Showing posts with label network. Show all posts
Showing posts with label network. Show all posts

Saturday, July 7, 2012

Ideas For Old Computers

When you look at that old single core machine you probably see a pile of junk. You might even think that the components are so old they couldn't be used for anything. Well I'm here to tell you they are good for something. I will concede they are not up to playing the latest games and running modern programs (at least in the windows world) but they are still useful machines. Some of my ideas may call for an upgrade or two, but most of these ideas can make use out of your hardware as is.

Build A Firewall/Router

A firewall can be built using little more than a Pentium II system, two NICs, and 256 MB RAM. Download and install a Linux distro that is designed to act as a firewall/router, and you are ready to go. The low hardware requirements and easy setup make this an easy project for anyone with a little tech know-how and tight budget. A couple of distros worth mentioning are Devil Linux and IP Cop.

Setup An Internet Surfer

These can be built with a Pentium III system with 512 MB RAM and a NIC. Add Xubuntu, Lubuntu and you are set. For systems that have at least a 1GHz processor and 1GB of RAM, you could install Ubuntu or PC Linux. I like to clear off the desktop and add a shortcut to Firefox and rename it "Internet". It's an easy solution for visitors, and it reduces the possibility of compromising your machine.

Build A File Server

A simple server to store and serve up files is cheap and easy to build. A Pentium III with 512 MB RAM should do nicely. I'm not talking about RAID arrays. Just a simple file server for storing files and backups. Gentoo or Slackware are good choices for this. For the average home user, this will do nicely. Grab an account with a dynamic DNS provider like No-IP.com and access your files from everywhere.

Setup A PBX

If you still use telephones, you could build a PBX system. The faster the system the better, but you could build a PBX capable of handling 1-2 lines with a Pentium III equipped with 512 MB RAM. This project isn't simple or easy. For starters you can't use just any hardware for connectivity. Setting one up requires doing research and LOTS of configuration time. If you are looking for a challenging project, this is for you. Visit Asterisk to get started.

Media Center

You will need a Pentium IV system, 2 GB of RAM, TV tuner, and all of the disk space you can stuff into it. Luckily there are a few great options for software. If you are running Winders, Media portal is a great open source option, if you do not own Windows Media Center Edition, or XBMC. For Linux there is MythTV, XBMC, LinuxMCE, and GeeXboX. All of them have enough skins, features, and plugins to make a really nice media center.

Setup A MAME Box

Go to MameDev.org and load it on your old Windows box. Then head out to Cool Rom or ROM World to grab a few ROMs. Mame is a ROM emulator that runs old video game ROMs that are no longer being marketed. If your box will run Windows, it will most certainly run MAME. This is a great way to put old joysticks to use as well.

Setup an Active Directory Domain

Depending on the version of Windows Server you have, a Pentium III with 512 MB RAM should suffice. Load up Windows Server, configure Active Directory, and add it to your network. It's a great way of adding security and control to your network.

Build A RADIUS Server

Add authentication to your network with a RADIUS server. FreeRADIUS.org offers a free Linux based RADIUS server to install on your machine. A Pentium II with 256 MB RAM should be sufficient to run a small home RADIUS server.

Honeypot

Configure any old machine, put it in your DMZ, and hack it. Invite your friends to hack it. This is a great way to learn computer security. It's fun, too.

Serve Your Website

For small personal sites, this is the way to go. Pentium III with 512 MB RAM. Grab an account at No-Ip.com and serve your visitors from home.

Surveillance

Hook up a few cams, grab EyeSpyFX.com software, and make it accessible from everywhere. I would recommend a Pentium III, at least 768 MB RAM, and 100 GB disk for recording, less disk space if not. This makes good use of those old webcams.

Jukebox

Install Winamp and load it down with your favorite songs. Add some quality powered speakers, or connect to your stereo for hours of non-stop music.

Tuesday, July 3, 2012

To (Almost) Catch A Hacker (By Accident)

About eight or so years ago I was providing support at a small upstart company here in the DFW metroplex. The business was growing pretty rapidly and had a pretty sophistacated network that was segmented by department, several servers of mixed flavors, used AD for user management, enterprise level "traffic control" with Cisco equipment, and all wired. It was a sweet setup. They had wisely spent some money on doing their network right and had plenty of room to grow. This was before Sarbanes-Oxley, when smaller companies first started thinking about security, but it was only half-assed implemented if at all. When they decided the time had come to add a shipping department, someone had cobbled together a small wireless network using SOHO equipment, and that's where the problems began.

One day my co-worker and I decided to check some things out in shipping. They had been complaining about dropped connections and printer issues, nothing out of the ordinary. The router usually needed a quick reboot, and printer problems usually revolved around ink, user, or driver issues. No big deal. Everything was running smoothly, no issues from other departments, so we decided to go in tandem and resolve them.

Normally someone would perform a quick reboot of the router to get the connection back. Sometimes the employees would do this as well, but lately they have been pushing for a better router. My co-worker decided to log in the router and check it out while I dealt with a low ink cartridge. While "in" the router, my co-worker calls me over to have a look. There were two wireless on this particular segment connected at all times. Always. Now there were three. Houston, we have a problem.

After verifying that the employees were not using an unauthorized machine, we went outside. In an adjacent parking lot, which was always empty, sat a lone car with someone in it. As we approached the car, it drove off and disappeared quickly. We checked the router again, and the connection count was back to two. The network had been compromised.

Luckily, the new segment didn't have system-wide access. After viewing router and server logs, we were able to determine that nothing of any value had been compromised. We caught him in the act. But back then there was really nothing we could do except secure that router and upgrade it. Today it would be a different story. It taught us some important lessons that sticks with me today:

  • No target is too small.
  • Always thoroghly secure a wireless device.
  • Don't become passive with seemingly unimportant or temporary setups
  • Log into ALL network equipment and read logs regularly.
  • Don't use cheap equipment for enterprise purposes.

Sunday, July 1, 2012

Port Blocking

It seems like everyone has a router these days, but not everyone understands how to take advantage of their features. I'm going to show you some common protocols to block and how do it my Linksys router. This feature can not only be used to block unwanted traffic, but can also be used to protect your children from adult content. Home routers do not offer the same protections as their enterprise counterparts, but a little traffic filtering can go a long way. Here are some basics:

The picture below shows the Access Restrictions and protocols blocked on my first rule. On this router, only 3 protocols can be blocked per rule. As you can see, the policy is enabled and I have it applied to every PC on my network (not shown). I'm not blocking access to any PCs nor do I have any website filters setup. To filter websites, simply fill in some keywords or actual web addresses in the appropriate areas and save your changes. This feature can be used in conjunction with, or if you are on a tight budget, instead of nanny softwares. It offers some protection for your kids, or any annoying websites you wish to block. Again, you can setup multiple rules to block additional sites.

As you can see, I have blocked Telnet (shell access), SNMP (simple network management protocol), and TFTP (trivial file transfer protocol) on this rule. Some additional protocols to block are SMB (Windows file sharing), VNC (remote control software), and RPC (windows remote control protocol). For more effective filtering, research the protocols in use on your network, and block the ones that are not in use. A complete list of ports and their assigned protocols can be found at www.iana.org/assignments/port-numbers

Port blocking and web filtering aren't difficult to achieve with home routers and offer another layer of protection against the outside network. Filtering is not only good for children, but it can be used to protect the integrity of your network by blocking out spammy or other suspicious sites.

Thursday, June 28, 2012

Cybersecurity and IP Law

**This article was published prior to this date**

These subjects are currently being debated as Congress begins the process of beefing up IP law and cybersecurity. While we do have a need to protect our infrastructure, there is little (if any) real dialogue about actually securing national resources. The bills that have been introduced revolve around censoring the internet in an attempt to protect the IP (intellectual property) interests of Hollywood, the recording industry, patent holders, and major software manufacturers. They seem to be using critical infrastructure as a convenient excuse to create new legislation. No one involved in drafting these bills seem to have even a passing understanding of IT or network security.

After reading this 3 part article and this one on Forbes.com, I have serious reservations about the drafting process and the people involved in it. Any hacker worth their salt knows corporate naming conventions. AV programs and firewalls are good for scanning files and traffic control, but they offer no protection against a pointed attack. These attacks can be launched in many different ways using common ports, applications, and protocols. They may or may not leave any evidence behind, other than empty log files. Any hacker will tell you the only sure fire defense is to disconnect your machine from the network and shut it down. To assert that any serious security firm would prescribe AV and firewalls as a serious defense against these types of attacks is laughable. The fact that these attorneys don't get it is disturbing. How can people with such a poor understanding of corporate IT draft legislation to deal with cyber threats? Do they actually know what they are doing?

How is blocking pirated media, websites, or stiffening intellectual property going to secure the national power grid? The problem with the proposed legislation is the lack of protection for internet users from over zealous and tyrannical policing of content that may not be popular with the powers that be. Websites could be taken offline on a whim. It could take years to get a site back online, if at all. It could also potentially keep new technological break throughs, in virtually every field of science, from ever being used outside of the select few that develop or own them. These laws could potentially be used to erase or cripple other technologies.

The cybersecurity and IP legislation in their current form are being created to protect corporate profits, and nothing more. I'm not against turning a profit, it's the American way. But when does IP become more valuable than our rights as American citizens? I have a feeling we're about to find out.

11 Things To Know About Your Home Network

Many people are surprised to learn they are criminally responsible for the use of their home network. In some jurisdictions it's a crime to run an unsecured wireless network. Here are 11 things you should know about your network in order to avoid future issues:

  1. Encrypt your wireless network - Use WPA, never use WEP. While WPA can still be broken, it's widely available, stronger than WEP, and is actually easier to setup.
  2. Hide your SSID - Less visibility is always better.
  3. Control addressing - Use a subnet calculator to calculate a new address scheme, link addresses to machines if using DHCP, or use static addressing.
  4. Block basic protocols - Most users can block protocols like TFTP, Telnet, and SNMP on their network. If no file shares are present, protocols like SMB and NFS can be blocked. It's worth looking into.
  5. Enable Logging - Make it a point to check your logs every week.
  6. Adjust network range - Play with this setting until you achieve the right balance of lowest range setting and connectivity. Most users don't need to run their router full on.
  7. Turn off "Web Utility Access" - Only allow your router to be configured from a wired connection.
  8. Turn off Remote Management - If you can access your router's settings over the network, so can an attacker.
  9. Block the IPs of any machine you don't want accessing the web
  10. Use Wireless MAC filtering - By restricting access to only your machines, you reduce the risk of infiltration.
  11. Change the default password and username.