Jump to content

tom_newton

Smoothwall Staff
  • Posts

    5,873
  • Joined

Everything posted by tom_newton

  1. One to watch - the log viewer has an "ignore filter" - most of the time you don't want to see the reams of css and javascript. Turn off the ignore filter, and add another one (eg. domain filter) to keep the results manageable, and you should see the things you're blocking. As for webcams.. could be RTSP.. or RTMP 554 and 1492 i think
  2. Is this on the same tin? IIRC some NICs don't like to spoof MAC..
  3. Hope folk are interested.. Cumbria in June/July? Yes please
  4. Camera Price Buster - UKs cheapest camera gear is a good place to look - apparently the Canon 1000D can be had with the regular 18-55 kit lens plus a 75-300 for just north of 500 quid. Interesting. No indication of the 75-300 being IS, which i'd class as a "nice to have" but not essential for handholding in bright african sun. If I get chance i'll do a bit more looking when I get home.. now.. back to er... posting about web filtering, yes, that's it
  5. Indeed... and for VPN you want a UTM box rather than the SWG, but that wont make much difference to you except for..er.. being able to VPN A combination of h/w and s/w smoothies should do it for you. Express is able to do site-to-site VPN, but only in the less secure "PSK" mode of IPSec, although we're talking degrees of security here that probably don't apply
  6. ..and it is still slowly creeping out to customers... slowly.
  7. OTOH, if you want to talk to us, we'll be happy to treat our education customers with the respect they deserve
  8. This is a valid concern with the free editions - we do commercially supported filtering options (and some ISPs will resell these too) which are very easy to manage once set up. You will almost certainly be OK on a DSL line with so few PCs, I would personally avoid the expense of a leased line, and go with consumer grade dsl.
  9. If you manually stick that wpad file into a browser's config (its functionally equivalent to proxy.pac, put it there), does that work?
  10. Suggest you hunt out a decent IFA as well - good one can save you $ and help explain stuff like this. If you're in west yorks area I know just the chap.
  11. You might find this Camera Price Buster - UKs cheapest camera gear useful. Definitely try bargaining in highstreet shops. I got mine in PC world Leeds. Advantage there is you can see jessops from their window... "i'm just going to head over there then..." just stick to your guns.
  12. I got my 40D from PC world when the 50D had just come out... managed to get £200 off. Took an hour of bargaining though! Bodies tend to lose value quickly... i'd hope you'd get one on ebay fairly sharpish that would be ok, but i'd be inclined to look for new old-stock style bargains.
  13. Only just saw this post. Yes to cumulative filter. Call me to good ideas! 0113 3874166 don't think my signature works on mobile.
  14. Hm, they do sell CDs still, maybe they are out of touch enough to think that pirates use a technology from 1971 to rip off their starving artistes..
  15. Mr hicks is right (sorry, meant to answer that too... one of those "at work" posts where i get interrupted 6-8 times during writing)... this will have been a random portscan looking for something to attack. What malware types want is an ftp site to which they can upload stuff that will be served on the web. This isn't because they cant afford their own bandwidth, but to leverage "url trust" somewhere else - say they manage to put malware payload on a company's website, they can reliably hope that won't be blocked by "dumb" url filters and it might get plenty of passing visitors to infect. They'll pick a block of IPs, and scan for services, sometimes selling IP:service lists to others who then do the attack, sometimes they do the attack themselves. You are more likely to be attacked if you have a dns entry, or you're on a static IP as these are decently indicitave of value. Just to re-iterate earlier advice... FTP probably _is_ the tool for the job (especially if a break in would be quickly noticed and little harm could be done as you are backed up) - online services will prove costly for your data volumes, and vpn is overkill (especially if your dad is not uber-savvy). The only options i'd table if you're concerned are scp and sftp, but neither of these directly mitigate brute force attacks like the one seen - though pubkey ssh auth does, it is again subject to marginal setup overhead. Oh.. and you could make your ftp directory readonly. That sounds like "a plan". Best of luck
  16. FTP is inherently insecure, but this has to be taken with a few caveats... the reason it is insecure is that user credentials are generally transmitted in the clear. This is exploited by sniffing packets along the network route between user (your dad) and ftp server. Obviously this hasn't happened - if they had sniffed a password they would not be brute forcing. As such, there's no "problem" with insecure FTP as long as you are vigilant (it seems you are) and your dad keeps his machine looked after (some viruses install keyloggers that look for ftp creds). Easy Suggestions: Back up the photos - if someone does break in, they are more likely to add than remove, but this wont hurt Make sure no accounts are enabled with "standard" names like root, anonymous, guest Make sure your dad's password is better than trivially complex Slightly harder suggestions, depending on your FTP server SecureFTP (doesn't mitigate this issue, may help others, less likely to ) Block all IPs not in the netblock of your Dad's ISP (assume he's on a dynamic IP) Use a nonstandard port (yick, makes your dad have to work something... if hes anything like my dad, thats a non-starter) Check his password with John The Ripper Use something like denyhosts (is denyhosts ssh only...? meh..) Use SSH/SCP - would require him to use winscp Run the ftp daemon in a chroot jail to protect the rest of your server Dont show the welcome banner until after user auth
  17. Once went in the wife's bag for an umbrella at here instruction... "which one do you want?" was my reply Yesterday I looked in there and saw 6 pens, without moving anything, if i dug I bet there are 15. I'm not allowed to"rat" in her bag though
  18. UI wise it hasn't changed a right lot... since 30/3 anyway
  19. @john; yeah, happy for you to do that. Are you on a release version yet, BTW?
  20. I'm not sold on "3 click anywhere" personally - i'd rather have 4 clicks that make sense over 3 that don't The G3 interface makes some stuff really easy - for example blocking and allowing sites. Setup is always going to be slightly more complicated than some, as we offer so much choice in authentication, for example. There are still some points where our interface isn't as i'd like if i'm honest, but G3 represents a good step forward, as did last year's new Auth setup. Sure someone here would be happy to give you a dem.
  21. @simcfc - which driver is it that you need updating? There are new drivers in this release, however it will be a little while before what we have released, and is being trickled out, makes it onto a new built ISO image. This means it might be "quite hard" to get your micro server working just yet, as you'd have to at least get the disks & network recognised before you could install the relevant update IYSWIM.
  22. Next bett will be my 10th - and I can honestly say i don't think there's one thing i'll miss about the olympia. Given that i've done 9 Infosecs at Olympia or Earls Court, it will be nice to be in a new area of london too!
×
×
  • Create New...