January 2008
Integrating amavisd-new Into Postfix For Spam- And Virus-Scanning
by lecyborg & 1 otherThis article shows how to integrate amavisd-new into a Postfix mail server for spam- and virus-scanning. amavisd-new is a high-performance interface between MTAs such as Postfix and content checkers: virus scanners, and/or SpamAssassin. We will use ClamAV for virus scanning and SpamAssassin for spam scanning in this tutorial.
I want to say first that this is not the only way of setting up such a system. There are many ways of achieving this goal but this is the way I take. I do not issue any guarantee that this will work for you!
December 2007
PHP Login script
by lecyborg & 2 othersIf you're looking for a serious script to manage your users then you're at the right place. Built with security in mind and packed with dozens of features, our PHP login script is the right solution for every webmaster looking to take his website to the next level. Trust us, we've stayed (and we still do for early versions) open-source long enough to learn what people really need.
November 2007
SSH-Agent Tutorial
by lecyborg & 1 otherSecurity is best when it is handy. ssh-agent is pretty darn handy. Ssh-agent can authenticate you to a remote machine via keypairs, rather than the traditional hand-typed username/password combination, with no loss of security.
Certificat SSL client apache
by lecyborgSSL côté client
Pour accéder à ce serveur, le client devra posséder un certificat authentifié par (c'est à dire signé ou crypté par la clé privée de) l'autorité de certification choisie. Pour produire un tel certificat au format PKCS#12
How to Install Openvpn
by lecyborgThe purpose of this document is to describe how to install OpenVPN server on an Ubuntu Linux system and have it utilize an Ethernet bridge to access your local network. Ethernet bridges essentially allow the operating system to treat multiple network interfaces as one combined port. When used with OpenVPN a bridge will allow you to easily connect external users to your internal network and have them receive all traffic as though they were locally connected. The alternative is to use OpenVPN with a route but that will not allow some forms of traffic through (such as multicast), multicast traffic is important to me as many games require multicast data.
IPtables log analizer
by lecyborgIPTables log analizer (TODO : find a nice name for it) displays Linux 2.4 iptables logs (rejected, acepted, masqueraded packets...) in a nice HTML page (it support rough netfilter logs but also Shorewall and Suse Firewall logs).
This page shall be easy to read and understand to reduce the manual analysis time.
This page containts statistics on packets and links to more detailled information on a given host, port, domain and so on.
firewall Eyes : iptables log analysis tool
by lecyborgFirewall Eyes est un outil d'analyse de logs en temps réel pour le pare-feu iptables. Grâce à une interface Web, vous visualisez et supervisez simplement et efficacement l'activité réseau traversant votre firewall.
Vous détectez aisément les activités suspectes et ajustez votre politique de sécurité.
October 2007
Running eBox on debian sarge
by lecyborg & 2 othersThis article shows how to run a file-, print-, HTTP proxy- DHCP-, and time server for small and medium enterprises (SME) on one single Debian Sarge system. It is very easy to set up, and management is done with an easy-to-use web interface called eBox so once the system is set up, you can forget about the command line. eBox was developed to administrate advanced services for corporate networks, and it was created for Debian Sarge.
I want to say first that this is not the only way of setting up such a system. There are many ways of achieving this goal but this is the way I take. I do not issue any guarantee that this will work for you!
Smoothwall router on XenEnterprise - community.smoothwall.org
by lecyborgHowto run smoothwall on Xen.
The perfect start with Smoothwall Express 3.0
by lecyborgSmoothwall Express is an internet firewall, which allows you to protect your network, as well as providing NAT functionality. It is ease to use and configurable via a web-based GUI. This open source firewall distribution requires absolutely no knowledge of Linux to install or use. This workshop shows the installation and basic configuration of the current release Smoothwall Express 3.0.
Firewall et sécurisation d'un réseau personnel sous Linux
by lecyborg & 1 otherCe document a pour but d'expliquer les rudiments de la sécurité d'une machine Linux placée dans un réseau local (typiquement une maison on un appartement), reliée à Internet. Il est tout particulièrement destiné aux utilisateurs néophytes, ou n'ayant pas ou peu de connaissance sur la sécurité informatique en général, et sous Linux en particulier.
June 2007
Pinholes, DMZ et ipcop
by lecyborgThread de forum décrivant le fonctionnement des Pinholes sous IPcop
HOWTO: IPCop-OpenVPN
by lecyborg & 2 othersI’m a huge fan of IPCop. It’s a great firewall distro that makes administration a snap using a slick web interface. My goal was to use IPCop and an easy-to-use VPN client to allow access to my LAN while away from home.
I ended up going with the ZERINA OpenVPN addon for IPCop and the OpenVPN GUI for Windows.
Howto Roadwarrior | ZERINA - OpenVPN for IPCops
by lecyborgHowto for ZERINA 0.9.0b - ZERINA 0.9.4b
This howto will guide you step by step on howto configure the OpenVPN addon, so that you can run an OpenVPN server on your IPCop firewall, so that roadwarrior clients (Win32 in this howto)can reach your lan.
This is what we call "hassle free roadwarrior vpn" ;-)
April 2007
SÉCURITÉ Ssh sans mot de passe
by lecyborgOu comment se connecter à une machine distante sans avoir à rentrer son mot de passe.
Il existe une méthode de configuration plus rapide. Vous pouvez en une seule commande ajouter votre clé dans le fichier `authorized_keys` du serveur distant grâce à `ssh-copy-id`. Pour cela procédez comme suit :
Sandcat Web Application Security
by lecyborgSandcat allows web administrators to perform aggressive and comprehensive scans of an organization's web server to isolate vulnerabilities and identify security holes.
The Sandcat scanner requires basic inputs such as host names, start URLs and port numbers to scan a complete web site and test all the web applications for security vulnerabilities.
De la sécurité d'une architecture DNS d'entreprise
by lecyborg & 1 otherTutorial très détaillé avec des graphiques
March 2007
Providing Active Directory authentication via Kerberos protocol in Apache
by lecyborgProviding Active Directory authentication via Kerberos protocol in Apache
Forums: Samba et Active Directory
by lecyborg & 1 otherUn serveur samba doit etre integré au domaine de la meme facon qu'un poste windows : par un administrateur du domaine. Méthode d'ajout dans le domaine.
Configuration du SSO NTLM pour Apache 2
by lecyborgTutorial en français pour permettre à apache d'authentifier les gens sous Windows
January 2007
Squid content filtering
by lecyborgBloquer et interdire l'accès a certains fichiers avec Squid, le proxy. Ici exemple pour la musique et les vidéos.
Backdooring configuration files
by lecyborg & 1 otherOu comment avec la main quelques secondes on peut faire bien plus sur une machine
1
(25 marks)