Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Saturday, November 27, 2010

Understand your home network

A home network is a very complex issue. Taking information from one place to another, which might not eve on the same continent is a pretty big deal. This article will not go into too much technical jargon, but it will be an in-depth answer to the general (and some complex) questions about networking, especially wireless networks. We see the most fundamental aspects of a wireless network in a question / answer format.

How does the signal get my computer to myrouter, Internet, and vice versa?

When a computer user is connected to the Internet are almost constantly sending signals to multiple locations. The way this is done from binary code. Any user is not divided and transmitted in binary code (in this case, wireless) to the router and then to the destination that you gave. In the case of a wireless connection, the card is sent to the wireless router using a protocol called CSMA / CA (CarrierSense Multiple Access with Collision Avoidance) that allows only one node (or computer) access to the router at once. If a computer uses the router and a second computer may also use the second system is sent a "busy signal" and must wait a certain period of time. When time expires, the request of the computer. For reference, a cable connection using CSMA / CD (Carrier Sense Multiple Access with Collision Detection), which allows the computer to sense whenanother node is using the router. In this way the request is sent in the first place.

This, of course, makes more sense, but it is not possible with a wireless connection, since there is no permanent connection to the router. Connections involving stops when the request is met, unlike the cable connection that is always the cable. The router is now based on the OSI 7-layer model (which is too large and sophisticated to fit in this article, but Google can andfriend) host.Basically to receive information to and from the destination, the router (which by the argument will run as a DNS server in this scenario) is the IP address assigned by Google and launches its request Google for their web server . The link is at the door 80 for accessing a Web page and then processed by a web server for Google. The signal is sent in the same way it was sent from the computer. When it comes toback, the user sees on the display of Google. This process is done very quickly if you see sometimes a matter of less than one second. If you live in the U.S. and the Web server in China (again, just for the sake of argument), the speed with which this happens is quite impressive to the uninitiated. This is a brief description of how the process works.

What protection is available for wireless networks?

There are some optionswireless encryption. Encryption is very useful because it helps to get people out of your wireless network, if they should not. This is basically a password protection for the connection. Some of the most popular choices are:

WEP (Wired Equivalent Privacy)

WEP uses a 128-bit encryption system using a series of 26 hexadecimal (base 16) characters. 256-bit is available, but historically it is quite unusual. This encryption method is a bit 'datedbut it is still used by some. This is replaced by safer WAP and WAP2 discussed below. The way in which a computer is checked by receiving a clear challenge to the router for encryption and the challenge of delivery.

WPA and WPA2 (Wi-Fi Protected Access)

WPA2 is preferred by many because it is probably the safest available for home users. A 256-bit key used to encrypt all network traffic. There are two types of WPA, TKIP and PSK. Let usdiscuss this a bit ':

TKIP

Temporal Key Integrity Protocol (TKIP) was designed originally designed to replace WEP WEP without replacing the hardware. The repaired many of the flaws of WEP, but has had its problems, including the ability to be decoded by others in short bursts. This was a problem with the WEP, which is passed, TKIP.

PSK

Pre-Shared Key mode (PSK) is designed for those who do not need sophisticated security, such as home users. A number of minorCompanies use this as well. It offers a password-protected security is in decent though not as strong as a large company can have. Many home users to implement this because of its ease of use. The only real weakness of this protocol that a user at home should be concerned about a weak password. weak passwords are the main reasons that sometimes lose some effectiveness.

Advice on network security

There are some things that the average home user can do to ensuretheir network and your computer from intruders. The network, set a strong password is essential. This should be placed at the top of someone. Second, by hiding the router Service Set Identifier (SSID) works very well. If the hacker can not find the network, can not penetrate the network. What if one of the personal computer, immediately change the Administrator account a different name. Hackers try this account most of the time, in order to gain administrative access onuser. If the user name is still responsible for the potential attacker has won half the battle. The only unknown is the password. However, if the FozzyBear administrator user name or user name or password is known and the attacker has to spend much more time and will probably just give up, even if they manage the network. As a side note, a good anti-virus and firewall are not forgotten. These are vital for information security generally.

If you havequestions, please contact me via my website below and I'll gladly answer.

Friends Link : Memory Module

Wednesday, November 24, 2010

Finding the MAC address on wired and wireless network cards

The response of the Media Access Control Question

In recent weeks I have a lot 'of e-mails about Ethernet cards, both wired and wireless, and more specifically, about Media Access Control (MAC). I think the main reason that I have received many questions about Ethernet cards, and MAC addresses is people trying to own wireless home networks and their desire to use the MAC address filtering to secure. This type of filter in wireless networks can be configured toAllow or deny use of specific computers or connect to the wireless network based on the MAC.

My first thought was that of a single article on wireless Ethernet MAC addresses and write. After thinking, I decided to expand on this and to move some specific information about Ethernet cards and communication.

Different ways to find your MAC address and much more

There are several ways to Ethernet protocol and communication and information. Many Ethernet cardmanufacturer's proprietary software that can reveal this information, but behave differently depending on the manufacturer. So we'll use the Windows 2000 and XP "ipconfig" utility since this is available in most Windows operating systems.

First, go to "Start" -> "Run" and type "cmd" without quotes. Then press the Enter key. At the command prompt type "ipconfig / all", again without the quotes. In fact, just typing ipconfig without the '/ all will work, but it will onlyprovide summary information of network adapters. An example of what one might see by typing "ipconfig / all" command is below each said in green:

Fault Tolerant and High Availability Computer Systems

There are several ways to Ethernet protocol and communication and information. Many software vendors Ethernet card owners who can reveal this information, but behave differently depending on themanufacturer. So we'll use the Windows 2000 and XP "ipconfig" utility since this is available in most Windows operating systems.

First, go to "Start" -> "Run" and type "cmd" without quotes. Then press the Enter key. At the command prompt type "ipconfig / all", again without the quotes. In fact, just typing ipconfig without the '/ all will work, but provide only summary information of network adapters. An example of what one might see by typing"Ipconfig / all" command is as follows:

Output of "ipconfig / all" command

Windows IP Configuration

Host Name. . . . . . . . . . . . : Home Computer

This is the name of the computer, usually defined during the installation of Windows. However, it can be changed after installation.

Primary DNS Suffix.. . . . . . : Domain.com

If your computer has an active network, such as a Microsoft Windows domain this entry may contain the name ofdomain.

Node Type. . . . . . . . . . . . : Unknown

The node type can say unknown, or peer-to-peer, or in some cases "hybrid". It is an institution that has to do with Windows Internet Naming Services used in certain types of Windows domain networks.

IP Routing Enabled. . . . . . . . : No

This setting determines whether Windows XP or 2000 functions as an IP router. If you have two or more network cards you can configure the system to act as a router, forwarding communicationsrequests from one network to another. Windows 2000 can be configured to do this in a nice straight forward, Windows XP will need a change in the registry.

WINS Proxy Enabled. . . . . . . . : No

WINS Proxy is another institution that is linked to the "Node Type" we discussed earlier. It is not normally a required setting in a home or small office or the newer type of Microsoft Windows domains.

Ethernet adapter Wireless Network Connection 2:

If youover Ethernet (network) cards in your system, if I were in this laptop, you will have multiple listings. This is the second Ethernet card, a wireless Ethernet card inside.

Description. . . . . . . . . . . : Broadcom 802.11b / g WLAN

This is the description of the Ethernet card, usually the name / manufacturer and type of Ethernet card. In this case it is a Broadcom wireless Ethernet card built into my laptop.

Physical Address. . . . . . . . . :00-90-4B-F1-6E-4A

And here we have the MAC address. The MAC address is a 48-bit hexadecimal code and is suppose to be a completely unique address. It is 48 bits because each number or letter in hexadecimal represents 8 bits. Hexadecimal numbers range from 0,1,2,3,4,5,6,7,8,9, A, B, C, D, E, F. There are 6 alpha-numeric codes is 6 * 8 = 48 (bit). The first 3 codes identify the manufacturer of the card and the other codes are used to create a unique number. Theoretically there should never be acard with the same MAC address of a local network. However, there are some exceptions. There are software tools that allow you to change this code. In reality, this is a step some hackers take to attack other machines on a local network. I speak the local network because MAC addresses are not routable between network segments. By spoofing this address, you can impersonate another machine on the network. Traffic that was bound for the objective may be redirected to the hacker's computer. This isthe address is also possible to use a physical address or MAC address table before setting up wireless access point to support MAC address filtering to people.

DHCP enabled. . . . . . . . . . . : Yes

DHCP or Dynamic Host Control Protocol, if enabled means your computers IP address provided by a DHCP server on the network. The DHCP server can cable wireless access point / router DSL, cable modem or a network server. Although aDHCP server is enabled on the network, the computer operating system will automatically generate a random IP address within a predefined interval. This means you could network a group of interconnected, without having to manually assign the IP settings.

IP address. . . . . . . . . . . . : 192.168.0.117

This parameter allows your current IP address. The address above is what is called a "private" addresses. There are several classes of IP addressesare reserved for private use. This means that for the internal network, local or private home or office. Such addresses are not, or not, are routable on the Internet. The Internet routes called "valid" IP addresses. The cable / DSL router or cable modem has a valid IP address assigned to the "outside" of the network. The external interface of the phone or cable TV cable.

Subnet Mask. . . . . . . . . . . : 255.255.255.0

Subnet Mask is aspecial issue, or in a sense, the filter, which breaks your IP address, in this case a private IP address in certain areas. IP addresses and subnet mask can be a complicated issue and would require an entire article to be about.

Default Gateway. . . . . . . . . : 192.168.0.254

The default gateway IP addresses of the above, the IP address of the device that will route your request, such as when you try to browse a website on the Internet. It 's a bit complicatedthan that, but as a gateway or router traffic to different networks, the other private networks. At home or small office, this gateway most likely is your cable modem / DSL or router.

DHCP Server ... . . . . . . . . : 192.168.0.49

The DHCP server, remember we talked a bit 'above, the device indicates that the computer has an IP address and other information. DHCP server can assign all kinds of information, including: StandardGateway, DNS (Domain Name), IP address, Subnet Mask, Time Server, and more.

DNS Server ... . . . . . . . . : 192.168.0.49, 64.105.197.58

The DNS servers are internal or external, to fully resolve the names (FQDN), such as http://www.defendingthenet.com full domain of IP addresses. This is because computers are not really about your request using the domain, use the IP address assigned to the FQDN. For mosthome or small office, DNS server IP address from your primary Cable / DSL Router. The Cable / DSL Router to ask an external DNS server on the Internet to perform address the effective resolution of the FQDN to IP. The address 192.168.0.49 is an internal private device on my network that 64.105.197.58 is an external public Internet DNS server and is available in case my router has difficulty performing the DNSResolution tasks.

Lease obtained. . . . . . . . . . : Sunday, March 19, 2006 18:38:16

This information tells you when the computer received its IP address and other information from a DHCP server. You will notice that says "Lease obtained", it is because most of the DHCP server just give the IP address lease from a pool of addresses available. For example, the pool may be 192.168.1.1 through 192.168.1.50. So your DHCP server has 50 IP addresses to choose from whenassigning the IP address of your computer.

Lease expires. . . . . . . . . . : Wednesday, March 29, 2006 21:38:16

If the IP address assigned by the DHCP server will attempt to lease expiring lease is the same or a different IP address. This can usually be changed on the DHCP server. For example, on some fully functional DHCP server, you can never rent due within one day and so on.

Why are so MAC addressesImportant and how they work

To jump back into the MAC address for just a bit '. You might think that IP addresses are the most important thing when it comes to network communication. The reality is, MAC addresses are very important because without them computers would not be able to communicate over Ethernet networks. When a computer wants to talk to another computer on a local network, broadcasts a query, or ask a question, who owns a particular IP address. For example,The computer can say, "Who is 192.168.0.254". Using the information above, my default gateway is 192.168.0.254 and say "I am" 00-90-4B-F1-6E-4A "192.168.0.254". You send the MAC address. That the MAC address then in what is called a (ARP) Address Resolution Protocol table on your computer. You can use this information to the command prompt like you did above and typing "arp-a". You can obtain information such as the following:

Internet Address Physical AddressType

192.168.0.49 00-12-17-5C-A2-27 dynamic

192.168.0.109 00-12-17-5C-A2-27 dynamic

192.168.0.112 00-0C-76-93-94-b2 dynamic

192.168.0.254 00-0E-2E-2e-15-61 dynamic

How can a hacker use MAC addresses in an attack

You will notice that the IP addresses and the right of their MAC addresses. Without this information, without the MAC address, it would not be reading this right now. MAC addresses are not routable, such as IP addresses. They work on localor private network. However, the devices on the Internet, to perform the same tasks. Routers and switches keep a list of their colleagues MAC address devices such as computers and devices on your home or office network. I mentioned that MAC addresses can be modified to meet demand. For example, if I'm on your corporate network and you had an internal Web server that took personal information as input, I could tell the computer to my laptop for the websitebroadcasting my MAC address with the real web server IP address. I would do if the computer asks, "Who is the" Real Web Server ". I could set up a fake web server that looks just like the real thing, and start gathering information that the real web servers normally collect. You can see how it can be dangerous.

Conclusion

There are many other simple ways to protect your MAC address, but can be a bit 'of confusion if you have more than oneinternal network. Most external USB or PCMCIA wired and wireless Ethernet cards have their MAC address printed on them. Where the wired or wireless network adapter in your computer, such as in laptops, the MAC address is sometimes printed on the bottom of the laptop. Even Desktop systems cards that are inserted in PCI slots have the MAC address printed on the Ethernet card.

You can print or publish this article free of charge as long as the bylines areincluded.

Original URL (the web version of this article)

http://www.defendingthenet.com/NewsLetters/FindingYourMACAddressOnWiredAndWirelessNetworkCards.htm

Friends Link : Network Tools Store. LOWER Prices

Monday, November 22, 2010

How to make your home computer network routers can be configured to help fight malware in 3 Easy Steps

We all have things we like. Often it is something we want to do or get. For some people it is something you would like to have or to have. Sometimes people seek to learn how to make someone or something. Maybe you want to protect your family from the dangers of online pornography and adult websites including, for example. Many people want. The fact is that, if you know what, that's not really difficult. To protect your family from the dangers of online pornographydestructive and other online threats by configuring the router home computer in three easy steps, this article will help you so.

To find the way to your router to OpenDNS's "Family Filter", used to combat malware to help in 3 easy steps, simply set up to find out more.

Step 1 - Open the configuration settings for the router at home.

The preferences you set in your Web browser, a URL with numbers (eg 192.168.0.1). This IP address is also knownas "default gateway", which is the first router you need to pass on the way to the Internet. Login here and enter your password .. The reason we have to do the domain name server (DNS server) that the computer to connect online to have a direct impact on the quality of your experience online .. You want to avoid this step for fear of messing up connection on-line or quality of service with your Internet Service Provider. Not to worry. Millions of peopleworldwide, including Fortune 500 companies, businesses of all sizes, schools, governments, libraries, and a growing number of home users have made the switch.

It will be very important to finish this first step with care, operate fully, efficiently and well. Failure to follow this first step will result in not being able to enjoy the benefits of OpenDNS's "Family Filter".

Step 2 - Add the OpenDNS DNS server to your list.

Analysis for 'letters DNS next to a field that the numbers two or three sets of numbers, each divided into four groups of 1-3. It would be as follows: 68.64.229.28 68.64.229.29 and the like. Be careful to avoid looking in the wrong part of the configuration settings and to obtain quickly, without double check in this position.

Step 3 - Enter the addresses of the OpenDNS servers as the DNS server settings.

The first DNSServer you want to get in is 208.67.222.123. The second DNS server that you put in 208.67.220.123. Click "Save" or "Apply". The main reason that this will be significant is that without this last step of your router searches the domain name are directed to the appropriate servers. If you configure this error, you may not be able to access the Internet at all until this is corrected.

What will be important to avoid getting in a hurry. Makerelax, and check your work. If an error occurs, start again with step 1, step 2, then Step 3, checking your work as you go. After considering a couple of times, it will become easier. Follow the above tips and you have little or no problems.

Then you configure the router network computer malware in 3 easy steps successfully and well, with the convenience and speed. And you can enjoy any advantage over the lineprotecting your family from online pornography and other malicious threats.

Related : Frequent Urination Causes Buy Chill Store

Monday, November 15, 2010

How to make a Windows NTP Network Time Server Configuration

computer synchronization is very important in modern computer networks, precision and time synchronization is critical in many applications, particularly time sensitive operations. Imagine buying an airline seat only to be told at the airport that the ticket was sold twice because it was then purchased a computer that had a slower clock!

Modern computers have internal clocks called Real Time Clock chips (RTC) that provide time and date. Thischips are battery backed so that even during power outages, they can maintain time but personal computers are not designed to be perfect clocks. Their design is optimized for mass production and low cost rather than maintaining accurate time.

For many applications, can be quite adequate, although many of these machines need time to be synchronized with other PCs on a network and the computers are not synchronized with each other problems can arise, such as file sharing networkor, in some environments even fraud!

Microsoft Windows 2000, a time synchronization utility built into the operating system called Windows Time (W32Time.exe) that can be configured to operate as a network server. Microsoft and others recommend that you configure a time server with a hardware source rather that the Internet where there is no authentication.

If you want to configure the Windows Time service to use the internal hardware clock, thenfirst check that w32time is located in the list of system services in the registry to check:

Click Start, Run and type regedit and click OK.

Locate and click the following registry entry:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Time

We strongly recommend that you back up the registry as serious problems can occur if you modify the registry, the changes to the registry is done at your own risk.

To begin the configuration of ainternal clock, click the following subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, right-click ReliableTimeSource, click Edit.

In the Edit DWORD Value, then type 1 in the Value data box, click OK

Close the Registry Editor

To restart the Windows Time service, Run (or alternatively use the Command Prompt).

Type: net stop w32time & & net start w32time

Then press Enter.

Onlocal reset 'time the computer, type the following on all computers except the time server which must not be synchronized with itself:

w32tm-s

Configuring the Windows Time service to use an external time source, regedit, click Start, Run, and type and then click OK.

Locate the following subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, click Type then click Edit Edit Value, type NTP in the Value data boxbox and click OK.

Now, in the right pane, right-click ReliableTimeSource, click Edit.

In Edit DWORD Value data box, type 0, click OK.

NtpServer right mouse button in the right pane, click Edit.

In Edit Value, type the Domain Name System (DNS), each DNS must be unique.

Now click on OK.

For Windows 2000 Service Pack 4 only the time correction settings to do thisfind:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, right-click MaxAllowedClockErrInSecs, and then click Modify the Edit DWORD Value box, a second time in seconds the maximum difference between the local clock and the time received from the NTP server types should be considered as a valid new time.

Click OK.

To find the polling interval:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

Inthe right pane, right-click the period, and then click Edit.

In Edit DWORD Value data box, type 24 then click OK

Close the Registry Editor

Click Start, then Run and type the following command and press Enter:

Net stop w32time & & net start w32time

the local 'Recovery time computer, type the following on all computers except the time server which must not be synchronized with itself:

Network Time Protocol (NTP) is an Internet protocol used totransfer of accurate time information for the time, so that an exact time can be obtained

For the Network Time Protocol, NTPServer, locate and click:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpServer

In the right pane, click Enabled, and then click Edit.

In the Edit DWORD Value, type 1 under Value data, click OK.

Now go back and click onon

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParametersNtpServer

In the right pane, click NtpServer, and then click Edit in the Edit DWORD Value data, type in the right pane, click NtpServer, and then click Edit in the Edit DWORD Value data, type the domain name system ( DNS), each DNS must be unique and need 0x1 to the end of each DNS name otherwise changes will have no effect.

Now click on OK.

Identification andClick on the following

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpClientSpecialPollInterval

In the right pane, special poll interval right mouse button, click Modify.

In Edit DWORD Value data box, type the number of seconds for each poll, ie 900 to poll every 15 minutes, and then click OK.

To configure the correct settings, found:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Timeconfig

In the rightRight click MaxPosPhaseCorrection, and change, in the Edit DWORD Value, under Base, click Decimal, under Value data, type a time in seconds as 3600 (one hour) and then click OK.

Now go back and click:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Timeconfig

In the right pane, right-click MaxNegPhaseCorrection, and then click Change.

In the Edit DWORD Value box, under Base, click Decimal, type in the data value of the time in seconds that you want to poll such as 3600 (polls inhour)

Close the Registry Editor

Now that Windows Time Service, click Start, Run (or alternatively use the Command Prompt) and type reboot:

net stop w32time & & net start w32time

And on any computer other than the time server, type:

W32tm / s

And this is the server which should now be up and running.

Friends Link : Virtual Space

Friday, November 5, 2010

CompTIA Network + Certification Exam Tutorial: DHCP and DHCP relay agents

CompTIA Network + exam as a candidate, you're probably familiar with DHCP - but just in case, here we will review bases DHCP, and then a discussion of DHCP relay agents to go.

When it comes to assign an IP address of all PCs in our network, along with their network masks, DNS server location, and more, we have two choices on how to do it:

Or go to each workstation and statically configure the workstation

Or go to each workstation andall set to use DHCP

What we have here is the classic argument "static vs. dynamic". I do not want you think I'm lazy, but it will be a dynamic way of doing things almost every break.

One might ask why it matters, because both methods include a visit to every workstation. You're right about this, and although it's much faster to configure a workstation to mask gets its IP address from a DHCP server and then configure the IP address and the entirestatic form, the real benefits come when the network changes.

And from me - the network will change. The hosts clear, add the host, and if the previous operation did not plan for future growth, the day may come when you have the numbering system for IP network for change. The choice was originally between the static and DHCP configuration will determine how easy the change will come.

o If the network is statically configured, younow every workplace and their IP address to the new regime to change.

o If the network with DHCP, you only need to change the pattern of the network on the DHCP server and allow the workstations to get their new addresses dynamically.

Believe me, I run IP address changes, both in fashion and I assume DHCP every time! Avoid static IP address assignments also cuts the likelihood that the two machines on your network are assigned the same IPaddress.

As host gets an IP address via DHCP is not a permanent part of the host. The address is actually leased from a DHCP server. We walk through the DHCP process from the point of view the array of view.

The primary DHCP client boots and sends a DHCP Discover packet on the network. The landlord does to "discover" a DHCP server or servers. Explore this packet is a transmission of a Layer 3 IP destination address is255.255.255.255.

Each package includes a DHCP server responds with this broadcast a DHCP server, and is an IP address and a mask that is offered. The proposal also includes a subnet mask DHCP, the IP address from the DHCP server sending the response and how long the host can) keep this address (the DHCP lease time.

If multiple DHCP servers happen to hear this broadcast, each have an IP address.

The DHCP client to accept the first offer isreceives. It does this by sending another broadcast a DHCP request packet.

The server that the DHCP server offer is accepted, it will send an acknowledgment DHCP, DNS, which contains the rest of the information that the host to the demands of work, including the location of one. The DHCP server pool made the offer was not accepted, it returns the IP address offered to its range of assignable addresses, the address.

I made several referencesIn this chapter on DHCP packets are broadcast. Remember that the device forwards broadcast network connectivity? That's right, it's our old friend, the router!

If a PC is on one side of the DHCP server and router is on the other hand, we have a problem. The first is a broadcast DHCP Discover packet, and sends the router does not broadcast to the DHCP server. Fortunately, this does not mean that we all need a DHCP serversubnet in the network, because we can configure the router as a DHCP relay agent.

A DHCP Relay Agent DHCP server DHCP requests to send. You can also configure a Windows server as a DHCP relay agent. Of course, the relay agent on the same physical segment as the hosts can not reach the DHCP server - not on the same segment as the DHCP server itself.

Configuring a router as a DHCP relay agent is very differentconfiguration of a Windows server and the network + exam does not require the user to configure it. Need to know why the need for a relay agent there, and you need to configure your network, always check the vendor documentation.

Related : Corrugated Plastic Compare Price Store Spark Energy

Sunday, October 24, 2010

The dangers of leaving your unsecured wireless network

If the search for wireless networks in a busy city where you would be surprised at how many unsecured networks, see, many people are not aware of the dangers, but I would like these sketches.

Why I am referring to a unsecured wireless network that is accessible without the need for a network key, even if WEP is terribly insecure I will not even cover its weaknesses in this article. Provide an attacker in a series that can connect to unsecuredwireless network and the local network infrastructure. Ok, so now what? The attack would have a scan on the IP subnet to determine what is currently connected to the network. At this point the attacker can perform several scans (port scans, and so on) against these targets. It should be noted that this type of scan would not be possible outside the network as a router usually acts as a firewall and only forward traffic to the ports assigned to transmit.

Withthe above in mind, you run the risk of certain exploits as a striker is a part of your network, what services are dependent on use and if you do not have a software firewall in place, but the following are the most serious exploits that are the real dangers that your privacy and confidential information possible, and in general a software firewall will not protect you against this danger.

ARP poisoning - To be placed byallows an attacker to "put down" like a computer or other device, usually your router! This is done simply by sending a certain amount of ARP replies to the victim say that is the MAC address of the router. The victim then updates the ARP table and sends all traffic destined for the router to the attackers MAC address. In this way the attack can then monitor all traffic coming to and from the victim. This should explain why the risk is very low. Anotherconfidential information (username, password) are sent over the Internet in plain text or with weak encryption, allowing the attacker to your email account or other websites that are using compromised. There is also the problem of the attacker almost everything can be done online! including all MSN conversations, etc.

DHCP spoofing - This exploit requires a bit 'more patience in the name of the attackers, however, if implemented could be very bad news forvictim. The attacker creates a DHCP server on their system, when a new user is online address where the card is automatically set to an IP, DHCP server, the attackers attempt to provide a DHCP packet before the router is, if the victim accepts the request the attacker can include all the details they want, usually their IP address as gateway and DNS server (s) of these problems are presented below.

DNS Poisoning -This is the most serious form of abuse, the attacker can do this in two ways. The first is explained above, the second is for the attacker to gain access to the router (unsecured networks are most in default, this means that the password for the router is usually standard and can be easily guessed or found online! ) And that change the DNS server it uses for one of the attackers (this could be a classroom on the attackers machine, or a rogue statehosted elsewhere) All the attacker needs to do now is create a DNS record to redirect the victim to rogue imitations of websites, these usually look the same, but once the user name and password are entered and submitted, which are sent the striker in place of where they should be sent! The attacker can also send the details page aftewards correct site, then the attack is completely unnoticed. Obviously this is a very big problem, especiallyfor sites such as eBay, PayPal, and especially online banking.

These exploits are on the most common use for an attacker to obtain sensitive information, there are many, and much depends on the design of the machine on the network and victims.

In short, it is clear that leaving an unsecured wireless network can have serious consequences, and gives attackers an open door to their access to various confidential information. The following securityprecautions are recommended for maximum security for home users to give:

-Always protect your network with a WPA or WPA2, make sure that the key is long in length and complexity. Avoid WEP at all, is unnecessary and can be divided into a couple of minutes that an attacker has a good signal.

-Implement MAC address filtering, this only makes the movement of domains MAC addresses. While MAC addresses can be spoofed, it can be a difficult process, as an attacker to intercept traffic and anaylseframe headers for the source / destination MAC address of an authenticated client to see, this can be very difficult for a customer associates.

t-Don 'your SSID broadcast, but that alone will not stop an attacker, it is an extra layer of security.

-Use a software firewall, I recommend Agnitum Outpost.

Although no system can ever be 100% sure, it is important to implement security as far as possible to prevent attacks to exploit. With the abovepoints instead of a striker has been a very difficult time gaining access to the network.

Recommend : Video Cards Store. LOWER Prices HTC Phone Store Vulnerability Security

Thursday, September 30, 2010

Commands to troubleshoot network problems - you should know this

IPCONFIG. Abbreviation for Internet Protocol configuration, use ipconfig on the windows to the configuration screen of the PCP / IP, including IP addresses, subnet mask, default gateway, DNS server ...

Ipconfig is a command such as problem solving, as shown below

ipconfig / release is used to release the IP configuration of your computer, and prepares the network for a new TCP / IP for.
renew ip config / network with the newConfiguring TCP / IP.

PING. Short for Packet Internet Groper is used to test connectivity between two network devices. The receiver sends an Internet Control Message Protocol, known as an ICMP echo request, the destination node then responds with an ICMP Echo Reply.

PING 127.0.0.1 The IP address is used in combination with the computer to test ping the loopback address. The tool is very useful, and would be the firstto try to network problems never arise. The IP address 127.0.0.1 is a class that the reserve in order to test the network and TCP / IP stack is working fine.

Traceroute and tracert in Windows used to display the location of an IP packet from the source to the destination computer.

TELNET (Telecommunication Network). This is a command used to access another computer remotely. Also known as commandrequest, it is widely used by network administrators. A Telnet application may be accepted or rejected by the remote computer, with the consent may be required for a user name and password. The example below:

Microsoft Telnet> o

(To) 192.168.1.1

Connecting to 192.168.1.1 ...

The telnet command is used on Windows 7, and may be different on other operating systems. Telnet is not enabled by default on Windows 7 and Windows XP, you mustdone through the Control Panel.

Nslookup. Often used by network administrators, nslookup command is a tool used for DNS (Domain Name System) testing and troubleshooting. It is advisable to learn how DNS works before using this command. The example below:

C: \ Users \ Berbie> nslookup "only to illustrate"

Default Server: SE572

Address: 192.168.1.1

Host Name. Used in a truth of platforms, the command usedset up or find the name of a computer or other network device. An example under the windows:

C: \ Users \ Berbie hostname>

Berber PC

ARP. Short for Address Resolution Protocol, ARP is used to find a MAC address or physical address known only when the IP address. The example below:

C: \ arp> Users \ Berbie-a

Interface: 192.168.1.11 --- 0xb

Internet Address Physical Address Type

192.168.1.500-01-E3-EF-69-B0 dynamic

192.168.1.255 FF-FF-FF-FF-FF-FF static

224.0.0.22 01-00-5e-00-00-16 static

network commands are great tools used by computer and network administrators to run the network. The list of commands shown and described above is not exhaustive, there are many more and you should do some research on your own. We saw the basic commands that could help solve the problemswithin the home network or medium.

Thanks To : All In Ones Printers Store

Saturday, September 25, 2010

How to Create a Windows NTP Network Time Server Configuration

Synchronization of computer is very important in modern computer networks, precision and timing is crucial in many applications, particularly time sensitive operations. Imagine buying an airline seat only to hear at the airport that the ticket was sold twice because it was then purchased a computer that had a slower clock!

modern computers have internal clocks called Real Time Clock chips (RTC), the date and information. Thischips supported the battery so that even during power outages, may time but personal computers are not designed to be perfect to keep the clocks. Their design has been optimized for mass production and low cost rather than maintaining accurate time.

For many applications this can be quite adequate, but often need time machines to be synchronized with other PCs on a network and when computers are not synchronized with every other problem may arise, Such as file-sharing networksor, in some environments even fraud!

Microsoft Windows 2000, a time synchronization tool built into the operating system called Windows Time (W32Time.exe) that can be configured to operate as a network server. Strongly Microsoft and others recommend a server when configured with a hardware source instead Internet, where there is no authentication.

If you configure the Windows Time service to the internal hardware clock, usefirst make sure W32Time is the list of system services in the registry to verify:

Click Start, Run and type regedit and click OK.

Locate and click the following registry entry:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Time

It is strongly recommended that you back up the registry as serious problems can occur if you modify the registry incorrectly, modifications to the registry at your own risk.

To begin configuring ainternal clock, click the following subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, click ReliableTimeSource, click Change.

In the Edit DWORD Value, type 1 in the Value data box, click OK

Close the Registry Editor

To start the Windows Time Service click Start, Run (or alternatively use the operations command prompt).

Type net stop w32time & & net start W32Time

Then press Enter.

Alocal reset 'time on the computer, type the following on all computers except the time server which must not be synchronized with itself:

w32tm-s

To configure the Windows Time service to an external source, click Start, Run, type regedit and then click OK.

Locate the following subkey:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, click Type then click Modify, in edit Value type NTP in the Value dataand click OK.

Now, in the right pane, right-click ReliableTimeSource, click Change.

In the Edit DWORD Value window, under Value data, type 0, click OK.

NtpServer right mouse button in the right pane, click Edit.

In the Edit DWORD Value, type the Domain Name System (DNS), DNS, each unique.

Click OK.

For Windows 2000 Service Pack 4, set the settings to make this correctionfound:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

In the right pane, click MaxAllowedClockErrInSecs right, then change the Edit DWORD Value box, type a time when the second maximum number of seconds difference between the local clock and the received time from the NTP server to be considered a valid new time.

Click OK.

To find the polling interval:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParameters

Inright pane, click Period, then click Edit.

In the Edit DWORD Value window, under Value data, type 24 then click OK

Close the Registry Editor

Click Start, then Run and type the following and press Enter:

Net stop w32time & & net start W32Time

To reset the local 'time of the computer, type the following on all computers except the time server which must not be synchronized with itself:

Network Time Protocol (NTP) is an Internet protocol used toaccurate transfer of time, time that the information together, so an exact time can be obtained

For the Network Time Protocol, NTPServer, locate and click:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpServer

In the right pane, click Enabled, then click Edit.

In the Edit DWORD Value, type 1 under Value data, click OK.

Now go back and clickon

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeParametersNtpServer

In the right pane, click NtpServer, then change the Edit DWORD Value data, type in the right pane, click NtpServer, then change the Edit DWORD Value data, type the Domain Name System (DNS), each DNS must be unique and need 0x1 to the end of each DNS name otherwise changes will not take effect.

Click OK.

Research andClick on the following

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32TimeTimeProvidersNtpClientSpecialPollInterval

In the right pane, click Special Poll Interval, click Edit.

In the Edit DWORD Value window, under Value data, type the number of seconds you want for each poll, ie 900 will poll every 15 minutes, and then click OK.

To configure correction, found:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Timeconfig

LawMaxPosPhaseCorrection right mouse button, then change the Edit DWORD Value box, under Base, click Decimal, under Value data, type a time in seconds such as 3600 (one hour) then click OK.

Now go back and click:

HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesW32Timeconfig

In the right pane, click MaxNegPhaseCorrection, then change.

In the Edit DWORD Value window below, click Decimal in the Value data type the time in seconds that you want to poll such as 3600 (in pollshour)

Close the Registry Editor

Now it is time to restart Windows, click Start, Run (or alternatively use the command prompt facility) and type:

net stop w32time & & net start W32Time

And on each computer, other than the time server, type:

W32tm / s

And this is the time server should be up and running now.

Friends Link : Preview Games Console XBOX 360 Hardware Store Save!

Monday, September 6, 2010

Network Security - Little Known Threats

Little Known Network Security Threats

There are a number of common network security threats that can damage your network. Some prime examples include remote login capability, SMTP hijacking and backdoor entry to a computer network. There are however dozens of other ways someone can inadvertedly access your network and steal or damage your data. Here are just a few network security threats you should be aware of, whether you operate a private or corporate network.

DNS - DNS or denial of service involves a major attack on Websites. Usually this threat is reserved for large computer networks. When a denial of service attack occurs there is often little a company can do immediately to recover from the attack. When this happens a hacker connects to the server multiple times purposefully even though the hacker is denied access. Over time these repeated requests cause the system to slow and crash.

Macros - This is an application that allows someone to create a script of commands that can run on your network. These macros are capable of crashing computers and destroying data.

Virus - A computer virus is one of the most common threats any private or corporate network user faces. Fortunately viruses can usually be prevented using modern anti-viral software.

OS bugs - Operating system bugs occur when backdoors are accessed to operating systems. Usually a backdoor is left open to attacks when inadequate network security systems are in place. Fortunately adequate network security including use of firewalls can help limit ones exposure to this security threat.

See Also : Bulk Email Friendly

Wednesday, September 1, 2010

CompTIA Network+ Certification Exam Tutorial: DHCP and DHCP Relay Agents

As a CompTIA Network+ exam candidate, you're probably familiar with DHCP - but just in case, we're going to review DHCP basics here and then go into a discussion of DHCP Relay Agents.

When it comes to assigning an IP address to all the PCs on our network, along with their network mask, DNS server location, and more, we've got two choices on how to do it:

o Go to every workstation and configure the workstation statically

o Go to every workstation and configure them all to use DHCP

What we have here is the classic "static vs. dynamic" argument. I don't want you to think I'm lazy, but I'll take the dynamic way of doing things almost every single time.

You may wonder why it matters, since both methods involve visiting each workstation. You're right about that, and even though it's a lot quicker to configure a workstation to get its IP address and mask from a DHCP server than it is to configure the entire IP address and mask statically, the real benefits come in when the network changes.

And take it from me - your network will change. You'll remove hosts, you'll add hosts, and if the previous network manager didn't plan for future growth, the day may come when you've got to change the IP numbering scheme for your network. The choice that was made originally between static configuration and DHCP will then determine how easy the change will be.

o If the network was statically configured, you will now have to go to every single workstation and change their IP addressing to the new scheme.

o If the network is using DHCP, you simply change the networking scheme on the DHCP server and allow the workstations to get their new addresses dynamically.

Believe me, I've performed IP address changes in both fashions, and I'll take DHCP every time! Avoiding static IP address assignments also cuts down on the chances of two hosts in your network being assigned the same IP address.

When hosts receive an IP address from DHCP, it does not belong to that host permanently. The address is actually leased from a DHCP server. Let's walk through the DHCP process from the host's point of view.

First, the DHCP Client boots up, and sends a DHCP Discover packet onto the network. The host does this in order to "Discover" a DHCP server or servers. This Discover packet is a Level 3 broadcast, which has a destination IP address of 255.255.255.255.

Every DHCP Server that hears this broadcast will respond with a DHCP Offer, and it's an IP address and mask that is being offered. The DHCP Offer also includes a subnet mask, the IP address of the DHCP Server sending the response, and how long the host can keep this address (the DHCP lease duration).

If multiple DHCP Servers happen to hear this broadcast, they will each offer an IP address.

The DHCP Client will accept the first offer it receives. It does so by sending another broadcast, a DHCP Request packet.

The DHCP Server that made the offer that's being accepted will now send a DHCP Acknowledgement, which contains the rest of the information the host needs to function, including the location of a DNS server. The DHCP Server that made the offer that was not accepted will return the offered IP address to its range of assignable addresses, its address pool.

I made several mentions in this section about these DHCP packets being broadcasts. Do you remember which network connectivity device does not forward broadcasts? That's right, it's our old friend, the router!

If a PC is on one side of the router and the DHCP Server is on another side, we've got a problem. The initial DHCP Discover packet is a broadcast, and the router will not forward that broadcast to the DHCP Server. Luckily, this doesn't mean that we need a DHCP server on every single subnet on the network, because we can configure the router as a DHCP Relay Agent.

A DHCP Relay Agent will forward DHCP Requests to the DHCP Server. You can also configure a Windows server as a DHCP Relay Agent. Naturally, the Relay Agent must be on the same physical segment as the hosts that cannot reach the DHCP Server - never put it on the same segment as the DHCP Server itself.

Configuring a router as a DHCP Relay Agent is a lot different than configuring a Windows server, and your Network+ exam will not require you to configure either. You should know why the need for a Relay Agent exists, though, and should you need to configure one on your network, always check the vendor's documentation.

Related : PDA Mobiles Spark Energy

Monday, August 30, 2010

Wireless Network Trouble Shooting

Wireless Network Trouble Shooting

1. Wireless Adapter - First check to see if your wireless adapter is on and working properly. If you are using a PCMICA wireless adapter ensure that the card is pressed completely in. If the wireless adapter card was not plugged in when you started your laptop you may want to restart your computer for a fresh start. If you are using a laptop with a built in wireless adapter. What Wireless Network - Check the bottom right hand task bar to see if you are connected to a wireless network. Many people are connected to the wrong wireless network with a weak signal or hardly any connectivity. You want to change your wireless adapter setting to choose Infrastructure access points only so you're not connecting to rogue wireless access points.

3. SSID and ME - Next check your wireless settings for the following: DO you have the correct SSID typed in, is your encryption key typed in correctly, does your wireless router and wireless adapter have the same security settings.

4. DHCP ME - If you don't have a manual TCP/IP address then your wireless router needs to have it's DHCP server turned on. Connected to your web interface and turn on your DHCP server. Next go to your wireless network icon in the bottom right hand corner and disable your wireless adapter and then enable it. This will renew your DHCP request to the routers DHCP server.

5. PING!- Next we will use a command line function called PING. Type "cmd" in the run box, this will bring up your DOS window. Now type in ping and then type in the TCP/IP addressof your default gateway. If you have not changed it your default gateway's ip address should be 192.168.1.1 or 192.168.0.1. If you receive a reply then you know that you are connected properly to your router.

6. WWW...WHAT - Now try and surf the web. Go to google.com or another simple page. If nothing comes up then you might have a manually configured IP address with the correct DNS servers entered. Connect to your wireless routers web interface and check the status. You are looking for the multiple DNS server IP address. Copy these IP addresses into you adapters TCP/IP settings and hit ok.

7. Google ME - Once your DNS servers are entered you should be able to surf the net. If you still can't surf the net try restarting your computer and check you cables again to make sure you haven't missed something.

Thanks To : Blu Ray Disks Sony Bravia Save! Store

Tuesday, August 24, 2010

Your VPN Doctor for Virtual Private Network Troubleshooting VPN Guide

Here are some troubleshooting guides for particular topics.

(1) Your Virtual Network Connection

(2) VPN Troubleshooting Error Messages

(3) VPN Modems Troubleshooting Guide

(4) VPN ISP Troubleshooting Guide.

(1) Your Virtual Private Network Connection

Having trouble connecting to the Internet at home try these steps before calling for help.

1. Do you have an IP address? Try ipconfig /all. If you do not have an IP address reboot your PC. If that doesnt work power cycle your Cable/DSL modem and routers and reboot your PC again after the network devices are up and stable. Be sure all of your network cables are plugged in tight.

2. After your PC reboots check that your network adapter is active and packets are flowing. Perform the ipconfig /all check again.

3. Check your connectivity by pinging several Internet sites. If that does not work, ping the loopback address 127.0.0.1. If that fails, your adapter may not be working or it is not properly configured.

To check your IP address. From command prompt enter ipconfig /all (as shown in the picture) you should see an IP Address and several DNS Server addresses. The domain name system (DNS) is the way that Internet domain names are located and translated into IP addresses and is required for browsing the Internet.

Ping 127.0.0.1 - loopback Test (as shown in the picture). The loopback test is used to check if the IP stack is responding. If it times out or you get an error the problem may occur if any one or more of the following conditions is true:

*The TCP drivers are corrupted

*The network adapter is not working

*Another service is interfering with IP

Check your network adapter, click the Start menu, Settings, Control Panel, and select Network Connections. Double click on the Local Area Connection or the Wireless Adapter whichever one you are using. Be sure its Connected. If you have multiple network cards disable the one you are not using.

There should be Packets displayed in both the Sent and Received counters. If the Received counter is 0 check that the adapter has an IP address. Select Properties.

Click the check boxes for Show icon and Notify me below. A twin PC icon will appear on the lower right portion of the taskbar in the tray area and will flash while sending and receiving packets. You can place your mouse over the icon to get the status and click on it to get more details.

Tracert displays the connection path to the target location and the number of hops. Each hop is the trip from one router to another. Tracert is a handy tool both for understanding where problems are in the network and for determining latency between hops.

Ping is used to determine whether a host exists and is active on the network and can determine the round trip time to the device. You can enter a host name or an IP address if you know it. If the request times out then the host is not reachable because it's offline or there is a problem with the connection. Try several sites, if none work then ping the loopback address 127.0.0.1 Also, if your DNS is not working or properly configured you can only ping the host with an IP address and you will not be able to browse the Internet.

If you are having intermittent problems, perform a ping -t for 5 to 6 minutes then hit CTRL C to see the results of the test to determine if you are dropping network packets (lost packets). If you are, this usually indicates an ISP problem or Cable/DSL modem problem. See VPN ISP Troubleshooting Guide

(2) VPN Troubleshooting Error Messages

Q1 Error Message: Remote Host not responding: or Unable to Resolve the IP address of the Remote Server

Cause: This indicates that the Contivity VPN Switch never responded to the connection attempt. The problem could either be with the Contivity switch itself, (switch may be down) or your machine may be having a problem resolving the IP address.

Action: Try pinging your destination name (Example: VPN.something.com). If you received a message that says "Request Timed Out" from the ping command, call your ISP to make sure that their DNS is functioning correctly.

Q2 Error Message: Maximum number of sessions reached

Cause: This indicates that the maximum number of users for the account you are using are currently logged on.

Action: If you are the only user with VPN to your account, it is possible to get this error if you restarted a connection immediately after losing the dial-up connection to your ISP. This is because the Contivity VPN Switch takes up to one hour to determine that your connection has been dropped and log you off from your account.

Q3 Error Message: Login failed, Please consult the switch log for further information

Cause: The User Name or the Password is incorrect for the user name entered.

Action: Verify that the User Name you entered is correct and retype the Password before trying the connection again.

Q4 Error Message: The physical connection has been lost

Cause: Your connection to your ISP was disconnected.

Action: Re-establish your connection to your ISP before you re-establish the Contivity connection to the remote network.

Q5 Error Message: The secure Contivity connection has been lost

This message can result due to a number of different reasons, and there are several recommended actions you can take to try and re-connect.

Cause(s):

If you receive this error before the client connects then something is blocking a necessary port (such as ESP port 50). This can result if your firewall is not configured properly and is restricting the necessary port(s).

If you receive this error during a connection and you suddenly get the error it may mean one of the following:

1. Something closed the connection;

2. The VPN Contivity switch where you were trying to connect to thought your client was down or timed out;

3. Your local ISP did something that interrupted your network connection long enough for the VPN Contivity switch to identify your client was not responding;

4. The VPN Contivity switch that you are connected to has either logged your connection off or the Switch is no longer responding, or a device that does not support IPSEC NAT Traversal is causing the connection failure.

Action(s):

1. Try re-establishing the Contivity connection by clicking the Connect button. If this works, the connection was probably lost due to the Idle Timeout configured on the Contivity VPN Switch. If no data is transferred through the Contivity connection for a long period of time, 15 minutes or more, the Contivity VPN Switch automatically disconnects the connection;

2. If you were unable to successfully re-establish the Contivity Connection, the dial-up connection may be preventing data from traveling between the Contivity VPN Client and the Contivity VPN Switch. Hang up the dial-up connection and reconnect before you try to re-establish a connection to the Contivity VPN Switch;

3. If you are still unable to connect to the Contivity VPN Switch, open a Command Prompt and try pinging the Contivity VPN Switch using the host name or address that you specified in the Destination field.

(a) If you receive a "Destination Unreachable error" there is a routing problem at the ISP.

(b) If you receive a "Request Timed Out" error message, the Contivity VPN Switch is probably not available, and you should contact your Network Administrator.

4. If you keep getting this message and are unable to connect, then it may indicate that the Contivity VPN Switch is unable to communicate with the client because it is behind some kind of NAT (Network Address Translation) device. NAT (Network Address Translation) Traversal allows a number of devices on a private network to access the Internet simultaneously without each requiring its own external IP address. Most hotels and airports that provide Internet connectivity use NAT to connect to the Internet.

Q6 Error Message: Cannot Alter Routing Table

Cause: Message means the you the user, an application on your machine, or your ISP attempted to change the routing table via an ICMP redirect attempt and it was not successful. The client detects the attempt to make the change, determines it's a security breach and shuts down the client's connection. Any time you make a VPN connection, you cannot change the routing table, because the VPN Client views this as a security risk and you will get disconnected.

Some applications require an ICMP redirection in order to work such as a game or other third party software.

Action: If you receive this error and cant connect due to an ICMP redirect attempt, shut down any other applications you are using which may be causing the ICMP redirect attempt. If it is the ISP that is doing it, you will need to block the ICMP redirect request. You can identify that ICMP redirect has occurred, by seeing a message saying there has been an IP address routing table change.

Q7 Error Message: Receiving Banner Text Information

Cause: Message means you are experiencing a Banner Sock issue, and will see a window displaying the "Receiving Banner Text" message and then gets disconnected.

Actions:

1. Disable the firewall completely to test. This is a port 500 issue and often means that the you have a personal Firewall that is blocking port 500 or you have a router that does not support IPSEC pass-through, and the you are connecting to a VPN switch that does not have NAT Traversal enabled.

2. If using wireless, temporarily remove Wireless from the picture and focus on the Ethernet card. Check the Ethernet card speed and duplex parameters and then make sure that the hub, switch, or router that is on the other end has the same parameters. If not, the VPN connection will drop as the link goes up and down, or due to a large number of errors on the port from a duplex and or speed mismatch.

3. Firewall that blocks the connection, such that system will crash. (This will rarely happen) NSDF (Norton Symantec Desktop Firewall) and NSPF (Norton Symantec Personal Firewall) can do this though, if you do not trust the IP address of the VPN connection.

If you do not trust the VPN address of the VPN client, the firewall will cause you to crash. In your Internet browser click on "Tools > Internet Options > Security > Trusted Sites > Sites" and add the destination VPN address(es) to your trusted sites.

Q8 Error Message: You already have the maximum number of adapters installed

Cause: You may have installed to many virtual adapters in your IP Stack

Actions:

1. Remove any unnecessary adapters;

2. Create multiple boot scenarios disabling the adapters that are not required for that function;

3. You may also get Banner Sock errors on Win 95 & 98 units with this condition;

4. For more information, see this Microsoft article: KB217744: Unable to Bind Protocols to More Than 5 Network Adapters (copy and paste into the search tool bar > enter).

Q9 Upgrade Errors: The following are some errors that may occur when trying to upgrade / install the Nortel VPN Client 4.65

Error (1): Failed to get Registry key value for NT_IPSECSHM

Cause: This is caused because an important registry key that cannot be found in the system registry.

Actions:

1. Uninstall and Reinstall the VPN Software

Error (2): Login Failure due to: Driver Failure

Cause: This is generally caused by either not having Admin rights to the PC or by trying to install/use a Nortel VPN client that predates the operating system.

Actions:

1. Ensure that you have admin rights to the PC.

2. Update/Install the most current version of the Nortel VPN client.

Error (3): Create socket failed with 10048.

Cause: This problem generally will occur whenever you have another VPN client software installed on the system. The most noted conflicting clients are: AOL, Cisco VPN Client(s), SSH Sentinel and PGP.

Actions:

1. Removing these clients will in most cases, resolve the issue.

(3) VPN Modems Troubleshooting Guide

Q1 Are Cable Modems supported for VPN Access?

Yes, you can use cable modems for VPN access. However you must be aware of the following conditions and be able to work within them:

*Some cable modems require that you log into an NT network to get authenticated.

*Some cable modems use a client similar to the Extranet Client for VPN and both will not run at the same time.

*Some cable modem Contracts/Acceptable Use Policies specify that you cannot use them for business purposes or they want to charge you another fee to use them for business purposes. Make sure you read your contract thoroughly.

*Your Cable modem provider is your ISP. Please see the VPN-connection-guide.html">ISP Troubleshooting Guide for more information.

Q2 Why does my modem seem to perform erratically?

Always make sure that you do not let the operating system select a generic modem. If required, go to the appropriate web site for the vendor of the modem and get the updated INF file so that the proper parameters are configured for the modem.

Q3 Why do I always seem to get a slower connection speed than others with the same modem?

1. Always check the modem configuration to verify that its maximum speed has been selected.

2. It is common when auto-installing modems that the highest speed is not selected automatically.

3. Do not check the box that says run at maximum speed only.

Q4 I plugged my modem into the phone line at the hotel or customers office and now it does not work.

Always make sure that the phone line you are plugging into when visiting somewhere is an analog line not a digital one. Plugging into a digital line can permanently damage your modem, requiring a replacement unit. To avoid these situations please contact the local site phone support personnel.

Q5 Why cant I get a 56Kb V.90 connection from some locations that I go to?

Here are some of the reasons why you might not get a 56K connection:

1. You are located more than 3 ½ miles from your telephone companys central office (CO).

2. A SLICK or Subscriber Loop System is used in your area.

3. You are calling from a digital PBX system, which creates a Digital to Analog conversion and then an Analog to Digital conversion.

4. Your line contains digital pads or Robbed Bit Signaling (RBS), which can degrade your connection speeds.

5. Your wiring may be of poor quality.

6. Your modem's firmware may not be up-to-date. Check that your modem has the newest V.90 code installed with all the patches from the vendor's web site.

Q6 Why cant I get higher speed on my 56K v.90 modem into some NAG?

Here are some possible reasons:

1. A 56k v.90 modem is asymmetric by design where download speed can be as much as 56k but upload speed will be up to 33.6bps. For 56k to work, there must be only one analog-to-digital (A/D) conversion in your local phone loop. Thus when modems at both ends are analogue, 56k speeds will never be achieved as most PSTN exchanges run digital routing between the exchanges.

2. Some NAG sites use analog phone lines with Cisco and standard 56k modems, and most PC's dial-ups use a similar modem. Between the two modems, it limits the download speed to about 33.6kbps maximum.

3. Also, many users might experience lower connection speeds due to other reasons, such as more poor line quality. These factors will also contribute to the quality and speed of the line.

(4) VPN ISP Troubleshooting Guide

Q1 If you are getting the message "Unable to Resolve the IP address of the Remote Server. Verify the Host Name in the destination field is correct." when trying to connect with the Extranet Client.

Try pinging your destination name (Example: VPN.something.com) and if it fails call your ISP to make sure that their DNS is functioning correctly.

Q2 Why do I get No Domain Available when dialing my ISP?

On your Internet Service Providers (ISP) dial connection. Right click the mouse and select the properties button. Click on the Server Type tab and make sure that the Log On To Network box is unchecked.

Q3 Why do I seem to be running slowly through my VPN connection?

Try turning off the Software Compression option on your Internet Service Providers (ISP) dial connection as the VPN client has it's own compression. Right click the mouse and select the properties button. Click on the Server Type tab and uncheck the

Q4 I keep getting busy signals when trying to connect to my ISP, what should I do?

Contact your ISP giving the numbers you are trying to connect to. Many times you will find that can give you an alternate number not published yet that will work just fine. If not you may need to find another ISP that provides better service.

Q5 When configuring the dial icon for my ISP what should I put in the DNS/WINS settings?

Your ISP should supply you with the DNS/WINS settings of your dial connection. Most only give you DNS, in this case just leave the WINS settings blank.

Q6 Why when I load the Extranet Client on my PC and Winpoet is installed on my machine it crashes or does not work properly?

There are issues running Winpoet software on the PC with the Nortel Extranet (VPN) Client.

To repair your system, boot in safe mode and uninstall the Winpoet Software.

A simple solution is to install the Linksys BEFSR41 hardware router. It has a firmware PPPOE connector, which eliminates Winpoet from the PC and provides the added benefit a NAT firewall with the ability to hook up to three other PCs.

A second option is to find a PPPOE Client that does not interfere with VPN Clients.

Please See Your VPN Doctor for Picture Guide and further Details.

Need a Qiuck Fix, Tool, Trick or Tip? Your VPN Doctor has the Cure!

See Also : Mechanic Gloves Cool Automotive Save Price! Store

Monday, August 16, 2010

Seven Tips for Securing Your Organization's Network from Spam and Email Viruses

Providing security against email related threats has become a burden for most IT professionals in 2006. According to a recent study by Postini, spam and email viruses now make up to 80% of all emails sent out as compared to 50% in 2000. As a result, IT professionals now face a tougher challenge in providing network security for this amount of spam. IT professionals also have the disadvantage of defending against new forms of email threats such as spam zombies, directory harvest attacks, mass mailing trojans, as well as the latest email virus.

In this article, I have listed the seven most effective spam fighting tips for organizations with in-house mail servers. These seven tips are proven techniques I have used for my customers, partners and associates who wish to tighten their perimeter (network) security.

1. Firewall:

A firewall is your first line of defense against hackers, crackers, and spammers. Without a firewall, your network is a disaster waiting to happen and could give any novice hacker free reign over your network. If your organization has multiple Internet users, this tool is essential for securing your network.

2. Block Port 25:

On your firewall, allow outbound traffic on TCP port 25 for all mail servers. Block traffic on outbound TCP port 25 for all other computers and servers. On the Internet, TCP port 25 is used for email traffic through SMTP (Simple Mail Transport Protocol). Blocking this port is a good security practice and prevents mass mailing worms and spam zombies from sending mail from your users’ computers.

3. Managed Email Filtering:

Consider using a managed filtering solution such as Postini, Brightmail, or SpamSoap. Managed Email Filtering services quarantine spam, viruses, and email threats before reaching the email servers on your network. In comparison to desktop filters and server appliances, managed filtering services provide superior perimeter (network) protection by preventing delivery of spam and viruses to your network and servers.

4. Check Relay Setting:

A mail server’s relay setting controls which computers and servers are able to send SMTP email on your organization’s behalf. Check your settings and limit the IP address range to email users on your local network. Some mail servers have settings to limit email relay through authentication. If authentication-based relay is available, setup and configure it too. NOTE: If the relay is not set properly, spammers will be able to send email from your mail server. This exploit is commonly known as an “Open Relay” or a “Spam Relay.” Use the Open Relay test at [http://www.abuse.net/relay.htm] to check if spammers can relay mail from your server.

5. Black Lists:

Setup your mail server(s) with a black list. A black list (black hole list) is a database or listing of known spam sources. Most modern email servers can be configured to query inbound email against online blacklists. Messages originating from these sources can then be blocked. I recommend configuring your email server with SpamHaus blacklist. Spamhaus.org is an excellent free service to use. Some other good blacklists are DBSL and SpamCop.

6. Reverse DNS:

Reverse DNS (rDNS) associates an IP Address with a Domain Name. Most mail servers, as an anti-spam feature, often use a reverse DNS lookup to compare an email address domain name with its IP address. If the IP address found from the rDNS lookup does not match the domain name, it is probably spam. If you haven’t done so, setup and configure reverse DNS records on your DNS server.

7. Anti-Virus Scan:

There are many tools that provide adequate anti-virus protection for desktops at the workplace. Most anti-virus software is good at detecting viral threats that proliferate email spam such as mass mailing worms, trojans, and directory harvesters. Large organizations might want to use enterprise anti-spam software with management and monitoring tools that will allow tracking of network virus outbreaks.

Recommended Links:

- http://www.spam-x.com [Postini service – managed filtering, 1 to 500 users]

- http://www.postini.com [Postini service – managed filtering, 500+ users]

- [http://www.spamhaus.org] [Blacklist]

- http://www.dbsl.org [Blacklist]

- http://www.spamcop.net [Blacklist]

- [http://www.abuse.net/relay.htm] [Open relay test]

- http://www.dnsreport.com [DNS report/open relay test]

- http://www.dnsstuff.com [Spam database lookup and open relay test]

- [http://www.cnn.com/2004/TECH/ptech/02/17/spam.zombies.ap] [Spam Zombie Article]

Email viruses and related threats delivered through spam have cost businesses billions of dollars in expenses and lost productivity. Each spam email sent or received from your domain costs your organization money and bandwidth. By implementing these seven tips, your organization can reduce spam and recover costs.

This article: © Copyright 2006 Todd Green and free for republishing.

Friends Link : Buy Cheap Logitech Keyboards | LOWER Prices

Sunday, August 15, 2010

The Dangers Of Leaving Your Wireless Network Unsecured

If you were to browse for wireless networks in a busy city you would be surprised at how many unsecured networks you will find, many people are oblivious to the dangers, however I would like to outline these.

By unsecure I am referring to a wireless network that is accessible without the need for a network key, although WEP is horribly insecure also I will not be covering its vulnerabilities in this article. Providing an attacker is in range he can connect to an unsecured wireless network and become a part of the local network. Ok so now what? The attack could then run an ip scan on the subnet to establish what is currently connected to the network. At this point the attacker could run various scans (port scans and so on) against the targets. It should be noted that this kind of scan would not be possible from outside of the network as usually a router acts as a firewall and only forwards on traffic to ports that have been assigned for forwarding.

With the above in mind you are at risk to certain exploits if an attacker becomes a part of your local area network, these however are dependent upon what services you are running and if you have any software firewall in place, however the following are more serious exploits that are the real dangers that will jeopardize your privacy and possible confidential details, and generally a software firewall will NOT protect you from these.

ARP poisoning - To put it simply this exploit enables an attacker to 'pose' as another computer or device, usually your router! This can be done simply by sending a certain amount of arp replies to the victim saying that he has the MAC address of the router. The victim then updates its ARP table and sends all traffic destined for the router to the attackers MAC address. By doing this the attack can then monitor ALL traffic coming in and out of the victim. This needs very little explanation as to why it poses a risk. A lot of confidential details (usernames,passwords) are sent over the internet in plain text or with weak encryption, thus allowing the attacker to compromise your email accounts or other websites you use. There is also the problem of the attacker being able to view pretty much everything your doing online! including all your msn conversations etc.

DHCP spoofing - This exploit requires a little more patience on the attackers behalf however if executed it can be very bad news for the victim. The attacker creates a DHCP server on their system, when a new user comes online whose adapter is set to automatically assign an ip address; the attackers DHCP server attempts to offer a DHCP packet before the router does, if the victim acknowledges the request the attacker can include any details they want, usually their own IP address as the gateway and also DNS server(s) The problems of this are explained below.

DNS poisoning - This is the most serious type of exploit, the attacker can execute this in two ways. The first is explained above, the second is for the attacker to gain access to the router (most unsecured networks are left with default settings, this means the password for the router is usually default also and can easily be found online or guessed!) and then changing the DNS server that it uses to one of the attackers (this could be a local one on the attackers machine, or a rogue one hosted elsewhere) All the attacker needs to do now is create some rogue DNS records that redirect the victim to imitations of websites, usually these look identical however once the username and password are entered and submitted, they get sent to the attacker instead of where they should be sent! The attacker can even get the page to forward the details onto the correct site aftewards, therefore the attack going completely unnoticed. Obviously this is a very big problem especially for sites such as ebay, paypal, and especially online banking.

These exploits above are the most common for an attacker to use to gain confidential information, there are many more and a lot are dependent upon the setup of the network and victims machine.

In summary, it is clear to see that leaving a wireless network unsecure can have serious implications, and gives attackers an open door for them to gain access to all kinds of confidential information. The following security precautions are advised to give optimal security for home users:

-Always secure your network with a WPA or WPA2 key, make sure that the key is long in length and also complex. Avoid WEP at all costs, it is redundant and can be broken in minutes providing an attacker has a good signal.

-Implement MAC address filtering, this only allows traffic from registered MAC addresses. While MAC addresses can be spoofed, it can be a hard process as an attacker has to sniff traffic and anaylse frame headers to see source/target MAC addresses of an authenticated client, this can be very difficult for an unassociated client.

-Don't broadcast your SSID, while this on its own will not stop an attacker, it is an extra layer of security.

-Use a software firewall, I recommend Agnitum Outpost.

While no system in the world will ever be 100% secure, it is important to implement as many security precautions as possible to prevent attackers from exploiting. With the above points in place an attacker would have an extremely hard time ever gaining access to your network.

Thanks To : Network Attack Case, Information Blu-Ray Movies Store