Showing posts with label Network. Show all posts
Showing posts with label Network. Show all posts

Thursday, September 17, 2009

Way to watching your network with LANguard

Making sure your network is secure can be a daunting task. Here's how you can use LANguard Network Security Scanner to help get a handle on things.

Many tasks face a typical network administrator daily, from normal duties to -- in smaller shops -- user support. In situations like these, all the help an application can provide is welcome to relieve some of the daily work load of the administrator or support staff.

Enter LANguard Network Security Scanner from GFI, a multi-purpose tool designed to view and fix vulnerabilities are on your network. This article will look at the product as a whole, discuss pricing and availability, and then dive into the remaining features.

Note: During the installation process, you will be prompted to supply a domain administrator user account and password to assure that LANguard can properly access your network. You will also be asked to point LANguard at your e-mail server so notifications and alerts can be sent appropriately. For the purposes of this article, I will be running LANguard on a single Windows Vista PC, with local administrator credentials supplied.

The LANguard Network Security Scanner

The interface for LANguard Network Security Scanner (LNSS) displays a paned format with the list of tools on the left in an Explorer-style layout. The top pane shows the items being scanned with results; the bottom, the current progress. The default layout for a new installation of LNSS is shown in Figure A.

Figure A

The LNSS Console.

Note: Please click here to continue reading this article

How to Reinstall the TCP/IP Protocol

If you've worked on previous versions of Windows,
there are times when you need to completely reinstall the TCP/IP protocol stack.
This is typically due to corrupted files.

To do this with XP,
you need to run a small script:

netsh int ip reset [ log_file_name ]

the log_file_name needs to be specified.

e.g.
netsh int ip reset ip_reset.txt

How to limit your personal data in online directories

How to limit your personal data in online directories

Internet phone books, people-finding services, and other online directories make it almost impossible to keep your personal contact information entirely off the Web.

It's fairly easy for anyone to find your name, phone number, home address, or e-mail address—for business or social purposes, advertising or marketing, or even criminal intent.

Here are a few ways to help control the amount of personal information you give to the world.

How to Keep DNS servers from contributing to a DDoS attack

Is your public DNS server just waiting to participate in a distributed denial-of-service (DDoS) attack? If it's using recursion, then the answer is yes. DDoS and DNS attacks aren't new, but they're on the rise.

Using authoritative name service, DNS servers primarily advertise to the world the various records associated with the domain they serve. Because users prefer common names and networks prefer numbers, DNS servers handle the translation between what a user types in a browser—such as techrepublic.com—and the actual IP address the network understands.

The task of answering a query recursively is completely different. According to a US-CERT report, between 75 and 80 percent of all DNS servers can handle recursive requests.
Recursive DNS provide answers to queries for records by asking other DNS servers and providing that response to the client that made the request. Here's an example:

  1. A user enters www.techrepublic.com into a Web browser.
  2. The computer contacts its local DNS server to determine the IP address of www.techrepublic.com.
  3. The DNS server looks up www.techrepublic.com in its local tables (i.e., its cache) but does not find it listed.
  4. The DNS server sends a query to a root server for the IP address of www.techrepublic.com.
  5. The root server replies with a referral to the top-level domain (TLD) servers for www.techrepublic.com.
  6. The DNS server then contacts the TLD server to determine the IP address of www.techrepublic.com.
  7. The TLD server replies with a referral to the name server for www.techrepublic.com.
  8. The DNS server contacts the name server for www.techrepublic.com to determine the IP address.
  9. The name server checks a zone file that defines a CNAME record, which shows www.techrepublic.com is an alias of techrepublic.com.com. DNS returns both the CNAME and the A record for techrepublic.com.com
  10. The DNS server sends this response to the original client: techrepublic.com.com = 216.239.113.146 (with CNAME record www.techrepublic.com=techrepublic.com.com).

How can a recursive query become a DDoS attack? For the attack to work, the attacker needs to be in control of one DNS record.

He or she then populates the TXT field of that record with information. (The maximum size of the TXT field is approximately 4,200 bytes.) And then the fun begins. Here's how:
  1. The attacker programs bots to continuously execute requests for this record against recursive DNS.
  2. The bots spoof the source IP address of these requests, replacing it with the DDoS target.
  3. The recursive servers take the record from the attacker-controlled zone, and send it along to the IP address they think the request came from.
Multiply this by the number of bots participating in the attack, and you've got a DDoS attack. If your DNS server is a target of this attack, your network will grind to a halt because none of its clients can resolve an IP address.

What's the solution? It's quite simple: Run two different DNS servers. Let the internal server handle all requests from your network (even recursive for your clients only).
On the external DNS server, disable recursion. With recursion disabled, the external DNS server won't send queries on behalf of other name servers or clients, which stops attackers from bouncing DoS attacks off your DNS server by querying for external zones.
Final thoughts


Open DNS recursion isn't the problem—it's a symptom of the problem. IP address spoofing is the real problem, and this spoofing provides a ready venue for DDoS, spam, and other headaches.
In my opinion, IP address verification is the answer, and the tools already exist to solve that problem. I know the Internet Engineering Task Force (IETF) is
looking at the issue, but it needs to stop investigating and take action.

How to Create an IP address tracking batch tool in Windows XP Pro

When you're troubleshooting DHCP problems in Windows XP Pro and want to find out which addresses in a range of IP addresses aren't in use, you may open a command prompt window and launch a ping loop with the For…In…Do command. For example, to find out which IP addresses aren't being used in the range 192.168.1.1 to 192.168.1.100, you might use the command For /L %f in (1,1,100) Do Ping.exe -n 2 192.168.1.%f.

This command will report all the IP addresses, whether in use or not; you'll also have to scroll through a vast number of entries on the command line. You can avoid these inconveniences with a short batch file that returns only those IP addresses that aren't in use, and then compiles the results in a text file. Here's how:

  1. Launch Notepad and type the following commands:
    @Echo off
    date /t > IPList.txt
    time /t >> IPList.txt
    echo =========== >> IPList.txt
    For /L %%f in (1,1,100) Do Ping.exe -n 2 192.168.1.%%f Find
    "Request timed out." && echo 192.168.1.%%f Timed Out >>
    IPList.txt && echo off
    cls
    Echo Finished!
    @Echo on
    Notepad.exe IPList.txt
  2. Save the file as IPTracker.bat and close Notepad.

Keep in mind that the entire For…In…Do command consists of several commands strung together with &&s. The command begins with the word For and ends with the word off, and the entire command must be on one line. Also, be sure to replace the example numbers with numbers from the IP addresses you wish to track.

Now when you troubleshoot a DHCP problem, you can locate and double-click the IPTracker.bat file in Windows Explorer, and then launch an IP address tracking tool batch that will find only those addresses that aren't in use and then display the results in Notepad. (In this case, the saved batch file becomes an IP address tracking tool that can be created once and used over and over.)

Note: This tip applies only to Windows XP Professional.

Speeding Up your Network Browsing

There are a lot of things which can negatively impact how fast XP will browse network shares.
One has been previously covered regarding browsing to Win9x computers.

Other things you can try, especially when there is slow browsing to network shares with a lot of files:

1. Remove current shortcuts in My Network Places

2. Change the registry so shared folders on remote computers are not automatically added to My Network Places when you even open a document from that shared folder

  1. Start Regedit
  2. Create a DWORD value:
  3. HKEY_Current_User Software Microsoft Windows CurrentVersion Policies Explorer NoRecentDocsNetHood to 1.
  4. I have also seen setting the following help as well.
    HKEY_Current_User Software Microsoft Windows CurrentVersion Policies Explorer UseDesktopIniCache to 1.

Download Reg file to do both

3. Increase the amount of data is buffered at one time to send to a client. On the computer with the shared directory:

  1. Start Regedit
  2. Go to HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesLanmanServerParameters
  3. Create a DWORD Key called SizReqBuf
  4. Give it a value of Hex FFFF