etc/ssh/sshd_config
Find PermitRootLogin no and change it to PermitRootLogin yes
Sometimes it is PermitRootLogin prohibit-password, which means password login is prohibited. Change it to yes.
Then restart the SSH service.
sudo systemctl restart ssh
GUI
Open gdm-password
nano /etc/pam.d/gdm-password
Comment out the following line and reboot.
auth required pam_succeed_if.so user != root quiet_success
Changing Sources for Debian/Ubuntu
We use the campus network joint mirror sources: Debian, Ubuntu
nano /etc/apt/sources.list
Clear the content inside and replace it with the mirror source.
Older systems like Debian10 might lack some files.
Here, we recommend using Alibaba Cloud mirror sources: Debian, Ubuntu
Note! The Alibaba source is relatively slow (usually around 500KB/s). It is only recommended for Alibaba Cloud servers or systems not supported by university sources (e.g., Debian9 and below).
Switching Debian to Chinese
Check the current system language
locale
LANG should be changed to zh_CN.UTF-8
Enter locales
sudo apt-get update
sudo apt-get install locales
sudo dpkg-reconfigure locales
Find and install zh_CN.UTF-8 in there
Select zh_CN.UTF-8 and install Chinese fonts
sudo update-locale LANG=zh_CN.UTF-8
sudo apt-get install fonts-wqy-zenhei
After rebooting the system, check with locale that it is zh_CN.UTF-8.
Some systems have the issue of locking to "C"
Check if bashrc and profile have locked the language to "C"
nano ~/.bashrc
nano ~/.profile
If there is code that locks to "C", comment it out.
Setting Debian Color Rendering
rm ~/.bashrc
nano ~/.bashrc
# ~/.bashrc: executed by bash(1) for non-login shells.
# see /usr/share/doc/bash/examples/startup-files (in the package bash-doc)
# for examples
# If not running interactively, don't do anything
case $- in
*i*) ;;
*) return;;
esac
# don't put duplicate lines or lines starting with space in the history.
# See bash(1) for more options
HISTCONTROL=ignoreboth
# append to the history file, don't overwrite it
shopt -s histappend
# for setting history length see HISTSIZE and HISTFILESIZE in bash(1)
HISTSIZE=1000
HISTFILESIZE=2000
# check the window size after each command and, if necessary,
# update the values of LINES and COLUMNS.
shopt -s checkwinsize
# If set, the pattern "**" used in a pathname expansion context will
# match all files and zero or more directories and subdirectories.
#shopt -s globstar
# make less more friendly for non-text input files, see lesspipe(1)
#[ -x /usr/bin/lesspipe ] && eval "$(SHELL=/bin/sh lesspipe)"
# set variable identifying the chroot you work in (used in the prompt below)
if [ -z "${debian_chroot:-}" ] && [ -r /etc/debian_chroot ]; then
debian_chroot=$(cat /etc/debian_chroot)
fi
# set a fancy prompt (non-color, unless we know we "want" color)
case "$TERM" in
xterm-color|*-256color) color_prompt=yes;;
esac
# uncomment for a colored prompt, if the terminal has the capability; turned
# off by default to not distract the user: the focus in a terminal window
# should be on the output of commands, not on the prompt
#force_color_prompt=yes
if [ -n "$force_color_prompt" ]; then
if [ -x /usr/bin/tput ] && tput setaf 1 >&/dev/null; then
# We have color support; assume it's compliant with Ecma-48
# (ISO/IEC-6429). (Lack of such support is extremely rare, and such
# a case would tend to support setf rather than setaf.)
color_prompt=yes
else
color_prompt=
fi
fi
if [ "$color_prompt" = yes ]; then
PS1='${debian_chroot:+($debian_chroot)}\[\033[01;32m\]\u@\h\[\033[00m\]:\[\033[01;34m\]\w\[\033[00m\]\$ '
else
PS1='${debian_chroot:+($debian_chroot)}\u@\h:\w\$ '
fi
unset color_prompt force_color_prompt
# If this is an xterm set the title to user@host:dir
case "$TERM" in
xterm*|rxvt*)
PS1="\[\e]0;${debian_chroot:+($debian_chroot)}\u@\h: \w\a\]$PS1"
;;
*)
;;
esac
# enable color support of ls and also add handy aliases
if [ -x /usr/bin/dircolors ]; then
test -r ~/.dircolors && eval "$(dircolors -b ~/.dircolors)" || eval "$(dircolors -b)"
alias ls='ls --color=auto'
#alias dir='dir --color=auto'
#alias vdir='vdir --color=auto'
#alias grep='grep --color=auto'
#alias fgrep='fgrep --color=auto'
#alias egrep='egrep --color=auto'
fi
# colored GCC warnings and errors
#export GCC_COLORS='error=01;31:warning=01;35:note=01;36:caret=01;32:locus=01:quote=01'
# some more ls aliases
#alias ll='ls -l'
#alias la='ls -A'
#alias l='ls -CF'
# Alias definitions.
# You may want to put all your additions into a separate file like
# ~/.bash_aliases, instead of adding them here directly.
# See /usr/share/doc/bash-doc/examples in the bash-doc package.
if [ -f ~/.bash_aliases ]; then
. ~/.bash_aliases
fi
# enable programmable completion features (you don't need to enable
# this, if it's already enabled in /etc/bash.bashrc and /etc/profile
# sources /etc/bash.bashrc).
if ! shopt -oq posix; then
if [ -f /usr/share/bash-completion/bash_completion ]; then
. /usr/share/bash-completion/bash_completion
elif [ -f /etc/bash_completion ]; then
. /etc/bash_completion
fi
fi
Basic UFW Firewall Commands
Install UFW
sudo apt-get update
sudo apt-get install ufw
Add basic rules
sudo ufw allow 22
sudo ufw allow 22/tcp
sudo ufw allow 22/udp
Add source IP rules (Allow access from IPs in the 10.x.x.x segment)
sudo ufw allow from 10.0.0.0/8 to any port 22
sudo ufw allow from 10.0.0.0/8 to any port 22 proto tcp
sudo ufw allow from 10.0.0.0/8 to any port 22 proto udp
Add multiple IP rules (For machines with multiple public IPs)
sudo ufw allow from any to {server IP} port 22
sudo ufw allow proto tcp from any to {server IP} port 22
sudo ufw allow proto udp from any to {server IP} port 22
Enable UFW firewall
sudo ufw enable
View firewall rules
sudo ufw status
Delete firewall rules (View the rule numbers and delete rule number 1)
sudo ufw status numbered
sudo ufw delete 1
Reload firewall
sudo ufw reload
Installing WARP for IPv6-only Servers to Access IPv4 Resources
nano /etc/resolv.conf
Add 2001:67c:2960::64 or 2a00:1098:2b::1
bash <(curl -fsSL git.io/warp.sh) menu
First, install 4. Install WireGuard related components
Then install 5. Automatically configure WARP WireGuard IPv4 network
If the installation reports an error, it might be that iptables is not installed in some LXC containers. Install it and restart.
apt update && apt install -y iptables
systemctl restart wg-quick@wgcf
This note is finished. Next: