Skip to content

Instantly share code, notes, and snippets.

#!/bin/bash
#set -x
function die {
echo "ERROR: $*";
exit 1
}
usage_info="Usage: $0 ca_dir
#!/bin/bash
#set -x
function die {
echo "ERROR: $*";
exit 1
}
usage_info="Usage: $0 ca_dir client|server certificate_name
@selivan
selivan / music.yandex.ru userstyle
Last active August 11, 2018 14:15
Userstyle for music.yandex.ru - remove all shit but leave side ads. Use with https://github.com/openstyles/stylus/
@-moz-document domain("music.yandex.ru") {
.bar-below_plus {
position: absolute !important;
z-index: -100;
}
.ads-block{
display: none !important;
}
.d-overhead{
position: absolute !important;
@selivan
selivan / rsyslog.conf
Last active August 12, 2022 22:10
config for rsyslog/rsyslog issue 2899
# Default logging rules can be found in /etc/rsyslog.d/50-default.conf
#################
#### MODULES ####
#################
module(load="imuxsock") # provides support for local system logging
module(load="imklog" PermitNonKernelFacility="on") # provides kernel logging support
#module(load="immark") # provides --MARK-- message capability
module(load="omrelp") # provides support for RELP protocol
@selivan
selivan / letsencrypt-update.sh
Created June 11, 2018 13:54
Letsencrypt update certs using webroot
#!/bin/bash
DOMAINS=example.net
WEBROOT=/var/www/html
iptables -A INPUT -p tcp --dport 80 -j ACCEPT
certbot certonly --webroot --webroot-path "$WEBROOT" --register-unsafely-without-email -d "$DOMAINS"
iptables -D INPUT -p tcp --dport 80 -j ACCEPT
apache2ctl graceful
#!/usr/bin/env python3
"""
Import XML configuration files using Zabbix API:
https://www.zabbix.com/documentation/3.4/manual/api/reference/configuration/import
"""
import argparse
from urllib import request
import json
import sys
from pprint import pformat
@selivan
selivan / OCSP-generate.sh
Last active February 17, 2018 18:58 — forked from denji/OCSP-generate.sh
Priming the OCSP cache in Nginx
#!/bin/sh
ISSUER_CER=$1
SERVER_CER=$2
URL=$(openssl x509 -noout -ocsp_uri -in "$SERVER_CER")
openssl ocsp -noverify -no_nonce -respout ocsp.resp -issuer "$ISSUER_CER" -cert "$SERVER_CER" -url "$URL"
# Where “ocsp.resp” is whatever file you have configured in Nginx for the “ssl_stapling_file“.
@selivan
selivan / my-ublock-filters.txt
Last active February 11, 2018 13:00
Additional filters for uBlock
! https://adblockplus.org/en/filter-cheatsheet
! https://github.com/gorhill/uBlock/wiki/Static-filter-syntax
! Some shit from Yandex.Market Sovetnik
! Block everywhere except Yandex.Market
||yastatic.net/sovetnik/_/js/*$script
@@||yastatic.net/sovetnik/_/js/*$script,domain=market.yandex.com,market.yandex.ua,market.yandex.ru
# Firejail profile for skypeforlinux
# This file is overwritten after every install/update
# Persistent local customizations
include /etc/firejail/skypeforlinux.local
# Persistent global definitions
include /etc/firejail/globals.local
ignore private-dev
whitelist /dev/dri
whitelist /dev/full
@selivan
selivan / gist:926479e48c799cb4b7a37eb741af6c12
Last active January 19, 2018 17:36
Files in /dev used by skypeforlinux with firejail 0.9.52
open("/dev/null", O_RDONLY) = 0
open("/dev/urandom", O_RDONLY) = 3
open("/dev/urandom", O_RDONLY) = 3
open("/sys/devices/system/cpu/cpu0/tsc_freq_khz", O_RDONLY) = -1 ENOENT (No such file or directory)
open("/sys/devices/system/cpu/cpu0/cpufreq/cpuinfo_max_freq", O_RDONLY) = 4
open("/sys/devices/system/cpu", O_RDONLY|O_NONBLOCK|O_DIRECTORY|O_CLOEXEC) = 14
[pid 17] open("/dev/null", O_RDONLY) = 20
[pid 17] open("/dev/urandom", O_RDONLY) = 5
[pid 17] open("/dev/urandom", O_RDONLY) = 5
[pid 17] open("/sys/devices/system/cpu/cpu0/tsc_freq_khz", O_RDONLY) = -1 ENOENT (No such file or directory)