Tuesday, October 30, 2007

How To Identify Counterfeit Ap2

Blocking msn messenger

Here I am back, I admit that now, if I am absent a little but well, here I am back now to show browser settings and email client under CCProxy, so that it was much blabla and little action.

Internet Explorer

Call it Internet Explorer, Firefox, Opera, Safari, etc basically all navegadore are regulated in the same protocols and Internet Explorer remains the most popular in the world (Spare me the discussion of which is better) I will use that screen to show how to configure the access right through.



We're going to Tools, Internet Options, Connections, LAN Settings
uncheck them (if it were) the box Automatically detect settings, mark the box Use a server proxy for your LAN (...) in the fields immediately activated to enter the proxy server data as well as the port. In the example I am occupying port 8080
we move and click the advanced options to set one by one the protocols. This will be useful if, for example, we have some other software such as the socks.
Once completed, we accept everyone and preferably close the browser and restart. OJO most of the problems of non-detection of proxy have put bad lie in the server ip or port. Before you break your head if malviajadas heroic solutions, check that.

email client

This example will use the settings Microsoft Outlook (bone, which comes with Office) to illustrate the configuration. In my house occupied the version 2007. He may be a previous version, or Outlook Express or any other mail client you will be definitively used this configuration. Just to comment, I have held thunderbird without problems.

If this is the first time you start, you should only choose to occupy a POP3 mail server, if it is to re-configure then go to Tools, Account Settings, choose the account (if you had several) and enter the following screen:



If you can not be put in the first two fields, we're screwed.
Mail Server incoming and outgoing: here is where we put the ip of the computer that is running CCProxy. Do not forget that the user should be allowed to use the mail to work (this is another very common error)
logon information (here comes the good part): There are two types of ways to authenticate, the first deal is as follows : (for login and sending mail) usuario@usuario.com # mail.usuario.com That first form is used regularly for mail "business" or those who pay to use them, in short, you income occur when a server where mail.usuario.com is our incoming mail server.
The second form is the one that would look for some free service like yahoo for example, and would stay user # mail.usuario.com As we can see, this second option does not need to put the entire domain, which is a small but significant difference between that works or not your email right through outlook. Cat
The symbol will make CCProxy differentiate what the user name and what server name.

Once done, we click on more settings and advance to the next screen:



Here there is no major problem, we must put the same thing at the beginning of session to receive mail. Ok we all and send and receive test mail test mail. A Lot
eye configurations supported by your mail server, not me ask how to configure mail in your company because they know as valid users to send or receive mail, besides of course, if you are an administrator and you do not know they'd better find out or you go looking for another job. The point is fully aware of these settings, and that really depends on how successful connection is configured the mail client. Unlike many proxies, CCProxy not require you to set directly on the server you're using, but the customer who requests to connect to, which can be very reassuring if we occupy many email account.

Monday, October 22, 2007

Lab 8 Population Genetics

client configurations Account Manager Advanced

Ok ok, I admit, I was skipping this part, but the truth is that even if I wanted, I went to work, so like I was the plane but here I am, ready to redeem the error, let us begin.


Account Manager


Account Manager is an extremely important part, you can work without defining it, but would lose its essence is to regulate and audit traffic navigation. In this part we define the behavior of users pasenpor CCProxy and combining with local or domain level policies can achieve results. Allow

category: In this part we will find:
Allow all: All connections are allowed only
Allow: Addresses ip or mac listed will have access to, discarding anything that is not within
Allow all but: The small but this is like "ban" certain disclosures allowing the majority to pass except those listed

Authorization Type: is the type of authentication whereby users must pass. This type of validation is affected by the selection made in "category enable" ip address
: CCProxy verify that the ip address listed is the same as the client to access the service, if it is true, reject it.
Mac Address: exactly the same, but on the MAC address
Username / password: ask for a username and password if you want surfing no matter the previous two criteria
Username / password + IP: Same as above, but this time to review the IP matches the one listed for that user
Username / password + IP: Same as above, but on the MAC address
IP + MAC: The IP address must match the MAC address, if any not equal to what is defined to reject it.

see right now:

Web Filter:
The tyranny looms, the whip of the prohibition generates its thunder with evil and the devil that runs all decide where if and where not. Exactly, here you can spend hours and hours of fun unhealthy, prohibiting access to pages and practicing your diabolical laughter when the user asks: why I can not get in here?



And as said jack the ripper, we Parts:

Web Filter Name: I think there is much to say, so if I recommend is do not put 'code' pon clear names, you understand and remember that created them, of course, will not speak at length making lengthy description that is, with some simple but consistent enough, also, in theory no one else but you will have access to the proxy. Filter

site: for the filter function must be enabled obviously is a great puzzle out how to activate and deactivate, I leave for work

Allowed Sites / Banned Sites: That's right, the fun starts here. When activated the option of allowed sites means that everything is prohibited, except for sites that list here. The upside is forbidden, everything is permitted except as there ready. Ocupalo according to criteria.
And the million dollar question: how to fill those lists? Well, you can put the full address of the site to block / allow (www.misitio.com) or fill in the holy wildcard as DOS, bone, asterisks, for example if I put *. I misitio.com block all this before. "misitio.com" This is because there are sites that deal redirects, and do not start with "www" such as blogger, vista.misitio.com which could override the filter. The wildcard can be placed anywhere you like, often involves creativity in defining the filter.

banned URL: Here is where to place what kind of files can not be downloaded, here is where we can put all your music files, compressed, executable, etc etc etc, however cautious, especially when blocking. exe as there are sites with real-time processes that occupy. exe eg Aspel site (www.aspel.com) queries and see in the address bar in certain parts points to an executable, which means that if the filter defines executable so that nothing could affect this page.

Content Forbidden: this is where we will: cheap sex, porn, crack, warez, old hairy, all things that comes to mind, but beware, if we for example sex and an application form asks you your sex is likely to block . (You can also put the name of a sister or cousin whore for anyone in your job's going to hire)

now return to the main screen
account manager
We click on the button again, next to the table for create an account to access:



User / Group: define a name for this account (personally, I put the computer name
Password: We set a password for the user accessing the service
Enable: Box punches is that the account is operational, otherwise it is disabled
ip address / ip range: one direction (or several in case of a group) iran in this part
MAC Address: , here is the MAC address of the computer that is intended to provide access
TIP!: The MAC address is definitely the safest option for a user validation as IP can be changed, but the MAC as it is a physical address, unique for each card and can not be changed. How to know it? If you pay attention you will see a sign? with the two boxes listed above das click there and it opens another window:



In the name of the place the name of the computer, then click on to obtain both IP and MAC address as you will be returned.

As a group: Checking the box define that this occasion will be a group and not an account, for example, the group of ugly gossip. Once created, the group can add users to the
Belongs to group: if existing groups by selecting this checkbox the user can append the group, for example if we have a group of gossipy old and ugly, we can add to juanitacotorra group.
We will stop to talk to the groups. The groups help us to save some work, say an example, let's create the group HRV (old and ugly and gossip). Once created, define this group will be subject to no1 web filter, which restricts the whole sailing with the exception of pages of government previously defined, nor Telnet access (because apart from gossips have the morning to download the screen saver as are puppet under the guise of "look good tender" and of course, brings spyware and some other viruses) also have remote dial access, or FTP or other. This done, we juanita user parrot, when we get to the part of "Belongs to group" then select VFC and at that point the user will acquire the characteristics of the group. This is especially useful if juanitacotorra has an army of clones like her service.

Continued ... Maximo
Number: Refers to the number of connections that the user can do, it may be useful to stop spyware attacks, as such, the user can be restricted to 5 connections and as the pop ups generated by some bichillo begin, the rejection for exceeding them.
Bandwidth (byte / s): Here we limit the bandwidth occupied by the user. Mind you, this measurement is in BYTES so careful with this field.

www, mail, telnet, automatic dialing, ftp, socks, other: are protocols that USER will be allowed to the user or group is created.

Web Filter: created here select the filter that will apply to www in the desired user or group

Hours: schedule is defined in which the group or user will have access to defined services. Clicking on the E takes us to the time ranges to define

Autodisabled: Disconnect the service at the right time to finish

already in the main window you can find the button autoscanear, which is useful for detecting all the teams with their mac address and avoided a great job in the case of many users
Now if, in the following configurations of clients and see if! for dessert, the configuration to block messenger

Wednesday, October 17, 2007

Pir Sensorcircuit Diagram



Today you see the Advanced options within options CCProxy. The first tab only refers to the framework with which we are all now familiar, so I internare in this option, continue with:


Cache This option can set the cache CCProxy. Update
cache: allowed to cool the contents of the cache for fast loading pages, you can define a time range in which the proxy look for new items. Change
options via IE: since it is based on IE technology, CCProxy can set certain parameters basing extras in IE, then here we LEAN THE cache, cookies, etc.., which are stored on your computer.
always loaded from the cache: activated, enables CCProxy customer always load pages based on what is downloaded, otherwise allow the fly





External Proxy Enable external proxy : selecting this option can take up another proxy for CCProxy (cascading). We can define which protocol is the one to go through another proxy. An example of this would have a proxy only for mail that could handle spam and virus filters, so would expedite the speed of downloading and sending emails, of course, also security as to what is received. It defines the port and if necessary the username and password.



Activity Log



Here is a interesting option. CCProxy can keep detailed records of activity for each connection, ie web sites visited, the titles of photos which are quite useful when doing an audit. Save
records: Specifies the path where records are kept. These files are stored on a day that can be exported to excel, by user or in general. If not checked the box, are only connections on the fly as they occur without bone save the activity.
Url's requested, picture info, web title info: : complement more accurately what is being stored in the logs.
Maximum number of lines: : refers to how many lines have each log max. If you have many users will need to consider a larger number than has by default. The new box to create a daily log file per day, otherwise it would be a huge file and very laborious to analyze.
Registration: record show "raw" connection and navigation information records
Clean: Deletes logs
Export to excel: generated log to open it in Excel, very

useful to analyze the connection Information
To enter this part, we go to the main window CCProxy on the green grid and we double click will open the following window:
This is the view of analysis real-time connections made by proxy.



Log analysis: by clicking on this button, you'll go to another window where we can see details of each user activity in general or busy protocol.




Logfile: First select the file to be analyzed (year-month-day)
Name: select the name of the user to analyze
Protocol: to analyze activity
Filter: here we can leave it blank, or put such playboy, so to analyze the log looking at you enter this the word playboy This would serve us when we know specifically that we
Anaylisis: running the search based on the above named fields. In the case of protocol if you leave blank will show all the activdad in all protocols.
Export: Export the test result as a html page
Open: opens the file connections
raw
This concludes options CCProxy advanced. Maybe they think that I swerve to give full explanation of the analysis of logs, but it definitely goes hand in hand with the option enabled, so leave it in another post is like to lose the thread, so that's why they continue. In the next we will see client configurations mail, instant messengers and browsers

PS: As I suffered with this post, uploading pictures was a triumph ...

Tuesday, October 16, 2007

What Happens When There Is No Bile?

Entering

Now we enter the first part of CCProxy options. Proxy services that control aspects of role play in the network.

Mail: Enables CCProxy to function as a mailer, that is, allow the pop and smtp traffic. Ojo, CCProxy NO stores emails sent or received.

DNS name resolution. This service is not enabled
regular Web
Cached: CCProxy The cache can make browsing faster and can be especially useful on slow connections. Depends in turn on other parameters located in Advanced -> cache

Remote Dial Up: Dial on demand or requested by users. It may not be very convenient

Autostartup: Automatic start when you can not install as a service (win98, Me, 95)

Autohide: immediately minimizes to the taskbar

Portmap: port mapping for applications requires a specific output



Protocols and ports



Here we define communication protocols and ports

Http / rtsp: This is the main port of communication, say "Here navigate" in the pages of internet browsers. By default is the 808, I am dealing with 8080. The rule indicates that proxies should be used preferably 3128 or 8080. You can actually put any port, the point is that this should not be occupied by any problem currently installed or intended to install in the future. In fact, if the port was busy CCProxy warning us that already in use

Secure FTP (Web), gopher , should be set to the same port this is more for convenience than anything, because then we would need a different port for each and hope that they were not busy and ultimately can occupy the same port without problems

Socks: Typically takes port 1080 for this purpose . This is commonly used for applications like msn messenger, yahoo messenger, Mirc (although the latter can be blocked by the servers to be considered insecure) and some others.

Ftp: by default brings 2121. This would look for FTP programs, not so much for navigation (for this is the ftp protocol (web). If you will not take any FTP client I recommend uninstalling it, because otherwise someone could detect and connect any client and download things at will.

Telnet: telnet former is enabled by default on port 23. You could serve to ping from any station to the internet, but before you do this you have to do CCProxy telnet and then do the ping. If it is not absolutely necessary should be disabled as it is a hazard for safety.

News: Port for connecting client programs to news servers.

In the bottom but we still have two options: Autodetect

: if we have a single card immediately detects that direction to allow traffic on it, if we had more for us to choose which traffic would enter

NT service: CCProxy installed as a service. Enabling this option is disabled
Autostartup
This concludes the tour CCProxy options. In the next post we shall enter the advanced options to see some more interesting options. I do not go in depth with explanations of protocols and I assume you have a basic knowledge about this, but I put some links for those who think they might shed some function thereof.