<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>TangoRangers.com's Blog &#187; good to know</title>
	<atom:link href="http://blog.tangorangers.com/category/good-to-know/feed/" rel="self" type="application/rss+xml" />
	<link>http://blog.tangorangers.com</link>
	<description>Misc crap and such</description>
	<lastBuildDate>Fri, 30 Jul 2010 01:13:05 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
		<item>
		<title>Secunia PSI is a must for any Windows machines</title>
		<link>http://blog.tangorangers.com/2010/07/secunia-psi-is-a-must-for-any-windows-machines/</link>
		<comments>http://blog.tangorangers.com/2010/07/secunia-psi-is-a-must-for-any-windows-machines/#comments</comments>
		<pubDate>Fri, 30 Jul 2010 00:58:17 +0000</pubDate>
		<dc:creator>DaijoubuKun</dc:creator>
				<category><![CDATA[good to know]]></category>
		<category><![CDATA[windows]]></category>

		<guid isPermaLink="false">http://blog.tangorangers.com/?p=252</guid>
		<description><![CDATA[Keeping up with program patches and updates can be extremely difficult, but thanks to your friends over at Secunia, those problems can be all but eliminated! This is a (somewhat) complete guide on getting Secunia PSI (Personal Software Inspector), installing, and running it! This program is a must for anyone who runs any Windows OS. [...]]]></description>
			<content:encoded><![CDATA[<p>Keeping up with program patches and updates can be extremely difficult, but thanks to your friends over at Secunia, those problems can be all but eliminated! This is a (somewhat) complete guide on getting Secunia PSI (Personal Software Inspector), installing, and running it! This program is a must for anyone who runs any Windows OS. This is partly because it&#8217;s only available for Windows. These images were taken from a Windows 7 Home Premium 64-bit OS, but it should be pretty much the same for any other OS.</p>
<p>At the time of this writing Secunia PSI was on version 1.5.0.2.</p>
<p>First, lets get Secunia PSI downloaded. Head on over to <a href="http://secunia.com/vulnerability_scanning/personal/" target="_blank">Secuina.com</a> and look for the download button.</p>
<p><img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_1.jpg" alt="this is an image" /></p>
<p>After downloading head over to where ever you saved it to, and double-click to run. NOTE: Windows may ask is you want to run the program, click yes!</p>
<p>Now follow the instructions. Images below will help guide you through the process.</p>
<p>Select a language.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_3.jpg" alt="this is an image" /><br />
Click Next<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_4.jpg" alt="this is an image" /><br />
I accept the terms of the License Agreement (Don&#8217;t forget to read it!)<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_5.jpg" alt="this is an image" /><br />
Select Personal Use, unless you are using it for business purposes.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_6.jpg" alt="this is an image" /><br />
More reading<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_7.jpg" alt="this is an image" /><br />
Tell it where to install<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_8.jpg" alt="this is an image" /><br />
Once done, click finish<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_9.jpg" alt="this is an image" /><br />
It will ask if you want to run it. Say yes.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/sec_10.jpg" alt="this is an image" /><br />
Once it starts you may see message saying &#8220;Please wait while network connectivity is verified.&#8221; Have no fear, this is normal. As soon as the program can see the servers it will continue. If you have a software firewall installed you may need to allow Secunia PSI access to the Internet.</p>
<p>Now onto usage!</p>
<p>After the program scans it will come up with a list like this. This image is a good scenario (of a bad situation), you may get one just like it or worse. If the insecure program is listed as a Microsoft product it should be dealt with by using Windows Update. I did not include how to do this because it varies from XP, Vista, and 7.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/secunia_psi_1.jpg" alt="this is an image" /></p>
<p>Here I&#8217;m going to update Adobe Flash Player 10.x. I click on the Blue down arrow, I get a dialog box to download the new software.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/secunia_psi_2.jpg" alt="this is an image" /></p>
<p>Save the file (remember where you save it to!)<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/secunia_psi_3.jpg" alt="this is an image" /></p>
<p>Then run it! Just follow the steps for each program. In this case there were many listings for Adobe Flash Player. You only need to download it once and run it once. Once you scan again it will show them all fixed up. (FYI: The reason it lists many copies is because Flash Player is installed in several places due to different web browsers)<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/secunia_psi_4.jpg" alt="this is an image" /></p>
<p>After you do this a few times and run windows update you can manually start the scan again. Once you are set you will see something like this.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/secunia_psi_5.jpg" alt="this is an image" /></p>
<p>You are set! Look at you! You have already mastered this awesome utility!</p>
<p>By default Secunia PSI is set to run at system startup. This may not be best if you are on a laptop, or have a very slow computer. If Secunia PSI is running you will see a little icon in the bottom left corner of your screen. It looks a little like this.<br />
<img src="http://www.tangorangers.com/files_blog/secunia_psi_pics/secunia_psi_7.jpg" alt="this is an image" /></p>
<p>Questions?</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.tangorangers.com/2010/07/secunia-psi-is-a-must-for-any-windows-machines/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Use SSH Keys Instead of Passwords</title>
		<link>http://blog.tangorangers.com/2010/05/use-ssh-keys-instead-of-passwords/</link>
		<comments>http://blog.tangorangers.com/2010/05/use-ssh-keys-instead-of-passwords/#comments</comments>
		<pubDate>Sat, 08 May 2010 21:47:41 +0000</pubDate>
		<dc:creator>DaijoubuKun</dc:creator>
				<category><![CDATA[good to know]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://blog.tangorangers.com/?p=246</guid>
		<description><![CDATA[I have been living and working in SSH environments for quite some time now. I even created a little bash script to help me keep track of all my connections. Today I wanted to talk about a new way (well, it&#8217;s not really new, but new to me I guess) of connecting to other Linux [...]]]></description>
			<content:encoded><![CDATA[<p>I have been living and working in SSH environments for quite some time now. I even created a little bash script to help me keep track of all my connections. Today I wanted to talk about a new way (well, it&#8217;s not really new, but new to me I guess) of connecting to other Linux systems by using keys instead of passwords.</p>
<p>Normally when you open an SSH connection you are presented with a password request. The down side to using passwords is that if your not paying attention you can be hit with a brute force or dictionary attack. Because you allow passwords to be used there is a chance of someone gaining access. With keys only you have nothing to fear from these types of attacks.</p>
<p>Here is how it works. Normally you enter a password. With keys all you need to do is form the SSH connection and the keys transmit automatically. Once the keys are paired you are connected with a shell. There are two different ways of performing key pairs. The first way is just the key. No need for a passphrase. The other is a passphrased key. I will talk about both.</p>
<p>First is the “no passphrase key.” In this example you will create a key, upload it to the host, then every time you connect you will not be asked for a password or passphrase. Keep in mind that by doing this there are risks involved. More on that later.</p>
<p>To make a “no passphrase key” you need to generate a key pair. The simplest way of doing this is:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">ssh-keygen -t rsa</pre></div></div>

<p>When it asks you for the password just hit enter. You will get an output of something like this.</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">Generating public/private rsa key pair.
Enter file in which to save the key (/home/user/.ssh/id_rsa):
Enter passphrase (empty for no passphrase):
Enter same passphrase again:
Your identification has been saved in /home/user/.ssh/id_rsa.
Your public key has been saved in /home/user/.ssh/id_rsa.pub.
The key fingerprint is:
52:b8:d4:fd:d3:f6:ef:46:d1:90:42:de:e2:94:f4:09 user@localhost
The key's randomart image is:
+--[ RSA 2048]----+
|           .E  . |
|       o . o.=o. |
|      o o . =.+..|
|     . o   + o ..|
|      o S   + o .|
|       .     o ..|
|               ..|
|                o|
|               oo|
+-----------------+</pre></div></div>

<p>NOTE: These are test keys I generated, they won&#8217;t work after today.<br />
This created two files. “id_rsa” and “id_rsa.pub”</p>
<p>Take the id_rsa.pub file and upload it to the remote system. There are several ways of doing this. You can use scp, or if you are already connected you can copy and paste the contents of the file in pico, nano, vi, vim, what ever your favorite editor it. Be sure if you use the copy and paste method you keep the entire key in one line!</p>
<p>For scp type:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">scp id_rsa.pub &lt;user&gt;@&lt;remote host&gt;:/.ssh/</pre></div></div>

<p>This will upload the pub file to the remote host. Once uploaded, login then navigate to ~/.ssh (your user&#8217;s home directory then to .ssh). Once there look for a file called “authorized_keys” and cat the contents of the pub file to it. If the file already exists type:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">cat id_rsa.pub &gt;&gt; authorized_keys</pre></div></div>

<p>If the file doesn&#8217;t exist use only one (1) “>”</p>
<p>For the copy and past method, cat the id_rsa.pub file to display the output. Select it. Login to the remote host. Open authorized_keys in an editor of your choice. Then paste the copied key. Make sure it stays all on one line! If you don&#8217;t it will not work. Save the file.</p>
<p>Once one of these two steps for implementing the key file has been completed you are good to go! You can delete the .pub file if you desire.</p>
<p>Now, onto part 2!</p>
<p>Here is where we generate passphrase keys. It&#8217;s basically the same task. When you generate a key put in a passphrase! Remember the passphrase. It is very important. Now when you login you will be prompted to enter you passphrase. This will unlock the key to be used for the connection. It should be different from your normal password.</p>
<p>Now, a few more little notes I want to talk about.</p>
<p>The problem with no passphrase keys: With out the need for a key is someone gains access to your system (like a laptop) they can gain access to any system you authorized that laptop to connect to. With passphrased keys you must type in a passphrase to authorize the key.</p>
<p>If you have problems make sure your ssh config is set to allow keys! Refer to your distro&#8217;s help files for more information. In the config you can also disallow passwords all together. The only way to login would be with the use the keys. The down side is if you lose your local key. If you do this method, ensure you have a backup plan. Like another computer with access keys. In Slackware Linux the lines to look for are in /etc/ssh/sshd_config</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">PubkeyAuthentication yes
AuthorizedKeysFile      .ssh/authorized_keys
PasswordAuthentication no</pre></div></div>

<p>Note that it becomes a pain if you generate multiple keys for multiple machines. There are ways of doing it, but it adds longer lines to your ssh commands. You can use the same .pub file on any other remote machine you wish to connect to. I don&#8217;t know for sure if it would be considered bad practice to do so, but I don&#8217;t see what problems would truly arise.</p>
<p>What&#8217;s the true benefit to this instead of saving time typing a password? Security. If an attacker can&#8217;t use a password (since many users passwords are weak) it would essentially eliminate their ability to gain SSH access. What do you think if the likelihood of the attacker to guess your key. Look at id_rsa. It&#8217;s a pretty big key to guess.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.tangorangers.com/2010/05/use-ssh-keys-instead-of-passwords/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Samba (cifs) through SSH</title>
		<link>http://blog.tangorangers.com/2010/04/samba-cifs-through-ssh/</link>
		<comments>http://blog.tangorangers.com/2010/04/samba-cifs-through-ssh/#comments</comments>
		<pubDate>Sun, 25 Apr 2010 22:59:11 +0000</pubDate>
		<dc:creator>DaijoubuKun</dc:creator>
				<category><![CDATA[good to know]]></category>
		<category><![CDATA[samba]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://blog.tangorangers.com/?p=234</guid>
		<description><![CDATA[Ever needed to work from home, but have the problem of using a Samba share on the server while at work, but not at home? Well here is a simple fix. In my example I&#8217;m working on a &#8220;sandbox&#8221; from home. The folders I work in have files with more than one owner. This becomes [...]]]></description>
			<content:encoded><![CDATA[<p>Ever needed to work from home, but have the problem of using a Samba share on the server while at work, but not at home? Well here is a simple fix.</p>
<p>In my example I&#8217;m working on a &#8220;sandbox&#8221; from home. The folders I work in have files with more than one owner. This becomes a nightmare even when I ssh in. Some might think an NFS share would be better. Unfortunately with NFS you are stuck with the current file permissions. With Samba those file permissions are given to you. That may sound a bit confusing, so let me try to clear it up a bit. Let us say there is only one file in the Samba share. User &#8220;ender&#8221; has ownership of the file. I can&#8217;t alter it. When I login with Samba the file appears to be owned by me not &#8220;ender&#8221;. Now I can do my work and when I log out the file is still owned by &#8220;ender&#8221;&#8230; wow, I don&#8217;t think I did a good job there either. Lets just say that when in comes to file permissions, Samba is the way to go.</p>
<p>But I need to work over ssh? Only port 22 is open from the outside. No problem!</p>
<p>We simply need to create a ssh tunnel. For this we already know we need to connect to port 139 on &#8220;sandbox&#8221;, and we need a local port to connect to. I would say just make it 139 also. Unfortunately for me I&#8217;m also running Samba on my local machine, and I can&#8217;t do that. So any non used port will do. How about 1139?</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">ssh user@remotehost -L 1139:localhost:139</pre></div></div>

<p>Simple as that. That will connect port 1139 on your local machine to 139 of the remote host. The &#8220;localhost&#8221; actually refers to the remote host. It&#8217;s saying connect 1139 to my local machine to the remote host&#8217;s &#8220;localhost&#8221; port 139. If you are actually connecting to a windows box on that network you can &#8220;bounce&#8221; off the linux host to the windows. For more information you can refer to a previous post: <a href="http://blog.tangorangers.com/2008/12/secure-vnc-for-free/">Secure VNC for free</a> for more information.</p>
<p>Now comes the fun part. You have 1139 on your local machine tied to 139 on the server. Now to mount the share as a local disk.</p>
<p>As root we mount the share.</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">mount -t cifs //sandbox/www /mnt/sandbox/ -o username=&lt;username&gt;,password=&lt;password&gt;,ip=127.0.0.1,port=1139,uid=&lt;your local UID&gt;,gid=&lt;your local GID&gt;,file_mode=0770,dir_mode=0770</pre></div></div>

<p>Fill in your Samba share&#8217;s username and password, then your local machine&#8217;s UID and GID. To find the UID and GID type:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">cat /etc/passwd | grep &lt;your local username&gt;
cat /etc/group | grep users</pre></div></div>

<p>This assumes your regular user is part of the &#8220;users&#8221; group.<br />
It will show 2 numbers. UID is most likely 500 or 1000, and GID is likely to be 100.</p>
<p>After filling in the blanks hit enter and your set! This will use the local port 1139 through the ssh connection to 139 on the server. It may seem a little slow at first, but that may be from the old server I&#8217;m connecting to.</p>
<p>If you want to store the info in fstab try:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">//sandbox/www    /mnt/sandbox     cifs        noauto,rw,username=&lt;username&gt;,password=&lt;password&gt;,ip=127.0.0.1,port=1139,uid=&lt;UID&gt;,gid=&lt;GID&gt;,file_mode=0770,dir_mode=0770          0   0</pre></div></div>

<p>Now for some reason I can&#8217;t quite get this to work, but others seem to have no problem with it. You can add the mount line above into your /etc/fstab file so a regular user can mount. I did this, but it doesn&#8217;t work for me. I get an error saying &#8220;only ROOT can mount this&#8221;. If you get this error try:</p>

<div class="wp_syntax"><div class="code"><pre class="text" style="font-family:monospace;">chmod +s /usr/sbin/mount.cifs
chmod +s /usr/sbin/umount.cifs</pre></div></div>

<p>Like I said, it didn&#8217;t work for me, however after creating the ssh tunnel I simply open a new terminal window, su to root and then type &#8220;mount //sandbox/www&#8221; and it works fine.</p>
<p>Also, the reason I don&#8217;t background the ssh connection is because if it drops you may run into some problems with trying to mount it again (or umount even). I had this problem and it gave me a head ache to try to fix it without just rebooting. I&#8217;m sure I could have forced an umount.cifs, but I didn&#8217;t try (actually I didn&#8217;t realize it was actually still mounted). When logging in I recommend running a command that continuously sends data like &#8220;top&#8221;. That will help prevent the connection from being lost. If the connection is lost you must umount the share, reform the ssh tunnel, and try again.</p>
<p>NOTE: If you are connecting to a share on a Windows 7 box you must open 2 ports, 139 and 443 (or so I&#8217;m told). To do this open up a few terminal windows and create two separate connections. After that I do not know as I have never tried.</p>
<p>EDIT NOTE: I wrote this some time ago and just now got around to posting it. I hope everything works fine for you as the mount works fine for me (except under fstab for some reason). Don&#8217;t forget that by typing the command into the shell it will be stored in your history. If the password is sensitive I would recommend clearing out your history after mounting the share.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.tangorangers.com/2010/04/samba-cifs-through-ssh/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>An Interesting Conversation About Computer Security</title>
		<link>http://blog.tangorangers.com/2009/10/an-interesting-conversation-about-computer-security/</link>
		<comments>http://blog.tangorangers.com/2009/10/an-interesting-conversation-about-computer-security/#comments</comments>
		<pubDate>Wed, 14 Oct 2009 01:19:22 +0000</pubDate>
		<dc:creator>DaijoubuKun</dc:creator>
				<category><![CDATA[good to know]]></category>
		<category><![CDATA[firefox]]></category>
		<category><![CDATA[secunia]]></category>
		<category><![CDATA[spyware]]></category>

		<guid isPermaLink="false">http://blog.tangorangers.com/?p=215</guid>
		<description><![CDATA[A few days ago I was with one of my good friends who owns a computer repair shop. I love going there because he always has something new and cool to show me (and I get to change to &#8220;geek out&#8221; for a bit), plus I like helping out so I don&#8217;t forget how to [...]]]></description>
			<content:encoded><![CDATA[<p>A few days ago I was with one of my good friends who owns a computer repair shop. I love going there because he always has something new and cool to show me (and I get to change to &#8220;geek out&#8221; for a bit), plus I like helping out so I don&#8217;t forget how to fix even the most basic computer problems. While there, a long time customer of his came in to pick up his computer and a very interesting conversation came up. The customer asked why his computer won&#8217;t stay clean after bringing it down to the shop.</p>
<p>It&#8217;s an interesting thing isn&#8217;t it? Why is it that we as admins and security experts and never seem to keep computers clean? Even the most skilled professionals can&#8217;t keep a computer clean. Well, it&#8217;s not our fault. There are so many security issues out there, and to be very blunt, the bad guys are always one step ahead of the security experts. Sometimes the good guys get a patch out (or publish the exploit) before the bad guys get a chance to exploit the security hole.</p>
<p>Unfortunately even when the good guys find the security hole before the bad guys there is the problem of getting the OS patched before someone becomes a victim. For example, a short time ago there was an ActiveX Draw exploit that affected millions of Windows PCs. Basically the bad guys somehow gained access to Google&#8217;s Adsence archive (and several other advertiser&#8217;s archives) and &#8220;infected&#8221; roughly 20% of the ads in the archive. I&#8217;m unsure of how the exploit functioned. I have heard everything from nothing to allowing someone to gain full control of your computer. Now, lets say for example that you visit a site, any site. You usually have two ads. One along the top and one down the side. So with one page view you have seen two ads. You click on something, new page, four ads have now been seen. You click again, six ads. Now you have reached the mark. There is a high probability you just saw one of the exploited ads. Whether you like it or not what you see in your web browser is also stored locally on your computer. No one was at fault with this (excluding the bad guys). Microsoft put out a patch after about a week of the exploit being known and Google fixed the hole allowing the bad guys to gain access to the Adsence servers. The problem now? Actually, two problems. One, some people are still making ads that are infected and trying to get them onto your computer. Two, there are still millions of computers that have not been updated.</p>
<p>There are always problems like this. I never like to blame any company directly unless they know of the issue but don&#8217;t bother fixing it. Other examples include more advanced techniques. You can gain access to a computer by sending certain information to it causing a hole to open temporarily.</p>
<p>The $1000 question is how do we keep out computer clean. Everyone has their own ways, but we came up with just a few basics. So if you run Windows try these out: Run <a href="http://www.mozilla.com">FireFox</a> instead of Internet Explore. Within FireFox get the extensions <a href="https://addons.mozilla.org/en-US/firefox/addon/1865">Adblock Plus</a> and <a href="https://addons.mozilla.org/en-US/firefox/addon/722">NoScript</a>. Make sure you have a good Virus Scanner and it&#8217;s up to date. Turn on Automatic Windows Updates and keep your Windows up to date. Get anti-spyware programs like <a href="http://www.lavasoft.com/">Adaware</a> (the free one is fine for me) and <a href="http://www.safer-networking.org/en/index.html">Spybot: Search and Destroy</a>. Make sure you have a firewall even if it&#8217;s the one built into Windows XP (or later), and lastly, be sure your not connected directly to the internet. Most ISPs will provide you with a modem or router, make sure you have a router even if it has the modem built in! It adds just that slight bit of extra protection.</p>
<p>Granted, those are just a few of the things you can do to keep your computer clean. I always recommend talking to an expert when wanting to try new software. If you feel your computer may not be clean find a &#8220;hole in the wall&#8221; style computer shop. Those are often the better choice compared to the larger companies. Ask questions to the shopkeep. Will they charge you even if they don&#8217;t fix the problem? Do they guarantee their work for at least 30 days? Will they wipe your computer&#8217;s hard drive or remove personal files without asking? Will they look at your personal files or web history? The best repair shops will answer honestly and quickly. Hesitation is a bad sign.</p>
<p>Lastly for all your Windows users out there. Get a program called <a href="http://secunia.com/vulnerability_scanning/personal/">Secunia PSI.</a> It is free for home users. This program will check almost every piece of software on your computer and see if there is an update for it. It works very well. For example a few weeks ago Adobe was consistently updating their Flash Player because of several security holes. Secunia PSI found the version I was running was insecure and provided me with a link to directly download and install the updated version! I must say it has been one of the best security programs I have seen for some time.</p>
<p>P.S. Just a note about NoScript. It can be hard for some users to get accustom to using it, and if you unblock the wrong script you will get infected.</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.tangorangers.com/2009/10/an-interesting-conversation-about-computer-security/feed/</wfw:commentRss>
		<slash:comments>3</slash:comments>
		</item>
		<item>
		<title>Using SSH as a secure proxy</title>
		<link>http://blog.tangorangers.com/2009/07/using-ssh-as-a-secure-proxy/</link>
		<comments>http://blog.tangorangers.com/2009/07/using-ssh-as-a-secure-proxy/#comments</comments>
		<pubDate>Fri, 03 Jul 2009 20:18:23 +0000</pubDate>
		<dc:creator>DaijoubuKun</dc:creator>
				<category><![CDATA[good to know]]></category>
		<category><![CDATA[proxy]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://blog.tangorangers.com/?p=183</guid>
		<description><![CDATA[Recently I started school (which is why I haven&#8217;t done much of anything on my sites) where they have a wifi connection just like at a coffee shop. The problem with these open networks is that people (like myself) can run a packet catcher like WireShark and get user names and password for various sites [...]]]></description>
			<content:encoded><![CDATA[<p>Recently I started school (which is why I haven&#8217;t done much of anything on my sites) where they have a wifi connection just like at a coffee shop.  The problem with these open networks is that people (like myself) can run a packet catcher like <a href="http://www.wireshark.org/" target="_blank">WireShark</a> and get user names and password for various sites such as yahoo, facebook, and myspace.  Since when you log in to those you are doing so without https (encryption).  Also my school logs every site to visit and when I&#8217;m bored in class I don&#8217;t want them to know I&#8217;m researching hacking sites.</p>
<p>To solve this I setup a Linux box on my network and point port 22 to it.  22 is the default SSH port in case you didn&#8217;t know.  Then I create a secure tunnel from my laptop to my home box (my laptop also running Linux).</p>
<pre>SSH -D 1080 username@ip</pre>
<p>This creates what is essentially a SOCKS v5 proxy on port 1080.  Anything and everything you do remotely can be routed through 1080 (any port works, I just like that number).</p>
<p>Now I don&#8217;t know how to setup my Linux machine so that I don&#8217;t need to configure every program I use to work with the proxy and currently have to setup everything manually.  Here is how to do it with FireFox.</p>
<p>Open FireFox, goto Edit &#8211;> Preferences &#8211;> Advanced &#8211;> Network &#8211;> Connection &#8211;> Settings<br />
<img src="http://www.tangorangers.com/files_blog/ssh_proxy1.jpg" alt="pic1" /><br />
Click &#8220;Manual proxy configuration:&#8221;, then under SOCKS Host put &#8220;localhost&#8221; port &#8220;1080&#8243; and make sure that SOCKS v5 is clicked.<br />
Where it says &#8220;No Proxy For&#8221; you can leave localhost in, I&#8217;m not really sure, never tried.  I just cleared it out and everything went smoothly.<br />
<img src="http://www.tangorangers.com/files_blog/ssh_proxy2.jpg" alt="pic2" /><br />
Close the window and start surfing!</p>
<p>As long as you keep the SSH connection alive this will work.  If you SSH connection does die you will know right away when you can&#8217;t surf.  You will also need to revert your connection settings back when you are no longer using the SSH proxy.  Also keep in mind that even tho you are routing via an encrypted tunnel to your remote machine, traffic will still be unencrypted after that point.  Surfing may take longer than you would like.  This is due to the fact that ALL traffic will be routed first to your remote machine then to you via the tunnel.</p>
<p>Lastly, I&#8217;m told that not every SSHd configuration allows SSH proxies.  Mine does.  I&#8217;m not sure why, I haven&#8217;t bothered to look into that yet.  You may need to check your /etc/sshd_config file as there may be an option there.  If you need help you know where to ask for it.  Enjoy! </p>
]]></content:encoded>
			<wfw:commentRss>http://blog.tangorangers.com/2009/07/using-ssh-as-a-secure-proxy/feed/</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Secure VNC for free</title>
		<link>http://blog.tangorangers.com/2008/12/secure-vnc-for-free/</link>
		<comments>http://blog.tangorangers.com/2008/12/secure-vnc-for-free/#comments</comments>
		<pubDate>Wed, 24 Dec 2008 01:33:01 +0000</pubDate>
		<dc:creator>DaijoubuKun</dc:creator>
				<category><![CDATA[good to know]]></category>
		<category><![CDATA[kde]]></category>
		<category><![CDATA[linux]]></category>
		<category><![CDATA[ssh]]></category>
		<category><![CDATA[ssh tunnel]]></category>
		<category><![CDATA[vnc]]></category>

		<guid isPermaLink="false">http://blog.tangorangers.com/?p=27</guid>
		<description><![CDATA[Here are my instructions on how to get VNC in KDE 3.5+ working through an SSH tunnel. It&#8217;s easier than you might think. To start all you need is 2 or 3 linux machines with OpenSSH installed. Most distros come with it (altho I know Ubuntu does not). NOTE: All my machines run Slackware 12.0 [...]]]></description>
			<content:encoded><![CDATA[<p>Here are my instructions on how to get VNC in KDE 3.5+ working through an SSH tunnel. It&#8217;s easier than you might think.</p>
<p>To start all you need is 2 or 3 linux machines with OpenSSH installed.  Most distros come with it (altho I know Ubuntu does not).<br />
NOTE: All my machines run Slackware 12.0 or higher.</p>
<p>Step 1 &#8211; Setup the host.<br />
This is fairly simple, open up you Control Center, and find Desktop Sharing.  Just look at my picture below and see the settings I would recommend for this.<br />
<img src="http://www.daijoubu.net/how2s/secure-vnc/vnc-settings.png" alt="settings"/><br />
Just make sure you set a STRONG password!</p>
<p>Now comes the fun part. Creating the SSH tunnel. By default the VNC connection is on port 5900.<br />
For this example you have 2 computers. Your at a coffee shop with free wifi but your smarter than everyone else, so your going to use encryption to your home desktop and surf the internet from there.<br />
Your home computer (lets say) has a domain name. For my examples it will be daijoubu.net, and your internal computer is 192.168.1.2.<br />
Make sure you set your router to forward port 22 (the SSH default) to 192.168.1.2<br />
Open up a terminal (some times it&#8217;s called Konsole) and type:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #c20cb9; font-weight: bold;">ssh</span> dkun<span style="color: #000000; font-weight: bold;">@</span>daijoubu.net <span style="color: #660033;">-L</span> <span style="color: #000000;">5931</span>:localhost:<span style="color: #000000;">5900</span></pre></div></div>

<p>The user name I&#8217;m using is dkun, just put in your user name<br />
You will be prompted for your password, after entered you have formed the SSH connection.  What this command does is it takes all traffic from your desktop port 5900, and forwards it to your laptop (at the coffee shop) to localhost port 5915.<br />
Seems complicated, but trust me, it works!<br />
Now open up Krcd and type</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;">vnc:<span style="color: #000000; font-weight: bold;">/</span>localhost:<span style="color: #000000;">5915</span></pre></div></div>

<p> Just as shown below.<br />
<img src="http://www.daijoubu.net/how2s/secure-vnc/window1.jpg" alt="window1"/><br />
If you have 3 computers. For example, you don&#8217;t forward to your desktop (for security reasons) but you do forward to a file server. Lets say your file server is 192.168.1.3 and your desktop if 192.168.1.2 type:</p>

<div class="wp_syntax"><div class="code"><pre class="bash" style="font-family:monospace;"><span style="color: #c20cb9; font-weight: bold;">ssh</span> dkun<span style="color: #000000; font-weight: bold;">@</span>daijoubu.net <span style="color: #660033;">-L</span> <span style="color: #000000;">5915</span>:192.168.1.2:<span style="color: #000000;">5900</span></pre></div></div>

<p>This will form the SSH tunnel to your server (192.168.1.3) then forward port 5915 from 192.168.1.2 through the SSH tunnel back to you.<br />
Reminder: Doing it this was results in plain text from 192.168.1.3 to 192.168.1.2. This is only a problem if you don&#8217;t trust your internal network!</p>
<p>From here is gets simple, after you click <i>Connect</i> you will be prompted for the following window.<br />
<img src="http://www.daijoubu.net/how2s/secure-vnc/window2.jpg" alt="window2"/><br />
These are the settings I recommend for over the Internet, VNC can take a lot of bandwidth.<br />
Next you will get a password prompt, type in your password and hit OK<br />
<img src="http://www.daijoubu.net/how2s/secure-vnc/window3.jpg" alt="window3"/><br />
Your remote desktop will appear! if you look quickly you will see this at the bottom right of the screen<br />
<img src="http://www.daijoubu.net/how2s/secure-vnc/window4.jpg" alt="window4"/><br />
That&#8217;s it! Now you can use your remote desktop over a secure connection!<br />
<img src="http://www.daijoubu.net/how2s/secure-vnc/window5.jpg" alt="window5"/><br />
WARNINGS! If you attempt a connection without the SSH tunnel your passwords will be sent in plain text! That is BAD!<br />
DO NOT FORWARD PORT 5900 ON YOUR ROUTER!</p>
<p>Extra Notes: If you do not have a domain name to work off of, you can put in an IP address after the username@, make sure it&#8217;s an internet IP address, 192.168.1.2 will NOT work<br />
If you don&#8217;t have a static IP address you can use <a href="http://www.dyndns.com/" target="_blank">dyndns</a> to get you one. They are really good, but if your IP changes you will have to update your opendns account.  I would recommend checking before you head out.</p>
<p>Special Thanks to Spyder_3lite of <a href="http://www.UCoD.com" target="_blank">UCoD.com</a>. If it weren&#8217;t for you showing me something way cool with SSH, I never would have been able to do this.</p>
<p>Note: This was originally written on my other site <a href="http://www.daijoubu.net">Daijoubu.net</a>.  I have moved it here for better indexing from Google.  ^_^</p>
]]></content:encoded>
			<wfw:commentRss>http://blog.tangorangers.com/2008/12/secure-vnc-for-free/feed/</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
