Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts

Friday, October 28, 2011

Configuring DSCP on SPARC Enterprise(XSCF)

Configuring DSCP

The Sun SPARC Enterprise Server Administration Guide explains how to set up DSCP, but it is really quite simple. The easiest method is using the syntax:
    setdscp -i NETWORK -m NETMASK 
Choose a network address (be sure to pick a subnet that is not in use at your facility) and the corresponding netmask, and setdscp will do the rest. For example, in my lab the subnet 192.168.244.0 is unused, so I do:
    XSCF> setdscp -i 192.168.224.0 -m 255.255.255.0 
There are other ways to set up the DSCP network addresses, but this is really the best approach.

setdscp will assign an IP address to the SP, and reserve one IP address for every possible domain (the M9000-64 supports 24 domains, so a maximum of 25 IP addresses are reserved). A common question that's asked is, if you're running PPP between the SP and each domain, don't you need to two addresses for each domain, one for the domain and one for the SP? No, not really. Since routing is done based on the destination address, we can get away with using the same IP address for the SP on every PPP link. So technically speaking, the NETWORK and NETMASK are not defining a DSCP subnet; they are defining a range of IP addresses from which DSCP selects endpoint addresses. A subtle difference, but still a difference.

On the SP, showdscp will display the IP addresses assigned to each domain and the SP, for example:

    XSCF> showdscp      DSCP Configuration:      Network: 192.168.224.0     Netmask: 255.255.255.0       Location     Address     ----------   ---------     XSCF         192.168.224.1     Domain #00   192.168.224.2     Domain #01   192.168.224.3     Domain #02   192.168.224.4     Domain #03   192.168.224.5 
In Solaris, the prtdscp(1M) command will display the IP address of that domain and the SP (prtdscp is located in /usr/platform/SUNW,SPARC-Enterprise/sbin). You can get the same basic information from ifconfig sppp0:
    % /usr/platform/SUNW,SPARC-Enterprise/sbin/prtdscp     Domain Address: 192.168.224.2     SP Address: 192.168.224.1      % ifconfig sppp0     sppp0: flags=10010008d1 mtu 1500 index 3             inet 192.168.224.2 --> 192.168.224.1 netmask ffffff00 

Monday, September 26, 2011

Cloud Flare ++ It'll supercharge your website.




Cloud Flare?

CloudFlare is a FREE system that acts as a proxy between you and our server. By acting as a proxy, CloudFlare caches static content from the site, which lowers the number of requests to the server, but still allows you to access the site. There are several advantages of the CloudFlare system which are answered below. Cloudflare (like explained above) acts as a proxy to speed up and make it less "heavy" on traffic to the VPS, which means acting like a proxy through the DNS, DDoS attacks are easily diverted keeping the site and forum chugging along nicely.

CloudFlare has just announced that they happened to pick up a cool $20 million in investment last November. Almost a 1000% increase on funds raised in 2009, proving that someone thinks they’re on to something. And Qwerty.ie couldn’t agree more, that’s why we already use CloudFlare!

For those that haven’t heard of CloudFlare yet (the emphasis being on the yet), it provides a distributed network that creates a community environment to help protect your website and all other members within the network. Information about unwanted traffic is shared which means if one website is attacked then that attack can quickly be blocked from accessing everyone in CloudFlare! It’s added security for your website. As if that wasn’t enough, CloudFlare will distribute your website across the network, making it practically indestructible (please do not test this on Qwerty.ie!). Your website will be faster and use less bandwidth.



CloudFlare and W3 Total Cache WordPress Integration

CloudFlare protects and accelerates any website online. Once your website is a part of the CloudFlare community, its web traffic is routed through our intelligent global network. We automatically optimize the delivery of your web pages so your visitors get the fastest page load times and best performance. We also block threats and limit abusive bots and crawlers from wasting your bandwidth and server resources. The result: CloudFlare-powered websites see a significant improvement in performance and a decrease in spam and other attacks.

CloudFlare’s system gets faster and smarter as our community of users grows larger. We have designed the system to scale with our goal in mind: helping power and protect the entire Internet.

CloudFlare can be used by anyone with a website and their own domain, regardless of your choice in platform. From start to finish, setup takes most website owners less than 5 minutes. Adding your website requires only a simple change to your domain’s DNS settings. There is no hardware or software to install or maintain and you do not need to change any of your site’s existing code. If you are ever unhappy you can turn CloudFlare off as easily as you turned it on. Our core service is free and we offer enhanced services for websites who need extra features like real time reporting or SSL.

To get straight to the point of using CloudFlare, here are the advantages:

  • Your website will loads twice as fast
  • Your website will uses 60% less bandwidth
  • Your website will have 65% fewer requests
  • Your website will be way more secure

And all this is for free!



Presentation:
http://cdata.github.com/presentations/what-else-is-cloudflare/

Sunday, November 28, 2010

Setup port forwarding on ZyXEL router.

Setup port forwarding on ZyXEL router.


To setup port forwarding on this router your computer needs to have a static ip address. Take a look at our Static IP Address guide to setup a static ip address. When you are finished setting up a static ip address, please come back to this page and enter the ip address you setup in the Static IP Address box below.

Do not skip this step!




Open a web browser like internet explorer or Netscape. Enter the ip address of your router in the address bar of your browser. In the picture above the address bar has http://www.google.com in it. Just replace all of that with the ip address of your router. By default the ip address should be set to 192.168.1.1.




You should see a box prompting you for your password. Enter your password now. By default your password is admin. Click the Login button to log in to your router.




Click the Network link near the left side of the page.

You should now see a new menu. In this new menu, click NAT.




Click the Port Forwarding button near the top of the page.




Select User define from the Service Name drop down box.


Rule Setup
Active
Service Name
Start Port
End Port
Server IP Address

We will list a series of lines here that will show you exactly how to forward the ports you need to forward. HTTP requires you to forward the 80 ports. Go ahead and enter the settings shown above into the Rule Setup menu and then click Apply.

Click the Security link near the left side of the page.

You should now see a new menu. In this new menu, click Firewall.




Remove the checkmark from the Active Firewall checkbox.

When you're finished, click Apply near the bottom of the screen to save your changes.

And that's it! You're done!

Saturday, September 4, 2010

Command line scanner in the OfficeScan client

Here are the options that you can use:


Option

Function

/?

Displays the “Help”

/S

Scan all files in specified directory and all subdirectories

/C

Clean virus-infected files without any prompting

/D

Delete virus-infected files without any prompting

/B

Scan boot/partition area only

/P

Scan hard disk partition only

/NM

Do not scan memory

/NB

Do not scan boot sector/partition are of disk

/NC

Scan only, do not take any action on virus files

/BK[+|-]

Clean virus-infected files backup switch

/P=path

Specify virus pattern path

/P=file[;file...]

Specify virus pattern file(s)

/LAPPEND

Open LOG file with append mode

/LR[=file]

Write standard report to the specified file

Default name “report.log”

/LD[=file]

Write detected files to the specified file

Default name “detect.log”

/LU[=file]

Write undetected files to the specified file

Default name “undetect.log”

/LC[=file]

Write clean results to the specified file

Default name “clean.log”

/LCF[=file]

Write clean fail results to the specified file

Default name “cfail.log”

/VER

Display the version information

/I

Display more information about scanning results

/NV

Only display the files without virus infection

/CLEANALL

Scan and clean the file until no virus is found

/HOSPITAL=path -

Move the virus files to specific directory

/DISKIMAGE[=drive]

Scan disk images (with or without restoring)

/NZ

Do not scan zip files (e.g. PKZIP, ARJ)

/NLITE

Do not scan pklite files (e.g. PKLITE, LZEXE)

/NMICE

Do not scan some softmice files

/NMACRO

Do not scan macro files (e.g. DOC, XLS)

/NJAVA

Do not scan java files

/NSCRIPT

Do not scan script files

/NGENERIC

Do not use generic scan

/ZIPACTION

Enable zip virus action in callback

/ZIPBREAK

Enable zip virus break in callback

/VSCHAR=n

Set character environment type from “n”

(1: Traditional Chinese; 2: Japanese)

/VSZIP=n

Set decompress layer

/ACTIVEACTION=n

Enable Active Action and se the ProjectID

/VSTEMP=path

Set the default temporary path

/VSEXT=file

Set/Add process extensions from file

/VSEXEXT=file

Set/Add exclude process extensions from file

/VIRUSNAME

List all detectable virus name (n: # to read)

/UNICODESCAN

Scanning and cleaning with Unicode files

/Q

Disable all output message

/RENAME

Rename virus-infected files without any prompting


Product:
OfficeScan - 10.0, 7.0, 7.3, 8.0
Operating System:
Windows - 2000 Server Series SP4, 2003, 2003 Server Series SP1, Server 2008 Enterprise, Server 2008 Standard, Vista, XP


Solution: Yes, the OfficeScan client has a command line scanner called VScanTM. You can run this from the OfficeScan client program file location:



vscanwin32 [/|-option] Drive:[path[filename|@script]] [Drive:[path[filename]]

Tuesday, March 11, 2008

Symantec ManHunt™ - Basic command

Symantec ManHunt™ - Basic command

manhunt install path: /usr/manhunt

start -
Start manhunt process
stop -
Stop manhunt process
restart -
Restart manhunt process

manhunt tools: /usr/manhunt/tools
adduser
dumplog.sh
manual-trigger
nodepwd
setuserpassword

backupdbs
edppwd
mhdrv-ctl
promote-demote
sigc

checkstatus
log2html.pl
mh_els_lit
re1000gdump
sym_sid

dbverify.sh
logtotext
mh-handoff-console
rotatelogs

======================================
Example:
[root@Octus]#/usr/manhunt/restart

shutting down ManHunt server
----------------------------
stopping status monitor [11914]
stopping AF... OK.
stopping other processes:
stopping alertd [11834]
stopping avmon [11881]
stopping dbsync [11904]
stopping edprcvr [11864]
stopping esp [11851]
stopping fds [11901]
stopping ftf [11816]
stopping handoff [11823]
stopping memdb [11822]
stopping mhdb.020 [11762]
stopping qspmon [11965]
stopping qspproxy [11856]
stopping resourced [11811]
stopping sniffmon [11838]
waiting for processes to clean up.... OK.
stopping mhlogd [11796]...OK.
done.
please wait...
starting...

starting manhunt....
database up and running.
please wait... done.