Network

Cisco IOS Commands

Fadıl

Privileged Mode

enable – get to privileged mode
disable– get to user mode
enable password <password_here> – sets privileged mode password
enable secret <password_here>– sets encrypted privileged mode password

Setting Passwords

enable secret <password_here> – s et encrypted password for privileged access enable password <password_here>– set password for privileged access (used when there is no enable secret and when using older software) Set password for console access:

    (config)#line console 0
    (config-line)#login 
    (config-line)#password <password_here>

Set password for virtual terminal (telnet) access(password must be set to access the router through telnet):

How to SMTP Over an SSH Tunnel?

Fadıl

Spammers would sniff it out fairly quickly, and proceed to hammer it. To get around this, I decided to set up an SSH tunnel from a port on my laptop to port 25 on the mail server. It was a fairly easy task, and well worth it in the long run. The remainder of this article will explain how I set things up.

Set up the Tunnel

The first thing I decided was to establish the tunnel as a non-root user. Since the tunnel was going to exist for solely mail relaying purposes, I created a relay user on both my laptop and the server in question. I also ran ssh-keygen(1) and gave the relay user an empty passphrase. If you’re overly paranoid, you can use a passphrase and then use ssh-agent(1). The way I figure is if someone gets into my laptop, I have more things to worry about than them sending mail through my relay.

How do you know when someone probing your network?

How do you know when someone probing your network?

Fadıl

How do you know if someone is probing your network?  Logs are a great place to start, especially your FW-1 logs.  Unfortunately, those logs can be difficult and time consuming to sift through (especially if you are logging 400+ B every day). Wouldn’t it be great if there was an automated method of alerting you?

There are a variety of different probes and attacks black-hats will attempt. he types we will be focusing on is port scans. Port scans are where an individual attempt to connect to a variety of ports to identify what services a system is running.  The scans can be used on a specific target or used to scan entire IP ranges, often chosen at random.  This is one of the most popular information gathering methods used by black-hats today as it identifies what ports and services are open.

Ip Check Using PHP

Fadıl

If you have ever had the need to validate an IP address then this small script is for you.

function validate_ip($ip) {
if (is_string($ip) && ereg('^([0-9]{1,3}).([0-9]{1,3}).' .
'([0-9]{1,3}).([0-9]{1,3})$',
$ip, $part)) {
if ($part[1] <= 255 && $part[2] <= 225 && $parg[3] <= 255 && $part[4] <= 255)
return TRUE; # Valid IP
}
return FALSE; # Invalid IP
}

Ok, that’s all fine and dandy but what does it mean?

The fist if the statement is breaking the IP up into 3 sections and removing the ‘.’ from the user input. It then stores the results in the $part var then the second If statement checks to see if all of the parts are valid. If everything is fine and dandy it will return TRUE and if something has gone wrong it will return FALSE.
Hope this helps anyone.

How to install ssh on Linux?

Fadıl

Building and Installing SSH

For most Unix systems, the installation of SSH is pretty straightforward. Simply download the GNU-zipped tar file from one of the FTP mirror sites listed at http://www.ssh.fi/sshprotocols. (Note: Typically there’s a new version of SSH released every few months.) In order to compile SSH, you need an ANSI C compiler such as gcc. The simplest way to build this software is to do the following:

# ./configure

# make

# make install

The configure script should recognize your system type, discover important information about your build environment, and–if everything checks out–create a corresponding Makefile. The make program uses this Makefile to build the software. The make install directive installs the SSH components and man pages in the right places and generates the initial 1024-bit host key pair (if it doesn’t already exist).