Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.
Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.
Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.
Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.
Go to Blogger edit html and find these sentences.Now replace these sentences with your own descriptions.This theme is Bloggerized by Lasantha Bandara - Premiumbloggertemplates.com.
WikiLeaks has been experiencing some issues lately ranging from having its Web hosting services shutdown to having its accounts frozen and the flow of money cut off. Some cheer those actions, while others see them as an attack on liberty and free speech and are coming to WikiLeaks' defense.
WikiLeaks is no stranger to controversy. Exposing confidential government documents and communications evokes a passionate response--either for or against the activity. The WikiLeaks site has been the target of DDoS (distributed denial of service) attacks--either by government agencies that don't want sensitive information exposed, or by activist groups that believe WikiLeaks is a threat to international diplomacy and national security.
However, there are also hacktivists--a mashup of hackers and activists--who are willing to cross some lines to defend WikiLeaks as well. The Swiss bank that froze WikiLeaks founder Julian Assange's assets, and PayPal--which cut off the WikiLeaks account used for collecting donations to fund the site--have both been targeted by DDoS attacks of their own.
Noa Bar Yossef, senior security strategist for Imperva, commented via e-mail to say, "Operation Payback's goal is not hacking for profit. In the classical external hacker case we see hackers grab information from wherever they can and monetize on it. In this case though, the hackers' goal is to cripple a service, disrupt services, protest their cause and cause humiliation. In fact, what we see here is a very focused attack - knocking the servers offline due to so-called 'hacker injustice'."
Botnets and DDoS attacks are not new. Botnets are exceedingly common. Typically, PCs of unwitting users are compromised in stealth and sit idly waiting for instructions from the attackers. A botnet can harness thousands, tens of thousands, or possibly hundreds of thousands of compromised PCs at one time to mount massive spam distribution or denial of service attacks.
The WikiLeaks defense is a different story, though. Noa Bar Yossef explains, "In this case however, the Operation Payback is recruiting people from within their own network. They are actually asking supporters to download the piece of code, the DDoSing malware itself, that upon wake-up call the computer engages in the DoS. There is no victimized machine as the participants knowingly engage in what they call an act of defiance."
In other words, rather than simply harnessing the combined power of infected machines without the PC owner's knowledge or consent, the Operation Payback hacktivist botnet is actively seeking volunteers to willingly join the botnet and assist in the effort to make organizations pay for trying to silence WikiLeaks.
WikiLeaks walks a very thin line between paragon of freedom of speech and threat to national security. Even if you have strong opinions one way or the other about Wikileaks, I don't recommend volunteering to compromise your PC in support of any hacktivist efforts. You can't be sure that is all the malware is doing, and you might not be able to control or remove the botnet code once your hacktivism days are over.
The Internet vigilante group Anonymous has been thrust into the spotlight this week as the WikiLeaks story continues to erupt like a media volcano. So like any group at center of a story would do, Anonymous has put out (yes) a press release outlining the motivations behind the attacks on PayPal, Mastercard and Visa and implying a change in strategy after attacks on Amazon never materialized.
“We do not want to steal your personal information or credit card numbers. We also do not seek to attack critical infrastructure of companies such as Mastercard, Visa, PayPal or Amazon. Our current goal is to raise awareness about WikiLeaks and the underhanded methods employed by the above companies to impair WikiLeaks’ ability to function.”
Thus far Operation Payback has orchestrated DDoS attacks on the corporate sites of companies deemed enemies of WikiLeaks after it started releasing thousands of diplomatic cables over Thanksgiving weekend.
The Anonymous hacktivist group behind Operation Payback had its main Twitter account and Facebook pages taken away on Wednesday and has since the been decentralized in its social media efforts. This however didn’t stop one of the splinter accounts from tweeting out the below release, stating that the group essentially did not want to injure the companies targeted, but in fact wanted to “raise awareness.”
“While it is indeed possible that Anonymous may not have been able to take Amazon.com down in aDDoS attack, this is not the only reason the attack never occured. After the attack was so advertised in the media, we felt that it would affect people such as consumers in a negative way and make them feel threatened by Anonymous. Simply put, attacking a major online retailer when people are buying presents for their loved ones, would be in bad taste. The continuing attacks on PayPal are already tested and preferable: while not damaging their ability to process payments, they are successful in slowing their network down just enough for people tonotice and thus, we achieve our goal of raising awareness.”
While the logic here is inconsistent (don’t people also use Paypal and Mastercard to buy presents for their loved ones?) the release hints at a kinder gentler Anonymous afraid of (yes) bad press. If so that would explain this further evidence of a more positive pivot, a mission statement asking group members to cull the most interesting parts of the WikiLeaks cables and republish — An action which, granted, does spread more awareness than the firing of a LOIC cannon.
Gathering evidence on Facebook has become standard legal practice, so a social sting operation was bound to happen. That’s how the Federal Bureau of Investigation caught a would-be terrorist in Baltimore.
An FBI informer made the initial contact with 21-year-old Antonio Martinez after he posted publicly on Facebook about his desire for jihad earlier this fall, according to AFP.
AFP cited a prepared statement by the U.S. Justice Department:
An affidavit filed in support of the criminal complaint alleges that on September 29, 2010, Martinez publicly posted on his Facebook account a statement calling for violence to stop the oppression of Muslims, and that on Oct. 1, 2010, he publicly posted a message stating that he hates any person who opposes Allah and his prophet.
The FBI set Martinez up with a fake car bomb, and then apprehended him when he was about to set it off remotely. He’d rigged the faux explosive in a vehicle parked just outside of a U.S. military recruitment office in a suburban Maryland shopping mall.
Martinez was charged with attempting to murder federal officers and employees, along with the attempted use of a weapon of mass destruction on government property. He faces possible life in prison for these charges, and is being held in custody until a court hearing scheduled for Monday.
The timing of all this — officials were able to nab this suspect within six weeks of his jihad-seeking post on Facebook — appears brisk compared to the pace of other sting operations. The case may set an example for future continued use of the social network for stings.
Readers, what do you think about the advent of sting operations on Facebook? What effect might this have on the community?.
Dutch authorities said today that they have arrested a 16-year-old hacker involved in the pro-WikiLeaks attacks on the Web sites of MasterCard and PayPal.
The Dutch National Prosecutors Office said that the teen, who was not named, was arrested by a high-tech crime team last night.
The arrest comes after a group known as Anonymous--a label that's been adopted before by activists who have electronically assaulted the Church of Scientology and the Australian government--organized attacks on Web sites of companies that have distanced themselves from WikiLeaks. Distributed denial-of-service attacks enlist thousands of computers, all making simultaneous connections, in hopes of overwhelming a target.
Visa.com was taken offline briefly yesterday afternoon, though the company told CNET that no payments or transactions were affected. MasterCard.com was unreachable yesterday morning. A Web site for the Swedish prosecution agency, which is trying to extradite WikiLeaks editor Julian Assange on sexual assault allegations, has been targeted too.
Amazon.com was attacked today, but unlike Anonymous' other victims, it has a massive server infrastructure that can bring additional capacity online instantly. That famously robust system proved able to fend off what's being called Operation Payback.
"We have changed our target--the Hive isn't big enough to attack Amazon," AnonOpsNet announced through Twitter. The new target: PayPal's Web-based system for processing payments.
It's unclear how successful those efforts were. A third-party monitoring service operated by WatchMouse.com reports that PayPal was experiencing significant problems in Japan, South Africa, and Germany, but not in the United States or most of Western Europe. The api.paypal.com Web site, however, was inaccessible from CNET's newsroom this afternoon.
Also today:
• Attorney General Eric Holder says the Feds are investigating the pro-WikiLeaks attacks. "We are aware of the incidents," Holder said in Washington today, Bloomberg reports. "We are looking into them." No word on whether the U.S. Department of Justice is looking into the attacks on WikiLeaks itself.
• An article in WalesOnline.co.uk says that alleged WikiLeaks source Bradley Manning, the former Welsh schoolboy who's now facing criminal charges, was barred from receiving visitors. "His family, including his mum Susan who suffers ill health after a series of strokes, is understood to have flown out from Wales to the U.S. to visit him. However, despite their trip, it is understood the request to visit the 23-year-old soldier, who is being held in solitary confinement, was turned down."
• In a very democratic fashion, Anonymous appears to be holding a poll to determine who should be attacked now. The U.S. Senate--that is, senate.gov--is currently in the lead.
• Russian autocrat Vladimir Putin is taking up the cause of WikiLeaks and Assange. "Why was Mr. Assange hidden in jail? Is that democracy? As we say in the village: the pot is calling the kettle black," Putin said.
• Edge.org has a solid collection of essays addressing these questions: "When does my right to privacy trump your need for security? Should a democratic government be allowed to practice secret diplomacy? Would we rather live in a world with guaranteed privacy or a world in which there are no secrets? If the answer is somewhere in between, how do we draw the line?"
• One reason why Anonymous' attack on Amazon.com didn't fare so well: The online retailer's "European datacenter, which formerly hosted the WikiLeaks Web site, accounts for more than a third of all Internet-facing Web servers in Ireland." That's from Netcraft.
• The American Conservative magazine published an article making the conservative case for WikiLeaks. Excerpt: "Conservatives should prefer an explosion of whistle-blower groups like WikiLeaks to a federal government powerful enough to take them down."
• Amazon.co.uk previously sold (for about 7 British pounds) a Kindle book titled "WikiLeaks documents expose US foreign policy conspiracies." The Web page is now offline, but here's Google's cached version.
In order to make it impossible to ever fully remove Wikileaks from the Internet, we need your help.
if you have a unix-based server which is hosting a website on the Internet and you want to give wikileaks some of your hosting resources, you can help!
Please follow the following instructions:
* Setup an account where we can upload files using RSYNC+SSH (preferred) or FTP
* Put our SSH key in this server or create an FTP account
* Create a virtual host in your web server, which, for example, can be wikileaks.yourdomain.com
* send the IP address of your server to us, and the path where we should upload the content. (just fill the form below)
We will take care of all the rest: Sending pages to your server, updating them each time data is released, maintaining a list of such mirrors. If your server is down or if the account don't work anymore, we will automatically remove your server from the list.
Our content is only html/css/javascript/png static files, so we don't require much resource to host it.
The complete website should not take more than a couple of GB at the moment (with base website and cablegate data)
To add your mirror to the list, please download the SSH key you will find below, then fill the following form to add your website to our mirror list :
Form
Halo selamat malam berikut adalah hidangan malam ini dari saya.
Wikileaks memang sedang controversi tetapi apakah semuanya
benar saya rasa itu anda yang menilai.Terus terang saja semua ini
entah rekayasa atau bukan tetep menarik untuk di ikuti.
sayang belum ada yang dari jakarta yang katanya ada 3% wo mari
kita lihat sejauh mana paman sam memegang kartu as di seluruh dunia
termasuk indonesia.nantikan kabar berikutnya .Thanks salam sesat.
Hai coming againt with some linux slackware hehehehe ,well let make the slacky rock
firs make a new file in directory /etc/sysctl.conf and then copy the code to your file.
this the source:
# increase TCP max buffer size setable using setsockopt()
net.core.rmem_max = 16777216
net.core.wmem_max = 16777216
# increase Linux autotuning TCP buffer limits
# min, default, and max number of bytes to use
# set max to at least 4MB, or higher if you use very high BDP paths
net.ipv4.tcp_rmem = 4096 87380 16777216
net.ipv4.tcp_wmem = 4096 65536 16777216
# don’t cache ssthresh from previous connection
net.ipv4.tcp_no_metrics_save = 1
net.ipv4.tcp_moderate_rcvbuf = 1
# recommended to increase this for 1000 BT or higher net.core.netdev_max_backlog = 30000
# Turn off timestamps if you’re on a gigabit or very busy network
# Having it off is one less thing the IP stack needs to work on
#net.ipv4.tcp_timestamps = 0
# disable tcp selective acknowledgements.
net.ipv4.tcp_sack = 0
#enable window scaling
net.ipv4.tcp_window_scaling = 1
Yups and then save.Ok and your next job make this always running after reboot hheehe
and what for this file?. Try in your slacky and happy browsing.If you something trouble post in coment or send e-mail to localdisaster@gmail.com. Thanks all .
Hardening The Linux Kernel With Grsecurity (debian base)
Security is based on three characteristics: prevention, protection and detection. Grsecurity is a patch for Linux kernel that allows you to increase each of these points.
This howto was performed on a Debian Lenny system. Thus some tools are Debian specific. However, tasks can be performed with other distro specific tools or even with universal tools (make).
Everything will done with root privileges. However, you can perform them with a limited account thanks to sudo and fake-kpkg tools. 1. Preliminary Note
To compile the kernel, you need to install some specific packages:
If you like to configure your kernel in graphical console mode (make menuconfig), you must install one more package:
rom1:/root# aptitude install libncurses5-dev
Check that iniramfs-tools (used to generated the init ramdisk) is installed (it should be):
rom1:/usr/src# dpkg -l initramfs*
Desired=Unknown/Install/Remove/Purge/Hold
| Status=Not/Installed/Config-files/Unpacked/Failed-config/Half-installed
|/ Err?=(none)/Hold/Reinst-required/X=both-problems (Status,Err: uppercase=bad)
||/ Name Version Description
+++-==============-==============-============================================
ii initramfs-tool 0.85i tools for generating an initramfs
rom1:/usr/src#
NB: you may need to configure wget in case you are using an HTTP proxy (which may use authentication). You need to edit /root/.wgetrc so it looks like this:
http_proxy=192.168.0.1
proxy-user=foo # Put this line if you need to authenticate against your proxy
proxy-passwd=bar # Put this line if you need to authenticate against your proxy
Decompress the archive of the kernel:
rom1:/usr/src# tar xzvf linux-2.6.24.5.tar.gz
Create a symbolic link on the new kernel folder to ease the following tasks:
rom1:/usr/src# ln -s linux-2.6.24.5 linux
Now, the environment is ready. Let's go hardening! 2. Patch the vanilla kernel
Move the grsecurity patch to the new directory:
Now the patch is applied and the source of the kernel was modified. Let's configure the kernel to enable Grsecurity. 3. Configure the hardened kernel
In this example, we will configure the kernel using a console menu (make menuconfig). This is why we installed the libncurses5-dev package. However, you can configure in pure console mode (make config), or in GUI mode (make xconfig).
Grsecurity has predefined levels: low, medium, high. It can also be configured in custom level where you choose to enable or not option by option. See http://www.grsecurity.net/confighelp.php/ for more info on each option. In this HowTo, we will configure Grsecurity in High level.
rom1:/usr/src/linux# make menuconfig
Now, we will enable Grsecurity in the menu.
Go to Security options > Grsecurity > tick Grsecurity. Then, you can go to Security Level and tick High.
You can profit from configuring Grsecurity to optimise your kernel. Eg: On your server you probably don't need support for infrared, blutooth, probably neither wifi, ipx, X25, token ring, ATM, firewire, PCcard, joystick, mouse, sound.... 4. Compile the hardened kernel
It is now time to compile your hardened kernel. First, just in case, clean up:
rom1:/usr/src/linux# make-kpkg clean
Launch compilation itself (this may take a while depending on your CPU power and RAM availability!!!):
In case you are not using a Debian distro, you can compile the classic way with:
make mrproper
make menuconfig
make clean
make
make modules_install
mkinitramfs
make install 5. Install the hardened kernel
Your new kernel is now compiled and a .deb package file has been generated in the /usr/src folder. You need to install your kernel as any .deb package:
During the installation, an initrd image will be generated. This may take a while depending on your CPU power and RAM availability! You may also check that the new kernel image is really a kernel !
rom1:/usr/src# file vmlinuz-2.6.24.5-grsec
vmlinuz-2.6.24.5-grsec: Linux kernel x86 boot executable RO-rootFS, root_dev 0x801, swap_dev 0x1, Normal VGA
It is now time to restart your system with your new hardened kernel:
rom1:/usr/src/linux# shutdown -r now
Now that your system has restarted, you can check that your new kernel is running:
rom1:~# uname -r
2.6.24.5-grsec. 6. Testing the hardened kernel
Except the fact that uname -r is saying your kernel is a grsec one, how do you know you are running a hardened kernel ? This is where we will use paxtest which will simulate an attack on the kernel and show if you are vulnerable or not. Download paxtest:
rom1:/tmp# tar xzvf paxtest-0.9.7-pre5.tar.gz
rom1:/tmp# cd paxtest-0.9.7-pre5
Compile it (type make to have the list of targets):
rom1:/tmp/paxtest-0.9.7-pre5# make generic
Run it (there are 2 differents modes: kiddie and blackhat):
rom1:/tmp/paxtest-0.9.7-pre5# ./paxtest kiddie
NB: unless you are using high grsecurity level or custom level, you will have a vulnerable kernel. Indeed, you are only getting userland ASLR protection in a medium mode.
NTP atau Network Time Protocol di Debian itu cara settingnya kira-kira begini:
(Dari Command Prompt / Terminal Console)
1. Install NTP Server nya: apt-get install ntp ntpdate ntp-server
(Kalau mau pakai aptitude sebagai pengganti apt-get juga boleh)
2. Ubah konfigurasi NTP server nya: nano /etc/ntp.conf
2.a. Pada baris "server ..." buat baris baru yang isinya "server id.pool.ntp.org" dan remark (beri awalan #) atau hapus baris "server ..." lainnya. Ini supaya sinkronisasi time nya ke lokasi server Indonesia saja.
2.b. Tambahkan baris "restrict a.b.c.d mask 255.255.255.0 nomodify notrap" dimana a.b.c.d adalah network IP anda (misalnya 192.168.1.0). Ini gunanya untuk memperbolehkan IP di jaringan anda untuk mengakses NTP Server anda. Kalau tidak mau repot, bisa menggunakan "restrict 0.0.0.0 mask 0.0.0.0 nomodify notrap" untuk memperbolehkan semua IP.
2.c. Save file nya, dan exit
3. Sinkronisasikan NTP Server anda ke NTP Server induk: ntpdate id.pool.ntp.org
4. Restart NTP Server nya: /etc/init.d/ntp restart
Sudah selesai deh konfigurasi NTP Server di Debian.
Untuk memastikan bahwa NTP nya sudah sinkron, bisa gunakan perintah: ntpq -d
Building an embedded Linux system emulator
by Gilad Ben-Yossef
One of the hallmarks of embedded system programming is working with specialized hardware. Unfortunately, embedded system developers do not always have the luxury to develop and test their code on the actual hardware they target. Often, the hardware is developed in tandem with the system software and therefore it it is not available for much of the embedded system software development cycle.
While one can develop and test much of our code on a PC running Linux, such a PC is a very different environment from the target board. More often then not, the target board is not even of the same architecture as the PC. A solution to this problem can be obtained by using an emulator - a software tool that executes software code of our target platform in a virtual machine that is running on our development host, and running our system software in it.
The following article describes how to build an embedded Linux system running inside an emulator which can be used to develop, test and debug target code even without access to target hardware.
The components
To build our emulator we will need the following components:
Hardware emulator (we'll use Qemu)
Minimal Linux root file system containing a C library and Busybox
Created by Fabrice Ballard, Qemu is an open source machine emulator supporting seven target architectures, including x86, MIPS, ARM, and PowerPC. As first step, we will download and install the emulator. Depending on the Linux distribution you use on your workstation, you might be able to use the native package management system of the distribution to do so.
For Debian, Ubuntu and derivatives:
$ sudo apt-get install qemu
For Fedora and derivatives (as root):
# yum install qemu
For other distributions lacking a Qemu package, or for those wishing to obtain the very latest package (note that the "i386" label refers to the host running the emulator, and not the target platform):
$ wget http://bellard.org/qemu/qemu-0.9.1-i386.tar.gz
$ cd /
$ sudo tar zxvf qemu-0.9.1-i386.tar.gz
Or, as root:
# tar zxvf qemu-0.9.1-i386.tar.gz
Alternatively, you can download the sources and build the emulator from scratch. This has the added advantage that you can later adapt the emulator to more accurately reflect your actual hardware:
$ wget http://bellard.org/qemu/qemu-0.9.1.tar.gz
$ tar zxvf qemu-0.9.1.tar.gz
$ cd qemu-0.9.1/
$ ./configure
$ make
$ sudo make install
Or, as root:
# make install
Kernel and file system images
The Qemu emulator we have just installed provides a virtual machine mimicking our target hardware. To actually get Linux running on this virtual machine, however, we will need to download an image of the Linux kernel and a suitable root file system image for our target architecture.
Luckily, the Qemu project provides test images for several architectures that can be used to get a fast start with Qemu as an embedded Linux system emulator. Go to the Qemu project download page and choose one of the Qemu test disk images suitable for your embedded platform and download it to your Linux host (in this example we use ARM):
Start up Qemu with the following command line, adjusting the architecture name, kernel file name, and root file system image name according to your specific architecture (again, we use ARM in this example):
The above command line starts Qemu in system emulation mode, booting into the kernel image zImage.integrator while loading into the virtual machine RAM the arm_root.img file system, and instructing Qemu to make your entire host root file system available for access via TFTP from the emulated machine (more on this ahead).
You should now be seeing a window similar to the following in which the emulated LCD display of the board is shown:
Qemu screenshot
(Click to enlarge)
You can log-in with the user "root" -- no password is required.
Transferring files to and from the host
The emulator and file system are set up to automatically configure a virtual Ethernet interface in the virtual machine with an internal IP. Through that virtual network interface, the emulator is set up to enable transferring of files to and from the host machine file system using the TFTP protocol.
For example, the following command will copy the file "/home/gby/hello_emu" from the host file system to the current directory inside the emulator:
In addition, you can use the "wget" comment to transfer files using the FTP and HTTP protocol to the emulator from any compatible server accessible in the network:
$ wget http://codefidence.com/some/file
Qemu supports numerous other way to interact with the host and it's environment, including bridged virtual network interfaces (as opposed to the default NAT used in the example above). Bridged virtual network interfaces enable:
Using NFS to communicate with the host
Remote debugging from the host
VLAN support
Exposing the host file system as a FAT file system
Mounting disk, flash, or CDROM images from the host file system
Using USB devices connected to the host
For more information on these advanced options, please refer to the Qemu user manual.
Debugging user applications
Using the GNU debugger GDBserver agent, we can debug applications running inside the emulator using the GDB debugger on the host. To do this, first use one of the methods outlined above to copy the "gdbserver" executable to the emulator. Note that you will need a gdbserver executable that was built to run on the target architecture (such as ARM, in the example above), and not on that of the host!
Also note that since the test images do not contain debugging symbols for the system libraries, you will only be able to debug statically compiled applications using them. This limitation can be removed by building your own kernel and file system image (see below for more information on this topic).
Next, assign the gdbserver binary execute permissions:
$ chmod u+x gdbserver
Now, run the gdbserver agent, instructing it to use port 9999 (which we previously redirected to the emulator, when we launched qemu-system-arm from the command-line) to listen for connections from the debugger:
$ gdbserver 0.0.0.0:9999 /bin/myprog
Or, if you wish to attach to an already running program, use:
$ gdbserver 0.0.0.0:9999 --attach 1234
Finally, run the GDB debugger on your host and instruct it to connect to the host local port 9999:
$ arm-linux-gdb target/bin/myprog
GNU gdb 6.6-debian
Copyright (C) 2006 Free Software Foundation, Inc.
...
(gdb) set solib-absulote-prefix /dev/null
(gdb) set solib-search-path target/lib/
(gdb) target remote 127.0.0.1:9999
Debugging the kernel
Using the Qemu emulator to debug kernel code is quite straight forward, as Qemu incorporates a minimal GDB agent as part of the emulator itself. To debug the Linux kernel running inside the emulator, add the "-s" parameter to the command line used to start Qemu:
Now when the emulator starts, it will wait for a debugger connection on the default port "1234" (or a different port specific with the "-p" option), before proceeding with the boot. Once the emulator has started, you can debug the Linux kernel running inside it, using GDB on the host:
$ arm-linux-gdb linux/vmlinux
GNU gdb 6.6-debian
Copyright (C) 2006 Free Software Foundation, Inc.
...
(gdb) target remote 127.0.0.1:1234
You can use GDB as you normally would. For example, type "cont" to launch the kernel:
(gdb) cont
Building your own kernel and file system images
So far we have seen how to use the Qemu emulator with the test kernel and file system images that are available on the Qemu site. To make full use of the emulator, we can create our own custom kernel and file system images that will better reflect the real target we are trying to develop for.
First, query Qemu regarding which boards it can emulate for your chosen architecture. Replace "arm" in the example above with one of: mips, x86_64, ppc, or sparc. For i386, simply use "qemu" as the command:
$ qemu-system-arm -M \?
Choose the board that most closely resembles your real target environment. Note that you can add support to Qemu of your specific true board. This requires some programming though, and we shall not cover it in this tutorial.
The creation of a kernel and file system for our emulated target is no different then doing the same task for real hardware. In fact, many tools are freely available to accomplish this task. In this example, we shall use the Buildroot framework. Buildroot is a set of make files and patches that simplify the generation of a cross-compilation tool chain and root file system for your target Linux system, using the uClibc C library.
First, we shall download the latest Buildroot release from the project web site and extract it:
$ wget http://buildroot.uclibc.org/downloads/snapshots/buildroot-snapshot.tar.bz2
$ tar jxvf buildroot-snapshot.tar.bz2
$ cd buildroot/
Next, let's configure Buildroot for our chosen target board:
$ make menuconfig
You will be presented with a menu enabling you to pick your architecture, sub-architecture, specific board to build for. Other options include GCC and uClibc versions, and related details. For each menu choice in the configuration tool, you can find associated help information describing the purpose of the entry.
At minimum, the following configuration options needs to be set:
Target Architecture option -- choose your target architecture (e.g., arm.)
Target Architecture Variant option -- Chose a specific model of the architecture (e.g., arm926t).
Target options menu -- If the target board you wish to emulate (that is supported by Qemu) is listed, turn on support for that board (e.g., enable the "ARM Ltd. Device Support" menu, and inside it choose the "Integrator arm926" option).
Toolchain menu -- Turn on "Build gdb server for the Target" option, and if you would like to test C++ programs on the emulator, also the "C++ cross-compiler support" option.
Target filesystem options menu -- Enable the "cpio the root filesystem" option, and choose the "gzip" compression method. You may also request the file system image to be copied to a specified directory once it is generated.
Kernel menu -- Choose the "linux (Advanced configuration)" option, and pick one of the offered Linux kernel versions of the list offered. Also, select the "zImage" binary format. Here, you can also specify a directory to copy the generated kernel to.
In addition, you will need to supply a proper Linux kernel configuration file. Note that you can extract the kernel configuration file used to generate the kernel supplied as part of the test images, by issuing the following command from inside the emulator:
$ zcat /proc/config.gz > linux.config
Alternatively, Linux provides specific kernel configuration for optimal use with Qemu for some architectures. Run the following command to inspect the default kernel configuration included in a specific Linux kernel version:
$ make help
When you're done configuring Buildroot, exit the configuration utility (making sure to OK saving the changes) and type: "make". Buildroot will now download all required sources, and build your new kernel and file system image for you. You should now be able to run the emulator using the kernel and file system image you have just created. Use the file name and path of the zImage binary as a parameter to Qemu's "-kernel" option, and the file name and path of the file system image with Qemu's "-initrd" parameter, like so:
As we have shown, the Qemu emulator provides a fairly simple way to develop, debug, and test Linux kernels, drivers, and applications for a variety of embedded architectures, even when no actual hardware is available. More information about the software used in this article can be found on the qemu, gdb, and Buildroot websites.