Posts

PfSense

I finally made the switch from m0n0wall to PfSense today. It all went well (PfSense can import the m0n0wall config file directly), except for one thing: After the switch, I didn't have any audio when calling through one of my VoIP provider. I fixed the problem by enabling advanced outbound NAT, and enabling the static port feature for the default rule. I needed that because PF, the packet filter used in PfSense, scrambles automaticallly the source port for more security, but VoIP needs it to be the same port to know what session it is part of. Next step is to enable it only for my Asterisk server and my Vonage ATA, instead of my whole lan. In the end, PfSense is worth the try. I think the VoIP traffic shaping is still not perfect, but it'll probably be fixed before it is released as stable (it is now RC1). Feel free to share your experiences with firewalls :).

SquidGuard

Hi, I played with SquidGuard in the past few days to control what users can access on the net and when. Is it quite a great package, as it did what I needed to do. That is basically how it works: You can define Time Spaces You can define source groups (hosts or networks, or IP addresses ranges, or users) You can define destination groups (domains, urls, regex) Finally, you define acls with all those parameters You can add blacklists to the mix I have recommendations for people who would like to try squidguard: Don't forget that SquidGuard is a redirector, if you don't configure a redirect URL, it will do not block anything Check all the logs You need to know that when SquidGuard encounters a problem (config or else), it goes into emergency mode, in with it does nothing (nothing is blocked) I suggest you avoid using the webmin module. I can't tell it is 100% sure you'll have trouble with it, but I lost many hours because of it. If I can find some time eventually, ...

Exchange Replacement : Scalix

I was looking for a way to satisfy a group of users who were used to work with Microsoft Exchange, but are familiar with the performance and reliability of Linux, and would like to save money in the process of getting their own collaborative server. I had a list of potential replacement packages: Kolab Open-xchange Scalix OSMER Opengroupware Egroupware Horde Gordano @mail Bynari Kerio Zimbra Which one is the best? I can't tell... Which one won? Well, Scalix. Why? Because of native Outlook connectivity(note: you have to install a free software on your Windows PC, free for up to 25 users Ease of installation No database required Very nice (AJAX-based) webmail interface We're still testing it, so I'll keep you posted on the results.

Skinks!

Image
Recently, I (re)discovered a very nice lizard species: Skinks. In fact, I knew blue-tongued skinks, and I discovered prehensile skinks. Prehensile are especially nice, since they have a prehensile tail, their tail can support the weight of the lizard. Here is a picture of a magnificent one (see left): I really think it is the ideal lizard: Vegetarian or omnivore (many people don't like feeding their pet with live insects), and very calm. I wish I could beed them, but I don't think it is realistic. They cost about 200$ each, and it requires a lot of time and care. I can just hope that skink reproduction will raise in my area.

Asterisk VoIP

Image
I now have a PBX at home, based on Asterisk, and it is amazing... It is incredible the quantity and quality of features that it includes. I really love it. I've been helped by someone who works with that all day long, but I'm getting more and more comfortable at configuring it and the related hardware (IP phones, ATAs). Hopefully, I'll be completely able to install Asterisk servers on my own.

Another Lizard!

Image
... Ornate climber. Or maybe is it a blue-eyed crested climber... Not sure. It doesn't have a name yet, so please feel free to send me ideas. It is a male. I think I'll call him Brutus.

Got published!

Hey! Insecure Mag just published an article I wrote some time ago for them about MailScanner and server-side spam and virus filtering. You can read it in the new issue (1.5). Have fun, and... your comments are welcome!

Greylisting - Francais

Je considérais le Greylisting comme un sujet assez important pour traduire mon article sur ce mécanisme anti-spam: Voici une explication du "Greylisting", un mécanisme très efficace contre les spams: Basé sur des " triplets " (adresse de courriel de l'expéditeur, adresse de courriel du destinataire, adresse IP du serveur d'origine). Quand un serveur recoit une connexion SMTP d'un autre serveur, il vérifie le triplet. Si le triplet est connu, le message continue son chemin. Sinon, le serveur refusera la connexion à l'aide d'un message SMTP 450 (échec temporaire), donc disant au serveur d'origine: Je ne peux accepter le message présentement, veuillez revenir plus tard. La plupart des serveurs de courriel respectent cette règle ( RFC821 ) et ré-essayent une connexion quelques minutes plus tard (Microsoft Exchange et Hotmail: normalement 1 minute, Yahoo: ~5, Sendmail: ~7, Postfix: ~1, Exim: ~3). Les délais sont normalement minimes, si perce...

Stats

Finally, an easy-to-use and friendly stats engine for my blog... Thanks to http://www.sitemeter.com/ . See my stats here .

Gift Idea!

Image
I really need this shower notepad ! No kiddin'. ;-)

Hoax?

What is a hoax? The sound you make when you sneeze? Nah... It is a false rumor. You probaly receive e-mails saying, for example, that a little boy in a foreign country will earn 5 c ents every time you forward this e-mail... Or that a new virus has been announced by Microsoft? Those are not true, but forwarded by people who just don't know how to check. There is nothing good with these e-mail messages and their only consequences are losses of time for a lot of people. Please don't forward these e-mails before checking if the information they contain is real and true. But how to do that? I'll give you the means today. You need to know if a message is real or a hoax? Go see HoaxBuster (french) this other site . Anti-virus vendors also have such sections on their website ( Mcafee and Symantec ) You want to be aware of virus trends? Every anti-virus vendor has a database of viruses ( Mcafee , Symantec , Kaspersky ). Microsoft is not (as of today) an anti-virus vendo...

Basic tips for free security

Computer security is important for everyone. People often underestimate the cost of computer labour and think that when they buy a computer, there will be no other costs other than the purchase cost. Wrong! But you can easily reduce the risk of needing computer specialists' services with a few tips (there is no cost associated with those). Short version: get AVG anti-virus , free edition, and MS Anti-Spyware . Long version: Get a free anti-virus. I recommend AVG, Free Edition . Not really because it is the best... I haven't tested them all. However, it is the one I've been using at home for a long while and I'm pretty satisfied with it. It is also easier for me to help anyone who's using the same software as I use. Note: AVG Free Edition can not be used in a business context. It is only allowed for personal use at home. Please respect licences. WinClam is an open-source virus-scanner Get a free anti-malware program. If you have a legal copy of Windows...

Phishing

You don't know what phishing is? Well, it is basically a fraud attempt using e-mail messages. It is usually a malicious person who impersonates a big corporation, usually banks, or online services like eBay or Paypal, and ask you to go to some site and enter your credentials (username/password/card #) for whatever reason. What people usually don't know is that it is easy to make a link that leads somewhere else than what it says. For example, it is easy for me to make a link to one website, and make it look like another. For example: www.patatebleue.com links to google. So here are the rules... Banks never communicate with their clients by e-mail. Watch out for typos. Phising are usually full of mistakes. You should never be prompted by e-mail to "refresh" your password. Businesses don't deactivate their client's account just for the fun of it. Think about it: Customers are of value for a business, why close accounts? Also, most business gather informa...

Firefox 1.5 is here, with cool extensions!

Good news, the new Firefox is out! I tried it out and it has been reviewed many times already. I suggest you upgrade, unless you really need one extension that is not 1.5-ready yet. It has a few improvements over 1.0.x, such as: Automatic updates Faster browsing Drag-n-drop re-ordering of tabs Better pop-up blocking You can report sites that are not Firefox-friendly directly in Firefox Many others I also found many cool extensions thanks to this article . Go there and get cool extensions! What about security ? Well, Firefox 1.5 just got its first security alert . Critical? Nah... far from that. However, that doesn't mean Firefox is 100% secure. But the automatic update feature, it is getting close. It is a lot better than Internet Explorer, since Internet Explorer has roots in the Windows operating system, and Firefox doesn't. This means that a vulnerability in Internet Explorer can typically be more critical than a similar one in Firefox. But, I really believe th...

msncheck.41m dot com

Hi, I reported suspicious activities on this website recently msncheck dot 41m dot com to the SANS institute. They were offering to let people know who blocked them on MSN. But that required that you enter your MSN credentials (e-mail address/password). Do you remember you should never give your password to anyone? I must admit they looked fair and honest since they were recommending you to change your password before and after, so that they don't know your real password. But the thing is: do you have an idea of how much e-mail addresses they can harvest this way? That is an easy way to build a list of addresses to send spam or phishing... Now the site is down, but I don't know if my report has anything to do with it... I'll ask.

Greylisting

Hi, Just begun playing around with GreyListing. It is another anti-spam technique. Simply said, what it does is: It is based on tuplets (sender, recipient, originating IP). The first time a server receives a message of one specific tuplet, it says to the originating server : I don't accept your message now, please come back a bit later. Real e-mail servers usually respect this and retry a few (typically 15) minutes later. When the server retries, the delays don't apply and the message is accepted. Then, the tuplet is added to a database (held in memory, dumped once in a while on disk), so that this tuplet is not subject to greylisting (delays) for a given period Spambots, zombie infected computers don't retry, so a lot of spam is denied just there, no more processing is needed. The benefits are two-fold There is less spam in the users' mailboxes There is less load on mail servers. Effectively, most servers use anti-spam software that uses a lot of resources (ne...

Spam

Hi, Just got a spam in comments. I get an e-mail everytime there is a comment and I delete it if it is a spam right away, so spammers: don't waste your time.

m0n0wall gets a span port option!

Thanks to some people on the m0n0wall mailing list (Edward Mzj), who worked hard to add new features, it is now possible fot m0n0 to use an interface as a span port (also called 'mirror port'). A span port is usually used for packet sniffing and, more importantly, for Intrusion detection system usage. With a span port, all the traffic going through interfaces is 'copied' to the span interface so it can be sniffed by another computer. I'll finally be able to run an IDS at home without buying an (overkill) smart or manageable switch! Thanks guys!

APC (American Power Conversion)

For those who don't know, APC is a well-known manufacturer of power-protection equipement, such as UPSs and Surge protectors. An UPS is like a surge protector (protects your equpment from "too much electricity" (spikes, surges), but it has a battery pack that protect equipment in case of drop of voltage (brownout) or power outages. I had to deal with APC support yesterday. In fact, I was a troubleshooting an issue for about une week by e-mail and I called them yesterday. Here is my opinion about APC: 1- They make very good hardware, although I think that Powerware is offering UPSs that have more features (their 9000-serie). 2- I love their live support on their web site. It is probably the thing that makes me buy APC. I can chat directly with a sales rep before buying. 3- I don't like their software. I use Apcupsd on my Linux servers, for a reason. APC's software, PowerChute, will not install on a Linux server without having X installed. I don't instal...

Google Adsense

I'm trying Google Adsense. Feel free to click on links in the white box.