Showing posts with label networking. Show all posts
Showing posts with label networking. Show all posts

Tuesday, August 14, 2012

SSH server

I found this over at the Hak5 site. I highly recommend watching the full video:

Basic Client Setup in Linux
ssh -D 8080 user@host
The -D option, from the man pages
-D [bind_address:]port
Specifies a local dynamic application-level port forwarding. This works by allocating a socket to listen to port on the local side, optionally bound to the specified bind_address. Whenever a connection is made to this port, the connection is forwarded over the secure channel, and the application protocol is then used to determine where to connect to from the remote machine
Setting up a Linux OpenSSH Server
On a Debian based Linux machine setting up ssh can be as simple as issuing "sudo apt-get install ssh". In this segment Darren goes over some of the configuration lines you would find useful to modify in /etc/ssh/sshd_config.

AllowTcpForwarding yes GatewayPorts yes RSAAuthentication yes PubkeyAuthentication yes AuthorizedKeysFile %h/.ssh/authorized_keys AllowUsers bob alice PermitRootLogin no Protocol 2 Port 222 LoginGraceTime 1m ListenAddress ClientAliveInterval 60 ClientAliveCountMax 0
Be sure to restart the SSH deamon after editing the configuration. stop ssh;start ssh;service ssh restart;/etc/init.d/ssh restart #one of these should do it! :)
On a Linux OpenSSH server for example these key pairs will be found in /etc/ssh/*key*. The public keys will be world readable while the private keys can only be read by a superuser.
On a Linux client for example the key fingerprints of remembered servers are stored in ~/.ssh/known_hosts. Since SSH version 4 the username and hostnames associated with these servers are hashed.
To remotely verify the key fingerprint of an SSH server
ssh-keyscan -t rsa,dsa REMOTEHOSTNAME > /tmp/ssh_host_rsa_dsa_key.pub ssh-keygen -l -f /tmp/ssh_host_rsa_dsa_key.pub
Alternatively, on the remote server the key fingerprints can be found by:
cd /etc/ssh ls *key* cat ssh_host_key # this is the private key # permission will be denied if not superuser cat ssh_host_key.pub # this is the public key ssh-keygen -lf ssh_host_rsa_key.pub # field 1 = bit length of key # field 2 = fingerprint of key # field 3 = name of key
Setting up Key Pair Authentication in Linux with OpenSSH
On the remote host:
mkdir .ssh chmod 700 .ssh cd .ssh
On the local host:
ssh-keygen -t rsa scp ~/.ssh/id_rsa.pub user@host:.ssh/authorized_keys2
Back on the remote host:
ls -la authorized_keys2 chmod 600 authorized_keys2 exit
On the local host:
ssh user@host

Cisco vpn installer

Cisco vpn installer:

sudo apt-get install network-manager-vpnc

Now you need to select IPV4 Settings tab click on routes

Here you need to select “Use this connection only for resources on its network” click ok otherwise your traffic significantly slowed down

Know Your Network: The Complete Guide [Night School]

Know Your Network: The Complete Guide [Night School]:
We spent last week learning all about your home network, your routers, and all the cool things you can do with them. Here's the complete guide that will teach you how to pick out the best network hardware, get to know it better, make it perform at its best, and access just about anything on your network from practically anywhere in the world. More »


How to Crack a Wi-Fi Network's WPA Password with Reaver [Video]

How to Crack a Wi-Fi Network's WPA Password with Reaver [Video]:
Your Wi-Fi network is your conveniently wireless gateway to the internet, and since you're not keen on sharing your connection with any old hooligan who happens to be walking past your home, you secure your network with a password, right? Knowing, as you might, how easy it is to crack a WEP password, you probably secure your network using the more bulletproof WPA security protocol. More »

Lock Down Your Computer Like the NSA [Security]

Lock Down Your Computer Like the NSA [Security]:

Want to secure your computer with the same techniques used by the National Security Agency? Turns out the NSA has published guides for securing Windows, Mac, Linux, and Solaris operating systems using methods that "are currently being used throughout the government and by numerous entities as a security baseline for their systems." More »


How to Turn Your Computer Into the Ultimate Remote Access Media Server [Video]

How to Turn Your Computer Into the Ultimate Remote Access Media Server [Video]:

If you're out of the house a lot but still want access to files on your home computer, one of the best ways to solve that problem involves setting up your computer as a remotely accessible home media server. Here's a look at how to not only access your files (and control your computer) remotely, but also share files with others, stream music and video, access your photo library, and a whole lot more. More »

How to Secure and Encrypt Your Web Browsing on Public Networks (with Hamachi and Privoxy) [How To]

How to Secure and Encrypt Your Web Browsing on Public Networks (with Hamachi and Privoxy) [How To]:

When you're browsing from a public Wi-Fi connection—like at your favorite coffee shop—anyone on that network can snoop on what you're doing, with very few exceptions. So can the IT crew at your workplace. Today, we're going to walk through setting up an encrypted proxy server on your home computer so you can secure your browsing session no matter where you're connected, keeping your private data significantly more private. More »