Thursday, February 26, 2015
Logon failure: the user has not been granted the requested logon type for this computer.
2. Have you turned off Password protection?
Try checking the Advanced Sharing Settings from Network and Sharing Center. To do this, follow these steps.
1. Click Start, Control Panel and then Network and Sharing Center.
2. Now click Change Advanced Sharing Settings.
3. Now make sure File and Printer Sharing is Turned On and Password Protected Sharing is Turned Off.
If that does not resolve the problem, try to check the Group Policy Settings.
1. Click Start and type gpedit.msc in the start search box and press Enter.
2. Navigate to the following location
Computer Configuration/ Windows Settings/ Security Settings/ Local Policies
3. Under this click on User Rights Assignment.
4. Double click Access this computer from the network and check that EVERYONE is added to the list.
5. If not add it by clicking Add User or group and then type EVERYONE, click OK and then Apply and OK.
Refer: http://windows.microsoft.com/en-US/windows7/Networking-home-computers-running-different-versions-of-Windows
Sunday, February 15, 2015
Remote access to Debian Printing (CUPS) web interface from LOCAL
Install Software:
aptitude update
aptitude install cups cups-client
Start the software:
/etc/init.d/cups start
The easiest way is to use the cups web interface. You can see it by going to
http://localhost:631/admin
But to get to this page remotely for a server, you need to first make some edits to the cupsd.conf file. So do the following:
1. Edit the cups configuration file by first running the following command on your server:
sudo nano /etc/cups/cupsd.conf
2. Change this section :
# Only listen for connections from the local machine.
#Listen localhost:631
Port 631
Listen /var/run/cups/cups.sock
3. Then change this sections :
< Location / >
# Restrict access to the server...
Order allow,deny
Allow from@LOCAL
< /Location >
< Location /admin >
# Restrict access to the admin pages...
Order allow,deny
Allow from@LOCAL
< /Location >
< Location /admin/conf >
AuthType Default
Require user @SYSTEM
# Restrict access to the configuration files...
Order allow,deny
Allow from@LOCAL
< /Location >
4. Finally, restart cups with the following:
sudo /etc/init.d/cups restart
5. You should now be able to log into cups on your server with:
http://your_server_ip_address:631
https://your_server_ip_address:631
You might also have to open/port forward tcp port 631.
Wednesday, February 12, 2014
Iptables String Matching for Advanced Firewalling
Introduction.
When it comes to any server or network connected to the internet, security from malicious files and hack attempts is a matter of concern for any administrator. Linux provides its own firewall from the early releases itself. The current iptables firewall maintained by the netfilter team is advancing to more powerful security and network management tool with the recent releases.It will be a topic of interest for any linux based server/network administrator. This article covers effective configuration and optimization of the iptables firewall system in 2.6.x kernels in order to more effectively defend against TCP attacks and to drop unwanted packets without messing them up with your business critical services!!Kernels from 2.6 include support for matching strings present in IP packets, inspecting the entire packet data. Earlier kernels supported matching at the IP header level only, which was a limitation as the rules can be formed only based on header values like IP addresses, ports, packet state etc. The netfilter iptables firewall system has undergone great advancements in the latest kernels, with the modified string matching option being more interesting among them for server administrators. The rules, based on string matching functions, are very easy to implement. This guide intends to introduce the method to users with a basic understanding of networking and iptables.
System Requirements.
- Preferred kernel version : 2.6.18 or later.
- The iptables program(1.3.5 or later) installed on your machine.
- The kernel should be compiled with string matching support. To do
this, the following line should be added to the .config file prior to
compiling the kernel:
CONFIG_NETFILTER_XT_MATCH_STRING=m
If you use a pre-complied kernel, check for this option in the config file with the appropriate version of the kernel in your /boot directory. If present, it means that netfilter string matching is compiled as a module. Make sure that the module is loaded (using the lsmod command or by looking for the appropriate entry in the /proc/modules file). The minimum requirement is a 2.6.14 kernel, however it is a bit difficult to get it working on kernels before 2.6.18. Customising the kernel and iptables is required in that case. Suggested configuration options for older kernels can be detailed in another article, if there is demand.
Formating the Rules.
If iptables is installed with string matching support, its man page can be found with the following command:iptables -m string -helpHere is the relevant section from the iptables(8) man page:
string
This modules matches a given string by using some
pattern matching strategy. It requires a linux kernel >= 2.6.14.
--algo bm|kmp
Select the pattern matching strategy. (bm = Boyer-
Moore, kmp = Knuth-Pratt-Morris)
--from offset
Set the offset from which it starts looking for any
matching. If not passed, default is 0.
--to offset
Set the offset to which it starts looking for any
matching. If not passed, default is the
packet size.
--string pattern
Matches the given pattern. --hex-string pattern
Matches the given pattern in hex notation.
In iptables 1.3.5, you need to specify the algorithm to use for string matching using the --algo option. We may limit the search by specifying the offset values as well. Two algorithms can be used, Boyer-Moore and Knuth-Morris-Pratt. More information regarding these algorithms can be found at Wikipedia - for Boyer-Moore the URL is:
http://en.wikipedia.org/wiki/Boyer%E2%80%93Moore_string_search_algorithm
and for Knuth-Morris-Pratt the URL is:
http://en.wikipedia.org/wiki/Knuth%E2%80%93Morris%E2%80%93Pratt_algorithm
Boyer-Moore is efficient and fast and is preferable in most cases.
Common Applications and Useful Example Rules:
1) To prevent an intrusion attempt.
In case, a suspecious URL upload using the webserver was detected, You could frame similar rules as follows.iptables -I INPUT 1 -p tcp --dport 80 -m string --string "cmd.exe" --algo bm -j DROPThe rule blocks all packets to port 80 containing the string cmd.exe. Mod_security is an option for the same, but it can be an overload to your busy webservers.
2) To defend DDOS to a service.
It is a common case where we need to drop requests to a domain when it is under DDOS. mod_dosevasive is an option, but it really overloads the webserver. String matching option can be utilized here without overloading the webserver.iptables -I INPUT 1 -p tcp --dport 80 -m string --string "domain.com" --algo kmp -j DROPThe rule, blocks all web requests to domain.com. These rules can also be used in conjunction with other iptables matches and options depending on what is required.
3) To Defend against E-mail Spoofing.
We can make use of the string matching option in numerous cases to drop intruder and spam packets before they enter the server. Another instance for example is, if the mail server is receiving many spoofed e-mails with a common 'Subject'.If the spammer is using a unique IP address, it is very easy to block him using RBLs, conventional iptables rules etc. But when the spammer is using different IP addresses, it makes things difficult for the administrator.In such a case, the following string based rule can be added to the firewall so that the mail server will not get overloaded by the spoofed mails.iptables -I INPUT -p tcp --dport 25 -m string --string "Subject" --algo bm -j DROP
**Do it now with an optimised rule!
The same rule might be modified to one with less overhead (that is, it uses less resources) by limiting the search specifying offset values, and by assuming that the SMTP subject header will be within an offset limit of 15000 in the packet.iptables -I INPUT -p tcp --dport 25 -m string --string "Subject" --algo bm --to 15000 -j DROP
4) Other general cases.
Apart from the instances discussed above, you can make use of the string matching options, wherever you need to manage the packets entering a server or network,based on strings like URLs, file names, file contents etc.Conclusion.
The string matching option can be effectively utilized when a network needs to be filtered using strings. We can block the packets right at the kernel level itself without overloading your server applications. However, there is a higher overhead involved for the kernel with string matching, compared to other ordinary iptables matchings. Offset limits should be specified for searching wherever possible in order to reduce this overhead.Sunday, July 22, 2012
How-to: Mount a Network drive in Ubuntu
- First you will need to install the “smbfs” package. This is what we will use to mount the drive.
sudo aptitude install smbfs
- We will also need a folder to mount the drive in. I used /media/public.
sudo mkdir /media/public
- Then, we need to edit /etc/fstab. This is where we add all the
information needed to find and mount the drive. Open /etc/fstab using
the command:
gksudo gedit /etc/fstab
At the end of the file add the following lines:
# Mount our network drive
Where “SERVER” is the name of your drive on the network. This can be either a name or IP address. For example, mine was “MAXTOR”. Replace “SHARE” with the folder in the drive you’d like to mount– mine was “Public”. “MOUNT-POINT” is the directory we created earlier, such as “/media/public”. The rest of the parameters have to do with permissions, and also where you can add advanced options. For more information on the advanced preferences, see
//SERVER/SHARE /MOUNT-POINT smbfs guest 0 0
man mount.smbfs
- The final step is to tell the system to reload /etc/fstab and mount our drive. Do this with the command:
sudo mount -a
Then, you’re done! At this point you should be able to see the files in your drive with the command
ls /MOUNT-POINT
Wednesday, November 18, 2009
How to Set up Network Bonding in Ubuntu 6.10
Why you may want to do this:
Network Bonding, otherwise known as port trunking allows you to combine multiple network ports into a single group, effectively aggregating the bandwidth of multiple interfaces into a single connection. For example, you can aggregate two gigabyte ports into a two-gigabyte trunk port. Bonding is used primarily to provide network load balancing and fault tolerance. First, we will run two different network tools to check for network connectivity and capability. Run mii-tool to check your interfaces for connectivity:
# mii-tool
For our purposes, we will assume you have three interfaces. The result of the mii-tool command is listed below:
eth0: negotiated 100baseTx-HD, link ok
eth1: negotiated 100baseTx-HD, link ok
eth2: negotiated 100baseTx-HD, link ok
Next run ethtool for each interface to check to see what capabilities:
# ethtool eth0 && ethtool eth1 && ethtool eth3
The result of the ethtool command is listed below:
Settings for eth0:
Supported ports: [ TP MII ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
Advertised auto-negotiation: Yes
Speed: 100Mb/s
Duplex: Half
Port: MII
PHYAD: 1
Transceiver: internal
Auto-negotiation: on
Supports Wake-on: g
Wake-on: g
Current message level: 0x00000007 (7)
Link detected: yes
Settings for eth1:
Supported ports: [ TP ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Full
Advertised auto-negotiation: Yes
Speed: Unknown! (65535)
Duplex: Unknown! (255)
Port: Twisted Pair
PHYAD: 0
Transceiver: internal
Auto-negotiation: on
Supports Wake-on: umbg
Wake-on: d
Current message level: 0x00000007 (7)
Link detected: no
Settings for eth3:
Supported ports: [ TP ]
Supported link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Full
Supports auto-negotiation: Yes
Advertised link modes: 10baseT/Half 10baseT/Full
100baseT/Half 100baseT/Full
1000baseT/Full
Advertised auto-negotiation: Yes
Speed: Unknown! (65535)
Duplex: Unknown! (255)
Port: Twisted Pair
PHYAD: 0
Transceiver: internal
Auto-negotiation: on
Supports Wake-on: umbg
Wake-on: d
Current message level: 0x00000007 (7)
Link detected: no
Next, we need to install ifenslave. It’s a simple install:
# apt-get update && apt-get install ifenslave
Options for mode types:
You can set up your bond interface according to your needs. In order to do this, you simply change the mode type depicted in the examples below (mode=X). There are seven mode types available. They are as follows:
mode=0
This mode uses the Round-robin policy: Transmit packets in sequential order from the first available slave through the last. This mode provides load balancing and fault tolerance.
mode=1
This mode uses an Active-backup policy: Only one slave in the bond is active. A different slave becomes active if, and only if, the active slave fails. The bond's MAC address is externally visible on only one port (network adapter) to avoid confusing the switch. This mode provides fault tolerance. The primary option affects the behavior of this mode.
mode=2
Transmit based on [(source MAC address XOR'd with destination MAC address) modulo slave count]. This selects the same slave for each destination MAC address. This mode provides load balancing and fault tolerance.
mode=3
Broadcast policy: transmits everything on all slave interfaces. This mode provides fault tolerance.
mode=4
IEEE 802.3ad Dynamic link aggregation. Creates aggregation groups that share the same speed and duplex settings. Utilizes all slaves in the active aggregator according to the 802.3ad specification.
*Pre-requisites:
1. Ethtool support in the base drivers for retrieving the speed and duplex of each slave.
2. A switch that supports IEEE 802.3ad Dynamic link aggregation. Most switches will require some type of configuration to enable 802.3ad mode
mode=5
Adaptive transmit load balancing: channel bonding that does not require any special switch support. The outgoing traffic is distributed according to the current load (computed relative to the speed) on each slave. Incoming traffic is received by the current slave. If the receiving slave fails, another slave takes over the MAC address of the failed receiving slave.
*Prerequisite: Ethtool support in the base drivers for retrieving the speed of each slave.
mode=6
Adaptive load balancing: includes balance-transmit load balancing plus receive load balancing for IPV4 traffic, and does not require any special switch support. The receive load balancing is achieved by ARP negotiation. The bonding driver intercepts the ARP Replies sent by the local system on their way out and overwrites the source hardware address with the unique hardware address of one of the slaves in the bond such that different peers use different hardware addresses for the server.
Now append the following items to your aliases file:
# pico /etc/modprob.d/aliases
# Append to the bottom of this file:
alias bond0 bonding
alias eth0 e100
alias eth1 e100
alias eth2 e100
options bonding mode=0 miimon=100
Next, append the following items to your i386 file:
# pico /etc/modprob.d/arch/i386
# Append to the bottom of this file:
alias bond0 bonding
options bonding mode=0 miimon=100 downdelay=200 updelay=200
Now we have to modify the interface file. Start off by commenting out any information on the physical interfaces, eth0, eth1, etc, and create a virtual interface such as bond0, configure it similar to below, and be sure to choose a unique hwaddress. Be sure to leave the loopback interface configuration intact.
# pico /etc/network/interfaces
It should look something like this:
# This file describes the network interfaces available on your system
# and how to activate them. For more information, see interfaces(5).
# The loopback network interface
auto lo
iface lo inet loopback
# The primary network interface
#auto eth0
#iface eth0 inet static
# address 192.168.0.120
# netmask 255.255.255.0
# network 192.168.0.0
# broadcast 192.168.0.255
# gateway 192.168.0.1
auto bond0
iface bond0 inet static
address 192.168.0.120
netmask 255.255.255.0
network 192.168.0.0
broadcast 192.168.0.255
gateway 192.168.0.1
hwaddress ether 00:03:B3:48:50:2C
post-up ifenslave bond0 eth0 eth1
Save the file and then reboot the system:
# shutdown -r now
Monday, November 17, 2008
/etc/network/interfaces
auto lo
iface lo inet loopback
##### Wire Network #####
#auto eth1
iface eth1 inet dhcp
##### Wireless network #####
auto eth1
iface eth1 inet static
address 10.0.0.X
netmask 255.0.0.0
network 10.0.0.0
gateway 10.0.0.YYY
dns-nameservers 10.0.0.YYY 10.0.0.ZZZ
# broadcast 10.255.255.255
wpa-driver wext
# wpa-conf /etc/wpa_supplicant.conf
wpa-ssid Wireless_Network_SSID
wpa-ap-scan 2
wpa-proto RSN
wpa-pairwise CCMP TKIP
wpa-group TKIP
wpa-key-mgmt WPA-PSK
wpa-psk TOP_SECRET_PASSWORD
######## Example ###########
#wpa-driver wext
#wpa-conf managed
#wpa-ssid
#wpa-ap-scan 2
#wpa-proto RSN
#wpa-pairwise CCMP
#wpa-group CCMP
#wpa-key-mgmt WPA-PSK
#wpa-psk
############################
#auto eth2
iface eth2 inet dhcp
#auto ath0
iface ath0 inet dhcp
#auto wlan0
iface wlan0 inet dhcp
Direct DOS print outs to network printers on Microsoft Windows
For example, let's say your DOS program prints to LPT1 (most DOS programs do) and your printer is on the network at the following network path:
\\MY_SERVER\PRINTER
- Go to the "DOS/Command Prompt"
- Type the following command:
NET USE LPT1: \\MY_SERVER\PRINTER
and press ENTER.
