Archive for the 'OS Tips & Tricks' Category

Securing Access to Terminal Server

The how-to available at msterminalservices.org outlines a nifty way to tightly control exactly which client installations (which PCs) can access your Terminal Server over RDP. It’s free to impliment and is fairly simple to do. Check it out.

Remote desktop XP to Ubuntu Linux

It took me some time to figure this one out. I found many sites / blogs / wikis / forums giving very elaborate instructions on how to do this, but they all seemed much to complicated. What I wanted to do seemed like a simple “want” to me. How do I access my Ubuntu linux box remotely (over the LAN) from a windows xp machine? My linux machine runs Ubuntu. If you are trying to RD into another distro you will have to modify these instructions accordingly. So here is what I did:

  1. Activate XDMCP on Ubuntu - SYSTEM >> Preferences >> Remote Desktop - “Allow other users to view your desktop” - “Allow other users to control your desktop”
  2. Install Cygwin/X onto the Windows XP machine. - Download and run setup.exe from http://www.cygwin.com/ - Install the standard packages on Cycwin/X along with :

    - X11 –> X-Startup-scripts - X11 –> xorg-x11-base (this will set a lot of x11 dependencies to install also — you want to install these)

  3. Run Cycgwin
  4. In the Cgywim terminal enter the following command: $ XWin.exe :1.0 -unixkill -scrollbars -screen 0 1280 1024 -emulate3buttons -once -query (NAME / IP) & Put the name of the linux computer or its IP address
  5. You should then see the Ubuntu login page. Voila.

It’s possible I installed one or two other things on the Ubuntu system. I don’t recall just now as I tried so many other ways to get this functionality working I now forget exactly what was done for what. If you try the above and it does not work, let me know and I’ll figure out what else has to go onto the Ubuntu system. I know I installed freeNX although I am not sure if this was for the Cygwin connection or not. If you want to use SSH to Ubuntu via Cygwin there are some instructions here. I tried various SSH related ways of going about this. SSH from Windows directly and SSH via the Cygwin terminal. I kept getting the error that the port was not open. I tried port 177 (which XDCMP users) and 5901 and others, all to no avail. I am not sure how to make these ports available from Ubuntu. But the Xwin route works great.

A little extra info on this tip can be found here, along with links for further research 

Microsoft OneCare Fails

I am not sure how Microsoft manage to do it. It’s just one of those ongoing mysteries in this world of ours…

Microsoft is one of the largest companies in the world, with more money and technical resource than any other software developer in Earthly existence, and yet they consistently fail to turn out software that does what one would expect it to do (and without doing all sorts of crap one would not expect nor want it to do). Microsoft are preparing to launch their first attempt at a full firewall product called OneCare. It one seem that OneCare is more than one step away from caring enough to be worth using as a firewall system. I refer to the following media release from Agnitum, the highly respected makers of Outpost Firewall (a product I’ve been using for a few years now).

Concern expressed over low level of customer protection provided

28 JUNE 2006, ST.PETERSBURG, RUSSIA - SAN JOSE, CALIFORNIA. The firewall security experts at Agnitum, developers of the widely-acclaimed Outpost Firewall product family, have conducted an in-depth analysis of Microsoft’s new OneCare Firewall, part of Microsoft’s “Live” security initiative. The results are so far below industry standards that the company felt obliged to share the results of its analysis with the public.

Highlights of the report include the following:

  • The OneCare firewall failed all but the simplest leak tests and does not offer even the most basic intrusion detection capability, leaving users’ PCs wide open to being hijacked into a botnet

  • The OneCare firewall database of pre-approved applications is very small, and adding each new application requires several user interactions and a reboot

  • Application access rules are limited to ‘allowed’ and ‘not allowed’ - users cannot configure different rules for different types or times of usage, such as allowing IE to connect with some but not all websites

  • Similar limitations apply to network file access and remote desktop operations

  • The Windows Defender anti-spyware component of OneCare imposes significant delays on program execution, and is updated on a separate schedule than other OneCare components

Agnitum engineers also found compatibility issues with OneCare - but not the ones they had expected. Before installing the software, they already had a firewall running, as would most people. OneCare did not request the de-installation of any existing firewall, so Outpost Firewall Pro was left in place. OneCare worked smoothly alongside Outpost Firewall Pro - so smoothly that Outpost was the first to monitor the system, ask questions and protect the user, not OneCare.

The full analysis can be found on the Agnitum website at http://www.agnitum.com/r/firewall/onecare/

“Microsoft has tried to create software for novice users, making it very limited in settings and customization. The problem is, they’ve gone too far. OneCare is too simple. Yes, it’s easy to use. But unfortunately, it doesn’t provide much protection,” says Alexey Belkin, Chief Software Architect at Agnitum. “This ‘one product for everyone’ attempt is likely to end up being ‘one product for no one.’ The product itself looks like it was designed as a mandatory part of the operating system, and that is simply shortchanging users who haven’t yet decided what security solution to invest in.”

The business community worldwide, as well as the firewall security vendor community, has reacted swiftly to the appearance of this new player, not only from a technology perspective but also from the point of view of Microsoft’s business practices. Reactions concerning “predatory pricing” (first discussed by Sunbelt president Alex Eckelberry in his blog http://sunbeltblog.blogspot.com/2006/06/microsoft-practices-predatory-pricing.html) are arising, primarily that Microsoft is setting artificially low prices. But “cheap” doesn’t equal “good value,” as can be seen in the Agnitum analysis of the OneCare firewall.

“No one is underestimating the potential impact of Microsoft entering the Internet Security market, but at Agnitum we are seeing this development having more positive than negative effects,” says Mikhail Penkovsky, Global VP of Sales & Marketing at Agnitum. “The updating of the Windows Firewall in Vista makes a clear statement that the personal firewall is a must-have; Outpost and other third-party firewalls will still be there for customers when they realize - as many will - that the protection provided by OneCare is extremely limited. Our key distributors and resellers are in full agreement that OneCare is nice to look at but that’s pretty much all there is to it.”

About Agnitum ltd.

Founded in 1999, Agnitum (www.agnitum.com) is committed to delivering and supporting high quality security software products. The company’s headline products are Outpost Firewall Pro, securing personal and family computers, and Outpost Network Security, ensuring reliable endpoint protection and performance for small business networks. Agnitum firewall technology is licensed by Novell, Sophos, and Lavasoft.

Windows XP Netorking - TCP/IP

For those wishing to customise the way TCP/IP is handled on Windows XP the follow MS Knowledge Base article(s) may be of assistance…

Microsoft Baseline Security Analyzer (MBSA)

Microsoft has a free tool called “Microsoft Baseline Security Analyzer” or MBSA for short. If you use Windows XP then this can be a useful tool for checking up on your computer’s security status in accordance with MS security recommendations. Here’s the intro to it from Microsoft.

Microsoft Baseline Security Analyzer (MBSA) is an easy-to-use tool designed for the IT professional that helps small- and medium-sized businesses determine their security state in accordance with Microsoft security recommendations and offers specific remediation guidance. Improve your security management process by using MBSA to detect common security misconfigurations and missing security updates on your computer systems.

MBSA 2.0 offers an intuitive user interface and more informative dialogs compared to previous versions. Using the new Windows Update Agent and Microsoft Update catalog, MBSA 2.0 has automatically expanding product support.

It’s home page lives here… Microsoft Baseline Security Analyzer (MBSA).




Bad Behavior has blocked 154 access attempts in the last 7 days.