<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>[LINICKX].com &#187; Security</title>
	<atom:link href="http://www.linickx.com/tag/security/feed" rel="self" type="application/rss+xml" />
	<link>http://www.linickx.com</link>
	<description>Moments of Genius followed by Trash.</description>
	<lastBuildDate>Tue, 07 Feb 2012 15:06:32 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.3.1</generator>
		<item>
		<title>Hacking Cisco ISE UDI</title>
		<link>http://www.linickx.com/3550/hacking-cisco-ise-udi</link>
		<comments>http://www.linickx.com/3550/hacking-cisco-ise-udi#comments</comments>
		<pubDate>Tue, 07 Feb 2012 10:06:06 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[Hacking]]></category>
		<category><![CDATA[ISE]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[VM]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3550</guid>
		<description><![CDATA[The back story&#8230; you&#8217;ve deployed your ISE appliance and the world is great! Your management need you to make a change &#8220;right now&#8221; but that virtual machine in the lab you have been using for testing is 91 days old &#8230; <a href="http://www.linickx.com/3550/hacking-cisco-ise-udi">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.linickx.com/files/2012/02/ISE-CAM-VM-CLEAN.png" rel="lightbox[3550]"><img src="http://www.linickx.com/files/2012/02/ISE-CAM-VM-CLEAN-150x150.png" alt="ISE Virtual Machine that thinks it a CAM" title="ISE-CAM-VM-CLEAN" width="150" height="150" class="alignright size-thumbnail wp-image-3552" /></a><br />
The back story&#8230; you&#8217;ve deployed your <a href="http://www.cisco.com/go/ise">ISE appliance</a> and the world is great! Your management need you to make a change &#8220;right now&#8221; but that virtual machine in the lab you have been using for testing is 91 days old and the eval no longer works. You raise a case to get budget and a PO over to Cisco for a lab ISE appliance or license but this change is critical, if only there was a way to use your appliance license on your VM?</p>
<p>Perhaps you should log into your ISE appliance and make a note of the Product Identifier (PID), Version Identifier (VID) and the Serial Number (SN).</p>
<p>What you might want to do now is shutdown your ISE VM and mount the disk&#8230; I always have a <a href="http://centos.org/">CentOS</a> server kicking around for this kind of thing, so if I was to do this, I would mount the ISE virtual disk as an extra disk that CentOS has access to.</p>
<p>From within CentOS you can use fdisk -l to view the hard drive partitions&#8230; When you&#8217;re hacking a VM you mount as many of the ISE partitions as you can (<em>some will fail</em>) to see what&#8217;s there. On my test machine <code>/dev/sdb7</code> was the partition of interest as it had an <code>/opt</code> directory (<em>cisco always install stuff in opt</em>).</p>
<p>Inside <code>mount-point/opt/system/bin/</code> you might find a file called <code>cars_udi_util</code>, that&#8217;s the puppy that the license is bound to.</p>
<p>What you might want to do is rename that file and replace it with something that always gives the &#8220;right&#8221; answer. Attached is <a href="http://www.linickx.com/files/2012/02/cars_udi_util.txt">cars_udi_util.txt</a>, a shell script I have been testing, edit the top of the file and insert the PID/VID/SN you found earlier.</p>
<p>Now save the <a href="http://www.linickx.com/files/2012/02/cars_udi_util.txt">cars_udi_util.txt</a> to <code>mount-point/opt/system/bin/cars_udi_util</code>, that&#8217;s right <b>remember to remove the <code>.txt</code>!</b></p>
<p>Unmount the disk, shutdown Centos and boot up ISE. </p>
<p>Now I&#8217;ve been hacking my machine and after this change the services wouldn&#8217;t start (<code>show application status ise</code>) to fix that I ran <code>application reset-config ise</code> from the ISE CLI Shell, rebooted and Voila! &#8230;The machine booted up with a blank default config.</p>
<p>After changing the default admin password (<em>from cisco</em>) it would now be possible for you to use your proper appliance license on your VM&#8230; of course this is only a temporary thing and I fully expect &amp; recommend you undo these changes as soon as your new license arrives from Cisco.</p>
<p>Happy Hacking!</p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3550/hacking-cisco-ise-udi/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>password-less ssh login to JunOS</title>
		<link>http://www.linickx.com/3537/password-less-ssh-login-to-junos</link>
		<comments>http://www.linickx.com/3537/password-less-ssh-login-to-junos#comments</comments>
		<pubDate>Tue, 17 Jan 2012 13:35:05 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[id_rsa]]></category>
		<category><![CDATA[Juniper]]></category>
		<category><![CDATA[JunOS]]></category>
		<category><![CDATA[ssh]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3537</guid>
		<description><![CDATA[Juniper (JunOS) SRX&#8217;s support ssh public key authentication. No-one likes to type passwords! Copyright &#169; 2012 [LINICKX].com. This Feed is for personal non-commercial use only. Please check my Site Terms and Conditions for full details on copyrights. If you have &#8230; <a href="http://www.linickx.com/3537/password-less-ssh-login-to-junos">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p><a href="http://www.linickx.com/files/2012/01/junos_login.png" rel="lightbox[3537]"><img src="http://www.linickx.com/files/2012/01/junos_login.png" alt="" title="junos_login" width="471" height="234" class="aligncenter size-full wp-image-3538" /></a></p>
<p>Juniper (JunOS) SRX&#8217;s support ssh public key authentication.</p>
<pre class="brush: plain; title: ; notranslate">
nick&gt; show configuration system login | display set
set system login user nick uid 2001
set system login user nick class super-user
set system login user nick authentication ssh-rsa &quot;PASTE_KEY&quot;
nick&gt;
</pre>
<p>No-one likes to type passwords!</p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3537/password-less-ssh-login-to-junos/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Blue Coat Proxy, iPhone&#8217;s multiple authentication issues.</title>
		<link>http://www.linickx.com/3520/blue-coat-proxy-iphones-multiple-authentication-issues</link>
		<comments>http://www.linickx.com/3520/blue-coat-proxy-iphones-multiple-authentication-issues#comments</comments>
		<pubDate>Wed, 04 Jan 2012 07:59:18 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Security]]></category>
		<category><![CDATA[authentication]]></category>
		<category><![CDATA[bluecoat]]></category>
		<category><![CDATA[ipad]]></category>
		<category><![CDATA[iphone]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3520</guid>
		<description><![CDATA[Recently a colleague pointed me at the following Blue Coat KB about NTLM issues as basically the iPhones on the corp network were getting multiple authentication challenges even though the username &#038; password are saved in the connection profile! To &#8230; <a href="http://www.linickx.com/3520/blue-coat-proxy-iphones-multiple-authentication-issues">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>Recently a colleague pointed me at the following Blue Coat <a href="https://kb.bluecoat.com/index?page=content&#038;id=KB4741">KB about NTLM issues</a> as basically the iPhones on the corp network were getting multiple authentication challenges even though the username &#038; password are saved in the connection profile!</p>
<p>To resolve we created a second authentication realm on the bluecoat with Kerberos &#038; NTLM authentication disabled (<em> i.e. only basic auth</em>), we then created an authentication rule which matches user agent strings and authenticates against the new basic-only realm. Below is some command lines to point you in the right direction:</p>
<pre class="brush: plain; title: ; notranslate">
!- BEGIN authentication
security iwa create-realm uk 10.10.10.10 16101
security iwa edit-realm uk ;mode
alternate-server 10.10.10.11 16101
exit
security iwa create-realm ukBasicAuth 10.10.10.10 16101
security iwa edit-realm ukBasicAuth ;mode
alternate-server 10.10.10.11 16101
credentials-kerberos disable
credentials-ntlm disable
exit
</pre>
<p>I should point out that the KB is out of date; upon implementing we noticed a lot of windows users getting unwanted authentication challenges therefore I suggest you only match against <code>iphone</code> &amp; <code> ipad</code>&#8230; in-fact I stuck <code>Macintosh</code> in as well and my macbook is getting less challenges too!</p>
<p>Enjoy the CPL goodness below!</p>
<pre class="brush: plain; title: ; notranslate">
;; Description: BlueCoat KB4741
define condition __CondList1BasicUserAgents
        request.header.User-Agent=&quot;iphone&quot;
        request.header.User-Agent=&quot;ipad&quot;
        request.header.User-Agent=&quot;Macintosh&quot;
        request.header.User-Agent=&quot;CFNetwork&quot;
end condition __CondList1BasicUserAgents

define condition BasicUserAgents
        condition=__CondList1BasicUserAgents
end condition BasicUserAgents

&lt;Proxy&gt;
        condition=BasicUserAgents authenticate(ukBasicAuth)  authenticate.force(no) authenticate.mode(proxy)    ; KB4741
        authenticate(uk)  authenticate.force(yes) authenticate.mode(proxy)      ; All Internet Traffic
</pre>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3520/blue-coat-proxy-iphones-multiple-authentication-issues/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Cisco ASA Firewalls and IP Ranges in ACLS</title>
		<link>http://www.linickx.com/3205/cisco-asa-firewalls-and-ip-ranges-in-acls</link>
		<comments>http://www.linickx.com/3205/cisco-asa-firewalls-and-ip-ranges-in-acls#comments</comments>
		<pubDate>Fri, 29 Jul 2011 15:05:55 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[asa]]></category>
		<category><![CDATA[bash]]></category>
		<category><![CDATA[firewall]]></category>
		<category><![CDATA[script]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3205</guid>
		<description><![CDATA[I&#8217;ve google&#8217;d and I cannot find a way of creating a firewall range style object in an ASA, you know the kind of thing whereby you want to allow IP addresses 192.168.1.10 thru 192.168.1.20 in an ACL. In my frustration &#8230; <a href="http://www.linickx.com/3205/cisco-asa-firewalls-and-ip-ranges-in-acls">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve google&#8217;d and I cannot find a way of creating a firewall range style object in an ASA, you know the kind of thing whereby you want to allow IP addresses 192.168.1.10 thru 192.168.1.20 in an ACL.</p>
<p>In my frustration I have given up and created a shell script which converts a CSV into an ASA output, simply create a two column CSV with Col A containing your starting IP and Col B containing you end IP.</p>
<p>The script is a recursive loop so should support large outputs such as 10.1.2.10 to 10.2.1.20 howvere I&#8217;m not actually sure you&#8217;d want that in your firewall config but I wrote the computability for the fun it!</p>
<p>Have fun, click &#8220;more&#8221; below if you can&#8217;t see the script!</p>
<p><span id="more-3205"></span></p>
<pre class="brush: bash; title: ; notranslate">
#!/bin/bash

# Commas separated VAR....
IFS=&quot;,&quot;
while read name firstip lastip
# Loop around CSV
do

# Split up our first ip into it's octects
firstipfirstoctect=$(echo $firstip | awk -F &quot;.&quot; '{print $1}')
firstipsecondoctect=$(echo $firstip | awk -F &quot;.&quot; '{print $2}')
firstipthirdoctect=$(echo $firstip | awk -F &quot;.&quot; '{print $3}')
firstipforthoctect=$(echo $firstip | awk -F &quot;.&quot; '{print $4}')

# Split up our last IP into it's ocects
lastipfirstoctect=$(echo $lastip | awk -F &quot;.&quot; '{print $1}')
lastipsecondoctect=$(echo $lastip | awk -F &quot;.&quot; '{print $2}')
lastipthirdoctect=$(echo $lastip | awk -F &quot;.&quot; '{print $3}')
lastipforthoctect=$(echo $lastip | awk -F &quot;.&quot; '{print $4}')

	# Re-set BASH
	unset IFS 

	# Echo out the object GROUP name
	echo &quot;object-group network $name&quot;

	# Loop through 1st Octect
	for a in `seq $firstipfirstoctect $lastipfirstoctect`;
	do
		# test to see if we need to print the whole range
		if [ $firstipfirstoctect -lt $lastipfirstoctect ]
		then
			firstipsecondoctectCOUNTER=&quot;0&quot;
			lastipsecondoctectCOUNTER=&quot;255&quot;
		fi

		# first IP might not be 1
		if [ $a -eq $firstipfirstoctect ]
		then
			firstipsecondoctectCOUNTER=$firstipsecondoctect
		fi

		# last IP might not be 255
		if [ $a -eq $lastipfirstoctect ]
		then
			lastipsecondoctectCOUNTER=$lastipsecondoctect
		fi

			# Loop through 2nd Octect
			for b in `seq $firstipsecondoctect $lastipsecondoctect`;
			do

				# Same tests as before except, next octect.
				if [ $firstipsecondoctect -lt $lastipsecondoctect ]
				then
					firstipthirdoctectCOUNTER=&quot;0&quot;
					lastipthirdoctectCOUNTER=&quot;255&quot;
				fi

				if [ $b -eq $firstipsecondoctect ]
				then
					firstipthirdoctectCOUNTER=$firstipthirdoctect
				fi

				if [ $b -eq $lastipsecondoctect ]
				then
					lastipthirdoctectCOUNTER=$lastipthirdoctect
				fi

					# Loop through 3rd Octect
					for c in `seq $firstipthirdoctectCOUNTER $lastipthirdoctectCOUNTER`;
					do

						# copy / paste / tweak
						if [ $firstipthirdoctect -lt $lastipthirdoctect ]
						then
							firstipforthoctectCOUNTER=&quot;0&quot;
							lastipforthoctectCOUNTER=&quot;255&quot;
						fi

						if [ $c -eq $firstipthirdoctect ]
						then
							firstipforthoctectCOUNTER=$firstipforthoctect
						fi

						if [ $c -eq $lastipthirdoctect ]
						then
							lastipforthoctectCOUNTER=$lastipforthoctect
						fi

							# final octect... echo result.
							for d in `seq $firstipforthoctectCOUNTER $lastipforthoctectCOUNTER`;
							do
								echo &quot; network-object $a.$b.$c.$d  255.255.255.255&quot;
							done

					done
			done
	done

done&lt;./FirewallRanges.csv
</pre>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3205/cisco-asa-firewalls-and-ip-ranges-in-acls/feed</wfw:commentRss>
		<slash:comments>2</slash:comments>
		</item>
		<item>
		<title>Secret Keys for the Cloud</title>
		<link>http://www.linickx.com/3343/secret-keys-for-the-cloud</link>
		<comments>http://www.linickx.com/3343/secret-keys-for-the-cloud#comments</comments>
		<pubDate>Mon, 25 Jul 2011 14:56:09 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[github]]></category>
		<category><![CDATA[secretkey]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3343</guid>
		<description><![CDATA[I&#8217;ve had an idea, whether it&#8217;s a good one or not is yet to be seen; one of the big issues to cloud application and servers is encryption key management, there is a simple chicken n egg issue, if the &#8230; <a href="http://www.linickx.com/3343/secret-keys-for-the-cloud">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve had an idea, whether it&#8217;s a good one or not is yet to be seen; one of the big issues to cloud application and servers is encryption key management, there is a simple chicken n egg issue, if the secret key is on the server/application then it&#8217;s a vector to be attacked if the key isn&#8217;t then usability issues exist.</p>
<p>My idea is a CA / DH kinda thing, what if the actual key used for encryption was derived from the cloud it&#8217;s self, the basic premise is adding an extra layer to be compromised in order for an attacker to decypt the data.</p>
<p>Using RedHat&#8217;s new <a href="http://openshift.redhat.com/">OpenShift</a> service I&#8217;ve knocked up a demo -> <a href="https://secretkey-linickx.rhcloud.com/">secretkey-linickx.rhcloud.com</a>.<del datetime="2011-07-26T19:50:57+00:00"> The demo is over HTTP (not HTTPS) so</del> You wouldn&#8217;t use the demo in production probably because you do not trust me but I&#8217;ve pushed the code to github -> <a href="https://github.com/linickx/secretkey">github.com/linickx/secretkey</a> for users/dev/people/someone to take a copy and have a play.</p>
<p>Comments welcome, <strong>Pull requests preferred</strong>!</p>
<p><strong>2011-07-26 UPDAT</strong>E: Openshift has SSL termination, HTTPS does work, however as seen in <a href="https://github.com/linickx/secretkey/commits/master">my commit log</a> the PHP cannot detect it as the SSL is being handled by a proxy.</p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3343/secret-keys-for-the-cloud/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Undelete</title>
		<link>http://www.linickx.com/3274/undelete</link>
		<comments>http://www.linickx.com/3274/undelete#comments</comments>
		<pubDate>Sat, 30 Apr 2011 07:13:51 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[del.icio.us]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[undelete]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3274</guid>
		<description><![CDATA[I&#8217;ve just used this little gem to recover files off a memory card&#8230; awesome! PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from hard disks, CD-ROMs, and lost pictures (thus the Photo &#8230; <a href="http://www.linickx.com/3274/undelete">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;ve just used this little gem to recover files off a memory card&#8230; awesome!</p>
<blockquote><p>PhotoRec is file data recovery software designed to recover lost files including video, documents and archives from hard disks, CD-ROMs, and lost pictures (thus the Photo Recovery name) from digital camera memory. PhotoRec ignores the file system and goes after the underlying data, so it will still work even if your media&#8217;s file system has been severely damaged or reformatted.<br />
PhotoRec is free &#8211; this open source multi-platform application is distributed under GNU General Public License.</p></blockquote>
<p>Link: <a href="http://www.cgsecurity.org/wiki/PhotoRec">http://www.cgsecurity.org/wiki/PhotoRec</a></p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3274/undelete/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Help combat phising</title>
		<link>http://www.linickx.com/3242/help-combat-phising</link>
		<comments>http://www.linickx.com/3242/help-combat-phising#comments</comments>
		<pubDate>Thu, 03 Mar 2011 08:00:25 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[del.icio.us]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[bookmarks]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3242</guid>
		<description><![CDATA[People receiving scam emails are urged to forward them on to email@actionfraud.org.uk. Reference: http://www.actionfraud.org.uk/help-disrupt-fraudsters-by-reporting-scam-emails-feb11 Copyright &#169; 2012 [LINICKX].com. This Feed is for personal non-commercial use only. Please check my Site Terms and Conditions for full details on copyrights. If you have any &#8230; <a href="http://www.linickx.com/3242/help-combat-phising">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<blockquote><p>People receiving scam emails are urged to forward them on to <strong><a href="mailto:email@actionfraud.org.uk">email@actionfraud.org.uk</a></strong>.</p></blockquote>
<p>Reference: <a href="http://www.actionfraud.org.uk/help-disrupt-fraudsters-by-reporting-scam-emails-feb11">http://www.actionfraud.org.uk/help-disrupt-fraudsters-by-reporting-scam-emails-feb11</a></p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3242/help-combat-phising/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco ACS 5.2 works in VirtualBox</title>
		<link>http://www.linickx.com/3229/cisco-acs-5-2-works-in-virtualbox</link>
		<comments>http://www.linickx.com/3229/cisco-acs-5-2-works-in-virtualbox#comments</comments>
		<pubDate>Wed, 02 Mar 2011 18:33:47 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Cisco]]></category>
		<category><![CDATA[PICS]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[acs]]></category>
		<category><![CDATA[Screenshot]]></category>
		<category><![CDATA[virtualbox]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3229</guid>
		<description><![CDATA[My how to get ACS 5.1  running in VirtualBox is one of my more popular posts; recently I was asked if 5.2 would work, the answer is yes! I&#8217;ve posted an updated ks.cfg &#8230; if you compare it to the &#8230; <a href="http://www.linickx.com/3229/cisco-acs-5-2-works-in-virtualbox">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>My <a title="Cisco ACS 5.1 in VirtualBox" href="http://www.linickx.com/archives/2961/cisco-acs-5-1-in-virtualbox">how to get ACS 5.1  running in VirtualBox</a> is one of my more popular posts; recently I was asked if 5.2 would work, the answer is yes!</p>
<p><a href="http://www.linickx.com/files/2011/03/ACS_5-2_inVirtualBox.png" rel="lightbox[3229]"><img class="aligncenter size-medium wp-image-3234" title="Cisco ACS 5.2 in VirtualBox" src="http://www.linickx.com/files/2011/03/ACS_5-2_inVirtualBox-300x187.png" alt="" width="300" height="187" /></a></p>
<p>I&#8217;ve posted an updated <a title="Kick Start file for ACS 5.2" href="http://www.linickx.com/files/2011/03/ks.cfg_.txt">ks.cfg</a> &#8230; if you compare it to <a title="Kickstart File for ACS 5.1" href="http://www.linickx.com/files/2010/03/ks.cfg_.txt">the old one</a> the only real difference is an updated set of version numbers, all the other instructions are exactly the same&#8230;.well, except now <a href="http://vault.centos.org/4.7/isos/i386/">centos 4.7 can be found in the vault</a> <img src='http://www.linickx.com/wp/wp-includes/images/smilies/icon_smile.gif' alt=':)' class='wp-smiley' /> </p>
<p>Next I plan to see if I can make this work in EC2 as I recon a cloud based ACS server would be pretty cool, wish me luck and enjoy the 5.2 goodness!</p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3229/cisco-acs-5-2-works-in-virtualbox/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>5 Minute CentOS/RHEL VPN</title>
		<link>http://www.linickx.com/3181/5-minute-centosrhel-vpn</link>
		<comments>http://www.linickx.com/3181/5-minute-centosrhel-vpn#comments</comments>
		<pubDate>Sun, 23 Jan 2011 09:51:09 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Enterprise Linux]]></category>
		<category><![CDATA[Linux]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[centos]]></category>
		<category><![CDATA[vpn]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3181</guid>
		<description><![CDATA[I&#8217;m looking at running two servers on EC2; as we all know the most important thing about running services in the cloud is encryption! Whilst googling on how to setup a host-to-host IPSEC VPN I was surprised at how easy &#8230; <a href="http://www.linickx.com/3181/5-minute-centosrhel-vpn">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m looking at running two servers on EC2; as we all know the most important thing about running services in the cloud is <strong>encryption</strong>!</p>
<p>Whilst googling on how to setup a host-to-host IPSEC VPN I was surprised at how easy it is&#8230;</p>
<p>On Host1 (192.168.56.101)&#8230;</p>
<pre class="brush: bash; title: ; notranslate">
[root@CentOS1 ~]# cat /etc/sysconfig/network-scripts/ifcfg-ipsec1
DST=192.168.56.102
TYPE=IPSEC
ONBOOT=no
IKE_METHOD=PSK
[root@CentOS1 ~]#
[root@CentOS1 ~]# cat /etc/sysconfig/network-scripts/keys-ipsec1
IKE_PSK=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
[root@CentOS1 ~]#
[root@CentOS1 ~]# ifup ipsec1
</pre>
<p>On host2 (192.168.56.102)&#8230;</p>
<pre class="brush: bash; title: ; notranslate">
[root@CentOS2 ~]# cat /etc/sysconfig/network-scripts/ifcfg-ipsec1
DST=192.168.56.101
TYPE=IPSEC
ONBOOT=no
IKE_METHOD=PSK
[root@CentOS2 ~]#
[root@CentOS2 ~]# cat /etc/sysconfig/network-scripts/keys-ipsec1
IKE_PSK=xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
[root@CentOS2 ~]#
[root@CentOS2 ~]#ifup ipsec1
</pre>
<p>&#8230; done!!!</p>
<pre class="brush: bash; title: ; notranslate">
[root@CentOS1 ~]# tcpdump -n -i eth1 host 192.168.56.102
tcpdump: verbose output suppressed, use -v or -vv for full protocol decode
listening on eth1, link-type EN10MB (Ethernet), capture size 96 bytes
09:46:37.306292 IP 192.168.56.101 &gt; 192.168.56.102: AH(spi=0x0aff2b10,seq=0x203): ESP(spi=0x00a0a3cc,seq=0x203), length 84
09:46:37.310197 IP 192.168.56.102 &gt; 192.168.56.101: AH(spi=0x09f82154,seq=0x203): ESP(spi=0x098f0ff9,seq=0x203), length 68
09:46:38.175048 IP 192.168.56.101 &gt; 192.168.56.102: AH(spi=0x0aff2b10,seq=0x204): ESP(spi=0x00a0a3cc,seq=0x204), length 84
09:46:38.179017 IP 192.168.56.102 &gt; 192.168.56.101: AH(spi=0x09f82154,seq=0x204): ESP(spi=0x098f0ff9,seq=0x204), length 68
09:46:39.313583 IP 192.168.56.101 &gt; 192.168.56.102: AH(spi=0x0aff2b10,seq=0x205): ESP(spi=0x00a0a3cc,seq=0x205), length 84
09:46:39.316427 IP 192.168.56.102 &gt; 192.168.56.101: AH(spi=0x09f82154,seq=0x205): ESP(spi=0x098f0ff9,seq=0x205), length 68

6 packets captured
6 packets received by filter
0 packets dropped by kernel
[root@CentOS1 ~]#
</pre>
<p>Now this is a simple IKE pre-shared key vpn, you might want to google for using certificates for stronger authentication, you can also edit /etc/racoon/racoon.conf  to change your IPSEC parameters.</p>
<p>Reference: <a href="http://www.centos.org/docs/5/html/Deployment_Guide-en-US/ch-vpn.htm">http://www.centos.org/docs/5/html/Deployment_Guide-en-US/ch-vpn.html</a></p>
<p><strong>UPDATE: To make this work in EC2, <a href="http://www.linickx.com/archives/3195/centosredhat-ipsec-and-ec2">you need to enable NAT-T see my hack here</a>!</strong></p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3181/5-minute-centosrhel-vpn/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
		<item>
		<title>Cisco: Uninstalling the CSD ActiveX Control</title>
		<link>http://www.linickx.com/3140/cisco-uninstalling-the-csd-activex-control</link>
		<comments>http://www.linickx.com/3140/cisco-uninstalling-the-csd-activex-control#comments</comments>
		<pubDate>Fri, 10 Dec 2010 10:53:14 +0000</pubDate>
		<dc:creator>Nick</dc:creator>
				<category><![CDATA[Blog]]></category>
		<category><![CDATA[Cisco]]></category>
		<category><![CDATA[Security]]></category>
		<category><![CDATA[CSD]]></category>
		<category><![CDATA[internet explorer]]></category>

		<guid isPermaLink="false">http://www.linickx.com/?p=3140</guid>
		<description><![CDATA[I&#8217;m installing Cisco Secure Desktop (CSD) for a customer and needed to re-test the installation process. Within internet explorer&#8217;s (IE Version 7 &#038; 8 ) managed add-on feature, I noticed that the CSD ActiveX Control doesn&#8217;t have an uninstall feature. &#8230; <a href="http://www.linickx.com/3140/cisco-uninstalling-the-csd-activex-control">Continue reading <span class="meta-nav">&#8594;</span></a>]]></description>
			<content:encoded><![CDATA[<p>I&#8217;m installing Cisco Secure Desktop (CSD) for a customer and needed to re-test the installation process. Within internet explorer&#8217;s (IE Version 7 &#038; 8 ) managed add-on feature, I noticed that the CSD ActiveX Control doesn&#8217;t have an uninstall feature.</p>
<p>To remove the control I had to close IE, browse to&#8230;</p>
<pre class="brush: plain; title: ; notranslate">C:\Windows\Downloaded Program Files</pre>
<p>..and remove the following files..</p>
<pre class="brush: plain; title: ; notranslate">
CSDWebInstaller.inf
CSDWebInstaller.ocx
</pre>
<p>When re-starting IE the control was gone and I could test the re-install, I hope this helps some other googler! <img src='http://www.linickx.com/wp/wp-includes/images/smilies/icon_cool.gif' alt=':cool:' class='wp-smiley' /> </p>
<img src="http://www.linickx.com/wp/wp-content/themes/linickx_v2/images/nick_sig_bggrey.png" alt="Nick" /> <hr/>Copyright &copy; 2012 <strong><a href="http://www.linickx.com">[LINICKX].com</a></strong>. This Feed is for personal non-commercial use only. Please check my <a href="http://www.linickx.com/?page_id=63">Site Terms and Conditions</a> for full details on copyrights. If you have any concerns with the content of this feed you may <a href="http://www.linickx.com/contact">contact me here</a>.<br/><span style="float: right;font-size: 7pt"><a href="http://blog.taragana.com/index.php/archive/wordpress-plugins-provided-by-taraganacom/">WP Copyright Plugin</a></span>]]></content:encoded>
			<wfw:commentRss>http://www.linickx.com/3140/cisco-uninstalling-the-csd-activex-control/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

