Saturday, September 25, 2010

VirtualBox Adventures & Recovering plaintext data from damaged drive

As a network tech, I should always follow the golden rule of backup up data.  I recently attempted resizing a partition (after neglecting this pinnacle of IT) & completed destroyed a PHP web application I had been working on.

The PHP web application was stored in a VM on the host's ext4 partition, and I had managed to destroy both the superblock & journal of the host's filesystem.  After an unsuccessful attempt to restore the superblock from a backup on the drive, I figured the FS to be toast, but couldn't accept that the data had been completely lost.

What I really should've done was taken a DD image from the get-go with the following command:

# dd if=/dev/sda4 of=/media/Storage/Drive_Backup.img

After a bit of research and IRC chat, I was directed toward the following page: http://wiki.yak.net/592.  The script seemed perfect for what I had needed to do.  I knew the destroyed partition had only been 0.1% non-contiguous, so my hope was to completely recover the virtual hard disk image, or at least a repairable copy.
 
To begin, I created a test, dynamically expanding VDI file & opened it within a hex editor:


I could now see that each VDI file began with the string "<<< Sun Virtualbox Disk Image >>>"--the idea was to copy a large amount of data past where the script managed to locate things string, and to chop off the residual data with a hex editor.

I proceeded to test the procedure by placing the small test VDI file on an ext4 drive, searching for the data by reading the drive byte by byte, and copying only a small amount of data (~1mb) past the point where the magic string was found.  The test was successful, though I still doubted I'd be able to recover a usable VDI file.

After a bit of modification to the script posted above (http://wiki.yak.net/592), I was able to successfully pick up around 10 VDI files off my dead drive (arbitrarily sized to 4GB past the magic string).  After a bit of searching through these recovered VDI files, I found the exact file I was looking for.  Unfortunately, my suspicions were confirmed when GRUB was found, but damaged beyond repair.

At this point, after a bit more research (http://www.linux.com/community/blogs/howto-read-a-virtualbox-vm-disk-wout-starting-the-vm.html), I began to realize that all a VDI file did was encapsulate the virtualized file system within VirtualBox metadata.

From here, I scrapped the whole idea of recovering the VDI and went directly for the plain text data off the drive itself.

To search through the drive, I ran the command:

$ grep -ab "php" /dev/sda4 > grepped

 As I knew I was searching for plain text files that began with "php"--the search worked flawlessly.  The "-b" option on grep, also records the decimal memory address where each instance of the string was found.

When the search completed, I had a list of the location of every instance of the "php" tag on the drive.  This was a massive amount of data to sift through, but I managed to find the location (or at least get close to the location) of the important data I needed, by refining the search with the code's filename; for example:


Basically, we can see that a reference to the filename "MY_Controller.php" & a memory address of 391021232450 (decimal).  After heading over to the offset through wxHexEditor, I can see quite clearly that my PHP code is in fact intact:



And it's complete with formatting & indentation :).  From here, I've simply copied & pasted out each file as I found them, though some were not quite as straightforward.

It'll take a lot of hard work & determination to get your files back, so you need to decide whether it's worth it.

Also try out PhotoRec & foremost if you need to recover stuff that isn't plain text.

(I may post a condensed version of this document with only a short summarization of plain text data recovery techniques if anyone actually reads this)

-CJ

Friday, September 24, 2010

Linux Enable Write-Caching On Disk

When booting a VM recently, I received the error message below regarding I/O writecaching & virtual hard disk corruption:


After Googling for a bit, I found that the first thing to check with this error is whether I/O write caching is enabled on the VM.  In my case, it was.

Next, a lot of the posts I was reading were stating the corruption was occuring on "ext4" partitions.  I assumed that the write caching was a filesystem option.  I had heard of the disk write cache when working on Windows servers, but never really knew the specifics. 

After a bit more research, I found disk write-caching was actually a drive option that could be set with the hdparm command.  It will improve performance by 10-20%, but can also cause system instability. 

To enable write-caching on the drive, I ran command:

[user@box ~]$ sudo hdparm -W1 /dev/sda
Password:

/dev/sda:
 setting drive write-caching to 1 (on)
 write-caching =  1 (on)


And rebooted the machine, effectively taking care of the error.

Tuesday, August 10, 2010

Exchange 2007 Offline Address Book 0x80070422

If you're getting frustrated by Outlook 2007 clients receiving error 0x80070422 when trying to Send/Receive the Offline Address Book, the first thing to check is your Exchange 2007 service URL's.

The quickest way to test this from the client end would be to hold CTRL & right click your Outlook 2007 Icon.  Choose the option "Test E-mail Autoconfiguration..."


This will open up a new window (see below).  In this window, uncheck the options "Use Guessmart" & "Secure Guessmart Authentication."  Enter your password & hit "Test."

If your AutoConfiguration test completes successfully, then you're probably wondering why you're still receiving error 0x80070422.  If your email AutoConfiguration test does not complete successfully, please verify your Exchange 2007 Web Service URL's as per this article.

Once you resolve any issues with email AutoConfiguration, many Outlook 2007 issues will also follow!  A good example would be when you know that your server certificate is valid, yet you're still receiving a security warning similar to:
 Check those service URL's!

Now, the next step to remediating your 0x80070422 error (which is a CLIENT SIDE ERROR), enable the BITS service on the client PC.

Sunday, July 18, 2010

USB Drive Fstab UUID (Arch Linux)

Just had an issue where I could not mount my USB drive at boot time I was getting an error along the lines of UUID=blah not found...I previously had performed the standard "sudo blkid" and received the following output:

[corte@ashbox ~]$ sudo blkid
Password:
/dev/sda1: LABEL="Boot" UUID="3a31d197-0436-4b87-9f06-b03080a3772f" TYPE="ext2"
/dev/sda2: UUID="ea73d633-0f71-43a3-9101-6461f19b1222" TYPE="swap"
/dev/sda3: LABEL="Root" UUID="63b1459a-3ee6-4d7a-9afa-9ad40db800bd" TYPE="ext4"
/dev/sda4: LABEL="Home" UUID="00e59ee8-019b-4ad2-9171-e8501a1022c3" TYPE="ext4"
/dev/sdb1: LABEL="Elements" UUID="7da36762-56c3-471d-bfa1-5b4895bfa0d7" TYPE="xfs" 

Noting the UUID of my external USB drive (Elements), I added the following line into my fstab file:

UUID=7da36762-56c3-471d-bfa1-5b4895bfa0d7 /media/Elements auto defaults 0 0

 Everything went dandy with a "mount -a" yet at the next reboot, I received an error stating that the device with the UUID 7da..could not be found.  A bit of research lead me to the solution...
Including "usb" before "filesystems" in the hooks section of your /etc/mkinitcpio.conf file:

 HOOKS="base udev autodetect pata scsi sata usb filesystems v86d"

Regenerate your mkinitcpio file with: 


sudo mkinitcpio -g kernel26.img

Then be sure to make a backup of your old /boot/kernel26.img

sudo mv /boot/kernel26.img /boot/kernel26.img.bak

Finally, copy your new kernel26.img to /boot.

cp kernel26.img /boot/kernel26.img 

Now reboot and your external drive should be mounted automatically with no issues.

Friday, June 18, 2010

Completely Unrelated...

Completely unrelated to the song, but quite a dope ass song:

1773 - Broken Star

Broken star,
I see you from afar,
With your upper torso pressed up against the passenger side of a car,
Attention directed towards some cat,
Pullin' over in the Cadalliac,
Cause he noticed your back was fat,
But the fact is your attempts are to supplement what you lack,
Trapped into believing what some stranger had promised you,
Mainpulating, stating, that this ain't nothing that you gotta do,
Conning you before you know he turns to you and speak,
Don't worry it's just gonna be,
Herpes you and me,
Now disease and the sea symoblize your promiscuity,

I knew a similar star that was already broken,
I'm speakin' on something that you already knowing,
Traveling all roads,
That long have been chosen by a man who control,
Her mind and her soul,
Always treated her cold, and always needed to know, where she would be,
And what time she was there 'til,
If he thought she was lyin',
He would give her a black bruise,
As a youngin',
She was always a tad lewd,
The story of her life,
Struggle to survive but barely staying alive,
Wanting to end the strife,

[Chorus]
Broken star,
Can't you see that you are falling oh so fast?
This won't last
She was a broken star and couldn't travel far,
Broken star,
Can't you see that you are falling oh so fast?
This won't last,
She was a broken star and couldn't travel far,

This broken star was constantly filled with pain,
No one was able to see, the tears in her name,
She was a slave, to the fear, that had claimed her life for so long what else can go wrong,
She could hardly hold on,
She said his grip was so strong,
And she couldn't break free,
And she get loose,
His hands, tied around, her neck like a noose,
She was tired of it, and wanted something new but didn't know where to start,
Alone in her heart,
Wanting to get far was the state of this star,

Mentally damaged with emotions to manage,
Physically famished to the point your lists have anything that's handed,
Branded by beasts who won't deny,
What they demanded and that seed that's implanted suddenly forced to vanish,
Created by a stranger and we didn't plant it,
It's the thought that led you to your decision,
Cause you figured it'd be better of dead than with an infected one to livin',
Given' the circumstances,
You justify your actions,
By saying you were given a corner and forced by back in,
But really it was what you chose that made this happen,

[Chorus]

To get ahead you feel you're doing what you have to do,
But simultaneously spreading what was passed to you,
Back when you were half developing, initiated,
Enabled to count all the times that you been degraded,
Now you feel you kid your soul and you wished you saved it,
Jaded from being so misguided and the world divided,
Thought this was the plan for life but now you wanna revise it,
It be wise you changed before you're old and scarred,
And grow so far from being who you know you are,
Cause you use to shine bright now you're a broken star,

She finally gathered the strength to leave this man,
No longer, will her face come in contact with his hand,
She's starting to realize that she seems to understand,
What it is she has done,
And what she's gotta do,
Now she sees the sun and the sky so blue,
And for the first time in her life, she feels real peace,
Left another man in her life, initials J.C.,
He heard her cry out when she yelled "save me!"
He came to her rescue and said I will mend you,
No longer broken star, my love now protects you,

[Chorus]

You're a star, you're a star,
So let your light shine,
Cause the nigga's see the light and the light so bright,
Let your light shine,
Cause the nigga's see the light and the light so bright.

Sunday, April 11, 2010

Searching Removable Drives Linux

Had some trouble with something I'd had earlier trouble with in the past.  When using the locate command (even after running updatedb), I was unable to search my removable USB drives.

The solution was to modify the /etc/updatedb.conf file, and remove /media from the prune path:

PRUNE_BIND_MOUNTS="yes"
# PRUNENAMES=".git .bzr .hg .svn"
PRUNEPATHS="/tmp /var/spool /media"
PRUNEFS="NFS nfs nfs4 rpc_pipefs afs binfmt_misc proc smbfs autofs iso9660 ncpfs coda devpts ftpfs devfs mfs shfs sysfs cifs lustre_lite tmpfs usbfs udf"


Guess this was more a mental note to myself :).

Tuesday, February 16, 2010

Hiding a Window

So I recently set up a VirtualBox VM on my Windows 7 machine so I could access my XFS hard disk through a network share.

Being there's no way to hide a VirualBox VM by default (even by running in headless mode), I went ahead & wrote a quick C# program to hide running windows.

First of all, I created a .bat file to run my VM headless...the contents are as follows:

 cd "C:\Program Files\Sun\VirtualBox"
VBoxHeadless.exe -s Ubuntu             
    

Simple enough?

Here's my error-prone, crappy window hiding app:

MD5: B53BF803244C53C92E9447597BF6AA9F
http://www.megaupload.com/?d=XTTQMSG1

If it crashes your system, doesn't work, etc.......too bad! :)

Tuesday, December 1, 2009

HTTP Traffic Blocked (Windows XP)

Yesterday, I got some work fixing a PC that was loaded with Trojans.  After a repair installation of XP Pro w/SP2, I was brought to the activation window which could not hit the internet.

Thinking the problem was a driver issue, I quickly pulled the Windows key + U trick to pull up an explorer window.  Finding the drivers were intact, I proceeded to both ping 4.2.2.2 & google.com, as well as nslookup google.com.  Both were successful.

I opened an IE window, checked the proxy settings, reset all the settings, etc...still could not browse--was getting the error "Internet Explorer can not open the search page." & a page cannot be displayed error.

Thinking the trojan was still impacting IE, I installed Firefox from a flash drive, and ended up with the same result.

I next attempted to telnet to port 80 & 8080 on a number of web sites.  All HTTP traffic was blocked.

After a few more hours of struggling & research, I realized the culprit:

Norton Internet Security Version 2006 (Symantec).

A run of the Norton Removal Tool (http://service1.symantec.com/Support/tsgeninfo.nsf/docid/2005033108162039) & reboot, and the issue was resolved.

Thursday, November 26, 2009

Terminal Services Event ID 6037

I recently struggled with this one for work, after I made a change to IIS on our terminal server (Server 2008 Standard).  I could not launch TS RemoteApps, as credentials were being consistently rejected, though correct.  The only error I could find in the event log was along these lines:

Log Name: System
Source: LsaSrv
Date: 10/27/2008 10:46:40 PM
Event ID: 6037
Task Category: None
Level: Warning
Keywords: Classic
User: N/A
Computer: Gateway
Description:
The program lsass.exe, with the assigned process ID 572, could not authenticate locally by using the target name TERMSERV/ts.xxxx.com. The target name used is not valid. A target name should refer to one of the local computer names, for example, the DNS host name.


This error may also contain address "HTTP/ts.xxxx.com"

Thanks to Chad A. Gross on the http://www.vistax64.com forums, I was pointed at a blog with a solution: http://blogs.technet.com/sbs/archive/2009/05/07/event-2436-for-sharepoint-services-3-search.aspx.

Though the blog states a solution for a different problem, it worked just as well for me:

Click Start, click Run, type regedit, and then click OK.
In Registry Editor, locate and then click the following registry key:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\Lsa\MSV1_0
Right-click MSV1_0, point to New, and then click Multi-String Value.
Type BackConnectionHostNames, and then press ENTER.
Right-click BackConnectionHostNames, and then click Modify.
In the Value data box, type the URL mentioned in the above warning event, and then click OK.
Quit Registry Editor, and then restart the IIS service.


For good measure, I restarted the server and bam, the error was gone.

Monday, October 19, 2009

Installing .TTF Fonts in Slackware 12.2

I was recently working on a project for my boss when I found I needed to install some new fonts for GIMP.

I had downloaded some free TTF's from http://www.1001freefonts.com/ & needed to install them.

Restarting X was a pain, so I found the following steps worked with only restarting GIMP:

1.)  Move your fonts into the ~/.fonts folder.  Create it if it doesn't exist.
2.)  Run command makefontdir
3.)  Run command makefontscale
4.)  Run command fc-cache
5.)  Finally, command xset fp rehash
6.)  Restart whatever application you're working with, be it GIMP, OOo, or whatever.

Your font should now be listed!